MedTech Terms
    The authoritative reference
    All terms
    Market SegmentsStrategic Landscape

    Respiratory Devices

    Devices for managing breathing and airway conditions.

    Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed May 5, 2026

    Definition

    Respiratory devices include CPAP/BiPAP for sleep apnea (ResMed, Philips), home oxygen concentrators, ventilators, nebulizers, inhaler delivery devices, and emerging implantable phrenic-nerve stimulators for central sleep apnea.
    What the regulation says
    Respiratory devices are controlled medical devices subject to specific regulatory requirements. The FDA classifies many respiratory devices, such as continuous positive airway pressure (CPAP) devices and ventilators, as Class II or Class III devices, requiring premarket notification (510(k)) or premarket approval (PMA) respectively. EU MDR Annex XVI lists certain devices without an intended medical purpose, including some aesthetic respiratory masks, which still fall under its scope. Requirements for these devices include adherence to quality system regulations like 21 CFR Part 820 and ISO 13485, as well as risk management per ISO 14971.

    What this means in practice

    Philips Respironics recall (2021–2024) reshaped the CPAP market. Connected CPAP data (myAir, AirView) drives adherence and payer reauthorization.

    Examples

    • A manufacturer developing a new CPAP device must submit a 510(k) to the FDA, demonstrating substantial equivalence to a predicate device.
    • A company designing an internet-connected ventilator needs to implement robust cybersecurity controls and conduct penetration testing to meet regulatory expectations.
    • Following a reported issue with nebulizer malfunction, the manufacturer initiates a field safety corrective action, documenting the process according to ISO 13485 procedures.
    Common pitfalls
    • Failing to identify all applicable classifications and regulatory pathways for a respiratory device across different markets can lead to significant delays.
    • Underestimating the cybersecurity risks associated with connected respiratory devices, particularly those transmitting patient data, is a common pitfall.
    • Not adequately addressing usability and human factors engineering during the design and development of respiratory devices can result in patient harm or misuse.
    • Overlooking post-market surveillance requirements for respiratory devices, especially in light of widespread recalls, can lead to enforcement actions and reputational damage.
    • Incorrectly assuming that software components of a respiratory device do not require separate regulatory consideration is a mistake quality professionals make.

    Frequently asked questions

    Connected respiratory devices must protect sensitive patient health information (PHI) in transit and at rest. Manufacturers should address risks such as unauthorized access, data breaches, and denial-of-service attacks, aligning with FDA's cybersecurity guidance and IEC 81001-5-1 for health software and health IT systems safety, effectiveness and security.
    Grouped by theme

    Primary references

    3 sources
    Link health: 3 verified· last checked 2026-06-20
    ATS·1MedTech Europe·1MedTech Dive·1
    1. 1
      American Thoracic Society
      Verified
      ATSthoracic.org
    2. 2
      MedTech Europe - Facts & Figures
      Verified
      MedTech Europemedtecheurope.org
    3. 3
      MedTech Dive
      Verified
      MedTech Divemedtechdive.com

    Inline markers like [1] jump to the matching reference above.