| 1 |
Prioritize usability and workflow fit |
Screen layout, navigation, patient identification, and staff workload |
Time required to locate a patient, review active alarms, and acknowledge an event during a supervised usability test |
Patient lookup: ≤30 seconds Alarm acknowledgement: ≤10 seconds Critical data visible: within one primary screen |
Task-completion results, user feedback, accessibility settings, and training requirements |
| 2 |
Verify alarm management quality |
Alarm priority, escalation, pause controls, configuration, and alarm history |
Whether alarm severity, sound, visual indicator, escalation path, and response status are clearly differentiated |
Alarm behavior should be documented and risk-tested in line with IEC 60601-1-8; every alarm should have a recorded state, timestamp, and response status |
Alarm matrix, escalation rules, alarm-log screenshots, configuration controls, and validation results |
| 3 |
Assess data security and access control |
Authentication, authorization, encryption, session control, and auditability |
Check whether data is encrypted in transit and at rest, user permissions are role-based, and security events are logged |
Encryption in transit: TLS 1.2 or higher Access: unique user accounts with role-based permissions Audit logs: timestamped and protected from unauthorized alteration |
Security architecture, encryption documentation, role-permission matrix, penetration-test summary, and audit-log retention policy |
| 4 |
Confirm data integrity and interoperability |
Data accuracy, synchronization, device connectivity, and interface standards |
Compare source-device values with central-display values and verify patient, timestamp, unit, and measurement mapping |
No unexplained value, unit, or patient mismatch; interface behavior should be documented for supported standards such as HL7 v2 or FHIR, where applicable |
Interface specification, message samples, synchronization test results, error-handling procedure, and data-mapping document |
| 5 |
Evaluate reliability and downtime protection |
Availability, network resilience, backup power, recovery, and offline behavior |
Simulate network interruption, server restart, power transfer, and restoration of communication |
Availability target: ≥99.9% per month, excluding approved maintenance Recovery: documented recovery-time and recovery-point objectives |
Service-level terms, redundancy diagram, backup and restore test, disaster-recovery plan, and downtime notification workflow |
| 6 |
Review compliance and lifecycle controls |
Risk management, software validation, change control, and cybersecurity maintenance |
Check whether the system has documented risk analysis, software lifecycle controls, release procedures, and vulnerability-response processes |
Evidence should address ISO 14971 risk management, IEC 62304 software lifecycle processes where applicable, and a documented security-update policy |
Risk-management file, software validation summary, change-control procedure, vulnerability disclosure process, and update history |
| 7 |
Compare scalability, support, and total cost |
Capacity, expansion, maintenance, training, support response, and five-year ownership cost |
Calculate installation, licensing, integration, training, maintenance, upgrade, cybersecurity, and replacement costs |
Capacity: support current load plus at least 20% planned growth Support: documented response times by severity Cost: five-year total cost of ownership available for comparison |
Capacity model, scalability test, support policy, training plan, maintenance schedule, upgrade roadmap, and five-year cost worksheet |