
safety, warnings, precautions, prohibitions
file: n:\article\cos14310m5-v1_06hpc-en\20120215_cos14310m5-v1.06hpc-en_manual_h-p-cosmos_running_machine.doc
© 2012 h/p/cosmos sports & medical gmbh [email protected] created 15.02.2012 printed 15.02.2012 page: 25 of 213
[4.F]
Medical device software
Software safety classification according to EN 62304 medical device software; software lifecycle processes:
The manufacturer has to assign a software safety class to any software, according to consequences caused by the software
in form of a danger on the patient, the applier or third parties.
The software safety classes, based on the severity, are assigned as follows:
Class A:
No injury or damage to health possible
Class B:
No SERIOS INJURY possible
Class C:
DEATH or SERIOS INJURY possible
Without risk reducing measurements and risk reducing design a software for treadmills and interface protocols would have to
be classified as Class C most dangerous with death result, because for example undesired and uncontrolled acceleration of
the running belt can always cause falling off with the possible result of a broken neck. Due to a possible technical
malfunction of a measurement (e.g. heart rate measurement), which has to be theoretically be taken into account, the patient
may be overloaded with the possible result of death.
Also on the part of the demand on SOUP (software of unknown provenance) it has to be stated, that medical treadmill
ergometers and their software use SOUP components. So the frequency inverter, motor regulation, firmware and parts of the
pc software are components of medical treadmill ergometers and the treadmill manufacturer has no access to design,
validation and maintenance of these components of suppliers. For this reason always the worst case of a malfunction has to
be taken into account.
h/p/cosmos classifies the internal firmware and software components as Class B due to a number of risk reducing design
features and measurments.
Healthy people in sports are usually able to activate the emergency stop button of the treadmill and this way to switch off the
treadmill quickly in case of emergency caused by a malfunction. Thus, the emergency switch off has to work completely
without software and has to brake the power supply of the treadmill. For patients and medical users fast reactions of the
patient and therewith a fast switch off of the treadmill are not guaranteed because for a patient also very light acceleration
may cause in falling off. To control the risk for patients and persons with any disabilities a fall prevention system (e.g. safety
arch with chest belt, harness and fall stop rope) which prevents falling off (catches the patient) has to be used for
applications with a higher risk of falling (e.g. patients after hip replacement, neurologic patients, cardiac patients, maximum
load tests, etc.) or in cases falling could result in serious injuries, for example if the patient is connected to invasive probes.
For the acceleration of the drive motor and running belt safety delay design measures have been incorporated, which
prevent from extreme fast acceleration in case of any malfunction.
Warning labels based on EN 957-6 about possible malfunction and inaccuracy of heart rate sensors are placed on the
treadmill and in the operation manual.
Furthermore the patient on the medical treadmill has to be observed permanently and the medical staff has to be within 1.5m
around the patient.
The risk analysis and risk control are included in the risk management according to EN 14971.