← Training

IEC 60601-1 / IEC 61508

Functional Safety for Medical Devices

Who it’s for

Who should attend


Hardware, software and systems engineers developing active and electrical medical devices, together with verification and validation engineers, risk managers, and the regulatory and quality staff who review their output. Suited to teams building devices that rely on protective functions to stay safe in a single fault condition, such as infusion pumps.

Curriculum

Course modules


  1. Introduction to functional safety for medical devices: definitions, the safe state, and why active and electrical medical devices rely on protective functions
  2. The anchor standards: single fault safety under IEC 60601-1 clause 4.7, with the programmable electrical medical system (PEMS) requirements of clause 14 alongside it, and how IEC 61508 provides the underlying functional safety framework
  3. Functional safety within the ISO 14971 risk control hierarchy: inherent safety by design first, then protective measures, then information for safety, with functional safety as a protective measure
  4. The single fault safety philosophy: a first random hardware failure can occur at any time and in any place; the first failure must not cause an unacceptable risk; if the first failure is obvious to the operator the device will no longer be used; if the first failure cannot be detected, a second failure is assumed after the MFOT; and the combination of the first and second failure must not cause a hazard
  5. The key time concepts: fault tolerance time (FTT), the time between the occurrence of a failure and harm to the patient or operator, and multiple fault occurrence time (MFOT), the time after a first failure within which the probability of a second independent failure is sufficiently low
  6. System roles: the control system (C, or CS) that achieves the intended use of the device, and the protective system (P, or PS) that prevents harm in the event of a single fault condition in the control system
  7. Safety architectures: CP, a control system with one protective system; CPP, a control system with two protective systems; and C+WD, a control system with a watchdog
  8. Fail-safe design: defined safe states, keeping the device under control, and how each architecture detects a failure and moves to the safe state
  9. Architecture requirements compared: how independency, effectiveness of the protective system, self-test frequency and self-test effectiveness differ across CPP, CP and C+WD. Self-test frequency is driven by the MFOT for the protective system in a CP architecture, and by the FTT for the control system together with the MFOT for the watchdog in a C+WD architecture. Self-test effectiveness is graded per IEC 61508-2, and in C+WD the watchdog must initiate the safe state independently of the control system
  10. Common mode failures: measures against supply voltage failures, including not placing two CPUs on a single voltage rail, and, for C+WD specifically, measures against failure of the time base
  11. Safety Integrity Levels (SIL) and why SIL 2 is the level typically applied to medical devices, with routes to a higher integrity level through redundancy
  12. The PEMS architecture document as a required deliverable: what it must capture and how it is reviewed
  13. Verification evidence: test evidence that the protective system is effective when the control system fails, and test evidence that the self-test detects a failure of the protective system
  14. Worked example, the infusion pump: hazards such as wrong flow rate, wrong volume, over-pressure, free-flow or reverse flow, air infusion and unintended start or stop, mapped to CP, CPP and C+WD architectures
  15. Integrating functional safety into the ISO 14971 risk management file, and the interfaces with the IEC 62304 software life-cycle processes

Outcomes

What you’ll be able to do


  • Apply the single fault safety philosophy and place functional safety within the ISO 14971 risk control hierarchy
  • Select a suitable safety architecture (CP, CPP or C+WD), set self-test frequency from the FTT and MFOT, and justify the target SIL
  • Produce the PEMS architecture document and the verification evidence a reviewer will expect

How it works

Delivery, group size and what’s included


Delivery formats

On-site at your premises, live remote, or public open course.

Duration

The durations shown are minimums. Most courses run from 2 to 5 days, and longer or combined programmes can be arranged to suit the course and your requirements.

Group size

No minimum for remote or private on-site training. Public courses run with a minimum of 10 attendees. There is no fixed maximum; above 20 we normally split into groups, though this is open to discussion.

Assessment

Courses include an assessment.

Tailoring

Private training can be tailored to your products and your quality system. Where a course is tailored, specific documents may be requested in advance. Public courses are general in scope, though relevant worked examples are provided.

Languages

English and Italian. German and Russian available on request through an associate.

Included in the fee

  • Full course slides (PDF)
  • Workshops
  • Practical exercises
  • Case studies
  • Open Q&A throughout
  • Certificate of attendance (PDF), issued by ALPA Medical
  • Up to 4 hours of post-course support

Get in touch

Enquire about “Functional Safety for Medical Devices”

Ask about dates, on-site or remote delivery, group size, or tailoring this course to your products and quality system.