Clinical Decision Software Guide Expands Oversight: Attorneys

Share

A new final guidance on Clinical Decision Support (CDS) Software appears to be “more expansive in scope” than an earlier draft version, and many software products previously not regulated by FDA may now be subject to agency oversight, according to a legal analysis by attorneys at the law firm DLA Piper. “The final guidance elaborates on FDA’s interpretation of the statutory guidelines set out in the 2016 21st Century Cures Act (Cures Act), adds new definitions and, most importantly, provides several new examples that inform software developers on how to navigate the complex regulatory framework surrounding CDS,” they write. But it departs from familiar concepts like International Medical Device Regulators Form (IMDRF) risk levels discussed in the earlier draft and moves to new concepts like “automation bias” that “shift the analysis,” the attorneys complain.

Under the Federal Food, Drug, and Cosmetic Act (FD&C Act), Section 520(o)(1)(E) carves out CDS software from the definition of medical device if the software functions meet four criteria, the attorneys say. They are troubled by the final guidance’s removal of the IMDRF risk categorization and the risk-based enforcement discretion policy. “Instead, the final guidance establishes a more binary system: (i) Non-Device CDS and (ii) Device CDS,” they say. “The final guidance focuses less on risk and more on elaborating on the agency’s interpretation of the four exclusion criterion from the statute.”

Additionally, the attorneys complain that the final guidance provides “extensive labeling or transparency recommendations to software developers, which must inform the recipient HCP [health care provider] of the basis for the recommendation in order to prevent such HCP from relying primarily on the data output,” and thus rely on their own clinical judgment when making patient care decisions, they say. “These labeling and disclosure requirements are extensive and, by their nature, effectively prohibit a HCP from using the data output in time sensitive or time-critical situations because such situations would have an insufficient amount of time to allow for the HCP to independently review the full basis of the recommendations presented by the software. These requirements seem to require transparency in both the reasoning behind the recommendations and the process of training and validating software, placing a clear and enhanced onus on HCPs to become AI [artificial intelligence] literate and stand as learned intermediaries for software as well as more traditional interventions.”

Read more