Skip to main content

Improving Software Risk Management Practices in a Medical Device Company

  • Conference paper
Making Globally Distributed Software Development a Success Story (ICSP 2008)

Part of the book series: Lecture Notes in Computer Science ((LNPSE,volume 5007))

Included in the following conference series:

  • 1525 Accesses

Abstract

Software is becoming an increasingly important aspect of medical devices (MDs) and MD regulation. MDs can only be marketed if compliance and approval is achieved from the appropriate regulatory bodies. MD companies must produce a design history file detailing the processes undertaken in the design and development of their MD software. The safety of all MD software produced is of primary importance and it is crucial that an effective and efficient risk management (RM) process is in place. The authors have developed a software process improvement RM model that integrates regulatory MD RM requirements with the goals and practices of the Capability Maturity Model Integration (CMMI). This model is known as the RM Capability Model (RMCM). This paper evaluates how introducing the RMCM into a MD company improved their RM process.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. World Health Organisation: Medical device regulations: global overview and guiding principles (2003), ISBN 92 4 154618 2

    Google Scholar 

  2. Burton, J., McCaffery, F., Richardson, I.: A Risk Management Capability Model for use in Medical Device Companies. In: 4th Workshop on Software Quality, ICSE 2006, Shanghai, China, May 21, 2006, pp. 3–8 (2006)

    Google Scholar 

  3. FDA: Quality Systems for Medical Device & Equipment/Software Manufacturers (QSR). Code of Federal Regulations (April 2005)

    Google Scholar 

  4. Donawa, M.: Useful US Guidance on Device Software. Medical Device Technology (December 2005), http://www.medicaldevicesonline.com

  5. Boehm, B.W.: Software Risk Management: Principles and Practices. IEEE Software 8(1), 32–41 (1991)

    Article  Google Scholar 

  6. FDA Mission Statement, http://www.fda.gov/opacom/morechoices/mission.html

  7. Eagles, S., Murray, J.: Medical Device Software Standards: Vision and Status (2001), http://www.devicelink.com/medicaldevicedi/archive/01/05/002.html

  8. CMMI Product Team: Capability Maturity Model® Integration for Development, Version 1.2, Technical Report CMU/SEI-2006-TR-008 (2006), http://www.sei.cmu.edu/publications/documents/06.reports/06tr008.html

  9. FDA/CDRH: Guidance for the Content of Premarket Submissions for Software Contained in Medical Devices (May 2005), http://www.fda.gov/cdrh/ode/guidance/337.pdf

  10. FDA/CDRH: Guidance for Off-the-Shelf Software Use in Medical Devices (September 1999), http://www.fda.gov/cdrh/ode/guidance/585.pdf

  11. FDA/CDRH Guidance Document. General Principles of Software Validation, Final Guidance for Industry and FDA Staff (January 2002)

    Google Scholar 

  12. FDA Regulations: Code of Federal Regulations 21 CFR Part 820 (April 2006), http://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfcfr/CFRSearch.cfm?CFRPart=820&showFR=1

  13. ANSI/AAMI/ISO 14971: Medical devices – Application of risk management to medical devices (2007)

    Google Scholar 

  14. ANSI/AAMI/IEC 62304:2006: Medical device software - Software life cycle processes Association for the Advancement of Medical Instrumentation (July 2006), http://www.techstreet.com/cgi-bin/detail?product_id=1277045 ISBN 1-57020-258-3

  15. BS EN 60601-1-4: Medical Electrical Equipment, Part 1 - General requirements for safety (2000)

    Google Scholar 

  16. IEC 60812: Analysis technique for system reliability- procedure for failure modes and effects analysis (FMEA) (1985)

    Google Scholar 

  17. ISPE: GAMP Guide for Validation of Automated Systems. GAMP 4 (December 2001), http://www2.ispe.org/eseries/scriptcontent/orders/ProductDetail.cfm?pc=4BOUNDFUS

  18. AAMI TIR32: Medical device software risk management (2005)

    Google Scholar 

  19. AAMI: New Guidance Offered on Software Risk Management 40(2) (2005)

    Google Scholar 

  20. Baskerville, R.L.: Investigating Information Systems with Action Research. Communications of the Association of Information Systems 2, article 19 (1999)

    Google Scholar 

  21. Susman, G., Evered, R.: An Assessment of The Scientific Merits of Action Research. Administrative Science Quarterly 4(23), 582–603 (1978)

    Article  Google Scholar 

  22. Liamputtong, P., Ezzy, D.: Qualitative Research Methods, 2nd edn. (2006), ISBN 9 78019551 7446

    Google Scholar 

  23. FDA/CDRH: Software related recalls for fiscal years 1983-91. US Department of Health and Human Services (1992)

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Editor information

Qing Wang Dietmar Pfahl David M. Raffo

Rights and permissions

Reprints and permissions

Copyright information

© 2008 Springer-Verlag Berlin Heidelberg

About this paper

Cite this paper

Burton, J., McCaffery, F., Richardson, I. (2008). Improving Software Risk Management Practices in a Medical Device Company. In: Wang, Q., Pfahl, D., Raffo, D.M. (eds) Making Globally Distributed Software Development a Success Story. ICSP 2008. Lecture Notes in Computer Science, vol 5007. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-540-79588-9_4

Download citation

  • DOI: https://doi.org/10.1007/978-3-540-79588-9_4

  • Publisher Name: Springer, Berlin, Heidelberg

  • Print ISBN: 978-3-540-79587-2

  • Online ISBN: 978-3-540-79588-9

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics