Eleven Builder Tools Take a Device From Evidence Inventory to Release
The eleven field tools for builders of medical devices, in the order a design team uses them.
Companion to Medical Device Connectivity · Updated 2026-09-29
These are the builder tools, in the order a design team uses them: from listing the evidence the device produces to the release gate for its interfaces. The chapters work each tool on one of the book’s recurring devices, but every tool applies to any institutional device class: a magnetic resonance imaging system, a blood gas analyzer, an electrosurgical unit, an extracorporeal membrane oxygenation console, an intravenous compounding robot, a fetal monitor, or a low-temperature sterilizer. Copy them for your own design reviews and release gates. Fill in one copy per product or release. Keep each copy with the design records it informed.
- List Every Kind of Evidence a Device Produces
- Review the Architecture for Any Dependence on the Network
- Give Each Dependency Failure a Row and Four Questions
- Record Where Each of the Twelve Identities Comes From
- Write Down What the Device Means Before Choosing a Protocol
- Start the Threat Model With Every System Element
- Write Fleet Capability Into the Product Requirements
- Check Update and Rollback Before Every Field Release
- Test Disconnection as a Normal Operating Condition
- Pass an Evidence Item Only When Normal Operation Produces It
- An Interface Is Done When the Customer Can Use It Without You
In this section
- List Every Kind of Evidence a Device Produces
A table that lists every item of clinical, therapeutic, operational, and assurance evidence a device produces, where it lives, and who needs it.
- Review the Architecture for Any Dependence on the Network
An eight-layer architecture review that shows whether essential function depends on the network.
- Give Each Dependency Failure a Row and Four Questions
A worksheet that defines the degraded mode for each dependency failure.
- Record Where Each of the Twelve Identities Comes From
A matrix that models each identity a device touches, how the device learns it, and which records carry it.
- Write Down What the Device Means Before Choosing a Protocol
A worksheet that records the device’s events, states, and commands before any standard is mapped.
- Start the Threat Model With Every System Element
A starter threat model with one row for each element of the device system, including elements the manufacturer does not own.
- Write Fleet Capability Into the Product Requirements
A checklist of what a product must do so an institution can run all its units as one fleet.
- Check Update and Rollback Before Every Field Release
A release checklist for updates, including rollback, signed by software, quality, security, and field-service leads.
- Test Disconnection as a Normal Operating Condition
Fourteen induced conditions, each with a pass criterion, for testing journaling and reconnection across the whole connected system.
- Pass an Evidence Item Only When Normal Operation Produces It
A checklist of the evidence customers, surveyors, and investigators ask for, and the device event that should produce each item.
- An Interface Is Done When the Customer Can Use It Without You
A twelve-item release gate for any interface.
