AAMI TIR97
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Definition
AAMI TIR97 is a Technical Information Report providing guidance on post-market security risk management activities for medical device manufacturers. Where AAMI TIR57 covers security risk management across the full lifecycle (and aligns with ISO 14971), TIR97 zooms in on the post-market phase: vulnerability monitoring, intake and triage, exploitability and patient-safety impact assessment, coordinated disclosure, patch development, customer notification, and the metrics for an effective post-market security program.What this means in practice
TIR97 is the operational playbook for the post-market obligations introduced by FDA Section 524B and the FDA 2023 Cybersecurity in Medical Devices guidance. It defines roles, intake workflows, severity classification (linking exploitability and patient harm), and the artifacts (advisories, VEX statements, customer letters) that prove a vulnerability monitoring plan is real. Many manufacturers structure their post-market security SOPs as a TIR97 implementation.- •Implementing TIR57 without TIR97, the lifecycle standard sets requirements that TIR97 makes operationally measurable.
- •Skipping the patient-safety impact assessment step and defaulting to CVSS, TIR97 expects an explicit linkage between exploitability and harm.
- •Treating customer notification as a marketing artifact rather than a TIR97-required communication with defined content and timing.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsAAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
A documented process for receiving, triaging, and responsibly disclosing security vulnerabilities reported by external researchers.
International standard defining secure-product-lifecycle activities for health software, including medical devices.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
More in Cybersecurity
· Same categoryThe federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
A machine-readable statement that explains whether a known vulnerability is actually exploitable in a specific product.
AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Primary references
3 sources- 1
AAMI TIR97:2019VerifiedAAMIarray.aami.org
- 2
FDA Cybersecurity in Medical Devices Guidance (2023)VerifiedFDAfda.gov
- 3
HSCC - Health Sector Coordinating CouncilVerifiedHSCChealthsectorcouncil.org
Inline markers like [1] jump to the matching reference above.