Life Sciences & HealthcareOctober 24, 2019

What Medical Device Companies Must Know To Comply

Medical device companies who want to bring devices and solutions to market…
Avatar Shashank Nanivadekar

Medical device companies who want to bring devices and solutions to market in North America must abide by strict FDA regulations to ensure that they’re essentially making the right devices the right way.

Patient safety is a complex, multivariate, and multi-faceted problem because in addition to the obvious technical considerations a device company needs to make prior to submitting for and even after receiving a 510(k) clearance or Pre Market Authorization (PMA) approval, the factors they need to consider extend beyond the device itself.

The FDA’s 21 CFR Part 820 is designed to determine what a medical device company needs to factor in during the months and years that lead up to their application for a 510(k) or PMA. Documents that they need to submit in their bid to bring a product to market include a Design History File (DHF), Device Master Records (DMR), and a Device History Record (DHR).

As device and design data is of prime importance, so is the need to record and maintain all communications, reviews, approvals, and signatures, that are part of the device’s lifecycle up and down the supply-chain. Being able to record and trace all the considerations that go into making device and design level decisions ultimately impact patient-level decisions and patient quality of life.

What Does All This Have To Do With 21 CFR Part 11?

Traditionally, all documentation that medical devices gathered has been paper-based. Since 1997, however, the FDA established the criteria of acceptance for electronic records, signatures, and handwritten signatures executed to electronic documents.

In order to be 21 CFR Part 11 compliant in record keeping by FDA standards, medical device companies need to understand how the FDA views any record that a company creates, modifies, maintains, archives, retrieves, and/or transmits during the device’s lifecycle.

Records and signatures primarily need to have three key aspects:

  • Unique authentication
  • Completeness
  • Security

The FDA defines criteria for these in the context of electronic records in 21 CFR Part 11 Subpart B, and in the context of the actual electronic signatures in Subpart C.

Electronic Records

Controls For Closed And Open Systems

Whether you use a closed or open system to manage and keep records, the key priorities are authenticity, integrity, and confidentiality of the record. Anyone contributing to a record, either by approval, stamping, reviewing, or creating it is not able to repudiate the record. This means controlling system access and providing the right level of system access to each user. This is done to ensure only those who should provide approval are authorized to do so.  For open systems, administrators need to ensure authenticity, integrity, and confidentiality of a record from the time it is created all the way until it is received by the responsible authority or recipient.

Signature Manifestations

Signed electronic records need to show the printed name, date and time of the signature and also whether the signature indicates that it is a review, approval, authorship, or responsibility.

Signature And Record Linking

Electronic signatures and handwritten signatures executed to electronic records should be linked to the correct electronic records. This is done to create clear traceability and make it harder for anyone to try to falsify electronic records by copying signatures.

Electronic Signatures

Electronic Signatures And Controls

Signatures collected electronically must be completely genuine. This is of prime importance otherwise anyone can sign for the designated authority with impunity and that exposes a lot of risk. Unique identification of people interacting with electronic records to create, authorize, approve, review, or authenticate must be tied to their unique identification and password. It goes without saying that User IDs and passwords should only be used by those to whom the ID belongs.

Controls For Identification Codes And Passwords

While it doesn’t need to be said that you must keep your user IDs and passwords secure, password security is still a very pressing issue for cyber-safety and cybersecurity. Passwords can be compromised through many different ways, so preserving the integrity of user IDs and passwords is critical to ensure no data and approval record is lost, stolen, missing, or otherwise compromised.

A key requirement for any company trying to take their record-keeping and approvals paperless needs to make 21 CFR part 11 compliance a key focus. The ability of users to create, maintain, and authorize the authenticity of records in a secure and safe manner lies entirely in their ability to uniquely perform these tasks. Medical device companies who prioritize paperless initiatives can then have a chance to automate approvals, collaboration, and accelerate their time to market. Going paperless is the seed to that vision.

Learn more about how compliant systems can be used to automate key functions and accelerate medical devices to market at Accelerate 2019 in Waltham, MA on Nov 19-20.  Register to attend now.

Editor’s Note: See how Dassault Systèmes is driving digital transformation in the Life Sciences industry.

Stay up to date

Receive monthly updates on content you won’t want to miss


Register here to receive a monthly update on our newest content.