Compliance

AI in medicine: what ScaleQuality proves for you

Brazilian Federal Council of Medicine Resolution 2.454/2026 requires every medical institution, and every physician, that develops or contracts AI systems to maintain governance, classify risk and hand over audit reports when the Regional Council asks. This page shows, measure by measure, which evidence the platform produces and what remains the institution's own duty.

Who the resolution reaches

Article 14 says "the medical institution or the physician who develops or contracts". It does not reach only those who build AI: the hospital, the health plan and the clinic that merely use a third party tool also need a governance process. Enforcement sits with the Regional Council of Medicine (Art. 15), and the Technical Director answers for it (Annex III, III).

There is no adaptation period Article 21 applies the resolution to systems in development or already in use on the date it came into force, 26 August 2026. And Annex III, VIII requires the institution to be able to hand over audit, monitoring and configuration reports whenever an authority asks. Without continuous measurement, that report does not exist to be handed over.

That opens a second front for health software vendors: the hospital that contracts them now needs the vendor's evidence in order to answer its own Council.

Annex III: the eight mandatory measures

Article 14 makes the Annex III measures mandatory. Each one below, with the matching evidence.

#What the resolution requiresWhat the platform produces
ITransparency of AI use and governance, with regular reports in managerial languageAudit export: AI usage inventory, cost measured per area, human review coverage and policy violations
IIPrevention and mitigation of discriminatory bias, with stratified analysis of outputsRemains with the institution
IIIInternal governance, with the Technical Director responsible for oversightAI initiatives with a declared owner and an audit trail of who did what
IVInteroperability, with open standards and APIsPublic evidence API, internal portal integrations and SBOM in CycloneDX
VAuditable, configurable solutions rather than black boxesMethodology published with a permanent DOI under an open licence
VILifecycle managed as a product: requirements, validation, testing, deployment, periodic review in production, defect correction and safe evolutionEngineering and code maturity measured and versioned, quality gate in CI, fixes proven by re-scan, continuous vulnerability inventory
VIIIntegration interfaces with other institutions' health information systemsThe same evidence API and integrations as item IV
VIIIAccess for oversight bodies to audit, monitoring and configuration reportsAudit export carrying the source of each block, action trail in CSV or JSON, compliance diagnostic as PDF

In the body of the resolution

ArticleRequirementEvidence
Art. 9 §2Specialised audit and continuous monitoring mechanismsMeasurement on every build, with versioned history comparable across dates
Art. 17Security measures matching the state of the art and the criticality of the dataCode security analysis, secrets, infrastructure configuration and CVEs in dependencies and container image
Art. 6Confidentiality, integrity and security of health dataThe platform measures the software and never reads the content it processes

That last point usually settles the legal review: adopting ScaleQuality does not add a processor of sensitive patient data to the institution's chain.

What else the sector demands

The CFM resolution is the one with a date on it, but not the only one asking for evidence from whoever builds or runs health software. Below, what each demands and what the platform produces. The right column also says how it arrives: as a ready-made regulation inside the product, or as technical evidence feeding the technical file.

RegulationWhat it demandsWhat comes out of here
HIPAA · 45 CFR 164.520What the privacy notice must contain: uses and disclosures of health information, individual rights, the entity's duties and how to complainPoint by point review of the notice, citing the paragraphReady-made in the product, 37 criteria
ANVISA RDC 657/2022Lifecycle and quality evidence for software as a medical deviceCode maturity measured and versioned, with history comparable across releasesReady-made in the product, 29 criteria, plus versioned code maturity
IEC 62304 · SOUP controlIdentify third party software in the device and monitor known anomaliesContinuous dependency inventory with advisories, refreshed on every build instead of frozen in the fileTechnical evidence
FDA · section 524BSBOM and post market vulnerability surveillanceCycloneDX SBOM per repository and continuous CVE monitoring in dependencies and container imageTechnical evidence, exportable
ISO 14971 · risk managementA risk management file for the software, kept through the product's lifeRisks with severity and business impact, with a remediation trail proven by re-scanTechnical evidence
LGPD with sensitive dataTechnical safeguards in software that handles patient dataCode security, secrets, infrastructure and dependencies, measured continuouslyReady-made in the product, 40 criteria
About the paid standards IEC 62304 and ISO 14971 are copyrighted standards, unlike statutes and agency rules. The platform produces the evidence that supports meeting them, but does not reproduce their text: neither appears as a ready-made regulation inside the product, and that is a choice rather than a gap.

What remains the institution's duty

The platform produces technical evidence; it does not issue a regulatory opinion. These remain with the institution:

  • Classifying each system's risk as low, medium, high or unacceptable (Art. 12 and 13, Annex II)
  • Creating the AI and Telemedicine Committee under medical coordination (Art. 14, sole paragraph)
  • Recording AI use in the patient's medical record (Art. 4, V)
  • Informing the patient and honouring an informed refusal (Art. 5 and Art. 11)
  • Monitoring clinical bias in the model's outputs (Annex III, II)

We say this in the first conversation, not in the audit. A vendor promising to solve the whole regulation is usually the first one a committee distrusts, and rightly so: the Technical Director answers to the Council, not the vendor.

Where to start

Connect the repositories and the AI providers' admin key. Measurement starts with no rule to configure, and the baseline lands in the first week. In Content Compliance the CFM resolution ships ready as a context: pick the regulation, submit the consent form, the internal policy or the communication material, and get a point by point diagnostic citing the article behind each finding, as a PDF to attach to the file.

Official text of the resolution: Resolution CFM 2.454/2026 (PDF)