Home → Guides → Medical device adverse incident
Healthcare compliance guide

What to do after a suspected medical device adverse incident

When a device harms or nearly harms someone, a healthcare provider needs to protect current and future patients, preserve the device and records, report through the correct route and close corrective actions. This guide uses an England provider example. MHRA Yellow Card device reporting applies to healthcare professionals in England, Wales and Northern Ireland according to current MHRA guidance, while Scotland uses a different route for relevant provider incidents.

Start with the patient and the device in front of you

A pump stops during treatment. A monitor displays a plausible but wrong value. A wheelchair brake fails just before transfer. A clinical software tool assigns the wrong result to a patient. An implant or disposable item appears damaged during use. These events may have different causes, but each can require prompt clinical care and preservation of the device and records. Do not wait for an engineer to prove a manufacturing defect before treating the event as a suspected device safety incident.

MHRA Yellow Card guidance says to report adverse incidents involving medical devices, and the GOV.UK reporting page includes events that injure or almost injure someone, interrupt treatment or contribute to a wrong diagnosis. A near miss matters even when no patient harm occurred. The device may have a wider population in use, and an early report can help identify a recurring problem. A healthcare provider should not assume that reporting is only for an event labelled serious inside its own incident system. MHRA: Yellow Card scheme guidance; GOV.UK: report a problem with a medicine or medical device.

First provide the clinical response required for the person affected. This may involve stopping a procedure, switching to a suitable alternative, monitoring the patient, obtaining specialist review or arranging urgent care. Those are clinical decisions made by qualified staff. At the same time, remove the suspect device from routine use if that can be done safely, prevent another patient from being exposed, and tell the local medical device safety lead or equivalent. If the device is implanted or needed to sustain care, the response is more complex and must be directed by the clinical team. This guide does not instruct staff to remove an implant or interrupt life support equipment.

Field safety notices from a manufacturer across a device population, and contamination and release when a used device is sent for repair, are separate pathways with their own owners. This page owns the incident that the provider discovers first: clinical impact, evidence preservation, reporting and investigation. A device fault may later lead to a repair or notice, but those are subsequent pathways.

Put the suspect item on hold without destroying evidence

Identify the exact device, accessory, consumable and software configuration involved. Record manufacturer, model, serial or lot number, unique device identifier if available, asset location, user, date, time and status at the event. Include connected components such as leads, batteries, sensors, tubing, cartridges or data interfaces. A fault described only as monitor broken may be impossible to investigate if the actual sensor or software version is later changed. Keep the packaging and instructions if they may clarify the product identity or use conditions.

MHRA guidance says not to throw away or repair a device involved in an incident. If police or a coroner is involved, retain it until the MHRA contacts you. Otherwise it may be made available to the manufacturer for analysis. Do not send the device to MHRA unless specifically asked. This means the usual maintenance workflow needs an incident hold. A technician should not reset an error, replace a part, wipe a log or dispose of a single use item before the evidence plan is agreed. If a safety action cannot wait, record what was done and preserve what can reasonably be preserved.

Quarantine the item securely, with a clear status label and named custodian. Record who has physical possession, whether it has been cleaned or decontaminated, and any access restriction needed for patient data. A contaminated device may need safe handling before it can be stored or examined, and infection prevention and clinical engineering should decide that process without erasing evidence unnecessarily. If the item is a software medical device, preserve relevant versions, logs, timestamps and configuration through an approved technical process. Do not upload raw patient data to a general compliance tracker.

Check the same model or batch elsewhere. A local event does not prove that all similar devices are unsafe, but it can justify an immediate risk review of other units pending competent advice. Identify where they are, which patients rely on them and what alternative capacity exists. A blanket shutdown can itself create patient risk. The clinical and device safety team should decide whether to withdraw, inspect, increase monitoring or continue with controls. Record the basis and review point. Do not convert a precaution into an unrecorded permanent policy.

Build an incident timeline while memories and logs are available

The MHRA device checklist suggests recording device model, event details and effects, settings, error messages, date and time. Add the clinical sequence, who was present, what the device was intended to do, what it actually did, what alternative action was taken and whether the patient received delayed or different care. Keep observations separate from interpretation. An alarm sounding at a recorded time is an observation. A battery defect causing the alarm is a hypothesis until investigated. MHRA: Devices in Practice checklists.

Preserve relevant maintenance, inspection, training, installation and previous fault records. A service certificate may show that the device passed a check last month; it does not prove that it was working correctly at the incident time. A user report may be accurate even if the fault cannot be reproduced later. Review whether other staff saw similar warnings or workarounds. Include the environmental or network context where relevant, such as power supply, connectivity, connected software or storage conditions. Do not assume that a manufacturer fault is the only possible explanation.

Take photographs or screenshots through an approved process if they will help capture a transient state. Make sure they do not disclose unnecessary patient details or alter the device. Ask the clinical engineering or digital team to export logs before retention windows or automated updates remove them. Record the chain of custody for physical items and data. If a manufacturer wants to collect the device, agree how the provider will retain copies of records and what will happen to patient data. If a regulator or police investigation is possible, obtain appropriate legal and governance advice before transfer.

Assign separate owners for clinical review, technical preservation and regulatory reporting. A single incident ticket can coordinate them, but each has its own status. The clinical team may complete immediate patient care while the device remains held. The Yellow Card may be submitted before technical causation is known. The engineering investigation may continue after the report is filed. Closing one strand should not silently close the others.

Assess patient impact and further exposure

The clinical lead should determine what happened to the patient or user, whether treatment was interrupted or delayed, and whether any diagnostic or therapeutic result may be unreliable. Consider other patients who were treated with the same unit, batch, sensor or software configuration during the plausible fault window. A device that produced one visibly wrong measurement may have produced earlier plausible values that went unquestioned. Conversely, one mishandled accessory may not affect every device in the service. The scope should be based on evidence and specialist advice.

Trace the affected use through approved clinical records and device logs. Record confidence in each link. If the equipment has a shared asset number but no patient level traceability, note the limitation and decide whether a wider review is required. MHRA Managing Medical Devices guidance supports inventory, maintenance and incident management for healthcare organisations. Do not invent a universal period of retrospective review. The device’s failure mode, previous checks and patient risk determine the boundary. MHRA: Managing Medical Devices.

The provider should use its patient safety process to decide whether people need review, disclosure, monitoring or follow up. Where the provider is in scope of NHS England’s Patient Safety Incident Response Framework, response and learning should follow that framework and local policy. Do not assume that framework applies identically to every independent provider. Other duties, including candour and CQC notifications in England, need a fact specific assessment. A Yellow Card report does not replace patient communication or local incident investigation. NHS England: Patient Safety Incident Response Framework.

Keep the patient’s clinical record authoritative. A general safety action system can hold a reference, aggregate affected counts and named governance actions, but it should not become an unapproved repository for diagnoses, imaging, detailed observations or treatment decisions. Limit access to the identifiable patient list. If the device itself stores patient information, agree access and secure handling before repair or transfer. Clinical care and data protection decisions are separate from whether the machine can be made to run again.

Report through the current device route

For healthcare professionals in England, Wales and Northern Ireland, MHRA says adverse incidents involving medical devices should be reported to the Yellow Card scheme in line with their organisation’s medical device procedures. MHRA’s public page says a suspected problem should be reported as soon as possible and anyone can report. The provider should not wait for a manufacturer to confirm the cause. The report can make clear what is known, what is suspected and what information is still being gathered. Keep its reference number and update the internal record when further evidence becomes available.

Scotland’s provider reporting route differs. MHRA guidance directs relevant Scottish incidents to the Health Facilities Scotland system, while its Yellow Card medical device page refers to the Incident Reporting and Investigation Centre. Scottish private care can have a different route. A page targeting Scotland would need a separate current process check before publication. Do not label Yellow Card as the only UK device reporting route. MHRA: Yellow Card medical devices page.

Do not confuse provider reporting with manufacturer vigilance reporting. The MHRA manufacturer requirements address the manufacturer’s legal reporting and trend duties. A hospital or clinic using a device should follow its own provider route and tell the manufacturer about the problem, as the MHRA checklist recommends. It should not assume that a manufacturer will make the provider’s Yellow Card report, or that a provider report discharges the manufacturer’s obligations. MHRA: manufacturer vigilance reporting requirements.

Identify other applicable routes. The provider may have local incident reporting, NHS patient safety reporting, a CQC notification assessment, occupational injury reporting or contractual notification to a commissioner. Whether each applies depends on the actual event and organisation. List the route, decision maker, decision, deadline if one applies and evidence of submission or reason not to submit. Do not merge them into a vague reported to authorities tick box. An unsubmitted form draft is not a completed report.

Work with the manufacturer without surrendering the investigation

The manufacturer may ask for logs, the device, consumables or use details. Share what is necessary through an approved process, with attention to patient confidentiality and any ongoing statutory investigation. Get a written account of what the manufacturer receives, what tests it will perform, when results are expected and whether its analysis could alter or destroy the item. Preserve copies or photographs of key identifiers. Ask how it will communicate findings and whether it knows of similar reports or a field safety corrective action.

Manufacturer analysis can be valuable but is only one part of the provider’s decision. The provider still needs to review its own use, maintenance, training, system integration and clinical impact. A conclusion of no fault found may reflect a transient problem, incomplete logs or a use context issue. The clinical engineering team should consider whether the device can safely return, whether additional checks are needed and whether the operating instructions or training require change. Do not close a patient safety investigation solely because a warranty repair has completed.

If the manufacturer later issues a field safety notice, move that notice through the separate field safety notice response workflow. Match affected serials, locations and users, complete its required actions and retain evidence. A local Yellow Card incident and a later notice are related records, but they answer different questions. The incident concerns what occurred to patients or users; the notice concerns a defined population and manufacturer corrective action. Link them without double counting or losing either.

If repair is needed, use a controlled decontamination and repair handover. The incident hold should explicitly say when the device may be released to a manufacturer or engineer, what evidence must be copied first, and whether it can ever return to patient use. Some devices may need disposal instead. These are technical and clinical decisions, not a default result of a completed work order.

Decide on return to service or withdrawal

A return to service decision should name the specific device, configuration and fault. The clinical engineering team can verify repairs, performance, applicable electrical safety and manufacturer instructions. The clinical service can decide whether the equipment is suitable for its intended patient pathway and whether operators need training or altered checks. The provider should confirm that any patient investigation, regulator report or evidence retention requirement does not bar the proposed action. A green asset status should follow these decisions, not create them.

Record the defect found, parts and software changed, tests performed, results, remaining restrictions, signatories and date of release. If the underlying cause remains uncertain, the team may require enhanced monitoring, a limited scope of use or continued withdrawal. There is no universal number of successful test cycles that proves every device safe. The test plan depends on the device and failure mode. If another unit of the same model remains in service, confirm whether a population action is also required.

Learn from the event beyond the single asset. Could the incident have been detected sooner by routine checks? Did a user report reach the right person? Were patient and device identifiers linked? Did the team know to preserve the item? Did an automated software update change the version overnight? Were technicians able to access logs before they expired? A corrective action should address the system weakness and be tested. A general corrective action effectiveness method applies here to a device specific safety event.

A worked example of a plausible wrong reading

A community clinic notices that a monitoring device repeatedly gives a normal looking value that conflicts with a patient’s symptoms and a second method. The clinician assesses and cares for the patient using qualified judgement. The device is removed from routine use and labelled. The team saves its serial number, settings, software version, maintenance record and relevant display data through the approved process. It checks whether the same unit was used for other patients during the plausible fault period. The clinical lead decides whether any previous results need review.

The medical device safety officer submits a Yellow Card with the suspected problem and available facts. The manufacturer is told and asked to investigate without destroying evidence before the provider has documented what it needs. The clinic identifies two other units of the same model and checks their status, but does not automatically stop all monitoring without assessing alternative capacity. The engineer finds an intermittent sensor connection. A repair and performance test are completed, followed by separate clinical release. The patient safety review remains open until any affected records and communication decisions are settled.

The example illustrates why the event has at least four tracks: immediate patient care, evidence and device control, external reporting, and organisational learning. It gives no diagnostic threshold or mandatory lookback period. Those decisions need case specific professional review.

Where Complys fits

Where implemented and verified, Complys supports incident and asset evidence workflows: a non clinical incident reference, device identity, an evidence preservation task, a report confirmation, supplier response and corrective action follow up. It does not submit Yellow Cards, trace patients, investigate causation, make clinical decisions or certify a device safe for use. Keep patient assessment and identifiers in approved clinical systems and link by a controlled reference. A reported badge should be tied to an actual submission reference or documented route decision, and a closed engineering task should not auto close the clinical review or regulator response.

Sources

Related: hospitals compliance software, incident reporting software, and other compliance guides.