Medical gases — oxygen above all — are a continuous life-support utility, and the patients who depend on them cannot tolerate an interruption. This Article covers how a healthcare facility's medical-gas systems are engineered to survive equipment failure, source depletion, maintenance outages, and disasters: the layered redundancy NFPA 99 requires at the source, the reserve and emergency-supply provisions that buy time, the connections that let a relief crew restore supply from the curb, and the operational planning that turns hardware into actual resilience.
The companion Articles in this Chapter establish the building blocks: one covers the gas and vacuum sources (cryogenic bulk oxygen, manifolds, compressors, vacuum and WAGD producers), and another covers distribution (piping, zone valves, area and master alarms, outlet layout). This Article is the layer above — it treats those components as a system that must keep delivering when something breaks, and it is where reserve sizing, source-valve strategy, emergency oxygen supply connections (EOSC), automatic switchover, and continuity-of-operations planning live.
A loss of medical oxygen is, at the bedside, a loss of life support — for ventilated ICU patients, neonates, ECMO and anesthesia patients, it is measured in minutes, not hours. Resilience of the medical-gas system is therefore not a nicety; it is mandated through several overlapping authorities:
Continuity is also an EMTALA issue indirectly: a hospital that cannot supply oxygen cannot stabilize emergency patients and may be forced to divert — so source resilience is part of keeping the doors open.
The defining redundancy article in NFPA 99 is that a positive-pressure gas source (oxygen, nitrous oxide, medical air via cylinders, etc.) is not a single tank or manifold — it is a coordinated set of three supplies:
For a cryogenic bulk oxygen system, this manifests as the main vessel plus a reserve — historically a high-pressure cylinder header or a second cryogenic vessel sized to carry the facility through a defined window while a refill or repair is arranged. For manifolded cylinder gases, it manifests as two cylinder banks (primary/secondary, alternating automatically) plus a reserve bank.
The principle behind the three-supply model is no single point of failure at the source: any one supply can be empty, isolated for maintenance, or failed, and gas keeps flowing. The sibling sources Article describes the physical equipment; the point here is the architecture — duplicate-plus-reserve, automatic changeover, and alarmed transitions.
For the gases that are produced on site rather than stored — medical air (from compressors) and medical-surgical vacuum (from vacuum pumps), plus WAGD (waste anesthetic gas disposal) and instrument air — NFPA 99 requires that the production equipment be arranged so that the system can meet the facility's peak calculated demand with the single largest component out of service. In practice this means at least two compressors / two vacuum pumps (and often three) configured so that any one can be taken down for maintenance or can fail outright while the remainder still carry full design load. This is the classic N+1 redundancy: enough capacity to serve demand, plus one extra unit's worth of margin.