The Clinical Realist

When the Algorithm Is a Device: AI, the FDA, and the Question Almost Nobody Is Asking

Episode 20

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 15:13
The AI tool you bought last quarter, the one bundled into your EHR upgrade, the one your hospital piloted on your unit. Was it cleared by the FDA as a medical device? Most physicians do not know the answer. The vendor's pitch deck almost certainly did not lead with it. And the answer matters, because once an algorithm crosses into FDA medical device territory, the rules that govern what it can claim, how it has to perform, who is liable when it fails, and what evidence the manufacturer had to produce before it reached your practice change categorically. In this episode of The Clinical Realist, Dr. Sarah Matt walks listeners through three questions: when is an AI tool a medical device, what do the three FDA approval pathways actually mean about the evidence behind a product, and what does professional liability look like when the algorithm is the one making the call. What you will take away: - When a clinical AI tool crosses the line into FDA-regulated medical device territory - What 510(k), De Novo, and PMA clearance pathways actually say about the evidence behind a product - Why the word cleared is doing enormous amounts of work in this industry - What changes for physicians, procurement teams, and health system leaders when the algorithm is making the call Book a Discovery and Clarity Session: https://calendly.com/sarahmattmd Subscribe to The Sarah Matt Briefing: https://drsarahmatt.com/newsletter-signup



Resources & Links:

📖 Get the Book: "The Borderless Healthcare Revolution" is available now on Amazon and major retailers.

💼 Work with Dr. Matt:
Looking for a keynote speaker or strategic advisor?
Visit: drsarahmatt.com

🔗 Connect on Social:
LinkedIn: https://www.linkedin.com/in/sarahmattmd/
YouTube: https://www.youtube.com/@DrSarahMatt-ClinicalRealist

📧 Subscribe to The Briefing: drsarahmatt.com/newsletter-signup
 

Disclaimer:
The views expressed on this podcast are those of Dr. Sarah Matt and her guests. They do not necessarily reflect the official policy or position of any affiliated institutions. This content is for informational and educational purposes only and does not constitute medical advice or a professional consulting relationship.

SPEAKER_00

So I want to start with a question that almost no buyer of clinical AI in this country has been asked directly. Here it is. The last AI tool you started using, the one your group bought last quarter, or the one bundled into the EHR upgrade, the one your hospital pirated on your unit, the one your investor company is selling to the health system you advise. Was it cleared by the FDA as a medical device? See, most of you don't even know the answer now. And that's not a physicism. The product probably did not tell you. A vendor's fish deck almost certainly did not lead with it. It was in there somewhere, maybe. And the trainer who walked your team through the workflow definitely didn't bring it up. The procurement committee that approved the contract may not have known to ask. But the answer matters because if a tool is a medical device under FDA regulations, the rules that govern it, what it can claim, how it has to perform, and what happens when it fails, who's liable when something goes wrong, and what evidence the manufacturer had to produce before it reached your practice are categorically very different from the rules that govern most software in your stack. So this is a clinical realist of Dr. Sarah Matt. On location here at a Rostar. Amazing. So today we're going to walk through these questions. Every clinician, every health system buyer, and every health tech founder in the audience needs to be able to answer clearly. How do you tell when an algorithm is a micro device? What do the three FDA approvals pathways actually mean about the evidence behind a product? And what does professional liability look like when the device is the one making the thought? So this episode pairs directly with this week's conversation on medical economics. There, I argued that most healthcare AI fails on financial grounds because the user, the decider, and the payer are three different people with three different incentives. Today, we're adding a fourth seat to that tape. They're regulators. And the regulator's answer to the question of whether your AI is a voice shapes everything the other three were operating saying. So let's start. The FDA defines a medical device very broadly, but statutory language has been in place since 1976 in the medical device amendments. So a medical device is any instrument, apparatus, or other article intended for the use in the diagnosis, cure, mitigation, treatment, or prevention of disease, or intended to affect the structure or function of the body. Wow, that's a big one. The web definition is older than most of the technology use, and maybe older than us. It's been doing double duty in the AI era. So when the FDA looks at an AI tool, the question is not, is this software? Software is everywhere. The question is, what is this software claiming to do? If the tool is nuclear diagnosis, subtoriate diagnosis, recommended treatment, predicting an outcome that drives a clinical decision or marketing on a clinical condition. It's functioning as a medical device. So the official regulatory category is software as a medical device, or to say MD. Now, first of all, I'm gonna put out there, I am not a lawyer nor a regulator. So no matter what, you always have to check. In the meantime, though, let's see if we can make sure we all understand this a little bit better. So three quick examples to make this concrete. Example one. So say you have an AI tool that reads a retinal image and tells you that the patient has signs of diabetic retinopathy. That's medical device. It's making a diagnosis. The FDA has cleared at least one product in this category, IDX-DR, and the clearance process took years. Now, example two, an AI tool that monitors your charting and suggests an alternative diagnosis you might consider. That could be a medical device too. It's supported a diagnosis. The clearance pathway depends on what the tool claims to detect and how confident the manufacturer is willing to be in writing. Example three, an AI scribe that listens to your visit and drafts your no. Is that a medical device? Probably not. Again, and this is currently positioned by most vendors. The scribe is drafting documentation, but it's not making it or supporting a clinical decision. So the FDA has signaled that ambient documentation tools really sit outside an open advice pathway as long as the physician is the one signing them. But and this is the part most procurement teams miss, that boundary is not stable. The moment that ambient scribes start suggesting a bone code or surfacing a clinical alert or flagging a possible diagnosis you didn't consider, they may have crossed the line. So the tool you bought last quarter as a documentation aid might actually be performing as a clinical decision support. And clinical decision support, depending on how the manufacturer markets it, may or may not need VTA clearance. So this is also where the 21, 21st century Cures Act starts to matter. So Cures passed in 2016 and carved out certain clinical decision support tools from FDA oversight under very specific conditions. One of the central positions, the physician has to be able to independently review the basis for recommendation. If the AI is a black box and a dot can't see the reasoning, exemption, if the AI is starting to see recommendation and clear logic, the physician can independently evaluate, it might be. So the line is drawn in transparency, not on the underlying technology. So for the clinicians in the audience, the practical takeaway is sure. Ask the question. Ask that question of every AI tool in reverse flow. At least the medical device. If a vendor can't answer, or the answer is we are exempt, ask them to point you to the specific exemption. They are a real same. For the health tech founders in the audience, the same question applies in reverse. So you should be able to answer it clearly and clean. Your customers are going to start asking. The buyers who get good at this are going to drive procurement standards across Clistry inside the next 18 months. And for the health system procurement teams in the audience, the failure mode is uniform. Most AI vendors' due diligence today still leads with security and data hit mode. And those are necessary. They're not necessarily sufficient, though. The regulatory status of the product belongs in the first 10 questions of the procurement conversation. And if it's not there in your process, that's a process gap to close. So you don't need to become a regulatory expert to operate well in this environment. What you need to know is that you need to know enough to push the question, and you need the discipline to push it on every patron. And once a tool is classified as a medical device, the FDA evaluates it through one of three primary pathways. And each pathway means something very different about how reduced the tool was tested before it reached your practice. Now remember, just because it's cleared by the FDA doesn't mean it's going to improve critical outcomes. It doesn't mean it's going to be ready for your workflow. It just means it's cleared from a regular perspective. So the audience for this episode, clinicians, buyers, founders should know how to read these. First is pathway one, 510K clearance. And this is the most common pathway. It's also the one that people misunderstand. It's not the same as approval. A 510K means the manufacturer demonstrated the device is substantially equivalent to a predicate device, one that's already on the game. Now bars comparison, not safety and efficacy in the trial sense that we usually associate with the FDA proof role. So for AI tools, the 510K pathway is currently the most common route, and it's faster than the alternatives, often six to nine months if you're lucky. The trade-off is that the evidence the FDA reviewed before clearance might be relatively limited. So if you see a press release that says a clinical AI tool is FDA cleared, and you don't see any other qualifier, that almost means always that it was a 510K. So translate that as the manufacturer demonstrated similarity to something else the FDA has previously seen. Doesn't mean the tool was studied in a large multi-site clinical shot. So this is also where the most common procurement misread happens. The phrase FDA cleared gets used in DEX all the time as if it means the same thing as FDA approved. And it really doesn't. A health system that does not know the difference is going to make different decisions than one that does. So the good news is the difference is easy to teach. And bad news is that most procurement teams have not been taught. Now, what is pathway two? Well, this is de novo. And the de novo pathway is for novel, lower to moderate risk devices that don't have a predicate to compare against. And many of the early AI tools that the FDA cleared, including the ones for diabetic retinopathy detection that I mentioned earlier, went through de novo. And de novo process requires a manufacturer to make a risk-based case from scratch and to commit to specific performance characteristics. So it's a lot more rigorous than 510K and establishes a new device type that subsequent products can then use as a predicate. Now, the de novo pathway is the one to look for if you're evaluating a tool in a clinical area that did not exist as a device category before AI. The clearance letter usually contains performance specifications. And this is information you can ask the vendor to share. As for it, the letter is a public document. If they aren't gonna provide it, well, that itself is a signal worthwhile. And then there's pathway three, pre-market approval, PMA. So this is the most stringent pathway. PMA is required for class three devices, the highest risk category. PMA requires clinical trial evidence. So it's what most physicians have in mind when they think of FDA approval. But very few AI tools are currently going through PMA because most are positioned as class two or lower risk class three. So if a tool you're evaluating cleared PMA, you can ask for trial data, and it exists by regular requirement. So the takeaway from this is very short. When a vendor tells you their AI tool is FDA cleared, ask which pathways. The answer will tell you what kind of evidence the FDA review. And remember, F10K. And remember, 510K is a floor, de novo is more substantial, and PMA is the gold standard. But none of them is a guarantee that the tool is going to perform well on your specific patient population. But all three give you a starting point to evaluate the depth of the regulatory review behind the product. Now, for the founders in the audience, the pathway you choose at submission time is a signaling decision. Substantially equivalent claims are fast and easy to underwrite, harder to defend in sophisticated procurement room. A de novo or PMA track product carries a much higher cost at a longer timeline and substantially harder evidence on the back end. So the right answer really depends on the buyer you're selling to and the bar the buyer is going to hold you to. Now, if the buyer's sophisticated, maybe the most rigorous pathway you can credibly secure. The shortcut is more expensive than it looks. So now we get to the question that most nobody is talking about in the AI procurement meeting. Liability. The standard of care in medicine is what a reasonable physician will similar train and experience would do under similar circumstances. And what's the framework that governs malpractice cases? It's also what your insurer is underrated against. And it was designed way before any clinical workflow involved that black box algorithm. So there's three liability questions every provider using an AI tool should be able to answer. And there are also three parallel questions every health system procurement team should be able to answer about every AI tool they're solving for. I'm gonna walk through all three from both angles. So question one if the AI gets it wrong, who's responsible? You, the manufacturer, or both? Now, the kernel medial answer in most jurisdictions is it really depends on whether you reasonably relied on the tool and whether the tool was being used as the manufacturer. If you use the tool off-label, though, or if you ignored a clinical signal that contraindicated the AI output, the picture gets hard. The standard of care does not vanish because an algo got involved. It just gets harder to articulate. Now, on the procurement side, does the vendor indemnify the health listed in the event of an AI-driven inherent event? And under what conditions? Now, almost every AI vendor contract I've read in the last 12 months tries to push that liability back onto the practice and institution. And some of it's very reasonable, but some of it may not be. So the clauses to look for are the indemnification scope, the cap on vendor liability, and the exceptions list. Now the exceptions list is usually where the operative risk lies. Now, question two When the LGO updates, are you using a different device? And now this one's unique to AI because most medical devices are static. And the fibrillator does not get smarter over time. Many AI tools do. So the FTA is a guidance side of what it calls predetermined change control, which allows manufacturers to update certain device brands without triggering a brand new clearance. Updated software can gain meaningfully different performance. And if the AI you trusted six months ago has been retrained, maybe on new data, the new reliance on its output is reliant on a different model. So the vendor should be able to tell you when the model is off-updated. And if they can't, that's a question with raising. The procurement side version of this is: does the contract require the vendor to notify the health system in material model updates? Does it give the health system any right to evaluate performance on the new model before it goes live? Now, a lot of contracts don't carry that clause by default, and not a lot of procurement teams are asking for it. And that's probably a gap you should definitely look into. Then there's question three. What did the AI actually see and can you reconstruct its reasoning? So if you ever face a malpractice action involved in an AI assisted decision, you're gonna be asked what information AI had access to, what its output was, and why you act about it. And if the tool does not produce an audit trail, you may be not able to answer those questions. Some AI vendors maintain detailed logs of every input and output, others don't. The data retention policy would be in the contract. So read it before something goes wrong, not after. And on the procurement side, does the contract require the vendor to retain inference logs at a level of detail the illegal team can actually use in the position? The duration of your statute of limitations exposure. Now, most contracts will probably retain logs for 90 or 180 days. However, most state malpractice statutes of limitations are two to seven years. So the mismatch could be very structural. The cure is in the contract red log. So I'm not telling you any of this to scare you off of using clinical AI. Used well, these tools are saving logs. And the diagnostic AI that identifies a melanoma you would have missed is an unambiguous patient benefit. The triage tool that flags a sepsis case six hours earlier is a clinical win. And AI in clinical practice is here. It's going to expand, and the institutions learn how to use it well. Will the regulatory and liability of scaffolding in place are going to deliver much better care to more patients while maintaining and managing the downside? What I am telling you is that because the regulatory and liability environment is moving faster than the average procurement conversation, permissions, leaders, et cetera, are being handed AI tools and asked to use them. And health systems are being asked to sign through-year contracts on products whose model versions are gonna change inside of that contract life, maybe a whole bunch of times. Founders for building are being asked to define more evidence-based to procurement teams that are getting more and more sophisticated as reported. And the conversations about FDA status, model versioning, audit trails, and standards of care are happening in legal offices, not necessarily in exam rooms or in board rooms. And they should be happening all three. So I'm gonna close with the operational layer. Three S for each of the three seats at this table. If you're a clinician using AI tools in your practice this week, ask your vendor whether the tool is regulated as an auto-device. If they say yes, switch pathway. Each tells you something different about the evidence behind the tool. If they say no, we'll ask them to point you to a specific exemption they're relying on. Write it down. And if a question ever comes up about a clinical decision, if the tool informed, you will want that documentation. Now, if you're a health system procurement leader, open your three largest AI contracts, the active ones, this week. Read the identification, model versioning, and audit log retention clauses. Compare the audit log retention period to your state statute of limitations. And if there's a gap document, if there's a gap, document it and route it back to a vendor for renegotiation of the next renewal law. If you don't have a renewal coming up soon, document the gap and route to your legal team and your insurance proper. The risk doesn't vanish because the contract doesn't address it. Now, if you're a health tech founder selling a clinical AI product, the procurement teams you are selling to are about to get really good at this. Now, buyers who learn the questions in this episode are gonna drive this standard across the restraint inside the next 15 months. So if your product can't answer cleanly, you're gonna lose deals you would have won six months ago. The fix is really straightforward. It's right a one-page regulatory posture. Make sure you name your FDA pathway. Make sure your model versioning policy is clear and your audit log retention is also documented. Remember, you're gonna wanna negotiate a demnification posture. When you have a really hot prospect, make sure they have it. We have first procurement conversation. The deals are gonna make tons faster and you're gonna sleep a lot better. Now, if you're an investor sitting on the board of a health AI company, ask the file of these questions at your next board meeting. And if the answers are not raised, it's your data point. The valuation premium for clean regulatory posture is going to widen substantially this year. So help your portfolio company close the gap before the next round. So I want to bring this back to the question I started with. The last AI tool you started using was accurate by the FDA as a medical device. Most of you still don't know the answer, but after this episode, you should know what to find, how to find it, and what the answer tells you, and what the follow-up question should be. That's the goal. So clinical AI is not slowing down. The regulatory environment is going to keep moving, the liability frameworks are going to keep evolving, and the institutions and the founders who treat this question as foundational, not optional, are gonna define how this technology gets deployed in the next decade. You absolutely don't need to be a regulatory expert, but you need to be regulatorily literalish. There's a big difference. I'll see you next Wednesday. Thanks for joining the Clinical Realist.