Medical Device Power Interruptions: Which State Must Survive a Restart?
Determine which medical device settings and state must survive a power dip or battery swap, derive essential performance criteria, and structure verification under the QMSR.

A medical device should retain the state needed to keep it safe and performing as intended, or detect state loss and recover through a risk-controlled process. Which route is acceptable depends on the clinical function, the applicable product standards and the consequences of delay or incorrect operation. A restart that restores the screen can still restore the wrong treatment schedule. A restart that pauses output can also be unacceptable when continuity of that function is necessary.
For manufacturers, the practical deliverable is a state-retention requirement for each safety-relevant item, linked to an observable verification result. This guide connects the public evidence to that decision and provides a template for qualified design-verification teams. It covers mains disturbances, extended outages and battery replacement as distinct scenarios; it does not prescribe a common storage technology, battery duration or clinical recovery limit.
What Counts as a Power Interruption: Dips, Short Interruptions and Outages
The IEC 61000-4-11:2020 publication record describes a common method for testing immunity to voltage dips, short interruptions and voltage variations. Its scope is equipment drawing no more than 16 A per phase on 50 Hz or 60 Hz AC networks; 400 Hz networks are excluded. IEC explains that product committees determine whether the method applies and which levels to use. The method standard alone therefore cannot choose a medical device’s acceptance criteria.
Voltage dip: a temporary reduction of supply voltage. Record residual voltage as well as duration; a dip to 70% means that 70% remains, rather than that the voltage falls by 70%.
Short interruption: loss of the supply for the selected test interval, followed by restoration. The interruption itself and the restoration can challenge different aspects of device behavior.
Voltage variation: a change in the supply level over time. Avoid treating a changing supply, repeated interruptions and a prolonged outage as interchangeable test cases.
For medical electrical equipment within its scope, IEC 60601-1-2:2014+AMD1:2020, Edition 4.1 adds electromagnetic-disturbance requirements to the general safety standard. Its public abstract describes immunity levels by equipment port and intended environment: professional healthcare facilities, home healthcare and special environments. That framework does not establish that every test has a different level in each environment. Confirm the relevant port, edition and any applicable particular standard when selecting a test schedule.
TDK-Lambda’s May 2017 article presents five AC-port dip/interruption examples for the fourth edition before Amendment 1:2020. The table below records that historical vendor summary, not a verified Edition 4.1 test schedule. The vendor’s suggested performance categories are not adopted here as end-device pass criteria.
| Residual input voltage | Duration in the 2017 vendor summary | Time calculated from cycles |
|---|---|---|
| 0% | 0.5 cycle | 10 ms at 50 Hz; about 8.33 ms at 60 Hz |
| 0% | 1 cycle | 20 ms at 50 Hz; about 16.67 ms at 60 Hz |
| 40% | 10/12 cycles | 200 ms at either frequency |
| 70% | 25/30 cycles | 500 ms at either frequency |
| 0% | 250/300 cycles | 5 seconds at either frequency |
The AMETEK CTS method summary separately shows class-based levels under IEC 61000-4-11. Its Class 2 dip row contains 0% for half a cycle, 0% for one cycle and 70% for 25/30 cycles. Class 3 includes additional conditions, including 40% for 10/12 cycles and 80% for 250/300 cycles. Both classes show a 0% short interruption for 250/300 cycles. The slash denotes 50 Hz/60 Hz cycle counts, not a duration range. These method classes should not be substituted for the applicable medical product standard’s test schedule.
The same TDK-Lambda article discusses load-dependent hold-up and modified low-voltage operation, as well as battery backup for longer interruption. Hold-up behavior depends on the supply design and load, and operation during a reduced-voltage dip can differ from operation during a zero-voltage interruption. For a particular design, measure whether the supply remains usable, whether the system resets and what the connected function does. An extended outage and an unpowered battery swap require their own risk-based scenarios; a short EMC interruption test cannot demonstrate all outage or replacement behavior.
The Pass Line Is Essential Performance, Not Total Memory
The IEC 60601-1 Edition 3.2 record identifies the general standard for basic safety and essential performance and explains that collateral or particular standards can supplement or modify its requirements. Where a particular standard exists, IEC says the general standard should not be used alone. This matters for state retention: an editorial framework cannot override a device-specific requirement for retained settings, continuity or recovery.
A manufacturer-hosted IEC 60601-1 component test report illustrates the documentation at sub-clause 11.8. On PDF page 82, the form addresses whether interruption and restoration compromise basic safety or essential performance. The entry is marked N/A for the power-supply component and deferred to an end-use investigation. It demonstrates a report-form checkpoint, not completed verification of a medical device or proof that a certified component makes its host system compliant.
FDA’s June 2022 EMC guidance recommends device-specific, quantitative and observable immunity acceptance criteria documented before testing. For the 60601 family, it connects those criteria to basic safety and essential performance identified through risk analysis. Essential performance concerns clinical-function degradation beyond specified limits that creates unacceptable risk. For transient disturbances, a risk-justified recovery interval may be acceptable. This is conditional guidance, not permission to interrupt every function or a law requiring one restart sequence.
As a planning approach, write two separate requirements: what output is permitted during the disturbance, and what state is valid when operation becomes available again. A stored therapy setting does not authorize resumption by itself. Conversely, requiring an operator to restart every device may create an unacceptable delay. Evaluate both unwanted output and loss of needed function, then specify automatic recovery, operator-mediated recovery or a protective state only where the device’s requirements support that choice.
flowchart TD
A["Identify state and its clinical use"] --> B["Check applicable standards and risk analysis"]
B --> C{"Would loss or a wrong value create unacceptable risk?"}
C -- "Yes" --> D["Define validated retention or detection and recovery controls"]
C -- "No" --> E["Justify a default or loss of state"]
D --> F["Specify permitted output and recovery time"]
E --> F
F --> G["Verify disturbance, restoration and recovered operation"]This decision process deliberately leaves the memory architecture open. The protocol should demonstrate the behavior required by the design inputs; it should not assume that a checksum, a backup cell or a shutdown routine is sufficient. A stored value can be intact but outdated, associated with the wrong session or expressed in the wrong units. State validity includes those relationships as well as whether bits survived.
A State Taxonomy: What Must Survive, What May Reset
The following six groups are an editorial inventory to help a team discover dependencies. They are not exhaustive and do not have regulator-assigned retention periods. For each item, choose a supported policy: retain a valid value; detect loss or uncertainty and follow a defined recovery path; or restore a justified default. Check the policy against applicable product requirements before accepting a reset.
1. Clinician-Set Therapy Settings and Safety Limits
Start with parameters that determine the authorized treatment or constrain its delivery. As an example to adapt, compare the pre-interruption configuration with the recovered configuration, including units, limits and its association with the intended patient or session. If re-entry is permitted, define who can perform it and what prevents use of an unverified value. The 2014 FDA home-use guidance discusses access lockouts and cautions against relying on them alone; it does not mandate a memory technology, CRC algorithm or indefinite retention.
2. Time, Date and Scheduling State
Review clocks wherever time selects an operating schedule or gives meaning to an event. In FDA recall Z-0146-2015, a faulty capacitor could cause ACCU-CHEK Spirit Combo insulin pumps to revert time and date to defaults during a power interruption such as a battery change. The pump prompted users to confirm those values, but an unnoticed default could shift a basal-rate time block. The Class 2 correction began in September 2014 and was terminated in January 2018. This is a historical hazard example, not evidence of current product risk or failure incidence.
The verification lesson is to test recognition of invalid time, not just the existence of a confirmation button. In an adapted test, initialize a non-default clock and a distinguishable schedule, then compare the selected schedule before and after the interruption. If the design allows recovery through user action, examine what the user is shown and what operation is permitted while the time remains uncertain. A prompt cannot be presumed effective from its presence alone.
3. Active Operation and In-Progress Delivery
Separate saved settings from the progress of an operation. For a hypothetical delivery device, a retained rate, a retained cumulative amount and an active command answer different questions. Decide how an interrupted session is identified, whether completed work can be distinguished from work still pending, and whether recovery could repeat or omit an action. The permitted response may be continuity, automatic recovery or a pause. Do not impose universal manual confirmation or universal automatic resumption.
4. Event, Dose and Alarm Histories
Identify which records support safe continued use, interpretation of completed work or investigation of an interruption. Define which entries must persist, how incomplete entries are represented and how the interruption affects timestamps. A useful test compares the visible history and any relevant external record with the known sequence of actions. This is a proposed verification approach; the retained evidence does not establish a universal permanent archive or a required journaling technique.
5. Calibration and Service Constants
Consider values that determine how the device interprets a signal or controls an output. An example test would compare the valid pre-event configuration and its identity with the recovered configuration, then check the associated function. Define how an invalid or missing value is detected and what use is permitted afterward. Choosing write protection, integrity checks or another control belongs to the design; this guide does not present any one implementation as mandatory.
6. Preferences and Temporary Session Data
A preference may be allowed to reset only after the team has checked its consequences. A sort order may be cosmetic in one workflow and affect interpretation in another. Brightness or volume may affect whether a user sees an important message or hears an alarm. Evaluate the default in the intended use context instead of classifying every display or sound setting as harmless. Record the reasoning for items excluded from retention testing.
| State group | Question before choosing a policy | Example observation | Basis for accepting recovery |
|---|---|---|---|
| Therapy settings | Could a changed or stale setting alter intended treatment? | Compare values, units, limits and session association. | Approved configuration or a validated re-entry path. |
| Clock and schedule | Can invalid time select the wrong operating interval? | Check time validity and the schedule actually selected. | Required time accuracy or an effective invalid-time recovery control. |
| Active operation | Could restart repeat, omit or unexpectedly resume an action? | Compare completed and pending work; observe output. | Device-specific continuity, restart and output requirements. |
| Logs and histories | Which missing or ambiguous records matter to safe use? | Compare entries and timestamps with known events. | Defined persistence and incomplete-record handling. |
| Calibration data | Could an invalid value produce misleading measurement or output? | Check configuration identity and resulting function. | Valid data or a defined protective response. |
| Preferences | Can the default affect recognition or interpretation? | Observe the interface and relevant alerts after reset. | Justified defaults under the intended conditions. |
The Interrupted-Operation, Saved-Settings and Safe-Recovery Test Matrix
The matrix below is an editorial verification template. It joins disturbance scenarios to state observations without assigning universal thresholds. Apply each relevant row to the state groups above, select the conditions from the applicable standard or justified design scenario, and enter measurable acceptance limits in the approved protocol. Extra engineering scenarios supplement the formal standard tests; they do not replace them.
| Scenario to define | State to prioritize | During the event | At restoration | After recovery |
|---|---|---|---|---|
| Selected brief zero-voltage dip; historical examples are 0.5 and 1 cycle | Active operation, session state and clock | Measure output, resets and alerts against the specified limits. | Record any reset and its effect on retained data. | Compare operation and configuration with the approved recovery requirement. |
| Selected reduced-voltage dip; choose residual level and duration from the applicable schedule | Therapy settings, active state and calibration | Observe delivered function and any protective action. | Check for an unintended mode or configuration change. | Verify valid state and required performance within the specified interval. |
| Selected short interruption; 250/300 cycles is a historical vendor example | All safety-relevant state groups | Record permitted loss of function, backup transition and alerts. | Observe whether recovery is automatic or requires action. | Verify the approved output, state and recovery-time criteria. |
| Extended outage through relevant backup or retention limits | Retained settings, clocks and required records | Observe backup operation and behavior at depletion, where applicable. | Identify missing or uncertain state and its indication. | Verify the defined recovery path and limits on operation. |
| Repeated brownout or unstable restoration; waveform and repetition justified by the design | Active commands, data updates and reset handling | Observe repeated transitions and incomplete actions. | Check for unexpected output, boot loops or invalid stored data. | Verify consistent recovery rather than acceptance of one successful restart. |
| User-replaceable battery removal; interval selected from the intended replacement process | Clock, saved settings and active session | Document the state at removal and behavior while unpowered. | Compare time, settings and session identity at insertion. | Verify detection of defaulted or uncertain data and the specified user workflow. |
Build an execution case by pairing one disturbance row with one state requirement. For example, a hypothetical scheduled-delivery requirement could identify the clock as an input to schedule selection. The case would begin with a known non-default time and schedule, apply the selected interruption, observe the actual schedule selected at restoration, and verify either valid time or the defined invalid-time response. Its permitted timing error and recovery interval must come from that device’s requirements; the table supplies neither.
Make the initial condition reproducible. Record the hardware and software versions, power mode, relevant accessories, configured state, active function and the point at which interruption occurs. Where an update or operation can be partly completed, choose interruption points that challenge the associated risk control. These are proposed case-design steps: justify the selected cases rather than treating every possible combination as a compulsory regulatory test.
Keep three observation windows in the same record: during the event, immediately at restoration and after the defined recovery sequence. A value comparison at the last window cannot establish that the output was acceptable earlier. Record the measured function, elapsed recovery time, changed data, alerts and any operator actions. Where a window is not relevant, give a reason instead of filling it with a presumed pass.
The team can cross-reference this record in its safety and EMC evidence, but that does not establish conformity to both standards. A shared protocol is useful only when it identifies the relevant clauses, uses their required methods and covers their distinct acceptance criteria. Consult the design-verification protocol guide for the general protocol structure; the distinctive work here is connecting interrupted operation to state validity.
Home Healthcare, IVD and Environment Differences
The FDA recognition entry for ANSI/AAMI HA60601-1-11:2015 including AMD1:2021 lists complete recognition under number 19-47, Recognition List 058, with an entry date of May 30, 2022. It identifies the US modified adoption of IEC 60601-1-11 and includes it in ASCA. Its home-healthcare scope applies to both lay operators and trained healthcare personnel. Recognition does not make the standard universally mandatory or establish that the unmodified IEC text is identical to the US adoption.
FDA’s 2014 home-use design guidance recommends considering backup options for AC-dependent devices, explaining outage arrangements and stating continued operating time or available procedures in the IFU. When backup is supplied, it recommends stating the expected duration. These are dated, nonbinding recommendations. The document’s older standard editions and former 21 CFR 820.30 references should not be silently treated as current-law citations.
For the proposed matrix, connect recovery observations to the intended user’s actions. Does the device indicate that power was lost? Can the user distinguish a retained setting from a restored default? Does the labeling describe the tested backup limitation and recovery process? These questions help a team examine its claims; they do not establish a universal requirement for an integral battery or prove the usability of a prompt.
For most laboratory equipment and IVDs, the 2022 EMC guidance recommends test methods from IEC 61326-1:2020 and IEC 61326-2-6:2020, with device-specific acceptance criteria. It also discusses using 60601-1-2 test levels or foreseeable environmental levels. Routing to a laboratory standard therefore does not remove the need to assess disturbance severity. Adapt the state inventory to relevant specimens, analysis progress and result validity without assuming that a therapy-device restart policy applies.
Documentation, Labeling and the Boundaries of the Evidence
The FDA QMSR page confirms that the amended 21 CFR Part 820 became effective February 2, 2026 and incorporates ISO 13485:2016. It also explains that IDE devices remain subject to design and development requirements under 21 CFR 820.10(c) and the relevant ISO 13485 provisions. Determine the requirements applicable to the device; this overview does not assign the same design-control obligations to every class or claim that QMSR mandates this matrix.
Where design verification applies, retain the executed cases within the controlled design and development records. The following is a proposed evidence chain for this power-recovery decision, rather than a required list of five document names:
State requirement: identify the item, the function it supports, its retention or recovery policy and any applicable product-standard requirement.
Risk rationale: explain what wrong, absent or stale state would do, including loss of needed function during recovery and unintended output after restoration.
Approved protocol: identify the selected disturbance, reproducible initial state, observations and measurable acceptance limits before execution.
Execution record: capture what happened at each window, the exact configuration, operator actions, anomalies and deviations. Preserve evidence for each conclusion.
User-facing claim: reconcile the tested behavior with statements about settings, battery replacement, backup duration and restarting operation.
An engineering result and a user-workflow result answer different questions. A bench record may show that invalid clock data is detected and a prompt appears. It cannot alone show that the intended user understands the prompt or takes the right action. If safe recovery depends on that action, identify the additional evidence needed for the risk control. The terminated recall illustrates why those conclusions should remain separate.
Boundaries of the Evidence and Standard Limitations
The IEC webstore records establish the cited editions and their scope; their public abstracts do not reproduce the detailed test schedules. The component report illustrates a clause checkpoint and expressly defers the end-device evaluation. The two vendor pages explain historical or method-level conditions, so they are not evidence that this article’s examples form the current mandatory schedule for a reader’s product. No original device tests or clinical performance measurements are reported here.
Before executing the template, resolve the applicable standards and editions, any specific retention or recovery requirements, and the device’s quantitative limits. Then trace each retained, detected or defaulted state to evidence. The useful outcome is a reviewable answer for each item: which state remains valid, what the device permits when validity is uncertain, and how the manufacturer demonstrated that behavior.