Showing posts with label Medical Software. Show all posts
Showing posts with label Medical Software. Show all posts

Thursday, May 28, 2015

HR 2396 Introduced – Medical Software

Earlier this month Rep. Blackburn (R,TN) introduced HR 2396, the Sensible Oversight for Technology which Advances Regulatory Efficiency (SOFTWARE) Act, that addresses the regulation of medical software. In many ways it is similar to her HR 3303 of last session, but there are some subtle differences.

Definitions

The bill starts off by adding a new definition to the Federal Food, Drug and Cosmetic Act (at 21 USC 321); that defines ‘health software’. It defines the term in the negative sense, explaining what it is not. In short it defines ‘health software’ as medically related software that would have no direct effect on patient health or safety.

Under the same paragraph it also defines another, somewhat odder term; ‘accessories’. This is not specifically software; it is defined as a product that {new §321ss(2)}:

Is intended for use with one or more parent devices;
Is intended to support, supplement, or augment the performance of one or more parent devices.

Software Regulation

Section 3 of the bill would add a new section to the Drugs and Devices chapter of the Federal Food, Drug, and Cosmetic Act. This section provides authority for the Secretary of Health and Human Services to regulate software. First though, it begins with a negative, prohibiting the Secretary from regulating health software.

But this prohibition does have an exception for health software that “provide patient-specific recommended options to consider in the prevention, diagnosis, treatment, cure, or mitigation of a particular disease or condition” {new §321ss(1)(F)} where the Secretary determines that the software “poses a significant risk to patient safety” {new 21 USC 361o(b)(1)(B)}.

The real difference between this bill and the one from last session lies in paragraph (c) of the new §361o that specifically provides authority for the Secretary to regulate software (other than ‘health software). It also provides authority for the Secretary to regulate software via ‘administrative order’ as long as proposed orders are first published in the Federal Register.

It also requires the Secretary to review existing regulations and guidance regarding the regulation of software and to update those regulations and guidance as necessary. In conducting the review the following areas will be reviewed {new §361o(c)(3)}:

∙ Classification of software;
∙ Standards for development of software;
∙ Standards for validation and verification of software;
∙ Review of software;
∙ Modifications to software;
∙ Manufacturing of software;
∙ Quality systems for software;
∙ Labeling requirements for software; and
∙ Post-marketing requirements for reporting of adverse events.

Moving Forward

Blackburn is a mid-ranking member of the Health Subcommittee of the House Energy and Commerce Committee. That combined with the fact that her co-sponsor {Rep. Green (D,TX)} is the Ranking Member of the Subcommittee there is a pretty good chance that this bill will be considered by the Committee.

There does not appear to be anything in the bill that would cause any serious opposition to the bill if it does make its way to the floor of the House. The only question is if Blackburn and Green can convince to the leadership to move the bill forward.

Commentary

In light of the recent controversy surrounding the security vulnerabilities reported in the Hospira Infuson Pump software I am surprised and disappointed in not seeing security specifically mentioned as one of the areas for review of software regulations. With patient safety also not being specifically identified I am concerned that the FDA may not feel justified in taking actions to regulate the security of medical device software.

There are, of course, a number of places still in the legislative process where an amendment could add language addressing these two issues. Some specific changes (in italics) to §361o(c)(3) that I would like to see would include:

(B) Standards for development of software including secure development practices;
(C) Standards for validation and verification of software including security testing;
(E) Modifications to software including security patching;
(I) Postmarketing requirements for reporting of adverse events and security vulnerabilities, including coordination with ICS-CERT for security vulnerabilities.


It would also be helpful if there were specific language requiring the Secretary to coordinate with NIST and DHS during the required software regulation review process. And finally there should be a specific requirement for users of the software to report any suspected cyberattacks on regulated software to be reported to the FBI and ICS-CERT.

Friday, February 14, 2014

S 2007 Introduced – Medical Software

As I mentioned earlier this week Sen. Fisher (R,NE) Introduced S 2007, the Preventing Regulatory Overreach to Enhance Care Technology (PROTECT) Act of 2014, a bill to limit the regulation of various types of medical software. Its intent is similar to HR 3303, but the provisions are subtly different.

Definitions

Section 3(a) of the bill would add two new definitions to 21 USC 321; ‘clinical software’ and ‘health software’. Clinical software is intended to be used in a clinical setting by trained medical personnel. It would capture, analyze, change or present clinical data and perhaps even recommend treatment, but does not actually act upon or change the body. Health software is not clinical software though it may similarly may capture, analyze, change or present patient clinical data or to provide administrative or operational support to health care, or act as a platform to run or connect other software; but is not used in direct patient care.

Exempts from Coverage

Section 3(b) would add a new section to Subchapter A of chapter V of the Federal Food, Drug, and Cosmetic Act (FFDCA) (21 U.S.C. 351 et seq.) that would prohibit clinical software and health software from being regulated under the FFFDCA.

Section 4 of the bill would exclude clinical software and health software from the definition of ‘device’ under 21 USC §321(h).

HR 3303 specifically gave FDA authority to regulate medical software other than clinical software or health software. This bill does not do that; it essentially ignores all other medical software once it blocks coverage of clinical or health software.

One of the consequences of this bill would be that it would leave no agency of the federal government to regulate the security of any medical software other than that which specifically controls the operation of medical devices. The authority to regulate that software is derivative of the authority to regulate devices, not specifically spelled out in the USC.

Moving Forward


This is a rather obscure bill and somewhat technical in nature. It is unlikely that this will capture the attention of enough members to command action. If it catches the attention of someone in the right position, it might be able to make it through floor action under one of the limited debate processes used to advance non-controversial legislation. It is more likely to advance by being added to an authorization bill or a spending bill; again that would require special support for the legislation from someone in a key leadership position.

Monday, November 18, 2013

Congressional Hearings – Week of 11-17-13

Both the House and Senate will be back in session today. While there are a number of hearings scheduled for this week only three appear to be of specific potential interest to readers of this blog: they include medical software, FirstNet and DHS confirmation hearings. And it looks like the Senate may actually consider the 2014 National Defense Authorization Act, S 1197.

Medical Software

The Health Subcommittee of the House Energy and Commerce Committee will be holding a hearing tomorrow looking at “Federal Regulation of Mobile Medical Apps and Other Health Software” and HR 3303. As I mentioned in my blog post about that bill, there is nothing currently in the bill that would extend FDA regulatory authority to software security issues. There is an outside chance that this will come up during this hearing.

BTW: There is a nice background document on the hearing web site, but no mention of software security issues.

FirstNet

The Communications and Technology Subcommittee of the House Energy and Commerce Committee will hold an oversight hearing on FirstNet and the Advancement of Public Safety Wireless Communications. No witness list is currently available.

DHS Confirmation

The Senate Homeland Security and Governmental Affairs Committee will vote tomorrow on the nomination of Jeh C. Johnson to be the Secretary of DHS. While there has been some controversy about the background of Mr. Johnson, this vote coming so soon after his appearance before the Committee probably means that a favorable vote will be forth coming.

S 1197

According to the Congressional Record, the Senate is scheduled to vote on a cloture motion to allow the Senate to proceed to consideration of S 1197. As I noted earlier this bill has a number of cybersecurity provisions. It’s original consideration was held up by the general disagreement between the Republicans and Democrats on spending issues. I’m not sure what has changed, but it would seem that Sen. Reid (D,NV) thinks that he has enough votes to move this bill forward.

If it passes (and it probably will if the cloture vote succeeds) it will then be tacked onto the House Bill (HR 2397) which probably means another spending conference committee. Many of the same folks will be on that conference as are on the budget conference that is trying to iron out differences between the Senate (read Democrats) and House (Republicans) so that a final 2014 spending bill can be put together.


This move by Reid may signal that there is at least some agreement between the conferees on defense issues.
 
/* Use this with templates/template-twocol.html */