Certification does not end medical device reporting duties. My starting point: protect patients, record when you learned of the event, and assign a reporting owner. Most qualifying manufacturer FDA Medical Device Reports (MDRs) are due within 30 calendar days - some require action within 5 work days.

I use these checks to keep safety, reporting, and repair work aligned:

  • Choose the right reporting path. Assess MDR duties, corrections or removals, privacy notices, and vulnerability disclosures separately. A cybersecurity finding alone does not require an MDR.
  • Confirm who files and when. Manufacturers, importers, and healthcare facilities have different duties. Another party’s filing may not satisfy yours.
  • Protect patients and preserve records. Coordinate containment with care teams, save logs, and document device details, patient impact, decisions, and communications.
  • Report, then follow through. <u>Do not wait for root-cause analysis.</u> Track submission receipts, follow-up reports, retention rules, and manufacturer responses.
  • Check fixes before closure. Test device function and clinical workflows, monitor for recurrence, and update risk records. Aim for zero overdue mandatory reports and 100% validation of high-risk fixes - as targets, not proof of success.

My goal is an audit-ready case file: one linked record showing what happened, who acted, why reporting was - or was not - required, and how the fix was checked.

Medical Device Incident Reporting Workflow

Medical Device Incident Reporting Workflow

#365: Medical Device Reporting: The Do's and Don'ts

Determine Reporting Triggers, Deadlines, and Owners

Assign one internal regulatory owner to each event, even when another party files the external report. After safe containment, classify the event and decide whether it requires reporting. Record the applicable awareness date, available information, and reporting decision.[2][12]

Apply FDA Medical Device Reporting Requirements

Under 21 CFR Part 803, assess whether the device may have caused or contributed to the event. Manufacturers and importers must also assess whether a malfunction would likely cause death or serious injury if it happened again.[2][13][14]

Use this map to determine who reports, what triggers the report, who receives it, and when it is due.

Reporter and trigger Recipient Deadline Coordination duty
Manufacturer: suspected device-related death, serious injury, or qualifying malfunction FDA 30 calendar days after awareness Gather facts and track follow-up.
Manufacturer: remedial action needed to prevent an unreasonable risk of substantial harm to public health, or an event specifically designated by FDA FDA 5 work days after awareness Escalate immediately for executive, clinical-safety, regulatory, and legal review.
Importer: suspected device-related death or serious injury FDA and manufacturer 30 calendar days after awareness Share evidence with both recipients.
Importer: qualifying malfunction Manufacturer 30 calendar days after awareness Provide malfunction details and the risk of recurrence.
Device user facility: suspected device-related death FDA and manufacturer 10 work days after awareness Confirm both required submissions.
Device user facility: suspected device-related serious injury Manufacturer; FDA if the manufacturer is unknown 10 work days after awareness Verify the manufacturer’s identity and receipt of the report.
Device user facility: malfunction alone No general mandatory user-facility MDR No general Part 803 deadline Escalate to the manufacturer and assess other duties.
Device user facility: annual summary of death and serious-injury reports FDA January 1 for the preceding year Reconcile reportable-event records.

Sources: FDA reporting requirements and guidance.[2][11][12][13][14]

Evaluate Corrections, Removals, and Other Notices

Manufacturers and importers must evaluate corrections, replacements, and removals under 21 CFR Part 806. An action generally requires an FDA report within 10 working days after initiation if it reduces a risk to health or remedies a regulatory violation that may present a risk to health. Performance or quality improvements without those triggers generally do not require a report.[5][6][7]

Certain submissions under Parts 803 or 1004, or FDA-ordered recalls under Part 810, can eliminate a separate Part 806 submission. Do not assume another filing is enough. Document the applicable exception, risk assessment, affected devices, initiation date, communications, and the reason the action is not reportable.[5][6][7]

Once the notice type is clear, assign who files, who notifies, and who tracks follow-up.

Assess HIPAA, state-law, contractual, and vulnerability-disclosure notices separately with privacy, legal, and security teams. A cybersecurity incident does not automatically qualify as a reportable PHI breach. Conduct the HIPAA breach analysis separately.[9][10]

Define Healthcare and Vendor Responsibilities

Use one incident record to route duties across clinical, regulatory, legal, and vendor teams. Confirm device-user-facility status before assigning those duties.

Healthcare teams escalate events and preserve evidence. Manufacturers and importers file required reports. Distributors and service providers promptly route complaints and service records. Teams share reporting work, but the correct regulated party remains responsible for filing.[2][4][8]

The internal owner should track each party’s recipients, deadlines, decisions, and submission confirmations. Another party’s report does not automatically satisfy your organization’s obligations.[2][4][8]

Collect Evidence for Reports and Investigations

Keep one incident record for device details, patient impact, evidence, communications, corrective actions, and closure. A restricted spreadsheet or ticketing system works only if it tracks required fields, change history, and named ownership.

Assign owners for patient impact, device condition, medical device security risks, privacy, or compliance, and incident coordination. One person may cover multiple roles. Gather the facts before logs roll over, devices undergo service, or records get scattered across teams.

Document Device Details and Patient Impact

Record the facts needed for both the report and the investigation: manufacturer, model or catalog number, UDI, serial or lot number, software and firmware versions, location, connected systems, and maintenance history. Record occurrence, detection, awareness, and reporting-decision dates separately, including timestamps and time zones. Note whether the device was in clinical use, maintenance, testing, storage, or transit.

Document any death, serious injury, malfunction, treatment delay, incorrect or delayed diagnosis, interrupted therapy, device unavailability, or PHI exposure. Include the number of potentially affected patients, procedures, and devices, plus the clinical service and time window.

Separate observed facts from assumptions, and identify each item’s source and confidence level. Keep patient names, medical-record numbers, images, and other PHI in restricted systems linked to an internal case number. FDA guidance says not to enter the patient’s name in an MDR report.[2]

Preserve Logs and Forensic Evidence

Preserve the device’s original state before remediation changes the evidence. Save device event logs, audit trails, authentication records, network-flow data, configurations, diagnostic files, screenshots, error codes, relevant CVE identifiers, and manufacturer advisories before they are overwritten.

Record the device clock, collector system clock, time zone, and any known clock drift. Coordinate collection with the treating team, clinical engineering, biomedical engineering, information security, and the manufacturer.

Do not power-cycle, reimage, update, factory-reset, or disconnect the device without documented patient-safety approval. Keep originals read-only and analyze working copies. Give each artifact an evidence ID, source, collector, collection time, method, hash, and custody history.

Keep Reporting Decisions and Remediation Records

Keep the reportability rationale, approvals, submissions, acknowledgments, supplemental-report requirements, and closure approval in one file. Include supporting facts and submission identifiers.

Link manufacturer or vendor communications and corrective actions to the affected devices, owners, due dates, validation results, residual risk, and closure approval.

User-facility MDR files require 2 years of retention from the event. Manufacturer and importer MDR files require 2 years from the event or the device’s expected life, whichever is longer.[15] Correction-and-removal records require 2 years beyond the device’s expected life.[5]

Build Reporting Into Healthcare Incident Response

Use one intake path and one shared incident log for every event, but keep safety, security, privacy, and reporting decisions on separate tracks. Assign a primary owner and an alternate for each role.

Clinical leadership approves changes that affect care. Security coordinates technical containment, and quality determines reporting pathways. An executive incident lead resolves conflicts. Shared deadlines and documented handoffs help prevent delays and conflicting instructions.

Function Escalation trigger Action Required record Handoff
Security operations Suspicious device traffic, unauthorized access, malware, or loss of device availability Preserve evidence, assess scope, and coordinate containment. Record alerts, timestamps, indicators, affected assets, and evidence-custody details. Clinical engineering and incident commander
Clinical engineering Device malfunction, unsafe behavior, failed alarm, unexpected configuration, or service issue Assess device safety, availability, service status, and replacement or workaround needs. Record device identifier, model, serial number, software version, maintenance history, and test results. Patient safety, quality, and care leadership
Patient safety Patient harm or risk of harm Protect patients, notify clinical leaders, and coordinate mitigation that keeps care safe. Record patient impact, intervention, outcome, and clinical timeline. Quality, risk management, and regulatory owner
Quality or regulatory affairs Potential MDR, correction, removal, complaint, or CAPA issue Document the reporting decision and due date. Retain reporting rationale, applicable rule, submitted form, acknowledgment, and follow-up date. Compliance, legal, manufacturer, and executive sponsor
Privacy Possible PHI or PII exposure Assess breach and notification obligations. Record data elements, affected individuals, disclosure scope, and assessment. Privacy officer, legal, and security
Legal Litigation risk, serious harm, disputed causation, or external inquiry Issue preservation guidance and review communications and notices. Retain legal hold, advice, approvals, and communication record. Executive leadership and compliance
Compliance Missed or approaching deadline, incomplete submission, or conflicting obligation Monitor the regulatory calendar and verify submission evidence. Record deadlines, owner, alternate, status, and acknowledgment. Incident commander and quality
Vendor or manufacturer liaison Device defect, vulnerability, recall, field action, or requested investigation Open the manufacturer case and share verified facts. Record case number, contacts, correspondence, requested artifacts, and response dates. Quality, clinical engineering, and security

Once owners are assigned, move straight to triage with patient safety first.

Triage and Contain Incidents Safely

Start with two clear questions: Could continued use harm a patient? Could the device or connected environment be compromised? Reconcile the answers before isolating a device, suspending an account, rebooting, patching, replacing equipment, or using a clinical workaround.

For every containment decision, document the clinical risk, security benefit, approving authority, start time, alternative controls, and reassessment time.

Hypothetical example: An infusion pump shows unusual outbound traffic, and its manufacturer confirms possible compromise. Because isolation could disrupt remote monitoring or an alarm pathway during medication delivery, the care team and clinical engineering prepare an approved replacement, verify medication and settings, and supervise the transition. Only after the replacement is operational do they isolate the suspected pump and preserve it for examination. Record who approved the action and when it must be reassessed.

Submit Reports and Manage Follow-Up

Once containment starts, use the triage facts to build the reporting record and deadline log. Give every deadline a primary owner and an alternate. Track the awareness date, report type, due date, submission channel, acknowledgment, and follow-up.

Submit required reports on time. Don't wait for root-cause analysis.

Validate Fixes and Update Risk Records

After submission, validate the fix before closing the incident. Work with the manufacturer and clinical engineering to check patches and controls against device function, alarms, connectivity, and clinical workflow.

Set a recurrence-monitoring period and review related devices. Feed findings into complaint handling, corrective action, continuity planning, ISO 14971 post-production risk review, and applicable IEC 81001-5-1 security-lifecycle activities.[16][17] Assign these activities by role: healthcare organizations and manufacturers do not have identical duties.

Coordinate Risk Management With Censinet RiskOps

Censinet RiskOps™ supports risk ownership and remediation coordination. It does not replace FDA submissions, incident forensics, or legal review.

Conclusion: Keep Incident Reporting Audit-Ready

An audit-ready case file shows how post-certification reporting, safety actions, and remediation stayed aligned across compliance, safety, and enterprise risk. Link the trigger, awareness timestamp, owner, preserved evidence, patient-protection decision, and verified remediation. Use the deadline already set for the event. Record why the reporting pathway applies - or why no external report is required.

The case file should show that the process can be repeated, not just that the work is complete. Add these controls to the incident-response workflow used for safety and security events:

  • Keep device inventories current and link each device to a named clinical owner.
  • Test after-hours manufacturer contacts.
  • Assign primary and backup submitters for every filing channel, and keep confirmation receipts. You can also use automated questionnaire responses to streamline documentation for these channels.
  • Set severity-based escalation procedures with named contacts and internal response times.

Use individual accounts and least-privilege access. Store reports in access-logged or immutable form. Define who approves supplemental reports, how changed facts link to the original submission, and where approvals are kept. Test these controls with clinical operations, clinical engineering, cybersecurity, privacy, quality, legal, supply chain, and vendor representatives.

Measure whether the process works. Use operational metrics to check that reporting and remediation stay on time throughout post-market monitoring and closure. Track time to triage and notify, the number and age of overdue investigations, recurring issues by device model or software version, and remediation validation status. Treat zero overdue mandatory reports and 100% validation of high-risk fixes before closure as targets - not proof that the process works.

FAQs

When does the reporting clock start if device involvement is uncertain?

The Medical Device Reporting (MDR) clock starts when the manufacturer learns of a reportable event. This includes a device-related death, serious injury, or malfunction that could happen again and cause either outcome [1][2].

If the device’s role is unclear, investigate thoroughly. No report is needed if the investigation confirms that the device did not contribute, as long as a qualified professional fully documents the decision not to report [3].

What should we do if a manufacturer disputes reportability?

If a manufacturer disputes whether an event must be reported, a qualified individual must decide whether to withhold the report. This person may be a physician, nurse, risk manager, or biomedical engineer [1][2]. They must document why the event does not meet the reporting threshold for a death, serious injury, or malfunction [1][2].

Keep this documentation in the device’s risk management file or quality management system, where it’s ready for regulatory inspection [3][2].

How should we update a report when new evidence emerges?

If you receive new information about a medical device incident after filing your initial report, submit a supplemental report to the FDA within one month. This keeps the agency’s records complete and accurate [1][2].

Update your internal risk assessment, design controls, and CAPA records with the new findings [1][2]. Censinet RiskOps™ keeps device risk records in one place, helping teams add new vulnerability details and keep documentation in sync [3].

Related Blog Posts