Overview
ISO/TS 20405:2018 - "Health informatics - Framework of event data and reporting definitions for the safety of health software" - defines a consensus-based model to improve surveillance, recording, analysis and reporting of safety-related events involving health software. The technical specification focuses on the data elements, principles and process model needed to describe incidents, near-misses and unsafe conditions where health software contributes to patient safety risk.
Keywords: ISO/TS 20405:2018, health informatics, health software safety, event reporting, patient safety, incident reporting.
Key Topics and Requirements
- Scope and purpose: Provides a model framework for consistent identification and documentation of health software safety events to support learning and mitigation.
- Core definitions: Clarifies terms such as health software, hazard, hazardous event, incident, near‑miss and unsafe condition (drawing on IEC/ISO terminology).
- Principles: Establishes guiding principles including proactivity, objectivity, accountability, transparency, preparedness and comprehensiveness to underpin event surveillance and reporting.
- Data concepts: Emphasizes accuracy, timeliness, comparability, usability and relevance of event data to make surveillance actionable.
- Process model: Recommends organizational processes for recording, analysing and reporting event-specific information about health software safety.
- Patient safety data elements: Specifies the types of data elements to capture-event identification, event date/time, report date, reporter information, and supplementary event details-plus categorization and classification (e.g., input/output errors).
- Annex and examples: Provides information on existing national and organizational reporting systems to illustrate implementation approaches.
Applications and Practical Value
- Standardizes how organizations collect and share safety data about electronic health records, clinical decision support, medical device software and interoperable health IT.
- Enables better surveillance, cross-system comparisons, trend analysis and root-cause investigations.
- Supports regulatory reporting, vendor post-market surveillance, hospital safety programs, and academic research into health software-related harm.
- Helps design or improve incident management workflows, event databases, and reporting templates to meet patient safety goals.
Who Should Use This Standard
- Health IT vendors and software developers
- Healthcare providers, clinical safety officers and risk managers
- Regulatory and health authority surveillance teams
- Quality improvement teams, patient safety researchers and standards implementers
Related Standards
- IEC 82304-1 (health software definition and lifecycle considerations)
- ISO/IEC Guide 51 and ISO Guide 73 (risk and terminology foundations)
- National reporting frameworks referenced in the specification (e.g., AHRQ common formats, NHS NRLS) as implementation examples
Adopting ISO/TS 20405:2018 helps organizations create consistent, comparable event data and reporting processes that improve the safety and reliability of health software in clinical settings.