All terms
Quality & RiskQuality System
Hazard, Hazardous Situation, and Harm
ISO 14971 distinction underpinning all medical-device risk analysis.
Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed May 5, 2026
Definition
A hazard is a potential source of harm. A hazardous situation occurs when people, property, or the environment are exposed to a hazard. Harm is injury or damage to health that results from exposure during a hazardous situation. What the regulation says
Under ISO 14971:2019, the international standard for risk management of medical devices, these terms are fundamental to the risk management process. Regulators worldwide, including the FDA and those enforcing the EU MDR, expect manufacturers to identify hazards, characterize hazardous situations, and estimate harm as part of a comprehensive risk analysis, as outlined in ISO 14971:2019 clause 4.3 and Annex E. The IMDRF also emphasizes these distinctions in its guidance on MedTech risk management.
What this means in practice
Many risk tables conflate these terms. Correctly modeling the chain hazard → sequence of events → hazardous situation → harm is essential for defensible risk control decisions.Examples
- A sharp edge on a device (hazard) moving into proximity with a patient during use (hazardous situation) could cause a laceration (harm).
- A software defect (hazard) that causes incorrect data display (hazardous situation) could lead a clinician to administer an incorrect dose of medication (harm).
- A power supply failure (hazard) during a surgical procedure (hazardous situation) could result in the loss of critical device function and injury to the patient (harm).
Common pitfalls
- •Conflating "hazard" with "hazardous situation" can lead to an incomplete or inaccurate risk analysis, potentially missing crucial risk controls.
- •Failing to clearly define the sequence of events leading from a hazard to a hazardous situation and then to harm can obscure the true risk.
- •Assuming all hazards will automatically lead to harm without considering intervening events or mitigating factors is a common error.
- •Overlooking indirect or latent harms that may manifest after a significant time delay can lead to underestimation of risk.
- •Not comprehensively identifying all potential hazardous situations for a given hazard can result in inadequate risk control measures.
Frequently asked questions
In cybersecurity, a vulnerability in a medical device can be considered a hazard. A hazardous situation arises when that vulnerability is exploited, potentially leading to unauthorized access, data compromise, or device malfunction, which then results in harm to the patient or operator.
Cross-references
Used by
Things that build on this term.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsMore in Quality & Risk
· Same categoryQuality & Risk
Biocompatibility
Ability of a material to perform with an appropriate host response in a specific application.
Quality & Risk
CAPA Effectiveness Check
Verification step confirming a corrective or preventive action actually fixed the problem.
Quality & Risk
Change Control
Formal QMS process for evaluating, approving, and implementing changes that could affect product quality or compliance.
Quality & Risk
Complaint Handling
Process for receiving, evaluating, and responding to device complaints.
Cited by
Where this term appears across MedTech Terms.
Ecosystems (1)
Primary references
3 sourcesLink health: 3 verified· last checked 2026-06-20
ISO·2AAMI·1
- 1
ISO 14971:2019VerifiedISOiso.org
- 2
ISO 13485 Standard PageVerifiedISOiso.org
- 3
AAMI - Quality Systems ResourcesVerifiedAAMIaami.org
Inline markers like [1] jump to the matching reference above.