The Signals Existed. Nothing Connected Them In Time

What is the most expensive moment in a medical device company's life?

It isn't the failed submission. It isn't the missed quarter. It's the moment a signal that was already inside your own systems becomes public before you have acted on it.

Enterprise-ai-cover
Resilient Systems Series • Part Two
April 15, 2026

The signals existed

Gladys Knepper was 93. Before her pacemaker battery failed, her daughter told The New York Times, she did her own laundry, cooked her own meals, managed her own medications. She had surgery to replace the failed device. By then her heart was too damaged, and she died three weeks later, in June 2024.

Six months after her death, the manufacturer issued a recall. The FDA designated it Class I in February 2025, disclosing 832 injuries and two deaths. The recall was expanded, then expanded again, eventually reaching roughly 1.6 million devices, with a further Class I correction and software update in May 2026.

In March 2026, a New York Times investigation reported that battery tests at the manufacturer’s own factory had shown batteries failing unexpectedly for years, citing internal records and government inspection documents. The company disputes the article’s overall positioning, stating that it omits key context and that it stands behind the safety and effectiveness of its devices and quality system.

Set the dispute aside for a moment, because the structural point survives it either way.

The signals existed. Nothing connected them in time.

Factory test data lived in one system. Field complaints lived in another. Adverse event reports lived in a third. Each function could have shown you a defensible record of its own work. No function held the picture.

Gladys is not an outlier

Most device-related harm is not a single catastrophic event. It is a slow-building pattern that the system was never designed to catch.

The scale of what that costs is hard to look at directly. The most-cited estimate comes from the International Consortium of Investigative Journalists’ 2018 *Implant Files* investigation, which analyzed a decade of FDA adverse event data (2008–2017) and identified more than 1.7 million injuries and nearly 83,000 deaths potentially linked to medical devices in the US alone. The GAO has since cited the same figure in its own assessments of FDA postmarket surveillance.

It is an imperfect number – adverse event reports are noisy, and the FDA is explicit that causation cannot be inferred from a report alone. But it is the best public estimate available, and nothing in the intervening years suggests the underlying dynamic has reversed.

Each failure compounds along the same path: harm, then reactive recall, then supply chain disruption, then cost, then eroded trust.

The data exists. Nothing synthesizes it.

Here is the uncomfortable diagnosis. The information needed to catch these patterns early is almost always already in the building.

Safety signals originate at the point of care and immediately fragment: MAUDE and AEMS, recalls and FSCA, EUDAMED, complaints, service logs, patient registries, EHRs, claims. Each stream is noisy. Each arrives in a different format on a different cadence. Each lands in a different internal system – databases, spreadsheets, siloed departmental tools, ad-hoc reporting.

The result is not a data shortage. It is signals masked by low-quality data, duplicates and conflicts, manual workflows that impose delay, and decisions made late.

The missing piece is not more data. It is a system-level capability that closes the loop.

PMS used to be a linear workflow

For most of the industry’s history, post-market surveillance ran in a straight line:

Complaint / AE → Code → Report → Trend → CAPA

Each stage handed off to the next. Each had an owner. The process was auditable, comprehensible, and adequate to the volumes and expectations of its era.

It isn’t anymore.

The new reality is eight systems that don’t talk to each other: complaints, adverse events, service records, risk files, CAPA, public databases, literature, and field voices – distributors, clinicians, patients.

We don’t lack data. We lack a way to make data speak the same language. And critically:

The signal often lives in the relationships between records, not inside any single one.

A small uptick in complaints looks harmless. A small shift in a failure mode looks harmless. A cluster in one geography looks harmless. A device family reaching a particular point in its time in market looks harmless. Put complaints, adverse events, IMDRF codes, failure modes, CAPA history, geography, time in market and the risk file on the same surface, and those four harmless observations may be one story.

No linear workflow can see that story, because the workflow processes records one at a time, and the story isn’t in any record.

Two events. One device. Two answers.

Consider a Class III device maker with a global footprint.

On the same morning, the same device – implanted in two patients – fails.

At 08:42 CET in Barcelona, a surgeon reports unexpected device behavior mid-procedure. The call routes to the European call center, is taken in Spanish by Agent A, and is coded as a malfunction.

At 03:42 EST in Cleveland – the same moment, half a world away – a nurse calls the US support line about a different patient and the same device. Agent B takes it in English and codes it as use error.

Two call centers. Two handlers. Two languages. One device family. One risk file.

Will both events be recorded, triaged, investigated and closed the same way, on time?

Now stretch the same problem across time rather than geography. A reviewer in São Paulo codes an event as a device malfunction, not reportable. Three weeks later, a reviewer in Los Angeles codes a materially similar event as use error, reportable, and opens a CAPA.

Neither reviewer is wrong on the facts in front of them. Both are working without the one thing that would have made them consistent:

institutional memory. We have seen events like this before. They were coded this way. This region treated similar events as reportable. This decision differs from historical precedent.

That memory exists in the organization. It just isn’t available at the moment of decision.

Coding is not data entry

This is the part most organizations underestimate. Coding is how a real-world signal becomes a regulatory decision.

One event passes through many lenses: the IMDRF code, the internal failure code, the clinical consequence, the risk-file linkage, the reportability decision, and then the Brazilian, US and EU views of all of the above.

And then comes the question that actually decides audits:

Why?

Not what we decided – why we decided. Why this code. Why this report. Why this trend escalated. Why this risk remained acceptable.

Which means a modern PMS system has to preserve a reasoning trail: the source data and where it came from, the classification logic and how it was coded, any model suggestion and whether AI participated, the human review and who validated it, the final decision, and the justification for acting.

Without that trace, automation creates risk. With it, automation creates accountability.

The regulatory moment

On 2 February 2026, QSR became QMSR for US medical devices. ISO 13485:2016 is now incorporated into US regulation by reference, with FDA clarifications where US requirements extend beyond ISO, replacing the 21 CFR Part 820 framework US manufacturers grew up on.

This was a decade in the making and in preparation since 2019, with a consistent direction of travel: emphasis on data integration, alignment with IMDRF regulator goals, a follow-on to MDSAP, and convergence with EU MDR practice.

What it expects is specific – feedback and complaint handling, analysis of data with trending and KPIs, improvement through CAPA, and connections to risk management.

Meanwhile EU MDR has required a PMS *system* (Art. 83), a PMS plan (Art. 84 and Annex III), PMS reports and PSURs (Art. 85–86), and vigilance reporting and trending (Art. 87–88) – with the obligation to actively and systematically gather, record and analyze device data across its lifetime, feeding root cause analysis and CAPA, risk management, and clinical evaluation.

There is a genuine piece of good news here: **if you’ve built for EU MDR, you’re closer to QMSR than you think. The harder regulator already paid for most of the work. The open question is whether your evidence speaks both languages.

The harder news is that risk is still interpreted differently across markets. Brazil’s ANVISA operates a Tecnovigilância framework with local timelines and coding alignment still in transition. The US runs MDR reporting thresholds, public MAUDE visibility, and periodic/5-day/30-day rules. The EU runs EUDAMED vigilance modules, PSUR and trend reporting, its own serious incident definitions, and PMCF integrated with PMS.

The challenge is global consistency with local regulatory intelligence – simultaneously.

And the burden falls entirely on the manufacturer: harmonize, track every signal end to end, interpret messy real-world data, act at the right moment, justify every decision, and prove consistency years later.

This is no longer a human-scale task.

A 483 isn’t a compliance event. It’s a market event.

Which brings us to what happens when the system doesn’t keep up.

Inspection observations and warning letters become public the moment they’re filed. The market reads them before the company can respond.
  • A top-five device manufacturer, October 2025: an 8.3% intraday drop on disclosure of an FDA warning letter covering three manufacturing sites. FDA cited complaint handling, corrective and preventive action, design validation, and adverse event reporting.
  • A top-five device manufacturer, December 2021: a 9% decline after a warning letter to its diabetes group’s manufacturing facility. FDA cited risk assessment, CAPA, complaint handling, and adverse event reporting.
  • A therapeutics company, March 2026: 21% in a single day, roughly $2B in market capitalization, following a warning letter on product promotion – and then securities class actions.

Look at what FDA cited in the device cases. Complaint handling. CAPA. Adverse event reporting. Risk assessment. These are not exotic findings. They are the core of post-market surveillance.

And in every case, the signal lived inside the company’s own systems before the inspector found it.

The market punishes the discovery, not the violation.

That is the visible cost – the one with a timestamp and a share price attached, the one everybody can point to afterward.

It is not the largest one.

the costs that never arrive as a single event – the iceberg beneath every PSUR, where a quality failure actually lands inside a commercial organization, and what a closed loop looks like in operation.

Ready to See It in Action?

empowerreg is a Health Safety Intelligence company. Connect with us to modernize your journey

hello@empowerreg.ai