12.4 Device Error vs. Use Error, Repair Prioritization & Clinical Staff Education

Key Takeaways

  • The ACI Problem Solving domain requires the technician to differentiate a device error from a use error and determine the appropriate action — a device error is a failure of the equipment to perform as designed, while a use error is an action or omission that produces a different result than the manufacturer or the user intended.
  • Use error is a design and system issue, not simply operator blame: ANSI/AAMI HE75 and IEC 62366 treat foreseeable use error as a hazard the manufacturer and the facility must control, which is why the corrective action for a use error is usually labelling, configuration, workflow or training rather than a parts replacement.
  • A No Fault Found result is a finding, not a dead end; repeated NFF returns on the same model or unit demand trending in the CMMS, review of the use environment, and escalation to the manufacturer, because the alternative is an intermittent hardware fault returning to patient care.
  • Repair prioritization is a three-axis judgment — clinical risk if the device fails or is unavailable, urgency driven by the patient and schedule, and downtime impact given available substitutes — and life-support equipment with no backup always outranks a convenience device with ten spares in the storeroom.
  • Effective in-service education is short, hands-on, scheduled across all shifts, and closed out with documentation of who attended; cross-training between HTM, nursing and IT is what converts a recurring use error into a permanently solved problem.
Last updated: August 2026

Device Error vs. Use Error, Repair Prioritization & Clinical Staff Education

Three of the eleven sub-topics in the ACI Healthcare Technology Problem Solving domain are not about circuits at all. They require the technician to:

  • "Prioritize repairs of medical devices based on level of risk, urgency, and potential downtime."
  • "Differentiate between a device error and a use error to determine appropriate action."
  • "Provide education to staff on proper use of equipment and can effectively communicate verbally and in writing with, including but not limited to, clinicians, other hospital personnel, and manufacturers about technical issues and projects (in-service or cross-training)."

These are examinable, and they are the skills that most distinguish a certified technician from a competent bench repairer.


1. Device Error versus Use Error

Definitions worth memorizing.

  • A device error (malfunction) is a failure of the equipment to perform according to its specification: a component has failed, firmware has faulted, calibration has drifted outside tolerance, or a mechanism has worn beyond its limit. The device did not do what it was designed to do.
  • A use error is, in the language of IEC 62366 and ANSI/AAMI HE75, an act or omission of an act that results in a different medical device response than intended by the manufacturer or expected by the user. The device did exactly what it was designed to do, in response to what it was told.

The older term "user error" has been deliberately retired by human-factors standards, and the reason matters. Calling something user error implies blame and ends the investigation. Calling it use error frames it as a predictable interaction between a human and a design, which means it can be engineered out. A pump whose secondary infusion requires an undocumented head-height difference, or a monitor whose alarm limits silently reset on discharge, will generate use errors from competent, careful clinicians indefinitely until something about the design, configuration, labelling or workflow changes.

A third category sits between them: system or process error — the right device, used correctly, but supplied with the wrong disposable, connected to the wrong gas outlet, running an out-of-date drug library, or placed in an environment it was not designed for.

Distinguishing them at the bedside

EvidencePoints toward device errorPoints toward use error
Device self-test / diagnosticsLogged internal fault codesClean logs, normal self-test
ReproducibilityFault reproduces on the bench, independent of operatorOnly occurs with certain staff, shifts or workflows
Event logSensor or subsystem failure entriesSequence of legitimate keypresses producing the outcome
Performance verificationMeasured output outside toleranceAll parameters within tolerance
Population patternOne serial number repeatedlyMany units, one unit, one workflow
ConsumablesCorrect set, correct lotWrong set, expired, third-party, or reused

The investigative discipline. Before you touch a tool, preserve the scene. For any event involving patient harm, the device, its disposables, its settings and its packaging are quarantined, not cleaned and reset. Then interview the user — not to assign fault, but to reconstruct the exact sequence: what was displayed, what was pressed, what was connected, what alarm sounded. Then download the event log. Only then bench-test.

No Fault Found is a finding

Roughly a fifth to a third of clinical returns in many departments test clean. A No Fault Found (NFF) disposition is legitimate, but it is only acceptable when it is documented and trended. One NFF is noise. Three NFF returns on the same serial number, or a pattern across one model or one unit, is data. The three real explanations are:

  1. An intermittent hardware fault that does not reproduce on the bench — the most dangerous, because the device goes back to a patient.
  2. A use error or unmet expectation — the device works as designed but not as the clinician expected.
  3. An environmental or system interaction — RF interference, a network fault, an incompatible consumable, a power quality problem, something that exists on the unit but not in the shop.

Trending NFF in the CMMS by model, unit and reported symptom is how those three get separated. Where a use error is identified, the corrective action is an in-service, a labelling change, a default-configuration change or a workflow change — and that action goes in the work order, so the loop is closed and auditable.


2. Prioritizing Repairs: Risk, Urgency and Downtime

On any given morning the queue exceeds the hours available. Prioritization is a defensible, repeatable judgment across three axes.

Axis 1 — Clinical risk. What is the consequence if this device fails or stays unavailable? This is the same logic as the equipment risk scoring used to build the maintenance inventory: life support and therapeutic delivery outrank diagnostic, which outranks analytical, which outranks patient-related and support equipment.

Axis 2 — Urgency. Is a patient waiting right now? Is a case scheduled? Is the department at its last working unit? A defibrillator failure in an ED with three others available is a different problem from the same failure in a standalone clinic.

Axis 3 — Downtime impact. How many substitutes exist, how fast can one be deployed, and what does the absence cost clinically? A ventilator with a fleet of twenty spares is a lower-priority repair than a single unique piece of equipment on which a service depends.

A practical triage grid:

PriorityDefinitionTarget responseExamples
P1 — EmergencyLife support in use or no backup; any device involved in patient harm; a safety hazardImmediate, drop everythingVentilator in use, only defibrillator on a unit, device with a smoke or shock event
P2 — UrgentClinical operations impaired; procedure delayed; last unit in serviceSame shiftSole anaesthesia machine for tomorrow's list, telemetry central down
P3 — RoutineFailed device with adequate substitutes available24–72 hoursOne of twelve infusion pumps, an exam-room otoscope
P4 — ScheduledPM, upgrades, cosmetic, non-urgent modificationsPlanned windowAnnual PM, firmware campaign, cable replacement

Two rules cut through most arguments about priority:

  • A device involved in a patient-harm event is never "repaired first and investigated later." It is quarantined, exactly as received, pending investigation and possible regulatory reporting. That takes precedence over restoring the device to service.
  • A safety hazard outranks an availability problem. A device that is working but unsafe — visible shock hazard, damaged mains cord, failing electrical safety, a defeated interlock — comes out of service immediately even though nobody has complained.

Communicate the priority you assigned. Most HTM/nursing friction is not about the repair time; it is about the clinical unit not knowing where their device sits in the queue. A one-line update — "P3, parts ordered, expect Thursday, two loaners delivered" — resolves most of it.


3. Educating Staff and Communicating Technical Information

The outline requires you to educate staff and to communicate effectively, verbally and in writing, with clinicians, other hospital personnel and manufacturers.

In-service education that actually works.

  • Short and specific. Ten focused minutes on the two behaviours that are causing the problem beats a forty-minute product overview nobody remembers.
  • Hands-on. The clinician performs the action on the actual device. Watching a slide is not training.
  • Scheduled around clinical reality. Shift change, and repeated across all shifts including nights and weekends. Training only the day shift guarantees the problem returns at 02:00.
  • Tied to the observed error. "Three pumps came to us last month with the cassette seated incorrectly; here is how to confirm the seat" lands, where a generic overview does not.
  • Documented. Date, topic, device model, attendees, trainer. Accreditation surveys ask for competency and training records, and the record is also your evidence that a use error was addressed.

Cross-training is the durable version of the same idea. HTM teaching nursing what an alarm code actually means, nursing teaching HTM how the device is used at three in the morning, and IT and HTM teaching each other where the boundary between a network fault and a device fault falls — these permanently reduce both false service calls and missed real faults.

Written communication is a clinical and legal artifact. The service record is discoverable. Write measurements, not adjectives:

Weak: "Checked pump, seems OK now, returned to service."

Strong: "Reported intermittent downstream occlusion alarm. Event log shows 6 occlusion alarms in 48 h, all on the same channel. Bench test with calibrated pressure source: alarm threshold measured 23.5 psi against a 10.0 ± 2.0 psi specification. Performed multi-point force-transducer calibration at 0/5/10/15 psi; post-calibration threshold 10.2 psi. Flow accuracy verified at 100 mL/h, −1.1% error. Electrical safety: protective earth 0.08 Ω, chassis leakage 19 µA NC / 142 µA SFC. Returned to service; PM label applied. Unit educated on cassette seating (4 RNs, 2026-08-15)."

Communicating with manufacturers. Come with data, not adjectives: model, serial, software revision, exact error codes, event-log extract, the conditions that reproduce the fault, and what you have already eliminated. Ask directly whether the failure is a known issue with a service bulletin, whether a field modification exists, and whether the event meets the manufacturer's reporting criteria. Log the case number in the CMMS work order. If the event involved death or serious injury, the facility's reporting obligation under 21 CFR Part 803 is independent of whatever the manufacturer says.

Test Your Knowledge

Four smart infusion pumps from the same oncology unit are returned in one month with the complaint "runs dry and alarms early." All four pass full bench verification, event logs show only legitimate keypresses, and flow accuracy is within specification. Pumps of the same model on other units show no such returns. How should the technician classify and act on this?

A
B
C
D
Test Your Knowledge

A technician is holding four open work orders at the start of a shift. Which should be worked first?

A
B
C
D
Test Your Knowledge

Human factors standards such as IEC 62366 and ANSI/AAMI HE75 deliberately use the term "use error" rather than "user error." Why does this distinction matter to a CBET performing an incident investigation?

A
B
C
D
Test Your Knowledge

Which service-record entry best satisfies both the technical and the legal purpose of HTM documentation after correcting a drifted occlusion alarm threshold?

A
B
C
D