Overview
ISO/TR 80001-2-6:2014 is a Technical Report that provides application guidance for responsibility agreements used when incorporating medical devices into IT-networks. Intended to support compliance with IEC 80001-1, this guidance helps define and document the roles and responsibilities of all stakeholders - including the Responsible Organization (RO), medical device manufacturers, and IT suppliers - across the complete lifecycle of a Medical IT‑Network. The report is informative in nature and complements IEC 80001-1 by offering practical steps to implement documented responsibility arrangements.
Key topics and requirements
- Purpose and scope: Guidance on establishing responsibility agreements that cover lifecycle activities for medical IT‑networks.
- Prerequisites: RO top management commitment, approved risk management policies, defined risk acceptability criteria, resource provisioning, and appointment of a Medical IT‑Network Risk Manager.
- Stakeholders and participants: Identification of Responsible Organizations, device manufacturers, IT suppliers, clinical staff and other parties with duties affecting safety, effectiveness and data/system security.
- Agreement types & communication: Options for bilateral vs. multilateral agreements, use of non‑disclosure agreements, and processes for updating information and documentation.
- Lifecycle coverage: Responsibilities should address design, configuration control, change management (e.g., change permits), monitoring, event management, maintenance, and decommissioning.
- Methods for assigning responsibilities: Practical approaches (including RACI-style role allocation - Annex A) and typical documents to include (Annex B).
- Key properties: Emphasis on managing the three IEC 80001 key properties - safety, effectiveness, and data & system security - through clear contractual and operational arrangements.
Practical applications
- Creating formal agreements before connecting medical devices to enterprise networks (e.g., alarm routing, remote programming, data feeds).
- Defining who conducts impact assessments and regression/back‑out testing for infrastructure updates (firmware, antivirus, network patches).
- Documenting responsibilities for incident/event management, monitoring, and ongoing risk control.
- Facilitating information exchange between device manufacturers and healthcare delivery organizations to meet risk management needs.
Who should use this standard
- Healthcare delivery organizations (ROs) implementing IEC 80001 risk processes
- Clinical engineering and IT departments responsible for medical IT‑networks
- Medical device manufacturers and IT suppliers negotiating responsibilities
- Risk managers, procurement, legal teams, and compliance officers involved in medical device integration
Related standards
- Normative reference: IEC 80001-1:2010 (Roles, responsibilities and activities)
- Companion parts in the ISO/IEC TR 80001 series (2-1 through 2-8) provide further application guidance on topics such as wireless networks, security disclosures, and HDO self-assessment.
Keywords: ISO TR 80001-2-6:2014, responsibility agreements, IEC 80001-1, risk management, medical IT-network, medical devices, Responsible Organization, RACI, change management.