R-TF-013-002 Risk management record
This record is carried out following the procedure GP-013 Risk management and according to R-TF-013-001 Risk management plan, which is also carried out following GP-013. The definition of the risk control options, the risk levels, risk acceptability and everything else, can be found in GP-013 Risk management.
ID? | Hazard or Use Error? | Type? | Hazardous Situation or Vulnerability? | Foreseeable sequence of events? | Harm? | Risk or Threat? | Security (CIAA)? | User group? | User task? | Cause Requirement(s)? | Affected Asset, Part or People? | Likelihood (Initial)? | Severity (Initial)? | RPN (Initial)? | Control Opt (ABC)? | Implemented mitigation measures? | Mitigation or Control Requirement(s)? | Responsible? | Verification of implementation of risk control measures? | Severity (Controlled)? | Likelihood (Controlled)? | RPN (Controlled)? | Residual risk evaluation? | Verification of effectiveness of risk control measures? | Benefit-risk analysis? | Risks arise from risk control measures?? | Is risk control complete?? | Overall residual risk acceptability? | Threat Model Ref(s)? | Post-Market Plan Ref(s)? |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| R-2TP | The endpoints of the device are not compatible with the user's software | Product | The care provider's IT personnel must develop custom code, which in some cases may not be viable. |
| Delays in patient diagnosis and/or treatment follow up.; User frustration | The name of the endpoints of the device do not follow a standard | IntegrityAvailability | PRS-1V6PRS-1XUPRS-5LJ | Managing Organisation | 4 | 3 | 12 | AC | The endpoints of the device follow HL7's FHIR interoperability standard and information in Instructions for Use | PRS-1V6PRS-1XUPRS-5LJPRS-9F2 | Technical director | Process for verification is defined in GP-012 Design, redesign and development. In addition, IFU verification is recorded at R-TF-001-006 IFU and label validation 2023_001 to ensure that they include the information (TEST_011_We facilitate the integration of the device into the users' system). HL7's FHIR standard compliance is verified at the TEST_013_The data that users send and receive follows the FHIR healthcare interoperability standard. | 3 | 1 | 3 | Acceptable | R-TF-012-015 Summative evaluation report_2024_001 | Not applicable (acceptable risk) | FALSE | TRUE | Acceptable | T-024-006-API-002T-024-006-API-004 | T-024-007-DEP-002T-024-007-INT-002 | ||
| R-A96 | Incompatibility in classification systems | Product | Mismatch between the name or code of the ICD class of the medical device and the ones used by the healthcare provider's software |
| Misdiagnosis; User frustration | The name of the endpoints of the device do not follow a standard | PRS-0MCPRS-1XUPRS-5LJPRS-8QJPRS-9J5 | Managing Organisation | 4 | 3 | 12 | AC | The endpoints of the device follow ICD-9, ICD-10 and ICD-11, and they are also mapped to the output | PRS-0MCPRS-1XUPRS-5LJPRS-8QJPRS-9J5 | Technical director | Verification of REQ_004 is recorded in the TEST_004_The user receives an interpretative distribution representation of possible ICD categories represented in the pixels of the image. | 3 | 1 | 3 | Acceptable | R-TF-012-015 Summative evaluation report_2024_001 R-TF-015-003 Clinical Evaluation Report (section: Valid clinical association of the International Classification of Diseases (ICD) classes) | Not applicable (acceptable risk) | FALSE | TRUE | Acceptable | |||||
| R-HBD | Misrepresentation of magnitude returned by the device | Usability Product | The care provider's system represent a value as if was representing a different magnitude. |
| Misdiagnosis; delay in diagnosis/patient's follow up/treatment | The name of the endpoints of the device do not follow a standard | ITP | Use a stable internet connection | PRS-1XUPRS-5LJ | Managing Organisation | 3 | 3 | 9 | AC | The endpoints of the device follow HL7's FHIR interoperability standard and we developed a integration manual within the IFU that explains the values, as well as a Swagger documentation | PRS-1XUPRS-5LJ | Technical director | IFU verification is recorded at R-TF-001-006 IFU and label validation 2023_001 and in TEST_011 to ensure that they include the information. HL7's FHIR standard compliance is verified at the TEST_013_The data that users send and receive follows the FHIR healthcare interoperability standard. | 3 | 1 | 3 | Acceptable | R-TF-012-015 Summative evaluation report_2024_001 | Not applicable (acceptable risk) | FALSE | TRUE | Acceptable | |||
| R-BDR | Misinterpretation of data returned by the device | Product | The care provider's system represent a value as if was representing a different clinical endpoint. |
| This could lead to misdiagnosis; delays in treatment and worsening of the patient's health status. | The name of the endpoints of the device do not follow a standard | PRS-1XUPRS-5LJ | Managing Organisation | 5 | 3 | 15 | C | The endpoints of the device follow HL7's FHIR interoperability standard and we developed a integration manual within the IFU that explains the values, as well as a Swagger documentation We define the minimum user interface requirements to show the medical device outputs to HCPs Minimum user interface requirements are provided in the IFU | PRS-1XUPRS-5LJ | Technical director | IFU verification is recorded at R-TF-001-006 IFU and label validation 2023_001 and in TEST_011 to ensure that they include the information. HL7's FHIR standard compliance is verified at the TEST_013_The data that users send and receive follows the FHIR healthcare interoperability standard. | 3 | 1 | 3 | Acceptable | R-TF-012-015 Summative evaluation report_2024_001 | Not applicable (acceptable risk) | FALSE | TRUE | Acceptable | |||||
| R-75H | Incorrect clinical information | Product | The care provider receives into their system data that is erroneous |
| This could lead to misdiagnosis; delays in treatment and worsening of the patient's health status. | The interpretive distribution assigns a low probability to the correct ICD class among the potential ICD classes. | PRS-1V6PRS-1XUPRS-5LJPRS-8QJ | Managing Organisation | 4 | 3 | 12 | AC | Information about device outputs are detailed in the IFU. The medical device returns metadata about the output that helps supervising it, such as explainability media and other metrics. AI models undergo retraining using expanded dataset of images. | PRS-1V6PRS-1XUPRS-5LJPRS-8QJ | Technical director | Process for verification is defined in GP-012 Design, redesign and development. We specify in the intended purpose of the device that is a support tool, not a diagnosis one, meaning that it must always be used under the supervision of HCPs, who should confirm or validate the output of the device considering the medical history of the patient, and other possible sympthoms they could be suffering, especially those that are not visible or have not been supplied to the device (TEST_011). Verification of the implementation of metadata about the output of the device to help supervising the output: TEST_001, TEST_002, TEST_003 | 3 | 2 | 6 | As far as possible | R-TF-012-015 Summative evaluation report_2024_001 R-TF-015-003 Clinical Evaluation Report (sections: Instructions for Use, Associated Design Product Requirement, Clinical performance) | Benefits outweigh the risks | FALSE | TRUE | Acceptable | |||||
| R-DAG | Incorrect diagnosis or follow up | Usability Regulatory | The medical device outputs a wrong result |
| This could lead to misdiagnosis; delays in treatment and worsening of the patient's health status. | The interpretive distribution assigns a low probability to the correct ICD class among the potential ICD classes. | HCP | User logs into the system. | PRS-1V6PRS-1XUPRS-5LJPRS-8QJPRS-9J5 | Patient | 4 | 3 | 12 | AC | Information about device outputs are detailed in the IFU. The medical device returns metadata about the output that helps supervising it, such as explainability media and other metrics. The device returns an interpretative distribution representation of possible ICD categories, not just one single condition. AI models undergo retraining using expanded dataset of images. | PRS-1V6PRS-1XUPRS-5LJPRS-8QJPRS-9J5 | Technical director | Process for verification is defined in GP-012 Design, redesign and development. Implementation of device output information in the IFU verified in TEST_011. Verification of the implementation of metadata about the output of the device to help supervising the output: TEST_001, TEST_002, TEST_003. Verification of the implementation of interpretative distribution representation of possible ICD categories verified in TEST_004. | 3 | 2 | 6 | As far as possible | R-TF-012-015 Summative evaluation report_2024_001 R-TF-015-003 Clinical Evaluation Report (sections: Instructions for Use, Associated Design Product Requirement, Valid clinical association of the International Classification of Diseases (ICD) classes, Clinical performance) | Benefits outweigh the risks | FALSE | TRUE | Acceptable | |||
| R-SKK | Incorrect results shown to patient | Usability Cybersecurity Regulatory Artificial Intelligence | The patient see erroneous results. |
| The patient is affected and may suffer anxiety or delays visiting the HCP and their consequent treatment; worsening their health status. | The interpretive distribution assigns a low probability to the correct ICD class among the potential ICD classes.,Patient is using the device without the HCP monitoring | IntegrityAvailability | HCP | User takes a photo of the patient's lesion. | PRS-1V6PRS-1XUPRS-4QWPRS-5LJPRS-8QJPRS-9J5 | Patient | 4 | 3 | 12 | AC | Information about device outputs are detailed in the IFU. The medical device returns metadata about the output that helps supervising it, such as explainability media and other metrics. The device returns an interpretative distribution representation of possible ICD categories, not just one single condition. AI models undergo retarining using expanded dataset of images. | PRS-1V6PRS-1XUPRS-4QWPRS-5LJPRS-8QJPRS-9J5 | Technical director | Process for verification is defined in GP-012 Design, redesign and development. Implementation of device output information in the IFU verified in TEST_011. Verification of the implementation of metadata about the output of the device to help supervising the output: TEST_001, TEST_002, TEST_003. Verification of the implementation of interpretative distribution representation of possible ICD categories verified in TEST_004. | 3 | 1 | 3 | Acceptable | R-TF-012-015 Summative evaluation report_2024_001 R-TF-015-003 Clinical Evaluation Report (sections: Instructions for Use, Associated Design Product Requirement, Valid clinical association of the International Classification of Diseases (ICD) classes, Clinical performance) | Not applicable (acceptable risk) | FALSE | TRUE | Acceptable | T-024-006-AML-001T-024-006-DAT-002 | T-024-007-AUD-001T-024-007-CVE-002 |
| R-D1I | Unauthorized patient access to clinical data | Product Cybersecurity | The patient somehow manages to get access to the clinical endpoints of the device. |
| The patient is affected and may suffer anxiety or delays visiting the HCP and their consequent treatment; worsening their health status. | The medical device is hacked and a patient access to inaccesible data. | ConfidentialityAuthenticity | PRS-1V6PRS-1XUPRS-2KQPRS-3YHPRS-4QWPRS-5LJPRS-7Z8PRS-9F2 | Patient | 3 | 3 | 9 | AB | State-of-the-art security measures to avoid unauthorized access to data, malignant uses and hacking, and information about authentication process for users are available in IFU | PRS-1V6PRS-1XUPRS-2KQPRS-3YHPRS-4QWPRS-5LJPRS-7Z8PRS-9F2 | Technical director | TEST_014 The user authentication feature is functioning correctly, TEST_015 Ensure all API communications are conducted over HTTPS, TEST_017 Verification of authorized user registration and body zone specification in device API, TEST_018 Ensure API stability and cybersecurity of the medical device. IFU verification is recorded at R-TF-001-006 IFU and label validation 2023_001 and in TEST_011 to ensure that they include the information. | 3 | 1 | 3 | Acceptable | R-TF-012-015 Summative evaluation report_2024_001 R-TF-015-003 Clinical Evaluation Report (sections: Associated Design Verification Test, Requirement on devices that incorporate software or for software that are devices in themselves (GSPR 17.2), Instructions for Use) | Not applicable (acceptable risk) | FALSE | TRUE | Acceptable | T-024-006-AUT-001T-024-006-AUT-003 | T-024-007-VUL-001T-024-007-VUL-003 | ||
| R-AGQ | Image artefacts or poor resolution | Product | The medical device receives an input that does not have sufficient quality in a way that affects its performance |
| Misdiagnosis; delays in treatment and worsening of the patient's health status. | Improper image acquisition, poor image capture conditions,Inadequate image processing algorithms | PRS-1V6PRS-1XUPRS-5LJPRS-7XK | Managing Organisation | 4 | 3 | 12 | AC | A requirement of the device defines the creation of a processor whose purpose is to ensure that the image have enough quality. In other words, an algorithm, similar to the ones used to classify diseases, is used to check the validity of the image and provides an image quality score. The device returns meaningful messages to the users about the quality score of the images. This allows care providers to re-take a photo. The IFU contain the `How to take pictures` section with recommendation on how to take pictures with high quality. We also offer training to the users to optimize the imaging process so that it is optimal for the device's operation. | PRS-1V6PRS-1XUPRS-5LJPRS-7XKPRS-9F2 | Technical director | Verification is defined in: TEST_009_Notify the user if the quality of the image is insufficient, TEST_007_If something does not work, the API returns meaningful information about the error, TEST_011_We facilitate the integration of the device into the users' system R-TF-001-006 IFU and label validation | 3 | 2 | 6 | As far as possible | R-TF-015-003 Clinical Evaluation Report (sections: Associated Design Product Requirement, Associated Design Verification Test, Clinical performance) R-TF-012-015 Summative evaluation report_2024_001 | Benefits outweigh the risks | FALSE | TRUE | Acceptable | |||||
| R-E7Z | Inaccessible skin areas | Usability | The device cannot analyse certain skin areas |
| Misdiagnosis; delays in treatment and worsening of the patient's health status. | Inability to access or take a picture of the skin structure due to its location in an unreachable body site and lack of aid in the process | HCP | User takes a photo of the patient's lesion. | PRS-1V6PRS-1XUPRS-5LJPRS-7XK | Patient | 3 | 3 | 9 | AC | A requirement of the device defines the creation of a processor whose purpose is to ensure that the image have enough quality. In other words, an algorithm, similar to the ones used to classify diseases, is used to check the validity of the image and provides an image quality score. The device returns meaningful messages to the users about the quality score of the images. This allows care providers to re-take a photo. The IFU contain the `How to take pictures` section with recommendation on how to take pictures with high quality plus in the Contraindications section of the IFU we state the following: We advise the user not to use the device if skin structures are not accessible by a camera, such as being located in a skin fold or is otherwise covered. We also offer training to the users to optimize the imaging process so that it is optimal for the device's operation. | PRS-1V6PRS-1XUPRS-5LJPRS-7XKPRS-9F2 | Technical director | TEST_009_Notify the user if the quality of the image is insufficient TEST_007_If something does not work, the API returns meaningful information about the error TEST_011_We facilitate the integration of the device into the users' system R-TF-001-006 IFU and label validation | 3 | 1 | 3 | Acceptable | R-TF-015-003 Clinical Evaluation Report (sections: Associated Design Product Requirement, Associated Design Verification Test, Clinical performance) R-TF-012-015 Summative evaluation report_2024_001 | Not applicable (acceptable risk) | FALSE | TRUE | Acceptable | |||
| R-T8Q | Data transmission failure from healthcare provider's system | Product | The healthcare provider's system cannot connect to the medical device |
| Delays in patient diagnosis and poorer treatment follow-up. | Error in the API token or the authentication process, connectivity problems, firewall, incompatibility between systems | PRS-1V6PRS-4QWPRS-9F2 | Managing Organisation | 4 | 3 | 12 | AB | State-of-the-art techniques of security and software availability. The device returns meaningful messages about the error | PRS-1V6PRS-4QWPRS-9F2 | Technical director | API REST connection performance and security verification is recorded in TEST_014 The user authentication feature is functioning correctly, TEST_015 Ensure all API communications are conducted over HTTPS, TEST_017 Verification of authorized user registration and body zone specification in device API, TEST_018 Ensure API stability and cybersecurity of the medical device. TEST_007 verifies REQ_007 | 3 | 2 | 6 | As far as possible | R-TF-012-015 Summative evaluation report_2024_001 | Benefits outweigh the risks | FALSE | TRUE | Acceptable | |||||
| R-3N5 | Data input failure | Product | The medical device cannot receive data from healthcare providers' system |
| Delays in patient diagnosis and poorer treatment follow-up. | Error in the API token or the authentication process, connectivity problems, firewall, incompatibility between systems, interface issues | PRS-1V6PRS-4QWPRS-9F2 | Manufacturer | 4 | 3 | 12 |