HN user

5440

243 karma
Posts0
Comments36
View on HN
No posts found.

My son was just arrested for using this in his hacking club at high school. Be careful if you have kids with one. According to witnesses in the room, he was showing it to kids in his hacking club and they all thought it was just turning off Apple phones in the classrooom. Apparently, it turned off phones including several teachers in adjoining classrooms. Anyways. The police came to the school and arrested him and are threatening him/us with federal crimes. They also executed a search warrant in our house and took all electronics. Its been a little traumatising to say the least.

For those of you in FDA regulated devices, my clients started receiving FDA NSE letters for not performing fuzz testing. For example, "Though you have provided penetration testing, it does not appear that you have addressed the other items identified such as static and dynamic code analysis, malformed input (fuzz) testing, or vulnerability scanning. This testing is necessary to assess the effectiveness of the cybersecurity controls implemented and to determine whether the residual risk of your device is acceptable."

I'm a regulatory consultant and I am currently submitting at least 5-10 510ks/DeNovos per week to FDA for AI/ML devices for a variety of companies. I can't imagine the actual throughput from companies as I am just one person out of many consultants out there. 95% of the software devices I edit and submit are hosting their databases on AWS. Essentially they transer the DICOM images to AWS and then run their algorithms against the data and then present the indications to the physcian. These run the range of CT/MRI/Ultrasound/pathology slides/genomic sequencing. Like I said, most of the databases are on AWS. A few are on Azure and a few european companies are on Orange.

CDC File Transfer 4 years ago

I'm currently working on a required CDC (Center for Disease Control) reporting function for a COVID test. For a second I thought this article was going to be extremely helpful.

I audit a lot of these Fentanyl API (Active Pharma Ingredient) factories in China. Its noticeable to me when I go through the warehouses as to how much product is going to Mexico. Other segments go to India for legal fill finishing prior to North America, while other small shipments are going to compounding facilities across the US. I always thought FDA might want to relay this information to homeland security, because its pretty easy for FDA inspectors to sneakily gather information during site inspections. At quite number of sites I often run into a mix of legal and nefarious activity at these massive API sites

I think those are generally good questions but the majority of submissions that FDA CDRH are reviewing are for imaging of ultrasound, MRI, XRAY etc, with a sprinkling of audio AI and maybe some individualized vaccines predictions at CDER.

These questions are generally addressed during the pre-sub for each FDA submission but I agree that the demographic information could be pretty infinite. I'm working on at least 5 of these AI submissions per week.

For example, lets say you have an AI submission for identifying cardiac ultrasound images. FDA will ask for very specific demographic information in the training and performance tests, as well as comorbidities (such as hypertension) for each training image. In addition, they will want at least three physicians to annotate the images. The training dataset is likely to contain at least 100-200K images.

The new draft literally doesn't change anything. It just defines some of the things that FDA has been already asking for in the past 7 years for every device submission.

Just my opinion as someone who has worked on many infusion pumps; that FDA review division is the best at FDA. They probably ask more cybersecurity questions than any other group I've encountered.

I review a minimum of 5x - 510ks a week.

I couldn't disagree with you more. I live in BC (and ONT), and all of us that migrated from the UK are much more pro-monarchy than most brits back in the homeland.

I review software for at least 3-5 companies per week as part of FDA submission packages. The FDA requirements require traceability between reqs and the validation. While many small companies just use excel spreadsheets for traceability, the majority of large companies seem to use JIRA tickets alongside confluence. While those arent the only methods, they seem to be 90% of the packages I review.

Before I entered management, I spent about 15 years as an engineer building "greenfield" drug manufacturing sites using automation packages such as Allen-Bradley, Emerson DeltaV and Siemens. There is nothing more time consuming than trying to tune the hundreds of PID loops in these facilities not only during site acceptance testing of equipment, but also during validation. These companies try to offer PID packages but they were always really inadequate. I wouldve loved a tool like this.

One of my biggest mistakes was tuning a loop during the winter shutdown on a large scale vaccine reactor. It dramatically increased the cells growth rate to a point where we would have had to modify our drug application. Understandably, the regulatory people had me de-tune the loop.

I can give you a laundry list right now. For example, millions of vials are cracking around the rim, several of the filling rooms have mold issues, one of the vial hoppers is leaving metal particulates in the vials, weekly OOS for manufacturing impurities..I think the public would freak out if they knew what was happening in the supply chain.

I'm a regulatory consultant for AI software and submit several AI/ML FDA submissions per week. Overall, I've submitted 100+ AI/ML submissions to date. Generally, FDA has been really focused on locked algorithms even though there has been some guidance lately stating the the new Good Machine Learning Practice (GMLP) will provide some allowance for iterations without submitting new 510ks. I will say that a number of companies are slightly tuning their algorithms without FDA resubmission within the confines of the FDA Guidance "https://www.fda.gov/regulatory-information/search-fda-guidan...". That said, most companies most companies are just leaving their specifications at sensitivity/specificity of 80% which gives them some leeway to improve above those limits. In truth most companies are above 97%-99%. While most of the submissions I work on are MRI/CT image related, I'm starting to get a lot more in the predictive space centered around ovarian (CA125), breast or PSA cancer scores. Lately pathology AI is escalating rapidly.

I received one of these packages from singapore yesterday. There is no website on the packaging or inside of the envelope. Therefore, I don't understand the amazon review thing. Its just a package of seeds in a manila envelope.

As an FDA law firm engineer, I review and submit about three AI devices a week to FDA (Ive probably done at least 50 AI submissions at this point) As part of that I review the all the submission docs including the design specification for each submission. Im convinced that none of the companies understand how any of the math works and they just submit models they have grabbed from Tensor or Pytorch

The most common model that we are putting in front of FDA several times per week for many companies is the AUROC model with minimum FDA requirements for specificity and sensitivity. I have some concern that the commentators on this article aren't actually aware of how many of these ML based software packages are actually being cleared by FDA at the moment through the DeNovo and 510k processes.