Electronic system for a medical device, a medical device equipped with such an electronic system, an external device for communicating with the electronic system, a method for exchanging data between a medical device and an external device, and corresponding machine-readable code and a data storage medium containing such code

JP2024535903A5Pending Publication Date: 2025-10-01SANOFI SA(FR)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024518319
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-09-24
Filing Date
2022-09-22
Publication Date
2025-10-01

AI Technical Summary

Technical Problem

Medical devices, particularly handheld infusion devices and blood glucose measuring devices, face challenges with bulkiness and high power consumption due to the need for user interfaces and embedded electronics to record and store medical data, limiting memory and increasing power usage.

Method used

An electronic system for medical devices that transmits and stores data externally, reducing the need for on-device user interfaces and incorporating a memory unit with non-volatile storage, and a communication unit for wireless or wired data transfer, allowing remote data management and lower power consumption.

Benefits of technology

This system enables sophisticated, compact medical devices with reduced power consumption and enhanced data management capabilities by offloading data processing to external devices, optimizing memory usage and power efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Electronic system for a medical device, a medical device comprising such an electronic system, an external device for communicating with the electronic system, a method for exchanging data between the medical device and the external device, as well as corresponding machine-readable code and a data storage medium comprising such code.Proposed is an electronic system for recording medical data for a medical device, comprising an electronic control unit configured for transmitting the medical data to an external device and / or for storing the medical data, the electronic control unit (12) being configured for calculating a data integrity value (C) based on the medical data (B) and at least one additional data (A) not comprised in the medical data, the electronic control unit being configured for transmitting the data integrity value to the external device and / or for storing the data integrity value in correlation with the medical data.
Need to check novelty before this filing date? Find Prior Art

Description

[Background technology]

[0001] Medical devices, especially injection devices (e.g. pen-type or automatic injectors), blood pressure measuring devices, blood glucose measuring devices, pulse measuring devices, electrocardiogram devices, etc., are known to measure medical data and record them. The recorded data is accessible via a user interface on the medical device. This leads to bulky medical devices, especially when the medical device is a handheld device, resulting in high power consumption. Also, users often use smartphones to centralize their personal data.

[0002] Needle-Based Injection System (NIS) devices are used by patients to conveniently perform frequent (e.g., subcutaneous) injections, such as, for example, insulin for diabetics. These NIS devices usually have a mechanism for selecting the dose of drug to be injected within certain limits, i.e., the dose to be injected can be varied within these limits. Modern NIS devices include electronics to measure and / or detect the selected and / or injected dose and then store it in an internal memory.

[0003] In small electromechanical medical devices designed to record, store, and possibly transmit diagnostic or therapeutic data (e.g., blood glucose levels, insulin units dispensed, etc.), the embedded electronics impose limitations on the memory space available for these records. Summary of the Invention [Means for solving the problem]

[0004] An electronic system for recording medical data for a medical device (e.g. an infusion device), e.g. medical data of or related to a medical device, is proposed, the medical device comprising an electronic control unit configured to transmit and / or store the medical data to an external device. This allows for an elegant design of the medical device, where the data can be viewed and managed remotely from the external device. User interfaces on the medical device can for example be reduced in number and / or functionality. This also allows for lower power consumption, since there is no need to power the user interface to display the collected data. These data transmissions can include data on recent events performed by the medical device.

[0005] The electronic control unit may comprise a memory unit for storing the medical data. The memory unit may comprise a non-volatile memory to save power consumption. The memory unit may include, for example, a flash memory, or an electrically erasable memory (such as a NAND flash memory, a NOR flash memory, an EEPROM (electronically erasable programmable memory), a NVRAM (non-volatile random access memory), or other suitable memory. Alternatively, the memory unit may comprise a volatile memory unit that requires a constant power supply to maintain the stored data. The electronic control unit and the memory unit may or may not be formed by a single integrated circuit. The electronic control unit may comprise an application specific integrated circuit (ASIC). Alternatively, the electronic control unit may comprise a processing unit for executing the machine-readable code stored in the memory unit. The machine-readable code may be stored in a read-only memory of the memory unit. The machine-readable code may be stored in a rewritable memory to allow updates. Alternatively, the machine-readable code may be stored in the same memory as the medical data.

[0006] The electronic system may comprise a communication unit for transmitting data to an external device. In this specification, "transmitting data" may mean providing an instruction to the communication unit to transmit data. The electronic control unit and the communication unit may or may not be formed by a single integrated circuit. The communication unit may be, for example, a wireless communication unit based on Bluetooth Low Energy (BLE) technology, Bluetooth technology, NFC technology (Near Field Communication), IEEE 802.11 (Wi-Fi) technology, or other wireless transmission technology.

[0007] Alternatively, the communication unit may be a wire-based communication unit based on Universal Serial Bus (USB) technology, Lightning technology, Thunderbolt technology or other serial or parallel transmission technology. The wire-based communication unit may comprise an (electromechanical) interface, e.g. a plug or socket, for providing connectivity to an external device.

[0008] The external device may be a general-purpose device, such as a PC or a smartphone, that executes dedicated machine-readable code for communicating with the electronic system, or it may be a dedicated device, such as a specialized device whose only purpose is to communicate with one or more electronic systems and collect respective data. The external device may be a user terminal device. The external device may be a handheld device or a stationary device.

[0009] As used herein, an electronic control unit being "configured" to perform a task may mean that it is specifically programmed and / or has particular circuitry to perform that task. During its operation, the control unit is capable of performing the task.

[0010] According to a further embodiment, the electronic control unit is configured to calculate a data integrity value based on the medical data and at least one additional data not included in the medical data, and the electronic control unit is configured to transmit the data integrity value to an external device and / or store the data integrity value in correlation with the medical data. This allows detection of errors in the stored or transmitted medical data. Depending on the method used for the calculation, this may also allow correction of erroneous data. Furthermore, this allows reducing the amount of data that needs to be stored or transmitted in correlation with the medical data, since the additional data does not need to be explicitly transmitted or stored. This allows the use of smaller memory units (memory units that store less data) and / or the recording of more data in the same memory unit. This may also reduce power consumption. For safety reasons, it is important to include all necessary information in the medical data record to avoid possible harmful ambiguities.

[0011] "Data" (eg, additional data) may refer to multiple pieces of data or to a single piece of data.

[0012] The data integrity value may be calculated according to a function that is at least sensitive to changing any single bit of the data used in the calculation. The function being "sensitive" may mean that any bit of the data used in the calculation, if flipped, will give a different or unique result than if the calculation was performed on the original data. The function may be sensitive to changes in 2, 3, 4, 5, 6, 7, 8 or more bits of data. The data integrity value may be calculated according to a hash function, according to a cyclic redundancy check (CRC) method, or may be a checksum. The data integrity value may also be a signature type control value. Asymmetric encryption methods may be used. When calculating the data integrity value, the data integrity value may be encrypted, for example, with a private encryption key known only to the electronic system, while the external device can decrypt the verification data using the corresponding public encryption key. Medical data may also be encrypted (signed) by this method. This also ensures data integrity, but also includes cryptographic information (usually to verify the origin or creator of the data).

[0013] In this specification, "correlated transmission" may mean that the data integrity value and the medical data form a data package transmitted in a single transmission session, for example in a continuous data stream, or in multiple consecutive transmission sessions, in which later transmissions include an identifier to reference earlier data transmissions in order to correlate the data integrity value with the respective medical data. In other words, after transmission, the data integrity value and the medical data can (still) be correlated.

[0014] As used herein, "correlatedly storing" may mean that the data consistency values ​​and the medical data form a data set. The medical data and the data consistency values ​​may be stored in a manner that represents a table. Multiple sets of medical data and corresponding data consistency values ​​may be stored in a single table or table-like data structure.

[0015] According to another embodiment, the electronic control unit may be configured not to transmit the additional data and / or not to store the additional data in correlation with the medical data. The additional data may be stored or transmitted separately. The additional data may be transmitted, for example, in another communication session or data stream, preferably without reference to the data stream transmitting the medical data or vice versa. The additional data may be stored outside the data set or table containing the medical data and the respective data integrity value. The additional data may be general data that is stored or transmitted only once, for example, when pairing the medical device with the external device. In further cases, at least a part of the additional data is never transmitted explicitly or separately to the external device. The additional data may be data that is already known to the external device and / or data that can be deduced by the external device.

[0016] According to further embodiments, the additional data is or includes at least one of a medical data storage location identifier, a device identifier, a device type identifier, a patient identifier, a treatment identifier, a medication identifier, or a conversion factor identifier. The additional data may be inferred from other information (e.g., a serial record number and / or a storage location identifier). The additional data may be static (e.g., a patient identifier, a type of medication, a unit of measure, etc.). The additional data may be within a small range of values ​​(easily inferable).

[0017] The storage location identifier may be a record number that identifies the location, e.g., a column or row, of the medical data in a data structure, e.g., a table. Successively recorded medical data may be associated with successive integer values. The Nth recorded medical data may be stored in the Nth row of the table representation of the data structure used.

[0018] A device identifier can be a data value, such as an alphanumeric string, to uniquely identify a device among all devices of the same type, from the same manufacturer, and / or manufactured worldwide.

[0019] A device type identifier may be data that describes characteristics of a device, such as size, color, capacity, and / or available features.

[0020] The patient identifier may be data representing the patient's name or nickname, or an associated number or alphanumeric identifier. The patient identifier may also include location or address information for "lost and found" scenarios.

[0021] The treatment identifier may be data representing a particular schedule for use of the medical device. The electronic system may include an alarm unit to remind the user of the schedule.

[0022] A medication identifier may be data that represents a medication or type of medication that is present in a medical device.

[0023] The conversion factor identifier may be data representing one or more units of measurement used for the medical data. The medical data may be stored and / or transmitted as purely numerical values, such as integers, floating point numbers, or strings. The conversion factor identifier may enable the translation or conversion of the medical data from purely numerical values ​​to true physical quantities. The conversion factor identifier may include a representation of a unit of measurement and / or a numerical factor. The units of measurement may be m (meters), kg (kilograms), s (seconds), min (minutes), h (hours), V (volts), A (amperes), cm (cm), ... 3 (cubic centimeter), l (liter), hPa (hectopascal), mmHg (millimeter of mercury), or composite or derived units thereof, or the corresponding units of the imperial measurement system. Alternatively, the measurement unit may be the International Unit (IU) for the dosage of a medicine, for example insulin. The measurement unit may include a prefix to set the dimension of the measurement unit, for example m (milli), μ (micro), n (nano), k (kilo), M (mega), G (giga), T (tera). The numerical coefficient may be 1 or another value, for example a conversion coefficient between the respective measurement units in the SI or imperial system.

[0024] According to further embodiments, the electronic system comprises at least one detector unit, and the electronic control unit is configured to obtain medical data based on the readings of the detector unit. Additionally or alternatively, the electronic system comprises an electromechanical interface coupled to the medical device, and the medical device may comprise one or more sensors coupled to the detector unit. The electronic system and the sensor unit may be separate units electrically connected to each other or may be part of a single integrated unit. The detector unit may comprise an electronic clock, e.g. a real-time clock (RTC) and / or a counter that counts a certain time interval from a known point in time or since initialization. The detector unit may comprise at least one sensor for detecting or measuring a physical quantity, e.g. current, voltage, resistance, velocity, angular momentum, light intensity, magnetic flux, relative position (distance or angular distance / difference), chemical concentration or composition, pressure, etc.

[0025] The electronic system may further comprise a cell or battery unit, for example a rechargeable or non-rechargeable cell or battery unit, for powering the electronic control unit, the memory unit, the communication unit and / or the detector unit.

[0026] According to another embodiment, the medical data includes at least time information and / or measurements. The medical data may consist of only time information and one or more related measurements, for example a single measurement, such as a value characterizing the size of a dispensed dose. The time information may be information indicating a specific date and / or time, or an amount of time that has passed since a known point in time or since initialization of the device. The measurements may be values ​​and / or calculated values ​​associated with sensor data from the detector unit, or may be the sensor data. The control unit may be configured to evaluate the sensor data and determine the measurement from a single sensor value or a series of sensor values. The time information may be time information associated with a time at which the measurement data, or the sensor data for determining the measurement data, was collected.

[0027] The medical device may be a drug delivery device or an infusion device. The medical data may be, for example, dosage information, including dosage information (such as information regarding the dose of medicinal product dispensed by the device in one dispensing operation) and time information (such as the time when the dispensing operation to dispense the dose occurred). The dosage information may be the amount of medicinal product expelled from the medical device. The dosage information may be determined from the distance that a plunger of the medical device has traveled relative to a container for the medicinal product, such as a cartridge or a syringe. The distance that the plunger has traveled may be detected from the plunger itself or from the movement, in particular the rotation, of any other part of the drive mechanism that drives the plunger. This also provides the option of a semi-automated treatment recording mechanism (dosage diary).

[0028] According to a further embodiment, the electronic control unit is configured to transmit non-medical data to an external device. The non-medical data may in particular include a device identifier of the medical device. Alternatively or additionally, the non-medical data may include a current time value, a device type identifier, a patient identifier, a treatment identifier, a medication identifier, and / or a conversion factor identifier.

[0029] The electronic control unit may be configured to transmit data, e.g., medical or non-medical data, upon, and in particular only upon, receipt of a request from an external device, which may reduce power consumption and / or allow for on-demand requests by the external device.

[0030] Furthermore, a medical device, in particular a needle-based injection device and / or a pen-type device, comprising the above-described electronic system is proposed, the pen-type device having a shape similar to a pen, for example a fountain pen, thereby allowing easy handling of the medical device by the user, such as for self-administration.

[0031] Also proposed is a medical device, in particular a (needle-based) injection device and / or a pen-type device, with an (electromechanical) interface adapted to be coupled with such an electronic system. The medical device is advantageously a drug delivery device. The electronic system may comprise a housing with an (electromechanical or purely mechanical) interface for coupling with the medical device. The interface between the housing and the medical device may each comprise electrical contacts for electrically connecting an electrical control unit and / or a detector unit of the electronic system with sensing means integrated in the medical device. Alternatively, the sensing means may be integrated in the electronic system. All electronic components may be incorporated in the electronic system. In such a modular system, the electronic system may be reused after the medical device is replaced with a new one, for example after the stored medicine has been used up or after the device has become defective or reached an otherwise determined "end of usability", thereby reducing costs. As an alternative to a medical device that may be releasably coupled with the electronic system, the electronic system may be an integral component of the medical device.

[0032] Alternatively, the medical device may be a device for measuring blood glucose level, blood pressure, pulse rate, oxygen concentration, body or skin temperature, electrocardiogram, or other medical data. The medical device and / or electronic system may be configured to perform measurements (obtaining medical data) in a regular but infrequent manner, for example several times a day.

[0033] The (needle-based) injection device may comprise a drive mechanism including an energy buffer. The energy buffer may be pre-charged or may be charged upon setting of a dose, such as by a user. The energy buffer may be a spring, e.g., a torsion or compression spring, a compartment of compressed gas, e.g., air, an electric cell or battery for driving an electric motor, and / or other suitable means. Alternatively, the device may be a manually driven, e.g., user-driven, device.

[0034] The medical device may include at least one container filled with a pharmaceutical agent, or a receptacle for receiving such a container. The container may include sufficient amounts of pharmaceutical agent for multiple doses to be dispensed by the device.

[0035] If the electronic system is integrated in the device and if the device is a drug delivery device, the device can preferably be used with multiple containers. In other words, the device can be a reusable device. Of course, the electronic system as an add-on module can also be used with a reusable medical device. The user only needs to replace the emptied container in the receptacle with a new one and reconnect the receptacle to the drive mechanism of the device.

[0036] The medical device may be a variable dose device, in which the size of the dose of medicinal product to be delivered may be set within a range defined by a mechanism of the device.

[0037] The terms "drug" or "medication" are used interchangeably herein to describe a pharmaceutical formulation containing one or more active pharmaceutical ingredients or pharma- ceutically acceptable salts or solvates thereof, and optionally a pharma- ceutically acceptable carrier. An active pharmaceutical ingredient ("API") is broadly defined as a chemical structure that has a biological effect on humans or animals. In pharmacology, drugs or medicines are used to treat, cure, prevent, or diagnose diseases, and to promote physical or mental well-being. Drugs or medicines may be used for a limited period of time or on a regular basis for chronic conditions.

[0038] As described below, a drug or pharmaceutical product can include at least one API, or a combination thereof, in various types of formulations for the treatment of one or more diseases. Examples of APIs can include small molecules with a molecular weight of 500 Da or less, polypeptides, peptides, proteins (e.g., hormones, growth factors, antibodies, antibody fragments, enzymes, etc.), carbohydrates and polysaccharides, as well as nucleic acids, double-stranded or single-stranded DNA (including naked and cDNA), RNA, antisense nucleic acids such as antisense DNA and RNA, small interfering RNA (siRNA), ribozymes, genes, and oligonucleotides. Nucleic acids can be incorporated into molecular delivery systems such as vectors, plasmids, liposomes, etc. Mixtures of one or more drugs are also contemplated.

[0039] The drug or pharmaceutical agent may be included in a primary package or "drug container" adapted for use with a drug delivery device. The drug container may be, for example, a cartridge, syringe, reservoir, or other solid or flexible container configured to provide a chamber suitable for storage (e.g., short-term or long-term storage) of one or more drugs. For example, in some embodiments, the chamber may be designed to store the drug for at least one day (e.g., 1 day to at least 30 days). In some embodiments, the chamber may be designed to store the drug for about one month to about two years. Storage may be at room temperature (e.g., about 20° C.) or at refrigerated temperatures (e.g., about −4° C. to about 4° C.). In some embodiments, the drug container may be or include a dual-chamber cartridge configured to separately store two or more components of a pharmaceutical formulation to be administered (e.g., an API and a diluent, or two different drugs), one in each chamber. In such cases, the two chambers of the dual-chamber cartridge may be configured to allow mixing between the two or more components prior to and / or during dispensing into the human or animal body. For example, the two chambers may be configured to be in fluid communication with one another (e.g., by a conduit between the two chambers) and may allow a user to mix the two components if desired prior to dispensing. Alternatively or additionally, the two chambers may be configured to allow mixing when the components are dispensed into the human or animal body.

[0040] The drugs or pharmaceuticals contained in the drug delivery devices described herein may be used for the treatment and / or prevention of many different types of medical disorders. Examples of disorders include, for example, diabetes or complications related to diabetes, such as diabetic retinopathy, thromboembolic disorders, such as deep vein thromboembolism or pulmonary thromboembolism. Further examples of disorders include acute coronary syndromes (ACS), angina pectoris, myocardial infarction, cancer, macular degeneration, inflammation, hay fever, atherosclerosis, and / or rheumatoid arthritis. Examples of drug substances and drugs are those found in handbooks such as the Rote Liste 2014, including, but not limited to, those found in major groups 12 (antidiabetic drugs) or 86 (oncology drugs), and the Merck Index 15th Edition.

[0041] Examples of APIs for the treatment and / or prevention of type 1 or type 2 diabetes, or complications associated with type 1 or type 2 diabetes, include insulin, e.g., human insulin, or a human insulin analog or derivative, glucagon-like peptide (GLP-1), a GLP-1 analog or GLP-1 receptor agonist, or an analog or derivative thereof, a dipeptidyl peptidase-4 (DPP4) inhibitor, or a pharma-ceutically acceptable salt or solvate thereof, or a mixture thereof. As used herein, the terms "analog" and "derivative" refer to a polypeptide having a molecular structure that can be formally derived from the structure of a naturally occurring peptide, e.g., human insulin, by replacing and / or replacing at least one amino acid residue present in the naturally occurring peptide and / or by adding at least one amino acid residue. The added and / or replaced amino acid residue can be either a codable amino acid residue or other naturally occurring residue, or a purely synthetic amino acid residue. Insulin analogs are also referred to as "insulin receptor ligands". In particular, the term "derivative" refers to a polypeptide having a molecular structure that can be formally derived from the structure of a naturally occurring peptide, e.g., human insulin, in which one or more organic substituents (e.g., fatty acids) are attached to one or more amino acids. Optionally, one or more amino acids present in the naturally occurring peptide may be deleted and / or substituted with other amino acids, including non-codeable amino acids, or amino acids, including non-codeable amino acids, may be added to the naturally occurring peptide.

[0042] Examples of insulin analogues are Gly(A21), Arg(B31), Arg(B32) human insulin (insulin glargine), Lys(B3), Glu(B29) human insulin (insulin glargine), Lys(B28), Pro(B29) human insulin (insulin lispro), Asp(B28) human insulin (insulin aspart), human insulin in which the proline at position B28 may be replaced by Asp, Lys, Leu, Val or Ala and the Lys at position B29 may be replaced by Pro, Ala(B26) human insulin, Des(B28-B30) human insulin, Des(B27) human insulin, and Des(B30) human insulin.

[0043] Examples of insulin derivatives are e.g. B29-N-myristoyl-des(B30) human insulin, Lys(B29)(N-tetradecanoyl)-des(B30) human insulin (insulin detemir, Levemir®), B29-N-palmitoyl-des(B30) human insulin, B29-N-myristoyl human insulin, B29-N-palmitoyl human insulin, B28-N-myristoyl LysB28ProB29 human insulin, B28-N-palmitoyl-LysB28ProB29 human insulin, B30-N-myristoyl-ThrB29LysB30 human insulin. insulin, B30-N-palmitoyl-ThrB29LysB30 human insulin, B29-N-(N-palmitoyl-gamma-glutamyl)-des(B30) human insulin, B29-N-omega-carboxypentadecanoyl-gamma-L-glutamyl-des(B30) human insulin (insulin degludec, Tresiba®), B29-N-(N-lithocholyl-gamma-glutamyl)-des(B30) human insulin, B29-N-(ω-carboxyheptadecanoyl)-des(B30) human insulin, and B29-N-(ω-carboxyheptadecanoyl) human insulin.

[0044] Examples of GLP-1, GLP-1 analogs and GLP-1 receptor agonists include, for example, Lixisenatide (Lyxumia®), Exenatide (Exendin-4, Byetta®, Bydureon®, a 39 amino acid peptide produced by the salivary glands of the Gila Monster), Liraglutide (Victoza®), Semaglutide, Taspoglutide, Albiglutide (Syncria®), Dulaglutide (Trulicity®), rExendin-4, CJC-1134-PC, PB-1023, TTP-054, Langlenatide / HM-11260C (Efpeglenatide), HM-15211, CM-3, GLP-1 Eligen, ORMD-0901, NN-9423, NN-9709, NN-9924, NN-9926, NN-9927, Nodexen, Viador-GLP-1, CVX-096, ZYOG-1, ZYD-1, GSK-2374697, DA-3091, MAR-701, MAR709, ZP-2929, ZP-3022, ZP-DI-7 0.

[0045] An example of an oligonucleotide is, for example, mipomersen sodium (Kynamro®), a cholesterol-lowering antisense therapeutic for the treatment of familial hypercholesterolemia, or RG012 for the treatment of Alport Syndrome.

[0046] Examples of DPP4 inhibitors are linagliptin, vildagliptin, sitagliptin, denagliptin, saxagliptin, berberine.

[0047] Examples of hormones include hypothalamic hormones or regulatory active peptides and their antagonists, such as gonadotropins (Follitropin, Lutropin, Choriongonadotropin, Menotropin), somatropin, desmopressin, terlipressin, gonadorelin, triptorelin, leuprorelin, buserelin, nafarelin, and goserelin.

[0048] Examples of polysaccharides include glycosaminoglycans, hyaluronic acid, heparin, low molecular weight heparin or very low molecular weight heparin or derivatives thereof, or sulfated polysaccharides, such as the polysulfated forms of the above polysaccharides, and / or pharmaceutically acceptable salts thereof.An example of a pharmaceutically acceptable salt of polysulfated low molecular weight heparin is enoxaparin sodium.An example of a hyaluronic acid derivative is sodium hyaluronate Hylan GF 20 (Synvisc®).

[0049] The term "antibody" as used herein refers to an immunoglobulin molecule or an antigen-binding portion thereof. Examples of antigen-binding portions of an immunoglobulin molecule include F(ab) and F(ab')2 fragments that retain antigen-binding ability. An antibody can be a polyclonal antibody, a monoclonal antibody, a recombinant antibody, a chimeric antibody, a deimmunized antibody or a humanized antibody, a fully human antibody, a non-human antibody (e.g., a murine antibody), or a single chain antibody. In some embodiments, an antibody has effector function and can fix complement. In some embodiments, an antibody has reduced or no ability to bind to Fc receptors. For example, an antibody can be an isotype or subtype, an antibody fragment or a variant that does not support binding to Fc receptors, e.g., has a mutated or deleted Fc receptor binding region. The term antibody also includes antigen-binding molecules based on tetravalent bispecific tandem immunoglobulins (TBTIs) and / or dual variable region antibody-like binding proteins with crossover binding region orientation (CODV).

[0050] The term "fragment" or "antibody fragment" refers to a polypeptide derived from an antibody polypeptide molecule (e.g., an antibody heavy chain polypeptide and / or an antibody light chain polypeptide) that does not include the full-length antibody polypeptide, but includes at least a portion of the full-length antibody polypeptide that is still capable of binding to an antigen. An antibody fragment may include truncated portions of a full-length antibody polypeptide, but the term is not limited to such truncated fragments. Antibody fragments useful in the present invention include, for example, Fab fragments, F(ab')2 fragments, scFv (single-chain Fv) fragments, linear antibodies, mono- or multispecific antibody fragments such as bi-, tri-, tetra-, and multispecific antibodies (e.g., diabodies, triabodies, tetrabodies), mono- or multivalent antibody fragments such as bi-, tri-, tetra-, and multivalent antibodies, minibodies, chelating recombinant antibodies, tribodies or bibodies, intrabodies, nanobodies, small modular immunopharmaceuticals (SMIPs), binding domain immunoglobulin fusion proteins, camelized antibodies, VHH-containing antibodies, and the like. Additional examples of antigen-binding antibody fragments are known in the art.

[0051] The term "complementarity-determining region" or "CDR" refers to short polypeptide sequences within the variable regions of heavy and light chain polypeptides, which are primarily responsible for mediating specific antigen recognition. The term "framework region" refers to amino acid sequences within the variable regions of heavy and light chain polypeptides that are not CDR sequences, which are primarily responsible for maintaining the correct position of the CDR sequences to allow antigen binding. Although the framework region itself is usually not directly involved in antigen binding, as is known in the art, certain residues within the framework region of a particular antibody may be directly involved in antigen binding or may affect the ability of one or more amino acids within the CDRs to interact with the antigen.

[0052] Examples of antibodies are anti-PCSK-9 mAb (e.g., alirocumab), anti-IL-6 mAb (e.g., sarilumab), and anti-IL-4 mAb (e.g., dupilumab).

[0053] Pharmaceutically acceptable salts of any of the APIs described herein are also contemplated for use in the drug or pharmaceutical agent in the drug delivery device. Pharmaceutically acceptable salts include, for example, acid addition salts and base salts.

[0054] Those skilled in the art will appreciate that modifications (addition and / or removal) of the various components of the APIs, formulations, devices, methods, systems, and embodiments described herein may be made without departing from the full scope and spirit of the invention, which encompasses such modifications and all equivalents thereof.

[0055] Exemplary drug delivery devices may include needle-based injection systems as described in Table 1 of Section 5.2 of ISO 11608-1:2014(E). As described in ISO 11608-1:2014(E), needle-based injection systems may be broadly categorized into multi-dose container systems and single-dose (with partial or complete evacuation) container systems. The container may be an exchangeable container or an integrated non-exchangeable container.

[0056] As further described in ISO 11608-1:2014(E), a multi-dose container system may include a needle-based injection device with an exchangeable container. In such a system, each container holds multiple doses, the size of which may be fixed or variable (pre-set by the user). Another multi-dose container system may include a needle-based injection device integrated with a non-exchangeable container. In such a system, each container holds multiple doses, the size of which may be fixed or variable (pre-set by the user).

[0057] As further described in ISO 11608-1:2014(E), the single-dose container system may include a needle-based injection device with an exchangeable container. In one example of such a system, each container holds a single dose, which expels the entire deliverable volume (full expulsion). In a further example, each container holds a single dose, which expels a portion of the deliverable volume (partial expulsion). As also described in ISO 11608-1:2014(E), the single-dose container system may include a needle-based injection device with an integrated non-exchangeable container. In one example of such a system, each container holds a single dose, which expels the entire deliverable volume (full expulsion). In a further example, each container holds a single dose, which expels a portion of the deliverable volume (partial expulsion).

[0058] Preferably, but not exclusively, in combination with the electronic system described above as a counterpart of the electronic device, an external device is proposed, which comprises at least one further electronic control unit configured to receive medical data from the electronic system described above. The further electronic control unit may comprise a memory unit for storing the received medical data. The further electronic control unit may comprise a processing unit for executing a machine-readable code stored in the memory unit. The machine-readable code may be stored in a read-only memory of the memory unit. The machine-readable code may be stored in a rewritable memory to allow updates. Alternatively, the further electronic control unit may comprise an application-specific integrated circuit (ASIC) instead of a processing unit for executing the machine-readable code, especially if the external device is a special-purpose / dedicated device.

[0059] The further electronic control unit may be configured to send a data request to the electronic system.

[0060] The data request may be a request for non-medical data. The non-medical data may in particular include a device identifier of a medical device. Alternatively or additionally, the non-medical data may include a current time value, a device type identifier, a patient identifier, a treatment identifier, a medication identifier, and / or a conversion factor identifier. This may improve the functionality and safety of the device.

[0061] The data request may be a request for recorded medical data. The data request may include range information indicating at least one storage location of the medical data in the electronic system, and the further electronic control unit is configured to receive the requested range of medical data and to store the medical data. The range information may include a first identifier indicating an initially requested set of medical data. The range information may include a second identifier indicating a last requested set of medical data. The range information may include the first identifier and the second identifier even if they are identical. The electronic control unit of the electronic system may be configured to transmit the recorded set of requested medical data according to the requested range. The further electronic control unit may be configured to receive the requested set of medical data.

[0062] According to a further embodiment, the further electronic control unit is configured to receive a data integrity value in correlation with the medical data received from the electronic system, the further electronic control unit being configured to calculate a verification value based on the medical data and at least one additional data not transmitted in correlation with the medical data, and to compare the verification value with the data integrity value. The further electronic control unit is configured to calculate the verification value according to the same method as used in the electronic system to calculate the data integrity value.

[0063] The additional data may be data already known to the external device or data that can be deduced by the further electronic control unit. The additional data may be at least one of a storage location identifier of medical data in the electronic system, a device identifier, a device type identifier, a patient identifier, a treatment identifier, a medication identifier, or a conversion factor identifier.

[0064] The storage location identifier may be estimated to be the next free storage location according to previously received data in the external device. For example, the external device may have already received and / or stored N sets of medical data. Thus, the expected storage location identifier would be for N+1.

[0065] The device identifier, device type identifier, patient identifier, treatment identifier, medication identifier, or conversion factor identifier may be data that is already known to the device from a previous data transmission, for example, during a setup or pairing process between the electronic system and the external device.

[0066] According to a further embodiment, if the data integrity value and the verification value do not match, the further electronic control unit is configured to estimate a correction value for the additional data and to repeat the calculation and comparison of the verification value based on the correction value. The further electronic control unit may be configured to repeat the correction, calculation, and comparison until the verification value matches the data integrity value. The further electronic control unit may be configured to repeat the correction, calculation, and comparison until a set maximum number of iterations is reached. The number of iterations depends on or may be the number of bits of the data integrity value. If the additional data includes a storage location identifier, the further electronic control unit may be configured to increment the storage location identifier by one position (e.g. from N+1 to N+2) and repeat the calculation.

[0067] Alternatively, if no correction value can be found where the verification value and the data integrity value match, the electronic control unit may be configured to perform one or several actions. One of these actions may be to request a retransmission of data from the electronic system to rule out a transmission error. Another of these actions may be to inform the user of the inconsistent transmission. In particular, if the external device is used by multiple users in association with different medical devices, or even the same medical device, and there are different user profiles selectable on the medical device and / or the external device, and if a patient identifier and / or a device identifier are part of the additional data, it may be suggested to the user that an incorrect user profile has been selected.

[0068] The additional data may be an expected storage location identifier of the medical data in the electronic system, and if the verification value based on the correction value matches the data consistency value, the further electronic control unit is configured to send a data request and range information between the correction value and the last storage location information where the medical data was received (e.g. before the one currently being evaluated). Thus, the first identifier may be the last storage location where the medical data was received, or one storage location above. Thus, the second identifier may be the correction value or one value below. The range information may include two location identifiers. The range information may include as the first identifier a storage location identifier for the first set of medical data missing in the storage of the further electronic control unit. The range information may include as the second identifier a storage location identifier for the last set of medical data missing in the storage of the further electronic control unit. The electronic system, e.g. the electronic control unit of the electronic system, may be configured to send a requested range of the medical data set upon receiving a request from an external device. The requested range may include two or more sets of medical data, e.g. three, four, five or more. Alternatively, the further electronic control unit can send a separate data request for each data set that is missing in the storage of the further electronic control unit, e.g. even if more than one data set is missing, however requesting a range may be more efficient, e.g. in terms of power consumption.

[0069] Further, a corresponding method is proposed for exchanging data between an electronic system, such as an electronic system for a medical device as described above, and an external device, such as an external device as described above, the method comprising establishing a communication channel between the electronic system and the external device and transmitting data, such as device data, from the medical device to the external device.

[0070] Prior to the transmission, the method may include a step of requesting specific data from the electronic system by the external device. Requesting the specific data may include a data request for the recorded medical data. The data request may include range information indicating at least one storage location of the medical data in the electronic system.

[0071] The electronic control unit may be configured to receive the requested range of medical data and to store the medical data.

[0072] The transmitting of the data may further include transmitting the medical data and at least one data integrity value in correlation with the medical data, the data integrity value being based on the medical data and at least one additional data not transmitted in correlation with the medical data.

[0073] The method may further include receiving the medical data and the data integrity value at the external device.

[0074] The method may further include calculating a verification value based on the received medical data and the at least one additional data, and comparing the verification value to the data integrity value.

[0075] The method may also include requesting additional medical data from the electronic system by the external device if the verification value does not match the data integrity value.

[0076] A machine-readable code is proposed which, when executed in the control unit of the external device, e.g. in its processing unit, causes the external device to function as the external device described above. This can be an app on the user's / patient's smartphone. The machine-readable code can be stored in a data storage medium, e.g. in cloud storage, on the external device, or on a distribution medium such as a USB storage stick or CD.

[0077] A machine readable code is proposed which, when executed in a control unit of an electronic system for a medical device, causes the electronic system to function as the electronic system described above. The machine readable code can be stored on a data storage medium, for example in a cloud storage, or on a distribution medium such as a USB-storage stick or a CD, or can be provided by a data stream.

[0078] Further aspects, embodiments, and advantages will become apparent from the following description of exemplary embodiments taken in conjunction with the drawings. [Brief description of the drawings]

[0079] [Figure 1] FIG. 1 is a schematic diagram of a medical device including an electronic system and an external device. [Diagram 2] 1 is a schematic diagram of an alternative medical device, an electronic system, and an external device. [Figure 3a] 1 is a schematic diagram of a method for exchanging and evaluating data between an electronic system and an external device; [Figure 3b] 1 is a schematic diagram of a method for exchanging and evaluating data between an electronic system and an external device; [Figure 3b] 1 is a schematic diagram of a method for exchanging and evaluating data between an electronic system and an external device; DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0080] In the drawings, identical elements, identically acting elements, or elements of the same type may be provided with the same reference numerals.

[0081] 1 shows a medical device 20. The medical device 20 comprises an electronic system 10 for recording medical data for the medical device 20, the electronic system 10 comprising an electronic control unit 12 configured to transmit the medical data to an external device 30 and to store the medical data.

[0082] The electronic system 10 comprises a memory unit 13 for storing the medical data. The memory unit is electrically connected to the electronic control unit 12. The electronic system 10 comprises a communication unit 14 for transmitting the medical data to an external device 30. The communication unit 14 is electrically connected to the electronic control unit. The communication unit 14 is a Bluetooth low energy module. The electronic control unit 12 is an ASIC or a processing unit for executing machine readable code.

[0083] The medical device 20 is a needle-based injection device (hereinafter also referred to as NIS (Needle-Based Injection System)). The medical device 20 is a pen-type device. However, the present invention may also be implemented in other medical devices, for example in automatic injectors. The medical device 20 comprises an elongated housing 22. The medical device 20 comprises a receptacle 26 for receiving a container 25. The container 25 is filled with a medicinal product. The container 25 may be replaced with a different one by partially disassembling the medical device, for example an empty container may be replaced with a full container. The medical device 20 comprises a needle 27 in fluid communication with the container 25 at a first end. The medical device 20 comprises a cap 24 which may be mechanically connected to the housing 22 and which covers the needle 27 when connected to the housing 22. The medical device 20 comprises a dial 23 rotatably coupled to the housing 22 at a second end opposite the needle. By rotating the dial 23, the dose of medicinal product to be expelled from the medical device (and injected into the human body) can be selected. The dial 23 also serves as a release to initiate the expulsion of the medicinal product upon pressing along the cylinder axis. This allows the energy buffer to release energy to drive the medicinal product delivery. The medical device 20 comprises a drive unit 29 and a plunger 28. The drive unit 29 drives the plunger 28 into the container 25 a specific distance for the set dose. As an alternative to a device with a separate energy source for the drive mechanism, the device may be manually driven, i.e. the force required to move the plunger in the container may be provided by the user.

[0084] The electronic system 10 comprises a detector unit 16. The detector unit 16 is electrically connected to the electronic control unit 12. The detector unit 16 comprises an electric clock 18. The detector unit comprises a movement detector 17 for detecting the amount of movement of the plunger 28. To drive the plunger 28, a drive unit 29 converts a rotational movement into a linear movement of the plunger 28. The movement detector 17 is provided to measure the amount of rotation in the drive unit to determine the amount of linear movement of the plunger 28. The movement detector 17 can function optically, electrically and / or magnetically. Alternatively, the movement detector may directly measure the linear movement of the plunger 28, for example by laser distance measurement or via a mechanical vernier scale. The electronic control unit 12 is configured to obtain medical data based on the readings of the detector unit. The electronic control unit 12 is configured to determine the dosage based on the readings of the movement detector 17 and to associate the time values ​​given by the electronic clock 18 to the dosage to form a set of medical data. According to different embodiments, the detector unit 16 may additionally or alternatively be directly connected to the memory unit 13 to directly store the measurement data, while the electronic control unit 12 may be in a low energy / sleep state, and the electronic control unit 12 may be configured to determine a set of medical data using data from the memory.

[0085] The electronic control unit 12 is configured to store the medical data in the memory unit 13 .

[0086] Fig. 2 shows an alternative medical device 20 and electronic system 10. The medical device 20 does not include an electronic system. The electronic system 10 includes a separate housing 11. The separate housing 11 and the housing 22 of the medical device 20 each include a mechanical interface with a locking function for removably fixing the separate housing 11 to the housing 22. The separate housing 11 has a ring-like shape that can be attached / pressed onto the housing 22. Alternatively, other shapes are also possible, for example a C-like shape. The electronic system 10 and the medical device 20 form a modular system. This allows the electronic system 10 to be used with multiple medical devices in an alternating or serial manner.

[0087] The drive unit 29 of the medical device 20 comprises markings, e.g. optical, magnetic and / or ferroelectric markings, that can be observed from outside the housing 22 by the motion detector 17 of the electronic system 10. According to an alternative embodiment, the motion detector 17 may be partially integrated in the medical device 20, and the interface between the housing 22 and the separate housing 11 may constitute an electrical and / or mechanical connection of the motion detector 17 to the detector unit 16. Alternatively, the motion detector 17 may comprise a needle that reaches into the housing 22 to mechanically scan ripples on the moving parts of the drive unit 29. The needle may be formed of two mechanically or magnetically coupled parts, one part integrated in the housing 22 and one part integrated in the separate housing 11.

[0088] Also shown in Fig. 1 and Fig. 2 is an external device 30. The external device 30 is a smartphone. The external device 30 comprises a further electronic control unit 32. The further electronic control unit 32 comprises a processing unit for executing a certain machine-readable code. The machine-readable code is provided in the form of an app from a cloud storage (app shop). The further electronic control unit 32 is configured to receive medical data from the electronic system 10. The external device 30 comprises a communication unit 34 for receiving data from the electronic system 10. The communication unit 34 of the external device 30 is compatible with the communication 14 unit of the electronic system 10. The communication unit 34 is a Bluetooth module. The external device 30 comprises a memory unit 33 for storing the medical data.

[0089] In the first method, a communication channel is first established between the external device 30 and the electronic system 10 and an initialization is performed. During the initialization, the external device 30 requests essential non-medical data from the electronic system 10. The further electronic device 32 is configured to send a data request for the non-medical data to the electronic system 10. The electronic system 10 provides the non-medical data to the external device. The electronic control unit 12 is configured to send the non-medical data to the external device 30 upon request. The non-medical data comprises device-specific data (device data). The non-medical data comprises a device identifier (UDI (Unique Device Identification)). The non-medical data comprises a current time signal of the electronic clock 18. The non-medical data comprises a drug identifier of the drug in the container. The drug type may be predefined in the settings of the electronic system 10 and only certain drug types may be adapted to the medical device 20 or the detector unit 17 comprises an additional sensor for detecting the container identifier, e.g. a certain color or shape. The non-medical data comprises a conversion factor identifier. The user may create a user profile in the external device. The further electronic control unit 32 may be configured to transmit the user identifier to the electronic system for storage as non-medical data.

[0090] The electronic control device 12 may be configured to transmit the non-medical data as a single string, thus simplifying the interface and minimizing the number of commands required. The external device 30, in particular the further electronic control unit 32, can then use this information to take one or more of the following actions, including but not limited to: - Identifying each unique medical device 20 (pen) connected. -Inform the user of UDI information (serial number, lot, etc.) -Adapting the artwork based on color information about medical devices in the non-medical data. -Performs automatic checks regarding memory capacity, manufacturing date and generates relevant warning messages for the patient. -Partially provide data to a cloud database or service center.

[0091] The further electronic control unit 32 can also send data requests for any selection of non-medical data to the electronic system 10 whenever required after initialization.

[0092] In other words, a connected NIS device has a data communication channel established to transmit dosage records to the external device. This data channel may be used or extended (e.g., by additional Bluetooth characteristic values) to transmit supplementary data as well. Since this data is usually not required with every data transmission, if it is not part of the basic data channel, a return channel must be used or implemented to transmit request commands on demand.

[0093] According to a second method, the electronic control unit 12 is configured to calculate a data integrity value based on the medical data and at least one additional data not included in the medical data, and the electronic control unit is configured to store the data integrity value in correlation with the medical data. The data integrity value is calculated according to an 8-bit cyclic redundancy check (CRC) scheme. The data integrity value is an 8-bit value. The electronic control unit 12 is configured to perform a data verification of the recorded medical data periodically, for example on a daily, weekly or monthly basis. The electronic control unit 12 is configured to recalculate the data integrity value based on the set of stored medical data and the additional data, and compare it with the stored data integrity value. If a difference is found in this comparison, the electronic control unit 12 can be configured to mark the set of medical data as defective or to perform a corrective action based on the found difference.

[0094] To ensure that no records (sets of medical data) are lost, each record counts from 0 upwards in increments of 1 (i.e. record numbers 0, 1, 2, 3, 4, etc.) to obtain consecutive dose numbers. Each record also contains an 8-bit Cyclic Redundancy Check (CRC) type control value (data integrity value) for data integrity. The dose number is included when the CRC value is calculated, but is not stored in the dose record itself. Instead, the device (medical device 20 / electronic control unit 10) keeps a count of the number of records already stored in memory 13 and uses memory addressing to translate the dose record number to a specific memory address and select the correct dose record.

[0095] A third method for exchanging data between the electronic system 10 and the external device 30 includes sending a data request from the external device to the electronic system 10. The data request is for the recorded medical data, and the data request includes range information indicating at least one storage location of the medical data in the electronic system. The range information includes a first identifier for a storage location of an initially requested set of medical data. The range information includes a second identifier for a storage location of a last requested set of medical data. The further electronic control unit 32 is configured to send the data request to the electronic system 10. The third method further includes establishing a communication channel between the electronic system 10 and the external device 30. The third method further includes sending data from the electronic system 10 to the external device 30. The further electronic control unit 32 is configured to receive the requested range of medical data and store the medical data.

[0096] In other words, when the external device 30 is replaced, the app is reinstalled, or a dose record transmission from the NIS 20 is interrupted or missed, the external device 30 may need to request transmission of one or more dose records (sets of medical data) stored in the memory 13 of the NIS. To do so, the external device 30 sends a request command to the NIS 20. This may be accomplished using one or more dose record identifiers (typically dose record numbers (storage location identifiers)) to request a range of records or a single record. In the case of a contiguous range, two identifiers may be sent to identify start and end parameters. In the case of a single record, either a single identifier, or two identifiers equal to each other, or two identifiers not equal to each other (in the case of a non-inclusive implementation), may be sent. To minimize internal memory consumption, the NIS 20 does not explicitly store the dose record identifier in the dose record (medical data) itself, since the dose record identifier is typically given by the absolute dose record location in the internal memory 13. The NIS 20 can transmit the requested medical data together with a data integrity value calculated based on the medical data and the record identifier (storage location identifier). By temporarily including the record identifier when creating the checksum (data integrity value), the identifier is implicitly stored in the record without incurring any memory penalty. The external device 30 can then verify the correctness of the dosage record identifier by adding the estimated and expected record identifier for checksum calculation and verification, and the external device 30 can verify that the received record is indeed the previously requested record. The dosage record can include an explicit checksum portion to verify data integrity.

[0097] According to a fourth method for exchanging data between an electronic system and an external device, the electronic system 10 and the external device 30 establish a connection. The electronic control unit 12 is configured to calculate a data integrity value based on the latest medical data and at least one additional data not included in the latest medical data, and the electronic control unit 12 is configured to transmit the data integrity value to the external device 30 in correlation with the latest medical data. The transmission of data includes transmitting the medical data and at least one data integrity value in correlation with the medical data, the data integrity value being based on the medical data and at least one additional data not transmitted in correlation with the medical data. The electronic control unit 12 is configured not to transmit the additional data in correlation with the medical data. The electronic control unit 12 is configured not to explicitly transmit the storage location data of the transmitted medical data in any way.

[0098] The additional data includes a storage location identifier for the medical data. The additional data also includes a device identifier. According to other embodiments, other parameters may be included in or excluded from the additional data.

[0099] The further electronic control unit 32 is configured to receive a data integrity value in correlation with the medical data received from the electronic system 10. The medical data and the data integrity value are received at the external device. The further electronic control unit 32 is configured to calculate a verification value based on the received medical data and at least one additional data not transmitted in correlation with the medical data, and to compare the verification value with the data integrity value. The further control unit 32 is configured to use a value stored in the memory unit 33 of the external device for a part of the additional data (a device identifier). The further control unit 32 is configured to estimate another part of the additional data. The further control unit 32 is configured to estimate a storage location identifier to a value one higher than the storage location identifier of the last received transmission before the currently received transmission.

[0100] In other words, at each initial and / or subsequent communication event between the NIS device and the receptor, the current dose number is exchanged. From that point on, both devices count the number of records independently, without directly exchanging numbers again. However, it is important that the devices are synchronized. When a new record is sent (usually in chronological order), the receptor device can use its own counter to estimate the dose number of the new record and include it in a CRC check. If this is successful (i.e. matches the CRC in the record), then both data integrity and the correct dose number are verified.

[0101] If the data integrity value and the verification value do not match, the further electronic control unit 32 is configured to estimate a correction value for the storage location identifier and repeat the calculation and comparison of the verification value based on the correction value. The storage location identifier is incremented and the verification value is recalculated until the verification value and the data integrity information match or the increment limit for the storage location is reached.

[0102] If a correction value for the storage location identifier is found and a verification value based on the correction value matches the data integrity value, a third method is executed by the external device 30 to request additional medical data from the electronic system 10, where range information (e.g., for the requested medical data to be sent from the system to the device) is between the correction value and the last storage location information from which medical data was received.

[0103] In special cases, for example after an app is newly (re)installed on the external device 30, the first identifier of the range information may be associated with a first data set recorded and / or stored in the electronic system 10.

[0104] In other cases, the fourth method will be triggered when the transmission of the previous record did not complete properly or when multiple sets of medical data have been recorded since the last connection.

[0105] In FIG. 3 a , medical data B and additional data A are used to calculate a data consistency value C.

[0106] In Fig. 3b, only medical data B and data integrity value C are stored or transmitted in correlation with each other. Redundant or easily guessable information A is not stored or transmitted in correlation with medical data B or data integrity value C.

[0107] In Figure 3c, the estimated additional data A* is used together with the received and / or stored medical data B to calculate a verification value C*. The verification value C* is then compared with the stored and / or received data integrity value C.

[0108] The scope of protection is not limited to the examples given herein above. Any invention is embodied in each novel feature and each combination of features, including in particular any combination of features described in the claims, even if this feature or this combination of features is not explicitly described in the claims or examples. Features of the above-described embodiments may be combined. The layout, functions, and number of components may be changed in other embodiments. [Explanation of symbols]

[0109] 10 Electronic Systems 11 Separate housing 12 Electronic control unit 13 Memory Unit 14 Communication unit 16 Detector Unit 17 Motion Detector 18 Electronic Clock 20 Medical Devices 22 Housing 23 Dial 24 Cap 25 Container 26 Receptacle 27 needles 28 Plunger 29 Drive unit 30 External Devices 32 Further Electronic Control Units 33 Memory Unit 34 Communication Unit A. Additional Data A* Estimated additional data B. Medical Data C Data Integrity Value C* validation value

Claims

1. 1. An electronic system (10) for recording medical data (B) for a medical device (20), comprising: an electronic control unit (12) configured to transmit the medical data to an external device (30) and / or store the medical data, the electronic control unit (12) configured to calculate a data integrity value (C) based on the medical data (B) and at least one additional data (A) not included in the medical data, the electronic control unit configured to transmit the data integrity value to the external device in correlation with the medical data and / or store the data integrity value.

2. 2. The electronic system of claim 1, wherein the electronic control unit (12) is configured to not transmit the additional data (A) in correlation with the medical data (B).

3. 3. The electronic system of claim 1 or 2, wherein the medical data (B) includes at least time information and / or measurement values, and / or the medical device (20) is an injection device and the medical data is dosage information.

4. The electronic system of any one of claims 1 to 3, wherein the electronic control unit (12) is configured to transmit non-medical data to the external device (30).

5. A medical device, in particular a needle-based injection device and / or a pen-type device, comprising an electronic system (10) according to any one of claims 1 to 4 or comprising an interface adapted to couple to such an electronic system.

6. 6. The medical device of claim 5, comprising at least one container filled with a pharmaceutical agent or a receptacle for receiving such a container.

7. The medical device of claim 6 , further comprising a container filled with a pharmaceutical agent, said container received in said receptacle.

8. The medical device of any one of claims 5 to 7, wherein the medical device is an automatic injector.

9. an external device (30) comprising at least one further electronic control unit (32) configured to receive medical data (B) from the electronic system according to any one of claims 1 to 4, said further electronic control unit being configured to receive a data integrity value (C) in correlation with said medical data (B) received from said electronic system (10), said further electronic control unit being configured to calculate a verification value (C*) based on said medical data and at least one additional data not transmitted in correlation with said medical data, and to compare said verification value with said data integrity value, If the data consistency value and the verification value do not match, the further electronic control unit (32) is configured to estimate a correction value for the additional data and repeat the calculation and comparison of the verification value based on the correction value.

10. 10. The external device of claim 9, wherein the further electronic control unit (32) is configured to send data requests to the electronic system.

11. the data request is for recorded medical data (B), the data request includes range information indicating at least one storage location of the medical data in the electronic system (10), and the further electronic control unit (32) is configured to receive the medical data in the requested range and store the medical data; 11. The external device of claim 10, wherein the additional data includes an expected storage location identifier of the medical data in the electronic system, and wherein the further electronic control unit is configured to send the data request if the verification value based on the correction value matches the data integrity value, and the range information is between the correction value and the last storage location information from which the medical data was received.

12. A method for exchanging data between an electronic system and an external device (30), comprising: - establishing a communication channel between said electronic system and said external device; - transmitting data, e.g., device data, from said electronic system (10) to said external device (30), including transmitting medical data (B) and at least one data integrity value (C) correlated with said medical data, said data integrity value being calculated by said electronic system based on said medical data and at least one additional data (A) not transmitted correlated with said medical data; receiving, at the external device, the medical data and the data integrity value; - calculating a verification value (C*) based on the received medical data and at least one additional data and comparing said verification value with said data integrity value; - if the data integrity value and the verification value do not match, estimating a correction value for the additional data and repeating the calculation and comparison based on the correction value; A method comprising:

13. The method according to claim 12, wherein the electronic system is an electronic system (10) for a medical device (20) according to any one of claims 1 to 4, and the external device is an external device (30) according to any one of claims 9 to 11.

14. Machine readable code which, when executed in a control unit of an external device, causes the external device to function as an external device according to any one of claims 9 to 11.

15. 15. A data storage medium containing the machine-readable code of claim 14.