Medical device usability engineering

Risk management under ISO 14971 runs across the device lifecycle. At Perdigó Medical we author the risk management plan and carry out the analyses within it: hazard identification, design and process FMEA, fault tree analysis, use-related and software risk analysis, and the risk control tracing that follows.

All Capabilities

Usability engineering at Perdigó Medical

Usability engineering addresses a device’s usability as it relates to safety: who the intended users are, what they do with the device, where a use error could cause harm, and how the design reduces that risk. The screen, the physical controls, the labelling and the instructions for use are treated as one user interface.

IEC 62366-1:2015/AMD1:2020 is the normative standard. For medical electrical equipment, however, IEC 60601-1-6 is the usability collateral standard, aligned with the same process. Risk management under ISO 14971 exchanges information with it in both directions: use-related hazards feed the risk analysis, and risk controls return as interface requirements.

We work across the full process: user research, the use specification, task analysis, use-related risk analysis, the user interface specification, the interface itself, and the formative evaluations that inform it. Records are produced as the design develops.

Integrated usability development

We design the user interface against three inputs: the use specification, the task analysis and the use-related risk analysis, each described in the following sections. The design work covers the structure of the interface, its behaviour, its appearance and its accessibility.

Information architecture and navigation: Screen inventory, menu hierarchy, navigation model and state logic, delivered as a UI flowchart. Alarm and settings access paths are specified explicitly. The flowchart is reviewed with firmware before it is frozen.

Wireframes: Low-fidelity layouts for each key screen and hardware control arrangement, produced for evaluation before graphic design begins.

Interaction design: Task flows, states, transitions, input handling and feedback. Error prevention and recovery. Confirmation steps on critical tasks. Documented as the UI behaviour specification.

Graphic design and design system: UI graphic design plus a reusable system: colour, typography, iconography, grid, component states and usage rules, aligned to your brand and to alarm colour conventions. We maintain the system as the product range develops.

Accessibility: Contrast ratios, text and target sizes, legibility at the intended viewing distance and angle, gloved and one-handed operation, colour-blind safe coding, and audible and visual redundancy where a single channel is insufficient.

Physical ergonomics and hardware controls

We design hardware controls, handles, connectors, display placement and device form for the intended users, in the postures and environments where the device is used. Reach, force, grip and cleanability are design inputs.

Anthropometric data sets the envelope. Where the device is medical electrical equipment, IEC 60601-1-6 applies the usability process to basic safety and essential performance.

Alarm and safety signal design: we design priority assignment, visual and auditory signal characteristics, information signals, alarm limits, silencing logic, and legibility at the intended viewing distance. Acoustic verification of audible alarms is arranged with an external laboratory.

Prototyping and interface implementation

We build prototypes at the fidelity each evaluation round requires: paper and wireframe for early concept work, clickable software prototypes for interaction testing, and non-functional or partly functional hardware mock-ups for simulated use.

We then programme the embedded user interface from the approved flowchart, wireframe and graphic design, and update it until UI design freeze. The interactive builds used in formative testing are produced from the device codebase.

User research and the use specification

We conduct the research in-house, including recruitment and moderation. Six methods are available, selected according to what the device and the user groups require.

Contextual inquiry and field observation: We observe and interview users in the real context of use, whether clinic, home or ambulance, to establish the actual workflow, the workarounds and the environmental constraints.

One-on-one interviews: We plan, recruit for, moderate and analyse individual sessions with clinicians, patients or carers, reported as transcript-based thematic analysis.

Focus groups: We design and moderate group discussion with representative users to explore needs and perceptions of early concepts.

Surveys and questionnaires: We build, distribute and analyse questionnaires for broad feedback from current or potential users, including standardised instruments for perceived usability and workload.

Clinical and expert advisory panels: We set up and run recurring panels of clinicians, key opinion leaders and representative users, and document their input and how it was addressed.

Day-in-the-life analysis: We map device interaction across a typical day or shift, covering set-up, use, cleaning, maintenance, storage and handover.

The use specification

The research produces the use specification: intended use and medical indication, patient population, the part of the body or tissue interacted with, an intended user profile per user group, an intended use environment per user group, and the operating principle. It is the first formal deliverable of the process and the reference for every subsequent decision.

Alongside it we produce personas and journey maps per user group, the user requirements specification, and the workflow analysis that derives the use cases.

Task analysis and critical tasks

We decompose device use into tasks, sub-tasks, decisions and user-device interactions, then identify the critical tasks, categorised by the severity of the harm a use error could cause. The selection process is documented alongside the result, and depth is set by workflow complexity. Four analyses run within it.

Perception, cognition and action: We break each critical task step into what the user must perceive, decide and do, and identify at which of the three a use error could occur. The result feeds the root cause analysis directly.

Function analysis and allocation: We identify the functions required to achieve the intended use and allocate each to the user, the device, or both, so that task boundaries and automation limits are set before the interface is specified.

Time and motion: We measure task timings and required movements under realistic conditions, to confirm the workflow fits the available clinical time and to expose steps prone to shortcuts and workarounds.

Workload assessment: We assess the cognitive and physical demand placed on the user during critical tasks, using standardised subjective instruments and observed indicators, and identify where demand is high enough to increase use-error likelihood.

Use-related risk analysis and the interface specification

The analysis runs from a characteristic of the user interface through to a written requirement, ranked by the severity of potential harm:

Interface characteristics related to safety: Every safety-related characteristic of the interface is listed with the use errors associated with it, and the primary operating functions defined by any applicable product-specific safety standard.

Use-related hazards and hazardous situations: Known and foreseeable use-related hazards, and the hazardous situations they can lead to, are identified within the risk analysis itself, conducted to ISO 14971.

Hazard-related use scenarios: A team brainstorm generates the scenarios, and each is documented: task sequence, user group, use environment, device response, potential use error, and the resulting hazardous situation. A task where use error could lead to significant harm is a critical task.

Selection of scenarios for summative evaluation: We apply a selection scheme driven by severity and by circumstances specific to your device, and record the scheme, its rationale and the results of applying it.

Use-related risk analysis: Use errors, their causes, the potential harm and its severity, the risk controls and the evidence of their effectiveness, built as a use FMEA, with fault tree analysis where the causal structure calls for it. Maintained as the design changes.

User interface specification: Each risk control becomes a technical requirement traceable to the analysis that produced it, alongside the usability requirements and any requirement on accompanying documentation and training.

UI evaluation plan: Which formative evaluations run and when, and the summative strategy: how participants represent the intended user profiles, how they are grouped for determining numbers, the test environment and its rationale, the definition of correct use per scenario, and how data is collected for later analysis.

Residual use-related risk: We prepare the evaluation and its acceptability criteria, to ISO 14971, ready to be closed out on summative evidence.

medical device engineers discussing risk management plans

Formative evaluation and use error analysis

Formative evaluation runs in rounds through development, from early concepts to near-final devices. We run it in-house.

Expert usability review: Specialists inspect the interface against recognised usability principles and against the available concepts or prototypes, and report prioritised findings with recommended changes.

Cognitive walkthrough: We step through each critical task sequence as the intended user, assessing at every step whether the user will know what to do, see the control and understand the feedback, and documenting the predicted failure points.

Formative evaluations: Each round has a stated objective and method, a protocol and task set drawn from the risk analysis, moderated sessions with representative users on prototypes, and a report recording the findings and the design changes made in response.

Simulated use: Where realism affects the result, we run sessions in a simulated use environment, using manikins, clinical props, controlled lighting and noise conditions, and multi-camera recording.

Use error and root cause analysis: We analyse observed use errors to root cause, distinguishing perception, cognition, action, labelling and training, and answer each cause with a design or documentation change.

Findings return to the use-related risk analysis and the user interface specification.

Developing a medical device?

Perdigó Medical is the specialist medical device design and development partner you can rely on. Schedule a scoping call now.

No commitment. Just clarity