GUIDES: Medical Device Sales and Marketing Compliance
The MedTech Europe Code of Ethical Business Practice sets the conduct standard for every company that promotes, sells, or supports medical technology in Europe.
The MedTech Europe Code of Ethical Business Practice is the industry-wide ethical standard governing how medical device and in vitro diagnostics companies may interact with healthcare professionals, healthcare organisations, and patient organisations across Europe. Adopted by MedTech Europe and its national member associations, the Code sets binding rules for promotional activities, transfers of value, educational grants, consultancy arrangements, and transparency reporting. For compliance officers, regulatory affairs teams, and sales and marketing leadership, understanding the Code precisely is not optional, it governs what your representatives may say and do in front of a surgeon, a procurement officer, or a hospital administrator. This guide covers what the Code requires, what it prohibits, how to build a compliant programme, and where companies most commonly fall short.
Annual
Transparency Reports Required from Member Companies Every Calendar Year
MedTech Europe member companies and national association members are required to publish annual transparency reports disclosing transfers of value to healthcare professionals and healthcare organisations. The reporting obligation covers consultancy fees, educational support, grants, and hospitality. The purpose is to allow public scrutiny of the financial relationships between the medtech industry and the healthcare community. Source: MedTech Europe: Code of Ethical Business Practice
Zero
Gifts or Entertainment Provided as Inducements to Purchase or Recommend Are Permitted
The Code prohibits providing gifts, hospitality, or other benefits to healthcare professionals where the purpose or effect is to induce the purchase or recommendation of a medical device. Items of minimal value that serve a genuine educational purpose may be permitted within strict limits. Cash or cash equivalents are prohibited outright regardless of amount. Source: MedTech Europe: Code
Written
Contracts Required for All Consultancy and Educational Grant Arrangements with HCPs
Every consultancy arrangement between a member company and a healthcare professional must be documented in a written contract before the engagement begins. The contract must specify the nature of the services, the fair market value compensation, and the business rationale. Verbal arrangements or post-hoc documentation do not satisfy the Code’s requirements. Source: MedTech Europe: Code
The MedTech Europe Code of Ethical Business Practice is a self-regulatory framework developed by MedTech Europe, the European trade association for the medical technology industry, in collaboration with its national member associations. The Code applies to companies that are members of MedTech Europe or of any MedTech Europe national member association. It governs the full range of business interactions between medtech companies and healthcare professionals (HCPs), healthcare organisations (HCOs), and patient organisations (POs) across European markets.
The Code operates alongside, and in some areas more strictly than, applicable national laws and EU regulations. Where national law is more restrictive than the Code, national law applies. Where the Code is more restrictive than national law, the Code applies. Companies that operate in multiple European markets must navigate both the Code and the national-level implementation by each member association, meaning the same interaction that is Code-compliant at the European level may still be subject to additional national restrictions.
Who the Code covers
The Code covers all MedTech Europe member companies and all members of national associations affiliated with MedTech Europe. It applies to the company’s own employees, contracted sales representatives, distributors where the company directs their conduct, and any third party acting on the company’s behalf in interactions with HCPs, HCOs, or patient organisations. Responsibility for Code compliance rests with the member company regardless of whether the interaction is conducted by a direct employee or a third party.
What is not covered
The Code does not apply to purely commercial B2B arrangements between companies where no healthcare professional or patient organisation is involved. It does not govern interactions with health authorities acting in their regulatory capacity. It does not apply to companies that are not members of MedTech Europe or an affiliated national association, though many non-member companies adopt the Code voluntarily as a standard, and some national laws impose equivalent or similar obligations regardless of membership.
Before any sales representative, clinical specialist, or account manager interacts with a healthcare professional under the Code, the company must have certain foundational elements in place. These are not procedural formalities, they are the infrastructure that makes compliant interactions possible and defensible in a review or audit.
A written Code compliance policy adopted by senior leadership
The company must have a written compliance policy that incorporates the Code’s requirements. This policy must be approved at senior leadership level, not drafted by compliance and left in a document repository. The policy must be communicated to all personnel who interact with HCPs, HCOs, and patient organisations, and must be updated whenever the Code is revised. A policy that has not been updated to reflect the current version of the Code does not satisfy this requirement.
A trained compliance function with review authority
The company must have a compliance function, whether internal or supported by external expertise, with authority to review and approve promotional materials, HCP agreements, educational grants, and event arrangements before they proceed. A compliance function that can advise but cannot stop a non-compliant activity is not an effective compliance function for Code purposes. Review authority must be real, documented, and exercised before interactions occur.
Training for all personnel who interact with HCPs
Every person who interacts with healthcare professionals on behalf of the company must receive training on the Code before their first such interaction and on a regular refresher basis thereafter. Training must cover not only the rules but how to apply them in the specific interaction types the person will conduct, HCP meetings, educational events, consultancy arrangements, and product demonstrations. Documentation of training completion is required and must be maintained.
Systems for recording and reporting transfers of value
The transparency reporting obligation requires the company to track all transfers of value to HCPs, HCOs, and patient organisations throughout the year and report them accurately in the annual transparency report. This requires a system, whether a dedicated compliance platform, a controlled spreadsheet process, or an integrated CRM feature, that captures transfers at the point they are approved or made, not at year-end from memory. Year-end reconstruction of transfer records is a common cause of reporting errors and omissions.
Consultancy arrangements that lack a documented business need
The most common consultancy failure is engaging an HCP as a consultant without a genuine, documented business need. When the HCP selected is a high-volume user of the company’s products in the same market where their consultancy services are being engaged, the risk that the consultancy is functioning as a reward for purchasing is real and reviewable. The business need must be documented before the HCP is identified, not after. If the compliance team cannot articulate why this specific service was needed independently of the purchasing relationship, the arrangement cannot be defended.
Hospitality that is not modest or is not incidental to a genuine purpose
Hospitality failures typically arise when events are designed around the hospitality rather than around the educational or scientific content. A dinner at a premium restaurant without a documented scientific agenda, a training event held at a resort venue where recreational activities are the primary draw, or travel arrangements that go significantly beyond economy class and standard hotel accommodation for what the event requires, these are patterns that signal the hospitality is the purpose rather than incidental to it. The Code’s test is objective: would an outside observer conclude that the hospitality was the reason HCPs attended?
Promotional materials with claims not substantiated by clinical evidence
Promotional material failures frequently involve clinical claims that go beyond what the supporting evidence demonstrates. Absolute superlatives (“best in class”, “superior outcomes”), claims that rely on unpublished or preliminary data, comparisons to competitor products that are not supported by head-to-head clinical evidence, and claims that present a subset of data as though it represents the full picture, these are material accuracy failures. Sales representatives who make oral claims during product demonstrations that go beyond the approved product labelling are equally non-compliant, even when those claims are not in any written material.
Transparency reports that are incomplete or based on year-end reconstruction
Transparency reporting failures are typically process failures rather than deliberate omissions. Companies that lack a systematic capture process for transfers of value at the time they occur will produce incomplete reports. Common omission categories include: hospitality provided at field-level events that bypasses the central approval process; consultancy fees paid directly by a business unit without routing through the compliance or finance system; educational grants approved by a subsidiary without central visibility; and patient organisation support that is categorised as general marketing rather than as a reportable transfer. The system must capture all transfers, not just those that go through formal approval channels.
The Code applies to third parties acting on your behalf, you cannot outsource the compliance obligation
A distributor, contracted sales representative, or promotional partner who makes a non-compliant interaction with an HCP on your behalf is your problem, not theirs. The Code places the compliance obligation on the member company regardless of whether the conduct was carried out by an employee or a third party. Third-party due diligence, written contractual Code compliance obligations, and monitoring of third-party conduct are not optional risk management measures, they are programme essentials.
The test for any HCP benefit is always objective: would an outside observer view this as an inducement?
The Code does not require that a benefit was intended as an inducement, it requires that it could be perceived as one by an objective observer. This is a higher standard than intent. A meal, a gift, a consultancy fee, or a hospitality arrangement that would strike a reasonable outside observer as a reward for purchasing or prescribing is non-compliant regardless of the company’s intention in providing it. Every benefit decision should be made by applying this observer test before approval.
Transparency reporting is not a disclosure exercise, it is the output of a year-round capture process
Companies that approach transparency reporting as an annual data collection exercise will produce incomplete and inaccurate reports. The Code’s reporting obligation is only satisfiable if transfers of value are captured at the time they occur, through systems and processes that operate throughout the year across all business units, subsidiaries, and third parties. The annual transparency report is the output of that year-round process, not the process itself. Building the capture system is a more important compliance investment than building the report template.
What is the MedTech Europe Code of Ethical Business Practice?
The MedTech Europe Code of Ethical Business Practice is a self-regulatory framework developed by MedTech Europe, the European trade association for the medical technology industry, governing how member companies may interact with healthcare professionals, healthcare organisations, and patient organisations. It sets rules for promotional activities, transfers of value, consultancy arrangements, educational grants, company-sponsored events, and transparency reporting. The Code applies to MedTech Europe member companies and members of national associations affiliated with MedTech Europe. It operates alongside applicable national laws and EU regulations, applying whichever standard is more restrictive in any given situation. Source: MedTech Europe: Code
Does the MedTech Europe Code apply to companies that are not MedTech Europe members?
The Code is formally binding only on MedTech Europe member companies and members of national associations affiliated with MedTech Europe. Non-member companies are not contractually bound by the Code. However, many non-member companies adopt the Code voluntarily as a compliance standard, particularly when operating in European markets where customers, healthcare procurement authorities, or national healthcare systems expect Code-aligned conduct. Additionally, some EU member states have national laws governing HCP interactions that impose similar or equivalent obligations on all medtech companies operating in that market regardless of Code membership.
What transfers of value must be included in the annual transparency report?
The annual transparency report must include all transfers of value made during the preceding calendar year to healthcare professionals, healthcare organisations, and patient organisations. This covers: consultancy fees paid to HCPs for services including speaking, advisory board participation, and clinical training delivery; educational grants and support for third-party educational events; hospitality costs including meals, travel, and accommodation provided in connection with company events; sponsorship of HCP attendance at external conferences and educational events; and financial support provided to patient organisations. The report must be publicly accessible and cover all business units and subsidiaries of the member company, including relevant third-party activity the company directed. Source: MedTech Europe: Code
Can a medtech company pay a healthcare professional to speak at a company-organised event?
Yes, under specific conditions. An HCP may be engaged as a speaker at a company-organised event where there is a genuine business need for the HCP’s expertise, the HCP is selected based on their qualifications and relevance to the topic, the compensation is at fair market value for the speaking services provided, and the arrangement is documented in a written contract before the engagement begins. The event itself must have a legitimate educational or scientific purpose, and the speaking arrangement must not be structured or perceived as a reward for the HCP’s purchasing decisions. The compensation must also be disclosed in the company’s annual transparency report.
What hospitality can a medtech company provide to healthcare professionals at a company event?
Hospitality provided to HCPs at company-organised events must be modest and appropriate to the occasion, and it must be secondary to the primary educational or scientific purpose of the event. This means meals that are reasonable in cost and appropriate to the setting, standard hotel accommodation for the duration of the event, and economy class travel where travel is necessary for participation. Premium restaurant dinners, luxury hotel upgrades, and business class travel for routine domestic events are the types of hospitality that the Code identifies as potentially non-compliant. Recreational activities, entertainment, and accompanying persons’ costs may not be covered. The guiding test is whether the hospitality is incidental to the educational purpose or whether it is a draw in its own right.
How should a medtech company manage Code compliance when using distributors?
The Code places responsibility for compliance on the member company regardless of whether a distribution partner carries out the interaction with HCPs. Companies using distributors must include Code compliance obligations in the distributor agreement, conduct due diligence to assess the distributor’s capacity and commitment to compliance, provide training on the Code’s requirements, and monitor distributor conduct through periodic reviews, audits, or reporting mechanisms. Transfers of value made by distributors at the company’s direction or on its behalf are reportable in the company’s transparency report. A distributor violation is a company problem, not a basis for the company to disclaim responsibility.
What is the difference between the MedTech Europe Code and the EUCOMED Code?
EUCOMED was the European trade association for the medical device industry that merged with Edma (the European Diagnostic Manufacturers Association) in 2016 to form MedTech Europe. The EUCOMED Code of Ethical Business Practice was the predecessor to the current MedTech Europe Code. The MedTech Europe Code, developed following the 2016 merger, applies to the full scope of medical technology including both medical devices and in vitro diagnostics. Companies that were previously operating under the EUCOMED Code are now subject to the MedTech Europe Code. The substantive principles are similar, but the current Code represents the current binding standard and any compliance programme should reference it, not the legacy EUCOMED Code.
Who enforces the MedTech Europe Code and what are the consequences of non-compliance?
The Code is enforced through a self-regulatory mechanism involving MedTech Europe and its national member associations. National associations typically have complaints and adjudication processes through which violations can be reported and investigated. Consequences available under the self-regulatory framework include formal sanctions, required corrective actions, and reputational consequences. In addition, Code violations may constitute or overlap with violations of national anti-bribery laws, national HCP interaction regulations, or EU law, in those cases, national regulatory authorities and law enforcement may be involved independently of the self-regulatory process. The self-regulatory nature of the Code does not mean it is without consequence, it means the enforcement mechanism is industry-led rather than government-led.
Law
Medicare Agent Marketing Compensation Rules: CMS Law
The regulatory parallel in the US healthcare market, covering how CMS governs agent compensation, promotional conduct, and the prohibition on inducements in the Medicare context, with direct comparison value for compliance teams operating across both markets.
Law
Medicare Part D Medication Therapy Management Law
The regulatory framework governing another healthcare professional interaction domain, medication therapy management, with direct relevance for compliance teams who manage both sales conduct and clinical programme obligations across a healthcare product portfolio.
Worker Safety
Medicare Beneficiary Protections Agent Training Guide
The agent conduct standard for the US Medicare market, covering the beneficiary protection rules that govern sales interactions, with thematic parallels to the Code’s HCP interaction standards for understanding how comparable principles are applied across different regulatory systems.
MEDICAL DEVICE SALES AND MARKETING COMPLIANCE
More Medical Device Compliance Guides
Explore VelSafe’s medical device compliance library for guides covering HCP interaction standards, sales conduct requirements, promotional material obligations, and the compliance programme design considerations for medtech companies operating across global markets.
Explore All Guides