2 Addendum for CARESCAPE Monitor B450 technical manual 2062973-013
11 September 2013 Contents Purpose and scope ......................................................................................... 5 Purpose of the CARESCAPE Monitor B450 connection to a network ........... 5 CARESCAPE Monitor B450 network interface technical specifications .................................................................................................. 5 Network information flows............................................................................. 7 Required characteristics and configuration of the network for support of the CARESCAPE Monitor B450.................................................................. 13 Potential risks to safety, effectiveness, or security resulting from failure of IT network to provide the required characteristics ..................... 13
2062973-013 Addendum for CARESCAPE Monitor B450 technical manual 3
4 Addendum for CARESCAPE Monitor B450 technical manual 2062973-013 Purpose and scope This disclosure is intended to satisfy the requirements of IEC 60601-1:2005 clause 14.13 and IEC/ISO 80001-1:2010 clause 3.5 for disclosure of network-related specifications, requirements, and residual risks in order to facilitate the responsible organization’s risk management activities (e.g., pursuant to 80001-1) for their networks incorporating the CARESCAPE Monitor B450.
Purpose of the CARESCAPE Monitor B450
connection to a network The CARESCAPE Monitor B450 is intended to be connected to a network in order to support the following functionality: ● Providing real-time patient data (such as parameters, waveforms and alarms) to compatible network devices such as central stations or other bedside monitors. ● Remote viewing of 12SL ECG reports at compatible network devices. ● Remote configuration (patient admission, alarm settings, etc.) from compatible network devices. ● Remote service diagnostics and configuration (Webmin/InSite). ● Printing to a compatible network printer. ● Acting as a Citrix client for network access to applications on remote Citrix servers.
CARESCAPE Monitor B450 network interface
technical specifications Connection Name 1 Mission critical (MC) network port - S/5 network port Physical network connection IEEE 802.3-1998 10/100BaseT Ethernet type Speeds and duplex modes 10 Mbps half and full duplex, 100 Mbps half and full duplex, supported Autonegotiate (default) Default IP Address (from MC: factory) IP address — 172.16.x.y NOTE: x and y are equal to the last two octets of the MAC address. Subnet mask — 255.255.0.0 Gateway — 172.16.254.254 IP Addressing MC: IPV4 Static S/5: Virtual Plug ID QoS Support IP layer DSCP tagging
Connection Name 2 Information exchange (IX) network port
Physical network connection IEEE 802.3-1998 10/100BaseT Ethernet type Speeds and duplex modes 10 Mbps half and full duplex, 100 Mbps half and full duplex, supported Autonegotiate (default)
2062973-013 Addendum for CARESCAPE Monitor B450 technical manual 5
Connection Name 2 Information exchange (IX) network port Default IP Address (from IP address — 172.18.x.y factory) NOTE: x and y are equal to the last two octets of the MAC address. Subnet mask — 255.255.0.0 Gateway — 172.18.254.254 IP Addressing IPv4 Static (default) or DHCP QoS Support No Markings
Connection Name WLAN
General WLAN 802.11a/b/g Standards/Certifications ● USA: FCC Part 15.247, 15.205, 15.207, 15.209, 15.407 FCC ID: PVH0926 ● Canada: RSS-210, RSS-Gen IC ID: 5325A-0926 ● European R&TTE Directive 1999/5/EC: EN 300 328 V1.7.1, EN 301 893 V1.6.1 EN 301 489-1 V1.8.1, EN 301 489-17 V2.1.1 EN 61000-6-2 (2005) ● Safety Compliance: IEC 60950-1:2005 (2nd Edition)/EN 60950-1:2006 Medical Electrical Equipment ● IEC 60601-1-2 (2007) (for single antenna configurations) Antenna Gain 2.4 GHz: +2.4dBi Avg., +2.6dBi Maximum 5 GHz: +0.3dBi Avg., +3.5dBi Maximum Supported Channel Range 2.4 GHz: 1-14 5 GHz: 36-165 Transmit Power Range 2.4 GHz TRP: up to +12dBm 2.4 GHz EIRP: up to +19dBm 5 GHz TRP: up to +8dBm 5 GHz EIRP: up to +16dBm May be further restricted on some channels according to regulatory domain. Supported Data Rates (Mbps) and Corresponding Receive Sensitivity (dBm), referenced to antenna conducted output: 2.4 GHz DSSS EIS (802.11b) 11 Mbps: Channel 1/-67 dBm, Channel 6/-88 dBm, Channel PHYs 11/-90 dBm (Sensitivity corresponds to 8% max packet error rate with 1024 byte MPDU.)
6 Addendum for CARESCAPE Monitor B450 technical manual 2062973-013
Connection Name WLAN 2.4 GHz OFDM EIS (802.11g) 54 Mbps: Channel 1/-71 dBm, Channel 6/-76 dBm, Channel PHY 11/-76 dBm (Sensitivity corresponds to 10% max packet error rate with 1024 byte MPDU.) 5 GHz OFDM EIS (802.11a) 24 Mbps: Channel 36/-79 dBm, Channel 48/-79 dBm, PHY Channel 60/-79 dBm, Channel 100/-83 dBm, Channel 140/-77 dBm, Channel 165/-77 dBm (Sensitivity corresponds to 10% max packet error rate with 1024 byte MPDU.) Minimum Expected RSSI in -60dBm +/-5dB @ 54Mbps Coverage Area Dynamic Frequency 802.11h DFS Selection Transmit Power Control 802.11h TPC Dynamic Transmit Power Adaptation MAC-layer QoS and Power 802.11e HCF-EDCA / EDCF / WMM: Four standard access Save Support categories plus legacy DCF and customizable CWmin, CWmax, AIFS and TXOP settings Data Encryption Support 802.11e WMM: Customizable Cwmin, Cwmax, AIFS, TXOP, DSCP settings Authentication Support Open WEP (128-bit) WPA-PSK (TKIP) WPA2-PSK (AES-CCMP) Over-the-air Configuration None Support IP Addressing IPv4 statically configured IP Layer QoS DSCP tagging per dataflow, 802.11e, WMM
Network information flows
Flow Name 1 Unity Services Network Connection on MC network device Usage Type Clinical Function Waveforms, parameters, alarms Purpose Transmit clinical data to other devices on the network Licensed/optional/required Licensed Communication Partner Unity Devices/MC Network Device/IP Address/Network Middle Layer Protocols UDP Application Layer Protocol Unity and Encoding
2062973-013 Addendum for CARESCAPE Monitor B450 technical manual 7
Flow Name 1 Unity Services Ports Standard Unity ports Traffic characterization and Periodic traffic. Bandwidth Requirements Incoming unicast traffic is approximately 50 Kbps if viewing a remote bed. Outgoing unicast traffic is approximately 50 Kbps per patient view. Outgoing broadcast traffic is small (< 0.7 Kbps). Maximum of 10 views supported on wireless network. Maximum of 1024 views supported on wired network. Latency max 250 ms
Flow Name 1 S5 Network
Network Connection on MC – S5 network device Usage Type Clinical Function Waveforms, parameters, alarms Purpose Transmit clinical data to other iCentral devices Licensed/optional/required Licensed Communication Partner iCentral Device/IP Address/Network Middle Layer Protocols DRI Application Layer Protocol DRI and Encoding Traffic characterization and Variable Bandwidth Requirements
Flow Name 2 InSite ExC
Network Connection on IX Network device Usage Type Device servicing Function GEHC remote service Purpose Device health status notification Licensed/optional/required Optional (user can disable service) Communication Partner InSite ExC Server/https://us1-ws.service.gehealth- Device/IP Address/Network care.com/Internet, GE VPN Middle Layer Protocols TCP Application Layer Protocol HTTPS/128 bit SSL and Encoding Ports 443 Traffic characterization and Periodic (4kbytes/minute) Bandwidth Requirements On-Demand (file transfers)
8 Addendum for CARESCAPE Monitor B450 technical manual 2062973-013
Flow Name 3 InSite ExC Tunnel Network Connection on IX Network device Usage Type Device servicing Function GEHC remote service Purpose Device health status notification Licensed/optional/required Optional (user can disable service) Communication InSite ExC Server/https://us1-rd.service.gehealth- PartnerDevice/IP care.com/Internet, GE VPN Address/Network Middle Layer Protocols TCP Application Layer Protocol HTTPS/128 bit SSL and Encoding Ports 443 Traffic characterization and Periodic (4kbytes/minute) Bandwidth Requirements On-Demand (file transfers)
Flow Name 4 HTTP/HTTPS proxies
Network Connection on IX Network device Usage Type/Function/Pur- Network Services/InSite ExC pose Licensed/optional/required Optional (user can disable InSite ExC) and only necessary if hospital requires HTTP/HTTPS proxy for Internet access. Communication Partner Proxy server/Hospital Device/IP Address/Network Middle Layer Protocols TCP Application Layer Protocol HTTP/HTTPS and Encoding Ports Customer defined Traffic characterization and Periodic (4kbytes/minute) Bandwidth Requirements On-Demand (file transfers)
Flow Name 5 Webmin
Network Connection on IX Network device Usage Type/Function/Pur- Device servicing/Hospital biomed service pose Licensed/optional/required Required Communication Partner PC/IX, Hospital Network Device/IP Address/Network Middle Layer Protocols TCP
2062973-013 Addendum for CARESCAPE Monitor B450 technical manual 9
Flow Name 5 Webmin Application Layer Protocol HTTPS/AES-256 and Encoding Ports 10000 Traffic characterization and On-demand, user-initiated/varies by usage Bandwidth Requirements
Flow Name 6 Ping – Hospital Network
Network Connection on IX Network device Usage Type/Function/Pur- Device servicing/Network troubleshooting (IX only) pose Licensed/optional/required Required Communication Partner PC, Other Medical Devices/Hospital Network Device/IP Address/Network Middle Layer Protocols ICMP Application Layer Protocol N/A and Encoding Ports N/A Traffic characterization and On-demand, user-initiated, 64bytes/sec for any requested Bandwidth Requirements ping request, only one ping request can be run at a time, multiple requests could be received from other devices.
Flow Name 7 Ping – IX Network
Network Connection on IX Network device Usage Type/Function/Pur- Device servicing/Network troubleshooting (IX only) pose Licensed/optional/required Required Communication Partner PC, Other Medical Devices/IX Network Device/IP Address/Network Middle Layer Protocols ICMP Application Layer Protocol N/A and Encoding Ports N/A Traffic characterization and On-demand, user-initiated, 64bytes/sec for any requested Bandwidth Requirements ping request, only one ping request can be run at a time, multiple requests could be received from other devices.
Flow Name 8 Ping – MC Network
Network Connection on MC Network device Usage Type/Function/Pur- Device servicing/Network troubleshooting (MC only) pose
10 Addendum for CARESCAPE Monitor B450 technical manual 2062973-013
Flow Name 8 Ping – MC Network Licensed/optional/required Required Communication Partner PC, Other Medical Devices/MC Network Device/IP Address/Network Middle Layer Protocols ICMP Application Layer Protocol N/A and Encoding Ports N/A Traffic characterization and On-demand, User-initiated, 64bytes/sec for any requested Bandwidth Requirements ping request, only one ping request can be run at a time, multiple requests could be received from other devices.
Flow Name 9 Software Transfer
Network Connection on IX Network device Usage Type/Function/Pur- Device servicing/perform software upgrades pose Licensed/optional/required Required Communication Partner PC/IX Network Device/IP Address/Network Middle Layer Protocols TCP Application Layer Protocol HTTP and Encoding Ports 10001 Traffic characterization and On-demand. Approximately 100 MB of software download Bandwidth Requirements at low priority and very infrequently.
Flow Name 10 View 12SL from MUSE
Network Connection on IX Network device Usage Type Clinical Function Retrieving Purpose Displaying 12SL reports Licensed/optional/required Licensed/Optional Communication Partner Muse Server/Hospital Device/IP Address/Network Middle Layer Protocols TCP Application Layer Protocol HTTP and Encoding Ports 80 Traffic characterization and On-demand, user initiated, from 500 KB to 1 MB. Bandwidth Requirements
2062973-013 Addendum for CARESCAPE Monitor B450 technical manual 11
Flow Name 11 Printing Network Connection on IX Network device Usage Type/Function/Pur- Clinical pose Licensed/optional/required Required Communication Partner Networked printer/IX Network Device/IP Address/Network Middle Layer Protocols UDP/TCP Application Layer Protocol IPP and Encoding Ports 80,631 Traffic characterization and On-demand, user initiated Bandwidth Requirements
Flow Name 12 DNS
Network Connection on IX Network device Usage Type/Function/Pur- Network services/Domain name resolution pose Licensed/optional/required Required Communication Partner DNS server/Hospital network Device/IP Address/Network Middle Layer Protocols UDP Application Layer Protocol DNS and Encoding Ports 53 Traffic characterization and Sporadic Bandwidth Requirements
Flow Name 13 DHCP
Network Connection on IX Network device Usage Type/Function/Pur- Network services/Dynamic address assignment pose Licensed/optional/required Required Communication Partner Networked printer/Hospital network Device/IP Address/Network Middle Layer Protocols UDP/TCP Application Layer Protocol DHCP and Encoding Ports 67,68 Traffic characterization and Sporadic Bandwidth Requirements
12 Addendum for CARESCAPE Monitor B450 technical manual 2062973-013
Flow Name 14 Citrix ICA Network Connection on IX Network device Usage Type/Function/Pur- Clinical/Connection to Citrix Server pose Licensed/optional/required Licensed/Optional Communication Partner Citrix server/Hospital network Device/IP Address/Network Middle Layer Protocols TCP Application Layer Protocol Citrix ICA and Encoding Ports Customer defined (default 1494) Traffic characterization and On-demand, user initiated Bandwidth Requirements
Required characteristics and configuration
of the network for support of the CARESCAPE Monitor B450 The network must meet the specific requirements identified in the network information flows described in this document for all traffic flows associated with the subset of features, use cases and workflows required by the responsible organization’s users.
Potential risks to safety, effectiveness, or
security resulting from failure of IT network to provide the required characteristics Loss of network connectivity can result in the following hazardous situations: ● Missed alarm at a remote viewing station (bedside or display) ● Complete or partial loss or deterioration of remote monitoring of waveform and parameter data at remote viewing device Device mitigations: ● Low alarm volume is increased if network communication fails. ● Audio off, audio pause, and sleep states are interrupted if network communication fails. ● User is notified of network communication failure. A message is displayed until the user acknowledges it. ● User is notified if a duplicate IP address is detected. ● User is notified if a duplicate unit or bed name is detected.
2062973-013 Addendum for CARESCAPE Monitor B450 technical manual 13
WARNING — BEFORE INSTALLATION — Compatibility is critical to safe and effective use of this device. Please contact your local sales or service representative prior to installation to verify equipment compatibility.
WARNING — INTERFACING OTHER EQUIPMENT — Connect only items
that are specified as part of the system and as compatible. For more information, see the CARESCAPE Modular Monitors Supplemental Information Manual.
In addition to the hazardous situations identified in this section, connection of the
CARESCAPE Monitor B450 to a network that includes other equipment could result in other unidentified risks to patients, operators, or third parties. The responsible organization should identify, analyze, evaluate and control these risks on an ongoing basis, including after changes to the network such as these listed, which could introduce new risks and require additional analysis: ● Changing the network configuration. ● Connecting additional items to the network. ● Disconnecting items from the network. ● Updating equipments connected to the network. ● Upgrading equipments connected to the network.
14 Addendum for CARESCAPE Monitor B450 technical manual 2062973-013
content Headquarters Asia Headquarters GE Healthcare Finland Oy GE Medical Systems GE Medical Systems Kuortaneenkatu 2 Information Technologies, Inc. Information Technologies Asia; GE (China) Co., Ltd. FI-00510 Helsinki 8200 West Tower Avenue No1 Huatuo Road, Finland Milwaukee, WI 53223 USA Zhangjiang Hi-tech Park Pudong Tel: + 358 10 39411 Tel: + 1 414 355 5000 Shanghai P.R.China 201203 Fax: + 358 9 1463310 1 800 558 5120 (US only) Tel: + 86 21 5257 4650 www.gehealthcare.com Fax: + 1 414 355 3790 Fax: + 86 21 5208 2008