home  /  biomechanical & medical device  /  device malfunction
biomechanical & medical device · forensic engineering

Medical device malfunction analysis.

An infusion pump over-delivers, a ventilator alarm never sounds, a monitor resets mid-procedure — the cause is rarely obvious from the outside, and the device itself usually holds the answer.

get started

What failed?

Start a conversation with our AI Research Concierge, already scoped to device malfunction. Pick a starting point, or describe your situation directly.

AI Research Conciergedevice malfunction · triage, not a substitute for an expert
I can help scope a device malfunction — likely mechanisms, what to preserve before the log is lost, and which expert fits. What happened?

Active medical devices fail the way most electromechanical systems fail — through a defect in software, a sensor that has drifted out of calibration, a battery that cannot deliver the current it is asked for, or a mechanical actuator that binds. What makes this category different is the stakes attached to each failure mode and the layers of evidence available to investigate it: onboard event logs, firmware build records, the FDA's MAUDE adverse-event database, and a design history file documenting what the manufacturer knew and when. The forensic question is almost never whether the device malfunctioned — the log usually settles that — it is why, and whether the same defect exists in every unit on the market or only this one.

mechanisms

How medical devices malfunction.

Active device failures trace to a handful of subsystems. Identifying which one applies determines what data and testing the investigation needs.

Firmware & software defects

Logic errors, race conditions, and state-machine faults producing incorrect dosing, output, or a failure to respond to an alarm condition.

Sensor drift & calibration failure

Pressure, flow, or optical sensors drifting out of specification over time or after a shock event, leading to under- or over-delivery.

Battery & power-management failure

Cell degradation, charging-circuit faults, or brownout conditions causing unexpected shutdown mid-therapy or mid-procedure.

Alarm system failure

Alarms that are masked, suppressed by a prior override, or never triggered because the fault fell outside the detection logic.

Electromagnetic interference

External RF or electrical fields inducing spurious commands, resets, or display errors in insufficiently shielded circuitry.

Mechanical actuator failure

Gear-train wear, occlusion-detection failure, or a pump mechanism binding — producing an output error the electronics never see.

methodology

What the evidence shows — and what we examine.

Device investigations start with the data the device itself recorded, then move to reproducing the fault under controlled conditions.

Device data & log extractionOnboard event logs, error codes, and usage histories establishing the sequence of events before the malfunction.
Firmware forensic analysisBuild-version verification, code review, and comparison against the as-manufactured configuration and design history file.
Functional & performance testingReproducing the alleged fault on exemplar or returned units under the reported operating conditions.
X-ray, CT & teardownNon-destructive and documented internal inspection of actuators, connectors, and circuit boards.
EMI/EMC susceptibility testingTesting device response to RF fields and electrical transients against IEC 60601-1-2 immunity limits.
Human factors & use-error reviewComparing the alleged use scenario against the usability engineering file and labeled instructions for use.
what's at stake

A malfunction rarely stays confined to one device.

A confirmed device malfunction routinely puts several of these in motion at once:

patient injury or death product-liability litigation FDA recall / field correction FDA MDR reporting exposure hospital & provider liability insurance subrogation

Do not reset, update, or discard the device.

A firmware update, factory reset, or battery swap can overwrite the exact event log that proves what happened. Preserve the device, its accessories, and disposables in the as-found state.

common questions

Medical device malfunctions — the questions we hear.

How do you determine whether a device malfunctioned or was used incorrectly?

The device's own event log is usually the starting point — most infusion pumps, ventilators, and monitors record programmed settings, alarms, and error codes independent of what a clinician recalls. That log is compared against the labeled instructions for use, the usability engineering file, and, where relevant, hospital biomedical-engineering records. A malfunction and a use error frequently look identical from the outside; they diverge once the internal record is read.

Can firmware be examined without the manufacturer's source code?

Yes, though the depth of analysis differs. Compiled firmware can be extracted from the device and analyzed through decompilation, behavioral testing, and comparison against known build and version records, which is often sufficient to identify the fault class. Access to source code and design history files, typically obtained through litigation discovery, allows a more precise root-cause finding rather than an inference from external behavior.

What data actually survives after a device is returned or reset?

It depends on the device and how it was handled afterward. Many devices retain non-volatile event logs, error histories, and usage counters that survive a power cycle, but a factory reset, firmware update, or battery replacement can overwrite or clear them. This is why devices should be secured and imaged as soon as a malfunction is suspected, before routine biomedical servicing touches them.

How does the FDA's MAUDE database factor into an individual case?

MAUDE aggregates adverse-event reports for a device model and can show whether a given failure mode is a recognized pattern rather than an isolated incident, which matters for both causation and notice arguments. It is a screening tool, not proof: individual MAUDE reports are unverified narratives, and a pattern in the database still has to be tied to the physical or data evidence in the specific unit at issue.

What is the difference between a design defect and a manufacturing defect in device electronics?

A design defect is present in every unit built to that specification — a firmware logic error or an underrated component selection, for example. A manufacturing defect is a deviation from the specification in a specific unit or lot — a cold solder joint, a miscalibrated sensor at final test, or a component substitution. The distinction is drawn by comparing the failed unit against the design documentation and against exemplar units built to the same specification, and it usually determines whether the exposure is a single-unit matter or a fleet-wide one.

insights

Analysis on device malfunction.

Technical briefings from our work in this area.

all biomechanical & medical device insights
related

Related specialization areas & resources.

A device malfunctioned. Find out why.

Tell us what happened. We will triage it and connect you with the right expert — usually within one business day.

failure-analysis assistanttriage · not a substitute for an expert
I can help scope a device malfunction — likely mechanisms, what to preserve before the log is lost, and which expert fits. What happened?