Human factors and use error
Designing so that mistakes are hard to make, especially at 3 a.m. by a tired caregiver. IEC 62366, use-related risk, and why watching one person set up your device without help teaches more than any spec.
You are skimming: the title, the first figure, and the short version. Switch to Read in the header for the full page, or Deep to open every deep dive.
A device that works perfectly when you use it and fails when a caregiver uses it at 3 a.m. is a device that fails. Human factorsHuman factorsDesigning so the device fits how people actually behave, especially under stress and fatigue, so that errors are hard to make. Glossary entry engineering designs for how people actually behave under stress, fatigue, and distraction, so that the wrong action is hard to take. IEC 62366IEC 62366The standard for usability engineering of medical devices, aimed at preventing use errors. Glossary entry is the standard; the FDA requires a human factors report for any device where a use errorUse errorA mistake made while using a device that the design invited, as opposed to random user carelessness. Glossary entry could cause harm. The core method costs nothing: watch someone who is not you try to use the thing, and do not help.
Use error is a design property
When a nurse programs an infusion pump with a dose ten times too high because the decimal point was easy to miss, the pump’s designers made the error easy. The term is use error, not user error, on purpose: the same person with a better display does not make the mistake. Human factors starts from the assumption that people will be tired, interrupted, and inexpert, and asks what the design does then.
The process
Identify users and use environments. The person with ALS, the caregiver, the therapist. The bedroom at night, the clinic, the car. Each pair has different capabilities and constraints.
Identify critical tasks. The steps where an error could cause harm: applying the electrodes, confirming an urgent message, stopping the wheelchair.
Analyze for use-related hazards. For each critical task, how could it go wrong? Wrong electrode in the wrong socket. Stop gesture confused with go. Volume turned to zero by accident.
Design to prevent. Connectors that fit only one way. A stop gesture that is physically different from every other gesture. Interlocks. Feedback that confirms what the device thinks happened. Defaults that are safe.
Formative evaluation. Early and often: a few representative users try the tasks while you watch and take notes. Fix. Repeat.
Summative (validation) testing. At the end, fifteen representative users per user group perform the critical tasks in a realistic environment, with no help, and every error and near-miss is recorded and analyzed. This is what the FDA reads.
You watch a caregiver set up your speller. They plug the reference electrode into the bias socket, and it works, badly. What is the correct fix?
Make the mistake impossible or make the device catch it. Labels and manuals are the weakest mitigation; the caregiver had a label and a manual and it was 3 a.m. Different connector shapes, colour-coded to sockets, or an impedance check that says “reference and bias appear swapped” are design fixes. Human factors is the discipline of preferring the design fix every time.
The observation
Ask someone who has never seen your device to set it up and use it from the written instructions. Sit where you can see their hands. Do not speak. Note every hesitation, every wrong move, every glance at the manual, every time they look at you for help. Time each step. Then ask them to talk through what they were thinking at each hesitation. One session like this reveals more than a semester of your own testing, because you cannot see your own assumptions.
Do it with the caregiver, in their home. The bedroom’s lighting, the bed’s height, the cable’s route to the outlet, and the interruptions are the use environment, and none of them exist in your lab.
Feedback and modes
Two design principles do most of the work. The device says what it did. After every action, an unambiguous confirmation: a tone, a colour, a word. A silent device is one whose state the user must guess. Modes are dangerous. If the same gesture means different things in different modes, users will be in the wrong mode. Minimize modes, make the current mode impossible to miss, and never let a safety-critical action depend on which mode you are in.
Deep dive Alarm fatigue 2 min
Hospital monitors produce hundreds of alarms per patient per day, most of them clinically meaningless, and staff learn to ignore them, which is how the important one gets missed. Any device that alarms must be designed so that alarms are rare and meaningful, with severity reflected in the sound, and with the ability to silence a nuisance alarm without disabling a critical one. Your electrode-lift alarm competes with every other sound in the room; design it accordingly.
Deep dive Accessibility is human factors for the actual user 2 min
For assistive technology the primary user has the disability the device addresses, and human factors has to be done with them: a speller tested only by sighted, able-bodied engineers has not been tested. Recruit representative users for formative testing from the start. The universal design page continues this.
Explain what this page was about to your roommate in three sentences. No jargon they would not know.