FDA Issues Final Guidance on Mobile Medical Apps

Oct 24, 2013 | Blogs, Featured Blogs, Healthcare Tech

SOURCE: Sway Medical

DSC_3909

by Michael Zagorski

The FDA final guidance on Mobile Medical Applications is finally here. The final document effectively creates three categories of mobile applications in the mobile health space:

1. Apps not considered to be medical devices such as educational, reference, and training apps, or apps for   general office management and administration

2. Apps that meet the definition of a medical device, but due to the low risk nature the FDA has decided not to pursue regulation at this time

3. Apps that meet the definition of a medical device and may pose risk to patients and therefore fall under FDA’s oversight (Discretion Apps)

The first two groups offer little surprise. Historically the FDA has not regulated general administrative or reference apps and nothing indicated this would change. On the other hand, FDA has focused on the functionality rather than platform, so, if a device, whether hardware, or a software, or an accessory met a definition of a medical device, the FDA would expect compliance with the regulations.

Somewhat unexpected action by the FDA was the creation of category of apps under “enforcement discretion”, such as exercise and fitness apps, smoking cessation, dietary and calorie tracking, location based asthma applications, and activity trackers. All these apps would be considered medical devices depending on the claims made by the manufacturer; however the FDA has not provided any more detail around that.

By placing these apps under “Enforcement Discretion” the FDA provides developers time to plan for and establish quality and regulatory processes required by General and Special Controls, and probably the FDA itself to provide clearer guidance and determine how to enforce regulations for all these apps. Under the enforcement discretion, the FDA will not require manufacturer to submit a pre-market application or comply with other general controls such as Quality System Regulation, for the time being.

Creation of the “Discretion Apps” group is generally good news for the developers of this type of apps; however it eliminates probably the only objective information whether the application performs as the developer or the manufacturer claims the app does. Not to say that all developers create inferior applications, but with so many applications out there and some of them being created by teams consisting of only one or two people, there is a real need for a comprehensive certification process to provide a respected review of apps to ensure data will be safe and the applications will perform as expected.

What’s next?

Now that the final guidance is here, the FDA may now begin to take more direct regulatory action towards mobile health app makers not in compliance, though not failing to recognize that it may take some time for players new to the regulated space to determine applicable regulatory requirements.

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more