‘Known Software Bug’ Disrupts Brain-Tumor Zapping
wired.com
wired.com
But anyway, I wonder what programming techniques are in use for these devices. They sound like they are very expensive but don't need much computational power, which is a good case for using a very high-level language. It may run slowly, but it's easier to get right. (The Therac-25 was controlled by a complicated application written in a very low-level language. A simple programming oversight which the language made very easy killed several people. Using a higher-level language would have prevented this bug.)
Most of these sorts of devices (patient-facing medical devices) are divided into two physically separated pieces: the part that touches the patient and the part that interacts with the other device.
In the imaging case, the system that actually shoots radiation at the patient should have a hardware failsafe, opto-coupled i/o, clean power, etc. The software is usually written in C or something on an embedded RTOS. Data processing is usually done in Windows or some flavor of *nix running well-tested software.
D. J. Bernstein would disagree probably... (yes - I know his soft is faulty too, but his code is a couple orders of magnitude better than 99.999% of other programmers' code and people needed years to find those bugs)
When stuff like what's in this article happens, it is quite disappointing. Luckily none of the projects I've worked on have come close to endangering patients.
Never mind that - let somebody really good work on that.
Why would a bug like that not lead to an instant communication to halt all use of the devices until a patch could be distributed ?
Good thing the couch wasn't driven by a worm-wheel or there would have been no way to pull that person out.
An emergency switch should be independent of software anyway, that's the norm in machining tools, the 'e-stop' circuitry has to be set up according to very specific rules to be approved, you'd expect more stringent controls on hospital equipment.
Good advice. Essential for things that cut you or shoot radiation at you.
It would also be nice if consumer electronics devices did this. I remember badly reflashing my iPod once; the reflash locked up and the iPod was stuck displaying a message without the backlight on. There was no way to reboot it without waiting for the battery to drain itself (or to open the device up). This took a few days, but I did get it working again.
A simple hardware reset switch would have saved me a lot of time. I don't buy Apple products anymore.
In this case the US regulatory agency, NRC, initiated an investigation and forced Elekta to fix it. It sounds like they assumed it wasn't critical enough from the initial report that all treatments with this model should stop before the patch was distributed (the incident happened months ago).