Software in Medical Devices

To content | To menu | To search

The essential list of guidances for software medical devices

babel.jpg

This page gathers the guidances and other documents about CE mark and FDA 510k for software medical devices. I limited the list to documents, which have an impact on design.

CE Mark Guidances

I picked the documents in websites of the following organisms:

If you’re looking for documents about other steps of the software lifecycle (clinical evaluation & investigation, post-market surveillance and vigilance), you’ll find what you’re looking for in those websites.

Is your software a medical device?

The MEDDEV 2.1.6 Qualification and Classification of stand alone software contains information to let you determine if your software is a medical device. I hope for you that your software falls out of the scope of medical devices. You will save money! But I’ll be sad, because you won’t need to read my blog any more :-)

What is its classification?

The MEDDEV 2.4.1 rev9 Classification of medical devices contains a comprehensive interpretation of the classification rules of the 93/42 directive.

Not yet sure of its classification?

Have a look at the Manual on borderline and classification of medical devices. It has, amongst other things, an interesting chapter about Picture Archiving and Communication Systems (PACS).

How should I proceed to CE mark?

The NB-MED 2.2.4 rev5 Software and Medical Devices contains indications about how applying the annexes II to VII of the 93/42 CE directive.

How should I design it?

CE organizations are not talkative about software design. You have to rely on IEC 62304 standard (see posts in the "standards" category of this blog). The FDA issued the "general principles of software validation" guidance. The link is in the section about FDA guidances futher in this page.

How to do clinical evaluation?

I put the clinical evaluation in the list hence it may have an impact on design. The MEDDEV 2.7.1 rev 3 Clinical evaluation - Guide for manufacturers and notified bodies contains recommendations about clinical evaluation.
The NBOG CL 2010-1 Checklist for audit of Notified Body’s review of Clinical Data-Clinical Evaluation is also interesting to see what is expected from the notified body during clinical data evaluation.

What information should I put in the design dossier?

The NB-MED 2.5.1 rev5 Technical Documentation contains the structure of the design dossier submitted (or not, if you’re in class I) to the notified body. It’s a very generic document and doesn’t contain a lot about software.
The GHTF SG1 N11 Summary Technical Documentation for Demonstrating Conformity to the Essential Principles of Safety and Performance of Medical Devices (STED) has some more information about software.
See also my templates repository page on design documents you should provide with your design dossier.
Furthermore, you may have a look at the NBOG_BPG_2009_1 Guidance on Design-Dossier Examination and Report to see what data notified bodies expect to find in your design dossier.

What do I put in the declaration of conformity?

If you do it by yourself (your’re in class I), the MDEG – 2009–12-01 Guidance notes for manufacturers of class I medical devices contains all information about CE mark of class I devices.
Have a look also at the NB-MED 2.5.1 Rec4 Content of mandatory certificates contains interesting data on what notified bodies put in the declarations of conformity.

How do I handle design changes?

This is a big issue with software, which are always perfectible and continuously improved. The NB-MED 2.5.2 rev8 Reporting of design changes and changes of the quality system contains information on when and how to report changes to design.
Have a look also at the NB-MED 2.5.1 rev6 Renewal of EC Design-Examination and Type-Examination. It contains recommendation about when to decide to renew the design examination by a notified body.

Do I have to translate it?

Another really big issue for software, where translation may lead to design changes. The Mandatory Languages Requirements for Medical Devices is made for you.
Warning! It’s a bit old. You should have a look at the most recent regulations of member states. The advantage is if you find that a language is mandatory in this document, you won’t have to do further investigations.

Do I have to print the instructions for use?

The easiest way to deliver the IFU is to give it in an electronic format. The Council Decision on electronic instructions for use of medical devices gives information about when printing instructions is mandatory.

Here's my list so far for CE mark.


Let's see now the FDA 510k guidances for software.

FDA 510k Guidances

I picked all the documents on FDA's website: medical devices guidances search page
This is my unique source of information. Compared to what is found about CE mark, the FDA has the immense virtue to gather all the precious information! I think that FDA guidances are a little verbose. But their content is always of good level and may be used to find answers on subjects that EU guidances don’t tackle.

What is the classification of my device?

Classification of devices is most of times straightforward, with the help of the FDA database on classification of medical devices. However, things are changing quickly for software with the rush of medical devices manufacturers on Smartphones. The Draft Guidance on Mobile Medical Applications gives clues about the qualification and classification of Smartphone Apps.

How do I design it ?

Surely the most important document of the FDA about software design (after the CFR, of course!), the General Principles of Software Validation; Final Guidance for Industry and FDA Staff is one of the most comprehensive documents about software design in the medical devices industry. It covers all steps of software design and more. Read it carefully!

What about COTS?

COTS (Components Off The Shelf) are also named SOUP (Software of Unknown Provenance) in IEC 62304 standards. While some may say the concepts are slightly different, I prefer to make things simple and put the “COTS” or “SOUP” sticker on every software, for which I don’t have the source code. The guidance on Off-The-Shelf Software Use in Medical Devices deals with problems about hazards brought by this kind of software.

What about human factors engineering?

Human factors in a recent subject of concern of regulation agencies. FDA is not the last one in the race for new guidance about it with the Draft guidance on Applying Human Factors and Usability Engineering to Optimize Medical Device Design. While this new guidance still in draft state, the older guidance about Incorporating Human Factors Engineering into Risk Management remains the state of the art of FDA. Fortunately, both have a lot in common. The draft guidance integrates the latest developments on ergonomics found in IEC 62366 and AAMI HE75 standards.

What about software system security?

Software security is a non-functional requirement, which is probably the most difficult to implement if software wasn’t initially designed the right way. There are two documents on security. The first one is the transcript of a seminar about cybersecurity in medical devices. You will find on that web page the links to download the slides presented during the seminar. Instead of reading the full transcript, you may have a look at the slides. They contain treasuries about cybersecurity and legal aspects like HIPAA. The second document is the guidance about Cybersecurity for Networked Medical Devices Containing Off-the-Shelf (OTS) Software. It focuses on problems about updating COTS software (like installing a patch delivered by the COTS editor), which have impact on security.

Do I have to print the instructions for use?

The draft guidance on Acceptable Media for Electronic – Product User Manuals contains new information about cases where delivering user manuals in printed format is mandatory. If you fall out of the scope of mandatory print copies of instructions for use, enjoy.

What do I put in my 510k submission ?

FDA gives instructions about software in medical device in the Guidance for the Content of Premarket Submissions for Software Contained in Medical Devices. Another document more specific on medical Imaging software is the Guidance for the Submission Of Premarket Notifications for Medical Image Management Devices.

My device changes, should I submit a new 510k ?

The guidance on 510(k) Device Modifications: Deciding When to Submit a 510(k) for a Change to an Existing Device contains a very done decision tree and a lot of explanations new information about software. This guidance was issued in 1997 and should be udpated soon by the FDA. A new draft guidance was published by the FDA in 2011 but it was withdrawn. Expect though to have a new draft guidance soon published by the FDA.

Published on Wednesday 22 February 2012 by Mitch