SITUATIONAL: Medical Device Safety Reporting
The Complaint File That Became a Warning Letter:
A Medical Device Safety Reporting Case Study
A mid-size manufacturer of Class II patient warming devices received an FDA Form 483 following a routine inspection in September 2023. The finding was narrow but critical: the company had not established internal systems for timely and effective identification, communication, and evaluation of events that may be subject to Medical Device Reporting requirements. When the company’s response to the 483 was judged inadequate, the situation escalated to a warning letter. This case study reconstructs the sequence of events, the root causes, and the specific MDR programme failures that allowed a correctable gap to become a public enforcement action.
#1
FDA 483 Observation Year After Year
Medical Device Reporting procedure failures and failure to properly evaluate complaints for reportability have been one of the most common FDA Form 483 observations year after year. MDR non-compliance is not a rare edge case, it is a persistent, industry-wide pattern.
RAPS: MDR Reporting Discussion (2023)
30 days
Standard MDR Reporting Deadline
Under 21 CFR 803.50, manufacturers must report a death or serious injury within 30 calendar days of becoming aware of the event. A 5-working-day report is required when the malfunction necessitates remedial action to prevent unreasonable public health risk. The clock starts when anyone in the organisation becomes aware, not when the formal investigation is complete.
21 CFR Part 803
96%
Rise in FDA Device Warning Letters 2023 to 2024
FDA issued 47 medical device warning letters in fiscal year 2024, up 96% from 24 in FY2023. MDR deficiencies, inadequate reporting procedures, failure to evaluate complaints for reportability, and late or missing reports, were among the most cited findings.
MedDeviceGuide: FDA MDR Analysis 2026
A manufacturer of Class II patient warming blankets, the kind used in surgical suites to maintain body temperature during procedures, had operated for eleven years without a warning letter. Their MDSAP audit history was clean. They had a written MDR procedure. They had a designated regulatory affairs contact for reportability evaluations. On paper, the medical device safety reporting programme was functional.
The FDA inspection ran for eight days in September 2023. The investigator reviewed complaint files and MDR event records for the 24-month period under review. What she found was not a catastrophic absence of procedures, it was a systematic gap between what the written procedure required and what actually happened when a complaint came in.
The core finding: a procedure that existed on paper but not in practice
The company’s written MDR procedure described an internal system for identifying events, routing them to the designated decision-maker, and documenting the reportability evaluation. The investigator found that the actual complaint handling process did not reliably trigger this system. Complaints received by the customer service team were entered into the complaint database, but the step that was supposed to flag complaints for MDR evaluation had been bypassed in a software update 14 months earlier. The MDR decision-maker had not received 23 complaints that the investigation later determined should have been evaluated for reportability under 21 CFR 803.
Root Cause 1: Software change control did not include regulatory affairs review
The complaint management software upgrade was treated as an IT project. The change control record included validation of data migration and system performance, standard software validation categories. It did not include a step requiring regulatory affairs to confirm that MDR workflow functions were intact after the upgrade. A QMS whose software change control process does not involve regulatory affairs review is structurally unable to protect MDR programme integrity across software changes. The gap was not a one-time oversight, it was a process design failure.
Root Cause 2: The MDR decision-maker had no independent visibility into complaint volume
An MDR programme that depends entirely on automated routing, with no periodic manual reconciliation between complaint volume and MDR evaluation volume, has a single point of failure. When the routing broke, the decision-maker did not notice because she had no baseline to compare against. A monthly check of total complaints received versus total MDR evaluations initiated would have exposed the gap within 30 days. No such reconciliation existed.
Root Cause 3: The 483 response corrected the symptom but not the root cause
The company’s 483 response described fixing the software routing flag and revising the MDR procedure. It did not address three things the FDA expected: a retrospective review of all 23 unevaluated complaints, late MDR submissions for the three events that met the reporting threshold, and a CAPA that addressed why the software change control process failed to involve regulatory affairs. Fixing the software without retrospectively evaluating what the broken software missed is not a complete corrective action under 21 CFR 820.100. The FDA said so in the warning letter.
Root Cause 4: No internal audit had covered the MDR complaint routing process
The company’s internal audit programme covered complaint handling, MDR procedures, and CAPA. None of the audit records for the 14 months before the FDA inspection had included a check of complaint volume against MDR evaluation volume, the single test that would have caught the routing failure. Internal audits that check whether MDR procedures are written correctly but do not verify whether the MDR pipeline is actually receiving complaints cannot serve as a control for MDR programme integrity.
Immediate: Retrospective review of all 23 unevaluated complaints
The facility was required to conduct a complete retrospective review of all 23 complaints that had not been evaluated for MDR reportability. Each complaint was reviewed by the MDR decision-maker against the criteria in 21 CFR 803.3 for death, serious injury, and malfunction. The review had to be documented with written rationale for each determination, regardless of the outcome. This retrospective documentation became part of the MDR event file for each complaint.
Immediate: Submit late MDR reports for the three patient intervention events
The three events in which patients required nursing intervention were submitted as late 30-day MDR reports to the FDA. Each report included an explanation of the delay, the circumstances of the routing failure, and a summary of the event. Late reports are always preferable to no reports, the FDA expects them to be filed as soon as the reporting obligation is identified, regardless of how much time has elapsed.
CAPA: Fix the software routing and add a monthly reconciliation check
The software routing flag was restored and validated. A monthly reconciliation check was added to the MDR procedure: the MDR decision-maker reviews total complaints received versus total MDR evaluations initiated each month and documents the reconciliation. Any gap triggers an immediate investigation. This check provides an independent verification that the MDR pipeline is functioning regardless of what the software is doing.
CAPA: Revise software change control SOP to include mandatory regulatory affairs review
The software change control SOP was revised to include a mandatory regulatory affairs review step for any change to systems that touch complaint handling, MDR routing, or CAPA workflows. The review must confirm, with documented evidence, that regulated workflows function correctly after the change, including the MDR routing pathway. This requirement was added as a QA gate: no software change affecting regulated workflows can be closed without regulatory affairs sign-off.
Systemic fix: Add MDR pipeline verification to the internal audit programme
The internal audit checklist for complaint handling was revised to include a verification step: auditors compare the complaint log total against MDR evaluation totals for the audit period. If these numbers do not reconcile, the audit finding is opened immediately. The audit frequency for complaint handling and MDR was increased from annual to semi-annual. The internal audit team was required to review the reconciliation methodology with the MDR decision-maker during each audit cycle.
A software change that touches complaint handling is a regulatory change, treat it as one
Any modification to a system used for complaint intake, complaint routing, MDR evaluation, or CAPA tracking must include regulatory affairs in the change control review. The technical question, does the software work?, is separate from the regulatory question, does the software still do what our MDR procedures require it to do? Both must be answered before the change is closed.
MDR volume should be periodically reconciled against complaint volume, not assumed to be accurate
An MDR programme that has no periodic check of complaint volume versus MDR evaluation volume has no way to detect a pipeline failure. The check does not need to be elaborate: a monthly count of complaints received against MDR evaluations initiated, documented by the decision-maker, provides a simple and verifiable control that the pipeline is functioning. Facilities that rely entirely on automated routing without a manual reconciliation have one point of failure with no backstop.
A 483 response that fixes the symptom without addressing the root cause is not a 483 response that satisfies FDA
When the FDA issues a Form 483, they expect the response to: address the specific finding with documented corrective action, address the root cause of the finding (not just its surface manifestation), and address any events that occurred because the finding existed. In this case, the missing elements were retrospective complaint reviews and late MDR filings, the records showing the facility closed the gap, not just fixed the system. A 483 response is not complete until the backlog is cleared, not just the process fixed.
A clean MDSAP audit history does not protect against an FDA inspection finding
This facility had no MDSAP findings in the prior cycle. The MDSAP audit did not catch the routing gap because the gap developed after the last audit and the audit checklist, like the internal audit checklist, did not include a reconciliation check between complaint volume and MDR evaluation volume. MDSAP acceptance by FDA as a substitute for routine inspection does not mean FDA will not inspect when a specific concern arises. And MDSAP auditors miss what they do not check.
MDR failures are rarely the result of deliberate non-compliance, they are usually process design failures
This facility had an MDR procedure. They had a designated decision-maker. They had a complaint management system. What they did not have was a system that kept working when one component changed. MDR programme integrity requires resilience, controls that survive software updates, personnel transitions, and process changes, not just a procedure that is correct on the day it is written.
FDA warning letters for MDR deficiencies are rising sharply, the enforcement environment has changed
A 96% increase in medical device warning letters from FY2023 to FY2024, with MDR deficiencies among the most cited findings, signals a shift in FDA’s enforcement posture on post-market reporting. Facilities that operated for years with procedural MDR gaps without enforcement action should not assume that trend will continue. The inspection that exposes this facility’s gap today is more likely than it was two years ago.
The 483 response is as important as the 483 finding, an inadequate response is what turns an observation into a warning letter
In every case in this article, the escalation from 483 to warning letter was driven not by the original finding but by an inadequate response. FDA gave each facility the opportunity to demonstrate corrective action. The facilities that generated warning letters responded with partial corrections, fixing the forward-looking process without closing the backward-looking gap. A complete 483 response addresses three things: the systemic fix, the root cause of the systemic gap, and the events that occurred because the gap existed. Any response that only addresses the first is incomplete.
What is medical device safety reporting and what does it require?
Medical device safety reporting in the US is governed by 21 CFR Part 803, the Medical Device Reporting regulation. It requires device manufacturers to report to the FDA when they become aware that a device may have caused or contributed to a death or serious injury (30-day report), or when a device malfunction would likely cause or contribute to serious injury if it were to recur (30-day report), or when an event requires remedial action to prevent unreasonable risk to public health (5-day report). Manufacturers must also evaluate every complaint for MDR reportability and maintain written MDR procedures and event files. Source: 21 CFR Part 803
When does the 30-day MDR clock start?
The 30-day MDR clock starts when the manufacturer becomes aware of information suggesting that a device may have caused or contributed to a death or serious injury, not when the investigation is complete, not when the root cause is confirmed, and not when the regulatory affairs team formally reviews the event. “Becomes aware” means when any employee receives information, a complaint call, a service report, a distributor communication, or a social media post, that reasonably suggests an MDR-reportable event may have occurred. Starting the clock at the end of the investigation is one of the most common MDR compliance errors. Source: FDA: Medical Device Reporting, How to Report
What must an MDR event file include for a non-reportable determination?
Under 21 CFR 803.18, MDR event files must be maintained for all events that were evaluated for reportability, whether or not a report was ultimately filed. A non-reportable determination file must include: the information received about the event, the date of receipt, the evaluation criteria applied (typically the 21 CFR 803.3 definitions of death, serious injury, and malfunction), the written rationale for the non-reportable determination, and the name of the person who made the determination. A checkbox marked “not reportable” without a written rationale is not an MDR event file that meets 21 CFR 803.18 requirements. Source: 21 CFR 803.18
What makes an FDA Form 483 response adequate?
An adequate 483 response must: address every observation in the 483 separately and completely, describe the specific corrective actions taken and the timeline for implementation, address the root cause of the observed deficiency (not just its surface manifestation), and provide objective evidence, not promises, of the corrections. For MDR findings specifically, an adequate response typically also includes: a retrospective review of events that may have been affected by the deficiency, late MDR filings for any events that should have been reported, and a CAPA that addresses why the MDR programme gap existed and how it will be prevented from recurring. A response that describes what the facility plans to do but provides no evidence of what it has done is routinely found inadequate. Source: FDA: Responding to FDA Form 483s
Can a facility submit an MDR after the 30-day deadline has passed?
Yes, and it is required. A reporting deadline that has passed does not eliminate the obligation, it creates a late report situation that must be addressed as part of the CAPA response to any MDR finding. Late reports should be submitted as soon as the reporting obligation is identified, with an explanation of the circumstances of the delay. FDA’s position is that late reports are preferable to no reports. A CAPA that corrects the systemic cause of an MDR programme failure without also submitting the outstanding late reports does not fully resolve the finding and will typically be found inadequate. Source: 21 CFR Part 803
What is the regulatory definition of “serious injury” for MDR purposes?
Under 21 CFR 803.3, a serious injury is an injury or illness that is life-threatening, results in permanent impairment of a body function or permanent damage to a body structure, or necessitates medical or surgical intervention to preclude permanent impairment of a body function or permanent damage to a body structure. The critical phrase is “necessitates medical or surgical intervention to preclude”, this means that if medical intervention was required to prevent a worse outcome, the event is a serious injury even if no permanent harm occurred. A nurse restarting an infusion pump to prevent temperature loss, a clinician administering a reversal agent to address a device-related effect, or a surgeon removing a migrated component all constitute medical intervention under this definition. The absence of permanent harm does not make the event non-reportable. Source: 21 CFR 803.3
How does FDA enforcement for MDR violations differ from MDSAP findings?
An MDSAP Chapter 4 finding for adverse event reporting is an audit observation graded by the Auditing Organisation. It requires a CAPA response and is visible to all five MDSAP participating regulatory authorities, but it is not an FDA enforcement action. An FDA warning letter is a public enforcement action that appears on FDA’s website, triggers escalating scrutiny, and can precede injunctions, consent decrees, and import restrictions. A facility can have MDSAP Major findings without receiving a warning letter, and can receive a warning letter without having had a prior MDSAP Major finding, as in this case study. The two oversight systems are related but not identical, and an MDSAP clean record does not insulate a facility from FDA enforcement. Source: FDA: Warning Letters
Guides
21 CFR Part 803: Medical Device Reporting Requirements
The complete MDR reporting guide covering 30-day, 10-day, and 5-day timelines, the routing rules for each entity type, and the event file requirements that this case study’s audit directly examined.
Situational
MDSAP Chapter 4: What 14 Missed Reports Cost One Facility
A parallel case study showing how MDSAP Chapter 4 adverse event findings develop, the same root causes (missing written rationale, misclassified events) from the MDSAP audit perspective rather than FDA inspection.
Insights
MDSAP Production Controls: Where Audit Findings Hide
Evidence-based analysis of why production and service control processes, including complaint handling and CAPA, generate the most findings in MDSAP audits, directly relevant to the systemic gaps described in this case study.
MEDICAL DEVICE COMPLIANCE LIBRARY
More Case Studies and Regulatory Analysis
Explore VelSafe’s situational library for case studies, incident analyses, and regulatory enforcement breakdowns covering FDA inspections, MDSAP audits, and complaint handling failures across the medical device industry.
Explore Situational Articles