IDE Human Factors and Use-Related Risk Summary¶
| Field | Value |
|---|---|
| Status | Use-related risk summary; no summative human-factors validation report is included |
| Baseline | ide-software-freeze-2026-08-21 / 91c0e98a9bc9429a0486bebdebffc7d8dbbe300e |
| Date | 2026-09-08 |
| Clinical disposition | Available engineering UI, formative real-device, and clinical-review evidence is accurately described; no separate formal participant usability study is claimed |
1. Purpose and Evidence Boundary¶
The frozen investigational software baseline's use environment, safety-critical tasks, use-related hazards, controls, formative evidence, and residual use risks are identified below.
Engineering unit, UI, simulation, formative real-device, and operator testing are evidence of design evaluation. They are not formal summative human-factors validation. No completed summative human-factors validation report is available in this controlled package.
2. Intended Study Users¶
The final protocol, Optimizing Automated Insulin Delivery to Meet Pregnancy Glycemic Targets, Version 1.0, dated 1 September 2026, describes:
- nonpregnant female participants, ages 18 through 49, with type 1 or type 2 diabetes who meet study eligibility criteria
- trained clinical and study personnel who provision the phone, configure clinical settings, train participants, review status/evidence, and manage study escalation
The source protocol remains under study-team document control.
3. Use Environment¶
- supervised clinic setup and training
- outpatient and home use, including routine movement away from the phone or devices and periods of weak Bluetooth connectivity
- iPhone operation with Dexcom G7, Omnipod DASH, a study glucose meter, and access to study-team support
- relaunch, background/foreground transitions, device replacement, temporary network loss, and temporary CGM or pump communication loss
- investigational use with protocol training, monitoring, and escalation
4. Safety-Critical User Tasks¶
| Task | Potential use error | Primary controls |
|---|---|---|
| Confirm current glucose, Pod, and algorithm status | Misread stale or transient device state | Freshness rules, status hierarchy, disconnect display debounce, explicit alerts, VoiceOver labels |
| Announce a meal | Submit during suspension, forced-open mode, active delivery, or unresolved state; misunderstand whether insulin was delivered | Preflight gating, exact reason copy, in-modal progress, cancellation and reconciliation evidence, exactly-once attribution |
| Enter fingerstick BG | Enter wrong value, submit twice, use stale value, or assume entry was already consumed | Numeric range validation, separate exact-value review, step-scoped pending state, single consumption, pending/used chart distinction |
| Respond to CGM loss | Delay required BG entry or assume automated dosing continues unchanged | BG due countdown, escalating alerts, gold BG control emphasis, backup-basal bridge, IFU instructions |
| Replace or recover a G7 sensor | Attach to another person's G7 | Planned-replacement isolation, authenticated acquisition, staleness-never-adopts rule, acquisition guidance, and trained post-connection comparison; the accepted D06 disposition requires controlled testing of automatic replacement triggers and first-reading behavior before participant deployment |
| Replace or recover a Pod | Replace a transiently disconnected pod or misunderstand delivery reconciliation | Debounced display, pod identity checks, explicit recovery states, no silent session restart, retained evidence |
| Suspend and resume insulin | Forget to resume or announce a meal while suspended | Relocated control, reminder, Home paused status, direct Resume action, 15-minute escalation, meal rejection before execution |
| Start or end a Temporary Target | Use unintended target/duration or leave an incomplete draft | No preselection, review/confirm step, unsaved-change warning, visible end time, persisted expiry and automatic return |
| Change Clinical Settings | Unauthorized or accidental dosing-configuration change | First-save boundary, subject-scoped single-use offline unlock, expiration, review/save flow, study-staff operation |
| Recover study records | Share wrong participant/session files or expose raw local records | Clinical-gated export, exact-session ZIP isolation, protected staging, partial-content disclosure, no participant Files sharing |
5. Use-Related Hazards and Risk Controls¶
| Hazard theme | Related risk IDs | Control summary | Residual consideration |
|---|---|---|---|
| Incorrect insulin from wrong/stale input | RA-002, RA-003, RA-004, RA-012, RA-014 |
Input validation, freshness and pump-state gates, reference-host command construction, exact-step meal/BG policy | User timing and device availability remain variable |
| Insulin interruption not understood | RA-011, RA-015, RA-018 |
Alert severity/precedence, Home status, fingerstick-supported outage guidance, backup-basal behavior, suspend/resume recovery | Notification permission and user response affect timeliness |
| Delivery duplicated, omitted, or misattributed | RA-005, RA-016, RA-017, RA-020 |
Request-step identity, persisted issued-dose state, evidence precedence, bounded replay, exactly-once consumption | Assumed-delivered policy can conservatively over-account when evidence is irrecoverable |
| Wrong device adopted | RA-007, RA-023 |
Active-pod identity controls are separate. G7 replacement may begin manually or from defined device-lifecycle events; staleness alone does not start replacement. Authenticated discovery, physical isolation for planned replacement, and trained post-connection comparison reduce risk, but comparison does not gate the first accepted reading and automatic triggers may occur without planned isolation. | D06 and D07 accept the submission disposition and residual risk; no participant deployment may occur before controlled multi-device testing and final deployment disposition |
| Unsafe configuration or reset | RA-013, RA-019, RA-021, RA-022 |
Clinical unlock, save review, reset guardrails, explicit target/duration, range checks | Use depends on trained study-staff configuration and controlled access |
| Misleading display or missing evidence | RA-008, RA-010, RA-024 |
Source-tagged status, discrete chart samples, pending/used BG distinction, complete active-session step archive, recovery ZIP | Formal visual/operator evidence is incomplete |
| Study-data confidentiality or loss | RA-009, RA-024 |
Protected storage, backup exclusion, no Files sharing, retained sequence, clinical-gated export | Scout is supportive; official outcomes come from Dexcom Clarity and the BionicLoop CSV, and safety information is recorded in staff-entered electronic CRFs |
6. Training and Investigational-Use Mitigations¶
- one-on-one training by qualified study personnel before outpatient use
- participant teach-back and competency confirmation described by the protocol
- instruction on Dexcom G7, Omnipod DASH, meal announcement, fingerstick BG, alerts, device replacement, suspension/resumption, and escalation
- study-team follow-up and ready access to glucose meter, carbohydrate, glucagon, and replacement supplies
- investigational-use labeling and protocol restrictions
- IFU workflows and alert-response guidance
- study monitoring and contact pathways
Training records, trainer qualification records, completed competency records, and site-specific escalation procedures are sponsor/site records and are not included in this controlled package.
7. Available Formative, UI, and Operator Evidence¶
- app unit and UI tests for Home, meals, BG entry, Clinical Settings, Temporary Target, suspension/resumption, alerts, and recovery states
- simulation and pod-simulation scenarios for interruption, relaunch, reconciliation, and insulin conservation
- formative real-device observations used to identify and correct use and display problems before the freeze
- supporting study-staff observations of selected real-device workflows on the designated build
- an operator worksheet retained as a supporting workflow record, not as a separate formal hardware-validation claim
- IFU-BL-001 workflow narrative, screenshots, alert table, and study-staff reference
Operator-reported results remain supporting evidence until the exact build, device or subject, operator, UTC window, result, and signature are attached and accepted.
8. Evidence Not Claimed or Retained Outside This Package¶
- no separate formal participant usability or summative human-factors study is claimed; this evidence boundary was clinically approved on 2026-08-27
- documented critical-task validation protocol, acceptance criteria, and report
- signed retained physical/operator evidence for any hardware or visual claims kept in submission scope
- approved participant and staff training records and competency criteria
9. Residual Use Risks¶
- participants may delay responding to a BG request, device alarm, or insulin suspension reminder
- transient Bluetooth states can be difficult to distinguish from device loss, despite display debounce and status guidance
- a participant may misunderstand assumed-delivered or replayed insulin evidence without training
- notification permission or OS behavior may delay background notification even though in-app status remains available
- data recovery and device replacement require trained study-staff procedures
- participant consent and training wording must remain consistent with the distinct fingerstick mode described by the protocol and app
10. Required Disposition¶
The study team accepted the package description of engineering UI testing, formative real-device testing, and clinical review without claiming a separate formal participant usability study. IFU-BL-001 revision 1.17 is approved for IDE submission. Remaining software-package action is residual-use-risk acceptance.