Medical Device Software IEC 62304 Code Review Plan
Formulate a structured remediation and validation plan to resolve code review audit findings for regulated medical software.
Use this template when preparing medical device software for formal verification audits and IEC 62304 regulatory compliance. It maps technical remediation actions to software lifecycle safety milestones.
Role: Principal Medical Device Software Quality Engineer with deep expertise in IEC 62304, FDA 21 CFR Part 820, and safety-critical embedded architecture.
Context
- Medical Device Name: {{medical_device_name}}
- Regulatory Software Safety Class: {{regulatory_class}}
- Primary Programming Language & Framework: {{codebase_language}}
- Audit Findings Summary: {{audit_findings_summary}}
- Quality Management System Standard: {{quality_management_system}}
- Regulatory Submission Deadline: {{target_submission_deadline}}
Task
Produce a phased, audit-ready code review remediation plan that systematically resolves outstanding static analysis and peer review defects across the {{medical_device_name}} codebase while guaranteeing compliance with {{quality_management_system}} before {{target_submission_deadline}}.
Method
- Analyze the defect profile in {{audit_findings_summary}} against safety requirements dictated by {{regulatory_class}}.
- Segment the {{codebase_language}} codebase into risk-isolated architectural modules to isolate safety-critical routines.
- Establish coding standard rulesets (e.g., MISRA, CERT C/C++) tailored to address specific static analysis failures.
- Design a prioritized work breakdown schedule sorting remediation tasks by hazard severity and architectural dependency.
- Define standardized pull request approval requirements, code coverage gates, and verification criteria for every remediated unit.
- Formulate unit and integration re-test protocols to prove bug eradication without introducing behavioral regressions.
- Establish traceability linking each code remediation commit back to software risk mitigation IDs in the hazard analysis file.
Constraints
- MUST align all code review criteria with the designated {{regulatory_class}} risk profile.
- MUST NOT permit pull request merges without automated static analysis pass reports and dual-peer signoff.
- Every remediation task must identify explicit technical owners and verification artifacts.
- Keep all scheduling milestones anchored strictly before {{target_submission_deadline}}.
Output format
- Executive Summary & Defect Risk Matrix (150-200 words)
- Phased Remediation Work Breakdown (3 chronological phases with duration and tasks)
- Pull Request Review & Gatekeeping Protocol (5 mandatory acceptance criteria)
- Regulatory Traceability & QMS Signoff Table (5 columns: Defect ID, Unit, Safety Impact, Reviewer, Artifact)
Self-review
- Confirm all 6 variables are seamlessly integrated into the plan context and deliverables.
- Verify the method steps specifically address the defect types outlined in {{audit_findings_summary}}.
- Ensure remediation phases fit within the timeframe leading up to {{target_submission_deadline}}.
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.