- Gregory Palliere
In large pharmaceutical companies, one phrase invariably comes up whenever a digital project
involves healthcare: “We take no regulatory risks.”
The intention is commendable, and so is the culture that drives it: for decades, these companies have operated under a system of approvals, pharmacovigilance, and oversight where mistakes can be extremely costly.
But applying this zero-risk requirement wholesale to the world of healthcare software amounts to misinterpreting the situation. Zero regulatory risk does not exist for a patient or healthcare professional app, and it never will. The real question, therefore, is not “Are we immune to all risk?” but “Are we able to justify, with the relevant regulations in hand, the position we have taken?”
In large pharmaceutical companies, one phrase invariably comes up whenever a digital project
involves healthcare: “We take no regulatory risks.” The intention is commendable, and the culture that
underpins it is equally so: for decades, these companies have operated under a system of approvals,
pharmacovigilance, and oversight where mistakes can be extremely costly. But applying this
zero-risk requirement as-is to the world of healthcare software amounts to applying the wrong framework.
Zero
regulatory risk does not exist for a patient or healthcare professional application, and it never will
exist. The real question, therefore, is not “Are we free from all risk?” but “Are we
able to justify, with the relevant regulations in hand, the position we have taken?”
A clarification is needed right from the start, as it shapes how everything that follows is interpreted.
This discussion does
not apply to all health-related software.
Some applications have such a clearly
medical purpose that no interpretation can prevent them from being classified as medical devices: calculating
an insulin dose for a diabetic patient, detecting skin cancer, or monitoring a
vital sign with an automatic alert to the physician. For these uses, the path is well-known and perfectly
feasible: that of a genuine, certified medical device, which in the vast majority of cases involves
a notified body—a demanding process, but one that is by no means insurmountable.
This is the context that must be established even before designing such a platform
—not to downplay
the regulatory challenges, but to ground them in reality:
a European framework, Regulation (EU)
2017/745 on medical devices (MDR)
and the guidelines of the Medical Device Coordination
Group
(notably document MDCG 2019-11 on the qualification and classification
of software), which establishes
criteria and an intent—not an exhaustive list
of use cases.
As soon as software relates to health,
these criteria must be interpreted
in light of its intended purpose and functionalities. In this area, there is no
single
truth: there is an interpretation, which one must be able to defend.
To put this finding into practice, we have been using a four-tier scale for several years,
ranging from the safest to the most restricted.
Between white—which, in practice, does not exist for an ambitious solution—and black—which, to remain compliant, requires full medical device status and approval by a notified body in the vast majority of cases since the MDR took effect—the gray area encompasses virtually all uses of interest to those who wish to remain outside this classification: symptom monitoring, care pathway questionnaires, and data reporting to patients and healthcare professionals.
This gray area itself breaks down into a light gray—which is defensible—and a dark gray, which slides toward black as soon as interpretation becomes more opportunistic than rigorous.
This is a message that must be conveyed from the very start of a project, not when a regulatory department discovers—spreadsheet in hand—that a module of its application raises an objection.
Insisting on perfecting a digital project down to the last detail is a recipe for never launching anything at all—or for launching products so stripped-down that they lose all value for both patients and healthcare professionals.
The zone theory only makes full sense when applied to specific design choices.
The table below lists the most common trade-offs encountered in projects for monitoring chronic conditions across all therapeutic areas—particularly regarding clinical scores, which are the most sensitive and defining factor for classification as a medical device.
In practical terms—and this is a methodology that the MDCG guidelines themselves suggest adopting—this approach translates into a simple yet rigorous process: for each feature of a platform, we document its description, the relevant regulatory criteria, the level of risk of reclassification as a medical device, the justification provided, and the sources supporting it—guidance from the French National Agency for Medicines and Health Products Safety (ANSM), MDCG documents, available case law, and the positioning of comparable market players.
This work, recently carried out module by module on several self-monitoring applications intended for patients and their healthcare professionals—in dermatology, as well as in women’s health and ophthalmology—clearly illustrates the process described above: adjustments to the wording that, without changing the substance of the solution, shifted it from a dark gray to a light gray, regardless of the therapeutic area in question.
This work also changes the nature of the risk involved. A justified interpretation—even one contested by an authority during an inspection—is not fraud: it results, if necessary, in a notice of non-compliance accompanied by a deadline for compliance—and, in the most severe cases, a request for immediate withdrawal from the market until compliance is achieved.
This is no trivial matter: the European regulation (MDR, Article 113) leaves it up to each Member State to define its own penalties, which may go beyond a simple recall depending on the country, not to mention the potential impact on the company’s reputation.
But this is in no way comparable to the image of an “outlaw” operator that regulatory authorities so fear: it is the result of a difference in interpretation, not a desire to circumvent the law.
It is precisely this methodological rigor—systematic documentation, identified sources, and a defensible justification for each feature—that allows us to build, project after project, solid positions in the face of an inspection.
This reality is not unique to Europe: we conduct the same classification exercise in other geographic regions—the Americas, the Middle East—where the same question—“diagnostic assistance software or simply a reading aid”—arises in very similar terms.
This observation confirms that the difficulty is not a European peculiarity: it is struct
This issue is not merely theoretical for us. For several years now, we have been designing and deploying digital platforms for patients and healthcare professionals, particularly for the management of chronic conditions and to reduce diagnostic uncertainty in rare diseases.
This repeated experience, project after project, has allowed us to build in-depth regulatory expertise that is inseparable from our product expertise: we never design a feature without simultaneously asking ourselves what value it brings and what regulatory implications it entails.
The principle that underpins all our solutions is simple to state but demanding to uphold: the platform is not intended to replace the healthcare professional; rather, it is designed to provide them with qualitative and quantitative data that enables them to better care for their patients.
It is not the platform that interprets; rather, the platform empowers the healthcare professional to interpret.
In practical terms, this means collecting patient data much more frequently than a traditional consultation allows, and presenting it in a simple and intuitive way—both to the healthcare professional, who gains a more continuous and objective view of the patient’s progress, and to the patient themselves, who learns to better observe and describe their own symptoms rather than experiencing them purely subjectively.
It is precisely this design choice—to present the data rather than interpret it, to support healthcare professionals rather than compete with them—that allows these platforms to remain in a gray area while delivering considerable added value, from early detection to long-term follow-up of patients with chronic conditions.
Regulatory rigor is not an obstacle to product ambition; on the contrary, it is one of the conditions for long-term success.
In the field, we come across health apps every week that fall short of regulatory standards. Their interpretation often veers into very dark gray territory, and sometimes into the black: displaying scores without a critical threshold, using diagnostic terminology with confidence, and making quantified promises of clinical performance.
We must face this reality head-on—not to emulate it, but to put into perspective the anxiety of certain internal regulatory departments, which sometimes refuse to move forward even into the light gray area, even as less cautious players move forward unhindered.
Being more royalist than the king does not provide greater protection for the patient: it simply deprives the organization of its ability to innovate, without eliminating the residual risk—since, by its very nature, this risk can never be reduced to zero for this type of solution, which straddles the line between medical devices and other technologies.
The real danger for a major pharmaceutical company seeking to innovate in the digital realm is therefore not to adopt a “light gray” approach following a rigorous and well-documented analysis. The real danger is to believe that zero risk exists, to pursue it as an attainable goal, and, in doing so, to forgo solutions that could tangibly improve the screening and monitoring of millions of patients.
European digital health regulations consist of principles to be interpreted, not checkboxes to be ticked. This is certainly a constraint—but it is also, for those who know how to navigate it rigorously, a space for innovation.
At iRevolution, we’ve made this space our area of expertise: working with the regulatory teams of our pharmaceutical partners to build ambitious platforms for patients and healthcare professionals—platforms that are solidly justified and deliberately positioned in the light gray zone—never in the white zone, because, for this type of solution, the white zone doesn’t exist.
iRevolution © 2024 All rights reserved.