The past year, as in previous years, life has not been easy for many reasons,…

Software in Medical Devices – Update for Q3/42 2025
The past year, as in previous years, life has not been easy for many reasons, especially that investments have been hard to come by.
In the past 3 – 4 years, the FDA has been moving forward with new standards. The MDR/IVDR is still happening but is moving slowly. There is a major backup in getting to the notified body.
This is a continuation of the software updates I have been sending out for numerous years. Please check out all the references for download and/or purchase. If you have any questions, please contact us.
Software is everywhere in medical devices and IVDs. The FDA and CE are becoming more pedantic in how they review and relate to software. The number of companies getting into the field is growing and the amount of software being developed for medical devices is exceptionally large (especially the number of companies involved with AI/ML).
The FDA has been very critical of the software documentation and the cybersecurity documentation when reviewing a submission. The better the documentation, the less deficiencies are received. Even though the documentation may be good, this is not a reason that the software should not be good. The amount of recalls due to software is growing each year and this reflects the quality of the software and not the documentation.
Software Recalls Q3-Q4/2025
We have been following the recalls and there are a growing number of recalls listed where software played a role in the recall. It is interesting to note that software has been the leading cause of recalls in the FDA for the past 15 years. This trend does not look like it will change.
The following are additional examples of recalls involving software directly as listed on the FDA website, including Israeli developed software. There may be more but classified not under software. There are a large number of class I recalls after patients were severely injured. The descriptions given for the recall are taken from the FDA database. For further details on the recalls, you can check them out on the FDA’s recall database.
Please note that the content for each recall is taken from the FDA database and is not our content.
- Dexcom, Dexcom G6 and G6 Pro Android US CGM App, Class I – A software defect in version v1.15.0 of the G6 Android app can cause the app to terminate unexpectedly, which may result in the user not receiving estimated glucose values, alarms, alerts or notifications. This could result in the missed detection of a hyperglycemic or hypoglycemic event, protentional resulting in severe hyperglycemia, diabetic ketoacidosis (DKA), or hyperosmolar hyperglycemic state (HHS).
- Fresenius Kabi, Ivenix Infusion System (IIS), Class I – Software version 5.10.1 and earlier contain anomalies that have the potential to cause serious patient harm or death.
- Tandem Diabetes Care, Tandem Mobi Insulin Pump, Class I – Insulin pump includes a vibration motor that gives tactile feedback for any alerts, alarms, or malfunctions. Pump may exhibit false vibration motor failure due to a software issue causing Malfunction 12: “Pump cannot operate, the mobile app can no longer receive data from the pump. Insulin delivery and any active CGM Sessions have been stopped”, which could result in hyperglycemia.
- Abiomed, Automated Impella Controller (AIC), Class I – Potential cybersecurity vulnerabilities related to the operating system in the Automated Impella Controller (AIC).
- NOXBOX, NOxBOXi Nitric Oxide Delivery System, Class I – Fluctuations may be more likely to occur if the total flow through the device sensor (used by the device to determine flow) is less than the minimum device requirement of 0.5 LPM. In addition, dose fluctuations have been observed when Bunnel LifePulse HFJV system or conventional ventilators have the following device settings: low service pressures generally less than 3.0 PSI, a pressure difference greater than 5.0cm H2O; or at breath per minute rates of 300 (5 Hz).
- Dexcom, Dexcom ONE+ Continuous Glucose Monitoring System, Class I – The affected devices are the Dexcom G7 Continuous Glucose Monitoring System (CGM System) using iOS, watchOS and Android App software (versions 2.8.0 or earlier) and Dexcom ONE+ CGM System using iOS and Android App software (versions 1.4.0 or earlier), henceforth referred to as the App. The affected App does not provide an expected “Sensor Failed” alert when the transmitter sends a “Transmitter Failed” error message to the App when the CGM experiences a hardware or firmware failure. Instead, the App ends the CGM sensor session, stops reporting glucose values and displays the Start Sensor screen or No active sensormessage without alerting the user, which can lead to missed detection of a hyperglycemic or hypoglycemic event and a delay in treatment.
- CareFusion 303, BD Alaris Pump Module Model, Class I – Infusion pump module used with compatible pump infusion sets may perform outside the established performance ranges for flow rate and bolus accuracy, downstream and upstream occlusion time to alarm, and post-occlusion bolos volume.
- ICU Medical, Plum Duo Infusion System, Class I – ICU Medical identified two sequences of programming events and alarm interactions that may cause the user interface to become unresponsive.
- Philips Ultrasound, Philips EPIQ Ultrasound Systems (various models) used in conjunction with the X5-1c transducer, Class II – Ultrasound may experience an unexpected automatic reboot, resulting in damage to transducer.
- ICU Medical, LifeShield Drug Library Management (DLM) & LifeShield Infusion Safety Software Suite, Class II – Software issue only allows Concentration Limits to be defined to one digit of precision past the decimal point (0.1) instead of three digits (0.001). If the user is unable to use Concentration Limits as intended, they may need to change the limits to something other than what is recommended by the drug manufacturer, which may result in over- or under-delivery.
- Medtronic MiniMed, C InPen App, Class II – When app is uninstalled and reinstalled, insulin pen software issue causes Choose Notification Style Screen to not show during setup so users can’t choose to allow notifications to override phone settings when on mute/Do Not Disturb, and previously set up override permission is deleted, so audible and vibratory notifications not received, which may lead to delayed insulin therapy, hyperglycemia.
- Intelerad Medical Systems, IntelePACS – InteleConnect / TechPortal, Class II – Software application that receives digital images and data to be communicated, processed, manipulated, enhanced, stored, displayed has a bug that could cause data loss in Relevant Clinical Info field when modifying studies through Case Editor in either Technologist Portal or Referring Physician Portal, which could result in loss of clinical information, which could impact clinical decision-making.
- Change Healthcare Canada, Change Healthcare Radiology Solutions, Class II – Due to software issue, radiology reports may not be fully displayed when viewing.
- Beckman Coulter, DxC 500 AU Module w/ISE, Class II – On a clinical analyzer, when ordering a Clinical Chemistry (CC) combination test simultaneously with an Immunoassay (IA) test, if the IA test is processed between the CC tests, CC sample status will remain In Progress with no errors, may cause processing delays.
- Bard Peripheral Vascular, Venclose digiRF Generators, Class II – Software version 3.35 of the Venclose digiRF Generator incorporates a catheter verification feature specifically designed to detect internal wiring anomalies in Venclose EVSRF Ablation Catheters prior to clinical use. This automated diagnostic check is executed immediately upon catheter connection to the generator, occurring before the procedure interface becomes accessible. When a catheter fails this verification process, the generator displays a Red X indicator on the screen without accompanying error codes, effectively disabling catheter functionality. However, BD has determined that software version 3.35 generates false positive failures due to temperature-dependent verification parameters, incorrectly flagging properly functioning Venclose EVSRF Ablation Catheters as defective when the catheter temperature is not at steady state during the check initiation.
- Elekta, MOSAIQ Oncology Information System with Particle Therapy License, Class II – Using oncology information system that manages workflow may result in overtreatment if: Plan delivered with Particle Therapy IHE-RO TDW-II interface, with one field per fraction or last field partial treatment, partial treatment occurs followed by treatment field interruptions with manually recorded partial treatment, then treatment unit doesn’t check meter set value, so partial treatment delivered twice.
- Medtronic MiniMed, CareLink Clinic, Class II – Software error causing incorrect data to be displayed on the 24-hour Sensor Glucose Overview Graph, any potential therapy decisions were made based on the incorrect data displayed on the 24-hour sensor glucose overview graph may lead to hypoglycemia or hyperglycemia.
- Tandem Diabetes Care, t:slim X2 insulin pump with Interoperable Technology, Class II – A software defect in versions 7.9.0.1 and 7.10.1 of the pump software for Tandem t:slim X2 and version 7.9.0.1 of the Tandem Mobi pump with Control-IQ+ technology that are paired with a G7 sensor may result in an unexpected automatic insulin correction bolus (autobolus) which could result in hypoglycemia.
- Kico Knee Innovation, ARVIS, Class II – Complaint identified issue with AI surgical planning software that may result in implant malalignment and/or decrease range of motion.
- Zap Surgical Systems, ZAP-X Radiosurgery System, Class II – If the radiosurgery system triggers a proximity error message during a long gantry move (greater-than180 degrees), and a subsequent proximity error message occurs after the automatic reduction of speed, a software defect could potentially lead the collimator to collide with patient shoulders or the patient table.
- Reflexion Medical, RefleXion X1 Model RXM1000, Class II – Due to incorrect software configuration that potentially allows more than two (2) fractions within a 12-hour period (fraction Limits) and could potentially lead to adverse events (toxicity).
- PIE Medical Imaging, 3mensio Workstation, Class II – When fenestrated analysis with clock measurements is started in diagnostic bioimaging software (intended to measure/visualize cardiovascular structures) and the 12h position of a single clock is changed, other clock measurements are not updated relative to the new 12h position which may cause stent graft fenestrations at incorrect position, which may lead to blood flow disruption and tissue damage.
- Philips Medical Systems, Pinnacle 3 with TumorLOC, Class II – Due to software issue, Radiation Therapy Planning system may provide incorrect dataset calculations when performing the “Stopping Power Ratio” (SPR).
- Remote Diagnostic Technologies, Inseego USB8 4G Dongle Kit, Class II – Kit USB flash drive contains outdated software, which could result in reverting patient monitor to outdated software and reintroducing the video laryngoscope issue (related to an August 2023 recall), which could lead to delay in diagnosis, delayed treatment, hypoxia due to unexpected loss of video laryngoscopy and all other monitor measurements during system restart.
- GE Medical Systems Israel, GE Healthcare Omni Legend, Class II – There is a potential intermittent issue on certain Omni Legend systems that can result in a streaking artifact in the PET clinical scan images. This streaking artifact is most easily identified in transaxial slices on the acquisition console (both corrected and non-corrected for attenuation).
- ICU Medical, ICU Medical Plum Solo Precision IV Pump, Class II – Plum Solo and Duo Infusion pumps include a feature, that when selected, automatically flushes the downstream line after a piggyback therapy. The programmed flush volume is delivered from the primary line container at the piggyback therapy rate after the piggyback therapy is complete. In certain cases, as described below, the clinician may receive an Upper Hard Limit (UHL) or Lower Hard Limit (LHL) Violation message when programming a piggyback flush, which prevents the flush from being programmed.
- Philips Medical Systems Nederland, Philips Azurion system, Class II – Philips has identified two (2) software issues affecting device systems that may result in loss of imaging (X-ray) functionality and/or loss of motorized movement, and/or incorrect image content and/or loss of data. Issue 1 – System remains in continuous restart mode after the start-up. Issue 2 – Longitudinal Position Error Applicable only to systems with Poly-G3 frontal stand.
- Medtronic Neuromodulation, A71200 Vanta Clinician Programmer Application (CP App), Class II – Complaints received that Vanta A71200 CP App does not function as intended during use. There is a potential for prolonged or postponed surgical procedure.
- Sophysa, Pressio 2 ICP Monitoring System, Class II – Customer complaints of Pressio monitor rebooting.
- Philips North America, Philips Smart-hopping 2.0 AP 1.4 GHz. Patient Monitor, Class II – It was found that the MX40 device could not reconnect to the PIC iX when moving between Radiohead and Trident 1.4 GHz access points if the signal strength changed quickly.
- Medtronic Neuromodulation, Restore Clinician Programmer Application, Class II – Software issue where a Device Reset message displayed on the app was unable to be cleared. In rare cases, this resulted in an inability to resume therapy, and the patient experienced a recurrence of underlying pain symptoms. Resolution would require surgical replacement of the INS.
- DICOM Grid, Intelerad InteleShare software, Class II – .
- CareFusion, CCE Enterprise, Class II – Software intended to aid in diagnosing conditions, planning treatments, visualizing anatomical structures has a bug that, if all of following are met: Viewing images in InteleShare viewer; Multiplanar reconstruction applied; Manual rotation applied, could result in inaccurate length measurement tool values that could compromise diagnostic accuracy, lead to misdiagnosis or inappropriate follow-up.
- Abbott Laboratories, Alinity ci-series System Control Module, Class II – Abbott Laboratories is recalling their Alinity ci-series System Control Module, a chemistry/immunoassay analyzer, by correction. The reason for the recall is potential performance issues found in the Alinity ci-series System software versions 3.6.1. and lower that could lead to erroneous results for multiple analytes. The issue was identified by Abbott during the internal testing of complaint investigations.
- Fresenius Medical Care Holdings, 5008X CAREsystem +CLiC +CDX, Class II – Several software anomalies with the potential to impact patient treatment, of which one includes the possibility to result in treatment stop if certain conditions are fulfilled.
- Mindray DS, Hardware configuration of the BeneVision Central Monitoring System (CMS), Class II – When the Workstation of the BeneVision DMS has a specific hardware configuration, the computer may experience audio playback failure or screen freezing.
- Philips Ultrasound, Lumify Diagnostic Ultrasound System, Class II – Ultrasound system compatibility issues with Apple devices running iOS 18 may cause a failure to perform live imagining.
- Medtronic, Aurora EV-ICD and Clinical EV-ICD, Class II – There is a potential for delayed time to high-voltage (HV) therapy should a rare sequence of events occur.
- Cellavision, Automated Digital Cell Morphology analyzer DI-60, Class II – Automated cell-locating device barcode reader may read the barcode of the previously processed slide resulting in a misattribution of diagnostic results.
- Elekta Solutions, MOSAIQ Oncology Information System, Class II – When appending a care plan that contains one or more wave medication orders, the occurrence and frequency of the appended orders may not match the intended schedule.
- Abbott Laboratories, Alinity hq Analyzer, Class II – Software issue for hq analyzer results in system not visibly applying appropriate flagging to results when saturation is present which may result in incorrect results.
- Spacelabs Healthcare, Sentinel V11, Class II – Due to two distinct issues: 1. During patient admission, patient demographic fields may default to those of a previously viewed patient. 2. Systems configured with Resting/Rhythm ECG functionality, under specific navigation conditions, test data intended for one patient may be saved under another patient’s record.
- Beckman Coulter, CellMek SPS Sample Preparation System, Class II – Automated pipetting, diluting and specimen processing workstations for flow cytometric analysis device instructions for use list incorrect dead volumes: Cassette Type/List volume/correct volume, B/750/1582 microliters, and E/1300/2093 microliters. Device software does not rock Cassette E, used with 15mmX92mm Sarstedt tubes. May lead to incorrect diagnosis or error in patient management/treatment.
- Vantive US Healthcare, Sharesource Connectivity Platform for Use with Homechoice Claria, Class II – Vantive has identified a software defect within the Sharesource Claria software, which may cause a patient s updated prescription program settings to not be properly saved on the actual cycler that the patient is using to perform their therapy. As a result, the clinician may think that the patient is receiving the correct prescribed therapy because of what is erroneously displayed on the clinician’s remote Sharesource application, when in fact the cycler that is with the patient is actually delivering an outdated and incorrect therapy.
- Becton Dickinson, BD Veritor Connect Software, Class II – Product service credentials used by some BD technical support teams to access certain BD products were accessed by an unauthorized actor. Until these product service credentials are updated, there is a risk of unauthorized access that may impact the confidentiality, integrity and/or availability of the relevant products and associated data.
- Wipro GE Healthcare Private, GE Healthcare Carescape Central Station (CSCS), Class II – GE HealthCare has identified an issue affecting Carescape Central Station (CSCS) with software version V3.0.5, which can cause the system to enter a continuous reboot cycle. If this occurs, a loss of central monitoring of connected patients could result. This issue occurs only when the number of central stations connected to the network is 118, 119 or 120.
- GE HealthCare Service, LOGIQ P9 R4.5 ultrasound system, Class II – The Ultrasound-Guided Attenuation Parameter (UGAP) measurement data may display inaccurate values representing liver steatosis. This could potentially lead to inappropriate clinical decisions impacting overall care.
- Insulet Corporation, Omnipod 5 iOS application, Class II – The failure occurs if a user on the Omnipod 5 iOS application selects and holds down on a manual entry field, to magnify the visual field using the magnifying feature of the iPhone, while simultaneously selecting a single number on the keyboard. This causes the single digit number to duplicate. This could result in errors in manual entry of digits – examples: bolus entry, I:C ratio, bolus calculator, prior to starting the bolus insulin delivery. Therefore, this may result in over delivery of insulin which may cause hypoglycemia.
- Medical Communications, Ashvins variant HEYEX 2 / HEYEX PACS, Class II – Potential that the measured value may be smaller than the actual area.
- Mindray DS USA, BeneVision N1 Patient Monitor (N1), Class II – Potential for activation of an abnormal alarm pause.
- Tandem Diabetes Care, t:slim X2 Insulin Pump with Interoperable Technology, Class II – An app defect that occurs when the phone is set to a right-to-left language, which causes app-pump pairing issues and graphical defects, which can potentially lead to incorrect therapy decisions and subsequent hypoglycemia or hyperglycemia.
- Medical Information Technology, MEDITECH Expanse Laboratory (LAB), Microbiology (MIC), Anatomical Pathology (PTH), Genetics (GEN). Calculator/data processing module for clinical use, Class II – Entering multiple keys that trigger input simultaneously may remove data from first field of screens and/or questionnaires with more than one field.
- Philips Medical Systems, Pinnacle Radiation Therapy Planning System, Class II – Due to a software issue, there is a potential image error of the Region of Interest for expansion/contraction for HFP (Head First Prone), FFS (Feet First Supine) and FFP (Feet First Prone) orientations.
- Philips Medical Systems Nederland, IntelliSpace Cardiovascular, Class II – Software issue that results in the display of outdated information.
- Siemens Medical Solutions USA, Artis Pheno Image-Intensified Flouroscopic X-Ray System, Class II – Limited system movements after startup.
- Caris Life Sciences, MI Cancer Seek, Class II – Due to an incorrect test results provided that indicated the incorrect drug therapy recommendation.
- Philips Medical Systems Nederland, Allura R8.2.x Systems, Class II – Potential for temporary loss of imaging (X-ray) functionality due to software issue.
- Medtronic, CareLink SmartSync Patient Connector, Class II – In prior SmartSync application versions, the Abort button stopped the test that was selected. During an induction test, there was a limited window of time for the user to abort a therapy, thereby limiting the user’s ability to cancel a high voltage therapy delivery.
- GE Medical Systems Israel, Varicam, Millennium VG, Millennium VG Hawkeye, Discovery VH Nuclear Medicine System, Class II – Unintended radial detector motion may occur during patient setup or during patient scan if system does not have correct version of gantry software installed. Unintended detector motion may result in life-threatening injury.
- STRATASYS, TrueDent White, Class II – Customers unable to use cartridges due to formatting error in expiration date which leads to switching the day with the month. Or, the system will not recognize that a resin is expired and will not prevent the user from using an expired material.
- Change Healthcare Canada, Change Healthcare Cardiology Hemo Software, Class II – Due to complaints, software update may cause software to unexpectedly shutdown.
- Baxter Healthcare, Novum IQ LVP, Class II – Baxter Healthcare Corporation is issuing an Urgent Medical Device Correction for the Novum IQ Large Volume Pump (LVP) and Novum IQ Syringe Pump (SP) due to software anomalies that may result in a blank Run screen (LVP and SP) and/or false motor movement system error (SP only).
- Medtronic Perfusion Systems, MC3 VitalFlow Console, Class II – As of August 6, 2025, Medtronic has received eleven reports of VitalFlow Consoles displaying an E70 error code during normal operation. When this occurs, the touch screen may become temporarily unresponsive and go blank for up to two minutes before recovering to full functionality. Importantly, the console continues to maintain set pump speed and function throughout.
- GE Medical Systems, AW Server, Class II – Firm has identified a security vulnerability in AW Server products. If exploited, a malicious actor could compromise the confidentiality, integrity, and availability of patient data.
- Raysearch Laboratories, RayStation, Class II – Potential for the invalidation for calculated radiation dose does not work as intended for certain Regions of Interest (ROIs). This issue occurs for some ROI(s) which have no contours and either have a material override defined, or are of type Bolus, Fixation, or Support. In these cases, adding geometry to the ROI, subsequently modifying geometry, or removing the material override does not invalidate dose as intended.
- Mazor Robotics, Mazor X robotic guidance system, Class II – Software errors that can result in incorrect surgical instrument positioning during spinal surgery.
- C-RAD Positioning, Catalyst+, Class II – Due to issues with the system’s stereotactic radiosurgery (SRS) treatment cannot be guaranteed for all couch angles and system setups. n certain cases, the system may indicate the patient as correctly positioned at the isocenter, even when the isocenter is positioned outside of the indicated tolerance.
- Securitas Healthcare, Arial 900 MHz Call Station, Class II – Securitas Healthcare has become aware of a firmware issue in the Call Stations in the Affected Lots that may cause Call Stations in the Affected Lots to (1) not transmit a low battery alert to the Arial Wireless Emergency Call System prior to battery failure, or (2) not transmit a low battery alert to the Arial Wireless Emergency Call system at least seven (7) days prior to the battery failing.
- CareFusion 303, BD Pyxis ES Enterprise Server, Class II – Due a software issue that may result in equipment not receiving timely updates of patient, medication, or related information from enterprise systems.
- Noah Medical Corporation, Galaxy System, Class II – Due to Users not having access to the Instructions for Use/User Manual due to it being password protected.
- Beckman Coulter, DxFLEX Flow Cytometer, Class II – Due to a software error code that crashes during acquisition on patient sample when running customer defined acquisition protocol. This may lead to delayed patient results.
- Philips Medical Systems, CT 5300, Class II – Issue 1: The potential for unintentional continued gantry/couch movement when a specific button series is used requiring use of manual stop. Issue 2. When performing a helical/Axial scan with ORI (Dose Right index)/ DOM (Dose Modulation), the WED (Water Equivalent Diameter) value might set itself to zero, and this may lead to an insufficient dose setting after the surview. If operator misses the insufficient dose and the WED value in User Interface and continues with the subsequent helical/Axial scans, then the obtained images will be noisy due to low dose setting. Issue 3: Due to a software failure, the ECG wave file is not saved. As a result, the cardiac offline image reconstruction fails due to the missing ECG wave file, and the user might rescan the patient. Issue 4: This issue is software fault in which the patient orientation will be changed to NULL under specific random scenarios resulting in radiation being delivered from the wrong orientation (surview scan) or in the wrong position (clinical scan) and will generate incorrect and undiagnosable surview/clinical images. Patients may be rescanned for surview and/or clinical images. Issue 5: During scanning, the preview image display is not consistent, the images are not arriving at a fixed rate, skipping images from time to time during scanning. The obtained images might not support making the clinical diagnosis and the user might decide to re-scan the patient. Issue 6: If a user presses the left and middle/right mouse buttons together or afterwards in a short time, both commands are executed and an incorrect auto ROI is created. This ROI coordinates won t be assigned as the object is empty. As a result, the threshold of contrast level will not be reached in the UI and this will prevent the system from automatically triggering the subsequent clinical scan. There is potential safety risk identified for additionally tracker shots and/or rescan of a patient when the clinical scan is not triggered. This issue only affects the manual ROI process.
- Surgical Theater, SuRgical Planner, Class II – A software anomaly, under specific conditions when large rotational alignment values are applied in 2D Image Fusion, may lead to misalignment of any secondary image layer(s) to the primary image layer.
- Raysearch Laboratories, RayStation, Class II – DICOM SOP Instance UID and Series Instance UID from RayGateway, i.e. the interface to Accuray’s iDMS, are not guaranteed to be unique.
- Medtronic MiniMed, InPen App, Class II – Medtronic MiniMed, Inc. is recalling InPen App for iOS and Android users due to software design errors that could lead to a missed short-acting insulin dose reminder and a recommendation to correct a high glucose value. It does not impact insulin delivery, long-acting insulin dose reminders, or CGM alerts, and users can still use the pen itself to calculate a dose, deliver insulin, record the dose date/time, and view CGM data. This issue was identified during internal testing before release in the US but after release to OUS customers, no complaints or MDRs related to this recall have been reported. Use of the affected device may result hyperglycemia by failing to alert the user and delay treatment of diabetes.
- Fresenius Kabi, Ivenix Infusion System (IIS), Class II – Emphasizing instructions for LVP duration programming located in the IFU.
- Philips North America, IntelliVue MP60, Class II – Potential issue where the IntelliVue monitors did not alarm.
- CareFusion 303, BD PYXIS Medbank Mini, Class III – Reports of delayed access to medication in automated dispensing cabinets because of the override/Add Item workflow.
FDA Launches TEMPO
The FDA announced in December the Technology-Enabled Meaningful Patient Outcomes (TEMPO) for Digital Health Devices Pilot, a voluntary pilot designed to promote access to certain digital health devices while safeguarding patient safety. The pilot will evaluate a new, risk-based enforcement approach that supports digital health devices intended for use to improve patient outcomes in cardio-kidney-metabolic, musculoskeletal, and behavioral health conditions.
FDA Alerts to Regularly Check Diabetes-Related Smartphone Device Alert Settings
The FDA alerted patients who use diabetes devices and their caregivers of reports where users of continuous glucose monitors (CGMs), insulin pumps, automated insulin dosing systems, and other diabetes devices did not receive or did not hear alerts from their smartphones. A missed alert for a diabetes-related safety issue may lead to serious harm, including severe hypoglycemia (low blood sugar), severe hyperglycemia (high blood sugar), diabetic ketoacidosis (when the body does not have enough insulin to use blood sugar for energy), and death.
If a user’s smartphone is not configured correctly, critical safety alerts that the user expects to receive may be missed. They might not be delivered, or the volume might be too low to notice audible alerts.
Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions
The FDA issued the newest update to the Cybersecurity guidance in June 2025, which replaced the guidance from September 2023. Key changes include describing what are “cyber devices” and the implications, based on Section 524B of the FD&C Act.
This document provides the FDA’s recommendations to industry regarding cybersecurity device design, labeling, and the documentation that FDA recommends be included in premarket submissions for devices with cybersecurity risk.
This guidance also clarifies the FDA’s recommendations for cyber devices under section 524B of the FD&C Act for cyber devices. The guidance provides the following examples for internet connectivity, requiring cybersecurity:
- Network, server, or cloud service provider connections
- Radio-frequency communications (e.g., Wi-Fi, cellular, Bluetooth, Bluetooth low energy)
- Magnetic inductive communications (utilizes induced magnetic fields for short-range, low-power wireless data transfer)
- Hardware connectors capable of connecting to the internet (e.g., USB, ethernet, serial port)
Where the previous guidance referred to reasonable assurance in the context of the safety and effectiveness of the device, the new guidance is explicit that manufacturers must demonstrate a reasonable assurance of cybersecurity of their cyber device.
https://www.fda.gov/media/119933/download
Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions
The FDA released this guidance in August to provide recommendations for predetermined change control plans (PCCPs) tailored to artificial intelligence (AI)-enabled devices.
https://www.fda.gov/media/166704/download
Computer Software Assurance for Production and Quality System Software
FDA has issued this guidance in September to provide recommendations on computer software assurance for computers and automated data processing systems used as part of medical device production or the quality system. This guidance: describes “computer software assurance” as a risk-based approach to establish confidence in the automation used for production or quality systems, and identifies where additional rigor may be appropriate; and describes the various methods and testing activities that may be applied to establish computer software assurance and provide objective evidence to fulfill regulatory requirements, such as computer software validation requirements in quality system obligations.
https://www.fda.gov/media/188844/download
Considerations for the Use of Artificial Intelligence to Support Regulatory Decision-Making for Drug and Biological Products
The FDA has issued this draft guidance on the use of artificial intelligence (AI) to produce information or data intended to support regulatory decision-making regarding safety, effectiveness, or quality for drugs.
https://www.fda.gov/media/184830/download
FDA Recognized Consensus Standards
The following are the consensus standards recognized by the FDA in the second half of 2025 for STG #13 (software/informatics) :
- AAMI CR515:2025, Cybersecurity Consideration Unique to Machine-Learning Enabled Medical Devices
- ISO IEEE 11073-10472 Second edition 2024-09, Health informatics – Device Interoperability – Part 10472: Personal health device communication – Device specialization – Medication monitor
- IEEE Std 11073-10472-2023, Health informatics – Device Interoperability – Part 10472: Personal Health Device Communication – Device Specialization – Medication Monitor
- IEEE Std 11073-10421-2023, Health Informatics-Device Interoperability – Part 10421: Personal Health Device Communication – Device Specialization – Peak expiratory flow monitor (peak flow)
- ISO IEEE 11073-10421 Second Edition 2024-08, Health informatics – Device Interoperability – Part 10421: Personal health device communication – Device specialization – Peak expiratory flow monitor (peak flow)
- ISO TS 5615:2025, Health informatics – Accelerating safe effective and secure remote connected care and mobile health through standards-based interoperability solutions addressing gaps revealed by pandemics
- IEEE Std 11073-10429-2022, Health informatics – Device Interoperability – Part 10429: Personal Health Device Communication – Device Specialization – Spirometry
- IEEE Std 11073-10442-2023, Health informatics – Device Interoperability Part 10442: Personal health device communication – Device specialization – Strength fitness equipment
- IEEE Std 11073-10471-2023, Health Informatics – Device interoperability – Part 10471: Personal health device communication – Device specialization – Independent living activity hub
- ISO IEEE 11073-10471 Second Edition 2024-09, Health Informatics – Device Interoperability – Part 10471: Personal Health Device Communication – Device Specialization-Independent Living Activity Hub
Medical Devices that Incorporate Sensor-based Digital Health Technology (sDHT)
The FDA encourages the development of innovative, safe, and effective medical devices, including devices that incorporate sensor-based digital health technology (sDHT).
The sDHT medical device list is a resource intended to identify sDHT medical devices that are authorized for marketing in the United States. Digital health innovators can refer to this list to gain insights into the current device landscape and regulatory expectations, which helps foster innovation of safe and effective devices. This list can also provide transparency to health care providers and patients to clearly identify when medical devices use sDHT. In addition, this list can further support the incorporation of sDHTs in medical product development programs, as appropriate.
In a recently published update of digital health technologies listings, the FDA has consolidated their approved devices and SaMD listings for sensors (sDHT), AI medical devices and AR/VR. The FDA enables the development of innovative, safe, and effective medical devices that incorporate digital health technologies.
MDCG 2019-11 Rev.1
The CE released this Guidance on Qualification and Classification of Software in Regulation (EU) 2017/745 – MDR and Regulation (EU) 2017/746 – IVDR in June.
https://health.ec.europa.eu/document/download/b45335c5-1679-4c71-a91c-fc7a4d37f12b_en?filename=mdcg_2019_11_en.pdf
MDCG 2025-6
The CE released in June this FAQ on Interplay between the Medical Devices Regulation (MDR) & In vitro Diagnostic Medical Devices Regulation (IVDR) and the Artificial Intelligence Act (AIA).
MDCG 2025-4
The CE released in June the Guidance on the safe making available of medical device software (MDSW) apps on online platforms.
CDRH Proposed Guidances for Fiscal Year 2026
A-List Final Guidance Topics
- Use of Real-World Evidence to Support Regulatory Decision-Making for Medical Devices
- Predetermined Change Control Plans for Medical Devices
A-List Draft Guidance Topics
- Policy for Device Software Functions (title changed from “Policy for Device Software Functions and Mobile Medical Applications”)
B-List Final Guidance Topics
- Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management Considerations and Marketing Submission Recommendations
- Content of Human Factors Information in Medical Device Marketing Submissions
White House releases AI Action Plan, looks to speed adoption in healthcare
The White House released its AI Action Plan in July, which focused on deregulating the technology, establishing regulatory sandboxes to test artificial intelligence innovation and promoting standards for the technology.
While healthcare is only directly mentioned a few times in the 28-page document, many of the proposals could potentially impact healthcare AI innovators.
The AI Action Plan has three pillars: accelerating AI innovation, building American AI infrastructure and leading in international AI diplomacy and security.
To accelerate AI innovation in the U.S., the White House says it will cut “bureaucratic red tape” hindering American industries.
Trump directive to agencies could chop healthcare regulations faster than expected
The National Institute of Standards and Technology (NIST) will play a significant role in Trump’s America First AI agenda. The NIST will launch domain-specific efforts, including in healthcare, to convene stakeholders to develop and adopt standards for AI and measure how AI increases productivity.
Proposed changes to IEC 62304 Edition 2
- Change of Scope – IEC 62304 is currently the standard for medical device software where IEC 82304 relates to heath software. Under the change, IEC 62304 will be the standard for all medical device and health software.
- Risk Classification to Rigor Level – this new version of IEC 62304 replaces the three software safety classifications (Class A, Class B and Class C) with a two “rigor level” model. Effectively, this moves all Class B software into Class C (and all the extra requirements that come with it). While this simplifies the decision process for rigor level, this will add a large number of requirements and associated documentation) for software currently sat under Class B.
- Software Development Process – There are key revisions to the Software Development Plan, Software Requirements Analysis, and Software Architecture Design sections. These changes should enhance clarity and consistency in the software development lifecycle.
- Removal of reference to ISO 13485 and ISO 14971 – This new version of IEC 62304 has removed any reference to ISO 13485 and ISO 14971 for two technical reasons:
- The new scope of the standard includes all health software, not just medical devices (SaMD and SiMD), and non-medical device health software is not obliged to follow ISO 13485 or ISO 14971, so they cannot be made a requirement of IEC 62304.
- IEC 62304 is a standard about how to design software and not how to meet general regulatory requirements. Does this mean medical device software developers can stop following ISO 13485 and ISO 14971? NO!
- AI Health Software Development – There is only one AI-specific requirement with guidance for AI as a Medical Device (AIaMD) developers on how best to plan, assess and confirm their AI development.
- Legacy Software – Legacy software was covered in section 4 of the standard and was over indulged. In the new version it has been moved to an Annex.
- Maintenance vs Development – This new version of the standard makes clear the distinction between Software Maintenance and Development which was intended but not clear in the previous Development includes the creation of new software as well as the introduction of new features or changes to existing software, whereas Maintenance permits the developer to use a smaller process to implement rapid changes in response to urgent problems.
When will the changes to IEC 62304 come into effect? This new draft is proposed to be released by August 2026. Assuming this will be approved, we should see it sometime around 2028-2029.
Health software and health IT systems safety, effectiveness and security — Part 5-1: Security — Activities in the product life cycle
IEC 81001-5-1 is the standard used by the Notified Bodies for cybersecurity in medical devices. It is not yet harmonized, but is considered state-of-the-art and the NB expects you to meet these requirements.
How Frequently Can you Release Medical Device Software?
We have been asked numerous times by our clients: “How frequently can we release our medical-device software?” Usually, the person asking is a software-engineer who has used agile in another field and is used to frequent rapid releases.
The short answer is: You can release software updates as frequently as you want so as long as:
- The changes don’t require regulatory submissions
- You can produce all of the necessary design change documentation.
In practice, we’ve seen software development firms who can release updates as quickly as every two weeks. Usually, however, monthly or quarterly releases are more realistic.
If you need more information on this, please contact us.
Tools to Investigate
We are recommending the use of various tools in order to make the FDA/CE happy and, at the same time, improve the quality of the software. These tools include (but definitely not limited to):
- AI for code reviews
- Defect management
- Code control
- Static code analysis
- Dynamic code analysis
- Unit and integration testing
- Continuous integration
- Penetration testing
- Functional safety
- SBOM
When choosing the tools, check the local support. Even though everyone offers Internet support, nothing beats having the support done locally by someone who has the experience and speaks your language. For further information concerning the tools, please feel free to contact us and we’ll refer you to the tool vendors with the tools you need.
Various tools to think about (they cost a little money but will save much more):
- Static Code Analysis – Parasoft, Coverity, Polyspace, SonarQube, Axivion, PQRA, Klocwork, Grammatech, LDRA, IAR C-STAT
- SBOM – MergeBase, FOSSA, Sonatype, Insignary, Snyk
- Defect management – Jira, Asana, Azure DevOps
- Unit & integration testing – Cantata
- Safe embedded operating systems – Seggar RTOS
If you need more information on the tools and where to purchase them (with support), please contact us.
Summary
There are many ways to screw up your software in the medical device whether it is embedded in dedicated hardware (also known as SiMD – Software in a Medical Device) or stand-alone health software (also known as SaMD – Software as a Medical Device). The latest buzz words are: Sensor-based Digital Health Technology, aka sDHT. Many companies are incorporating sensors into their devices and the FDA realizes that this is becoming very common.
It doesn’t take too much talent to do this (as we all know) and companies are doing it daily. Many companies mess up royally and don’t know how to get out of the mess. In many cases, they don’t even know that they are in deep trouble until the recall is issued.
You can work properly without breaking the bank. There are many ways to handle the software development/maintenance life cycle and the software validation.
If there are any questions or requests, please feel free to contact us.
Mike