Independent learning for medical-device professionals
CommentaryConsulting
LearningMTL-118 · CORE MEDICAL DEVICE TOPIC

Electrical Safety and Electromagnetic Compatibility

How to engineer protection against electrical and electromagnetic hazards into the complete medical device—and preserve the evidence from architecture through production and change.

What you will learn

By the end of this topic, you should be able to define the product and environment that must be assessed, develop a risk-based electrical-safety concept, select and preserve means of protection, connect essential performance to EMC acceptance criteria, plan representative testing, control safety-critical production details and assess changes against the established safety case.

01

Safety and EMC are designed—not added by the test laboratory

Electrical safety prevents unacceptable risk from electric shock, excessive temperatures, fire, hazardous energy and related failures. Electromagnetic compatibility limits disturbances produced by the device and ensures that basic safety and essential performance remain acceptable when foreseeable disturbances are present.

Standards testing is an important part of the evidence, but passing a test does not transfer responsibility to the laboratory. The manufacturer must define the intended product, identify applicable requirements, establish risk controls and acceptance criteria, provide representative samples and decide whether the complete evidence supports release.

The central principle

Begin with clinical use, foreseeable environments and risk. A test report is credible only when its configuration, criteria and observations represent the device that users will actually receive.

This topic concentrates on engineering practice. Use MTL-304 — IEC 60601 Electrical Safety and EMC for the structure and application of the IEC 60601 family.

02

Define the complete product and its environments

Safety depends on more than the main enclosure. Power supplies, charging equipment, accessories, cables, patient connections, networks, mounting arrangements and equipment used nearby can alter current paths, insulation, emissions and immunity.

  • Define users, patient populations, clinical functions and foreseeable misuse.
  • Identify professional, home, transport, emergency, industrial or other electromagnetic environments.
  • List normal operating modes, start-up, charging, cleaning, service, storage and transport conditions.
  • Define applied parts, accessible parts, patient and operator connections and possible simultaneous contact.
  • Identify every power source, interface, accessory, cable length and permitted system configuration.
  • Record altitude, humidity, contamination, mains characteristics and foreseeable nearby emitters.
  • Distinguish the tested system from external equipment whose behaviour is an assumption.

Keep this definition aligned with MTL-102 — Intended Purpose, Users and Use Environments and the system boundary developed in MTL-112 — Systems Engineering, Architecture and Interfaces.

03

Build one coherent safety concept

The safety concept explains how the architecture prevents hazards, detects failures, controls energy and maintains or recovers essential functions. It should connect risk controls across electronics, mechanics, software and information supplied with the device.

Clinical functionWhat the device must do and the consequences of absence, degradation or unintended output
Hazard and sequenceHow normal operation, a fault or a disturbance could create a hazardous situation
Protection strategyInherent design, protective measures, monitoring, safe states and information for safety
Allocated requirementMeasurable limits and behaviour assigned to hardware, software, enclosure and interfaces
Verification methodAnalysis, inspection and testing under representative normal and fault conditions
Residual-risk conclusionResults, anomalies, limitations, labelling and the final evaluation of acceptability

Use MTL-105 — Medical-device Risk Management to build the overall risk process and MTL-113 — Essential Performance and Safety Concepts to define safety-significant performance.

04

Look beyond electric shock

Shock

Accessible voltages, leakage currents, patient connections, stored charge and loss of protective barriers.

Thermal and fire

Hot surfaces, overloaded components, batteries, ignition sources, flammable materials and inadequate containment.

Energy

High current, capacitive or inductive energy, moving actuators and unintended outputs triggered by a fault.

Functional failure

Incorrect sensing, therapy, alarm, display or control when power quality or electromagnetic disturbance affects the system.

Mechanical interaction

Loss of shielding, spacing, insulation or earth continuity after impact, vibration, wear, assembly or service.

System interaction

External equipment, cables, networks and accessories that bridge isolation or introduce disturbance and ground paths.

Analyse normal condition, reasonably foreseeable abnormal conditions and relevant single faults. Consider how one fault can expose a second weakness and whether supposedly independent controls share power, components, software, data or physical construction.

05

Make every means of protection explicit

Protection can include insulation, protective earth, protective impedance, separation, current limiting, enclosures and other measures. The required arrangement depends on who is protected, the possible voltage and current path, the intended environment and the equipment configuration.

  • Draw an insulation and isolation diagram that covers mains, secondary circuits, patient, operator and external interfaces.
  • Identify which barriers provide operator protection and which provide patient protection.
  • Define working voltages and the conditions used to determine clearance, creepage and solid insulation.
  • Account for altitude, pollution, material, coating, production tolerance and ageing.
  • Control protective-earth connections, fasteners, bonding and resistance where used.
  • Identify leakage-current paths created by filters, shields, cables, accessories and test equipment.
  • Show how protection remains effective after foreseeable assembly, cleaning, service and mechanical stress.

Do not treat an approved power supply or isolation component as proof of the complete device. Its approvals apply within stated conditions, and the surrounding circuitry and construction can change the result.

06

Control power architecture and safety-critical components

Mains input, external adapters, batteries, charging, DC conversion and stored energy should be considered as one architecture. Define start-up, shutdown, brownout, interruption, overvoltage, reverse connection, overload and depleted-battery behaviour.

Power source

Ratings, mains category, fusing, inrush, isolation, protective earth and permitted adapters.

Energy storage

Battery chemistry, charging limits, protection, temperature, replacement, transport and end-of-life behaviour.

Conversion

Normal and fault stresses, component derating, feedback failure, transformer construction and thermal margin.

Critical parts

Safety approvals, exact manufacturer and type, ratings, conditions of acceptability and controlled alternatives.

A component list becomes safety evidence only when it identifies why each part is critical and how purchasing, incoming control, assembly and change management preserve the assessed construction.

07

Carry the safety concept through PCB, cables and enclosure

Detailed implementation can defeat a sound block diagram. PCB slots, copper edges, test points, fasteners, wiring, connectors, displays, ventilation and conductive coatings can alter spacing, current paths and electromagnetic behaviour.

  • Control safety distances in footprints, layout rules, panelisation and manufacturing tolerances.
  • Separate noisy, high-energy and sensitive measurement areas and manage their return paths.
  • Prevent wiring movement, abrasion, pinching and incorrect reconnection during assembly or service.
  • Coordinate enclosure seams, apertures, shields, conductive finishes, gaskets and cable terminations.
  • Ensure mechanical fasteners cannot compromise insulation or become the only uncontrolled protective path.
  • Define connector keying, pin sequencing and behaviour under partial or incorrect connection.
  • Review the complete assembly, not only the schematic and bare PCB.

These details should remain connected to MTL-114 — Electrical and Electronic Design and MTL-115 — Mechanical Design and Materials.

08

Assess temperature, abnormal operation and fire together

Temperature limits protect patients, operators, materials and component reliability. Test and analysis should cover representative loading, ambient conditions, ventilation, mounting and the operating modes that create the greatest heating.

Abnormal conditions may include blocked ventilation, stalled motors, shorted outputs, failed cooling, incorrect supply, component faults and software-controlled loads remaining energised. The design should limit energy, interrupt unsafe operation or contain the consequence without relying on an instruction where an inherent control is practicable.

Where software controls a thermal or energy hazard, define the sensor, limit, reaction time, diagnostic coverage, independence and behaviour if data, power, communication or the controller itself fails.

09

Turn essential performance into observable criteria

EMC immunity testing asks whether basic safety and essential performance remain acceptable during and after disturbance. Statements such as “operates normally” or “no loss of function” are rarely sufficient for a complex device.

  • Identify the clinical function and unacceptable consequence of degradation.
  • Define quantitative limits, timing, accuracy and allowed transient behaviour.
  • State whether automatic recovery is permitted and how quickly it must occur.
  • Specify alarms, safe states, data integrity and user intervention during degradation.
  • Describe how each criterion will be stimulated, observed and recorded during testing.
  • Consider silent corruption, delayed output and plausible but incorrect data—not only resets.
  • Trace criteria to risk analysis, design inputs and the released product configuration.
10

Understand the electromagnetic phenomena

Emissions

Conducted and radiated energy from clocks, converters, motors, switching loads, cables and wireless functions.

Electrostatic discharge

Direct and indirect discharge through enclosures, displays, controls, connectors and nearby structures.

Radio-frequency immunity

Radiated and conducted coupling from communications equipment and other transmitters.

Power disturbances

Fast transients, surge, voltage dips, interruptions and disturbance on AC or DC power ports.

Magnetic fields

Power-frequency and proximity fields that can affect sensors, transformers and magnetic components.

Wireless coexistence

Performance when intended radios share spectrum and physical space with other users and interferers.

Applicable tests, levels and ports depend on the device, edition, intended environment and product-specific requirements. Special environments may need an assessment beyond a default laboratory programme.

11

Control coupling paths at source, path and victim

Robust EMC design reduces disturbance at its source, interrupts the coupling path and increases the tolerance of susceptible circuits. Effective controls usually cross discipline boundaries.

  • Reduce loop areas and control high-frequency current return paths.
  • Partition power conversion, digital switching, radios, actuators and sensitive analogue functions.
  • Place filtering and transient protection at the boundary where disturbance enters or leaves.
  • Define grounding, bonding, chassis and shield termination deliberately.
  • Coordinate cable type, length, routing, connector shell and enclosure aperture.
  • Protect inputs against overvoltage and ensure recovery after transient events.
  • Use firmware to detect implausible data, communication loss and corrupted states without masking faults.
  • Preserve diagnostics and logs that help distinguish upset, recovery and permanent damage.

A ferrite or filter added during formal testing may change signal quality, safety spacing, leakage current, thermal behaviour, manufacturability and the released bill of materials. Treat remediation as a controlled design change.

12

Build a representative safety and EMC test strategy

The strategy should explain why selected samples and configurations represent the product family. Consider component variants, software versions, power sources, patient connections, accessories, cables, operating modes and loads.

ScopeMarkets, standards, editions, particular requirements and justified exclusions
ConfigurationSamples, options, accessories, cables, firmware, support equipment and setup
ConditionsNormal use, fault states, loading, environment and worst-case combinations
CriteriaSafety limits, essential performance, permitted degradation and recovery
ObservationInstrumentation, simulators, logs, video, data capture and operator checks
DispositionResults, anomalies, deviations, root cause, corrective action and regression

Link the strategy to MTL-106 — Verification and Validation so protocols, samples, methods, results and conclusions form controlled objective evidence.

13

Use early testing to learn—not merely to predict a pass

Pre-compliance work is most valuable while architecture and layout can still change. It can expose emissions margin, sensitive frequencies, discharge paths, immunity thresholds, thermal hotspots and unexpected fault behaviour.

Record the configuration and observations even when the setup is informal. Near-field probes, current probes, spectrum measurements, controlled ESD, power interruption and targeted RF injection can help locate mechanisms. A result without configuration or diagnostic notes is difficult to reproduce.

Test more than one sample or known design corner where variation matters. Formal evidence may still require accredited or otherwise competent facilities, but early engineering evidence reduces late surprises and improves the quality of the formal plan.

14

Engage the laboratory before design freeze

Provide the laboratory with the intended-use and environment definition, applicable-standards plan, classifications, insulation diagram, essential-performance rationale, risk-based criteria, configurations, operating instructions and monitoring arrangements.

Manufacturer owns

Product definition, risk decisions, criteria, representative configuration and the final conformity conclusion.

Laboratory contributes

Technical interpretation, equipment, controlled execution, observations and an independent report.

Shared preparation

Sample readiness, modes, simulators, accessories, cables, support equipment and safety precautions.

Shared investigation

Reproduction, evidence collection and separation of symptom, coupling path and root cause.

Review draft reports for factual accuracy, sample identity, photographs, configuration, criteria, observations and deviations. A pass statement cannot compensate for a report that describes the wrong product.

15

Translate assessed construction into production controls

Formal evaluation usually examines a small number of samples. Production controls must ensure that manufactured units preserve the barriers, components, workmanship and configurations on which the safety conclusion depends.

  • Identify safety-critical components, materials, fasteners, wiring and processes.
  • Control approved manufacturers, exact part numbers and justified alternatives.
  • Define assembly inspections for earth, insulation, spacing, routing, shielding and labelling.
  • Specify appropriate routine electrical-safety tests and calibrated equipment.
  • Set acceptance limits, reaction plans and investigation requirements.
  • Train assemblers and service personnel on safety-critical construction.
  • Control firmware, programmable-device and product-variant configuration.
  • Use production and service data to identify drift or recurring weaknesses.

Change review should address new component revisions, suppliers, PCB layouts, enclosures, coatings, cables, batteries, power supplies, firmware and accessories. The decision may require analysis, focused regression or wider retesting.

16

Electrical safety and EMC across the lifecycle

1

Define the equipment and environment

Establish intended use, users, patient contact, applied parts, accessories, power sources, connections, operating modes and electromagnetic environments.

Typical evidence: Use specification, system boundary, equipment classifications, environment profile and applicable-standards plan.
2

Develop the safety concept

Identify electrical, thermal, fire, energy and functional hazards; define essential performance and allocate means of protection and risk controls.

Typical evidence: Risk analysis, essential-performance rationale, insulation and protection diagrams, safety requirements and architectural decisions.
3

Design the complete product

Coordinate power, isolation, earthing, PCB layout, enclosure, cabling, filtering, shielding, components, software monitoring and recovery.

Typical evidence: Schematics, layouts, calculations, drawings, component evidence, interface specifications and design reviews.
4

Plan representative testing

Select configurations, modes, loads, accessories, cables, faults and measurable acceptance criteria that represent the product placed on the market.

Typical evidence: Safety and EMC plans, configuration matrix, pass/fail criteria, monitoring methods and laboratory agreement.
5

Test early and formally

Use analysis and pre-compliance work to find weaknesses, then conduct controlled safety and EMC evaluations on identified representative samples.

Typical evidence: Calculations, inspection records, pre-compliance results, formal reports, raw observations, deviations and corrective actions.
6

Transfer controls into production

Protect safety-critical construction through approved suppliers, controlled processes, inspections and routine tests appropriate to the production design.

Typical evidence: Critical-component list, drawings, work instructions, acceptance criteria, routine-test records and supplier controls.
7

Maintain the safety case

Assess component, layout, firmware, enclosure, cable, accessory and supplier changes, and use complaints and field events to improve the evidence.

Typical evidence: Change-impact assessments, regression rationale, updated risk records, surveillance, investigation and retest evidence.
17

Build a connected evidence chain

A reviewer should be able to move from a hazardous situation or applicable requirement to the chosen protection, its detailed implementation, the configuration tested, the result and the released production control.

BasisIntended use, environment, applicable standards, risk analysis and essential performance
RequirementsProtection, limits, fault behaviour, emissions, immunity and acceptance criteria
DesignArchitecture, schematics, insulation, layout, enclosure, components and software controls
EvaluationReview, calculations, inspection, pre-compliance work and formal testing
ConclusionResults, anomalies, deviations, residual risk and representative configuration
MaintenanceProduction controls, suppliers, changes, complaints, field events and regression

Organise this evidence through MTL-104 — Design Controls and Technical Documentation; avoid leaving the test report as an isolated document with no traceable connection to product decisions.

18

Common misconceptions

“A medical-grade power supply makes the product safe.”

It addresses only part of the complete equipment. Loading, wiring, earthing, enclosure, patient connections and interfaces still require assessment.

“EMC means controlling emissions.”

Medical-device EMC also requires immunity evidence for basic safety and essential performance in relevant environments.

“The laboratory decides essential performance.”

The manufacturer defines it from clinical function and risk, with measurable criteria the laboratory can observe.

“A pass covers every product variant.”

Coverage depends on a documented rationale showing that configurations and samples represent the released family.

“Firmware recovery solves an immunity failure.”

Recovery is acceptable only when specified criteria permit the degradation and safety is maintained throughout.

“A component substitution is minor.”

Changes in electrical, mechanical or electromagnetic characteristics can invalidate protection, test margin or the assessed configuration.

19

Practical review checklist

  • Are the device, accessories, cables, power sources and environments completely defined?
  • Are equipment classifications, applied parts and possible patient and operator current paths clear?
  • Does the risk analysis identify electrical, thermal, fire, energy and electromagnetic hazards?
  • Are basic safety and essential-performance requirements measurable and allocated?
  • Does an insulation and protection diagram explain every required barrier?
  • Are safety-critical parts and conditions of acceptability controlled?
  • Do PCB, enclosure, wiring and cable designs preserve safety distances and EMC paths?
  • Are normal, abnormal and single-fault conditions justified?
  • Does the EMC plan define representative modes, ports, accessories, monitoring and pass/fail criteria?
  • Has pre-compliance work investigated margin and failure mechanisms?
  • Do formal reports identify the exact tested configuration and all deviations?
  • Do production inspections and routine tests preserve assessed construction?
  • Are changes assessed against safety, EMC, risk and regression evidence?
20

Authoritative references

Confirm the current editions, amendments, national adoptions, regulatory recognition and any applicable collateral or particular standards for the device and intended markets.

KEY TAKEAWAY

The tested configuration must be the designed—and manufactured—configuration

Electrical safety and EMC are credible only when product definition, risk, architecture, detailed construction, test criteria, laboratory evidence, production controls and change assessment tell the same story.