Class III device programs increasingly add smartphone apps, cloud services, and bring-your-own-device displays to systems that were approved with dedicated hardware. Because the parent device carries a PMA, the software function is regulated as part of that Class III system, and the regulatory question is which supplement type the change requires rather than whether a submission is needed at all. Choosing wrong costs time: an under-scoped submission can be converted by FDA, and an over-scoped one commits the sponsor to evidence and review clock it did not need.
The analysis below works through how FDA classifies a mobile or BYOD software function by intended use, how that determination maps onto the PMA supplement pathways available for a change to an approved device, and what evidence each pathway typically expects. It then reviews PMA supplement precedents where app or BYOD functionality was added to an approved Class III system, with citations to the underlying FDA decision records.
Want Rhizome's help on your own question? Try it for free.
Adding a mobile app or BYOD platform to a Class III device: which FDA submission, and the PMA supplement precedents
When a mobile app or a bring-your-own-device (BYOD) display/control platform is added to a device that reached market through Premarket Approval (PMA), the change is almost always handled as a PMA supplement, not a new PMA and not a 510(k). The parent device is Class III, so the added software function is regulated as part of that Class III system, and the question for regulatory affairs is not whether a submission is needed but which type of PMA supplement fits the change. FDA's own framework tells sponsors to characterize the modification, run a risk analysis, define the evidence needed to show continued safety and effectiveness, and only then select the supplement pathway. FDA may disagree with the sponsor's choice. 2743
The app itself is a device software function, judged by intended use
FDA's software policy is function-based and platform-agnostic. A software function is assessed the same way whether it runs on a dedicated receiver, a smartphone, a tablet, a web/cloud service, or another general-purpose computing platform, and oversight concentrates on functions whose failure could pose a patient-safety risk. 1366 A mobile app becomes a regulated "mobile medical app" when it is intended either to be an accessory to a regulated medical device or to transform a mobile platform into a regulated device, judged by labeling, promotion, and distribution. 5351
Two of FDA's categories are directly relevant to adding an app to a Class III device:
- Extending or controlling the parent device, or analyzing its data. Apps that connect (wired or wireless) to control a device's function, modes, or energy source, or that display and analyze its data, are within FDA's oversight focus. Examples FDA cites include apps that control blood-pressure-cuff inflation or transmit control signals to an insulin pump. 6850
- Transforming the platform into a device through attachments, sensors, or displays, in which case the software must meet the classification of the transformed device. 5052
Because the classification follows the function, an app bolted onto a Class III system generally inherits Class III controls, and its modification is worked through the PMA-supplement decision tree below rather than the 510(k) modification logic that applies to Class II devices. 6568
Choosing the PMA supplement type
The pathway turns on how significant the change is and how much evidence is needed to re-establish safety and effectiveness. 2743
| Supplement type | When it fits an added app / BYOD platform | Typical evidence |
|---|---|---|
| Panel-track supplement | A significant change in design or performance, or a new indication for use. If the app pushes an indication change (for example moving a CGM display from adjunctive to non-adjunctive use), this is the pathway FDA considers most appropriate. 24 | Generally substantial clinical data. 24 |
| 180-day supplement | A significant change in components, materials, design, specifications, software, or labeling that is not a panel-track change, including changes to the principle of operation, control mechanism, performance, or new acceptance criteria. Most substantive app additions (a new smartphone user interface, display, or control channel) land here. 2434 | Preclinical data, sometimes limited confirmatory clinical data. 24 |
| Real-time supplement | A minor software, design, or labeling change (not affecting indications or contraindications) that needs no new clinical data, is supported by accepted methods/standards, and is reviewable within a single scientific discipline, where FDA grants a joint-review meeting. 26 | Preclinical/bench testing; no new clinical data. 26 |
| Special PMA Supplement (Changes Being Effected) | Changes that enhance safety without altering effectiveness, such as adding or strengthening safety information in labeling. 2446 | The change must not affect effectiveness. 46 |
| 30-day notice | A change in a manufacturing procedure/method affecting safety or effectiveness that does not alter design or performance specifications. Explicitly not available for changes that accommodate device design/performance-spec changes, material-spec changes, or device operating software — so it does not fit an app that changes the user interface or control. 273338 | Manufacturing documentation; FDA can escalate to a 135-day supplement if inadequate. 32 |
Practical read: a genuinely new app or BYOD display/control capability is a software/design change and typically a 180-day supplement; a minor, standards-supported tweak may qualify for a real-time supplement; anything that moves the indication is panel-track. The 30-day-notice route is closed to operating-software changes. 2426333438
Evidence FDA looks for, and the BYOD wrinkle
Even outside a Class III context, FDA flags new connectivity features as changes that can affect cybersecurity and may require a premarket submission, alongside changes to authentication/encryption or software-update mechanisms. 9 For interoperability, FDA expects evaluation of the interface(s), the intended connections, the effect of the connection on device performance, foreseeable misuse, data delays/corruption/format mismatches, security vulnerabilities, and the mitigations. 185 If a cyber device's change requires a submission, the FD&C Act section 524B cybersecurity requirements also attach. 915
The BYOD dimension (an app running on the patient's own consumer phone) is handled by constraining and validating the operating environment rather than by a distinct pathway. In practice FDA approvals specify supported operating systems and require a compatible companion device, and human-factors findings on consumer platforms have driven design changes: for Eversense, testing showed some Android users did not promptly check the app after a background low-battery alert, so the sponsor added banner notifications on Android to match the iOS behavior. 120236 These are the same design-control expectations FDA applies to any device software function: quality-system practices in design and development, software verification/validation, and human-factors evaluation appropriate to the risk. 68
PMA supplement precedents for added apps / BYOD platforms
The clearest body of precedent sits in continuous glucose monitoring and other patient-worn Class III systems, where smartphone apps were added to existing PMAs by supplement.
| Device (PMA) | Supplement | What the app/platform added |
|---|---|---|
| Dexcom G4/G5 CGM (P120005, Class III) | S028 – Dexcom Share | Added BLE to the receiver and a Share mobile app on the user's Apple device to remotely notify a "follower" of the patient's glucose data (secondary remote monitoring). 247 |
| Dexcom G5 Mobile (P120005) | S033 – G5 Mobile app | Added the Dexcom G5 Mobile app as a smartphone interface displaying CGM data and accepting calibration entry directly from compatible Apple devices. 244 |
| Dexcom G5 Mobile (P120005) | S057 – Android app | Added the G5 Mobile Android app as an additional display device for compatible smart devices. 237 |
| MED-EL cochlear implant (P000025, Class III) | S109 – AudioKey 1.0 / AudioLink | Added an optional mobile medical app on iOS or Android giving the same remote-control functions as the previously approved physical remote, with the AudioLink accessory bridging the audio processor to the phone. 120 |
| Tandem t:slim X2 insulin pump (P140015, Class III) | S020 | Approved pairing with the Dexcom G5 Mobile CGM so the pump could receive and display CGM data; also expanded age range and moved CGM use to non-adjunctive (an indication change riding with the connectivity change). 89 |
| Eversense implanted CGM (P160048, Class III) | Original PMA | The Eversense App on a patient's iOS/Android phone is the display for glucose data streamed by Bluetooth from the smart transmitter, with alerting and calibration entry; the record specifies OS and connectivity requirements for the consumer device. 113116118 |
| Medtronic Guardian Connect (P160007, Class III) | Original PMA | The Guardian Connect app is the primary display for sensor glucose values on a smartphone, with predictive glucose alerts. 114117 |
| Jewel P-WCD wearable defibrillator (P230022, Class III) | Original PMA | An optional iPhone app mirrors device status and can transmit therapy/event data after a shock for clinician review. 129134 |
Two points a reviewer should take from this set. First, the app is treated as a component of the Class III system: when it is a component of the PMA system it comes in through the original PMA or through a supplement, not through a 510(k) (a separately classified interoperable function is a different case). Second, the supplement type tracks the substance of the change: adding a "follower" notification channel (Share) or a new smartphone display/control app is a software/design change, while a change that also shifts the indication (t:slim X2 moving to non-adjunctive CGM display) carries the heavier evidentiary burden associated with an indication change. 24724489
Predetermined Change Control Plans for planned app changes
For apps that will iterate, an FDA-authorized Predetermined Change Control Plan (PCCP) can avoid a further marketing submission for a modification that is specifically described in, and implemented consistently with, the authorized plan. Anything outside the PCCP must still be evaluated under the applicable device-modification requirements, and a new submission made if required. 319 Building a PCCP into the PMA or PMA supplement is the mechanism that lets a BYOD app be updated for new phone models or OS versions without a fresh supplement each cycle.
Bottom line
Adding a mobile app or BYOD platform to a Class III device is a PMA supplement. Scope the change first: an indication shift is panel-track; a new or materially changed software interface, display, or control is typically a 180-day supplement; a minor, standards-backed change may be a real-time supplement; and the 30-day notice route is unavailable for operating-software changes. 24263334 The app is regulated by its function and inherits the parent device's Class III controls, so expect software V&V, human-factors, wireless/EMC, and cybersecurity/interoperability evidence, with the consumer-platform (BYOD) environment pinned down by supported-OS constraints and companion-device compatibility. 91868120 The CGM and cochlear-implant supplements above (Dexcom P120005 S028/S033/S057, MED-EL P000025 S109, Tandem P140015 S020) are the working precedents. 24724423712089