Taiwan's Ministry of Health and Welfare launched the National Medical Informatics Certification Laboratory on August 18, 2026. The ministry, Taiwan's central agency for health and welfare policy, said the laboratory will develop common tests for the interoperability, compatibility and performance of medical information products and services.
The program is being built around FHIR Box, Taiwan's integration architecture for health data, rules and applications. The ministry has announced three planned certification tracks, but its release does not provide test cases, pass thresholds, certificate terms or rules for reassessing a changed product. That leaves hospitals and suppliers without a public measure of how much of their own acceptance testing a certificate could replace.
Three tracks cover different parts of a deployment
The ministry said it plans a software track for clinical decision-support modules and SMART on FHIR applications connected to FHIR Box, a hardware track for the performance and reliability of FHIR Box equipment, and a provider track for deployment and maintenance capability. The announcement describes mechanisms the laboratory will establish, not completed certification results.
| Planned track | Published scope | Evidence not supplied by the track description |
|---|---|---|
| Software | Clinical decision-support modules and SMART on FHIR apps linked to FHIR Box | Intended clinical use, patient population, model version and performance outside the test sites |
| Hardware | Performance and reliability of equipment running FHIR Box | Local capacity, firmware control, patching, maintenance and integration with other equipment |
| Solution provider | Ability to deploy, maintain and support a complete medical information technology solution | Service boundaries, subcontractors, incident ownership, data export and contract exit |
The three tracks could reduce repeated interface work only if hospitals can reuse results across procurements and product versions. The ministry has not said how certificates will transfer between hospitals or which software and hardware changes will trigger another assessment. Its release also does not state that laboratory certification replaces separate clinical evidence or any country-specific medical device review.
FHIR, SMART on FHIR and FHIR Box have separate jobs
Fast Healthcare Interoperability Resources (FHIR) is developed by HL7 International. HL7 defines FHIR as a standard for exchanging health information electronically, with reusable Resources as its basic building blocks, and says automated clinical decision support requires structured and standardized data. The standard defines how information is represented and exchanged; it does not make a missing source value appear or prove that a local code was mapped correctly.
SMART App Launch operates at the application-access layer. Version 2.2.0 defines OAuth 2.0-based patterns for applications to authorize, authenticate and connect to FHIR systems, while scopes limit the access delegated to an application. Those patterns do not set a hospital's identity policy, credential lifecycle, audit response or legal basis for access.
FHIR Box is a Taiwan-specific architecture, not another international data standard. Taiwan's health ministry describes it as a layer above existing hospital systems that unifies data conversion, validation, governance and exchange rather than as a single device. FHIR Box can use FHIR-formatted data and support SMART applications, but the three names do not describe the same component.
Interoperability tests do not establish AI performance
A system can pass an interface test without showing that an AI model works for its intended patients and clinical setting. The International Medical Device Regulators Forum's (IMDRF) 2025 principles for AI-enabled medical devices call for representative datasets, independent training and test sets, external validation proportionate to risk, testing of the human-AI team and monitoring after deployment.
Those controls answer different questions from a FHIR conformance test. A valid resource can still carry data from a patient group, scanner or workflow that differs from the model's evaluation data. Overall accuracy can also conceal weaker performance in a subgroup, while a software update or changing clinical population can alter performance after installation.
The IMDRF also places software engineering, data quality, data management, cybersecurity and maintenance across the product lifecycle. A valid SMART access token does not show that a supplier patches dependencies, limits support access or detects model drift. The Taiwan laboratory's public track descriptions do not yet show whether or how those controls will be scored.
Five evidence layers keep a certificate in scope
A hospital procurement record can separate evidence into five layers so that a technical certificate does not stand in for clinical or operational review. Each layer needs to identify the exact product version, deployment site and intended use to which the evidence applies.
- Data specification: The record identifies the FHIR version, implementation profiles, code systems, required fields and handling of missing or invalid data.
- Clinical evidence: It states the intended use, patient population, test sites, reference standard, subgroup results and role of staff in reviewing the output.
- Certification scope: It names the software, hardware and provider versions that were tested, the tests they passed and the functions that were outside the assessment. Any medical device status is checked separately for each country.
- Operations and change control: The plan covers security updates, model monitoring, drift signals, incident handling, human override and the changes that require retesting.
- Responsibility and exit: The contract assigns patching, breach response, data export, log retention, rollback and service termination to named parties.
These layers are not five separate licenses. They are a way to keep interoperability, clinical performance, regulatory status and operational responsibility from being treated as one claim. A certificate can answer only the tests and product scope printed on it.
Public details are still too limited to measure the effect
The ministry's August 18 release does not publish a test catalog, pass-fail thresholds, certificate duration, audit process, registry of certified products or retesting rule. APPI News also could not find published nationwide data comparing FHIR Box integration costs, staffing or deployment rates across hospital tiers at the time of writing.
Those gaps do not show that the data or procedures do not exist. They mean the laboratory's effect on purchasing costs, repeated testing and adoption cannot yet be measured from public evidence. The launch creates a common venue for technical assessment, while clinical evidence and lifecycle controls remain separate parts of a medical AI deployment decision.
Sources and further reading
- Taiwan launches the National Medical Informatics Certification Laboratory (Chinese)(Taiwan Ministry of Health and Welfare)Launch date and planned software, hardware and solution-provider tracks
- Taiwan describes the FHIR Box architecture (Chinese)(Taiwan Ministry of Health and Welfare)Data conversion, validation, governance and exchange above existing hospital systems
- FHIR overview(HL7 International)
- SMART App Launch 2.2.0 overview(HL7 International)
- Good machine learning practice for medical device development: Guiding principles(International Medical Device Regulators Forum)