MDD
Hong Kong - MDD
Medical Device Administrative Control System (MDACS)
Authority
Medical Device Division, Department of Health
Enforced
2004 (voluntary MDACS launched)
Legal framework
Voluntary Medical Device Administrative Control System (MDACS) operated by the MDD; PDPO (Cap. 486) for personal data; CSL bill under development for critical infrastructure including healthcare.
Scope
All medical devices marketed in Hong Kong via voluntary MDACS listing. Separate from mainland China's NMPA regime. SaMD covered by MDACS Technical Reference TR-004.
Pre-market
Reliance-based: listing requires evidence of approval by at least one Reference Country regulator (FDA, EU, Health Canada, TGA, PMDA). Cybersecurity expectations follow the reference-country submission.
Post-market
MDACS adverse-event reporting; PCPD handles personal-data breach notifications under PDPO.
SBOM
RecommendedNot mandated by MDACS, but reference-country SBOMs accepted as part of the listing dossier.
Vulnerability disclosure
HKCERT coordinates ICT incidents; no medical-device-specific CVD requirement.
Penalty
Removal from MDACS listing; healthcare procurement consequences (most HA tenders require MDACS-listed devices).
Unique requirements
- 01Local Responsible Person appointment
- 02Reference-country approval as the gating evidence
- 03Traditional Chinese labelling for consumer devices
Highlights
- Reliance on FDA/CE/HC/TGA/PMDA approvals
- Listing is voluntary but de-facto required for HA procurement
- Separate regime from mainland China NMPA
Aligns with
Timeline
-
2004
MDACS voluntary listing launched
-
2021
PDPO amendments tighten doxxing/data-protection rules
-
2024
Cybersecurity Legislation Bill (CSL) for CII published for consultation
Key documents
How to submit in Hong Kong
Playbook reviewed · 2026-07-16
Submission route
MDACS voluntary listing with Hong Kong Department of Health
Hong Kong's Medical Device Administrative Control System is voluntary. Cybersecurity documentation is not separately mandated but recommended.
Authority portalStep-by-step
-
Step 01
Appoint local representation
Most jurisdictions require a locally-established entity to hold the registration or act as authorised representative before submission.
-
Step 02
Reuse FDA or CE package as baseline
Adapt the cybersecurity subsection you already prepared for FDA or CE; regulators here typically accept the structure and ask for local labeling additions.
-
Step 03
Translate and localise
Local-language technical summary and labeling are usually mandatory; certified translation is safest.
-
Step 04
Submit + track queries
Respond to clarification rounds promptly; each unanswered question can add 30-90 days to the clock.
Evidence checklist
| Item | Level | FDA equivalent | Notes |
|---|---|---|---|
| Cybersecurity documentation (baseline FDA or CE) | Required | SPDF | |
| Local authorised representative agreement | Required | — | |
| Local-language labeling and IFU | Required | — | |
| SBOM | Recommended | — | Not mandatory but reduces clarification rounds. |
Common MDACS rejections
Documentation not aligned with MDACS classification
OccasionalFix · Follow the MDACS classification rules and provide matching evidence.
Typical timeline
End-to-end window: 3-6 months
Phase 01
Local rep + dossier prep
2-4 months
Phase 02
Regulatory review
3-6 months
Phase 03
Approval + market entry
1-3 months
Related markets
Frequently asked about Hong Kong
Is SBOM required for medical devices in Hong Kong?
Recommended. Not mandated by MDACS, but reference-country SBOMs accepted as part of the listing dossier.
What does MDD require for pre-market cybersecurity?
Reliance-based: listing requires evidence of approval by at least one Reference Country regulator (FDA, EU, Health Canada, TGA, PMDA). Cybersecurity expectations follow the reference-country submission.
What are the post-market cybersecurity obligations under MDD?
MDACS adverse-event reporting; PCPD handles personal-data breach notifications under PDPO.
What is the penalty for non-compliance with MDD cybersecurity rules?
Removal from MDACS listing; healthcare procurement consequences (most HA tenders require MDACS-listed devices).
How much of my FDA cybersecurity package is reusable in Hong Kong?
Roughly 90% - an editorial estimate based on overlapping evidence requirements (threat model, SBOM, security risk assessment, pen-test report).