Risk Manager
  • Solution
    • The Validated Approval Accelerator
      • Risk Management According to ISO 14971
      • Usability Engineering According to EN 62366
      • Essential Requirements According to MDR 2017/745 & IVDR 2017/746
      • Conformity Report for Medical Electrical Equipment According to EN 60601-1
      • Risk Management for IT Networks According to IEC 80001-1
      • Process Validation According to DIN EN ISO 13485
      • Clinical Evaluation According to MDR 2017/745 & MEDDEV 2.7.1
      • Software Lifecycle Process According to IEC 62304
    • References
      • What Our Customers Say – Success Stories
      • MST-Instrumente: Work and Time Savings
      • University Hospital rechts der Isar: Faultless Documentation and Achievement of the IEC 80001-1
      • Euroimmun: Cost Savings in Usability Engineering
      • biotrics bioimplants AG: Enrichment of the approval process by BAYOOSOFT Risk Manager
      • Selection from Our Customer List
      • Continuous Development since 1998 – Version History
  • Modules & Features
    • Modules
      • Risk Management
      • Usability Engineering
      • Essential Requirements
      • Medical Electrical Equipment
      • Machinery Directive
      • Requirements Engineering
      • Clinical Evaluation
      • Software Lifecycle Process
      • Medical IT Networks
      • REST API
      • Advanced Reporting
      • Pre-Validation Package
    • Features
      • Preliminary Hazard Analysis
      • Failure Mode and Effect Analysis
      • Structured Work According to Lifecycle Phase
      • Medical Device Classification
      • Post Market Surveillance
      • Self-Learning Knowledge Database
      • Fine-Grained Authorization Management
      • Visualizing with the Grey Box
  • Services
    • Services
      • Individual Services
      • Medical device classification
      • Software Validation – Your Service Options
      • License Model
      • System Requirements
      • Frequently Asked Questions
    • Contact
      • Upcoming Events
      • Test Now
      • Contact Request
  • Company
    • Company
      • About us
      • We think proactively
    • Our Partners
      • Get to know Our Partners
      • Become Partner now
  • Blog
  • Upcoming Events
  • Test Now
  • Customer Center
  • Search
  • Menu Menu

IEC 80001-1: Risk management in hospitals – how safe are you?

Are you sure that your CRITIS is secure? This is a question that is closely linked to the IEC 80001-1 standard. Because this describes the risk management for the operation of IT systems and networks in critical infrastructures (CRITIS), such as hospitals, over the entire product life cycle.

Hacker attacks, sabotage or manual errors in the interconnection of medical and IT networks – all this can cause harm to people. That’s why IEC 80001-1 specifies protection goals and defines roles. What are these? And who decides what? We have summarised it for you.

A case study from the VDE: In a large hospital, a ventilator is connected to an intensive care information management system (IMS) so that data can be easily transmitted. After an unspecified period of time, the ventilator suddenly switched off – without any prior error message or alarm signal. What happened?

The device driver of the PDMS regularly repeated a data request. Each time, a new process was generated in the ventilator without releasing the memory area. In the course of time, a memory overflow occurred. The memory area essential for the operation of the ventilator was overwritten and the operating software crashed completely.

An error that can have fatal consequences. In order to avoid such cases, IEC 80001-1 describes objectives to protect patients, users and third parties.

Source:

Position paper of the German Association for Electrical, Electronic & Information Technologies DGBMT – German Society for Biomedical Engineering in the VDE (date: November 2012).

What are the protection goals of the IEC 80001-1 standard?

IEC 80001-1 specifies three protection goals:

  • Safety for patients

  • Effectivity

  • Data and system security

Just like risk management for IT networks containing medical devices, the protection goals also apply to the entire life cycle. However, the three objectives cannot be considered separately, because they are interdependent.

So how do you ensure that no one hacks the IT system? How can you integrate a new medical device securely into the CRITIS network so that the day-to-day operations in the hospital run effectively? In order to fulfil questions like these and thus the protection goals, the standard specifies processes and defines responsibilities.

What processes does the standard mention? And who is responsible?

In order to create an acceptable level of safety for patients, users and third parties, IEC 80001-1 specifies various requirements and processes as well as responsible parties.

Responsible organisation

According to IEC 80001-1, you have the overall responsibility for the risk management of the medical IT network. This includes the entire process from planning, development and installation of medical devices to connection, configuration, safe use, maintenance and ultimately decommissioning. Thus, the responsible organisation assumes the liability risk, as it is responsible for the proper operation of the devices.

As top management, you create guidelines, provide and coordinate resources (including appointing a Med-IT risk manager) and monitor the risk management process. The risk management includes a 10-point plan with the main topics:

  • Risk analysis
  • Risk assessment
  • Risk governance
  • Residual risk assessment and report

Top management

Med-IT risk manager

As the designated risk manager, you organise and implement the risk management process with a view to the defined protection goals. While you report to top management, internal and external communication (e.g. with the manufacturer) is also part of the responsibility. Even if tasks such as carrying out the risk management process are delegated, the responsibility still remains with the Med-IT risk manager.

What needs to be considered if the medical device is not used as standalone software but integrated into the IT network? Questions like these are answered by the medical device manufacturers.

You must provide information about the product and its intended use. You must also include the requirements necessary for the integration of the medical device in the IT network of the CRITIS, such as technical specifications.

Medical device manufacturer

Goot to know:

The responsible organisation is required by IEC 80001-1 to create and maintain a risk management file for the medical IT network. Information about the associated configuration management must also be included – as a document or by reference.

Who decides what?

With responsibility, of course, comes decision-making power. We have shown you above who has what responsibilities according to IEC 80001-1. Delegating tasks in order to be able to fulfil the requirements does not, of course, exclude responsibility. And this responsibility – for the overall process of compliance with risk management – is borne by the top management.

How can the goals of IEC 80001-1 be reached and processes fully documented?

Hospital operators are required to ensure that the operation of a medical IT network is trouble-free and fail-safe and to identify potential risks at an early stage. Documentation of risk management activities that is always comprehensible and focuses on the dependency of critical processes contributes significantly to the safety of patients. Software solutions that focus on comprehensible documentation and completeness support this process.

Sounds interesting? Share our post with your network
  • Share on Facebook
  • Share on WhatsApp
  • Share on LinkedIn
  • Share by Mail

Interesting links

Here are some interesting links for you! Enjoy your stay :)

Pages

  • Blog
  • Company
  • Contact
  • Contact support
  • Customer Center
  • Customer Voices
  • Digital flyer
  • Edit profile
  • Features
  • Forum
  • Landingpage Medica 2020
  • Legal
  • Login
  • Medical Device Regulation Clinical Evaluation
  • Medical electrical equipment IEC 60601-1
  • Medical IT networks according to IEC 80001-1
  • Modules
  • Modules & Features
  • Newsletter Unsubscribe
  • Privacy Policy
  • References
  • Reset password
  • Services
  • Solution
  • Special precautions for IT networks according to ISO 80001
  • Start
  • Test Now
  • The Validated Approval Accelerator
  • Upcoming Events

Categories

  • BAYOOSOFT Themis
  • Editorial
  • Events
  • News
  • Releases
  • Uncategorized
  • Privacy Policy
  • Legal
BAYOOSOFT @ MEDICA 2022Now available: Themis Documentation Guide
Scroll to top