Regulatory guide · FDAUpdated October 8, 2026

FDA digital health technologies guidance: a guide for sponsors and QA

What FDA's final guidance on DHTs for remote data acquisition asks of sponsors and investigators, section by section, and what it means for the data system that receives the readings. General information, not legal advice.

  • Final guidance, December 2023
  • Data flow and source data
  • Not legal advice

Free sandbox · No credit card · 21 CFR Part 11 aligned

DHT data flow to plan and describe (demo study)
  1. DHT records the measurement

    Sensor, wearable or app

  2. Data and metadata transmitted

    Secured in transit, alerts on failure

  3. 3

    First durable electronic data repository

    FDA treats this copy as source data

  4. 4

    Investigator review per safety plan

    As specified in the protocol

  5. 5

    Retention and inspection

    Human-readable, with metadata

Simplified summary of the guidance. Your submission should describe your own data flow in detail.

Key points

  • Not legal advice. This page summarises FDA's guidance as published. Confirm how it applies to your program with your review division and regulatory adviser.
  • The guidance is Digital Health Technologies for Remote Data Acquisition in Clinical Investigations, issued as final in December 2023 (docket FDA-2021-D-1128) by CDER, CBER, CDRH and the Oncology Center of Excellence. It covers drugs, biologics and devices and is nonbinding.
  • A DHT is a system that uses computing platforms, connectivity, software and/or sensors for health care and related uses. Wearables, sensors and eCOA apps all qualify.
  • Sponsors should show the DHT is fit-for-purpose: verification (it measures the parameter accurately), validation (it captures the clinical event in your population) and usability.
  • FDA treats the first durable electronic data repository that receives DHT data as the source. If data and metadata reach it securely, FDA does not intend to inspect individual devices for source data.

The document

What the DHT guidance is, and what sits around it

FDA finalized the guidance on 22 December 2023, after a 2021 draft. It responds in part to section 3607 of the Food and Drug Omnibus Reform Act of 2022, which asked FDA to issue guidance on DHTs in clinical investigations. It applies to investigations of drugs, biological products and medical devices, and it is addressed to sponsors, investigators and other stakeholders, including IRBs.

Three other FDA documents are usually read with it. The Framework for the Use of Digital Health Technologies in Drug and Biological Product Development (March 2023) sets out how CDER and CBER organize their DHT work; it is a program framework, not guidance. Conducting Clinical Trials With Decentralized Elements (final, September 2024) covers remote visits and local providers. And Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers (final, October 2024) gives FDA's current Part 11 recommendations, including access controls and audit trails for data captured remotely. Our 21 CFR Part 11 compliance checklist covers that side in detail.

Whether a DHT is itself a device matters for the paperwork, not for the core expectations. The guidance explains when an investigational device exemption may be needed, for example for a significant risk DHT used in a drug trial, and when a cleared device used within its indications needs no IDE. Verification and validation are expected either way.

Section by section

What each part of the guidance asks for

Section IV of the guidance holds the practical recommendations. This table maps each part to what a sponsor typically writes down.

Guidance sectionWhat FDA recommendsWhat you document
A. Selection and rationaleMatch the DHT to the clinical event, the population and the trial design; set minimum technical and performance specificationsSelection rationale, model and version list, population considerations
B. Description in a submissionExplain why the DHT is fit-for-purpose and describe the data flow to the first durable repositoryDHT description, data flow diagram, access controls, data management plan
C. Verification, validation, usabilityObjective evidence that the DHT measures accurately and captures the event in your population; usability evaluationsV&V reports (yours or the manufacturer's), usability findings
D and E. Endpoints and statisticsJustify novel endpoints; plan the analysis and how missing data are minimized and handledEndpoint justification, statistical analysis plan
F. RisksClinical, cybersecurity and privacy risks, including end-user licence terms that share dataRisk assessment, consent language
G. Record protection and retentionTransfer data and metadata securely to a durable repository; keep it human-readableRetention plan, source data definition
H. Other considerationsSponsor and investigator roles, training, updates, loss and error procedures, closeoutTraining materials, risk management plan, safety monitoring plan, update log

Summary only. Read the full guidance on fda.gov for the exact recommendations and footnoted regulations.

Selection and validation

Showing that a DHT is fit-for-purpose

The guidance separates two ideas. Verification confirms that the device measures the physical parameter, such as acceleration or temperature, accurately and precisely. Validation confirms that it measures the clinical event or characteristic, such as step count or heart rate, in your population. FDA gives the example of a step algorithm built on healthy volunteers that may not hold for people with a shuffling gait. Evidence can come from the manufacturer, from device labeling or from a right of reference to another submission, but the sponsor has to judge whether it fits the trial.

Usability gets its own attention. Sponsors should look for use errors before the trial starts, and feed what they learn into training. Selection should also consider who will use the device: age, language, education, health and technical skill all affect whether participants can use it as the protocol intends.

Participant-owned devices and phones

Sponsors may let participants use their own DHT or their own smartphone, which can reduce burden. The guidance asks sponsors to weigh this, notes it may not suit highly specialized devices, and says sponsor-provided devices and connectivity should be available so that people without their own are not excluded. The BYOD ePRO guide covers the questionnaire side of this choice.

What it means for your data system

The durable repository is where inspectors will look

Section G is the part that lands on the data system. Data captured by the DHT, with relevant metadata such as when each measurement was made, should be securely transferred to and kept in a durable electronic data repository as part of the trial record. For data collected directly from participants, FDA considers the data in the first durable repository they reach to be the source data, and that copy should be available for inspection. FDA generally does not intend to ask for raw machine data such as voltages that need processing to be understood, but the data must be retained and human-readable.

That has practical consequences. Your submission should name the repository and draw the flow from device to repository. You need to know whether the first durable copy sits with the device maker, a middleware vendor or your EDC, because that is where retention, access control and audit trail expectations apply. The investigator must also be able to review source data where the protocol says so, and FDA generally does not expect continuous monitoring; the safety monitoring plan should say how often continuous data are reviewed and how abnormal readings are handled.

Section H then lists what the sponsor should plan: training for staff and participants before use, technical support, a risk management plan covering misuse, loss, malfunction and updates, confirmation that data actually reached the repository, and closeout steps such as ending transmission and revoking access. For the wider integrity picture, the ALCOA+ data integrity checklist is a useful companion.

DHT documentation pack (demo study)

Devices in scope

1

Open items

2

  • Selection rationale and minimum specificationsModel and version listed
  • Verification and validation evidenceManufacturer report reviewed
  • Usability evaluation and training materials
  • Data flow to first durable repositoryDiagram in draft
  • Consent language on third-party data accessCheck device terms of service
  • Update and version log process
Illustrative only. Your list follows from your protocol and your submission.

Map your DHT data flow in a working study

Build the visits, ePRO and device settings in the free sandbox, test the audit trail and exports, and pay only when you go live.

Start free in the sandbox

Risks, consent and change

Points sponsors most often miss

Taken from sections F and H of the guidance.

Terms of service that share data

Some devices and phone platforms have licence terms that let the maker access data. Consider negotiating study terms, and tell participants who may access their data and for how long.

Consent content specific to the DHT

Explain what the device collects, how it is used and monitored, what to do about a concerning reading, privacy limits and any added costs such as data charges.

Software and operating system updates

Keep a record of the timing and nature of updates per device. If an update could change measurements, check before and after data and plan sensitivity analyses before unblinding.

Loss, damage and malfunction

Have replacement procedures and, where possible, an alternative way to record data while a device is out of use.

Cybersecurity

Protect data at rest and in transit, and consider FDA's cybersecurity information where a compromised reading could harm a participant.

Closeout

Define when transmission ends and when system access is revoked at the end of the study.

Where Capture fits

What a study platform can and cannot do for you here

Most of the guidance is sponsor work: choosing and validating the device, justifying endpoints and writing the plans. A study platform helps with the record those plans depend on. In Capture, a study team enables a wearable per study and can mark it required; the participant connects their own account through the vendor's sign-in (for example Oura), and data then sync automatically, with a last-sync time, a Sync now option and a disconnect control. Device data sit in the same study as site eCRFs, ePRO and eConsent.

Every change to study data is written to a field-level audit trail with the user, timestamp, old value, new value and reason, and the trail is append-only and hash-chained. Access is role-based, with participant names visible to site staff and coded IDs for researchers. Data are hosted in the EU (Frankfurt) or the US (N. Virginia), encrypted with AES-256 at rest and TLS in transit, and export to CSV or Excel with a data dictionary, or to CDISC SDTM datasets with Define-XML. These are 21 CFR Part 11 aligned controls; your validation, procedures and DHT evidence complete the picture. Whether Capture is the first durable repository for your device depends on your data flow, so draw it and confirm it with your team. See remote patient monitoring and the decentralized clinical trial guide for adjacent topics.

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

Is the FDA DHT guidance final?

Yes. Digital Health Technologies for Remote Data Acquisition in Clinical Investigations was issued as final guidance in December 2023, replacing the 2021 draft. Like all FDA guidance it is nonbinding, and alternative approaches can be used if they satisfy the regulations.

What counts as a digital health technology?

FDA defines a DHT as a system that uses computing platforms, connectivity, software and/or sensors for health care and related uses. Wearable sensors, connected devices and eCOA apps on phones or tablets are typical examples.

What is the durable electronic data repository?

It is the system where DHT data and metadata are securely stored as part of the trial record. FDA considers the data in the first durable repository that receives them to be source data, and does not intend to inspect individual devices if data reach the repository as the sponsor planned.

Does a DHT need an IDE?

It depends. A cleared or approved device used within its indications generally does not, and nonsignificant risk use can follow abbreviated requirements. A significant risk DHT may need an IDE. Discuss your case with the relevant FDA center.

Can participants use their own smartphone or wearable?

The guidance allows it after weighing pros and cons, but sponsor-provided devices and connectivity should be offered so that people without their own are not excluded.

What happens if a device gets a software update mid-trial?

Sponsors should log updates for each DHT, check that the device remains fit-for-purpose, compare data before and after if measurements may have changed, and describe how differences will be handled in the analysis before unblinding.

Does Capture validate my DHT?

No. Device verification and validation is the sponsor's responsibility, often using manufacturer evidence. Capture provides the study record: synced device data, audit trail, access controls and exports.

Put device, site and patient data in one audited study

Build and test the whole study in the free sandbox with every feature. No credit card; pay only when you go live.

Start free in the sandbox