FDA Consultant Specialist
FDA regulatory consulting for medical device manufacturers covering submission pathways, Quality System Regulation (QSR), HIPAA compliance, and device cybersecurity requirements.
Table of Contents
FDA Pathway Selection
Determine the appropriate FDA regulatory pathway based on device classification and predicate availability.
Decision Framework
Predicate device exists?
├── YES → Substantially equivalent?
│ ├── YES → 510(k) Pathway
│ │ ├── No design changes → Abbreviated 510(k)
│ │ ├── Manufacturing only → Special 510(k)
│ │ └── Design/performance → Traditional 510(k)
│ └── NO → PMA or De Novo
└── NO → Novel device?
├── Low-to-moderate risk → De Novo
└── High risk (Class III) → PMA
Pathway Comparison
| Pathway |
When to Use |
Timeline |
Cost |
| 510(k) Traditional |
Predicate exists, design changes |
90 days |
$21,760 |
| 510(k) Special |
Manufacturing changes only |
30 days |
$21,760 |
| 510(k) Abbreviated |
Guidance/standard conformance |
30 days |
$21,760 |
| De Novo |
Novel, low-moderate risk |
150 days |
$134,676 |
| PMA |
Class III, no predicate |
180+ days |
$425,000+ |
Pre-Submission Strategy
- Identify product code and classification
- Search 510(k) database for predicates
- Assess substantial equivalence feasibility
- Prepare Q-Sub questions for FDA
- Schedule Pre-Sub meeting if needed
Reference: See fda_submission_guide.md for pathway decision matrices and submission requirements.
510(k) Submission Process
Workflow
Phase 1: Planning
├── Step 1: Identify predicate device(s)
├── Step 2: Compare intended use and technology
├── Step 3: Determine testing requirements
└── Checkpoint: SE argument feasible?
Phase 2: Preparation
├── Step 4: Complete performance testing
├── Step 5: Prepare device description
├── Step 6: Document SE comparison
├── Step 7: Finalize labeling
└── Checkpoint: All required sections complete?
Phase 3: Submission
├── Step 8: Assemble submission package
├── Step 9: Submit via eSTAR
├── Step 10: Track acknowledgment
└── Checkpoint: Submission accepted?
Phase 4: Review
├── Step 11: Monitor review status
├── Step 12: Respond to AI requests
├── Step 13: Receive decision
└── Verification: SE letter received?
Required Sections (21 CFR 807.87)
| Section |
Content |
| Cover Letter |
Submission type, device ID, contact info |
| Form 3514 |
CDRH premarket review cover sheet |
| Device Description |
Physical description, principles of operation |
| Indications for Use |
Form 3881, patient population, use environment |
| SE Comparison |
Side-by-side comparison with predicate |
| Performance Testing |
Bench, biocompatibility, electrical safety |
| Software Documentation |
Level of concern, hazard analysis (IEC 62304) |
| Labeling |
IFU, package labels, warnings |
| 510(k) Summary |
Public summary of submission |
Common RTA Issues
| Issue |
Prevention |
| Missing user fee |
Verify payment before submission |
| Incomplete Form 3514 |
Review all fields, ensure signature |
| No predicate identified |
Confirm K-number in FDA database |
| Inadequate SE comparison |
Address all technological characteristics |
QSR Compliance
Quality System Regulation (21 CFR Part 820) requirements for medical device manufacturers.
Key Subsystems
| Section |
Title |
Focus |
| 820.20 |
Management Responsibility |
Quality policy, org structure, management review |
| 820.30 |
Design Controls |
Input, output, review, verification, validation |
| 820.40 |
Document Controls |
Approval, distribution, change control |
| 820.50 |
Purchasing Controls |
Supplier qualification, purchasing data |
| 820.70 |
Production Controls |
Process validation, environmental controls |
| 820.100 |
CAPA |
Root cause analysis, corrective actions |
| 820.181 |
Device Master Record |
Specifications, procedures, acceptance criteria |
Design Controls Workflow (820.30)
Step 1: Design Input
└── Capture user needs, intended use, regulatory requirements
Verification: Inputs reviewed and approved?
Step 2: Design Output
└── Create specifications, drawings, software architecture
Verification: Outputs traceable to inputs?
Step 3: Design Review
└── Conduct reviews at each phase milestone
Verification: Review records with signatures?
Step 4: Design Verification
└── Perform testing against specifications
Verification: All tests pass acceptance criteria?
Step 5: Design Validation
└── Confirm device meets user needs in actual use conditions
Verification: Validation report approved?
Step 6: Design Transfer
└── Release to production with DMR complete
Verification: Transfer checklist complete?
CAPA Process (820.100)
- Identify: Document nonconformity or potential problem
- Investigate: Perform root cause analysis (5 Whys, Fishbone)
- Plan: Define corrective/preventive actions
- Implement: Execute actions, update documentation
- Verify: Confirm implementation complete
- Effectiveness: Monitor for recurrence (30-90 days)
- Close: Management approval and closure
Reference: See qsr_compliance_requirements.md for detailed QSR implementation guidance.
HIPAA for Medical Devices
HIPAA requirements for devices that create, store, transmit, or access Protected Health Information (PHI).
Applicability
| Device Type |
HIPAA Applies |
| Standalone diagnostic (no data transmission) |
No |
| Connected device transmitting patient data |
Yes |
| Device with EHR integration |
Yes |
| SaMD storing patient information |
Yes |
| Wellness app (no diagnosis) |
Only if stores PHI |
Required Safeguards
Administrative (§164.308)
├── Security officer designation
├── Risk analysis and management
├── Workforce training
├── Incident response procedures
└── Business associate agreements
Physical (§164.310)
├── Facility access controls
├── Workstation security
└── Device disposal procedures
Technical (§164.312)
├── Access control (unique IDs, auto-logoff)
├── Audit controls (logging)
├── Integrity controls (checksums, hashes)
├── Authentication (MFA recommended)
└── Transmission security (TLS 1.2+)
Risk Assessment Steps
- Inventory all systems handling ePHI
- Document data flows (collection, storage, transmission)
- Identify threats and vulnerabilities
- Assess likelihood and impact
- Determine risk levels
- Implement controls
- Document residual risk
Reference: See hipaa_compliance_framework.md for implementation checklists and BAA templates.
Device Cybersecurity
FDA cybersecurity requirements for connected medical devices.
Premarket Requirements
| Element |
Description |
| Threat Model |
STRIDE analysis, attack trees, trust boundaries |
| Security Controls |
Authentication, encryption, access control |
| SBOM |
Software Bill of Materials (CycloneDX or SPDX) |
| Security Testing |
Penetration testing, vulnerability scanning |
| Vulnerability Plan |
Disclosure process, patch management |
Device Tier Classification
Tier 1 (Higher Risk):
- Connects to network/internet
- Cybersecurity incident could cause patient harm
Tier 2 (Standard Risk):
- All other connected devices
Postmarket Obligations
- Monitor NVD and ICS-CERT for vulnerabilities
- Assess applicability to device components
- Develop and test patches
- Communicate with customers
- Report to FDA per guidance
Coordinated Vulnerability Disclosure
Researcher Report
↓
Acknowledgment (48 hours)
↓
Initial Assessment (5 days)
↓
Fix Development
↓
Coordinated Public Disclosure
Reference: See device_cybersecurity_guidance.md for SBOM format examples and threat modeling templates.
Resources
scripts/
| Script |
Purpose |
fda_submission_tracker.py |
Track 510(k)/PMA/De Novo submission milestones and timelines |
qsr_compliance_checker.py |
Assess 21 CFR 820 compliance against project documentation |
hipaa_risk_assessment.py |
Evaluate HIPAA safeguards in medical device software |
references/
| File |
Content |
fda_submission_guide.md |
510(k), De Novo, PMA submission requirements and checklists |
qsr_compliance_requirements.md |
21 CFR 820 implementation guide with templates |
hipaa_compliance_framework.md |
HIPAA Security Rule safeguards and BAA requirements |
device_cybersecurity_guidance.md |
FDA cybersecurity requirements, SBOM, threat modeling |
fda_capa_requirements.md |
CAPA process, root cause analysis, effectiveness verification |
Usage Examples
# Track FDA submission status
python scripts/fda_submission_tracker.py /path/to/project --type 510k
# Assess QSR compliance
python scripts/qsr_compliance_checker.py /path/to/project --section 820.30
# Run HIPAA risk assessment
python scripts/hipaa_risk_assessment.py /path/to/project --category technical
1---2name: fda-consultant-specialist3description: FDA regulatory consultant for medical device companies. Provides 510(k)/PMA/De Novo pathway guidance, QSR (21 CFR 820) compliance, HIPAA assessments, and device cybersecurity. Use when user mentions FDA submission, 510(k), PMA, De Novo, QSR, premarket, predicate device, substantial equivalence, HIPAA medical device, or FDA cybersecurity.4---5
6# FDA Consultant Specialist
7
8FDA regulatory consulting for medical device manufacturers covering submission pathways, Quality System Regulation (QSR), HIPAA compliance, and device cybersecurity requirements.
9
10## Table of Contents
11
12- [FDA Pathway Selection](#fda-pathway-selection)
13- [510(k) Submission Process](#510k-submission-process)
14- [QSR Compliance](#qsr-compliance)
15- [HIPAA for Medical Devices](#hipaa-for-medical-devices)
16- [Device Cybersecurity](#device-cybersecurity)
17- [Resources](#resources)
18
19---
20
21## FDA Pathway Selection
22
23Determine the appropriate FDA regulatory pathway based on device classification and predicate availability.
24
25### Decision Framework
26
27```
28Predicate device exists?
29├── YES → Substantially equivalent?
30│ ├── YES → 510(k) Pathway
31│ │ ├── No design changes → Abbreviated 510(k)
32│ │ ├── Manufacturing only → Special 510(k)
33│ │ └── Design/performance → Traditional 510(k)
34│ └── NO → PMA or De Novo
35└── NO → Novel device?
36 ├── Low-to-moderate risk → De Novo
37 └── High risk (Class III) → PMA
38```
39
40### Pathway Comparison
41
42| Pathway | When to Use | Timeline | Cost |
43|---------|-------------|----------|------|
44| 510(k) Traditional | Predicate exists, design changes | 90 days | $21,760 |
45| 510(k) Special | Manufacturing changes only | 30 days | $21,760 |
46| 510(k) Abbreviated | Guidance/standard conformance | 30 days | $21,760 |
47| De Novo | Novel, low-moderate risk | 150 days | $134,676 |
48| PMA | Class III, no predicate | 180+ days | $425,000+ |
49
50### Pre-Submission Strategy
51
521. Identify product code and classification
532. Search 510(k) database for predicates
543. Assess substantial equivalence feasibility
554. Prepare Q-Sub questions for FDA
565. Schedule Pre-Sub meeting if needed
57
58**Reference:** See [fda_submission_guide.md](references/fda_submission_guide.md) for pathway decision matrices and submission requirements.
59
60---
61
62## 510(k) Submission Process
63
64### Workflow
65
66```
67Phase 1: Planning
68├── Step 1: Identify predicate device(s)
69├── Step 2: Compare intended use and technology
70├── Step 3: Determine testing requirements
71└── Checkpoint: SE argument feasible?
72
73Phase 2: Preparation
74├── Step 4: Complete performance testing
75├── Step 5: Prepare device description
76├── Step 6: Document SE comparison
77├── Step 7: Finalize labeling
78└── Checkpoint: All required sections complete?
79
80Phase 3: Submission
81├── Step 8: Assemble submission package
82├── Step 9: Submit via eSTAR
83├── Step 10: Track acknowledgment
84└── Checkpoint: Submission accepted?
85
86Phase 4: Review
87├── Step 11: Monitor review status
88├── Step 12: Respond to AI requests
89├── Step 13: Receive decision
90└── Verification: SE letter received?
91```
92
93### Required Sections (21 CFR 807.87)
94
95| Section | Content |
96|---------|---------|
97| Cover Letter | Submission type, device ID, contact info |
98| Form 3514 | CDRH premarket review cover sheet |
99| Device Description | Physical description, principles of operation |
100| Indications for Use | Form 3881, patient population, use environment |
101| SE Comparison | Side-by-side comparison with predicate |
102| Performance Testing | Bench, biocompatibility, electrical safety |
103| Software Documentation | Level of concern, hazard analysis (IEC 62304) |
104| Labeling | IFU, package labels, warnings |
105| 510(k) Summary | Public summary of submission |
106
107### Common RTA Issues
108
109| Issue | Prevention |
110|-------|------------|
111| Missing user fee | Verify payment before submission |
112| Incomplete Form 3514 | Review all fields, ensure signature |
113| No predicate identified | Confirm K-number in FDA database |
114| Inadequate SE comparison | Address all technological characteristics |
115
116---
117
118## QSR Compliance
119
120Quality System Regulation (21 CFR Part 820) requirements for medical device manufacturers.
121
122### Key Subsystems
123
124| Section | Title | Focus |
125|---------|-------|-------|
126| 820.20 | Management Responsibility | Quality policy, org structure, management review |
127| 820.30 | Design Controls | Input, output, review, verification, validation |
128| 820.40 | Document Controls | Approval, distribution, change control |
129| 820.50 | Purchasing Controls | Supplier qualification, purchasing data |
130| 820.70 | Production Controls | Process validation, environmental controls |
131| 820.100 | CAPA | Root cause analysis, corrective actions |
132| 820.181 | Device Master Record | Specifications, procedures, acceptance criteria |
133
134### Design Controls Workflow (820.30)
135
136```
137Step 1: Design Input
138└── Capture user needs, intended use, regulatory requirements
139 Verification: Inputs reviewed and approved?
140
141Step 2: Design Output
142└── Create specifications, drawings, software architecture
143 Verification: Outputs traceable to inputs?
144
145Step 3: Design Review
146└── Conduct reviews at each phase milestone
147 Verification: Review records with signatures?
148
149Step 4: Design Verification
150└── Perform testing against specifications
151 Verification: All tests pass acceptance criteria?
152
153Step 5: Design Validation
154└── Confirm device meets user needs in actual use conditions
155 Verification: Validation report approved?
156
157Step 6: Design Transfer
158└── Release to production with DMR complete
159 Verification: Transfer checklist complete?
160```
161
162### CAPA Process (820.100)
163
1641. **Identify**: Document nonconformity or potential problem
1652. **Investigate**: Perform root cause analysis (5 Whys, Fishbone)
1663. **Plan**: Define corrective/preventive actions
1674. **Implement**: Execute actions, update documentation
1685. **Verify**: Confirm implementation complete
1696. **Effectiveness**: Monitor for recurrence (30-90 days)
1707. **Close**: Management approval and closure
171
172**Reference:** See [qsr_compliance_requirements.md](references/qsr_compliance_requirements.md) for detailed QSR implementation guidance.
173
174---
175
176## HIPAA for Medical Devices
177
178HIPAA requirements for devices that create, store, transmit, or access Protected Health Information (PHI).
179
180### Applicability
181
182| Device Type | HIPAA Applies |
183|-------------|---------------|
184| Standalone diagnostic (no data transmission) | No |
185| Connected device transmitting patient data | Yes |
186| Device with EHR integration | Yes |
187| SaMD storing patient information | Yes |
188| Wellness app (no diagnosis) | Only if stores PHI |
189
190### Required Safeguards
191
192```
193Administrative (§164.308)
194├── Security officer designation
195├── Risk analysis and management
196├── Workforce training
197├── Incident response procedures
198└── Business associate agreements
199
200Physical (§164.310)
201├── Facility access controls
202├── Workstation security
203└── Device disposal procedures
204
205Technical (§164.312)
206├── Access control (unique IDs, auto-logoff)
207├── Audit controls (logging)
208├── Integrity controls (checksums, hashes)
209├── Authentication (MFA recommended)
210└── Transmission security (TLS 1.2+)
211```
212
213### Risk Assessment Steps
214
2151. Inventory all systems handling ePHI
2162. Document data flows (collection, storage, transmission)
2173. Identify threats and vulnerabilities
2184. Assess likelihood and impact
2195. Determine risk levels
2206. Implement controls
2217. Document residual risk
222
223**Reference:** See [hipaa_compliance_framework.md](references/hipaa_compliance_framework.md) for implementation checklists and BAA templates.
224
225---
226
227## Device Cybersecurity
228
229FDA cybersecurity requirements for connected medical devices.
230
231### Premarket Requirements
232
233| Element | Description |
234|---------|-------------|
235| Threat Model | STRIDE analysis, attack trees, trust boundaries |
236| Security Controls | Authentication, encryption, access control |
237| SBOM | Software Bill of Materials (CycloneDX or SPDX) |
238| Security Testing | Penetration testing, vulnerability scanning |
239| Vulnerability Plan | Disclosure process, patch management |
240
241### Device Tier Classification
242
243**Tier 1 (Higher Risk):**
244- Connects to network/internet
245- Cybersecurity incident could cause patient harm
246
247**Tier 2 (Standard Risk):**
248- All other connected devices
249
250### Postmarket Obligations
251
2521. Monitor NVD and ICS-CERT for vulnerabilities
2532. Assess applicability to device components
2543. Develop and test patches
2554. Communicate with customers
2565. Report to FDA per guidance
257
258### Coordinated Vulnerability Disclosure
259
260```
261Researcher Report
262 ↓
263Acknowledgment (48 hours)
264 ↓
265Initial Assessment (5 days)
266 ↓
267Fix Development
268 ↓
269Coordinated Public Disclosure
270```
271
272**Reference:** See [device_cybersecurity_guidance.md](references/device_cybersecurity_guidance.md) for SBOM format examples and threat modeling templates.
273
274---
275
276## Resources
277
278### scripts/
279
280| Script | Purpose |
281|--------|---------|
282| `fda_submission_tracker.py` | Track 510(k)/PMA/De Novo submission milestones and timelines |
283| `qsr_compliance_checker.py` | Assess 21 CFR 820 compliance against project documentation |
284| `hipaa_risk_assessment.py` | Evaluate HIPAA safeguards in medical device software |
285
286### references/
287
288| File | Content |
289|------|---------|
290| `fda_submission_guide.md` | 510(k), De Novo, PMA submission requirements and checklists |
291| `qsr_compliance_requirements.md` | 21 CFR 820 implementation guide with templates |
292| `hipaa_compliance_framework.md` | HIPAA Security Rule safeguards and BAA requirements |
293| `device_cybersecurity_guidance.md` | FDA cybersecurity requirements, SBOM, threat modeling |
294| `fda_capa_requirements.md` | CAPA process, root cause analysis, effectiveness verification |
295
296### Usage Examples
297
298```bash
299# Track FDA submission status
300python scripts/fda_submission_tracker.py /path/to/project --type 510k
301
302# Assess QSR compliance
303python scripts/qsr_compliance_checker.py /path/to/project --section 820.30
304
305# Run HIPAA risk assessment
306python scripts/hipaa_risk_assessment.py /path/to/project --category technical
307```