home  /  insights  /  use-error-and-what-the-design-record-anticipated
Biomechanical & Medical Device

Use error, device error, and what the design record anticipated

Calling a device event operator error settles nothing. Usability engineering treats a mistake at the interface as evidence about the design, and the manufacturer's own file records which mistakes were foreseen.

July 30, 2026 · 7 min read

The short answer

Calling a medical device event operator error settles nothing. When an infusion pump delivers the wrong dose or a ventilator runs at a setting nobody intended, operator error is usually the first explanation offered: it is efficient, and it closes the file quickly. Operator error is also a conclusion that current device standards do not allow anyone to reach casually. Usability engineering treats a mistake made at the interface as a signal about the design as much as about the person, and the device manufacturer is expected to have recorded which mistakes it anticipated. That design record, rather than the recollection of a clinician working a night shift, is usually where the question is actually settled.

What this article establishes

  • IEC 62366-1, the usability engineering standard for medical devices, separates correct use, use error and abnormal use; use error is deliberately neutral and describes an outcome, not a failing, while the phrase operator error collapses all three categories, and whether an event is use error or abnormal use frequently decides the matter.
  • A medical device use specification is the manufacturer’s own statement of the conditions the device was designed to survive: if the clinician, the setting and the task fall inside it, the design was meant to accommodate them, including their fatigue, interruptions and varying familiarity; if they fall outside it, the argument shifts to labeling, training and institutional practice.
  • ISO 14971 requires hazard identification to consider reasonably foreseeable misuse, and it ranks risk controls with inherently safe design first, protective measures second and information for safety last and weakest, so a hazard controlled only by a sentence in the instructions for use invites the question of whether a design change or protective measure was practicable.
  • In discovery, the productive question about formative and summative usability evaluation is rarely whether it happened but what it found: an error observed in summative evaluation, analyzed and accepted as residual risk, leads to different arguments about notice and adequacy than an error the process never contemplated.
  • Reconstructing the keystroke sequence required to produce the recorded setting is often more informative than any recollection, and where a plausible error path is short, unremarkable and unguarded, that is a design observation rather than a character observation.
  • Many pumps, ventilators and monitors are configurable by the purchasing institution, and settings such as dose-error-reduction libraries, soft and hard limits and alarm defaults are protective measures chosen locally; that splits responsibility in a way both sides tend to underplay, and configuration records, library versions and the profile loaded on the unit establish which limits existed to be crossed.

What is use error under IEC 62366-1, and how does it differ from operator error?

Under IEC 62366-1, the usability engineering standard for medical devices, use error is an act or omission producing a different result than the manufacturer intended or the user expected, and it differs from operator error because the phrase operator error collapses three categories that IEC 62366-1 keeps separate: correct use; use error; and abnormal use, meaning a deliberate violation of reasonable use that lies outside what design can control. Use error is a defined and deliberately neutral term, not a verdict: it describes an outcome, not a failing, and IEC 62366-1 supplies vocabulary that a medical device dispute otherwise lacks.

The collapse of those three IEC 62366-1 categories into operator error does the argumentative work. Whether a medical device event sits in the second category, use error, or the third, abnormal use, frequently decides the matter.

What is a medical device use specification, and why does it matter when a clinician’s mistake is blamed?

A medical device use specification is the manufacturer’s own statement of the conditions the device was designed to survive, and it matters because it marks whether the clinician, the setting and the task were ones the design was meant to accommodate. Every usability engineering file begins with a use specification, which sets out the intended indication, the patient population, the intended user profile, the environment of use and the operating principle.

If the clinician, the setting and the task fall inside the medical device use specification, the design was meant to accommodate them, including their fatigue, their interruptions and their varying levels of familiarity. If they fall outside the use specification, the argument shifts to labeling, training and institutional practice.

Does ISO 14971 require medical device manufacturers to consider foreseeable misuse?

Yes. ISO 14971 requires hazard identification for a medical device to consider reasonably foreseeable misuse, not intended use alone. Under ISO 14971, misuse is therefore not an escape hatch for the device manufacturer; it is a category the manufacturer was obliged to think about in advance and to document in the risk file.

ISO 14971 also sets a hierarchy of risk control: inherently safe design first; protective measures such as guards, interlocks and alarms second; and information for safety, meaning labeling, warnings and training, last and weakest. A medical device hazard controlled only by a sentence in the instructions for use invites the question of whether a design change or a protective measure was practicable, and what the manufacturer’s file says about why it was not adopted.

What should discovery look for in a medical device’s formative and summative usability evaluations?

In discovery, the productive question about a medical device’s formative and summative usability evaluations is rarely whether that testing happened; it is what the testing found. The usability engineering process runs from hazard-related use scenarios, through formative evaluation during development, to summative validation with representative users under representative conditions, and each stage leaves records.

An error observed during summative evaluation of a medical device, analyzed and accepted as residual risk, is a very different posture from an error the usability engineering process never contemplated, and the two lead to different arguments about notice and adequacy.

Which medical device interface features generate predictable use errors?

Certain interface patterns recur across active medical devices as sources of predictable errors: decimal and unit entry that permits an order-of-magnitude slip, defaults carried over between patients, visually similar screens serving different modes, soft keys whose function changes with context, and confirmation steps performed so often they become automatic.

Reconstructing the keystroke sequence required to produce the setting actually recorded on a medical device is often more informative than any recollection. Where a plausible error path through the device interface is short, unremarkable and unguarded, that is a design observation rather than a character observation.

How does the purchasing facility’s configuration of a pump, ventilator or monitor affect responsibility for a use error?

The purchasing facility’s configuration of a pump, ventilator or monitor splits responsibility for a use error in a way both sides of a dispute tend to underplay. Many pumps, ventilators and monitors are configurable by the purchasing institution: care-area profiles, dose-error-reduction libraries, soft and hard limits, alarm defaults, and which parameters a user may override. These are protective measures whose settings are chosen locally.

Configuration records, library versions and the profile loaded on the unit establish which limits existed to be crossed on a particular pump, ventilator or monitor.

How do training, staffing and the environment of use bear on a medical device use error?

Training, staffing and the environment of use speak to two questions about a medical device use error: whether the information-for-safety control was actually delivered, and whether the use environment matched the device’s use specification. Manufacturer in-service records, competency assessments and the presence or absence of a designated super-user speak to whether the information-for-safety control was actually delivered.

Ambient noise, lighting, alarm burden and interruption rate speak to whether the environment in which a medical device was used matched the environment of use in the manufacturer’s use specification.

What records is a medical device manufacturer expected to keep, and what do they show about use error?

A medical device manufacturer is expected to keep design and development records, complaint files, and corrective and preventive action records, all of which are mandatory under the quality system requirement and all of which are discoverable. That quality system requirement was historically 21 CFR Part 820 and is now expressed through ISO 13485 following the QMSR transition.

Together, the usability engineering file, the use specification, the hazard-related use scenarios, the formative and summative evaluation reports, complaints describing similar difficulty, and reports made under the medical device reporting requirement at 21 CFR Part 803 show what the medical device manufacturer knew about how its device was being used before the event in question.

How are expert opinions on medical device use error challenged?

Expert opinions on medical device use error are predictably challenged on four grounds: that the reconstructed error path was inferred rather than demonstrated; that the exemplar unit was configured differently from the one in use; that the users observed in testing did not represent the actual user population; and that the environment recreated for analysis was quieter and calmer than the one in which the event occurred.

Use error work that identifies the use specification, tests against the configuration actually loaded on the device, and distinguishes what the manufacturer’s file anticipated from what it did not survives that scrutiny. An assertion that the medical device interface was confusing, offered without the manufacturer’s file, does not.

This article is general technical orientation, not a failure analysis, an engineering opinion, or advice on any specific matter. Determining the cause of a particular incident requires hands-on examination by a credentialed expert.

For informational purposes only. Not engineering or legal advice, and not an opinion on the cause of any specific failure or on the conduct of any party.

Related

The practice area

failure-analysis assistanttriage · not a substitute for an expert
Happy to. Tell me what failed, how it failed, and whether the failed part and the scene are still preserved. That last one often decides what can still be established.