3 ms·
I've worked on a variety of vital systems including some in health care. We defined vital systems as severe injury or death could occur if the system failed or
by davismwfl 5y ago
I've worked on a variety of vital systems including some in health care. We defined vital systems as severe injury or death could occur if the system failed or failed unsafely.
The article dharmab linked is pretty well known and I think does a fair job of describing one of the key differences. Redundancy, reliability, durability and safety are not all the same thing in vital systems. In web systems and many other types of systems which are software driven, being redundant is good enough, not true in vital systems.
It is critical each device being designed must define what it means for that device to be reliable, redundant (if necessary), durable and safe. In some medical systems failing to a known safe condition is all that is required, in others the device needs multiple redundant systems to prevent a failure under a defined set of normal circumstances.
In health care failure of systems does happen, when it happens there are processes and procedures defined to manage them generally. In almost every case when a machine fails there is a manual method to take over. I've not worked on the radiological side (outside of some CV work), but I would assume they have separate systems monitoring exposures and causing fail safe shutdowns etc. That is generally the requirement (and common pattern) for any medical device that isn't supporting life, e.g. if it fails it needs to fail in a known safe state.
Honestly this is a huge topic I could ramble for a long time about, but in the end it comes down to defining requirements, defining outcomes, defining testing, testing and good processes to handle failure conditions.