ISO/TS 81001-2-1:2025 PDF
Health software and health IT systems safety, effectiveness and security — Part 2-1: Coordination — Guidance and requirements for the use of assurance cases for safety and security
Health software and health IT systems safety, effectiveness and security — Part 2-1: Coordination — Guidance and requirements for the use of assurance cases for safety and security
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 46
- Дата публикации:
- 10 января 2025 г.
- Издание:
- ISO TS 81001 edition 1 version 1
- ICS:
- 35.240.80
This document establishes requirements and gives guidance on assurance case framework for healthcare delivery organizations (HDOs) and for health software and medical device manufacturers (MDMs) and can be used to support the communication and information transfer between all parties. An assurance case can be used to communicate information and knowledge about different risks to other roles. This document establishes: — an assurance case framework for HDOs and health software and MDMs for identifying, developing, interpreting, updating and maintaining assurance cases. — one of the possible means to bridge the gap between manufacturers and HDOs in providing adequate information to support the HDOs risk management of IT-networks; — best practice by leveraging ISO/IEC/IEEE 15026-2 and other standards to identify key considerations and for the structure and contents of an assurance case, e.g. iterative and continuous approaches; — example structure, method and format to improve the consistency and comparability of assurance cases. This document is applicable to all parties involved in the health software and health IT systems life cycle, including: a) organizations, health informatics professionals and clinical leaders specifying, acquiring, designing, developing, integrating, implementing and operating health software and health IT systems, for example health software developers and MDMs, system integrators, system administrators (including cloud and other IT service providers); b) healthcare service delivery organizations, healthcare providers and others who use health software and health IT systems in providing health services; c) governments, health system funders, monitoring agencies, professional organizations and customers seeking confidence in an organization’s ability to consistently provide safe, effective and secure health software, health IT systems and services; d) organizations and interested parties seeking to improve communication in managing safety, effectiveness and security risks through a common understanding of the concepts and terminology used in safety, effectiveness and security management; e) providers of training, assessment or advice in safety, effectiveness and security risk management for health software and health IT systems; f) developers of related safety, effectiveness and security standards. This document is for use by organizations and people who build, acquire, operate, maintain, use or decommission health software and health IT systems (including medical devices). It is applicable to all organizations involved, regardless of size, complexity or business model.
Abstract
Overview
ISO/TS 81001-2-1:2025 provides requirements and guidance for using assurance cases to manage the safety, effectiveness and security of health software and health IT systems. It establishes an assurance case framework for healthcare delivery organizations (HDOs) and health software / medical device manufacturers (MDMs) to identify, develop, interpret, update and maintain assurance cases that support risk management across the full lifecycle. The technical specification supports consistent communication and information transfer between manufacturers, HDOs, service providers and regulators.
Key topics and requirements
- Assurance case framework: Defines objectives, structure and lifecycle use of assurance cases to communicate risk and confidence for safety, effectiveness and security.
- Development process: A stepwise, iterative approach (identify goal → define basis → identify strategy → elaborate strategy → identify solution) for constructing assurance cases.
- Notation and argument elements: Guidance on common elements (goals, strategies, solutions/evidence, context, assumptions, justifications) and relationships (SupportedBy, InContextOf) to improve consistency and comparability.
- Evidence and argument considerations: Requirements for identifying, documenting and maintaining evidence supporting claims about safety and security.
- Change management: Guidance for updating assurance cases as systems evolve, including during deployment, operation, maintenance and decommissioning.
- Security assurance cases: Specific considerations for security risks and integration with overall safety and effectiveness arguments.
- Patterns and examples: Informative annexes provide generic risk-based HIT patterns, IEC 80001-1 compliance patterns, AI and security assurance case patterns to accelerate practical adoption.
- Standards alignment: Leverages ISO/IEC/IEEE 15026-2 and aligns with ISO 81001-1 and IEC 80001-1 to bridge manufacturer–HDO information gaps.
Applications and who uses it
ISO/TS 81001-2-1 is applicable to all parties in the health software and health IT lifecycle, including:
- Health software developers and medical device manufacturers (MDMs) - to produce assurance cases that communicate product risks and evidence.
- Healthcare delivery organizations (HDOs) - to extend manufacturer information into site-specific assurance cases for integration, configuration and operation.
- System integrators, cloud and IT service providers, system administrators - to demonstrate safe and secure deployment choices.
- Regulators, funders and monitoring agencies - to assess organizational capability and evidence of risk management.
- Training providers and assessors - to teach and evaluate assurance case creation and use.
Practical use cases include supplier-to-provider risk handover, procurement evaluation, deployment acceptance, safety/security audits and lifecycle change control.
Related standards
- ISO 81001-1 - foundational principles for health software and health IT systems.
- IEC 80001-1 - roles, responsibilities and assurance case concept for risk management of health IT infrastructures.
- ISO/IEC/IEEE 15026‑2 - guidance leveraged for assurance case structure and considerations.
Технические детали
- Технический комитет
- ISO/TC 215 - Health informatics
- SKU
- ISO/TS 81001-2-1:2025
Похожие стандарты
Стандарты, упомянутые в описании
PD ISO/TR 80001-2-7:2015
Application of risk management for IT-networks incorporating medical devices. Application guidance - Guidance…
1 Scope The purpose of this part of ISO/TR 80001 is to provide guidance to HDOs on self-assessment of their conformance against IEC 80001-1. The purpose of this part of ISO/TR 80001 is to a) provide…
BS ISO 81001-1:2021
Health software and health IT systems safety, effectiveness and security - Principles and concepts
What is ISO 81001‑1 about? ISO 81001‑1 provides the principles, concepts, terms and definitions for health software and health IT systems, key properties of safety, effectiveness and security, across…
PD ISO/TS 81001-2-1:2025
ДействующийHealth software and health IT systems safety, effectiveness and security - Coordination. Guidance and require…
1 Scope This document establishes requirements and gives guidance on assurance case framework for healthcare delivery organizations (HDOs) and for health software and medical device manufacturers (MD…