How medical device manufacturers are implementing standards like GDPR and HIPAA

Chromemo

Registered
I’m curious from a tactical standpoint how medical device manufacturers are implementing standards like GDPR and HIPAA either inside or outside the QMS. Do you use the same quality systems and the SOP hierarchy you use for QMS processes or roll them into a different business process?

There is resistance to release Operating procedures and Work instructions within the QMS as there is concern that they could be “discoverable” by regulators like FDA and ISO auditors.

I’m concerned if they aren’t structured as QMS requirements they not be followed strictly, and there could be real or perceived conflicts.
 

Ed Panek

QA RA Small Med Dev Company
Leader
Super Moderator
We added a section to our QMS called BUS for business because is satisfies customer or partner queries and interest. Our QMS is a nice way to control all our documents, not only ones related to a standard. Yes an auditor can review them but what standard and scope would they claim that gives them authority over these processes? We also have in our QMS disaster and recovery plans, some ISMS documents but any 9001 or 13485 auditor would have no governance over them.

If they argue about it show them this from ISO 13485: "It is not the intent of this International Standard to imply the need for uniformity in the structure of different quality management systems, uniformity of documentation or alignment of documentation to the clause structure of this International Standard."
 
Last edited:

yodon

Leader
Super Moderator
This is an interesting discussion. ISO 13485 states:

5.2 Customer focus
Top management shall ensure that customer requirements and applicable regulatory requirements are
determined and met.


Further:

8.2.4 Internal audit
The organization shall conduct internal audits at planned intervals to determine whether the quality management system:
a) conforms to planned and documented arrangements, requirements of this International Standard, quality management system requirements established by the organization, and applicable regulatory requirements;


(my emphasis added in both).

If you're 13485 and selling into Canada, the AOs I've worked with require that an internal audit cover MDSAP requirements. If you're selling in the US, they can look at compliance to the QSR. And if in EU, the MDR is now in play So where IS the line drawn? What constitutes a 'complete' internal audit? GDPR and HIPAA are "applicable" regulatory requirements if you're in those areas. Why should those be out of scope for either internal or external audit?
 

Ed Panek

QA RA Small Med Dev Company
Leader
Super Moderator
Interesting.

Can you be non GDPR but CE compliant? Non HIPAA but QSR compliant? Not FCC but QSR compliant? What if a MDR audit finds a a problem with MHLW (Japan) compliance?
 

yodon

Leader
Super Moderator
If you're not collecting / managing protected (health) info then yes.

By MDR audit, do you mean technical file review? If so then they wouldn't care. If an ISO audit and Japan is in scope, ???
 

Ed Panek

QA RA Small Med Dev Company
Leader
Super Moderator
What if you are collecting data? Would an ISO auditor in the USA know enough to protect EU patients under GDPR and make a finding?
 
Thread starter Similar threads Forum Replies Date
K Medical Device file and "Component" Manufacturers? Other Medical Device and Orthopedic Related Topics 6
J Average number of Nonconformances during internal quality audit for Medical Device Manufacturers Internal Auditing 3
JoCam Certified QMS for MDR - Class I medical device manufacturers EU Medical Device Regulations 8
I Japanese medical device recall requirements & procedure for foreign manufacturers Japan Medical Device Regulations 4
H Is Product Liability Insurance Compulsory for Medical Device Manufacturers? Other Medical Device Regulations World-Wide 2
S Manufacturers Obligations for Medical Device Servicing and/or Repair EU Medical Device Regulations 10
A One Medical Device - Two Legal Manufacturers ISO 13485:2016 - Medical Device Quality Management Systems 5
M New Medical Device Contract Manufacturers Excise Tax Requirements US Food and Drug Administration (FDA) 8
Marc Guide To Inspections Of Medical Device Manufacturers - 1997 (06/08/2010) US Food and Drug Administration (FDA) 3
M Problems implementing ISO 13485 for Software-Only Medical Device Manufacturers? ISO 13485:2016 - Medical Device Quality Management Systems 4
B FDA Requirements for Retaining Non-Conformance Tags (Medical Device Manufacturers) 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 2
L First Article Inspection Criteria for Medical Device Manufacturers Inspection, Prints (Drawings), Testing, Sampling and Related Topics 5
S First Article Inspection - General Practices for Medical Device Manufacturers Inspection, Prints (Drawings), Testing, Sampling and Related Topics 3
A Home Based Medical Device Manufacturers or Component Vendors (Suppliers)? Other US Medical Device Regulations 3
S MSA (Measurement System Analysis) for Medical Device Manufacturers Other US Medical Device Regulations 3
A Validation of PLC's with Medical Device Manufacturers 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 7
T Korean requirements for foreign medical device contract manufacturers? Japan Medical Device Regulations 2
T Definition Certificate of Conformance - Meaning and Definition of - Medical Device Manufacturers Definitions, Acronyms, Abbreviations and Interpretations Listed Alphabetically 4
Al Rosen FDA Compliance Manual, Inspection of Medical Device Manufacturers, Available ISO 13485:2016 - Medical Device Quality Management Systems 2
V Records of Obsolete Medical Device(s) for Contract Manufacturers Records and Data - Quality, Legal and Other Evidence 6
adztesla Sterile packaging validation for medical device - ASTMD4332 and ISTA2A ISO 13485:2016 - Medical Device Quality Management Systems 2
P On-going stability study requirement for medical device US Food and Drug Administration (FDA) 2
N Regulations for Medical Device in Jamaica Other US Medical Device Regulations 0
M Classification of device according to China medical device regulations China Medical Device Regulations 4
adztesla Design change and Process change Class 3 medical device Medical Device and FDA Regulations and Standards News 2
M Importing a custom component for our medical device 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 1
adztesla Adding new supplier/ Medical device design change ISO 13485:2016 - Medical Device Quality Management Systems 2
adztesla Medical device Drawing related change justification Other Medical Device Related Standards 0
O Medical Device With 2 Power Cords IEC 60601 - Medical Electrical Equipment Safety Standards Series 5
Stoic Which medical device companies are using Recombinant Factor C (rFC) instead of Limulus Amebocyte Lysate (LAL) for endotoxin testing? Sustainability, Green Initiatives and Ecology 0
I Commercializing a non medical device software Medical Information Technology, Medical Software and Health Informatics 10
I Non-medical device software Preventive Action and Continuous Improvement 1
C California Prop 65 for medical device labels US Medical Device Regulations 3
adztesla GDP rules- redline drawings in medical device Medical Device and FDA Regulations and Standards News 2
R Instructions for Use supplied with Medical Device Components Medical Device and FDA Regulations and Standards News 4
M Deburring plastic medical device Manufacturing and Related Processes 1
W Training software medical device Medical Device Related Standards 0
S Modification of medical device EU Medical Device Regulations 2
P Do Barcode scanners need validation in Medical device manufacturing? Manufacturing and Related Processes 6
B FDA Requirements for medical device to be used for training purposes only US Food and Drug Administration (FDA) 9
F Adding wireless communication to existing medical device IEC 60601 - Medical Electrical Equipment Safety Standards Series 4
J Medical device sizes and system and procedure packs EU Medical Device Regulations 0
U Does Medical Device training video falls under labeling requirement ? Other US Medical Device Regulations 4
dgrainger Informational MHRA Guidance: Crafting an intended purpose in the context of Software as a Medical Device (SaMD) UK Medical Device Regulations 0
B Medical device disposables - Stored in a controlled environment for 4 months - Effects on Sterilization Medical Device and FDA Regulations and Standards News 1
W MOOPs in Medical Device Charger IEC 60601 - Medical Electrical Equipment Safety Standards Series 1
adztesla Specification (Significant digits) - Measurement (Medical device) ISO 13485:2016 - Medical Device Quality Management Systems 3
S Accessory to medical device or not? EU Medical Device Regulations 1
K Question on registration of class 1 medical device in Turkey Other Medical Device Regulations World-Wide 0
N Class II Medical Device with Metallic Enclosure IEC 60601 - Medical Electrical Equipment Safety Standards Series 11

Similar threads

Top Bottom