Regulated Mobile Applications



Similar documents
FDA Issues Final Guidance on Mobile Medical Apps

Mobile Medical Application Development: FDA Regulation

Regulatory Considerations for Medical Device Software. Medical Device Software

WHITEPAPER: SOFTWARE APPS AS MEDICAL DEVICES THE REGULATORY LANDSCAPE

The U.S. FDA s Regulation and Oversight of Mobile Medical Applications

What is the correct title of this publication? What is the current status of understanding and implementation?

Medical Software Development. International standards requirements and practice

Kofax White Paper. Mobile Technology for Advanced AP Automation. Executive Summary

Medical Device Software Do You Understand How Software is Regulated?

INTRODUCTION. This book offers a systematic, ten-step approach, from the decision to validate to

An introduction to the regulation of apps and wearables as medical devices

Mobile Medical Applications: FDA s Final Guidance. M. Elizabeth Bierman Anthony T. Pavel Morgan, Lewis & Bockius, LLP

GAMP 4 to GAMP 5 Summary

Developing a Mobile Medical App? How to determine if it is a medical device and get it cleared by the US FDA

How To Know If A Mobile App Is A Medical Device

This interpretation of the revised Annex

Notifications for Time and Attendance

Monitoring manufacturing, production and storage environments in the pharmaceutical industry

Mobile Medical Apps. Purpose. Diane Romza Kutz Fredric E. Roth V. Regulation and Risks. Purpose of today s presentation

Mobile application testing is a process by which application software developed for hand held mobile devices is tested for its functionality,

COMMISSION STAFF WORKING DOCUMENT. on the existing EU legal framework applicable to lifestyle and wellbeing apps. Accompanying the document

Regulatory Asset Management: Harmonizing Calibration, Maintenance & Validation Systems

The Shifting Sands of Medical Software Regulation

Mobile App Testing Process INFLECTICA TECHNOLOGIES (P) LTD

Considerations for using the Web for Medical Device Applications

CDRH Regulated Software

White Paper Bridging the Essential Gap between Continuous Quality and Crowd Based Testing

GE Healthcare Life Sciences. Validation Services. Compliance support through life cycle management

Medical Device Software Standards for Safety and Regulatory Compliance

White Paper. Bridging the essential gap between Mobile Cloud and crowd based testing. 1. Introduction. 2. Testing Lifecycle

Microsoft Dynamics NAV 2015 What s new?

From Traditional Functional Testing to Enabling Continuous Quality in Mobile App Development

Medical Product Software Development and FDA Regulations Software Development Practices and FDA Compliance

FDA Regulation of Whole Slide Imaging (WSI) Devices: Current Thoughts

Regulation of Medical Apps FDA and European Union

Norton Mobile Privacy Notice

Reduce Trial Costs While Increasing Study Speed and Data Quality with Oracle Siebel CTMS Cloud Service

Monitoring the autoclaving process in the pharmaceutical industry

Re: Docket No. FDA 2014 N 0339: Proposed Risk-Based Regulatory Framework and Strategy for Health Information Technology Report; Request for Comments

Breakout Sessions: FDA s Regulation of Mobile Health and Medical Applications

Integrated Multi-Client Platform for Smart Meters

ASHVINS Group. Mobile Application Testing Summary

Sending images from a camera to an iphone. PowerShot G1X MarkII, PowerShot SX600 HS, PowerShot N100, PowerShot SX700 HS, PowerShot ELPH 340 HS

Welcome. Panel. Cloud Computing New Challenges in Data Integrity and Security 13 November 2014

QUESTIONS FOR YOUR SOFTWARE VENDOR: TO ASK BEFORE YOUR AUDIT

Medical Device Software

Marathon Information Management Program

SMART CRM Desk for Service Sector. Solution for Customer Relationship Mgmt (CRM) in Service Industry

Medical Equipment Management. Medical Equipment Management Activities (EC and EC )

Regulation of Mobile Medical Apps

Mobile App Testing Guide. Basics of Mobile App Testing

Use of Mobile Medical Applications in Clinical Research

JOURNAL OF MEDICAL INFORMATICS & TECHNOLOGIES Vol. 21/2012, ISSN

Mobile Medical Applications

Rethinking the FDA s Regulation of. By Scott D. Danzis and Christopher Pruitt

GAMP5 - a lifecycle management framework for customized bioprocess solutions

msupply Pharmaceutical Supply Chain Software October 2013

Presented by Rosemarie Bell 24 April 2014

HOW SMART DEVICES AND MIDDLEWARE INTEGRATION ARE REVOLUTIONIZING HEALTHCARE

Software as a Medical Device. A Provider View from Canada

Welcome Computer System Validation Training Delivered to FDA. ISPE Boston Area Chapter February 20, 2014

Computer System Configuration Management and Change Control

Validation Consultant

Clinical Intervention Definitions

Healthcare Delivery. Transforming. through Mobility Solutions. A Solution White Paper - version 1.0

Using SharePoint 2013 for Managing Regulated Content in the Life Sciences. Presented by Paul Fenton President and CEO, Montrium

ComplianceSP TM on SharePoint. Complete Document & Process Management for Life Sciences on SharePoint 2010 & 2013

KPMG Advisory. Microsoft Dynamics CRM. Advisory, Design & Delivery Services. A KPMG Service for G-Cloud V. April 2014

Perspectives on the FDASIA Health IT Report and Public Workshop

Validation Best Practice for a SaaS

Sending images from a camera to an Android smartphone

The CIO s Guide to HIPAA Compliant Text Messaging

Medical Equipment Management. Medical Equipment Management Activities (EC and EC )

Digital Marketplace - G-Cloud

GSK Vaccines: Easing Compliance with SAP Process Control

Information Shield Solution Matrix for CIP Security Standards

GAMP 5 and the Supplier Leveraging supplier advantage out of compliance

Automated testing for Mobility New age applications require New age Mobility solutions

How To Use The Elena Mobile App

PKI Adoption Case Study (for the OASIS PKIA TC) ClinPhone Complies with FDA Regulations Using PKIbased Digital Signatures

Ariett Purchasing & Expense Management. Go Paperless, Go Mobile, Go Easy.

COTS Validation Post FDA & Other Regulations

e-health Initiative Lina Abou Mrad MBA, PMP Director, National E-Health Program Health Insight 4 -March 2014

Two-Factor Authentication over Mobile: Simplifying Security and Authentication

For more information, contact Joe Lewelling, AAMI's VP of Standards Development & Emerging Technologies, at jlewelling@aami.org.

Quick Start Guide. Version R9. English

Transcription:

Regulated Mobile Applications Sion Wyn Conformity +[44] (0) 1492 642622 sion.wyn@conform-it.com Waters, Wilmslow, November 2014 1 Introduction According to industry estimates, 500 million smartphone users worldwide will be using a health care application by 2015, and by 2018, 50 percent of the more than 3.4 billion smartphone and tablet users will have downloaded mobile health applications. These users include health care professionals, consumers, and patients. US FDA 2 1

Overview What do we mean by regulated mobile applications? What are the risks and regulatory expectations? How can we leverage GAMP good practice principles? 3 Example Uses To improve patient compliance to a medical regimen As a marketing tool Aid to diagnosis As a channel for patient reporting As an interface to a medical device To control a medical device 4 2

Opportunities A smartphone app that uses a phone's camera to analyse urine Can tested for the presence of 10 elements - including glucose, proteins and nitrites Tests for 25 different health issues could help diagnose and treat diseases in the developing world. 5 Risks Apps may delay skin cancer diagnosis using phones rather than seeking expert help could be harmful The University of Pittsburgh tested four applications with 188 pictures of cancers and other skin conditions. Three of the apps using automated algorithms wrongly labelled the cancerous lesions as unproblematic in almost a third of cases. 6 3

Mobile Medical Apps Mobile medical apps are medical devices that are mobile apps, meet the definition of a medical device and are an accessory to a regulated medical device or transform a mobile platform into a regulated medical device. US FDA 7 Part of a GxP System Components of a GxP regulated computerized system: Interface for warehouse management, including goods receipt or movement Dashboard interface to a number of laboratory systems Interface to manufacturing equipment, with the ability to adjust set-points Access to enterprise applications such as ERP 8 4

9 FDASIA Food and Drug Administration Safety and Innovation Act (2012), required A proposed strategy and recommendations on an appropriate, risk-based regulatory framework pertaining to health information technology, including mobile medical applications, that promotes innovation, protects patient safety, and avoids regulatory duplication. 10 5

FDA Mobile Medical Applications Guidance for Industry and Food and Drug Administration Staff Document issued on: September 25, 2013 11 MEDDEV 2.1/6 MEDICAL DEVICES: Guidance document Qualification and Classification of stand alone software GUIDELINES ON THE QUALIFICATION AND CLASSIFICATION OF STAND ALONE SOFTWARE USED IN HEALTHCARE WITHIN THE REGULATORY FRAMEWORK OF MEDICAL DEVICES January 2012 12 6

Other References Regulation of medical software and mobile medical 'apps', Australian Therapeutic Goods Administration, 13 September 2013 Guidance on medical device stand-alone software (including apps), UK Medicines and Healthcare Products Regulatory Agency, 19 March 2014 Medical Information Systems guidance for qualification and classification of standalone software with a medical purpose; Swedish Medical Products Agency 13 Environment Complex, rapidly changing, and volatile Regulatory situation unclear National / regional differences Drug companies becoming software companies Software companies becoming medical device suppliers 14 7

GAMP Good Practice Guide: A Risk-Based Approach to Regulated Mobile Applications 15 Purpose Identify and explain the unique risks related to this type of application Describe solutions and controls Consider how the GAMP framework and principles may be applied 16 8

Purpose Managing software on a variety of operating systems at different version levels on many different devices Ensuring compliance with applicable regulations, including implications for data integrity and data privacy / protection Recommendations for retiring mobile apps including data retention and destruction 17 Scope How current industry good practice as described in GAMP guidance may be applied to mobile apps. Not intended to cover all detailed requirements for medical device classification, registration, development, and support. 18 9

Scope Detailed requirements for medical devices will vary from region to region, and it is the responsibility of organizations and individuals involved to identify, interpret, and apply such requirements as applicable Companies need to be familiar with the local regulations in any country where they intend to deploy a regulated mobile app. Relevant international standards such as IEC 62304 and ISO 13485 should be consulted. 19 How to Use The Guide 1. An overview of those aspects and risks specific to mobile apps, and how to address them at a high level 2. Further information on how to apply the GAMP 5 life cycle and Quality Risk Management approach to mobile apps 3. More detailed how to guidance for practitioners on specific topics 4. Case study examples 20 10

Readership Those requiring an overview of the topic should read Those seeking further information on the mobile apps life cycle, should also read Practitioners requiring detailed information on developing and supporting mobile apps should also consider Suppliers of mobile apps should read 21 What s Special about Mobile Apps? Novel and particular aspects of mobile apps that require specific consideration and action Refers to other sections within the guide that provide further guidance on these topics. 22 11

Structured Analysis Management Project Operational Technical Data Usability Platforms Communication 23 Risk Management Mobile apps may be required to run on several different platforms and operating systems, and at different version levels In most cases will not be under the control of an IT department Reliability of communications cannot be guaranteed 24 12

Risk Management Users cannot be effectively trained User behavior cannot be controlled they have the ability to refuse updates, upgrade the O/S, or download other software without the controls normally applied though formal change management Some of the users may be patients in some cases they could harm themselves by misusing an app 25 Risk Management Quality Risk Management (QRM) approach for mobile apps is described Based on GAMP 5, and aligned with ISO 14971 ISO 14971:2007 Medical devices - Application of risk management to medical devices 26 13

Life Cycle Mobile Application Product Life Cycle concept production operation and support retirement Mobile Application Data Life Cycle 27 Concept Intended use User population Initial Assessment Mobile medical app? Part of a GxP regulated system? Product Quality Plan 28 14

Is security software needed? Does the app need to synchronize? Does the app generate notifications? Does the app need to auto-update? 4G 10:52 AM Monday January 21 What happens when battery power fails? Are there dependencies on communication? Short range, Wi-Fi, or cellular? Are there audible alarms that should not be disabled? Is there a critical dependency on clock or calendar functions? Is the app always opened by the user or does it run in the background? Does the app have a special dedicated communication channel? Does the app send email? Are there specific device configuration requirements? Does the app send SMS messages (i.e. text messages)? Are there specific browser requirements? How does the user obtain the app? Production Supplier selection Prototyping and evaluation Requirements User Interface / Usability Requirements Connectivity Requirements Data Security Requirements Target Platform Requirements Testing User documentation, support, and maintenance. 30 15

Operation and Support Change Management Maintenance Problem Identification and Resolution Feedback Mechanism for users from within the Mobile App (e.g. via a form submitted to a web service, or mail-based feedback) Process to deal with that feedback 31 Support in the Market An established process for medical device reporting (for Mobile Medical Apps) An established process for medical device field action / correction (for Mobile Medical Apps) Retirement, replacement, or withdrawal of product Retention, migration, or destruction of data 32 16

Conclusions Define intended use, and identify user community Identify risks and appropriate controls Apply a managed life cycle, following GAMP principles 33 Thank You! Sion Wyn Conformity +[44] (0) 1492 642622 sion.wyn@conform-it.com 34 17