Regulatory Science Innovations Catalyzing Medical Device Development

FDA published a meeting notice seeking public input on future medical device regulatory science. While the notice is broad, it is relevant to privacy because connected, software-driven, and sensor-based devices depend on governance for data handling within digital health systems. The agenda-setting process may influence how privacy and cybersecurity questions are addressed in device development and oversight.

Sources:

Third meeting of the Global Initiative on AI for Health

WHO’s event page for the third meeting of the Global Initiative on AI for Health highlights privacy-preserving evaluation approaches that keep clinical data under institutional control while models are assessed securely. This is relevant to privacy because it points to governance and technical methods that reduce the need to centralize sensitive health data. The meeting suggests continued international interest in evaluating health AI without broad data sharing.

Sources:

Hims & Hers

The FTC updated its case page for an enforcement action alleging that a telehealth company shared sensitive health information with advertising platforms. The matter is notable for privacy because it centers on handling of health-related data in a consumer-facing digital care setting. It also signals continued regulator focus on how telehealth firms disclose, use, and share sensitive information for marketing and advertising purposes.

Sources:

Reports on Non-Device Software Functions

FDA requested input for its 2026 report on non-device software functions, covering areas such as electronic patient records and software that transfers or displays data. The request is privacy-relevant because these functions often involve the handling, movement, and presentation of sensitive patient information, even when they are not regulated as medical devices. It also highlights patient-safety implications tied to data management tools that sit outside traditional device oversight.

Sources:

HTI-3 Final Rule

ASTP/ONC’s HTI-3 Final Rule updates federal health IT policy on information blocking, including privacy-related changes. The rule adds a new Protecting Care Access Exception and revises provisions connected to reproductive health information, which is significant for how providers, developers, and health information networks handle sensitive data requests and disclosures. For privacy watchers, this is a notable regulatory development affecting access, permitted restrictions, and compliance expectations in electronic health information exchange.

Sources:

Clinical Decision Support Software Guidance for Industry and Food and Drug Administration Staff January 2026

FDA’s January 2026 final guidance clarifies which clinical decision support software functions are excluded from device regulation. While focused on regulatory scope, the guidance matters for privacy because it helps define oversight boundaries for software that uses, analyzes, or presents patient data in clinical settings. The document is relevant to ongoing questions about digital health data use, accountability, and when federal requirements attach to software functions handling sensitive health information.

Sources: