IFU Document ID: G3-IFU-EN
IFU Version: 2.2
Date of issue: 3 September 2026
1. Device Description
Device: Gosta AI Operating System (UDI-DI: 06429830288503)
Software Version: 4.X.X
Device Classification: Class I (self-certified, MDR 2017/745)
The Gosta AI Operating System is stand-alone medical software designed to support healthcare professionals in creating, reviewing, and managing clinical documentation and taxonomy based on spoken or transcribed encounters. The software uses artificial intelligence, including large language models, to:
Capture spoken input from healthcare professionals or patients
Generate draft clinical records
Facilitate documentation accuracy, efficiency, and completeness
Assist with administrative workflows
The device is designed to improve efficiency, accuracy, and completeness of administrative and clinical record-keeping workflows within healthcare settings. By automating clinical documentation, the device improves the quality of patient-physician interactions while at the same time improving the completeness and quality of clinical documentation.
The device is not intended for clinical decision support or diagnostic use. All generated content must be validated by the healthcare professional prior to being added to the electronic health record (EHR/EMR).
The software is available through a web interface and a native mobile application.
2. Intended Purpose
The Gosta AI Operating System is intended to:
Generate draft clinical notes from spoken or written input
Support healthcare professionals in improving quality and efficiency of record-keeping
Assist with administrative workflow steps based on patient encounters
It is intended solely for administrative documentation support and does not:
Provide diagnostic or therapeutic guidance
Recommend clinical interventions
Perform risk stratification, prediction, or decision support
All note content must be reviewed and approved by qualified healthcare professionals before incorporation into patient records.
3. Intended Users and Use Environment
Intended Users
Licensed healthcare professionals (physicians, physicists, nurses, psychologists, allied health personnel)
Social care professionals (for non-medical use — outside MDR’s scope)
The device is not intended for patient self-use.
Use Environment
Hospitals
Clinics and outpatient facilities
Offices where clinical or social-care-related documentation is created or reviewed.
Alongside travelling healthcare professionals (such as travelling nurse)
4. Intended Indications and Contra-Indications
The software indirectly supports all patient populations for whom professionals generate documentation. Therefore, it is intended for all indications.
Supported languages: English, Spanish, Portuguese, Dutch, Italian, French, Swedish, German, Finnish, Russian, Estonian, and Czech.
No contraindications are known.
5. Mode of Operation
5.1 Starting a New Encounter
To begin a new session, the user selects New Encounter. The system verifies microphone signal strength and, depending on configuration, prompts for:
Language selection
Appointment type / note template
Recording begins when the user presses Start Recording.
5.2 Creating the Clinical Note
During or after recording, users initiate draft generation using the Create Note button. Processing comprises two stages:
Finalising transcription
Generating the draft note
Users may interrupt any stage by pressing Interrupt Processing.
5.3 Editing the Draft
Each draft note is divided into sections, which users may click to edit.
The selected section is framed by a black border
“Save” and “Cancel” options appear beneath the editing area
Users may freely add, modify, or remove text
5.4 Regenerating with Additional Instructions
If the draft requires refinement, the user may select Regenerate, which opens a window allowing:
Additional instructions (typed or voice-dictated)
Quick commands (e.g., “add missing details,” “remove mentions,” “translate”)
Regeneration is executed with default parameters if the instruction field is left empty
5.5 Transferring Note Content to the EMR
Once finalised, documentation is transferred manually:
Using Copy Note to copy the entire note to the clipboard
Using section-specific copy icons to copy individual sections
A feedback interface appears after copying, prompting the user to rate the initial model output. Users are reminded not to include sensitive or personal data in free-text feedback.
Note! Do not include personal data or other sensitive information in your feedback.
5.6 Deleting Notes
Local copies of notes (stored in the browser session) can be deleted using the Delete icon next to the appointment. If notes are not manually deleted, they are automatically removed when the browser closes. Deleted notes cannot be restored, so users must ensure EMR transfer beforehand.
Note! For information security reasons, any local copies of clinical notes should be permanently deleted immediately after transfer.
6. Technical Requirements
6. Technical Requirements
Gosta AI Operating System is a software-based medical device that requires a compatible end-user device and a functioning internet connection. Use of audio features additionally requires a functioning microphone.
The performance of the device may be affected by factors such as the end-user device, quality of the internet connection, operating environment, session duration, and the technical complexity of the language models used. Variations in performance, such as response times, may occur during use.
6.1 Desktop Operating Systems
To use the Gosta AI Operating System web application, the computer must run at least one of the following operating system versions:
Windows 10 or later
macOS 14 (Sonoma) or later
No local software installation is required to use the web application.
6.2 Web Browsers
The web application is accessed using a supported web browser. The browser version must be at least:
Firefox 128 (released July 2024)
Safari 16.4 (released March 2023)
Chrome 111 (released March 2023)
Edge 111 (released March 2023)
Use of newer browser versions is recommended.
6.3 Mobile Devices
Use of the mobile application requires a supported smartphone or tablet with a functioning internet connection. The mobile device must run at least one of the following operating system versions:
iOS 18.0 (released September 2024)
Android 11 (released September 2020)
Use of audio features in the mobile application requires a functioning microphone and the necessary microphone permissions to be granted to the application.
6.4 Infrastructure & Access
Users can authenticate and access the device through Single-Sign On, using their employer’s credentials, such as Azure-based authentication. When Single-Sign on is not available, users can authenticate and access with a unique username and password.
7. Data Protection & Cybersecurity
Personal data is stored only for the duration of transcription, note generation, and workflow processing.
When the clinician leaves the encounter, all patient data is deleted automatically.
No long-term storage of personal data is performed by the system.
Users must follow institutional policies regarding device encryption, login security, and the safeguarding of copied data.
If background documents containing sensitive information or patient data are uploaded to the system from the user's computer:
Any local copies must be deleted by the user without undue delay after use.
The documents must be uploaded to Gosta using the same file name as in the patient information system. The file name must not subsequently be changed in either system. The file name enables subsequent identification of the patient whose attachment was processed.
Users must use a strong password when logging into the system.
A strong password is recommended to be at least 15 characters long and include a combination of uppercase and lowercase letters, numbers, and special characters. Passwords must not be shared with others and must be kept confidential. To enhance security, users are advised to change their password regularly and to use a different password than those used for other services.
Guidelines for creating a strong password:
The system is developed and operated according to ISO/IEC 27001-certified information security practices.
8. Safety Information
General Safety Notes
All generated content must be reviewed for accuracy, completeness, and clinical correctness.
AI-generated drafts may contain incomplete, repeated, ambiguous, or incorrectly placed information (e.g., mixing contexts or omitting relevant details).
The system does not generate diagnoses or treatment recommendations.
Residual Risks
Despite established risk controls, including human review, risk of erroneous EMR entry cannot be completely eliminated.
Warnings
All generated content must be reviewed for accuracy, completeness, and clinical correctness.
User responsibility for safe use of the system
Safe use of the Gosta system requires that the user follows the instructions below regarding authentication and device protection.
Authentication and password
Users must use a strong password when logging into the system. A strong password is recommended to be at least 15 characters long and to contain a combination of upper- and lowercase letters, numbers and special characters. The password must not be shared with anyone and must be kept confidential. Users should use a different password from other services, and they must change the password immediately if they suspect it has been compromised or disclosed to others.
Guidance on strong passwords (in Finnish): https://www.traficom.fi/fi/ohjeet-ja-oppaat/ohjeet-ja-oppaat-yksityishenkiloille/salasanat-haltuun-kuka-kayttaa-tiliasi
User accounts are personal and must not be shared with anyone else.
Users must have multi-factor authentication (MFA) enabled. The MFA device or application must be kept secure, and any loss or suspected compromise must be reported immediately to the organisation's administrator.
Locking the workstation
The Gosta Web application does not have an automatic session timeout, because patient appointments can be long and may include intentional pauses. It is the user's responsibility to lock the workstation whenever leaving it unattended, even briefly (Windows: Win+L, macOS: Ctrl+Cmd+Q), to keep a strong login password and an automatically locking screensaver enabled on the workstation, and to log out of Gosta at the end of the shift.
Locking the mobile device
The Gosta Mobile application does not have a separate application-level lock, so protection of the mobile device relies on the operating system's device lock. It is the user's responsibility to keep a PIN, password or biometric authentication (fingerprint or face) enabled on the mobile device at all times. Without a device lock, the application cannot protect the data stored on the device. Notify the organisation's administrator and GostaLabs immediately if the mobile device is lost or compromised, so that the device pairing can be revoked from the server side.
Import of disclosed information — prohibited
In accordance with the requirements applicable to social and healthcare services in Finland, processing of customer and patient information obtained on the basis of disclosure (luovutusperuste) requires authentication based on the social and healthcare professional certificate card (Sote-varmennekortti). Gosta does not currently support certificate-card authentication, and therefore importing disclosed information into Gosta is not permitted: users must not retrieve customer or patient information from another service provider's system (including the Kanta services) on the basis of disclosure and transfer it to Gosta. Both the service provider and the user are responsible for complying with this restriction.
9. Incidents
9.1 Identifying an incident
An incident means a malfunction, deterioration in performance, or incorrect output of the device that has led, or could have led, to harm to the health of a patient, user or other person.
For more information on identifying and reporting incidents: Fimea – Reporting of incidents
9.2 Reporting an incident
Professional users must report all incidents related to the device both to the manufacturer and to the competent authority of the Member State.
Reporting to the manufacturer: by e-mail: [email protected]
In urgent cases, the report may first be made by telephone (+358 40 0634429, Ilona Lehtinen, QARA), but a written report must also be submitted without undue delay.
Reporting to the authority (Fimea):
In accordance with Fimea's current guidance: Fimea – Reporting of incidents
10. Maintenance, Updates, and Storage
As a cloud-based software solution:
No user maintenance is required.
Updates are deployed centrally by Gosta Labs; no actions are needed from users.
No physical storage, cleaning, or disposal by users is required.
11. Compliance
MDR 2017/745 Class I (self-certified)
ISO/IEC 27001 compliant information security management
12. Manufacturer info
Gosta Labs Oy
Otakaari 5
02150 Espoo
Finland
Email: [email protected]
Chat support: available to logged-in users
Revision history
Version | Date | Description of change |
2.2 | 3 September | Chapter 6 revised, chapter 7 revised |
2.1 | 28 April | Information about safe use added, chapter 9 Incidents added |
2.0 | 27 March 2026 | Information security related guidance |
1.0 | 30 January 2026 | Initial release |
