bg-left bg-right

Incident Reporting Essentials for Medical Device Manufacturers

background
user-icon 15 Apr 2026

Running a medical device company involves responsibilities that extend far beyond product development and manufacturing. — You’re responsible for its safety and performance throughout its entire lifecycle. Things can go wrong in the real world: a pump stops working during surgery, a stent doesn’t deploy right, or a diagnostic tool gives misleading results. When that happens, incident reporting isn’t optional paperwork—it is a critical mechanism for identifying risks, protecting patients, and maintaining regulatory compliance and trust.

Incident reporting—often referred to as vigilance reporting in the European Union or Medical Device Reporting (MDR) in the United States—refers to the structured process by which manufacturers collect, evaluate, investigate, and report events associated with their devices that have resulted in, or could cause, harm. This process is a core element of post-market surveillance (PMS), ensuring continuous oversight of devices once they are in clinical use.

Why does it feel so important right now? Regulations like the EU Medical Device Regulation (MDR 2017/745) and the FDA’s 21 CFR Part 803 have gotten stricter. ISO 13485 (the quality management standard many companies follow) ties right into this with requirements for complaint handling, corrective actions, and risk management. Failure to comply can result in regulatory action, market restrictions, recalls, or, most critically, preventable patient harm.

What Qualifies as an “Incident”?

Not every complaint or device issue needs a full report, but knowing the difference is essential.

An incident is basically any event linked to a medical device that:

  • Causes (or has the potential to cause) unexpected harm to patients, users, or other individuals; and
  • Is linked to factors such as design flaws, manufacturing defects, unclear instructions, poor maintenance advice, user errors (sometimes), or environmental conditions.

A serious incident represents a higher level of severity and typically includes events that result in death, life-threatening situations, permanent impairment, serious deterioration in health, or unplanned hospitalization. Importantly, events that have not yet resulted in harm but could do so if they recur may also be reportable.

Under EU MDR (Articles 87–92), manufacturers are required to report “serious incidents” and perform trend reporting. In the US (FDA), manufacturers must report deaths, serious injuries, or malfunctions that could cause harm if they recur. Other jurisdictions, including Canada and Australia, operate similarly, often aligned through IMDRF guidelines.

Quick rule of thumb: When in doubt, report. Regulators generally view over-reporting more favorably than missed reportable events.

Why Incident Reporting Matters Beyond Compliance?

While regulatory compliance is mandatory, effective incident reporting delivers broader organizational value:

  • Patient safety — Early identification of safety signals prevents escalation into widespread harm.
  • Product improvement—Investigations highlight root causes, leading to better designs, clearer IFUs (instructions for use), or training updates.
  • Regulatory credibility — Transparent and timely reporting strengthens relationships with regulators and notified bodies.
  • Avoids costly surprises—Proactive corrective actions reduce the likelihood of large-scale recalls or enforcement actions, which could be potentially expensive.
  • Audit readiness—A well-integrated vigilance system is a key focus area during ISO 13485 and regulatory audits.

Incident reporting should not be viewed as a narrow extension of complaint handling. Instead, it serves as a frontline safety system that supports continuous improvement and long-term market sustainability.

Key Steps in the Incident Reporting Process

Most manufacturers follow a structured process aligned with regulatory guidance and best practices.

  1. Receipt and Documentation of the Complaint

Complaints may come from users (hospitals, doctors, patients), distributors, or internal field personnel. Everything should be documented promptly—date, device details (model, lot/serial), event description, and reporter details. Centralized electronic systems are strongly recommended to ensure traceability and prevent data loss.

  1. Initial Triage and Assessment. 
  • The manufacturer must determine whether the device contributed to the event, whether harm occurred or could occur, and whether the event meets the criteria for reportability. If serious public health threat → Report in 2 days (EU MDR).
  • Death or unanticipated serious deterioration → 10 days.

Other serious incidents → 15 days (EU) or 30 days (FDA for most). Regulatory timelines begin at the point when the manufacturer becomes aware of a potentially reportable event and should not be delayed while additional information is gathered.

3. Investigation and root cause analysis 

A thorough investigation should be conducted, incorporating device history, user statements, and photos if possible, and return the device for testing if feasible. Involve engineering, quality, and clinical experts. Root cause analysis should be documented using established methodologies such as the 5 Whys or fishbone diagrams.

4. Report to Authorities

Reportable incidents must be submitted to the relevant competent authorities using the required formats and systems.

  • EU: Manufacturer Incident Report (MIR) form via Eudamed (or national portals until fully live).
  • US: FDA Form 3500A electronically via eMDR. Include all details, your assessment, and initial actions. Follow up with final reports once the investigation wraps (often within months).

5. Take Corrective Actions

Where necessary, manufacturers must implement corrective actions, which may include design changes, manufacturing controls, labeling updates, field safety corrective actions (FSCA), or recalls. Actions should be managed through the CAPA system and monitored for effectiveness.

6. Trend monitoring and closing the loop.

Manufacturers should regularly review incident data for emerging trends. EU MDR requires “trend reporting” if incidents increase unexpectedly. Incident files should only be closed once all actions have been implemented and verified.

Common Pitfalls and How to Avoid Them

Regulatory inspections frequently identify recurring weaknesses in vigilance systems, including:

  • Late or missed reporting due to internal delays.
  • Poor documentation — No photos, incomplete logs, or vague descriptions compromise credibility.
  • Failure to recognize “potential” harm — 
  • Poor communication between regulatory, quality, and technical teams.
  • Overlooking user errors—Sometimes misuse stems from bad instructions; that’s on the manufacturer.
  • Inadequate training of commercial or service personnel.

Pro tip: Establishing clear SOPs, providing regular training, and conducting periodic mock incident exercises can significantly reduce these risks.

Best Practices That Make It Easier

Manufacturers with mature vigilance systems typically:

  • Integrate incident reporting fully within their QMS. Use digital tools—software for logging, trending, and auto-reminders — performs better than spreadsheets.
  • Foster a non-punitive reporting culture
  • Stay updated.
  • Collaborate — Work closely with distributors and users; they spot issues first.

For companies operating internationally, aligning with these global standards is essential for maintaining market access and supporting business growth.

Wrapping Up: It’s About More Than Compliance

Incident reporting can feel like a burden. But when implemented effectively, it transforms adverse events into actionable insights, strengthens regulatory confidence, and supports continuous improvement.

If you’re in Switzerland or anywhere building medical devices, start small: review your current process against MDR/FDA/ISO requirements, train your team, and test it with a mock report. The peace of mind—and the regulatory green lights—is worth it.

At TS Q&E, we help medical device manufacturers set up robust vigilance systems, integrate them with ISO 13485 QMS, handle reporting timelines, and prepare for audits. From gap analysis to SOP updates and training, we make sure your incident reporting is practical, compliant, and effective. Reach out if you’d like a no-pressure chat about your setup—we’d love to help keep your devices (and your business) safe and successful.

About the author:
Gianluca Tordi

Tags

MDR Guidelines

Worldwide regulation resources

Latest News

Contact us / Ask a quote now

We will help You find the right solution for Your Projects

CONTACT US

SOME OF OUR CLIENTS