Confusing user satisfaction with use safety
A high usability score is not evidence. The question the standard asks is narrower and harder: can a representative user, in a realistic environment, make an error that hurts someone?
IEC 62366-1 is the standard for applying usability engineering to medical devices. Its purpose is safety, not satisfaction: it requires a manufacturer to identify how a device will realistically be used and misused, and to demonstrate through evaluation with representative users that use errors capable of causing harm have been designed out.
The formative and summative distinction is the part teams miss. Formative work is iterative and diagnostic — it is design research, and it is expected to change the product. Summative evaluation is a validation activity conducted on the final user interface with representative users performing hazard-related tasks. If it uncovers a new use error with safety consequences, you change the design and run it again.
For software this is closer to ordinary usability testing than most engineering teams fear. What differs is the discipline around it: the participant sampling, the task list, and the analysis of every observed difficulty have to be planned and recorded against the risk file rather than run as an informal session.
FDA’s human factors expectations, set out in its own guidance, overlap heavily with 62366-1 but are not identical. A study designed for one is usually adaptable to the other, but not automatically acceptable to it.
A high usability score is not evidence. The question the standard asks is narrower and harder: can a representative user, in a realistic environment, make an error that hurts someone?
It has to be the final user interface. Testing an approximation and then changing the product invalidates the evidence you just paid for.
Representative users means people with the actual clinical role and training level, and without your product’s implicit knowledge.
Formative evaluation runs during design. It is diagnostic, iterative, and expected to change the product. Summative evaluation is a validation activity on the final user interface, with representative users performing hazard-related tasks, producing the evidence that the design is safe in use. Finding a new safety-relevant use error in summative means fixing the design and running it again.
IEC 62366-1 does not fix a number; it expects a justified sample. FDA’s human factors guidance conventionally looks for 15 participants per distinct user group, and that figure is widely used as the benchmark in practice. Distinct user groups — clinician, patient, carer — are counted separately, not pooled.
Not automatically. FDA has its own human factors expectations that overlap heavily but are not identical, particularly around use-related risk analysis and how validation results are reported. A study designed to 62366-1 is usually adaptable to FDA, but assuming it transfers unchanged is a common and expensive misreading.
Working out how IEC 62366-1 applies to what you are building is usually the first conversation.
Get in touch →