How to debug intermittent symptoms during medical EMC tests
A medical device that resets once during a three-minute RF dwell is harder to diagnose than one that fails continuously. The disturbance may last milliseconds, while the visible symptom appears several seconds later.
Intermittent EMC symptoms demand more than repeated testing and visual observation. You need synchronised evidence from the disturbance source, equipment under test, power rails, communications and software state, without adding instrumentation that changes the coupling path.
Why intermittent EMC symptoms are difficult to isolate
Marginal immunity failures often sit at the boundary between analogue behaviour, digital timing and software recovery. A disturbance may perturb a sensor input without immediately exceeding an alarm threshold. It might corrupt one transaction, delay a task, increment an error counter or push an analogue-to-digital converter into saturation. The watchdog reset then occurs later, after a queue fills or a control loop misses several deadlines.
That delay encourages the wrong diagnosis. Engineers understandably focus on the disturbance frequency present when the visible symptom appears, even though the initiating event may have occurred during an earlier dwell, modulation cycle or transient application.
Medical equipment adds another layer. The assessment should address basic safety and essential performance as defined for the particular device, not simply whether its display remains illuminated. A temporary communication loss might be acceptable in one architecture but unacceptable where it prevents delivery of a risk control or delays a clinically significant alarm.
IEC 60601-1-2 provides the EMC framework commonly used for medical electrical equipment and systems, while product-specific or particular standards may impose additional conditions. The current editions, amendments, test levels, frequency ranges, operating modes and performance criteria must be checked against the product scope and intended electromagnetic environment. A generic immunity sweep cannot establish suitability for every medical application.
Define the symptom before changing the hardware
Start with a precise failure signature. “The unit glitched” is not actionable. Record whether the event was a processor reset, watchdog intervention, brownout, corrupted measurement, frozen user interface, communication timeout, false alarm, actuator interruption or loss of stored configuration.
Define the recovery path as well. Did the device recover automatically? Was operator intervention needed? Was basic safety or essential performance affected? Did the event leave a persistent diagnostic record? These distinctions determine both the engineering priority and the evidence required for the medical device risk-management process.
Before opening the enclosure or fitting ferrites, preserve the initial configuration:
- Hardware and firmware revisions, including bootloader and programmable logic versions
- Power supply, battery state and connected accessories
- Cable types, lengths, routing, terminations and unused-port treatment
- EUT operating mode, loads, patient simulators and representative peripherals
- Disturbance method, level, modulation, polarity, dwell and application point
- Observed symptom, timestamp, recovery and operator actions
Without that baseline, a successful retest may only show that the setup changed.
Build logging that survives the disturbance
Useful logging must capture causes, not merely report that a reboot occurred. Store reset-cause registers, watchdog source, task heartbeat status, exception information, supply-monitor flags, communication errors and selected application-state variables. Where practicable, place the record in retained RAM or non-volatile memory using a write strategy that cannot corrupt the entire log if power collapses mid-write.
Time resolution matters. A one-second software timestamp is inadequate when an electrical fast transient burst, ESD event or communication upset develops over a much shorter interval. Conversely, high-rate logging can itself alter processor loading, bus traffic and interrupt latency. That can either reveal a timing weakness or conceal it.
A ring buffer is often preferable to continuous external streaming. It preserves pre-trigger context and avoids making a USB, Ethernet or serial logging cable the dominant RF coupling path. Freeze the buffer when a watchdog precursor, brownout flag, missed deadline or implausible measurement occurs.
External monitoring still has value, but use it deliberately. Fibre isolation can reduce unintended conductive coupling. Battery-powered loggers may help, provided their grounding, probe capacitance and enclosure are understood. An oscilloscope protective-earth connection attached casually to an isolated secondary circuit can create a new common-mode return path and materially change the test response.
Correlate software events with the applied disturbance
The EUT log, immunity generator record and video should share a usable time reference. A spare EUT output can toggle at the start of an internal error condition, while a monitored generator trigger or amplifier control signal marks disturbance timing. The aim is not metrology-grade clock synchronisation. It is to determine whether the first abnormal event preceded the visible reset by microseconds, milliseconds or several dwell periods.
Video is underrated. Frame-by-frame review can reveal the first display artefact, relay transition or alarm indication, especially when the operator notices only the eventual reset. Keep the device, relevant indicators and test-controller display in view where laboratory rules permit.
Separate reset, lock-up and data corruption mechanisms
A watchdog event does not prove that software is the root cause. RF may disturb an oscillator, power-management IC, external memory, reset supervisor or communication interface. Software then reacts correctly to a hardware fault by timing out.
Probe reset, regulated rails, clock validity and watchdog servicing where access is safe and does not invalidate the setup. Use high-impedance, low-capacitance probes with the shortest practical return connection. An unnecessarily long ground lead adds inductance and can both pick up the applied field and misrepresent a fast rail excursion.
Look for sequencing. A supply dip followed by reset assertion points in a different direction from reset assertion on an apparently stable monitored rail. Do not assume the oscilloscope has captured every local disturbance. A rail measured at the regulator can look clean while a processor supply pin suffers a short drop across a ferrite bead, via field or poorly placed decoupling network.
Data corruption needs similar discipline. Add range checks, sequence numbers, cyclic redundancy checks and freshness indicators at subsystem boundaries. If an RF disturbance corrupts a sensor frame but the software accepts it as valid, the visible output may look like an analogue susceptibility problem when the actual weakness lies in digital integrity handling.
Watch for sampling aliasing and beat effects
Aliasing can make a continuous RF disturbance appear intermittent. Rectification in an analogue front end can produce a low-frequency component, while interaction between modulation, sampling frequency, multiplexing and digital filtering can create a repeating beat pattern. The resulting error may cross a software threshold only occasionally.
Capture raw samples where possible, not just filtered display values. Compare the symptom period with the ADC sampling rate, channel scan period, control-loop interval and applied modulation. Small changes to sample timing or disturbance frequency can alter the beat pattern dramatically. That sensitivity is diagnostic evidence, although changing timing is not automatically an acceptable production fix.
Also check for saturation and slow recovery. An amplifier driven beyond its input range may take far longer to settle than the RF exposure that caused it. Software can then encounter stale, clipped or implausible data after the disturbance has moved to another frequency.
Use controlled perturbations, one at a time
Once the failure is repeatable enough to study, change one variable per run. Reduce the level only as needed to obtain a stable failure probability, then investigate frequency, modulation, cable orientation, grounding, load state or application point.
Temporary fixes are diagnostic tools. A clamp ferrite may indicate common-mode cable current. Local shielding over a processor or analogue front end can distinguish enclosure coupling from cable coupling. Additional decoupling may expose a power-distribution weakness. Keep leads short and document every change. A loosely fitted shield or long capacitor connection can produce misleading results through its own parasitics.
Near-field probes and current probes can help locate resonant paths during pre-compliance investigation, but their readings are comparative engineering data unless the method defines a calibrated measurement. Do not confuse a local probe response with formal radiated or conducted immunity test levels.
Typical scenario
Consider an illustrative mains-powered patient-monitoring device undergoing radiated RF immunity testing. During one part of the sweep, the displayed measurement freezes briefly. Roughly two seconds later, the watchdog resets the processor. The event occurs on some sweeps but not others.
The team first reproduces the original cable layout, patient simulator, operating mode and dwell sequence. Firmware logging shows that an external sensor interface stops delivering valid frames before the watchdog event. Raw sample capture then reveals periodic corruption whose timing changes with small frequency steps, suggesting interaction between RF demodulation, interface timing and software timeout handling.
The likely test setup includes the appropriate radiated immunity system, field monitoring, a representative support arrangement and non-intrusive EUT observation. If conducted RF immunity is also being investigated under IEC 61000-4-6 as called up by the applicable product standard, a CDN or another method permitted by that test plan would be selected for the relevant port. A LISN would not be used for that immunity test because its role is conducted emissions measurement on applicable power ports.
Selecting the wrong coupling device or allowing diagnostic cables to bypass the intended test arrangement can produce false confidence. Early investigation at an accessible pre-compliance setup gives the team time to compare cable filtering, interface protection, firmware recovery and PCB changes before committing to a formal programme.
EMC Hire can support this work through medical device EMC testing support, equipment selection, on-site investigation and access to an EMC laboratory hire facility. Where appropriate, the same engineering trail can inform later formal testing, technical file records and the manufacturer’s conformity assessment work. Pre-compliance results improve confidence but do not, by themselves, prove compliance.
When to Hire EMC Equipment
Hiring is often the rational choice when intermittent EMC symptoms require two weeks of concentrated debugging rather than permanent internal test capacity. It avoids capital expenditure on generators, amplifiers, antennas, coupling networks, monitoring equipment or analysers that may not suit the next programme.
A defined rental window can cover a prototype sprint, formal-test preparation or an unexpected failure investigation. It also avoids long-term storage, servicing and calibration overheads, while allowing capability to scale during project peaks. This is particularly useful when a team needs a specific CDN, ESD simulator, transient generator, current-injection arrangement or measurement receiver for one applicable method.
Equipment selection still needs engineering review. Frequency coverage, output capability, coupling accessories, software control and EUT power ratings must match the current test plan. Buying an apparently versatile instrument without checking these details can leave the business owning an expensive system that cannot support a future product family.
EMC Hire uses test equipment with calibration traceable through an appropriate ISO/IEC 17025 accredited calibration provider. Suitable traceable calibration supports measurement accuracy, repeatability, comparison between development and formal testing, and a stronger evidence trail for engineering, corporate or regulatory review.
Teams can also review the available EMC test facility overview when deciding whether equipment hire, laboratory access or on-site support best fits the debugging plan.
Common EMC Testing Mistakes to Avoid
Adding a logging cable without repeating the baseline
A copper debug cable can become an efficient antenna or common-mode return path. If the symptom disappears, the cable may have detuned the system rather than improved diagnosis. Repeat the baseline after every instrumentation change.
Recording only the final reset
The watchdog is often the last event in a chain. Without pre-trigger logging of rail flags, interface errors and task timing, engineers may modify watchdog settings while leaving the initiating susceptibility untouched.
Changing cable routing between runs
Small routing changes alter induced current and coupling into enclosure seams or PCB references. A marginal failure can appear random when the actual uncontrolled variable is cable geometry.
Testing an unrepresentative operating mode
An idle processor, inactive radio or disconnected sensor does not exercise the timing, loading or port activity present in clinical use. The resulting pass may provide little evidence about the risk-relevant configuration.
Ignoring detector and bandwidth settings during emissions follow-up
If an immunity fix is followed by conducted or radiated emissions checks, the receiver settings must match the applicable emissions standard and frequency range. Peak, quasi-peak and average detectors are not interchangeable, and neither are their specified resolution bandwidths. Incorrect settings can hide a new emission or create an apparent failure.
Failing to preserve complete records
Photographs, cable positions, firmware versions, disturbance parameters and EUT modes are part of repeatability. A report that says only “reset at RF” cannot support later design review, risk assessment or a defensible technical file.
Frequently Asked Questions (FAQs)
Should the watchdog be disabled during immunity debugging?
Usually not as the only test condition. Disabling it may reveal the lock-up mechanism, but it also changes recovery behaviour and can remove a risk control. If engineers run a diagnostic build without the watchdog, they should label it clearly, record the deviation and repeat relevant testing with production-intent firmware.
How many repetitions are enough for an intermittent failure?
There is no universal number. Use enough controlled repetitions to estimate whether a change has materially affected occurrence, while recognising the limits of a small sample. Record passes and failures against identical conditions rather than relying on recollection.
Can oscilloscope probes invalidate a medical EMC test?
They can alter it. Probe capacitance, loop area, earth connection and cable routing may change both local impedance and RF coupling. Use the least intrusive method available and compare instrumented behaviour with the documented baseline.
Does passing pre-compliance testing establish IEC 60601-1-2 compliance?
No. Pre-compliance testing supports debugging and planning. Formal evidence depends on the applicable standards, complete configuration, documented performance criteria and the manufacturer’s chosen conformity route. See EMC Hire’s overview of medical device EMC compliance for further context.
What should go into the technical file after an intermittent failure?
Retain the failure description, investigation records, test configurations, calibrated data, design changes, verification results and links to risk-management decisions. The manufacturer or responsible economic operator should confirm the applicable legislation, latest standards, documentation obligations and Declaration of Conformity requirements.
When might an appropriately accredited laboratory be required?
That depends on regulatory, contractual, customer and programme requirements. EMC Hire can provide pre-compliance engineering and compliance testing for self-certification applications where accredited testing is not specifically mandated. Some medical, defence, automotive or aerospace programmes may require final work from an appropriately accredited laboratory.
Plan the investigation before the next test slot
Limited chamber time rewards preparation. Define the failure signature, implement disturbance-tolerant logging, prepare production and diagnostic firmware, identify safe probe points and agree the sequence of controlled changes before testing begins.
EMC Hire’s engineering team can help review the test method, select suitable hire equipment, arrange on-site testing, support pre-compliance investigation or discuss formal compliance testing where appropriate. Space can also be booked at the EMC Hire test facility.
To discuss intermittent EMC symptoms in a medical device programme, request an equipment hire quotation or plan a focused debugging session, call +44 (0)1462 817111 or email sales@emchire.co.uk.
Disclaimer: Content is for informational purposes only and does not constitute formal engineering or regulatory advice. Always verify testing procedures against current official standards (e.g., ISO, MIL-STD, DEF STAN). EMC Hire Limited accepts no liability for outcomes resulting from the use of this information.