5.4 FDA, FCC, HIPAA, & NRC: Federal Regulators Beyond CMS and Accreditors
Key Takeaways
- FDA regulates medical devices mainly through manufacturers, but hospitals as device user facilities must report device-related deaths and serious injuries under 21 CFR Part 803.
- FCC rules govern medical radio spectrum; Wireless Medical Telemetry Service (WMTS) devices use 608–614, 1395–1400, and 1427–1432 MHz and must be registered with the designated frequency coordinator, ASHE.
- The HIPAA Security Rule (45 CFR Part 164, Subpart C) requires administrative, physical, and technical safeguards for ePHI stored on or transmitted by medical devices.
- The HIPAA Breach Notification Rule requires notifying affected individuals without unreasonable delay and no later than 60 calendar days after a breach is discovered.
- The NRC or an Agreement State licenses radioactive materials used in nuclear medicine and radiation therapy, while X-ray equipment use is regulated mainly by state radiation control programs.
FDA, FCC, HIPAA, & NRC: Federal Regulators Beyond CMS and Accreditors
Item F of the CHTM Operations outline asks the manager to comply with "federal, state, and local regulatory requirements, accreditation requirements, and deemed status organizations (e.g., CMS, FDA, FCC, HIPAA, NRC)." Sections 5.2 and 5.3 covered CMS and the accrediting organizations. This section covers the other four and the state agencies that usually enforce radiation rules.
Exam tip: Many questions test which agency governs a situation. Match the hazard to the regulator: device safety and reporting → FDA; radio spectrum and interference → FCC; patient data privacy and security → HHS Office for Civil Rights (HIPAA); radioactive materials → NRC or an Agreement State; X-ray machines in use → state radiation control program; worker safety → OSHA (section 10.4).
1. FDA: The Device Regulator
The Food and Drug Administration (FDA), through its Center for Devices and Radiological Health (CDRH), regulates devices mostly by regulating manufacturers:
- Classification and premarket review: Class I, II, and III devices, with 510(k) clearance, De Novo classification, or premarket approval (PMA) depending on risk. A device's cleared labeling defines its intended use.
- Quality system and labeling: Manufacturers must follow FDA's quality management system regulation, which since February 2, 2026 incorporates ISO 13485 by reference. The instructions for use and service manuals are part of the labeling HTM relies on.
- Postmarket duties: Manufacturers report adverse events (21 CFR Part 803), report corrections and removals (Part 806), and run recalls (Part 7 and Part 810).
- Unique Device Identification (UDI): Device labels carry a UDI. Recording the UDI or model and lot data in the CMMS speeds recall searches.
What FDA requires of hospitals directly: As device user facilities, hospitals must report device-related deaths to FDA and the manufacturer, and serious injuries to the manufacturer (or to FDA if the manufacturer is unknown), within 10 work days, and file the annual Form 3419 (section 9.1). Hospitals must also cooperate with device tracking orders (21 CFR Part 821) for certain implants and life-sustaining devices used outside the facility.
Servicing versus remanufacturing: FDA's May 2024 guidance on remanufacturing distinguishes servicing — returning a device to its original safety and performance specifications — from remanufacturing, which significantly changes a device's performance, safety specifications, or intended use. A remanufacturer takes on manufacturer obligations. An HTM department that changes a device's design (for example, substituting a component that changes performance, or modifying software) may cross that line.
Using FDA data:
- MAUDE (Manufacturer and User Facility Device Experience) is FDA's public database of medical device reports. It helps HTM spot failure modes and use problems before buying or while troubleshooting. Limits: reports are unverified, underreported, and lack denominators, so MAUDE shows what can happen, not how often.
- The FDA recall database and safety communications show classified recalls and emerging hazards.
2. FCC: Medical Radio Spectrum
The Federal Communications Commission (FCC) controls radio spectrum use. Wireless medical devices must operate on spectrum and under rules the FCC allows:
| Service | Frequencies | HTM relevance |
|---|---|---|
| Wireless Medical Telemetry Service (WMTS) | 608–614 MHz, 1395–1400 MHz, 1427–1432 MHz | Protected spectrum for patient telemetry. Users must register devices with the FCC-designated frequency coordinator, the American Society for Health Care Engineering (ASHE), before operation and keep the registration current when adding or moving systems. |
| Medical Device Radiocommunication Service (MedRadio) | Core band 401–406 MHz (plus adjacent bands) | Implants and body-worn sensors, such as pacemaker programmers and remote monitoring |
| Medical Body Area Network (MBAN) | 2360–2400 MHz | Low-power body-worn sensor networks in health care facilities (with coordination for the 2360–2390 MHz portion) |
| Unlicensed (FCC Part 15) | Wi-Fi 2.4, 5, and 6 GHz bands; Bluetooth | No interference protection — devices must accept interference, so critical alarms on Wi-Fi need careful design |
Management actions: Keep an inventory of wireless devices and their frequencies; register WMTS systems with ASHE; coordinate with IT and facilities before adding transmitters; investigate dropouts for interference (for example, from digital TV transmitters near 608–614 MHz or crowded Wi-Fi channels); and consider radio frequency when buying or relocating telemetry.
3. HIPAA: Protecting ePHI on Medical Devices
The Health Insurance Portability and Accountability Act (HIPAA) rules are enforced by the HHS Office for Civil Rights (OCR). Many medical devices store or transmit electronic protected health information (ePHI) — monitors, imaging systems, infusion pump servers, and ECG management systems.
- Security Rule (45 CFR Part 164, Subpart C):
- Administrative safeguards: risk analysis and risk management that include medical devices; workforce training; security incident procedures; business associate agreements (BAAs) with vendors who access ePHI, including remote service; and a contingency plan with data backup, disaster recovery, and emergency-mode operation plans.
- Physical safeguards: facility access controls, workstation security, and device and media controls covering disposal and re-use (see NIST SP 800-88 Rev. 2 in section 2.3).
- Technical safeguards: access control and unique user IDs, audit controls, integrity controls, authentication, and transmission security. Encryption is an "addressable" specification — required where reasonable and appropriate, or documented alternatives.
- Breach Notification Rule: For unsecured ePHI, notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach. Breaches affecting more than 500 residents of a state also require notice to prominent media, and all breaches are reported to HHS (breaches of 500 or more individuals within 60 days; smaller ones within 60 days after the end of the calendar year).
- Privacy Rule: Limits uses and disclosures. HTM staff see PHI during repairs, so training and minimum-necessary practices apply.
A lost, unencrypted ultrasound hard drive or a monitor sold without sanitization is a likely reportable breach. That is why HTM builds sanitization into decommissioning and requires BAAs for depot repair of data-bearing devices.
4. NRC, Agreement States, and State Radiation Control
- The Nuclear Regulatory Commission (NRC) licenses radioactive materials — for example, nuclear medicine radiopharmaceuticals, sealed calibration sources, and brachytherapy or other radiation therapy sources — under rules such as 10 CFR Part 35 (medical use) and 10 CFR Part 20 (radiation protection standards, including the 5 rem, or 50 mSv, annual occupational dose limit).
- In Agreement States — most U.S. states — the state radiation program issues and enforces these licenses under rules compatible with the NRC's.
- X-ray machines (radiography, fluoroscopy, CT, mammography) do not use radioactive material. The NRC does not regulate them; state radiation control programs register them and set inspection and physicist-survey requirements. FDA sets manufacturer performance standards (21 CFR 1020), and mammography also falls under FDA's MQSA program.
- HTM roles: Coordinate service on licensed-material devices through the Radiation Safety Officer; keep source inventories and leak tests on schedule; make sure imaging service engineers wear dosimeters; and never dispose of or ship a sealed source without the RSO.
5. Building an HTM Regulatory Register
| Regulator / rule | What it governs | HTM evidence to keep |
|---|---|---|
| CMS §482.41(d)(2), §482.15 | Equipment maintenance; emergency preparedness | Inventory, maintenance records, AEM file, emergency power and equipment plans |
| Accrediting organization (TJC, DNV, others) | Deemed-status survey | Survey-ready CMMS reports; corrective action evidence |
| FDA | Device reporting, recalls, UDI, servicing vs. remanufacturing | MDR files (2 years), Form 3419, recall work orders |
| FCC | WMTS and other medical radios | WMTS registrations with ASHE; wireless device inventory |
| HHS OCR (HIPAA) | ePHI security and breaches | Device risk analysis, BAAs, sanitization certificates, contingency plans |
| NRC / Agreement State | Radioactive materials | License conditions met through the RSO; source inventories and leak tests |
| State radiation program | X-ray equipment registration and inspection | Registrations, physicist surveys, corrective actions |
| OSHA | Worker safety | Lockout/tagout, bloodborne pathogens, hazard communication programs |
Review the register at least annually and whenever a new service line or technology arrives.
A hospital adds 40 new patient-worn telemetry transmitters that operate in the 1.4 GHz Wireless Medical Telemetry Service (WMTS) band. What regulatory step must HTM complete before the system goes live?
During decommissioning, a technician discovers that an ultrasound system shipped last month to a used-equipment broker still had an unencrypted hard drive containing about 900 patient exams. Which regulatory framework drives the hospital's next steps, and what is the key deadline?
A nuclear medicine department asks HTM to dispose of an old gamma camera, including its Co-57 flood source used for daily uniformity checks. Who must control the disposition of the source?