Skip to main content

INSTRUCTIONS FOR USE (IFU)

IFU Document ID: G3-IFU-EN

IFU Version: 2.2

Date of issue: 3 September 2026

1. Device Description

Device: Gosta AI Operating System (UDI-DI: 06429830288503)

Software Version: 4.X.X

Device Classification: Class I (self-certified, MDR 2017/745)

The Gosta AI Operating System is stand-alone medical software designed to support healthcare professionals in creating, reviewing, and managing clinical documentation and taxonomy based on spoken or transcribed encounters. The software uses artificial intelligence, including large language models, to:

  • Capture spoken input from healthcare professionals or patients

  • Generate draft clinical records

  • Facilitate documentation accuracy, efficiency, and completeness

  • Assist with administrative workflows

The device is designed to improve efficiency, accuracy, and completeness of administrative and clinical record-keeping workflows within healthcare settings. By automating clinical documentation, the device improves the quality of patient-physician interactions while at the same time improving the completeness and quality of clinical documentation.

The device is not intended for clinical decision support or diagnostic use. All generated content must be validated by the healthcare professional prior to being added to the electronic health record (EHR/EMR).

The software is available through a web interface and a native mobile application.

2. Intended Purpose

The Gosta AI Operating System is intended to:

  • Generate draft clinical notes from spoken or written input

  • Support healthcare professionals in improving quality and efficiency of record-keeping

  • Assist with administrative workflow steps based on patient encounters

It is intended solely for administrative documentation support and does not:

  • Provide diagnostic or therapeutic guidance

  • Recommend clinical interventions

  • Perform risk stratification, prediction, or decision support

All note content must be reviewed and approved by qualified healthcare professionals before incorporation into patient records.

3. Intended Users and Use Environment

Intended Users

  • Licensed healthcare professionals (physicians, physicists, nurses, psychologists, allied health personnel)

  • Social care professionals (for non-medical use — outside MDR’s scope)

The device is not intended for patient self-use.

Use Environment

  • Hospitals

  • Clinics and outpatient facilities

  • Offices where clinical or social-care-related documentation is created or reviewed.

  • Alongside travelling healthcare professionals (such as travelling nurse)

4. Intended Indications and Contra-Indications

The software indirectly supports all patient populations for whom professionals generate documentation. Therefore, it is intended for all indications.

Supported languages: English, Spanish, Portuguese, Dutch, Italian, French, Swedish, German, Finnish, Russian, Estonian, and Czech.

No contraindications are known.

5. Mode of Operation

5.1 Starting a New Encounter

To begin a new session, the user selects New Encounter. The system verifies microphone signal strength and, depending on configuration, prompts for:

  1. Language selection

  2. Appointment type / note template

Recording begins when the user presses Start Recording.

5.2 Creating the Clinical Note

During or after recording, users initiate draft generation using the Create Note button. Processing comprises two stages:

  1. Finalising transcription

  2. Generating the draft note

Users may interrupt any stage by pressing Interrupt Processing.

5.3 Editing the Draft

Each draft note is divided into sections, which users may click to edit.

  • The selected section is framed by a black border

  • “Save” and “Cancel” options appear beneath the editing area

  • Users may freely add, modify, or remove text

5.4 Regenerating with Additional Instructions

If the draft requires refinement, the user may select Regenerate, which opens a window allowing:

  • Additional instructions (typed or voice-dictated)

  • Quick commands (e.g., “add missing details,” “remove mentions,” “translate”)

    ​Regeneration is executed with default parameters if the instruction field is left empty

5.5 Transferring Note Content to the EMR

Once finalised, documentation is transferred manually:

  • Using Copy Note to copy the entire note to the clipboard

  • Using section-specific copy icons to copy individual sections

A feedback interface appears after copying, prompting the user to rate the initial model output. Users are reminded not to include sensitive or personal data in free-text feedback.

Note! Do not include personal data or other sensitive information in your feedback.

5.6 Deleting Notes

Local copies of notes (stored in the browser session) can be deleted using the Delete icon next to the appointment. If notes are not manually deleted, they are automatically removed when the browser closes. Deleted notes cannot be restored, so users must ensure EMR transfer beforehand.

Note! For information security reasons, any local copies of clinical notes should be permanently deleted immediately after transfer.

6. Technical Requirements

6. Technical Requirements

Gosta AI Operating System is a software-based medical device that requires a compatible end-user device and a functioning internet connection. Use of audio features additionally requires a functioning microphone.

The performance of the device may be affected by factors such as the end-user device, quality of the internet connection, operating environment, session duration, and the technical complexity of the language models used. Variations in performance, such as response times, may occur during use.

6.1 Desktop Operating Systems

To use the Gosta AI Operating System web application, the computer must run at least one of the following operating system versions:

  • Windows 10 or later

  • macOS 14 (Sonoma) or later

No local software installation is required to use the web application.

6.2 Web Browsers

The web application is accessed using a supported web browser. The browser version must be at least:

  • Firefox 128 (released July 2024)

  • Safari 16.4 (released March 2023)

  • Chrome 111 (released March 2023)

  • Edge 111 (released March 2023)

Use of newer browser versions is recommended.

6.3 Mobile Devices

Use of the mobile application requires a supported smartphone or tablet with a functioning internet connection. The mobile device must run at least one of the following operating system versions:

  • iOS 18.0 (released September 2024)

  • Android 11 (released September 2020)

Use of audio features in the mobile application requires a functioning microphone and the necessary microphone permissions to be granted to the application.

6.4 Infrastructure & Access

Users can authenticate and access the device through Single-Sign On, using their employer’s credentials, such as Azure-based authentication. When Single-Sign on is not available, users can authenticate and access with a unique username and password.

7. Data Protection & Cybersecurity

  • Personal data is stored only for the duration of transcription, note generation, and workflow processing.

  • When the clinician leaves the encounter, all patient data is deleted automatically.

  • No long-term storage of personal data is performed by the system.

  • Users must follow institutional policies regarding device encryption, login security, and the safeguarding of copied data.

  • If background documents containing sensitive information or patient data are uploaded to the system from the user's computer:

    • Any local copies must be deleted by the user without undue delay after use.

    • The documents must be uploaded to Gosta using the same file name as in the patient information system. The file name must not subsequently be changed in either system. The file name enables subsequent identification of the patient whose attachment was processed.

  • Users must use a strong password when logging into the system.

The system is developed and operated according to ISO/IEC 27001-certified information security practices.

8. Safety Information

General Safety Notes

  • All generated content must be reviewed for accuracy, completeness, and clinical correctness.

  • AI-generated drafts may contain incomplete, repeated, ambiguous, or incorrectly placed information (e.g., mixing contexts or omitting relevant details).

  • The system does not generate diagnoses or treatment recommendations.

Residual Risks

Despite established risk controls, including human review, risk of erroneous EMR entry cannot be completely eliminated.

Warnings

All generated content must be reviewed for accuracy, completeness, and clinical correctness.

User responsibility for safe use of the system

Safe use of the Gosta system requires that the user follows the instructions below regarding authentication and device protection.

Authentication and password

Users must use a strong password when logging into the system. A strong password is recommended to be at least 15 characters long and to contain a combination of upper- and lowercase letters, numbers and special characters. The password must not be shared with anyone and must be kept confidential. Users should use a different password from other services, and they must change the password immediately if they suspect it has been compromised or disclosed to others.

Locking the workstation

The Gosta Web application does not have an automatic session timeout, because patient appointments can be long and may include intentional pauses. It is the user's responsibility to lock the workstation whenever leaving it unattended, even briefly (Windows: Win+L, macOS: Ctrl+Cmd+Q), to keep a strong login password and an automatically locking screensaver enabled on the workstation, and to log out of Gosta at the end of the shift.

Locking the mobile device

The Gosta Mobile application does not have a separate application-level lock, so protection of the mobile device relies on the operating system's device lock. It is the user's responsibility to keep a PIN, password or biometric authentication (fingerprint or face) enabled on the mobile device at all times. Without a device lock, the application cannot protect the data stored on the device. Notify the organisation's administrator and GostaLabs immediately if the mobile device is lost or compromised, so that the device pairing can be revoked from the server side.

Import of disclosed information — prohibited

In accordance with the requirements applicable to social and healthcare services in Finland, processing of customer and patient information obtained on the basis of disclosure (luovutusperuste) requires authentication based on the social and healthcare professional certificate card (Sote-varmennekortti). Gosta does not currently support certificate-card authentication, and therefore importing disclosed information into Gosta is not permitted: users must not retrieve customer or patient information from another service provider's system (including the Kanta services) on the basis of disclosure and transfer it to Gosta. Both the service provider and the user are responsible for complying with this restriction.

9. Incidents

9.1 Identifying an incident

An incident means a malfunction, deterioration in performance, or incorrect output of the device that has led, or could have led, to harm to the health of a patient, user or other person.

For more information on identifying and reporting incidents: Fimea – Reporting of incidents

9.2 Reporting an incident

Professional users must report all incidents related to the device both to the manufacturer and to the competent authority of the Member State.

  • Reporting to the manufacturer: by e-mail: [email protected]

    • In urgent cases, the report may first be made by telephone (+358 40 0634429, Ilona Lehtinen, QARA), but a written report must also be submitted without undue delay.

10. Maintenance, Updates, and Storage

As a cloud-based software solution:

  • No user maintenance is required.

  • Updates are deployed centrally by Gosta Labs; no actions are needed from users.

No physical storage, cleaning, or disposal by users is required.

11. Compliance

  • MDR 2017/745 Class I (self-certified)

  • ISO/IEC 27001 compliant information security management

12. Manufacturer info

Gosta Labs Oy

Otakaari 5

02150 Espoo

Finland

Chat support: available to logged-in users

Revision history

Version

Date

Description of change

2.2

3 September

Chapter 6 revised, chapter 7 revised

2.1

28 April

Information about safe use added, chapter 9 Incidents added

2.0

27 March 2026

Information security related guidance

1.0

30 January 2026

Initial release

Did this answer your question?