Unapproved Medical Software Highlights Regulatory Lag in Digital Health Oversight
A public call for regulatory reform underscores the growing gap between FDA review timelines and rapid software updates in diabetes management.
By The Global Wire Newsroom · Reported from Dana P Goldman
Link preview · horizonglobalnews.com
Unapproved Medical Software Highlights Regulatory Lag in Digital Health Oversight
A public call for regulatory reform underscores the growing gap between FDA review timelines and rapid software updates in diabetes management.

WASHINGTON — A growing debate surrounding the regulation of digital health technologies has re-emerged following commentary published by health economist and researcher Dana P. Goldman, who detailed personal experience using software not approved by the U.S. Food and Drug Administration to manage diabetes. Goldman argued that federal regulatory agencies face structural hurdles in evaluating medical software, contending that traditional safety review frameworks are fundamentally mismatched with the rapid pace of digital updates and algorithmic development. The statement underscores a broader challenge confronting public health authorities as patients increasingly adopt open-source and unregulated tools to manage chronic medical conditions.
The Challenge of Software Velocity
In commentary authored by Goldman, the central premise asserts that traditional regulatory mechanisms designed for physical medical hardware cannot adapt quickly enough to modern software development cycles. Specifically, Goldman noted that it is no longer possible to ask the Food and Drug Administration to keep pace with software development by attempting to conduct the same traditional reviews at a faster rate.
Unlike conventional medical hardware—such as physical insulin pumps, pacemakers, or diagnostic machinery—digital platforms and software algorithms undergo continuous modification. In software engineering, code updates, bug fixes, and feature additions occur in cycles measured in days or weeks, whereas standard federal medical device reviews frequently require months or years to complete. Under existing regulatory standards, when software is classified as a medical device, substantial code modifications can potentially trigger requirements for additional regulatory review or formal re-clearance.
This disparity has created a widening rift between formal regulatory timelines and the real-world deployment of digital health solutions. As code evolves rapidly, software tools designed to optimize chronic disease management can become outdated under rigid review regimes, leading some users to seek software solutions outside established regulatory pathways.
Patient Innovation and Unapproved Tools
The reliance on non-approved software is particularly pronounced within the diabetes management community, where patient-led initiatives have developed custom automated insulin delivery systems. These networks, built largely upon open-source code and community-driven development, connect continuous glucose monitors with external insulin pumps using independent algorithms.
Known broadly as automated insulin delivery or closed-loop systems, these setups automatically adjust background insulin delivery based on real-time blood glucose readings. While commercial versions of these automated systems have received regulatory clearance in recent years, open-source alternatives developed independently frequently offer higher levels of customization, broader compatibility across different hardware brands, and faster feature updates.
Patients who choose unapproved software often cite improved blood glucose control, fewer severe fluctuations, and a reduced daily operational burden associated with managing chronic illness. However, because these platforms operate without formal verification from public health authorities, individuals accept personal responsibility for potential system errors, software bugs, or hardware communication breakdowns.
Limits of Traditional Medical Device Review
The FDA classifies software intended for medical diagnosis, treatment, or management as Software as a Medical Device. Under federal statutes, medical software must satisfy safety and effectiveness standards proportional to the risk it poses to patients. Software that directly calculates or controls drug dosages—such as insulin administration algorithms—is categorized among the highest risk tiers because improper dosing can lead to severe health complications, including severe hypoglycemia or diabetic ketoacidosis.
Public health agencies maintain that rigorous, independent evaluation is necessary to protect patient safety, prevent unintended algorithmic errors, and maintain cybersecurity protections against unauthorized access. Regulators evaluate not only the core therapeutic logic of an algorithm but also user interface design, system error handling, and hardware interoperability.
However, critics of the current regulatory model contend that forcing dynamic software through static review pipelines creates unintended negative outcomes. When cleared software remains locked in static configurations to avoid regulatory delays, patients may be left relying on outdated interfaces or less responsive control algorithms. Consequently, a subset of patients chooses to bypass official regulatory channels entirely to access newer software features.
Proposals for Adaptive Regulatory Frameworks
The friction highlighted by Goldman reflects ongoing policy discussions regarding how software-based medical technologies should be evaluated in the future. Regulatory experts and public health scholars have increasingly examined alternative oversight models designed to accommodate continuous software development while maintaining baseline safety standards.
One proposed direction involves shifting focus from approving individual software builds to evaluating a developer's organizational processes and quality management infrastructure. Under pre-certification concepts, developers that demonstrate robust engineering standards, automated testing protocols, and real-world performance monitoring capabilities could receive streamlined authorization to issue iterative software updates without undergoing full re-evaluation for every minor revision.
Another regulatory framework emphasizes expanded post-market surveillance. Rather than relying almost exclusively on pre-market evaluation, oversight bodies could monitor real-world operational data collected from active software deployments. By analyzing performance metrics in real time, regulators and developers could identify potential safety anomalies or performance regressions as they occur, enabling targeted interventions without halting software improvements.
Broader Impact on Digital Health Integration
The debate surrounding diabetes management software serves as a key case study for the broader digital health industry. As artificial intelligence, machine learning, and personal health analytics become increasingly integrated into consumer devices, regulatory agencies worldwide face similar challenges across multiple clinical fields.
Digital health applications now assist in monitoring cardiac conditions, analyzing neurological activity, managing respiratory illnesses, and tracking medication schedules. Many of these digital applications rely on adaptive algorithms that process ongoing patient data, presenting novel questions for regulatory frameworks historically built around static medical equipment.
Balancing public health protection with technological innovation remains a complex policy challenge. While regulatory authorities seek to prevent safety failures, the continued adoption of independent software highlights a growing demand among patients for flexible, modern digital health tools.
This article reports on commentary originally published by Dana P. Goldman.
How this story was produced
This report was written by The Global Wire newsroom from reporting first published by Dana P Goldman. We verify the core facts against the original report, write our own account, and add the background and consequences a short wire item leaves out. Drafting is AI-assisted inside an editor-supervised pipeline, and every story is checked for accuracy of attribution, structure and duplication before it appears — full detail in our AI and funding disclosure.
Spotted an error? Tell us at corrections@horizonglobalnews.com and read our corrections policy or editorial standards.




Reader comments
Loading comments…