Добавил:
kiopkiopkiop18@yandex.ru t.me/Prokururor I Вовсе не секретарь, но почту проверяю Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:
Ординатура / Хирургия / Библиотека им академика М.И. Перельмана / Книга_5432_Библиотеки_им_академика_М_И_Перельмана.pdf
Скачиваний:
0
Добавлен:
10.10.2026
Размер:
10 Мб
Скачать
☆
380 Cobert’s Manual of Drug Safety and Pharmacovigilance
Standards Development Organization (IHTSDO), Euro-
pean Committee for Standardization (CEN), and others
have implemented a single, common ICSR standard,
ISO IS 27953-2:2011: Health informatics — Pharma-
covigilance — Individual case safety report — Part 2:
Human pharmaceutical reporting requirements for
ICSR. This double-badged standard (owned by ISO and
HL7), has been developed based on ICH E2B(R3) busi-
ness requirements. ICH has developed an ICH Imple-
mentation Guide as part of an implementation package
that is composed of several documents, including Q&A.
Founding regulators have issued regional Implementa-
tion Guides to supplement the ICH package and have
used the entire package for implementation.
ISO has also developed a complex suite of five stan-
dards and nine supporting documents for Identification
of Medicinal Products (IDMP), intended for use with
ICSR exchange. These standards specify data elements
and structures to uniquely identify and exchange infor-
mation across the entire lifecycle of a drug product,
i.e., products in development, investigational products,
products under evaluation, and approved products:
ISO IS 11238:2012
Health informatics — Identification of medicinal prod-
ucts — Data elements and structures for the unique
identification and exchange of regulated information
on substances.
ISO IS 11239:2012
Health informatics — Identification of medicinal prod-
ucts — Data elements and structures for the unique
identification and exchange of regulated information
on pharmaceutical dose forms, units of presentation,
routes of administration and packaging.
ISO IS 11240:2012
Health informatics — Identification of medicinal prod-
ucts — Data elements and structures for the unique
identification and exchange of units of measurement.
ISO IS 11616:2012
Health informatics — Identification of medicinal prod-
ucts — Data elements and structures for the unique
identification and exchange of regulated pharmaceuti-
cal product information.
ISO IS 11615:2017
Health informatics — Identification of medicinal prod-
ucts — Data elements and structures for the unique
identification and exchange of regulated medicinal
product information.

Database Migration

At some point, most companies will have to migrate
their safety data (often called “the legacy data”) to a
new or upgraded safety database, or from one vendor to
another. Many companies will also, at some point, have
to import safety data should they acquire an already
marketed product. Sometimes companies merge and
combine their safety systems. These situations require
the transfer of data from the originator’s database into
the acquirer’s database or vice versa. This data trans-
fer is generally a painful exercise requiring the exper-
tise of the drug safety, IT, regulatory, and other groups.
It can be difficult and time-consuming if participant
numbers are in the hundreds of thousands to millions,
with billions (or more) of data points! However, with
most database having E2B capabilities, the transfer of
the information from one system to the next is becom-
ing easier. The data will still have to be examined and
mapped into the new database and if the previous data-
base had a lot of customizations, this will also create
challenges. Although much of the data can be automati-
cally transferred using algorithms, some of the data will
need to be examined and transferred manually. This is
the case with conversion of E2B(R2) data to conform
with the E2B(R3) requirements (and vice versa). The
transferring team will find inexplicable data and not be
able to trace the “cleaning rules” applied when the data
were entered or transferred in the past. Multiple moves
of data over the years worsen this problem. This hap-
pens to companies, regulators, and service providers.
The migration process can take months to a year for
large and complex databases. An internal team, often
with outside consultant assistance, should be assem-
bled for this project, with careful project management,
quality control, validation, and full documentation of
all processes, changes, and alterations. The company
should expect an inspection by the concerned health
Information Technology and the Safety Database 381
agencies (FDA, EMA, MHRA in particular) after the
migration.
When a company makes the determination to
migration safety data from one place to another, great
care should be taken to ensure accuracy and com-
pleteness of the information migrated. The company
should put into place a migration plan to document
the steps involved for the transfer, how discrepancies
will be managed, and how the migration itself will be
documented. During a BIMO inspection for example, it
is largely assumed that any database migration will be
subject to review and scrutiny.
1. Something to consider when preparing for and
conducing a safety database migration should be
to Create a Data Migration Plan which summa-
rizes and documents:
a. New and old Safety Database information,
such as database names, version information,
MedDRA version information, etc.
b. Date of the migration initiation & target com-
pletion dates
c. Risk Management procedures for delays in
the migration and how those risks will be
mitigated
d. Responsible persons/parties involved in the
migration and a table outlining roles and
responsibilities between each party
e. Source of incoming data and data type to be
transferred (Line listings, MedWatch, CIOMS,
E2B .xml files, narratives, source data infor-
mation, etc.)
f. How the data will be transferred (electroni-
cally or manually, or both)
g. What steps will be taken to ensure all cases
received were successfully migrated, such as a
reconciliation step at the end of the migration
to ensure case A made it from Database X to
Database Y for example
h. How to handle discrepancies or errors found
in the case files during the migration phase
i. If a clinical trial is ongoing at the time of migra-
tion, how incoming cases will be handled
(will they go directly into the new system or
will initial case processing pause with the new
system until all legacy data is transferred?)
j. What will signify when the migration is com-
plete? Will the company implement a data
migration completion form that requires a sig-
nature of the owning/responsible parties?
k. Where will the documents of the transfer be
stored
The process of creating such a plan will ultimately
improve the outcome of the migration and help when
one may have to review the migration activities during
an inspection.
Clinical Data Interchange
Consortium
CDISC is a global, multi-disciplinary, non-profit “SDOs”
that has established electronic data standards to support
the acquisition, exchange, submission, and archive of
clinical research data and associated metadata (www.
cdisc.org). Their goal is to develop and support global,
platform-independent data standards that enable infor-
mation systems to easily exchange data to improve
medical research and healthcare.
CDISC standards are vendor-neutral, platform-in-
dependent, and freely available.
Systematized Nomenclature
of Medicine Clinical Terms
SNOMED is a hierarchical, clinical terminology or dic-
tionary that covers diseases, clinical data, microorgan-
isms, drugs, procedures, adverse events, and more. It
has more than 344,000 “concepts”. It will encompass
MedDRA and much more, although there is not a 1:1
correlation of these two terminologies. It was created
by the College of American Pathologists and the UK
National Health Service. The US Department of Health
and Human Services in 2007 agreed to participate in
the development of Systematized Nomenclature of
Medicine Clinical Terms (SNOMED CT) for use with
electronic health records. It is available free of charge to
everyone in the US.
382 Cobert’s Manual of Drug Safety and Pharmacovigilance
This is a highly complex area that is constantly
changing and evolving. Not all efforts are fully har-
monized around the world, and it is possible, if not
likely, that multiple standards will develop over time.
Although these efforts are just beginning to touch drug
safety, it is expected that the systems, procedures, busi-
ness models, IT, and all other aspects of drug safety will
change over the years as these standards are put into
practice.

Frequently Asked Question

Q: This seems incredibly complex and not
necessarily understandable by non-IT people
doing pharmacovigilance. Is this a problem?
A: Well, it certainly is in some companies and agen-
cies. The bureaucratic, IT, and regulatory complexity
is increasing rapidly as we now enter Drug Safety 3.0!
More and more jobs are compartmentalized, making it
much harder to have a good overview of how PV works.
The creation in the EU of the Pharmacovigilance System
Master File (PSMF) helps one figure out how the system
works at a high level, even if it is very complex. Such
a document does not exist in the US. This document,
however, may not cover IT in sufficient detail looking
at all IT systems (validated and non-validated) in use.
Many have pointed out that such complexity may make
it easier to hack a system, thus, putting everyone at risk.
So yes, this is a problem! We need greater IT literacy
and transparency in pharmacovigilance.
CHAPTER
383
35
Data Privacy
and Security
A
pproximately 30 or so years ago,
with the advent of enormous
changes in communication, the
Internet, personal computers, smart
phones and tablets, social media, Artifi-
cial Intelligence (AI), etc., it has become
clear that personal privacy and data
security are major issues in medicine.
With the Internet and identity theft,
the question of who has access to what
data is now in the forefront of people’s
and governments’ minds.

Introduction

For many years, medical data were believed to be the
property of the treating physician or hospital, and they
were kept confidential by those parties. In the United
States, Europe, and elsewhere, there was no right to
privacy as defined by law, and sometimes patients were
denied the right to obtain or even see their own medical
records. The law that was in place in the United States
was state law, which varied from state to state, offering
inconsistent levels of protection. Similarly, in Europe
and elsewhere, laws were national or local, such as they
were.
That viewpoint has largely changed, and a person’s
health data are now believed to be owned by that indi-
vidual. There are now clear limitations on what third
parties (physicians, hospitals, companies, and govern-
ments) can and cannot do with the data. In the United
States, the federal government and local governments
have enacted laws on privacy. The European Union now
has rules and regulations that cover all member states
(some of which have put forth additional and tougher
privacy and security protections). There is even an EU
Data Protection Supervisor, an independent position
appointed by the European Parliament and the Coun-
cil with responsibility for protection of personal data
384 Cobert’s Manual of Drug Safety and Pharmacovigilance
handled by EU institutions, bodies, and agencies. Can-
ada, Australia, Japan, and other countries have also
tightened their privacy protections.
For the purposes of drug safety and pharmacovig-
ilance, two major governmental acts, worth studying
in detail, largely represent the state of privacy around
the world: the US Health Insurance Portability and
Accountability Act (HIPAA) and the European Union
(EU) Data Privacy Regulation & Directive and recent
changes, including the General Data Protection Regula-
tion (GDPR), which became effective in 2018. They are
reviewed here and the implications and effects on drug
safety are discussed.
In keeping with the context of this text, this chap-
ter intends to provide a general summary of some of
the data privacy laws and regulations that could impact
drug development and research, but it by no means pro-
vides the complete summary of the topics that should
be considered. Relevant to drug safety and pharma-
covigilance, the concerns regarding data protection and
privacy apply to the collection of source information as
it pertains to adverse event data, mainly serious events,
and the clinical course of the patient which often
requires the attainment of electronic medical records
from sources such as physician notes, hospital admis-
sion and discharge summaries, surgical records, and
post mortem autopsy reports. Since the implementation
of laws such as US HIPAA and EU GDPR (https:gdpr.
eu), pharmaceutical companies and drug developers
have, and continue to, struggle with the fine balance
of obtaining relevant clinical data to support the prod-
uct development, and maintaining patient and data
privacy and security. All Marketing Authorization Hold-
ers (MAHs) must comply with pre and post-marketing
pharmacovigilance requirements, such as reporting of
adverse events (AEs), while simultaneously ensuring
that personal data are processed only where necessary
and only where the parties involved assess this necessity
at every stage of the PV process. This is a difficult and
overwhelming task to ensure compliance and should be
overseen and managed not only by the safety group, but
be heavily managed by a Data Protection Officer (DPO)
and Compliance Officer.
United States Health
Insurance Portability and
Accountability Act (HIPAA)
Unlike the European Union, the United States does
not have one global law for data privacy and security.
Rather, different parts, or “sectors,” of the country have
different approaches. The healthcare sector is covered at
the federal level by the Health Insurance Portability and
Accountability Act (HIPAA) as well as various other
state and local laws, regulations, and court cases. Laws
and regulations, which have been revised several times,
are arcane and complex.
These regulations cover health plans, healthcare
clearinghouses, and those healthcare providers (“cov-
ered entities”) who handle personal healthcare data and
conduct certain financial and administrative transac-
tions on paper or electronically. All medical records and
other individually identifiable health information held
or disclosed by a covered entity in any form, whether
held electronically, on paper, or orally, are covered.
Some of the privacy and security features are summa-
rized as follows:
Providers and health plans must give patients a
clear written explanation of how they can use, keep,
and disclose their health information.
Patients must be able to see and get copies of their
records and request changes and corrections. Cor-
rections are not required to be made by the docu-
ment holder, but, if not, the “dissenting opinion”
must become a part of the record. In addition, a his-
tory of most disclosures must be made accessible to
patients on request.
Patients’ authorization to disclose information must
be obtained before their medical information is
shared. In addition, specific patient consent must
be obtained for certain other uses, such as releasing
information to financial institutions or drug compa-
nies, etc.
Patient consent to release information must not be
coerced.
Data Privacy and Security 385
Disclosures of personal information must be limited
to the minimum necessary to fulfill the intended
purpose of the request.
Covered entities must follow these requirements, at
a minimum:
Written privacy procedures must be in place and
must include who has access to protected informa-
tion, how it will be used within the entity, and when
the information would or would not be disclosed
to others. Covered entities must also take steps to
ensure that their business associates, e.g., contrac-
tors and vendors, etc., protect the privacy of health
information.
Covered entities must designate a privacy officer
and provide sufficient training to staff so that their
employees understand and follow the privacy pro-
tections and procedures.
Covered entities must provide a means for patients
to make inquiries or complaints regarding the pri-
vacy of their records.
Psychotherapy notes (used only by a psychother-
apist) are held to a higher standard of protection
because they are not part of the medical record and
are never intended to be shared with anyone else.
Failure to comply may lead to civil or criminal pen-
alties, including fines and imprisonment.
Examples of when personal health information may
be released:
Oversight of the healthcare system, including qual-
ity assurance activities;
Public health research approved by a privacy board
or institutional review board;
Judicial and administrative legal proceedings;
Certain law enforcement activities;
Emergency circumstances;
Identification of the body of a deceased person or
the cause of death; or
Activities related to national defense and security.
The HIPPA requirements clearly have implications
for pharmacovigilance. Much discussion occurred and
the Food and Drug Administration (FDA) ultimately
issued a clarification regarding the appropriate and
responsible release of patient-specific information
(Manufacturers Sharing Patient Specific Information
from Medical Devices with Patients Upon Request:
Guidance for Industry and Food and Drug Administra-
tion Staff, October 30, 2017).
The FDA fully recognized that pharmaceutical
companies are required by law and regulation to main-
tain databases of adverse events occurring in individu-
als who have taken their products, reported by health
professionals and others. The data identify the person
making the report and may or may not identify the indi-
vidual patient or subject. The data come both from clin-
ical trials of new products and from the post-marketing
data of drugs already on the market.
Although in such data there is often no specific
patient identification (e.g., name and address), there
may be sufficient patient data such that it would be
possible in many cases, with only minimal effort, to
identify the patient based on the known data (e.g., hos-
pital, dates of hospitalization, age or birth date, patient
initials, sex, diagnosis, treatment, and hospital course).
These data are often required to be submitted to health
authorities and are necessary for clinical and epidemio-
logic evaluation of the adverse event and safety profile
of the drug. It is vitally important to know that certain
events occur in special populations (e.g., only in chil-
dren, females, or the elderly). There is a broad consen-
sus in the industry and in the health authorities that
these data are vital for maintaining and protecting pub-
lic health. Removal of these demographic data would
make the data much less useful for safety and epidemi-
ologic analyses. Identification of safety problems occur-
ring with both new and old drugs would suffer if the
flow of these data were hindered.
The FDA addressed this in the March 2005 Guid-
ance for Industry: Good Pharmacovigilance Practices
and Pharmacoepidemiologic Assessment. The FDA
notes: “It is of critical importance to protect patients
and their privacy during the generation of safety data
and the development of risk minimization action plans.
During all risk assessment and risk minimization
386 Cobert’s Manual of Drug Safety and Pharmacovigilance
activities, sponsors must comply with applicable regu-
latory requirements involving human subjects research
and patient privacy.”
It is also clear that “covered entities”, such as
pharmacists, physicians, or hospitals, are permitted to
report AEs to the health authorities without problem
from HIPAA. The FDA notes: “The Privacy Rule specif-
ically permits covered entities to report adverse events
and other information related to the quality, effective-
ness, and safety of FDA-regulated products both to
manufacturers and directly to FDA (45CFR164.512(b)
(1)(i) and (iii), and 45CFR164.512(a)(1)).” In 2018
the FDA commented on MedWatch and HIPAA: “The
HIPAA Privacy Rule recognizes the legitimate need
for public health authorities and others responsible
for ensuring public health and safety to have access
to protected health information to carry out their
public health mission. The Rule also recognizes that
public health reports made by covered entities are an
important means of identifying threats to the health
and safety of the public at large, as well as individuals.
Accordingly, the Rule permits covered entities to dis-
close protected health information without authoriza-
tion for specified public health purposes.” See: https://
www.fda.gov/safety/reporting-serious-problems-fda/
hipaa-compliance-reporters-fda-medwatch
In various subsequent initiatives and documents,
FDA has reiterated its commitment to protecting pri-
vacy and there is a broad understanding that drug safety
data may be reported to manufacturers (sponsors) and
to the FDA in the interest of public health.
The European Union and
the Privacy Regulation &
Directive
The European Union’s approach to privacy is somewhat
different from that of the United States. The United
States does not really have the equivalent of the pan-
European protections that exist in the European Union,
where a key directive (95/46) covered data protection
and privacy. A Regulation (2016/679) and a Direc-
tive (2016/680) have been issued in 2016; Regulation
repeals the Directive 95/46 since May 28, 2018. Each
EU member state was required to transpose the Direc-
tive into local legal requirements no later than May 6,
2018. A good summary of the current European Union
Privacy Legislation can be found at the website of the
European Commission and the website of the EU Data
Protection Supervisor.
In October 1995, the European Commission pro-
posed “Directive 95/46/EC on the protection of individ-
uals with regard to the processing of personal data and
on the free movement of such data.” All member states
in the European Union implemented local laws and reg-
ulations covering the contents of this directive. These
laws and regulations vary from country to country, and
some are stronger (more protective of privacy) than the
EU regulation itself. It had an impact on drug safety,
although less than originally feared.
Regulations and Directives cover all personal data,
whether electronic or on paper, and are not limited to
health information but broadly cover all other areas of
personal data including racial or ethnic origin, political
opinions, religious or philosophical beliefs, trade union
membership, processing of genetic data, biometric data
for the purpose of uniquely identifying a natural per-
son, data concerning a natural person’s sex life or sexual
orientation, and so forth. The legislation refers to the
“processing” of personal data. Processing refers to “any
operation ... which is performed ... such as collection,
recording, organization, storage, adaptation or alter-
ation, retrieval, consultation, use, disclosure by trans-
mission, dissemination ...”
As a general rule, processing of personal data is a
priori prohibited in the EEA, except in the following
circumstances:
The person in question has given consent. The
processing is necessary for the performance of a
contract;
The processing is necessary to meet a legal
obligation;
The processing is needed to protect the vital inter-
ests of the person in question;
The processing is needed to carry out a task that is
in the public interest or is done in exercise of offi-
cial authority;
Data Privacy and Security 387
The processing relates to personal data which are
obviously made public by the data subject;
Healthcare
“Processing is necessary for the purposes of pre-
ventive or occupational medicine, for the assess-
ment of the working capacity of the employee,
medical diagnosis, the provision of health or
social care or treatment or the management of
health or social care systems and services on the
basis of Union or Member State law or pursuant
to contract with a health professional (…);
Processing is necessary for reasons of public
interest in the area of public health, such as
protecting against serious cross-border threats
to health or ensuring high standards of quality
and safety of health care and of medicinal prod-
ucts or medical devices, on the basis of Union
or Member State law which provides for suitable
and specific measures to safeguard the rights
and freedoms of the data subject, in particular
professional secrecy”.
Member States may maintain or introduce more
specific provisions to adapt the application of the rules
of this Regulation to ensure lawful and fair processing.
Personal data can only be processed for speci-
fied explicit and legitimate purposes and may not be
processed further in a way incompatible with those pur-
poses. The person (European Union citizen) in ques-
tion has the right to be informed when his or her data
are processed. The person has the right to see all the
data processed about him or her as well as the right to
changes and corrections to incorrect or incomplete data.
The data must be accurate and relevant to the purpose
they are collected for, should not contain more infor-
mation than is necessary, and should not be kept longer
than necessary. The person may object at any time to
the processing of personal data for direct marketing.
A “right to erasure” (to be forgotten) and a “right to
restriction of processing” have been introduced in the
EU. This is rather controversial. Any EU citizen may
therefore request to:
Erase personal data when
No longer necessary;
Consent withdrawal;
Data unlawfully processed;
Data collected in relation to the offer of infor-
mation society services;
Restrict personal data processing when
Accuracy of the personal data is contested;
Processing is unlawful;
Personal data required by the data subject for
the establishment, exercise or defence of legal
claims;
Data subject has objected to processing.
A supervisory authority is to be nominated in each
member state. They shall monitor and enforce the
actual application of this regulation. All EU supervisory
authorities shall cooperate with each other.
Data may not be transferred to a third country
where there is an inadequate level of data protection (if
personal data are transferred outside the EEA, special
safeguards are foreseen to ensure that the protection
travels with the data). The United States is not consid-
ered to have adequate levels of protection for European
Union data. EUGDPR — Information Portal https://
eugdpr.org/ “The EU General Data Protection Regu-
lation (GDPR) is an important change that strength-
ens data privacy; enforcement began on 25 May 2018.
Organisations that are not compliant could face heavy
penalties, including monetary fines. Additional detailed
information is available on the GDPR portal: https://
eugdpr.org/.”
Data Privacy in Clinical Trials
and Product Development
Data privacy in clinical research as well as in the post
approval stage of product development is a cumber-
some task that involves and touches many aspects of
a company’s system. In clinical trials, documents such
as the Informed Consent and Protocol should have lan-
guage included that contains statements regarding the
collection, handling, processing, reporting, and storing
of protected health information such as personal data
as well as biological samples. A quick search of local
regulations (HHS.gov for the US for example) can pro-
vide you with examples, checklists and templates to
388 Cobert’s Manual of Drug Safety and Pharmacovigilance
consider when drafting the consent form and taking
into consideration the language required regarding data
privacy and protection. ICH E6 (make sure you are ref-
erencing the most current version and any addendum
published) regarding Good GCP, includes a checklist
for declaring what information will be collected, how
it will be kept private, and details for how long it will
be held. It is important that a company’s DPO or Legal
officer be a part of the review to ensure compliance with
applicable privacy laws.
When it comes to a company’s obligation to pub-
lish and provide data protection activities, one has to
consider all of the inbound and outbound communi-
cation channels possible for the collection of sensitive
personal and protected health and other information.
Systems such as a company website that tracks personal
data will most likely now have “Privacy Disclosures”
with references to contact their corporate legal group
with any further questions.
Other areas to consider where data can be obtained
and stored which should have policies in place docu-
menting protection measures include company phone
lines, fax, email addresses, corporate databases such as
the safety database or Medical Information Call Cen-
ter (MICC), and online media sources such as product
websites and social media pages.
A note on Record Retention:
Companies must implement procedures which docu-
ment the use and retention of personal drives, network
folders, and e-Mailboxes such that it is clear how the
network is accessed, by who, and for how long data
is retained. There are a variety of laws which required
MAHs to retain relevant records pertaining to the
development of a product and companies should dis-
close these obligations to the public as it pertains to
the records and maintenance of their data. MAHs must
retain PV data for at least 10 years after that product is
no longer on the EU market unless stricter local require-
ments apply. For example, Finland requires that AEs
gathered in Finland be kept for 50 years after the mar-
keting authorization expires; this requirement applies
to data gathered from Finland and from occurrences
that took place in Finland. Different rules apply outside
the EU; e.g., Health Canada requires keeping individual
reports for 25 years from case creation.

Frequently Asked Question

Q: This is rather complex. How should compa-
nies handle this?
A: Clearly internal legal and regulatory expertise and
communication must be in place to cover and protect
data and patients in all jurisdictions involved. If the
company cannot handle this internally, external assis-
tance must be used. There is little tolerance, by both
governments and individuals, for breaches in data pri-
vacy and protection. In addition, attention must be
paid to external vendors (e.g., server parks, archiving
companies) who also handle the data. Many companies
have established a data protection office headed by a
Chief Data Privacy Officer.
CHAPTER
389
36
Children, Elderly,
and Other Special
(Vulnerable) Groups
S
imilar to the testing of new drugs
in pregnant women, the testing
of drugs in special (“vulnerable”)
groups pose unique challenges. Special
groups include children, neonates, and
the elderly as well as other groups with
specific disease states, genetic condi-
tions, and, sometimes controversially,
various ethnic, racial, or religious back-
grounds. The question here is whether
the presence of the “special” condition
alters the effects of the drug and pro-
duces more or different adverse events
(AEs). The benefit–risk balance of a
product may be different in these dif-
ferent groups, particularly if cognitive
challenges adversely impact the con-
sent process.

The Theory

Children

Children are a special group because they are not sim-
ply “small adults” but rather are (depending on age and
other factors) biologic beings, who absorb, distribute,
metabolize, and excrete drugs differently from adults.
This can change over time in an individual as organs
mature.
Key documents on pediatric drug development
have been developed by the International Council for
Harmonization (ICH):
(a) The “E11 Guideline: Clinical Investigation of
Medicinal Products in the Pediatric Population”
(2000):
(b) The “Addendum to ICH E11: Clinical Investi-
gation of Medicinal Products in the Pediatric
Population E11(R1)” (2017) with an associated
FDA guidance in 2018
(c) “Pediatric Extrapolation”.