What 524B and QMSR Change About Medical Device Risk

Two regulatory changes have landed close together, and together they reset what adequate protection means for a medical device company. FDA’s Section 524B cybersecurity requirements now govern how connected devices reach and stay on the market. The Quality Management System Regulation, which took effect on February 2, 2026, rewrites the quality system rules that sit underneath every device a company makes.

🩺 Daily Picks by Our Team
Brought to you by Healthwise Feed’s “Daily Picks” team. Curated from credible health sources.
👉 Follow us @healthwisefeed1 for more wellness tips and updates.

Most coverage of these two changes treats them as compliance work, something for regulatory and quality teams to absorb. That view is incomplete. Both changes move the underlying risk a device maker carries, and that shift shows up in liability, in contracts, and in the insurance program that is supposed to answer a claim. A company can be fully compliant on paper and still carry uninsured exposure that the new baseline created.

This piece walks through what each change requires, how each maps to real exposure, where device makers are commonly underinsured against the new baseline, what underwriters are starting to ask for, and a short checklist for founders and quality leaders heading into a coverage review.

What The Two Changes Actually Require

Section 524B of the Federal Food, Drug, and Cosmetic Act applies to cyber devices, which the statute defines broadly. A cyber device is one that includes software, can connect to the internet, and has technological characteristics that could be vulnerable to cybersecurity threats. For those devices, a premarket submission has to show a plan to monitor, identify, and address postmarket vulnerabilities, including a coordinated disclosure process. It has to show that the device and the systems it connects to are reasonably secure. And it has to make security updates and patches available on a regular cycle, supported by a software bill of materials that lists the components inside the device. FDA has authority to refuse submissions that do not meet these requirements.

The important word is postmarket. 524B is not a one-time gate at clearance. It creates an ongoing obligation to watch for vulnerabilities and respond to them for as long as the device is in use. That ongoing duty is where the risk lives, because it means a company’s exposure does not end when the product ships. It follows the device into the field.

The Quality Management System Regulation replaced the older Quality System Regulation and took effect on February 2, 2026. It aligns FDA’s quality system requirements with the international standard ISO 13485 and folds risk management more deeply into the quality system. In practice it changes documentation, terminology, and the expectations around how a company demonstrates that its processes are controlled. For companies already certified to ISO 13485, much of the work is reconciliation. For companies that built their quality system around the older regulation, it is a genuine transition, and the transition itself is a moment when gaps surface.

How Each Maps To Real Exposure

The two changes touch four kinds of exposure a device maker already carries.

Cybersecurity exposure. A connected device that is compromised does not produce a tidy, single-category claim. Consider a monitoring device that feeds data into a hospital network. A vulnerability in that device that leads to patient harm can trigger a product liability claim. The same event can trigger a cyber claim for the data and network side, and a regulatory response tied to the postmarket obligations under 524B. The postmarket duty raises the stakes further. A company that knew about a vulnerability and did not act on it faces a very different claim than one that followed a documented response process. The paper trail becomes part of the liability picture.

Product liability exposure. QMSR sharpens the connection between quality system failures and product liability. When a claim alleges a defect, the company’s quality records are the defense. Strong process control, traceability, and risk documentation make a claim defensible. Gaps in the quality system make the same claim harder to defend and more expensive to resolve. Under QMSR, the quality system is not just a compliance artifact. It is evidence, and the quality of that evidence often decides how a claim resolves.

Recall exposure. Both changes raise the odds of a field action and change its shape. A cybersecurity vulnerability can require a correction that looks like a recall even when no patient has been harmed yet. A quality system finding can force a correction across a product line. Recall costs, including notification, retrieval, and the business interruption that follows, are their own category of exposure, and they are frequently underinsured or left out of the program entirely.

Management liability. When a regulatory or quality lapse damages the company, the people who run it can face claims that they failed to oversee the risk. Directors and officers exposure rises as regulatory scrutiny rises, and both of these changes raise scrutiny. For a venture-backed device company, that exposure also touches the investors and board members who sit above the founders.

Where Device Makers Are Underinsured Against The New Baseline

The most common problem is a mismatch between how the risk now behaves and how the policies were written.

Many cyber policies were built around data breach and network events, and they exclude bodily injury. A connected device that harms a patient through a security failure can fall into the gap between a cyber policy that excludes bodily injury and a product liability policy that was not written with software in mind. Neither policy clearly answers the claim, and the company discovers the gap at the worst possible moment.

Product liability policies often do not address software, firmware, and the post-market updates that 524B now requires a company to push. A device that changes after it ships, through a patch or an update, is a different risk than a device that is fixed at the point of sale. Policy language written for the second kind of device can leave the first kind exposed, and the update obligation under 524B guarantees that many devices now change after they ship.

Recall coverage is frequently absent, or set at a limit that reflects an earlier and smaller product footprint. Retroactive dates and claims-made structures can leave prior acts outside the policy that is in force when a claim finally arrives. The theme is consistent. The regulations moved the risk. In many programs, the policy language did not move with them.

What Underwriters Are Asking For, And How Contracts Fit

Underwriting is catching up to both changes, and the questions are becoming more specific. A device maker preparing for a review or renewal should expect to be asked for its software bill of materials and its postmarket vulnerability management process. Expect questions about coordinated disclosure, patch cadence, and incident response. Expect to be asked whether the quality system is aligned with ISO 13485 and how risk management is documented. Expect questions about recall planning and any prior field actions.

The companies that answer these questions well tend to place coverage on better terms, because the answers are evidence of a controlled risk. The companies that cannot answer them are harder to place and pay more for narrower coverage.

Contracts sit alongside the underwriting. Hospital agreements, distributor agreements, and contract manufacturing relationships almost always specify insurance requirements, and those requirements are written by parties who are paying attention to the same regulatory changes. A company that has not updated its program to reflect 524B and QMSR can find that its coverage no longer satisfies the insurance schedule its customers require. Reading those requirements before signing, rather than after a claim, is where a company keeps its leverage.

A Checklist Before Your Next Coverage Review

  • Map your connected devices against the 524B definition and confirm which ones carry postmarket cybersecurity obligations.
  • Read your cyber policy and your product liability policy side by side. Find the line where bodily injury from a device compromise would fall, and confirm one of them answers it.
  • Confirm your product liability language accounts for software, firmware, and post-market updates, not only the device as shipped.
  • Check your recall coverage and its limit against your current product footprint, not the footprint you had when the policy was written.
  • Confirm your quality system documentation reflects the QMSR transition and that your risk management records would support a product liability defense.
  • Review the retroactive date and claims-made terms so prior acts are not stranded outside your current policy.
  • Read the insurance requirements in your hospital, distributor, and manufacturing contracts, and confirm your program actually meets them.

The Practical Takeaway

Section 524B and QMSR are compliance obligations, but they are also risk events. They changed what a device company is exposed to, and a program that was adequate a year ago may no longer match the risk. The work is not complicated, but it is specific. Read the policies against the new baseline, close the gaps between them, confirm the coverage still satisfies your contracts, and make sure the quality and security evidence a claim would depend on actually exists. The companies that do this before a renewal are in a far stronger position than the ones that discover the gaps during a claim.

The post What 524B and QMSR Change About Medical Device Risk appeared first on MedTech Intelligence.





🔗 Read the full article on the original source



💬 Enjoyed this article? Share it with others:



Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top