Independent learning for medical-device professionals
SearchCommentaryConsulting
Learning libraryMTL-140 · GUIDED LEARNING PATHWAY

Start here: developing a medical device

Follow the decisions from intended purpose to maintenance. Build a small, connected evidence set as you learn.

One device, seven linked stages

Read the linked modules, complete each short exercise and compare your approach. Keep your answers in one notebook so the requirements, risks, design and evidence remain linked. You do not need to read the whole library before beginning.

The teaching device: a standalone syringe infusion pump

A fictional reusable, electrically powered pump delivers a clinician-programmed intravenous infusion from a compatible syringe for adult patients in a hospital. It combines a motor-driven lead screw and plunger coupling, mechanical retention, position and force sensing, an embedded controller, a local display and keys, audible and visual alarms, and mains power with battery backup.

No connectivity: no Wi-Fi, Bluetooth, network, app, cloud, remote control or external data port. All operation is local. There is no AI. Servicing requires physical access by authorised personnel.

This is an educational design brief, not a complete product specification. Intended therapies, delivery limits, alarm behaviour, service life and acceptance criteria require justified clinical and engineering input. No numerical clinical limits or universal regulatory class are assigned here.

A learning sequence, not a one-pass process

Risk management, usability, quality, configuration control and evidence planning run throughout. New findings can reopen earlier decisions. The exercises produce a learning record, not a complete design dossier or release authorisation.

Begin stage 1: intended purpose →
STAGE 1 OF 7 · INTENDED PURPOSE

Define the clinical task and its boundaries

Begin with the clinical need, intended users, patient population, environment and delivery function. Define compatible consumables and foreseeable use conditions. Identify market-specific qualification, classification and evidence questions before committing to the design.

Short exercise · 10–15 minutes

Write five sentences defining the pump’s purpose: therapy-delivery task, adult population, trained user and hospital setting, compatible syringe system, and limitations. Add two exclusions and one question needing clinical input.

Keep this output: A bounded intended-purpose statement and an assumptions list with owners.

Compare your approach

The fictional pump delivers a clinician-programmed intravenous infusion from a specified compatible syringe in an adult hospital setting. Trained healthcare professionals select and confirm the prescribed settings locally. It does not determine the prescription. Home use and paediatric use are outside this teaching scope. The clinical lead must justify the intended therapies and delivery range; those are not established by this exercise.

Ready to continue? Can another learner identify who uses the pump, for whom, where and to perform which task? Carry these boundaries into the requirements.

STAGE 2 OF 7 · REQUIREMENTS

Translate the task into measurable behaviour

Derive identifiable design inputs from user needs, risks and operating conditions. Cover delivery performance, syringe loading, local controls, alarms, power, cleaning and service. Give each requirement a rationale and verification method. Define acceptance criteria before collecting evidence.

Short exercise · 10–15 minutes

Write three requirements: prevent starting when the syringe retention mechanism is open; display and require local confirmation of the programmed rate; and respond to mains-power loss. For each, state the setup, expected result and evidence to retain. Identify performance limits still needing justification.

Keep this output: A three-row requirements table with ID, source, requirement, acceptance criterion and verification method.

Compare your approach

REQ-01: while the retention mechanism is detected as open, a local Start command shall not initiate plunger-drive motion and the display shall identify the loading condition. Test the defined open positions and retain motion and display evidence. A separate fault analysis must address incorrect sensor indications. For power loss, specify and justify continued battery operation, indication and the eventual controlled response; do not assume an abrupt stop is always safest.

Ready to continue? Are the requirements testable without inventing clinical limits? Carry the loading requirement into the risk exercise.

STAGE 3 OF 7 · RISK

Follow a failure through to patient harm

Consider mechanical, electrical, software and use-related causes of over-delivery, under-delivery, interruption or delay. Describe the sequence from hazard to hazardous situation and harm. Choose controls, turn them into design requirements and plan evidence for implementation and effectiveness. Review residual risk using defined criteria.

Short exercise · 10–15 minutes

Describe how an incorrectly retained syringe or disengaged plunger coupling could interrupt therapy. Propose two controls, explain how each interrupts the sequence, and identify a failure of each control. Add a separate risk question about occlusion and delivery after an occlusion is released.

Keep this output: One risk record with causes, sequence to harm, controls, linked requirements and evidence needed.

Compare your approach

An inadequately retained syringe can allow ineffective plunger movement, causing under-delivery and delayed therapy. Consider positive mechanical retention, detection of loading state and clear setup feedback, with a justified response to a detected fault. A switch alone may report “closed” despite incorrect engagement; test foreseeable misloading and sensor faults. An alarm requires evidence that users recognise it and respond appropriately. Occlusion detection and post-occlusion delivery require their own analysis rather than being assumed covered by the loading interlock.

Ready to continue? Can you explain why each control reduces risk and what evidence will support that conclusion? Allocate the controls in the architecture.

STAGE 4 OF 7 · DEVELOPMENT

Integrate mechanics, electronics and embedded software

Allocate functions and controls across the drive mechanism, syringe restraint, sensors, controller, power supply and local user interface. Define interfaces and tolerances. Control drawings, circuit designs, embedded-software versions, suppliers and assembly processes. Plan manufacturing and servicing while developing the product.

Short exercise · 10–15 minutes

Sketch the motor and lead screw, plunger coupling, syringe retention, position and force sensing, embedded controller, local display and keys, alarm sounder, battery and mains supply. Place REQ-01 and your risk controls on the sketch. Identify two interface assumptions and one supplier change that could invalidate them.

Keep this output: A system sketch, interface notes and a versioned baseline list.

Compare your approach

The mechanical drawing defines engagement geometry; electronics acquire the loading signal; embedded software prevents drive initiation and presents the local message. Specify how sensor states, motor commands and power transitions interact. A replacement switch with different travel or a changed lead-screw tolerance can affect the control even when the software is unchanged. Baseline the mechanical revision, PCB, embedded software, sensor calibration, compatible syringes and assembly instructions together. The pump has no external data interfaces.

Ready to continue? Does each requirement have an implementation owner, with interface assumptions documented? Use this exact baseline in verification.

STAGE 5 OF 7 · VERIFICATION

Test the system and validate its use

Verification demonstrates specified requirements; validation addresses intended use and user needs. Plan both from the beginning. Use identified samples and configurations, justified conditions and prespecified criteria. Include tolerances, ageing, power transitions and fault conditions where relevant. Record failures and their impact on the evidence.

Short exercise · 10–15 minutes

Draft a verification protocol for REQ-01, including open positions, attempted starts, motion measurement and expected display behaviour. Add one sensor-fault test and a separate user-validation scenario involving syringe loading and recovery from an alarm. Explain how you would investigate a delivery-performance failure at one operating condition.

Keep this output: One verification protocol, one representative-use scenario and a failure-investigation decision.

Compare your approach

Confirm that the identified pump does not start drive motion with the retention mechanism open and that the specified message appears. Simulate an incorrect sensor signal to evaluate the separately specified fault controls. Observe representative trained users loading the syringe and responding to the alarm without coaching. Assess delivery performance across the justified range of syringe, rate, load, power and environmental conditions; a satisfactory average does not erase an out-of-limit condition. Clinical and engineering specialists must justify the limits and test design.

Ready to continue? Does the evidence cover the actual claim and critical use tasks? Carry unresolved failures and limitations to release review.

STAGE 6 OF 7 · RELEASE

Decide whether the complete device is ready

Review the identified baseline, verification and validation, residual risks, unresolved anomalies, labelling, manufacturing transfer and service readiness. Identify accountable approvers and market-specific conditions. Internal release approval and permission to place a device on a market are distinct decisions.

Short exercise · 10–15 minutes

The pump passes nominal delivery tests, but the loading interlock fails with one tolerance combination, battery endurance evidence is incomplete and the revised loading instructions have not been validated. Decide release or hold, then assign three actions with owners and evidence required before reconsideration.

Keep this output: A release decision identifying the configuration, unmet criteria, accountable reviewers and required evidence.

Compare your approach

Hold the proposed release. Mechanical and electronics leads investigate the tolerance-related interlock failure and verify the correction across justified conditions. The power-system lead completes the battery evidence. Human-factors and clinical reviewers validate the affected loading task and instructions. Quality records the gaps and regulatory reviewers assess applicable market requirements. Define production acceptance checks, service instructions and approved component substitutions before release. A deadline or nominal pass result cannot close these gaps.

Ready to continue? Is the decision supported by evidence for the exact production configuration? Prepare maintenance arrangements before eventual release.

STAGE 7 OF 7 · MAINTENANCE

Learn from use without remote connectivity

Plan inspection, preventive maintenance, battery replacement, complaint handling, repairs and controlled changes. Obtain field information through users, service records, returned devices and periodic reviews. Keep device serial number and hardware and software configuration traceable. Assess whether emerging information changes risks, requirements or service intervals.

Short exercise · 10–15 minutes

Service reports describe increasing syringe-retention wear after repeated cleaning. Write five actions covering containment, investigation, impact assessment, controlled correction and effectiveness review. Define a monitoring measure, its denominator, an owner and how its trigger will be justified.

Keep this output: A service-and-monitoring record linked to affected devices, the risk file and a change request.

Compare your approach

Review wear findings per inspected pump, stratified by age, service history, component revision and cleaning practice. State inspection coverage: returned pumps may not represent the installed population. Preserve returned parts, assess patient impact and determine appropriate interim instructions or removal from service through responsible clinical and quality processes. Investigate material, geometry and cleaning compatibility. Verify the correction, validate affected tasks and review subsequent inspections. Any embedded-software change is performed through a controlled, manufacturer-authorised physical service process; there is no remote update or telemetry.

Ready to continue? Which risk assumptions, requirements, design details or service instructions need revision? Return to the earliest affected stage.

COMPLETE THE JOURNEY

Follow the syringe-retention evidence thread

Bring together your seven outputs: purpose statement, requirements, risk record, architecture and baseline, evidence plan, release decision and maintenance response.

  1. Purpose: deliver the prescribed infusion through the defined syringe system.
  2. Requirement: prevent drive initiation when the retention mechanism is detected as open.
  3. Risk: incorrect engagement can cause under-delivery; a misleading sensor indication needs separate controls.
  4. Design: link retention geometry, sensing, controller logic and the local message in one controlled baseline.
  5. Evidence: connect tolerance and fault tests with representative loading and recovery tasks.
  6. Release: hold until the interlock failure and other evidence gaps are resolved.
  7. Maintenance: use wear findings to reassess materials, cleaning compatibility, inspections and the affected design evidence.

Done criterion: a colleague can follow one requirement through all seven outputs, distinguish evidence from assumptions and identify each open question and its owner. A justified hold decision is a successful learning outcome.

Choose your next step