Software as a NON-medical device

Junn1992

Quite Involved in Discussions
Hi Bill, to build upon Tidge's earlier point on Cybersecurity and Data Privacy, I will assume your software is not a MD, and will use the example of Zoom for use in Telehealth setting. You're lucky that I had to do a presentation on this for our company yesterday, so the info is fresh in my mind.

Is Zoom a MD? Obviously not. But it can be used in healthcare settings to facilitate tele-health conferences. Since it is only intended to display information, ie: Doctor and Patient face and video, and possibly display some medical information, here is what you should think about:

1. Cybersecurity. The directives are:
- NIS Directive 2016/1148
- EU Cybersecurity Act 2019/881
- Also recommend ENISA website. Have fun with this.
- Some standards to begin with: ISO 27799 or ISO 27001 series, those that apply in healthcare
- Do note that HIPAA is not recognised in the EU

2. GDPR: Personal Data Protection
- There was some dispute about EU-US Privacy Shield, not sure about specifics, but since you are based in the US, good to know
- Doctor Face, Patient Face, Patient Health Records, all these fall under 'data concerning health', and are regulated under Article 9 of the GDPR. This is important to note!
- Also, each individual EU state might have slight differences when it comes to application of the GDPR, good to check with your GDPR rep or EU rep
- Data transfer to third country: Would you need to setup a physical server location in the EU? Not sure, depends.
- maximilian schrems vs facebook. This is a good case study on why GPDR is important.

3. Software Development:
- Since it's not a MD, do whatever you want. Scrum Ninja Six Black Belt whatever

Sooo yep that's all I know about. Maybe others will point out some stuff not already covered. Have fun!
 

DanMann

Involved In Discussions
Again this is NOT my case. I am dealing with a NON medical device. What you are sending is MDCG 2019-11 (software for medical purposes).
Thank you!!
I know I'm coming in late on this, but this guidance (MDCG 2019-11) also has a lot of explanation of the boundary between a medical device software and a non-medical device software, which I'm not sure from the message chain whether this was answered for you clearly for the EU.
 

iam1235

Starting to get Involved
Hello,
I am in the same case as you Bill, could you tell me what document you have prepared for non-medical device software, is there a risk management to be done?
Thanks in advance,
 

DanMann

Involved In Discussions
Hello,
I am in the same case as you Bill, could you tell me what document you have prepared for non-medical device software, is there a risk management to be done?
Thanks in advance,
Hi Iam,
I'm not sure if you mean a document explaining why the product is not a medical device or the technical documentation, so I'll answer both.

1. I wrote up a policy document that laid out the crtieria from MDCG 2019-11 and explained in detail for each why it didn't apply, including anywhere there might be a misinterpretation that could mean the criteria applied. This wasn't a requirement, but I thought would be good practice in case a regulator or auditor ever enquired.

2. I was working at a medical device company, so we still followed our product development process and created the majority of a technical file (e.g. requirements, verification, validation), only missing things like the ERC/GSPRC and the Declaration. We also tailored some of the requirements to make them easier (e.g. fewer users in the usability testing). What is required for medical devices is also good practice for non-medical device products and my company was used to following our standard process, so agreed that it would deliver a quality product.
In our situation, this wasn't much of a concern, but by implementing some or all of the SaMD requirements, it meant that if a regulator ever disagreed with our assessment or we want to enter a market with different definitions of a SaMD that included our product, we would be closer to compliance.
 
Thread starter Similar threads Forum Replies Date
I Commercializing a non medical device software Medical Information Technology, Medical Software and Health Informatics 10
I Non-medical device software Preventive Action and Continuous Improvement 1
sagai Is service related software a non medical device? IEC 62304 - Medical Device Software Life Cycle Processes 4
S Do you follow your QMS for non-device software features? Medical Information Technology, Medical Software and Health Informatics 4
J Can we register non-device clinical decision support software under draft guidance? Other US Medical Device Regulations 5
B Risk Assessment Checklist for Non product Software IEC 62304 - Medical Device Software Life Cycle Processes 1
M How to calculate benefits? Moving some developed non controlled software/automation systems Service Industry Specific Topics 2
M FDA News Digital Health Update: USFDA Report on Non-Device Software Functions Now Available Medical Device and FDA Regulations and Standards News 0
A Non-Conforming Material Control and Inventory Software System Recommendations Quality Assurance and Compliance Software Tools and Solutions 5
S Documentation needed when changing software due non-compliance of 21 CRF Part 11 Qualification and Validation (including 21 CFR Part 11) 2
T Importing Non-Electromedical Device (PACS Software) into South Africa Other Medical Device Regulations World-Wide 2
T 510k Submission - Class II Software communicates with a Non-Classified Device 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 5
M Non-Conforming Material Hold Tracking Software Quality Assurance and Compliance Software Tools and Solutions 2
G Non-Conformance Management Software Quality Assurance and Compliance Software Tools and Solutions 55
R Data Analysis Software classified as MDSW IVD? EU Medical Device Regulations 3
V PQ parameters for computer system validation of configurable software of laboratory equipment Qualification and Validation (including 21 CFR Part 11) 0
W Training software medical device Medical Device Related Standards 0
R IVDR software requirements CE Marking (Conformité Européene) / CB Scheme 2
T Class B IEC 62304 - 5.4 Software Detailed Design IEC 62304 - Medical Device Software Life Cycle Processes 4
T New guidance "Content of Premarket Submissions for Device Software Functions" IEC 62304 - Medical Device Software Life Cycle Processes 5
J Determination of software safety class (62304) prior to software risk analysis ISO 14971 - Medical Device Risk Management 3
T OTS (Off-the -Shelf) Software involved in error control and messaging US Food and Drug Administration (FDA) 1
dgrainger Informational MHRA Guidance: Crafting an intended purpose in the context of Software as a Medical Device (SaMD) UK Medical Device Regulations 0
G Compatibility Report for third-party software Medical Information Technology, Medical Software and Health Informatics 2
L Directive 2012/19/EU for medical software EU Medical Device Regulations 2
S Need guidance for Software validation Qualification and Validation (including 21 CFR Part 11) 5
C Can SaMD consist almost entirely of Software of Unknown Provenance (SOUP)? IEC 62304 - Medical Device Software Life Cycle Processes 4
Sam.F ISO9001/AS9100 Software Quality Assurance and Compliance Software Tools and Solutions 1
M Software Safety Classification and Legacy Software IEC 62304 - Medical Device Software Life Cycle Processes 4
Ron Rompen Document archiving software & hardware Document Control Systems, Procedures, Forms and Templates 0
Vader22 INTELEX software for their IATF 16949 QMS IATF 16949 - Automotive Quality Systems Standard 0
D Quality Gates for software development Software Quality Assurance 2
M Update to software after CE-certificate has expired. EU Medical Device Regulations 1
K Monitors supplied with software EU EU Medical Device Regulations 4
K Best automation presentation software Manufacturing and Related Processes 0
Paul Simpson Quality management system software development - looking for candidate organizations Quality Assurance and Compliance Software Tools and Solutions 2
N Software update after placed on the market Medical Device and FDA Regulations and Standards News 2
MaHoDie Is it possible to assign medical software to security class A (according to IEC 62304)? EU Medical Device Regulations 8
T Aircraft GAPP Software Testing Compliance Question AS9100, IAQG, NADCAP and Aerospace related Standards and Requirements 1
Q Training Matrix Software Training - Internal, External, Online and Distance Learning 2
I SaMD Software bug and issue tracking. Manufacturing and Related Processes 3
MaHoDie Where to show the Software version IEC 62304 - Medical Device Software Life Cycle Processes 2
W Looking for IATF 16949 (and ISO 17025) QMS software Suggestions Quality Tools, Improvement and Analysis 8
9 ECi M1 Software Consultants in Ohio Manufacturing and Related Processes 0
T SaMD or Software system? EU Medical Device Regulations 2
I Registration of MD software IEC 62304 - Medical Device Software Life Cycle Processes 0
Q Quality Plan for eQMS software ISO 13485:2016 - Medical Device Quality Management Systems 2
Ed Panek Validation of Signature Software (Off the shelf) US Medical Device Regulations 6
C FMEA Software Report View FMEA and Control Plans 1
jeancloude17 Advice for ISO 9001 for software Design and Development of Products and Processes 2

Similar threads

Top Bottom