[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"skill-aws-labs-medical-device-software-compliance":3,"mdc--1g3c41-key":50,"related-org-aws-labs-medical-device-software-compliance":2709,"related-repo-aws-labs-medical-device-software-compliance":2891},{"slug":4,"name":4,"fn":5,"description":6,"org":7,"tags":12,"stars":26,"repoUrl":27,"updatedAt":28,"license":29,"forks":30,"topics":31,"repo":45,"sourceUrl":48,"mdContent":49},"medical-device-software-compliance","assess software for medical device compliance","Reason about SaMD (Software as a Medical Device) regulatory compliance for FDA, EU MDR, and global submissions. Use when the user asks about IEC 62304 safety classification, ISO 14971 risk management, 21 CFR 820\u002FQMSR quality system requirements, Design History File structure, 510(k)\u002FDe Novo\u002FPMA pathway selection, SOUP\u002FOTS assessment, verification and validation planning, cybersecurity for medical devices, PCCP for AI\u002FML devices, design reviews, traceability matrices, or post-market surveillance. Triggers include \"SaMD\", \"medical device software\", \"IEC 62304\", \"ISO 14971\", \"ISO 13485\", \"21 CFR 820\", \"QMSR\", \"510(k)\", \"De Novo\", \"PMA\", \"design history file\", \"DHF\", \"software safety classification\", \"SOUP list\", \"risk management\", \"hazard analysis\", \"design review\", \"V&V protocol\", \"FDA submission\", \"EU MDR\", \"clinical evaluation\", \"PCCP\", \"predetermined change control\", \"GMLP\", \"cybersecurity premarket\", \"Part 11\", \"design controls\", \"design inputs\", \"design outputs\", \"traceability matrix\", \"post-market surveillance\", \"CAPA\", \"Class II device\", \"Class III device\", \"regulatory pathway\", \"predicate device\", \"substantial equivalence\".",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},"aws-labs","AWS Labs","https:\u002F\u002Fpexgzepcugksgbtrxkhf.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Forg-logos\u002Faws-labs.png","awslabs",[13,17,20,23],{"name":14,"slug":15,"type":16},"Healthcare","healthcare","tag",{"name":18,"slug":19,"type":16},"FDA","fda",{"name":21,"slug":22,"type":16},"Regulatory Compliance","regulatory-compliance",{"name":24,"slug":25,"type":16},"Risk Assessment","risk-assessment",4,"https:\u002F\u002Fgithub.com\u002Fawslabs\u002Fhcls-agent-skills","2026-07-25T05:56:34.955181",null,0,[32,33,34,35,36,37,38,39,40,41,42,43,44],"agent-skills","agentcore","ai-agents","amazon-quick-desktop","claims-processing","drug-discovery","genomics","healthcare-ai","kiro","life-sciences","medical-imaging","risk-adjustment","strands-agents",{"repoUrl":27,"stars":26,"forks":30,"topics":46,"description":47},[32,33,34,35,36,37,38,39,40,41,42,43,44],"Agent skills for healthcare and life sciences: genomics, imaging, claims, drug discovery, and more. Works with Amazon Quick, Kiro, Amazon AgentCore, AWS Strands SDK, Claude Code, Codex, and any Agent Skills-compatible platform.","https:\u002F\u002Fgithub.com\u002Fawslabs\u002Fhcls-agent-skills\u002Ftree\u002FHEAD\u002Fskills\u002Fmedical-device-software-compliance","---\nname: medical-device-software-compliance\ndescription: 'Reason about SaMD (Software as a Medical Device) regulatory compliance for FDA, EU MDR, and global submissions. Use when the user asks about IEC 62304 safety classification, ISO 14971 risk management, 21 CFR 820\u002FQMSR quality system requirements, Design History File structure, 510(k)\u002FDe Novo\u002FPMA pathway selection, SOUP\u002FOTS assessment, verification and validation planning, cybersecurity for medical devices, PCCP for AI\u002FML devices, design reviews, traceability matrices, or post-market surveillance. Triggers include \"SaMD\", \"medical device software\", \"IEC 62304\", \"ISO 14971\", \"ISO 13485\", \"21 CFR 820\", \"QMSR\", \"510(k)\", \"De Novo\", \"PMA\", \"design history file\", \"DHF\", \"software safety classification\", \"SOUP list\", \"risk management\", \"hazard analysis\", \"design review\", \"V&V protocol\", \"FDA submission\", \"EU MDR\", \"clinical evaluation\", \"PCCP\", \"predetermined change control\", \"GMLP\", \"cybersecurity premarket\", \"Part 11\", \"design controls\", \"design inputs\", \"design outputs\", \"traceability matrix\", \"post-market surveillance\", \"CAPA\", \"Class II device\", \"Class III device\", \"regulatory pathway\", \"predicate device\", \"substantial equivalence\".'\nusage: Invoke when evaluating SaMD regulatory compliance or planning FDA\u002FEU MDR submissions.\nversion: 1.0.0\ntags: [skill, category:reasoning, samd, fda, iec-62304, iso-14971, iso-13485, regulatory, medical-device, hcls]\n---\n\n# SaMD Compliance — Reasoning Skill\n\n## Overview\n\nYou are an expert in Software as a Medical Device (SaMD) regulatory compliance. When the\nuser asks about FDA software device submissions, IEC 62304 lifecycle, ISO 14971 risk\nmanagement, design controls, or global regulatory strategy, apply the decision frameworks\nbelow.\n\n## Usage\n\n- Invoke when evaluating SaMD regulatory compliance for FDA, EU MDR, or multi-market submissions\n- Use when planning design controls, risk management, V&V, or submission strategy\n- Activate for safety classification, SOUP assessment, or AI\u002FML device lifecycle questions\n\n---\n\n## Response Format\n\n- Lead with the direct recommendation or classification (≤3 sentences)\n- Structure as: recommendation → justification (citing specific standards\u002Fclauses) → caveats\n- Use tables for comparisons; bullet points for criteria lists\n- Omit background the user already knows — they asked the question\n- Target: 200-400 words unless the user requests exhaustive detail\n\nThe decision trees and frameworks in this skill are for internal reasoning only. Apply them to reach your conclusion, but do not reproduce them in your response. Present only the final recommendation with supporting evidence.\n\n---\n\n## 1. IEC 62304 Safety Classification Decision Tree\n\n```\nDoes the software system contribute to a hazardous situation?\n├─ No → Class A (no injury possible)\n│  Requirements: Basic documentation, no architecture decomposition required\n├─ Yes, but not SERIOUS injury → Class B (non-serious injury possible)\n│  Requirements: Architecture documentation, SOUP risk analysis, unit testing ≥80%\n└─ Yes, SERIOUS injury or DEATH possible → Class C (serious injury\u002Fdeath possible)\n   Requirements: Detailed design, full SOUP verification, unit testing ≥95%,\n                 additional detailed architecture documentation\n\nCan harm be mitigated by external measures (hardware, clinical workflow)?\n├─ Yes, reduced to non-serious → Downgrade to Class B\n│  Document: Mitigation measure, residual risk, why measure is reliable\n└─ No reliable external mitigation → Stays Class C\n\nClass determination timing:\n├─ At system level: Assign initial class based on intended use\n├─ At software item level: May assign LOWER class if item is isolated\n│  Condition: Item cannot contribute to higher-class hazard\n└─ NEVER assign lower class at system level than hazard analysis supports\n```\n\n## 2. FDA Regulatory Pathway Decision Tree\n\n```\nIs the device substantially equivalent to a legally marketed predicate?\n├─ Yes, same intended use + same\u002Fdifferent technology (equiv. safety\u002Fefficacy)\n│  └─ 510(k) — Demonstrate substantial equivalence\n│     Timeline: 3-6 months (traditional), 6-12 months (special)\n├─ No predicate, but low-to-moderate risk (Class I or II)\n│  └─ De Novo — Establish new classification with general\u002Fspecial controls\n│     Timeline: 9-12 months\n│     Note: Creates a new predicate for future 510(k)s\n├─ High risk, Class III, life-sustaining\u002Fsupporting\n│  └─ PMA — Full clinical evidence, manufacturing controls\n│     Timeline: 12-24+ months\n└─ Clinical Decision Support meeting Cures Act Section 3060(a)?\n   All 4 criteria met:\n   1. Not intended to acquire\u002Fprocess\u002Fanalyze medical images\u002Fsignals\n   2. Intended for healthcare professionals (not patients)\n   3. Intended to enable HCP to independently review basis\n   4. Intended as aid (not to replace clinical judgment)\n   └─ Exempt from device regulation — document determination\n```\n\n## 3. Design Controls Lifecycle (21 CFR 820.30 \u002F QMSR)\n\n| Phase | Key Output | IEC 62304 Mapping | Blocking Gate |\n|-------|-----------|-------------------|---------------|\n| User Needs | User Needs Document | §5.2 Software requirements process | None |\n| Design Input | SRS (Software Requirements Spec) | §5.2.1-5.2.6 Requirements | DR1 |\n| Design Output | Architecture + Detailed Design | §5.3 Software architectural design | DR2 |\n| Verification | Test protocols + reports | §5.5 Software integration testing, §5.6 System testing | DR3 |\n| Validation | Clinical validation evidence | §5.7 Software release | Submission |\n| Transfer | Manufacturing\u002Fdeployment procedures | §5.8 Maintenance process | Release |\n| Changes | Design change assessment | §5.2 (re-entry) | Per-change |\n\n**Critical rule:** Design Reviews (DR1, DR2, DR3) are BLOCKING for Class B\u002FC devices. Each requires documented attendees, findings, and formal sign-off.\n\n## 4. SOUP\u002FOTS Assessment Framework\n\n### Risk-Based SOUP Classification\n\n```\nIs the SOUP item's failure capable of contributing to a hazardous situation?\n├─ No → Low-risk SOUP\n│  Document: Name, version, intended use, license\n│  Action: Monitor for known anomalies annually\n├─ Yes, contributes to Class B hazard → Medium-risk SOUP\n│  Document: Above + known anomalies list, mitigation for each\n│  Action: Version pin, anomaly monitoring, update assessment per release\n└─ Yes, contributes to Class C hazard → High-risk SOUP\n   Document: Above + detailed integration testing, published problem reports\n   Action: Above + verify adequate testing by SOUP vendor, consider alternatives\n\nSOUP Acceptance Criteria:\n├─ Vendor maintains the software (active development)? → Preferred\n├─ Known anomaly list published? → Required for Class B\u002FC\n├─ CVE history acceptable? → No unresolved critical CVEs\n└─ License compatible with medical device distribution? → Required\n```\n\n### SOUP vs Custom Decision\n\n| Factor | Use SOUP | Build Custom |\n|--------|----------|-------------|\n| Well-validated open source library | ✅ | |\n| Critical safety function with no validated library | | ✅ |\n| Standard utility (logging, HTTP, encryption) | ✅ | |\n| Regulatory precedent for the library | ✅ | |\n| SOUP vendor unresponsive to anomaly reports | | ✅ |\n| Time-to-market critical, library mature | ✅ | |\n\n## 5. ISO 14971 Risk Management Process\n\n### Severity Classification\n\n| Level | Description | Examples | Acceptable Probability |\n|-------|-------------|----------|----------------------|\n| S1 | Negligible | Inconvenience, no injury | Any |\n| S2 | Minor | Temporary minor injury | Occasional |\n| S3 | Serious | Injury requiring intervention | Remote |\n| S4 | Critical | Permanent impairment | Improbable |\n| S5 | Catastrophic | Death | Improbable |\n\n### Risk Control Priority (ISO 14971 §7.1)\n\n```\nRisk exceeds acceptability threshold?\n├─ Option 1: Inherent safety by design (ALWAYS try first)\n│  Example: Eliminate hazard entirely via architecture\n├─ Option 2: Protective measures in device or manufacturing\n│  Example: Software watchdog, timeout, bounds checking\n├─ Option 3: Information for safety (warnings, labeling, training)\n│  Example: Clinical alert, user manual warning\n└─ NEVER: Skip to Option 3 without documenting why Options 1-2 are infeasible\n\nResidual Risk Assessment:\n├─ Individual residual risk acceptable? → Document and proceed\n├─ Individual unacceptable but reducible? → Apply additional controls\n└─ Overall residual risk vs. benefit determination\n   Required: Document benefit-risk analysis for entire device\n```\n\n### Hazard Analysis Common Pitfalls\n\n1. **Wrong:** Listing software bugs as hazards\n   **Right:** Trace bug → hazardous situation → harm. The HARM is what matters.\n2. **Wrong:** Copying generic hazard lists without device-specific analysis\n   **Right:** Analyze YOUR device's specific failure modes in YOUR clinical context\n3. **Wrong:** Assuming software cannot cause physical harm\n   **Right:** Delayed diagnosis, wrong treatment recommendation, alert fatigue ALL cause harm\n4. **Wrong:** Risk controls that rely entirely on user vigilance\n   **Right:** Design-level controls first; training\u002Fwarnings are last resort\n\n## 6. V&V Planning by Safety Class\n\n| Activity | Class A | Class B | Class C |\n|----------|:-------:|:-------:|:-------:|\n| Requirements traceability | ✅ | ✅ | ✅ |\n| Unit testing | Optional | ≥80% coverage | ≥95% coverage |\n| Integration testing | Optional | ✅ | ✅ + fault injection |\n| System testing | ✅ | ✅ | ✅ + stress\u002Fboundary |\n| Regression testing | On change | Full suite | Full suite + risk-based |\n| Clinical validation | If claimed | If claimed | ✅ Mandatory |\n| Cybersecurity testing | If connected | ✅ Penetration test | ✅ Full threat model |\n| Usability validation | If HCP user | ✅ Formative | ✅ Summative |\n\n### V&V Failure Recovery Decision Tree\n\n```\nTest fails acceptance criteria\n├─ Safety-related requirement?\n│  ├─ Yes → MUST fix before release (no exceptions)\n│  └─ No → Evaluate options below\n├─ Options:\n│  A) Fix defect and retest (preferred)\n│  B) Lower performance claim (update labeling + submission)\n│  C) Change predicate (if comparative claim fails)\n│  D) Add compensating evidence (additional clinical data)\n│  E) Scope reduction (remove failed feature)\n│  └─ F) Accept with justification (NON-SAFETY only, document rationale)\n└─ All options require: updated risk assessment, traceability update, re-review\n```\n\n## 7. Cybersecurity Requirements (FDA 2023 Guidance)\n\n### Threat Modeling Minimum Scope\n\n| Category | Must Address | Example Threats |\n|----------|-------------|----------------|\n| Confidentiality | PHI exposure | Unencrypted API, debug endpoints |\n| Integrity | Data\u002Falgorithm tampering | Model poisoning, input manipulation |\n| Availability | Denial of service | Resource exhaustion, dependency failure |\n| Authentication | Unauthorized access | Default credentials, session hijacking |\n| Update mechanism | Secure patching | Unsigned updates, rollback attacks |\n\n### SBOM Requirements (per FDA Refuse-to-Accept checklist)\n\n- Format: CycloneDX 1.5+ or SPDX 2.3+\n- Must include: ALL direct + transitive dependencies\n- Per component: name, version, supplier, license, known CVEs\n- Update frequency: Every release + within 24h of critical CVE disclosure\n- **FDA will RTA (Refuse to Accept) submissions without SBOM as of Oct 2023**\n\n## 8. AI\u002FML SaMD Lifecycle (PCCP Framework)\n\n### FDA Total Product Lifecycle for AI\u002FML\n\n```\nInitial Authorization (510(k) \u002F De Novo)\n├─ Locked Algorithm: Standard pathway, no PCCP required\n│  Future changes → new 510(k) for each modification\n├─ Locked Algorithm + Anticipated Changes: Include PCCP\n│  Changes within PCCP scope → no new submission\n│  Changes outside PCCP scope → new 510(k)\n└─ Adaptive Algorithm: PCCP MANDATORY (FDA Dec 2024 Guidance)\n   PCCP must specify:\n   ├─ Description of modifications (what could change)\n   ├─ Modification Protocol (how changes are developed + validated)\n   ├─ Impact Assessment (risk analysis for each change type)\n   └─ Transparency (how users are notified of changes)\n```\n\n### Good Machine Learning Practice (GMLP) — 10 Principles\n\n| # | Principle | Verification Method |\n|---|-----------|-------------------|\n| 1 | Multi-disciplinary team | Document team roles (clinical + engineering + regulatory) |\n| 2 | Good Software Engineering Practice | IEC 62304 compliance |\n| 3 | Representative clinical data | Dataset demographics vs. intended population |\n| 4 | Independent training\u002Ftest\u002Fvalidation sets | No data leakage verification |\n| 5 | Reference datasets (ground truth) | Adjudication process documented |\n| 6 | Model design fits intended use | Architecture justification document |\n| 7 | Clinically relevant performance metrics | Sensitivity\u002FSpecificity\u002FPPV\u002FNPV\u002FAUC |\n| 8 | Testing across patient subgroups | Bias analysis across demographics |\n| 9 | Clear user information | Labeling re: capabilities + limitations |\n| 10 | Deployed model monitoring | Drift detection + performance tracking |\n\n### Performance Monitoring Thresholds\n\n| Metric | Action Threshold | Escalation |\n|--------|-----------------|-----------|\n| Overall performance (AUC\u002FF1) | >5% degradation from validation | Investigate root cause |\n| Subgroup performance | >10% gap vs. majority subgroup | Bias review |\n| False negative rate (safety) | Any increase >2% | Immediate CAPA |\n| Data distribution shift | OOD rate >15% of inputs | Retraining evaluation |\n| Alert volume (CDS devices) | >20 alerts\u002Fclinician\u002Fshift | Alert fatigue review |\n\n## 9. Traceability Requirements\n\n### Bidirectional Traceability Matrix Structure\n\n```\nUser Need (UN-001)\n  → Design Input \u002F Requirement (REQ-001, REQ-002)\n    → Design Output \u002F Architecture Component (ARCH-001)\n      → Implementation (code module \u002F unit)\n        → Verification Test (VER-001, VER-002)\n          → Validation Evidence (VAL-001)\n            → Risk Control (RC-001) [if requirement is risk-derived]\n```\n\n### Traceability Completeness Rules\n\n| Check | Blocking? | Description |\n|-------|:---------:|-------------|\n| Orphan requirement (no parent UN) | Yes | Every REQ must trace to a user need |\n| Unverified requirement | Yes | Every REQ must have ≥1 verification test |\n| Unimplemented risk control | Yes | Every RC in hazard analysis must trace to code |\n| Dead code (no tracing requirement) | Warning | May indicate scope creep or incomplete specs |\n| Missing validation link | Class B\u002FC | Each user need must trace through to validation |\n\n## 10. Design Review Checklist (DR1 \u002F DR2 \u002F DR3)\n\n### DR1 — Inception Exit (Before Construction)\n\n| Item | Criteria |\n|------|----------|\n| User needs documented | All clinical needs captured with acceptance criteria |\n| Requirements complete | SRS covers all 9 categories (functional, performance, interface, cybersecurity, usability, risk control, data integrity, PHI, regulatory) |\n| Risk management plan | ISO 14971 plan approved, initial hazard analysis complete |\n| Regulatory strategy | Pathway selected, predicates identified |\n| Traceability (initial) | UN → REQ links established |\n\n### DR2 — Pre-Validation (After Construction, Before V&V)\n\n| Item | Criteria |\n|------|----------|\n| Architecture documented | IEC 62304 §5.3 satisfied |\n| SOUP assessed | All 3rd-party items risk-classified |\n| Code reviews complete | All units reviewed, findings resolved |\n| Design freeze | No more code changes during V&V |\n| Risk controls implemented | All controls in hazard analysis coded + unit tested |\n| SBOM generated | CycloneDX\u002FSPDX with all dependencies |\n\n### DR3 — Pre-Submission (After V&V)\n\n| Item | Criteria |\n|------|----------|\n| All tests pass | 0 open failures on safety\u002Fefficacy tests |\n| Coverage met | Class-appropriate thresholds achieved |\n| Residual risk acceptable | Benefit-risk documented and favorable |\n| Traceability closed | Full bidirectional, no orphans |\n| Anomalies dispositioned | All defects resolved or risk-accepted |\n| Labeling reviewed | Intended use, contraindications, IFU complete |\n\n## 11. FDA vs EU MDR Comparison for SaMD\n\n| Aspect | FDA (US) | EU MDR 2017\u002F745 |\n|--------|----------|-----------------|\n| Classification | Risk-based (Class I\u002FII\u002FIII) | Rule 11: SaMD is IIa minimum; IIb\u002FIII if serious |\n| Pathway | 510(k), De Novo, PMA | Notified Body conformity assessment |\n| Clinical evidence | Substantial equivalence (510k) or clinical studies (PMA) | Clinical Evaluation Report ALWAYS required |\n| Post-market | Annual reports, MDRs | PMCF + PSUR annually + vigilance |\n| AI\u002FML updates | PCCP framework | Notified Body re-assessment for significant changes |\n| Cybersecurity | Mandatory SBOM + threat model (2023) | MDCG 2019-16 guidance (recommended) |\n| QMS standard | 21 CFR 820 \u002F QMSR (aligned with ISO 13485) | ISO 13485 certification required |\n| Software lifecycle | IEC 62304 (recognized consensus standard) | IEC 62304 (harmonized standard) |\n| Timeline | 510(k): 3-6mo; De Novo: 9-12mo; PMA: 12-24mo | NB audit cycle: 12-18 months |\n| Labeling | 21 CFR 801 + unique labeling requirements | Annex I GSPR + SSCP (for implants\u002FClass III) |\n\n**Key gotcha:** EU MDR Rule 11 classifies most SaMD as IIa minimum (vs FDA Class II). SaMD providing information for diagnosis of serious conditions = Class IIb or III in EU even if Class II in US. Plan for the higher classification upfront if dual-market.\n\n## 12. Common SaMD Compliance Mistakes (Severity-Ranked)\n\n1. **Wrong:** Treating IEC 62304 safety class as equivalent to FDA device class\n   **Right:** IEC 62304 Class A\u002FB\u002FC is SOFTWARE safety; FDA Class I\u002FII\u002FIII is DEVICE risk. A Class II device can have Class C software.\n   **Why:** Incorrect classification leads to insufficient documentation and testing — Critical severity\n\n2. **Wrong:** Starting code before design inputs are documented\n   **Right:** Document user needs → derive requirements → get DR1 approval → THEN build\n   **Why:** 21 CFR 820.30(c) requires design input documentation before design output. FDA will cite this. — Critical severity\n\n3. **Wrong:** Omitting SOUP from the risk analysis\n   **Right:** Every SOUP item must be assessed for known anomalies that could contribute to hazards\n   **Why:** IEC 62304 §7.1.3 mandates SOUP risk assessment; unassessed SOUP = undocumented risk — High severity\n\n4. **Wrong:** Using \"testing\" as the only risk control\n   **Right:** Testing VERIFIES a risk control works — it is not itself a control. Controls are architectural (watchdogs, bounds checks, redundancy).\n   **Why:** Confusing verification with mitigation leaves residual risk unaddressed — High severity\n\n5. **Wrong:** No traceability between risk controls and verification tests\n   **Right:** Each risk control in the hazard analysis must link to a specific test proving it works\n   **Why:** Without this link, you cannot demonstrate risk controls are effective — submission deficiency — High severity\n\n6. **Wrong:** Performing design reviews as rubber-stamp exercises\n   **Right:** Design reviews must have documented attendees, specific findings, action items, and resolution evidence\n   **Why:** FDA inspectors look for \"objective evidence\" of review — generic sign-offs get 483s — High severity\n\n7. **Wrong:** Assuming De Novo is slower\u002Fharder than 510(k) for novel devices\n   **Right:** De Novo creates a new predicate, establishing your market category. Average review: 9-12 months.\n   **Why:** Forcing substantial equivalence to a poor predicate leads to Additional Information requests and delays — Medium severity\n\n8. **Wrong:** Treating cybersecurity as optional for non-connected devices\n   **Right:** FDA's 2023 guidance applies to ALL devices with software. Threat model scope includes supply chain, update mechanism, and data-at-rest.\n   **Why:** FDA will RTA submissions without cybersecurity documentation — Medium severity\n\n## 13. Part 11 (Electronic Records) Decision Tree\n\n```\nDoes your system create, modify, maintain, or transmit records required by FDA regulations?\n├─ No → Part 11 not applicable (document why)\n├─ Yes → Assess scope:\n│  ├─ Full Part 11 (production system with regulatory records)\n│  │  Requirements: Audit trails, electronic signatures, access controls,\n│  │  system validation, backup\u002Frecovery, authority checks\n│  ├─ Part 11-lite (hospital IT manages infrastructure)\n│  │  Requirements: Your application provides audit trail + access control;\n│  │  rely on hospital IT for infrastructure validation\n│  └─ Development-only records (training data, model versions)\n│     Requirements: Version control with audit trail, access control,\n│     backup integrity verification\n\nElectronic Signature Requirements (if applicable):\n├─ Signature = legally binding (equivalent to handwritten)\n├─ Must include: signer name, date\u002Ftime, meaning (approval\u002Freview\u002Fauthorship)\n├─ Must be linked to record (cannot be separated)\n└─ Biometric or non-biometric (ID + password) with controls\n```\n\n## 14. Post-Market Surveillance Essentials\n\n### Mandatory Activities by Market\n\n| Activity | FDA | EU MDR | Frequency |\n|----------|:---:|:------:|-----------|\n| Medical Device Report (MDR\u002Fvigilance) | ✅ | ✅ | Within 30 days (FDA) \u002F immediately for serious (EU) |\n| Annual report | ✅ | | Annually |\n| Periodic Safety Update Report (PSUR) | | ✅ | Annually (Class IIa+) |\n| Post-Market Clinical Follow-up (PMCF) | | ✅ | Ongoing |\n| Complaint handling | ✅ | ✅ | Per event |\n| CAPA process | ✅ | ✅ | Per finding |\n| Trend analysis | ✅ | ✅ | Quarterly minimum |\n| Software update reporting | ✅ | ✅ | Per update (risk-based) |\n\n### CAPA Trigger Decision Tree\n\n```\nSignal detected (complaint, trend, field event)\n├─ Safety-related?\n│  ├─ Yes → Immediate CAPA + potential field corrective action\n│  └─ No → Evaluate below\n├─ Systematic (affects multiple units\u002Fusers)?\n│  ├─ Yes → CAPA (root cause likely systemic)\n│  └─ No → Correction only (isolated incident)\n├─ Recurring (≥3 occurrences same root cause)?\n│  └─ Yes → CAPA mandatory (correction alone is insufficient)\n└─ Regulatory requirement (audit finding, FDA warning letter)?\n   └─ Yes → CAPA mandatory with defined timeline\n```\n\n## When NOT to Use This Skill\n\n- General software engineering without medical device claims — design controls add overhead without regulatory value\n- Clinical data standards (CDISC SDTM\u002FADaM) — use cdisc-compliance skill instead\n- Wellness\u002Ffitness apps with NO diagnostic or therapeutic claims — not regulated as devices\n- eCTD submission assembly or eSTAR portal mechanics — this skill covers device compliance, not submission logistics\n- Manufacturing quality (GMP, process validation for physical devices) — this skill focuses on software lifecycle\n\n## When to Escalate to Human Expert\n\n- Safety classification disagreement where reasonable arguments support multiple classes — requires cross-functional risk team decision\n- Predicate selection for 510(k) where no clear substantial equivalence exists — may need pre-submission meeting with FDA\n- Clinical evidence sufficiency questions — requires clinical affairs and biostatistics expertise\n- EU MDR classification under Rule 11 for borderline CDS\u002Fwellness software — requires Notified Body pre-assessment\n- Post-market safety signal assessment for potential field action — requires medical director and regulatory affairs\n",{"data":51,"body":64},{"name":4,"description":6,"usage":52,"version":53,"tags":54},"Invoke when evaluating SaMD regulatory compliance or planning FDA\u002FEU MDR submissions.","1.0.0",[55,56,57,19,58,59,60,61,62,63],"skill","category:reasoning","samd","iec-62304","iso-14971","iso-13485","regulatory","medical-device","hcls",{"type":65,"children":66},"root",[67,76,83,89,95,115,119,125,153,158,161,167,180,186,195,201,400,411,417,424,433,439,557,563,569,715,721,730,736,802,808,1017,1023,1032,1038,1044,1161,1167,1198,1204,1210,1219,1225,1432,1438,1555,1561,1567,1576,1582,1696,1702,1708,1795,1801,1899,1905,2003,2009,2216,2226,2232,2404,2410,2419,2425,2431,2626,2632,2641,2647,2675,2681],{"type":68,"tag":69,"props":70,"children":72},"element","h1",{"id":71},"samd-compliance-reasoning-skill",[73],{"type":74,"value":75},"text","SaMD Compliance — Reasoning Skill",{"type":68,"tag":77,"props":78,"children":80},"h2",{"id":79},"overview",[81],{"type":74,"value":82},"Overview",{"type":68,"tag":84,"props":85,"children":86},"p",{},[87],{"type":74,"value":88},"You are an expert in Software as a Medical Device (SaMD) regulatory compliance. When the\nuser asks about FDA software device submissions, IEC 62304 lifecycle, ISO 14971 risk\nmanagement, design controls, or global regulatory strategy, apply the decision frameworks\nbelow.",{"type":68,"tag":77,"props":90,"children":92},{"id":91},"usage",[93],{"type":74,"value":94},"Usage",{"type":68,"tag":96,"props":97,"children":98},"ul",{},[99,105,110],{"type":68,"tag":100,"props":101,"children":102},"li",{},[103],{"type":74,"value":104},"Invoke when evaluating SaMD regulatory compliance for FDA, EU MDR, or multi-market submissions",{"type":68,"tag":100,"props":106,"children":107},{},[108],{"type":74,"value":109},"Use when planning design controls, risk management, V&V, or submission strategy",{"type":68,"tag":100,"props":111,"children":112},{},[113],{"type":74,"value":114},"Activate for safety classification, SOUP assessment, or AI\u002FML device lifecycle questions",{"type":68,"tag":116,"props":117,"children":118},"hr",{},[],{"type":68,"tag":77,"props":120,"children":122},{"id":121},"response-format",[123],{"type":74,"value":124},"Response Format",{"type":68,"tag":96,"props":126,"children":127},{},[128,133,138,143,148],{"type":68,"tag":100,"props":129,"children":130},{},[131],{"type":74,"value":132},"Lead with the direct recommendation or classification (≤3 sentences)",{"type":68,"tag":100,"props":134,"children":135},{},[136],{"type":74,"value":137},"Structure as: recommendation → justification (citing specific standards\u002Fclauses) → caveats",{"type":68,"tag":100,"props":139,"children":140},{},[141],{"type":74,"value":142},"Use tables for comparisons; bullet points for criteria lists",{"type":68,"tag":100,"props":144,"children":145},{},[146],{"type":74,"value":147},"Omit background the user already knows — they asked the question",{"type":68,"tag":100,"props":149,"children":150},{},[151],{"type":74,"value":152},"Target: 200-400 words unless the user requests exhaustive detail",{"type":68,"tag":84,"props":154,"children":155},{},[156],{"type":74,"value":157},"The decision trees and frameworks in this skill are for internal reasoning only. Apply them to reach your conclusion, but do not reproduce them in your response. Present only the final recommendation with supporting evidence.",{"type":68,"tag":116,"props":159,"children":160},{},[],{"type":68,"tag":77,"props":162,"children":164},{"id":163},"_1-iec-62304-safety-classification-decision-tree",[165],{"type":74,"value":166},"1. IEC 62304 Safety Classification Decision Tree",{"type":68,"tag":168,"props":169,"children":173},"pre",{"className":170,"code":172,"language":74},[171],"language-text","Does the software system contribute to a hazardous situation?\n├─ No → Class A (no injury possible)\n│  Requirements: Basic documentation, no architecture decomposition required\n├─ Yes, but not SERIOUS injury → Class B (non-serious injury possible)\n│  Requirements: Architecture documentation, SOUP risk analysis, unit testing ≥80%\n└─ Yes, SERIOUS injury or DEATH possible → Class C (serious injury\u002Fdeath possible)\n   Requirements: Detailed design, full SOUP verification, unit testing ≥95%,\n                 additional detailed architecture documentation\n\nCan harm be mitigated by external measures (hardware, clinical workflow)?\n├─ Yes, reduced to non-serious → Downgrade to Class B\n│  Document: Mitigation measure, residual risk, why measure is reliable\n└─ No reliable external mitigation → Stays Class C\n\nClass determination timing:\n├─ At system level: Assign initial class based on intended use\n├─ At software item level: May assign LOWER class if item is isolated\n│  Condition: Item cannot contribute to higher-class hazard\n└─ NEVER assign lower class at system level than hazard analysis supports\n",[174],{"type":68,"tag":175,"props":176,"children":178},"code",{"__ignoreMap":177},"",[179],{"type":74,"value":172},{"type":68,"tag":77,"props":181,"children":183},{"id":182},"_2-fda-regulatory-pathway-decision-tree",[184],{"type":74,"value":185},"2. FDA Regulatory Pathway Decision Tree",{"type":68,"tag":168,"props":187,"children":190},{"className":188,"code":189,"language":74},[171],"Is the device substantially equivalent to a legally marketed predicate?\n├─ Yes, same intended use + same\u002Fdifferent technology (equiv. safety\u002Fefficacy)\n│  └─ 510(k) — Demonstrate substantial equivalence\n│     Timeline: 3-6 months (traditional), 6-12 months (special)\n├─ No predicate, but low-to-moderate risk (Class I or II)\n│  └─ De Novo — Establish new classification with general\u002Fspecial controls\n│     Timeline: 9-12 months\n│     Note: Creates a new predicate for future 510(k)s\n├─ High risk, Class III, life-sustaining\u002Fsupporting\n│  └─ PMA — Full clinical evidence, manufacturing controls\n│     Timeline: 12-24+ months\n└─ Clinical Decision Support meeting Cures Act Section 3060(a)?\n   All 4 criteria met:\n   1. Not intended to acquire\u002Fprocess\u002Fanalyze medical images\u002Fsignals\n   2. Intended for healthcare professionals (not patients)\n   3. Intended to enable HCP to independently review basis\n   4. Intended as aid (not to replace clinical judgment)\n   └─ Exempt from device regulation — document determination\n",[191],{"type":68,"tag":175,"props":192,"children":193},{"__ignoreMap":177},[194],{"type":74,"value":189},{"type":68,"tag":77,"props":196,"children":198},{"id":197},"_3-design-controls-lifecycle-21-cfr-82030-qmsr",[199],{"type":74,"value":200},"3. Design Controls Lifecycle (21 CFR 820.30 \u002F QMSR)",{"type":68,"tag":202,"props":203,"children":204},"table",{},[205,234],{"type":68,"tag":206,"props":207,"children":208},"thead",{},[209],{"type":68,"tag":210,"props":211,"children":212},"tr",{},[213,219,224,229],{"type":68,"tag":214,"props":215,"children":216},"th",{},[217],{"type":74,"value":218},"Phase",{"type":68,"tag":214,"props":220,"children":221},{},[222],{"type":74,"value":223},"Key Output",{"type":68,"tag":214,"props":225,"children":226},{},[227],{"type":74,"value":228},"IEC 62304 Mapping",{"type":68,"tag":214,"props":230,"children":231},{},[232],{"type":74,"value":233},"Blocking Gate",{"type":68,"tag":235,"props":236,"children":237},"tbody",{},[238,262,285,308,331,354,377],{"type":68,"tag":210,"props":239,"children":240},{},[241,247,252,257],{"type":68,"tag":242,"props":243,"children":244},"td",{},[245],{"type":74,"value":246},"User Needs",{"type":68,"tag":242,"props":248,"children":249},{},[250],{"type":74,"value":251},"User Needs Document",{"type":68,"tag":242,"props":253,"children":254},{},[255],{"type":74,"value":256},"§5.2 Software requirements process",{"type":68,"tag":242,"props":258,"children":259},{},[260],{"type":74,"value":261},"None",{"type":68,"tag":210,"props":263,"children":264},{},[265,270,275,280],{"type":68,"tag":242,"props":266,"children":267},{},[268],{"type":74,"value":269},"Design Input",{"type":68,"tag":242,"props":271,"children":272},{},[273],{"type":74,"value":274},"SRS (Software Requirements Spec)",{"type":68,"tag":242,"props":276,"children":277},{},[278],{"type":74,"value":279},"§5.2.1-5.2.6 Requirements",{"type":68,"tag":242,"props":281,"children":282},{},[283],{"type":74,"value":284},"DR1",{"type":68,"tag":210,"props":286,"children":287},{},[288,293,298,303],{"type":68,"tag":242,"props":289,"children":290},{},[291],{"type":74,"value":292},"Design Output",{"type":68,"tag":242,"props":294,"children":295},{},[296],{"type":74,"value":297},"Architecture + Detailed Design",{"type":68,"tag":242,"props":299,"children":300},{},[301],{"type":74,"value":302},"§5.3 Software architectural design",{"type":68,"tag":242,"props":304,"children":305},{},[306],{"type":74,"value":307},"DR2",{"type":68,"tag":210,"props":309,"children":310},{},[311,316,321,326],{"type":68,"tag":242,"props":312,"children":313},{},[314],{"type":74,"value":315},"Verification",{"type":68,"tag":242,"props":317,"children":318},{},[319],{"type":74,"value":320},"Test protocols + reports",{"type":68,"tag":242,"props":322,"children":323},{},[324],{"type":74,"value":325},"§5.5 Software integration testing, §5.6 System testing",{"type":68,"tag":242,"props":327,"children":328},{},[329],{"type":74,"value":330},"DR3",{"type":68,"tag":210,"props":332,"children":333},{},[334,339,344,349],{"type":68,"tag":242,"props":335,"children":336},{},[337],{"type":74,"value":338},"Validation",{"type":68,"tag":242,"props":340,"children":341},{},[342],{"type":74,"value":343},"Clinical validation evidence",{"type":68,"tag":242,"props":345,"children":346},{},[347],{"type":74,"value":348},"§5.7 Software release",{"type":68,"tag":242,"props":350,"children":351},{},[352],{"type":74,"value":353},"Submission",{"type":68,"tag":210,"props":355,"children":356},{},[357,362,367,372],{"type":68,"tag":242,"props":358,"children":359},{},[360],{"type":74,"value":361},"Transfer",{"type":68,"tag":242,"props":363,"children":364},{},[365],{"type":74,"value":366},"Manufacturing\u002Fdeployment procedures",{"type":68,"tag":242,"props":368,"children":369},{},[370],{"type":74,"value":371},"§5.8 Maintenance process",{"type":68,"tag":242,"props":373,"children":374},{},[375],{"type":74,"value":376},"Release",{"type":68,"tag":210,"props":378,"children":379},{},[380,385,390,395],{"type":68,"tag":242,"props":381,"children":382},{},[383],{"type":74,"value":384},"Changes",{"type":68,"tag":242,"props":386,"children":387},{},[388],{"type":74,"value":389},"Design change assessment",{"type":68,"tag":242,"props":391,"children":392},{},[393],{"type":74,"value":394},"§5.2 (re-entry)",{"type":68,"tag":242,"props":396,"children":397},{},[398],{"type":74,"value":399},"Per-change",{"type":68,"tag":84,"props":401,"children":402},{},[403,409],{"type":68,"tag":404,"props":405,"children":406},"strong",{},[407],{"type":74,"value":408},"Critical rule:",{"type":74,"value":410}," Design Reviews (DR1, DR2, DR3) are BLOCKING for Class B\u002FC devices. Each requires documented attendees, findings, and formal sign-off.",{"type":68,"tag":77,"props":412,"children":414},{"id":413},"_4-soupots-assessment-framework",[415],{"type":74,"value":416},"4. SOUP\u002FOTS Assessment Framework",{"type":68,"tag":418,"props":419,"children":421},"h3",{"id":420},"risk-based-soup-classification",[422],{"type":74,"value":423},"Risk-Based SOUP Classification",{"type":68,"tag":168,"props":425,"children":428},{"className":426,"code":427,"language":74},[171],"Is the SOUP item's failure capable of contributing to a hazardous situation?\n├─ No → Low-risk SOUP\n│  Document: Name, version, intended use, license\n│  Action: Monitor for known anomalies annually\n├─ Yes, contributes to Class B hazard → Medium-risk SOUP\n│  Document: Above + known anomalies list, mitigation for each\n│  Action: Version pin, anomaly monitoring, update assessment per release\n└─ Yes, contributes to Class C hazard → High-risk SOUP\n   Document: Above + detailed integration testing, published problem reports\n   Action: Above + verify adequate testing by SOUP vendor, consider alternatives\n\nSOUP Acceptance Criteria:\n├─ Vendor maintains the software (active development)? → Preferred\n├─ Known anomaly list published? → Required for Class B\u002FC\n├─ CVE history acceptable? → No unresolved critical CVEs\n└─ License compatible with medical device distribution? → Required\n",[429],{"type":68,"tag":175,"props":430,"children":431},{"__ignoreMap":177},[432],{"type":74,"value":427},{"type":68,"tag":418,"props":434,"children":436},{"id":435},"soup-vs-custom-decision",[437],{"type":74,"value":438},"SOUP vs Custom Decision",{"type":68,"tag":202,"props":440,"children":441},{},[442,463],{"type":68,"tag":206,"props":443,"children":444},{},[445],{"type":68,"tag":210,"props":446,"children":447},{},[448,453,458],{"type":68,"tag":214,"props":449,"children":450},{},[451],{"type":74,"value":452},"Factor",{"type":68,"tag":214,"props":454,"children":455},{},[456],{"type":74,"value":457},"Use SOUP",{"type":68,"tag":214,"props":459,"children":460},{},[461],{"type":74,"value":462},"Build Custom",{"type":68,"tag":235,"props":464,"children":465},{},[466,482,497,512,527,542],{"type":68,"tag":210,"props":467,"children":468},{},[469,474,479],{"type":68,"tag":242,"props":470,"children":471},{},[472],{"type":74,"value":473},"Well-validated open source library",{"type":68,"tag":242,"props":475,"children":476},{},[477],{"type":74,"value":478},"✅",{"type":68,"tag":242,"props":480,"children":481},{},[],{"type":68,"tag":210,"props":483,"children":484},{},[485,490,493],{"type":68,"tag":242,"props":486,"children":487},{},[488],{"type":74,"value":489},"Critical safety function with no validated library",{"type":68,"tag":242,"props":491,"children":492},{},[],{"type":68,"tag":242,"props":494,"children":495},{},[496],{"type":74,"value":478},{"type":68,"tag":210,"props":498,"children":499},{},[500,505,509],{"type":68,"tag":242,"props":501,"children":502},{},[503],{"type":74,"value":504},"Standard utility (logging, HTTP, encryption)",{"type":68,"tag":242,"props":506,"children":507},{},[508],{"type":74,"value":478},{"type":68,"tag":242,"props":510,"children":511},{},[],{"type":68,"tag":210,"props":513,"children":514},{},[515,520,524],{"type":68,"tag":242,"props":516,"children":517},{},[518],{"type":74,"value":519},"Regulatory precedent for the library",{"type":68,"tag":242,"props":521,"children":522},{},[523],{"type":74,"value":478},{"type":68,"tag":242,"props":525,"children":526},{},[],{"type":68,"tag":210,"props":528,"children":529},{},[530,535,538],{"type":68,"tag":242,"props":531,"children":532},{},[533],{"type":74,"value":534},"SOUP vendor unresponsive to anomaly reports",{"type":68,"tag":242,"props":536,"children":537},{},[],{"type":68,"tag":242,"props":539,"children":540},{},[541],{"type":74,"value":478},{"type":68,"tag":210,"props":543,"children":544},{},[545,550,554],{"type":68,"tag":242,"props":546,"children":547},{},[548],{"type":74,"value":549},"Time-to-market critical, library mature",{"type":68,"tag":242,"props":551,"children":552},{},[553],{"type":74,"value":478},{"type":68,"tag":242,"props":555,"children":556},{},[],{"type":68,"tag":77,"props":558,"children":560},{"id":559},"_5-iso-14971-risk-management-process",[561],{"type":74,"value":562},"5. ISO 14971 Risk Management Process",{"type":68,"tag":418,"props":564,"children":566},{"id":565},"severity-classification",[567],{"type":74,"value":568},"Severity Classification",{"type":68,"tag":202,"props":570,"children":571},{},[572,598],{"type":68,"tag":206,"props":573,"children":574},{},[575],{"type":68,"tag":210,"props":576,"children":577},{},[578,583,588,593],{"type":68,"tag":214,"props":579,"children":580},{},[581],{"type":74,"value":582},"Level",{"type":68,"tag":214,"props":584,"children":585},{},[586],{"type":74,"value":587},"Description",{"type":68,"tag":214,"props":589,"children":590},{},[591],{"type":74,"value":592},"Examples",{"type":68,"tag":214,"props":594,"children":595},{},[596],{"type":74,"value":597},"Acceptable Probability",{"type":68,"tag":235,"props":599,"children":600},{},[601,624,647,670,693],{"type":68,"tag":210,"props":602,"children":603},{},[604,609,614,619],{"type":68,"tag":242,"props":605,"children":606},{},[607],{"type":74,"value":608},"S1",{"type":68,"tag":242,"props":610,"children":611},{},[612],{"type":74,"value":613},"Negligible",{"type":68,"tag":242,"props":615,"children":616},{},[617],{"type":74,"value":618},"Inconvenience, no injury",{"type":68,"tag":242,"props":620,"children":621},{},[622],{"type":74,"value":623},"Any",{"type":68,"tag":210,"props":625,"children":626},{},[627,632,637,642],{"type":68,"tag":242,"props":628,"children":629},{},[630],{"type":74,"value":631},"S2",{"type":68,"tag":242,"props":633,"children":634},{},[635],{"type":74,"value":636},"Minor",{"type":68,"tag":242,"props":638,"children":639},{},[640],{"type":74,"value":641},"Temporary minor injury",{"type":68,"tag":242,"props":643,"children":644},{},[645],{"type":74,"value":646},"Occasional",{"type":68,"tag":210,"props":648,"children":649},{},[650,655,660,665],{"type":68,"tag":242,"props":651,"children":652},{},[653],{"type":74,"value":654},"S3",{"type":68,"tag":242,"props":656,"children":657},{},[658],{"type":74,"value":659},"Serious",{"type":68,"tag":242,"props":661,"children":662},{},[663],{"type":74,"value":664},"Injury requiring intervention",{"type":68,"tag":242,"props":666,"children":667},{},[668],{"type":74,"value":669},"Remote",{"type":68,"tag":210,"props":671,"children":672},{},[673,678,683,688],{"type":68,"tag":242,"props":674,"children":675},{},[676],{"type":74,"value":677},"S4",{"type":68,"tag":242,"props":679,"children":680},{},[681],{"type":74,"value":682},"Critical",{"type":68,"tag":242,"props":684,"children":685},{},[686],{"type":74,"value":687},"Permanent impairment",{"type":68,"tag":242,"props":689,"children":690},{},[691],{"type":74,"value":692},"Improbable",{"type":68,"tag":210,"props":694,"children":695},{},[696,701,706,711],{"type":68,"tag":242,"props":697,"children":698},{},[699],{"type":74,"value":700},"S5",{"type":68,"tag":242,"props":702,"children":703},{},[704],{"type":74,"value":705},"Catastrophic",{"type":68,"tag":242,"props":707,"children":708},{},[709],{"type":74,"value":710},"Death",{"type":68,"tag":242,"props":712,"children":713},{},[714],{"type":74,"value":692},{"type":68,"tag":418,"props":716,"children":718},{"id":717},"risk-control-priority-iso-14971-71",[719],{"type":74,"value":720},"Risk Control Priority (ISO 14971 §7.1)",{"type":68,"tag":168,"props":722,"children":725},{"className":723,"code":724,"language":74},[171],"Risk exceeds acceptability threshold?\n├─ Option 1: Inherent safety by design (ALWAYS try first)\n│  Example: Eliminate hazard entirely via architecture\n├─ Option 2: Protective measures in device or manufacturing\n│  Example: Software watchdog, timeout, bounds checking\n├─ Option 3: Information for safety (warnings, labeling, training)\n│  Example: Clinical alert, user manual warning\n└─ NEVER: Skip to Option 3 without documenting why Options 1-2 are infeasible\n\nResidual Risk Assessment:\n├─ Individual residual risk acceptable? → Document and proceed\n├─ Individual unacceptable but reducible? → Apply additional controls\n└─ Overall residual risk vs. benefit determination\n   Required: Document benefit-risk analysis for entire device\n",[726],{"type":68,"tag":175,"props":727,"children":728},{"__ignoreMap":177},[729],{"type":74,"value":724},{"type":68,"tag":418,"props":731,"children":733},{"id":732},"hazard-analysis-common-pitfalls",[734],{"type":74,"value":735},"Hazard Analysis Common Pitfalls",{"type":68,"tag":737,"props":738,"children":739},"ol",{},[740,757,772,787],{"type":68,"tag":100,"props":741,"children":742},{},[743,748,750,755],{"type":68,"tag":404,"props":744,"children":745},{},[746],{"type":74,"value":747},"Wrong:",{"type":74,"value":749}," Listing software bugs as hazards\n",{"type":68,"tag":404,"props":751,"children":752},{},[753],{"type":74,"value":754},"Right:",{"type":74,"value":756}," Trace bug → hazardous situation → harm. The HARM is what matters.",{"type":68,"tag":100,"props":758,"children":759},{},[760,764,766,770],{"type":68,"tag":404,"props":761,"children":762},{},[763],{"type":74,"value":747},{"type":74,"value":765}," Copying generic hazard lists without device-specific analysis\n",{"type":68,"tag":404,"props":767,"children":768},{},[769],{"type":74,"value":754},{"type":74,"value":771}," Analyze YOUR device's specific failure modes in YOUR clinical context",{"type":68,"tag":100,"props":773,"children":774},{},[775,779,781,785],{"type":68,"tag":404,"props":776,"children":777},{},[778],{"type":74,"value":747},{"type":74,"value":780}," Assuming software cannot cause physical harm\n",{"type":68,"tag":404,"props":782,"children":783},{},[784],{"type":74,"value":754},{"type":74,"value":786}," Delayed diagnosis, wrong treatment recommendation, alert fatigue ALL cause harm",{"type":68,"tag":100,"props":788,"children":789},{},[790,794,796,800],{"type":68,"tag":404,"props":791,"children":792},{},[793],{"type":74,"value":747},{"type":74,"value":795}," Risk controls that rely entirely on user vigilance\n",{"type":68,"tag":404,"props":797,"children":798},{},[799],{"type":74,"value":754},{"type":74,"value":801}," Design-level controls first; training\u002Fwarnings are last resort",{"type":68,"tag":77,"props":803,"children":805},{"id":804},"_6-vv-planning-by-safety-class",[806],{"type":74,"value":807},"6. V&V Planning by Safety Class",{"type":68,"tag":202,"props":809,"children":810},{},[811,838],{"type":68,"tag":206,"props":812,"children":813},{},[814],{"type":68,"tag":210,"props":815,"children":816},{},[817,822,828,833],{"type":68,"tag":214,"props":818,"children":819},{},[820],{"type":74,"value":821},"Activity",{"type":68,"tag":214,"props":823,"children":825},{"align":824},"center",[826],{"type":74,"value":827},"Class A",{"type":68,"tag":214,"props":829,"children":830},{"align":824},[831],{"type":74,"value":832},"Class B",{"type":68,"tag":214,"props":834,"children":835},{"align":824},[836],{"type":74,"value":837},"Class C",{"type":68,"tag":235,"props":839,"children":840},{},[841,861,884,905,926,949,971,994],{"type":68,"tag":210,"props":842,"children":843},{},[844,849,853,857],{"type":68,"tag":242,"props":845,"children":846},{},[847],{"type":74,"value":848},"Requirements traceability",{"type":68,"tag":242,"props":850,"children":851},{"align":824},[852],{"type":74,"value":478},{"type":68,"tag":242,"props":854,"children":855},{"align":824},[856],{"type":74,"value":478},{"type":68,"tag":242,"props":858,"children":859},{"align":824},[860],{"type":74,"value":478},{"type":68,"tag":210,"props":862,"children":863},{},[864,869,874,879],{"type":68,"tag":242,"props":865,"children":866},{},[867],{"type":74,"value":868},"Unit testing",{"type":68,"tag":242,"props":870,"children":871},{"align":824},[872],{"type":74,"value":873},"Optional",{"type":68,"tag":242,"props":875,"children":876},{"align":824},[877],{"type":74,"value":878},"≥80% coverage",{"type":68,"tag":242,"props":880,"children":881},{"align":824},[882],{"type":74,"value":883},"≥95% coverage",{"type":68,"tag":210,"props":885,"children":886},{},[887,892,896,900],{"type":68,"tag":242,"props":888,"children":889},{},[890],{"type":74,"value":891},"Integration testing",{"type":68,"tag":242,"props":893,"children":894},{"align":824},[895],{"type":74,"value":873},{"type":68,"tag":242,"props":897,"children":898},{"align":824},[899],{"type":74,"value":478},{"type":68,"tag":242,"props":901,"children":902},{"align":824},[903],{"type":74,"value":904},"✅ + fault injection",{"type":68,"tag":210,"props":906,"children":907},{},[908,913,917,921],{"type":68,"tag":242,"props":909,"children":910},{},[911],{"type":74,"value":912},"System testing",{"type":68,"tag":242,"props":914,"children":915},{"align":824},[916],{"type":74,"value":478},{"type":68,"tag":242,"props":918,"children":919},{"align":824},[920],{"type":74,"value":478},{"type":68,"tag":242,"props":922,"children":923},{"align":824},[924],{"type":74,"value":925},"✅ + stress\u002Fboundary",{"type":68,"tag":210,"props":927,"children":928},{},[929,934,939,944],{"type":68,"tag":242,"props":930,"children":931},{},[932],{"type":74,"value":933},"Regression testing",{"type":68,"tag":242,"props":935,"children":936},{"align":824},[937],{"type":74,"value":938},"On change",{"type":68,"tag":242,"props":940,"children":941},{"align":824},[942],{"type":74,"value":943},"Full suite",{"type":68,"tag":242,"props":945,"children":946},{"align":824},[947],{"type":74,"value":948},"Full suite + risk-based",{"type":68,"tag":210,"props":950,"children":951},{},[952,957,962,966],{"type":68,"tag":242,"props":953,"children":954},{},[955],{"type":74,"value":956},"Clinical validation",{"type":68,"tag":242,"props":958,"children":959},{"align":824},[960],{"type":74,"value":961},"If claimed",{"type":68,"tag":242,"props":963,"children":964},{"align":824},[965],{"type":74,"value":961},{"type":68,"tag":242,"props":967,"children":968},{"align":824},[969],{"type":74,"value":970},"✅ Mandatory",{"type":68,"tag":210,"props":972,"children":973},{},[974,979,984,989],{"type":68,"tag":242,"props":975,"children":976},{},[977],{"type":74,"value":978},"Cybersecurity testing",{"type":68,"tag":242,"props":980,"children":981},{"align":824},[982],{"type":74,"value":983},"If connected",{"type":68,"tag":242,"props":985,"children":986},{"align":824},[987],{"type":74,"value":988},"✅ Penetration test",{"type":68,"tag":242,"props":990,"children":991},{"align":824},[992],{"type":74,"value":993},"✅ Full threat model",{"type":68,"tag":210,"props":995,"children":996},{},[997,1002,1007,1012],{"type":68,"tag":242,"props":998,"children":999},{},[1000],{"type":74,"value":1001},"Usability validation",{"type":68,"tag":242,"props":1003,"children":1004},{"align":824},[1005],{"type":74,"value":1006},"If HCP user",{"type":68,"tag":242,"props":1008,"children":1009},{"align":824},[1010],{"type":74,"value":1011},"✅ Formative",{"type":68,"tag":242,"props":1013,"children":1014},{"align":824},[1015],{"type":74,"value":1016},"✅ Summative",{"type":68,"tag":418,"props":1018,"children":1020},{"id":1019},"vv-failure-recovery-decision-tree",[1021],{"type":74,"value":1022},"V&V Failure Recovery Decision Tree",{"type":68,"tag":168,"props":1024,"children":1027},{"className":1025,"code":1026,"language":74},[171],"Test fails acceptance criteria\n├─ Safety-related requirement?\n│  ├─ Yes → MUST fix before release (no exceptions)\n│  └─ No → Evaluate options below\n├─ Options:\n│  A) Fix defect and retest (preferred)\n│  B) Lower performance claim (update labeling + submission)\n│  C) Change predicate (if comparative claim fails)\n│  D) Add compensating evidence (additional clinical data)\n│  E) Scope reduction (remove failed feature)\n│  └─ F) Accept with justification (NON-SAFETY only, document rationale)\n└─ All options require: updated risk assessment, traceability update, re-review\n",[1028],{"type":68,"tag":175,"props":1029,"children":1030},{"__ignoreMap":177},[1031],{"type":74,"value":1026},{"type":68,"tag":77,"props":1033,"children":1035},{"id":1034},"_7-cybersecurity-requirements-fda-2023-guidance",[1036],{"type":74,"value":1037},"7. Cybersecurity Requirements (FDA 2023 Guidance)",{"type":68,"tag":418,"props":1039,"children":1041},{"id":1040},"threat-modeling-minimum-scope",[1042],{"type":74,"value":1043},"Threat Modeling Minimum Scope",{"type":68,"tag":202,"props":1045,"children":1046},{},[1047,1068],{"type":68,"tag":206,"props":1048,"children":1049},{},[1050],{"type":68,"tag":210,"props":1051,"children":1052},{},[1053,1058,1063],{"type":68,"tag":214,"props":1054,"children":1055},{},[1056],{"type":74,"value":1057},"Category",{"type":68,"tag":214,"props":1059,"children":1060},{},[1061],{"type":74,"value":1062},"Must Address",{"type":68,"tag":214,"props":1064,"children":1065},{},[1066],{"type":74,"value":1067},"Example Threats",{"type":68,"tag":235,"props":1069,"children":1070},{},[1071,1089,1107,1125,1143],{"type":68,"tag":210,"props":1072,"children":1073},{},[1074,1079,1084],{"type":68,"tag":242,"props":1075,"children":1076},{},[1077],{"type":74,"value":1078},"Confidentiality",{"type":68,"tag":242,"props":1080,"children":1081},{},[1082],{"type":74,"value":1083},"PHI exposure",{"type":68,"tag":242,"props":1085,"children":1086},{},[1087],{"type":74,"value":1088},"Unencrypted API, debug endpoints",{"type":68,"tag":210,"props":1090,"children":1091},{},[1092,1097,1102],{"type":68,"tag":242,"props":1093,"children":1094},{},[1095],{"type":74,"value":1096},"Integrity",{"type":68,"tag":242,"props":1098,"children":1099},{},[1100],{"type":74,"value":1101},"Data\u002Falgorithm tampering",{"type":68,"tag":242,"props":1103,"children":1104},{},[1105],{"type":74,"value":1106},"Model poisoning, input manipulation",{"type":68,"tag":210,"props":1108,"children":1109},{},[1110,1115,1120],{"type":68,"tag":242,"props":1111,"children":1112},{},[1113],{"type":74,"value":1114},"Availability",{"type":68,"tag":242,"props":1116,"children":1117},{},[1118],{"type":74,"value":1119},"Denial of service",{"type":68,"tag":242,"props":1121,"children":1122},{},[1123],{"type":74,"value":1124},"Resource exhaustion, dependency failure",{"type":68,"tag":210,"props":1126,"children":1127},{},[1128,1133,1138],{"type":68,"tag":242,"props":1129,"children":1130},{},[1131],{"type":74,"value":1132},"Authentication",{"type":68,"tag":242,"props":1134,"children":1135},{},[1136],{"type":74,"value":1137},"Unauthorized access",{"type":68,"tag":242,"props":1139,"children":1140},{},[1141],{"type":74,"value":1142},"Default credentials, session hijacking",{"type":68,"tag":210,"props":1144,"children":1145},{},[1146,1151,1156],{"type":68,"tag":242,"props":1147,"children":1148},{},[1149],{"type":74,"value":1150},"Update mechanism",{"type":68,"tag":242,"props":1152,"children":1153},{},[1154],{"type":74,"value":1155},"Secure patching",{"type":68,"tag":242,"props":1157,"children":1158},{},[1159],{"type":74,"value":1160},"Unsigned updates, rollback attacks",{"type":68,"tag":418,"props":1162,"children":1164},{"id":1163},"sbom-requirements-per-fda-refuse-to-accept-checklist",[1165],{"type":74,"value":1166},"SBOM Requirements (per FDA Refuse-to-Accept checklist)",{"type":68,"tag":96,"props":1168,"children":1169},{},[1170,1175,1180,1185,1190],{"type":68,"tag":100,"props":1171,"children":1172},{},[1173],{"type":74,"value":1174},"Format: CycloneDX 1.5+ or SPDX 2.3+",{"type":68,"tag":100,"props":1176,"children":1177},{},[1178],{"type":74,"value":1179},"Must include: ALL direct + transitive dependencies",{"type":68,"tag":100,"props":1181,"children":1182},{},[1183],{"type":74,"value":1184},"Per component: name, version, supplier, license, known CVEs",{"type":68,"tag":100,"props":1186,"children":1187},{},[1188],{"type":74,"value":1189},"Update frequency: Every release + within 24h of critical CVE disclosure",{"type":68,"tag":100,"props":1191,"children":1192},{},[1193],{"type":68,"tag":404,"props":1194,"children":1195},{},[1196],{"type":74,"value":1197},"FDA will RTA (Refuse to Accept) submissions without SBOM as of Oct 2023",{"type":68,"tag":77,"props":1199,"children":1201},{"id":1200},"_8-aiml-samd-lifecycle-pccp-framework",[1202],{"type":74,"value":1203},"8. AI\u002FML SaMD Lifecycle (PCCP Framework)",{"type":68,"tag":418,"props":1205,"children":1207},{"id":1206},"fda-total-product-lifecycle-for-aiml",[1208],{"type":74,"value":1209},"FDA Total Product Lifecycle for AI\u002FML",{"type":68,"tag":168,"props":1211,"children":1214},{"className":1212,"code":1213,"language":74},[171],"Initial Authorization (510(k) \u002F De Novo)\n├─ Locked Algorithm: Standard pathway, no PCCP required\n│  Future changes → new 510(k) for each modification\n├─ Locked Algorithm + Anticipated Changes: Include PCCP\n│  Changes within PCCP scope → no new submission\n│  Changes outside PCCP scope → new 510(k)\n└─ Adaptive Algorithm: PCCP MANDATORY (FDA Dec 2024 Guidance)\n   PCCP must specify:\n   ├─ Description of modifications (what could change)\n   ├─ Modification Protocol (how changes are developed + validated)\n   ├─ Impact Assessment (risk analysis for each change type)\n   └─ Transparency (how users are notified of changes)\n",[1215],{"type":68,"tag":175,"props":1216,"children":1217},{"__ignoreMap":177},[1218],{"type":74,"value":1213},{"type":68,"tag":418,"props":1220,"children":1222},{"id":1221},"good-machine-learning-practice-gmlp-10-principles",[1223],{"type":74,"value":1224},"Good Machine Learning Practice (GMLP) — 10 Principles",{"type":68,"tag":202,"props":1226,"children":1227},{},[1228,1249],{"type":68,"tag":206,"props":1229,"children":1230},{},[1231],{"type":68,"tag":210,"props":1232,"children":1233},{},[1234,1239,1244],{"type":68,"tag":214,"props":1235,"children":1236},{},[1237],{"type":74,"value":1238},"#",{"type":68,"tag":214,"props":1240,"children":1241},{},[1242],{"type":74,"value":1243},"Principle",{"type":68,"tag":214,"props":1245,"children":1246},{},[1247],{"type":74,"value":1248},"Verification Method",{"type":68,"tag":235,"props":1250,"children":1251},{},[1252,1270,1288,1306,1324,1342,1360,1378,1396,1414],{"type":68,"tag":210,"props":1253,"children":1254},{},[1255,1260,1265],{"type":68,"tag":242,"props":1256,"children":1257},{},[1258],{"type":74,"value":1259},"1",{"type":68,"tag":242,"props":1261,"children":1262},{},[1263],{"type":74,"value":1264},"Multi-disciplinary team",{"type":68,"tag":242,"props":1266,"children":1267},{},[1268],{"type":74,"value":1269},"Document team roles (clinical + engineering + regulatory)",{"type":68,"tag":210,"props":1271,"children":1272},{},[1273,1278,1283],{"type":68,"tag":242,"props":1274,"children":1275},{},[1276],{"type":74,"value":1277},"2",{"type":68,"tag":242,"props":1279,"children":1280},{},[1281],{"type":74,"value":1282},"Good Software Engineering Practice",{"type":68,"tag":242,"props":1284,"children":1285},{},[1286],{"type":74,"value":1287},"IEC 62304 compliance",{"type":68,"tag":210,"props":1289,"children":1290},{},[1291,1296,1301],{"type":68,"tag":242,"props":1292,"children":1293},{},[1294],{"type":74,"value":1295},"3",{"type":68,"tag":242,"props":1297,"children":1298},{},[1299],{"type":74,"value":1300},"Representative clinical data",{"type":68,"tag":242,"props":1302,"children":1303},{},[1304],{"type":74,"value":1305},"Dataset demographics vs. intended population",{"type":68,"tag":210,"props":1307,"children":1308},{},[1309,1314,1319],{"type":68,"tag":242,"props":1310,"children":1311},{},[1312],{"type":74,"value":1313},"4",{"type":68,"tag":242,"props":1315,"children":1316},{},[1317],{"type":74,"value":1318},"Independent training\u002Ftest\u002Fvalidation sets",{"type":68,"tag":242,"props":1320,"children":1321},{},[1322],{"type":74,"value":1323},"No data leakage verification",{"type":68,"tag":210,"props":1325,"children":1326},{},[1327,1332,1337],{"type":68,"tag":242,"props":1328,"children":1329},{},[1330],{"type":74,"value":1331},"5",{"type":68,"tag":242,"props":1333,"children":1334},{},[1335],{"type":74,"value":1336},"Reference datasets (ground truth)",{"type":68,"tag":242,"props":1338,"children":1339},{},[1340],{"type":74,"value":1341},"Adjudication process documented",{"type":68,"tag":210,"props":1343,"children":1344},{},[1345,1350,1355],{"type":68,"tag":242,"props":1346,"children":1347},{},[1348],{"type":74,"value":1349},"6",{"type":68,"tag":242,"props":1351,"children":1352},{},[1353],{"type":74,"value":1354},"Model design fits intended use",{"type":68,"tag":242,"props":1356,"children":1357},{},[1358],{"type":74,"value":1359},"Architecture justification document",{"type":68,"tag":210,"props":1361,"children":1362},{},[1363,1368,1373],{"type":68,"tag":242,"props":1364,"children":1365},{},[1366],{"type":74,"value":1367},"7",{"type":68,"tag":242,"props":1369,"children":1370},{},[1371],{"type":74,"value":1372},"Clinically relevant performance metrics",{"type":68,"tag":242,"props":1374,"children":1375},{},[1376],{"type":74,"value":1377},"Sensitivity\u002FSpecificity\u002FPPV\u002FNPV\u002FAUC",{"type":68,"tag":210,"props":1379,"children":1380},{},[1381,1386,1391],{"type":68,"tag":242,"props":1382,"children":1383},{},[1384],{"type":74,"value":1385},"8",{"type":68,"tag":242,"props":1387,"children":1388},{},[1389],{"type":74,"value":1390},"Testing across patient subgroups",{"type":68,"tag":242,"props":1392,"children":1393},{},[1394],{"type":74,"value":1395},"Bias analysis across demographics",{"type":68,"tag":210,"props":1397,"children":1398},{},[1399,1404,1409],{"type":68,"tag":242,"props":1400,"children":1401},{},[1402],{"type":74,"value":1403},"9",{"type":68,"tag":242,"props":1405,"children":1406},{},[1407],{"type":74,"value":1408},"Clear user information",{"type":68,"tag":242,"props":1410,"children":1411},{},[1412],{"type":74,"value":1413},"Labeling re: capabilities + limitations",{"type":68,"tag":210,"props":1415,"children":1416},{},[1417,1422,1427],{"type":68,"tag":242,"props":1418,"children":1419},{},[1420],{"type":74,"value":1421},"10",{"type":68,"tag":242,"props":1423,"children":1424},{},[1425],{"type":74,"value":1426},"Deployed model monitoring",{"type":68,"tag":242,"props":1428,"children":1429},{},[1430],{"type":74,"value":1431},"Drift detection + performance tracking",{"type":68,"tag":418,"props":1433,"children":1435},{"id":1434},"performance-monitoring-thresholds",[1436],{"type":74,"value":1437},"Performance Monitoring Thresholds",{"type":68,"tag":202,"props":1439,"children":1440},{},[1441,1462],{"type":68,"tag":206,"props":1442,"children":1443},{},[1444],{"type":68,"tag":210,"props":1445,"children":1446},{},[1447,1452,1457],{"type":68,"tag":214,"props":1448,"children":1449},{},[1450],{"type":74,"value":1451},"Metric",{"type":68,"tag":214,"props":1453,"children":1454},{},[1455],{"type":74,"value":1456},"Action Threshold",{"type":68,"tag":214,"props":1458,"children":1459},{},[1460],{"type":74,"value":1461},"Escalation",{"type":68,"tag":235,"props":1463,"children":1464},{},[1465,1483,1501,1519,1537],{"type":68,"tag":210,"props":1466,"children":1467},{},[1468,1473,1478],{"type":68,"tag":242,"props":1469,"children":1470},{},[1471],{"type":74,"value":1472},"Overall performance (AUC\u002FF1)",{"type":68,"tag":242,"props":1474,"children":1475},{},[1476],{"type":74,"value":1477},">5% degradation from validation",{"type":68,"tag":242,"props":1479,"children":1480},{},[1481],{"type":74,"value":1482},"Investigate root cause",{"type":68,"tag":210,"props":1484,"children":1485},{},[1486,1491,1496],{"type":68,"tag":242,"props":1487,"children":1488},{},[1489],{"type":74,"value":1490},"Subgroup performance",{"type":68,"tag":242,"props":1492,"children":1493},{},[1494],{"type":74,"value":1495},">10% gap vs. majority subgroup",{"type":68,"tag":242,"props":1497,"children":1498},{},[1499],{"type":74,"value":1500},"Bias review",{"type":68,"tag":210,"props":1502,"children":1503},{},[1504,1509,1514],{"type":68,"tag":242,"props":1505,"children":1506},{},[1507],{"type":74,"value":1508},"False negative rate (safety)",{"type":68,"tag":242,"props":1510,"children":1511},{},[1512],{"type":74,"value":1513},"Any increase >2%",{"type":68,"tag":242,"props":1515,"children":1516},{},[1517],{"type":74,"value":1518},"Immediate CAPA",{"type":68,"tag":210,"props":1520,"children":1521},{},[1522,1527,1532],{"type":68,"tag":242,"props":1523,"children":1524},{},[1525],{"type":74,"value":1526},"Data distribution shift",{"type":68,"tag":242,"props":1528,"children":1529},{},[1530],{"type":74,"value":1531},"OOD rate >15% of inputs",{"type":68,"tag":242,"props":1533,"children":1534},{},[1535],{"type":74,"value":1536},"Retraining evaluation",{"type":68,"tag":210,"props":1538,"children":1539},{},[1540,1545,1550],{"type":68,"tag":242,"props":1541,"children":1542},{},[1543],{"type":74,"value":1544},"Alert volume (CDS devices)",{"type":68,"tag":242,"props":1546,"children":1547},{},[1548],{"type":74,"value":1549},">20 alerts\u002Fclinician\u002Fshift",{"type":68,"tag":242,"props":1551,"children":1552},{},[1553],{"type":74,"value":1554},"Alert fatigue review",{"type":68,"tag":77,"props":1556,"children":1558},{"id":1557},"_9-traceability-requirements",[1559],{"type":74,"value":1560},"9. Traceability Requirements",{"type":68,"tag":418,"props":1562,"children":1564},{"id":1563},"bidirectional-traceability-matrix-structure",[1565],{"type":74,"value":1566},"Bidirectional Traceability Matrix Structure",{"type":68,"tag":168,"props":1568,"children":1571},{"className":1569,"code":1570,"language":74},[171],"User Need (UN-001)\n  → Design Input \u002F Requirement (REQ-001, REQ-002)\n    → Design Output \u002F Architecture Component (ARCH-001)\n      → Implementation (code module \u002F unit)\n        → Verification Test (VER-001, VER-002)\n          → Validation Evidence (VAL-001)\n            → Risk Control (RC-001) [if requirement is risk-derived]\n",[1572],{"type":68,"tag":175,"props":1573,"children":1574},{"__ignoreMap":177},[1575],{"type":74,"value":1570},{"type":68,"tag":418,"props":1577,"children":1579},{"id":1578},"traceability-completeness-rules",[1580],{"type":74,"value":1581},"Traceability Completeness Rules",{"type":68,"tag":202,"props":1583,"children":1584},{},[1585,1605],{"type":68,"tag":206,"props":1586,"children":1587},{},[1588],{"type":68,"tag":210,"props":1589,"children":1590},{},[1591,1596,1601],{"type":68,"tag":214,"props":1592,"children":1593},{},[1594],{"type":74,"value":1595},"Check",{"type":68,"tag":214,"props":1597,"children":1598},{"align":824},[1599],{"type":74,"value":1600},"Blocking?",{"type":68,"tag":214,"props":1602,"children":1603},{},[1604],{"type":74,"value":587},{"type":68,"tag":235,"props":1606,"children":1607},{},[1608,1626,1643,1660,1678],{"type":68,"tag":210,"props":1609,"children":1610},{},[1611,1616,1621],{"type":68,"tag":242,"props":1612,"children":1613},{},[1614],{"type":74,"value":1615},"Orphan requirement (no parent UN)",{"type":68,"tag":242,"props":1617,"children":1618},{"align":824},[1619],{"type":74,"value":1620},"Yes",{"type":68,"tag":242,"props":1622,"children":1623},{},[1624],{"type":74,"value":1625},"Every REQ must trace to a user need",{"type":68,"tag":210,"props":1627,"children":1628},{},[1629,1634,1638],{"type":68,"tag":242,"props":1630,"children":1631},{},[1632],{"type":74,"value":1633},"Unverified requirement",{"type":68,"tag":242,"props":1635,"children":1636},{"align":824},[1637],{"type":74,"value":1620},{"type":68,"tag":242,"props":1639,"children":1640},{},[1641],{"type":74,"value":1642},"Every REQ must have ≥1 verification test",{"type":68,"tag":210,"props":1644,"children":1645},{},[1646,1651,1655],{"type":68,"tag":242,"props":1647,"children":1648},{},[1649],{"type":74,"value":1650},"Unimplemented risk control",{"type":68,"tag":242,"props":1652,"children":1653},{"align":824},[1654],{"type":74,"value":1620},{"type":68,"tag":242,"props":1656,"children":1657},{},[1658],{"type":74,"value":1659},"Every RC in hazard analysis must trace to code",{"type":68,"tag":210,"props":1661,"children":1662},{},[1663,1668,1673],{"type":68,"tag":242,"props":1664,"children":1665},{},[1666],{"type":74,"value":1667},"Dead code (no tracing requirement)",{"type":68,"tag":242,"props":1669,"children":1670},{"align":824},[1671],{"type":74,"value":1672},"Warning",{"type":68,"tag":242,"props":1674,"children":1675},{},[1676],{"type":74,"value":1677},"May indicate scope creep or incomplete specs",{"type":68,"tag":210,"props":1679,"children":1680},{},[1681,1686,1691],{"type":68,"tag":242,"props":1682,"children":1683},{},[1684],{"type":74,"value":1685},"Missing validation link",{"type":68,"tag":242,"props":1687,"children":1688},{"align":824},[1689],{"type":74,"value":1690},"Class B\u002FC",{"type":68,"tag":242,"props":1692,"children":1693},{},[1694],{"type":74,"value":1695},"Each user need must trace through to validation",{"type":68,"tag":77,"props":1697,"children":1699},{"id":1698},"_10-design-review-checklist-dr1-dr2-dr3",[1700],{"type":74,"value":1701},"10. Design Review Checklist (DR1 \u002F DR2 \u002F DR3)",{"type":68,"tag":418,"props":1703,"children":1705},{"id":1704},"dr1-inception-exit-before-construction",[1706],{"type":74,"value":1707},"DR1 — Inception Exit (Before Construction)",{"type":68,"tag":202,"props":1709,"children":1710},{},[1711,1727],{"type":68,"tag":206,"props":1712,"children":1713},{},[1714],{"type":68,"tag":210,"props":1715,"children":1716},{},[1717,1722],{"type":68,"tag":214,"props":1718,"children":1719},{},[1720],{"type":74,"value":1721},"Item",{"type":68,"tag":214,"props":1723,"children":1724},{},[1725],{"type":74,"value":1726},"Criteria",{"type":68,"tag":235,"props":1728,"children":1729},{},[1730,1743,1756,1769,1782],{"type":68,"tag":210,"props":1731,"children":1732},{},[1733,1738],{"type":68,"tag":242,"props":1734,"children":1735},{},[1736],{"type":74,"value":1737},"User needs documented",{"type":68,"tag":242,"props":1739,"children":1740},{},[1741],{"type":74,"value":1742},"All clinical needs captured with acceptance criteria",{"type":68,"tag":210,"props":1744,"children":1745},{},[1746,1751],{"type":68,"tag":242,"props":1747,"children":1748},{},[1749],{"type":74,"value":1750},"Requirements complete",{"type":68,"tag":242,"props":1752,"children":1753},{},[1754],{"type":74,"value":1755},"SRS covers all 9 categories (functional, performance, interface, cybersecurity, usability, risk control, data integrity, PHI, regulatory)",{"type":68,"tag":210,"props":1757,"children":1758},{},[1759,1764],{"type":68,"tag":242,"props":1760,"children":1761},{},[1762],{"type":74,"value":1763},"Risk management plan",{"type":68,"tag":242,"props":1765,"children":1766},{},[1767],{"type":74,"value":1768},"ISO 14971 plan approved, initial hazard analysis complete",{"type":68,"tag":210,"props":1770,"children":1771},{},[1772,1777],{"type":68,"tag":242,"props":1773,"children":1774},{},[1775],{"type":74,"value":1776},"Regulatory strategy",{"type":68,"tag":242,"props":1778,"children":1779},{},[1780],{"type":74,"value":1781},"Pathway selected, predicates identified",{"type":68,"tag":210,"props":1783,"children":1784},{},[1785,1790],{"type":68,"tag":242,"props":1786,"children":1787},{},[1788],{"type":74,"value":1789},"Traceability (initial)",{"type":68,"tag":242,"props":1791,"children":1792},{},[1793],{"type":74,"value":1794},"UN → REQ links established",{"type":68,"tag":418,"props":1796,"children":1798},{"id":1797},"dr2-pre-validation-after-construction-before-vv",[1799],{"type":74,"value":1800},"DR2 — Pre-Validation (After Construction, Before V&V)",{"type":68,"tag":202,"props":1802,"children":1803},{},[1804,1818],{"type":68,"tag":206,"props":1805,"children":1806},{},[1807],{"type":68,"tag":210,"props":1808,"children":1809},{},[1810,1814],{"type":68,"tag":214,"props":1811,"children":1812},{},[1813],{"type":74,"value":1721},{"type":68,"tag":214,"props":1815,"children":1816},{},[1817],{"type":74,"value":1726},{"type":68,"tag":235,"props":1819,"children":1820},{},[1821,1834,1847,1860,1873,1886],{"type":68,"tag":210,"props":1822,"children":1823},{},[1824,1829],{"type":68,"tag":242,"props":1825,"children":1826},{},[1827],{"type":74,"value":1828},"Architecture documented",{"type":68,"tag":242,"props":1830,"children":1831},{},[1832],{"type":74,"value":1833},"IEC 62304 §5.3 satisfied",{"type":68,"tag":210,"props":1835,"children":1836},{},[1837,1842],{"type":68,"tag":242,"props":1838,"children":1839},{},[1840],{"type":74,"value":1841},"SOUP assessed",{"type":68,"tag":242,"props":1843,"children":1844},{},[1845],{"type":74,"value":1846},"All 3rd-party items risk-classified",{"type":68,"tag":210,"props":1848,"children":1849},{},[1850,1855],{"type":68,"tag":242,"props":1851,"children":1852},{},[1853],{"type":74,"value":1854},"Code reviews complete",{"type":68,"tag":242,"props":1856,"children":1857},{},[1858],{"type":74,"value":1859},"All units reviewed, findings resolved",{"type":68,"tag":210,"props":1861,"children":1862},{},[1863,1868],{"type":68,"tag":242,"props":1864,"children":1865},{},[1866],{"type":74,"value":1867},"Design freeze",{"type":68,"tag":242,"props":1869,"children":1870},{},[1871],{"type":74,"value":1872},"No more code changes during V&V",{"type":68,"tag":210,"props":1874,"children":1875},{},[1876,1881],{"type":68,"tag":242,"props":1877,"children":1878},{},[1879],{"type":74,"value":1880},"Risk controls implemented",{"type":68,"tag":242,"props":1882,"children":1883},{},[1884],{"type":74,"value":1885},"All controls in hazard analysis coded + unit tested",{"type":68,"tag":210,"props":1887,"children":1888},{},[1889,1894],{"type":68,"tag":242,"props":1890,"children":1891},{},[1892],{"type":74,"value":1893},"SBOM generated",{"type":68,"tag":242,"props":1895,"children":1896},{},[1897],{"type":74,"value":1898},"CycloneDX\u002FSPDX with all dependencies",{"type":68,"tag":418,"props":1900,"children":1902},{"id":1901},"dr3-pre-submission-after-vv",[1903],{"type":74,"value":1904},"DR3 — Pre-Submission (After V&V)",{"type":68,"tag":202,"props":1906,"children":1907},{},[1908,1922],{"type":68,"tag":206,"props":1909,"children":1910},{},[1911],{"type":68,"tag":210,"props":1912,"children":1913},{},[1914,1918],{"type":68,"tag":214,"props":1915,"children":1916},{},[1917],{"type":74,"value":1721},{"type":68,"tag":214,"props":1919,"children":1920},{},[1921],{"type":74,"value":1726},{"type":68,"tag":235,"props":1923,"children":1924},{},[1925,1938,1951,1964,1977,1990],{"type":68,"tag":210,"props":1926,"children":1927},{},[1928,1933],{"type":68,"tag":242,"props":1929,"children":1930},{},[1931],{"type":74,"value":1932},"All tests pass",{"type":68,"tag":242,"props":1934,"children":1935},{},[1936],{"type":74,"value":1937},"0 open failures on safety\u002Fefficacy tests",{"type":68,"tag":210,"props":1939,"children":1940},{},[1941,1946],{"type":68,"tag":242,"props":1942,"children":1943},{},[1944],{"type":74,"value":1945},"Coverage met",{"type":68,"tag":242,"props":1947,"children":1948},{},[1949],{"type":74,"value":1950},"Class-appropriate thresholds achieved",{"type":68,"tag":210,"props":1952,"children":1953},{},[1954,1959],{"type":68,"tag":242,"props":1955,"children":1956},{},[1957],{"type":74,"value":1958},"Residual risk acceptable",{"type":68,"tag":242,"props":1960,"children":1961},{},[1962],{"type":74,"value":1963},"Benefit-risk documented and favorable",{"type":68,"tag":210,"props":1965,"children":1966},{},[1967,1972],{"type":68,"tag":242,"props":1968,"children":1969},{},[1970],{"type":74,"value":1971},"Traceability closed",{"type":68,"tag":242,"props":1973,"children":1974},{},[1975],{"type":74,"value":1976},"Full bidirectional, no orphans",{"type":68,"tag":210,"props":1978,"children":1979},{},[1980,1985],{"type":68,"tag":242,"props":1981,"children":1982},{},[1983],{"type":74,"value":1984},"Anomalies dispositioned",{"type":68,"tag":242,"props":1986,"children":1987},{},[1988],{"type":74,"value":1989},"All defects resolved or risk-accepted",{"type":68,"tag":210,"props":1991,"children":1992},{},[1993,1998],{"type":68,"tag":242,"props":1994,"children":1995},{},[1996],{"type":74,"value":1997},"Labeling reviewed",{"type":68,"tag":242,"props":1999,"children":2000},{},[2001],{"type":74,"value":2002},"Intended use, contraindications, IFU complete",{"type":68,"tag":77,"props":2004,"children":2006},{"id":2005},"_11-fda-vs-eu-mdr-comparison-for-samd",[2007],{"type":74,"value":2008},"11. FDA vs EU MDR Comparison for SaMD",{"type":68,"tag":202,"props":2010,"children":2011},{},[2012,2033],{"type":68,"tag":206,"props":2013,"children":2014},{},[2015],{"type":68,"tag":210,"props":2016,"children":2017},{},[2018,2023,2028],{"type":68,"tag":214,"props":2019,"children":2020},{},[2021],{"type":74,"value":2022},"Aspect",{"type":68,"tag":214,"props":2024,"children":2025},{},[2026],{"type":74,"value":2027},"FDA (US)",{"type":68,"tag":214,"props":2029,"children":2030},{},[2031],{"type":74,"value":2032},"EU MDR 2017\u002F745",{"type":68,"tag":235,"props":2034,"children":2035},{},[2036,2054,2072,2090,2108,2126,2144,2162,2180,2198],{"type":68,"tag":210,"props":2037,"children":2038},{},[2039,2044,2049],{"type":68,"tag":242,"props":2040,"children":2041},{},[2042],{"type":74,"value":2043},"Classification",{"type":68,"tag":242,"props":2045,"children":2046},{},[2047],{"type":74,"value":2048},"Risk-based (Class I\u002FII\u002FIII)",{"type":68,"tag":242,"props":2050,"children":2051},{},[2052],{"type":74,"value":2053},"Rule 11: SaMD is IIa minimum; IIb\u002FIII if serious",{"type":68,"tag":210,"props":2055,"children":2056},{},[2057,2062,2067],{"type":68,"tag":242,"props":2058,"children":2059},{},[2060],{"type":74,"value":2061},"Pathway",{"type":68,"tag":242,"props":2063,"children":2064},{},[2065],{"type":74,"value":2066},"510(k), De Novo, PMA",{"type":68,"tag":242,"props":2068,"children":2069},{},[2070],{"type":74,"value":2071},"Notified Body conformity assessment",{"type":68,"tag":210,"props":2073,"children":2074},{},[2075,2080,2085],{"type":68,"tag":242,"props":2076,"children":2077},{},[2078],{"type":74,"value":2079},"Clinical evidence",{"type":68,"tag":242,"props":2081,"children":2082},{},[2083],{"type":74,"value":2084},"Substantial equivalence (510k) or clinical studies (PMA)",{"type":68,"tag":242,"props":2086,"children":2087},{},[2088],{"type":74,"value":2089},"Clinical Evaluation Report ALWAYS required",{"type":68,"tag":210,"props":2091,"children":2092},{},[2093,2098,2103],{"type":68,"tag":242,"props":2094,"children":2095},{},[2096],{"type":74,"value":2097},"Post-market",{"type":68,"tag":242,"props":2099,"children":2100},{},[2101],{"type":74,"value":2102},"Annual reports, MDRs",{"type":68,"tag":242,"props":2104,"children":2105},{},[2106],{"type":74,"value":2107},"PMCF + PSUR annually + vigilance",{"type":68,"tag":210,"props":2109,"children":2110},{},[2111,2116,2121],{"type":68,"tag":242,"props":2112,"children":2113},{},[2114],{"type":74,"value":2115},"AI\u002FML updates",{"type":68,"tag":242,"props":2117,"children":2118},{},[2119],{"type":74,"value":2120},"PCCP framework",{"type":68,"tag":242,"props":2122,"children":2123},{},[2124],{"type":74,"value":2125},"Notified Body re-assessment for significant changes",{"type":68,"tag":210,"props":2127,"children":2128},{},[2129,2134,2139],{"type":68,"tag":242,"props":2130,"children":2131},{},[2132],{"type":74,"value":2133},"Cybersecurity",{"type":68,"tag":242,"props":2135,"children":2136},{},[2137],{"type":74,"value":2138},"Mandatory SBOM + threat model (2023)",{"type":68,"tag":242,"props":2140,"children":2141},{},[2142],{"type":74,"value":2143},"MDCG 2019-16 guidance (recommended)",{"type":68,"tag":210,"props":2145,"children":2146},{},[2147,2152,2157],{"type":68,"tag":242,"props":2148,"children":2149},{},[2150],{"type":74,"value":2151},"QMS standard",{"type":68,"tag":242,"props":2153,"children":2154},{},[2155],{"type":74,"value":2156},"21 CFR 820 \u002F QMSR (aligned with ISO 13485)",{"type":68,"tag":242,"props":2158,"children":2159},{},[2160],{"type":74,"value":2161},"ISO 13485 certification required",{"type":68,"tag":210,"props":2163,"children":2164},{},[2165,2170,2175],{"type":68,"tag":242,"props":2166,"children":2167},{},[2168],{"type":74,"value":2169},"Software lifecycle",{"type":68,"tag":242,"props":2171,"children":2172},{},[2173],{"type":74,"value":2174},"IEC 62304 (recognized consensus standard)",{"type":68,"tag":242,"props":2176,"children":2177},{},[2178],{"type":74,"value":2179},"IEC 62304 (harmonized standard)",{"type":68,"tag":210,"props":2181,"children":2182},{},[2183,2188,2193],{"type":68,"tag":242,"props":2184,"children":2185},{},[2186],{"type":74,"value":2187},"Timeline",{"type":68,"tag":242,"props":2189,"children":2190},{},[2191],{"type":74,"value":2192},"510(k): 3-6mo; De Novo: 9-12mo; PMA: 12-24mo",{"type":68,"tag":242,"props":2194,"children":2195},{},[2196],{"type":74,"value":2197},"NB audit cycle: 12-18 months",{"type":68,"tag":210,"props":2199,"children":2200},{},[2201,2206,2211],{"type":68,"tag":242,"props":2202,"children":2203},{},[2204],{"type":74,"value":2205},"Labeling",{"type":68,"tag":242,"props":2207,"children":2208},{},[2209],{"type":74,"value":2210},"21 CFR 801 + unique labeling requirements",{"type":68,"tag":242,"props":2212,"children":2213},{},[2214],{"type":74,"value":2215},"Annex I GSPR + SSCP (for implants\u002FClass III)",{"type":68,"tag":84,"props":2217,"children":2218},{},[2219,2224],{"type":68,"tag":404,"props":2220,"children":2221},{},[2222],{"type":74,"value":2223},"Key gotcha:",{"type":74,"value":2225}," EU MDR Rule 11 classifies most SaMD as IIa minimum (vs FDA Class II). SaMD providing information for diagnosis of serious conditions = Class IIb or III in EU even if Class II in US. Plan for the higher classification upfront if dual-market.",{"type":68,"tag":77,"props":2227,"children":2229},{"id":2228},"_12-common-samd-compliance-mistakes-severity-ranked",[2230],{"type":74,"value":2231},"12. Common SaMD Compliance Mistakes (Severity-Ranked)",{"type":68,"tag":737,"props":2233,"children":2234},{},[2235,2257,2278,2299,2320,2341,2362,2383],{"type":68,"tag":100,"props":2236,"children":2237},{},[2238,2242,2244,2248,2250,2255],{"type":68,"tag":404,"props":2239,"children":2240},{},[2241],{"type":74,"value":747},{"type":74,"value":2243}," Treating IEC 62304 safety class as equivalent to FDA device class\n",{"type":68,"tag":404,"props":2245,"children":2246},{},[2247],{"type":74,"value":754},{"type":74,"value":2249}," IEC 62304 Class A\u002FB\u002FC is SOFTWARE safety; FDA Class I\u002FII\u002FIII is DEVICE risk. A Class II device can have Class C software.\n",{"type":68,"tag":404,"props":2251,"children":2252},{},[2253],{"type":74,"value":2254},"Why:",{"type":74,"value":2256}," Incorrect classification leads to insufficient documentation and testing — Critical severity",{"type":68,"tag":100,"props":2258,"children":2259},{},[2260,2264,2266,2270,2272,2276],{"type":68,"tag":404,"props":2261,"children":2262},{},[2263],{"type":74,"value":747},{"type":74,"value":2265}," Starting code before design inputs are documented\n",{"type":68,"tag":404,"props":2267,"children":2268},{},[2269],{"type":74,"value":754},{"type":74,"value":2271}," Document user needs → derive requirements → get DR1 approval → THEN build\n",{"type":68,"tag":404,"props":2273,"children":2274},{},[2275],{"type":74,"value":2254},{"type":74,"value":2277}," 21 CFR 820.30(c) requires design input documentation before design output. FDA will cite this. — Critical severity",{"type":68,"tag":100,"props":2279,"children":2280},{},[2281,2285,2287,2291,2293,2297],{"type":68,"tag":404,"props":2282,"children":2283},{},[2284],{"type":74,"value":747},{"type":74,"value":2286}," Omitting SOUP from the risk analysis\n",{"type":68,"tag":404,"props":2288,"children":2289},{},[2290],{"type":74,"value":754},{"type":74,"value":2292}," Every SOUP item must be assessed for known anomalies that could contribute to hazards\n",{"type":68,"tag":404,"props":2294,"children":2295},{},[2296],{"type":74,"value":2254},{"type":74,"value":2298}," IEC 62304 §7.1.3 mandates SOUP risk assessment; unassessed SOUP = undocumented risk — High severity",{"type":68,"tag":100,"props":2300,"children":2301},{},[2302,2306,2308,2312,2314,2318],{"type":68,"tag":404,"props":2303,"children":2304},{},[2305],{"type":74,"value":747},{"type":74,"value":2307}," Using \"testing\" as the only risk control\n",{"type":68,"tag":404,"props":2309,"children":2310},{},[2311],{"type":74,"value":754},{"type":74,"value":2313}," Testing VERIFIES a risk control works — it is not itself a control. Controls are architectural (watchdogs, bounds checks, redundancy).\n",{"type":68,"tag":404,"props":2315,"children":2316},{},[2317],{"type":74,"value":2254},{"type":74,"value":2319}," Confusing verification with mitigation leaves residual risk unaddressed — High severity",{"type":68,"tag":100,"props":2321,"children":2322},{},[2323,2327,2329,2333,2335,2339],{"type":68,"tag":404,"props":2324,"children":2325},{},[2326],{"type":74,"value":747},{"type":74,"value":2328}," No traceability between risk controls and verification tests\n",{"type":68,"tag":404,"props":2330,"children":2331},{},[2332],{"type":74,"value":754},{"type":74,"value":2334}," Each risk control in the hazard analysis must link to a specific test proving it works\n",{"type":68,"tag":404,"props":2336,"children":2337},{},[2338],{"type":74,"value":2254},{"type":74,"value":2340}," Without this link, you cannot demonstrate risk controls are effective — submission deficiency — High severity",{"type":68,"tag":100,"props":2342,"children":2343},{},[2344,2348,2350,2354,2356,2360],{"type":68,"tag":404,"props":2345,"children":2346},{},[2347],{"type":74,"value":747},{"type":74,"value":2349}," Performing design reviews as rubber-stamp exercises\n",{"type":68,"tag":404,"props":2351,"children":2352},{},[2353],{"type":74,"value":754},{"type":74,"value":2355}," Design reviews must have documented attendees, specific findings, action items, and resolution evidence\n",{"type":68,"tag":404,"props":2357,"children":2358},{},[2359],{"type":74,"value":2254},{"type":74,"value":2361}," FDA inspectors look for \"objective evidence\" of review — generic sign-offs get 483s — High severity",{"type":68,"tag":100,"props":2363,"children":2364},{},[2365,2369,2371,2375,2377,2381],{"type":68,"tag":404,"props":2366,"children":2367},{},[2368],{"type":74,"value":747},{"type":74,"value":2370}," Assuming De Novo is slower\u002Fharder than 510(k) for novel devices\n",{"type":68,"tag":404,"props":2372,"children":2373},{},[2374],{"type":74,"value":754},{"type":74,"value":2376}," De Novo creates a new predicate, establishing your market category. Average review: 9-12 months.\n",{"type":68,"tag":404,"props":2378,"children":2379},{},[2380],{"type":74,"value":2254},{"type":74,"value":2382}," Forcing substantial equivalence to a poor predicate leads to Additional Information requests and delays — Medium severity",{"type":68,"tag":100,"props":2384,"children":2385},{},[2386,2390,2392,2396,2398,2402],{"type":68,"tag":404,"props":2387,"children":2388},{},[2389],{"type":74,"value":747},{"type":74,"value":2391}," Treating cybersecurity as optional for non-connected devices\n",{"type":68,"tag":404,"props":2393,"children":2394},{},[2395],{"type":74,"value":754},{"type":74,"value":2397}," FDA's 2023 guidance applies to ALL devices with software. Threat model scope includes supply chain, update mechanism, and data-at-rest.\n",{"type":68,"tag":404,"props":2399,"children":2400},{},[2401],{"type":74,"value":2254},{"type":74,"value":2403}," FDA will RTA submissions without cybersecurity documentation — Medium severity",{"type":68,"tag":77,"props":2405,"children":2407},{"id":2406},"_13-part-11-electronic-records-decision-tree",[2408],{"type":74,"value":2409},"13. Part 11 (Electronic Records) Decision Tree",{"type":68,"tag":168,"props":2411,"children":2414},{"className":2412,"code":2413,"language":74},[171],"Does your system create, modify, maintain, or transmit records required by FDA regulations?\n├─ No → Part 11 not applicable (document why)\n├─ Yes → Assess scope:\n│  ├─ Full Part 11 (production system with regulatory records)\n│  │  Requirements: Audit trails, electronic signatures, access controls,\n│  │  system validation, backup\u002Frecovery, authority checks\n│  ├─ Part 11-lite (hospital IT manages infrastructure)\n│  │  Requirements: Your application provides audit trail + access control;\n│  │  rely on hospital IT for infrastructure validation\n│  └─ Development-only records (training data, model versions)\n│     Requirements: Version control with audit trail, access control,\n│     backup integrity verification\n\nElectronic Signature Requirements (if applicable):\n├─ Signature = legally binding (equivalent to handwritten)\n├─ Must include: signer name, date\u002Ftime, meaning (approval\u002Freview\u002Fauthorship)\n├─ Must be linked to record (cannot be separated)\n└─ Biometric or non-biometric (ID + password) with controls\n",[2415],{"type":68,"tag":175,"props":2416,"children":2417},{"__ignoreMap":177},[2418],{"type":74,"value":2413},{"type":68,"tag":77,"props":2420,"children":2422},{"id":2421},"_14-post-market-surveillance-essentials",[2423],{"type":74,"value":2424},"14. Post-Market Surveillance Essentials",{"type":68,"tag":418,"props":2426,"children":2428},{"id":2427},"mandatory-activities-by-market",[2429],{"type":74,"value":2430},"Mandatory Activities by Market",{"type":68,"tag":202,"props":2432,"children":2433},{},[2434,2458],{"type":68,"tag":206,"props":2435,"children":2436},{},[2437],{"type":68,"tag":210,"props":2438,"children":2439},{},[2440,2444,2448,2453],{"type":68,"tag":214,"props":2441,"children":2442},{},[2443],{"type":74,"value":821},{"type":68,"tag":214,"props":2445,"children":2446},{"align":824},[2447],{"type":74,"value":18},{"type":68,"tag":214,"props":2449,"children":2450},{"align":824},[2451],{"type":74,"value":2452},"EU MDR",{"type":68,"tag":214,"props":2454,"children":2455},{},[2456],{"type":74,"value":2457},"Frequency",{"type":68,"tag":235,"props":2459,"children":2460},{},[2461,2482,2502,2522,2542,2563,2584,2605],{"type":68,"tag":210,"props":2462,"children":2463},{},[2464,2469,2473,2477],{"type":68,"tag":242,"props":2465,"children":2466},{},[2467],{"type":74,"value":2468},"Medical Device Report (MDR\u002Fvigilance)",{"type":68,"tag":242,"props":2470,"children":2471},{"align":824},[2472],{"type":74,"value":478},{"type":68,"tag":242,"props":2474,"children":2475},{"align":824},[2476],{"type":74,"value":478},{"type":68,"tag":242,"props":2478,"children":2479},{},[2480],{"type":74,"value":2481},"Within 30 days (FDA) \u002F immediately for serious (EU)",{"type":68,"tag":210,"props":2483,"children":2484},{},[2485,2490,2494,2497],{"type":68,"tag":242,"props":2486,"children":2487},{},[2488],{"type":74,"value":2489},"Annual report",{"type":68,"tag":242,"props":2491,"children":2492},{"align":824},[2493],{"type":74,"value":478},{"type":68,"tag":242,"props":2495,"children":2496},{"align":824},[],{"type":68,"tag":242,"props":2498,"children":2499},{},[2500],{"type":74,"value":2501},"Annually",{"type":68,"tag":210,"props":2503,"children":2504},{},[2505,2510,2513,2517],{"type":68,"tag":242,"props":2506,"children":2507},{},[2508],{"type":74,"value":2509},"Periodic Safety Update Report (PSUR)",{"type":68,"tag":242,"props":2511,"children":2512},{"align":824},[],{"type":68,"tag":242,"props":2514,"children":2515},{"align":824},[2516],{"type":74,"value":478},{"type":68,"tag":242,"props":2518,"children":2519},{},[2520],{"type":74,"value":2521},"Annually (Class IIa+)",{"type":68,"tag":210,"props":2523,"children":2524},{},[2525,2530,2533,2537],{"type":68,"tag":242,"props":2526,"children":2527},{},[2528],{"type":74,"value":2529},"Post-Market Clinical Follow-up (PMCF)",{"type":68,"tag":242,"props":2531,"children":2532},{"align":824},[],{"type":68,"tag":242,"props":2534,"children":2535},{"align":824},[2536],{"type":74,"value":478},{"type":68,"tag":242,"props":2538,"children":2539},{},[2540],{"type":74,"value":2541},"Ongoing",{"type":68,"tag":210,"props":2543,"children":2544},{},[2545,2550,2554,2558],{"type":68,"tag":242,"props":2546,"children":2547},{},[2548],{"type":74,"value":2549},"Complaint handling",{"type":68,"tag":242,"props":2551,"children":2552},{"align":824},[2553],{"type":74,"value":478},{"type":68,"tag":242,"props":2555,"children":2556},{"align":824},[2557],{"type":74,"value":478},{"type":68,"tag":242,"props":2559,"children":2560},{},[2561],{"type":74,"value":2562},"Per event",{"type":68,"tag":210,"props":2564,"children":2565},{},[2566,2571,2575,2579],{"type":68,"tag":242,"props":2567,"children":2568},{},[2569],{"type":74,"value":2570},"CAPA process",{"type":68,"tag":242,"props":2572,"children":2573},{"align":824},[2574],{"type":74,"value":478},{"type":68,"tag":242,"props":2576,"children":2577},{"align":824},[2578],{"type":74,"value":478},{"type":68,"tag":242,"props":2580,"children":2581},{},[2582],{"type":74,"value":2583},"Per finding",{"type":68,"tag":210,"props":2585,"children":2586},{},[2587,2592,2596,2600],{"type":68,"tag":242,"props":2588,"children":2589},{},[2590],{"type":74,"value":2591},"Trend analysis",{"type":68,"tag":242,"props":2593,"children":2594},{"align":824},[2595],{"type":74,"value":478},{"type":68,"tag":242,"props":2597,"children":2598},{"align":824},[2599],{"type":74,"value":478},{"type":68,"tag":242,"props":2601,"children":2602},{},[2603],{"type":74,"value":2604},"Quarterly minimum",{"type":68,"tag":210,"props":2606,"children":2607},{},[2608,2613,2617,2621],{"type":68,"tag":242,"props":2609,"children":2610},{},[2611],{"type":74,"value":2612},"Software update reporting",{"type":68,"tag":242,"props":2614,"children":2615},{"align":824},[2616],{"type":74,"value":478},{"type":68,"tag":242,"props":2618,"children":2619},{"align":824},[2620],{"type":74,"value":478},{"type":68,"tag":242,"props":2622,"children":2623},{},[2624],{"type":74,"value":2625},"Per update (risk-based)",{"type":68,"tag":418,"props":2627,"children":2629},{"id":2628},"capa-trigger-decision-tree",[2630],{"type":74,"value":2631},"CAPA Trigger Decision Tree",{"type":68,"tag":168,"props":2633,"children":2636},{"className":2634,"code":2635,"language":74},[171],"Signal detected (complaint, trend, field event)\n├─ Safety-related?\n│  ├─ Yes → Immediate CAPA + potential field corrective action\n│  └─ No → Evaluate below\n├─ Systematic (affects multiple units\u002Fusers)?\n│  ├─ Yes → CAPA (root cause likely systemic)\n│  └─ No → Correction only (isolated incident)\n├─ Recurring (≥3 occurrences same root cause)?\n│  └─ Yes → CAPA mandatory (correction alone is insufficient)\n└─ Regulatory requirement (audit finding, FDA warning letter)?\n   └─ Yes → CAPA mandatory with defined timeline\n",[2637],{"type":68,"tag":175,"props":2638,"children":2639},{"__ignoreMap":177},[2640],{"type":74,"value":2635},{"type":68,"tag":77,"props":2642,"children":2644},{"id":2643},"when-not-to-use-this-skill",[2645],{"type":74,"value":2646},"When NOT to Use This Skill",{"type":68,"tag":96,"props":2648,"children":2649},{},[2650,2655,2660,2665,2670],{"type":68,"tag":100,"props":2651,"children":2652},{},[2653],{"type":74,"value":2654},"General software engineering without medical device claims — design controls add overhead without regulatory value",{"type":68,"tag":100,"props":2656,"children":2657},{},[2658],{"type":74,"value":2659},"Clinical data standards (CDISC SDTM\u002FADaM) — use cdisc-compliance skill instead",{"type":68,"tag":100,"props":2661,"children":2662},{},[2663],{"type":74,"value":2664},"Wellness\u002Ffitness apps with NO diagnostic or therapeutic claims — not regulated as devices",{"type":68,"tag":100,"props":2666,"children":2667},{},[2668],{"type":74,"value":2669},"eCTD submission assembly or eSTAR portal mechanics — this skill covers device compliance, not submission logistics",{"type":68,"tag":100,"props":2671,"children":2672},{},[2673],{"type":74,"value":2674},"Manufacturing quality (GMP, process validation for physical devices) — this skill focuses on software lifecycle",{"type":68,"tag":77,"props":2676,"children":2678},{"id":2677},"when-to-escalate-to-human-expert",[2679],{"type":74,"value":2680},"When to Escalate to Human Expert",{"type":68,"tag":96,"props":2682,"children":2683},{},[2684,2689,2694,2699,2704],{"type":68,"tag":100,"props":2685,"children":2686},{},[2687],{"type":74,"value":2688},"Safety classification disagreement where reasonable arguments support multiple classes — requires cross-functional risk team decision",{"type":68,"tag":100,"props":2690,"children":2691},{},[2692],{"type":74,"value":2693},"Predicate selection for 510(k) where no clear substantial equivalence exists — may need pre-submission meeting with FDA",{"type":68,"tag":100,"props":2695,"children":2696},{},[2697],{"type":74,"value":2698},"Clinical evidence sufficiency questions — requires clinical affairs and biostatistics expertise",{"type":68,"tag":100,"props":2700,"children":2701},{},[2702],{"type":74,"value":2703},"EU MDR classification under Rule 11 for borderline CDS\u002Fwellness software — requires Notified Body pre-assessment",{"type":68,"tag":100,"props":2705,"children":2706},{},[2707],{"type":74,"value":2708},"Post-market safety signal assessment for potential field action — requires medical director and regulatory affairs",{"items":2710,"total":2890},[2711,2732,2753,2763,2776,2789,2799,2809,2830,2845,2860,2875],{"slug":2712,"name":2712,"fn":2713,"description":2714,"org":2715,"tags":2716,"stars":2729,"repoUrl":2730,"updatedAt":2731},"agentcore-investigation","investigate Bedrock AgentCore runtime sessions","Investigate Bedrock AgentCore runtime sessions via CloudWatch Logs Insights — resolve session\u002Ftrace IDs, query OTEL spans, filter noise, build timelines. Use when debugging AgentCore agent sessions, tracing tool calls, or analyzing latency.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2717,2720,2723,2726],{"name":2718,"slug":2719,"type":16},"AWS","aws",{"name":2721,"slug":2722,"type":16},"Debugging","debugging",{"name":2724,"slug":2725,"type":16},"Logs","logs",{"name":2727,"slug":2728,"type":16},"Observability","observability",9427,"https:\u002F\u002Fgithub.com\u002Fawslabs\u002Fmcp","2026-07-12T08:37:22.601527",{"slug":2733,"name":2734,"fn":2735,"description":2736,"org":2737,"tags":2738,"stars":2729,"repoUrl":2730,"updatedAt":2752},"amazon-aurora-dsql","amazon aurora dsql","build applications with Aurora DSQL","Build with Aurora DSQL — manage schemas, execute queries, handle migrations, diagnose query plans, load data, and develop applications with a serverless, distributed SQL database. Covers IAM auth, multi-tenant patterns, MySQL-to-DSQL and PostgreSQL-to-DSQL schema conversion, FK replacement code generation, OCC retry patterns, ORM migration (Django\u002FHibernate\u002FRails), DDL operations, query plan explainability, SQL compatibility validation, and bulk data loading. Triggers on phrases like: DSQL, Aurora DSQL, create DSQL table, DSQL schema, migrate to DSQL, distributed SQL database, serverless PostgreSQL-compatible database, DSQL query plan, DSQL EXPLAIN ANALYZE, why is my DSQL query slow, DSQL foreign key, DSQL OCC retry, DSQL multi-region, load into DSQL, load CSV into DSQL, bulk load DSQL, aurora-dsql-loader.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2739,2742,2743,2746,2749],{"name":2740,"slug":2741,"type":16},"Aurora","aurora",{"name":2718,"slug":2719,"type":16},{"name":2744,"slug":2745,"type":16},"Database","database",{"name":2747,"slug":2748,"type":16},"Serverless","serverless",{"name":2750,"slug":2751,"type":16},"SQL","sql","2026-07-12T08:36:45.053393",{"slug":2754,"name":2755,"fn":2735,"description":2736,"org":2756,"tags":2757,"stars":2729,"repoUrl":2730,"updatedAt":2762},"aurora-dsql","aurora dsql",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2758,2759,2760,2761],{"name":2718,"slug":2719,"type":16},{"name":2744,"slug":2745,"type":16},{"name":2747,"slug":2748,"type":16},{"name":2750,"slug":2751,"type":16},"2026-07-12T08:36:42.694299",{"slug":2764,"name":2765,"fn":2735,"description":2736,"org":2766,"tags":2767,"stars":2729,"repoUrl":2730,"updatedAt":2775},"aws-dsql","aws dsql",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2768,2769,2770,2773,2774],{"name":2718,"slug":2719,"type":16},{"name":2744,"slug":2745,"type":16},{"name":2771,"slug":2772,"type":16},"Migration","migration",{"name":2747,"slug":2748,"type":16},{"name":2750,"slug":2751,"type":16},"2026-07-12T08:36:38.584057",{"slug":2777,"name":2778,"fn":2735,"description":2736,"org":2779,"tags":2780,"stars":2729,"repoUrl":2730,"updatedAt":2788},"distributed-postgres","distributed postgres",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2781,2782,2783,2786,2787],{"name":2718,"slug":2719,"type":16},{"name":2744,"slug":2745,"type":16},{"name":2784,"slug":2785,"type":16},"PostgreSQL","postgresql",{"name":2747,"slug":2748,"type":16},{"name":2750,"slug":2751,"type":16},"2026-07-12T08:36:46.530743",{"slug":2790,"name":2791,"fn":2735,"description":2736,"org":2792,"tags":2793,"stars":2729,"repoUrl":2730,"updatedAt":2798},"distributed-sql","distributed sql",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2794,2795,2796,2797],{"name":2718,"slug":2719,"type":16},{"name":2744,"slug":2745,"type":16},{"name":2747,"slug":2748,"type":16},{"name":2750,"slug":2751,"type":16},"2026-07-12T08:36:48.104182",{"slug":2800,"name":2800,"fn":2735,"description":2736,"org":2801,"tags":2802,"stars":2729,"repoUrl":2730,"updatedAt":2808},"dsql",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2803,2804,2805,2806,2807],{"name":2718,"slug":2719,"type":16},{"name":2744,"slug":2745,"type":16},{"name":2771,"slug":2772,"type":16},{"name":2747,"slug":2748,"type":16},{"name":2750,"slug":2751,"type":16},"2026-07-12T08:36:36.374512",{"slug":2810,"name":2810,"fn":2811,"description":2812,"org":2813,"tags":2814,"stars":2827,"repoUrl":2828,"updatedAt":2829},"cost-efficiency-analyzer","analyze cost efficiency and expenses","Analyzes cost structure, cost efficiency, and expense management from P&L data. Use when the user asks about costs, expenses, COGS, operating expenses, cost ratios, cost control, spending efficiency, margin compression from cost side, or wants to understand where money is going. Also use for \"are we spending too much\", \"cost breakdown\", \"expense analysis\", or \"how efficient are our operations\". NOT for revenue or top-line analysis.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2815,2818,2821,2824],{"name":2816,"slug":2817,"type":16},"Accounting","accounting",{"name":2819,"slug":2820,"type":16},"Analytics","analytics",{"name":2822,"slug":2823,"type":16},"Cost Optimization","cost-optimization",{"name":2825,"slug":2826,"type":16},"Finance","finance",3176,"https:\u002F\u002Fgithub.com\u002Fawslabs\u002Fagentcore-samples","2026-07-12T08:40:03.29555",{"slug":2831,"name":2831,"fn":2832,"description":2833,"org":2834,"tags":2835,"stars":2827,"repoUrl":2828,"updatedAt":2844},"executive-financial-briefing","generate executive financial briefings","Generates a concise executive-level financial briefing or summary suitable for a CEO, CFO, or board presentation. Use when the user asks for a summary, briefing, executive summary, board update, financial overview, financial health check, or \"how is the business doing\". Covers the full P&L picture in one page. Also use for \"give me the highlights\", \"what do I need to know\", or \"quick financial update\".",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2836,2837,2838,2841],{"name":2718,"slug":2719,"type":16},{"name":2825,"slug":2826,"type":16},{"name":2839,"slug":2840,"type":16},"Management","management",{"name":2842,"slug":2843,"type":16},"Reporting","reporting","2026-07-12T08:40:02.066471",{"slug":2846,"name":2846,"fn":2847,"description":2848,"org":2849,"tags":2850,"stars":2827,"repoUrl":2828,"updatedAt":2859},"multi-quarter-trend-analysis","analyze multi-quarter financial trends","Analyzes financial trends across multiple quarters by comparing P&L metrics over time. Use when the user wants to see trends, patterns, trajectories, or directional movement across 3 or more quarters. Also use for \"how are we trending\", \"show me the trend\", \"track performance over time\", \"quarter over quarter comparison across all quarters\", or any multi-period longitudinal analysis.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2851,2852,2853,2856],{"name":2819,"slug":2820,"type":16},{"name":2825,"slug":2826,"type":16},{"name":2854,"slug":2855,"type":16},"Financial Statements","financial-statements",{"name":2857,"slug":2858,"type":16},"Variance Analysis","variance-analysis","2026-07-12T08:40:00.79141",{"slug":2861,"name":2861,"fn":2862,"description":2863,"org":2864,"tags":2865,"stars":2827,"repoUrl":2828,"updatedAt":2874},"pdf","process and manipulate PDF documents","Use this skill whenever the user wants to do anything with PDF files. This includes reading or extracting text\u002Ftables from PDFs, combining or merging multiple PDFs into one, splitting PDFs apart, rotating pages, adding watermarks, creating new PDFs, filling PDF forms, encrypting\u002Fdecrypting PDFs, extracting images, and OCR on scanned PDFs to make them searchable. If the user mentions a .pdf file or asks to produce one, use this skill.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2866,2869,2872],{"name":2867,"slug":2868,"type":16},"Automation","automation",{"name":2870,"slug":2871,"type":16},"Documents","documents",{"name":2873,"slug":2861,"type":16},"PDF","2026-07-12T08:41:44.135656",{"slug":2876,"name":2876,"fn":2877,"description":2878,"org":2879,"tags":2880,"stars":2827,"repoUrl":2828,"updatedAt":2889},"quarterly-kpi-calculator","calculate quarterly financial KPIs","Calculates quarterly financial KPIs from P&L data. P&L figures can be provided directly by the user or fetched from the financial data MCP server. Use when the user wants KPI calculations such as Gross Margin %, EBITDA Margin %, Operating Expense Ratio, or Revenue Growth % QoQ. Also use for quarterly performance review, P&L analysis, or interpreting financial ratios against benchmarks.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2881,2882,2885,2886],{"name":2816,"slug":2817,"type":16},{"name":2883,"slug":2884,"type":16},"Data Analysis","data-analysis",{"name":2825,"slug":2826,"type":16},{"name":2887,"slug":2888,"type":16},"KPI","kpi","2026-07-12T08:39:59.54971",150,{"items":2892,"total":2986},[2893,2910,2925,2937,2950,2963,2976],{"slug":2894,"name":2894,"fn":2895,"description":2896,"org":2897,"tags":2898,"stars":26,"repoUrl":27,"updatedAt":2909},"aws-genai-ml-architect","design AWS GenAI and ML architectures","Reasoning skill for designing AWS GenAI and ML architectures for healthcare and life sciences workloads. Use when the user asks to choose between SageMaker and Bedrock, design a RAG system over medical literature, architect clinical NLP or medical imaging inference, plan genomics or drug discovery pipelines on AWS, address HIPAA\u002FPHI compliance in ML systems, design MLOps for regulated clinical models, or optimize cost for HCLS ML workloads. Triggers include \"AWS architecture\", \"SageMaker vs Bedrock\", \"HIPAA ML\", \"clinical RAG\", \"medical imaging inference\", \"genomics on AWS\", \"PHI training\", \"MLOps healthcare\", \"Bedrock guardrails\", \"HealthLake\", \"HCLS cloud architecture\", \"BAA compliance\", \"SageMaker endpoint\", \"Bedrock knowledge base\", \"clinical NLP on AWS\", \"FDA SaMD on AWS\".",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2899,2902,2903,2904,2906],{"name":2900,"slug":2901,"type":16},"Architecture","architecture",{"name":2718,"slug":2719,"type":16},{"name":14,"slug":15,"type":16},{"name":2905,"slug":41,"type":16},"Life Sciences",{"name":2907,"slug":2908,"type":16},"LLM","llm","2026-07-12T08:38:07.975937",{"slug":2911,"name":2911,"fn":2912,"description":2913,"org":2914,"tags":2915,"stars":26,"repoUrl":27,"updatedAt":2924},"biomarker-discovery","guide biomarker discovery and validation","Reason about biomarker discovery and validation in HCLS — classifying biomarker intent, choosing feature-selection and cross-validation strategies, avoiding leakage, and planning external replication. Use when the user asks to discover, develop, or validate a biomarker; select features from high-dimensional omics or clinical data; design a validation study; choose evaluation metrics; justify sample size; combine multi-omics signals; or assess clinical utility. Triggers include \"discover a biomarker\", \"validate biomarker\", \"prognostic vs predictive\", \"feature selection\", \"LASSO vs elastic net\", \"nested cross-validation\", \"data leakage\", \"C-index\", \"time-dependent AUC\", \"decision curve analysis\", \"external validation cohort\", \"events per variable\", \"optimism-corrected\", \"multi-omics integration\", \"clinical utility of a biomarker\", \"is this biomarker ready\".",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2916,2917,2920,2921],{"name":2718,"slug":2719,"type":16},{"name":2918,"slug":2919,"type":16},"Bioinformatics","bioinformatics",{"name":2905,"slug":41,"type":16},{"name":2922,"slug":2923,"type":16},"Research","research","2026-07-12T08:37:49.295301",{"slug":2926,"name":2926,"fn":2927,"description":2928,"org":2929,"tags":2930,"stars":26,"repoUrl":27,"updatedAt":2936},"cdisc-compliance","reason about CDISC SDTM and ADaM implementation","Reason about CDISC SDTM and ADaM implementation for regulatory submissions. Use when the user asks about SDTM domain mapping, ADaM dataset design, controlled terminology versioning, define.xml completeness, FDA or PMDA submission requirements, query prioritization by clinical impact, SUPPQUAL usage, or CDISC compliance review. Triggers include \"SDTM mapping\", \"ADaM dataset\", \"CDISC compliance\", \"controlled terminology\", \"define.xml\", \"FDA submission data\", \"PMDA submission\", \"SDTM domain\", \"ADSL\", \"ADAE\", \"ADLB\", \"BDS structure\", \"SUPPQUAL\", \"RELREC\", \"value-level metadata\", \"CDISC CT\", \"regulatory submission data standards\", \"eCTD datasets\", \"SDTM 3.3\", \"ADaM 1.1\", \"query prioritization\", \"clinical data review\".\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2931,2934,2935],{"name":2932,"slug":2933,"type":16},"Clinical Trials","clinical-trials",{"name":2905,"slug":41,"type":16},{"name":21,"slug":22,"type":16},"2026-07-12T08:37:33.35594",{"slug":2938,"name":2938,"fn":2939,"description":2940,"org":2941,"tags":2942,"stars":26,"repoUrl":27,"updatedAt":2949},"cell-type-annotation","annotate single-cell RNA-seq clusters","Generate code to assign cell type labels to single-cell RNA-seq clusters using CellTypist, SingleR, marker-based annotation, or reference label transfer (scANVI\u002Fingest). Triggers on requests to \"annotate cell types\", \"label clusters\", \"run CellTypist\", \"SingleR annotation\", \"marker gene dotplot\", \"transfer labels from reference atlas\", \"cell identity\", \"automated annotation\", \"reference mapping\", \"scANVI label transfer\", \"canonical markers\", \"immune cell types\", \"hierarchical annotation\", \"majority voting CellTypist\", \"over-clustering annotation\".",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2943,2944,2945,2946],{"name":2918,"slug":2919,"type":16},{"name":2883,"slug":2884,"type":16},{"name":2905,"slug":41,"type":16},{"name":2947,"slug":2948,"type":16},"RNA-seq","rna-seq","2026-07-12T08:38:05.443454",{"slug":2951,"name":2951,"fn":2952,"description":2953,"org":2954,"tags":2955,"stars":26,"repoUrl":27,"updatedAt":2962},"cheminformatics","calculate molecular properties with RDKit","Cheminformatics pipeline for small-molecule property calculation, filtering, and similarity analysis using RDKit. Use when the user asks to compute molecular descriptors, filter compounds by Lipinski or Veber rules, detect PAINS, calculate fingerprint similarity, run matched molecular pair analysis, generate ADMET descriptors, or process SMILES. Triggers include \"RDKit\", \"molecular descriptors\", \"Lipinski\", \"rule of five\", \"Veber\", \"PAINS\", \"pan-assay interference\", \"Morgan fingerprint\", \"Tanimoto\", \"fingerprint similarity\", \"matched molecular pair\", \"MMP\", \"mmpdb\", \"ADMET\", \"druglikeness\", \"SMILES\", \"cheminformatics\", \"compound filtering\", \"chemical similarity\".",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2956,2957,2960,2961],{"name":2918,"slug":2919,"type":16},{"name":2958,"slug":2959,"type":16},"Chemistry","chemistry",{"name":2883,"slug":2884,"type":16},{"name":2922,"slug":2923,"type":16},"2026-07-12T08:37:28.334619",{"slug":2964,"name":2964,"fn":2965,"description":2966,"org":2967,"tags":2968,"stars":26,"repoUrl":27,"updatedAt":2975},"claims-analytics","analyze and parse healthcare claims data","Pipeline skill for healthcare claims data parsing, analysis, and fraud detection. Use when the user asks to parse X12 837 or 835 claim files, manipulate ICD-10 CPT or HCPCS codes, detect billing pattern anomalies, profile providers against specialty peers, identify outlier billing behavior, validate NCCI edits programmatically, detect duplicate claims, run Benford's law analysis on charges, build claims data pipelines, or analyze E&M code distributions. Triggers include \"parse X12 837\", \"parse 835\", \"claims SQL\", \"ICD-10 manipulation\", \"CPT code analysis\", \"provider profiling\", \"billing outlier\", \"NCCI validation code\", \"duplicate claim detection\", \"Benford's law charges\", \"claims ETL\", \"E&M distribution analysis\", \"claims analytics pipeline\".\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2969,2970,2971,2974],{"name":2883,"slug":2884,"type":16},{"name":14,"slug":15,"type":16},{"name":2972,"slug":2973,"type":16},"Insurance","insurance",{"name":2905,"slug":41,"type":16},"2026-07-12T08:37:34.815088",{"slug":2977,"name":2977,"fn":2978,"description":2979,"org":2980,"tags":2981,"stars":26,"repoUrl":27,"updatedAt":2985},"claims-billing-rules","analyze healthcare claims billing rules","Reasoning skill for healthcare claims billing rules and fraud detection logic. Use when the user asks about CMS billing rules, place of service codes, global surgery periods, modifier usage (25 59 76 77), NCCI edit logic, column 1 column 2 code pairs, mutually exclusive procedures, modifier indicators, fraud waste and abuse patterns, E&M upcoding, unbundling, phantom billing, impossible day detection, coding error versus fraud distinction, FWA investigation methodology, or claims audit logic. Triggers include \"CMS billing rules\", \"NCCI edits\", \"modifier 25\", \"modifier 59\", \"global surgery period\", \"upcoding\", \"unbundling\", \"phantom billing\", \"impossible day\", \"FWA\", \"fraud waste abuse\", \"coding error vs fraud\", \"claims audit\", \"billing compliance\", \"E&M level selection\".\n",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[2982,2983,2984],{"name":14,"slug":15,"type":16},{"name":2972,"slug":2973,"type":16},{"name":21,"slug":22,"type":16},"2026-07-12T08:38:28.210856",40]