Software That Flags a Heart Problem Now Has Its Own Rulebook


SILVER SPRING, MD – There is now a written rulebook for software that suggests you may have a heart condition.

The FDA published it on 11 September 2026. It took effect the same day.

The rule does two things at once. It makes this kind of software easier to bring to market. And it sets out, in detail, what a company must prove first.

What the software is allowed to be#

The definition is careful, and the care is the point.

“Cardiovascular machine learning-based notification software employs machine learning techniques to suggest the likelihood of a cardiovascular disease or condition for further referral or diagnostic follow-up.”

Three limits sit inside that sentence and the ones around it.

It suggests a likelihood rather than diagnosing. The order says the software “is intended as the basis for further testing and is not intended to provide diagnostic quality output.”

That is a statement of what the software is for, and it is what puts a product inside this class.

It handles one condition at a time, from ordinary non-invasive readings, during ordinary care.

And one job sits outside this class. The definition says the software “is not intended to identify or detect arrhythmias”, so software that does that is not covered here rather than forbidden.

What a company has to prove#

The rule attaches four sets of conditions. They are where the substance is.

The software must be tested on people it was not trained on. The validation data has to be “real-world data acquired from a representative patient population”, independent of the training data.

Read Also:  My Mother and Higher-Value Care · Hanh D. Brown

It must work in more than one place. This is the sharpest line in the document.

“The test dataset must include a minimum of three geographically diverse sites, separate from sites used in training of the model.”

A model that works beautifully at the hospital that built it is not enough.

The results must be broken apart, not averaged. Companies must report the standard accuracy measures, and the order requires demographic breakdowns “for each study site, relevant demographic sub-groups, and acquisition systems.”

That matters because a tool can look accurate overall and be much weaker on one group. An average hides it.

The rule names no group. It requires the breakdown and leaves which groups are relevant to the study.

Somebody must test whether users misread it. The rule requires a human factors assessment to “evaluate the risk of misinterpretation of device output.”

What the label must say#

Seven things. Two carry the word Warning, and the rule addresses them to the person using the software rather than to the patient.

The first is a warning against false comfort.

“Warning that the user should not rely on the lack of a suspected finding to rule out follow-up”.

In plain words, the software finding nothing is not a reason to skip the next test.

The second is about the reading itself, and it is easy to miss.

“Warnings identifying sensor acquisition factors that may impact measurement results”.

In plain words, how the reading was taken can change what the software sees.

A third item is not a warning but limits what the result is worth on its own.

Read Also:  The model that knew too much and understood nothing · Hanh D. Brown

“A statement that the device output should not replace a full clinical evaluation of the patient …”

The same item adds that the output “may not be sufficient as the sole basis for further testing”.

The label must also name where the software may not work, listing “device limitations or subpopulations for which the device may not perform as expected.”

Why the rule makes the market easier, and why it took three years#

This is the part that is easy to miss. The order puts the software into class II, and writes it into the regulations as the codified section 870.2380.

Without that, anything genuinely new falls into class III by default. That is the automatic route, and it requires premarket approval.

The agency states this as a belief rather than a finding. It writes: “We believe this action will also enhance patients’ access to beneficial innovative devices, in part by reducing regulatory burdens.”

And the easing dates from the 2023 classification. This order codifies it.

Class II is the middle tier. It means general rules alone are not enough, but that a written set of extra conditions can do the job.

There is a second effect. Once a device is classified this way it can serve, in the order’s words, as “a predicate for future devices of that type”.

The order spells out the consequence. Other companies “do not have to submit a De Novo request or premarket approval application to market a substantially equivalent device.”

They use what the order calls “the less burdensome 510(k) process, when necessary”. So one company’s request opened a door for devices of the same type.

Read Also:  AI Is Not a Faster Chip. It Is a Reinvention of Computing. · Hanh D. Brown

The decision behind this rule is older than the rule.

A company called Viz.ai asked for the classification on 10 January 2023, and the FDA granted it on 3 August 2023.

The text that writes it into the regulations arrived three years later, on 11 September 2026.

The order states both dates and gives no reason for the gap. This page will not invent one. A date is the part of a rule most easily read wrong, and checking one is a skill.

What it does not say#

It sets no single accuracy figure that every product must clear. It does require each product to carry one of its own. The label must state “the expected minimum performance of the device”.

And the goals a company tests against have to be defended. They “must be justified in the context of risks associated with follow-up testing”.

It does not say how many products now sit in this class. It creates the class and names the one company that asked for it, Viz.ai, and the one product that request covered.

And the conditions cover testing, software, human factors and labelling. They contain no duty to report back once the software is in use. Whatever oversight follows a mistake comes from somewhere else.

For a patient, the useful part is short. Software of this kind is a prompt, not an answer. A quiet result is not a reason to stop. And the label, written for whoever uses the software, is now required to say both.

Related: when a machine decides, AI is deciding Medicare coverage, and what a scoring tool decides.

Source: Federal Register 2026-18612, 91 FR 57785, published 11 September 2026, full text read.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top