Skip to content

AI governance for medical device companies

Use AI with your business data. Keep quality and design files controlled.

Cocha helps medical device companies govern Claude and Copilot where they connect to Microsoft 365. Start with the access boundaries around design-history, quality-system, supplier, and submission-support files your teams use.

60-minute working session · Written findings · Follow-up review · No obligation to purchase

What your team needs to decide.

Design and quality evidence

Identify sensitive design-history and QMS records in SharePoint, Teams, or connected repositories, and confirm who should have access.

External collaboration

Review supplier and partner sharing, guest membership, and ownership of access reviews.

Controlled AI workflows

Agree on approved sources and use cases with IT, security, and quality stakeholders before expanding the rollout.

Govern access to evidence without changing its authority.

Start with a focused diagnostic. Where deeper analysis or changes are needed, we agree on a paid scope with your team before work begins. Implementation and ongoing advisory are tailored to the environment, not included in the free Snapshot.

A data-access view

Selected information sources, relevant permission questions, and evidence gaps for your team to investigate.

A bounded pilot

Approved users, connectors, and workflows, with human review of outputs and clear escalation to the appropriate owner.

Documented decisions

A record of agreed controls, outstanding issues, and responsibilities your IT and quality teams can use together.

This service governs enterprise AI and business-data access. It does not provide device cybersecurity testing, FDA submission preparation, regulatory certification, or approval of QMS evidence.

A useful next step before a bigger commitment.

The free AI Readiness Snapshot covers five areas: data security posture, data access, monitoring coverage, Shadow AI exposure, and a Microsoft Secure Score baseline.

Your administrator reviews and runs a read-only SharePoint exposure script before the 60-minute working session. We provide written findings within five business days after the session and receipt of the required inputs, then hold a 30-minute review.

A bounded diagnostic, not a complete tenant audit, penetration test, regulatory certification, or implementation plan.

Read the Snapshot scope · See preparation requirements

Bring your existing IT team.

We work alongside internal IT, security, and your MSP. Your team remains part of the decisions, implementation, and handoff.

Steven R. Combs brings 30 years in IT and 15 years working with law firms to the access and governance questions shared across organizations. Gabriella San Miguel coordinates project activity and scheduling.

Already have an agreed project? Request a project conversation.

Questions before you begin

Is this a device cybersecurity or FDA submission service?

No. We focus on access and governance around enterprise information, including files used to support quality and FDA evidence. Device testing and regulatory submissions remain with your specialist teams.

Do we have to buy anything after the Snapshot?

No. The working session, written findings, and follow-up review are free. You can act on the findings with your own team. Deeper assessments, implementation, and advisory are scoped separately.

When will you respond?

We aim to respond within 4–8 business hours, Monday–Friday, 8 AM–5 PM Central. The overall schedule depends on your team's availability and the agreed inputs.

Read before you book.

Existing Cocha articles relevant to these decisions.