Back
on
by

21 CFR 880.6310 Explained: The MDDS Regulation and What It Still Means After the Cures Act

21 CFR 880.6310 Explained
21 CFR 880.6310 is the federal regulation that classifies Medical Device Data Systems as Class I medical devices — but the 21st Century Cures Act of 2016 has substantially superseded its application to software. A practical walk-through of what the regulation says, what it does, and what it doesn't.

21 CFR 880.6310 is the federal regulation, codified at Title 21 of the Code of Federal Regulations Part 880.6310, that defines Medical Device Data Systems (MDDS) and classifies them as Class I medical devices subject to general controls. The regulation was created by the FDA’s February 15, 2011 final rule that down-classified MDDS from Class III to Class I, recognizing that pure data-handling software did not pose risks sufficient to justify Premarket Approval. The regulation remains on the books today, but the 21st Century Cures Act of 2016 amended the underlying definition of a “device” in the FD&C Act, with the practical effect that software meeting the MDDS criteria is no longer regulated as a device under federal law.

What 21 CFR 880.6310 Actually Says

The regulation is short but structured. It has two main subparts: an Identification subpart that defines Medical Device Data Systems and lists the four allowable functions, and a Classification subpart that establishes the Class I designation. Walking through each subpart clarifies exactly what 21 CFR 880.6310 governs, and what it doesn’t.

Subpart (a) Identification — What is a Medical Device Data System?

The Identification subpart defines a Medical Device Data System as hardware or software that is intended to provide one or more of the following uses, without controlling the functions or parameters of any other medical device: (1) electronic transfer of medical device data, (2) electronic storage of medical device data, (3) electronic conversion of medical device data from one format to another in accordance with a preset specification, or (4) electronic display of medical device data. The regulation explicitly states that an MDDS may include software, electronic or electrical hardware (such as physical communications media, modems, interfaces, and communications protocols), or any combination thereof.

Subpart (b) Classification — Class I (general controls)

The Classification subpart establishes the Class I designation under 21 U.S.C. 360c(a)(1)(A) and notes that the device is subject to the general controls of the FD&C Act, including registration of the establishment, listing of the device, labeling, prohibition of adulteration and misbranding, and Medical Device Reporting (MDR) for adverse events. Class I is the lowest-risk FDA device category. When 21 CFR 880.6310 was created in 2011, this Class I status was a substantial reduction from the pre-2011 Class III classification, which had required Premarket Approval,  the highest-burden submission pathway in the FDA framework.

The Four Allowable MDDS Functions Under 21 CFR 880.6310

The four allowable functions defined in 21 CFR 880.6310(a) are the boundary that determines what does and does not qualify as MDDS. The regulation’s language is terse; the practical interpretation requires unpacking each function.

Function 1 — Electronic transfer of medical device data

Moving medical device data from one location to another without modifying or analyzing it. Examples in practice include transmitting glucose readings from a CGM to a smartphone app, sending vital sign data from a connected monitor to a cloud server, or routing HL7 messages from a hospital information system to an integration engine. The transfer function does not include any analysis, interpretation, or modification of the data beyond what’s needed to deliver it intact.

Function 2 — Electronic storage of medical device data

Saving medical device data for later retrieval. Examples include archiving heart rate data in a cloud database, retaining historical glucose values for trend reporting, or maintaining a log of device telemetry events. The storage function is purely about persistence; the data sits in storage in the same form it was received.

Function 3 — Electronic conversion of medical device data from one format to another in accordance with a preset specification

Converting data formats based on a fixed specification, without applying analysis or judgment. Examples include transforming HL7 v2 messages into FHIR resources, restructuring proprietary device output into standardized CSV exports, or mapping device-specific units to clinician-facing units (mg/dL to mmol/L for glucose values). The key qualifier is ‘in accordance with a preset specification’; the conversion is deterministic. Software that converts based on analysis-driven logic falls outside the MDDS conversion function.

Function 4 — Electronic display of medical device data

Presenting medical device data to clinicians, patients, or other users. Examples include showing a CGM trend graph on a smartphone, displaying vital signs on a clinician dashboard, or rendering medical device telemetry in a patient portal. Pure display, without analysis-driven alerts, treatment recommendations, or clinical decision support, qualifies as MDDS. The line is whether the display presents information that exists in the underlying data or generates new clinical insights.

How 21 CFR 880.6310 Came to Be — and How It Was Substantially Superseded for Software

21 CFR 880.6310 was created by FDA in 2011 as part of a deliberate effort to right-size the regulatory burden on Medical Device Data Systems. Over the following decade, the regulatory environment continued to evolve: enforcement discretion in 2015, a structural change via federal statute in 2016, and formal implementation guidance in 2019. Understanding this evolution clarifies why the regulation still exists but has limited current application to software.

2011 — The final rule that created 21 CFR 880.6310

Before 2011, Medical Device Data Systems were classified as Class III devices,  the highest-risk category, requiring Premarket Approval (PMA) for market entry. On February 15, 2011, the FDA issued a final rule to down-classify MDDS from Class III to Class I and to codify the new MDDS classification at 21 CFR 880.6310. The rule recognized that pure data-handling software did not pose the patient risks that justified PMA review. The Class I classification subjected MDDS to general controls (registration, listing, labeling, MDR) but not to premarket review.

2015 — Enforcement discretion announced

On February 9, 2015, FDA issued final guidance titled “Medical Device Data Systems, Medical Image Storage Devices, and Medical Image Communications Devices.” The 2015 guidance announced enforcement discretion; FDA stated it does not intend to enforce compliance with the regulatory controls that apply to MDDS. In practice, this meant 21 CFR 880.6310 remained in effect, manufacturers were technically subject to Class I controls, but FDA would not enforce them. This was a regulatory policy decision, not a change to the underlying regulation.

2016 — The 21st Century Cures Act superseded the regulation for software

The structural change came with the 21st Century Cures Act, signed into law on December 13, 2016. Section 3060(a) of the Cures Act amended section 520 of the Federal Food, Drug, and Cosmetic Act to add subsection (o), which removed certain software functions from the statutory definition of a “device” in section 201(h) of the FD&C Act. One of the excluded categories was software intended for the transfer, storage, conversion in accordance with a preset specification, or display of medical device data. The practical effect: software meeting the MDDS criteria — the same criteria defined in 21 CFR 880.6310 — is no longer a “device” under federal law at all and therefore not subject to FDA device regulation, including the requirements imposed by 21 CFR 880.6310.

2019 — FDA’s formal implementation of the Cures Act change

On September 27, 2019, FDA issued final guidance titled “Changes to Existing Medical Software Policies Resulting from Section 3060 of the 21st Century Cures Act,” which formalized FDA’s interpretation of the Cures Act’s impact. FDA simultaneously issued conforming revisions to the 2015 MDDS guidance and three other software guidance documents to align them with the Cures Act’s statutory changes. The 2019 guidance also introduced terminology distinguishing between “Non-Device-MDDS” (software-only functions, no longer a device under federal law) and “Device-DDS” (hardware functions, still technically a device under 21 CFR 880.6310 but subject to FDA enforcement discretion).

Why 21 CFR 880.6310 Is Largely Historical for Software MDDS

21 CFR 880.6310 was never formally repealed. The regulation still exists in the Code of Federal Regulations. But it now applies to a narrower scope than it did before December 2016. The Cures Act amended the FD&C Act’s definition of “device” such that software meeting the MDDS criteria isn’t a device at all under federal law — and a regulation that classifies non-devices as Class I devices has nothing to classify. The regulation continues to apply to hardware components that perform MDDS functions (FDA’s “Device-DDS” category), but FDA exercises enforcement discretion even for those.

The practical effect for startups: most references to 21 CFR 880.6310 in regulatory guidance, consultancy materials, and older publications now reflect a pre-2016 view of the regulatory landscape. The regulation is still cited because it’s the codified definition of MDDS — but the device-regulation consequences it once carried for software MDDS have been superseded by section 520(o) of the FD&C Act. Reading 21 CFR 880.6310 today as if it still imposed the Class I requirements it did in 2011 overlooks the most important regulatory development of the past decade.

Where 21 CFR 880.6310 Still Applies — Device-DDS Hardware

21 CFR 880.6310 continues to apply to hardware components that perform the four MDDS functions. FDA refers to these as “Device-DDS” in the 2019 implementation guidance. Examples include gateway devices that physically receive, store, convert, or transmit medical device data; hospital data hubs that aggregate device output into clinical infrastructure; and physical communication media such as cables, modems, or wireless transmitters designed and marketed specifically for medical device data handling.

For Device-DDS hardware, the regulation’s Class I classification and general controls technically apply, but FDA exercises enforcement discretion with respect to the same regulatory controls covered in the 2015 guidance. The hardware manufacturer is technically required to register, list, comply with general controls, and maintain MDR processes, but FDA does not enforce these requirements against hardware that fits the MDDS function definition. The hardware exists in a regulatory gray zone: technically subject to regulation but not enforced in practice.

How 21 CFR 880.6310 Relates to Other FDA Software Regulations

21 CFR 880.6310 doesn’t exist in isolation. It connects to other FDA software regulations and statutes that together define the current regulatory landscape for medical device data handling. Understanding the connections clarifies what 21 CFR 880.6310 does and doesn’t determine.

Section 201(h) of the FD&C Act — the device definition

Section 201(h) of the Federal Food, Drug, and Cosmetic Act is the statutory definition of a “device,” the foundation that determines whether FDA’s device regulations apply at all. Before 2016, software meeting the MDDS criteria was a device under 201(h) and was therefore subject to 21 CFR 880.6310’s Class I designation. After the Cures Act’s amendment to section 520, software meeting the MDDS criteria is excluded from the 201(h) definition. The statutory exclusion supersedes the regulatory regulation.

Section 520(o) of the FD&C Act — the Cures Act exclusion

Section 520(o) of the FD&C Act, added by Section 3060(a) of the 21st Century Cures Act, defines five categories of software functions excluded from the device definition: administrative support of healthcare facilities, encouragement of healthy lifestyles, electronic patient records, transfer/storage/conversion/display of medical device data (the MDDS criteria), and limited clinical decision support. The MDDS exclusion in section 520(o)(1)(D) supersedes 21 CFR 880.6310 for software-only MDDS.

FDA guidance documents on MDDS (2015 and 2019)

The 2015 final guidance announced FDA’s enforcement discretion policy under the pre-Cures-Act regulatory framework; the September 2019 guidance interpreted the Cures Act’s impact and formalized the post-Cures-Act position. Both documents reflect FDA’s interpretation of how 21 CFR 880.6310 should be applied in practice: first, by not enforcing it; then, by recognizing that the underlying statutory definition no longer includes the software it once classified. Walking through the guidance documents is covered separately in the FDA MDDS Guidance guide.

Other 21 CFR Part 880 subparts — related medical devices

21 CFR Part 880 covers general hospital and personal use devices. Other subparts in Part 880 cover related medical device categories, including 21 CFR 880.6315 (Medical Image Storage Device) and 21 CFR 880.6320 (Medical Image Communications Device), both of which were addressed alongside MDDS in FDA’s 2015 enforcement discretion guidance. Understanding 21 CFR 880.6310 in the context of these related regulations clarifies the FDA’s broader position on data-handling hardware and software.

What 21 CFR 880.6310 Means for Startups Preparing for IDE Submission Today

For startup medical device companies preparing for an Investigational Device Exemption (IDE) submission, 21 CFR 880.6310 serves as a definitional reference; it defines what counts as an MDDS, but it doesn’t impose current regulatory requirements on software-only MDDS. The practical implication: the regulation’s four-function definition (transfer, storage, conversion, display) is the test used to determine whether your software is Non-Device-MDDS (no FDA device regulation), Device-DDS (technically regulated as Class I but subject to enforcement discretion), or SaMD (full FDA device regulation). Getting the definitional analysis right matters; the regulation’s specific Class I requirements no longer do for software.

Sequenex helps startup medical device companies make this definitional analysis deliberately, with awareness of how 21 CFR 880.6310 relates to the broader regulatory framework that has evolved around it since 2011. The work happens early in IDE-stage planning, typically before significant engineering investment, when the cost of changing course is lowest.

Frequently Asked Questions About 21 CFR 880.6310

What is 21 CFR 880.6310?

21 CFR 880.6310 is the federal regulation, codified at Title 21 of the Code of Federal Regulations Part 880.6310, that defines Medical Device Data Systems (MDDS) and classifies them as Class I medical devices subject to general controls. The regulation was created by FDA’s February 15, 2011 final rule down-classifying MDDS from Class III to Class I. It defines the four allowable MDDS functions: electronic transfer, storage, conversion, and display of medical device data.

Is 21 CFR 880.6310 still in effect?

The regulation itself is still in effect; it has never been formally repealed. But its applicability to software MDDS has been substantially superseded. Section 3060(a) of the 21st Century Cures Act of 2016 amended the FD&C Act’s definition of a device to exclude software meeting the MDDS criteria. So, while 21 CFR 880.6310 still exists, software that meets its criteria is no longer regulated as a device under federal law.

Does 21 CFR 880.6310 apply to software?

Not in practice, for most software. The 21st Century Cures Act of 2016 amended the FD&C Act to exclude software meeting the MDDS criteria from the statutory definition of a device. Since 21 CFR 880.6310 only regulates items that qualify as devices, software that meets the MDDS criteria isn’t subject to it in practice. Hardware components performing MDDS functions are still technically subject to 21 CFR 880.6310 as Class I devices, but FDA exercises enforcement discretion on these as well.

What is the difference between 21 CFR 880.6310 and the FDA MDDS guidance?

21 CFR 880.6310 is the codified regulation, the federal rule that defines MDDS and classifies it as Class I. The FDA MDDS guidance documents (issued in 2015 and updated in 2019/2022) are non-binding statements of FDA policy interpreting how the regulation should be applied. The 2015 guidance announced enforcement discretion; the 2019 guidance formalized the post-Cures-Act position. The regulation is the underlying rule; the guidance is FDA’s interpretation of how to apply it.

What products are subject to 21 CFR 880.6310?

Following the 21st Century Cures Act of 2016, software-only products that meet the MDDS criteria are not subject to 21 CFR 880.6310 in practice; they aren’t devices under federal law. Hardware products that perform MDDS functions (gateway devices, hospital data hubs, certain physical communications hardware) are still technically classified as Class I MDDS under 21 CFR 880.6310, though the FDA exercises enforcement discretion. The regulation continues to define what qualifies as MDDS even where it imposes no practical requirements.

How does 21 CFR 880.6310 relate to the 21st Century Cures Act?

Section 3060(a) of the 21st Century Cures Act of 2016 amended section 520 of the FD&C Act by adding subsection (o), which removed certain software functions — including those that meet the MDDS criteria- from the statutory definition of a device. This statutory change supersedes 21 CFR 880.6310 for software MDDS, since the regulation can only classify what the statute considers a device. The Cures Act didn’t repeal 21 CFR 880.6310, but it largely emptied the regulation’s scope as applied to software.

Get the Regulation Right — and the Path Forward Clear

21 CFR 880.6310 is still cited as if its pre-2016 Class I requirements apply, but for software MDDS, the Cures Act of 2016 has substantially changed what the regulation actually does. Sequenex helps startup medical device companies understand the current regulatory landscape, apply it correctly to their software architecture, and accurately scope IDE submissions based on what the FDA actually requires today.

This article describes 21 CFR 880.6310, the federal regulation defining Medical Device Data Systems, and its current applicability under the 21st Century Cures Act of 2016, for informational purposes only; it is not legal or regulatory advice. The regulation and its interpretation continue to evolve; current FDA positions should be verified against the most recent guidance documents at fda.gov and the regulation text at ecfr.gov. Companies preparing for FDA submission should consult qualified regulatory professionals before finalizing classification or submission strategy.

Want to schedule a demo of NEX?

Contact us
SaMD and Connected Devices Software Experts
© 2025 Sequenex. All rights reserved.