Medical device configuration analyzer

The medical device unauthorized change detection system addresses the issue of unauthorized changes by monitoring attribute states and generating alerts, effectively preventing unsafe configurations and maintaining device integrity.

WO2025114150A1PCT designated stage expired Publication Date: 2025-06-05KONINKLIJKE PHILIPS NV
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/083232
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-27
Filing Date
2024-11-22
Publication Date
2025-06-05

AI Technical Summary

Technical Problem

Unauthorized changes to medical devices can compromise patient safety, medical efficacy, and the device's lifecycle, while also affecting the OEM's reputation and financial standing.

Method used

A medical device unauthorized change detection system that uses a database to store attributes for components, with annotations on whether they can be changed by human intervention. The system monitors attribute states, generates alerts for unauthorized changes, and performs remedial actions.

Benefits of technology

Effectively distinguishes between authorized and unauthorized updates, detects configuration changes, and prevents operation of unauthorized modifications, thereby ensuring patient safety and maintaining device integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024083232_05062025_PF_FP_ABST
    Figure EP2024083232_05062025_PF_FP_ABST
Patent Text Reader

Abstract

A medical device unauthorized change detection system (10) includes a database (30) storing attributes (32) for components for a plurality of medical devices (12), with the attributes annotated as to whether the attributes are capable of being changed by human intervention. At least one electronic processor (20) is programmed to monitor states of the attributes for the components of the medical devices; generate an alert (34, 38) indicative of an unauthorized change to at least one component of one of the medical devices when at least one of the attributes for the at least one component (i) fails an acceptance criterion and (ii) is annotated as capable of being changed by human intervention; and perform one or more remedial actions in response to the generated alert.
Need to check novelty before this filing date? Find Prior Art

Description

MEDICAL DEVICE CONFIGURATION ANALYZER FIELD

[0001] The following relates generally to the medical device maintenance arts, medicalimaging device maintenance arts, medical device configuration arts, imaging device arts, andrelated arts. BACKGROUND

[0002] During the life cycle of a medical device, changes may be made to the device overtime. Some changes are of types that are authorized by the original equipment manufacturer (OEM), such as replacement of worn or failed parts with a replacement part that meets the original bill of materials (BOM) of the medical device, software upgrades provided by the OEM or otherwise approved by the OEM for use with the medical device, addition of approved add-on components, and so forth. Authorized changes can also include adjusting the configuration of the medical device within OEM-approved operational ranges. Another example of an authorized change can be a relocation of the medical device to another location that satisfies the device placement specification provided by the OEM.

[0003] However, some changes to a medical device may be problematic. These changescan be considered to be unauthorized changes, that is, changes that are not authorized by the original equipment manufacturer. Some examples of unauthorized changes can include replacing a worn or failed part with a replacement part that does not meet the BOM, installing unapproved software or unapproved software upgrades, modifying the device configuration in a manner thattakes the device outside of an OEM-approved operating range, or relocating the device to alocation that does not satisfy the placement specification provided by the OEM (for example, the medical device may be placed too close to a wall, or too close to another medical device, or may be placed in an insufficiently ventilated room). These types of unauthorized changes can have an undesirable impact on patient safety and / or medical efficacy of usage of the medical device, and / or can have a detrimental effect on the life cycle of the medical device or components thereof (e.g., configuring an X-ray tube to operate at a higher current leading to accelerated X-ray tube degradation). Such adverse effects of unauthorized changes can also negatively impact the OEM reputationally and / or financially (in spite of the OEM not authorizing the changes).2023PF00387 2

[0004] The following discloses certain improvements to overcome these problems andothers. SUMMARY

[0005] In one aspect, a medical device unauthorized change detection system includes adatabase storing attributes for components for a plurality of medical devices, with the attributes annotated as to whether the attributes are capable of being changed by human intervention. At least one electronic processor is programmed to monitor states of the attributes for the components of the medical devices; generate an alert indicative of an unauthorized change to at least one component of one of the medical devices when at least one of the attributes for the at least one component (i) fails an acceptance criterion and (ii) is annotated as capable of being changed by human intervention; and perform one or more remedial actions in response to the generated alert.

[0006] In another aspect, a non-transitory computer readable medium stores instructionsexecutable by at least one electronic processor to perform a medical device unauthorized changedetection method including monitoring states of the attributes for the components for a pluralityof medical devices, with the attributes annotated as to whether the attributes are capable of beingchanged by human intervention; generating an alert indicative of an unauthorized change to atleast one component of one of the medical devices when at least one of the attributes for the at least one component (i) fails an acceptance criterion and (ii) is annotated as capable of being changed by human intervention; removing the generated alert when the generated alert is determined to be indicative of an authorized change to the at least one component of the medical device using at least one model; and performing one or more remedial actions in response to the generated alert.

[0007] In another aspect, a medical device unauthorized change detection method includesmonitoring states of the attributes for the components for a plurality of medical devices, with the attributes annotated as to whether the attributes are capable of being changed by human intervention; generating an alert indicative of an unauthorized change to at least one component of one of the medical devices when at least one of the attributes for the at least one component (i) fails an acceptance criterion and (ii) is annotated as capable of being changed by human intervention, wherein the generated alert corresponds to an unauthorized hardware modification of the at least one component; preventing operation of the at least one component of the medical2023PF00387 3device until the unauthorized hardware modification is resolved; receiving an input via at least one user input device from an authorized user, the input being indicative of overriding the prevention of the operation of the at least one component or the medical device; and resuming operation of the at least one component in response to the received input.

[0008] One advantage resides in distinguishing between authorized and unauthorizedupdates to a medical device.

[0009] Another advantage resides in detecting configuration changes in a medical deviceand classifying the changes as either authorized or unauthorized.

[0010] Another advantage resides in implementing both a static analyzer and a dynamicanalyzer to determine changes in configurations for a medical device by improving a quality ofconfiguration changes detection using both the static analyzer and the dynamic analyzer.

[0011] Another advantage resides in using a maintenance schedule and / or a set ofauthorized users to distinguish between authorized and unauthorized updates to a medical device.

[0012] A given embodiment may provide none, one, two, more, or all of the foregoingadvantages, and / or may provide other advantages as will become apparent to one of ordinary skill in the art upon reading and understanding the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] The disclosure may take form in various components and arrangements ofcomponents, and in various steps and arrangements of steps. The drawings are only for purposes of illustrating the preferred embodiments and are not to be construed as limiting the disclosure.

[0014] FIGURE 1 diagrammatically illustrates a medical device configuration analysisapparatus in accordance with the present disclosure.

[0015] FIGURE 2 diagrammatically illustrates an embodiment of a medical deviceconfiguration analysis method using the apparatus of FIGURE 1.DETAILED DESCRIPTION

[0016] The following discloses an analysis system for detecting problematic (i.e.,unauthorized) changes. The disclosed analysis system in some illustrative embodiments includes a static analyzer and a dynamic analyzer. The static analyzer looks at the present state of the device, monitoring the attributes of components of the medical device. A suspicious alert is generated if an attribute is both (1) out of range, and (2) can be changed by intervention of a2023PF00387 4human. (If the attribute cannot be changed by intervention of a human, then it cannot constitutean unauthorized change to the medical device, but rather indicates a different problem such as adevice malfunction or performance degradation over time). Whether an attribute is out-of-rangeis determined in the illustrative embodiments using a medical device health model, which can be constructed as a set of rules, an artificial intelligence (AI) component trained on annotated historical machine log data and / or change logs, or some combination thereof. The inputs for analysis of the current state of the medical device can be obtained from machine logs, using API calls to retrieve current device configuration values, extracted from manually and / or automatically maintained change logs, and / or so forth. Machine logs are typically generated for use indiagnosing problems with the medical device, and as disclosed herein are repurposed for detectingchanges and determining whether such changes are authorized or unauthorized.

[0017] The dynamic analyzer tracks changes in the attributes of the medical device. In thedisclosure, attribute changes over fixed time increments are determined. As with the static analyzer, a suspicious alert is generated if an attribute changes in a way that is out-of-range (as suitably defined using rules, trained AI, or some combination thereof) and if that attribute can be changed by intervention of a human.

[0018] These analyzers may be constructed to detect problems that are not directlyidentifiable by the corresponding attributes. For example, if a temperature sensor indicates a temperature rise of a component during use that is faster than acceptable, this could be used to infer the medical device is improperly placed (too close to a wall or in a poorly ventilated room so that it is not adequately air-cooled, for example).

[0019] The static and dynamic models output suspicious alerts. These are optionallyfurther filtered by an OEM service model and / or an OEM authorization model. The OEM servicemodel provides information on the expected servicing of the medical device. A suspicious alertthat matches servicing expected according to the OEM service model may be filtered out as itlikely corresponds to OEM-approved servicing. The OEM authorization model in someembodiments identifies personnel that are authorized to perform servicing, and changes to themedical device may be labeled (for example, in a service log) with identification of the personwho performed or approved the respective changes. As an example of use of this model, a suspicious alert may be filtered out if an appropriate change was performed by a qualified serviceengineer, whereas the suspicious alert is retained if it was performed by an unauthorized person.2023PF00387 5Other types of filtering could be applied, such as geographical filtering (e.g., a.c. operation at 50 Hz is standard in Europe while 60 Hz is standard in the United States, so a geographical model would filter out any suspicious events relating to a.c. frequency that are permissible in the geographical region where the medical device is located).

[0020] In some embodiments, pre-processing can be implemented to reduce the amount ofdata being analyzed. A medical device may experience a very high number of changes, but mostof these changes are the result of normal operation of the medical device. Hence, pre-processing can remove these normal changes and retain and input only significant changes to the static and dynamic analyzers, thus improving computational efficiency of the analysis system. In one type of pre-processing, autocorrelation is applied to the attributes data stream generated by the medical device to detect significant changes. In another approach, the attributes data stream generated by the medical device is compared against a reference device data stream in a cross-correlationapproach to detect significant changes. In yet another approach, the comparison is against a cohortof comparable devices of a fleet of medical devices.

[0021] The output of the analysis system are suspicious alerts that are indicative ofsuspected unauthorized changes to the medical device. These suspected unauthorized changealerts can be variously utilized. In one use case, the suspected unauthorized change alerts are sentto the customer (e.g., hospital administrator). Notification to the customer of a suspected unauthorized change can enable the customer to take remedial action if it determines it should not have made the change. Notification to the customer of a suspected unauthorized change can also serve as due diligence that the OEM has taken reasonable action to ensure the product is used inconformance with OEM authorized operation. In another use case, the suspected unauthorizedchange alerts are sent to a remote service engineer (RSE) or other agent of the OEM. Notification to the RSE can enable the RSE to contact the customer to further investigate the suspicious alert.In yet another use case, the suspected unauthorized change alerts may be stored at a database ofthe OEM for consideration if the customer raises concerns about malfunctioning of the medical device. In these use cases, the suspected unauthorized change alerts are essentially informational in nature, and are not mutually exclusive (e.g., notification of a suspected unauthorized change can be sent to both the customer and the RSE and may also be stored in the OEM database).

[0022] In other use cases, the suspected unauthorized change alerts may be utilized in moreactive roles, e.g., serving as an automatic safety interlock or rollback feature of the medical device2023PF00387 6that prevents (or at least limits) usage of the medical device with the suspected unauthorized change. For example, a suspected unauthorized change alert of an unauthorized software modification could trigger an automatic rollback of that software modification. As another example, a suspected unauthorized change alert relating to a suspected unauthorized hardware modification of a component of the medical device could trigger the user interface (UI) of the medical device to display the suspected unauthorized change alert every time the medical device is operated in a manner that uses that component. In a more aggressive intervention, the suspected unauthorized change alert relating to a hardware component could prevent the suspect component from being used during operation of the medical device, or even prevent the medical device from being used at all. In these more aggressive interventions, a suitably authorized person (e.g., a biomed of the customer / hospital or a service engineer of the OEM) could in some implementations override the intervention, thus ensuring it is reviewed by an authorized person.

[0023] The disclosed analysis system could be implemented at a server controlled by theOEM or could be implemented at a customer server (e.g., hospital IT server). In either case, the analysis system would use rules and / or AI developed by the OEM. The OEM or customer server suitably receives periodic uploads of machine log data generated by the medical device on which the unauthorized change analysis is performed.

[0024] With reference to FIGURE 1, an illustrative medical device configuration analysissystem or apparatus 10 for monitoring a configuration of a medical device 12 is shown. Themedical device 12, for example, can comprise an illustrative medical imaging device 12 (alsoreferred to as a medical device, an imaging device, imaging scanner, and variants thereof) which can be a magnetic resonance imaging (MRI) scanner, a computed tomography (CT) scanner, a positron emission tomography (PET) scanner, a gamma camera for performing single-photon emission computed tomography (SPECT), an interventional radiology (IR) device, an X-ray device, an image-guided therapy (IGT) device, an ultrasound (US) device, or so forth. Althoughdescribed herein as an imaging device, the medical device 12 can also be any other suitablemedical device that is used with patients to perform medical functions such as diagnosis and / ortreatment, such as a patient monitor, a radiation therapy device, a mechanical ventilator, and soforth. Although only one medical device 12 is shown in FIGURE 1, the system 10 can beconfigured to monitor a plurality of medical devices 12 (i.e., a fleet of medical devices 12).2023PF00387 7

[0025] An electronic processing device 18, such as a workstation computer, or moregenerally a computer, a smart device (e.g., a cellular telephone (“cell phone”), a smart tablet, andso forth), is operable by a service engineer (SE). The electronic processing device 18 may alsoinclude a server computer or a plurality of server computers, e.g., interconnected to form a server cluster, cloud computing resource, or so forth, to perform more complex computational tasks. Theelectronic processing device 18 includes typical components, such as an electronic processor 20(e.g., a microprocessor), at least one user input device (e.g., a mouse, a keyboard, a trackball,and / or the like) 22, and a display device 24 (e.g., an LCD display, plasma display, cathode raytube display, and / or so forth). In some embodiments, the display device 24 can be a separatecomponent from the electronic processing device 18 or may include two or more display devices.

[0026] The electronic processor 20 is operatively connected with one or more non-transitory storage media 26. The non-transitory storage media 26 may, by way of nonlimitingillustrative example, include one or more of a magnetic disk, RAID, or other magnetic storage medium; a solid-state drive, flash drive, electronically erasable read-only memory (EEROM) orother electronic memory; an optical disk or other optical storage; various combinations thereof; orso forth; and may be, for example, a network storage, an internal hard drive of the workstation 18,various combinations thereof, or so forth. It is to be understood that any reference to a non-transitory medium or media 26 herein is to be broadly construed as encompassing a single mediumor multiple media of the same or different types. Likewise, the electronic processor 20 may beembodied as a single electronic processor or as two or more electronic processors. The non-transitory storage media 26 stores instructions executable by the at least one electronic processor20. The instructions include instructions to generate a visualization of a graphical user interface (GUI) 28 for display on the display device 24.

[0027] The electronic processing device 18 is also in communication with a database 30(shown in FIGURE 1 as a server computer) that stores attributes 32 for components for a pluralityof medical devices 12, with the attributes annotated as to whether the attributes are capable of being changed by human intervention. The attributes 32 can comprise, for example, numerical values representing an acceptable range for each component of the medical devices 12.

[0028] The apparatus 10 is configured as described above to perform a medical deviceunauthorized change detection method or process 100. The non-transitory storage medium 26stores instructions which are readable and executable by the at least one electronic processor 20 to2023PF00387 8perform disclosed operations including performing the maintenance assessment method or process 100. In some examples, the method 100 may be performed at least in part by cloud processing.In other examples, the server computer 30 can include at least one electronic processorprogrammed to perform the method 100.

[0029] With reference to FIGURE 2, and with continuing reference to FIGURE 1, anillustrative embodiment of an instance of the method 100 is diagrammatically shown as aflowchart. At an operation 102, states of the attributes 32 for the components of the medicaldevices 12 are monitored.

[0030] At an optional operation 103, significant changes in the values of at least one of theattributes 32 for the at least one component are detected, and monitored states that do notcorrespond to significant changes are removed from a set of attributes 32 for further analysis.

[0031] At operation 104, an alert 34, 36 is generated. The alert 34, 36 is indicative of a(possible) unauthorized change to at least one component of one of the medical devices 12 whenat least one of the attributes 32 for the at least one component (i) fails an acceptance criterion and(ii) is annotated as capable of being changed by human intervention.

[0032] The monitoring operation 102 and the alert generation operation 104 can beperformed in a variety of manners. In a first embodiment, the monitoring operation 102 includesmonitoring the states of the attributes 32 for the components of the medical devices 12 includinga static state of at least one of the attributes 32 for at least one component of the medical devices12. The alert generation operation 104 includes a static alert 34 for the at least one componentwhen at least one of the attributes 32 for the at least one component (i) has its static state outsideof a predetermined value range for the static state of that attribute 32, and (ii) is annotated ascapable of being changed by human intervention. To do so, a static analyzer module 36 comprisesan artificial intelligence (AI) component (e.g., a neural network (NN), a decision tree, and so forth)trained on annotated historical machine log data (or change logs) 42 from the plurality of medicaldevices 12. The static analyzer module 36 is configured to monitor the static state(s) of theattributes 32 and generate the static alert(s) 34.

[0033] In a second embodiment (which can be implemented in addition to, or in lieu of,the first embodiment), the monitoring operation 102 includes monitoring the states of the attributes32 for the components of the medical devices 12 including a dynamic state of at least one of theattributes 32 for at least one component of the medical devices 12 determined by tracking changes2023PF00387 9in values of at least one of the attributes 32 for at least one component. The alert generationoperation 104 includes a dynamic alert 38 for the at least one component when at least one of theattributes 32 for the at least one component (i) has its dynamic state outside of a predetermined value range for the static state of that attribute 32, and (ii) is annotated as capable of being changed by human intervention. To do so, a dynamic analyzer module 40 comprises an AI component (e.g., a NN, a decision tree, and so forth) trained on the annotated historical machine log data (orchange logs) 42 from the plurality of medical devices 12. The dynamic analyzer module 40 isconfigured to monitor the static state(s) of the attributes 32 and generate the dynamic alert(s) 38.

[0034] At an operation 106, the generated alert(s) 34, 38 are removed from a list of thegenerated alerts when the generated alert is determined to be indicative of an authorized change tothe at least one component of the medical device 12 using at least one model. In someembodiments, the at least one model includes a service model 44 of an expected servicing sessionfor the at least one component of the medical device 12. The service model 44 is configured toremove one or more of the generated alerts 34, 38 when the service model 44 of the expectedservicing session indicates the generated alert 34, 38 corresponds to a change to the at least one component that is authorized by the service model 44.

[0035] In some examples, another model of the system 10 includes an authorization model46 identifying personnel authorized to perform a servicing session for the at least one component.The authorization model 46 is configured to remove one or more of the generated alerts 34, 38when the authorization model 46 indicates the generated alert 34, 38 corresponds to a change tothe at least one component that was authorized by an authorized person as indicated by the authorization model 46.

[0036] In some examples, another model of the system 10 includes a geographic model 48indicating authorized changes by geographical region (e.g., a.c. operation at 50 Hz is standard in Europe while 60 Hz is standard in the United States, so a geographical model would filter out any suspicious events relating to a.c. frequency that are permissible in the geographical region wherethe medical device is located). The geographic model 48 is configured to remove one or more ofthe generated alerts 34, 38 when the geographic model 48 indicates the generated alert 34, 38corresponds to a change to the at least one component that is authorized in a geographical region within which the corresponding medical device 12 is located.2023PF00387 10

[0037] After the alert removal operation 106 is performed by one or more of the models44, 46, 48, a list 50 of the remaining generated alerts 34, 38 is created. At an operation 108, oneor more remedial actions in response to the generated alerts 34, 38 in the list 50. In a first example,the remedial action can include displaying the generated alerts 34, 38 in the list 50 on a displaydevice 24. In another example, the remedial action can include transmitting the generated alerts34, 38 in the list 50 to an electronic processing device (not shown – such as a cellphone, laptop,or smart tablet) operable by a remote servicing engineer (RSE) or by a customer of the medicaldevice 12 for which the alerts 34, 38 are generated. In another example, when one or more of thegenerated alerts 34, 38 corresponds to an unauthorized software modification, the remedial actioncan include automatically rolling back the unauthorized software modification. By “rolling back,”the remedial action can include reversing and / or “un-doing” at least some changes to theunauthorized software modification to restore the medical device 12 to a previous state before theunauthorized software modification was implemented in the medical device 12. In another example, when one or more of the generated alerts 34, 38 corresponds to an unauthorized hardware modification of the at least one component, the remedial action includes modifying the GUI 28presented on the display device 24 of the corresponding medical device 12 to display the generatedalert 34, 38 corresponding to the unauthorized hardware modification when the at least one component is operated or attempted to be operated.

[0038] In another example, the generated alert 34, 38 corresponds to an unauthorizedhardware modification of the at least one component. The remedial action then may include, forexample, preventing operation of the at least one component of the medical device 12 until theunauthorized hardware modification is resolved. In addition, an authorized user can provide an input via the at least one user input device 22 that is indicative of overriding the prevention of theoperation of the at least one component or the medical device 12. Operation of the at least onecomponent can be resumed in response to the received input. These are merely illustrative examples and should not be construed as limiting. EXAMPLE

[0039] The following describes the apparatus 10 and the method 100 in more detail. Thedatabase 30 stores a configuration of a medical device with unique identifier UID in time moment2023PF00387 11•• ••••••( , ••) = ••(••) × ••(••) × … × ••(••), where ••(••) is the state of the i-th component of the medical device 12 at the moment •• .

[0040] The database 30 also stores a default set of •• attributes 32 for every component’sstate ••(••) = {••, … ,representing, for voltage in the component, temperature, slot, etc.Each attribute is a pair •• = {•••, •••}, where ••• represent a value of the l-th attribute (e.g., voltage,temperature, degree of natural degradation, position in a slot, etc.) at the moment ••, and ••• = 1if this value can be changed by an intervention of a human and 0 otherwise.

[0041] The static analyzer 36 contains sets of valid values for every attribute ••• in •• anddefines a set of valid configurations of the device. If any of •••inout of range of the corresponding set of valid values, static analyzer outputs a corresponding alert. If for all such••• holds ••• = 0, then the generated static alert 34 is considered as an authorized change.Otherwise, it is considered as potential unauthorized change, and this static alert 34 along withdate of the change comes to service model 44 and the authorization model 46.

[0042] In some examples, for two configurations ••••••( , ••) and••••••( , ••••) of the device in consecutive time moments •• and •••• are analyzedby the dynamic analyzer 40. If •••••••( , •••• • ••) =••) × ••(••) ×there is a difference in any values ••• of any attribute ••, for which holds ••• = 1, the dynamicanalyzer 40 outputs a dynamic alert 38 regardless of an output of the static analyzer 36.

[0043] The service model 44 contains an OEM’s maintenance schedule for the medicaldevice 12. The service model 44 contains maintenance dates for planned maintenance servicetogether with a list of authorized persons who are in charge for the maintenance in the scheduled dates, and reaction time T. The service model 44 is configured to filter suspicious static anddynamic alerts 34, 38. For an alert 34, 38 which was raised within T days after scheduled maintenance service, the service model 44 sends that alert to the authorization model 46. Otherwise, the service model 44 marks this alert as unauthorized.

[0044] The authorization model 46 contains a list of authorized users who are authorizedto make changes in components and / or their attributes. If a change was made to the medical device 12 by a person in the list of authorized users, the authorization model 46 marks the alert 34, 38 asauthorized, and marks the alert 34, 38 as unauthorized otherwise.2023PF00387 12

[0045] If alerts 34, 38 coming from static analyzer 36 and the dynamic analyzer 40 weremade in accordance with service model 44 and the authorization model 46, these alerts 34, 38 areconsidered as authorized, and considered unauthorized otherwise (i.e., if maintenance was not conducted in accordance with a maintenance schedule or was not done by an authorized person).

[0046] In some embodiments, the electronic processing device 18 can implement anautoregressive module configured to detect changes in a sequence of device’s configurationscompared to a lagged subsequence of itself over the time.

[0047] In some embodiments, the electronic processing device 18 can implement aclustering module configured to detect devices in an install base which configurations’ life cyclediffers from vast majority of devices in the install base.

[0048] In some embodiments, there is a sequence of configurations of a medical device 12at timestamps ••, ••, …where •• denotes an installation moment of the device 12 in a hospital:••••••( , ••), … , ••••••( , ••). An autocorrelation module can useautocorrelation (i.e., an autoregressive mode) or any other change detection process to detectchangepoints / pattern changes in the device’s configuration sequence.

[0049] In another example, a sequence of configurations or / and alerts of a given device 12can be compared with the configurations or / and alerts of a reference device of the same type in the same install base (template) by aligning them on a time line (e.g., starting from installation date at hospital).

[0050] In another example, there can be sequences of configurations of medical devices12, where each of the devices belongs to the same install base. An install base changes moduleuses any appropriate clustering method for clustering the configuration sequences. This clusteringmethod can be done over a configuration space directly, or by initial mapping of the configurationspace into alerts’ space followed by clustering of alerts’ time series. Any outlier detection processcan be used afterwards to detect devices whose configuration life cycle differs from the similar devices from the same install base.

[0051] The disclosure has been described with reference to the preferred embodiments.Modifications and alterations may occur to others upon reading and understanding the preceding detailed description. It is intended that the exemplary embodiment be constructed as including all such modifications and alterations insofar as they come within the scope of the appended claims or the equivalents thereof.

Claims

2023PF00387 13CLAIMS:

1. A medical device unauthorized change detection system (10), comprising:a database (30) storing attributes (32) for components for a plurality of medical devices (12), with the attributes annotated as to whether the attributes are capable of being changed by human intervention; and at least one electronic processor (20) programmed to: monitor states of the attributes for the components of the medical devices; generate an alert (34, 38) indicative of an unauthorized change to at least one component of one of the medical devices when at least one of the attributes for the at least one component (i) fails an acceptance criterion and (ii) is annotated as capable of being changed byhuman intervention; andperform one or more remedial actions in response to the generated alert.

2. The system (10) of claim 1, wherein the at least one electronic processor (20) is programmed to: monitor the states of the attributes for the components of the medical devices (12) including a static state of at least one of the attributes for at least one component; generate the alert comprising a static alert (34) for the at least one component when at least one of the attributes for the at least one component (i) has its static state outside of a predetermined value range for the static state of that attribute, and (ii) is annotated as capable ofbeing changed by human intervention.

3. The system (10) of either one of claims 1 and 2, wherein the at least one electronicprocessor (20) is programmed to: monitor the states of the attributes for the components of the medical devices (12) including a dynamic state determined by tracking changes in values of at least one of the attributes for at least one component; generate the alert comprising a dynamic alert (38) for the at least one component2023PF00387 14when at least one of the attributes for the at least one component (i) has its dynamic state outside of a predetermined value range for the dynamic state of that attribute, and (ii) is capable of being changed by human intervention.

4. The system (10) of any one of claims 1-3, wherein the generation of the alert (34, 38) for the at least one component includes: determining whether the at least one of the attributes for the at least one component fails the acceptance criterion using an artificial intelligence (AI) component (36, 40) trained onannotated historical machine log data or change logs from the plurality of medical devices (12).

5. The system (10) of any one of claims 1-4, wherein the at least one electronic processor (20) is further programmed to: remove the generated alert (34, 38) when the generated alert is determined to be indicative of an authorized change to at least one component of the medical device (12) using at least one model (44, 46, 48).

6. The system (10) of claim 5, wherein: the at least one model includes a model of an expected servicing session for the at least one component using a service model (44); and the generated alert (34, 38) is removed when the model of the expected servicing session indicates the generated alert corresponds to a change to the at least one component that is authorized by the service model.

7. The system (10) of either one of claims 5 and 6, wherein: the at least one model includes an authorization model identifying personnel authorized to perform a servicing session for the at least one component using an authorization model (46); and the generated alert (34, 38) is removed when the authorization model indicates the generated alert corresponds to a change to the at least one component that was authorized by an authorized person as indicated by the authorization model.2023PF00387 158. The system (10) of any one of claims 5-7, wherein: the at least one model includes a geographic model (48) indicating authorized changes by geographical region; and the generated alert (34, 38) is removed when the geographic model indicates the generated alert corresponds to a change to the at least one component that is authorized in a geographical region within which the corresponding medical device is located.

9. The system (10) of any one of claims 1-8, wherein the at least one electronic processor (20) is programmed to: detect significant changes in the values of at least one of the attributes (32) for the at least one component; and remove monitored states that do not correspond to significant changes prior to the generation of the alert (34, 38).

10. The system (10) of any one of claims 1-9, wherein the one or more remedial actions performed in response to the generated alert (34, 38) includes: displaying the generated alert on a display device (24).

11. The system (10) of any one of claims 1-9, wherein the one or more remedial actions performed in response to the generated alert (34, 38) includes: transmitting the generated alert to an electronic processing device operable by a remote servicing engineer (RSE) or by a customer of the medical device (12) for which the alerts are generated.

12. The system (10) of any one of claims 1-11, wherein the generated alert (34, 38) corresponds to an unauthorized software modification, and the one or more remedial actions performed in response to the generated alert includes: automatically rolling back the unauthorized software modification.

13. The system (10) of any one of claims 1-12, wherein the generated alert (34, 38)corresponds to an unauthorized hardware modification of the at least one component, and the one2023PF00387 16or more remedial actions performed in response to the generated alert includes: modifying a user interface (UI) (28) presented on a display device (24) of the corresponding medical device (12) to display the generated alert corresponding to the unauthorized hardware modification when the at least one component is operated or attempted to be operated.

14. The system (10) of any one of claims 1-13, wherein the generated alert (34, 38)corresponds to an unauthorized hardware modification of the at least one component, and the oneor more remedial actions performed in response to the generated alert includes: prevent operation of the at least one component of the medical device (12) until the unauthorized hardware modification is resolved.

15. The system (10) of claim 14, wherein the at least one electronic processor (20) is further programmed to: receive an input via at least one user input device (22) from an authorized user, the input being indicative of overriding the prevention of the operation of the at least one component or the medical device (12); and resuming operation of the at least one component in response to the received input.

16. A non-transitory computer readable medium (26) storing instructions executable by at least one electronic processor (20) to perform a medical device unauthorized change detectionmethod (100), the method comprising:monitoring states of the attributes for the components for a plurality of medical devices (12), with the attributes annotated as to whether the attributes are capable of being changed by human intervention; generating an alert (34, 38) indicative of an unauthorized change to at least one component of one of the medical devices when at least one of the attributes for the at least one component (i) fails an acceptance criterion and (ii) is annotated as capable of being changed by human intervention; removing the generated alert when the generated alert is determined to be indicative of an authorized change to the at least one component of the medical device (12) using at least one model (44, 46, 48); and2023PF00387 17performing one or more remedial actions in response to the generated alert.

17. The non-transitory computer readable medium (26) of claim 16, wherein: the at least one model includes a model of an expected servicing session for the at least one component using a service model (44); and the generated alert (34, 38) is removed when the model of the expected servicing session indicates the generated alert corresponds to a change to the at least one component that is authorized by the service model.

18. The non-transitory computer readable medium (26) of either one of claims 16 and 17, wherein: the at least one model includes an authorization model identifying personnel authorized to perform a servicing session for the at least one component using an authorization model (46); and the generated alert (34, 38) is removed when the authorization model indicates the generated alert corresponds to a change to the at least one component that was authorized by an authorized person as indicated by the authorization model.

19. The non-transitory computer readable medium (26) of any one of claims 16-18, wherein: the at least one model includes a geographic model (48) indicating authorized changes by geographical region; and the generated alert (34, 38) is removed when the geographic model indicates the generated alert corresponds to a change to the at least one component that is authorized in a geographical region within which the corresponding medical device is located.

20. A medical device unauthorized change detection method (100), comprising:monitoring states of the attributes for the components for a plurality of medical devices (12), with the attributes annotated as to whether the attributes are capable of being changed by human intervention;2023PF00387 18generating an alert (34, 38) indicative of an unauthorized change to at least one component of one of the medical devices when at least one of the attributes for the at least one component (i) fails an acceptance criterion and (ii) is annotated as capable of being changed by human intervention, wherein the generated alert corresponds to an unauthorized hardware modification of the at least one component; preventing operation of the at least one component of the medical device until the unauthorized hardware modification is resolved; receiving an input via at least one user input device (22) from an authorized user, the input being indicative of overriding the prevention of the operation of the at least one component or the medical device; and resuming operation of the at least one component in response to the received input.

Citation Information

Patent Citations

  • Examination reserve system, maintenance service system, medical imaging apparatus, examination reserve method, and maintenance service method

    EP1331589A2

  • Method of configuring and monitoring system unit in medical diagnostic system and those equipment

    JP2001309891A

  • Systems and methods for maintenance services

    WO2023046576A1