Let’s Talk Risk! brings together MedTech leaders and practitioners for thoughtful conversations on the challenges that shape risk, quality, innovation, and leadership. With 150+ episodes and more than 30K downloads, it helps professionals gain the clarity and confidence to lead through complex decisions.
Case Study: Why FDA Cybersecurity Expectations Are Really QMS Expectations
vendredi 10 juillet 2026 • Durée 17:29
You cannot bolt cybersecurity onto a medical device at the end of development.
FDA’s cybersecurity guidance makes a clear shift: cyber risk is now a quality system issue, a patient safety issue, and a lifecycle management issue. For connected and software-enabled devices, it is not enough to show that the software works as intended. Manufacturers also need to show how cybersecurity risks were identified, controlled, verified, traced to patient harm, and managed after release.
In this audio summary, we walk through why FDA’s expectations go beyond submission documentation and why QA/RA teams need to understand the practical connections between SPDF, threat modeling, SBOMs, vulnerability management, postmarket patching, and the medical device QMS.
Key highlights covered in the audio:
* Why cybersecurity now needs to be treated as part of the medical device QMS
* How Section 524(b) changes expectations for “cyber devices”
* Why cyber risk needs to connect to patient harm, not just IT vulnerability
* How SPDF, threat modeling, architecture views, and testing evidence fit together
* Why machine-readable SBOMs and VEX documentation matter for vulnerability management
* How postmarket patching, CVD, and cybersecurity management plans create lifecycle obligations
Keywords:
FDA cybersecurity guidance, medical device cybersecurity, cyber device, SPDF, SBOM, medical device QMS, cybersecurity risk management, patient safety, postmarket cybersecurity.
🎧Click Play above to listen to a brief audio summary about this case and lessons QA/RA and Clinical professionals can apply in practice using the newly released FDA Guidance.
Thanks for reading Let's Talk Risk!. If you liked this post, share with others.
Note:
The audio summary was prepared using Google NotebookLM, an AI-enabled research tool. Here are a few key resources used for this analysis:
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit naveenagarwalphd.substack.com/subscribe
LTR 160: IMSC26 Highlights - From Compliance to Proactive MedTech Safety
vendredi 3 juillet 2026 • Durée 47:18
Summary
“The biggest takeaway was realizing that our perspectives on risk and safety are not isolated. They are shared, validated, and strengthened by others in the field.”
In this special episode of the Let’s Talk Risk! conversation, host Naveen Agarwal brings together a panel of medtech safety and risk management leaders to discuss key takeaways from IMSC26 in Boston.
The conversation highlights why the conference has become a unique gathering place for the medtech safety community: a forum where risk, quality, regulatory, clinical, and engineering professionals can speak a shared language and challenge each other’s thinking.
The panel explores several major themes: moving beyond compliance, bringing patient perspective into risk management, understanding QMSR as a shift toward risk-based quality systems, strengthening judgment and critical thinking, and using AI as a thinking partner rather than a replacement for expertise.
Listen to the full 47-minute podcast or jump to a section of interest listed below.
Chapters
00:00 – Introduction and Panel Overview01:23 – Bijan Elahi on the Growth and Vision of IMSC06:23 – Proactive Safety from Clinic to Home08:28 – Patient Safety as the Central Stakeholder Theme10:15 – FDA, QMSR, and the Shift Toward Risk-Based Thinking18:53 – Design Control, Agile Software, and Surgical Robotics22:11 – Hidden Influences, Judgment, and Psychological Safety34:26 – AI as a Tool, Not a Replacement for Expertise40:00 – Career Day, Final Takeaways, and IMSC27 Preview
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit
LTR 152: Omar Al Kalaa on Telesurgery and the Future of Remotely Controlled Medical Systems
vendredi 24 avril 2026 • Durée 36:21
Summary
“FDA is still asking the same core question here: can the sponsor demonstrate that the full system is safe and effective for the patient?”
In this episode of the Let’s Talk Risk Podcast, host Naveen Agarwal sits down with Dr. Omar Al Kalaa to talkabout one of the most important emerging frontiers in MedTech: remotely controlled medical systems. From telesurgery to connected infusion therapy, these technologies are expanding what is possible in patient care—but they also introduce a very different kind of system risk.
Omar brings a rare perspective at the intersection of medical devices and telecommunications. We explore why the real issue is not just connectivity, but control; why access to care is a major driver of these technologies; and why companies entering this space must think beyond the device itself to the broader ecosystem of networks, partners, responsibilities, and safeguards.
Chapters
00:00 – Introduction01:56 – What “remote control” really means in MedTech04:36 – Telesurgery vs. interoperable connected care systems08:30 – Why access to healthcare is driving adoption11:31 – Connectivity failure modes and misunderstood telecom concepts13:47 – What fail-safe means in a telesurgery environment18:24 – Risk ownership, contracts, and service level agreements22:01 – How sponsors should think about FDA for novel connected systems30:13 – Practical advice for engaging FDA in a stressed environment32:35 – Why partnership, not silos, will shape the future of this field
“You are not gong to lose your job to AI, but you may lose your job to someone who knows how to use AI better than you do”.
In this episode of the Let's Talk Risk Podcast, we explore the benefits of applying Generative AI to improve consistency of quality system documentation in MedTech with Garth Conrad, VP of Quality at Flex Health Solutions.
G…
EU vs. FDA: Aligned but different in their approach to safety of AI/ML devices
mercredi 4 décembre 2024 • Durée 18:33
Applications of AI in medical devices are growing rapidly. The regulatory environment in both the US and the EU is also changing fast. In this dynamic environment, it is important to stay updated and practice a flexible approach to both risk management and your regulatory strategy.
Listen to a brief audio summary above, about the emerging regulatory environment in these two major jurisdictions, and key takeaways for risk practitioners and regulatory professionals.
Regulatory environment is changing rapidly but there is new guidance
There is good news! A new guidance document in the form of a questionnaire was recently published by the Team-NB, the European Association of Medical devices Notified Bodies. The joint Team-NB/IG-NB Questionnaire on Artificial Intelligence in Medical Devices offers device manufacturers a process-oriented roadmap to demonstrate conformity to the EU-MDR (or EU-IVDR) requirements.
The term risk(s) appears 50 times in this questionnaire, highlighting the significance of risk management as a critical factor in ensuring safety and effectiveness of AI devices throughout their lifecycle. Out of a total of 189 questions across 26 categories, 32 (17%) are explicitly related to risk management!
FDA’s regulatory approach is considerably less prescriptive and more collaborative. The regulatory framework for the pre-market review is no different for AI-enabled devices compared to medical devices in general, including Software as a Medical Device (SaMD). A majority of nearly 1000 AI/ML enabled devices have been authorized as Class II devices, either through the De Novo, or the 510k pathway. The most important requirement is to demonstrate safety and effectiveness through valid scientific evidence that benefits of the intended use outweigh probable risks.
Let us take a closer look at the emerging regulatory environment in the US and EU
First, there is broad alignment at a high level between FDA and the EU
At a high level both FDA and notified bodies are generally aligned on the need to demonstrate safety and effectiveness of AI-enabled medical devices. Here are 3 specific areas of convergence in these two :
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit
LTR 76: Challenges and opportunities of AI/ML in MedTech
vendredi 29 novembre 2024 • Durée 36:46
“The classic thing with AI is that the hard stuff is easy and the easy stuff is hard. It can do math I cannot do, but it cannot do the reasoning I find easy.”
In this Let’s Talk Risk! conversation, we discuss key challenges and opportunities for applying Artificial Intelligence/Machine Learning (AI/ML) in MedTech. This was an open conversation with a live audience as part of the weekly Let’s Talk Risk! conversation on LinkedIn.
AI/ML applications in MedTech are growing rapidly. FDA has authorized nearly 1000 such applications, and this trend is only expected to grow. Our conversation included a variety of topics about this rapidly evolving field.
Jump to a section of interest using these timestamps.
00:03:30 Key factors related to AI/ML applications in MedTech
00:05:30 Dynamic nature of AI/ML causing performance drift
00:07:30 Upcoming ISO guidance on risk considerations for AI/ML applications
00:09:00 Keeping the human in the loop
00:10:25 Data quality issues and best practices for AI/ML
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit
LTR 74: AR/VR devices in MedTech
vendredi 15 novembre 2024 • Durée 33:10
In this Let’s Talk Risk! conversation, Ritam Priya advises device manufacturers to engage early with the FDA through the Q-sub program. Applications of AR/VR in MedTech are growing rapidly, but the regulatory science is still evolving. There are many specific safety and performance concerns unique to AR/VR technologies used for medical purposes. Early engagement with the FDA can help in developing adequate plans for verification and validation of these devices.
Image quality, cyber-sickness, rapidly changing hardware and software technologies used in AR/VR applications, for example, are some of the concerns that need careful planning throughout design and development and in the post-market phase.
Listen to this Let’s Talk Risk! conversation with Ritam Priya, which also includes an open discussion with a live audience. Jump to a section of interest using these timestamps.
00:02:05 Introduction
00:01:30 Transitioning into a medical safety role from clinical practice
00:02:31 Overview of AR/VR applications in MedTech
00:06:15 Example of a recently cleared AR/VR based medical device
00:08:27 Image quality is a major concern for FDA in AR/VR devices
00:09:20 How FDA is advancing regulatory science for AR/VR technologies
00:11:18 Special safety and performance considerations for AR/VR devices
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit
LTR 73: It's time to up our game on medical device cybersecurity
jeudi 19 décembre 2024 • Durée 33:23
Summary
“Medical devices are now increasingly connected in a hospital network. Or even if they are not, they are vulnerable to cyber attacks”.
In this episode of the Let's Talk Risk Podcast, Eric Henry highlights the growing concern about security and cybersecurity of medical devices. As technology evolves and medical devices increasingly operate in an i…
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit naveenagarwalphd.substack.com/subscribe
LTR 72: A clinician's insights on risk and collaboration in MedTech
vendredi 1 novembre 2024 • Durée 33:37
“It comes down to collaboration. It comes down to intentional communication and ensuring there is trust and familiarity on both sides.”
In this Let’s Talk Risk! conversation, Dr. Olaf Hedrich emphasizes the need for collaboration, building trust and familiarity between clinicians and engineers. We all have a mutual desire to do the right things for our patients, but sometimes our lens is a bit narrow. It is important to understand some of the technical side of our individual functions so we can learn to speak the same language and broaden the aperture on our collective view.
Clinicians should learn some of the technical language and concepts of risk, and engineers should gain exposure to the practice of medicine relevant to their device.
He shares a specific example of how clinicians can help uncover the true nature of risk and find innovative solutions to challenging problems. It is not unusual for harm to occur even when there is no device malfunction or defect. In these situations, clinicians can help understand the true nature of risk through peer-to-peer communication with other clinicians in the field directly involved with the device.
Listen to this Let’s Talk Risk! conversation with Dr. Olaf Hedrich, which also includes an open discussion with a live audience. Jump to a section of interest using these timestamps.
00:00:40 Introduction
00:01:30 Transitioning into a medical safety role from clinical practice
00:03:50 How clinicians can help understand the true nature of risk
00:06:25 Keeping the patient in the center of everything we do
00:07:57 How intentional communication and trust drives collaboration
00:08:50 Emerging challenges for MedTech in a rapidly changing environment
00:11:25 Career advice to industry professionals for growth in this new environment
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit
LTR 71: Medical device cybersecurity now more critical than ever
vendredi 18 octobre 2024 • Durée 31:20
“It is not just about protecting your data. It is also about protecting safety of a medical device.”
In this Let’s Talk Risk! conversation, Nidhi Gani highlights the important difference between data security and cybersecurity, especially for a life-saving medical device such as a pacemaker. As medical devices become more inter-connected, they are also increasingly vulnerable to cyberattacks. Managing the risk of these vulnerabilities is a key party of cybersecurity risk management of medical devices and healthcare systems they are a part of.
Although the regulatory environment is changing rapidly, Nidhi encourages risk practitioners to apply the same basic principles of medical device safety to cybersecurity. A best practice is to apply the secure product development framework (SPDF) across the entire lifecycle of a medical device.
Listen to this Let’s Talk Risk! conversation with Nidhi Gani, which also includes an open discussion with a live audience. Jump to a section of interest using these timestamps.
00:01:25 Introduction
00:02:12 Why cybersecurity is important for medical devices
00:04:32 Medical devices today operate in a complex, connected environment
00:05:22 The SPDF approach to medical device development for cybersecurity
00:07:19 Current industry challenges in applying the SPDF approach
00:09:28 Cybersecurity challenges in the post-market phase
00:11:28 Exciting career opportunity for QA/RA professionals
* IMSC has become a true medtech safety community.The conference gives risk professionals a rare space to connect, compare experiences, and realize they are not alone in the challenges they face.
* Patient safety must be more than a slogan.The panel emphasized that patient perspective needs to show up directly in risk management, especially where traditional harm categories may miss emotional, psychological, or lived-experience impacts.
* Risk management is not just a compliance exercise.It is a human practice that requires collaboration, judgment, shared language, and cross-functional maturity.
* QMSR raises the bar for risk-based thinking.The discussion framed QMSR as a move toward connected quality systems where FDA may look at whether decisions, processes, and subsystems work together around patient safety.
* Judgment cannot be fully proceduralized.Procedures matter, but good risk decisions also require critical thinking, psychological safety, leadership, and comfort with ambiguity.
* AI can strengthen risk thinking, but it cannot replace expertise.The panel warned against over-reliance on AI while recognizing its value as a tool to organize thinking, challenge assumptions, and preserve institutional knowledge.
Bijan Elahias an award-winning medical device risk management author, professor and consultant.
Dr. Olaf Hedrich is the Chief Medical Safety Officer at Medtronic.
Michelle Lott is an executive advisor in regulatory strategy, principal and founder at LeanRAQA, LLC.
Aaron Josephis a principal consultant at Sunstone Pilot.
Let’s Talk Risk! with Dr. Naveen Agarwal is a bi-weekly live audio event on LinkedIn, where we talk about risk management related topics in a casual, informal way. Join us at 11:00 am EST every other Friday on LinkedIn.
Disclaimer
Information and insights presented in this podcast are for educational purposes only, and not as legal advice. Views expressed by all speakers are their own and do not reflect those of their respective organizations.
Parts of this article were created using AI-generated content, which was subsequently reviewed, edited, and fact-checked by the author to ensure accuracy and alignment with our standards.
* Remotely controlled medical systems are defined by control across distance, not just data transfer.
* Access to healthcare is one of the strongest drivers behind telesurgery and other remote-care models.
* The biggest risks are not limited to “connectivity problems”; they include misunderstood failure modes, unclear terminology, and weak cross-functional alignment between medical and telecom teams.
* Fail-safe behavior cannot be defined in the abstract. It depends on intended use, clinical context, and what the system should do when communication degrades or fails.
* In distributed systems, risk ownership is shared. That makes contracts, partner roles, and service expectations critical design inputs—not afterthoughts.
* FDA is still asking the same core questions it always does: is the system safe, and is it effective? The challenge is showing evidence across components the sponsor does not fully own.
* Sponsors should engage FDA early, bring a structured plan, and ask targeted questions grounded in a clear understanding of the broader ecosystem.
* The future of this space will belong to organizations that can collaborate across silos instead of trying to build everything alone.
Keywords
Telesurgery, remotely controlled medical systems, connected medical devices, healthcare connectivity, telecom, system safety, interoperability, risk ownership, service level agreements, FDA, IDE, systems engineering, cybersecurity, access to care
About Omar Al Kalaa
Omar Al Kalaais the Founder and Principal of Inovectrum, a technology advisory and innovation practice bridging MedTech and telecom. He advises companies on the design and deployment of high-performance connectivity solutions for medical devices, clinical environments, and digital health systems.
The team at Inovectrum supports clients across the full product lifecycle, from early design decisions through regulatory strategy and FDA submissions, with a focus on how connectivity, EMC, and system behavior translate into real-world performance. The practice also extends into interoperability and electrical safety, enabling a more complete evaluation of devices as they operate within complex, interconnected environments.
Before founding Inovectrum, Omar spent over eight years at the FDA, where he led regulatory science initiatives on 5G-enabled medical devices, developed wireless coexistence standards, and guided industry on complex compliance challenges. With a PhD in Electrical and Computer Engineering from the University of Oklahoma, he combines deep technical expertise with regulatory insight to advance future-ready connected health technologies.
Disclaimer
Information and insights presented in this podcast are for educational purposes only. Views expressed by all speakers are their own and do not reflect those of their respective organizations.
Parts of this article were created using AI-generated content, which was subsequently reviewed, edited, and fact-checked by the author to ensure accuracy and alignment with our standards.
Both the FDA and the European approach, reflected by Team-NB, prioritize patient safety and the effectiveness of AI-enabled medical devices.
2. Recognition of AI’s unique challenges
Both recognize that AI presents unique regulatory challenges due to its complexity, iterative nature, and reliance on data.
3. Importance of real-world monitoring
Both emphasize the need for ongoing monitoring of AI-enabled devices in real-world settings to ensure safety and performance.
Second, the Team-NB approach focuses on certifiability using a process-oriented questionnaire
1. Process-oriented approach for safety
The European approach, as evidenced by the questionnaire, focuses on ensuring the safety of AI-based medical devices through a comprehensive evaluation of processes throughout the device lifecycle.
2. Detailed requirements and documentation
The questionnaire outlines specific requirements for documentation, competence of development teams, risk management, data management, model development, and post-market surveillance.
3. Emphasis on certifiability
The questionnaire highlights the challenges of certifying AI-based medical devices, particularly those with self-learning capabilities, and emphasizes the need for robust validation processes.
4. Consideration of AI-specific security risks
The questionnaire addresses AI-specific cybersecurity risks like adversarial attacks and emphasizes the importance of security lifecycle management.
Finally, FDA’s approach is more collaborative and adaptive
1. Collaborative and adaptive
The FDA emphasizes collaboration with stakeholders (developers, patients, academia, global regulators) and a commitment to adapt regulations to the rapidly evolving AI landscape.
2. Focus on bias mitigation and health equity
The FDA prioritizes addressing bias in AI algorithms and promoting health equity by ensuring data representativeness.
3. Emphasis on lifecycle management
The FDA stresses the importance of managing AI applications throughout the medical product lifecycle, from design to deployment, monitoring, and maintenance.
4. Commitment to guidance and regulatory science
The FDA is actively developing guidance documents and supporting research to address the unique challenges of evaluating and regulating AI in medical products.
Key takeaways for risk practitioners and regulatory professionals
In this rapidly changing environment, it is very important for risk practitioners and regulatory professionals to stay current with evolving regulatory approaches. Here are 3 key takeaways to keep in mind:
1. Practice a flexible and adaptable approach to risk management
Risk practitioners and regulatory professionals need to stay informed of the latest developments and adjust their practices accordingly. They must also anticipate future changes and build flexibility into their risk management frameworks and compliance strategies.
2. Understand and address bias in AI systems
Identifying and quantifying bias in AI systems can be complex. Risk practitioners and regulatory professionals need to develop robust methodologies for assessing bias and its potential impact on patient safety and health equity. This includes understanding the sources of bias in training data, evaluating the fairness of AI algorithms, and implementing strategies for monitoring and mitigating bias in deployed systems.
3. Apply a tailored approach to address regulatory concerns in each market
The FDA is primarily focused on the end product and its intended use, while the EU is taking a more process-oriented approach that emphasizes the entire AI lifecycle. These differing approaches may lead to varying risk profiles and require adjustments to risk management strategies depending on the target market. Risk practitioners and regulatory professionals need to carefully consider these differences and develop tailored strategies that meet the specific requirements of each jurisdiction.
In conclusion
It is clear that AI applications in MedTech are going to continue growing. We are still in the early phase of AI applications, especially in healthcare.
At the same time, the regulatory environment is evolving rapidly. Both the FDA and the EU are moving fast to catch up with technology. While a focus on safety and effectiveness remains as the centerpiece of the regulatory approach, there are distinct differences in these two major jurisdictions. Good news is that new guidance from these regulators is coming out to clarify their latest thinking.
Risk management is an essential aspect of regulatory focus. There are new and emerging concerns about risks associated with AI/ML devices. Risk practitioners and regulatory professionals must stay current, and develop flexible, adaptable and tailored strategies to respond to this dynamic regulatory environment.
Disclaimer
This article was prepared with the help of Google NotebookLM, an artificial intelligence enabled research assistant, using the following sources:
* FDA white paper: Artificial Intelligence & Medical Products.
* Team-NB - Questionnaire: Artificial Intelligence in Medical Devices.
* FDA: Good Machine Learning Practice for Medical Device Development.
* IMDRF: Good machine learning practice for medical device development.
* Notes created using Google NotebookLM in response to user prompts
All output(s), including the audio summary, were reviewed by a human for accuracy and relevance. This article is intended for educational purposes only and should not be considered as regulatory advice.
If you liked this post, consider becoming a free or paid subscriber to Let’s Talk Risk!.
Information and insights presented in this podcast are for educational purposes only. Views expressed by all speakers are their own and do not reflect those of their respective organizations.
Ritam Priyais currently the Founder & Principal at Novarum MDRQ Consulting where she provides regulatory consulting services to MedTech clients in both pre- and post-market phases. She has over 20 years of experience in the medical industry, including leadership experience at top organizations. Her expertise includes regulatory requirements for marketing authorization of medical devices in major global markets including US, EU, UK, Australia and Canada. She holds a Bachelor’s degree in Mathematics, Computer Science and Economics, and an MBA in Strategy.
Let’s Talk Risk! with Dr. Naveen Agarwal is a weekly live audio event on LinkedIn, where we talk about risk management related topics in a casual, informal way. Join us at 11:00 am EST every Friday on LinkedIn.
Disclaimer
Information and insights presented in this podcast are for educational purposes only. Views expressed by all speakers are their own and do not reflect those of their respective organizations.
Dr. Olaf Hedrichis currently the Chief Medical Safety Officer at Medtronic. Previously he was at Boston Scientific in a career spanning more than 10 years in various roles of increasing responsibility. He transitioned into MedTech from his clinical practice as a cardiac electrophysiologist. He also served as instructor of medicine and clinical fellow at Tufts-New England Medical Center, and as instructor of medicine and chief resident at Saint Louis University. He is a Fellow of the Heart Rhythm Society and a Fellow of the American College of Cardiology.
Let’s Talk Risk! with Dr. Naveen Agarwal is a weekly live audio event on LinkedIn, where we talk about risk management related topics in a casual, informal way. Join us at 11:00 am EST every Friday on LinkedIn.
Disclaimer
Information and insights presented in this podcast are for educational purposes only. Views expressed by all speakers are their own and do not reflect those of their respective organizations.
Nidhi Ganiis currently a Cybersecurity regulatory affairs consultant at MCRA and an adjunct professor at Northeastern University. She holds a Bachelor’s degree in Biotechnology and Master’s degrees in Microbiology and Regulatory Affairs in Drugs, Biologics, and Medical Devices. She also has a certification in Cybersecurity from Harvard University. She applies her extensive technical and regulatory experience to help develop innovative solutions for medical device clients in this rapidly evolving space.
Let’s Talk Risk! with Dr. Naveen Agarwal is a weekly live audio event on LinkedIn, where we talk about risk management related topics in a casual, informal way. Join us at 11:00 am EST every Friday on LinkedIn.
Disclaimer
Information and insights presented in this podcast are for educational purposes only. Views expressed by all speakers are their own and do not reflect those of their respective organizations.
Découvrez des podcasts liées à Let's Talk Risk! Podcast. Explorez des podcasts avec des thèmes, sujets, et formats similaires. Ces similarités sont calculées grâce à des données tangibles, pas d'extrapolations !