ISO 13485 Quality Management System
NovelPACS employs a comprehensive quality management system that ensures consistent quality and regulatory compliance
Quality Management System
NovelPACS is built on a comprehensive quality management system that adheres to ISO 13485 principles, ensuring consistent delivery of safe and effective medical imaging software. Our QMS includes process documentation, quality objectives, management review mechanisms, and continuous improvement frameworks that maintain high standards throughout the product lifecycle.
Design Controls
Our development process incorporates robust design controls as mandated by ISO 13485, with structured design planning, input validation, output verification, and comprehensive design reviews. Each stage of product development follows a documented process with appropriate approvals, verification steps, and validation activities to ensure requirements are fully met.
Risk Management
NovelPACS implements a systematic risk management process throughout the product lifecycle, from initial requirements through post-market surveillance. Our approach includes hazard identification, risk assessment, mitigation strategies, and ongoing risk monitoring to ensure patient safety and system reliability in clinical environments.
Document Control
Comprehensive document control ensures all quality system documentation is managed with appropriate approval, version control, distribution, and change management processes. Our document management system maintains the integrity of all procedures, work instructions, forms, and records while ensuring only current versions are in use.
Software Validation
Our software validation processes verify that NovelPACS consistently meets all specified requirements and user needs in actual operating environments. We employ structured testing methodologies, validation protocols, and user acceptance testing to confirm software functionality, reliability, and clinical performance.
Post-Market Surveillance
Continuous monitoring of NovelPACS performance in clinical use enables early detection and response to potential issues, with comprehensive complaint handling and vigilance reporting systems. Our post-market processes include structured feedback collection, adverse event monitoring, and proactive quality improvement initiatives.
ISO 13485 Implementation Details
Comprehensive documentation of our ISO 13485 quality management system
NovelPACS implements a comprehensive quality management system that addresses all key requirements of ISO 13485:2016.
Requirement | Clause | Description | Implementation | Status |
|---|---|---|---|---|
| Quality Management System | 4.1 | Establish, document, implement and maintain a quality management system | Comprehensive QMS with process approach and continuous improvement | |
| Management Responsibility | 5.1 | Demonstrate management commitment to quality system development and implementation | Executive leadership involvement with documented quality policy and objectives | |
| Resource Management | 6.1 | Determine and provide necessary resources for QMS implementation | Dedicated quality team and resources with ongoing competency management | |
| Product Realization | 7.1 | Plan and develop processes needed for product realization | Structured development lifecycle with stage-gate approvals and design controls | |
| Design and Development | 7.3 | Establish documented procedures for medical device design and development | Comprehensive design control process with verification and validation | |
| Risk Management | 7.1 | Establish documented requirements for risk management throughout product realization | ISO 14971-aligned risk management process across entire product lifecycle | |
| Purchasing | 7.4 | Ensure purchased products conform to specified requirements | Supplier evaluation, selection and monitoring with documented criteria | |
| Production and Service | 7.5 | Plan and carry out production and service under controlled conditions | Controlled deployment, installation and upgrade processes with validation | |
| Monitoring and Measurement | 8.2 | Monitor information about customer satisfaction and internal processes | Comprehensive monitoring framework with user feedback and metrics tracking | |
| Nonconforming Product | 8.3 | Identify and control product that does not conform to requirements | Nonconformity identification, documentation, evaluation, and resolution process | |
| Corrective Action | 8.5.2 | Eliminate causes of nonconformities to prevent recurrence | Structured root cause analysis and verification of corrective action effectiveness | |
| Preventive Action | 8.5.3 | Identify and eliminate potential nonconformities to prevent occurrence | Proactive risk identification with preventive measures and effectiveness monitoring |
Our ISO 13485:2016 certificate and quality management system documentation are available upon request.
Comprehensive Risk Management
NovelPACS implements a thorough risk management process aligned with ISO 14971 principles, ensuring potential risks are identified and mitigated throughout the product lifecycle.
Our risk management approach integrates with all stages of product development, from initial requirements through post-market surveillance, ensuring patient safety and system reliability remain top priorities.
Risk Management Process:
- Risk Analysis
Systematic identification and evaluation of potential hazards
- Risk Evaluation
Assessment of risk levels against acceptability criteria
- Risk Control
Implementation and verification of risk mitigation measures
- Residual Risk Evaluation
Assessment of remaining risk after controls are implemented
- Risk Management Review
Regular review of risk management activities and results
- Post-Production Information
Monitoring of real-world performance for emerging risks
ISO 13485 Implementation Case Studies
How NovelPACS implemented ISO 13485 quality management principles for medical imaging
Regulatory Significance of ISO 13485
How ISO 13485 certification supports regulatory clearance in global markets
European Union (EU)
ISO 13485 certification is a vital component for demonstrating compliance with the European Medical Device Regulation (MDR). The MDR explicitly references ISO 13485 as a harmonized standard, making certification a key element in obtaining CE marking for medical devices.
For software as a medical device (SaMD) like NovelPACS, ISO 13485 certification helps demonstrate:
- Systematic quality management approach
- Comprehensive risk management
- Process validation and verification
- Post-market surveillance capabilities
Global Markets
ISO 13485 certification facilitates global market access through recognition by regulatory bodies worldwide. Many countries accept ISO 13485 certification as evidence of quality system compliance, streamlining the regulatory approval process.
NovelPACS ISO 13485 certification supports regulatory pathways in:
- Canada (Health Canada)
- Australia (TGA)
- Japan (PMDA)
- Brazil (ANVISA)
- Singapore (HSA)
- Many more countries
United States FDA
While the FDA's Quality System Regulation (21 CFR Part 820) is the primary quality system requirement for the US market, ISO 13485 certification provides valuable support for FDA submissions. The FDA recognizes ISO 13485:2016 as largely harmonized with QSR requirements.
Benefits for FDA Submissions:
- Demonstrates robust quality management
- Supports Design History File (DHF) requirements
- Documents risk management processes
- Aligns with software validation expectations
MDSAP Participation:
NovelPACS participates in the Medical Device Single Audit Program (MDSAP), which allows a single audit to satisfy quality system requirements of multiple regulatory authorities:
- US FDA
- Health Canada
- Brazil ANVISA
- Australia TGA
- Japan PMDA
Frequently Asked Questions About ISO 13485
Common questions about ISO 13485 quality management for medical imaging
What is ISO 13485 and why is it important for medical imaging software?
ISO 13485 is an internationally recognized standard for quality management systems specific to medical devices. It establishes requirements for a comprehensive quality management system for the design, development, production, installation, and servicing of medical devices. ISO 13485 certification demonstrates that an organization consistently meets both customer and applicable regulatory requirements for medical devices. For medical imaging software like NovelPACS, ISO 13485 compliance is particularly important because these systems are classified as medical devices in many regulatory frameworks, including the EU Medical Device Regulation (MDR), the US FDA Quality System Regulation, and similar regulations worldwide. Medical imaging software directly impacts patient diagnoses and treatment decisions, making quality management critical for patient safety. The standard ensures systematic approaches to quality throughout the entire product lifecycle, from initial concept through design, development, deployment, maintenance, and eventual retirement. By following ISO 13485 principles, medical imaging software manufacturers implement robust processes for risk management, design controls, validation, and post-market surveillance that help identify and mitigate potential issues before they affect clinical use. ISO 13485 also facilitates regulatory compliance across multiple jurisdictions, as many countries recognize ISO 13485 certification as evidence of an effective quality management system. For healthcare providers, selecting a vendor with ISO 13485 certification provides assurance that the medical imaging software was developed under controlled conditions with appropriate oversight, verification, and validation to ensure it performs as intended in clinical settings.
How does NovelPACS implement design and development controls required by ISO 13485?
NovelPACS implements a comprehensive design and development control process as required by ISO 13485 section 7.3, ensuring our medical imaging software is developed under controlled conditions with appropriate verification and validation at each stage. Our design and development process begins with detailed planning that defines responsibilities, activities, resources, and timelines for each project phase, with appropriate stage-gate reviews and approval processes. For requirements management, we employ a structured approach to capture and validate user needs, regulatory requirements, and system specifications, with complete traceability maintained throughout the development lifecycle. Each requirement is reviewed for clarity, feasibility, and verifiability before being approved for implementation. Our design process includes formal design reviews at defined stages (preliminary, critical, and final) where cross-functional teams evaluate design outputs against input requirements, identifying potential issues early in the development cycle. Design verification activities confirm that design outputs meet specified requirements through methods such as code reviews, static analysis, unit testing, integration testing, and system testing, all performed according to documented protocols with defined acceptance criteria. For design validation, we conduct comprehensive testing in environments that simulate actual clinical use conditions, including usability testing with representative users, to ensure the software meets user needs and intended uses. All design changes are controlled through a formal change management process that includes impact assessment, verification of changes, validation where appropriate, and approval before implementation. Throughout the design and development process, we maintain comprehensive documentation in our Design History File (DHF) that captures design inputs, outputs, verification results, validation results, and all design changes, providing traceability from requirements through implementation and testing. Risk management is integrated throughout the design process, with hazard identification, risk analysis, and risk control measures implemented and verified at each stage of development. This systematic approach to design and development ensures that NovelPACS is developed according to defined requirements, undergoes appropriate verification and validation, and incorporates necessary risk controls before release to market.
What risk management processes does NovelPACS employ to meet ISO 13485 requirements?
NovelPACS implements a comprehensive risk management process aligned with both ISO 13485 requirements and the specialized medical device risk management standard ISO 14971. Our approach addresses risks throughout the entire product lifecycle, from conception through post-market surveillance. The foundation of our risk management process is a documented risk management plan that defines responsibilities, activities, criteria for risk acceptability, and verification requirements for risk control measures. For each product version, we maintain a living risk management file that documents all risk management activities and decisions. Our risk identification process combines multiple techniques including Failure Mode and Effects Analysis (FMEA), Fault Tree Analysis (FTA), and systematic review of previous generation products, customer feedback, and published literature to identify potential hazards associated with the use of our imaging software. This comprehensive approach ensures we consider both obvious and non-obvious hazards. For each identified hazard, we conduct a thorough risk analysis to determine potential harm scenarios, estimate the severity of potential harm, and evaluate the probability of occurrence. This analysis forms the basis for risk evaluation against defined acceptability criteria. When risks exceed acceptable levels, we implement risk control measures following the hierarchy of: (1) inherent safety by design, (2) protective measures in the software itself, and (3) information for safety in the form of warnings, limitations, and training. All risk control measures undergo verification to ensure they are effectively implemented and do not introduce new risks. After implementation of risk controls, we conduct a residual risk evaluation to determine if the overall residual risk remains acceptable, with formal management review and approval of any risks that cannot be further reduced. Post-market information from customer feedback, incident reports, and real-world usage is continuously fed back into the risk management process to identify new hazards or changes in risk levels. Regular reviews of risk management data trigger updates to risk assessments and control measures when needed. To ensure risk management knowledge is maintained across the organization, we conduct regular training for our development, quality, and support teams on risk management principles and procedures. This comprehensive approach to risk management ensures that potential safety issues are identified and addressed proactively throughout the lifecycle of NovelPACS, protecting patients and users while meeting ISO 13485 requirements.
How does NovelPACS ensure software validation as required by ISO 13485?
NovelPACS employs a comprehensive software validation approach to ensure our medical imaging software performs as intended in its actual operating environment, in full compliance with ISO 13485 section 7.5.6. Our validation strategy encompasses both the validation of our software development processes and the validation of the software product itself. Our validation begins with a detailed validation planning phase where we define validation activities, responsibilities, methodologies, environments, and acceptance criteria tailored to the complexity and intended use of the software. These plans are reviewed and approved by qualified personnel before validation activities commence. For process validation, we employ a structured approach to validate our software development lifecycle, including our requirements management, design control, coding standards, testing methodologies, and change management processes. This ensures the processes used to develop NovelPACS consistently produce software that meets specified requirements. For product validation, we implement a multi-layered approach that includes: (1) Installation Qualification (IQ) to verify the software is correctly installed on target hardware configurations; (2) Operational Qualification (OQ) to verify the software functions according to specifications across its operational range; and (3) Performance Qualification (PQ) to verify the software consistently performs as intended in simulated real-world environments. Our validation incorporates rigorous testing methodologies including function testing, load testing, stress testing, security testing, and compatibility testing across supported platforms. We employ both manual and automated testing approaches with complete traceability to requirements. Particular attention is paid to validating critical functions that could impact patient safety or diagnostic accuracy, with enhanced test coverage and specialized test protocols. For clinical validation, we ensure the software meets user needs in actual clinical environments using realistic test scenarios and representative clinical data. This includes usability validation with intended users to verify the user interface is intuitive and error-resistant. All validation activities are documented in detailed validation reports that include test results, deviations, anomalies, and conclusions regarding software acceptability. Each validation report undergoes formal review and approval before software release. For software maintenance and changes, we employ a risk-based approach to revalidation, conducting appropriate validation activities based on the nature and extent of the changes, with particular attention to potential impacts on safety-critical functions. Throughout the validation process, we maintain comprehensive validation documentation that provides objective evidence of validation activities and results, ensuring traceability and supporting regulatory submissions. By implementing this robust validation approach, we ensure NovelPACS consistently meets all specified requirements, performs as intended in clinical environments, and complies fully with ISO 13485 requirements for software validation.
What document control and record management systems does NovelPACS implement to comply with ISO 13485?
NovelPACS implements a comprehensive document control and record management system that ensures full compliance with ISO 13485 sections 4.2.3 (Document Control) and 4.2.4 (Control of Records). Our system provides controlled management of all quality system documentation and records throughout their lifecycle. For document control, we employ a secure electronic document management system that ensures only approved, current versions of documents are available for use. All controlled documents undergo a defined approval workflow before release, with electronic signatures from authorized personnel based on their roles and responsibilities. Documents are systematically identified with unique identifiers, revision levels, approval dates, and effective dates to prevent the use of obsolete documentation. Our document change control process ensures changes to documents are reviewed and approved by the same functions that performed the original review and approval, with clear identification of changes and maintenance of change history. For external documents such as standards, regulations, and supplier documentation that are necessary for our quality management system, we maintain a controlled process for identification, distribution, and update notification. Record management is equally robust, with a systematic approach to identifying, collecting, indexing, accessing, filing, storing, maintaining, and disposing of quality records. Our record system maintains the integrity and confidentiality of records through access controls, backup procedures, and validation of electronic record systems. Records are stored in a manner that ensures they remain legible, readily identifiable, and retrievable, with protection against damage, deterioration, and loss. Each record type has a defined retention period based on the lifetime of the medical device, regulatory requirements, and organizational needs, with secure destruction procedures when retention periods expire. For electronic records, we implement additional controls including data integrity verification, secure authentication, audit trails of changes, regular backups, and disaster recovery capabilities. Our electronic record systems undergo validation to ensure they consistently create and maintain records that meet ISO 13485 requirements. To ensure compliance with regulatory requirements for different markets, our document and record control system accommodates varying documentation requirements and retention periods across different jurisdictions. Regular audits of our document control and record management system verify compliance with ISO 13485 requirements and identify opportunities for improvement. This comprehensive approach to document control and record management ensures that NovelPACS maintains appropriate documentation of all quality management system activities, providing evidence of conformity to requirements and effective operation of the quality management system as required by ISO 13485.
How does NovelPACS implement post-market surveillance to meet ISO 13485 requirements?
NovelPACS implements a comprehensive post-market surveillance (PMS) system that aligns with ISO 13485 requirements for monitoring product performance after release to market. Our PMS system actively collects and analyzes information about the real-world performance of our medical imaging software to identify potential issues early and drive continuous improvement. At the core of our PMS system is a documented process for gathering information from multiple sources including: (1) customer feedback collected through our support system, user surveys, and account management interactions; (2) user experience metrics automatically collected from deployed systems (with appropriate privacy controls); (3) incident and near-incident reports from users; (4) literature and database reviews for similar devices; and (5) performance data from our cloud-hosted implementations. All incoming information is systematically documented, categorized, and routed to appropriate teams for analysis and response. Our complaint handling process ensures all user-reported issues are promptly documented, investigated, and addressed, with risk-based prioritization to expedite the handling of potentially safety-related complaints. For adverse events that meet regulatory reporting criteria, we implement vigilance reporting procedures to ensure timely notification to relevant regulatory authorities in accordance with jurisdictional requirements. Our PMS activities include regular trend analysis of aggregated data to identify patterns that might not be apparent from individual reports, allowing us to detect and address potential systematic issues before they impact patient safety or clinical performance. Findings from PMS activities are fed back into our risk management process to update risk assessments based on real-world data, with implementation of additional risk control measures when necessary. For product improvements, our PMS data serves as a key input to our change management process, driving software enhancements, user interface improvements, and documentation updates based on real-world user experiences and needs. Performance data collected through PMS is systematically reviewed during management review meetings, with corrective and preventive actions initiated when performance does not meet expectations or when opportunities for improvement are identified. To ensure comprehensive market coverage, our PMS system is designed to collect information across different geographical markets, clinical specialties, and usage environments, providing a complete picture of product performance across our user base. All PMS activities, findings, and actions are thoroughly documented in our quality management system, with periodic reports summarizing PMS data, trends, analyses, and resulting actions. By implementing this robust PMS system, NovelPACS meets ISO 13485 requirements for post-market feedback, complaint handling, and regulatory reporting while continuously improving our product based on real-world performance data.
Have more questions about our ISO 13485 quality management system?
Contact Our Quality Team