Standards, Guidance & Notices
Showing 51–60 of 71
MHLW
Notice
Notice
MHLW-PSEHB-MDED-0331-No.1
Partial Amendment of Guideline on Software as a Medical Device Classification
Revision of 2021 SaMD classification guideline (2023 version). Clarifies and refines classification criteria based on accumulated consultation cases. Adds judgment criteria for AI/ML-enabled software, cloud-based programs, and wellness applications. Maintains alignment with IMDRF N10 and N12. Updates judgment flow based on intended use and risk.
Published: 2023-03-31
MHLW
Notice
Notice
医政参発0331-No.1
Guideline for Ensuring Cybersecurity of Medical Devices in Healthcare Facilities
MHLW notification of Cybersecurity Guideline for healthcare facility administrators and staff. Presents practical procedures for information collection from manufacturers, risk assessment, pre-implementation verification, vulnerability response during operation, and EOL management. Positioned as the healthcare facility counterpart to the related manufacturer-directed guideline, structured to promote coordination between both parties.
Published: 2023-03-31
MHLW
Notice
Notice
MHLW-PSEHB-MDED-0331-No.11
Revision of Cybersecurity Implementation Guideline for Medical Devices
MHLW notification of revised Cybersecurity Guideline for Medical Device Manufacturers (2nd Edition). Updated to align with Essential Principles Article 12(3) implementation. Provides practical procedures for security requirements identification, architecture design, SBOM, PSIRT establishment, and vulnerability disclosure. Functions as specific guidance for JIS T 81001-5-1 application.
Published: 2023-03-31
MHLW
Notice
Notice
MHLW-PSEHB-MDED-0331-No.8
Notice on Application of Essential Principles Article 12(3) for Medical Devices
Interpretation notice accompanying April 1, 2023 enforcement of Essential Principles Article 12(3) cybersecurity requirements. Mandates three elements for network-connected medical devices: lifecycle cybersecurity planning, risk reduction design, and minimum operational environment specifications. Recognizes JIS T 81001-5-1 conformance as equivalent to Article 12(3) compliance. Provides transition period until March 31, 2024.
Published: 2023-03-31
JFMDA
Notice
Notice
jfmda_20221020_b84d0618
Handling of Software as a Medical Device (SaMD) Class I Products_October 20, 2022
Overview of handling procedures for SaMD Class I products. This document summarizes materials presented during the 2022 SaMD regulatory compliance seminar as an activity report by the SaMD Regulation Response Sub-Working Group.
Published: 2022-10-20
JFMDA
Notice
Notice
jfmda_20221020_fcd85f82
Explanatory Document for Software Medical Device Applicability Guideline - JFMDA Edition Version 1.0 October 20, 2022
JFMDA explanatory document providing detailed guidance on software medical device applicability determination and classification. Clarifies regulatory interpretation for software qualification and classification to support industry compliance and regulatory submissions.
Published: 2022-10-20
IMDRF
IMDRF/AIMD WG/N67 (Edition 1)
Machine Learning-enabled Medical Devices: Key Terms and Definitions
Edition 1 of the IMDRF Artificial Intelligence Medical Devices (AIMD) Working Group document on key terms and definitions for Machine Learning-enabled Medical Devices (MLMD). It establishes terms and definitions across the total product life cycle to promote consistency, support global harmonization, and provide a foundation for future guidelines on MLMD. Section 5 provides key definitions relevant to machine learning used in medical devices (including the definition of MLMD), Section 6 gives definitions from technical standards (e.g., bias, continuous learning, reference standard, reinforcement learning), and Section 7 discusses common machine learning terms. Most terms were previously defined in GHTF documents or internationally recognized AI standards, while some were developed or discussed by the AIMD Working Group. The document also notes that the term "bias" is used differently in data science and in legal discussions.
Published: 2022-05-09
EU
MDCG
MDCG
Helsinki Procedure
Helsinki Procedure for borderline and classification under MDR & IVDR
Establishes the procedure by which competent authorities (CAs) in EU Member States consult one another on complex borderline and classification questions under the MDR (2017/745) and IVDR (2017/746), producing consistent EU-wide positions published in the Manual on Borderline and Classification. Manufacturers and trade associations can request an EU-wide opinion via a CA. The initiating CA submits a standardised enquiry describing the device, its intended purpose and the classification issue; other CAs respond within about one month. If more than 75% agree, a draft Manual entry is prepared and put to a vote (adoption requires a 75% majority); where consensus is not reached, the case is escalated to CA meetings or a task force, with coordination from other MDCG working groups (e.g. the New Technologies Working Group) for technology-specific questions. The full process, from enquiry to publication, takes roughly 5.5 months. The procedure is not limited to any particular product category and can be used for unclear qualification/classification questions involving SaMD.
Published: 2021-09-01
MHLW
Notice
Notice
MHLW-PSEHB-MDED-0831-No.14
Handling of Applications for Confirmation of Change Control Plans for Medical Devices
Foundational notification establishing Japan's IDATEN system (Improvement Design within Approval for Timely Evaluation and Notice). Defines the scope of eligible changes, application form requirements, supporting documentation, and notification procedures for implementing changes under a confirmed plan. Enables AI-enabled SaMD and other devices with anticipated post-market improvements to implement changes via minor change notification rather than full partial change approval.
Published: 2020-08-31
EU
MDCG
MDCG
MDCG 2019-16 rev.1
Guidance on cybersecurity for medical devices
Explains how manufacturers meet the cybersecurity-related general safety and performance requirements (GSPRs) in Annex I of the MDR (2017/745) and IVDR (2017/746) across the full device lifecycle, for medical devices and IVDs that include programmable electronic systems or software -- SaMD, embedded software, mobile apps, networked devices, and systems relying on hospital networks or cloud services. Its central principle is that "security is part of safety and risk management," and it distinguishes between (1) built-in security capabilities -- authentication, authorization, integrity protection, logging, backup/recovery, and secure update mechanisms -- and (2) security information that must be documented, covering the operating environment, configuration, accounts, network controls, updates and residual risk. Pre-market expectations include linking threat analysis to the safety risk management file, applying defence-in-depth controls (least privilege, strong identity management, protected communications, audit logging), and defining testable operating-environment requirements. Post-market expectations include active monitoring of vulnerability sources (databases, researcher reports, supplier notices, threat intelligence), risk assessment, coordinated disclosure, security updates and communication to users. The guidance frames cybersecurity as a shared responsibility between manufacturer and healthcare provider, while stressing that a manufacturer cannot transfer its own design and regulatory obligations to the hospital or user, and aligns with IMDRF's international guidance on medical device cybersecurity.
Published: 2020-07-01
