It isn't the failed submission. It isn't the missed quarter. It's the moment a signal that was already inside your own systems becomes public before you have acted on it.
Gladys Knepper was 93. Before her pacemaker battery failed, her daughter told The New York Times, she did her own laundry, cooked her own meals, managed her own medications. She had surgery to replace the failed device. By then her heart was too damaged, and she died three weeks later, in June 2024.
Six months after her death, the manufacturer issued a recall. The FDA designated it Class I in February 2025, disclosing 832 injuries and two deaths. The recall was expanded, then expanded again, eventually reaching roughly 1.6 million devices, with a further Class I correction and software update in May 2026.
In March 2026, a New York Times investigation reported that battery tests at the manufacturer’s own factory had shown batteries failing unexpectedly for years, citing internal records and government inspection documents. The company disputes the article’s overall positioning, stating that it omits key context and that it stands behind the safety and effectiveness of its devices and quality system.
Factory test data lived in one system. Field complaints lived in another. Adverse event reports lived in a third. Each function could have shown you a defensible record of its own work. No function held the picture.
Most device-related harm is not a single catastrophic event. It is a slow-building pattern that the system was never designed to catch.
The scale of what that costs is hard to look at directly. The most-cited estimate comes from the International Consortium of Investigative Journalists’ 2018 *Implant Files* investigation, which analyzed a decade of FDA adverse event data (2008–2017) and identified more than 1.7 million injuries and nearly 83,000 deaths potentially linked to medical devices in the US alone. The GAO has since cited the same figure in its own assessments of FDA postmarket surveillance.
It is an imperfect number – adverse event reports are noisy, and the FDA is explicit that causation cannot be inferred from a report alone. But it is the best public estimate available, and nothing in the intervening years suggests the underlying dynamic has reversed.
Each failure compounds along the same path: harm, then reactive recall, then supply chain disruption, then cost, then eroded trust.
Here is the uncomfortable diagnosis. The information needed to catch these patterns early is almost always already in the building.
Safety signals originate at the point of care and immediately fragment: MAUDE and AEMS, recalls and FSCA, EUDAMED, complaints, service logs, patient registries, EHRs, claims. Each stream is noisy. Each arrives in a different format on a different cadence. Each lands in a different internal system – databases, spreadsheets, siloed departmental tools, ad-hoc reporting.
The result is not a data shortage. It is signals masked by low-quality data, duplicates and conflicts, manual workflows that impose delay, and decisions made late.
The missing piece is not more data. It is a system-level capability that closes the loop.
For most of the industry’s history, post-market surveillance ran in a straight line:
Each stage handed off to the next. Each had an owner. The process was auditable, comprehensible, and adequate to the volumes and expectations of its era.
The new reality is eight systems that don’t talk to each other: complaints, adverse events, service records, risk files, CAPA, public databases, literature, and field voices – distributors, clinicians, patients.
A small uptick in complaints looks harmless. A small shift in a failure mode looks harmless. A cluster in one geography looks harmless. A device family reaching a particular point in its time in market looks harmless. Put complaints, adverse events, IMDRF codes, failure modes, CAPA history, geography, time in market and the risk file on the same surface, and those four harmless observations may be one story.
No linear workflow can see that story, because the workflow processes records one at a time, and the story isn’t in any record.
Consider a Class III device maker with a global footprint.
On the same morning, the same device – implanted in two patients – fails.
At 08:42 CET in Barcelona, a surgeon reports unexpected device behavior mid-procedure. The call routes to the European call center, is taken in Spanish by Agent A, and is coded as a malfunction.
At 03:42 EST in Cleveland – the same moment, half a world away – a nurse calls the US support line about a different patient and the same device. Agent B takes it in English and codes it as use error.
Two call centers. Two handlers. Two languages. One device family. One risk file.
Now stretch the same problem across time rather than geography. A reviewer in São Paulo codes an event as a device malfunction, not reportable. Three weeks later, a reviewer in Los Angeles codes a materially similar event as use error, reportable, and opens a CAPA.
institutional memory. We have seen events like this before. They were coded this way. This region treated similar events as reportable. This decision differs from historical precedent.
That memory exists in the organization. It just isn’t available at the moment of decision.
This is the part most organizations underestimate. Coding is how a real-world signal becomes a regulatory decision.
One event passes through many lenses: the IMDRF code, the internal failure code, the clinical consequence, the risk-file linkage, the reportability decision, and then the Brazilian, US and EU views of all of the above.
Not what we decided – why we decided. Why this code. Why this report. Why this trend escalated. Why this risk remained acceptable.
Which means a modern PMS system has to preserve a reasoning trail: the source data and where it came from, the classification logic and how it was coded, any model suggestion and whether AI participated, the human review and who validated it, the final decision, and the justification for acting.
Without that trace, automation creates risk. With it, automation creates accountability.
On 2 February 2026, QSR became QMSR for US medical devices. ISO 13485:2016 is now incorporated into US regulation by reference, with FDA clarifications where US requirements extend beyond ISO, replacing the 21 CFR Part 820 framework US manufacturers grew up on.
This was a decade in the making and in preparation since 2019, with a consistent direction of travel: emphasis on data integration, alignment with IMDRF regulator goals, a follow-on to MDSAP, and convergence with EU MDR practice.
What it expects is specific – feedback and complaint handling, analysis of data with trending and KPIs, improvement through CAPA, and connections to risk management.
Meanwhile EU MDR has required a PMS *system* (Art. 83), a PMS plan (Art. 84 and Annex III), PMS reports and PSURs (Art. 85–86), and vigilance reporting and trending (Art. 87–88) – with the obligation to actively and systematically gather, record and analyze device data across its lifetime, feeding root cause analysis and CAPA, risk management, and clinical evaluation.
There is a genuine piece of good news here: **if you’ve built for EU MDR, you’re closer to QMSR than you think. The harder regulator already paid for most of the work. The open question is whether your evidence speaks both languages.
The harder news is that risk is still interpreted differently across markets. Brazil’s ANVISA operates a Tecnovigilância framework with local timelines and coding alignment still in transition. The US runs MDR reporting thresholds, public MAUDE visibility, and periodic/5-day/30-day rules. The EU runs EUDAMED vigilance modules, PSUR and trend reporting, its own serious incident definitions, and PMCF integrated with PMS.
The challenge is global consistency with local regulatory intelligence – simultaneously.
And the burden falls entirely on the manufacturer: harmonize, track every signal end to end, interpret messy real-world data, act at the right moment, justify every decision, and prove consistency years later.
Which brings us to what happens when the system doesn’t keep up.
Look at what FDA cited in the device cases. Complaint handling. CAPA. Adverse event reporting. Risk assessment. These are not exotic findings. They are the core of post-market surveillance.
And in every case, the signal lived inside the company’s own systems before the inspector found it.
That is the visible cost – the one with a timestamp and a share price attached, the one everybody can point to afterward.
the costs that never arrive as a single event – the iceberg beneath every PSUR, where a quality failure actually lands inside a commercial organization, and what a closed loop looks like in operation.
empowerreg is a Health Safety Intelligence company. Connect with us to modernize your journey
hello@empowerreg.ai