A maintenance calendar is a promise about dates
A preventive maintenance calendar is a promise about dates, and the only version that matters is the one that gets kept. Most hospitals can produce a schedule. Far fewer can show that the schedule was executed on time, by whom, with what result, and what happened to the devices that were missed. The gap between those two things is where accreditation findings live. Build the calendar backwards from the evidence requirement and you will design something quite different from a spreadsheet of due months.
Start by separating three activities that get routinely conflated. Planned preventive maintenance is a scheduled intervention on a working device to keep it working. Calibration is a comparison against a traceable reference to establish measurement accuracy. Safety testing, such as electrical leakage measurement, checks that the device is not itself a hazard. A single visit may perform all three, but they carry different frequencies, different pass criteria, and different records, and merging them into one calendar line destroys your ability to prove any of them separately.
The calendar should be a live artefact with four states per task: due, in progress, completed, and deferred with a reason. The deferred state is the one hospitals leave out, so overdue work silently becomes invisible work. A deferral with a named approver and a review date is a defensible management decision that an assessor will accept. A task that quietly rolls forward from month to month with no record of the decision is simply a finding waiting to be written.

Setting frequency from criticality, not from the manual alone
Manufacturer manuals give you a starting frequency and should never be the only input. A manual is written for average use in an unspecified environment. Your defibrillator in a busy emergency department, your suction units in a coastal hospital with salt-laden air, and your ventilator fleet running continuously through a respiratory season are not average use. Frequency should move up from the manual wherever use intensity, environment, criticality, or your own recorded failure history says it should, and the reasoning should be written next to the interval.
A workable structure is three bands. Life-support and high-criticality devices such as ventilators, defibrillators, anaesthesia workstations, infant warmers and dialysis machines sit on a short cycle, typically quarterly or half-yearly, with user function checks between visits. Devices whose failure delays care without endangering it sit on a half-yearly to annual cycle. Devices whose failure is an inconvenience sit on annual. Then override the band with evidence: if a device family generated four breakdowns last year, its frequency is wrong whatever band it occupies.
Assessors under the NABH facility management standards routinely ask why a particular interval was chosen. A reference to the manual is a weaker answer than a statement that the manual specifies annual, that you perform half-yearly because this fleet runs in the ICU, and that three failures occurred in eighteen months. The second answer also happens to describe how a maintenance programme improves. A frequency set once at commissioning and never revisited is a programme running on inertia rather than on evidence.
Inputs that should push a maintenance frequency upwards
- The device supports life directly or is used in emergency response
- Recorded run hours or cycle counts well above typical use
- An environment with dust, humidity, salt air or unstable power
- Two or more breakdowns of the same fault type within a year
- A manufacturer field safety notice or CDSCO alert on the model
Scheduling around clinical use instead of against it
The single biggest cause of maintenance slippage is that the technician arrives when the device is in use. Clinical staff will always, and correctly, prioritise the patient in front of them, so a calendar that ignores clinical rhythm simply will not be executed. Scheduling has to be negotiated at department level: theatre equipment during the planned maintenance day or the gap between lists, ICU devices against the unit rotation of spare units, imaging during the downtime the department already blocks for its own housekeeping.
That requires float in the fleet. If the ICU has twelve ventilators and needs twelve, maintenance cannot happen without a clinical compromise, and the compromise will always be resolved against the technician. A fleet sized at operational need plus a modest buffer is what makes the maintenance programme executable at all, and that buffer is a maintenance cost appearing in the capital budget. This argument has to be made at purchase time, because it is impossible to make retrospectively once the money is spent.
Publish the month schedule to nursing in charge and department heads in the first week rather than turning up unannounced. Ask them to flag the dates that will not work, and reschedule inside the month rather than pushing to the next one. In practice a fifteen-minute planning conversation with each critical area removes most of the friction, and it converts planned maintenance from something done to a department into something agreed with it. The completion rate moves accordingly.

Making a monthly maintenance plan land with clinical areas
- Circulate the month device list to each unit in the first week
- Agree fixed maintenance windows for theatres and imaging in advance
- Confirm a spare or loaner exists before taking a device down
- Record who from the unit released the device, and at what time
- Reschedule inside the month rather than deferring to the next
Calibration traceability and what makes a certificate usable
Calibration is only meaningful if the instrument used to calibrate is itself traceable to a national standard. In India that chain normally runs through an NABL-accredited calibration laboratory and ultimately to the national standards maintained by CSIR-NPL. A certificate that does not name the reference standard used, that reference standard own calibration validity, and the measurement uncertainty is a piece of paper rather than a traceability record. Ask a prospective calibration vendor for a sample certificate before you appoint them, not after the first cycle.
Decide which parameters on which devices genuinely need calibration, because calibrating everything is expensive and calibrating nothing is indefensible. The usual list covers devices whose numerical output drives a clinical decision or a dose: infusion and syringe pumps, defibrillator delivered energy, anaesthesia and ventilator volumes and pressures, patient monitor parameters, laboratory pipettes and analysers, autoclave temperature and pressure sensors, and the temperature monitoring on blood bank and pharmacy refrigerators. Anything measuring for the record needs to be right.
Then manage validity as actively as you manage the maintenance calendar. Certificates expire, and an expired calibration on a device still in clinical use is a straightforward finding. Keep expiry as a field in the asset record with an alert window generous enough to arrange the vendor, typically six to eight weeks where equipment has to leave the hospital. Attach the certificate itself to the asset record. Certificates filed only in a quality department folder are reliably the ones nobody can find on the day.
What a usable calibration certificate must show
- Unique certificate number, date of issue and validity period
- Device identity by serial number, not merely make and model
- Reference standard used and its traceability to a national standard
- Measurement uncertainty and the acceptance criteria applied
- Named signatory and the accreditation scope of the laboratory
Logging breakdowns so that root cause becomes visible
A breakdown log recording only date, device and the word repaired tells you nothing you can act on. Capture the fault as reported by the user, the fault as found by the technician, a cause category, the parts consumed, and the clinical downtime in hours. The gap between reported and found is itself informative. A high rate of calls closed with no fault found almost always signals a user training issue or an accessory problem rather than a device problem, and training is far cheaper than replacement.
Use a small fixed set of cause categories and resist the urge to expand it. Wear and tear, user handling, accessory or consumable failure, power or environment, software or settings, and inherent defect will classify almost everything you see. Free-text causes cannot be aggregated, and a list of thirty categories is a list nobody applies consistently. Review the distribution quarterly. A shift towards user handling is a training plan. A shift towards wear and tear concentrated on one model is a replacement plan.
Feed that analysis back into the calendar, which is the step most often skipped. If a specific fault recurs on a specific model, then either the frequency is wrong, the checklist is missing a task, or the device has reached the end of its useful life. All three are actionable. All three are invisible if breakdowns and planned maintenance sit in separate systems that nobody reads together. This closed loop is the difference between a maintenance programme and a repair service that happens to keep records.

The evidence trail an assessor actually opens
An assessor rarely asks for the whole programme. They pick devices, usually from the highest-risk areas, and follow them. The pattern is consistent. They stand next to a ventilator in the ICU, read the maintenance label stuck to it, and ask to see the record behind that label. So the label has to be current and it has to lead somewhere. A label showing a last-done date that predates the interval written into your own policy is the fastest finding available to anyone walking a unit.
Then they ask for the programme document that explains why that device sits on that frequency, the completion rate for the last cycle, the list of overdue items with reasons and approvers, and the competence record of the person who signed the work. That last one catches hospitals out repeatedly. If a technician signs a maintenance record for an anaesthesia workstation, there should be evidence that the technician was trained on that device family, whether by the manufacturer, by an internal programme, or by qualification.
The tidiest way to survive this is to keep the whole trail in one place and let it be pulled by device rather than by month. Whether the asset record lives in a dedicated maintenance module, in HealUDoc alongside the department that owns the device, or in a genuinely disciplined shared drive matters less than whether one person can produce the full history of one serial number in under two minutes without telephoning anybody.
“The assessor did not audit our calendar. She picked three ventilators and one defibrillator and asked to see everything about them. That is the test now, and it is a much harder one to pass with a spreadsheet.”
How maintenance programmes decay, and how to catch it early
Decay is rarely dramatic. It starts when a busy month pushes ten tasks into the next month and nobody records that they moved. Three months later the backlog is a hundred tasks and the schedule has quietly become a wish list. The early indicator is not the completion percentage, which lags badly, but the deferral rate and the age of the oldest overdue task. Watch those two weekly and you will see the drift long before it becomes a year of missing records.
The second pattern is checklist erosion. A checklist that began with eighteen steps gets ticked in four minutes by a technician who has done it two hundred times, and the steps requiring a meter or a disassembly stop happening. The counter is uncomfortable but simple: require a recorded measurement rather than a tick for the steps that matter. A leakage current value or a delivered tidal volume figure cannot be entered without performing the test, and the record becomes self-verifying.
The third is ownership drift after a staff change. Programmes built around one capable person collapse when that person leaves, because the frequencies, the vendor contacts, and the workarounds all lived in their head. The defence is documentation a competent stranger could pick up: written frequency rationale, checklists per device family, a vendor contact list with escalation levels, and a calendar that exists outside anyone personal drive. Test it by asking someone else to run one month unaided and see what breaks.


