Why Regulation of Mobile Medical Apps Isn’t A Bad Thing

Sep 11, 2013 | Blogs, Featured Blogs, Healthcare Tech, Mobile

mobile health

SOURCE: Sway Medical

The most anticipated document in the history of the booming field of mobile health should be here any day.  The Mobile Medical Applications Guidance we’ve been waiting on for the past year could be published any day.  Or maybe it won’t be.  There is a fierce battle going on over the release of the guidance and anticipation grows every day that it is not released.  One of the most vocal, and well-regarded, individuals in the center of the debate is Brad Thompson, a counsel to the mHealth Regulatory Coalition, who has indicated his support of the FDA releasing the guidance immediately.  In a recent Mobihealthnews article. Mr. Thompson provides a rational and factual round-up of the reasons why the final guidance should be released now rather than delayed until after a coordinated effort of regulatory agencies to introduce the HIT regulatory framework, as mandated by the FDA Safety Innovation Act of 2012 (FDASIA).

This uncertainty has created a growing hesitation of investors and entrepreneurs in the mobile health space that is a direct result of the FDA’s lack of action in publishing further guidance for regulation of medical on mobile.  But it is important to remember that we are not waiting on new regulations and requirements for mobile applications that previously have not been in place.  We are simply waiting for further clarification on how the FDA proposes to enforce the existing regulations.  Making this differentiation highlights the lack of knowledge and experience of investors and innovators in the mobile health space and reaffirms the necessity of a strong quality control and regulatory expert who understands the landscape of mobile health and how to apply the current regulations to this industry.

There is a growing sentiment surrounding the final guidance that mobile health innovation is being hampered by the uncertainty around how mobile apps will be regulated, but a strong QA/RA director or consultant would know that is not the case.   A strong QA/RA professional would be able to help establish the necessary procedures to meet the standards that currently exist.  The value created by developing a robust quality system and obtaining FDA clearance creates a huge market differentiation and provides distinction from scores of other similar software applications. Although pre-market submission and implementing a quality system seem like an overwhelming task, they should be viewed positively, as process to provide a better and safer product as well as a barrier to entry for other competitors.  The required procedures and documentation that are expected of a medical device company will not change with any guidance publication.

By complying and operating under Quality System Regulations (similar to Quality System Standards such as ISO 9001 or ISO 13485), companies ensure that software design, development, and initial release or modifications follow a strict set of rules (i.e. design controls). In a company with the required quality system, consumers know that software is thoroughly tested and validated to ensure it performs the way the company claims.  Unregulated apps or those that have not implemented quality system procedures do not provide the same assurance and pose tremendous risk of error, malfunction, security breach, and harm to the patient/consumer based on false claims and uncontrolled development environments.

Regulation shouldn’t be avoided, it should be taken head on by mobile health companies because it creates a strong reassurance to customers and medical professionals that your product is safe and effective and performs as intended.  With the growing number of health apps available, there is no standard evaluation criteria or an effective way to determine which apps perform to meet the user requirements and achieving a clearance will provide a clear distinction from wellness and fitness app to clinical grade medical device.

The process of applying to the FDA for mobile health companies typically falls under a 510(k) application.  This process will help the mobile health company and the FDA determine information such as indications for use and all claims of intended use (health related), description of the device, detailed technical and design descriptions, descriptions of device testing (verification and validation, which often includes clinical and/or patient/user studies). The official clearance letter from the FDA that states a product is “cleared by the FDA” (not approved) ensures that the device has been thoroughly reviewed and was determined to be safe and effective.

The FDA (or international equivalent) clearance letter is the gold standard for mobile health companies and should be a requirement of any company that provides a tool to assist in the management, assessment or treatment in a medical condition.  The issuance of a guidance letter will do nothing at all to change this fact.  The true value of the FDA’s Final Guidance is improved clarity for what is expected of a submission to reduce the time it takes for the FDA to review and respond or provide clearance.  The issue of the amount of time it takes to get a response on a submission should be the focus on further clarification provided by the FDA, but it should not be construed as a declaration of new requirements.

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

October 2, 2026 | ITBriefcase.net Why it matters: Citrix disclosed two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway on September 27 — CVE-2026-88771 (CVSS 9.5, unauthenticated RCE in default configuration, no special setup required)...

read more
Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more