Functional Practice

Digital Health & Cybersecurity Practice

SaMD classification and submissions, AI/ML submission content, Predetermined Change Control Plans, and Section 524B cybersecurity documentation.

What This Practice Does

The Digital Health & Cybersecurity Practice supports software as a medical device (SaMD), AI/ML-enabled device submissions, and the cybersecurity documentation Section 524B now requires for cyber devices. That includes SaMD classification and pathway determination, the specific submission content an AI/ML-enabled device needs to support its classification, Predetermined Change Control Plan (PCCP) development for devices whose algorithms are expected to change after clearance, and the full 524B package: threat model, Software Bill of Materials (SBOM), vulnerability management process, and postmarket monitoring plan. The practice also covers interoperability considerations and the software documentation level determination that scopes how much technical detail a submission needs to include.

How the Work Is Run

Work typically starts with a classification and pathway call — is this device SaMD, is it a cyber device under 524B, or both — followed by a documentation-level assessment that sets the scope of everything downstream. For AI/ML devices, the practice builds out the Good Machine Learning Practice (GMLP) evidence a submission needs: training/test data provenance, population representativeness, and a monitoring plan for performance drift after deployment. For 524B, the practice reviews or builds the threat model against the device's actual architecture (not generic Secure Product Development Framework language), checks SBOM completeness and machine-readability, and confirms the vulnerability management and disclosure plan is in place before submission.

Device Areas This Practice Serves

This practice is the natural lead for the Digital Health & SaMD device area and works alongside the Regulatory Submissions practice on the 510(k) or De Novo filing itself. For connected cardiovascular devices — implantables with remote monitoring, for example — the practice coordinates 524B and SaMD work directly with the Clinical & IDE practice's device-area lead so cybersecurity and clinical strategy are built together, not bolted on afterward.

Typical Engagement Flow

Engagements typically start with a classification call to determine whether a device is SaMD, a cyber device under Section 524B, or both, which sets the documentation level and scope for everything downstream. For AI/ML devices, the practice then builds the GMLP evidence package and, where relevant, a Predetermined Change Control Plan alongside the submission draft. For 524B, the practice reviews or constructs the threat model, SBOM, and vulnerability management plan in parallel with the regulatory submission itself, so cybersecurity documentation and the device classification argument are developed together rather than as two disconnected workstreams that FDA reviewers end up reconciling on the sponsor's behalf.

Why a Single Director of Record Matters

AI/ML and connected-device submissions tend to draw more interactive review questions than a conventional device, because FDA reviewers are still working through how its SaMD and cybersecurity frameworks apply to a genuinely novel architecture. A director who built the threat model and the GMLP evidence package from the start can answer those questions directly from the device's actual design — rather than a second reader trying to reconstruct the reasoning behind a PCCP or an SBOM scoping decision after the fact. This practice is structured to keep that continuity through every round of review, including any post-clearance change evaluated under an already-authorized PCCP.

Who Leads It

Practice Director, Digital Health & Cybersecurity. Your practice director is named in the proposal and statement of work.

Related Services

Get Started

Talk to the Digital Health & Cybersecurity Practice

30 minutes to assess your SaMD classification, 524B readiness, or AI/ML strategy.