Rethinking Safety for Autonomous Medical Motion
Verena Schmidt, Martin NolewaikaAbstract
Autonomous medical systems with mechatronic motion, such as mobile X‑ray devices or autonomous medical robots, increasingly rely on perception‑based functions for navigation and collision avoidance. While medical device standards like IEC 60601‑1 and ISO 14971 effectively address failure‑based risks, hazardous situations may also arise without system malfunctions due to perception limitations and scenario uncertainty. In the automotive domain, these risks are addressed by Safety of the Intended Functionality (SOTIF) according to ISO 21448. This paper analyzes the relevance of SOTIF for autonomous medical systems and illustrates, using a representative use case, why functional safety alone is insufficient. Although ISO 21448 is not directly applicable to medical devices, its scenario‑based concepts provide valuable guidance for extending medical device safety toward transparent reasoning about system limits and the absence of unreasonable risk.