FDA’s Initial Thoughts on 3D Printing of Medical Devices Published Today

Curious about how regulations on 3D printing of medical device will evolve? Check out the draft guidance published today by the United States Food and Drug Administration (“FDA”). Comments and suggestions are welcome and should reach the FDA within the next 60 days.

The draft guidance looks interesting under a number of aspects. First of all, it provides a definition of additive manufacturing (“AM”), i.e., “a process that builds an object by iteratively building 2-dimensional (2D) layers and joining each layer below, allowing device manufacturers to rapidly alter designs without the need for retooling and to create complex devices built as a single piece.”

It also defines itself as a “leap-frog guidance” and clarifies that “leap frog guidances are intended to serve as a mechanism by which the Agency can share initial thoughts regarding emerging technologies that are likely to be of public health importance early in product development”, which is a nice way to say that the FDA recognizes that its thoughts are just initial and subject to change.

A number of caveats are singled out and manufacturers are invited to be careful about, and to design their quality systems so they take due account of:

  • device design, which can be altered in AM due to various factors (pixelation of features, various patient-matching techniques, effects of imaging, etc.)
  • software and software interactions;
  • machine parameters and environmental conditions;
  • material used (which can be raw material or recycled);
  • post-processing phase;
  • process validation and acceptance activities;
  • device testing;
  • cleaning and sterilization;
  • biocompatibility.

The FDA also believes that AM devices that are patient-matched should be subject to additional labelling information.

The draft guidance does not address the use or incorporation of biological, cellular, or tissue-based products in AM, which may require additional regulation. Also, point-of-care device manufacturing may raise additional technical considerations.

Art. 29 Working Party on EU-US Privacy Shield: Trust Not Yet Restored For Transatlantic Data Flows

Only few months after the 2015 Court of Justice of the European Union (CJEU) landmark decision that put an end to the Safe Harbour system, the EU Commission proudly announced a new framework agreement with the US authorities, allegedly providing strong safeguards, sufficient to “enable Europe and America to restore trust in transatlantic data flows” (Commissioner Věra Jourová).

According to the Commission’s press release, the Privacy Shield’s guarantees include:

  • strong obligations on companies and robust enforcement;
  • clear safeguards and transparency obligations on US government access;
  • a redress possibility through an independent Ombudsperson mechanism;
  • effective protection of EU citizens’ rights through various measures (a specific timeline for resolving complaints , a free of charge alternative dispute resolution solution, as well as the possibility for EU citizens to lodge complaints with their national Data Protection Authorities, who will work with the Federal Trade Commission to solve them).

Nevertheless, the newly issued opinion of the Art. 29 Working Party (“WP29”) already raised strong criticism against the Privacy Shield, tempering the Commission’s enthusiasm. Although WP29 did not abstain from underlining the improvements the Privacy Shield offers in comparison to the invalidated Safe Harbour decision, its concerns seem to eclipse those positive features, leading to the overall negative assessment of the new framework. Moreover, the impression is that the Privacy Shield led to more uncertainty, leaving everyone frustrated, with the exception of those authorities that negotiated it.

But what are, then, according to WP29, the improvements offered by the Privacy Shield? On the other hand, what major concerns does it raise? Finally, does it provide for adequate answers to post-Safe Harbour issues?

Firstly, it must be recognized, as WP29 certainly does, that the Privacy Shield represents a large step forward from Safe Harbour in terms of data protection. And, one could argue, it couldn’t be otherwise, since the Safe Harbour decision dates back sixteen years ago, before Facebook, the social network, big data era and the emergence of encryption vs. surveillance-like debates.

However, WP29 welcomes the additional recourses made available to individuals to exercise their rights, together with the extensive attention dedicated to data accessed for purposes of national security and law enforcement. Increased transparency measures are also appreciated by WP29: both those offered by the US administration on the legislation applicable to intelligence data collection and those provided through the introduction of two Privacy Shield Lists on the US Department of Commerce website (one containing the records of those organizations adhering to the Privacy Shield and one containing the records of those that have adhered in the past, but no longer do so).

Unfortunately, it seems that, these (few), general, positive notes are by far neutralized by the much more incisive negative remarks made by the WP29. WP29 points out the inadequate safeguards set forth to protect some key data protection principles under European law: the data retention principle is not expressly mentioned by Privacy Shield instruments (nor it can be clearly construed from their current wording) and onward transfers of EU personal data to third Countries are insufficiently framed. Despite the EU Commission’s enthusiastic press releases, WP29 underlines how, from the documents signed  by US authorities, it cannot be fully excluded that US administrations will continue the collection of massive and indiscriminate data. And one cannot abstain from noting how crucial the latter aspect is, being one of the main reasons that led the CJEU to invalidate the Safe Harbour decision. Moreover , WP29, while recognizing the effort to create additional oversight mechanisms, considers those efforts not satisfactory: the new redress mechanisms, in practice, may prove to be too complex and difficult to use and, more specifically, the capability of the Ombudsperson mechanism to be truly independent from US governmental authorities is strongly questioned. The lack of clarity of the new framework is also stigmatized by the WP29 by calling for a glossary of terms to be included in the negotiated instruments, in order to ensure that the key data protection notions of the Privacy Shield will be defined and applied in a consistent way. Lastly, the WP29 points out, rightly, how the newly issued Privacy Shield documents already appear out-of-date, considering the approval and forthcoming enter into force of the EU data protection reform, which will bring important improvements on the level of data protection offered to individuals, not at all reflected in the Privacy Shield.

The adequacy of the Privacy Shield to address the issues raised after the CJEU decision invalidating Safe Harbour is hence, at least, arguable. The significant uncertainty created after the fall of Safe Harbour is not only far from being clarified but, possibly, worsened. The major concerns raised by the CJEU have not been adequately tackled, especially if one considers the absence of clear-cut undertakings of the US authorities on mass surveillance programs by security intelligence agencies. Regulatory costs on companies and governmental agencies will not therefore be balanced by stability, certainty and higher levels of fundamental rights protection, leaving everyone dissatisfied.

So, what’s next for Privacy Shield? Another advisory decision is awaited from Article 31 Committee after the second half of May. Then, different options are available but, basically, the implementation of Privacy Shield could take place with or without addressing WP29’s most important concerns. In any case, legal challenges before the CJEU, as well as claims brought to national data protection authorities, will always be open and much likely to happen, given the overall uncertainty characterizing transatlantic data flows: trust is, indeed, very far from being restored.

Interview with Diana Saraceni of Panakés Partners

This post features an interview with Diana Saraceni, founder and managing partner of PANAKÈS PARTNERS , a venture capital investor that finances medical companies, early stage startup and SMEs in Europe and Israel.

Why does Panakés Partners focus on Med-Tech?

Life sciences, especially Med-Tech, have always been an innovative and growing sector. Improving health conditions is one of the goal of developed countries, and new challenges will always face us. Considering this highly changing environment, start-ups and small companies appears to have the best structure to generate innovative solutions. In Europe there are several areas of excellence in technology and chemistry, the ideal environment where promising Med-Tech start-ups can develop. Moreover, European regulatory system has faster and easier protocols for companies to get CE mark and go to market, especially compared to the American system, where FDA approval requires more efforts, both in economic and clinical terms, to enter the market. Lastly, if we consider that western countries invest, on average, 10% of GDP every year on health services and that medical and pharmaceutical enterprises are the most active in acquiring start-ups, the great opportunity Med-Tech represent for us becomes evident.

What are the specific areas where you expect more growth in the future?

Considering the ageing of population and the need of hospitals to optimize their resources and reduce costs, we expect a great demand for technologies designed for home healthcare and chronic pathologies management. These new solutions will allow patients to receive their treatment directly at their own home, letting hospitals to focus their resources on acute pathologies treatment. Furthermore, we are confident that there will be a significant growth in all technologies aimed to a minimally invasive medicine. We are talking about in vitro diagnostics systems or robot-assisted surgery, which will substitute, or at least reduce, tissue biopsies and traditional surgery. Lastly, we expect a great increase in solutions for personalized therapies. These technologies, which combine genetic profiling to Big Data algorithms, will help physicians in the definition of therapies specifically tailored for every patients, increasing the probability of success.

Which countries appears to have the best factors (in terms of legislation, culture, access to funding and applied research) that helps fostering innovation?

By tradition, Anglo-Saxons countries are the ones with a more innovation-oriented policy. Everyone who has interesting ideas is encouraged in developing them, entrepreneurs never stop to look for new opportunities and skip from one project to another, as if they have not realized anything yet, legislation offers benefits to support the creation of new companies. These are the reasons why realities such as incubators and venture capital funds were born and are widespread in these countries. Regarding the specific case of Italy, we can state that the presence of top-class engineers and the excellence of Italy in clinical research in several areas, combined with lower costs than the other developed countries, are the main factors for the success of many Italian start-ups.

Which challenges lay ahead of you?

We received hundreds of requests of funding from companies all over Europe. Now, our main challenge will be to select the most promising ones, both in terms of proposed technology and feasibility of the project. Furthermore, we need to enlarge our network, in order to reach more companies and to find those ones whith the potentiality to change the status of medicine and build up more success stories out of Europe. We like to think of Panakés as a highly entrepreneurial start-up from a certain point of view, with great opportunities and successes just waiting for us!

 

Encryption vs. Surveillance: How the Debate on Whether to Lock or Unlock a Cell Phone Will Shape Our Future

All of a sudden, the debate on privacy and encryption, typically confined within law school classes, between think tanks or on specialized blogs (such as ours), is making headlines.

Apple, the tech giant, is emerging as new privacy champion ready to fight against the US government, and possibly many other governments in the world in order to protect individual’s data.

It is probably too early to draw conclusions on this debate, the outcome of which will determine the degree of freedom that citizens will enjoy in the future, and the degree of surveillance that governments will have over citizens. The two extreme nightmare scenarios are clear:

  • an Orwellian world where individuals record every snippet of their life (including sensitive data such as health data!) and governments have unhindered access and control on such data;
  • a world devastated by terrorist groups, who want to destroy modern culture, yet have unconstrained access to encryption and to communication instruments that magnify their terror threats.

We are obviously eager to see what the US federal court will decide on the appeal announced by Apple. However, it is even more interesting to read the various positions on the issue in the debate. This is a list of articles that we have found more thought provoking:

Enjoy the reading!

Pause for the Holidays: an Exciting Year Lies Ahead!

No doubt you deserve the holiday break that is coming up! We wish you a peaceful time off and a fabulous new year.

Indeed, 2016 promises to be a very interesting year for life sciences.

From the business point of view, the title of Deloitte’s study says it all: “Moving forward with cautious optimism”.  Not too enthusiastic, admittedly… but the centrality of the health sector in an ageing society is expected to overcome the strictures of health spending’s decrease in mature markets.

When it comes to legislation, the European Commission has certainly grand plans for 2016.  Final language is ready for the General Data Protection Regulation and the Data Protection Directive in the Field of Law Enforcement: the new rules will have an impact on m-health and medical devices’ manufacturers in particular, as well as on European companies in general. Stay tuned! Will the Medical Device Regulation and In-Vitro Diagnostic Regulations see the light in 2016? That remains to be seen.

We hope you have enjoyed our musings on issues that lie at the intersection of law and technology in 2015: we intend to bring you more in 2016.

Warm wishes from the Life Sciences’ Team at Italy Legal Focus.

Electronic medical records and patients: a love and hate relationship.

What’s the status of e-health in Italy?

A fairly reliable benchmark may be represented by the implementation of the Electronic Medical File (Fascicolo Sanitario Elettronico) (“EMF”). The EMF was first introduced by Law Decree nr. 179 of 2012, as converted into law no. 221 of 2012; it was then implemented by way of Ministerial Decree dated September 3, 2015. The purpose of the EMF is to provide a tool to patients and healthcare professionals by collecting and providing web access to health-related data like hospitalizations, medical checks, drug administration, home assistance, and access to emergency rooms. In other words, the EMF promises to make all data relating to patients’ health readily available and accessible from any place in the world at an unparalleled speed.

Despite the intents, the new comprehensive tool is far from reaching the expected success.

Why that?

A legal-related reason may lie in the privacy concerns that the creation, population and maintenance of EMFs bring about. EMFs are in fact populated with data collected by healthcare professionals in the course of patients’ lives. The fear that data may be inadequately protected on the internet, and thus inappropriately divulged, may in fact push patients to deny their consent to the creation and population of EMFs. After all, although data are supposed to be processed in accordance with the provisions of the Code for the Digital Administration, and appropriate measures must be taken in order to ensure access authentication and authorization, suspicion may still populate patients’ mind as to the safety of the data processing.

Quite interestingly, a more common reason seems however to prevail. Italians just do not know about the EMF! According to a survey carried out by the Observatory for Digital Innovation in Health on a sample of 1,000 citizens, 83% of them has never heard about the EMF before, 88% ignores if such service is currently active in their Region, and 95% has never sought information about it[1]. Also, EMF seems not to be the most appealing item in blog discussions: out of 400,000 comments on e-health on the web, only 11% relates to the EMF[2]. Such a low impact seems to go hand in hand with quite a low use of other e-health services provided by hospitals and other health-care centers. Only a few patients seem in fact to have taken advantages of services like on-line booking of medical checks, testing records, and payments[3].

If, as mentioned, psychology plays a major role in the implementation of the EMF, so do the efforts thus far made by Regions and healthcare professionals. An inquiry into the implementation of the EMF in the Emilia Romagna Region reveals that not all services set forth in the law are currently included in the available EMF, and the availability of the services may depend on where the interested patient resides[4]. Also, hospitals and healthcare professionals seem to be responsible for having passively accepted the EMF, without truly understanding its potential[5]. Health-care professionals are reported to oftentimes look at the EMF as a burden rather than a revolutionary tool[6]. Lastly, many hospitals and healthcare centers keep on maintaining their independent presence on the web in parallel; as a consequence, patients rely on their website to use services that would be available on the EMF[7].

What can be done?

Perhaps the EMF would be more popular if patients were able to enjoy it through a mobile app, provided that security concerns are adequately addressed. Patients may thus access the EMF more easily, monitor the processing of the collected data and promptly report any inaccuracy or errors. However, if this suggestion may represent an improvement, it would in any case require further education and promotion through healthcare professionals and healthcare centers.

[1] Il Sole 24 Ore Sanità, September 29 – October 5, 2015, page 10.

[2] Ibidem.

[3] Ibidem.

[4] Il Sole 24 Ore Sanità, October 20 – October 26, 2015, page 8.

 

[5] Il Sole 24 Ore Sanità, October 20 – October 26, 2015, page 8.

[6] Ibidem.

[7] Ibidem.

Why E-Prescription is an Important Step Towards E-Health

Italian Regions are racing towards the goal of de-materialization of prescriptions of medicines. While the national average percentage of electronic prescriptions has not yet reached 50%, certain Regions are recording percentages above 80% (Veneto, Sicily, Campania, and Aosta Valley), according to the latest data published by Il Sole 24 Ore Sanità on the September 8-14 issue. The goal of 90% of de-materialized prescriptions, which has been postponed to 2016 by Law no. 11 of 2015, is getting closer. E-prescriptions will also have an interesting feature that may prove helpful for certain patients: the validity of e-prescriptions would no longer be limited to a single Region, but would spread to the national level.

What are the advantages of e-prescribing and why is it considered a crucial step towards E-Health? Saving on the cost of paper, as cited by certain commentators, is definitely not the point. E-Health requires costly investments in the field of Information Technology, which will not be easily set-off by money saved on paper!

E-prescriptions actually promise much more substantial benefits:

  • Increase of patients’ safety and error reduction: an electronic system can lead to less mistakes due, for example, to the selection of incorrect or unavailable drug dosages, the duplication of therapies or the misinterpretation of the content of the prescription, the avoidance of mistakes linked to the omission of certain information (e.g., allergies).
  • Better monitoring of appropriateness and control of the cost of therapies: e-prescriptions can be a formidable tool to gather data and keep track of health costs in real time, which may lead to a more efficient control on expenditures at every level. As an example, think about what an automatic alert suggesting more cost effective therapies or an optimization of the current therapy may do for a single patient and for the health system in general.

Let’s keep on counting electronic prescriptions (21 million out of 48 million last June!): they will not be the panacea for the national health system, but they can be a great step forward.

The Safe Harbor Decision (And What Is Wrong With It)

As most people and businesses on either side of the Atlantic are now aware, on October 6, 2015 the European Court of Justice invalidated the Commission’s Safe Harbor decision and made the transfer of personal data to the United States slightly more difficult for businesses.

The Court decision is based on two fundamental findings: first, the Commission’s Safe Harbor decision did not find – as it was required to do according to the Court – that the United States ensures a level of protection of fundamental rights essentially equivalent to that guaranteed within the European Union. Second, and equally important, the Court held that the Commission had no authority to restrict the powers of national data protection authorities to examine complaints of their citizens and assess whether the transfer of data to the United States affords an adequate level of protection.

Until the recent Court decision, the Safe Harbor program has provided a framework for the transfer of personal data from the European Union to the United States. Safe Harbor, however, is neither the only way to transfer personal data to the United States, nor the most commonly used. United States undertakings have consistently used – and will be able to continue to use even after the Court’s decision – model clauses and binding corporate rules.

As European and US undertakings have a wide variety of tools available to transfer data to the United States, the most troubling finding of the Court’s decision is not the invalidation of the Safe Harbor per se, but rather the recognition of much broader powers to member states’ data protection authorities. While the Safe Harbor scheme provided a single and simplified framework that was easily understood by United States’ businesses, the new decision leaves uncertainty as to the approach that each member state’s data protection authorities will take in connection with the export of their citizens’ data. As a consequence, in spite of the current efforts by European authorities to adopt a single data protection regulation ensuring a more uniform legislation throughout the continent, the Court decision is likely to lead – for at least some time – to a more fragmented and less clear legal framework among different member states.

Last, but not least, it is worth noting that one of the main reasons that led the Court to invalidate the Safe Harbor Commission’s decision has been the discovery of mass surveillance programs by US national security intelligence agencies and their rights to access personal data of European citizens. The concern of the European Court of Justice is well grounded and all of us, as individuals, are likely to share that same concern. However, why is the Court not equally worried about the surveillance programs and data retention policies adopted by several member states over the last few years?

Many have pointed out (see for instance here and here) that the Court decision is the result of different sensitivities between US and European people when it comes to the protection of their privacy, being the Europeans more keen to consider the protection of their personal data as a fundamental human right (or, rather, very keen on teaching data protection lessons to the United States). However, the failure of the European Court of Justice to acknowledge that such fundamental right is as much at risk within the borders of Europe as it is outside leaves us wondering whether the Court is really protecting the substance of our privacy as European citizens.