I have submitted a public comment to the FDA concerning the growing use of patient-specific algorithmic risk scores in clinical care, with NarxCare as an important case study.
A risk score is a number generated from selected information about a patient to estimate the likelihood of a particular outcome. Risk scores are used throughout medicine to estimate the chances of cardiovascular disease, stroke, cancer, surgical complications, hospital readmission, and other outcomes. When properly validated, transparent, and applied to a clearly defined outcome, they can support clinical judgment and informed discussions with patients.
NarxCare is a clinical decision-support platform that analyzes controlled-substance prescription histories obtained from state prescription drug monitoring programs. It presents clinicians and pharmacists with visualizations and numerical scores—including an “Overdose Risk Score”—intended to identify prescription patterns that may warrant further evaluation. Its reach is substantial: according to its developer, NarxCare is used in more than 20 states and by five of the six largest retail pharmacy companies. (Bamboo Health)
The FDA invited comments as it prepares its congressionally required 2026 report on software functions excluded from the definition of a medical device under the 21st Century Cures Act. The agency requested information about the risks and benefits of these “non-device” software functions, their effects on patient safety, and best practices for promoting safety, education, and user competency. The request specifically includes certain forms of clinical decision-support software. (FDA)
My concern is not with risk assessment itself. Clinical decision-support software can help clinicians recognize patients who may need additional evaluation, monitoring, education, or preventive interventions. But a score that can materially influence care must be transparent in how it is derived. Clinicians and patients should be able to determine what the score means, why a patient received it, how accurately it performs, what important information it omits, and what clinical action—if any—should follow.
An “Overdose Risk Score,” for example, may appear to predict whether an individual patient will overdose. Yet NarxCare’s developer states that the score is not an individual prediction of future overdose. It is a statistical comparison based on characteristics found in prescription drug monitoring program data. That distinction can easily be lost when a seemingly precise three-digit number appears prominently in a clinician’s workflow.
My comment asks the FDA to require clearly defined outcomes, clinically meaningful transparency, independent external validation, communication of uncertainty, and safeguards against automation bias—the tendency to place too much trust in a computer-generated result. It also emphasizes that predictive validity is not the same as clinical usefulness. Even an accurate statistical association does not establish that opioids should be reduced, withheld, or discontinued.
The FDA should also examine how these systems affect access to care. Risk scores may contribute to involuntary tapering, medication denial, patient dismissal, pharmacy refusal, or clinicians’ reluctance to care for medically complex patients.
Risk assessment should help clinicians ask better questions—not convert uncertainty into an authoritative number. A risk score should never acquire more authority than the evidence supporting it.
Read my complete FDA comment here. https://www.regulations.gov/comment/FDA-2018-N-1910-0342

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.