HIPAA Safe Harbor Coverage Audit
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
FDA regulatory consultant for medical device companies, covering 510(k)/PMA/De Novo pathways, QSR (21 CFR 820), HIPAA, and device cybersecurity.
$ npx skills add borghei/Claude-Skills --skill fda-consultant-specialist -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install borghei/Claude-Skills fda-consultant-specialist --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/fda-consultant-specialist .claude/skills/fda-consultant-specialist && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "fda-consultant-specialist" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/fda-consultant-specialist into .claude/skills/fda-consultant-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fda-consultant-specialist", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/fda-consultant-specialistType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add borghei/Claude-Skills --skill fda-consultant-specialist -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install borghei/Claude-Skills fda-consultant-specialist --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/ra-qm-team/fda-consultant-specialist .agents/skills/fda-consultant-specialist && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "fda-consultant-specialist" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/fda-consultant-specialist into .agents/skills/fda-consultant-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fda-consultant-specialist", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add borghei/Claude-Skills --skill fda-consultant-specialist -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install borghei/Claude-Skills fda-consultant-specialist --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/ra-qm-team/fda-consultant-specialist .cursor/skills/fda-consultant-specialist && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "fda-consultant-specialist" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/fda-consultant-specialist into .cursor/skills/fda-consultant-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fda-consultant-specialist", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/borghei/Claude-Skills.git --path ra-qm-team/fda-consultant-specialist--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add borghei/Claude-Skills --skill fda-consultant-specialist -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install borghei/Claude-Skills fda-consultant-specialist --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/ra-qm-team/fda-consultant-specialist .gemini/skills/fda-consultant-specialist && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "fda-consultant-specialist" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/fda-consultant-specialist into .gemini/skills/fda-consultant-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fda-consultant-specialist", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install borghei/Claude-Skills fda-consultant-specialistInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add borghei/Claude-Skills --skill fda-consultant-specialist -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/ra-qm-team/fda-consultant-specialist .github/skills/fda-consultant-specialist && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "fda-consultant-specialist" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/fda-consultant-specialist into .github/skills/fda-consultant-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fda-consultant-specialist", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add borghei/Claude-Skills --skill fda-consultant-specialist -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install borghei/Claude-Skills fda-consultant-specialist --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/ra-qm-team/fda-consultant-specialist .opencode/skills/fda-consultant-specialist && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "fda-consultant-specialist" agent skill from https://github.com/borghei/Claude-Skills/tree/main/ra-qm-team/fda-consultant-specialist into .opencode/skills/fda-consultant-specialist/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "fda-consultant-specialist", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
fda-consultant-specialistFDA regulatory consultant for medical device companies, covering 510(k)/PMA/De Novo pathways, QSR (21 CFR 820), HIPAA, and device cybersecurity.
Fda Consultant Specialist is an agent skill from borghei/Claude-Skills. FDA regulatory consultant for medical device companies, covering 510(k)/PMA/De Novo pathways, QSR (21 CFR 820), HIPAA, and device cybersecurity. Use for FDA submissions, predicate and substantial-equivalence analysis, and premarket strategy.
Its SKILL.md is about 8.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `references/device_cybersecurity_guidance.md`, `references/fda_capa_requirements.md` and `references/fda_submission_guide.md`).
It sits in Legal & Compliance, covering Healthcare and finance regulation. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 3 files in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
pythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Fda Consultant Specialist loads about 8.2k tokens when it runs, and up to ~31k if it reads all its reference files. Until then it costs about 67 tokens; SKILL.md has 3,161 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 3,161 words, ~8,189 tokens.
.claude/skills/fda-consultant-specialist/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.FDA regulatory consulting for medical device manufacturers covering submission pathways, Quality System Regulation (QSR), HIPAA compliance, and device cybersecurity requirements.
Before selecting a pathway or assessing compliance, confirm these inputs. If any is unknown or vague, ASK — do not assume:
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the analysis.
Determine the appropriate FDA regulatory pathway based on device classification and predicate availability.
Predicate device exists?
├── YES → Substantially equivalent?
│ ├── YES → 510(k) Pathway
│ │ ├── No design changes → Abbreviated 510(k)
│ │ ├── Manufacturing only → Special 510(k)
│ │ └── Design/performance → Traditional 510(k)
│ └── NO → PMA or De Novo
└── NO → Novel device?
├── Low-to-moderate risk → De Novo
└── High risk (Class III) → PMA| Pathway | When to Use | Timeline | Cost |
|---|---|---|---|
| 510(k) Traditional | Predicate exists, design changes | 90 days | $21,760 |
| 510(k) Special | Manufacturing changes only | 30 days | $21,760 |
| 510(k) Abbreviated | Guidance/standard conformance | 30 days | $21,760 |
| De Novo | Novel, low-moderate risk | 150 days | $134,676 |
| PMA | Class III, no predicate | 180+ days | $425,000+ |
Reference: See fda_submission_guide.md for pathway decision matrices and submission requirements.
Phase 1: Planning
├── Step 1: Identify predicate device(s)
├── Step 2: Compare intended use and technology
├── Step 3: Determine testing requirements
└── Checkpoint: SE argument feasible?
Phase 2: Preparation
├── Step 4: Complete performance testing
├── Step 5: Prepare device description
├── Step 6: Document SE comparison
├── Step 7: Finalize labeling
└── Checkpoint: All required sections complete?
Phase 3: Submission
├── Step 8: Assemble submission package
├── Step 9: Submit via eSTAR
├── Step 10: Track acknowledgment
└── Checkpoint: Submission accepted?
Phase 4: Review
├── Step 11: Monitor review status
├── Step 12: Respond to AI requests
├── Step 13: Receive decision
└── Verification: SE letter received?| Section | Content |
|---|---|
| Cover Letter | Submission type, device ID, contact info |
| Form 3514 | CDRH premarket review cover sheet |
| Device Description | Physical description, principles of operation |
| Indications for Use | Form 3881, patient population, use environment |
| SE Comparison | Side-by-side comparison with predicate |
| Performance Testing | Bench, biocompatibility, electrical safety |
| Software Documentation | Level of concern, hazard analysis (IEC 62304) |
| Labeling | IFU, package labels, warnings |
| 510(k) Summary | Public summary of submission |
| Issue | Prevention |
|---|---|
| Missing user fee | Verify payment before submission |
| Incomplete Form 3514 | Review all fields, ensure signature |
| No predicate identified | Confirm K-number in FDA database |
| Inadequate SE comparison | Address all technological characteristics |
Quality System Regulation (21 CFR Part 820) requirements for medical device manufacturers.
| Section | Title | Focus |
|---|---|---|
| 820.20 | Management Responsibility | Quality policy, org structure, management review |
| 820.30 | Design Controls | Input, output, review, verification, validation |
| 820.40 | Document Controls | Approval, distribution, change control |
| 820.50 | Purchasing Controls | Supplier qualification, purchasing data |
| 820.70 | Production Controls | Process validation, environmental controls |
| 820.100 | CAPA | Root cause analysis, corrective actions |
| 820.181 | Device Master Record | Specifications, procedures, acceptance criteria |
Step 1: Design Input
└── Capture user needs, intended use, regulatory requirements
Verification: Inputs reviewed and approved?
Step 2: Design Output
└── Create specifications, drawings, software architecture
Verification: Outputs traceable to inputs?
Step 3: Design Review
└── Conduct reviews at each phase milestone
Verification: Review records with signatures?
Step 4: Design Verification
└── Perform testing against specifications
Verification: All tests pass acceptance criteria?
Step 5: Design Validation
└── Confirm device meets user needs in actual use conditions
Verification: Validation report approved?
Step 6: Design Transfer
└── Release to production with DMR complete
Verification: Transfer checklist complete?Reference: See qsr_compliance_requirements.md for detailed QSR implementation guidance.
HIPAA requirements for devices that create, store, transmit, or access Protected Health Information (PHI).
| Device Type | HIPAA Applies |
|---|---|
| Standalone diagnostic (no data transmission) | No |
| Connected device transmitting patient data | Yes |
| Device with EHR integration | Yes |
| SaMD storing patient information | Yes |
| Wellness app (no diagnosis) | Only if stores PHI |
Administrative (§164.308)
├── Security officer designation
├── Risk analysis and management
├── Workforce training
├── Incident response procedures
└── Business associate agreements
Physical (§164.310)
├── Facility access controls
├── Workstation security
└── Device disposal procedures
Technical (§164.312)
├── Access control (unique IDs, auto-logoff)
├── Audit controls (logging)
├── Integrity controls (checksums, hashes)
├── Authentication (MFA recommended)
└── Transmission security (TLS 1.2+)Reference: See hipaa_compliance_framework.md for implementation checklists and BAA templates.
FDA cybersecurity requirements for connected medical devices.
| Element | Description |
|---|---|
| Threat Model | STRIDE analysis, attack trees, trust boundaries |
| Security Controls | Authentication, encryption, access control |
| SBOM | Software Bill of Materials (CycloneDX or SPDX) |
| Security Testing | Penetration testing, vulnerability scanning |
| Vulnerability Plan | Disclosure process, patch management |
Tier 1 (Higher Risk):
Tier 2 (Standard Risk):
Researcher Report
↓
Acknowledgment (48 hours)
↓
Initial Assessment (5 days)
↓
Fix Development
↓
Coordinated Public DisclosureReference: See device_cybersecurity_guidance.md for SBOM format examples and threat modeling templates.
| Script | Purpose |
|---|---|
fda_submission_tracker.py | Track 510(k)/PMA/De Novo submission milestones and timelines |
qsr_compliance_checker.py | Assess 21 CFR 820 compliance against project documentation |
hipaa_risk_assessment.py | Evaluate HIPAA safeguards in medical device software |
| File | Content |
|---|---|
fda_submission_guide.md | 510(k), De Novo, PMA submission requirements and checklists |
qsr_compliance_requirements.md | 21 CFR 820 implementation guide with templates |
hipaa_compliance_framework.md | HIPAA Security Rule safeguards and BAA requirements |
device_cybersecurity_guidance.md | FDA cybersecurity requirements, SBOM, threat modeling |
fda_capa_requirements.md | CAPA process, root cause analysis, effectiveness verification |
# Track FDA submission status
python scripts/fda_submission_tracker.py /path/to/project --type 510k
# Assess QSR compliance
python scripts/qsr_compliance_checker.py /path/to/project --section 820.30
# Run HIPAA risk assessment
python scripts/hipaa_risk_assessment.py /path/to/project --category technicalThe FDA finalized the Quality Management System Regulation (QMSR) in January 2024, replacing the legacy Quality System Regulation (QSR) with ISO 13485:2016 alignment. The rule became effective February 2, 2026.
| Aspect | Legacy QSR (21 CFR 820) | QMSR (Effective Feb 2026) |
|---|---|---|
| Framework | FDA-specific prescriptive requirements | Incorporates ISO 13485:2016 by reference |
| Design controls | 820.30 (FDA-specific) | ISO 13485 Clause 7.3 |
| CAPA | 820.100 | ISO 13485 Clause 8.5 |
| Document control | 820.40 | ISO 13485 Clause 4.2 |
| Management responsibility | 820.20 | ISO 13485 Clause 5 |
| Purchasing controls | 820.50 | ISO 13485 Clause 7.4 |
Key differences under QMSR:
| Category | Description | FDA Pathway |
|---|---|---|
| Locked algorithm | Algorithm does not change after deployment | Standard 510(k)/De Novo/PMA |
| Adaptive algorithm (PCCP) | Algorithm learns and changes with use | Predetermined Change Control Plan |
| Continuously learning | Real-time adaptation from new data | Case-by-case; PCCP required |
AI/ML SaMD Submission Package
├── Algorithm description and architecture
├── Training data characterization
│ ├── Data sources and collection methods
│ ├── Demographics and representativeness
│ ├── Data quality and labeling methodology
│ └── Training/validation/test split rationale
├── Performance evaluation
│ ├── Pre-specified performance goals
│ ├── Standalone performance metrics (sensitivity, specificity, AUC)
│ ├── Subgroup analysis (age, sex, race, site)
│ └── Real-world performance data (if available)
├── Reference standard justification
├── Predetermined Change Control Plan (if adaptive)
├── Human factors / user interface
├── Cybersecurity documentation
└── Software documentation per IEC 62304| Section | Content | Evidence |
|---|---|---|
| Description of modifications | Types of changes the algorithm will make | Change specification document |
| Modification protocol | How changes will be developed and tested | Validation protocol |
| Impact assessment | How each change type affects safety and effectiveness | Risk analysis per change type |
| Performance monitoring | Ongoing real-world performance tracking | Monitoring plan with metrics |
| Update verification | How each update will be verified before deployment | Verification and validation plan |
| Transparency | How users will be notified of changes | Communication plan |
| Category | Example | Verification Level |
|---|---|---|
| Performance improvement | Retrained model with additional data | Automated testing + clinical validation |
| Input adaptation | New imaging modality support | Full V&V cycle |
| Output modification | New risk categories or confidence levels | Clinical study |
| Architecture change | Model architecture update | New submission (510(k)/PMA supplement) |
The PATCH Act (effective March 2023, codified in FD&C Act §524B) requires:
| Requirement | Details | Evidence |
|---|---|---|
| Cybersecurity plan | Submit plan to monitor, identify, and address vulnerabilities | Premarket submission section |
| SBOM | Software Bill of Materials including commercial, open-source, off-the-shelf components | CycloneDX or SPDX format |
| Patch/update capability | Design device to be patchable throughout lifecycle | Architecture documentation |
| Coordinated vulnerability disclosure | Establish and maintain CVD process | Published security policy |
| Postmarket updates | Provide patches and updates in a reasonably justified cycle | Patch management plan |
Cybersecurity Premarket Package
├── Security risk assessment
│ ├── Threat model (STRIDE or equivalent)
│ ├── Security risk analysis per AAMI TIR57
│ └── Attack surface analysis
├── Security architecture
│ ├── Security controls implementation
│ ├── Cryptographic architecture
│ └── Network architecture and trust boundaries
├── SBOM (Software Bill of Materials)
│ ├── All software components (commercial, open-source, custom)
│ ├── Version information
│ └── Known vulnerability status
├── Security testing
│ ├── Static analysis (SAST)
│ ├── Dynamic analysis (DAST)
│ ├── Penetration testing report
│ ├── Fuzz testing results
│ └── Vulnerability scanning results
├── Lifecycle security plan
│ ├── Patch management process
│ ├── End-of-life/end-of-support plan
│ └── Customer communication plan
└── Coordinated vulnerability disclosure policyAI-enabled medical devices must comply with both FDA requirements and EU AI Act when marketed in both jurisdictions:
| Aspect | FDA Approach | EU AI Act Approach | Harmonization Strategy |
|---|---|---|---|
| Risk classification | SaMD risk framework (IMDRF) | Annex III high-risk (medical devices) | Map to both frameworks; use higher standard |
| Transparency | Labeling requirements | Art. 13 transparency obligations | Unified transparency documentation |
| Data governance | GMLP principles | Art. 10 data and data governance | Comprehensive data quality program |
| Human oversight | Human factors per IEC 62366 | Art. 14 human oversight | Integrated human factors + oversight design |
| Post-market | Real-world performance monitoring | Art. 72 post-market monitoring | Single monitoring system serving both |
| Technical documentation | FDA premarket submission | Annex IV technical documentation | Unified technical file |
See also:
../mdr-745-specialist/SKILL.mdfor EU MDR classification of AI/ML medical devices and../risk-management-specialist/SKILL.mdfor ISO 14971 risk management for AI devices.
As of October 1, 2023, FDA requires all 510(k) submissions to use the eSTAR template format. Paper submissions are no longer accepted.
| eSTAR Requirement | Details |
|---|---|
| Template | FDA eSTAR template (fillable PDF) |
| Format | Structured data fields + attachments |
| Attachments | PDF/A format, bookmarked, OCR-searchable |
| File naming | FDA naming convention required |
| Submission portal | CDRH Customer Collaboration Portal or FDA ESG |
| Maximum file size | 100MB per individual file; no total limit |
| eSTAR Section | Content | Common Deficiencies |
|---|---|---|
| Administrative | Cover letter, user fee, truthful/accurate statement | Missing signatures, incorrect fee |
| Device Description | Complete device description with images/diagrams | Insufficient detail, missing accessories |
| Substantial Equivalence | Predicate comparison table | Incomplete comparison criteria |
| Performance Testing | All test reports with summaries | Missing acceptance criteria, incomplete protocols |
| Software | Level of concern, hazard analysis, architecture | Outdated IEC 62304 compliance |
| Biocompatibility | ISO 10993 evaluation or testing | Missing risk assessment, incomplete contact analysis |
| Sterility | Sterilization validation summary | Missing reprocessing instructions (reusable devices) |
| Labeling | Device labels, IFU, patient materials | Non-compliant with 21 CFR 801 |
| EMC/Electrical Safety | IEC 60601-1 compliance | Missing particular standards |
| Clinical | Clinical data summary (if applicable) | Insufficient clinical evidence for new indications |
| Process Area | FDA (QMSR/QSR) | EU MDR 2017/745 | ISO 13485:2016 |
|---|---|---|---|
| Quality management system | 21 CFR 820 / QMSR | Annex IX, Annex XI | Clause 4 |
| Management responsibility | 820.20 / ISO 13485 Cl. 5 | Annex IX §2.2 | Clause 5 |
| Design controls | 820.30 / ISO 13485 Cl. 7.3 | Annex II §6.1, GSPR | Clause 7.3 |
| Document control | 820.40 / ISO 13485 Cl. 4.2 | Annex IX §2.3 | Clause 4.2 |
| Purchasing | 820.50 / ISO 13485 Cl. 7.4 | Annex IX §2.4 | Clause 7.4 |
| Production | 820.70 / ISO 13485 Cl. 7.5 | Annex IX §2.5 | Clause 7.5 |
| CAPA | 820.100 / ISO 13485 Cl. 8.5 | Art. 83 (PMS), Art. 89 (FSCA) | Clause 8.5 |
| Risk management | 820.30(g) / ISO 14971 | Annex I (GSPR), ISO 14971 | Clause 7.1 |
| Clinical evidence | 820.30(f) / clinical data | Annex XIV (clinical evaluation) | N/A (separate) |
| Post-market | 820.198 / MDR/MedWatch | Art. 83-86 (PMS), Art. 87-92 (vigilance) | Clause 8.2.1-8.2.3 |
| Labeling | 21 CFR 801 | Art. 10-13, Annex I Ch. III | N/A (separate) |
| UDI | 21 CFR 830 (FDA UDI) | Art. 27-29 (UDI-DI/PI) | N/A (separate) |
| Cybersecurity | §524B FD&C (PATCH Act) | MDCG 2019-16 | N/A (separate) |
| AI/ML devices | AI/ML SaMD framework + PCCP | EU AI Act + MDR | ISO 13485 + ISO 42001 |
Cross-references: See
../quality-manager-qms-iso13485/SKILL.mdfor ISO 13485 implementation aligned with QMSR, and../mdr-745-specialist/SKILL.mdfor EU MDR technical documentation requirements.
The FDA is aligning 21 CFR Part 820 with ISO 13485:2016 through the Quality Management System Regulation (QMSR), effective February 2, 2026:
eu-ai-act-specialist for EU AI Act requirements for AI medical devicesinfrastructure-compliance-auditor for technical cybersecurity checks| Area | FDA (QSR/QMSR) | EU MDR 2017/745 | ISO 13485:2016 |
|---|---|---|---|
| Design Controls | 820.30 / QMSR | Annex II | Clause 7.3 |
| Risk Management | 820.30(g) | Annex I GSPR | ISO 14971 |
| Clinical Evidence | 820.30(f) | Annex XIV | Clause 7.3.7 |
| CAPA | 820.90/100 | Art. 83, 89 | Clause 8.5 |
| Post-Market | 822, MDR | Chapter VII | Clause 8.2.1 |
| Cybersecurity | FDA Guidance | MDCG 2019-16 | IEC 62443 |
| AI/ML | PCCP Framework | EU AI Act | ISO 42001 |
| Problem | Possible Cause | Resolution |
|---|---|---|
| 510(k) submission returned as RTA (Refuse to Accept) | Missing user fee, incomplete Form 3514, no predicate identified, or inadequate SE comparison | Review the RTA checklist per FDA guidance; verify payment, complete all eSTAR fields, confirm K-number in FDA database, and address all technological characteristics in SE comparison |
| QSR compliance checker shows gaps in design controls (820.30) | Design History File incomplete or not aligned with ISO 13485 Clause 7.3 under QMSR | Map existing DHF to ISO 13485 Clause 7.3 structure; ensure design inputs, outputs, reviews, verification, and validation are documented with traceability |
| HIPAA risk assessment returns low score for technical safeguards | Missing encryption at rest/transit, no MFA implementation, or audit logging not enabled | Implement AES-256 encryption at rest, TLS 1.2+ in transit, MFA for all users with ePHI access, and comprehensive audit logging; run hipaa_risk_assessment.py with --category technical to validate |
| FDA AI request (Additional Information) received during 510(k) review | Performance testing insufficient, SE argument incomplete, or software documentation gaps | Respond within 180 days; address each question specifically; supplement with additional test data, clinical evidence, or software documentation per IEC 62304 |
| QMSR transition gap analysis reveals significant differences | Organization structured QMS around legacy 21 CFR 820 rather than ISO 13485 | Conduct systematic gap analysis mapping 820 subsections to ISO 13485 clauses; prioritize complaint handling (retained FDA requirement), risk-based evidence across all processes, and updated Quality Manual |
| Cybersecurity documentation rejected in premarket submission | SBOM incomplete, threat model missing, or coordinated vulnerability disclosure policy not published | Generate comprehensive SBOM in CycloneDX or SPDX format; complete STRIDE threat model per AAMI TIR57; publish CVD policy; document patch management lifecycle plan |
| AI/ML SaMD submission lacks Predetermined Change Control Plan | Adaptive algorithm deployed without PCCP framework | Develop PCCP covering modification types, validation protocol, impact assessment, performance monitoring, and user notification plan; include all four change categories with appropriate verification levels |
qsr_compliance_checker.py, with all critical subsections (design controls, CAPA, document control) showing evidence of implementationfda_submission_tracker.py milestonesIn Scope:
Out of Scope:
Important Notes:
| Skill | Integration | When to Use |
|---|---|---|
quality-manager-qms-iso13485 | ISO 13485 QMS implementation aligned with QMSR; process management and supplier qualification | When implementing QMS satisfying both ISO 13485 certification and FDA QMSR requirements |
mdr-745-specialist | Cross-framework mapping for dual US/EU market submissions; technical documentation alignment | When medical device requires both FDA clearance/approval and EU MDR CE marking |
capa-officer | CAPA process management per ISO 13485 Clause 8.5 (replacing legacy 820.100 under QMSR) | When managing corrective and preventive actions within the FDA quality system |
risk-management-specialist | ISO 14971 risk management integrated with design controls and cybersecurity risk assessment | When conducting risk analysis for premarket submissions per 820.30(g) and AAMI TIR57 |
eu-ai-act-specialist | Cross-jurisdictional AI/ML compliance for devices marketed in both US and EU | When AI-enabled medical device requires both FDA PCCP framework and EU AI Act conformity assessment |
infrastructure-compliance-auditor | Technical cybersecurity validation for connected device security controls | When documenting cybersecurity architecture and SBOM for premarket submissions |
Tracks FDA submission milestones and calculates regulatory timelines for 510(k), De Novo, and PMA pathways.
| Flag | Required | Description |
|---|---|---|
<project_dir> | Yes | Path to project directory containing submission documents |
--type <pathway> | No | Submission type: 510k (default), de_novo, pma, pma_supplement |
--json | No | Output results in JSON format |
Output: Milestone tracking with completion status, timeline calculations against FDA review goals, phase progress (planning, preparation, submission, review, decision), and overdue milestone alerts.
Assesses compliance with 21 CFR Part 820 / QMSR by analyzing project documentation for evidence of implementation.
| Flag | Required | Description |
|---|---|---|
<project_dir> | Yes | Path to project directory containing QMS documentation |
--section <section> | No | Check specific QSR section (e.g., 820.30 for design controls, 820.100 for CAPA) |
--json | No | Output results in JSON format |
Output: Per-section compliance status, evidence found (document patterns and keyword matches), compliance percentage, gap identification with required evidence descriptions.
Evaluates HIPAA Security Rule safeguards for medical device software and connected devices.
| Flag | Required | Description |
|---|---|---|
<project_dir> | Yes | Path to project directory for assessment |
--category <cat> | No | Assess specific category: administrative, physical, technical, or all (default) |
--json | No | Output results in JSON format |
Output: Per-safeguard compliance status across administrative (Section 164.308), physical (Section 164.310), and technical (Section 164.312) categories, with weighted scoring, evidence detection, and remediation recommendations.
© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 8 other files (scripts, references) in ra-qm-team/fda-consultant-specialist of borghei/Claude-Skills.
Open the folder on GitHubat commit 4a698e8
Fda Consultant Specialist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Fda Consultant Specialist this skillborghei/Claude-Skills | 891 | — | ~8.2k | Automated safety check: Pass | MIT | |
| HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed | 5.5k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed | 5.5k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance | 946 | 1 repos | ~2.3k | Automated safety check: Pass | MIT | |
| ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills | 48k | 1 repos | ~4.6k | Automated safety check: Notes | MIT | |
| Fda Consultant Specialistdavila7/claude-code-templates | 33k | 1 repos | ~2.7k | Automated safety check: Pass | MIT |
maziyarpanahi/openmed
Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.
maziyarpanahi/openmed
Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.
Sushegaad/Claude-Skills-Governance-Risk-and-Compliance
Expert HIPAA compliance assistant for healthcare and software contexts.
K-Dense-AI/scientific-agent-skills
Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.
davila7/claude-code-templates
Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.
mlunato47/claude-grc-plugin
Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…
borghei/Claude-Skills
Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.
borghei/Claude-Skills
Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.
borghei/Claude-Skills
Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.
borghei/Claude-Skills
Idea to AI-generated prototype to customer validation to engineering handoff.
borghei/Claude-Skills
Analytics engineering across data modeling, dbt, transformation, and semantic layers.
borghei/Claude-Skills
Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.
Categories
FDA regulatory consultant for medical device companies, covering 510(k)/PMA/De Novo pathways, QSR (21 CFR 820), HIPAA, and device cybersecurity. Fda Consultant Specialist is an agent skill from borghei/Claude-Skills. FDA regulatory consultant for medical device companies, covering 510(k)/PMA/De Novo pathways, QSR (21 CFR 820), HIPAA, and device cybersecurity.
Fda Consultant Specialist fits situations like: FDA submissions; predicate and substantial-equivalence analysis; premarket strategy.
Run `npx skills add borghei/Claude-Skills --skill fda-consultant-specialist -a claude-code`. Or copy the skill folder (ra-qm-team/fda-consultant-specialist in borghei/Claude-Skills) into .claude/skills/fda-consultant-specialist in your project. Claude Code loads it when a task matches its description.
Run `npx skills add borghei/Claude-Skills --skill fda-consultant-specialist -a codex`. Or copy the skill folder (ra-qm-team/fda-consultant-specialist in borghei/Claude-Skills) into .agents/skills/fda-consultant-specialist in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill fda-consultant-specialist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fda-consultant-specialist, .gemini/skills/fda-consultant-specialist, .github/skills/fda-consultant-specialist and .opencode/skills/fda-consultant-specialist in your project.
Going by SKILL.md and its folder, Fda Consultant Specialist needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Fda Consultant Specialist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 8.2k tokens (SKILL.md is roughly 33k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 23k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Fda Consultant Specialist: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 891 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.
Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.