InsightFab
Knowledge Base/Reliability Engineering in Medical Devices: ISO 14971 Risk Management
Reliability6 min read

Reliability Engineering in Medical Devices: ISO 14971 Risk Management

This article addresses common, often unarticulated challenges in reliability engineering for medical devices, focusing on ISO 14971 risk management. Through real-world case studies, it demonstrates practical approaches for risk identification and mitigation, offering actionable insights for immediate application.

The Day the CPK Report Came Out, Half of the Client's Face Turned Green

I still remember a few years ago when our factory first took on a medical device project. Everyone was very excited; after all, it was venturing into a new field. What happened? For the first batch of samples, the client came for inspection, and when the report came out, a critical process had a CPK value of only 1.08. To be honest, in our wafer fab, this number was barely on the edge of "acceptable," just scraping by. But when the client saw it, half of their face immediately turned green, their eyes full of "Are you kidding me?" It was then that I deeply realized that "reliability" in the medical device field is an entirely different universe.

What Was the Problem?

To put it bluntly, in the world of medical devices, even a slight lack of "reliability" can directly impact human lives. When we used to make wafers, at most, product yield would be a bit lower, the company would earn a bit less, and at worst, the client would argue with you. But in medical devices, a tiny malfunction could mean a patient doesn't receive timely treatment, or even faces a life-threatening situation. This is why they place such importance on risk management, which is what ISO 14971 is all about. It doesn't ask you to eliminate all risks—that's fundamentally impossible—but rather to "understand risks, evaluate risks, and then control risks to an acceptable level."

In other words, you must first know what undesirable events might occur, how high the probability of these events happening is, what severe consequences they might cause, and then consider how to avoid or reduce the probability or severity of these undesirable events.

How Is It Actually Done?

The core concept of ISO 14971 is "risk analysis." It sounds profound, but it's actually very simple.

  1. First, list all "hazards": What harm could your product cause? For example: battery overheating causing burns to the patient, software crashing leading to incorrect dosage, needle breaking off and remaining inside the body.
  2. Evaluate the "probability of occurrence" and "severity" for each hazard: These two are typically scored, for example, on a scale of 1-5. A probability of 1 is extremely low, 5 is extremely high. A severity of 1 is slight discomfort, 5 is death or severe permanent injury.
  3. Calculate the "risk level": This is usually the probability score multiplied by the severity score. For instance, a hazard with a probability of 3 and severity of 4 would have a risk level of 12.
  4. Determine if the "risk is acceptable": Each company sets its own standard; for example, a risk level exceeding 10 might be deemed unacceptable.
  5. If unacceptable, "find ways to reduce the risk": You can modify the design, add warnings, implement protective measures, improve the manufacturing process, and so on. Then re-evaluate until the risk is reduced to an acceptable range.

For example, we had a sensor where initial testing revealed that if a patient mishandled it, a certain button could get stuck, preventing an alarm from being sent. We assessed the probability of this "button sticking" as 3 (medium), and the "severity" caused by "failure to send an alarm" as 4 (serious harm). The risk level was 12—too high! So we redesigned the button mechanism, added waterproof and dustproof features, and specifically emphasized operating instructions in the user manual. After re-evaluation, the probability dropped to 1, the severity remained 4, and the risk level became 4. This was then acceptable.

The Most Common Pitfalls

To be honest, I've seen many engineers making the most common mistake when conducting risk analysis: "underestimating probability" or "underestimating severity." Because no one wants their design to be labeled "high risk," they tend to write down lower numbers. The result is that the report looks great on the surface, but the product still has potential underlying issues.

Another common pitfall is "forgetting to consider the user." We engineers often only think about risks from the design and manufacturing perspectives, neglecting how actual users might operate or "misoperate" your product under various unusual circumstances. Many times, the problem isn't with the product itself, but with the person.

One Thing You Can Do Today

Re-examine the top 3 critical failure modes of your current product and consider what "hazards" they might cause.

Want to try it yourself?

Every tool mentioned in this article is available on InsightFab — just upload a CSV to analyze.

Go to Tools