MedTech IP Primer
This primer recommends managing patent, FDA, trade-secret, and commercialization decisions through one coordinated governance process. Before any material external disclosure, leadership should confirm the regulatory pathway, identify patentable technical improvements, classify information for patenting or secrecy, reconcile factual positions across submissions, and assign accountable owners and decision dates. The principal business risks are loss of patent rights through premature disclosure, unsupported or ineligible AI claims, inconsistent patent and FDA positions, and erosion of trade-secret protection. The intended outcome is a defensible U.S. market-entry strategy that protects commercially important features without unnecessary disclosure.
A medical device company entering the United States usually encounters patent law and FDA law as two separate work streams. That separation is understandable, but it is often inefficient. The engineering team talks to patent counsel about claims and prior art. The regulatory team talks to FDA counsel or a regulatory consultant about classification, predicates, testing, labeling, quality systems, and the marketing submission. The business team tries to turn both streams into a product launch. The better approach is to recognize that these activities describe the same product from different legal perspectives. They should be coordinated from the beginning. Patent law asks what the company invented, what is new, what is nonobvious, what must be disclosed to support the claims, and what competitive territory the company should be able to exclude others from occupying. FDA law asks what the product is, what it is intended to do, how it performs, what risks it creates, how those risks are controlled, how changes will be managed, and what evidence supports safe and effective use. Those questions are not identical, but the underlying technical facts overlap substantially. A disciplined development program can therefore produce evidence that helps both processes. This is especially true for AI-enabled medical devices. An AI system may involve sensors, signal processing, data preprocessing, model architecture, training methods, feature extraction, model updating, thresholding, confidence measures, user interfaces, cloud infrastructure, cybersecurity controls, and post-market monitoring. Some of those features may be appropriate for patent protection. Others may be more valuable as trade secrets. Still others must be described to the FDA in enough detail to permit regulatory review. The company should decide deliberately which bucket each element belongs in instead of allowing the answer to emerge accidentally from what gets disclosed first. The timing also matters. Patent rights in the United States are built around a first-inventor-to-file system. Public disclosure can create prior-art problems in the United States and can immediately destroy rights in many foreign countries. FDA submissions, clinical studies, investor materials, conference presentations, product demonstrations, websites, instructions for use, scientific papers, customer pilots, and even regulatory strategy discussions can therefore affect the patent plan. Conversely, a good patent-development process can force the team to
identify technical distinctions, alternatives, failure modes, and design choices that make the FDA submission more precise and easier to defend. For foreign medical device developers, this coordination is even more important. A company may already have CE-marking materials, ISO 13485 documentation, technical files, risk-management records, software documentation, clinical data, and patents or applications filed outside the United States. Those materials are valuable starting points, but they should not simply be copied into a U.S. patent application or FDA submission. U.S. patent law and FDA law ask different legal questions, and the vocabulary used in one system can create unintended consequences in the other. The goal is consistency without needless disclosure.
A U.S. utility patent can protect a new and useful process, machine, manufacture, composition of matter, or improvement that satisfies the statutory requirements. For medical devices, patents frequently cover the physical device, a subsystem, a disposable component, a method of use, a manufacturing method, a signal-processing technique, software architecture, data handling, calibration, an AI training or inference technique, a user-interface interaction, or a combination of these. One commercial product may support several different patentable inventions. The claims define the legal boundary of a utility patent. The written description and drawings must support those claims, but the claims are the part that is ordinarily compared with an accused product or process. For that reason, a patent application should not be treated as a technical brochure. It is a legal instrument that needs enough technical disclosure to support meaningful claims while preserving room for foreseeable variations and design-arounds. Medical device developers should understand four statutory provisions in particular: 35 U.S.C. §§101, 102, 103, and 112. Section 101 addresses whether the claimed subject matter is the kind of thing the patent system will protect. Section 102 addresses novelty. Section 103 addresses obviousness. Section 112 addresses disclosure and claim clarity, including written description and enablement. A strong application is drafted with all four in mind at the same time. The normal U.S. utility-patent term is measured from the relevant filing date under 35 U.S.C. §154, subject to statutory adjustments and terminal disclaimers. Certain medical-device patents associated with lengthy regulatory review may also qualify for patent-term extension
under 35 U.S.C. §156. The extension provisions are technical and product-specific, but they are worth identifying early for PMA-type products because they can restore a portion of patent term consumed by qualifying regulatory review. The USPTO expressly recognizes certain medical devices as products that may be eligible for §156 patent-term extension. Patent applications are ordinarily published about eighteen months from the earliest claimed filing date. 35 U.S.C. §122(b). A U.S.-only applicant can sometimes request nonpublication, but that option is generally incompatible with pursuing foreign applications that require publication. Design applications are not published under the same eighteen-month publication rule. These timing rules have a direct trade-secret consequence: material disclosed in a published utility application ordinarily can no longer be treated as secret after publication. For most device companies, the important practical point is that a patent application does not need to claim every valuable detail. It should disclose and claim enough to protect the inventions for which patent exclusivity is worth the cost and public disclosure. Other details can remain outside the patent when trade-secret treatment is lawful, practical, and consistent with FDA obligations. That allocation should be intentional.
Section 101 has become a central issue for software and AI patent claims. The statute itself is broad, but Supreme Court decisions recognize judicial exceptions for laws of nature, natural phenomena, and abstract ideas. Under Alice Corp. v. CLS Bank International, 573 U.S. 208 (2014)(“Alice”), courts generally ask first whether a claim is directed to one of those excluded concepts and, if so, whether the claim contains an inventive concept sufficient to transform the claim into patent-eligible subject matter. The doctrine is easy to state and difficult to apply consistently. For medical devices, the safest drafting strategy is usually to describe a concrete technological problem and a concrete technological solution. Saying that an AI model analyzes patient data and produces a recommendation is often not enough. The application should explain what technical limitations existed, what architecture or processing techniques changed, how the claimed system operates differently, and what measurable or technically meaningful result follows. Examples may include reduced memory use, lower latency, improved sensor-noise handling, a new model architecture, a constrained training process, improved robustness, a
particular data structure, a hardware-software interaction, or a new way of managing model updates in a safety-critical environment. The Federal Circuit's 2025 decision in Recentive Analytics, Inc. v. Fox Corp., 134 F.4th 1205 (Fed. Cir. 2025)(“Recentive”), is an important warning. The court held that claims that did no more than apply established machine-learning techniques to new data environments, without disclosing an improvement to the machine-learning models being used, were patent ineligible under §101. The court emphasized that machine learning itself can support patent-eligible technological improvements, but generic application of machine learning to a new field is not enough. Rehearing was denied, and the Supreme Court denied certiorari on December 8, 2025. Recentive therefore remains binding Federal Circuit precedent. The USPTO's precedential Ex parte Desjardins, Appeal No. 2024-000567 (Appeals Review Panel Sept. 26, 2025)(“DesJardins”), shows the other side of the line. The Appeals Review Panel vacated a §101 rejection of claims directed to training machine-learning models where the record described improvements in the operation of the AI technology, including reduced storage requirements and reduced system complexity. The USPTO designated Desjardins precedential in November 2025 and incorporated its reasoning into examination guidance. The practical lesson is not that AI claims are suddenly easy. It is that claims and specifications should identify the technological improvement rather than merely announcing that AI is being used. There is also an institutional nuance. Recentive is binding appellate law. Desjardins is precedential within the USPTO and useful during examination, but it does not overrule the Federal Circuit. A patent that issues under an applicant-friendly examination framework still must survive later judicial review. The best drafting strategy therefore satisfies both audiences: it should show an actual technical improvement under the USPTO's practical-application framework and also avoid claims that can fairly be characterized under Recentive as generic machine learning applied to a new dataset or business environment. FDA development can help here. AI-enabled device submissions often require a careful description of inputs, outputs, model architecture, training and test data, performance characteristics, limitations, risk controls, human factors, monitoring, and change management. Those records can reveal the real technical contribution that should be captured in the patent application. The patent team should review that material early enough to file before public disclosure and before the technical story has been compressed into marketing language.
Trade-secret strategy also matters to §101. A company sometimes wants very broad patent claims while keeping the actual technical mechanism secret. That can be dangerous. If the claimed advance depends on a technical feature that is never adequately disclosed, the claim may look abstract under §101 and may also fail under §112. The company cannot always have a broad patent on the result while keeping every mechanism that produces the result undisclosed. The better approach is to identify which technical mechanisms must be disclosed to support defensible patent claims and which implementation details can remain secret without undermining the patent.
Section 102 asks whether the claimed invention is new in view of the prior art. Under the America Invents Act, prior art can include patents, published patent applications, printed publications, public use, sale, and other public availability before the effective filing date, subject to statutory exceptions. The United States has a limited one-year grace period for certain inventor-originated disclosures, but relying on that grace period is usually poor practice for an international medical-device company because many foreign jurisdictions are less forgiving. The practical rule is simple: file before public disclosure whenever possible. Regulatory activity can create disclosure risk even when the core submission to FDA is confidential. A company may publicize that it has submitted a 510(k), describe performance data at a conference, publish a clinical paper, recruit study sites with technical detail, demonstrate a prototype, place information on a distributor website, or circulate technical materials to investors and commercial partners. Any of those events can matter under §102. The patent team should therefore be part of the pre-publication review process, not merely called after the FDA submission has been assembled. Section 103 addresses obviousness. Even if no single prior-art reference discloses every limitation, a claim can be unpatentable if the differences from the prior art would have been obvious to a person having ordinary skill in the art. The familiar framework comes from Graham v. John Deere Co., 383 U.S. 1 (1966)(“Graham), and KSR International Co. v. Teleflex Inc.(“KSR”), 550 U.S. 398 (2007). Medical devices frequently combine known components, which makes the technical rationale and evidence of non-obviousness particularly important. FDA records can create useful evidence for §103. Design-control documentation, bench testing, clinical results, risk analyses, usability work, and engineering investigations may show that an
apparently simple change solved a problem others had not solved, produced an unexpected result, overcame a technical prejudice, or required more than routine optimization. Those facts may support patentability. They should be identified while memories are fresh and before the patent application is filed or prosecuted. The reverse is also true. Patent prior-art work can improve regulatory planning. A thorough search may reveal earlier device architectures, indications, data-processing approaches, or design alternatives that help the regulatory team understand the competitive and technical landscape. That information may be useful when evaluating potential 510(k) predicates or when deciding whether a device is sufficiently novel that a De Novo pathway is more realistic. Patentability and substantial equivalence are different legal tests, however. A patent reference is not automatically an FDA predicate, and an FDA predicate is not automatically the closest patent prior art. Consistency matters. In Bruno Independent Living Aids, Inc. v. Acorn Mobility Services, Ltd., 394 F.3d 1348 (Fed. Cir. 2005), the Federal Circuit affirmed an exceptional case determination based in part on prior art that had been disclosed to the FDA but not to the USPTO during concurrent patent prosecution. The case is an enduring reminder that the regulatory and patent teams cannot operate as sealed compartments. Material prior art known to one side may need to be evaluated for disclosure to the USPTO under the duty of candor. The practical solution is a cross-functional prior-art protocol. Regulatory personnel should know how to route potentially material references to patent counsel. Patent counsel should understand which FDA submissions and predicate analyses exist. The company should not assume that a reference becomes unimportant merely because it was found for a regulatory purpose rather than a patent search.
Section 112 is where patent strategy often collides most directly with trade-secret strategy. The specification must provide adequate written description and enablement for the claimed invention, and the claims must be sufficiently definite. A company cannot claim an entire technological territory while disclosing only a black box and keeping every enabling detail secret.
For an AI-enabled medical device, a useful specification should describe more than the statement that a machine-learning model processes data. Depending on the invention, relevant disclosure may include the nature of the input data, preprocessing, feature extraction, model type or architecture, training process, objective functions, validation approach, confidence or threshold rules, deployment architecture, interactions with sensors or other device components, update mechanisms, fallback modes, and representative alternatives. The level of detail should match the breadth of the claims being sought. That does not mean source code, model weights, full training datasets, proprietary manufacturing tolerances, vendor-specific parameters, or every optimization must be placed in the patent. The question is whether a person skilled in the art can make and use what is claimed without undue experimentation and whether the specification shows that the inventors possessed the claimed subject matter. If the company wants claims broad enough to cover multiple model types or sensing modalities, the disclosure should provide a reasoned technical foundation for that breadth. FDA documentation can be extremely helpful. Risk-management files, software architecture documents, verification and validation plans, clinical protocols, design inputs and outputs, cybersecurity documentation, and AI lifecycle materials frequently contain the technical facts needed for a robust patent disclosure. The patent attorney does not need to copy them wholesale. The value is that those documents force the engineering team to articulate how the system actually works and what can fail. The company should also consider future product generations. A patent application filed on version 1.0 cannot later be amended to add entirely new technical matter that was not originally disclosed. Continuation practice can pursue different claim scope from the same disclosure, but it cannot cure missing disclosure. For AI systems that are expected to evolve, the initial application should describe foreseeable model changes, alternative architectures, data sources, deployment modes, and update mechanisms when those alternatives are genuinely contemplated by the inventors. This is another reason not to overprotect by secrecy. A hidden technical fact may be a valuable trade secret, but if that fact is the only thing that makes a broad patent claim work, secrecy can undermine the patent. The decision should be made invention by invention, not by a blanket rule that all implementation detail stays secret.
Design patents protect the ornamental appearance of an article of manufacture rather than its utilitarian function. For medical devices, that can include the overall shape of a hand-held device, a wearable housing, a display arrangement, a cartridge, a connector, a disposable component, a graphical user interface, or a portion of a product. A design patent can be commercially valuable when appearance matters, when competitors can copy the look without copying the internal mechanism, or when the shape of the device contributes strongly to product recognition. A U.S. design patent generally has a fifteen-year term from grant for applications filed on or after May 13, 2015. 35 U.S.C. §173. The drawings are critical because the design shown in the drawings defines the claimed subject matter. Solid and broken lines, shading, perspective views, and the treatment of unclaimed portions can materially affect scope. Design applications should therefore be coordinated with industrial design and patent counsel before public release of the product design. The Federal Circuit's en banc decision in LKQ Corp. v. GM Global Technology Operations LLC, 102 F.4th 1280 (Fed. Cir. 2024)(“LKQ”), changed the obviousness analysis for design patents. The court overruled the rigid Rosen-Durling framework and held that design-patent obviousness should be evaluated under the more flexible statutory approach associated with Graham and KSR. The decision did not turn design patents into utility patents; the relevant inquiry remains focused on visual appearance and the perspective of an ordinary designer in the field. But the prior-art analysis is now less constrained by the old requirement for a nearly identical primary reference before combinations could be considered. For medical-device developers, LKQ makes portfolio quality even more important. A company should not file a large number of narrowly varied design applications merely because each drawing set is slightly different. It should identify the visual features that matter commercially, evaluate the prior-art design space, and use continuation or related filing strategies thoughtfully. A strong design portfolio can complement utility patents, particularly where the mechanical or software function is difficult to patent broadly but the product's recognizable appearance has market value. Design patents also fit naturally with trade-dress planning, but the doctrines are not interchangeable. A design patent can protect a qualifying ornamental design without proof that
consumers recognize it as identifying source. Product-design trade dress generally requires acquired distinctiveness or secondary meaning and cannot protect functional features. A company can therefore use design patents for early exclusivity while building the market recognition that may later support trade-dress rights. FDA review does not generally determine whether a medical-device design is ornamental or patentable, but regulatory requirements can influence appearance. Human-factors considerations, cleaning requirements, sterility, labeling, connector safety, and risk controls may constrain design choices. Those constraints should be documented because a feature driven entirely by function may be harder to protect through trade dress, while ornamental alternatives may remain good candidates for design patents.
The FDA regulates medical devices under the Federal Food, Drug, and Cosmetic Act and implementing regulations. The first question is whether the product or software function is a device at all. For software, that analysis has become increasingly important because certain clinical decision support functions may fall outside the statutory device definition under section 520(o) of the FD&C Act, while other software functions remain regulated devices. The FDA's January 2026 final Clinical Decision Support Software guidance is an important current reference for that analysis. If the product is a device, classification largely determines the premarket pathway. Class I devices are generally subject to general controls and may be exempt from premarket notification. Class II devices are generally subject to general and special controls and often require a 510(k), unless exempt. Class III devices ordinarily require Premarket Approval, or PMA, unless a particular pre-amendment pathway applies. The FDA describes PMA as its most stringent device marketing application and requires valid scientific evidence supporting reasonable assurance of safety and effectiveness. A 510(k) is a premarket notification used to demonstrate that a device is substantially equivalent to a legally marketed predicate device. Substantial equivalence is a regulatory concept, not a patent-law conclusion. The submitter must receive FDA clearance before commercial distribution where a 510(k) is required. For a new type of low- or moderate-risk device without an appropriate predicate, the De Novo process can provide risk-based
classification into Class I or Class II and can create a new device type that later devices may use as a predicate where appropriate. Premarket authorization is only part of the system. Medical device companies also must consider establishment registration, device listing, labeling, medical device reporting, corrections and removals, unique device identification where applicable, and manufacturing-quality requirements. Foreign establishments importing devices into the United States must satisfy applicable U.S. requirements and designate a U.S. agent. FDA states that foreign manufacturers are also subject to inspection and applicable post-market obligations. The quality-system landscape changed on February 2, 2026. The FDA's Quality Management System Regulation, or QMSR, is now effective and incorporates by reference ISO 13485:2016, while retaining FDA-specific statutory and regulatory requirements. This is particularly relevant for foreign manufacturers already operating under ISO 13485 because the systems are now more closely harmonized, but harmonization is not the same as identity. A company should still map its existing quality system to U.S. requirements and FDA inspection expectations. For AI-enabled devices, the regulatory file should be built around the total product lifecycle rather than a one-time frozen algorithm. The FDA's current digital-health materials address lifecycle management, model performance, transparency, bias, cybersecurity, and change management. The agency's final guidance on Predetermined Change Control Plans for AI-enabled device software functions, issued in final form in August 2025, allows manufacturers in appropriate circumstances to describe planned modifications, the methodology for developing and validating those modifications, and an impact assessment in advance. That can permit certain future changes to be implemented within an authorized framework rather than automatically requiring a new marketing submission for every anticipated modification. Cybersecurity has also become a statutory and submission-level issue. The FDA's current cybersecurity guidance addresses device design, labeling, quality management, and premarket documentation, including the requirements applicable to 'cyber devices' under section 524B of the FD&C Act. For connected and AI-enabled devices, cybersecurity cannot be treated as an afterthought because the security architecture may affect both regulatory acceptability and patentable technical features.
A well-run FDA program creates technical discipline. That discipline can improve patent quality if the patent team gets access to it early enough. The most useful contribution is not the FDA form itself. It is the structured engineering record behind the filing. First, FDA development can clarify what the invention actually is. Device teams often begin with a broad product concept and discover during verification, validation, human-factors work, cybersecurity testing, or clinical development that a narrower technical feature is what makes the product successful. That feature may be the real patentable invention. A patent filed too early with only marketing-level language can miss it. The solution is not necessarily to delay filing; it is to use staged filings and continuation strategy, so that later-developed inventions are captured before disclosure. Second, regulatory testing can generate evidence relevant to non-obviousness. Unexpected performance, reduced false positives, improved signal-to-noise ratio, better usability, reduced power consumption, safer failover behavior, improved robustness across patient populations, or a successful solution to a recognized technical problem may support §103 arguments. Patent counsel should know the evidence exists and should preserve the ability to use it when legally appropriate. Third, FDA documentation can support §112. Architecture diagrams, design specifications, software documents, risk analyses, and test protocols can help patent counsel understand enough alternative embodiments to draft a stronger application. This is particularly valuable for foreign developers whose first patent filing may have been drafted under a different disclosure culture and may not have been optimized for U.S. written-description and enablement practice. Fourth, FDA's AI lifecycle framework can expose patentable change-management inventions. A predetermined change control plan may identify model modifications, retraining methods, validation gates, drift detection, monitoring systems, and rollback or safety mechanisms. Some of these may be routine regulatory controls. Others may embody a novel technical architecture. The teams should ask the patent question before the details become public or are disclosed in materials that will later be released. Fifth, the FDA process can improve inventorship analysis. Design reviews and development records often show who conceived a particular technical feature and when. U.S. patent
inventorship turns on conception of claimed subject matter, not title, job position, or who managed the project. Regulatory and quality records can therefore be valuable factual evidence, although they should be created for legitimate development purposes rather than manufactured after the fact for patent litigation. The coordination must be controlled. FDA submissions can contain information that is protected from public disclosure, but regulatory confidentiality is not a substitute for a patent filing strategy. Once the FDA issues certain decisions, summaries and other information may become publicly available subject to protections for trade secrets and confidential commercial information. The patent team should identify patent-sensitive material before any public regulatory disclosure occurs.
Patent work can also make the regulatory process better. A good patent interview forces the development team to explain the product in functional, structural, and comparative terms. That exercise often reveals ambiguities that would later appear in an FDA submission. A patentability search can help map technical alternatives. It may identify prior devices, software architectures, sensing approaches, connectors, disposables, or data-processing methods that the regulatory team had not considered. The regulatory significance must be evaluated independently, but the search can prevent the company from developing its FDA strategy inside an artificially narrow view of the technology. Patent drafting also encourages deliberate definition of terminology. Words such as 'diagnose,' 'monitor,' 'predict,' 'recommend,' 'optimize,' and 'control' can carry important regulatory implications. The same is true for the description of intended users, patient populations, outputs, and the role of a healthcare professional. Patent language should not be allowed to define the FDA intended use accidentally, and FDA language should not needlessly narrow patent claims. The teams should understand why each document uses the language it uses. The patent process can also identify design-arounds. That matters to the FDA because a competitor's likely design-around may suggest which device changes the company should anticipate, which features may become industry norms, and where future product modifications could affect regulatory status. For AI devices, a patent portfolio that covers multiple model
architectures, training approaches, deployment configurations, or monitoring methods can support a product roadmap that is consistent with a PCCP and broader lifecycle strategy. The strongest coordination is not identical wording in every document. It is a common factual core with document-specific legal framing. Patent counsel, regulatory counsel, and the technical team should agree on the basic technical facts, but each filing should answer the legal questions asked by its own system.
Trade secrets can be the most valuable and the most fragile part of a medical-device portfolio. Under the federal Defend Trade Secrets Act, a trade secret can include scientific, technical, engineering, business, process, program, or code information if the owner takes reasonable measures to keep it secret and the information derives independent economic value from not being generally known or readily ascertainable through proper means. 18 U.S.C. §1839(3). State law also remains important. For medical devices, potential trade secrets include manufacturing know-how, calibration methods, tolerances, supplier specifications, source code, model weights, training datasets, data-cleaning methods, feature-engineering choices, labeling workflows, clinical-development strategy, test fixtures, cybersecurity details, failure-analysis methods, process controls, pricing, and customer information. Not everything secret is a good trade secret. The best candidates are information that can remain secret in actual commercial use and that competitors cannot readily reverse engineer or independently develop. AI increases both the value and the difficulty of trade-secret protection. A model may depend on a combination of dataset curation, architecture, training schedules, prompts, guardrails, human review, thresholds, monitoring, and postprocessing. No single element may be decisive, but the combination can be valuable. That is why piecemeal leakage is dangerous. A company can lose practical secrecy gradually by disclosing different fragments to different audiences until a knowledgeable competitor can reconstruct the whole system. A good trade-secret program therefore starts with identification. The company should know what its trade secrets are, who owns them, where they reside, who can access them, why they are valuable, and what controls apply. Generic confidentiality language in an employee
handbook is not enough for high-value technology. Reasonable measures should match the value and sensitivity of the information. Useful measures commonly include written policies, confidentiality agreements, invention-assignment agreements, role-based access, technical access controls, secure repositories, logging, vendor and consultant controls, clean onboarding and offboarding, marking where appropriate, need-to-know compartmentalization, training, incident-response procedures, and periodic review of what still qualifies as secret. For multinational organizations, the program should also account for local employment and data laws rather than assuming a U.S. agreement works everywhere. The program must also avoid over-compartmentalization. Patent and FDA teams need enough visibility to perform their legal duties. A trade secret should not be hidden from patent counsel if the company expects a claim that cannot be enabled without it. Prior art should not be hidden from patent counsel because it was found by the regulatory team. Safety-critical technical information should not be withheld from the FDA when disclosure is legally required. The objective is controlled disclosure, not organizational blindness. Trade secrets interact directly with §101. If the patent application says only that generic AI is used to achieve a desired result, while the actual technical improvement remains hidden, the claims may be vulnerable under Alice and Recentive. Desjardins shows the value of identifying a concrete improvement in how the machine-learning technology operates. If that improvement is the invention being patented, enough of it must be disclosed to support the claim. Trade secrets also interact with §§102 and 103. A secret itself is not necessarily prior art merely because it exists inside the company, but public disclosure, sale, use, patents, publications, and third-party activities can create prior art. The company should not confuse its own secrecy with the absence of external prior art. A trade-secret program should include a disclosure review process so that a presentation, pilot, publication, or sales activity does not unintentionally change the patent landscape. Section 112 creates the clearest tradeoff. A patent requires disclosure; a trade secret requires secrecy. A company should decide which protection is better for each technical feature. A hidden manufacturing parameter that cannot be reverse engineered and may remain useful for decades can be an excellent trade secret. A product architecture that will be visible as soon as the device is sold may be a poor trade secret and a better patent candidate. An algorithmic detail may fall
somewhere in the middle depending on whether it can be inferred from outputs, required in regulatory disclosure, or independently reproduced by competitors. The FDA generally protects legitimate trade secrets and confidential commercial information from public disclosure under its regulations, including 21 C.F.R. §20.61. PMA confidentiality rules expressly protect certain manufacturing methods and processes and other protected information, while also providing for public disclosure of specified information after an approval or denial. 21 C.F.R. §814.9. The important point is that FDA confidentiality has boundaries. A sponsor should label and organize confidential information properly, understand what the FDA will later publish, and avoid placing unnecessary secrets into public-facing portions of a submission. The same principle applies to 510(k) submissions. The FDA's regulations address when the existence and contents of a premarket notification become publicly available, and a 510(k) summary or statement is part of the regulatory framework. Companies should assume that significant regulatory information may become public and should coordinate patent filing before clearance-related disclosure. The goal is not to withhold required information from the FDA. The goal is to know in advance what may be released and to make the patent and trade-secret decisions first. For AI devices, a practical secrecy map can be useful. One column can identify information that must be disclosed to the FDA. A second can identify information planned for patent disclosure. A third can identify information intentionally retained as trade secret. A fourth can identify public-facing material such as labeling, websites, and 510(k) summaries. The map should be reviewed before each major regulatory or commercial disclosure.
Trade dress can protect the source-identifying appearance of a product or its packaging under the Lanham Act, but it is not a substitute for patent law. Product-design trade dress ordinarily requires secondary meaning: consumers must come to associate the design with a single source. Wal-Mart Stores, Inc. v. Samara Brothers, Inc., 529 U.S. 205 (2000). Functional product features cannot be protected as trade dress. The functionality rule is especially important for medical devices. In TrafFix Devices, Inc. v. Marketing Displays, Inc., 532 U.S. 23 (2001), the Supreme Court held that an expired utility
patent can be strong evidence that a claimed product feature is functional. That does not mean a medical-device company should avoid trade dress. It means the company should distinguish source-identifying ornamental or presentation features from features that perform the device's function. Trade dress can be valuable for mature product lines with distinctive housings, packaging, interface presentation, color arrangements, or other nonfunctional visual features. It often works best as a long-term layer that develops after design patents have provided earlier protection. Marketing should use distinctive features consistently if the company hopes those features will acquire source significance. Copyright protects original expression, not ideas, methods, systems, or functionality. For medical-device companies, copyright may protect source code, documentation, illustrations, training materials, certain graphical elements, website content, and other expressive works. The U.S. Copyright Office states that computer-program copyright does not extend to ideas, program logic, algorithms, systems, methods, or concepts. Copyright and trade secrets can coexist. The Copyright Office has procedures for registering computer programs that contain trade-secret material without requiring public deposit of every sensitive portion. Registration strategy should be coordinated with software and trade-secret counsel, particularly where source code has significant value. Neither copyright nor trade dress should be used to promise exclusivity over technical function that belongs in patent law or the public domain. They are complementary layers, not back doors to perpetual utility-patent protection.
The first portfolio question should not be, 'Can we patent this?' It should be, 'What are we trying to protect, and what form of protection gives us the best business result?' A patent is useful when exclusion matters, when competitors can discover or reverse engineer the invention, when the technology is likely to remain commercially relevant through the patent term, and when the claims can be drafted with meaningful scope. A trade secret may be better when the information can remain secret for a long time and public disclosure would teach competitors more than the eventual patent rights are worth.
The second question is whether the invention is worth patenting. Patent filings should be tied to commercial importance, competitive risk, licensing value, freedom to operate, regulatory pathway, and product roadmap. Filing because a feature is technically interesting can create an expensive portfolio that looks impressive by count but does little to protect the business. The third question is how many patents are enough. There is no universal number. One excellent patent family that covers the core product, key alternatives, and commercially realistic design-arounds can be worth more than twenty narrow applications. Conversely, a platform device with hardware, disposables, software, AI, data pipelines, manufacturing methods, interfaces, and multiple clinical uses may justify several coordinated families. The right number follows from the number of distinct inventions and business choke points, not from a target quota. The fourth question is whether the portfolio is layered. For a medical device, the strongest protection often combines utility patents, design patents, trade secrets, trademarks and trade dress, copyright, contracts, data rights, regulatory know-how, and speed of execution. Each layer protects something different. A competitor who avoids a utility claim may still confront a design patent, a protected brand presentation, a confidential manufacturing process, or copyrighted software. The fifth question is whether the claims protect the commercial product and the likely design-arounds. A patent that describes the product beautifully but claims an irrelevant sub-feature is not a strong business asset. Claim strategy should be tested against the company's own planned variants and against a hypothetical competitor instructed to avoid infringement while preserving the product's commercial value. The sixth question is whether the patent and FDA positions are consistent. If the company tells the FDA that a feature is essential for safety and effectiveness but tells the USPTO that the same feature is insignificant or absent from the prior art for a different reason, the inconsistency can become damaging. The legal tests are different, so the words do not need to be identical, but the factual story should be defensible in both forums. The seventh question is what should remain secret. This should be answered affirmatively, not by omission. The company should be able to identify the trade secrets associated with each product family and explain why patenting them would be inferior. It should also know when a
patent publication, FDA disclosure, software release, customer contract, or employee departure might expose them. The eighth question is where to file. A foreign developer entering the U.S. market may already have a priority filing. The U.S. application should be reviewed for U.S.-specific eligibility, §112 support, claim strategy, and continuation opportunities rather than treated as a translation exercise. International filing decisions should follow realistic market, manufacturing, competitor, and enforcement considerations. Patents are territorial; a worldwide filing program is expensive and should be selective. The ninth question is whether the portfolio has an update mechanism. AI-enabled devices evolve. New training methods, new datasets, new deployment architectures, new sensors, new model-monitoring methods, and regulatory changes can create new inventions after the first filing. The company should schedule recurring invention-harvesting reviews around engineering milestones, FDA submissions, major verification and validation events, PCCP development, and product releases. The tenth question is whether the company can explain its portfolio in one page. Senior management should be able to see what the core patents cover, what remains secret, what design and brand rights exist, what filings are pending, where the major gaps are, and how the portfolio maps to the product roadmap. If the portfolio cannot be summarized clearly, it is often a sign that filing activity has become disconnected from strategy.
Question — What to ask
Protection choice — Should this feature be patented, kept as a trade secret, protected by design/brand rights, or left unprotected?
Commercial importance — Does the right cover a feature customers value or competitors need to copy?
Claim quality — Do the claims cover the product and realistic design-arounds rather than merely describing the embodiment?
AI-specific technical contribution — What technological improvement exists beyond using generic AI or machine learning?
Regulatory consistency — Are patent and FDA factual positions consistent and explainable?
Secrecy — What is intentionally being kept secret, and are reasonable measures in place?
Geography — Where are the real markets, competitors, manufacturing locations, and enforcement needs?
Lifecycle — What new inventions are likely to arise during verification, validation, FDA review, PCCP development, and post-market monitoring?
Budget — Are resources concentrated on high-value rights rather than portfolio count?
Management visibility — Can the portfolio and its gaps be explained to management on one page?
An integrated workflow does not require a large legal department. It requires a few disciplined checkpoints. The first checkpoint is product definition. Before major external disclosure, the technical, patent, regulatory, and business leads should identify the intended use, key technical differentiators, likely regulatory pathway, likely public disclosures, and known prior art. The second checkpoint is invention capture. The company should document the core invention, alternatives, inventors, technical problems, technical solutions, and available test evidence. For
AI, the discussion should include what is new about the model or system beyond the fact that machine learning is present. If the novelty lies in data handling, training, monitoring, model architecture, hardware interaction, or workflow integration, say so explicitly. The third checkpoint is the patent-versus-secret decision. Each valuable feature should be classified as a likely patent candidate, likely trade secret, public by necessity, or undecided. Features that are required to support patent claims should not be withheld from the patent disclosure. Features that are not needed and can remain secret should not be disclosed merely because they are interesting. The fourth checkpoint is prior art and regulatory landscape review. Patent searching and predicate/regulatory research should be conducted separately but shared intelligently. References discovered by either team should be routed for appropriate legal evaluation. This is where the Bruno problem can be avoided before it exists. The fifth checkpoint is the pre-submission consistency review. Before a significant FDA submission and before major patent prosecution positions, the teams should compare the factual statements that matter. The objective is to identify contradictions, unnecessary admissions, public-disclosure issues, and valuable technical material that still needs patent coverage. The sixth checkpoint is public-release review. Press releases, conference abstracts, websites, product brochures, investor decks, clinical publications, instructions for use, FDA summaries, and software documentation should be reviewed against pending filing plans. This is especially important for foreign companies because a disclosure that may be survivable under the U.S. grace period can still destroy rights elsewhere. The seventh checkpoint is post-market invention harvesting. FDA clearance or approval is not the end of development. Manufacturing improvements, complaint investigations, cybersecurity work, AI performance monitoring, model updates, usability refinements, and new indications can produce patentable inventions and new trade secrets. The post-market quality system is therefore also an innovation record. The eighth checkpoint is annual portfolio pruning. Applications and patents should be reviewed against current products, regulatory plans, licensing opportunities, enforcement value, and maintenance costs. Low-value filings should not consume the budget needed for the few rights that matter most. Quality generally beats quantity.
For a foreign developer, one additional checkpoint is U.S. operational readiness. The FDA requires foreign establishments that manufacture devices imported into the United States to identify a U.S. agent, and applicable registration, listing, quality-system, premarket, labeling, reporting, and import requirements must be addressed. Patent ownership, assignments, inventor obligations, and U.S. entity structure should be reviewed at the same time so that the company entering the market is also the company that can actually enforce or license the relevant rights.
The first common mistake is filing a thin provisional application that contains a concept but not the technical detail needed for later claims. A provisional filing date is valuable only for subject matter that is actually supported by the provisional. A slide deck with aspirations may not support the patent the company later wishes it had. The second mistake is waiting for the FDA package to be finished before talking to patent counsel. By then, public disclosures may have occurred, design choices may have changed, and the most important technical improvements may have been documented without a filing plan. The third mistake is patenting everything and protecting nothing well. A large portfolio can consume prosecution and maintenance budgets while leaving the core product exposed. The portfolio should be built around commercial choke points, not invention-disclosure counts. The fourth mistake is treating AI as a magic patent word. Recentive makes clear that applying generic machine learning to a new dataset or environment is vulnerable under §101. The application should identify the actual technological improvement. The fifth mistake is treating trade secrets as whatever has not yet been published. Trade-secret rights depend on reasonable secrecy measures and economic value from secrecy. A company that cannot identify its secrets, control access, or show consistent protection is building on a weak foundation. The sixth mistake is disclosing secrets piecemeal. Engineers tell one part of the story at a conference, marketing reveals another part, a patent application discloses a third, an FDA summary reveals a fourth, and a vendor learns the rest. Each disclosure may look harmless by itself. Together they can destroy secrecy or make reverse engineering much easier.
The seventh mistake is assuming FDA confidentiality solves patent timing. It does not. Some submission materials remain protected, but some regulatory information becomes public, and commercial activity around the submission can itself create disclosure issues. Patent filing should be driven by the planned disclosure calendar, not by a generalized belief that 'FDA keeps everything confidential.' The eighth mistake is letting regulatory and patent positions contradict each other. The company should not make technically inconsistent factual statements simply because different outside professionals drafted different documents. A shared factual record and periodic cross-review can prevent most of these problems. The ninth mistake is forgetting design protection. Medical-device companies often focus exclusively on utility patents even when the housing, wearable form, cartridge, connector, or interface has a distinctive visual design that competitors could copy. After LKQ, design-patent obviousness is more flexible, but design patents remain an important and relatively focused form of protection. The tenth mistake is forgetting that FDA clearance is not freedom to operate. The FDA may permit marketing of a device that infringes someone else's patent. Patent clearance is not FDA clearance, and FDA clearance is not patent clearance. The two analyses should proceed in parallel.
The best medical-device portfolio is not a stack of patents. It is a coordinated system of legal and technical protection built around the product, the regulatory pathway, the competitive landscape, and the information the company can realistically keep confidential. For AI-enabled devices, coordination is even more important because the same technical feature may matter to patent eligibility, enablement, FDA safety and effectiveness, cybersecurity, change control, and trade-secret value. Recentive and Desjardins make the patent drafting question more concrete: what, specifically, has the company improved about the technology? The FDA's lifecycle approach asks a related question: how will that technology perform, change, and remain controlled over time? A good development process should be able to answer both. The central habit is to make disclosure decisions before disclosure occurs. Decide what should be patented. Decide what should remain secret. Decide what the FDA must receive. Decide
what the public will eventually see. Then coordinate those decisions with the filing calendar and the product roadmap. That is how patent law and FDA law stop being parallel expenses and become parts of the same business strategy.
A foreign developer should begin the U.S. project by mapping ownership, disclosure, and regulatory status at the same time. The company should identify the entity that owns the technology, the inventors, existing patent applications, employee or contractor assignments, major licenses, and any rights granted to universities, hospitals, distributors, or development partners. Those ownership facts should be resolved before a U.S. filing becomes urgent. A technically strong patent is of limited value if the company later discovers that a consultant or former employer owns part of the invention. The company should then create a disclosure timeline. That timeline should include priority applications, foreign patent publications, conference presentations, journal articles, clinical-trial registrations, CE-marking materials, notified-body communications that became public, sales offers, demonstrations, distributor activity, websites, social-media announcements, customer pilots, and investor disclosures. U.S. counsel can then determine what remains available for protection in the United States and what may already have been lost elsewhere. The analysis should be done with exact dates, not general recollections that something occurred 'last year.' Next comes regulatory classification and pathway planning. The company should identify the product code and classification regulation if one exists, determine whether the device is exempt, consider whether a 510(k), De Novo request, or PMA is the likely pathway, and evaluate whether any software function falls outside the statutory device definition. This regulatory analysis should be shared with patent counsel because the pathway often reveals what competitors, predicates, and technical comparisons will matter commercially. Foreign manufacturers also need a U.S. operational plan. The FDA requires a foreign establishment engaged in manufacturing devices imported into the United States to identify a U.S. agent as part of registration. Applicable establishment registration, device listing, labeling, Medical Device Reporting, quality-system, import, and premarket requirements must also be addressed. The U.S. agent is a regulatory liaison; the role should not be confused with the company's patent attorney, importer, distributor, or commercial representative unless the actual arrangements support those additional roles.
QMSR readiness should be treated as an evidence opportunity rather than only a compliance burden. A foreign company already certified to ISO 13485:2016 may have a strong starting point because the FDA's QMSR incorporates that standard by reference. The company should still identify U.S.-specific requirements, but its design and quality records can also help demonstrate the evolution of technical features, alternatives considered, verification results, and problem-solving that may be useful for patent drafting and prosecution. The U.S. patent filing should be reviewed as a U.S. application, not merely translated from the first foreign filing. U.S. practice may justify additional description of alternative embodiments, software implementations, AI architecture, system-level interactions, and technical effects. Counsel should also consider claim categories that may not have been emphasized abroad, including apparatus, method, system, software-related, manufacturing, use, and design claims where supported. New matter cannot be added to the old priority disclosure while retaining the old priority date for that new matter, so the timing and filing structure should be planned carefully. The company should also decide whether continuation practice will be important. A U.S. continuation can be strategically valuable for a platform device because it allows different claim scope to be pursued from the same disclosure while the family remains pending. Continuation practice can be used to respond to competitor products, changing commercial priorities, or a maturing understanding of which features matter most. It does not, however, cure an original disclosure that never described the later-claimed invention. For AI-enabled devices, data rights require a separate review. A company may have rights to use data for model training without having the right to disclose the data in a patent, regulatory submission, publication, or litigation. Hospital agreements, research collaborations, data-use agreements, privacy law, de-identification requirements, and third-party database licenses can all affect what the company may do. Patent counsel should not assume that because engineers trained a model on a dataset, the company is free to reproduce or describe the dataset publicly. The company should then align the public narrative. Marketing materials, intended-use language, claims of clinical performance, regulatory statements, and patent descriptions should all be based on the same technical reality. The documents will not use identical language because they have different purposes, but a competitor, regulator, patent examiner, judge,
investor, or acquirer should not be able to place them side by side and find irreconcilable factual stories. Finally, the foreign developer should budget for protection based on U.S. business value, not on the number of jurisdictions already filed. Entering the United States often justifies a more rigorous freedom-to-operate review, continuation strategy, design-patent analysis, trade-secret program, and contract cleanup. Those expenditures should be concentrated on the product families that are expected to reach the U.S. market.
An AI invention disclosure should begin with the technical problem, not with the phrase 'we use artificial intelligence.' The team should state what the prior system could not do well enough. Was the limitation memory, latency, false alarms, calibration, robustness, drift, explainability, data scarcity, sensor noise, domain shift, workflow burden, cybersecurity, power consumption, or safe updating? A concrete problem gives both patent counsel and the regulatory team a useful frame. The disclosure should next identify what changed technically. If the improvement is a new model architecture, describe the relevant architecture. If it is preprocessing, describe the transformation and why it matters. If it is a training method, explain the training sequence, objective, constraints, data selection, or transfer method. If it is postprocessing, explain thresholds, confidence handling, fusion, temporal filtering, or other logic. If it is a hardware-software interaction, identify what the hardware contributes and why the combination behaves differently. The disclosure should identify the inputs and outputs with enough specificity to understand the system. For a medical device, inputs may include images, waveforms, laboratory values, patient characteristics, device-state information, user entries, environmental data, or combinations. Outputs may be classifications, measurements, alarms, treatment recommendations, control signals, segmentation maps, risk scores, or quality indicators. The company should distinguish an output used by a clinician from one that directly controls therapy because the regulatory and patent implications can differ. The team should describe training and validation separately. What data were used for development? What data were held out? What were the relevant patient populations, sites,
devices, or acquisition conditions? How was ground truth established? What metrics matter clinically and technically? What failure modes were observed? Patent counsel may not need every regulatory detail, but the answers often reveal the real inventive contribution and support a more credible technical disclosure. The team should identify what is intended to change after deployment. Will the model be locked, periodically retrained, locally adapted, or centrally updated? What triggers a change? How is performance monitored? What validation gates apply? What rollback or fail-safe mechanism exists? These questions now have obvious FDA significance considering lifecycle regulation and PCCP planning, but they may also reveal patentable monitoring, update, or safety architectures. The team should identify what must remain secret. Candidate trade secrets may include model weights, source code, nonpublic datasets, labeling protocols, feature-engineering recipes, proprietary prompts, thresholds, internal evaluation sets, or manufacturing calibration information. Counsel should then ask whether any of those details are necessary to enable the patent claims being contemplated. If so, the company may need to disclose enough to support the patent or narrow the claims to avoid pretending the undisclosed secret does not matter. The disclosure should identify measurable technical effects. Reduced storage, reduced complexity, lower compute load, better calibration, improved robustness, reduced latency, improved detection under noisy conditions, reduced clinician interaction, or a safer failure mode can help distinguish a technological improvement from generic use of machine learning. This is the factual territory highlighted by the contrast between Recentive and Desjardins. Finally, the disclosure should list every planned external disclosure and its date. That includes FDA submissions, Q-Submissions, abstracts, papers, investor demonstrations, conferences, customer pilots, software releases, and marketing launches. The patent team can then choose filing dates deliberately. For AI products evolving quickly, this calendar is often more important than the traditional annual invention-review meeting.
Patent statutes: 35 U.S.C. §§101, 102, 103, 112, 122, 154, 156, 171-173, and 271(e)(1). Alice Corp. v. CLS Bank International, 573 U.S. 208 (2014) (patent eligibility framework for claims involving abstract ideas). Recentive Analytics, Inc. v. Fox Corp., 134 F.4th 1205 (Fed. Cir. 2025), rehearing denied July 23, 2025, cert. denied Dec. 8, 2025 (generic application of established machine-learning techniques to new data environments held ineligible where no improvement to the machine-learning model was disclosed). Ex parte Desjardins, Appeal No. 2024-000567 (USPTO Appeals Review Panel Sept. 26, 2025), designated precedential Nov. 4, 2025 (claims reflecting an improvement in AI technology found patent eligible under the USPTO framework). Graham v. John Deere Co., 383 U.S. 1 (1966), and KSR International Co. v. Teleflex Inc., 550 U.S. 398 (2007) (obviousness). LKQ Corp. v. GM Global Technology Operations LLC, 102 F.4th 1280 (Fed. Cir. 2024) (en banc) (design-patent obviousness; Rosen-Durling overruled in favor of a more flexible Graham/KSR-based analysis). Bruno Independent Living Aids, Inc. v. Acorn Mobility Services, Ltd., 394 F.3d 1348 (Fed. Cir. 2005) (patent-prosecution consequences of failing to disclose material prior art that had been submitted to the FDA). Eli Lilly & Co. v. Medtronic, Inc., 496 U.S. 661 (1990) (35 U.S.C. §271(e)(1) safe harbor applies to qualifying activities reasonably related to FDA information for medical-device approval). 18 U.S.C. §§1836 and 1839 (federal trade-secret protection and definition of trade secret). Wal-Mart Stores, Inc. v. Samara Brothers, Inc., 529 U.S. 205 (2000) (product-design trade dress requires secondary meaning). TrafFix Devices, Inc. v. Marketing Displays, Inc., 532 U.S. 23 (2001) (functionality and significance of utility-patent disclosures to trade-dress analysis). FDA, Overview of Device Regulation; Classify Your Medical Device; Premarket Notification 510(k); De Novo Classification Request; Premarket Approval (PMA); Device Registration and
Listing; U.S. Agents; and Importing Medical Devices and Radiation-Emitting Electronic Products into the U.S. FDA, Quality Management System Regulation (QMSR), effective Feb. 2, 2026, incorporating ISO 13485:2016 by reference within FDA's device CGMP framework. FDA, Marketing Submission Recommendations for a Predetermined Change Control Plan for Artificial Intelligence-Enabled Device Software Functions (Final Guidance, Aug. 2025). FDA, Artificial Intelligence-Enabled Device Software Functions: Lifecycle Management and Marketing Submission Recommendations (Draft Guidance, Jan. 2025; draft status should be checked before relying on it as final policy). FDA, Clinical Decision Support Software (Final Guidance, Jan. 2026). FDA, Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (current final guidance, 2026). 21 C.F.R. §§20.61, 807.95, and 814.9 (confidential commercial information, 510(k) confidentiality, and PMA confidentiality). U.S. Copyright Office, Circular 61, Copyright Registration of Computer Programs, and Computer Programs guidance (copyright protects expression in software, not ideas, algorithms, systems, or methods).
This primer is for general informational and educational purposes only. It is not legal advice and does not create an attorney-client relationship. Patent law, FDA law, trade-secret law, and the rules governing AI-enabled medical devices are complicated, fact-specific, and continually developing. A reader making a legal, regulatory, filing, disclosure, commercialization, or enforcement decision should consult an attorney familiar with the relevant technology and area of law, and should obtain appropriate FDA regulatory advice for the particular device. This primer is not a substitute for device-specific legal and regulatory analysis.