MedDeviceGuideMedDeviceGuide
Topic

Risk Management

24 articles

Cybersecurity

Medical Device Cybersecurity Patch Management: Regulated Update Deployment Under EU MDR, FDA Section 524B, and the Cyber Resilience Act (2026)

How to deploy cybersecurity patches to fielded medical devices while maintaining MDR conformity, FDA Section 524B postmarket obligations, and Cyber Resilience Act vulnerability handling timelines — covering risk-based triage, change control classification, coordinated disclosure integration with PSIRT, and the operational QMS workflow from vulnerability detection to verified field deployment.

Design Controls

Auto-Injector Critical-Task Matrix for Human Factors Validation: How to Identify, Document, and Test Every Safety-Critical Use Step

Practical guide to building the critical-task matrix for auto-injector and pen-injector human factors validation — task identification from URRA, needle shield removal, site selection, dose confirmation, hold time, misfire recovery, training decay, disposal, use-error root cause analysis, and FDA/IEC 62366 evidence expectations.

EU MDR / IVDR

EU AI Act + MDR Single Evidence Matrix: How to Build One Combined Technical File Without Duplicating Work

A field-by-field evidence matrix mapping MDR Annex II/III technical documentation, ISO 14971 risk management, PMS/PMCF, cybersecurity, data governance, human oversight, and QMS records to EU AI Act high-risk obligations — for manufacturers who must comply with both frameworks simultaneously.

Cybersecurity

FDA Cybersecurity Unresolved Anomalies Table: How to Document Vulnerabilities and Residual Risk in Premarketing Submissions

How to build the Unresolved Software Anomalies table for FDA premarket cybersecurity submissions — CVSS scoring, exploitability assessment, clinical impact analysis, compensating controls, SBOM linkage, VEX status, labeling language, release criteria, and common reviewer objections.

Post-Market Surveillance

GB PMSR/PSUR Dual-Report Architecture: How to Structure Post-Market Surveillance Reports for Devices Sold in Both EU and Great Britain

Step-by-step guide to building a dual PMSR/PSUR reporting architecture that satisfies both EU MDR/IVDR and Great Britain SI 2024/1368 requirements — data-period alignment, GB-specific content, MHRA standardized format, FSCA linkage, trend reporting, record retention, and responsible-owner mapping.

EU MDR / IVDR

MDR Article 88 Trend Reporting: How to Set Statistical Thresholds, Detect Adverse Trends, and Build a Defensible Reporting Workflow

A practical guide to implementing MDR Article 88 trend reporting — covering denominator selection, expected frequency calculation, statistical significance testing, severity escalation, complaint coding, CAPA linkage, PSUR/PMSR integration, and the MDCG 2025 draft Q&A requirements.

Digital Health & AI

PCCP Drift Monitoring Protocol for AI Imaging Devices: Dataset Shift Detection, Performance Thresholds, and Retraining Triggers

How to design and implement a drift monitoring protocol for AI-enabled imaging devices under FDA PCCP — dataset shift, scanner drift, demographic drift, performance thresholds, monitoring cadence, retraining triggers, labeling changes, and when FDA submission is still required.

Cybersecurity

FDA Cybersecurity Premarket Submission Deficiencies: 12 Common Rejection Reasons and How to Fix Them (2026)

Practical guide to the top 12 FDA cybersecurity deficiencies causing premarket submission holds in 2026 — SBOM gaps, threat modeling failures, risk assessment mistakes, and fixes aligned with the February 2026 final guidance and Section 524B.

Standards & Testing

Nanotechnology in Medical Devices: Regulatory Classification, Biocompatibility, Sterilization, and Risk Assessment

Regulatory and risk assessment guide for medical devices incorporating nanomaterials — covering EU MDR Rule 19 classification, FDA nanotechnology guidance, ISO 10993-22 biocompatibility, SCENIHR exposure framework, nanotoxicology testing, sterilization challenges, labeling requirements, and a decision tree for regulatory strategy.

Risk Management

Benefit-Risk Analysis for Medical Devices: FDA, EU MDR, and ISO 14971 Decision Framework

Complete guide to benefit-risk analysis for medical devices — ISO 14971:2019 residual risk evaluation, EU MDR AFAP requirements, FDA benefit-risk factors for PMA/De Novo/510(k), MDCG guidance, practical examples, and documentation best practices.

Risk Management

Fault Tree Analysis (FTA) for Medical Device Risk Management: When to Use It Instead of FMEA

How to perform Fault Tree Analysis under ISO 14971 for medical devices — FTA vs FMEA comparison, AND/OR gate logic, quantitative probability calculations, real-world examples, and when top-down analysis outperforms bottom-up methods.

Risk Management

Hazard Analysis Methods for Medical Devices: FMEA vs FTA vs PHA vs Use-Related Risk Analysis

Complete comparison of hazard analysis methods for medical device risk management — when to use FMEA, FTA, PHA, HAZOP, and use-related risk analysis under ISO 14971, IEC 62366, FDA, and EU MDR requirements, with examples and decision guidance.

Risk Management

ISO/TR 24971 for Medical Devices: Practical Guidance for Applying ISO 14971

Comprehensive guide to ISO/TR 24971:2020, the companion technical report to ISO 14971:2019 — how to use its annexes for hazard identification, risk analysis methods, benefit-risk analysis, cybersecurity, IVDs, and practical implementation across your risk management process.

Risk Management

Risk Management File vs Risk Management Report: ISO 14971 Documentation Explained

Clear guide to the differences between a risk management file and risk management report under ISO 14971:2019 — what each contains, how they relate, traceability requirements, and common audit findings from notified bodies and FDA.

Digital Health & AI

SOUP (Software of Unknown Provenance): IEC 62304 Compliance Guide for Medical Device Manufacturers

The complete guide to managing Software of Unknown Provenance (SOUP) under IEC 62304 — identification, risk assessment, safety classification, documentation requirements, open-source management, and post-market surveillance strategies.

Standards & Testing

IEC 62133 Battery Safety for Medical Devices: Testing, Compliance & Regulatory Requirements

A complete guide to IEC 62133 battery safety compliance for medical devices — test requirements, regulatory pathways (FDA, EU MDR), UN 38.3 transport, Battery Management Systems, risk management, and practical steps for global market access.

EU MDR / IVDR

EU MDR Classification Rules (Annex VIII): Complete Guide to All 22 Rules with 2026 Updates

Deep walkthrough of all 22 EU MDR classification rules in Annex VIII — non-invasive, invasive, active, and special rules — with MDD-to-MDR changes, software and nanomaterial up-classification, MDCG 2021-24 guidance, and practical strategies for correct device classification.

EU MDR / IVDR

EU MDR GSPR (Annex I) General Safety and Performance Requirements: Complete Walkthrough and Compliance Guide

How to demonstrate compliance with all 23 General Safety and Performance Requirements (GSPR) under EU MDR Annex I — chapter-by-chapter walkthrough, GSPR checklist template, harmonised standards mapping, cybersecurity and AI updates for 2026, and practical strategies for Notified Body submissions.

Standards & Testing

IEC 60601-1-2 EMC Testing for Medical Devices: The Complete Guide to Electromagnetic Compatibility

A comprehensive guide to IEC 60601-1-2 EMC compliance for medical electrical equipment — emissions and immunity requirements, Edition 4.1 changes, risk management integration, test plans, environment classification, and regulatory submission.

Standards & Testing

ISO 14155:2026 Clinical Investigation of Medical Devices — Complete GCP Guide

A comprehensive guide to ISO 14155:2026 for medical device clinical investigations — the 4th edition's risk management integration, Clinical Events Committees, estimand framework, sponsor and investigator responsibilities, adverse event reporting, and post-market study requirements.