AAMI Publishes TIR115: New Guidance for Using Public Cloud Computing in Medical Devices

Randy Horton
Randy Horton

The Association for the Advancement of Medical Instrumentation (AAMI) has published AAMI TIR115:2026, Guidance for the appropriate use of public cloud computing to enable medical device functions. It is the result of more than five years of work by volunteers from across the medical device and cloud computing industries.

TIR115 answers a question that more manufacturers face every year: how do you manage computing that is essential to your device when a third party operates it?

Orthogonal Chief Solutions Officer Randy Horton co-chaired the AAMI Cloud Computing Working Group with Pat Baird of Philips. Orthogonal Founder and CEO Bernhard Kappe and VP of Quality and Regulatory Megan Graham also served on the committee.

Why TIR115 was needed

The effort began when Pat Baird invited industry to respond to an FDA request: describe what “good” looks like when medical devices use cloud computing.

Much of the early work went into defining the actual problem. The group concluded that MedTech did not need another standard for cybersecurity or privacy requirements. What it lacked was guidance for devices that depend on computing a manufacturer controls only indirectly.

Public cloud gives manufacturers scalable compute, storage, networking and security capabilities without building and running that infrastructure themselves. The tradeoff is control. Cloud providers change their platforms continuously, and a manufacturer may not see those changes coming.

“The cloud isn’t software you inherit. It’s a service you buy. Once teams treat their cloud provider as a supplier to be managed rather than a black box to be tolerated, a lot of the uncertainty goes away.”

– Randy Horton, Chief Solutions Officer, Orthogonal, and Co-Chair, AAMI Cloud Computing Working Group

Five key ideas in TIR115

1. Acknowledge indirect control.

Using the cloud brings real benefits in economics, scalability and access to capabilities, including security. It also brings risks that are not unique to medical devices but are far more prevalent than before. The first step is recognizing that you depend on infrastructure you control only indirectly.

2. Take a risk-based approach.

Manufacturers should assess how they use the cloud and make sure the resulting risks are appropriately mitigated. If a risk can’t be mitigated and the tradeoff isn’t worth it, the right answer may be not to use the cloud for that function.

“A risk-based approach helps manufacturers size their cloud solution correctly and focus controls where patient safety depends on them.”

– Megan Graham, VP Regulatory and Quality, Orthogonal

3. Draw the device boundary carefully.

The working group found there was no existing term for computing a device relies on to function but that is not legally part of the device. TIR115 introduces the Medical Device Digital Environment (MDDE) to fill that gap. As a rule of thumb, general-purpose cloud components such as compute, storage and networking belong to the MDDE. Components that are truly clinical in nature, such as software libraries specific to the device’s function, belong to the Medical Device System (MDS).

4. Manage the cloud as a supplier, not as SOUP.

TIR115 explains that cloud infrastructure should not be treated as software of unknown provenance (SOUP). It should be treated as a purchased service, with the cloud service provider contracted and managed under ISO 13485 supplier management.

5. Design and test for constant change.

TIR115 recommends architectures that limit the impact of cloud changes on the device, a staging environment that mirrors production, and planned, periodic full regression testing. That testing catches the combined effect of many small changes, including ones the provider never announces.

The same challenge extends beyond the cloud

The working group also found that indirect control is not only a cloud issue. It arises whenever devices use distributed computing, including:

  • Bring-your-own-device smartphones and other consumer technology
  • Integrations with EHRs and other clinical systems
  • Consumer software ecosystems, such as combining clinical data with data from non-device wearables
  • Third-party APIs and web services
  • Third-party AI and machine-learning models, including generative AI

Each case raises the same questions. What does the device depend on? How much control does the manufacturer have? What risks does that dependency create, and how should they be managed? We already see this pattern of indirect control in how companies integrate distributed computing into medical devices.

More than five years of work

The effort started with an AAMI BI&T article on the safe and compliant use of cloud computing with medical devices, “Hey You, Get On the Cloud: Safe and Compliant Use of Cloud Computing with Medical Devices” (January/February 2021), which received the journal’s Article of the Year award. That work led to AAMI CR510, a consensus report on cloud computing for medical devices, and then to TIR115, which now supersedes CR510.

What comes next

We have submitted TIR115 to FDA for consideration as a recognized consensus standard.

FDA will review the TIR independently and decide whether to recognize it. FDA participants contributed during its development, but recognition is not guaranteed.

For manufacturers already using public cloud computing, or considering it, TIR115 offers a clear reference point for how cloud dependencies should be identified, evaluated and managed. We encourage you to buy it, read it, use it and recommend it to others.

You can purchase the AAMI TIR115 at the AAMI store for $279.00 for non-members and $159.00 for members.

Preparing for TIR115?

If your organization is interested in learning more about how to implement TIR115 within your organization and devices, Orthogonal’s cloud readiness assessment shows you where you stand against TIR115 and what to do next. Our team reviews:

  • Where your MDS ends and your MDDE begins
  • Whether your cloud service providers are qualified and managed as suppliers under your QMS
  • How your change control handles changes your cloud provider makes
  • How cloud risks are reflected in your risk management file

You receive a prioritized roadmap for aligning with the guidance.

Acknowledgments

TIR115 reflects the time and expertise of contributors from across the medical device, cloud computing, regulatory, quality and standards communities. In addition to Co-Chairs Randy Horton and Pat Baird, and committee members Bernhard Kappe and Megan Graham, contributors included:

Related Posts

Article

Your Next AI Algorithm May Not Be the Hard Part

Article

How MedTech Teams Must Evolve for the Agentic AI Era

Article

Why Ecosystem Design Controls Are Really About Moving Faster With the Right Rigor

Article

MedTech Teams Should Stop Paying for Compliance Twice