ADVISORY
Strategy · Cybersecurity · Compliance

Regulatory monitoring
that holds up in an audit.

RegMon checks the regulatory sources of the German health IT landscape for changes every day, historises each one in an audit-proof trail and prepares it so your team sees in the morning what actually matters. The system runs entirely on your own infrastructure – including the AI analysis.

In production at the first customer site since June 2026.

The problem

“We check regularly.”

  • Changes are noticed late or not at all – holidays, illness, people moving on.
  • There is no traceable record of when something was seen, and by whom.
  • What remains for the audit are folders of screenshots, emails and copy-paste lists.

“We subscribe to newsletters.”

  • Newsletters are incomplete, unstructured and rarely archivable in any systematic way.
  • Silent changes in file directories and update servers never appear in them at all.
  • Without change detection there is no signal, only noise.
You do not need another source of information. You need a system that detects changes, historises them and makes them provable in an audit – every day, without anyone having to remember.

What RegMon watches

Every source gets its own plug-in with its own state. That keeps operations robust: if a source goes down or an authority rebuilds its website, only that one plug-in is affected. New sources are added as further plug-ins – typically within days, not release cycles. Which sources are watched is a per-customer decision, not a fixed catalogue.

G-BA – resolutions Gematik – telematics news KBV – IT update index KBV – 12 web sections oBDS – XML schema DGP – pathology further sources on request

Two stages

Light change detection during the day, deep content analysis at night. The system stays lean in daily operation and still produces a defensible history.

Structure, not prose

Every detection becomes an event with type, source, timestamp and classification – new, changed or removed. From there it can be filtered, sorted and evaluated.

An archive that only grows

Nothing is deleted. Events marked as done or not relevant stay in the record and are simply filtered out of view – a compliance archive should never shrink.

6
source plug-ins running in the current scope
0
data leaving your infrastructure
450+
automated tests in the release gate

How RegMon works

By day: detect

The plug-ins fetch their sources and compare against stored state. Detected differences become events, are enriched with metadata deterministically and classified by a policy you can edit yourself in the admin area – for instance which wording signals a deadline.

By night: understand

During the night hours RegMon downloads the relevant documents, extracts their full text and has a locally running language model determine summary, subject area, deadlines and affected roles. During the day the server stays quiet.

Deterministic first, AI as reinforcement

Anything that can be solved with rules is solved with rules. The language model is an enhancement, not a dependency: if it fails or is switched off, RegMon keeps working and falls back to deterministic processing. No result rests on a model response alone – a property auditors tend to ask about.

Evidence and access

Hash-chained audit trail

Every writing action is logged and every entry carries the checksum of its predecessor. If an entry is altered, deleted or inserted, the chain breaks and the system reports it.

Roles and accounts

Separate roles for administration and daily work, enforced password change on first login, lockout after failed attempts. Every status change is attributable to a person.

Recovery

A staged escalation for the case where nobody can get in any more – from an administrative reset through a four-eyes procedure to a logged emergency access.

Designed for certifiable environments

RegMon is built to stand up inside a certified environment: a complete audit trail and data integrity for GxP, documented architecture, versioning and test evidence for ISO 13485 and IEC 62304, access control, logging and security headers for ISO 27001, data minimisation and local processing for the GDPR. RegMon is explicitly not a medical device and does not replace regulatory advice.

Operation and installation

  • Container installation on your server. One virtual machine is enough; no graphics processor required.
  • Works without remote access. Installation runs from a signed offline bundle directly on the console – no VPN, no inbound access needed.
  • Guidance inside the product. Quick start, reference cards and troubleshooting guides ship with the system and open from the help button – no internet connection involved.
  • No standing remote access for us. Maintenance happens on demand, through a path you open and log.

Built with practitioners

Basysdata GmbH, Basel

Developed together with a HealthIT company focused on medical informatics. Jointly designed since Q4 2025, in pilot operation from March 2026, running on-premise in production since June 2026 – including two sources built specifically for the customer’s pathology domain.

Named with the customer’s permission.

Scope and terms

What you get

  • The right to run RegMon on your own infrastructure
  • Dashboard, administration area and audit trail
  • Ongoing source maintenance when authorities rebuild their sites
  • Software updates and support

What is agreed separately

  • Additional sources beyond the agreed scope
  • Integration with your ticketing system
  • Reports and exports to your specification
  • Training beyond the initial session

Terms on request

A monthly fee for licence and maintenance; development work by effort and only on explicit instruction. We discuss the numbers directly, matched to your source and process landscape – no self-checkout, no hour packages in a web shop.

Frequently asked

Do we have to send data outside?

No. RegMon runs entirely on your side. It fetches publicly available sources and produces local artefacts. The AI analysis also runs on your server – there is no call to an external model provider.

What happens when a source is rebuilt?

That is the most common maintenance case and part of ongoing care. Because each source is a separate plug-in with its own state, a rebuild affects only that plug-in – everything else keeps running.

What happens if the language model fails?

RegMon keeps working. Detection, classification and the audit trail are deterministic and need no model; processing falls back to a rule-based variant. The model improves the result, it does not carry it.

We already have regulatory staff. Do we still need this?

Usually yes – but not as a replacement. RegMon removes the routine and supplies the history. Judgement stays with your specialists, with a better signal and less manual work.

Our market is not Germany. Is this still relevant?

If you sell into Germany, Austria or Switzerland, yes. Market access there means following G-BA, KBV, Gematik and the oBDS schema continuously, in German, from sources that rarely announce their changes. That is precisely the work RegMon takes over.

Does RegMon replace regulatory advice?

No, and deliberately so. RegMon observes, documents and prepares. The judgement and every reporting or approval decision remain with you.

Contact

An introductory call, 30 minutes, no obligation

Three pieces of information are usually enough to tell whether RegMon fits: your product category, the sources that affect you, and who in the organisation should receive the results.

Email: contact@rh-advisory.de
Phone: +49 170 8031194
Location: DE / EU – remote-first, installed on site with you.

This page is deliberately lean. It does not sell a feature list, but a system that produces evidence.