Literature searchClinical evaluationEU MDRMEDDEV 2.7/1MDCG 2020-13PRISMA

Literature search protocol for medical devices: what MEDDEV 2.7/1 Rev. 4 actually requires

Hatem RabehCo-founder, clinical evaluation expert9 min read

A literature search protocol for a medical device states what you will look for, where, and how you will decide what counts, written before you run a single query. MEDDEV 2.7/1 Rev. 4 puts it plainly: "The purpose of a literature search protocol is to plan the search before execution."

It is also the document most often written last, reconstructed from what the search returned. That is the version an assessor recognises immediately, because the protocol matches the results too neatly and the counts never quite reconcile.

Appendix A5 of MEDDEV 2.7/1 Rev. 4 sets out what the protocol has to contain, in three parts. Most of the protocols that come back with deficiencies are not missing the search strings. They are missing the justifications and the plans that sit around them.

Why it is written before the search, not after

The protocol exists to fix your decisions while you can still make them honestly. Once you have seen the results, every choice about databases, date ranges and exclusion criteria is made knowing what it will include or remove, and a criterion chosen for its effect on the outcome is not a criterion, it is a filter.

The protocol and the report are two documents for this reason: one states the plan, the other reports what happened. MEDDEV is explicit about the join between them: "Any deviations from the literature search protocol should be noted in the literature search report." A change is not a problem. An undocumented change is.

MEDDEV also expects the protocol to be "developed and executed by persons with expertise in information retrieval". If nobody on the file has that background, that is worth addressing before the search, not defending after it.

A5.1 Background: why this review exists

The first part documents the importance of and the rationale for the literature review. It is short, and it is routinely skipped, which makes the protocol read as though it began at the search string.

  • The device name and model.
  • The importance of the literature review to the risk management process. This is the link an assessor looks for: the review feeds the benefit/risk determination and what counts as acceptable side effects.
  • Previous literature reviews.
  • Previous literature searches conducted by the manufacturer.
  • If equivalent or benchmark devices are included, their name and model.

A5.2 Objective: the review question, built with PICO

The objective documents the research questions, and MEDDEV names the method: they "should be consistent with the scope of the clinical evaluation and carefully constructed using a process (e.g. PICO)". PICO gives you four things to state.

The inputs to those questions are the device description and the intended performance, including any clinical claims the manufacturer wants to make, plus the risk management output. A review question written without the risk file will miss the hazards the review is supposed to inform.

  • Population, disease or condition.
  • Intervention, which covers therapies, diagnostic measures and measures for managing a disease or condition.
  • Comparator group or control.
  • Outcomes and endpoints.

A5.3 Methods: the fourteen items

This is the part most people mean when they say "protocol", and it is longer than most protocols are. MEDDEV lists fourteen items. Every one has to be specific enough that somebody else could execute it and land on the same set of articles.

  • The literature search methodology, based on carefully constructed review questions.
  • The sources of data to be used, and a justification for choosing them.
  • The extent of any searches of scientific literature databases, meaning the database search strategy.
  • Attempts to identify all published literature.
  • Which electronic databases are to be searched, with justification. MEDLINE and Embase are the usual pair; naming only one invites the question of what the other would have returned.
  • The extent of any Internet searching and searching of non-published information, with the strategy and its justification.
  • Exact search terms and any limits.
  • Limits for the start and end dates of each search.
  • The selection criteria, such as inclusion and exclusion criteria, and a justification for choosing them.
  • Strategies for addressing the potential for duplication of data across multiple publications.
  • Strategies for avoiding retrieving publications of data the manufacturer already holds and generated itself.
  • The data collection plan, defining the data management practices that keep data intact during extraction, for example a quality control or second review of extracted data by an additional reviewer.
  • The appraisal plan, defining how each publication will be appraised, covering both its relevance to the intended clinical use and its methodological quality.
  • The analysis plan, defining how the data will be analysed, including processing and transformation.

The four that are usually missing

Across the protocols that come back with questions, the same four gaps recur. None of them is difficult; they are simply not in the template most people started from.

The word "justification" appears three separate times in A5.3, attached to the sources, the databases, the Internet searching and the selection criteria. A protocol that lists PubMed and Embase without saying why those two, and why not a third, has answered half of each item.

The strategy for data the manufacturer already holds is the one almost nobody writes. Your own study, published by your own investigators, can arrive back through the database search and be counted as independent evidence. Saying how you will spot and handle that is a required element, and it is also the difference between a clean evidence base and a circular one.

The data collection plan and the analysis plan are required in the protocol, not invented at extraction time. If a second reviewer checks extracted values, say so before the extraction, because doing it afterwards is not quality control, it is a correction.

What the assessor is checking: MDCG 2020-13 Section D

MEDDEV tells you what to write. MDCG 2020-13, the clinical evaluation assessment report template a notified body completes, tells you what will be done with it once written. Section D covers the clinical literature review, and its footnote on the literature search protocol points straight back at MEDDEV Appendix A5.

The assessor is asked to summarise your search strategy and comment on a specific set of points. Reading them as a pre-submission checklist is the cheapest review you will ever get.

  • Whether the search terms are broad enough to establish benchmarks, the general state of the art, potential risks and adverse events. The template is blunt about the failure case: a search restricted to the manufacturer’s own product or its chosen equivalent "could miss important information and therefore is not acceptable".
  • The databases used, with the explicit note that multiple databases should be used to minimise bias.
  • Whether the inclusion and exclusion criteria are acceptable.
  • Whether both favourable and unfavourable data were included.
  • The strategies for avoiding duplication of data, both across different publications and between manufacturer and published data.
  • How the manufacturer tested the protocol to demonstrate that all relevant data was actually retrieved.
  • Any deviations from the literature search protocol.
  • Whether a systematic method was used, with PICO, the Cochrane Handbook for Systematic Reviews of Interventions, PRISMA and the MOOSE proposal named as the examples.

Write criteria somebody else can apply

The most common weakness is criteria that read well and cannot be applied. "Studies of poor methodological quality will be excluded" is not applicable: it names no threshold and no instrument. "Case series with fewer than ten patients" is applicable, and it can be checked against the PRISMA counts.

A useful test before the protocol is final: hand the criteria and twenty abstracts to a colleague who did not write them. Where the two of you disagree is where the criterion is ambiguous, and it is much cheaper to find that now than in a deficiency letter.

Keep selection and appraisal apart while you are at it. Selection decides whether a paper enters the pool. Appraisal weighs what it contributes once it is in. Collapsing the two produces a protocol that excludes papers for being unconvincing, which is a judgement made at the wrong stage.

Keep the counts reconcilable from the first query to the final table

The PRISMA flow diagram is where a protocol either holds together or falls apart. Every number in it has to be traceable: records identified per source, duplicates removed, records screened on title and abstract, full texts assessed, studies included, and exclusions with reasons at the full-text stage.

The failure mode is arithmetic, not judgement. Numbers that do not add up tell a reviewer that the flow was assembled after the fact from separate spreadsheets, and once that is visible, the appraisal underneath it gets read with suspicion. Record the count at each step as you take it, not at the end.

Plan the update before you need it

A clinical evaluation is not finished when the report is signed. The protocol should say when the search will be repeated, and repeating it means running the same strings against the same sources with a new date range, then reporting the delta.

If the strings were not recorded verbatim the first time, the update is not an update; it is a new search that happens to cover a similar topic, and the comparison between the two is worth very little.

The short version

Write it first. Cover all three parts of Appendix A5, not only the methods. Justify the sources, the databases and the criteria, because the justification is the required part. Say how you will handle data you already own. Write criteria two people apply the same way. Record each count as you go. Say when you will do it again.

None of this makes the review shorter. It makes it defensible, which is the part that decides whether the work you already did survives review.

Common questions

What is a literature search protocol for a medical device?
It is the document that defines the objective, the sources, the search strategy and the selection, appraisal and analysis methods for a clinical evaluation literature review, written before the search is run. MEDDEV 2.7/1 Rev. 4 Appendix A5 sets its required contents in three parts: background, objective and methods.
Is the literature search protocol the same as the literature search report?
No. The protocol states the plan before the search; the report states what actually happened when it ran. MEDDEV 2.7/1 Rev. 4 requires that any deviations from the protocol be noted in the report, which is only possible if the two are separate documents written at different times.
Does MEDDEV 2.7/1 Rev. 4 require PICO?
It requires the research questions to be carefully constructed using a process, and names PICO as an example rather than the only permitted method. In practice PICO is the expected structure, and stating population, intervention, comparator and outcomes explicitly is the simplest way to show the question was constructed rather than assembled from the search terms.
Which databases should a medical device literature search cover?
MEDDEV does not prescribe a list. It requires that you state which electronic databases will be searched and justify the choice. MEDLINE and Embase are the common pair because their coverage differs, and a search of only one leaves the gap between them unaddressed. The justification is the required element, not any particular database.
How many items does Appendix A5.3 require in the methods section?
Fourteen. They run from the search methodology and the justified choice of sources and databases through the exact search terms and date limits, the selection criteria and their justification, the strategies for duplicate data and for data the manufacturer already holds, to the data collection plan, the appraisal plan and the analysis plan.
Does the notified body assess the literature search protocol itself?
Yes. MDCG 2020-13, the clinical evaluation assessment report template, gives assessors a dedicated section on the clinical literature review. They are asked to comment on the adequacy of the search terms, the databases used, the inclusion and exclusion criteria, whether unfavourable data was included, the handling of duplicate data, any deviations from the protocol, and whether a systematic method such as PICO or PRISMA was applied.
What happens if the search has to deviate from the protocol?
Nothing, provided it is documented. MEDDEV 2.7/1 Rev. 4 states that any deviations from the literature search protocol should be noted in the literature search report. A documented change is a normal part of executing a search; an undocumented one is what makes a reviewer question the rest of the method.