A SaMD technical file cannot be handled with the tools and methodology of a physical device. The specificities are real, and the notified bodies that review medical software files have precise requirements that manufacturers unfamiliar with the sector often discover too late.
Software requirements specification
Every SaMD technical file must contain documentation of the software requirements: what the software is supposed to do, under which conditions of use, with which performance constraints, and for which user population. This documentation is the starting point for all development and validation activities.
The requirements must be traceable: each validation test must be linkable to a precise requirement, and each requirement must have been tested.
Software validation according to IEC 62304
The IEC 62304 standard defines the requirements for the medical software life cycle. It covers requirements analysis, architectural design, detailed design, implementation, verification and validation testing, configuration management, and problem resolution.
The standard distinguishes three software safety classes according to the severity of the consequences of a defect: class A (no injury), class B (non-serious injury), class C (death or serious injury). The documentation and testing requirements increase with the class.
The IEC 62304 safety class is distinct from the MDR class, but the two are linked: a class IIb SaMD in most cases implies class B or C software according to IEC 62304.
Cybersecurity risk management
SaMD are exposed to specific cybersecurity risks absent from purely physical devices: attacks on patient data, manipulation of algorithms, service interruption. In 2019, the MDCG published (and has since updated) the MDCG 2019-16 guidance on the cybersecurity of medical devices.
The technical file of a SaMD must include cybersecurity risk management documentation: threat identification, cybersecurity risk assessment, protective measures put in place, and a post-market vulnerability management plan.
Specific clinical evaluation
Clinical data for a SaMD are different in nature from those of a physical device. Notified bodies accept algorithmic performance data (sensitivity, specificity, PPV, NPV on representative cohorts), clinical data assessing the impact of the software on clinical decisions and patient outcomes, and real-world data from registries or hospital databases.
The MDCG 2020-1 guidance on clinical data for SaMD specifies the acceptable sources and the criteria for assessing their quality.
Sources: