Fda consultant specialist
FDA regulatory consultant for medical device companies.
How to use it
Claude Code
- Run the line below. It pulls the whole folder into
~/.claude/skills/fda-consultant-specialist, including the files SKILL.md points to. - Describe your job in plain words. Claude Code follows the skill from there.
npx degit alirezarezvani/claude-skills/ra-qm-team/skills/fda-consultant-specialist#main ~/.claude/skills/fda-consultant-specialistFor one project only, change the path to .claude/skills/fda-consultant-specialist. This skill also uses fda_submission_guide.md, qsr_compliance_requirements.md, hipaa_compliance_framework.md, device_cybersecurity_guidance.md, fda_submission_tracker.py, qsr_compliance_checker.py — copying SKILL.md alone won't be enough. See the folder on GitHub.
Claude (web or desktop app)
- On this page open ⋯ → Download .md.
- Save it as SKILL.md in a folder, zip the folder, then Customize → Skills → + → Create skill → Upload a skill.
- Pick the file and Save. Claude shows the name and description and runs a security scan.
- Check the skill is switched on.
- Start a new chat and describe your job in plain words. The AI follows the skill from there.
ChatGPT or another app
- ChatGPT: make a Project and paste it into Instructions.
- Neither? Paste it at the top of a new chat — it works for that chat.
Not working?
- Check which app you pasted it into — the steps above name the right one.
- Some skills need the paid tier of Claude or ChatGPT.
Paste into Claude, ChatGPT or Cursor.
Source of Fda consultant specialist
Show the full text312 lines
| name | description |
|---|---|
| fda-consultant-specialist | FDA regulatory consultant for medical device companies. Provides 510(k)/PMA/De Novo pathway guidance, QMSR (21 CFR 820, which incorporates ISO 13485:2016 by reference since 2026-02-02; formerly QSR) compliance, HIPAA assessments, and device cybersecurity. Use when user mentions FDA submission, 510(k), PMA, De Novo, QMSR, QSR, ISO 13485 for FDA, premarket, predicate device, substantial equivalence, HIPAA medical device, or FDA cybersecurity. |
FDA Consultant Specialist
FDA regulatory consulting for medical device manufacturers covering submission pathways, the Quality Management System Regulation (QMSR, 21 CFR Part 820 — formerly the QSR), HIPAA compliance, and device cybersecurity requirements.
Table of Contents
- FDA Pathway Selection
- 510(k) Submission Process
- QMSR Compliance (formerly QSR)
- HIPAA for Medical Devices
- Device Cybersecurity
- Resources
FDA Pathway Selection
Determine the appropriate FDA regulatory pathway based on device classification and predicate availability.
Decision Framework
Predicate device exists?
├── YES → Substantially equivalent?
│ ├── YES → 510(k) Pathway
│ │ ├── No design changes → Abbreviated 510(k)
│ │ ├── Manufacturing only → Special 510(k)
│ │ └── Design/performance → Traditional 510(k)
│ └── NO → PMA or De Novo
└── NO → Novel device?
├── Low-to-moderate risk → De Novo
└── High risk (Class III) → PMA
Pathway Comparison
| Pathway | When to Use | Timeline | User Fee (FY2024) |
|---|---|---|---|
| 510(k) Traditional | Predicate exists, design changes | 90 days | $21,760 (FY2024) |
| 510(k) Special | Manufacturing changes only | 30 days | $21,760 (FY2024) |
| 510(k) Abbreviated | Guidance/standard conformance | 30 days | $21,760 (FY2024) |
| De Novo | Novel, low-moderate risk | 150 days | $134,676 (FY2024) |
| PMA | Class III, no predicate | 180+ days | $425,000+ (FY2024) |
User fees are set annually under MDUFA. Verify current-fiscal-year fees at fda.gov (MDUFA user fee schedule) before budgeting; small-business rates differ.
Pre-Submission Strategy
- Identify product code and classification
- Search 510(k) database for predicates
- Assess substantial equivalence feasibility
- Prepare Q-Sub questions for FDA
- Schedule Pre-Sub meeting if needed
Reference: See fda_submission_guide.md for pathway decision matrices and submission requirements.
510(k) Submission Process
Workflow
Phase 1: Planning
├── Step 1: Identify predicate device(s)
├── Step 2: Compare intended use and technology
├── Step 3: Determine testing requirements
└── Checkpoint: SE argument feasible?
Phase 2: Preparation
├── Step 4: Complete performance testing
├── Step 5: Prepare device description
├── Step 6: Document SE comparison
├── Step 7: Finalize labeling
└── Checkpoint: All required sections complete?
Phase 3: Submission
├── Step 8: Assemble submission package
├── Step 9: Submit via eSTAR
├── Step 10: Track acknowledgment
└── Checkpoint: Submission accepted?
Phase 4: Review
├── Step 11: Monitor review status
├── Step 12: Respond to AI requests
├── Step 13: Receive decision
└── Verification: SE letter received?
Required Sections (21 CFR 807.87)
| Section | Content |
|---|---|
| Cover Letter | Submission type, device ID, contact info |
| Form 3514 | CDRH premarket review cover sheet |
| Device Description | Physical description, principles of operation |
| Indications for Use | Form 3881, patient population, use environment |
| SE Comparison | Side-by-side comparison with predicate |
| Performance Testing | Bench, biocompatibility, electrical safety |
| Software Documentation | Level of concern, hazard analysis (IEC 62304) |
| Labeling | IFU, package labels, warnings |
| 510(k) Summary | Public summary of submission |
Common RTA Issues
| Issue | Prevention |
|---|---|
| Missing user fee | Verify payment before submission |
| Incomplete Form 3514 | Review all fields, ensure signature |
| No predicate identified | Confirm K-number in FDA database |
| Inadequate SE comparison | Address all technological characteristics |
QMSR Compliance (formerly QSR)
Quality Management System Regulation (QMSR) requirements for medical device manufacturers under 21 CFR Part 820.
QMSR transition (effective 2026-02-02): FDA's QMSR final rule (89 FR 7496) amended 21 CFR Part 820 to incorporate ISO 13485:2016 by reference and removed the legacy QSR subsection structure (820.20–820.198). Those subsection numbers are historical and no longer exist in the CFR; the corresponding requirements now flow from ISO 13485:2016 clauses plus the retained/renumbered sections 820.10 (requirements, incl. the ISO 13485 incorporation), 820.35 (records), and 820.45 (device labeling and packaging controls). 21 CFR Parts 801, 803, 806, and 830 are unchanged. Legacy QSR numbers below are kept only as a familiar index, each mapped to its current ISO 13485 clause.
Key Quality Subsystems (legacy QSR index → current ISO 13485:2016 clause)
| Legacy QSR Section (historical, pre-2026) | Title | Current authority under QMSR | Focus |
|---|---|---|---|
| 820.20 | Management Responsibility | ISO 13485 §5.1, 5.5, 5.6 | Quality policy, org structure, management review |
| 820.30 | Design Controls | ISO 13485 §7.3 | Input, output, review, verification, validation |
| 820.40 | Document Controls | ISO 13485 §4.2.4 | Approval, distribution, change control |
| 820.50 | Purchasing Controls | ISO 13485 §7.4 | Supplier qualification, purchasing data |
| 820.70 | Production Controls | ISO 13485 §6.3, 6.4, 7.5 | Process validation, environmental controls |
| 820.100 | CAPA | ISO 13485 §8.5.2, 8.5.3 | Root cause analysis, corrective actions |
| 820.181 | Device Master Record | ISO 13485 §4.2.3 (medical device file) + 21 CFR 820.35 | Specifications, procedures, acceptance criteria |
Design Controls Workflow (ISO 13485 §7.3; legacy QSR 820.30)
Step 1: Design Input
└── Capture user needs, intended use, regulatory requirements
Verification: Inputs reviewed and approved?
Step 2: Design Output
└── Create specifications, drawings, software architecture
Verification: Outputs traceable to inputs?
Step 3: Design Review
└── Conduct reviews at each phase milestone
Verification: Review records with signatures?
Step 4: Design Verification
└── Perform testing against specifications
Verification: All tests pass acceptance criteria?
Step 5: Design Validation
└── Confirm device meets user needs in actual use conditions
Verification: Validation report approved?
Step 6: Design Transfer
└── Release to production with DMR complete
Verification: Transfer checklist complete?
CAPA Process (ISO 13485 §8.5.2/8.5.3; legacy QSR 820.100)
- Identify: Document nonconformity or potential problem
- Investigate: Perform root cause analysis (5 Whys, Fishbone)
- Plan: Define corrective/preventive actions
- Implement: Execute actions, update documentation
- Verify: Confirm implementation complete
- Effectiveness: Monitor for recurrence (30-90 days)
- Close: Management approval and closure
Reference: See qsr_compliance_requirements.md for the historical QSR structure with full QMSR/ISO 13485:2016 clause mapping.
HIPAA for Medical Devices
HIPAA requirements for devices that create, store, transmit, or access Protected Health Information (PHI).
Applicability
| Device Type | HIPAA Applies |
|---|---|
| Standalone diagnostic (no data transmission) | No |
| Connected device transmitting patient data | Yes |
| Device with EHR integration | Yes |
| SaMD storing patient information | Yes |
| Wellness app (no diagnosis) | Only if stores PHI |
Required Safeguards
Administrative (§164.308)
├── Security officer designation
├── Risk analysis and management
├── Workforce training
├── Incident response procedures
└── Business associate agreements
Physical (§164.310)
├── Facility access controls
├── Workstation security
└── Device disposal procedures
Technical (§164.312)
├── Access control (unique IDs, auto-logoff)
├── Audit controls (logging)
├── Integrity controls (checksums, hashes)
├── Authentication (MFA recommended)
└── Transmission security (TLS 1.2+)
Risk Assessment Steps
- Inventory all systems handling ePHI
- Document data flows (collection, storage, transmission)
- Identify threats and vulnerabilities
- Assess likelihood and impact
- Determine risk levels
- Implement controls
- Document residual risk
Reference: See hipaa_compliance_framework.md for implementation checklists and BAA templates.
Device Cybersecurity
FDA cybersecurity requirements for connected medical devices.
Premarket Requirements
| Element | Description |
|---|---|
| Threat Model | STRIDE analysis, attack trees, trust boundaries |
| Security Controls | Authentication, encryption, access control |
| SBOM | Software Bill of Materials (CycloneDX or SPDX) |
| Security Testing | Penetration testing, vulnerability scanning |
| Vulnerability Plan | Disclosure process, patch management |
Device Tier Classification
Tier 1 (Higher Risk):
- Connects to network/internet
- Cybersecurity incident could cause patient harm
Tier 2 (Standard Risk):
- All other connected devices
Postmarket Obligations
- Monitor NVD and ICS-CERT for vulnerabilities
- Assess applicability to device components
- Develop and test patches
- Communicate with customers
- Report to FDA per guidance
Coordinated Vulnerability Disclosure
Researcher Report
↓
Acknowledgment (48 hours)
↓
Initial Assessment (5 days)
↓
Fix Development
↓
Coordinated Public Disclosure
Reference: See device_cybersecurity_guidance.md for SBOM format examples and threat modeling templates.
Resources
scripts/
| Script | Purpose |
|---|---|
fda_submission_tracker.py |
Track 510(k)/PMA/De Novo submission milestones and timelines |
qsr_compliance_checker.py |
Assess QMS documentation against the legacy-QSR checklist mapped to ISO 13485:2016 (QMSR) |
hipaa_risk_assessment.py |
Evaluate HIPAA safeguards in medical device software |
references/
| File | Content |
|---|---|
fda_submission_guide.md |
510(k), De Novo, PMA submission requirements and checklists |
qsr_compliance_requirements.md |
Historical QSR structure with QMSR/ISO 13485:2016 mapping, implementation templates |
hipaa_compliance_framework.md |
HIPAA Security Rule safeguards and BAA requirements |
device_cybersecurity_guidance.md |
FDA cybersecurity requirements, SBOM, threat modeling |
fda_capa_requirements.md |
CAPA process, root cause analysis, effectiveness verification |
Usage Examples
# Track FDA submission status
python scripts/fda_submission_tracker.py /path/to/project --type 510k
# Assess QMS documentation (legacy QSR section keys, mapped to ISO 13485 under QMSR)
python scripts/qsr_compliance_checker.py /path/to/project --section 820.30 # legacy checklist key = ISO 13485 §7.3 (design & development)
# Run HIPAA risk assessment
python scripts/hipaa_risk_assessment.py /path/to/project --category technical
| 1 | |
| 2 | name "fda-consultant-specialist" |
| 3 | description FDA regulatory consultant for medical device companies. Provides 510(k)/PMA/De Novo pathway guidance, QMSR (21 CFR 820, which incorporates ISO 13485:2016 by reference since 2026-02-02; formerly QSR) compliance, HIPAA assessments, and device cybersecurity. Use when user mentions FDA submission, 510(k), PMA, De Novo, QMSR, QSR, ISO 13485 for FDA, premarket, predicate device, substantial equivalence, HIPAA medical device, or FDA cybersecurity. |
| 4 | |
| 5 | |
| 6 | # FDA Consultant Specialist |
| 7 | |
| 8 | FDA regulatory consulting for medical device manufacturers covering submission pathways, the Quality Management System Regulation (QMSR, 21 CFR Part 820 — formerly the QSR), HIPAA compliance, and device cybersecurity requirements. |
| 9 | |
| 10 | ## Table of Contents |
| 11 | |
| 12 | [FDA Pathway Selection] |
| 13 | [510(k) Submission Process] |
| 14 | [QMSR Compliance (formerly QSR)] |
| 15 | [HIPAA for Medical Devices] |
| 16 | [Device Cybersecurity] |
| 17 | [Resources] |
| 18 | |
| 19 | |
| 20 | |
| 21 | ## FDA Pathway Selection |
| 22 | |
| 23 | Determine the appropriate FDA regulatory pathway based on device classification and predicate availability. |
| 24 | |
| 25 | ### Decision Framework |
| 26 | |
| 27 | |
| 28 | Predicate device exists? |
| 29 | ├── YES → Substantially equivalent? |
| 30 | │ ├── YES → 510(k) Pathway |
| 31 | │ │ ├── No design changes → Abbreviated 510(k) |
| 32 | │ │ ├── Manufacturing only → Special 510(k) |
| 33 | │ │ └── Design/performance → Traditional 510(k) |
| 34 | │ └── NO → PMA or De Novo |
| 35 | └── NO → Novel device? |
| 36 | ├── Low-to-moderate risk → De Novo |
| 37 | └── High risk (Class III) → PMA |
| 38 | |
| 39 | |
| 40 | ### Pathway Comparison |
| 41 | |
| 42 | | Pathway | When to Use | Timeline | User Fee (FY2024) | |
| 43 | |---------|-------------|----------|-------------------| |
| 44 | | 510(k) Traditional | Predicate exists, design changes | 90 days | $21,760 (FY2024) | |
| 45 | | 510(k) Special | Manufacturing changes only | 30 days | $21,760 (FY2024) | |
| 46 | | 510(k) Abbreviated | Guidance/standard conformance | 30 days | $21,760 (FY2024) | |
| 47 | | De Novo | Novel, low-moderate risk | 150 days | $134,676 (FY2024) | |
| 48 | | PMA | Class III, no predicate | 180+ days | $425,000+ (FY2024) | |
| 49 | |
| 50 | > User fees are set annually under MDUFA. Verify current-fiscal-year fees at fda.gov (MDUFA user fee schedule) before budgeting; small-business rates differ. |
| 51 | |
| 52 | ### Pre-Submission Strategy |
| 53 | |
| 54 | Identify product code and classification |
| 55 | Search 510(k) database for predicates |
| 56 | Assess substantial equivalence feasibility |
| 57 | Prepare Q-Sub questions for FDA |
| 58 | Schedule Pre-Sub meeting if needed |
| 59 | |
| 60 | **Reference:** See [fda_submission_guide.md] for pathway decision matrices and submission requirements. |
| 61 | |
| 62 | |
| 63 | |
| 64 | ## 510(k) Submission Process |
| 65 | |
| 66 | ### Workflow |
| 67 | |
| 68 | |
| 69 | Phase 1: Planning |
| 70 | ├── Step 1: Identify predicate device(s) |
| 71 | ├── Step 2: Compare intended use and technology |
| 72 | ├── Step 3: Determine testing requirements |
| 73 | └── Checkpoint: SE argument feasible? |
| 74 | |
| 75 | Phase 2: Preparation |
| 76 | ├── Step 4: Complete performance testing |
| 77 | ├── Step 5: Prepare device description |
| 78 | ├── Step 6: Document SE comparison |
| 79 | ├── Step 7: Finalize labeling |
| 80 | └── Checkpoint: All required sections complete? |
| 81 | |
| 82 | Phase 3: Submission |
| 83 | ├── Step 8: Assemble submission package |
| 84 | ├── Step 9: Submit via eSTAR |
| 85 | ├── Step 10: Track acknowledgment |
| 86 | └── Checkpoint: Submission accepted? |
| 87 | |
| 88 | Phase 4: Review |
| 89 | ├── Step 11: Monitor review status |
| 90 | ├── Step 12: Respond to AI requests |
| 91 | ├── Step 13: Receive decision |
| 92 | └── Verification: SE letter received? |
| 93 | |
| 94 | |
| 95 | ### Required Sections (21 CFR 807.87) |
| 96 | |
| 97 | | Section | Content | |
| 98 | |---------|---------| |
| 99 | | Cover Letter | Submission type, device ID, contact info | |
| 100 | | Form 3514 | CDRH premarket review cover sheet | |
| 101 | | Device Description | Physical description, principles of operation | |
| 102 | | Indications for Use | Form 3881, patient population, use environment | |
| 103 | | SE Comparison | Side-by-side comparison with predicate | |
| 104 | | Performance Testing | Bench, biocompatibility, electrical safety | |
| 105 | | Software Documentation | Level of concern, hazard analysis (IEC 62304) | |
| 106 | | Labeling | IFU, package labels, warnings | |
| 107 | | 510(k) Summary | Public summary of submission | |
| 108 | |
| 109 | ### Common RTA Issues |
| 110 | |
| 111 | | Issue | Prevention | |
| 112 | |-------|------------| |
| 113 | | Missing user fee | Verify payment before submission | |
| 114 | | Incomplete Form 3514 | Review all fields, ensure signature | |
| 115 | | No predicate identified | Confirm K-number in FDA database | |
| 116 | | Inadequate SE comparison | Address all technological characteristics | |
| 117 | |
| 118 | |
| 119 | |
| 120 | ## QMSR Compliance (formerly QSR) |
| 121 | |
| 122 | Quality Management System Regulation (QMSR) requirements for medical device manufacturers under 21 CFR Part 820. |
| 123 | |
| 124 | > **QMSR transition (effective 2026-02-02):** FDA's QMSR final rule (89 FR 7496) amended 21 CFR Part 820 to incorporate **ISO 13485:2016 by reference** and removed the legacy QSR subsection structure (820.20–820.198). Those subsection numbers are **historical** and no longer exist in the CFR; the corresponding requirements now flow from ISO 13485:2016 clauses plus the retained/renumbered sections 820.10 (requirements, incl. the ISO 13485 incorporation), 820.35 (records), and 820.45 (device labeling and packaging controls). 21 CFR Parts 801, 803, 806, and 830 are unchanged. Legacy QSR numbers below are kept only as a familiar index, each mapped to its current ISO 13485 clause. |
| 125 | |
| 126 | ### Key Quality Subsystems (legacy QSR index → current ISO 13485:2016 clause) |
| 127 | |
| 128 | | Legacy QSR Section (historical, pre-2026) | Title | Current authority under QMSR | Focus | |
| 129 | |-------------------------------------------|-------|------------------------------|-------| |
| 130 | | 820.20 | Management Responsibility | ISO 13485 §5.1, 5.5, 5.6 | Quality policy, org structure, management review | |
| 131 | | 820.30 | Design Controls | ISO 13485 §7.3 | Input, output, review, verification, validation | |
| 132 | | 820.40 | Document Controls | ISO 13485 §4.2.4 | Approval, distribution, change control | |
| 133 | | 820.50 | Purchasing Controls | ISO 13485 §7.4 | Supplier qualification, purchasing data | |
| 134 | | 820.70 | Production Controls | ISO 13485 §6.3, 6.4, 7.5 | Process validation, environmental controls | |
| 135 | | 820.100 | CAPA | ISO 13485 §8.5.2, 8.5.3 | Root cause analysis, corrective actions | |
| 136 | | 820.181 | Device Master Record | ISO 13485 §4.2.3 (medical device file) + 21 CFR 820.35 | Specifications, procedures, acceptance criteria | |
| 137 | |
| 138 | ### Design Controls Workflow (ISO 13485 §7.3; legacy QSR 820.30) |
| 139 | |
| 140 | |
| 141 | Step 1: Design Input |
| 142 | └── Capture user needs, intended use, regulatory requirements |
| 143 | Verification: Inputs reviewed and approved? |
| 144 | |
| 145 | Step 2: Design Output |
| 146 | └── Create specifications, drawings, software architecture |
| 147 | Verification: Outputs traceable to inputs? |
| 148 | |
| 149 | Step 3: Design Review |
| 150 | └── Conduct reviews at each phase milestone |
| 151 | Verification: Review records with signatures? |
| 152 | |
| 153 | Step 4: Design Verification |
| 154 | └── Perform testing against specifications |
| 155 | Verification: All tests pass acceptance criteria? |
| 156 | |
| 157 | Step 5: Design Validation |
| 158 | └── Confirm device meets user needs in actual use conditions |
| 159 | Verification: Validation report approved? |
| 160 | |
| 161 | Step 6: Design Transfer |
| 162 | └── Release to production with DMR complete |
| 163 | Verification: Transfer checklist complete? |
| 164 | |
| 165 | |
| 166 | ### CAPA Process (ISO 13485 §8.5.2/8.5.3; legacy QSR 820.100) |
| 167 | |
| 168 | **Identify**: Document nonconformity or potential problem |
| 169 | **Investigate**: Perform root cause analysis (5 Whys, Fishbone) |
| 170 | **Plan**: Define corrective/preventive actions |
| 171 | **Implement**: Execute actions, update documentation |
| 172 | **Verify**: Confirm implementation complete |
| 173 | **Effectiveness**: Monitor for recurrence (30-90 days) |
| 174 | **Close**: Management approval and closure |
| 175 | |
| 176 | **Reference:** See [qsr_compliance_requirements.md] for the historical QSR structure with full QMSR/ISO 13485:2016 clause mapping. |
| 177 | |
| 178 | |
| 179 | |
| 180 | ## HIPAA for Medical Devices |
| 181 | |
| 182 | HIPAA requirements for devices that create, store, transmit, or access Protected Health Information (PHI). |
| 183 | |
| 184 | ### Applicability |
| 185 | |
| 186 | | Device Type | HIPAA Applies | |
| 187 | |-------------|---------------| |
| 188 | | Standalone diagnostic (no data transmission) | No | |
| 189 | | Connected device transmitting patient data | Yes | |
| 190 | | Device with EHR integration | Yes | |
| 191 | | SaMD storing patient information | Yes | |
| 192 | | Wellness app (no diagnosis) | Only if stores PHI | |
| 193 | |
| 194 | ### Required Safeguards |
| 195 | |
| 196 | |
| 197 | Administrative (§164.308) |
| 198 | ├── Security officer designation |
| 199 | ├── Risk analysis and management |
| 200 | ├── Workforce training |
| 201 | ├── Incident response procedures |
| 202 | └── Business associate agreements |
| 203 | |
| 204 | Physical (§164.310) |
| 205 | ├── Facility access controls |
| 206 | ├── Workstation security |
| 207 | └── Device disposal procedures |
| 208 | |
| 209 | Technical (§164.312) |
| 210 | ├── Access control (unique IDs, auto-logoff) |
| 211 | ├── Audit controls (logging) |
| 212 | ├── Integrity controls (checksums, hashes) |
| 213 | ├── Authentication (MFA recommended) |
| 214 | └── Transmission security (TLS 1.2+) |
| 215 | |
| 216 | |
| 217 | ### Risk Assessment Steps |
| 218 | |
| 219 | Inventory all systems handling ePHI |
| 220 | Document data flows (collection, storage, transmission) |
| 221 | Identify threats and vulnerabilities |
| 222 | Assess likelihood and impact |
| 223 | Determine risk levels |
| 224 | Implement controls |
| 225 | Document residual risk |
| 226 | |
| 227 | **Reference:** See [hipaa_compliance_framework.md] for implementation checklists and BAA templates. |
| 228 | |
| 229 | |
| 230 | |
| 231 | ## Device Cybersecurity |
| 232 | |
| 233 | FDA cybersecurity requirements for connected medical devices. |
| 234 | |
| 235 | ### Premarket Requirements |
| 236 | |
| 237 | | Element | Description | |
| 238 | |---------|-------------| |
| 239 | | Threat Model | STRIDE analysis, attack trees, trust boundaries | |
| 240 | | Security Controls | Authentication, encryption, access control | |
| 241 | | SBOM | Software Bill of Materials (CycloneDX or SPDX) | |
| 242 | | Security Testing | Penetration testing, vulnerability scanning | |
| 243 | | Vulnerability Plan | Disclosure process, patch management | |
| 244 | |
| 245 | ### Device Tier Classification |
| 246 | |
| 247 | **Tier 1 (Higher Risk):** |
| 248 | Connects to network/internet |
| 249 | Cybersecurity incident could cause patient harm |
| 250 | |
| 251 | **Tier 2 (Standard Risk):** |
| 252 | All other connected devices |
| 253 | |
| 254 | ### Postmarket Obligations |
| 255 | |
| 256 | Monitor NVD and ICS-CERT for vulnerabilities |
| 257 | Assess applicability to device components |
| 258 | Develop and test patches |
| 259 | Communicate with customers |
| 260 | Report to FDA per guidance |
| 261 | |
| 262 | ### Coordinated Vulnerability Disclosure |
| 263 | |
| 264 | |
| 265 | Researcher Report |
| 266 | ↓ |
| 267 | Acknowledgment (48 hours) |
| 268 | ↓ |
| 269 | Initial Assessment (5 days) |
| 270 | ↓ |
| 271 | Fix Development |
| 272 | ↓ |
| 273 | Coordinated Public Disclosure |
| 274 | |
| 275 | |
| 276 | **Reference:** See [device_cybersecurity_guidance.md] for SBOM format examples and threat modeling templates. |
| 277 | |
| 278 | |
| 279 | |
| 280 | ## Resources |
| 281 | |
| 282 | ### scripts/ |
| 283 | |
| 284 | | Script | Purpose | |
| 285 | |--------|---------| |
| 286 | | `fda_submission_tracker.py` | Track 510(k)/PMA/De Novo submission milestones and timelines | |
| 287 | | `qsr_compliance_checker.py` | Assess QMS documentation against the legacy-QSR checklist mapped to ISO 13485:2016 (QMSR) | |
| 288 | | `hipaa_risk_assessment.py` | Evaluate HIPAA safeguards in medical device software | |
| 289 | |
| 290 | ### references/ |
| 291 | |
| 292 | | File | Content | |
| 293 | |------|---------| |
| 294 | | `fda_submission_guide.md` | 510(k), De Novo, PMA submission requirements and checklists | |
| 295 | | `qsr_compliance_requirements.md` | Historical QSR structure with QMSR/ISO 13485:2016 mapping, implementation templates | |
| 296 | | `hipaa_compliance_framework.md` | HIPAA Security Rule safeguards and BAA requirements | |
| 297 | | `device_cybersecurity_guidance.md` | FDA cybersecurity requirements, SBOM, threat modeling | |
| 298 | | `fda_capa_requirements.md` | CAPA process, root cause analysis, effectiveness verification | |
| 299 | |
| 300 | ### Usage Examples |
| 301 | |
| 302 | |
| 303 | # Track FDA submission status |
| 304 | python scripts/fda_submission_tracker.py /path/to/project --type 510k |
| 305 | |
| 306 | # Assess QMS documentation (legacy QSR section keys, mapped to ISO 13485 under QMSR) |
| 307 | python scripts/qsr_compliance_checker.py /path/to/project --section 820.30 # legacy checklist key = ISO 13485 §7.3 (design & development) |
| 308 | |
| 309 | # Run HIPAA risk assessment |
| 310 | python scripts/hipaa_risk_assessment.py /path/to/project --category technical |
| 311 | |
| 312 |
Discussion
Browse more free Claude skills or everything in Legal & compliance.