ISO 62304 and Validation of Medical Device Software Tools

E

Enkidu

#1
Hi,

Apologies if I'm asking a question that's already been answered. If so, any pointers an answer would be gratefully received.

I'm working with a manufacturer who is using an agile methodology to create class C medical device software. The organisation wants to ensure its QMS and practices are 62304 compliant. I'm supposed to be helping.

One of the issues I have is related to software tools. I'm struggling to understand the full extent of what's required to validate our configuration management software. What I'm finding hardest to understand is whether the tool needs to be on a dedicated server, how secure any server needs to be. Questions of that ilk.

Can anyone suggest where I might go for guidance? Or can anyone provide any guidance?

Any help gratefully received.
 
Elsmar Forum Sponsor
A

alex.Kennedy

#4
Re: ISO 62304 and Validation of Software Tools

This is one of the major concerns is using 'software tools' to manipulate software. You must validated your 'tools' thoroughly to give confidence that the software is not adultered.
This has often preclude the use of such tools in the pharmaceutical field. I.E. validation of the tools was a bigger task than validation of the software.
Where you store validated software must conform to cGMP requirements. That usually means validating the system to ensure security of the data from unauthorized access, fire, tempest, floods all other biblical disasters.
 
A

alex.Kennedy

#5
Re: ISO 62304 and Validation of Software Tools

This is one of the major concerns is using 'software tools' to manipulate software. You must validate your 'tools' thoroughly to give confidence that the software is not adultered by the use of the ‘Tools’.

This has often precluded the use of such tools in the pharmaceutical field. I.E. validation of the tools was a bigger task than validation of the software.

Storage of validated software, including tools used with this software, must conform to cGMP requirements. That usually means validating the system to ensure security of the data from unauthorized access/use/modification, fire or environmental degradation.

Alex Kennedy
 
Last edited by a moderator:
M

Micked

#6
Re: ISO 62304 and Validation of Software Tools

Validation of software tools is a never ending source of confusion, ask me I've been there...
Ever tried to validate a C compiler?

I have actually found some light in the AAMI guidance TIR-36. This has the usual setup of intended use - requirements - installation - verification - maintenance etc. The largest value of this report is the examples provided. They walk you through validation of everything from a simple spreadsheet through a C compiler to a complex manufacturing system. Highly recommended!
This technical report is also on its way to be an IEC TR (technical report).

Good luck!
 
Y

yalna

#7
Re: ISO 62304 and Validation of Software Tools

Sorry for bringing this thread back from the dead but...

I am currently in the middle of trying to validate a compiler (VS2010) and honestly, have no idea where to start from...

The FDA states in "Off-The-Shelf Software Use in Medical Devices" guideline the basic documentation required, one of which is: "5. How do you know it works?" part.

So how can I know a compiler works without covering all of the end cases?
Is assuming that millions of developers worldwide using it is sufficient?

Thanks,

Yalna
 

sagai

Quite Involved in Discussions
#8
Re: ISO 62304 and Validation of Software Tools

Hi Yalna,
that special control relates to OTS built into the MD, that guide has no relevance to your problem I think, due to compiler is not built into the MD.
What you are looking for is how to comply with 21CFR820.70(i) actually.

For compiler :)
Is assuming that millions of developers worldwide using it is sufficient?
In medical industry it does not save our soul. :cool:

what you can do is to drive your validation effort into almost zero with common sense involvement :tg:, namely the validity of the compiler operation is checked implicitly during the unit/subsystem/whatever product testing, because those test would fail obviously in case the compiler would have failed to fulfill itsown intended use.
Well it should be packaged nicely into a rational.

Regards
Szabolcs
 
Y

yalna

#9
Re: ISO 62304 and Validation of Software Tools

Thanks for the reply.

You helped me put some sense into the whole procedure.

Yalna
 
Thread starter Similar threads Forum Replies Date
M Risk Analysis Flow - Confusion between ISO 14971 and IEC 62304 IEC 62304 - Medical Device Software Life Cycle Processes 8
P Risk acceptability alignment between ISO 14971 and IEC 62304 IEC 62304 - Medical Device Software Life Cycle Processes 6
S Relationship between IEC 62304 problem resolution and ISO 13485 IEC 62304 - Medical Device Software Life Cycle Processes 8
T Is there any requirement to be compliant with IEC 62304 while implementing ISO 13485 ISO 13485:2016 - Medical Device Quality Management Systems 5
B Our NB says that IEC 62304 is an ISO 14971 Requirement ISO 14971 - Medical Device Risk Management 1
B Clarification on interpretation of some EN ISO 14971:2012 & IEC 62304:2006 req's ISO 14971 - Medical Device Risk Management 46
H ISO 14971 vs. IEC 62304 vs. 98/79/EC vs. ISO 13485 (Software Medical Device) ISO 14971 - Medical Device Risk Management 1
M IEC 62304, ISO 14971 and FDA Medical Device SW Guidance 21 CFR Part 820 - US FDA Quality System Regulations (QSR) 5
K ISO 14971 and IEC 62304 - Medical Device Software House ISO 14971 - Medical Device Risk Management 9
T ISO 62304 - Software requirements content IEC 62304 - Medical Device Software Life Cycle Processes 3
F How to Align a Software Consulting/Contract Firm to ISO 13485+14971 & 62304 ISO 13485:2016 - Medical Device Quality Management Systems 1
K Regarding ISO 62304 Clause 7.3.3 - Hazard and Risk Controls IEC 62304 - Medical Device Software Life Cycle Processes 9
Q ISO 62304 (Medical Device Software Development) Verification Requirements IEC 62304 - Medical Device Software Life Cycle Processes 1
D Applications that assist completing IEC 62304, ISO 14971 or ISO 13485 Documentation IEC 62304 - Medical Device Software Life Cycle Processes 7
K ISO 62304 Software Risk Management and Medical Device Class IEC 62304 - Medical Device Software Life Cycle Processes 5
I Is ISO 14971 certification required for IEC 62304? IEC 62304 - Medical Device Software Life Cycle Processes 11
I Software Design SOP to ISO 62304 (Software life cycle for Medical Device) IEC 62304 - Medical Device Software Life Cycle Processes 3
K Medical Device Software - Design Outputs? ISO 90003 and ISO 62304 IEC 62304 - Medical Device Software Life Cycle Processes 3
chris1price Archiving of paper records - ISO 9001 7.5.3.1b Records and Data - Quality, Legal and Other Evidence 2
M Transferring ISO 17025 from one company to another ISO 17025 related Discussions 1
D Common practices in ISO 9001 deployment ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 17
Q ISO 9001-2015 Internal audit finding Internal Auditing 12
B ISO 17025:2017 risk management Risk Management Principles and Generic Guidelines 0
P Audit check for IT company (ISO 9001) ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 7
M Label Making & Printing Standards ISO / ASTM ISO 13485:2016 - Medical Device Quality Management Systems 5
Sidney Vianna Interesting Discussion Should ISO 9004 be changed from a guidance standard to a requirements standard? ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 5
Ed Panek ISO 13485:2016 Section 5.5.3 ISO 13485:2016 - Medical Device Quality Management Systems 3
Q Do these certificates of calibration meet ISO 9001 requirements for traceability to NIST? ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 10
ebrahim QMS as per ISO 13485, Clause 4.2 Requirements for regulatory purposes for Medical Devices Authorized Representatives. ISO 13485:2016 - Medical Device Quality Management Systems 3
S ISO 2768-mk print call out Other ISO and International Standards and European Regulations 11
T ISO 17024, clauses 4.3.8. and 5.1.1. Other ISO and International Standards and European Regulations 4
C ISO 14001:2015 6.1.3 Compliance Obligations - Legal requirements monitoring ISO 14001:2015 Specific Discussions 0
C Requirement to link Quality Manual to ISO 9001 clause numbers? ISO 13485:2016 - Medical Device Quality Management Systems 13
D ISO 13485 scope (implantable) - Polymers for dental application EU Medical Device Regulations 9
W First time being audited (ISO 9001), asking for advice ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 9
John C. Abnet ISO 26262 ISO 26262 - Road vehicles – Functional safety 3
Marc ISO 26262- Road vehicles – Functional safety ISO 26262 - Road vehicles – Functional safety 0
John C. Abnet ISO 26262 IATF 16949 - Automotive Quality Systems Standard 0
A ISO/DIS 15223-1:2020 - Country of manufacture label (IEC 60417 No. 6049) - Which national law requires this symbol? Other Medical Device Related Standards 0
P ISO 14644 Class 8 Cleanroom Air Filter Requirements Other Medical Device Related Standards 4
K PDCA cycle and ISO processes alternative model Quality Management System (QMS) Manuals 14
N ISO 13485 7.3.9 Change control in medical device software ISO 13485:2016 - Medical Device Quality Management Systems 6
A ISO 13485 procedure change and reflect to legacy manufacture items ISO 13485:2016 - Medical Device Quality Management Systems 2
D ISO 13485 & CE Certification for Surgical Gloves CE Marking (Conformité Européene) / CB Scheme 0
S ISO 11137- Simulated product vs SIP Other Medical Device Related Standards 2
D Which ISO Standard to purchase? ISO 13485:2016 - Medical Device Quality Management Systems 7
V ISO 10360-5: 2020 Gap analysis and Action plan Excel .xls Spreadsheet Templates and Tools 1
Q ISO 9001 - Reseller Exclusions ISO 9000, ISO 9001, and ISO 9004 Quality Management Systems Standards 7
S Inventory Listing and ISO 13485:2016 ISO 13485:2016 - Medical Device Quality Management Systems 3
C ISO 45001 6.1.2.1 Hazard Identification Occupational Health & Safety Management Standards 1

Similar threads

Top Bottom