SlideShare a Scribd company logo
1 of 32
Download to read offline
IEC 62304: SDLC Conformance and Management
Rita King
CEO & Senior Consultant
(919) 313-3961
ritaking@methodsense.com
AboutMethodSense
Our Agenda
• Introductions
• IEC 62304 Historical Backdrop
• IEC 62304 Overview
• IEC 62304 Implementation
• Some Things to Watch Out For
© 2015 MethodSense, Inc. 2
AboutMethodSense
Introducing Your Presenter
Rita King - CEO & Senior Consultant
More than 25 years of experience as a regulator, technologist and
professional auditor with international reputation as a regulatory
expert. Rita is a founding member of the Underwriters Laboratories
team that defined, launched, and managed the operations of the first
US program to evaluate safety critical software used in commercial and
medical devices and developed the ANSI approved Standard for Safety
Critical Software, UL 1998.
Rita developed and commercialized InfoStrength Smart Enterprise
Suite, a 21 CFR Part 11 Software as a Service content management
solution specifically designed for the life science industry and founded
her company in 2000.
© 2015 MethodSense, Inc. 3
AboutMethodSense
MethodSense Experience
MethodSense is a Life Science service company
adding strategic value with integrated expertise:
• InfoStrength Software Solutions
• Regulatory Affairs
• Quality Assurance
• Technology Management
• Business Operations
© 2015 MethodSense, Inc. 4
HistoricalBackdrop
Software, Medical Devices and Managing Risk
• In the mid 1990’s the FDA and Underwriters
Laboratories (UL) observed a problem:
• High percentage of reported incidents of adverse events for medical
device software attributed to “user error” by Medical Device
Companies
• Research showed that a significant number of these incidents had
their root cause in the quality or unintended performance of the
software itself, not “user error”
• UL response to this problem – UL 1998:
• UL developed and published the standard UL 1998 for Safety Critical
Software
• UL 1998 applies to non-networked embedded microprocessor
software and addresses the risks unique to product hardware
controlled by software in programmable components
© 2015 MethodSense, Inc. 5
HistoricalBackdrop
Software, Medical Devices and Managing Risk
• FDA response to this problem: 21 CFR Part 11
• Part 11 requires FDA-regulated industries to implement controls,
including audits, system validations, audit trails, electronic
signatures, and documentation for software and systems involved in
processing electronic data that are:
• Required to be maintained by the FDA predicate rules or
• Used to demonstrate compliance to a predicate rule.
• Applies to software applications that support Medical Device
Businesses, Medical Device Products and software applications that
qualify as a Medical Device
•Part 11 Intent: Establish Safety and Efficacy by Validating or
Delivering Evidentiary Demonstration that Software Applications
Perform as the User Intends
© 2015 MethodSense, Inc. 6
HistoricalBackdrop
Software, Medical Devices and Managing Risk
• Classic Validation Representation
• Improved Product Quality
© 2015 MethodSense, Inc. 7
HistoricalBackdrop
Software, Medical Devices and Managing Risk
• Additional quality regulations designed to reduce
risk and enhance safety
• FDA’s 21 CFR Part 820 (GMPs)
• ISO 13485
• Does the following equation eliminate
unacceptable software risk?
GMPs / 13485 + Software Validation = Safe Medical Device
Software
© 2015 MethodSense, Inc. 8
HistoricalBackdrop
Software, Medical Devices and Managing Risk
• Assessing the equation: GMPs / 13485 + Software
Validation = Safe Medical Device Software
• GMPs & 13485 are vague when it comes to
software QA
• Validation insufficiently addresses software risk
• FDA Medical Recall Report: FY2003 to FY2012
“Evaluating the Most Common Cause of Recall – Software
Design Failures … Failure to implement software design
controls, and where appropriate, testing procedures, as well
as increasing complexity of the medical device use
environment (with increased connectivity and
interoperability) can lead to software anomalies often
requiring a correction or removal.”
© 2015 MethodSense, Inc. 9
HistoricalBackdrop
Software, Medical Devices and Managing Risk
• GMPs / 13485 and Software Validation do not
sufficiently eliminate unacceptable risk in medical
devices that are or incorporate software
• Enter IEC 62304
• Used by EU since 2008
• Incorporated into IEC 60601-1 3rd Edition
Amendment 1 (2014) & required by Clause 14
Clause 14 requires manufacturers to comply with IEC 62304 unless the device’s
software has no role in providing basic safety or essential performance or risk
analysis demonstrates that a failure of any Programmable Electronic Safety
System (PESS) does not lead to an unacceptable risk.
• Incorporated into IEC 61010 3rd Edition
© 2015 MethodSense, Inc. 10
HistoricalBackdrop
Software, Medical Devices and Managing Risk
• IEC 62304 enhances medical device safety by tying
the Software Development Life Cycle directly into
• ISO 14971 and Risk Management
• Compliant Quality Management System (e.g. ISO
13485)
• IEC 62304 addresses the risk gap by
• Creating specificity for software management where
GMPs or ISO 13485 are vague
• Incorporating ISO 14971 risk management where
Part 11 or Validation does not
• And requiring detail or rigor in software Design,
Testing, and Verification
© 2015 MethodSense, Inc. 11
IEC62304Overview
What is IEC 62304?
• IEC 62304 is the international standard that:
• Defines software development lifecycle requirements for
medical device software
• Requires all aspects of the software development life
cycle to be scrutinized, including:
• Development
• Risk management
• Configuration
• Problem resolution
• Maintenance
• Provides a common framework for medical device
manufacturers to develop software
© 2015 MethodSense, Inc. 12
IEC62304Overview
What Does Conformance with IEC 62304 Accomplish?
• Conformance with IEC 62304:
• Fulfills the requirements of the EU Medical Device
Directive
• Serves as a benchmark for compliance with regulatory
requirements in US because it is recognized by the FDA
as a consensus standard
• Recognized in most countries that use compliance
standards to fulfill regulatory requirements
• Conformance with IEC 62304 has become a part of
medical device commercialization roadmap
© 2015 MethodSense, Inc. 13
IEC62304Overview
Is Conformance with IEC 62304 Required?
• Is IEC 62304 Required in the US Market?
• Technically, “NO” because it is voluntary
• For all practical purposes, “YES” if you fall into one
of these categories
• IEC 60601-1 3rd Edition Amendment 1 is required
• The device relies upon software to perform Basic Safety
functions
• The device relies upon software for Essential Performance
• If you do not conform with IEC 62304 and also fall
into one of these categories then you must
demonstrate the software development process
used is as good as, or better than, the process
presented in IEC 62304, a form of de facto
compliance
© 2015 MethodSense, Inc. 14
IEC62304Overview
Is Conformance with IEC 62304 Required?
• How do I know if IEC 60601-1 3rd Edition
Amendment 1 Applies to My Device?
• If IEC 60601-1 3rd Edition Amendment 1 Clause
14 applies to the medical device, then
• Clause 14 requires manufacturers to comply
with IEC 62304
• Unless the device’s software has no role in
providing basic safety or
• Essential Performance or risk analysis
demonstrates that a failure of any Programmable
Electronic Safety System (PESS) does not lead to an
unacceptable risk.
© 2015 MethodSense, Inc. 15
IEC62304Overview
Is Conformance with IEC 62304 Required?
• How do I know if the device relies on software for
basic safety?
• If the role of the software includes risk mitigation
then the software has a role in providing basic
safety
• Examples:
• A primary function of the device is controlled by
software.
• Software mitigates a risk if hardware fails
• A risk analysis will identify your device’s level of
unacceptable risk and determine the role of
software in risk mitigation
© 2015 MethodSense, Inc. 16
IEC62304Overview
Is Conformance with IEC 62304 Required?
• How do I know if the device relies on software for
Essential Performance?
• Follow a process of elimination:
• List all functional aspects of your device, including accuracy,
measurements and its capabilities
• Determine whether any of these are already covered by the Basic
Safety requirements of IEC 60601-1 or whether any item is not part
of the device’s intended use
• For every item remaining that is controlled by software, pose the
question: “If this item degrades, will it create a risk for the patient?”
• If “YES” for any item, you must identify how product’s functionality
must be maintained so the risk is still acceptable (i.e. utilize
hardware controls as a back up mechanisms to a potential software
failure, include separate software controls, software validation, etc.)
• This is the device’s Essential Performance
© 2015 MethodSense, Inc. 17
IEC62304Overview
Is Conformance with IEC 62304 Required?
• Example of software as Essential Performance?
• Consider a device that claims its Essential Performance is
accurate within 5%.
• If the device is relying on software to maintain that
accuracy or provide an alert when outside of 5%, and
that software fails, then the manufacturer will be unable
to detect if the device’s Essential Performance is being
met.
• This means the software is providing Essential
Performance.
• Once you know your device software is responsible for
Essential Performance, you must comply with IEC 62304 to
ensure there is no unacceptable risk to a patient
© 2015 MethodSense, Inc. 18
IEC62304Implementation
How do You Conform with IEC 62304?
• IEC 62304 Challenge
• The Devil is in the Details……..
• There are A Lot of Details
• There are ways to practically tackle this challenge
to accommodate your company’s needs and
satisfy the requirements of the standard for a
medical device
© 2015 MethodSense, Inc. 19
IEC62304Implementation
How do You Conform with IEC 62304?
• Conforming with IEC 62304 requires 2 parts
• Processes – Policies & Procedures for your Software
Development Life Cycle
• Evidence that those processes are applied to the
medical device software
• The processes developed and applied to your
medical device software depends on its Software
Safety Classification
• Our Next Steps:
• Review Software Safety Classifications
• High Level Review and Practical Application of Processes
• Tying Processes to SDLC Evidence for the Test Laboratory
© 2015 MethodSense, Inc. 20
IEC62304Implementation
IEC 62304 Software Safety Classifications
Safety Classifications: IEC 62304 v. FDA Software
Level of Concern
• Safety Classifications Considerations
• The riskier the software, the more rigorous the controls
• Important Tip: Clear segmentation of software can
allow for discreetly classifying parts of the software
which may make the documentation and testing easier
IEC 62304 Software Safety Classification FDA Pre-Market Submission Software
Levels of Concern
Class A: No Injury or Damage to Health is
Possible
Minor: Failures or latent design flaws are
unlikely to cause any injury
Class B: Non-serious Injury is Possible Moderate: Failure or latent possible
design flaw could directly or indirectly
result in minor injury
Class C: Death or Serious Injury is Possible Major: Failure or flaw could directly or
indirectly result in death or serious injury
© 2015 MethodSense, Inc. 21
IEC62304Implementation
Software Development Life Cycle Process
•IEC 62304 Processes, Tasks and
Deliverables must be implemented
•Requires a Quality Management System
and Risk Management Process compliant
with ISO 14971
•However, IEC 62304 does not prescribe:
•An organizational structure
•A particular methodology
•A particular document format
© 2015 MethodSense, Inc. 22
IEC62304Implementation
IEC 62304 SDLC Deliverables
•Challenge: This has the look and feel of
an SDLC known as the Waterfall Model.
Is that so?
•NO. What this represents is a set of
deliverables for a Test Laboratory or a
Regulatory Authority (e.g. the FDA)
•Important: Think in terms of
incorporating into your SDLC
methodology the creation of these
deliverables
© 2015 MethodSense, Inc. 23
IEC62304Implementation
IEC 62304 SDLC Deliverables
•IEC 62304 is pretty clear about what
deliverables are required
•Test Laboratories have their own
check lists you can use as guidance to
demonstrate your IEC 62304
compliance
•MethodSense has created an IEC
62304 Action List that identifies the
required deliverables and we can
share this with you
•Therefore, the IEC 62304 deliverables
are well understood and we can focus
on practical considerations for
implementation
© 2015 MethodSense, Inc. 24
IEC62304Implementation
IEC 62304 Implementation for Alternative SDLC Methodologies
• Waterfall Model:
• Generally recognized as impractical and rarely used SDLC model
• Fails to account for the iterative nature of Software Development
• As a model accommodates the creation of deliverables (e.g.
documents) because it allows minimal change along the way
• Agile Model:
• Generally recognized as a very practical SDLC model
• Accounts for the iterative nature of software development
• As a model and depending on its implementation makes it difficult
to efficiently create the expected 62304 deliverables (e.g.
documents) since requirements may be changing during software
development
• How can you generate IEC 62304 deliverables in an
Agile environment?
© 2015 MethodSense, Inc. 25
IEC62304Implementation
IEC 62304 and Agile Development Methodologies
• IEC 62304 Conformance Tips in an Agile
Environment
• Map onto your Agile SDLC IEC 62304 deliverables
• Think about segmenting your software to allow the
Safety Classifications to apply differently to the
different software segments
• Ensure your automated tools will deliver documents
that meet expectations and conformance needs
• If your deliverables cannot keep up with your
method, think about scaling back iterative change in
a hybrid approach
© 2015 MethodSense, Inc. 26
IEC62304Implementation
IEC 62304 Tips
• Common software functionality manufacturers fail
to recognize as IEC 62304 compliance issues:
• Alarms and Alerts - often an Essential Performance
requirement because they are intended to detect
abnormalities
• Speed & Position Sensors - use software to limit range of
motion, speed and force which are Basic Safety concerns
• Algorithms - remove the software and the device is no
longer able to operate as intended, resulting in the
algorithms being part of Essential Performance
© 2015 MethodSense, Inc. 27
IEC62304Implementation
IEC 62304 Tips
• Pitfalls to Avoid
• Document Your Process Well – document
management is essential for meeting compliance
goals
• Software of Unknown Pedigree (SOUP) – manage
your SOUP appropriately
• Document Development – make certain you are
sufficiently resourced to support document
development needs
• Version Control & Updates – clearly define what is a
software update and further how the software will be
maintained in a validated state
© 2015 MethodSense, Inc. 28
IEC62304Implementation
IEC 62304 Tips
• What if Your Device Software is Developed by a
Third Party?
• Supplier Management Process – confirm that
software vendor complies with IEC 62304 and
processes are reviewed during vendor audit
• Quality Agreement – confirm that:
• It defines vendor responsibilities and 62304
Deliverables
• Vendors procedures used for software development
will be provided to you and the test lab for review
• Establish your SDLC – at minimum, your process
will define acceptance criteria (i.e. IEC 62304
compliance and deliverables) from your vendor
© 2015 MethodSense, Inc. 29
IEC62304Implementation
IEC 62304 Success
• IEC 62304 File will be reviewed to ensure:
• It contains all required documentation including a
risk management file
• Procedures meet the requirements of the standard
• Each check list item is satisfied
• A product review is conducted and further a review
of the relevant software segments if it has been
decided that the software performs Basic Safety or
Essential Performance for your device
•After the review, a Pass or Fail Report is
delivered
Move Commercialization Forward!
© 2015 MethodSense, Inc. 30
Confidential
MethodSense Thanks You!!!
Discussion / Q&A
© 2015 MethodSense, Inc. 31
Thank you.
Rita King
CEO & Senior Consultant
(919) 313-3961
ritaking@methodsense.com
© 2015 MethodSense, Inc.

More Related Content

What's hot

Iso 13485:2016
Iso 13485:2016Iso 13485:2016
Iso 13485:2016Suhas R
 
Quality Control for Medical Device Software - It Arena Lviv Presentation
Quality Control for Medical Device Software - It Arena Lviv PresentationQuality Control for Medical Device Software - It Arena Lviv Presentation
Quality Control for Medical Device Software - It Arena Lviv PresentationRoman Lavriv
 
Difference between fda 21 cfr part 820 and ISO 13485
Difference between fda 21 cfr part 820 and ISO 13485Difference between fda 21 cfr part 820 and ISO 13485
Difference between fda 21 cfr part 820 and ISO 13485Anil Chaudhari
 
ISO: 14971 Quality risk management of medical devices
ISO: 14971 Quality risk management  of medical devicesISO: 14971 Quality risk management  of medical devices
ISO: 14971 Quality risk management of medical devicesAtul Bhombe
 
Overview on “Computer System Validation” CSV
Overview on  “Computer System Validation” CSVOverview on  “Computer System Validation” CSV
Overview on “Computer System Validation” CSVAnil Sharma
 
Risk Management for Medical Devices - ISO 14971 Overview
Risk Management for Medical Devices - ISO 14971 Overview Risk Management for Medical Devices - ISO 14971 Overview
Risk Management for Medical Devices - ISO 14971 Overview Greenlight Guru
 
Process Validation & Verification (V&V) for Medical Devices
Process Validation & Verification (V&V) for Medical DevicesProcess Validation & Verification (V&V) for Medical Devices
Process Validation & Verification (V&V) for Medical DevicesRina Nir
 
FDA Design Controls: What Medical Device Makers Need to Know
FDA Design Controls: What Medical Device Makers Need to KnowFDA Design Controls: What Medical Device Makers Need to Know
FDA Design Controls: What Medical Device Makers Need to KnowGreenlight Guru
 
Medical Devices Regulation (MDR) 2017/745 - Postmarket surveillance
Medical Devices Regulation (MDR)  2017/745 - Postmarket surveillance Medical Devices Regulation (MDR)  2017/745 - Postmarket surveillance
Medical Devices Regulation (MDR) 2017/745 - Postmarket surveillance Arete-Zoe, LLC
 
Regulation of Medical Devices in US
Regulation of Medical Devices in USRegulation of Medical Devices in US
Regulation of Medical Devices in USAnkit Geete
 
An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...
An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...
An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...Greenlight Guru
 
Understanding the New ISO 13485:2016 Revision
Understanding the New ISO 13485:2016 RevisionUnderstanding the New ISO 13485:2016 Revision
Understanding the New ISO 13485:2016 RevisionGreenlight Guru
 
Risk management in-60601-1
Risk management in-60601-1Risk management in-60601-1
Risk management in-60601-1Stella Tsank
 
ISO 13485:2016 Revisions Webinar
ISO 13485:2016 Revisions WebinarISO 13485:2016 Revisions Webinar
ISO 13485:2016 Revisions WebinarDQS Inc.
 
ISO 13485:2016 (Medical Devices - Quality Management System) Awareness Training
ISO 13485:2016 (Medical Devices - Quality Management System) Awareness TrainingISO 13485:2016 (Medical Devices - Quality Management System) Awareness Training
ISO 13485:2016 (Medical Devices - Quality Management System) Awareness TrainingOperational Excellence Consulting
 
How to Prepare for the New EU Medical Device Regulations (MDR)
How to Prepare for the New EU Medical Device Regulations (MDR)How to Prepare for the New EU Medical Device Regulations (MDR)
How to Prepare for the New EU Medical Device Regulations (MDR)Greenlight Guru
 
20210413 nvfg acs iso14155 13_apr2021
20210413 nvfg acs iso14155 13_apr202120210413 nvfg acs iso14155 13_apr2021
20210413 nvfg acs iso14155 13_apr2021Annet Visscher
 
Understanding Post-market Surveillance under EU MDR: Being Proactive, not Rea...
Understanding Post-market Surveillance under EU MDR: Being Proactive, not Rea...Understanding Post-market Surveillance under EU MDR: Being Proactive, not Rea...
Understanding Post-market Surveillance under EU MDR: Being Proactive, not Rea...Greenlight Guru
 
Clinical investigation and evaluation of medical devices and ivd.pptx
Clinical investigation and evaluation of medical devices and ivd.pptxClinical investigation and evaluation of medical devices and ivd.pptx
Clinical investigation and evaluation of medical devices and ivd.pptxreechashah2
 

What's hot (20)

Iso 13485:2016
Iso 13485:2016Iso 13485:2016
Iso 13485:2016
 
Quality Control for Medical Device Software - It Arena Lviv Presentation
Quality Control for Medical Device Software - It Arena Lviv PresentationQuality Control for Medical Device Software - It Arena Lviv Presentation
Quality Control for Medical Device Software - It Arena Lviv Presentation
 
Difference between fda 21 cfr part 820 and ISO 13485
Difference between fda 21 cfr part 820 and ISO 13485Difference between fda 21 cfr part 820 and ISO 13485
Difference between fda 21 cfr part 820 and ISO 13485
 
ISO: 14971 Quality risk management of medical devices
ISO: 14971 Quality risk management  of medical devicesISO: 14971 Quality risk management  of medical devices
ISO: 14971 Quality risk management of medical devices
 
Overview on “Computer System Validation” CSV
Overview on  “Computer System Validation” CSVOverview on  “Computer System Validation” CSV
Overview on “Computer System Validation” CSV
 
Risk Management for Medical Devices - ISO 14971 Overview
Risk Management for Medical Devices - ISO 14971 Overview Risk Management for Medical Devices - ISO 14971 Overview
Risk Management for Medical Devices - ISO 14971 Overview
 
Process Validation & Verification (V&V) for Medical Devices
Process Validation & Verification (V&V) for Medical DevicesProcess Validation & Verification (V&V) for Medical Devices
Process Validation & Verification (V&V) for Medical Devices
 
FDA Design Controls: What Medical Device Makers Need to Know
FDA Design Controls: What Medical Device Makers Need to KnowFDA Design Controls: What Medical Device Makers Need to Know
FDA Design Controls: What Medical Device Makers Need to Know
 
ISO 14155.pdf
ISO 14155.pdfISO 14155.pdf
ISO 14155.pdf
 
Medical Devices Regulation (MDR) 2017/745 - Postmarket surveillance
Medical Devices Regulation (MDR)  2017/745 - Postmarket surveillance Medical Devices Regulation (MDR)  2017/745 - Postmarket surveillance
Medical Devices Regulation (MDR) 2017/745 - Postmarket surveillance
 
Regulation of Medical Devices in US
Regulation of Medical Devices in USRegulation of Medical Devices in US
Regulation of Medical Devices in US
 
An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...
An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...
An Inside Look at Changes to the New ISO 14971:2019 from a Member of the Stan...
 
Understanding the New ISO 13485:2016 Revision
Understanding the New ISO 13485:2016 RevisionUnderstanding the New ISO 13485:2016 Revision
Understanding the New ISO 13485:2016 Revision
 
Risk management in-60601-1
Risk management in-60601-1Risk management in-60601-1
Risk management in-60601-1
 
ISO 13485:2016 Revisions Webinar
ISO 13485:2016 Revisions WebinarISO 13485:2016 Revisions Webinar
ISO 13485:2016 Revisions Webinar
 
ISO 13485:2016 (Medical Devices - Quality Management System) Awareness Training
ISO 13485:2016 (Medical Devices - Quality Management System) Awareness TrainingISO 13485:2016 (Medical Devices - Quality Management System) Awareness Training
ISO 13485:2016 (Medical Devices - Quality Management System) Awareness Training
 
How to Prepare for the New EU Medical Device Regulations (MDR)
How to Prepare for the New EU Medical Device Regulations (MDR)How to Prepare for the New EU Medical Device Regulations (MDR)
How to Prepare for the New EU Medical Device Regulations (MDR)
 
20210413 nvfg acs iso14155 13_apr2021
20210413 nvfg acs iso14155 13_apr202120210413 nvfg acs iso14155 13_apr2021
20210413 nvfg acs iso14155 13_apr2021
 
Understanding Post-market Surveillance under EU MDR: Being Proactive, not Rea...
Understanding Post-market Surveillance under EU MDR: Being Proactive, not Rea...Understanding Post-market Surveillance under EU MDR: Being Proactive, not Rea...
Understanding Post-market Surveillance under EU MDR: Being Proactive, not Rea...
 
Clinical investigation and evaluation of medical devices and ivd.pptx
Clinical investigation and evaluation of medical devices and ivd.pptxClinical investigation and evaluation of medical devices and ivd.pptx
Clinical investigation and evaluation of medical devices and ivd.pptx
 

Similar to IEC 62304: SDLC Conformance and Management

Building a QMS for Your SaMD
Building a QMS for Your SaMDBuilding a QMS for Your SaMD
Building a QMS for Your SaMDEMMAIntl
 
Building a QMS for Your SaMD Part II
Building a QMS for Your SaMD Part IIBuilding a QMS for Your SaMD Part II
Building a QMS for Your SaMD Part IIEMMAIntl
 
Critical Steps in Software Development: Enhance Your Chances for a Successful...
Critical Steps in Software Development: Enhance Your Chances for a Successful...Critical Steps in Software Development: Enhance Your Chances for a Successful...
Critical Steps in Software Development: Enhance Your Chances for a Successful...Sterling Medical Devices
 
Health apps regulation and quality control case studies and session 2 present...
Health apps regulation and quality control case studies and session 2 present...Health apps regulation and quality control case studies and session 2 present...
Health apps regulation and quality control case studies and session 2 present...3GDR
 
Health apps regulation and quality control case studies and session 2 present...
Health apps regulation and quality control case studies and session 2 present...Health apps regulation and quality control case studies and session 2 present...
Health apps regulation and quality control case studies and session 2 present...3GDR
 
Software controlled electron mechanical systems reliability
Software controlled electron mechanical systems reliabilitySoftware controlled electron mechanical systems reliability
Software controlled electron mechanical systems reliabilityASQ Reliability Division
 
Software Testing - Software Quality (Part 2)
Software Testing - Software Quality (Part 2)Software Testing - Software Quality (Part 2)
Software Testing - Software Quality (Part 2)Ajeng Savitri
 
Overview of Software QA and What is Software Quality
Overview of Software QA and What is Software QualityOverview of Software QA and What is Software Quality
Overview of Software QA and What is Software QualityUniversity of Dhaka
 
Perforce user webinar fractyl dhb jb_dhb_adr edits
Perforce user webinar fractyl dhb jb_dhb_adr editsPerforce user webinar fractyl dhb jb_dhb_adr edits
Perforce user webinar fractyl dhb jb_dhb_adr editsPerforce
 
When Medical Device Software Fails Due to Improper Verification & Validation ...
When Medical Device Software Fails Due to Improper Verification & Validation ...When Medical Device Software Fails Due to Improper Verification & Validation ...
When Medical Device Software Fails Due to Improper Verification & Validation ...Sterling Medical Devices
 
Computer Software Assurance (CSA): Understanding the FDA’s New Draft Guidance
Computer Software Assurance (CSA): Understanding the FDA’s New Draft GuidanceComputer Software Assurance (CSA): Understanding the FDA’s New Draft Guidance
Computer Software Assurance (CSA): Understanding the FDA’s New Draft GuidanceGreenlight Guru
 
Software validation do's and dont's may 2013
Software validation do's and dont's may 2013Software validation do's and dont's may 2013
Software validation do's and dont's may 2013John Cachat
 
The critical role of QA in Medical Device Testing.pdf
The critical role of QA in Medical Device Testing.pdfThe critical role of QA in Medical Device Testing.pdf
The critical role of QA in Medical Device Testing.pdfMindfire LLC
 
Practical Advice for FDA’s 510(k) Requirements.pdf
Practical Advice for FDA’s 510(k) Requirements.pdfPractical Advice for FDA’s 510(k) Requirements.pdf
Practical Advice for FDA’s 510(k) Requirements.pdfICS
 
Usability Validation Testing of Medical Devices and Software
Usability Validation Testing of Medical Devices and SoftwareUsability Validation Testing of Medical Devices and Software
Usability Validation Testing of Medical Devices and SoftwareUXPA Boston
 
The Future of Quality and Regulatory for SaMD
The Future of Quality and Regulatory for SaMDThe Future of Quality and Regulatory for SaMD
The Future of Quality and Regulatory for SaMDJanel Heilbrunn
 
Software as a Medical Device (SaMD) Challenges and Opportunities for 2021 and...
Software as a Medical Device (SaMD) Challenges and Opportunities for 2021 and...Software as a Medical Device (SaMD) Challenges and Opportunities for 2021 and...
Software as a Medical Device (SaMD) Challenges and Opportunities for 2021 and...Greenlight Guru
 
5 Key Considerations at the Start of SaMD Development
5 Key Considerations at the Start of SaMD Development5 Key Considerations at the Start of SaMD Development
5 Key Considerations at the Start of SaMD DevelopmentICS
 
Unleashing agile testing under medical regulations
Unleashing agile testing under medical regulationsUnleashing agile testing under medical regulations
Unleashing agile testing under medical regulationsLuca Sturaro
 

Similar to IEC 62304: SDLC Conformance and Management (20)

Building a QMS for Your SaMD
Building a QMS for Your SaMDBuilding a QMS for Your SaMD
Building a QMS for Your SaMD
 
Building a QMS for Your SaMD Part II
Building a QMS for Your SaMD Part IIBuilding a QMS for Your SaMD Part II
Building a QMS for Your SaMD Part II
 
Critical Steps in Software Development: Enhance Your Chances for a Successful...
Critical Steps in Software Development: Enhance Your Chances for a Successful...Critical Steps in Software Development: Enhance Your Chances for a Successful...
Critical Steps in Software Development: Enhance Your Chances for a Successful...
 
Health apps regulation and quality control case studies and session 2 present...
Health apps regulation and quality control case studies and session 2 present...Health apps regulation and quality control case studies and session 2 present...
Health apps regulation and quality control case studies and session 2 present...
 
Health apps regulation and quality control case studies and session 2 present...
Health apps regulation and quality control case studies and session 2 present...Health apps regulation and quality control case studies and session 2 present...
Health apps regulation and quality control case studies and session 2 present...
 
Software controlled electron mechanical systems reliability
Software controlled electron mechanical systems reliabilitySoftware controlled electron mechanical systems reliability
Software controlled electron mechanical systems reliability
 
Software Testing - Software Quality (Part 2)
Software Testing - Software Quality (Part 2)Software Testing - Software Quality (Part 2)
Software Testing - Software Quality (Part 2)
 
Overview of Software QA and What is Software Quality
Overview of Software QA and What is Software QualityOverview of Software QA and What is Software Quality
Overview of Software QA and What is Software Quality
 
Perforce user webinar fractyl dhb jb_dhb_adr edits
Perforce user webinar fractyl dhb jb_dhb_adr editsPerforce user webinar fractyl dhb jb_dhb_adr edits
Perforce user webinar fractyl dhb jb_dhb_adr edits
 
When Medical Device Software Fails Due to Improper Verification & Validation ...
When Medical Device Software Fails Due to Improper Verification & Validation ...When Medical Device Software Fails Due to Improper Verification & Validation ...
When Medical Device Software Fails Due to Improper Verification & Validation ...
 
Computer Software Assurance (CSA): Understanding the FDA’s New Draft Guidance
Computer Software Assurance (CSA): Understanding the FDA’s New Draft GuidanceComputer Software Assurance (CSA): Understanding the FDA’s New Draft Guidance
Computer Software Assurance (CSA): Understanding the FDA’s New Draft Guidance
 
Software validation do's and dont's may 2013
Software validation do's and dont's may 2013Software validation do's and dont's may 2013
Software validation do's and dont's may 2013
 
The critical role of QA in Medical Device Testing.pdf
The critical role of QA in Medical Device Testing.pdfThe critical role of QA in Medical Device Testing.pdf
The critical role of QA in Medical Device Testing.pdf
 
Practical Advice for FDA’s 510(k) Requirements.pdf
Practical Advice for FDA’s 510(k) Requirements.pdfPractical Advice for FDA’s 510(k) Requirements.pdf
Practical Advice for FDA’s 510(k) Requirements.pdf
 
Usability Validation Testing of Medical Devices and Software
Usability Validation Testing of Medical Devices and SoftwareUsability Validation Testing of Medical Devices and Software
Usability Validation Testing of Medical Devices and Software
 
The Future of Quality and Regulatory for SaMD
The Future of Quality and Regulatory for SaMDThe Future of Quality and Regulatory for SaMD
The Future of Quality and Regulatory for SaMD
 
Software as a Medical Device (SaMD) Challenges and Opportunities for 2021 and...
Software as a Medical Device (SaMD) Challenges and Opportunities for 2021 and...Software as a Medical Device (SaMD) Challenges and Opportunities for 2021 and...
Software as a Medical Device (SaMD) Challenges and Opportunities for 2021 and...
 
5 Key Considerations at the Start of SaMD Development
5 Key Considerations at the Start of SaMD Development5 Key Considerations at the Start of SaMD Development
5 Key Considerations at the Start of SaMD Development
 
Unleashing agile testing under medical regulations
Unleashing agile testing under medical regulationsUnleashing agile testing under medical regulations
Unleashing agile testing under medical regulations
 
Software Development
Software DevelopmentSoftware Development
Software Development
 

Recently uploaded

Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...lizamodels9
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in managementchhavia330
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Servicediscovermytutordmt
 
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...lizamodels9
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsApsara Of India
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 
RE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechRE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechNewman George Leech
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessAggregage
 
Non Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxNon Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxAbhayThakur200703
 
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth MarketingShawn Pang
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024christinemoorman
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfpollardmorgan
 
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130  Available With RoomVIP Kolkata Call Girl Howrah 👉 8250192130  Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Roomdivyansh0kumar0
 

Recently uploaded (20)

Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
 
GD Birla and his contribution in management
GD Birla and his contribution in managementGD Birla and his contribution in management
GD Birla and his contribution in management
 
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Old Faridabad ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Service
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call GirlsCash Payment 9602870969 Escort Service in Udaipur Call Girls
Cash Payment 9602870969 Escort Service in Udaipur Call Girls
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
RE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman LeechRE Capital's Visionary Leadership under Newman Leech
RE Capital's Visionary Leadership under Newman Leech
 
Sales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for SuccessSales & Marketing Alignment: How to Synergize for Success
Sales & Marketing Alignment: How to Synergize for Success
 
Non Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxNon Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptx
 
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
 
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130  Available With RoomVIP Kolkata Call Girl Howrah 👉 8250192130  Available With Room
VIP Kolkata Call Girl Howrah 👉 8250192130 Available With Room
 

IEC 62304: SDLC Conformance and Management

  • 1. IEC 62304: SDLC Conformance and Management Rita King CEO & Senior Consultant (919) 313-3961 ritaking@methodsense.com
  • 2. AboutMethodSense Our Agenda • Introductions • IEC 62304 Historical Backdrop • IEC 62304 Overview • IEC 62304 Implementation • Some Things to Watch Out For © 2015 MethodSense, Inc. 2
  • 3. AboutMethodSense Introducing Your Presenter Rita King - CEO & Senior Consultant More than 25 years of experience as a regulator, technologist and professional auditor with international reputation as a regulatory expert. Rita is a founding member of the Underwriters Laboratories team that defined, launched, and managed the operations of the first US program to evaluate safety critical software used in commercial and medical devices and developed the ANSI approved Standard for Safety Critical Software, UL 1998. Rita developed and commercialized InfoStrength Smart Enterprise Suite, a 21 CFR Part 11 Software as a Service content management solution specifically designed for the life science industry and founded her company in 2000. © 2015 MethodSense, Inc. 3
  • 4. AboutMethodSense MethodSense Experience MethodSense is a Life Science service company adding strategic value with integrated expertise: • InfoStrength Software Solutions • Regulatory Affairs • Quality Assurance • Technology Management • Business Operations © 2015 MethodSense, Inc. 4
  • 5. HistoricalBackdrop Software, Medical Devices and Managing Risk • In the mid 1990’s the FDA and Underwriters Laboratories (UL) observed a problem: • High percentage of reported incidents of adverse events for medical device software attributed to “user error” by Medical Device Companies • Research showed that a significant number of these incidents had their root cause in the quality or unintended performance of the software itself, not “user error” • UL response to this problem – UL 1998: • UL developed and published the standard UL 1998 for Safety Critical Software • UL 1998 applies to non-networked embedded microprocessor software and addresses the risks unique to product hardware controlled by software in programmable components © 2015 MethodSense, Inc. 5
  • 6. HistoricalBackdrop Software, Medical Devices and Managing Risk • FDA response to this problem: 21 CFR Part 11 • Part 11 requires FDA-regulated industries to implement controls, including audits, system validations, audit trails, electronic signatures, and documentation for software and systems involved in processing electronic data that are: • Required to be maintained by the FDA predicate rules or • Used to demonstrate compliance to a predicate rule. • Applies to software applications that support Medical Device Businesses, Medical Device Products and software applications that qualify as a Medical Device •Part 11 Intent: Establish Safety and Efficacy by Validating or Delivering Evidentiary Demonstration that Software Applications Perform as the User Intends © 2015 MethodSense, Inc. 6
  • 7. HistoricalBackdrop Software, Medical Devices and Managing Risk • Classic Validation Representation • Improved Product Quality © 2015 MethodSense, Inc. 7
  • 8. HistoricalBackdrop Software, Medical Devices and Managing Risk • Additional quality regulations designed to reduce risk and enhance safety • FDA’s 21 CFR Part 820 (GMPs) • ISO 13485 • Does the following equation eliminate unacceptable software risk? GMPs / 13485 + Software Validation = Safe Medical Device Software © 2015 MethodSense, Inc. 8
  • 9. HistoricalBackdrop Software, Medical Devices and Managing Risk • Assessing the equation: GMPs / 13485 + Software Validation = Safe Medical Device Software • GMPs & 13485 are vague when it comes to software QA • Validation insufficiently addresses software risk • FDA Medical Recall Report: FY2003 to FY2012 “Evaluating the Most Common Cause of Recall – Software Design Failures … Failure to implement software design controls, and where appropriate, testing procedures, as well as increasing complexity of the medical device use environment (with increased connectivity and interoperability) can lead to software anomalies often requiring a correction or removal.” © 2015 MethodSense, Inc. 9
  • 10. HistoricalBackdrop Software, Medical Devices and Managing Risk • GMPs / 13485 and Software Validation do not sufficiently eliminate unacceptable risk in medical devices that are or incorporate software • Enter IEC 62304 • Used by EU since 2008 • Incorporated into IEC 60601-1 3rd Edition Amendment 1 (2014) & required by Clause 14 Clause 14 requires manufacturers to comply with IEC 62304 unless the device’s software has no role in providing basic safety or essential performance or risk analysis demonstrates that a failure of any Programmable Electronic Safety System (PESS) does not lead to an unacceptable risk. • Incorporated into IEC 61010 3rd Edition © 2015 MethodSense, Inc. 10
  • 11. HistoricalBackdrop Software, Medical Devices and Managing Risk • IEC 62304 enhances medical device safety by tying the Software Development Life Cycle directly into • ISO 14971 and Risk Management • Compliant Quality Management System (e.g. ISO 13485) • IEC 62304 addresses the risk gap by • Creating specificity for software management where GMPs or ISO 13485 are vague • Incorporating ISO 14971 risk management where Part 11 or Validation does not • And requiring detail or rigor in software Design, Testing, and Verification © 2015 MethodSense, Inc. 11
  • 12. IEC62304Overview What is IEC 62304? • IEC 62304 is the international standard that: • Defines software development lifecycle requirements for medical device software • Requires all aspects of the software development life cycle to be scrutinized, including: • Development • Risk management • Configuration • Problem resolution • Maintenance • Provides a common framework for medical device manufacturers to develop software © 2015 MethodSense, Inc. 12
  • 13. IEC62304Overview What Does Conformance with IEC 62304 Accomplish? • Conformance with IEC 62304: • Fulfills the requirements of the EU Medical Device Directive • Serves as a benchmark for compliance with regulatory requirements in US because it is recognized by the FDA as a consensus standard • Recognized in most countries that use compliance standards to fulfill regulatory requirements • Conformance with IEC 62304 has become a part of medical device commercialization roadmap © 2015 MethodSense, Inc. 13
  • 14. IEC62304Overview Is Conformance with IEC 62304 Required? • Is IEC 62304 Required in the US Market? • Technically, “NO” because it is voluntary • For all practical purposes, “YES” if you fall into one of these categories • IEC 60601-1 3rd Edition Amendment 1 is required • The device relies upon software to perform Basic Safety functions • The device relies upon software for Essential Performance • If you do not conform with IEC 62304 and also fall into one of these categories then you must demonstrate the software development process used is as good as, or better than, the process presented in IEC 62304, a form of de facto compliance © 2015 MethodSense, Inc. 14
  • 15. IEC62304Overview Is Conformance with IEC 62304 Required? • How do I know if IEC 60601-1 3rd Edition Amendment 1 Applies to My Device? • If IEC 60601-1 3rd Edition Amendment 1 Clause 14 applies to the medical device, then • Clause 14 requires manufacturers to comply with IEC 62304 • Unless the device’s software has no role in providing basic safety or • Essential Performance or risk analysis demonstrates that a failure of any Programmable Electronic Safety System (PESS) does not lead to an unacceptable risk. © 2015 MethodSense, Inc. 15
  • 16. IEC62304Overview Is Conformance with IEC 62304 Required? • How do I know if the device relies on software for basic safety? • If the role of the software includes risk mitigation then the software has a role in providing basic safety • Examples: • A primary function of the device is controlled by software. • Software mitigates a risk if hardware fails • A risk analysis will identify your device’s level of unacceptable risk and determine the role of software in risk mitigation © 2015 MethodSense, Inc. 16
  • 17. IEC62304Overview Is Conformance with IEC 62304 Required? • How do I know if the device relies on software for Essential Performance? • Follow a process of elimination: • List all functional aspects of your device, including accuracy, measurements and its capabilities • Determine whether any of these are already covered by the Basic Safety requirements of IEC 60601-1 or whether any item is not part of the device’s intended use • For every item remaining that is controlled by software, pose the question: “If this item degrades, will it create a risk for the patient?” • If “YES” for any item, you must identify how product’s functionality must be maintained so the risk is still acceptable (i.e. utilize hardware controls as a back up mechanisms to a potential software failure, include separate software controls, software validation, etc.) • This is the device’s Essential Performance © 2015 MethodSense, Inc. 17
  • 18. IEC62304Overview Is Conformance with IEC 62304 Required? • Example of software as Essential Performance? • Consider a device that claims its Essential Performance is accurate within 5%. • If the device is relying on software to maintain that accuracy or provide an alert when outside of 5%, and that software fails, then the manufacturer will be unable to detect if the device’s Essential Performance is being met. • This means the software is providing Essential Performance. • Once you know your device software is responsible for Essential Performance, you must comply with IEC 62304 to ensure there is no unacceptable risk to a patient © 2015 MethodSense, Inc. 18
  • 19. IEC62304Implementation How do You Conform with IEC 62304? • IEC 62304 Challenge • The Devil is in the Details…….. • There are A Lot of Details • There are ways to practically tackle this challenge to accommodate your company’s needs and satisfy the requirements of the standard for a medical device © 2015 MethodSense, Inc. 19
  • 20. IEC62304Implementation How do You Conform with IEC 62304? • Conforming with IEC 62304 requires 2 parts • Processes – Policies & Procedures for your Software Development Life Cycle • Evidence that those processes are applied to the medical device software • The processes developed and applied to your medical device software depends on its Software Safety Classification • Our Next Steps: • Review Software Safety Classifications • High Level Review and Practical Application of Processes • Tying Processes to SDLC Evidence for the Test Laboratory © 2015 MethodSense, Inc. 20
  • 21. IEC62304Implementation IEC 62304 Software Safety Classifications Safety Classifications: IEC 62304 v. FDA Software Level of Concern • Safety Classifications Considerations • The riskier the software, the more rigorous the controls • Important Tip: Clear segmentation of software can allow for discreetly classifying parts of the software which may make the documentation and testing easier IEC 62304 Software Safety Classification FDA Pre-Market Submission Software Levels of Concern Class A: No Injury or Damage to Health is Possible Minor: Failures or latent design flaws are unlikely to cause any injury Class B: Non-serious Injury is Possible Moderate: Failure or latent possible design flaw could directly or indirectly result in minor injury Class C: Death or Serious Injury is Possible Major: Failure or flaw could directly or indirectly result in death or serious injury © 2015 MethodSense, Inc. 21
  • 22. IEC62304Implementation Software Development Life Cycle Process •IEC 62304 Processes, Tasks and Deliverables must be implemented •Requires a Quality Management System and Risk Management Process compliant with ISO 14971 •However, IEC 62304 does not prescribe: •An organizational structure •A particular methodology •A particular document format © 2015 MethodSense, Inc. 22
  • 23. IEC62304Implementation IEC 62304 SDLC Deliverables •Challenge: This has the look and feel of an SDLC known as the Waterfall Model. Is that so? •NO. What this represents is a set of deliverables for a Test Laboratory or a Regulatory Authority (e.g. the FDA) •Important: Think in terms of incorporating into your SDLC methodology the creation of these deliverables © 2015 MethodSense, Inc. 23
  • 24. IEC62304Implementation IEC 62304 SDLC Deliverables •IEC 62304 is pretty clear about what deliverables are required •Test Laboratories have their own check lists you can use as guidance to demonstrate your IEC 62304 compliance •MethodSense has created an IEC 62304 Action List that identifies the required deliverables and we can share this with you •Therefore, the IEC 62304 deliverables are well understood and we can focus on practical considerations for implementation © 2015 MethodSense, Inc. 24
  • 25. IEC62304Implementation IEC 62304 Implementation for Alternative SDLC Methodologies • Waterfall Model: • Generally recognized as impractical and rarely used SDLC model • Fails to account for the iterative nature of Software Development • As a model accommodates the creation of deliverables (e.g. documents) because it allows minimal change along the way • Agile Model: • Generally recognized as a very practical SDLC model • Accounts for the iterative nature of software development • As a model and depending on its implementation makes it difficult to efficiently create the expected 62304 deliverables (e.g. documents) since requirements may be changing during software development • How can you generate IEC 62304 deliverables in an Agile environment? © 2015 MethodSense, Inc. 25
  • 26. IEC62304Implementation IEC 62304 and Agile Development Methodologies • IEC 62304 Conformance Tips in an Agile Environment • Map onto your Agile SDLC IEC 62304 deliverables • Think about segmenting your software to allow the Safety Classifications to apply differently to the different software segments • Ensure your automated tools will deliver documents that meet expectations and conformance needs • If your deliverables cannot keep up with your method, think about scaling back iterative change in a hybrid approach © 2015 MethodSense, Inc. 26
  • 27. IEC62304Implementation IEC 62304 Tips • Common software functionality manufacturers fail to recognize as IEC 62304 compliance issues: • Alarms and Alerts - often an Essential Performance requirement because they are intended to detect abnormalities • Speed & Position Sensors - use software to limit range of motion, speed and force which are Basic Safety concerns • Algorithms - remove the software and the device is no longer able to operate as intended, resulting in the algorithms being part of Essential Performance © 2015 MethodSense, Inc. 27
  • 28. IEC62304Implementation IEC 62304 Tips • Pitfalls to Avoid • Document Your Process Well – document management is essential for meeting compliance goals • Software of Unknown Pedigree (SOUP) – manage your SOUP appropriately • Document Development – make certain you are sufficiently resourced to support document development needs • Version Control & Updates – clearly define what is a software update and further how the software will be maintained in a validated state © 2015 MethodSense, Inc. 28
  • 29. IEC62304Implementation IEC 62304 Tips • What if Your Device Software is Developed by a Third Party? • Supplier Management Process – confirm that software vendor complies with IEC 62304 and processes are reviewed during vendor audit • Quality Agreement – confirm that: • It defines vendor responsibilities and 62304 Deliverables • Vendors procedures used for software development will be provided to you and the test lab for review • Establish your SDLC – at minimum, your process will define acceptance criteria (i.e. IEC 62304 compliance and deliverables) from your vendor © 2015 MethodSense, Inc. 29
  • 30. IEC62304Implementation IEC 62304 Success • IEC 62304 File will be reviewed to ensure: • It contains all required documentation including a risk management file • Procedures meet the requirements of the standard • Each check list item is satisfied • A product review is conducted and further a review of the relevant software segments if it has been decided that the software performs Basic Safety or Essential Performance for your device •After the review, a Pass or Fail Report is delivered Move Commercialization Forward! © 2015 MethodSense, Inc. 30
  • 31. Confidential MethodSense Thanks You!!! Discussion / Q&A © 2015 MethodSense, Inc. 31
  • 32. Thank you. Rita King CEO & Senior Consultant (919) 313-3961 ritaking@methodsense.com © 2015 MethodSense, Inc.