Solutions_Medical_StartSection.png

Medical Devices

Medical device development faces multiple challenges, including the rising threat of cyberattacks, extensive regulatory requirements, the need for agile development, efficient process management, and pressure to reduce R&D costs.

Vector Consulting provides professional support in the efficient usage of standards for regulatory compliance to FDA and MDCG guidelines, development standards like IEC 62304 (life-cycle), ISO 14971 (risk management), IEC 60601 (product development), etc., in agile methodologies as well as support in cybersecurity by offering independent risk-oriented Grey-Box Penetration Test of medical devices.

To address these demands, we deliver highly aligned development and life-cycle processes including robust cybersecurity and safety measures from design to deployment and SW-update management.

This includes strengthening system architecture, structured risk management, streamlining requirements and development, traceability, and cost-effective R&D while ensuring safety and security throughout the product lifecycle.

Solutions for Medical

  • Standards and Regulatory Compliance: Consulting and compliance support for FDA guidelines, MDCG regulations, IEC 60601, IEC 62304, ISO 14971 etc.
  • Risk Management: Systematic risk assessment methods using HARA and TARA enabling low residual risk.
  • Requirements Engineering and Product Management: Systematic requirements engineering to ensure consistency of requirements, product usability, risk management, system reliability, and regulatory compliance.
  • IT workflows & Agile for Medical: Streamline operations using CI/CT/CD (DevOps), boost efficiency, and reduce cycle times using agile methodologies.
  • Supplier Management: Efficiently manage suppliers and foster global collaborations.
  • Code Quality Analysis: Ensure code integrity and reliability for your medical software.
  • Cybersecurity Support: Cybersecurity Validation with independent risk-oriented Grey-Box Penetration Test safeguards systems against threats, while Security-by-Lifecycle ensures post-market surveillance through continuous monitoring, incident response, and vulnerability management.
  • Trainings: Individual trainings and training programs for customer specific competence development.

Standards

Vector Consulting supports implementing the most relevant standards required to comply to FDA and MDR/IVDR:

  • Quality Assurance with ISO 13485 (Medical devices, Quality management systems, Requirements for regulatory purposes). Based on traditional quality management standards and adapted to the medical domain.
  • IEC 62304 (Medical device software, software life-cycle processes) specifies life-cycle requirements for the development of medical software is building upon the widely used ISO/IEC 12207. It enhances life-cycle management by governance and observability, and mapping to specific medical needs.
  • ISO 14971 (Medical devices, Application of risk management to medical devices, medical risk management process) consists of several steps for the design, development and production of every medical device.
  • IEC 62366 (medical devices, application of usability engineering to medical devices) is the primary standard and specifies usability requirements for the development of medical devices, including negative use cases such as misuse and abuse. Usability matters for medical devices because they combine highest safety demands with lots of direct human interaction by a variety of stakeholders ranging from doctors to nurses, and from administrators to technicians.
  • Application of general-purpose standards to medical software development, such as test-management according to ISO/IEC/IEEE 29119 (software and systems engineering, software testing) for software testing, IEC 61508 for functional safety of electronic components and ISO 27001 which provides a framework for organizations to establish, implement, operate, monitor, review, maintain and continually improve the Information Security Management System (ISMS).

Medical Security

Security of medical devices is of prime importance as these deal with the health and data of people.

Examples of cyberattacks on medical devices: eavesdropping, data leakage, data corruption, password attacks, sensor confusion, vulnerabilities in application, deceiving forensic examiners (repudiation).

Most security attacks are process and implementation related. Therefore, security is about identification of the attack surface starting with Security Requirements and risk mitigation across the Lifecycle.

Vector security solutions for medical is about systematic risk- oriented methodologies for ensuring that security efforts are focused on most significant risks.

Security by Design

  • Promoted by safety-driven development
  • Critical systems should be "Secure by Design"
  • Frontloading with requirements, bottom-up protection and security engineering

Security by Lifecycle

  • Promoted by experience in IT and Software-intensive systems
  • Add-on to traditional "security-by-design" approach
  • Counters dynamic changes and evolution of threats and security mechanisms
Solutions_Medical_TechnicalArticle.png
IEEE Technical Article - Medical Software
Software is about people and technology. Medical software underlines this truism more than any other application domain. Health care is an advanced industry where latest software technologies fuel a fast evolution in a market characterized by high pressure on cost, time, and innovation but also demand strong governance. In this article, we explain medical software development from an industry perspective with practical guidance from our projects with Siemens Healthineers.
Your Partner for Engineering Excellence
Vector Consulting Services
Team
Your Partner for Engineering Excellence
Let us build the ideal setup for your engineering challenges together. Reach out to our team to explore how our powerful coaching can seamlessly integrate into your existing workflows.