Test Disconnection as a Normal Operating Condition

Synchronization Test Plan

Companion to Medical Device Connectivity · Updated 2026-09-29

Use this to test disconnection as a normal operating condition, across the device, gateway, network, and receiving systems, before release and after any interface change. Test and integration engineers run it, with the customer’s integration team where one is available; “Test the Whole Connected System, With an Owner for Every Boundary” works it on the automated probe reprocessor. Run it for any device that journals records and sends them later: a point-of-care glucose meter that uploads to its data manager, a hemodialysis machine, a fetal monitor, or a dispensing cabinet.

Run each condition under a realistic workload, against a real gateway and at least one type of receiving system. Compare the device’s journal with what the receiving system holds. Record each result as passed, failed, or untested.

The Synchronization Test Plan: fourteen conditions, each induced on purpose.

ConditionHow to induce itPass whenResult
Packet lossDrop packets between the device and the receiver.Every journaled record is delivered at least once and takes effect once, through idempotent receipt, in recorded sequence order, with duplicates discarded by the receiver. The device shows degraded connectivity while it lasts.
LatencyAdd delay between the device and the receiver.No timeout creates a duplicate or loses a record.
Duplicate eventsReplay events the receiver has already accepted.The receiver detects each duplicate by its identifier and discards it, so each record takes effect once. Record counts match the device journal.
ReorderDeliver events out of order.The receiver stores a late event and closes the gap it fills. It derives state only from the unbroken run of sequence numbers, never from an event that arrived ahead of a gap.
Network partitionCut the link for longer than the longest expected outage.Essential function continues, the journal holds every record, and all records synchronize after reconnection, marked as delayed. Records that staff also charted by hand go through the clinician review step and are reconciled, and no record overwrites a clinician’s entry. The operator sees the offline state throughout, and the receiving system detects the silence by missed heartbeats and escalates it.
Server restartRestart the receiving server during synchronization.Synchronization resumes from the last acknowledged record. Nothing is lost, and nothing takes effect twice.
Certificate expirationLet the device or server certificate expire.The device enters its defined degraded mode, keeps journaling, and recovers after renewal with no lost records.
Clock driftSet the device clock ahead of and then behind the reference time.Each record carries the device’s time, a time-quality flag, and a monotonic counter. Time sync measures the device-to-reference offset at reconnection; nobody infers it from when delayed records arrive. The receiver flags times it can’t trust, and the device judges command expiry by monotonic elapsed time, never by its wrong clock.
Stale cacheChange reference data (a patient association, a configuration, a consumable list) while the device is offline.The device marks cached data as stale, and the receiver flags or rejects records built on it.
Full local storageFill the device’s local storage.The device alerts at its documented fill level, sheds low-value telemetry first, and keeps every safety and therapeutic record. If it can no longer journal, it says so visibly.
Gateway outageStop the gateway.The device journals and waits, then synchronizes through the gateway after restart with no lost or doubled records.
Partial updateInterrupt a software update during installation.The device returns to a known safe version with its journal intact. If the journal had to be reinitialized, the device starts a new epoch, and the receiver treats it as a new stream flagged for review, never as a gap or as duplicates.
Incompatible schemaConnect a receiver that expects a newer or older schema version.Both sides detect and report the mismatch, and records wait rather than being misread.
Power interruption during synchronizationRemove power while records are synchronizing.After restart, every journal record and its send state agree, because both were written in one atomic write. Synchronization resumes with no record lost, doubled, or corrupted.

Record a condition the team couldn’t induce as untested, never as passed. The condition can still occur in the field, and the team has no evidence of how the system behaves when it does.