IEC 60601-1 - Essential performance doesn't make sense

Peter Selvey

Staff member
Super Moderator
#11
If I look through this thread, it seems the key point is the difference between "classification" and actual risk evaluation.

For the purpose of classification it is not unusual to assume something will fail with 100% probability. This is useful as it helps to highlight what is critical, what needs to be watched carefully in tests, and where risk controls should be applied.

However, once you move to the actual phase of adding risk controls and evaluating risks, you then need to switch to realistic values for probability of failure. Otherwise you get nonsensical results and infinite loops.

I believe that intention of IEC 60601-1 for essential performance. But it is poorly worded. In the classification phase it says to evaluate the "RISK from the loss or degradation of the identified performance beyond the limits specified".

Whereas after risk controls are implemented it is just "RISK from the loss or degradation of the identified performance".

So it seems the extra words "beyond the limits specified" are intended to mean an assumed loss/degradation with 100% probability.

But that is not clear.

IEC 62304 A1 has tied itself up in knots over the same issue, and it useful to look at that to help understand the same issue associated with essential performance.

In the pre-amendment version, in the initial classification phase you assume the software fails with 100% probability. Then, as a second stage if you have an external hardware risk control you could drop one class (e.g. Class C to Class B). It's not explicitly stated but it is obvious that in this second stage the software is no longer considered to fail 100%. Otherwise, a single external hardware risk control would not be enough to make the risk acceptable. With the external hardware risk control, it means that you now have two systems that both need to fail (2MOP structure) which then achieves very low probability as expected for high risk devices. For this to work though it's necessary to assume that both systems have fairly low probability of failure, including the software system. You can't assume software fails at 100%.

In A1 version, it starts out the same, initial classification assume software fails 100%. But they wanted to allow other risk controls, not just hardware so they said it can be any external risk control measure. But ... this means that weak risk controls could be used. So, it needs to be judged if the risk control is effective. Up to here all OK, but here comes the mistake ... they said just go back and do the classification again with the risk control in place. The problem is that we are still assuming the software fails with 100%, which means reasonable risk controls (like independent hardware protection) are no longer effective. For high severity applications, you would need two independent external protection systems in order achieve acceptable risk. Also if you did apply two external risk controls, the Class would drop from C to A, not C to B. For high severity harm, you can't get to Class B in the current version of IEC 62304.

All of this makes no sense, and it occurs because of the use of "100% failure" in the risk control phase, rather than just for initial classification.

I've already written a letter to the committee to fix this issue, and I proposed that for the initial phase it's OK to assume 100% failure, and then as a second stage say ... "if an external risk control measure is used, with an equivalent effectiveness as one means of protection in IEC 60601-1, then the software can be reduced one step in class."

It looks like something similar is needed for essential performance, i.e. to make it clear that to determine essential performance, assume 100% failure of the performance related function, but in the risk control phase use actual probability of harm.
 
Elsmar Forum Sponsor
Thread starter Similar threads Forum Replies Date
W IEC 60601 - Essential performance c.2.34 IEC 60601 - Medical Electrical Equipment Safety Standards Series 2
shimonv IEC 60601-1 Essential Performance - Is the signal accuracy specification an essential requirement? IEC 60601 - Medical Electrical Equipment Safety Standards Series 4
rezayatmand IEC 60601-2-18 Medical electrical equipment - Part 2-18: Particular requirements for the basic safety and essential performance of endoscopic equipmen IEC 60601 - Medical Electrical Equipment Safety Standards Series 2
Z In which country is essential to have and IEC 60601 CB Report? Other Medical Device Related Standards 0
D IEC 60601-1 - Performance limits for essential performance IEC 60601 - Medical Electrical Equipment Safety Standards Series 4
K IEC 60601-1 and Essential Performance IEC 60601 - Medical Electrical Equipment Safety Standards Series 5
M IEC 60601 - Limits of agreement as Essential Performance IEC 60601 - Medical Electrical Equipment Safety Standards Series 3
D IEC 60601-2-44: 202.101 Immunity Testing of Essential Performance IEC 60601 - Medical Electrical Equipment Safety Standards Series 0
L "Potential" Essential Performance in IEC 60601-2-54 (Definition) IEC 60601 - Medical Electrical Equipment Safety Standards Series 9
A Essential Performance in IEC 3rd edition of the 60601-1 IEC 60601 - Medical Electrical Equipment Safety Standards Series 5
JoCam IEC 60601-1 and 60601-1-2 retest after PCBA change IEC 60601 - Medical Electrical Equipment Safety Standards Series 3
K IEC 60601-1:2005/AMD2:2020, Why this standard version is 3.0? IEC 60601 - Medical Electrical Equipment Safety Standards Series 2
C IEC 60601 - 8.8.3 Dielectric Strength test. 4kv being applied to the ground conductor?! IEC 60601 - Medical Electrical Equipment Safety Standards Series 2
R IEC 60601-1 Clause 15.3.2, Push test IEC 60601 - Medical Electrical Equipment Safety Standards Series 0
A Defining a lower ESD test level in IEC 60601 safety test IEC 60601 - Medical Electrical Equipment Safety Standards Series 5
J IEC 60601-1-11 Home Class II With Ballasts IEC 60601 - Medical Electrical Equipment Safety Standards Series 3
A Coverage and differences: EN 60601-1:2006+A12:2014 Vs AAMI/IEC 60601-1:2005+AMD1:2012 IEC 60601 - Medical Electrical Equipment Safety Standards Series 2
T IEC 60601-1-8:2020 Is it necessary to change the alarm melody? IEC 60601 - Medical Electrical Equipment Safety Standards Series 1
M Is it normal / sufficient to have only the IEC 60601-1-2 test report without indicating IEC 60601-1? IEC 60601 - Medical Electrical Equipment Safety Standards Series 2
S IEC 60601-2-30 - Is it mandatory to claim alarms? IEC 60601 - Medical Electrical Equipment Safety Standards Series 1
Y Auditory alarm standard IEC 60601-1-8 Reliability Analysis - Predictions, Testing and Standards 0
R IEC 60601-1 - Power Supply Cords (Section 8.11.3.1) IEC 60601 - Medical Electrical Equipment Safety Standards Series 2
A Outsourcing IEC 60601-1 Ed 3.2 Testing IEC 60601 - Medical Electrical Equipment Safety Standards Series 0
R Complex IEC 60601-1 gap assessment IEC 60601 - Medical Electrical Equipment Safety Standards Series 0
D SINGLE FAULT CONDITION, short circuit and open circuit of any component (IEC 60601-1 3.1) IEC 60601 - Medical Electrical Equipment Safety Standards Series 9
H IEC 60601-1 ME equipment or ME system IEC 60601 - Medical Electrical Equipment Safety Standards Series 2
M How does IEC-60601-1 apply to a non-medical device in the patient vicinity? IEC 60601 - Medical Electrical Equipment Safety Standards Series 1
R IEC 60601-1 - 11.1.3 e) Test criteria - Temperature Measurements IEC 60601 - Medical Electrical Equipment Safety Standards Series 2
R IEC 60601-1 - Magnesium oxide used for the electrical insulation of heating elements IEC 60601 - Medical Electrical Equipment Safety Standards Series 3
M Is IEC 60601-1-2 required by FDA for all electronic medical devices? IEC 60601 - Medical Electrical Equipment Safety Standards Series 1
Z IEC 60601-2-25; Frequency response test Medical Device and FDA Regulations and Standards News 1
N IEC 60601-1-1 - Stress test, reference voltage IEC 60601 - Medical Electrical Equipment Safety Standards Series 2
R IEC 60601-1:2005+AMD1:2012+AMD2:2020 CSV IEC 60601 - Medical Electrical Equipment Safety Standards Series 1
B IEC 60601 - Creepage Distance - Relay that acts as a means of physical mechanical protection Process Maps, Process Mapping and Turtle Diagrams 0
T Single Fault Condition IEC 60601 Clause 8.7.1 shorting Cr/Cl in Patient Applied Part IEC 60601 - Medical Electrical Equipment Safety Standards Series 7
M What to Expect from Next IEC 60601-1 and IEC 60601-1-2 Amendments? IEC 60601 - Medical Electrical Equipment Safety Standards Series 7
D IEC 60601-1 - Service life testing IEC 60601 - Medical Electrical Equipment Safety Standards Series 8
R Hand transmitted vibration 9.6.3 of IEC 60601-1 IEC 60601 - Medical Electrical Equipment Safety Standards Series 4
A IEC 60601 11.2.2.1 Risk of Fire in an Oxygen Rich Environment, Source of Ignition IEC 60601 - Medical Electrical Equipment Safety Standards Series 0
E PEMS Hazards - IEC 60601 Clause 14.6 - Internal data use - Pressure sensor IEC 60601 - Medical Electrical Equipment Safety Standards Series 3
B IEC 60601-2-43 - Clause 203.6.103 - Physical button? IEC 60601 - Medical Electrical Equipment Safety Standards Series 1
M IEC 60601-1 1988 - Device developed in 2012 with standard of 1988 IEC 60601 - Medical Electrical Equipment Safety Standards Series 2
A IEC 60601-1 Dielectric Strength test for battery operated devices IEC 60601 - Medical Electrical Equipment Safety Standards Series 3
E IEC 60601-1 - Unearthed Medical Device Metal Parts IEC 60601 - Medical Electrical Equipment Safety Standards Series 1
JoCam Failure to test Class I medical device to IEC 60601-1-11 IEC 60601 - Medical Electrical Equipment Safety Standards Series 2
R IEC 60601-1 - Different methods of achievement of the isolation IEC 60601 - Medical Electrical Equipment Safety Standards Series 1
K What is mean by Oxygen Rich Environment as per the IEC 60601-1 clause no 11.2.2 IEC 60601 - Medical Electrical Equipment Safety Standards Series 5
K Dielectric strength test as per IEC 60601-1 -Infant incubator IEC 60601 - Medical Electrical Equipment Safety Standards Series 2
A Unused SIP/SOPs - IEC 60601-1 and IEC 60601-1-2 IEC 60601 - Medical Electrical Equipment Safety Standards Series 1
K Proper document of SMPS used in infant warmer for IEC 60601-1 testing IEC 60601 - Medical Electrical Equipment Safety Standards Series 1

Similar threads

Top Bottom