Independent learning for medical-device professionals
SearchCommentaryConsulting
Worked Examples & Case StudiesMTL-405 · WORKED PRODUCT CASE STUDY

Medical Electrical Equipment

An end-to-end example showing how essential performance, electrical safety, EMC, usability and service controls become one equipment safety case.

How to use this case study

This example follows a powered bedside monitor from clinical function through protection, alarms, electromagnetic disturbance and maintenance. Ask whether the definition of essential performance remains visible in every engineering and verification decision.

01

Case at a glance

A mains-powered bedside device continuously measures a physiological parameter through an applied sensor, displays the current value and trend, and provides audible and visual alarms when defined limits are crossed. It includes an internal battery for transport and temporary mains interruption.

Clinical value

Continuous, timely information supports clinical observation and response.

Equipment boundary

Main unit, applied sensor, power supply, battery, software, accessories and alarm outputs.

Essential performance

Accurate monitoring and effective alarm generation within defined conditions.

Principal uncertainty

Whether faults or disturbances can create plausible but misleading information.

02

Connect the clinical use to the equipment specification

Draft intended purpose

The equipment is intended for continuous monitoring of a specified physiological parameter in adult patients by trained healthcare professionals in hospital environments, providing displayed values, trends and alarms to support observation. It is not intended as the sole means of diagnosing deterioration.

The patient, environment, duration, operator, sensor placement and response expectations determine performance and safety requirements. Use MTL-102 — Intended Purpose, Users and Use Environments.

03

Define what must remain safe and effective

Essential performance includes accuracy sufficient for the claim, timely update, detection of invalid sensor conditions and alarm behaviour that enables an appropriate response. Loss or degradation must either remain within acceptable limits or become apparent quickly enough to prevent unacceptable risk.

Clinical functionContinuous monitoring supports professional observation
Failure consequenceMisleading value or missed alarm delays intervention
Performance limitAccuracy, latency, availability and alarm response criteria
Fault responseDetect, inhibit, alarm or enter a defined safe state
Test conditionNormal use, single fault, environment and disturbance
Residual informationWarnings, limitations, training and maintenance

See MTL-104 — Essential Performance and Safety Concepts.

04

Specify performance and protection together

  • The equipment shall meet defined measurement accuracy and update-time limits throughout the claimed operating range.
  • Sensor disconnection, degradation and implausible signals shall produce a clear technical alarm.
  • Alarm priority, sound, visibility, latching and silence behaviour shall support the intended clinical response.
  • Loss of mains power shall transfer to battery without loss of essential performance for the specified duration.
  • Single faults shall not expose patient or operator to unacceptable electrical, thermal, mechanical or fire hazards.
  • Electromagnetic disturbances shall not cause unsafe degradation or misleading output.
  • Service and calibration state shall be controlled and visible where it affects performance.
05

Risk controls span protection and information

Missed alarm

Threshold, algorithm, audio path or user setting prevents timely notification. Use independent checks and verify the complete alarm chain.

Leakage current

Insulation or protective-earth failure exposes patient or operator. Apply appropriate means of protection and production tests.

EMC disturbance

RF interference corrupts measurement while the display appears credible. Detect invalid states and test with representative accessories.

Battery degradation

Transport use ends unexpectedly. Monitor state, warn early, specify maintenance and verify ageing assumptions.

Risk management links the clinical consequence to electrical, mechanical, software and use-related causes. Apply MTL-114 — Medical-device Risk Management.

06

Make protective independence credible

The signal chain separates acquisition, plausibility checking, calculation, display and alarm control. Safety-significant power and watchdog functions do not rely on a single uncontrolled software path. The power architecture identifies protective earth, insulation barriers, patient isolation, battery charging and thermal protection. Accessories and applied parts are part of the assessed configuration.

07

Build an integrated verification programme

PERFORMANCE

Measurement and alarms

Accuracy, latency, limits, invalid states, alarm priority and complete signal-chain response.

SAFETY

Basic safety

Leakage, dielectric strength, temperature, mechanical hazards, power, battery and single-fault conditions.

EMC

Immunity and emissions

Representative cables, sensors, modes, performance criteria and recovery under disturbance.

USE

Usability and environment

Set-up, alarm response, cleaning, transport, lighting, noise, servicing and foreseeable misuse.

Plan the evidence using MTL-313 — IEC 60601 Electrical Safety and EMC.

08

Follow one missed-alarm thread

User needStaff need timely notice of a clinically significant change
HazardNo effective alarm delays clinical response
RequirementDetect threshold crossing and generate the specified alarm
ArchitectureValidated signal, alarm logic, annunciation path and watchdog
VerificationBoundary, fault, volume, visibility, EMC and power-transition tests
ValidationRepresentative users recognise and respond in the intended environment
09

Transfer production and service controls

Release includes approved components and accessories, programmed software, calibration, protective-earth and electrical-safety tests, alarm checks, battery acceptance, labelling and device history. Service procedures define safe isolation, replacement, calibration, software compatibility and return-to-use testing.

10

Use a component substitution to test lifecycle control

A display module becomes obsolete. The replacement has different brightness, emissions, timing and power characteristics. The team must assess alarm visibility, EMC, thermal behaviour, battery endurance, software timing, mechanical fit and production testing—not merely confirm connector compatibility.

Configuration and change control should follow MTL-129 — Configuration and Change Management.

DISCUSSION

Questions to challenge the case

  1. What exactly is essential performance for this equipment?
  2. Which failures could leave a plausible but wrong display?
  3. Are accessories included in EMC and safety evidence?
  4. Which protective functions require independence?
  5. How is battery ageing reflected in maintenance and warnings?
  6. What must be repeated after a component or software change?