Agent skill

Fda Consultant Specialist

by borghei in borghei/Claude-Skills

FDA regulatory consultant for medical device companies, covering 510(k)/PMA/De Novo pathways, QSR (21 CFR 820), HIPAA, and device cybersecurity.

MITAuto-check passedLegal & Compliance

Install Fda Consultant Specialist

skills CLI
$ npx skills add borghei/Claude-Skills --skill fda-consultant-specialist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install borghei/Claude-Skills fda-consultant-specialist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/borghei/Claude-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ra-qm-team/fda-consultant-specialist .claude/skills/fda-consultant-specialist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
fda-consultant-specialist
GitHub stars
891
Token cost
~8.2k tokens
SKILL.md length
3,161 words
Files
9 (incl. scripts, references)
Skills in repo
354
Repo updated
First seen
Licence
MIT

At a glance

FDA regulatory consultant for medical device companies, covering 510(k)/PMA/De Novo pathways, QSR (21 CFR 820), HIPAA, and device cybersecurity.

  • Works in 5 steps: Identify product code and classification → Search 510(k) database for predicates → Assess substantial equivalence feasibility → …
  • FDA submissions
  • SKILL.md covers Table of Contents, Clarify First, FDA Pathway Selection and 510(k) Submission Process, plus 5 more sections
  • Runs Python scripts from its folder; calls python

What it does

Fda Consultant Specialist is an agent skill from borghei/Claude-Skills. FDA regulatory consultant for medical device companies, covering 510(k)/PMA/De Novo pathways, QSR (21 CFR 820), HIPAA, and device cybersecurity. Use for FDA submissions, predicate and substantial-equivalence analysis, and premarket strategy.

Its SKILL.md is about 8.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `references/device_cybersecurity_guidance.md`, `references/fda_capa_requirements.md` and `references/fda_submission_guide.md`).

It sits in Legal & Compliance, covering Healthcare and finance regulation. The repository describes itself as: 385 AI skills, 77 expert agents, and 900 stdlib Python tools for every team: engineering, PM, marketing, C-level, compliance, business ops, research, and a LinkedIn toolkit… The licence is MIT.

When your agent uses it

  • FDA submissions
  • Predicate and substantial-equivalence analysis
  • Premarket strategy

Example prompts

  • “/fda-consultant-specialist”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Identify product code and classification
  2. Search 510(k) database for predicates
  3. Assess substantial equivalence feasibility
  4. Prepare Q-Sub questions for FDA
  5. Schedule Pre-Sub meeting if needed

What it can do on your machine

Read from SKILL.md and the folder at commit 4a698e8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Fda Consultant Specialist loads about 8.2k tokens when it runs, and up to ~31k if it reads all its reference files. Until then it costs about 67 tokens; SKILL.md has 3,161 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~8.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~31k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from borghei/Claude-Skills at commit 4a698e8, republished under its MIT licence (© borghei). 3,161 words, ~8,189 tokens.

Download SKILL.mdSave it as .claude/skills/fda-consultant-specialist/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
name
fda-consultant-specialist
description
FDA regulatory consultant for medical device companies, covering 510(k)/PMA/De Novo pathways, QSR (21 CFR 820), HIPAA, and device cybersecurity. Use for FDA submissions, predicate and substantial-equivalence analysis, and premarket strategy.
license
MIT + Commons Clause
metadata.version
1.0.0
metadata.author
borghei
metadata.category
compliance
metadata.domain
fda-compliance
metadata.updated
2026-03-31
metadata.tags
fda, 510k, pma, qsr, hipaa, cybersecurity

FDA Consultant Specialist

FDA regulatory consulting for medical device manufacturers covering submission pathways, Quality System Regulation (QSR), HIPAA compliance, and device cybersecurity requirements.

Table of Contents


Clarify First

Before selecting a pathway or assessing compliance, confirm these inputs. If any is unknown or vague, ASK — do not assume:

  • Device class and predicate — Class I/II/III and whether a predicate device exists (drives 510(k) vs De Novo vs PMA)
  • Intended use / indications — what the device claims and its use environment (sets the substantial-equivalence argument and clinical-evidence needs)
  • Software/AI nature — SaMD, adaptive AI needing a PCCP, or connected device (cybersecurity/SBOM) (changes the required documentation set)

Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the analysis.

FDA Pathway Selection

Determine the appropriate FDA regulatory pathway based on device classification and predicate availability.

Decision Framework
Predicate device exists?
├── YES → Substantially equivalent?
│   ├── YES → 510(k) Pathway
│   │   ├── No design changes → Abbreviated 510(k)
│   │   ├── Manufacturing only → Special 510(k)
│   │   └── Design/performance → Traditional 510(k)
│   └── NO → PMA or De Novo
└── NO → Novel device?
    ├── Low-to-moderate risk → De Novo
    └── High risk (Class III) → PMA
Pathway Comparison
PathwayWhen to UseTimelineCost
510(k) TraditionalPredicate exists, design changes90 days$21,760
510(k) SpecialManufacturing changes only30 days$21,760
510(k) AbbreviatedGuidance/standard conformance30 days$21,760
De NovoNovel, low-moderate risk150 days$134,676
PMAClass III, no predicate180+ days$425,000+
Pre-Submission Strategy
  1. Identify product code and classification
  2. Search 510(k) database for predicates
  3. Assess substantial equivalence feasibility
  4. Prepare Q-Sub questions for FDA
  5. Schedule Pre-Sub meeting if needed

Reference: See fda_submission_guide.md for pathway decision matrices and submission requirements.


510(k) Submission Process

Workflow
Phase 1: Planning
├── Step 1: Identify predicate device(s)
├── Step 2: Compare intended use and technology
├── Step 3: Determine testing requirements
└── Checkpoint: SE argument feasible?

Phase 2: Preparation
├── Step 4: Complete performance testing
├── Step 5: Prepare device description
├── Step 6: Document SE comparison
├── Step 7: Finalize labeling
└── Checkpoint: All required sections complete?

Phase 3: Submission
├── Step 8: Assemble submission package
├── Step 9: Submit via eSTAR
├── Step 10: Track acknowledgment
└── Checkpoint: Submission accepted?

Phase 4: Review
├── Step 11: Monitor review status
├── Step 12: Respond to AI requests
├── Step 13: Receive decision
└── Verification: SE letter received?
Required Sections (21 CFR 807.87)
SectionContent
Cover LetterSubmission type, device ID, contact info
Form 3514CDRH premarket review cover sheet
Device DescriptionPhysical description, principles of operation
Indications for UseForm 3881, patient population, use environment
SE ComparisonSide-by-side comparison with predicate
Performance TestingBench, biocompatibility, electrical safety
Software DocumentationLevel of concern, hazard analysis (IEC 62304)
LabelingIFU, package labels, warnings
510(k) SummaryPublic summary of submission
Common RTA Issues
IssuePrevention
Missing user feeVerify payment before submission
Incomplete Form 3514Review all fields, ensure signature
No predicate identifiedConfirm K-number in FDA database
Inadequate SE comparisonAddress all technological characteristics

QSR Compliance

Quality System Regulation (21 CFR Part 820) requirements for medical device manufacturers.

Key Subsystems
SectionTitleFocus
820.20Management ResponsibilityQuality policy, org structure, management review
820.30Design ControlsInput, output, review, verification, validation
820.40Document ControlsApproval, distribution, change control
820.50Purchasing ControlsSupplier qualification, purchasing data
820.70Production ControlsProcess validation, environmental controls
820.100CAPARoot cause analysis, corrective actions
820.181Device Master RecordSpecifications, procedures, acceptance criteria
Design Controls Workflow (820.30)
Step 1: Design Input
└── Capture user needs, intended use, regulatory requirements
    Verification: Inputs reviewed and approved?

Step 2: Design Output
└── Create specifications, drawings, software architecture
    Verification: Outputs traceable to inputs?

Step 3: Design Review
└── Conduct reviews at each phase milestone
    Verification: Review records with signatures?

Step 4: Design Verification
└── Perform testing against specifications
    Verification: All tests pass acceptance criteria?

Step 5: Design Validation
└── Confirm device meets user needs in actual use conditions
    Verification: Validation report approved?

Step 6: Design Transfer
└── Release to production with DMR complete
    Verification: Transfer checklist complete?
CAPA Process (820.100)
  1. Identify: Document nonconformity or potential problem
  2. Investigate: Perform root cause analysis (5 Whys, Fishbone)
  3. Plan: Define corrective/preventive actions
  4. Implement: Execute actions, update documentation
  5. Verify: Confirm implementation complete
  6. Effectiveness: Monitor for recurrence (30-90 days)
  7. Close: Management approval and closure

Reference: See qsr_compliance_requirements.md for detailed QSR implementation guidance.


HIPAA for Medical Devices

HIPAA requirements for devices that create, store, transmit, or access Protected Health Information (PHI).

Applicability
Device TypeHIPAA Applies
Standalone diagnostic (no data transmission)No
Connected device transmitting patient dataYes
Device with EHR integrationYes
SaMD storing patient informationYes
Wellness app (no diagnosis)Only if stores PHI
Required Safeguards
Administrative (§164.308)
├── Security officer designation
├── Risk analysis and management
├── Workforce training
├── Incident response procedures
└── Business associate agreements

Physical (§164.310)
├── Facility access controls
├── Workstation security
└── Device disposal procedures

Technical (§164.312)
├── Access control (unique IDs, auto-logoff)
├── Audit controls (logging)
├── Integrity controls (checksums, hashes)
├── Authentication (MFA recommended)
└── Transmission security (TLS 1.2+)
Risk Assessment Steps
  1. Inventory all systems handling ePHI
  2. Document data flows (collection, storage, transmission)
  3. Identify threats and vulnerabilities
  4. Assess likelihood and impact
  5. Determine risk levels
  6. Implement controls
  7. Document residual risk

Reference: See hipaa_compliance_framework.md for implementation checklists and BAA templates.


Device Cybersecurity

FDA cybersecurity requirements for connected medical devices.

Premarket Requirements
ElementDescription
Threat ModelSTRIDE analysis, attack trees, trust boundaries
Security ControlsAuthentication, encryption, access control
SBOMSoftware Bill of Materials (CycloneDX or SPDX)
Security TestingPenetration testing, vulnerability scanning
Vulnerability PlanDisclosure process, patch management
Device Tier Classification

Tier 1 (Higher Risk):

  • Connects to network/internet
  • Cybersecurity incident could cause patient harm

Tier 2 (Standard Risk):

  • All other connected devices
Postmarket Obligations
  1. Monitor NVD and ICS-CERT for vulnerabilities
  2. Assess applicability to device components
  3. Develop and test patches
  4. Communicate with customers
  5. Report to FDA per guidance
Coordinated Vulnerability Disclosure
Researcher Report
    ↓
Acknowledgment (48 hours)
    ↓
Initial Assessment (5 days)
    ↓
Fix Development
    ↓
Coordinated Public Disclosure

Reference: See device_cybersecurity_guidance.md for SBOM format examples and threat modeling templates.


Resources

scripts/
ScriptPurpose
fda_submission_tracker.pyTrack 510(k)/PMA/De Novo submission milestones and timelines
qsr_compliance_checker.pyAssess 21 CFR 820 compliance against project documentation
hipaa_risk_assessment.pyEvaluate HIPAA safeguards in medical device software
references/
FileContent
fda_submission_guide.md510(k), De Novo, PMA submission requirements and checklists
qsr_compliance_requirements.md21 CFR 820 implementation guide with templates
hipaa_compliance_framework.mdHIPAA Security Rule safeguards and BAA requirements
device_cybersecurity_guidance.mdFDA cybersecurity requirements, SBOM, threat modeling
fda_capa_requirements.mdCAPA process, root cause analysis, effectiveness verification
Usage Examples
bash
# Track FDA submission status
python scripts/fda_submission_tracker.py /path/to/project --type 510k

# Assess QSR compliance
python scripts/qsr_compliance_checker.py /path/to/project --section 820.30

# Run HIPAA risk assessment
python scripts/hipaa_risk_assessment.py /path/to/project --category technical

FDA QMSR — Quality Management System Regulation

Transition from QSR (21 CFR 820) to QMSR

The FDA finalized the Quality Management System Regulation (QMSR) in January 2024, replacing the legacy Quality System Regulation (QSR) with ISO 13485:2016 alignment. The rule became effective February 2, 2026.

AspectLegacy QSR (21 CFR 820)QMSR (Effective Feb 2026)
FrameworkFDA-specific prescriptive requirementsIncorporates ISO 13485:2016 by reference
Design controls820.30 (FDA-specific)ISO 13485 Clause 7.3
CAPA820.100ISO 13485 Clause 8.5
Document control820.40ISO 13485 Clause 4.2
Management responsibility820.20ISO 13485 Clause 5
Purchasing controls820.50ISO 13485 Clause 7.4

Key differences under QMSR:

  • ISO 13485:2016 is incorporated by reference as the primary QMS standard
  • FDA retains certain device-specific requirements not covered by ISO 13485 (e.g., complaint handling per 21 CFR 820.198)
  • Organizations already ISO 13485 certified have a significant head start
  • No separate FDA registration for QMS — single system serves both ISO and FDA
QMSR Transition Checklist
  • Gap analysis: ISO 13485:2016 vs. current QSR compliance
  • Update Quality Manual to reference ISO 13485 clause structure
  • Map existing SOPs to ISO 13485 clauses
  • Address FDA-specific retained requirements (complaint handling, MDR reporting)
  • Train staff on ISO 13485 terminology and structure
  • Update supplier agreements to reference new regulatory framework
  • Conduct internal audit against QMSR requirements
  • Update design history files to ISO 13485 Clause 7.3 format

AI/ML-Based Software as Medical Device (SaMD)

FDA AI/ML SaMD Framework
CategoryDescriptionFDA Pathway
Locked algorithmAlgorithm does not change after deploymentStandard 510(k)/De Novo/PMA
Adaptive algorithm (PCCP)Algorithm learns and changes with usePredetermined Change Control Plan
Continuously learningReal-time adaptation from new dataCase-by-case; PCCP required
AI/ML SaMD Submission Requirements
AI/ML SaMD Submission Package
├── Algorithm description and architecture
├── Training data characterization
│   ├── Data sources and collection methods
│   ├── Demographics and representativeness
│   ├── Data quality and labeling methodology
│   └── Training/validation/test split rationale
├── Performance evaluation
│   ├── Pre-specified performance goals
│   ├── Standalone performance metrics (sensitivity, specificity, AUC)
│   ├── Subgroup analysis (age, sex, race, site)
│   └── Real-world performance data (if available)
├── Reference standard justification
├── Predetermined Change Control Plan (if adaptive)
├── Human factors / user interface
├── Cybersecurity documentation
└── Software documentation per IEC 62304
Good Machine Learning Practice (GMLP) Principles
  1. Multi-disciplinary expertise throughout product lifecycle
  2. Good software engineering and security practices
  3. Representative training and test datasets
  4. Independent test datasets separate from training
  5. Reference datasets based on best available methods
  6. Model design tailored to available data and intended use
  7. Focus on performance of human-AI team
  8. Clinical study testing demonstrates real-world performance
  9. Users provided clear, essential information
  10. Deployed models monitored for performance with retraining managed

Predetermined Change Control Plan (PCCP) for AI/ML Devices

PCCP Structure
SectionContentEvidence
Description of modificationsTypes of changes the algorithm will makeChange specification document
Modification protocolHow changes will be developed and testedValidation protocol
Impact assessmentHow each change type affects safety and effectivenessRisk analysis per change type
Performance monitoringOngoing real-world performance trackingMonitoring plan with metrics
Update verificationHow each update will be verified before deploymentVerification and validation plan
TransparencyHow users will be notified of changesCommunication plan
PCCP Change Categories
CategoryExampleVerification Level
Performance improvementRetrained model with additional dataAutomated testing + clinical validation
Input adaptationNew imaging modality supportFull V&V cycle
Output modificationNew risk categories or confidence levelsClinical study
Architecture changeModel architecture updateNew submission (510(k)/PMA supplement)

Enhanced Cybersecurity Requirements (PATCH Act)

The PATCH Act (effective March 2023, codified in FD&C Act §524B) requires:

RequirementDetailsEvidence
Cybersecurity planSubmit plan to monitor, identify, and address vulnerabilitiesPremarket submission section
SBOMSoftware Bill of Materials including commercial, open-source, off-the-shelf componentsCycloneDX or SPDX format
Patch/update capabilityDesign device to be patchable throughout lifecycleArchitecture documentation
Coordinated vulnerability disclosureEstablish and maintain CVD processPublished security policy
Postmarket updatesProvide patches and updates in a reasonably justified cyclePatch management plan
Cybersecurity Documentation for Premarket Submissions
Cybersecurity Premarket Package
├── Security risk assessment
│   ├── Threat model (STRIDE or equivalent)
│   ├── Security risk analysis per AAMI TIR57
│   └── Attack surface analysis
├── Security architecture
│   ├── Security controls implementation
│   ├── Cryptographic architecture
│   └── Network architecture and trust boundaries
├── SBOM (Software Bill of Materials)
│   ├── All software components (commercial, open-source, custom)
│   ├── Version information
│   └── Known vulnerability status
├── Security testing
│   ├── Static analysis (SAST)
│   ├── Dynamic analysis (DAST)
│   ├── Penetration testing report
│   ├── Fuzz testing results
│   └── Vulnerability scanning results
├── Lifecycle security plan
│   ├── Patch management process
│   ├── End-of-life/end-of-support plan
│   └── Customer communication plan
└── Coordinated vulnerability disclosure policy

Cross-Reference: EU AI Act for AI Medical Devices

AI-enabled medical devices must comply with both FDA requirements and EU AI Act when marketed in both jurisdictions:

AspectFDA ApproachEU AI Act ApproachHarmonization Strategy
Risk classificationSaMD risk framework (IMDRF)Annex III high-risk (medical devices)Map to both frameworks; use higher standard
TransparencyLabeling requirementsArt. 13 transparency obligationsUnified transparency documentation
Data governanceGMLP principlesArt. 10 data and data governanceComprehensive data quality program
Human oversightHuman factors per IEC 62366Art. 14 human oversightIntegrated human factors + oversight design
Post-marketReal-world performance monitoringArt. 72 post-market monitoringSingle monitoring system serving both
Technical documentationFDA premarket submissionAnnex IV technical documentationUnified technical file

See also: ../mdr-745-specialist/SKILL.md for EU MDR classification of AI/ML medical devices and ../risk-management-specialist/SKILL.md for ISO 14971 risk management for AI devices.


Updated 510(k) Electronic Submission Requirements (eSTAR)

eSTAR Mandate

As of October 1, 2023, FDA requires all 510(k) submissions to use the eSTAR template format. Paper submissions are no longer accepted.

eSTAR RequirementDetails
TemplateFDA eSTAR template (fillable PDF)
FormatStructured data fields + attachments
AttachmentsPDF/A format, bookmarked, OCR-searchable
File namingFDA naming convention required
Submission portalCDRH Customer Collaboration Portal or FDA ESG
Maximum file size100MB per individual file; no total limit
eSTAR Section Mapping
eSTAR SectionContentCommon Deficiencies
AdministrativeCover letter, user fee, truthful/accurate statementMissing signatures, incorrect fee
Device DescriptionComplete device description with images/diagramsInsufficient detail, missing accessories
Substantial EquivalencePredicate comparison tableIncomplete comparison criteria
Performance TestingAll test reports with summariesMissing acceptance criteria, incomplete protocols
SoftwareLevel of concern, hazard analysis, architectureOutdated IEC 62304 compliance
BiocompatibilityISO 10993 evaluation or testingMissing risk assessment, incomplete contact analysis
SterilitySterilization validation summaryMissing reprocessing instructions (reusable devices)
LabelingDevice labels, IFU, patient materialsNon-compliant with 21 CFR 801
EMC/Electrical SafetyIEC 60601-1 complianceMissing particular standards
ClinicalClinical data summary (if applicable)Insufficient clinical evidence for new indications

Cross-Framework: FDA ↔ MDR ↔ ISO 13485 Mapping

Process AreaFDA (QMSR/QSR)EU MDR 2017/745ISO 13485:2016
Quality management system21 CFR 820 / QMSRAnnex IX, Annex XIClause 4
Management responsibility820.20 / ISO 13485 Cl. 5Annex IX §2.2Clause 5
Design controls820.30 / ISO 13485 Cl. 7.3Annex II §6.1, GSPRClause 7.3
Document control820.40 / ISO 13485 Cl. 4.2Annex IX §2.3Clause 4.2
Purchasing820.50 / ISO 13485 Cl. 7.4Annex IX §2.4Clause 7.4
Production820.70 / ISO 13485 Cl. 7.5Annex IX §2.5Clause 7.5
CAPA820.100 / ISO 13485 Cl. 8.5Art. 83 (PMS), Art. 89 (FSCA)Clause 8.5
Risk management820.30(g) / ISO 14971Annex I (GSPR), ISO 14971Clause 7.1
Clinical evidence820.30(f) / clinical dataAnnex XIV (clinical evaluation)N/A (separate)
Post-market820.198 / MDR/MedWatchArt. 83-86 (PMS), Art. 87-92 (vigilance)Clause 8.2.1-8.2.3
Labeling21 CFR 801Art. 10-13, Annex I Ch. IIIN/A (separate)
UDI21 CFR 830 (FDA UDI)Art. 27-29 (UDI-DI/PI)N/A (separate)
Cybersecurity§524B FD&C (PATCH Act)MDCG 2019-16N/A (separate)
AI/ML devicesAI/ML SaMD framework + PCCPEU AI Act + MDRISO 13485 + ISO 42001

Cross-references: See ../quality-manager-qms-iso13485/SKILL.md for ISO 13485 implementation aligned with QMSR, and ../mdr-745-specialist/SKILL.md for EU MDR technical documentation requirements.


FDA Regulatory Updates & Cross-Framework Integration

Show full SKILL.md (1,276 more words)Show less
FDA QMSR — Quality Management System Regulation

The FDA is aligning 21 CFR Part 820 with ISO 13485:2016 through the Quality Management System Regulation (QMSR), effective February 2, 2026:

  • Key Change: QSR (21 CFR 820) replaced by ISO 13485 as the recognized quality system standard
  • Impact: Manufacturers must comply with ISO 13485:2016 instead of QSR-specific requirements
  • Design Controls: ISO 13485 Clause 7.3 replaces 820.30
  • CAPA: ISO 13485 Clause 8.5 replaces 820.90/820.100
  • Transition: FDA accepting both QSR and QMSR during transition period
AI/ML-Based Software as Medical Device (SaMD)
  • Predetermined Change Control Plan (PCCP): Required for AI/ML devices that learn and adapt
  • Good Machine Learning Practice (GMLP): FDA's 10 guiding principles for AI/ML in medical devices
  • Transparency: Clear labeling of AI/ML-based functionality and limitations
  • Real-World Performance: Post-market monitoring of AI model performance drift
  • Cross-reference: See eu-ai-act-specialist for EU AI Act requirements for AI medical devices
Enhanced Cybersecurity Requirements (PATCH Act)
  • Premarket Submissions: Cybersecurity documentation required for all connected devices
  • Software Bill of Materials (SBOM): Mandatory for all premarket submissions
  • Coordinated Vulnerability Disclosure: Required policy for all connected device manufacturers
  • Postmarket Patches: Cybersecurity patches exempt from 510(k) requirements
  • Cross-reference: See infrastructure-compliance-auditor for technical cybersecurity checks
Cross-Framework Mapping (FDA ↔ MDR ↔ ISO 13485)
AreaFDA (QSR/QMSR)EU MDR 2017/745ISO 13485:2016
Design Controls820.30 / QMSRAnnex IIClause 7.3
Risk Management820.30(g)Annex I GSPRISO 14971
Clinical Evidence820.30(f)Annex XIVClause 7.3.7
CAPA820.90/100Art. 83, 89Clause 8.5
Post-Market822, MDRChapter VIIClause 8.2.1
CybersecurityFDA GuidanceMDCG 2019-16IEC 62443
AI/MLPCCP FrameworkEU AI ActISO 42001

Troubleshooting

ProblemPossible CauseResolution
510(k) submission returned as RTA (Refuse to Accept)Missing user fee, incomplete Form 3514, no predicate identified, or inadequate SE comparisonReview the RTA checklist per FDA guidance; verify payment, complete all eSTAR fields, confirm K-number in FDA database, and address all technological characteristics in SE comparison
QSR compliance checker shows gaps in design controls (820.30)Design History File incomplete or not aligned with ISO 13485 Clause 7.3 under QMSRMap existing DHF to ISO 13485 Clause 7.3 structure; ensure design inputs, outputs, reviews, verification, and validation are documented with traceability
HIPAA risk assessment returns low score for technical safeguardsMissing encryption at rest/transit, no MFA implementation, or audit logging not enabledImplement AES-256 encryption at rest, TLS 1.2+ in transit, MFA for all users with ePHI access, and comprehensive audit logging; run hipaa_risk_assessment.py with --category technical to validate
FDA AI request (Additional Information) received during 510(k) reviewPerformance testing insufficient, SE argument incomplete, or software documentation gapsRespond within 180 days; address each question specifically; supplement with additional test data, clinical evidence, or software documentation per IEC 62304
QMSR transition gap analysis reveals significant differencesOrganization structured QMS around legacy 21 CFR 820 rather than ISO 13485Conduct systematic gap analysis mapping 820 subsections to ISO 13485 clauses; prioritize complaint handling (retained FDA requirement), risk-based evidence across all processes, and updated Quality Manual
Cybersecurity documentation rejected in premarket submissionSBOM incomplete, threat model missing, or coordinated vulnerability disclosure policy not publishedGenerate comprehensive SBOM in CycloneDX or SPDX format; complete STRIDE threat model per AAMI TIR57; publish CVD policy; document patch management lifecycle plan
AI/ML SaMD submission lacks Predetermined Change Control PlanAdaptive algorithm deployed without PCCP frameworkDevelop PCCP covering modification types, validation protocol, impact assessment, performance monitoring, and user notification plan; include all four change categories with appropriate verification levels

Success Criteria

  • 510(k) submission accepted on first attempt -- zero RTA deficiencies, with all eSTAR sections complete, user fee verified, predicate identified, and SE comparison addressing all technological characteristics
  • QSR/QMSR compliance score above 85% -- as measured by qsr_compliance_checker.py, with all critical subsections (design controls, CAPA, document control) showing evidence of implementation
  • HIPAA technical safeguards fully implemented -- AES-256 encryption at rest, TLS 1.2+ in transit, MFA enforced, audit controls active, and automatic logoff configured for all systems handling ePHI
  • FDA submission timeline targets met -- 510(k) traditional within 90 days, De Novo within 150 days, PMA within 180 days, tracked via fda_submission_tracker.py milestones
  • QMSR transition completed -- Quality Manual references ISO 13485 clause structure, all SOPs mapped, FDA-specific retained requirements addressed, and internal audit conducted against QMSR requirements
  • Cybersecurity documentation complete for all connected devices -- SBOM, threat model, security testing reports, vulnerability disclosure policy, and patch management plan included in premarket submissions

Scope & Limitations

In Scope:

  • FDA regulatory pathway selection (510(k), De Novo, PMA) with decision framework and comparison
  • 510(k) submission process including eSTAR requirements, SE comparison, and RTA prevention
  • Quality System Regulation (21 CFR 820) and QMSR (ISO 13485:2016 alignment) compliance assessment
  • HIPAA Security Rule safeguard evaluation for medical device software
  • Device cybersecurity requirements including SBOM, threat modeling, and PATCH Act compliance
  • AI/ML SaMD framework including PCCP, GMLP principles, and training data characterization
  • Cross-framework mapping between FDA, EU MDR, and ISO 13485

Out of Scope:

  • Preparation or writing of actual FDA submission documents -- this skill provides frameworks and gap analysis, not document authoring
  • Clinical trial design, execution, or statistical analysis for PMA clinical data
  • FDA establishment registration, device listing, or UDI system implementation
  • Post-market surveillance reporting (MDR, MedWatch) beyond process guidance
  • De novo classification request scientific review preparation
  • Direct interaction with FDA reviewers or Pre-Submission (Q-Sub) meeting facilitation

Important Notes:

  • The QMSR became effective February 2, 2026 -- all manufacturers must now comply with ISO 13485:2016 as incorporated by reference, with FDA-specific retained requirements
  • The Quality System Inspection Technique (QSIT) has been withdrawn and replaced with updated inspection procedures under Compliance Program 7382.850
  • Risk-based thinking is now expected across all QMS processes under QMSR, not just design controls

Integration Points

SkillIntegrationWhen to Use
quality-manager-qms-iso13485ISO 13485 QMS implementation aligned with QMSR; process management and supplier qualificationWhen implementing QMS satisfying both ISO 13485 certification and FDA QMSR requirements
mdr-745-specialistCross-framework mapping for dual US/EU market submissions; technical documentation alignmentWhen medical device requires both FDA clearance/approval and EU MDR CE marking
capa-officerCAPA process management per ISO 13485 Clause 8.5 (replacing legacy 820.100 under QMSR)When managing corrective and preventive actions within the FDA quality system
risk-management-specialistISO 14971 risk management integrated with design controls and cybersecurity risk assessmentWhen conducting risk analysis for premarket submissions per 820.30(g) and AAMI TIR57
eu-ai-act-specialistCross-jurisdictional AI/ML compliance for devices marketed in both US and EUWhen AI-enabled medical device requires both FDA PCCP framework and EU AI Act conformity assessment
infrastructure-compliance-auditorTechnical cybersecurity validation for connected device security controlsWhen documenting cybersecurity architecture and SBOM for premarket submissions

Tool Reference

fda_submission_tracker.py

Tracks FDA submission milestones and calculates regulatory timelines for 510(k), De Novo, and PMA pathways.

FlagRequiredDescription
<project_dir>YesPath to project directory containing submission documents
--type <pathway>NoSubmission type: 510k (default), de_novo, pma, pma_supplement
--jsonNoOutput results in JSON format

Output: Milestone tracking with completion status, timeline calculations against FDA review goals, phase progress (planning, preparation, submission, review, decision), and overdue milestone alerts.

qsr_compliance_checker.py

Assesses compliance with 21 CFR Part 820 / QMSR by analyzing project documentation for evidence of implementation.

FlagRequiredDescription
<project_dir>YesPath to project directory containing QMS documentation
--section <section>NoCheck specific QSR section (e.g., 820.30 for design controls, 820.100 for CAPA)
--jsonNoOutput results in JSON format

Output: Per-section compliance status, evidence found (document patterns and keyword matches), compliance percentage, gap identification with required evidence descriptions.

hipaa_risk_assessment.py

Evaluates HIPAA Security Rule safeguards for medical device software and connected devices.

FlagRequiredDescription
<project_dir>YesPath to project directory for assessment
--category <cat>NoAssess specific category: administrative, physical, technical, or all (default)
--jsonNoOutput results in JSON format

Output: Per-safeguard compliance status across administrative (Section 164.308), physical (Section 164.310), and technical (Section 164.312) categories, with weighted scoring, evidence detection, and remediation recommendations.

© borghei, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 8 other files (scripts, references) in ra-qm-team/fda-consultant-specialist of borghei/Claude-Skills.

  • SKILL.md
  • references/device_cybersecurity_guidance.md
  • references/fda_capa_requirements.md
  • references/fda_submission_guide.md
  • references/hipaa_compliance_framework.md
  • references/qsr_compliance_requirements.md
  • scripts/fda_submission_tracker.py
  • scripts/hipaa_risk_assessment.py
  • scripts/qsr_compliance_checker.py

Open the folder on GitHubat commit 4a698e8

Compare with similar skills

Fda Consultant Specialist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Fda Consultant Specialist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Fda Consultant Specialist this skillborghei/Claude-Skills891—~8.2kAutomated safety check: PassMIT
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
HIPAA Pre-Deployment Compliance Checkmaziyarpanahi/openmed5.5k—~2kAutomated safety check: PassApache-2.0
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT
ISO Standards Readiness EvidenceK-Dense-AI/scientific-agent-skills48k1 repos~4.6kAutomated safety check: NotesMIT
Fda Consultant Specialistdavila7/claude-code-templates33k1 repos~2.7kAutomated safety check: PassMIT

Similar skills

  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Walks a data pipeline against the HIPAA Privacy and Security Rule checklist and produces a gap report before it processes patient data.

    5.5k GitHub stars~2k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • ISO Standards Readiness Evidence

    K-Dense-AI/scientific-agent-skills

    Organizes scope, controlled documents, risk files and traceability into draft evidence for human review against ISO 13485, 14971, 17025 and 15189.

    48k GitHub starsUsed in 1 repo~4.6k tokens
    Legal & ComplianceAuto-check: notes
  • Fda Consultant Specialist

    davila7/claude-code-templates

    Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.

    33k GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    184 GitHub stars~6.1k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed

More from borghei/Claude-Skills

All 354 skills in this repo
  • Agent Harness

    borghei/Claude-Skills

    Test and evaluation harness for AI agents — scenario suites, deterministic replay, regression diffing, cost and latency budgets.

    891 GitHub stars~3.1k tokensUpdated 3 days ago
    Auto-check passed
  • Agents In The Team

    borghei/Claude-Skills

    Run delivery when AI coding and ops agents take tickets. An agent skill from borghei/Claude-Skills.

    891 GitHub stars~4.2k tokensUpdated 3 days ago
    Auto-check passed
  • AI Content Disclosure

    borghei/Claude-Skills

    Check AI-generated marketing content and reviews for required disclosures under the EU AI Act, FTC rules and platform AI-label policies.

    891 GitHub stars~3.4k tokensUpdated 3 days ago
    Auto-check passed
  • AI Prototyping

    borghei/Claude-Skills

    Idea to AI-generated prototype to customer validation to engineering handoff.

    891 GitHub stars~3.6k tokensUpdated 3 days ago
    Auto-check passed
  • Analytics Engineer

    borghei/Claude-Skills

    Analytics engineering across data modeling, dbt, transformation, and semantic layers.

    891 GitHub stars~3.4k tokensUpdated 3 days ago
    Auto-check passed
  • Ansoff Matrix

    borghei/Claude-Skills

    Ansoff Matrix — 4-quadrant framework for growth options: market penetration, market/product development, and diversification.

    891 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed

Questions about Fda Consultant Specialist

What does Fda Consultant Specialist do?

FDA regulatory consultant for medical device companies, covering 510(k)/PMA/De Novo pathways, QSR (21 CFR 820), HIPAA, and device cybersecurity. Fda Consultant Specialist is an agent skill from borghei/Claude-Skills. FDA regulatory consultant for medical device companies, covering 510(k)/PMA/De Novo pathways, QSR (21 CFR 820), HIPAA, and device cybersecurity.

When should I use Fda Consultant Specialist?

Fda Consultant Specialist fits situations like: FDA submissions; predicate and substantial-equivalence analysis; premarket strategy.

How do I install Fda Consultant Specialist in Claude Code?

Run `npx skills add borghei/Claude-Skills --skill fda-consultant-specialist -a claude-code`. Or copy the skill folder (ra-qm-team/fda-consultant-specialist in borghei/Claude-Skills) into .claude/skills/fda-consultant-specialist in your project. Claude Code loads it when a task matches its description.

How do I install Fda Consultant Specialist in Codex?

Run `npx skills add borghei/Claude-Skills --skill fda-consultant-specialist -a codex`. Or copy the skill folder (ra-qm-team/fda-consultant-specialist in borghei/Claude-Skills) into .agents/skills/fda-consultant-specialist in your project. Codex loads it when a task matches its description.

Can I use Fda Consultant Specialist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add borghei/Claude-Skills --skill fda-consultant-specialist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/fda-consultant-specialist, .gemini/skills/fda-consultant-specialist, .github/skills/fda-consultant-specialist and .opencode/skills/fda-consultant-specialist in your project.

What does Fda Consultant Specialist need to run?

Going by SKILL.md and its folder, Fda Consultant Specialist needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3.

Does Fda Consultant Specialist access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Fda Consultant Specialist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Fda Consultant Specialist use?

Fda Consultant Specialist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Fda Consultant Specialist use?

About 8.2k tokens (SKILL.md is roughly 33k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 23k tokens, read only when the agent opens those files.

What are the alternatives to Fda Consultant Specialist?

Skills that share tags, products or a category with Fda Consultant Specialist: HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), HIPAA Pre-Deployment Compliance Check (maziyarpanahi/openmed, 5.5k stars), Hipaa Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars) and ISO Standards Readiness Evidence (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Fda Consultant Specialist?

borghei (a GitHub user) maintains it in borghei/Claude-Skills, which has 891 GitHub stars. The repository holds 354 skills in this directory. The repository was last updated on October 7, 2026.

Source: borghei/Claude-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.