Test the Vendor’s Written Answers Against a Working Device
25 Questions Before Buying an Institutional Medical Device
Companion to Medical Device Connectivity · Updated 2026-09-29
Use this in the due-diligence interview for any device class whose class minimum is above Level 1, after the vendor has returned the No Connectivity, No Purchase Checklist, to test the written answers against a working device and the people who support it. HTM leads the interview, with IT, security, the clinical or process owner, and procurement in the room; “Hospitals Should Make Connectivity the Default for Institutional Device Purchases” works it on the ventilator.
Use the interview to test the vendor’s written answers to the checklist’s seventeen items. Don’t ask those items again. Put a working device in the room. Ask the vendor to show each answer on the device or its interface. Adapt the words to the device class. For a CT scanner, the association in question 9 is the patient and the imaging order. For a sterilizer or washer-disinfector, it is the load and its instruments. Record each answer in the last column:
Shown:: The team saw it on the device or its interface. Told:: The vendor described it but didn’t show it. Unknown:: The vendor couldn’t answer.
The 25 Questions Before Buying an Institutional Medical Device, grouped by theme and asked with a working device in the room.
| # | Theme | Question | Shown, told, or unknown |
|---|---|---|---|
| 1 | Workflow and fit | Which of our workflows will this device’s data enter on the first day of use, and which system receives it in each one? | |
| 2 | Show us a user completing one full task on the device. Then show us every record that task produced, and where each record went. | ||
| 3 | At sites like ours, what does a user do on this device that someone later types into another system? | ||
| 4 | Which Connectivity Maturity Model level does this device reach in our environment at go-live, and what would it take to reach the next level? | ||
| 5 | Meaning and evidence | Show us a sample record from the interface with its documentation. Point to the units, the time source, and the quality flags. | |
| 6 | How does a record show whether a value was measured, entered, inferred, or derived? | ||
| 7 | Which events does the device show on its screen or keep in memory but never send out? | ||
| 8 | How long does the device keep its local records, and what happens when its storage is full? | ||
| 9 | Identity and context | Walk us through associating this device with a patient or specimen. Then show us what happens when that association is wrong or out of date. | |
| 10 | How does the device know who is operating it at this moment, and what happens to therapy changes and alarm acknowledgment when the identity provider is down or a credential has expired? | ||
| 11 | What does the device record when an operator overrides an alarm, a limit, or a process step? | ||
| 12 | Offline behavior and failure | Disconnect the network now. Show us what continues, what stops, what the operator sees, and what the receiving system shows when this device goes silent. | |
| 13 | Reconnect it. Show us the records created while it was offline arriving in recorded sequence order, marked as delayed, with duplicates discarded by the receiver. | ||
| 14 | What happened the last time a customer lost the network or your cloud service, and what did you change afterward? | ||
| 15 | Security | Give us the current software bill of materials (SBOM), the Manufacturer Disclosure Statement for Medical Device Security (MDS2, ANSI/NEMA HN 1-2019), and the list of network ports and interfaces. Who keeps each one current? | |
| 16 | Which components in the SBOM reach end of support first, and what is your plan for each one? | ||
| 17 | How do you tell customers about a vulnerability, and how did your most recent critical fix reach installed devices? | ||
| 18 | Which of your security controls, if any, limit our access to our own device data? | ||
| 19 | Fleet and lifecycle | Show us the fleet view: every unit, its location, software version, configuration, and last check-in. | |
| 20 | Show us an update rolled out to a subset of units and then rolled back. | ||
| 21 | What does your service organization see about our devices that we can’t see? | ||
| 22 | What is the support period for this model, and how much notice do you give before end of support? | ||
| 23 | Commercial terms and exit | Which of the capabilities you’ve described need an added license, subscription, or services contract? | |
| 24 | If we connect this device to another company’s system, what support do you give, and what does it cost? | ||
| 25 | Can we speak with customers who integrated this device without your professional services? |
Treat a “told” answer as a promise. Write the promise into the contract with the Connected Device RFP Language. If the vendor won’t put it in the contract, score the capability as missing. Take every “unknown” answer back to the vendor in writing before the evaluation closes.
