Independent learning for medical-device professionals
CommentaryConsulting
LearningMTL-114 · CORE MEDICAL DEVICE TOPIC

Electrical and Electronic Design

How to turn system requirements and safety decisions into robust circuits, interfaces, assemblies and evidence that remain controlled throughout the medical-device lifecycle.

What you will learn

By the end of this topic, you should be able to frame an electrical design from its medical and system context, structure an appropriate architecture, recognise safety and EMC obligations, manage accuracy and power budgets, select and control components, create production-ready design outputs and plan the objective evidence needed for release and lifecycle change.

01

Electrical design begins before the schematic

A circuit can be technically elegant and still be unsuitable for the medical device. The engineer must first understand what the product is intended to do, who interacts with it, where it operates, what can cause harm and how electrical functions interact with software, mechanics, users and external systems.

Medical purpose

Clinical function, patient population, claims, duration of use and consequences of incorrect, delayed or unavailable performance.

People and contact

Patients, operators, service personnel, applied parts, accessible parts and foreseeable contact in normal and fault conditions.

Environment

Professional facility, laboratory, home, transport or emergency use; supply quality, temperature, humidity, fluids, cleaning and electromagnetic conditions.

System context

Power sources, accessories, sensors, actuators, networks, chargers, computers, mobile devices, cloud services and third-party equipment.

Lifecycle

Storage, transport, installation, calibration, servicing, battery replacement, updates, refurbishment and end-of-life conditions.

Evidence route

Applicable standards, certification strategy, external laboratories, representative samples and records needed for regulatory submissions.

See MTL-102 — Intended Purpose, Users and Use Environments and MTL-103 — User Needs and Design Inputs for establishing the product definition and testable requirements.

Do not select the standard from the power supply

IEC 60601-1 commonly applies to medical electrical equipment, while laboratory and IVD equipment may fall under the IEC 61010 family. Intended use, equipment function and applicable particular standards determine the route—not simply whether the product contains electronics.

02

Build an electrical architecture that explains the design

The architecture should make power flow, signal flow, control, isolation, protection, diagnostics and external interfaces visible. It should also show how the design supports safety and essential performance.

SourcesMains, batteries, adapters, charging, energy storage and external supplies
DomainsVoltage rails, grounding, isolation, patient circuits and noisy loads
FunctionsSensing, processing, communication, indication and actuation
ProtectionLimits, barriers, monitoring, shutdown, alarms and fault containment
InterfacesElectrical, data, mechanical, thermal, human and supplier boundaries
EvidenceCalculations, analysis, inspection, testing and traceability

Use explicit engineering budgets

Allocate system-level requirements to electrical elements before detailed design. Useful budgets include power consumption, battery capacity, accuracy, noise, latency, timing, thermal rise, communication loading, memory, diagnostic coverage and reliability. Record margins and assumptions so later changes can be assessed.

  • Define normal, peak, start-up, charging, sleep and fault-condition power.
  • Identify current return paths, reference potentials, shielding and chassis strategy.
  • Allocate end-to-end accuracy and uncertainty across sensors, references, analogue stages, conversion, algorithms and calibration.
  • Define start-up, reset, brownout, watchdog, power-loss and recovery behaviour.
  • Specify interface voltage, timing, protocol, fault tolerance and compatibility.
  • Separate safety-relevant, high-noise, high-energy and sensitive measurement domains where needed.
  • Identify programmable devices and the boundary between hardware and software control.
  • Show product variants and permitted combinations of boards, accessories and firmware.

See MTL-112 — Systems Engineering, Architecture and Interfaces for system allocation, states and interface control.

03

Design electrical safety into the product

Electrical safety is not achieved by passing a final dielectric-strength test. It depends on the equipment classification, applied parts, supply, environment, insulation system, accessible parts, energy sources and behaviour in normal and fault conditions.

Protection strategy

Identify the required means of protection for patients and operators, then define how insulation, protective earth, impedance, spacing or other measures provide them.

Insulation coordination

Determine working voltages, overvoltage categories, pollution, material groups, creepage, clearance, solid insulation and dielectric requirements.

Leakage and patient connection

Control touch, earth and patient leakage currents, including applied-part paths, accessories, cables and single-fault conditions.

Energy and temperature

Limit accessible voltage, current, stored energy, mechanical actuation, component temperature, fire and battery hazards.

Abnormal operation

Consider component faults, blocked ventilation, reversed connection, liquid ingress, wrong accessories, supply variation and control failures.

Evidence and construction

Document critical components, insulation diagrams, protective measures, calculations, drawings, markings and representative test configurations.

The distinction between means of patient protection and means of operator protection affects construction and testing. It should be resolved with the complete use and contact model—not added to the schematic as an unexplained label.

External power supplies, isolation modules and certified components can support the strategy, but their certificates do not certify the finished medical device. Their ratings, conditions of acceptability, interfaces and use within the complete construction must be assessed.

04

Connect performance to risk

Electrical and electronic functions often implement clinical performance, protective measures or both. The design must show what happens when sensing, processing, power, communication or actuation is absent or degraded.

  • Identify electrical functions that implement or support essential performance.
  • Translate clinically meaningful limits into circuit and interface requirements.
  • Analyse open circuit, short circuit, drift, saturation, stuck output, intermittent connection and out-of-sequence behaviour.
  • Consider latent faults and whether diagnostics detect them before another failure occurs.
  • Assess common causes such as shared power, references, clocks, processors, connectors and environmental stress.
  • Define fault detection, annunciation, controlled continuation, recovery and shutdown.
  • Verify that risk controls remain effective at component tolerances and environmental boundaries.
  • Examine how cybersecurity compromise could affect electrical control, sensing or safety response.

Risk analysis should generate design requirements; design decisions should update the risk analysis. A failure-mode table completed after schematic release cannot substitute for this continuing engineering dialogue.

See MTL-113 — Essential Performance and Safety Concepts and MTL-105 — Medical-device Risk Management for the underlying safety reasoning.

05

Control sensing, measurement and actuation

Medical-device electronics frequently make decisions from small signals and then control functions with clinical consequences. The complete measurement or control chain must be understood, not merely each component’s nominal specification.

Sensor interface

Excitation, loading, bias, linearity, noise, drift, cross-sensitivity, ageing, placement and environmental sensitivity.

Analogue chain

Gain, offset, bandwidth, filtering, settling, saturation, common-mode range, protection and error accumulation.

Conversion and reference

Resolution, reference stability, sampling, aliasing, timing, missing codes and the relationship between counts and engineering units.

Calibration

Traceability, coefficients, range, storage integrity, versioning, equipment, intervals, acceptance and behaviour when calibration is invalid.

Actuation

Drive limits, feedback, motion or energy control, end conditions, stall, runaway, load variation and independent protective measures.

Diagnostics

Plausibility, range, cross-checks, continuity, self-test, watchdogs, fault injection and coverage of dangerous failures.

Accuracy requirements should include the complete chain and relevant uncertainty. A high-resolution converter does not create an accurate system when the sensor, reference, analogue front end, calibration, mechanics or environment dominate the error.

Boundary behaviour matters: start-up, warm-up, transition, overload, recovery and invalid data may be more safety-relevant than steady-state nominal operation.

06

Select components for the supported life

Component selection is a technical, manufacturing, supply and lifecycle decision. Nominal electrical fit is only the starting point.

  • Confirm ratings across voltage, current, power, temperature, frequency, duty cycle and environmental stress.
  • Apply justified derating and analyse tolerance, drift, ageing and worst-case combinations.
  • Assess package, assembly process, cleanliness, moisture sensitivity, handling and inspectability.
  • Review manufacturer quality, change notification, traceability, authenticity and supply continuity.
  • Identify safety-critical and performance-critical components with controlled specifications.
  • Record required approvals, certificates and conditions of acceptability.
  • Evaluate single-source exposure, lifecycle status, obsolescence and authorised alternatives.
  • Control programmable parts, factory configuration, calibration data and device identity.
  • Ensure substitutions receive technical, risk, manufacturing and verification impact assessment.

The bill of materials should identify what is actually controlled. A generic value such as “10 kΩ resistor” may be sufficient in one location and inadequate in another where voltage rating, tolerance, stability, construction, flammability or safety approval matters.

Availability is not equivalence

A purchasing substitute is a design change unless the released specification already demonstrates that the alternative meets every relevant electrical, safety, EMC, reliability, manufacturing and regulatory requirement.

07

Turn the circuit into a controlled physical design

The PCB and assembly are part of the circuit. Placement, routing, stack-up, materials, return paths, spacing, thermal behaviour and manufacturing processes determine whether the schematic’s intent survives in the product.

Placement and partitioning

Keep high-current, switching, radio, digital, analogue, patient-connected and protective areas organised according to their interactions.

Return paths

Control current loops, references, planes, stitching, cable shields and transitions rather than treating “ground” as one ideal node.

Signal integrity

Manage impedance, termination, edge rate, crosstalk, clocking, timing and connector discontinuities where they affect reliable operation.

Safety spacing

Preserve required creepage, clearance, slots, barriers and insulation through copper, components, coatings, fasteners and assembly tolerances.

Thermal design

Analyse dissipation, spreading, airflow, enclosure interaction, hot spots, accessible temperatures and component life.

Manufacturability and test

Provide fiducials, access, programming, calibration, inspection, in-circuit or functional test and unambiguous assembly information.

Use schematic, layout and manufacturing reviews with representatives from systems, mechanics, software, verification and production. The most damaging issues often occur at interfaces: connector orientation, shared references, mechanical stress, thermal paths, programming states or undocumented assembly options.

08

Engineer EMC rather than test for it

Electromagnetic compatibility requires both controlled emissions and adequate immunity. For medical devices, immunity acceptance criteria must be derived from safety and essential-performance behaviour, not limited to whether the device resets visibly.

  • Define intended electromagnetic environments and nearby sources.
  • Identify ports, cables, apertures, seams and power paths that can couple disturbances.
  • Control loop area, return continuity, filtering, shielding, grounding and enclosure bonding.
  • Place protection at the point of entry and provide a low-impedance path for disturbance energy.
  • Manage switching-node area, edge rates, clock harmonics and common-mode currents.
  • Protect high-impedance and low-level measurement circuits from conducted and radiated coupling.
  • Define performance criteria for every relevant test and operating mode.
  • Exercise representative loads, accessories, cables, communications and clinically significant functions.
  • Plan pre-compliance investigation early enough to change architecture or mechanics.
  • Record observations and recoveries even when the formal acceptance criterion is met.

Passing in one convenient configuration does not show that all marketed configurations are covered. Select and justify worst-case hardware, software, cables, accessories, power modes, radio activity, loads and operating states.

See MTL-304 — IEC 60601 Electrical Safety and EMC for the standards-led view.

09

Electrical engineering across the lifecycle

Electrical design continues from product definition through released-product support. The engineer’s evidence and decisions must mature with the device.

1

Understand the device context

Clarify intended purpose, users, environments, patient contact, clinical workflow, external systems, operating life and applicable product standards before selecting technology.

Typical evidence: Electrical context, applicable-standard assessment, use scenarios, environmental profile, system boundary and assumptions.
2

Establish requirements and budgets

Convert system needs, risks and interfaces into measurable electrical requirements, then allocate power, accuracy, timing, thermal, noise, reliability and communication budgets.

Typical evidence: Electrical requirements, interface specifications, allocation tables, calculation budgets and acceptance criteria.
3

Develop and review the architecture

Define power domains, isolation, sensing, processing, actuation, communications, diagnostics, protection and safe behaviour with explicit design rationale.

Typical evidence: Architecture diagrams, safety concept, preliminary analyses, technology evaluations and multidisciplinary reviews.
4

Implement controlled design outputs

Create schematics, component specifications, PCB data, programmable-logic sources, manufacturing information and test definitions under configuration control.

Typical evidence: Released schematics, bills of material, PCB files, calculations, component records, drawings and design-review evidence.
5

Verify progressively

Use analysis, simulation, inspection and testing from circuit prototypes through integrated systems, including boundaries, tolerances, disturbances, faults and ageing effects.

Typical evidence: Approved protocols, design calculations, simulation records, bench results, EMC and safety reports, anomalies and traceability.
6

Transfer into production

Confirm that suppliers, assembly processes, programming, calibration, inspection and production tests can realise the verified design consistently.

Typical evidence: Approved suppliers, manufacturing files, process qualifications, test fixtures, calibration methods, golden units and release records.
7

Control the supported lifecycle

Assess component changes, obsolescence, field failures, repairs, software updates and environmental experience against architecture, risk and existing evidence.

Typical evidence: Change assessments, failure analysis, updated risk records, regression rationale, service controls and post-market trends.
10

Verification, transfer and technical evidence

Verification should combine analysis and testing. Some conclusions—such as worst-case stress, tolerance, timing or thermal margin—cannot be demonstrated credibly by one nominal bench test. Others need physical evidence from representative assemblies.

Analysis

Worst-case circuits, tolerance stacks, power and thermal budgets, reliability, insulation coordination, fault analysis and measurement uncertainty.

Simulation

Analogue behaviour, power integrity, signal integrity, thermal response, control loops and fault cases where models are suitable and controlled.

Bench verification

Requirements, boundaries, stresses, calibration, diagnostics, faults, transitions, communications and environmental conditions.

External testing

Electrical safety, EMC, radio, environmental and other accredited or specialist testing using defined configurations and criteria.

Production evidence

Assembly inspection, programming, traceability, calibration, production tests, limits, test-system validation and nonconformance handling.

Lifecycle evidence

Supplier changes, component deviations, failure analysis, service findings, complaint trends and regression decisions.

Every important result should identify the requirement, method, equipment, configuration, environmental conditions, acceptance criteria, actual result, anomaly disposition and approval. Maintain traceability from system need and risk through electrical requirement, design output and evidence.

See MTL-106 — Verification and Validation for the wider evidence strategy.

11

Common misconceptions

“The certified power supply makes the product compliant.”

No. Certification can support the design, but the complete equipment, interfaces, construction, conditions of use and risk controls still require assessment.

“EMC is a laboratory test at the end.”

No. Architecture, enclosure, cables, layout, software behaviour and acceptance criteria must be developed before formal testing.

“A reference design removes the need for analysis.”

No. The application, environment, loads, layout, safety function and lifecycle may differ from the supplier’s assumptions.

“High resolution means high accuracy.”

No. Accuracy depends on the complete measurement chain, calibration, drift, uncertainty and operating conditions.

“The schematic is the electrical design.”

No. Components, PCB implementation, mechanics, firmware, manufacturing, calibration and test controls determine the realised behaviour.

“Equivalent components are a purchasing decision.”

No. Equivalence must be demonstrated against the controlled design requirements and affected evidence.

12

Electrical-design practical checklist

  1. Understand the medical purpose, users, environment, system boundary and applicable standards.
  2. Translate system needs and risks into measurable electrical requirements.
  3. Define architecture, interfaces, states, budgets, margins and fault behaviour.
  4. Establish the complete basic-safety and essential-performance strategy.
  5. Analyse measurement, control and diagnostic chains end to end.
  6. Select components for tolerance, stress, manufacturing, supply and supported life.
  7. Make PCB layout, grounding, thermal and mechanical decisions part of the controlled design.
  8. Engineer EMC and representative configurations before formal testing.
  9. Combine analysis, simulation, inspection and testing into traceable evidence.
  10. Transfer programming, calibration, inspection and production testing under control.
  11. Assess every component, supplier or design change against risk and existing evidence.
13

Authoritative starting points

The applicable electrical-safety, EMC, radio, battery, environmental and product-specific standards depend on the device, intended use, markets and configurations. Confirm current editions, amendments, national adoptions and transition dates in the organisation’s controlled regulatory strategy.