Medical device startups often mistakenly delay cybersecurity and regulatory planning
viewing them as final-stage hurdles rather than foundational design elements.
Ignoring compliance from the start can lead to catastrophic financial and reputational damage
such as having to pull a product from the market after significant investment.
Cybersecurity is now a critical part of the conversation with any customer or partner
and companies must be prepared to demonstrate their compliance and security practices.
It is far too expensive and difficult to re-engineer a product for regulatory and security compliance later
it must be designed-in from the ground up.
A product's classification as a 'wellness app' versus a 'medical device' depends on its user...
A product's classification as a 'wellness app' versus a 'medical device' depends on its user journey—if it involves patients, clinicians, and medical conditions, it is a medical device.
Raising capital for MedTech startups can be challenging
particularly in smaller markets like Australia, often necessitating a search for international investors.
The legal and regulatory framework for software as a medical device is not an optional feature but...
The legal and regulatory framework for software as a medical device is not an optional feature but a legal requirement that companies must address to operate legally and safely.
Companies must understand their product's user journey in detail to correctly identify its...
Companies must understand their product's user journey in detail to correctly identify its regulatory classification and associated requirements.
Episode Summary
In this episode of the Blue Goat Cyber podcast, host Christian Espinosa interviews Helen Souris, a seasoned expert in the medical technology field. Helen serves as the CEO and Executive Director of Cardihab, a digital therapeutics company focused on helping patients recover from heart events, and also sits on the board of the Medical Technology Association of Australia (MTAA), where she chairs the Digital Health Advisory Group. With a rich background that includes roles at pharmaceutical giants like Eli Lilly and AstraZeneca, Helen brings a deep understanding of the entire product lifecycle, from initial research to commercialization. The conversation delves into the critical and often overlooked importance of integrating regulatory compliance and cybersecurity into the development of medical devices from the very beginning, rather than as an afterthought.
Helen Souris makes a compelling case for a 'foundations-first' approach to MedTech product development. She highlights a common and costly mistake made by many startups: delaying considerations for cybersecurity and regulatory standards until just before market submission. To illustrate the severe consequences of this oversight, she shares a cautionary tale of a company that, after securing $93 million in capital, was forced to withdraw its product from the market upon discovering it was not compliant with FDA regulations. This real-world example underscores her central argument that building a product without these considerations from the ground up is a recipe for failure. It's not only financially devastating to re-engineer a product later, but it also erodes trust with customers and investors. Helen emphasizes that cybersecurity is no longer a peripheral issue but a core component of business development that comes up in every customer conversation, requiring constant reassurance through certifications and transparent practices like ISO standards.
The discussion also explores the nuanced distinction between wellness applications and regulated medical devices. Helen provides a clear framework for differentiation by analyzing the 'user journey.' If a product's workflow involves a patient, a medical condition being diagnosed or treated, and interaction with clinicians like doctors or nurses, it operates within the healthcare system and must be classified as a medical device. This is contrasted with a general wellness app, which might track steps but lacks the clinical context. Ultimately, Helen argues that for the digital health and MedTech industries to thrive and innovate responsibly, founders and developers must treat cybersecurity and regulatory compliance as non-negotiable, foundational pillars of their product strategy, a lesson that is far less costly to learn at the beginning of the journey.
Frequently Asked Questions
Quick answers drawn from this episode.
In this episode of the Blue Goat Cyber podcast, host Christian Espinosa interviews Helen Souris, a seasoned expert in the medical technology field.
Medical device startups often mistakenly delay cybersecurity and regulatory planning, viewing them as final-stage hurdles rather than foundational design elements. Ignoring compliance from the start can lead to catastrophic financial and reputational damage, such as having to pull a product from the market after significant investment. Cybersecurity is now...
With a rich background that includes roles at pharmaceutical giants like Eli Lilly and AstraZeneca, Helen brings a deep understanding of the entire product lifecycle, from initial research to commercialization. It's most useful for medical device manufacturers, cybersecurity engineers, regulatory affairs professionals, and MedTech...
Medical device startups often mistakenly delay cybersecurity and regulatory planning, viewing them as final-stage hurdles rather than foundational design elements.
Ignoring compliance from the start can lead to catastrophic financial and reputational damage, such as having to pull a product from the market after significant investment.
Listeners also asked
Quick answers pulled from related episodes.
What does Episode 36 cover about "How Cybersecurity Shapes Regulatory and Quality Success with Jim Goodmiller"?
In this episode of The Med Device Cyber Podcast, hosts Trevor Slattery and Christian Espinosa are joined by Jim Goodmiller of BioBridges to discuss the critical intersection of cybersecurity with regulatory and quality management in the medical device industry. Jim brings over...
What does Episode 14 cover about "Cybersecurity Challenges & Trends in US MedTech with Paul-Lukas Hoffschmidt"?
In this episode of The Med Device Cyber Podcast, host Christian Espinosa and co-host Trevor Slattery are joined by Paul-Lukas Hoffschmidt of Alpha Sophia. Paul's company provides a commercial intelligence platform designed to help medical device, digital health, and life...
What does Episode 28 cover about "Prevention Is Better Than Cure: Applying Medical Principles to Medtech Cybersecurity"?
In this episode of the Med Device Cyber Podcast, hosts Christian Espinosa and Trevor Slattery are joined by Stephen Smith, a MedTech veteran with over 27 years of experience in Quality Assurance (QA) and Regulatory Affairs (RA). Stephen, co-founder of Elevate MedTech, shares...
Pre-fills with: "Medical device startups often mistakenly delay cybersecurity and regulatory planning, viewing them as final-stage hurdles rather than foundational design elements."
What happens when a medical technology company raises $93 million... only to discover it isn't compliant with regulators?
In this episode of the Med Device Cyber Podcast, Christian Espinosa speaks with Helen Souris, CEO of CardiHab and Board Member of the Medical Technology Association of Australia (MTAA), about one of the biggest challenges facing digital health companies today: building products that are commercially successful, clinically valuable and compliant from the very beginning.
Helen explains why cybersecurity has become a requirement in customer procurement, why software as a medical device continues to confuse founders, and why quality management systems, regulatory strategy and cybersecurity must all be considered before products reach the market.
The discussion also covers fundraising, choosing the right investors, digital therapeutics, AI in healthcare, wearables, cybersecurity awareness and practical examples that help founders understand when their product becomes a regulated medical device.
In This Episode:
Find Helen Souris here on LinkedIn: https://www.linkedin.com/in/helen-souris/
The Med Device Cyber Podcast is brought to you by Blue Goat Cyber, cybersecurity experts providing essential security solutions for the medical device industry. Learn more by visiting https://bluegoatcyber.com.
If you're interested in our services or partnering with us, schedule a Discovery Session: https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session
Christian Espinosa is the CEO and founder of Blue Goat Cyber.
Christian Espinosa on LinkedIn: https://www.linkedin.com/in/christianespinosa/
Blue Goat Cyber on LinkedIn: https://www.linkedin.com/company/blue-goat-cyber/
Blue Goat Cyber on Instagram: https://www.instagram.com/bluegoatcyber/
Blue Goat Cyber on Facebook: https://www.facebook.com/bluegoatcyber/
Blue Goat Cyber on YouTube: https://www.youtube.com/@BlueGoatCyber/?sub_confirmation=1
Helen: after 93 million dollars in capital, they realized they were not compliant with the FDA. pulled their product from market.
Christian: Even though we tell people that it needs to be done early, people still come back and say, we don't need cyber security yet. We're not ready for it. We need it like right before submission.
Helen: Cyber security comes up in every single conversation that we have with with a customer. We have to remind everybody about our certifications, ISO standards, about our practices around cyber because it's the number one thing that blocks the conversation if you don't get it right. You should never build a product without that consideration from the ground up, because it's too late to do it later.
Christian: Welcome to the podcast, uh Helen. Glad to have you on here. I know we met in person uh in March time frame in Sydney. Uh we were down there, we went to a Formula One race in Melbourne and did a few other things for work and then we went to Singapore after that and Korea and back to the United States. We've been around the world a little bit.
Helen: Fantastic. Wonderful to be here and thanks for inviting me along.
Christian: Yeah, awesome. Maybe you can tell us, you do a couple things. I know you're part of MTAA and uh your own organization. So maybe you can tell us a little bit about, um, about both and your involvement with both and uh give us some perspective of what Medtech is like down under. We have a few cli- clients down under in Australia. Uh but there's be for our listeners be cool to hear your perspective as well.
Helen: Well, my main job is I am the CEO of a company called Cardihab. We're a digital therapeutics company that helps people recover from heart attacks, heart events through apps and uh care programs that we deliver through technology. So that's what keeps me busy most of my time. But I'm also on the board of the Medical Technology Association of Australia, which is a peak body that represents medical device companies. and I'm the chair of their digital health advisory group. and I guess the opportunity for me to join the MTAA's board was really to represent the startup ecosystem in Australia, but also to demonstrate what digital health can bring to an industry that is a regulated industry.
Uh the recent changes around regulation of software as a medical device or digital therapeutics or whatever you want to call them, um all has uh brought to a head I guess the the requirement for companies like ours, products like ours to be regulated and that's a very familiar territory for medical device companies who commercialize their products uh in any market.
Christian: And what made you start or get into uh your company Cardihab? Like what was like the the moment you decided you want to start that company or a little bit of the origin story?
Helen: Well, I actually had a long career in pharmaceutical, biotech, medical device companies working with Eli Lilly and AstraZeneca. and a lot of the companies um that used to be entrepreneurial would come to us at the at Eli Lilly or or Astra and ask us to buy their tech or buy their product or buy their drug. and uh I felt at that time there was a lot of things missing from the commercialization journey, that early stage. You know, I could do something with your product if you had these particular parameters in your clinical trial that will differentiate your product, or I could commercialize your device if it wasn't this shape or this size relative to the original device that you're trying to I guess complement.
And so I found myself surrounded by these wonderful entrepreneurs that if they had the right advice in the early stages of their sort of product development journey, uh they would have a much faster path to commercialization. So I started a consulting company um when I left Astra to help startups specifically with uh commercialization, that early stage, uh getting your clinical trials right, getting your design right. And one of the um clients that I had at that time was Cardihab. and they'd come to me after they had spun out of the CSIRO. Uh the company had taken two founders from Siro across to be the CEO and CTO. and for a few years they had struggled with that translation where everyone who's done a I guess an academic research project that then tries to get into the commercial world uh struggles with that that difference between academia and the difference between the commercial realities of what enterprise type clients would um tolerate, I guess, accept, love, from a product.
So, when I was approached to do some work with Cardihab, um there was an opportunity to put my money where my mouth was, I guess, and put my advice as a consultant forward and actually take that strategy into the business. and I joined as CEO, raised some capital, and seven years later, here I am.
Christian: Awesome. And what was that like raising capital? Was that a was that a challenging... We do a lot of We're part of a Medtech innovator and, you know, we hear a lot of pitches and, you know, capital is a big component of our industry because I think I heard it takes seven years and 35 million US dollars to bring a product to market. So there's always, you know, someone trying to raise money, right? So how was that experience for you? Just curious.
Helen: Oh, it's interesting. I'd never raised capital before outside of a large multinational, so that was a culture shock. Um but when I actually did uh went out to do our first capital raise, it was a downround and I didn't even know what that meant. I was like, well, we need to keep the doors open, we need to keep this business going. It's a great opportunity. So, um the very first capital raise I did in 2019 was a downround and I went, okay, let's just get going, let's just do it.
And we did. We raised the money and um now downrounds are the new black last year. So very popular, very common uh experiences, but it was hard to get that initial um investment, but we got it and since then we've obviously had a series of campaigns where you'd have to continuously inject uh capital into the Australian market. Um it's really hard to get access to the right level of capital in Australia. It's um it's too small a market really, to be honest with you, to get the kind of investments we need to keep all of the businesses like ours that require capital for regulatory, for long um development cycles to be successful. And so we have a combination of looking at the Australian market, but then also going overseas and looking for international investors as well.
But it's very, very hard and certainly recent announcements from the government's proposed changes to R&D tax and CGT on um on equity and shares is also a a I guess a concerning signal for startups and entrepreneurs in Australia.
Guest: Would you say that so it sounds like the fund-raising scene's definitely going to be a little bit different in Australia. Do you see a lot of Australian companies that are trying to come to places like the US or maybe even China, where fundraising is generally seen as a lot more accessible, and then still trying to sell their products in Australia or are they often looking at selling in those markets initially as well?
Helen: Absolutely looking for capital wherever you can get it. Um and so very open to looking at other markets where it's easier to raise, but the still the challenges are though that certain markets require you to commercialize in those markets if you're going to take investment. So uh most of the people I've spoken to that have been raising capital are very open-minded, but not everyone's able to just have multi-country launches from the very beginning of their business. So it becomes a question of if the access to capital is easier in the states, for example, and the market's more progressive and more I guess dynamic, then you will potentially consider taking your technology to the US and just doing it all from there.
Um so I think it's a really interesting uh challenge that we've got here because it's too hard to raise capital here and there's too many times where companies nearly fall um and the CEOs are exhausted with raising capital as opposed to growing the business which enables you to grow uh to be at least a little bit more independent and not dependent on capital um but also gives you the results that the investors want to see which is the growth in the business.
I think there's always been a country that has enormous ideas and fantastic ideas that have truly revolutionized industries across the board, not just in Medtech. Where we've struggled in Australia is to actually get those ideas to market. So that commercialization, that translation is where Australia has always struggled. Um but the narrative a lot more uh from the ecosystem is to highlight that that's a weakness and to actually focus energy on it. Uh there's translational research grants where you can actually take a concept and take it to market. Um there's a lot more accelerators and incubators trying to help get that expertise to take concepts to market.
Um so I think it is maturing, but um it's still constrained by really, really low levels of investment, um difficult access to capital, but also um struggles I guess within the context of the procurement of Australian made products in Australia is still a big barrier. We have a health system that's 50% public and 50% private and the processes to get procured in the private system is completely different to the processes to get procured in the public system, and you could easily spend 12 to 18 months, in some instances years to try and procure your product in a market. So, it's a very, very tough environment to commercialize in.
Christian: I think uh we haven't really had too many guests talk about raising capital. So it's a it's an interesting theme to go through and you kind of alluded to it's almost like it could become a CEO's full-time job. So you're spending all your time trying to raise capital versus growing the business, uh which is, you know, a struggle. From your perspective, how important is it to find the right investor? cuz I think this is my perspective. I I see this sometimes. I see the startup become a little bit desperate for an investor and they pick the first one and it may not be a a good fit, so it causes a lot of friction. Like what is your perspective on that?
Helen: That is such a such a an important point. Um the the ability to be choosy is very hard in Australia because you need to keep the doors open sometimes and you just have to take what you can get. Um but it is such a critical risk. I mean when you're raising capital, you typically can't raise it uh for a period longer than 18 months from my experience and from the people I've spoken to. So you're raising in 18 month cycles, which means that if you're in a business development um cycle that takes 18 months to sign contracts and you're raising capital every 18 months, which is a full-time job, that you really don't ever get out of the rhythm of raising capital. Now if you get an investor, um which we've been very fortunate with our wonderful investors that have come into Cardihab who are supportive, there is smart capital um that actually helps uh I guess contribute to your strategy growth or your business growth, then that's fantastic.
But if you are distracted by an investor who doesn't understand the industry, who who doesn't understand commercialization or who's forcing a pivot away from what you know is the right thing for sustainable growth for the business, you spend a lot of time then defending strategy or adjusting strategy to appease the investor as opposed to what you know might be the right thing for the business. And it's not always that the CEO's are right and the investors are wrong, please don't take that as my message. But um digital health particularly execution and and commercialization in digital health is new to everyone and there are very, very few investors out there who have actually seen a company go all the way through from startup to scale up to large successful businesses. So there's not a lot of expertise out there in the investment world to actually guide that pathway. So there's a lot of experimentation that can take you off-piste and distract you from what you know is going to drive a result.
Guest: I don't know too many people that are able to be highly selective, but uh it is a message that and a conscious thing that I say uh to my board as well as other people that I speak to on a regular basis is just be careful about where the um the incentives are for sorry, not the incentives, the agenda is for the investment as well as where the come the money's coming from, because it can really really distract you.
I guess going back to what you were mentioning about a lot of these companies trying to pivot towards other markets for some of the initial investment. Obviously, I'm sure the US is a pretty popular one, but do you see any other countries maybe a little bit closer towards Australia that are popular options for Australian companies to try to get that initial market access and funds?
Helen: Yes, uh I think we've heard a lot about the Singapore market um being incredibly mature relative to the rest of the world in terms of digital health. Um the UK market has been a great market for some businesses, some in companies that I've spoken to as well. And certainly um Ireland, it's proximity to the US, but also uh its connections to Europe. So there's some interesting pockets where people are considering. Um but it does depend on the tech that you've got and the I guess the Australian marketplace and the um synergies with how the product's been developed and designed if it's been an Australian healthcare product, um versus the market they're wanting to go into.
So, I think they're probably the usual suspects. The the European markets, Germany's amazing. We've got fantastic reimbursement structures. France has similar um reimbursement structures as well. Uh but I don't know too many people that are uprooting to go to Germany at this point. It's it's a bit more of a complex journey um to to go to those sorts of markets because if you don't have expertise in the market, if you don't know um the health system adequately, if you don't know the language, uh you're adding those layers of complexity to that that shift.
The regulation of software as a medical device and all of its different um terminologies is uh becoming more real to people, even though it's been in place for a very long time. In Australia, the regulations changed in November 2024, which meant any sort of device like ours, any software as a medical device, whether it's delivered through an app or whether it's delivered through a platform, uh should be a class 2A medical device, which is a full submission, full audit, full certification against ISO standards. Uh and a lot of companies, I just got back from um Melbourne last night from our massive uh digital health fest, which is Australia's national um largest digital health uh conference. Uh it's two days packed to the rafters with um digital health companies and entrepreneurs and procurers and health insurers, all the people who are interested in shaping and shaking the world with digital health.
and still, the despite the proliferation of great products and great um I guess uh ideas in Australia, there's a lot of companies who still don't understand regulation and understand that their products are actually medical devices that need to be registered with the TGA.
It's not optional. It's not a feature. It's not a product design element. It's actually the law. Um and I think people are not yet aware enough of that and they're making decisions about product design that don't really accommodate it.
Guest: I think it's perfect to equate it to drug development, because if you ask, I feel like that's something that people understand the severity of. If you ask anyone, 'Oh, well, what if your mother was taking unregulated drugs for some severe illness?' or like unregulated chemo drugs, what would you think about that? Pretty much anyone you talk to would go, oh, that sounds terrifying. I would never ever ever want that to happen. But there's seemingly not the same awareness in the device space. It seems to be a little bit more of a gray area and a lot more companies try to skirt around the regulations and say, well, we don't think that applies to us or...
Specifically within the cyber security space, usually what we hear is, you know, for a blanket statement, if you're a cyber device and if you're a class two or above product, you need to address cyber security. You are of high enough risk where this is a problem. Someone can get hurt if something goes wrong. But we still hear time and time again, a lot of manufacturers saying, well, we just don't think our device is high enough of a severity to have cyber security implications. It's like, well, what does that mean? What's the worst case that could actually happen from cyber security? And nine out of 10 times, it's going to be a lot worse than you thought. So, I think that awareness of what could actually go wrong is seemingly missing in times, it feels like. I don't know, would you agree with that?
Helen: Yeah, I think you need people to um talk through their journey in their words for them to understand what it is that we're talking about. So for example, if I was to ask uh a lot of startup companies come to me and say, what made you think about regulation? Why did you do it? And I say to them a fairly simple question which is describe your user journey to me. and describe the journey in ways that you want your product to be used. And they'll say things like, um, 'Well the patient has condition X and they go and see the nurse and then the nurse looks at the information in our app and then the um nurse talks to the doctor and the doctor has a look at the information and they make some decisions about the process and blah, blah, blah.'
And when you stop them from that conversation to say, now reflecting on that user journey, everything you said was medical. A patient is a medical term. A doctor and a nurse are medical people, they're healthcare professionals. So your entire journey operates within the healthcare system, therefore it's a medical device. And then depending on the severity of the condition, you're either a class one, two, three all the way up. Now, if your journey spontaneously to me was I went to the gym, I picked up the groceries, I looked at my tracker on my wearable, um then I detected, you know, I needed to go and do something. So I went home and I went on the treadmill for 15 minutes to do some more exercise. That is a user journey that is a consumer. It's wellness, has nothing to do with healthcare. It's health, but it's not healthcare. There's no doctor, there's no patient, there's no disease. So that journey is completely and utterly separate. And therefore you are a wellness product. Great. Lock yourself up. That's excellent. Don't be regulated, but be be safe.
Now, the minute you start asking people about their journey with data. What kind of information do they collect in their device? And could that information be identified to a human? and what would be the scenario where let's just say someone's up there presenting and the entire audience in a stadium finds out about your medical history from, you know, hacking into your app. Would that be a problem? Would that be okay? If you're standing up there and you've been talking about, you know, whatever topic it is, but your information that you've entered in your app is is hacked and someone shares that publicly.
Little examples where people start to personalize what does it mean for them, or what does it mean for the data they collect, I think that's where they start to understand practical examples of how the data could be at risk. And everyone needs to have those moments for themselves to understand. We do a lot of awareness. We do a huge amount of campaigning about the importance of it, but until people make it real and personal and practical, I don't think they appreciate it. And it's not that they're not trying. It's just that it's a different way of approaching the question. People need to understand what's in it for me or why should I bother really personally before they take any action. And what I've found in most instances where you say that to people, um probably five out of six times I've said that to people, they've come back and said that question changed my perspective and now we're going down the pathway because getting them to personalize their journey and then to personally think about how things could um could work.
It's such a big part of the, I love wearables, don't get me wrong, and I love all the opportunities that we've got ahead of us with healthcare and wearables. But if your ring tells you to go for a run, it won't know if you've just broken your ankle. It won't know if you have chronic back pain. It won't know if you have hypertension. It won't know anything, or heart failure. So telling you to go for a run could actually be the thing that kills you. You know?
I mean, we are talking about devices that hopefully people are a little bit more sensible, but we know that there's not a lot of common sense. Common sense is not common. So, what do we do in those instances where someone says, go for a walk because your steps are low. What about that patient if that patient has a mental health condition that means they've started to spiral into a depressive state and that person is so um sedentary because of their mental health. What is that ring going to do in that moment to encourage that person to do more steps in a healthy way? Or what is that that ring going to do for a person who's maybe on a beta blocker um and is telling them your heart rate's a little bit unusual, what are you going to do about it?
These things can't be intelligent around medical conditions without a medical lens. They have to be regulated. They have to be trained on appropriate data. They have to go through the rigor of clinical trials and validation, which a lot of device companies have. There are some really good ones who have done that. But until that point, we run the risk of having unregulated devices who do stuff and tell people to do things uh without any safety mechanisms in place for the patient. And I think coming back to the example of of so what if the data gets exposed or so what if the data is shared if you are presenting? I just use that scenario yesterday cuz someone at um a conference a couple of years back in Australia, he was a cyber expert and he actually um created a fake Wi-Fi account for the conference that he was at. And anyone who joined that WiFi connection, um he hacked into their data and presented it up on stage.
And said anyone who's joined this, this is your profile, these are your mobile phone numbers, this is all your information. Are you okay with this? I mean it was shocking to see people react to that to go that was accessible information purely because you set up this pseudo Wi-Fi connection password um and took everyone's information and presented it during his talk. and I think that was the most powerful example for people to understand A, why not to just join free Wi-Fi without secure access, but also what's possible in those mo- moments and in instances where you demonstrate what does it mean to me if my information is accessed through a device without my consent, without my permission. And they're really practical, powerful examples where people stop and think and talk and go, well, this this is something I need to take action on. This is something that could actually impact me in a way that I've never thought of before.
Christian: Well, we're coming up on time. So I'd like to go around the room and ask for some key takeaways or closing thoughts.
Helen: I think I'm so uh optimistic about the future of technology, but only if we start to take these matters seriously and appreciate the gravity of the decisions we're making around regulatory and cyber as foundational. You should never build a product without that consideration from the ground up, because it's too late to do it later. It's too expensive to rebuild. No one's got capital, no one's got access to the time and resources it takes to re-engineer products that haven't been built with that kind of governance and rigor in place. So just do it right from the beginning and then you have a wonderful foundation to build upon and scale upon.
And I think that's the message I'd probably give to anyone who's contemplating getting into healthcare or maybe started the journey without that. Just stop, reset, build the foundations and then take your market um go to market plan forward and get your product healthy from the beginning so that it doesn't run the risks that later on cost you a lot, a lot more reputationally, a lot more financially, a lot more um potentially uh depending on the severity of an attack or a breach, a lot more than what you'd ever encountered.
Christian: Awesome. I think my two are aligned with what you said there. The the moral of the story is to start early, especially in a regulated industry, otherwise it could it's going to be very costly, very frustrating down the road. Uh so, designing cyber security and having your regulatory strategy early on and your QMS even as you mentioned and the artifacts is extremely important. And then the other thing I like is your distinction on the wellness versus healthcare. If there's no patient, no disease, no doctor, no nurse involved, and you got a wearable but you're like, 'you need to get on the treadmill for 15 more minutes,' that's wellness, uh which is different. It's not a medical device. But if there is any of those things enabled, or involved in the journey, then it is a medical device, cuz I think a lot of people think well this is just a wellness device, but when you put it in that context, it makes it crystal clear. It's kind of blurring the line or is in fact a medical device.
Helen: Yeah.
Christian: Awesome. Well, thanks so much Helen for joining us all the way from Australia. I don't know if you may have been our only Australian guest so far.
Helen: Oh wow, fantastic. I'm very proud. Thank you. Thanks again. It's been a pleasure.
Christian: Awesome. Well thanks again and thanks everyone for tuning in to the Med Device Cyber Podcast. Hope to see you on the next one.