{"id":4316,"date":"2015-10-26T16:29:46","date_gmt":"2015-10-26T16:29:46","guid":{"rendered":"https:\/\/lorit-consultancy.com\/2015\/10\/it-may-be-safe-but-is-it-functionally-safe\/"},"modified":"2024-07-25T15:45:50","modified_gmt":"2024-07-25T13:45:50","slug":"it-may-be-safe-but-is-it-functionally-safe","status":"publish","type":"post","link":"https:\/\/lorit-consultancy.com\/en\/2015\/10\/it-may-be-safe-but-is-it-functionally-safe\/","title":{"rendered":"It may be safe, but is it functionally safe?"},"content":{"rendered":"\n<p><em>Last updated: 25.07.2024<\/em><\/p>\n\n\n\n<p>There are many standards focusing on the safety of medical devices. However, <strong>functional safety<\/strong> is oddly not so well represented. Much of this is partly due to the long list of standards and guidance documents that medical device manufacturers must work through. Another aspect is the lack of training and knowledge in the industry regarding this subject area.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What do we mean by functional safety?<\/h2>\n\n\n\n<p>Let\u2019s start by looking at the definitions.<\/p>\n\n\n\n<p><strong>ISO 26262<\/strong>: absence of unreasonable risk due to hazards caused by malfunctioning behavior of E\/E systems.<br><strong>ISO 25119<\/strong>: system that performs in a way that does not present an unreasonable risk of injury to operators or bystanders.<br>The <strong>IEC 61508<\/strong> Association: at its simplest, functional safety is the part of the overall safety relating to the equipment under control and its associated control system that depends on the correct functioning of the safety-related system.<\/p>\n\n\n\n<p>Functional safety is ultimately <strong>active safety<\/strong>, focusing on a device that implements some \u2018intelligent\u2019 functionality. It is a term that usually applies to electrical, electronic, or programmable systems, where the design of the product will introduce a control function that has a safety relevance. So basically, functional safety is about the active parts of the system functioning correctly and not causing harm through malfunction.<\/p>\n\n\n\n<p>In contrast to active safety, <strong>passive safety <\/strong>plays a big part in medical device development. Standards such as <a href=\"https:\/\/lorit-consultancy.com\/en\/standards\/medical-devices\/iec60601\/\" target=\"_blank\" rel=\"noreferrer noopener\">IEC 60601<\/a> and <a href=\"https:\/\/lorit-consultancy.com\/en\/standards\/medical-devices\/iec61010\/\" target=\"_blank\" rel=\"noreferrer noopener\">IEC 61010<\/a> cover many passive safety topics, e.g. the risk of electrocution, the concerns around mechanical injury, and the risk of burning to either operators or patients.<\/p>\n\n\n\n<p>Passive safety is most easily considered when looking at either the physical spacing across a printed circuit board (PCB) or the number of insulating jackets on a mains cable. In both cases, we have physically added a passive barrier to meet the electrical isolation requirements.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1286\" height=\"418\" src=\"https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2015\/10\/Pic1_Creepage-and-clearance.png\" alt=\"\" class=\"wp-image-7886\" srcset=\"https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2015\/10\/Pic1_Creepage-and-clearance.png 1286w, https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2015\/10\/Pic1_Creepage-and-clearance-1024x333.png 1024w, https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2015\/10\/Pic1_Creepage-and-clearance-768x250.png 768w\" sizes=\"auto, (max-width: 1286px) 100vw, 1286px\" \/><\/figure>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"594\" height=\"286\" src=\"https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2015\/10\/Pic2_Insulation-on-cable.png\" alt=\"\" class=\"wp-image-7888\"\/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<p class=\"has-text-align-center\"><em>Fig. 1 Passive safety<\/em><\/p>\n\n\n\n<p>Functional safety focuses on the potential malfunction or loss of control of an active system. In Figure 2, the microcontroller MCU1 is responsible for controlling the speed and torque of the motor. If there is a malfunction of this motor control, then this could lead to potential harm to a driver and other road users. Hence, our focus here is the safety of this \u2018intended function\u2019. To meet the functional safety goals of the motor drive, a second microcontroller, MCU2, is added to check the correct operation of MCU1.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1752\" height=\"848\" src=\"https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2015\/10\/Fig.2_motor-drive-system.png\" alt=\"\" class=\"wp-image-7890\" srcset=\"https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2015\/10\/Fig.2_motor-drive-system.png 1752w, https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2015\/10\/Fig.2_motor-drive-system-1024x496.png 1024w, https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2015\/10\/Fig.2_motor-drive-system-768x372.png 768w, https:\/\/lorit-consultancy.com\/wp-content\/uploads\/2015\/10\/Fig.2_motor-drive-system-1536x743.png 1536w\" sizes=\"auto, (max-width: 1752px) 100vw, 1752px\" \/><figcaption class=\"wp-element-caption\">Fig. 2 A motor drive system<\/figcaption><\/figure>\n<\/div>\n\n\n<p>Functional safety inherently means the safe operation of a product in its intended function. So, if we take an ECG stress system, to be functionally safe, it must maintain control of its treadmill throughout the entire time it is operating.<\/p>\n\n\n\n<p>To achieve a functionally safe system, a detailed analysis is required to determine potential malfunctions of the intended functionality followed by adding risk control mechanisms, such as MCU2 in Fig. 2, to mitigate the potential risk.<\/p>\n\n\n\n<p>For passive safety, the risk analysis is equally important, but the outcome will focus more on adding additional creepage, clearance or solid insulation in the form of, for example, cable jackets.<\/p>\n\n\n\n<p>Another passive safety concern might arise from insufficient information being given about the weight of the treadmill, causing an accident when someone moves it. This is typically mitigated by warning symbols and information in the accompanying documents.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Where the medical device industry is going<\/h2>\n\n\n\n<p>The medical device sector has seen a number of moves towards functional safety in the last few years. For example, IEC 61010-2-101 for in vitro devices has an annex referring to the use of functional safety standards such as ISO 13849 and IEC 62061, although with minimal explanation of what it actually means. IEC 60601-1 has the Programmable Medical Electrical Systems section 14, which introduces key terms from the functional safety world, but again with no real explanation of the meanings or potential solutions. It will be interesting to see what emerges in V4.0 of IEC 60601.<\/p>\n\n\n\n<p>By <a href=\"https:\/\/lorit-consultancy.com\/en\/about-us\/#alastair-walker\">Alastair Walker<\/a>, Owner \/ Consultant<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last updated: 25.07.2024 There are many standards focusing on the safety of medical devices. However, functional safety is oddly not so well represented. Much of this is partly due to the long list of standards and guidance documents that medical device manufacturers must work through. Another aspect is the lack of training and knowledge in [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":5353,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[92],"tags":[],"class_list":["post-4316","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-medical-devices"],"acf":[],"_links":{"self":[{"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/posts\/4316","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/comments?post=4316"}],"version-history":[{"count":9,"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/posts\/4316\/revisions"}],"predecessor-version":[{"id":7898,"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/posts\/4316\/revisions\/7898"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/media\/5353"}],"wp:attachment":[{"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/media?parent=4316"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/categories?post=4316"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lorit-consultancy.com\/en\/wp-json\/wp\/v2\/tags?post=4316"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}