Safety Assessment for Medical Test Lab. Dr. David Endler Systems Engineering Consultant Freelancer & Member of oose eg

Similar documents
Implementing IEC Standards for Safety Instrumented Systems

C. Mokkapati 1 A PRACTICAL RISK AND SAFETY ASSESSMENT METHODOLOGY FOR SAFETY- CRITICAL SYSTEMS

Functional safety. Functional safety of Programmable systems, devices & components: Requirements from global & national standards

Failure Modes, Effects and Diagnostic Analysis

Workshop Functional Safety

Safety Manual VEGAVIB series 60

A study on the relation between safety analysis process and system engineering process of train control system

Instrumented Safety Systems

18-642: Safety Plan 11/1/ Philip Koopman

YT-300 / 305 / 310 / 315 / 320 / 325 Series

Verification Of Calibration for Direct-Reading Portable Gas Monitors

Safety Manual VEGAVIB series 60

Every things under control High-Integrity Pressure Protection System (HIPPS)

Neles ValvGuard VG9000H Rev 2.0. Safety Manual

Pneumatic QEV. SIL Safety Manual SIL SM Compiled By : G. Elliott, Date: 8/19/2015. Innovative and Reliable Valve & Pump Solutions

M-06 Nitrogen Generator (Nitrogen Making Machine)

NGP-250/500 Nitrogen Generator Quick Start Guide

Ultima. X Series Gas Monitor

New Thinking in Control Reliability

Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis

Failure Modes, Effects and Diagnostic Analysis

Safety Manual. Process pressure transmitter IPT-1* 4 20 ma/hart. Process pressure transmitter IPT-1*

Title: INSTRUMENT AND EQUIPMENT DOCUMENTATION AND RECORDS

Introduction to Machine Safety Standards

The Key Variables Needed for PFDavg Calculation

Safety-Critical Systems

BASF Corporation Title: Portable Multi-Gas Monitoring Equipment. Individual Unit Function: Safety Procedure No.: GSS09 Page: 1 of 5

Analysis of Instrumentation Failure Data

Application Note. Safety Sub-function PUS Category 1, up to PL c. Application Note PUS, Category 1, up to PL c M20 S22 R20 M1 Q20

BOC Healthcare training

BIOGAS COMBUSTION PLANT MAINTENANCE MANUAL

The IEC61508 Inspection and QA Engineer s hymn sheet

HYPOXIC AIR FIRE PREVENTION SYSTEM TECHNICAL SPECIFICATION

Understanding the How, Why, and What of a Safety Integrity Level (SIL)

YT-3300 / 3301 / 3302 / 3303 / 3350 / 3400 /

Understanding safety life cycles

Solenoid gas valve. The solenoid gas valve is also applicable as a main gas valve Pilot gas valve for forced draft burners

Safety Manual OPTISWITCH series relay (DPDT)

Vaisala Pressure, RH & Temp. Transmitter. The instrument was operational upon receipt. The instrument was adjusted and calibrated.

Compiled by: B Beard. Approved by: SH Carstens. Description of requirements and procedures for compact provers to be used as verification standards.

The Safety Case. The safety case

Continuous Gas Analysis In situ laser gas analyzers TÜV and MCERTS add-on for LDS 6 operating instructions Compact Operating Instructions

ECS Protector Nitrogen Inerting Vent (PAV-WN)

Failure Modes, Effects and Diagnostic Analysis

Hydraulic (Subsea) Shuttle Valves

Standard Operating Procedure Measuring & Testing Equipment

Supersedes: The copy of this document located on Measurement Canada s website is considered to be the controlled copy.

SIL explained. Understanding the use of valve actuators in SIL rated safety instrumented systems ACTUATION

ISO INTERNATIONAL STANDARD. Hydraulic fluid power Filter elements Determination of resistance to flow fatigue using high viscosity fluid

Guidelines to the standard IEC60601

D-Case Modeling Guide for Target System

Certificate of Accreditation

Failure Modes, Effects and Diagnostic Analysis. Rosemount Inc. Chanhassen, MN USA

Valve Communication Solutions. Safety instrumented systems

Advanced LOPA Topics

Solenoid Valves used in Safety Instrumented Systems

METHOD 25A - DETERMINATION OF TOTAL GASEOUS ORGANIC CONCENTRATION USING A FLAME IONIZATION ANALYZER

CPX EMERGENCY STANDBY MANIFOLD INSTALLATION, OPERATIONS & MAINTENANCE MANUAL

SF 6 Product Guide. Gas Analysis Instruments and Accessories

Safety Management in Multidisciplinary Systems. SSRM symposium TA University, 26 October 2011 By Boris Zaets AGENDA

Failure Modes, Effects and Diagnostic Analysis

FAULT CODE TROUBLESHOOTING INDEX

STD-3-V1M4_1.7.1_AND_ /15/2015 page 1 of 6. TNI Standard. EL-V1M4 Sections and September 2015

DETERMINATION OF SAFETY REQUIREMENTS FOR SAFETY- RELATED PROTECTION AND CONTROL SYSTEMS - IEC 61508

CT433 - Machine Safety

Operator Exposed to Chlorine Gas

20. Semi-Closed Circuit Rebreather Instructor, Unit Specific- DOLPHIN, RAY, Atlantis, SUBMATIX ST100 & AZIMUTH

Application Note. Safety Sub-functions SSC Category 1, up to PL c PUS Category 1, up to PL c. Application Note SSC, PUS, Category 1, up to PL c STOP

CONFINED SPACE AWARENESS

PUBLIC COMPANY ORLEN LIETUVA OCCUPATIONAL HEALTH AND SAFETY PROCEDURE BDS-12 USE OF PORTABLE GAS ANALYZERS I. GENERAL

Proof Testing A key performance indicator for designers and end users of Safety Instrumented Systems

L&T Valves Limited SAFETY INTEGRITY LEVEL (SIL) VERIFICATION FOR HIGH INTEGRITY PRESSURE PROTECTION SYSTEM (HIPPS) Report No.

Unattended Bleeder Valve Thaws, Causing Fire

Solenoid Valves For Gas Service FP02G & FP05G

973-SF 6 Analyzer. Precise and Stable SF 6 Gas Analyzer REFLECTING YOUR STANDARDS

Bespoke Hydraulic Manifold Assembly

FP15 Interface Valve. SIL Safety Manual. SIL SM.018 Rev 1. Compiled By : G. Elliott, Date: 30/10/2017. Innovative and Reliable Valve & Pump Solutions

BOC Healthcare Training

Lecture 04 ( ) Hazard Analysis. Systeme hoher Qualität und Sicherheit Universität Bremen WS 2015/2016

Real-Time Smoothness Measurements on Concrete Pavements During Construction

VENTIlogic LS VENTIlogic plus. 100 % Mobility and Reliability in IV and NIV

Diving Standards. Health & Safety Authority March 2017

Pressure Gauge Failure Causes Release

Raw Material Spill. Lessons Learned. Volume 05 Issue USW

Combining disturbance simulation and safety analysis techniques for improvement of process safety and reliability

FUNDAMENTAL SAFETY OVERVIEW VOLUME 2: DESIGN AND SAFETY CHAPTER I: AUXILIARY SYSTEMS. A high-capacity EBA system [CSVS] [main purge]

Eutectic Plug Valve. SIL Safety Manual. SIL SM.015 Rev 0. Compiled By : G. Elliott, Date: 19/10/2016. Innovative and Reliable Valve & Pump Solutions

PROCESS AUTOMATION SIL. Manual Safety Integrity Level. Edition 2005 IEC 61508/61511

Data Sheet T 8389 EN. Series 3730 and 3731 Types , , , and. EXPERTplus Valve Diagnostic

Oxygen Dialflow Meter. Instructions for Use

Draeger Fabius GS Pre-Use Check

Hazard and risk analysis in pharmaceutical products 1

SIL Safety Manual. ULTRAMAT 6 Gas Analyzer for the Determination of IR-Absorbing Gases. Supplement to instruction manual ULTRAMAT 6 and OXYMAT 6

Safety Regulations and Procedures GENERAL SAFETY Confined Spaces - S New 11/96. To provide guidance for the safe entry of confined spaces.

ISO INTERNATIONAL STANDARD. Gas cylinders Operational procedures for the safe removal of valves from gas cylinders

1.0 Scope and Application. 2.0 Definitions. Cal Poly Risk Management Confined Space Program Page 1

Touch Screen Guide. OG-1500 and OG Part # T011

Policy for Testing of Oil Discharge Monitoring and Control System Operational Procedure : QOP (17) Revision: 0 Page 1

RESILIENT SEATED BUTTERFLY VALVES FUNCTIONAL SAFETY MANUAL

Transcription:

Safety Assessment for Medical Test Lab Dr. David Endler Systems Engineering Consultant Freelancer & Member of oose eg

Agenda DLR :envihab test laboratory System safety process Design iterations Safety integrity levels Safety requirements and V&V Summary Source:DLR SWISSED 2017 Zürich, Dr. David Endler 2

Introduction Dr. David Endler Systems Engineering Consultant Freelancer Independent member of oose eg Deputy Technical Director of INCOSE DIN representative in ISO JTC 1 / SC 07 / WG 07 (Software and systems engineering Life cycle management) Accredited trainer for SE-Zert trainings SWISSED 2017 Zürich, Dr. David Endler 3

Environment (1/2) DLR German Aerospace Center :envihab consists of 8 separate modules Source:DLR SWISSED 2017 Zürich, Dr. David Endler 4

Environment (2/2) Source: DLR SWISSED 2017 Zürich, Dr. David Endler 5

Research of DLR Institute of Aerospace Medicine The scientific work of the DLR-Institute of Aerospace Medicine in :envihab is concerned, among others, with the following questions: What happens to the human body on a flight to Mars? How does being confined to bed after a serious illness impact the body? How does the lack of daylight affect mood? Are there any measures to counteract these adverse effects? SWISSED 2017 Zürich, Dr. David Endler 6

Scope of Research DLR Institute of Aerospace Medicine Cardiovascular, bone and muscle research Laboratories for studying the effects of oxygen reduction and pressure decrease on test subjects SWISSED 2017 Zürich, Dr. David Endler 7

Applicable Safety Standards No safety standard in place for this application State-of-the-art SWISSED 2017 Zürich, Dr. David Endler 8

Standard Safety Process Plan System Safety Establish system description Identify safety requirements Identify, analyze and categorize hazards Treat risks Verify and validate safety requirements SWISSED 2017 Zürich, Dr. David Endler 9

Systems Engineering & System Safety Control Requirements Analysis Requirements Validation Requirements Hazard Assessment Functional Analysis Functional Verification Functional Hazard Assessment Safety Assessment Synthesis Design Verification Fault Tree Analysis, Dependence Diagrams, Markov Analysis Control Derived from ISO/IEC 26702:2007, figure 4 SWISSED 2017 Zürich, Dr. David Endler 10

Critical Functions Functions identified: 1. Allow access to laboratory 2. Supply laboratory with fresh air 3. Condition laboratory atmosphere 4. Ensure safe operation 5. Determine system state (to control laboratory atmosphere 6. Indicate system state 7. Control laboratory atmosphere 8. Provide comfort 9. Take away used air 10. Allow exit of laboratory SWISSED 2017 Zürich, Dr. David Endler 11

Critical Failure Condition Loss of safe operation Target: 1x10-8 /h FC_4.1_DAY Loss of safety monitoring (day) Adjust critical air mixture MONIITOR_DAY AIR-MIXTURE Total loss of safety circuit Total loss of portable devices SAFETY -CIRCUIT PORTABLE SWISSED 2017 Zürich, Dr. David Endler 12

Function Independence Separation of control circuit and safety circuit Control Circuit Control N 2 /CO 2 enriched atmosphere Control room temperature Control air humidity Safety Circuit Examine gas mixture Shut-off N 2 /CO 2 supply SWISSED 2017 Zürich, Dr. David Endler 13

Safety Circuit Item Independence Supply Air Exhaust Air CO 2 Sonsor 1 CO 2 Sensor 2 Controller O 2 Sensor 1 O 2 Sensor 2 Solenoid Valve SWISSED 2017 Zürich, Dr. David Endler 14

Day and Night Mode During night additional surveillance required Supply Air CO2 Sonsor 1 Safety Circuit Exhaust Air CO2 Sensor 2 Patient Monitor 68 Controller 983% O2 Sensor 1 Solenoid Valve O2 Sensor 2 30 Portable Device 19,8 %O 2 1,12 %CO 2 SWISSED 2017 Zürich, Dr. David Endler 15

Function Independence Separation of control circuit and safety circuit Control Circuit Control N 2 /CO 2 enriched atmosphere Control room temperature Control air humidity Safety Circuit Examine gas mixture Shut-off N 2 /CO 2 supply Monitor vital functions of test persons Examine gas mixture Alarm in case threshold is exceeded SWISSED 2017 Zürich, Dr. David Endler 16

Critical Failure Condition (Night) Loss of safe operation Target: 1x10-8 /h FC_4.1_NIGHT Loss of safety monitoring (night) Adjust critical air mixture MONITOR_NIGHT AIR-MIXTURE Total loss of safety circuit Total loss of portable devices Total loss of vital functions monitoring SAFETY -CIRCUIT PORTABLE VITAL-FUNCTIONS SWISSED 2017 Zürich, Dr. David Endler 17

Allocation of Safety Integrity Levels Safety Circuit meets SIL 2 requirements Patient Monitor meets IEC 60601-1 Class 2 requirements Portable Device: unclear Equivalent Level of Safety SWISSED 2017 Zürich, Dr. David Endler 18

Safety Requirements Safety requirements derived from the safety assessment include Failure rates for failure conditions Threshold values for sensors in supply and exhaust air Emergency procedures level of rigor Maintenance of equipment Item independence of sensors SWISSED 2017 Zürich, Dr. David Endler 19

Integration of System Safety Control Requirements Analysis Requirements Validation Requirements Hazard Assessment Functional Analysis Functional Verification Functional Hazard Assessment Safety Assessment Synthesis Design Verification Fault Tree Analysis, Dependence Diagrams, Markov Analysis Control Derived from ISO/IEC 26702:2007, figure 4 SWISSED 2017 Zürich, Dr. David Endler 20

V&V of Safety Requirements Verification of safety requirements by Test Analysis Demonstration Inspection Continuous monitoring of assumptions SWISSED 2017 Zürich, Dr. David Endler 21

Summary DLR :envihab operated by DLR Institute of Aerospace Medicine Safety standard for this application: state-of-the-art Establish safety requirements early in the lifecycle Establish system description to facilitate safety assessment Design iterations are inevitable Establish substantiation data to pass certification Make system safety integral part of system development SWISSED 2017 Zürich, Dr. David Endler 22