Project report — medical technology
User interfaces for a medical laser system
In a regulated setting, documentation is not a by-product of development but part of the product.
- Industry
- Medical technology, approval-relevant setting
- System type
- User interfaces of a laser system
- AereA's role
- Development, testing, documentation, code reviews
- Period
- over 4 years
Starting point
Planning and treatment interfaces of a laser system that must not only work but demonstrate that they work.
Approach
Development in C++ and Qt, extension of the associated test tools, unit tests, code reviews and continuous test documentation inside a regulated toolchain.
Result
Over 4 years of accompanied development with more than 4,000 documented test cases — including safety-critical updates to the approved estate.
Results at a glance
- Over 4 years accompanying the product in an approval-relevant setting
- More than 4,000 documented test cases, traceable back to the requirement
- Development of the planning and treatment interfaces in C++ and Qt
- Extension of the project-specific test tools — test infrastructure as a deliverable in its own right
- Safety-critical updates to the approved estate, each with its own evidence procedure
- Implementation of cyber security requirements as part of the regulatory picture
Starting point
A laser system in medical use is planned and controlled through its user interface. That interface is therefore not a frontend but a safety-relevant part of the device.
The task
Development, testing and documentation of the planning and treatment interfaces, plus extension of the associated test tools and implementation of safety-critical updates within the running product lifecycle.
Working in a regulated setting
Requirements live in DOORS, reviews run through Fisheye/Crucible, builds via Jenkins, versioning via SVN. The toolchain is part of the evidence: changes are traceable back to the requirement.
Development used C++ with Qt and Boost, built via CMake, complemented by Python for the test tools.
Quality assurance
Unit tests and code reviews were a fixed part of the approach, not an optional addition. Alongside them came the extension of the project-specific test tools — in regulated environments, test infrastructure is itself a deliverable.
Cyber security
Requirements for hardening and vulnerability handling have become part of the regulatory picture. Implementing them was part of the assignment.
Conclusion
This project is our evidence that evidence-keeping and development speed are not mutually exclusive, provided test documentation runs alongside from the start rather than being retrofitted at the end.
Technologies
Frequently asked questions
Did you own the approval?
No. We delivered development, testing and documentation in the form the manufacturer's quality management needs for approval. The procedure itself sits with the manufacturer.
What does a safety-critical update mean here?
A procedure of its own: change assessment, evidence, testing against the specified requirements and documented release — not a deployment.
Contact
Your contact
Quality assurance, test management & company management