The Impact of Regulations on Medical Device Design Richard C. Fries, PE, CRE Manager, Reliability Engineering Datex-Ohmeda Madison, Wisconsin.

Slides:



Advertisements
Similar presentations
PRINCIPLES OF A CALIBRATION MANAGEMENT SYSTEM
Advertisements

Medical Device Software Development
ISO 9000 Quality Standards ISO 9000 describes quality assurance elements in generic terms that can be applied to any business. It treats an enterprise.
HIPAA. What Why Who How When What Is HIPAA? Health Insurance Portability & Accountability Act of 1996.
Confidentiality and HIPAA
HIPAA Privacy Rule Training
COBB/DOUGLAS COMMUNITY SERVICES BOARD Confidentiality and Privacy of Consumer Information.
HIPAA PRIVACY REQUIREMENTS Dana L. Thrasher Constangy, Brooks & Smith, LLC (205) ; Victoria Nemerson.
HIPAA Health Insurance Portability and Accountability Act.
What is HIPAA? This presentation was created by The University of Arizona Privacy Office, The Office for the Responsible Conduct of Research on March 5,
WHAT IS HIPAA? The Health Insurance Portability and Accountability Act of 1996 (HIPAA) provides certain protections for any of your health information.
 The Health Insurance Portability and Accountability Act of  Federal Law designed to protect sensitive information.  HIPAA violations are enforced.
HIPAA HIPAA Health Insurance Portability and Accountability Act of 1996.
Professional Nursing Services.  Privacy and Security Training explains:  The requirements of the federal HIPAA/HITEC regulations, state privacy laws.
GMP Document and Record Retention
SAE AS9100 Quality Systems - Aerospace Model for Quality Assurance
Quality Management System
ISO 9001 Interpretation : Exclusions
HIPAA: It Doesn’t Only Impact Medical Records Basic HIPAA Stuff and Overall Information Protection 1.
External Defibrillators: Recalls, Inspections, and the Quality System Regulation Melissa Torres Office of Compliance December 15, 2010.
ISO 9000 Certification ISO 9001 and ISO
HIPAA Health Insurance Portability & Accountability Act of 1996.
Health Insurance Portability and Accountability Act (HIPAA)
ISO 9000 Introduction Imran Hussain.
ISO 9000 Overview The Purpose of this Overview l “What is ISO 9000?” l What will it require from YOU, as a (Company) Employee?
Huzairy Hassan School of Bioprocess Engineering UniMAP.
QUALITY MANAGEMENT SYSTEM ACCORDING TO ISO
Objectives 4 Understand the ISO standards. Why are standards required? 4 Need standards to ensure that a term means the same for all 4 Need company standards.
FDA Regulatory review in Minutes: What Product Development Executives Need-to-Know. Specifically, frequent causes of recalls and related areas that investigators.
HIPAA PRIVACY AND SECURITY AWARENESS.
1 © Mahindra Satyam 2009 Quality Management System Mahindra Satyam’s Quality Guide ISO Slides.
HIPAA OBJECTIVES  Define HIPAA  Define PHI  Use of PHI  Your rights  Your responsibilities.
1 HIPAA OVERVIEW ETSU. 2 What is HIPAA? Health Insurance Portability and Accountability Act.
ISO 9000 & TOTAL QUALITY ISO 9000 refers to a group of quality assurance standards established by the International Organization for Standardization.This.
Health Insurance Portability and Accountability Act (HIPAA)
PRIVACY AND HIPAA THE RIGHT THING TO DO. WHAT’S WRONG WITH THIS PICTURE? ? “ Did you hear that Jane from the 5 th floor is in the hospital?” “No!! Let’s.
How Hospitals Protect Your Health Information. Your Health Information Privacy Rights You can ask to see or get a copy of your medical record and other.
Product Development Chapter 6. Definitions needed: Verification: The process of evaluating compliance to regulations, standards, or specifications.
© 2009 The McGraw-Hill Companies, Inc. All rights reserved. 1 McGraw-Hill Chapter 2 The HIPAA Privacy Standards HIPAA for Allied Health Careers.
Health Insurance Portability and Accountability Act (HIPAA) CCAC.
Health Insurance Portability and Accountability Act of 1996 HIPAA Privacy Training for County Employees.
Understanding HIPAA (Health Insurandce Portability and Accountability Act)
© 2013 The McGraw-Hill Companies, Inc. All rights reserved. Ch 8 Privacy Law and HIPAA.
FleetBoston Financial HIPAA Privacy Compliance Agnes Bundy Scanlan Managing Director and Chief Privacy Officer FleetBoston Financial.
Copyright ©2014 by Saunders, an imprint of Elsevier Inc. All rights reserved 1 Chapter 02 Compliance, Privacy, Fraud, and Abuse in Insurance Billing Insurance.
Joel Gerber Zachary Reaver Kurt Schilling.  Provides physical proof of development  Maintains product design knowledge base  Meets government and corporate.
Quality Standards ISO:9000 ISO:9000 Quality Systems Under ISO:9000 Quality Systems Under ISO:9000 ISO:14000 ISO:14000 ISO Certification Process ISO Certification.
R EGULATING THE IMPORTATION & USE OF MEDICAL DEVICES.
ISO 9001:2015 Subject: Quality Management System Clause 8 - Operation
HIPAA HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT UI EMS Training Dept.
WORKSHOP ON ACCREDITATION OF BODIES CERTIFYING MEDICAL DEVICES INT MARKET TOPIC 9 CH 8 ISO MEASUREMENT, ANALYSIS AND IMPROVEMENT INTERNAL AUDITS.
 Health Insurance and Accountability Act Cornelius Villalon Jr.
Workshop on Accreditation of Bodies Certifying Medical Devices Kiev, November 2014.
The Health Insurance Portability and Accountability Act of 1996 “HIPAA” Public Law
Update of API Standards for Supply Chain Management API Standard 20J – Qualification of Distributors.
What is HIPAA? Health Insurance Portability and Accountability Act of HIPAA is a major law primarily concentrating on the prolongation of health.
Complaint Handling Medical Device Reporting May 19, 2016 Rita Harden, Director Customer Relations & Regulatory Reporting.
Device regulations USA Dr Phil Warner. USA Regulations MEDICAL DEVICES Food, Drug & Cosmetics Act Medical Device Amendments of 1976 (and other things)
HIPAA Privacy Rule Training
Medical Device Software Development
HIPAA PRIVACY & SECURITY TRAINING
Contingent Workforce: Cerner Quality System & Regulations
External Validation of Quality Programs
Proposal for a Regulation on medical devices and Proposal for a Regulation on in vitro diagnostic medical devices Key Provisions and GIRP Assessment.
Disability Services Agencies Briefing On HIPAA
ISO 9000 Dr. S. Thomas Foster, Jr..
Medical Device Design and Development
HIPAA Overview.
External Validation of Quality Programs
Presentation transcript:

The Impact of Regulations on Medical Device Design Richard C. Fries, PE, CRE Manager, Reliability Engineering Datex-Ohmeda Madison, Wisconsin

Extra Activities for Regulated Industries *Develop and maintain a Quality System *Product Documentation »Design History File »Technical File *Product submissions *Testing certifications *Extra time for: »Submissions »Answer questions from regulators »Re-submissions *Audits

The Typical Road to Market for a Non- Medical Device *Generate a new idea for a product *Design the product *Test the product *Manufacture the product *Ship the product

The Typical Road to Market for a Medical Device *Generate a new idea for a product *Design the product *Test the product *Submit data to the regulatory agency *Wait *Manufacture the product *Ship the product

Timing of Product Development *Establish a window of opportunity to sell the product *Determine the amount of time to manufacture the product *Determine the amount of time for regulatory approval *Determine the amount of time to test the product *Determine the amount of time to design the product *Determine the amount of time to specify the product *Start the development cycle

Types of Regulations *Process »ISO 9000 family »Audits by Notified Bodies *Product »Food and Drug Administration (FDA) »Medical Device Directive (MDD) »Individual country requirements (Canada, Australia, Japan, Russia) »City of Los Angeles »Other standards required for certain products »Environmental standards

Process Regulations *Basis for product regulations *Requires the company to show an experienced quality system in place *ISO 9000 family used as the gold standard *For companies with design capabilities, ISO 9001 is the foundation *For medical device companies, ISO is beginning to be accepted

ISO 9001 *Management responsibility *Quality system *Contract review *Design control *Document and data control *Purchasing *Control of customer supplied product *Product identification and traceability *Process control *Inspection and testing

ISO 9001 *Control of inspection, measuring, and test equipment Inspection and test status *Control of non-conforming product *Corrective and preventive action *Handling, storage, packaging, preservation, and delivery *Control of quality records *Internal quality audits *Training *Servicing *Statistical techniques

Design Control *Design and development planning *Organizational and technical interfaces *Design input *Design output *Design review *Verification *Validation *Design changes

Product Regulations *United States »FDA *Europe »Medical Device Directive *Other Countries »Australia »Canada »Japan »Russia

Food and Drug Administration *Quality system *Testing to prove the safety and efficacy of your product *Submission material dependent on the type of product you are making *Particular attention to software *MDRs *Recalls *Audits

Food and Drug Administration *Safety and efficacy: »Requirement verification »Risk analysis »Environmental testing »Clinical testing

Food and Drug Administration *Submissions: »Class ILittle regulation »Class II510(k) »Class IIIPMA

FDA 2004 User Fees *Large business: *510(k)$ 3,480 *PMA$206,811 »180 day supplement$ 44,464 »Real-time supplement$ 14,890

FDA 2004 User Fees *Small business: *510(k)$ 2,784 *PMA$ 78,588 »180 day supplement$ 16,896 »Real-time supplement$ 5,658

Food and Drug Administration *Software: »Based on an bad experience in Canada »FDA doesn’t understand it »Therefore, they over-regulate it »All current regulations are in draft form »Software in a device is the same level as the device »Excess documentation required »Auditors free to regulate according to their own principles

Food and Drug Administration *MDRs and Recalls: »MDR: a report sent to the FDA detailing the circumstances of your device killing or causing serious injury to a patient »The FDA also gets a report from the hospital or clinic where the situation occurred »Recall: a detailed plan for making design changes in all your devices currently in the field

Food and Drug Administration *Audits: »General »Triggered by submissions »Triggered by field failures »Triggered by unsolicited information

Medical Device Directive *Required for selling a product in Europe *Product must contain a CE mark *Must have a quality system *Product must meet a list of essential requirements *Certificates for all testing

Medical Device Directive Process *Analyze the device to determine which directive is applicable *Identify the applicable Essentials Requirements List *Identify any corresponding Harmonized standards *Confirm that the device meets the Essential requirements/Harmonized Standards and document the evidence *Classify the device

Medical Device Directive Process *Decide on the appropriate conformity assessment procedure *Identify and choose a notified body *Obtain conformity certifications for the device *Establish a Declaration of Conformity *Apply for the CE mark

Medical Device Directive *Three directives: »Active Implantable Medical Devices Directive (AIMDD) »Medical Devices Directive (MDD) »In Vitro Diagnostic Medical Devices Directive (IVDMDD)

Essentials Requirements List

Declaration of Conformance *Every device, other than a custom-made or clinical investigation device, must be covered by a declaration of conformity *Document that states you have met all the essential requirements for your device *Must include the serial numbers or batch numbers of the products it covers *Signed by a member of Senior Management

The CE Mark XXXX

Difference Between FDA and MDD *FDA: *A submission must be sent to the FDA for each product to be marketed *Must wait for approval *MDD: *A company may qualify for self-certification to MDD for their products. These are checked during scheduled audits.

Other Product Regulations *Countries »Japan »Australia »China »Russia *Type of Device »Alarms »Software *Environmental »EMC »Temperature/Humidity »Shipping

Audits *1-4 people in your spaces for 3 days to several months

Audits *Will cover in detail your process and products *Auditors will “dig-in” in they find the hint of a problem *Major discrepancies will shut you down until they are fixed *Legal and/or punitive steps may be taken

Newest of the Regulations *HIPAA *Health Insurance Portability and Accountability Act *Main components are Privacy and Security

Protected Health Information (PHI) *PHI is health Information that: 1) is created or received by a health care provider, health plan, employer, or health care clearinghouse, and 2) relates to the past, present, or future physical or mental health or condition of an individual, the provisions of health care to an individual, or the past, present, or future payment for the provision of health care to an individual, and i) that identifies the individual or ii) with respect to which there is a reasonable basis to believe the information can be used to identify the individual.

Protected Health Information (PHI) *Any health information that can be identified to a person *It includes information about treatment and care *PHI can include: »Name »Dates »Record number »Social security number »Full face photo »Any other unique identifying information

De-Identification *Patient information from which identifiers have been deleted, redacted, or blocked, so that remaining information cannot reasonably be used to identify a person. Identifiers to be deleted include: »Name »Social security number »Address »Telephone number »Birth date »Admission date »FAX numbers » addresses »Medical record numbers »Health plan beneficiary numbers »Account numbers »Certification/license numbers »Full face photos.

Civil Penalties for Non-Compliance *$100 for each violation *Total of $25,000 for all violations of an identical requirement in a calendar year

Criminal Penalties for Wrongful Obtainment/Disclosure of PHI *Not more than $50,000 and/or not more than 1 year impisonment *Not more than $100,000 and/or not more than 5 years imprisonment if the offense is “under false pretenses” *Not more than $250,000 and/or not more than 10 years imprisonment for the intent to sell, use for commercial advantage, personal gain, or malicious harm Protected Health Information

HIPAA Philosophy What I see here, What I hear here, When I leave here, Remains here!