This document provides the principles, concepts, terms and definitions for health software and health IT systems, key properties of safety, effectiveness and security, across the full life cycle, from concept to decommissioning, as represented in Figure 1. It also identifies the transition points in the life cycle where transfers of responsibility occur, and the types of multi-lateral communication that are necessary at these transition points. This document also establishes a coherent concepts and terminology for other standards that address specific aspects of the safety, effectiveness, and security (including privacy) of health software and health IT systems.
This document is applicable to all parties involved in the health software and health IT systems life cycle including the following:
a) Organizations, health informatics professionals and clinical leaders designing, developing, integrating, implementing and operating health software and health IT systems – for example health software developers and medical device manufacturers, system integrators, system administrators (including cloud and other IT service providers);
b) Healthcare service delivery organizations, healthcare providers and others who use health software and health IT systems in providing health services;
c) Governments, health system funders, monitoring agencies, professional organizations and customers seeking confidence in an organization’s ability to consistently provide safe, effective and secure health software, health IT systems and services;
d) Organizations and interested parties seeking to improve communication in managing safety, effectiveness and security risks through a common understanding of the concepts and terminology used in safety, effectiveness and security management;
e) Providers of training, assessment or advice in safety, effectiveness and security risk management for health software and health IT systems;
f) Developers of related safety, effectiveness and security standards.

  • Standard
    61 pages
    English language
    sale 15% off

IEC TR 60601-4-5:2021 provides detailed technical specifications for SECURITY features of MEDICAL DEVICES used in MEDICAL IT-NETWORKS. MEDICAL DEVICES dealt with in this document include MEDICAL ELECTRICAL EQUIPMENT, MEDICAL ELECTRICAL SYSTEMS and MEDICAL DEVICE SOFTWARE. MEDICAL DEVICE SOFTWARE, although not in the scope of IEC 60601 (all parts), can also make use of this document. Based on the seven foundational requirements described in the state-of-the-art document IEC TS 62443 1 1:2009, this document provides specifications for different MEDICAL DEVICE capability SECURITY LEVELS (SL C). The specified SECURITY capabilities of a MEDICAL DEVICE can be used by various members of the medical community to integrate the device correctly into defined SECURITY ZONES and CONDUITS of a MEDICAL IT-NETWORK with an appropriate MEDICAL IT NETWORK's target SECURITY LEVEL (SL T).
This document is applicable to MEDICAL DEVICES with external data interface(s), for example when connected to a MEDICAL IT-NETWORK or when a human interface is used for processing – e.g. entering, capturing or viewing – CONFIDENTIAL DATA.
This document does not apply to other software used on a MEDICAL IT-NETWORK which does not meet the definition of MEDICAL DEVICE SOFTWARE.
This document does not apply to in-vitro diagnostic devices (IVD).

  • Technical report
    51 pages
    English language
    sale 15% off

This document provides guidance on the development, implementation and maintenance of a risk management system for medical devices according to ISO 14971:2019.
The risk management process can be part of a quality management system, for example one that is based on ISO 13485:2016[24], but this is not required by ISO 14971:2019. Some requirements in ISO 13485:2016 (Clause 7 on product realization and 8.2.1 on feedback during monitoring and measurement) are related to risk management and can be fulfilled by applying ISO 14971:2019. See also the ISO Handbook: ISO 13485:2016 - Medical devices - A practical guide.

  • Technical report
    87 pages
    English language
    sale 15% off

This document specifies terminology, principles and a process for risk management of medical devices, including software as a medical device and in vitro diagnostic medical devices. The process described in this document intends to assist manufacturers of medical devices to identify the hazards associated with the medical device, to estimate and evaluate the associated risks, to control these risks, and to monitor the effectiveness of the controls.
The requirements of this document are applicable to all phases of the life cycle of a medical device. The process described in this document applies to risks associated with a medical device, such as risks related to biocompatibility, data and systems security, electricity, moving parts, radiation, and usability.
The process described in this document can also be applied to products that are not necessarily medical devices in some jurisdictions and can also be used by others involved in the medical device life cycle.
This document does not apply to:
- decisions on the use of a medical device in the context of any particular clinical procedure; or
- business risk management.
This document requires manufacturers to establish objective criteria for risk acceptability but does not specify acceptable risk levels.
Risk management can be an integral part of a quality management system. However, this document does not require the manufacturer to have a quality management system in place.
NOTE Guidance on the application of this document can be found in ISO/TR 24971[9].

  • Standard
    36 pages
    English language
    sale 15% off

IEC TR 60601-4-3:2018 is available as IEC TR 60601-4-3:2018 RLV which contains the International Standard and its Redline version, showing all changes of the technical content compared to the previous edition.IEC TR 60601-4-3:2018 contains a series of recommendations developed by an expert working group of IEC subcommittee 62A in response to questions of interpretation of IEC 60601-1:2005 and related collateral standards in the IEC 60601 series. IEC TR 60601-4-3:2018 is primarily intended to be used by:
– manufacturers of medical electrical equipment;
– test laboratories and others responsible for assessment of compliance with IEC 60601 1:2005, IEC 60601-1:2005/AMD1:2012, IEC 60601-1-8:2006, IEC 60601-1-8:2006/AMD1:2012, IEC 60601-1-11:2010, IEC 60601 1 11:2015 and IEC 60601-1-12:2014;
– those developing subsequent editions of IEC 60601-1.
The recommendations in the first edition of IEC TR 62296 were considered in preparing the third edition of IEC 60601-1. Similarly, it is expected that these recommendations within IEC 60601-4-3 will be considered when preparing future revisions of IEC 60601-1 and related collateral standards in the IEC 60601 series. The object of IEC TR 60601-4-3:2018 is to make the recommendations/interpretations available to those interested in the application of the third edition of IEC 60601-1 and applicable collateral standards. IEC TR 60601-4-3:2018 cancels and replaces the first edition of IEC 60601-4-3 published in 2015. This edition constitutes a technical revision. IEC TR 60601-4-3:2018 includes the following significant technical changes with respect to the previous edition: addition of 47 new recommendations.

  • Technical report
    144 pages
    English language
    sale 15% off

IEC TR 60601-4-4:2017(E) is intended to assist writers when drafting alarm system-related requirements for particular standards in the IEC 60601 and IEC 80601 or ISO 80601 series of standards.
The object of this document is to encourage consistent references to alarm system-related requirements when introducing those requirements to particular standards. This is accomplished by providing suggested model language, with examples, for common alarm system-related requirements. Each of the recommendations is based upon text that has been used in existing particular standards. The expectation is that this model language will be used when alarm system-related requirements are needed in particular standards.
The collateral standard for alarm systems, IEC 60601-1-8, contains the horizontal alarm system-related requirements for me equipment and me systems. The recommendations in this document are intended to aid the writers of particular standards when referencing IEC 60601-1-8:2006 and IEC 60601-1-8:2006/AMD1:2012.

  • Technical report
    22 pages
    English language
    sale 15% off

ISO/TR 80002-2:2017(E) applies to any software used in device design, testing, component acceptance, manufacturing, labelling, packaging, distribution and complaint handling or to automate any other aspect of a medical device quality system as described in ISO 13485.
ISO/TR 80002-2:2017 applies to
- software used in the quality management system,
- software used in production and service provision, and
- software used for the monitoring and measurement of requirements.
It does not apply to
- software used as a component, part or accessory of a medical device, or
- software that is itself a medical device.

  • Technical report
    84 pages
    English language
    sale 15% off

IEC TR 60601-4-1:2017(E) is intended to help a manufacturer through the key decisions and steps to be taken to perform a detailed risk management and usability engineering processes for medical electrical equipment or a medical electrical system, hereafter referred to as MEE or MES, employing a degree of autonomy (DOA).
This document provides a definition of DOA of MEE or MES and a medical robot, and also provides guidance on:
- methodologies to perform the risk management process and usability engineering for an MEE or MES with a DOA;
- considerations of basic safety and essential performance for an MEE and MES with a DOA; and
- identifying the use of DOA, and similar concepts in existing ISO/IEC standards dealing with MEE or MES with the goal to facilitate alignment of standards by consistent use of the concept of DOA; and
- distinguishing between medical robots, and other MEE and MES.
Unless specified otherwise, this document considers MEE and MES together.
The manufacturer of an MEE or MES with a DOA is expected to design and manufacture an MEE or MES that fulfils its intended use and does not have unacceptable risk throughout its life-cycle.
This document provides guidance to help the manufacturer in complying with the requirements of IEC 60601-1:2005 and IEC 60601-1:2005/AMD1:2012 for MEE and MES with DOA. The document is also intended as guidance for future standard writers.
There are no prerequisites to this document.

  • Technical report
    80 pages
    English language
    sale 15% off

IEC TR 80001-2-9:2017(E) establishes a security case framework and provides guidance to health care delivery organizations (HDO) and medical device manufacturers (MDM) for identifying, developing, interpreting, updating and maintaining security cases for networked medical devices. Use of this part of 80001 is intended to be one of the possible means to bridge the gap between MDMs and HDOs in providing adequate information to support the HDOs risk management of IT-networks. This document leverages the requirements set out in ISO/IEC 15026-2 for the development of assurance cases. It is not intended that this security case framework will replace a risk management strategy, rather, the intention is to complement risk management and in turn provide a greater level of assurance for a medical device by:
- mapping specific risk management steps to each of the IEC TR 80001-2-2 security capabilities, identifying associated threats and vulnerabilities and presenting them in the format of a security case with the inclusion of a re-useable security pattern;
- providing guidance for the selection of appropriate security controls to establish security capabilities and presenting them as part of the security case pattern (IEC TR 80001-2-8 provides examples of such security controls);
- providing evidence to support the implementation of a security control, hence providing confidence in the establishment of each of the security capabilities.
The purpose of developing the security case is to demonstrate confidence in the establishment of IEC TR 80001-2-2 security capabilities. The quality of artifacts gathered and documented during the development of the security case is agreed and documented as part of a responsibility agreement between the relevant stakeholders. This document provides guidance for one such methodology, through the use of a specific security pattern, to develop and interpret security cases in a systematic manner.

  • Technical report
    35 pages
    English language
    sale 15% off

IEC 82304-1:2016 applies to the safety and security of health software products designed to operate on general computing platforms and intended to be placed on the market without dedicated hardware, and its primary focus is on the requirements for manufacturers. It covers the entire lifecycle including design, development, validation, installation, maintenance, and disposal of health software products.

  • Standard
    55 pages
    English and French language
    sale 15% off

IEC TR 80001-2-8:2016, which is a Technical Report, provides guidance to Health Delivery Organizations (HDOs) and Medical Device Manufacturers (MDMs) for the application of the framework outlined in IEC TR 80001-2-2.

  • Technical report
    51 pages
    English language
    sale 15% off

IEC TR 60601-4-2:2016(E) applies to the performance of medical electrical equipment or a medical electrical system in the presence of electromagnetic disturbances.

  • Technical report
    57 pages
    English language
    sale 15% off

IEC TR 62366-2:2016(E), which is a Technical Report, contains background information and provides guidance that addresses specific areas that experience suggests can be helpful for those implementing a USABILITY ENGINEERING (HUMAN FACTORS ENGINEERING) PROCESS both as defined in IEC 62366-1:2015 and as supporting goals other than SAFETY. This technical report is not intended to be used for regulatory purposes. It contains no requirements and only provides guidance and tutorial information.
This publication is to be read in conjunction with IEC 62366-1:2015.

  • Technical report
    102 pages
    English language
    sale 15% off

IEC TR 60878:2015 provides a comprehensive compilation, for easy reference, of graphical symbols (graphics, title, description) and safety signs for medical electrical equipment. The graphical symbols are grouped in sections according to their specific field of application. This third edition cancels and replaces the second edition published in 2003. This third edition constitutes a technical revision.

  • Technical report
    283 pages
    English and French language
    sale 15% off

ISO/TR 80001-2-7:2015 is to provide guidance to HDOs on self-assessment of their conformance against IEC 80001-1.

  • Technical report
    102 pages
    English language
    sale 15% off

IEC 62366-1:2015 specifies a process for a manufacturer to analyse, specify, develop and evaluate the usability of a medical device as it relates to safety. This usability engineering (human factors engineering) process permits the manufacturer to assess and mitigate risks associated with correct use and use errors, i.e., normal use. It can be used to identify but does not assess or mitigate risks associated with abnormal use. This first edition of IEC 62366-1, together with the first edition of IEC 62366-2 (not published yet), cancels and replaces the first edition of IEC 62366 published in 2007 and its Amendment 1:2014. Part 1 has been updated to include contemporary concepts of usability engineering, while also streamlining the process. It strengthens links to ISO 14971:2007 and the related methods of risk management as applied to safety related aspects of medical device user interfaces. Part 2, once published, will contain tutorial information to assist manufactures in complying with Part 1, as well as offering more detailed descriptions of usability engineering methods that can be applied more generally to medical devices that go beyond safety-related aspects of medical device user interfaces. The contents of the corrigendum of July 2016 have been included in this copy.

  • Standard
    110 pages
    English and French language
    sale 15% off

IEC 60601-1-11:2015 is available as IEC 60601-1-11:2015 RLV which contains the International Standard and its Redline version, showing all changes of the technical content compared to the previous edition.
IEC 60601-1-11:2015 applies to the basic safety and essential performance of medical electrical equipment and medical electrical systems for use in the home healthcare environment. It applies regardless of whether the medical electrical equipment or medical electrical system is intended for use by a lay operator or by trained healthcare personnel. The home healthcare environment includes:
- the dwelling place in which a patient lives;
- other places where patients are present both indoors and outdoors, excluding professional healthcare facility environments where operators with medical training are continually available when patients are present.
This second edition cancels and replaces the first edition of IEC 60601-1-11, published in 2010, and constitutes a technical revision. The most significant changes with respect to the previous edition include the following modifications:
- correction of test method for relative humidity control at temperatures above 35 °C;
- redrafting of subclauses that altered instead of adding to the general standard or other collateral standards; and
- harmonizing with the changes to the amendments to the general standard and other collateral standards.

  • Standard
    125 pages
    English and French language
    sale 15% off

IEC TR 80001-2-5:2014(E) which is a technical report, gives guidance and practical techniques for responsible organizations, medical device manufacturers and providers of other information technology in the application of IEC 80001-1:2010 for the risk management of distributed alarm systems. This technical report applies to the transmission of alarm conditions between sources, integrator and communicators where at least one source is a medical device and at least one communication path utilizes a medical IT-network. This technical report provides recommendations for the integration, communication of responses and redirection (to another operator) of alarm conditions from one or more sources to ensure safety and effectiveness. Data and systems security is an important consideration for the risk management of distributed alarm systems.

  • Technical report
    39 pages
    English language
    sale 15% off

ISO/TR 80001-2-6:2014 provides guidance on implementing RESPONSIBILITY AGREEMENTS, which are described in IEC 80001-1 as used to establish the roles and responsibilities among the stakeholders engaged in the incorporation of a MEDICAL DEVICE into an IT-NETWORK in order to support compliance to IEC 80001-1. Stakeholders may include RESPONSIBLE ORGANIZATIONS, IT suppliers, MEDICAL DEVICE manufacturers and others. The goal of the RESPONSIBILITY AGREEMENT is that these roles and responsibilities should cover the complete lifecycle of the resulting MEDICAL IT-NETWORK.

  • Technical report
    15 pages
    English language
    sale 15% off

IEC TR 62354:2014 applies to medical electrical equipment. The object of this technical report is to provide guidance on general testing procedures according to IEC 60601-1:1988 (including the collateral provisions of IEC 60601-1-1:2000) and IEC 60601-1:2005 and IEC 60601-1:2005/AMD1:2012. This third edition cancels and replaces the second edition published in 2009. This edition constitutes a technical revision intended to align the guidance in this technical report with Amendment 1 to IEC 60601:2005. Several tests have been updated and additional test procedures added.
This technical report is to be read in conjunction with IEC 60601-1:1988, IEC 60601-1-1:2000 and IEC 60601-1:2005.

  • Technical report
    213 pages
    English language
    sale 15% off

IEC 62353:2014 applies to testing of medical electrical equipment and medical electrical systems, hereafter referred to as ME equipment and ME systems, or parts of such equipment or systems, which comply with IEC 60601-1:1988 (second edition) and its amendments and IEC 60601-1:2005 (third edition) and its amendments, before putting into service, during maintenance, inspection, servicing and after repair or on occasion of recurrent tests to assess the safety of such ME equipment or ME systems or parts thereof. For equipment not built to IEC 60601-1 these requirements may be used taking into account the safety standards for the design and information in the instructions for use of that equipment. This standard contains tables with allowable values relating to different editions of IEC 60601-1. For the purpose of this standard, the application of measuring methods is independent of the edition according to which the ME equipment or ME system is designed. This standard contains "general requirements", which contain clauses of general concern, and "particular requirements", further clauses handling special types of ME equipment or ME systems and applying in connection with the "General requirements". This standard is not suitable to assess whether ME equipment or ME systems or any other equipment comply with the relevant standards for their design. This standard is not applicable to the assembly of ME systems. For assembling ME systems see Clause 16 of IEC 60601-1:2005 + IEC 60601-1:2005/AMD1:2012. This standard does not define requirements for repair, exchange of components and modification of ME equipment or ME systems. All maintenance, inspection, servicing, and repair done in accordance with the manufacturer's instructions maintain the conformity to the standard used for the design of the equipment. Otherwise conformity to applicable requirements should be assessed and verified, before the tests of this standard are performed. This standard is also applicable to tests after repair. This second edition cancels and replaces the first edition of IEC 62353 published in 2007. This edition constitutes a technical revision including the following main revisions:
- clarification in 5.3.4.1 that measurements of leakage currents based on test configurations derived from IEC 60601-1 are an allowable alternative method and the inclusion of informative explanation in Annex A;
- revision of the protective earth resistance requirements for ME systems using multiple socket outlets to take account of IEC 60601-1:2005/AMD1:2012 on the safe allowed values of protective earth resistance of plugged-in equipment;
- the inclusion of expected minimum insulation resistance values in Table 2; and
- a reordering of the sequence of testing in Annex B.

  • Standard
    129 pages
    English and French language
    sale 15% off

IEC 60601-1-12:2014 constitutes a collateral standard to IEC 60601-1: Medical electrical equipment - Part 1: General requirements for basic safety and essential performance hereafter referred to as the general standard. Medical practice is increasingly using medical electrical equipment and medical electrical systems for monitoring, treatment or diagnosis of patients in the emergency medical services environment. The safety of medical electrical equipment in this uncontrolled, rough environment is a cause for concern. This collateral standard was developed with contributions from clinicians, engineers and regulators. The terminology, requirements, general recommendations and guidance of this collateral standard are intended to be useful for manufacturers of medical electrical equipment and medical electrical systems and for technical committees responsible for the development of particular standards. This International Standard applies to the basic safety and essential performance of medical electrical equipment and medical electrical systems, hereafter referred to as ME equipment and ME systems, which are intended, as indicated in the instructions for use by their manufacturer, for use in the EMS environment (Emergency Medical Services environment). The object of this collateral standard is to provide general requirements for ME equipment and ME systems carried to the scene of an emergency and used there, as well as in transport, in situations where the ambient conditions differ from indoor conditions. The object of this collateral standard is to specify general requirements that are in addition to those of the general standard and to serve as the basis for particular standards.

  • Standard
    101 pages
    English and French language
    sale 15% off

IEC TR 80002-3:2014 which is a technical report (TR), provides the description of software life cycle processes for medical devices. The medical device software life cycle processes are derived from IEC 62304:2006, with corresponding safety classes. They have been aligned with the software development life cycle processes of ISO/IEC 12207:2008 and are presented herein in full compliance with ISO/IEC 24774:2010. The content of these three standards provides the foundation of this TR. This TR does not:
- address areas already covered by existing related standards, e.g. the international standards that relate to the four standards used to build this TR (see Bibliography);
- FDA guidance documents; or
- software development tools. This TR describes the process reference model for medical device software development and is limited in scope to the life cycle processes described in IEC 62304:2006. The process names correspond to those of IEC 62304:2006. The mappings provided in Annex B are essential for the alignment between IEC 62304:2006 (which is based on ISO/IEC 12207:1995) and ISO/IEC 12207:2008, developed to address the detailed normative relationship between the two standards. This technical report is not intended to be used as the basis of regulatory inspection or certification assessment activities.

  • Technical report
    28 pages
    English language
    sale 15% off

IEC 60601-1-2:2014 applies to the basic safety and essential performance of Medical Equipment (ME) equipment and ME systems in the presence of electromagnetic disturbances and to electromagnetic disturbances emitted by me equipment and me systems. This collateral standard to IEC 60601-1 specifies general requirements and tests for basic safety and essential performance with regard to electromagnetic disturbances and for electromagnetic emissions of ME equipment and ME systems. They are in addition to the requirements of the general standard IEC 60601-1 and serve as the basis for particular standards. This fourth edition cancels and replaces the third edition of IEC 60601-1-2, and constitutes a technical revision. The most significant changes with respect to the previous edition include the following modifications:
- specification of immunity test levels according to the environments of intended use, categorized according to locations that are harmonized with IEC 60601-1-11: the professional healthcare facility environment, the home healthcare environment and special environments;
- specification of tests and test levels to improve the safety of medical electrical equipment and medical electrical systems when portable RF communications equipment is used closer to the medical electrical equipment than was recommended based on the immunity test levels that were specified in the third edition;
- specification of immunity tests and immunity test levels according to the ports of the medical electrical equipment or medical electrical system;
- specification of immunity test levels based on the reasonably foreseeable maximum level of electromagnetic disturbances in the environments of intended use, resulting in some immunity test levels that are higher than in the previous edition; and
- better harmonization with the risk concepts of basic safety and essential performance, including deletion of the defined term "life-supporting". This new edition includes the following main additions:
- guidance for determination of immunity test levels for special environments;
- guidance for adjustment of immunity test levels when special considerations of mitigations or intended use are applicable;
- guidance on risk management for basic safety and essential performance with regard to electromagnetic disturbances; and
- guidance on identification of immunity pass/fail criteria.

  • Standard
    188 pages
    English and French language
    sale 15% off

ISO/TR 17791:2013 provides guidance to National Member Bodies (NMBs) and readers by identifying a coherent set of international standards relevant to the development, implementation and use of safer health software. The framework presented in ISO/TR 17991:2013, together with the mapping of standards to the framework, illustrate relevant standards and how they can optimally be applied. The mapping works to clearly demonstrate where standards gaps and overlaps exist. Specifically, ISO/TR 17791:2013: - identifies a coherent set of international standards that promote the patient-safe (or safer) development, implementation and use of health software, - provides guidance on the applicability of these standards towards enabling optimal safety in health software within overall risk management and quality management approaches, as well as within the lifecycle steps and processes of health software development, - addresses the health software safety issues that remain, either as gaps or overlaps between or among the identified standards, and - discusses how those gaps and overlaps could be addressed?in the short or long term?through revision of the current standards or the development of new ones. Harm to the operators of health software, should any such risk exist, is outside the scope of ISO/TR 17791:2013.

  • Technical report
    47 pages
    English language
    sale 15% off

ISO TR 24971:2013 provides guidance in addressing specific areas of ISO 14971 when implementing risk management. This guidance is intended to assist manufacturers and other users of the standard to understand the role of international product safety and process standards in risk management, develop the policy for determining the criteria for risk acceptability, incorporate production and post-production feedback loop into risk management, differentiate between "information for safety" and "disclosure of residual risk", and evaluate overall residual risk.

  • Technical report
    12 pages
    English language
    sale 15% off

IEC/TR 62348:2012(E) which is a technical report, provides a tool to assist users of IEC 60601-1:2005 to assess the impact of the most significant changes in Amendment 1:2012. This technical report also provides a tool to assist users of IEC 60601-1 to trace requirements between the third edition and their source in the documents that form the basis of the third edition; principally the second edition as amended. This report is intended to be used by:
- those who must align standards based on the second edition of IEC 60601-1 with the third edition as amended;
- manufacturers of medical electrical equipment or medical electrical systems; and
- health care regulatory authorities, test houses and other organizations responsible for implementing standards for medical electrical equipment and medical electrical systems. This second edition cancels and replaces the first edition published in 2006. The second edition retains the mapping that traces the requirements of IEC 60601-1:2005 and its Amendment A1:2012 (Edition 3.1) from their source in the documents that relate to IEC 60601-1:1998 and its amendments (Edition 2.2). The second edition adds an assessment of the impact of the most significant changes in Amendment 1:2012.

  • Technical report
    101 pages
    English language
    sale 15% off

IEC/TR 80001-2-4:2012(E), which is a technical report, provides guidance to help a healthcare delivery organization fulfilling its obligations as a responsible organization in the application of IEC 80001-1. A healthcare delivery organization includes hospitals, doctors' offices, community care homes and clinics. Specifically, this guide helps the healthcare delivery organization assess the impact of IEC 80001-1 on the organization and establish a series of business as usual processes to manage RISK in the creation, maintenance and upkeep of its medical IT-networks. This technical report will be useful to those responsible for establishing an IEC 80001-1 compliant risk management framework within a healthcare delivery organization that is expecting to establish one or more medical IT-networks. It provides help through the key decisions and steps required to establish a risk management framework, before the organization embarks on a detailed risk assessment of an individual instance of a medical IT-network. The steps are supported by a series of decision points to steer the responsible organization through the process of understanding the medical IT-network context and identifying any organizational changes required to execute the responsibilities of top management.

  • Technical report
    24 pages
    English language
    sale 15% off

IEC TR 62348:2012 provides a tool to assist users of IEC 60601-1:2005 to assess the impact of the most significant changes in Amendment 1:2012, and to trace requirements between the third edition and the amended second edition.
The contents of the corrigendum of July 2014 and the interpretation sheet 1 of March 2021 have been included in this copy.

  • Standard
    232 pages
    English and French language
    sale 15% off

IEC/TR 80001-2-2:2012(E), which is a technical report, creates a framework for the disclosure of security-related capabilities and risks necessary for managing the risk in connecting medical devices to IT-networks and for the security dialog that surrounds the IEC 80001-1 risk management of IT-network connection. This security report presents an informative set of common, high-level security-related capabilities useful in understanding the user needs, the type of security controls to be considered and the risks that lead to the controls. Intended use and local factors determine which exact capabilities will be useful in the dialog about risk. The capability descriptions in this report are intended to supply health delivery organizations (HDOs), medical device manufacturers (MDMs), and IT vendors with a basis for discussing risk and their respective roles and responsibilities toward its management. This discussion among the risk partners serves as the basis for one or more responsibility agreements as specified in IEC 80001-1.

  • Technical report
    54 pages
    English language
    sale 15% off

IEC/TR 80001-2-1:2012(E), which is a technical report, is a step-by-step guide to help in the application of risk management when creating or changing a medical IT-network. It provides easy to apply steps, examples, and information helping in the identification and control of risks. All relevant requirements in IEC 80001-1:2010 are addressed and links to other clauses and subclauses of IEC 80001-1 are addressed where appropriate (e.g. handover to release management and monitoring). This technical report focuses on practical risk management. It is not intended to provide a full outline or explanation of all requirements that are satisfactorily covered by IEC 80001-1. This step-by-step guidance follows a 10-step process that follows subclause 4.4 of IEC 80001-1:2010, which specifically addresses risk analysis, risk evaluation and risk control. These activities are embedded within the full life cycle risk management process. They can never be the first step, as risk management follows the general process model which sets planning before any action.

  • Technical report
    66 pages
    English language
    sale 15% off

IEC/TR 80001-2-3:2012(E), which is a technical report, supports the Healthcare Delivery Organizations (HDO) in the risk management of medical IT-networks that incorporate one or more wireless links. The report, as part of IEC 80001, considers the use of wirelessly networked medical devices on a medical IT-network and offers practical techniques to address the unique risk management requirements of operating wirelessly enabled medical devices in a safe, secure and effective manner. The targeted audience for this technical report is the HDO IT department, biomedical and clinical engineering departments, risk managers, and the people responsible for design and operation of the wireless IT network.

  • Technical report
    49 pages
    English language
    sale 15% off

IEC 80001-1:2010 Recognizing that medical devices are incorporated into IT-networks to achieve desirable benefits (for example, interoperability), defines the roles, responsibilities and activities that are necessary for risk management of IT-networks incorporating medical devices to address safety, effectiveness and data and system security (the key properties). IEC 80001-1:2010 does not specify acceptable risk levels. IEC 80001-1:2010 applies after a medical device has been acquired by a responsible organization and is a candidate for incorporation into an IT-network. It applies throughout the life cycle of IT-networks incorporating medical devices. IEC 80001-1:2010 applies where there is no single medical device manufacturer assuming responsibility for addressing the key properties of the IT-network incorporating a medical device. IEC 80001-1:2010 applies to responsible organizations, medical device manufacturers and providers of other information technology for the purpose of risk management of an IT-network incorporating medical devices as specified by the responsible organization. It does not apply to personal use applications where the patient, operator and responsible organization are one and the same person.

  • Standard
    86 pages
    English and French language
    sale 15% off

IEC 60601-1-6:2010 specifies a process for a manufacturer to analyse, specify, design, verify and validate usability, as it relates to basic safety and essential performance of medical electrical equipment. This usability engineering process assesses and mitigates risks caused by usability problems associated with correct use and use errors, i.e., normal use. It can be used to identify but does not assess or mitigate risks associated with abnormal use. If the usability engineering process detailed in this collateral standard has been complied with and the acceptance criteria documented in the usability validation plan have been met (see 5.9 of IEC 62366:2007), then the residual risks, as defined in ISO 14971, associated with usability of me equipment are presumed to be acceptable, unless there is objective evidence to the contrary (see 4.1.2 of IEC 62366:2007). The object of this collateral standard is to specify general requirements that are in addition to those of the general standard and to serve as the basis for particular standards. This document cancels and replaces the second edition of IEC 60601-1-6 which has been technically revised. It was revised to align with the usability engineering process in IEC 62366. To allow for equipment manufacturers and testing organizations to make products and to equip themselves for conducting revised tests in accordance with this third edition, it is recommended by SC 62A that the content of this document not be adopted for mandatory implementation earlier than 3 years from the date of publication for equipment newly designed and not earlier than 5 years from the date of publication for equipment already in production.

  • Standard
    51 pages
    English and French language
    sale 15% off

IEC/TR 80002-1:2009(E) provides guidance for the application of the requirements contained in ISO 14971:2007, Medical devices - Application of risk management to medical devices to medical device software with reference to IEC 62304:2006, Medical device software - Software life cycle processes. It does not add to, or otherwise change, the requirements of ISO 14971:2007 or IEC 62304:2006. IEC/TR 80002-1:2009(E) is aimed at risk management practitioners who need to perform risk management when software is included in the medical device/system, and at software engineers who need to understand how to fulfil the requirements for risk management addressed in ISO 14971. ISO 14971, recognized worldwide by regulators, is widely acknowledged as the principal standard to use when performing medical device risk management. IEC 62304:2006, makes a normative reference to ISO 14971 requiring its use. The content of these two standards provides the foundation for this technical report. It should be noted that even though ISO 14971 and this technical report focus on medical devices, this technical report may be used to implement a safety risk management process for all software in the healthcare environment independent of whether it is classified as a medical device. IEC/TR 80002-1:2009 is not intended to be used as the basis of regulatory inspection or certification assessment activities.

  • Technical report
    64 pages
    English language
    sale 15% off

IEC/TR 62296:2009(E) contains a series of recommendations developed by an expert working group of IEC subcommittee 62A in response to questions of interpretation of the second edition of IEC 60601-1. IEC/TR 62296:2009(E) is primarily intended to be used by:
- manufacturers of medical electrical equipment;
- test houses and others responsible for assessment of compliance with IEC 60601-1:1988, and
- those developing subsequent editions of IEC 60601-1.
The recommendations in the first edition of IEC/TR 62296 were considered in preparing the third edition of IEC 60601-1. As the third edition of IEC 60601-1 has been published, some of the recommendations in the second edition of IEC/TR 62296 have been changed to align with requirements in IEC 60601-1:2005. Seven additional recommendations have been developed by IEC/SC 62A/WG 14 and are included in this edition of IEC/TR 62296. They are recommendations 57 through 63. This second edition cancels and replaces the first edition published in 2003. It constitutes a technical revision. This edition includes seven new recommendations: Recommendations 57 through 63. As the third edition of IEC 60601-1 has been published, some of the recommendations in this edition have been changed to align with requirements in IEC 60601-1:2005.

  • Technical report
    77 pages
    English language
    sale 15% off