intesy clinical suite (ics) security manual

40
P/N 070-2922-00 Rev. A | www.spacelabshealthcare.com August 2020 O P E R A T I O N S M A N U A L Intesy Clinical Suite (ICS) Security Manual

Upload: others

Post on 11-Jun-2022

10 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Intesy Clinical Suite (ICS) Security Manual

P/N 070-2922-00 Rev. A | www.spacelabshealthcare.com August 2020

O P E R A T I O N S M A N U A L

Intesy Clinical Suite (ICS) Security Manual

Page 2: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

www.spacelabshealthcare.comP/N 070-2922-00 Rev. A

©2020 Spacelabs Healthcare

All rights reserved. Contents of this publication may not be reproduced in any form without the written permission of Spacelabs Healthcare. Products of Spacelabs Healthcare are covered by U.S. and foreign patents and/or pending patents. Printed in U.S.A. Specifications and price change privileges are reserved.Spacelabs Healthcare considers itself responsible for the effects on safety, reliability and performance of the equipment only if:

• assembly operations, re-adjustments, modifications or repairs are carried out by persons authorized by Spacelabs Healthcare, and

• the electrical installation of the relevant room complies with the requirements of the standard in force, and• the equipment is used in accordance with the operations manual.

In the event of a serious incident, notify Spacelabs and the competent authority of the EU Member State.Spacelabs Healthcare will make available, on request, such circuit diagrams, component part lists, descriptions, calibration instructions or other information which will assist appropriately qualified technical personnel to repair those parts of the equipment which are classified by Spacelabs Healthcare as field repairable. Spacelabs Healthcare is committed to providing comprehensive customer support beginning with your initial inquiry through purchase, training, and service for the life of your Spacelabs Healthcare equipment.

CORPORATE OFFICES

Corporate Headquarters

Spacelabs Healthcare, Inc. 35301 SE Center StreetSnoqualmie, WA 98065 U.S.A.Telephone: (1) 800 287 7108Telephone: (1) 425 396 3300

Authorized EC Representative

MediMark® Europe. 11 rue E. Zola 38100Grenoble. France

Please refer to https://www.spacelabshealthcare.com/about-us/patents-trademarks for a full listing of Spacelabs Healthcare trademarks. Other brands and product names used herein are trademarks of their respective owners.

• Rx Only U.S. Federal law restricts the devices documented herein to sale by or on the order of a physician.

• Before use, carefully read the instructions, including all warnings and cautions.

Page 3: Intesy Clinical Suite (ICS) Security Manual

P/N 070-2922-00 Rev. A

Table of Contents

1 About This ManualOverview................................................................................................................ 1-1Conventions used in this manual........................................................................... 1-1

2 Intesys® Clinical Suite SecurityIntesys Clinical Suite (ICS) Description ................................................................. 2-1

Core Services ............................................................................................... 2-1Database ...................................................................................................... 2-2Application Suite ........................................................................................... 2-2System Details .................................................................................................. 2-4Network ............................................................................................................. 2-4Data Classification ............................................................................................ 2-5

Security and Privacy Controls for ICS ................................................................... 2-5User Authentication and Authorization .......................................................... 2-6Protection of Data in Transit ......................................................................... 2-7Wired Connectivity ............................................................................................ 2-7Remote Access ............................................................................................ 2-8Internal Systems Connections ...................................................................... 2-8Protection of Data at Rest ............................................................................ 2-8Audit Event Logging ..................................................................................... 2-9 Time Stamps ............................................................................................. 2-11Secure Configuration Baseline ................................................................... 2-11Security configuration (Recommended) .......................................................... 2-12Ports, Protocols and Services ......................................................................... 2-12Bug Reporting and Cybersecurity Product Updates .................................... 2-14Security Bugs/Defect Identification and Reporting .......................................... 2-14Antivirus ...................................................................................................... 2-14Incident Response ...................................................................................... 2-15

3 Appendix A — Symbols

I-iwww.spacelabshealthcare.com

Page 4: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

This page is intentionally blank.

I-ii P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 5: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

About This Manual

OverviewThis manual provides instructions on how to use specific security features of Intesys® Clinical Suite (ICS).

This manual has questions from the Manufacturer Disclosure Statement for Medical Device Security (MDS2) form and the answers are specifically about ICS. The sections that are not from the MDS2 are noted.

Conventions used in this manualCertain conventions are used throughout this manual for consistency and to aid in the search for information about ICS. • Non-blue italicized typeface are references to information outside this

manual. They indicate references to other manuals or information which is available in another form, as identified by a title or a part number.

• Bold typeface indicates text labels, phrases, or titles that show on an LCD or display which are part of a Spacelabs Healthcare software application.

• A non-bold term with Leading Capital Letters identifies the formal name of an icon, control, or view. These items do not include text as part of their identification, such as Home Screen, Patient View, or Setup Window.

Read this manual before use and pay attention to all warnings and cautions.

1-1P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 6: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

About This Manual

• Numbered steps are presented to accomplish a task. Some steps conclude in a step result—unnumbered indented text.

• Warnings and cautions are included before pertinent content to alert you to important information on the use of the monitor Notes are placed after pertinent content. An example of each follows.

Note:Notes alert the user to relevant facts and conditions.

Warnings indicate potentially harmful conditions that can lead to injury or death.

Cautions indicate conditions that can lead to damage to or malfunction of the device.

1-2 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 7: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

Intesys Clinical Suite (ICS) DescriptionIntesys Clinical Suite (ICS) is a core service framework and an application suite. It consists of:• Core Services, a group of low-level system components and services

• A tool for system administration

• An applications suite for reviewing patient information

Core ServicesCore Services provide the following functions: • Interfaces ICS applications with Spacelabs Healthcare monitoring

systems.

• Collects patient vital signs data from assigned monitors and inserts that data into the ICS portal database.

• Collects patient monitor channel waveform data from all assigned monitors and inserts that data into the ICS portal database.

• Collects print requests from all associated monitors and inserts that data into the ICS portal database.

• Collects generated 12-Lead reports from all assigned monitors and inserts that data into the ICS portal database.

• Reviews specific values in the portal database to update patient data on Spacelabs Healthcare monitors.

• Manages the data in the portal database.

• Provides ICS administrative tools.

2-1P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 8: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

DatabaseThe portal database is the storage mechanism for ICS Core Services.• It is a full schema database that must reside on a Microsoft SQL Server.

• It is a critical component of the suite and must be available to all ICS applications for proper operation.

Application SuiteThe following ICS applications may be installed and run as standalone applications, or they can be combined. These are used for reviewing patient information.

ICS Application Description

Custom Trends (92876) Provides the ability to customize trend templates for the enterprise.

Print Manager (92881)

Provides network printing services for Windows-compatible printers and print requests from the monitors. Auto-recorded alarms, as well as alarms configured to record to ICS, are stored here for availability for later reprint.

Smart Disclosure (Clinical Access) (92810)

Shows patient waveforms, trends, alarms, and12-leads collected from Spacelabs Healthcare monitors on the network and provides near real-time analysis of ECG data of selected patients.

Vital Signs Viewer (92880)

Provides a near real-time view of selected patient waveforms and vital signs.

Enterprise Network Interface (92848)

The ENI product provides historical information regarding past patient alarm events. The information is not provided in real time and is not intended as a basis for diagnosis, clinical decisions, or active patient monitoring. ENI is intended to transfer data to other vendors’ information systems using an industry standard data exchange protocol, such as XML or HL7. ENI is intended for use only when the patient is otherwise actively monitored.

12-Lead Electrocardiogram (ECG) Interface (92877)

Provides an interface for sending patient 12-Lead report data to ECG management systems.

2-2 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 9: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

Figure 2-1 ICS software

HL7 Admit Discharge Transfer (ADT) Interface (92842)

Provides an interface for Spacelabs Healthcare devices to receive patient demographic information from the hospital ADT system.

HL7 Vital Signs Interface (92843)

Provides an interface for the Spacelabs Healthcare devices to send patient vital signs data from the monitor to a Clinical Information System.

ICS Application Description

2-3P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 10: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

Figure 2-2 ICS Alarms

System Details

Network

Component: Details:

Software Intesys Clinical Suite (ICS)

Software version 5.5.0

Compatible Server Operating Systems Windows Server 2012 (64 bit)

Compatible Database SQL Server 2014 (64 bit)

Connectivity: Capable:

Wired Yes

Wireless No

Internet Ready Yes

Bluetooth No

2-4 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 11: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

Data Classification

Security and Privacy Controls for ICSSpacelabs provides its customers with capabilities to configure the ICS to meet their own security policies and requirements. The areas of responsibilities are shown below:

Remote Access Yes

Connectivity: Capable:

Data TypeElectronic Personal Health Information (ePHI)

Process/Display Transmit Store

Demographic (e.g., name, address, location, unique identification number Yes Yes Yes

Diagnostic/therapeutic (e.g., photo/radiograph, test results, or physiologic data with identifying characteristics) Yes Yes Yes

Medical record (e.g., medical record #, account #, test or treatment date, device identification number) Yes Yes Yes

Open, unstructured text entered by device user/operator? Yes Yes Yes

Security featureArea of responsibility

Customer

Authentication and Authorization ✔

Protection of Data in Transit ✔

Remote Access ✔

Internal System Connection ✔

Protection of Data at Rest ✔

Audit Event Logging ✔

2-5P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 12: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

User Authentication and AuthorizationAbility of the device to authenticate users and to determine the authorization of users.

Time Stamps ✔

Secure Configuration Baseline ✔

Bug Reporting and Cybersecurity Product Updates ✔

Antivirus ✔

Incident Response ✔

Security featureArea of responsibility

Customer

# Questions Responses

1 Does the device support user/operator-specific username(s) and password(s) for at least one user?

Yes * See Note 1 below

2 Does the device support unique user/operator specific IDs and passwords for multiple user? No

3Can the device be configured to authenticate users through an external authentication service (example: MS Active Directory, NDS, LDAP, etc)?

Yes

4 Can the device be configured to lock out a user after a certain number of unsuccessful logon attempts?

Yes * See Note 1 below

5 Can default passwords be changed at/prior to installation? Yes

6 Are any shared user IDs used in this system? Yes** See Note 2 below.

7Can the device be configured to enforce creation user account passwords that meet established complexity rules?

Yes * See Note 1 below

8 Can the device be configured so that account passwords expire periodically?

Yes * See Note 1 below

9 Can the device prevent access to unauthorized users through user login requirements or other mechanism?

Yes * See Note 1 below

2-6 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 13: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

* Note 1 - Intesys® Clinical Suite (ICS) is a core service framework and an application suite (no hardware). All services and applications run on Windows Server host systems. Customers are responsible for managing the installation of other software applications (such as antivirus software) on the server, along with upgrading the operating system. The operating system supports user/operator specific usernames and passwords, and can be configured to auto-logoff users after a predetermined length of inactivity.

** Note 2 - This device is within the hospital network, customers can work with their Enterprise Integration Manager to determine the best remote access method..

Customers are responsible for implementing and maintaining the servers and operating systems that ICS runs on. This implementation and maintenance includes the authentication and authorization of user accounts that used on the server.

Protection of Data in TransitThe ability of the device to ensure the confidentiality and integrity of transmitted data

ICS talks to other ICS components and customer EHR systems on the same internal hospital system network.

Wired Connectivity ICS uses the IEEE 802.3 standard for communications. This device is not capable of encrypting data transmissions.

Recommendation: ICS should be implemented within a VLAN(s) behind the firewall. Please use the ports, protocols, and services tables (“Ports,

10Can users be assigned different privilege level within an application based on ‘roles’ (example: guest, regular users, power users, administrators, etc)?

Yes * See Note 1 below

11Can the device owner/operator obtain unrestricted administrative privileges (example: access operating system or application via local root or admin account)?

No

# Questions Responses

# Questions Responses

1 Can PII/ePHI data be transmitted only via a point-to-point dedicated cable? No

2 Is PII/ePHI data encrypted prior to transmission via a network? No

3 Is PII/ePHI data transmission restricted to a fixed list of network destinations? Yes

4 Does the device support any mechanism intended to ensure data is not modified during transmission? No

2-7P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 14: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

Protocols and Services” on page 12) in the Secure Configuration Baseline section below to limit the ports to what is required.

Remote Access

This product is part of a suite of integrated software solutions installed on customer owned host platforms. The product does not enable remote access or service, but the customer could enable it on the host platform. Spacelabs recommends doing so to allow both internal customer employees and Spacelabs employees to remotely access system for troubleshooting purposes. Customers can work with their Enterprise Integration Manager to determine the best remote access method.

Internal Systems Connections

ICS can be composed of as little as one dedicated server to many. All separate servers communicate with each other over 802.3 Ethernet communications.

ICS also provides customer’s Electronic Health Record (EHR) system with patient data. The patient date passed to the EHR is accomplished by a connection to the customer’s interface system via HL7. Although these components are separated, they are still internal to the health system network.

Protection of Data at RestThe device ability to ensure unauthorized access does not compromise the integrity and confidentiality of data stored on the device.

# Questions Responses

1 Can the device be serviced remotely? Yes

2Can the device restrict remote access to/from specified devices or users or network locations (specific IP addresses)?

Yes

3 Can the device be configured to require the local user to accept or initiate remote access? No

# Questions Responses

1 Can this device connect to other Spacelabs products? Yes

2 Can this device connect to other non-Spacelabs products? Yes

2-8 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 15: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

Audit Event LoggingThe ability to reliably audit activity on the device.

# Questions Responses

1 Can the device encrypt data at rest? No

2 Are the device components maintaining PII/ePHI data physically secure (i.e. cannot be remove without tool? Yes

3 Does the device ensure the integrity of stored data with implicit or explicit error detection/correction technology? Yes

# Questions Responses

1 Can the device create an audit trail? Yes

2 Indicate which of the following events are recorded in the audit log:

2a Login/Logout Yes* See Notes below.

2b Display/presentation of data No

2c Creation/modification/deletion of data Yes

2d Import/export of data from removable media No

2e Receipt/transmission of data to/from external (example network) connection

Yes

2f Remote service activity (Remote Access) No* See Notes below.

2g Other events Not Applicable

3 Indicate what information is used to identify events recorded in the audit log

3a User ID Varies by ICS Component and Log

3b Date/Time Yes

4 Can the device send event logs to a SEIM Not Applicable

2-9P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 16: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

* ICS runs on COTS software. Windows installations can monitor activity on the operating systems via the Windows Event Logs (WEL). Customers will want to configure the WEL to their organization’s sever standards. Remote Access to the various ICS servers can be configured by the customer numerous ways. Many of these provide detailed logging of remote access. This is not a service ICS provides.

* ICS consists of multiple applications and services. Each component has different logging options that can be configured in the ICS Administration GUI installed on each ICS server. This will be implemented by Spacelabs in conjunction with the customer.

The following components log in the following ways:• ICS Monitor Loaders/Print Manager: ICS Monitor Loader logging is done

in the Windows Event Logs. Depending upon the space available and the level of logging required, there are many choices available. These logs do contain PHI.

• HL7 ADT & VSI Interface: The components log into the Windows Event Log. HL7 produces a large amount of logging data and is usually only configured for around an hour of messages. There are various option available in the ICS Admin Tool. These logs do contain PHI.

• ICS Data Loader: The ICS Data Loader creates detailed logs in the server’s C:\ProgramData\Spacelabs\SLNI\Logs file path. These logs will register various patient data points such as alarms on each patient, admissions, and discharges of patients as well as diagnostic information about the service and communications to the Xhibit Telemetry Receivers which provide it the data. This information is set by default and cannot be configured by the customer.

• ICS Database: All logging is provided in the WEL for the Database server. This server will also have logging events for the ICS Analysis service and the ICS Data Purger.

2-10 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 17: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

Time Stamps

The various components of ICS run on host platforms provided by the customer. Most ICS servers use local time for logging purposes. The ICS Data Loader server uses UTC in the logs it produces.

Recommendation: Spacelabs recommends configuring the ICS Database Server as the time source for other components. The customer can also setup an NTP source on each individual host platform.

Secure Configuration BaselineThe ability to configure/re-configure device security capabilities to meet user needs.

Spacelabs customers are responsible for following their own Change Control processes.

To ensure the proper operation and use of ICS Clinical Access:• To avoid ICS applications from malfunctioning due to software updates,

test any operating system updates, SQL server software updates, and patches in a test environment first before applying them to a production environment.

• Install anti-virus software on all devices running Windows operating systems.

Spacelabs customers can make changes to the following security features.

# Questions Responses

1 Does the medical device use an internal clock for time stamps? Yes

2 Can the time stamps be mapped to Coordinated Universal Time (UTC) or Greenwich Mean Time (GMT)? Yes

# Questions Responses

1 Can the device owner/operator/admin reconfigure product security features/capabilities? Yes

2-11P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 18: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

Security configuration (Recommended)• ICS consists of multiple applications and services. Firewalls should be

configured to allow for traffic in the list of ports, protocols, and services below.

• Passwords: The ICS product is a software suite that runs on COTS (commercial off the shelf) computer servers. The operating system supports user/operator specific usernames and passwords and can be configured to auto-logoff users after a pre-determined length of inactivity.

• Network Security: ICS Servers should be configured on a secure VLAN behind the customer firewall. Depending on the size of the customer’s installation, they can either be on the same VLAN as the Spacelabs monitors or a separate secure VLAN for servers. If an ICS Data Loader is configured, its network can be setup in one of two ways:

- Dedicated Layer 2 VLAN: In this configuration the Data Loader, Xhibit Telemetry Receiver (XTR) and Xhibit Central Stations all reside on a single flat VLAN. The Data Loader then also connects to the ICS Database server.

- Layer 3 Network: The Data Loader, XTR and Xhibits may all be on separate VLANs instead of one

• This device does not come configured for an Intrusion Detection System (IDS) nor an Intrusion Prevention System (IPS). The customer can configure its respective IDS/IPS system to capture activities to and from this device.

Ports, Protocols and ServicesSee the table below:

2-12 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 19: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

P

5asoa

5asoa

1

1

1

9

orts Protocol Service Purpose Source Destination Data Exchanged

1374 nd pecific ffsets bove

IP multicast and IP unicast over UDP using proprietary Spacelabs protocol

Monitor Loader Load monitor data into ICS

Monitors (91389, 91390, 91393, 91389)

SS DB Engine

Physiological waveforms, alarm and configuration information

1374 nd pecific ffsets bove

IP multicast and IP unicast over UDP using proprietary Spacelabs protocol

Data Loader Load telemetry data into ICS Data Loader SS DB

Engine

Physiological waveforms, alarm and configuration information)

433

TCP (MC-SMP, MS-TDS, MS-SSDTS, MS-BINXML, MS-SSCLRT)

SQL Server DB engine

Operation of ICS clients and services

ICS services, ICS Clinical Access application, and ICS Administration Console

SS DB Engine

SQL Server queries and data sets returned by queries

433 TCP (MS-SQLR)

SQL Browser service

Installation program and configuration of other ICS services and applications

ICS services, ICS Clinical Access application, and ICS Administration Console

SS DB Engine Named instances

3101

TCP (proprietary Spacelabs protocol)

Clinical Analysis Service

Perform analytics on clinical data in ICS Database

ICS Clinical Access Application

Clinical Analysis Service

Configuration and analysis commands

100 TCP (LPR) Print Manager

Connects ICS to Windows Network Printer Service

SS DB EngineEnterprise Network Print Services

Reports containing physiological waveforms

2-13P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 20: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

Bug Reporting and Cybersecurity Product UpdatesThe ability of on-site service staff, remote service staff or authorized customer staff to install/upgrade device security patches. The ability to report security bugs or product defects.

Security Bugs/Defect Identification and Reporting• Internal Spacelabs testing teams identified defects are forwarded to

Spacelabs Research and Development for investigation, analysis, and remediations.

• Customer identified defects are reported to Spacelabs by calling Spacelabs Global Technical Support (GTS) via phone (800-522-7025), via email ([email protected]) or via the Internet link (https://www.spacelabshealthcare.com/support/feedback-submission/)

Complaint management: Once a defect/complaint is received by Spacelabs, the GTS team works with the customer to remedy the defect or issue reported. If GTS is unable to remedy the customer's issue, the issue is escalated to higher level escalation teams, who work on the defect/complaint in conjunction with Spacelabs Research and Development. The customer will be involved on an as needed basis.

Patch Updates and Process: Windows Patches can be applied according to the customer's patching schedule.

Spacelabs recommends customers to use the Spacelabs Patch Test Reports page (https://www.spacelabshealthcare.com/products/security/patch-test-reports/) to determine what patches are required and safe to apply.

ICS updates are provided periodically and will need to be coordinated via the customer’s Enterprise Integration Manager. Customers may reach out to Technical Support at 800-522-7025 or their personal Spacelabs Sales Representative for further information on ICS patches or upgrades

AntivirusThe ability of the device to effectively prevent, detect and remove malicious software (such as malware, virus, etc.)

# Questions Responses

1 Can relevant OS and device security patches be applied to the device as they become available? Yes

2 Can security patches or other software be installed remotely? Yes

3 Can product security bugs be reported? Yes

2-14 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 21: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

Note:This product is sold as software that is implemented on the Healthcare organizations infrastructureThe customer is responsible for the installation, management and running of the Anti-virus solution that meets their company’s anti-virus policy and standard.

Incident Response

Customer can report security incidents by calling into Spacelabs Global Technical Support (GTS):• Via phone at 800-522-7025

• Via email at [email protected] and/or

• Via the internet at https://www.spacelabshealthcare.com/support/feedback-submission/

Once the incident is received, Spacelabs will investigate and prioritize appropriately.

# Questions Responses

1 Does the device support the use of anti-virus software? Yes

2 Can the user independently re-configure anti-virus settings? Yes

3 Does notification of virus/malware detection occur in the device interface? Not Applicable

4 Can only manufacturer-authorized persons repair systems when virus or malware has been detected? Not Applicable

5 Can the device owner install or update anti-virus software? Yes

6Can the device owner/operator (technically/physically) update virus definitions on manufacturer-install anti-virus software?

Yes

# Questions Responses

1 Does the manufacturer provide support to investigate security incidents involving the device? Yes

2-15P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 22: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Intesys® Clinical Suite Security

This page is intentionally blank.

2-16 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 23: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

The following list of international and safety symbols describes all symbols used on Spacelabs Healthcare products. No one product contains every symbol.

Note:Graphic elements of certain keys and symbols may vary between product lines.

HELP Key

? HELP (Explain Prior Screen) Key

MONITOR SETUP Key

REMOTE Key

3-1P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 24: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

TRENDS Key

RECORD Key

SPECIAL FUNCTIONS Key

NORMAL SCREEN Key

SAVE Key

No Network Connection

Network Connection

Do Not Connect to Network

No Connection to Intesys® Clinical Suite (ICS)

Compression

Magnifying Glass

File Cabinet

3-2 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 25: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

List of Rooms

Printer

Service Message

PREVIOUS MENU Key

HOME Key

Arrows

STANDBY KeyPower ON/OFF Key

ENTER Key

Delete

Nurse Alert Interface

ALARM SUSPEND/TONE RESET Key

ALARMS Key

Alarm, General

x

3-3P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 26: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

Alarm Reset

Alarm Audio ON

Alarm Audio OFF

Alarm Audio Paused

Alarm Indicator. On the display, the color of the symbol designates the priority of the alarm:• cyan = low• yellow = medium• red = high

On monitor hardware, this symbol indicates Alarm Output.

Alarms Paused

Alarm OFF or equipment has no alarm system

--- Parameter below measurement range

+++ Parameter above measurement range

??? Parameter measurement indeterminate

Indicator — Remote Control

Normal Screen

Clock/Time Setting Key

Slow Run

Activate Recorder for Graphics

3-4 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 27: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

Reset

START (NIBP) Key

Power Indicator LED

Activate Telemetry Recorder

Output (Non-terminated)

Data Input/Output

Input

No Output (Terminated)

Indicator — Local Control

Indicator — Out of Paper

Recorder Paper

Menu Keys

Waveform/Parameter Keys

Return to Prior Menu

Monitor SetupSelect Program Options

123 1

23

123

3-5P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 28: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

Set Initial Conditions Menu

Access Special Function Menu

Return Unit to Monitor Mode

Keypad

Serial Port 1

Serial Port 2

Serial Port

Auto Mode (NIBP)

External Marker Push Button Connection

Arterial Pulse

Gas Exhaust

Video Output

Television; Video Display

Video Output, Primary

Video Output, Secondary

123

A

123

B

123

1

2

1

2

3-6 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 29: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

Enlarge, Zoom

Input/Output

PCMCIA Card

Touchscreen, External

Universal Serial Bus

SDLC Port

Hard Drive

Antenna

Electrocardiograph or Defibrillator Synchronization

Foot Switch

Audio Output, Speaker

Event

Gas Sampling Port

Gas Return Port

SDLC

3-7P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 30: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

BatteryReplace only with the appropriate battery.

Battery Status

BatteryReplace only with the appropriate battery.

Low Battery

Replace only with the appropriate battery.(+ / - signs may be reversed)

Check battery switch on bottom of unit.

Battery off. Shipping and service mode.

Battery on. Regular operating mode.

All batteries should be disposed of properly to protect the environment. Lithium batteries should be fully discharged before disposal. Batteries such as lead-acid (Pb) and nickel-cadmium (Ni-Cd) must be recycled. Please follow your internal procedures and or local (provincial) laws regarding disposal or recycling.

This symbol indicates that the waste of electrical and electronic equipment must not be disposed as unsorted municipal waste and must be collected separately. Please contact an authorized representative of the manufacturer for information concerning the decommissioning of your equipment.

Caution - hazardous voltages. To reduce risk of electric shock, do not remove the cover or back. Refer servicing to a qualified field service engineer (U.S.A.).DANGER - High Voltage (International)

Protective Earth Ground

Replace Fuse Only as Marked

Power supply jack polarity. (+ / - signs may be reversed)

3-8 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 31: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

Alternating Current

Both Direct and Alternating Current

Functional Earth Ground

Fuse

Equipotentiality Terminal

Direct Current

Input Power. Use only Spacelabs Power Supply.

AC/DC Input

Loop Filter

Audio Output, Speaker

IEC 60601-1 Type B equipment. The unit displaying this symbol contains an adequate degree of protection against electric shock.

IEC 60601-1 Type BF equipment which is defibrillator-proof. The unit displaying this symbol is an F-type isolated (floating) patient-applied part which contains an adequate degree of protection against electric shock, and is defibrillator-proof.

IEC 60601-1 Type BF equipment. The unit displaying this symbol is an F-type isolated (floating) patient-applied part providing an adequate degree of protection against electric shock.

IEC 60601-1 Type CF equipment. The unit displaying this symbol is an F-type isolated (floating) patient-applied part providing a high degree of protection against electric shock, and is defibrillator-proof.

3-9P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 32: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

IEC 60601-1 Type CF equipment. The unit displaying this symbol is an F-type isolated (floating) patient-applied part providing a high degree of protection against electric shock.

IEC 60601-1 Class II equipment, double-isolated. The unit displaying this symbol does not require a grounded outlet.

Warning: Do not modify this equipment without authorization of the manufacturer.

Operates on Non-Harmonized Radio Frequencies in Europe

Adult Noninvasive Blood Pressure (NIBP)

Fetal Monitor Connection (Analog)

Fetal Monitor Connection RS-232 (Digital)

Physiological Monitor Connection RS-232 (Digital)

Noninvasive Blood Pressure (NIBP), Neonate

Symbol Set, Adult/Pediatric Cuff Sizes

Symbol Set, Neonatal Cuff Sizes

NIBP Cuff, Neonatal 1

NIBP Cuff, Neonatal 2

NIBP Cuff, Neonatal 3

NIBP Cuff, Neonatal 4

3-10 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 33: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

NIBP Cuff, Neonatal 5

NIBP Cuff, Single Hose

NIBP Cuff, Dual Hose

NIBP Cuff, Surface Applied to Patient

NIBP Cuff, Child Size (12 to 19 cm)

NIBP Cuff, Child Size, Long (12 to 19 cm)

NIBP Cuff, Small Adult Size, Long (17 to 25 cm)

NIBP Cuff, Small Adult Size (17 to 25 cm)

NIBP Cuff, Adult Size, Long (23 to 33 cm)

NIBP Cuff, Large Adult Size, Long (31 to 40 cm)

NIBP Cuff, Large Adult Size (31 to 40 cm)

NIBP Cuff, Adult Size (23 to 33 cm)

NIBP Cuff, Infant Size (8 to 13 cm)

NIBP Cuff, Neonatal 1 Size (3 to 6 cm)

NIBP Cuff, Neonatal 2 Size (4 to 8 cm)

NIBP Cuff, Neonatal 3 Size (6 to 11 cm)

THIS SIDE TO PATIENT

CHILD

CHILD, LONG

SMALL ADULT, LONG

SMALL ADULT

ADULT, LONG

LARGE ADULT, LONG

LARGE ADULT

ADULT

INFANT

NEONATAL 1

NEONATAL 2

NEONATAL 3

3-11P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 34: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

NIBP Cuff, Neonatal 4 Size (7 to 13 cm)

NIBP Cuff, Neonatal 5 Size (8 to 15 cm)

NIBP Cuff, Thigh Size (38-50 cm)

NIBP Cuff, Nylon Material

NIBP Cuff, Soft Material

NIBP Cuff, Vinyl Material

Quantity

Place Artery Symbol and Arrow over Brachial or Femoral Artery

eIFU = electronic Instructions for Use (CD-ROM or website) is available

Consult Instructions For Use

Follow Instructions For Use

Warning—Potential danger to patient or user (consult accompanying documents)

Caution—Potential damage to equipment (consult accompanying documents)

Note Note

Keep Dry

NEONATAL 4

NEONATAL 5

THIGH

NYLON

SOFT

VINYL

QTY

ARTERY

3-12 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 35: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

Indoor Use Only

Altitude Limit

Temperature Range

Fragile, handle with care

Handle with Care

This Way Up

Up Arrow

Down Arrow

Humidity Limit

Humidity limitation

Atmospheric pressure limitation

Open Padlock

Closed Padlock

12,200 m

3-13P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 36: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

PVC-Free (Polyvinyl Chloride)

Do Not Reuse; Single Use Only

Single patient - multiple use

Reusable

IPX1 Drip-Proof

IPX7 Unit can withstand accidental immersion in one meter of water for up to 30 minutes

Catalog Number or Order Number

Medical Device

Use by date [YYYY-MM-DD]

Recycle

Non Sterile

Latex Free – Not made with natural rubber latex

Contains latex

PVC

2

MD

NONSTERILE

3-14 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 37: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

Does not contain phthalates

Contains or presence of phthalates, such as DEHP

Date of Manufacture

Manufacturer

Radio transmitting device; elevated levels of non-ionizing radiation

A CE mark certifies that a product has met EU health, safety, and environmental requirements, which ensure consumer safety.

XXXX is the European Notified Body number. 0123 is the number for TÜV SÜD Product Service GmbH, München, Germany.

Canadian Standards Association Approved

Does not contain hazardous substances — Europe

Does not contain hazardous substances — China

Batch Code

Nellcor Oxisensor II Compatible

Novametrix Compatible

Spacelabs TruLink Compatible

Nellcor OxiMax Compatible

XXXX

NE2

NVX

3-15P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 38: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

ABBREVIATIONS USED AS SYMBOLS ARE SHOWN BELOW.

Spacelabs Compatible

UL certified for use in the United States and Canada

UL recognized component in Canada and United States

Nellcor OxiMax Compatible

Masimo SET Compatible

1 - 32 Access Codes 1 Through 32

AIR Air

A Amperes

ANT 1ANT 2

Diversity Antenna System 1Diversity Antenna System 2

Arr1ArrNet2

Arrhythmia Net 1Arrhythmia Net 2

avDO2 Arterial/Venous Oxygen Difference

CaO2 Arterial Oxygen

CHch

EEG, EMG, or ECG ChannelEEG Channels - CH1, CH2, CH3, CH4EMG Channel - CH5

cmH2O Centimeters of Water

C.O.CO

Cardiac Output

CvO2 Venous Oxygen

CO2CO2

Carbon Dioxide

3-16 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com

Page 39: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

DIAdia

Diastolic

ECGecg

Electrocardiogram

EEGeeg

Electroencephalogram

EMGemg

Electromyogram

ESIS Electrosurgical Interference Suppression

EXT External

FECG Fetal Electrocardiogram

FHR1FHR2

Fetal Heart Rate, Channel 1Fetal Heart Rate, Channel 2

GNDgnd

Ground

Hz Hertz

Hgb Hemoglobin

HLOhlo

High-Level Output

Multiview Multi-Lead Electrocardiogram

N2O Nitrous Oxide

NIBPnibp

Noninvasive Blood Pressure

O2AV Oxygen Availability

O2 Oxygen

PaO2 Partial Pressure of Arterial Oxygen

PRESSpressPRS

Pressure

PvO2 Partial Pressure of Mixed Venous Oxygen

Ref. Oxygen reference gas port

RESPresp

Respiration

SDLC Synchronous Data Link Control

3-17P/N 070-2922-00 Rev. A www.spacelabshealthcare.com

Page 40: Intesy Clinical Suite (ICS) Security Manual

Intesy Clinical Suite (ICS) Security Manual

Appendix A — Symbols

Serial number

Option

SVO2SvO2SvO2

Mixed Venous Oxygen Saturation

SYSsys

Systolic

T1T2T3T4

Temperature 1Temperature 2Temperature 3Temperature 4

TEMPtemp

Temperature

UA Uterine Activity or Umbilical Artery

UV Umbilical Venous

VAC Vacuum Connection

VO2 Oxygen Consumption

V Volts

W Watts

SN

3-18 P/N 070-2922-00 Rev. Awww.spacelabshealthcare.com