When a Test Result Becomes a Patient's Story
Imagine a patient lying in a hospital bed.
An infusion pump beside the bed is delivering medication. A monitor is displaying vital signs. A pulse oximeter is showing the patient's oxygen saturation. To the patient and family, these are simply machines helping the doctors provide treatment.
But behind every number on that screen is a chain of decisions.
Someone designed the device. Someone selected its components. Someone wrote or verified its software. Someone tested its electrical and functional performance. Someone checked whether the measuring instruments were calibrated. Someone reviewed the results. Someone documented deviations. Someone assessed the risks. Someone decided whether the device was safe enough to be released.
The patient may never know any of these people.
Yet the patient's safety depends on their work.
This is why quality in medical devices is not just about passing an audit or obtaining a certificate. It is about making sure that a device people depend on behaves as expected when it matters most.
Standards such as ISO 13485, ISO/IEC 17025, and ISO 14971 help create that chain of confidence. But their importance becomes much easier to understand when we look at what happens when quality controls work—and what can happen when they do not.
A medical device can be surprisingly complex.
Take a pulse oximeter. A person places it on a fingertip and sees a number such as 98%. It looks simple. But that number depends on sensors, light, electronics, signal processing, algorithms, software, calibration, manufacturing quality, environmental conditions, and the characteristics of the person using it.
An infusion pump may look like a small box attached to an IV line. But it is responsible for controlling the delivery of medication or fluids. Its motor, sensors, software, alarms, battery, user interface, and mechanical components all have to work together.
A radiation therapy machine is even more complex because an error in controlling radiation can have extremely serious consequences.
So the real question is not simply:
"Does the device work?"
The better question is
"Can we demonstrate, with reliable evidence, that the device performs safely for its intended use?"
That is where quality begins.
ISO 13485:2016 is the internationally recognised quality-management standard specifically developed for medical devices. It establishes requirements for organisations involved in activities such as designing, producing, installing, and servicing medical devices. ISO states that the standard helps organisations consistently meet customer and regulatory requirements related to safety and effectiveness.
The important idea here is that quality cannot simply be inspected into a product at the end.
Suppose a manufacturer discovers during final inspection that a component has been incorrectly designed. Finding the problem is useful, but it would have been much better to identify the design risk before hundreds or thousands of devices were manufactured.
That is why quality needs to begin much earlier.
Requirements have to be defined.
Designs have to be reviewed.
Risks have to be identified.
Changes have to be controlled.
Suppliers have to be evaluated.
Processes have to be monitored.
Test results have to be reviewed.
And records have to be maintained.
ISO 13485 provides a framework for managing these activities.
It does not mean that a company can simply display an ISO certificate and assume that every device is safe. A quality-management system is only meaningful when people actually follow it and when the organisation uses it to identify and control risks.
This distinction matters.
A certificate can demonstrate that a system has been assessed against requirements. It cannot replace good engineering and responsible decision-making.
What Happens Inside a Testing Laboratory?
A medical-device laboratory can sometimes look like a room full of instruments, cables, computers, probes, chambers, and test equipment.
But behind those instruments is a much bigger responsibility.
Imagine a laboratory testing a medical device for electrical safety or electromagnetic compatibility.
The engineer connects the device, selects the required test method, verifies the equipment, controls the test environment, performs the test, records observations, reviews the results, and prepares the report.
Now imagine that the measuring instrument being used has not been properly calibrated. The engineer may perform the procedure perfectly.
The report may look professional.
The numbers may appear reasonable.
But how much confidence should we have in those numbers?
This is why laboratory competence matters.
ISO/IEC 17025:2017 specifies requirements for the competence, impartiality, and consistent operation of testing and calibration laboratories. ISO explains that it allows laboratories to demonstrate that they operate competently and generate valid results.
In simple terms, the question is
"Can we trust this laboratory's measurement?"
That requires much more than having expensive equipment.
The laboratory needs appropriate test methods, competent personnel, suitable equipment, controlled environmental conditions, measurement traceability, technical records, and processes for reviewing results.
A laboratory should also be able to demonstrate what happened during a test. Which equipment was used?
Was it within calibration?
Who performed the test?
Which procedure was followed?
What were the environmental conditions?
Were there any deviations?
What was the original data?
Who reviewed the report?
These questions may sound administrative, but they become extremely important when a product is questioned later.
A test report is not just a document.
It is evidence.
Calibration is another part of this chain.
Consider a simple example.
A laboratory needs to determine whether a device produces 5 volts within an acceptable tolerance. The engineer uses a calibrated measuring instrument.
If the instrument itself has an unknown measurement error, the engineer could accept a device that actually falls outside the required range—or reject one that is actually acceptable.
Calibration helps establish confidence in the measurements produced by an instrument. But there is an important point:
Calibration does not automatically make every measurement valid.
The equipment still needs to be suitable for the application. The range, resolution, method, environment, and operator competence all matter.
This is why good laboratories treat calibration as part of a complete measurement system rather than simply as an expiry date on a certificate.
Quality is not only about asking whether something works.
It is also about asking:
"What happens if it fails?"
That is the heart of medical-device risk management.
ISO 14971 provides a framework for managing risks associated with medical devices. The FDA recognises ISO 14971:2019 as a consensus standard for medical-device risk management.
The basic idea is straightforward: identify hazards, estimate and evaluate risks, implement controls, and monitor whether those controls remain effective.
Consider an infusion pump.
What if it delivers medication faster than intended?
What if the battery fails?
What if an alarm does not activate?
What if software becomes unresponsive?
What if a component breaks?
What if a healthcare worker misunderstands an instruction?
These are not merely theoretical questions.
Each represents a possible pathway to harm.
Risk management allows engineers and quality teams to think about these possibilities before they become patient incidents.
Methods such as Failure Mode and Effects Analysis (FMEA), fault-tree analysis, hazard analysis, and other techniques can help organisations systematically examine potential failures.
The goal is not to pretend that risk can be reduced to zero.
The goal is to identify unacceptable risks and put appropriate controls in place.
One of the most powerful examples of why medical-device quality matters is the Therac-25 radiation therapy system.
Between 1985 and 1987, six known accidents involving Therac-25 resulted in massive radiation overdoses. Patients suffered severe injuries, and some died.
An investigation by Nancy Leveson and Clark Turner, published in IEEE Computer in 1993, examined the accidents and identified a combination of software, system, human, and organisational issues.
The lesson from Therac-25 is not simply "software can have bugs."
The deeper lesson is that a safety-critical medical device has to be treated as a complete system.
A device may contain functioning hardware, functioning software, trained operators, and written procedures, but the interaction between these elements can still create unexpected risks.
For modern medical-device engineers, this is an important reminder.
Safety cannot depend on assumptions.
A critical safety function should not be considered safe simply because engineers believe a particular failure is unlikely.
It needs appropriate verification, validation, risk analysis, testing, and, where necessary, independent safeguards.
The Therac-25 story is decades old, but its lesson feels remarkably modern because today's medical devices increasingly depend on software, connectivity, automated decisions, and complex user interfaces.
A Current Example: Pulse Oximeters and the Question of Who Was Tested. Now consider something much smaller: a pulse oximeter.
During the COVID-19 pandemic, pulse oximeters became familiar household devices. People used them to monitor oxygen saturation at home.
The device seems simple.
Put it on the finger.
Wait for the number.
Read the result.
But what if the device does not perform equally well for everyone?
This became an important area of scientific and regulatory attention.
The FDA has acknowledged concerns about differences in pulse-oximeter accuracy associated with skin pigmentation. In January 2025, the FDA issued draft guidance proposing updated recommendations for evaluating the performance of medical-purpose pulse oximeters across different skin pigmentation levels.
The FDA's proposed approach includes improving clinical study design, increasing the number of participants, and using both subjective and objective approaches to evaluate skin pigmentation. The agency considered laboratory testing as well as real-world performance data in developing its recommendations.
This is a powerful example of why "tested" does not automatically mean "tested under every relevant condition."
A device may perform well under controlled laboratory conditions but still need further evaluation to understand its performance across the population in which it is intended to be used.
This is not a failure of testing.
It is a reminder that good testing must ask the right questions.
The patient is not a laboratory instrument.
Real people have different skin pigmentation, circulation, temperature, movement, physiology, and other conditions.
Testing must therefore connect laboratory evidence with real-world use.
Sometimes quality issues become visible through recalls or safety corrections. These events provide a real-world look at why quality systems matter.
For example, in 2025, the FDA published a correction involving the ICU Medical Plum Duo Infusion System. The issue involved software that could potentially cause the pump to become unresponsive. The FDA classified the action as the most serious type of recall because continued use without correction could result in serious injury or death. ICU Medical sent an urgent correction to affected customers and recommended actions including identifying affected devices and quarantining them in specified circumstances.
This example is important because it shows that quality does not end when a product leaves the factory.
A device can be manufactured, tested, released, distributed, installed, and used—and a problem can still emerge later.
That is why medical-device quality must continue throughout the product life cycle.
Another FDA record from 2024 involved Baxter Spectrum infusion-pump battery modules. The recall concerned the possibility that the modules could fail to automatically document infusion status information back to a hospital's electronic medical-record system.
At first glance, this might sound like an information-technology problem rather than a medical device problem.
But in a hospital, information is part of care.
If information expected by healthcare professionals is missing or unreliable, it can affect decisions. This illustrates an increasingly important reality:
Modern medical-device safety is not only about hardware. It can also depend on software, data, connectivity, and communication.
Suppose a medical device fails in a hospital two years after it was manufactured.
An investigation begins.
The quality team needs to understand what happened.
They may ask:
Good documentation allows the organisation to reconstruct this story.
Without it, the investigation becomes guesswork.
This is why controlled documents, test records, calibration certificates, inspection reports, nonconformance records, training records, change-control records, and corrective-action records are so important.
In medical-device quality, it is better understood as the memory of the product. CAPA: Learning From What Went Wrong
No quality system can guarantee that problems will never occur.
What matters is how an organisation responds when they do.
This is where corrective and preventive action—commonly referred to as CAPA—becomes important.
Suppose a manufacturer discovers that several devices have the same failure. A weak response would simply replace the defective components.
A stronger response asks:
The purpose of root-cause analysis is to go beyond treating the visible symptom.
A good corrective action should address the cause and evaluate whether similar problems exist elsewhere.
That is how an organisation turns a failure into an opportunity to prevent another one. The Human Being Behind Every Test
Perhaps the most important part of quality is the person performing the work. Standards do not operate by themselves.
A laboratory technician has to understand the test.
An engineer has to understand the device.
A quality professional has to understand the evidence.
A calibration technician has to understand measurement.
A manufacturing employee has to follow the controlled process.
A reviewer has to be willing to question unexpected results.
Imagine a technician notices an unusual test value.
There are two possible reactions.
One is:
"It is probably fine. I will continue."
The other is:
"This result looks unusual. I need to investigate before I sign the report."
That small decision can matter.
Quality culture is created through thousands of such decisions.
A strong quality system encourages people to speak up when something does not look right. What Standards Really Give Us
It is easy to think of ISO standards as collections of clauses that organisations must satisfy for audits.
But their deeper value is much more practical.
ISO 13485 helps organisations build controlled quality-management processes around medical devices. ISO/IEC 17025 focuses on laboratory competence and reliable testing and calibration results. Risk-management principles help organisations identify hazards before they become incidents. Documentation creates traceability. CAPA creates a mechanism for learning from failures.
Together, these elements create layers of protection.
No single layer is perfect.
But multiple layers can prevent one mistake from becoming a patient incident. This is especially important because medical devices are becoming more complex.
Artificial intelligence, software, connected devices, remote monitoring, wearable technology, robotics, and automated decision-support systems are changing healthcare.
As technology becomes more powerful, the importance of quality does not decrease. It increases.
From the Laboratory to the Patient
A laboratory test may take a few minutes.
A calibration may take an hour.
A quality review may take a day.
A design investigation may take weeks.
An audit may take several days.
To someone outside the industry, these activities may seem slow compared with the speed of modern technology.
But there is a reason for the care.
The final customer of a medical device is often not simply a company or hospital. It is a person.
A patient who trusts a monitor.
A child receiving medication through an infusion pump.
A cancer patient undergoing radiation therapy.
A family member checking oxygen levels.
That human connection changes the meaning of quality.
A test report is no longer just a report.
It becomes part of the evidence that supports someone's safety.
A calibration certificate is no longer just a certificate.
It supports confidence in a measurement.
A risk assessment is no longer just a document.
It represents an attempt to anticipate harm before it happens.
A corrective action is no longer just a quality requirement.
It is an opportunity to stop the same problem from reaching another patient. Conclusion
The safest medical devices are not created by technology alone.
They are created through the combination of good engineering, competent testing, reliable measurement, risk management, controlled documentation, strong quality systems, responsible people, and continuous learning.
The Therac-25 accidents remind us that complex medical systems can fail when safety is assumed rather than demonstrated.
The continuing work on pulse oximeter performance reminds us that testing must reflect the people and conditions for which a device is intended.
Recent infusion-pump corrections remind us that quality does not stop at product release. Problems can emerge during real-world use, and organisations must be prepared to identify, communicate, correct, and learn from them.
References: