Consider the user and clinical context · Verify user knowledge before enabling riskier functions
Counts the explicit approaches or boundaries identified in this passage. Categories can overlap; the stated clinical scope still applies.
Read the source passage
2. CDRH seeks input on how to account for the spectrum of GenAI-enabled informational functions that vary in the degree to which they direct a user to a Vizma Carver, CISSP, PMP Vizma.carver@cg-hg.com 703-943-0894 particular action (i.e., between “non-directive” and “action-directing”). What characteristics of an output—such as its wording, specificity, personalization, or context—could be considered as modifiers of the risk associated with an informational function, after accounting for the device’s overall functionality and intended use? What additional information would provide manufacturers with sufficient clarity and predictability around risk assessment for informational functions while recognizing that directiveness may exist along a continuum rather than as a binary distinction? Response: Response 1: Build on existing terminology rather than creating a new vocabulary Defining the line between "non-directive" and "action-directing" is genuinely difficult, and a new taxonomy will be litigated at the margins for years. CDRH already has settled vocabulary in Factors to Consider When Making Benefit-Risk Determinations in Medical Device Premarket Approval and De Novo Classifications (FDA). Novel terminology increases the risk that manufacturers misread regulatory intent; reusing established terms reinforces it. Recommendation 1: do not treat directiveness as a new category, Treat it as a modifier of an existing factor — the probability of a harmful event. Reesponse 2: shift from a fixed IFU to risk-scaled competency affirmation This is software-based guidance, and software permits a protection mechanism that hardware does not: the device can confirm what the user understands before it operates. The current model — a fixed Instructions for Use, delivered once, with no affirmation of competency — assumes a static user. Categorical proxies such as patient versus HCP, or generalist versus specialist, are coarse and do not reflect how people actually engage with their care. Some patients become deeply expert in their own condition; others defer entirely to the medical establishment. A single label cannot distinguish them. Recommendation 2: permit and, at higher risk levels, require affirmation of user knowledge and competency as a gating precondition to enabling the function, with the depth of affirmation scaled to the device's risk level. A low- consequence informational function may need only acknowledgment. A function directing insulin titration should confirm that the specific user understands the correct output range, the failure modes, and the conditions requiring escalation, Vizma Carver, CISSP, PMP Vizma.carver@cg-hg.com 703-943-0894 before that capability unlocks — and should re-affirm on a defined interval or when the function is updated. 3. CDRH seeks input on whether and when a GenAI-enabled function that results in delivery of clinical information to patients, as opposed to HCPs, could present different or higher risks, while also recognizing the potential benefits associated with improved patient empowerment, engagement, and access to clinical information. What device characteristics, output features, or safeguards might mitigate risks that could arise when a user lacks the domain knowledge to independently evaluate an output, without unnecessarily underestimating patient capability? Response: The premise requires correction The question is framed around users "who lack the domain knowledge to independently evaluate an output," with patients as the implied class. We object to that framing as both inaccurate and counterproductive. The framing treats a credential as a proxy for a capability. It is not. Competence within any credentialed population is a distribution, not a constant — half of all practicing clinicians graduated in the bottom half of their class. Meanwhile, patients living with a chronic condition frequently accumulate more contextual and longitudinal knowledge of that condition than the generalist reviewing them for twelve minutes. Neither observation is a criticism of clinicians. Both are reasons that "patient versus HCP versus specialist" is the wrong variable. Credentialing does not reliably confer output-evaluation ability If professional credentialing were sufficient to catch incorrect clinical information, the patient safety movement of the last twenty-five years would not exist. To Err Is Human estimated 44,000 to 98,000 preventable deaths annually in U.S. hospitals and set a goal of halving errors within five years (National Academies). That goal was not met. More recently, an estimated 795,000 Americans are permanently disabled or die each year because dangerous diseases are misdiagnosed, across both hospital and clinic settings (BMJ Quality & Safety, AHRQ). These are errors made by credentialed professionals evaluating clinical information. A framework that shifts risk downward for HCP-facing functions on the strength of the credential alone assumes an error-detection capab
Original source ↗