FDA Issues Final Guidance on Mobile Medical Apps

Oct 24, 2013 | Blogs, Featured Blogs, Healthcare Tech

SOURCE: Sway Medical

DSC_3909

by Michael Zagorski

The FDA final guidance on Mobile Medical Applications is finally here. The final document effectively creates three categories of mobile applications in the mobile health space:

1. Apps not considered to be medical devices such as educational, reference, and training apps, or apps for   general office management and administration

2. Apps that meet the definition of a medical device, but due to the low risk nature the FDA has decided not to pursue regulation at this time

3. Apps that meet the definition of a medical device and may pose risk to patients and therefore fall under FDA’s oversight (Discretion Apps)

The first two groups offer little surprise. Historically the FDA has not regulated general administrative or reference apps and nothing indicated this would change. On the other hand, FDA has focused on the functionality rather than platform, so, if a device, whether hardware, or a software, or an accessory met a definition of a medical device, the FDA would expect compliance with the regulations.

Somewhat unexpected action by the FDA was the creation of category of apps under “enforcement discretion”, such as exercise and fitness apps, smoking cessation, dietary and calorie tracking, location based asthma applications, and activity trackers. All these apps would be considered medical devices depending on the claims made by the manufacturer; however the FDA has not provided any more detail around that.

By placing these apps under “Enforcement Discretion” the FDA provides developers time to plan for and establish quality and regulatory processes required by General and Special Controls, and probably the FDA itself to provide clearer guidance and determine how to enforce regulations for all these apps. Under the enforcement discretion, the FDA will not require manufacturer to submit a pre-market application or comply with other general controls such as Quality System Regulation, for the time being.

Creation of the “Discretion Apps” group is generally good news for the developers of this type of apps; however it eliminates probably the only objective information whether the application performs as the developer or the manufacturer claims the app does. Not to say that all developers create inferior applications, but with so many applications out there and some of them being created by teams consisting of only one or two people, there is a real need for a comprehensive certification process to provide a respected review of apps to ensure data will be safe and the applications will perform as expected.

What’s next?

Now that the final guidance is here, the FDA may now begin to take more direct regulatory action towards mobile health app makers not in compliance, though not failing to recognize that it may take some time for players new to the regulated space to determine applicable regulatory requirements.

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

October 2, 2026 | ITBriefcase.net Why it matters: Citrix disclosed two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway on September 27 — CVE-2026-88771 (CVSS 9.5, unauthenticated RCE in default configuration, no special setup required)...

read more
Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more