Bringing a Neonatal Retinal Imaging Platform up to Current FDA Requirements
How NexorTest’s SaMD regulatory expert team has rebuilt the entire regulatory framework of a cloud hosted SaMD platform, which constitutes remediation of full Design History File, IEC 62304 verification and validation, cybersecurity and HIPAA safeguards while engineering the product, labelling, and claims to match the classification and regulatory requirements as per US FDA regulations.
At a Glance
| Field | Details |
|---|---|
Product | Web based wide field retinal imaging and remote review platform (SaMD), used in NICU retinopathy-of-prematurity (ROP) screening programs |
| Engagement | SaMD regulatory remediation: DHF build-out, software remediation, Software V&V, cybersecurity, HIPAA 5 phases over 16 weeks |
| Classification outcome | FDA Class I, 510(k)-exempt (21 CFR 892.2020); IEC 62304 Class A |
| Frameworks | IEC 62304 · ISO 14971 · IEC 62366-1 · ISO 13485 / 21 CFR Part 820 (QMSR) · FDA 2023 Cybersecurity Guidance · IEC 81001-5-1 · HIPAA Security Rule |
| Delivered | 20+ controlled DHF documents; 68 requirements under end-to-end traceability; 7 verification batches + 5 clinical validation scenarios |
Background
Premature infants in neonatal intensive care are screened for retinopathy of prematurity (ROP), a condition where missed or delayed examination can cost an infant their sight. Product supports that mission: technicians upload wide field retinal images from the NICU, remote reading physicians review and annotate them, and referring physicians receive structured photo documentation reports. The platform is a multi-tenant, cloud-hosted. NET application with DICOM exchange, role based access and multi-site workflow support.
The software was FDA listed as a Class I device, but its design documentation had not kept pace with the product or with current FDA expectations. The company’s existing ISO 13485 quality system covered its hardware devices, not its software products.
The Challenge
The engagement began with assess for a clinically deployed SaMD platform; most of the Design History File either didn’t exist or existed only in fragments. Based on our baseline gap assessment, there is no user requirements specification, no ISO 14971 risk management file, no usability engineering file, no SOUP inventory, no HIPAA technical safeguards documentation, and no verification & validation protocols; fifteen of the seventeen DHF artifact categories we assessed were missing or partial, six of them rated critical.
Beneath the documentation gap sat a more strategic risk. Product’s Class I, 510(k) exempt status depends entirely on what the product does and our labelling claims. Image enhancement presented as diagnostic, automated clinical measurements, outcome claims could push the platform into Class II territory and trigger a 510(k) premarket submission: months of additional work, significant cost, and a frozen product roadmap while the submission is prepared and reviewed.
The task was therefore twofold: build an audit-ready DHF from near zero, and actively re-engineer the materials, their labelling and their claims so that the Class I position would hold up under FDA scrutiny.
How NexorTest Played a Critical Role
1. Classification strategy first, paperwork second
Before authoring a single DHF document, we completely rebuilt the regulatory strategy: a controlled Classification Rationale Memo anchoring PRODUCT to 21 CFR 892.2020 Class I, 510(k) exempt with a documented exemption assessment, an Applicable Standards Matrix, and a finalized Intended Use Document that draws a bright line. PRODUCT facilitates remote evaluation by qualified physicians; it does not diagnose, interpret, or decide. Every downstream artifact was written to defend that line.
2. Policing the device boundary software, IFU and marketing together
Class I positioning fails when the product’s behaviour, its instructions for use, and its marketing tell different stories. We reviewed all three as a single system and remediated wherever a claim or a feature crossed the boundary:
- Rewrote the intended use and indications of language across the IFU, labelling and training materials to consistently position the platform as workflow, communication and documentation support, with all clinical judgments retained by the physician.
- Identified and optimized the claim statements, including statements implying reduced litigation exposure and unsupported performance benefits, replacing them with the right workflow support language.
- Our data-flow review also surfaced at an integration point that needed remediation to stay fully aligned with the product’s stated intended use. We addressed it through standard containment and change control steps as part of the broader engagement.
- Brought hospital configurable screening logic under formal change control and validation, so field configuration cannot silently alter clinical behaviour.
3. A Design History File built around one anchor artifact
Every document we authored feeds a master Traceability Matrix threading user requirements → software requirements → architecture → risk controls → test cases → verification evidence. Around that spine, we delivered the full DHF: URS and SRS to IEC 62304 5.2; software architecture and interface specifications; ISO 14971 risk management file and hazard analysis; IEC 62366-1 usability engineering file; SOUP register and CycloneDX SBOM; configuration, maintenance, release and design transfer procedures; post-market surveillance plan; and a SaMD design control extension to the client’s existing ISO 13485 QMS and QMSR.
4. Verification & validation with our own engineers closing the failures
We structured, executed and documented V&V per IEC 62304: verification protocols keyed to the traceability matrix and executed in batches against the live platform, plus clinical validation scenarios covering the full NICU-to-reading-physician workflow. Because NexorTest ran both the regulatory and the engineering workstreams, findings didn’t stall in a hand-off: failures surfaced by verification were dispositioned, fixed in code by our own software expert team, and re-verified requirement gaps, risk-control actions like patient-identity confirmation at image commit and stale account deactivation, and defect fixes all flowed through documented change control.
5. Cybersecurity and HIPAA as engineering disciplines
We produced consolidated cybersecurity documentation proportionate to a Class I device but aligned to current expectations: STRIDE based threat modelling across trust boundaries, a security risk assessment per AAMI TIR57 and NIST CSF 2.0, DAST and manual code review with all critical and high findings remediated, independent penetration testing, an SBOM regenerated on every build per FD&C 524B, coordinated vulnerability disclosure, and incident-response and post-market monitoring procedures. In parallel, we implemented a HIPAA program for the platform risk analysis per NIST SP 800-30, a full safeguards matrix mapped to 45 CFR §164 citations, business associate obligations, and breach notification procedures.
Outcomes
- Class I, position preserved and defensible. Product behaviour, IFU, labelling, and marketing now tell one consistent story, backed by a controlled classification rationale.
- An audit ready Design History. File 40+ controlled documents spanning requirements, architecture, risk, usability, cybersecurity, HIPAA, V&V, PMS and release management, all navigable through a single traceability matrix.
- A better product. Verification failures and risk control gaps were fixed in code by the same engagement team and re-verified documentation that reflects the real product, not a parallel paper of reality.
- A repeatable SaMD design control framework extending the client’s ISO 13485 QMS, so the next release and the next product starts from process, not from zero.
Why This Matters
Most regulatory consultancies write documents. Most software firms write code. But SaMD remediation fails in the gap between them: documentation that doesn’t match the product, or product changes that quietly break the regulatory position. We NexorTest ran classification strategy, DHF authorship, V&V execution, security testing and software remediation as one integrated team which is why the boundary held, the failures got fixed, and the file will survive an audit.
Building or remediating Software as a Medical Device product? If your DHF has gaps, your claims are drifting towards a higher risk class, or your V&V evidence wouldn’t survive an FDA inspection talk to us before the FDA or a customer audit forces the conversation.
NexorTest Technologies SaMD regulatory engineering: classification strategy, DHF remediation, IEC 62304 V&V, cybersecurity and HIPAA compliance.
Meet Our Regulatory Expert
Dr. Pabbisetty PBS Kumar
Chief Compliance Officer at NexorTest Technologies
Newsletter
Sign up our newsletter to get update information, promotion or insight.