IMPLANTABLE MEDICAL DEVICE AND METHOD OF OPERATION OF AN IMPLANTABLE MEDICAL DEVICE - Patent application
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- BIOTRONIK SE & CO KG
- Filing Date
- 2023-04-04
- Publication Date
- 2026-03-19
AI Technical Summary
Implantable medical devices, particularly small devices like ILPs, face challenges in supporting complex behaviors while maintaining device lifetimes and safely managing worst-case reset situations, especially when multiple devices are implanted in a patient.
An implantable medical device with a processor, therapy signal generator, and memory units, including a ROM subunit, RAM subunit, and state element, which allows for controlled operation and treatment output based on received data and stored parameters, ensuring safe operation even under worst-case reset conditions.
The solution enhances patient safety by ensuring continued therapeutic support during worst-case reset situations and managing the transition between old and new medical devices, thereby preventing potential interference or failure in multi-device systems.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates generally to implantable medical devices, such as implantable leadless pacemakers, methods of operating such implantable medical devices, corresponding computer program products, computer readable data carriers, and systems including at least one such implantable medical device and an external computing device.
[0002] Active implantable medical devices (IMDs, implants), such as pacemakers (with leads), implantable cardiac monitors (ICMs), implantable leadless spacers (ILPs), implantable leadless pressure sensors (ILPSs), implantable cardioverter defibrillators (ICDs), subcutaneous ICDs (S-ICDs) or neurostimulators, such as spinal cord stimulators (SCSs), are configured to collect diagnostic and / or administer therapeutic signals to a patient to assist with such therapy, such as electrical stimulation of the heart. In the above diagnostic assistance applications, such devices conceptually include at least one sensor that collects physiological signals to monitor the patient's health status, and a critical communication unit infrastructure that allows the collected signals to be transmitted (as raw data or processed data depending on the situation and application) to an external computing device (e.g., smartphone, programmer, computer, remote server).
[0003] A cardiac pacemaker (or artificial pacemaker) is a medical device that generates electrical pulses delivered from electrodes connected to or fixedly attached to the pacemaker, which can cause the myocardial chambers (i.e., atria and / or ventricles) to contract and thus pump blood. With this output, the device replaces and / or regulates the function of the patient's cardiac electrical conduction system. One purpose of a pacemaker is to maintain an appropriate heartbeat (heart rate) as a replacement for defects in the heart's natural pacemaker or when there are blockages in the cardiac electrical conduction system. Additionally or alternatively, pacemakers can stimulate different locations within the ventricles to improve synchrony or provide anti-tachycardia pacing outputs to counter life-threatening arrhythmias. Today's pacemakers are programmable by an external computing device (programmer), allowing healthcare professionals (HCPs) to select the optimal pacing mode and configuration settings for an individual patient's needs.
[0004] An implantable intracardiac pacemaker (also known as an implantable leadless pacemaker ILP) is a miniature pacemaker that is fully implanted within the patient's ventricular or atrial blood volume. ILPs are crucial to the future of cardiac pacing. In addition to core sensing and pacing assistance, alternative or additional functions of conventional or intracardiac pacemakers include the delivery of electrical or electromagnetic signals separate from the pacing output to the heart or its surrounding tissues (e.g., to gather insight into thoracic impedance, etc.) and the evaluation of physical body movements or other physiological signals of interest. Also, the battery capacity of ILPs is small due to the highly limited size of the device.
[0005] ILPs and other small implantable medical devices are challenged in their ability to simultaneously support complex behaviors in a small form factor while still providing device longevity consistent with conventional designs. Additionally, the compact size of such devices, especially those that remain in the patient for extended periods of time, also creates challenges for end-of-service (EOS) removal. A readily envisioned future embodiment of such small medical device technology is the growing expectation that therapy will be coordinated across multiple implanted medical devices in supporting critical patient needs. Accordingly, the programming settings within these implants require special handling and attention under the implant's worst-case reset dynamics as established by the HCP at the most recent follow-up. Worst-case reset behavior is a state in which an active implantable medical device loses the ability to function according to its nominal intent, thereby governing the behavior of a "last resort option." In many designs of active implantable medical devices, a worst-case reset can occur when the RAM application running on the device becomes corrupted in an irreparable manner.
[0006] Known medical devices for cardiac rhythm management (CRM) assume that a safe response to a worst-case reset condition always embodies a behavior that results in the delivery of some form of corrective pacing output. This therapy output corresponds to a therapy that maintains the patient's support (albeit suboptimal) until the patient can contact his / her cardiologist, even though the particular therapy mode best suited for the patient may not be administered. However, it is known that providing an output at all times is not a safe condition in a situation where two or more medical devices capable of providing therapy are implanted within the patient. Furthermore, this type of worst-case reset has often been a reset that applies a pacing output with a large amplitude and long pulse width in conventional implantable medical devices, such as pacemakers / ILPs. Although such outputs provide a means of increasing the likelihood of effectively engaging the cardiac conduction system, the energy demands associated with such outputs are not easily matched with the limited power resources found in ILPs or other small implantable medical devices.
[0007] Thus, there is a need for an implantable medical device and method of operating the medical device that enhances patient safety in worst-case reset situations, particularly when the medical device is a component of a multi-device system or when there are issues associated with requiring physical removal of the device, where a device approaching end of life remains in the patient after a replacement device is implanted.
[0008] The above problem is solved by an implantable medical device having the features according to claim 1, a system having the features according to claim 6, a method for operating an implantable medical device having the features according to claim 8, a computer program product having the features according to claim 13 and a computer readable data carrier having the features according to claim 14.
[0009] In particular, the above problems are solved by an implantable medical device, e.g., an implantable leadless pacemaker, including a processor, a therapy signal generator, e.g., a pacing signal generator, and a communication unit and a memory unit, wherein the memory unit is configured to exchange data with the processor and includes a ROM subunit, a second memory subunit and a status element, the status element being configured to be set to one of a first state and at least one second state, the second memory subunit including a RAM, the communication unit is configured to receive information including status input information from an external computing device and transmit at least one data corresponding to the information to the processor, the processor is configured to set a state of the status element based on the received data corresponding to the status input information, and further configured to operate a therapy output determination and a control of transmission of the therapy output to the therapy signal generator based on the data stored in the ROM subunit and a current state of the status element if the processor identifies that the at least one predetermined RAM application has been irreparably corrupted.
[0010] An implantable medical device having the above characteristics may be an ILP, a conventional pacemaker, an implantable cardiac monitor (ICM), an ILPS, an ICD, an S-ICD, a neurostimulator, or the like.
[0011] The implantable medical device includes a processor, a therapy signal generator, e.g., a pacing signal generator, and a communication unit and a memory unit, the therapy signal generator, the communication unit and the memory unit being electrically interconnected to the processor and configured to exchange data with the processor.
[0012] A processor is generally considered to be a functional unit of a medical device that interprets and executes instructions, including an instruction control unit and an arithmetic logic unit. The processor may include or be a microprocessor, a controller, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a discrete logic circuit, or any combination thereof. Alternatively or additionally, the processor may be realized using dedicated integrated hardware logic, especially in the case of ILP due to small size and extreme power limitations.
[0013] The processor processes the data and information received from the communication unit and the memory unit. The processor can further process the signal data received from the detector to obtain physiological signals from the patient, such as electrical signals of the patient's heart detected over time. The signal data determined by the detector and the information received from the external computing device by the communication unit are transmitted to the processor.
[0014] The communication unit can be configured to receive information from an external computing device (one-way communication) or to communicate two-way with an external computing device. The communication can be wireless, including over the air interface via electromagnetic waves, acoustic, conductive, magnetic / inductive coupling, or other methods (typically with a programmer wand managing direct physical contact with the patient), or through the body in certain circumstances (other than those nominally used for power-consuming deep implants), for example using MedRadio / MICS / MEDS, EDGE, EV-DO, Flash-OFDM, GPRS, HSPA, LoRaWAN, RTT, UMTS, narrowband IoT, Bluetooth, WLAN (WiFi), ZigBee, NFC, LTE, wireless USB, Wibree (BLE), Ethernet or WiMAX in the radio frequency domain, or IrDA or free space optical communication (FSO) in the infrared or optical frequency domain. The external computing device (e.g., programmer) is configured to transmit parameters to the medical device by a patient / HCP-facing user interface. The entry / selection of the appropriate parameters and the transfer of these parameters to the medical device is referred to as programming.
[0015] The processor controls the determination of a therapy output based on parameters provided by the application and the memory unit, and additionally, if applicable, based on signal data received from the detector, and transmits the therapy output to a therapy signal generator that generates a therapy signal based on the therapy output and delivers the signal to the patient (e.g., the patient's tissue). The therapy signal generator generates, for example, an electrical or electromagnetic therapy signal based on the therapy output determined by the processor to provide associated assistance to the patient.
[0016] In particular, in the case of a pacemaker or ILP, the detector may be configured to detect time-dependent electrical depolarization and repolarization field signals, such as an electrocardiogram (ECG) or an intracardiac electrocardiogram (IEGM). These signals may include signals caused by depolarization of the atria (hereinafter also referred to as intrinsic atrial signals) and electrical signals caused by depolarization of the ventricles (hereinafter also referred to as intrinsic ventricular signals). In the case of an ILP, the intrinsic atrial signals may be far-field electrical signals. The detector may pre-process these data, for example, digitize the signals, and / or filter the signals, and / or amplify the signals before relaying the data to the processor. The processor may receive the detector signals, for example, intrinsic ventricular signals and intrinsic atrial signals derived from the electrical signals, for example, intrinsic atrial signals from P waves and intrinsic ventricular signals from QRS complexes.
[0017] A medical device that is an ILP or a conventional pacemaker can typically operate in a VDD pacing mode (i.e., a pacing mode that provides a therapeutic output of the processor so that the ventricle is stimulated in response to detected atrial activity) or a VVI-based pacing mode. In the VDD mode, the pacemaker synchronizes ventricular pacing with an intrinsic atrial signal using an AV delay. In a VDD ILP implanted in the right ventricle, atrial contraction information can be detected as a far-field electrical signal as described above. In the VDD mode, the processor can determine a measured intrinsic beat interval from the intrinsic atrial signal and the intrinsic ventricular signal or ventricular pacing signal, which in turn corresponds to an intrinsic heart rate. The measured current intrinsic beat interval can be used to provide a ventricular pacing control signal including a ventricular pacing time, which can then be sent to a pacing signal generator. The pacing signal generator forms an electrical pacing signal based on the pacing control signal and delivers it to the electrode to apply the signal to the cardiac tissue adjacent to the electrode. The pacing signal is a pulse that starts at a desired time and has a desired intensity and duration. Furthermore, the pulse shape can be varied, for example, in terms of pulse width and pulse amplitude. Information about the pacing signal, e.g., the ventricular pacing signal, required to form the correct pacing signal is provided from the pacing control signal of the processor, e.g., the ventricular pacing control signal, or from the pacing signal generator itself. In particular, the ventricular pacing control signal provides time information of the pacing signal, i.e., information about when the pacing signal should be delivered directly to the patient's heart, e.g., that pacing should be delivered without further deferral. In one embodiment, the pacing signal is overridden (i.e., blocked) by the patient's intrinsic cardiac activity, and thus the pacemaker avoids delivering a pacing output to the electrode when not needed, allowing for avoidance of stimulation. The VVI mode of operation is similarly aided by eliminating the effort to detect atrial signaling.
[0018] The medical device includes a memory unit, which may include any volatile, non-volatile, magnetic or electrical medium, such as a random access memory (RAM), a non-volatile RAM (NVRAM), an electrically erasable programmable ROM (EEPROM), a flash memory or any other memory device, where the memory unit specifically includes a read only memory (ROM) subunit, a second memory subunit including a RAM, and a status element. The memory unit stores parameters and other data required by the medical device to provide a predetermined therapy to the patient. The parameters and other data are required by the processor during the execution of the steps described above and below. The second memory subunit further includes a RAM program application, which is typically used by the medical device, and in particular its processor, to control the determination of the therapy output and the transmission of the therapy output to the therapy signal generator, thereby providing the predetermined therapy to the patient.
[0019] The state element is a section of the memory unit that contains state information. It can be realized as a part of the volatile memory space, including retention in RAM, hardware registers or other forms. According to a preferred embodiment, the state element is placed in hardware registers outside of the ROM code space and outside of the RAM code space as an additional safety strategy, and these registers are constructed for robustness against single event upsets (SEUs, such as cosmic radiation exposure). The state information here is used to control the behavior of the medical device according to a condition when the processor identifies that at least one predefined RAM application has been irreparably corrupted. The state element is configured to be set to one of a first state and at least one second state, for example, exactly one of the second states. The communication unit is configured to receive information including state input information from an external computing device, such as a smartphone, a programmer, a computer or a remote server, and to transmit at least one data corresponding to the information to the processor, and the processor is configured to set the state of the state element based on the data corresponding to the received state input information. Thus, the processor sets the state element to the first state or at least one second state. One of the second states can be the initial state of the state element. The current state of the state element is the state most recently set by the processor, or the initial state if there has been no state setting of the state element since the start of operation of the medical device. In a preferred embodiment, the setting of the state element is only supported during an active communication session with the external device, meaning that the implant itself does not have the ability to configure or change the element outside of a follow-up.For example, the communication unit and the medical device status elements are used in the context of an external computing device where an interface can be used to instruct a specific target medical device (among multiple medical devices present in a patient) to be designated as a device that is essential for administering therapy or as a device that should be disabled and therefore therapy signal output is denied. In the context of a switching condition, this can simply amount to indicating which medical device is the "old" medical device and which is the "new" alternative medical device. In the present case, the "old" medical device can be moved to an inactive state where it is denied the ability to deliver therapy at a later time, and the "new" medical device can be designated as the one intended to provide bradycardia symptom management from now on. Alternatively, in the context of coordinated therapy in a cluster of multiple medical devices, all participating medical devices can be expected to deliver therapy, and thus, using an interface accessible to the HCP of the external computing device, all medical devices can be designated as medical devices that can continue to deliver output even if it is only corrective under a worst-case reset (e.g., by using a downgrade mode support condition or a proposal for support with reduced functionality).
[0020] Thus, the processor is further configured to perform an action of the processor controlling the determination of the therapy output and the transmission of the therapy output to the therapy output generator based on the data stored in the ROM subunit and the current state of the state element when the processor identifies that at least one of the predetermined RAM applications has been irreparably corrupted (e.g., when the monitoring of the critical signature check of the bit flips is invalid and self-repair is found to be impossible). The state element determines the type of action of the processor in such a "last resort option" (i.e., when at least one of the predetermined RAM applications has been irreparably corrupted). From the multiple states adoptable by the state element, multiple processing modes or branches that can be executed by the processor in such a situation are determined, where the minimum number of processing modes or branches is two. In the latter case, the first state of the state element can be "0" and the second state of the state element can be "1". Additionally, the data stored in the ROM subunit, i.e., the worst-case program preconfigured and stored in the ROM, is used by the processor to adapt the operation of the processor to the specific needs of the medical device and the patient to provide therapy in one of the states. In other words, when a particular medical device switches from a normal operating state to a worst-case reset state (i.e., a state in which the implant's RAM application typically cannot be initiated), the device can be caused to land in a nominally ROM-oriented operating state.
[0021] In one embodiment, the processor is configured to prevent a therapy output determination when the first state is the current state of the state element, and to determine a therapy output based on data stored in the ROM subunit and transmit the determined therapy output to the therapy signal generator when one of the second states is the current state of the state element, also referred to as a ROM-oriented behavior. In such an embodiment, the ROM subunit should be configured to provide at least two operating modes under worst-case reset conditions, a first mode in which at least a therapy output determination is prevented and a second mode in which minimal therapy assistance is provided to the patient based on data stored in the ROM subunit.
[0022] In a likely alternative preferred embodiment, the processor is configured to determine the therapy output based on data stored in the ROM subunit, where the processor is further configured to prevent transmission of the determined therapy output to the therapy signal generator if the first state is the current state of the state element, and to transmit the determined therapy output to the therapy signal generator if one of the second states is the current state of the state element. For such an embodiment, the design of the ROM subunit can be structured in a manner that does not require evaluation or reference of content residing in a ROM external memory location, such that the resulting behavior of the implant is ultimately mediated by a completely independent hardware enable switch condition. In such a situation, a "one size fits all" ROM subunit configuration can be employed, where the administered therapy is always assumed to be a correct and safe behavior, as in conventional products, but the hardware enable switch condition is downstream of the settings to determine whether the ROM subunit data (settings) ultimately led to the delivery of therapy to the patient.
[0023] For an ILP or conventional pacemaker, the therapy signal delivered by the pacing signal generator may achieve a nominal (eg, 60 ppm) pacing rate.
[0024] In one embodiment, the second memory subunit additionally includes a predefined security memory subsection, and the processor is configured to make a therapy output decision based on at least one parameter additionally derived from the security memory subsection when one of the second states is the current state of the state element. The at least one parameter for therapy is stored in the predefined security memory section having higher operational reliability and accuracy than any other memory section, for example in one or more registers specifically designed to minimize the possibility of single event upsets (SEUs) (e.g. bit flip transitions associated with cosmic radiation exposure) or in RAM locations with associated redundancy. Such a security memory section can store at least one parameter that is used during normal operation of the medical device, i.e. not in worst case reset conditions, and thus can be adapted to the specific needs of a particular patient during follow-up. In one embodiment related to a pacemaker or ILP as a medical device, the at least one parameter derived from the predefined security memory subsection is a pulse width and / or a pulse amplitude. The present embodiment provides the ability for a medical device directed to therapy delivery (and subject to worst-case reset conditions) to provide a means to configure output amplitude and output pulse width based on recent historical conditions previously known to provide myocardial pacing capture, which may be applied to other medical devices as well.
[0025] Alternatively or additionally, the detector of the implantable medical device may include an accelerometer, a vibration sensor, an acoustic sensor (including ultrasound), and / or any other mechanical, electrical and / or magnetic sensor capable of detecting patient activity depending on time (i.e., a motion sensor), for example, a sensor capable of detecting whether the patient is lying, sleeping, sitting, moving with fast or slow movements including motion, etc. The motion sensor here collects the patient activity signal and converts it into an electrical signal. Furthermore, the detector may digitize, filter and / or smooth the analog signal to reduce signal noise. Some pre-processing steps may be provided by the detector as well. The signal formed and determined by the detector may be directly transmitted to the processor.
[0026] The implantable medical device may include further modules such as a power source (e.g., a battery), etc. The components or units of the implantable medical device described above and below may be arranged in a hermetically sealed housing.
[0027] The above object is further solved by a system including at least one implantable medical device according to any one of claims 1 to 5 and an external computing device, e.g. a programmer, configured to transmit information to the at least one implantable medical device. As indicated above, the HCP can use the external computing device to provide instructions for a "forward" treatment (or no treatment) state to any one of the above-mentioned medical devices resident in the patient, in particular for "forward" treatment (or no treatment) under a worst-case reset condition.
[0028] In one embodiment of the system, the system includes at least two medical devices, and the external computing device is configured to transmit information to a particular one of the at least two medical devices based on a unique identifier, e.g., a serial number, assigned to each of the at least two medical devices prior to implantation, In one embodiment, one of the at least two medical devices is intended to be substituted for another one of the at least two medical devices with respect to the prescription of a patient's treatment or diagnostic support.
[0029] Because of the limited data transmission capacity of deeply implanted medical devices (e.g., ILPs), instead of sending the (long) serial number of each device as a unique identifier every time the two medical devices communicate when they are within range of an external computing device, the serial numbers can be shortened to a short unique identifier that can be as simple as designating the first leadless cardiac pacemaker as device 1 and the second leadless cardiac pacemaker as device 2 or any single digit, e.g., the last digit of the serial number, where the shortened unique identifier must be defined such that there is a different number for each of the at least two medical devices.
[0030] The above objects are further solved by a method of operation of an implantable medical device, e.g., an implantable leadless pacemaker, including a processor, a therapy signal generator, e.g., a pacing signal generator, and a communication unit and a memory unit, the memory unit being configured to exchange data with the processor and including a ROM subunit, a second memory subunit, and a status element, the status element being set to one of a first state and at least one second state, the second memory subunit including a RAM, the communication unit receiving information including status input information from an external computing device and transmitting at least one data corresponding to the information to the processor, the processor setting a state of the status element based on the received data corresponding to the status input information, and if the processor identifies that the at least one predetermined RAM application has been irreparably corrupted, the processor operates to determine a therapy output and control transmission of the therapy output to the therapy signal generator based on the data stored in the ROM subunit and the current state of the status element. The operation method can be considered as a computer-implemented method since the operation method is performed by the processor of the implantable medical device.
[0031] In one embodiment of the method, if the first state is the current state of the state element, the processor prevents determining the therapy output, and if one of the second states is the current state of the state element, the processor determines the therapy output based on data stored in the ROM subunit and transmits the determined therapy output to the therapy signal generator.
[0032] In an alternative embodiment of the method, the processor determines a therapy output based on data stored in the ROM subunit, and if a first state is the current state of the state element, the processor prevents transmission of the determined therapy output to the therapy signal generator, and if one of the second states is the current state of the state element, the processor transmits the determined therapy output to the therapy signal generator.
[0033] In one embodiment of the method, the second memory subunit additionally includes a predetermined security memory subsection, and the processor additionally determines the therapy output based on at least one parameter derived from the security memory subsection when one of the second states is the current state of the state element.
[0034] In one embodiment of the method, the at least one parameter derived from the predetermined security memory subsection is a pulse width and / or a pulse amplitude, particularly if the implantable medical device is an ILP.
[0035] Each of the above-mentioned embodiments of the operating method has the same advantages as the above-mentioned medical device. Each of the above-mentioned embodiments of the medical device can be realized in the same way in the operating method. In this regard, reference is made to the above description of the medical device.
[0036] The above methods may be realized, for example, as a computer program comprising instructions which, when executed, cause a processing unit (processor) (executed by the cardiac pacemaker, and in particular by its processor) to perform each step of the above methods, where the instructions are either a combination of computer instructions and data definitions as described above and below that enable computer hardware to perform computational or control functions, or syntactic units consisting of declarations or statements or instructions necessary to solve a function, task or problem as described above and below that conform to the rules of a particular programming language.
[0037] Further disclosed is a computer program product comprising instructions which, when executed by a processor, cause the processor to perform the steps of the method defined above. Accordingly, disclosed is a computer readable data carrier having stored thereon such a computer program product.
[0038] The above-mentioned medical devices, operating methods, systems, computer programs and computer program products maximize patient safety under worst-case reset behavior in a multi-device system. Moreover, in a particular switchover situation where an "old" medical device is set to a disabled state and a "new" medical device is set to a therapeutic state, the above-mentioned solutions provide a system and method for preventing the "old" device from delivering a therapeutic output under worst-case reset. Providing such an output by the "old" device may result in the "new" device being blocked while at the same time failing to capture the patient's state. Thus, the above-mentioned subject matter helps to avoid the possibility of leaving a patient without therapeutic support in a worst-case reset configuration where removal of an expired medical device is not clinically possible. In the particular situation of a possible future system where a group of medical devices coordinate their respective behaviors to deliver a resulting therapy, the above-mentioned subject matter provides a means to ensure safe device-patient interaction (i.e., ensure safe and consistent output delivery under worst-case reset as nominally employed in conventional products) without violating the above-mentioned fundamental behavior and safety requirements. When a therapeutic output is expected from a medical device and the same device is monitoring for a worst-case reset, the output provided by the device finds a balance between putting a grotesque strain on the limited power support available in small medical devices and providing the expected capture response to enable therapeutic support that is viable until the next follow-up.
[0039] The invention will now be described in more detail with reference to the accompanying schematic drawings. [Brief description of the drawings]
[0040] [Figure 1] FIG. 2 illustrates a first embodiment of two ILPs in a cross-section of a patient's heart. [Diagram 2] FIG. 2 is a block diagram showing the functions of one ILP shown in FIG. 1. [Diagram 3]FIG. 2 is an enlarged side view of one ILP shown in FIG. 1. [Figure 4] 2 is a flow chart illustrating a first embodiment of a method of operation of one ILP shown in FIG. 1 . [Diagram 5] 2 is a flow chart illustrating a second embodiment of a method of operation of one ILP shown in FIG. 1 .
[0041] The invention will be described below in the context of a system including a programmer as an external computing device and two ILPs as implantable medical devices, although systems including other implantable medical devices or a different number of medical devices or other external computing devices are equally feasible.
[0042] FIGURE 1 illustrates an exemplary first ventricular leadless pacemaker (ILP) 10 and an exemplary second ILP 11 implanted in a heart 20 of a patient 30. The exemplary first ILP 10 is shown in an expanded view in FIGURE 3. The second ILP 11 has a similar configuration and operates similarly to the first ILP 10.
[0043] The first ILP 10 has a distal end 10a and a proximal end 10b, and may be configured to be implanted within the right ventricle 21 of the heart 20 to pace the ventricle, sense intrinsic ventricular depolarizations and possibly intrinsic atrial (e.g., right atrium 22) depolarizations, and inhibit ventricular pacing in response to detected intrinsic ventricular signals in VDD and VVI based variations. A programmer 40 is used to program the ILPs 10, 11 and retrieve data from the ILPs 10, 11 using wireless communication such as WLAN.
[0044] In Fig. 2, a functional block diagram of the circuit 101 of the ILP 10 configured to be implanted in the ventricle 21 (Fig. 1) is shown. The circuit 101 of the ILP 10 includes a clocked processor 120, a counter for clock signals, a memory unit 122, a pacing signal generator 124, a detector unit 126, a communication unit 128 for communicating with the programmer 40, and a power source 132. The power source 132 can be electrically connected to one or more of the other components 120, 122, 124, 126, 128 (not shown in Fig. 2) and can include a battery, for example a rechargeable battery or a non-rechargeable battery. The power source is electrically connected to all units and components of the ILP 10 to provide electrical energy to these units and components, in particular all units mentioned above. The units included in the ILP 10 referred to here represent corresponding functions. Similar or identical units and functions may also be included in the ILP 10. The units of the pacemaker of the present disclosure may include any discrete and / or integrated electronic circuit components implementing analog and / or digital circuits capable of providing the functions attributed to the units herein. For example, the units may include analog circuits, such as amplification circuits, filtering circuits, and / or other signal conditioning circuits. The units may include digital circuits, such as combinational or sequential logic circuits, memory devices, and the like. The units may further be realized using integrated dedicated hardware logic circuits. The memory unit 122 may include any volatile, non-volatile, magnetic, or electrical media described above. Additionally, the processor 120 may include instructions that, when executed by one or more processing circuits, cause each unit to perform the various functions attributed to those units herein. The functions attributed to the units or components herein may be embodied as one or more processors, hardware, firmware, software, or any combination thereof.The depiction of various features as units or components is intended to highlight different functional aspects and does not necessarily imply that such units must be realized by separate hardware or software components. Rather, functionality associated with one or more units or components may be performed by separate hardware or software components or may be incorporated within a common or separate hardware or software component. Memory unit 122 can store computer-readable instructions that, when executed by processor 120, cause processor 120 to perform various functions ascribed to processor 120 herein. Additionally, memory unit 122 can store parameters for these functions, such as pacing signal parameters, conditions, and thresholds described above and below. Pacing instructions and pacing signal parameters, conditions, and thresholds can be updated by a programmer using communication unit 128. Communication unit 128 can include an antenna or a transceiver.
[0045] The processor 120 is in communication with, and can transmit signals to, the pacing signal generator 124 and the detector 126. The pacing signal generator 124 and the detector 126 are electrically coupled to the electrodes 111, 112 of the ILP 10. The detector 126 is configured to monitor signals from the electrodes 111, 112 to detect electrical activity of the heart 20. Additionally, the detector 126 can include a motion sensor, such as an accelerometer or any other motion sensor described above. The motion sensor collects a time-dependent motion signal as described above and communicates the signal to the processor 120. The pacing signal generator 124 is configured to deliver electrical stimulation signals to the ventricle 21 via the electrodes 111, 112. The processor 120 can control the pacing signal generator 124 to generate and deliver electrical stimulation to the ventricle 21 via the electrodes 111, 112. The electrical stimulation can include pacing pulses.
[0046] The electrode 112 is placed where there is a mechanical hitch, which means that in a preferred or practical constructed embodiment, the electrode 112 is not easily placed at the most proximal end (as shown in FIG. 3). A better approach is to place the ring electrode closer to the proximal end, and not at the absolute extreme end of the device.
[0047] The processor 120 can control the pacing signal generator 124 to deliver the electrical stimulation therapy according to one or more therapy programs including pacing parameters that can be stored in a memory unit 122 .
[0048] The detector 126 may further include circuitry for acquiring time-dependent electrical signals from the heart, including intrinsic cardiac electrical activity (e.g., electrical depolarization and repolarization signals). The detector 126 may filter, amplify and digitize or otherwise preprocess the acquired electrical signals of heart chamber contractions. The processor 120 may receive the intrinsic electrical signals generated by the detector 126 and recognize intrinsic atrial and ventricular signals of the patient's heart.
[0049] The processor 120 can evaluate the intrinsic atrial and intrinsic ventricular signals received from the detector 126 and is configured to determine the intrinsic interval or intrinsic AV interval (the interval between an intrinsic atrial signal and a subsequent ventricular signal) of two successive ventricular signals (at least one of which is intrinsic).
[0050] The ILP 10 may include a housing 105, a fixation tine 107, and electrodes 111, 112. The housing 105 may have a pill-like cylindrical form factor in some examples. The fixation tine 107 is configured to connect (e.g., anchor) the ILP 10 to the heart 20. The fixation tine 107 may be made of a shape memory material, such as Nitinol. In some examples, the fixation tine 107 may connect the ILP 10 within one of the chambers of the heart 20. For example, as shown and described herein with respect to FIG. 1, the fixation tine may be configured to anchor the ILP 10 within the right ventricle 21 of the heart 20. Although the ILP 10 includes a plurality of fixation tines 107 configured to anchor the ILP 10 to cardiac tissue within the right ventricle, it is contemplated that a pacemaker according to the present disclosure may be fixed to cardiac tissue of the other chamber of the patient's heart 20 using other types of fixation mechanisms.
[0051] The ILP 10 may include two electrodes 111, 112, although in other embodiments, three or more electrodes may be included in the pacemaker. The electrodes 111, 112 may be spaced apart by a sufficient distance to detect various electrical signals generated by the heart 20, such as P waves generated by the atria and QRS waves generated by the ventricles. For example, a first electrode 111 is located at a distal end 10a of the ILP 10 and a second electrode 112 is located at a proximal end 10b of the ILP 10. The housing 105 contains the electronic components (circuitry 101) of the ILP 10. The electronic components may include any discrete and / or integrated electronic circuit components implementing analog and / or digital circuits capable of forming the functions attributed to the ILP 10 described above and below.
[0052] A communication unit 128 of the circuitry 101 may enable the ILP 10 to communicate with other electronic devices, such as a programmer 40 or other external patient monitor. In some examples, the housing 105 may house an antenna or transceiver for wireless communication. The housing may also include a power source 132.
[0053] The processor 120 can be adapted to control the pacing of the right ventricle 21 in VDD mode based on an intrinsic atrial signal including atrial contractions and an intrinsic ventricular signal indicative of ventricular contractions. Alternatively, an assist or alternate mode can be used by the processor 120 if the VDD mode proves inappropriate for an individual patient in the current situation or is associated with a particular device variant.
[0054] The memory unit 122 includes a ROM subunit 122a, a second subunit 122b including a RAM, and a state element 122c. The state element 122c can adopt two states, namely "0" and "1". Parameters for the determination and application of appropriate pacing signals by the processor 120 are stored in the ROM subunit 122a and the second subunit 122b, e.g., a RAM. The second subunit 122b, particularly the RAM, includes predefined security memory subsections, e.g., registers specially designed to minimize the possibility of bit flip transitions (DICE registers) or RAM locations with associated redundancy.
[0055] Processor 120 provides synchronization and timing for ventricular pacing and inhibition based on clinical programming and intrinsic cardiac sensed timing (e.g., electrical signals sensed from the heart) provided by detector 126. In addition, detector 126 can provide a detected time-dependent motion signal that can be sent to processor 120.
[0056] To control the ILPs 10, 11, the programmer 40 can use an interface within the programmer's environment to instruct the HCP to designate a particular target ILP 10, 11 as either essential for administering therapy or as one that should be disabled and therefore have its stimulation output rejected. Each ILP 10, 11 is addressed using a unique identifier that is assigned to the ILP 10, 11 prior to implantation. In the context of a change condition, such an indication amounts simply to indicating which ILP is the "old" ILP (e.g., ILP 10) and which is the "new" replacement ILP (e.g., ILP 11). In the present case, the "old" ILP 10 is transitioned to an inactive state when the "old" ILP 10 is not expected to deliver therapy at a later time and the "new" ILP is designated as intended to deliver future pacing. Alternatively, in the context of coordinated therapy between clusters of ILPs 10, 11, all of the involved ILPs are expected to provide therapy, and therefore the HCP-accessible interface designates all of the ILPs as those that will continue to administer output even under worst-case reset, when only corrective measures can be achieved (e.g., by using downgraded mode support conditions or support suggestions at reduced functionality). Furthermore, the programmer interface allows the HCP to set or change the state of the status element 122c. The communication unit 128 receives this information and any other parameters provided by the programmer 40 and transmits these data to the processing unit 120. The processing unit 120 manages the storage of these data in the respective units or areas of the memory 122.
[0057] When one of the ILPs 10, 11, for example ILP 10, switches from a normal operating state to a worst-case reset condition (i.e., a state in which the implant's RAM application cannot be started, typically represented in box 140 of FIG. 4 or FIG. 5), ILP 10 transitions to a nominal ROM-oriented operating state (box 142). Two embodiments of such operation are described below in conjunction with the flow charts shown in FIG. 4 and FIG. 5.
[0058] In a first embodiment shown in Fig. 4, a worst-case reset or ROM-oriented behavior is initiated (step 142), where the processor 120 queries the current state from the state element 122c (step 144). Based on the received current state of the state element 122c, the processor 120 executes one of two action paths (boxes 148, 149) (represented by box 146). In the first action path (branch starting from box 148 in Fig. 4), the ROM is designed to evaluate as a factor related to its activation at least one parameter (e.g., pacing rate) from the ROM 122a (see step 150) and at least one parameter stored in an off-ROM memory location of the second sub-unit 122b, which includes a predefined security memory sub-section and defines aspects of the resulting ROM-oriented behavior (e.g., pulse width and pulse amplitude parameters) obtained using the contents found in the security memory sub-section. The respective therapy is determined by the processor 120 and sent to the pacing generator 124 for delivery (step 154), where the amplitude and pulse width settings are tantamount to setting values that are expected to aid capture while at the same time avoiding any tendency to overtax the limited on-board power resources. This approach requires a degree of confidence that the ROM can assign to the robustness and reliability of the memory contents referenced in determining the device's behavior. If the processor 120 identifies the state of the status element 122c as "1", then this type of ROM-oriented behavior (i.e., the branch starting from box 148) is provided.
[0059] If processor 120 derives a current state value of "0" from state element 122c, then no therapy from ILP10 is delivered (see the branch beginning at box 149 in FIG. 4). As discussed above, for example, the "old" ILP10 is shut off because the "new" ILP11 now provides pacing of the patient's heart in the same way as ILP10.
[0060] Alternatively, as shown in FIG. 5, a "one size fits all" ROM configuration may be employed as a worst case reset after the ROM-oriented behavior is initiated in step 142. In this embodiment, it is assumed that the therapy determination and delivery by the processor 120 (see step 156) is always the correct and safe behavior for a worst case reset condition that also uses pulse width and amplitude parameters derived from other than the ROM security enhanced memory location (see step 158). In addition, there is a hardware enable switch condition downstream of the ROM setting and resulting therapy decision to determine whether or not such settings ultimately led to the delivery of therapy to the patient. The condition is provided to the status element 122c by a query for a current state (step 160), where the current state of the status element is either "0" or "1". If the current state of the status element 122c is the value "1", the determined therapy signal is sent to the pacing generator 124 and applied to the patient (step 164). However, if the processor 120 derives a value "0" from the status element 122c as the current status, the determined pacing signal is not sent to the pacing generator and therefore is not applied, thereby preventing pacing of the patient (step 162).
[0061] Boxes 146 and 160 in Figures 4 and 5 further indicate that the state of the state element 122c can be set or changed before implantation or during follow-up by the programmer 40. The programmer 40 can provide a respective interface to the HCP, and as indicated above, the values stored in the state element 122c can be, for example, "0" and "1", thereby representing two different states. As indicated by box 165 and lock 166 in Figure 5, the dedicated programmer 40 can unlock the state element 122c for write access to enhance the security of the operation of the ILPs 10, 11.
[0062] For the two embodiments shown in Figures 4 and 5, the ROM design can be structured in a manner that requires little or no evaluation or reference of content residing in out-of-ROM memory locations, such that the resulting behavior of the implant is ultimately mediated largely (if not entirely) by the conditions of independent hardware enable switches. Variations of this approach can be implemented, both with the option to completely ignore any settings in out-of-ROM memory locations, and with variations that simply access only the less frequently accessed locations (e.g., for the purpose of setting only pulse duration and amplitude).
[0063] The above embodiment ensures that in a worst-case reset behavior, which corresponds to a situation where an active implantable medical device loses its capabilities, one implantable medical device among many active medical devices, e.g., ILP 10, 11, operates at its nominal intent by having a ROM governing the device's operation. Furthermore, means are provided to ensure that such "option of last resort" behavior (whether governed by ROM or partially governed by other means) recognizes the HCP's intent as defined at last follow-up and continues to hold the particular device in a therapeutic or non-therapeutic state.
Claims
1. An implantable medical device (10, 11), such as an implantable leadless pacemaker, includes a processor (120), a therapeutic signal generator (124), such as a pacing signal generator, and a communication unit (128) and a memory unit (122), The memory unit is configured to exchange data with the processor and includes a ROM subunit (122a), a second memory subunit (122b), and a state element (122c), wherein the state element is configured to be set to one of a first state and at least one second state, and the second memory subunit includes RAM. The communication unit is configured to receive information including state input information from an external computing device (40) and to transmit at least one piece of data corresponding to the information to the processor. The processor is configured to set the state of the state element based on received data corresponding to state input information, and the processor is further configured to determine a treatment output and control the transmission of the treatment output to the treatment signal generator based on data stored in the ROM subunit and the current state of the state element when it identifies that at least one predetermined RAM application has been corrupted in an irreparable manner. Medical devices (10, 11).
2. The processor (120) is configured to prevent the determination of the treatment output when the first state is the current state of the state element (149), and to determine the treatment output based on the data stored in the ROM subunit when one of the second states is the current state of the state element, and to transmit the determined treatment output to the treatment signal generator (124) (154). The medical device according to claim 1.
3. The processor (120) is configured to determine the treatment output based on the data stored in the ROM subunits (156, 158). The processor is further configured to prevent the transmission of a determined treatment output to the treatment signal generator (124) when the first state is the current state of the state element (162), and to transmit the determined treatment output to the treatment signal generator (124) when one of the second states is the current state of the state element (164). The medical device according to claim 1.
4. The second memory subunit (122b) further includes a predetermined security memory subsection, The processor is configured to determine the treatment output (154, 164) based on at least one parameter additionally derived from the security memory subsection when one of the second states is the current state of the state element. The medical device according to claim 1.
5. The medical device according to claim 4, wherein at least one parameter derived from the predetermined security memory subsection is pulse width and / or pulse amplitude.
6. It is a system, A system comprising at least one implantable medical device (10, 11) as described in claim 1, and an external computing device (40), such as a programmer, configured to transmit information to the at least one medical device.
7. The system includes at least two medical devices (10, 11), The external computing device (40) is configured to transmit information to a specific one of the at least two medical devices based on a unique identifier assigned to each of the at least two medical devices prior to implantation. The system according to claim 6.
8. A method for operating an implantable medical device (10, 11), including a processor (120), a therapeutic signal generator (124), such as a pacing signal generator, and a communication unit (128) and a memory unit (122), for example, a method for operating an implantable leadless pacemaker, The memory unit is configured to exchange data with the processor and includes a ROM subunit (122a), a second memory subunit (122b), and a state element (122c), wherein the state element is set to one of a first state and at least one second state, and the second memory subunit includes RAM. The communication unit receives information including state input information from an external computing device (40), and transmits at least one piece of data corresponding to the information to the processor. The processor sets the state of the state element based on the received data corresponding to the state input information, and when it identifies that at least one predetermined RAM application has been corrupted in an irreparable manner, it operates the control of determining the treatment output and transmitting the treatment output to the treatment signal generator based on the data stored in the ROM subunit and the current state of the state element. How it works.
9. The processor (120) prevents the determination of a treatment output when the first state is the current state of the state element (149), and when one of the second states is the current state of the state element, it determines a treatment output based on the data stored in the ROM subunit and transmits the determined treatment output to the treatment signal generator (124) (154). The method according to claim 8.
10. The processor (120) determines the treatment output based on the data stored in the ROM subunits (156, 158), If the first state is the current state of the state element, the transmission of the determined treatment output to the treatment signal generator (124) is blocked (162), and if one of the second states is the current state of the state element, the determined treatment output is transmitted to the treatment signal generator (124) (164). The method according to claim 8.
11. The second memory subunit (122b) further includes a predetermined security memory subsection, The processor determines the treatment output (154, 164) based on at least one parameter additionally derived from the security memory subsection when one of the second states is the current state of the state element. The method according to claim 8.
12. The method according to claim 11, wherein at least one parameter derived from the predetermined security memory subsection is pulse width and / or pulse amplitude.
13. A computer program product that, when executed by a processor (120), includes instructions causing the processor to perform a step of the method according to any one of claims 8 to 12.
14. A computer-readable data carrier storing the computer program product described in claim 13.