Expert knowledge for digital decisions
What to do in case of security incidents and reportable events?
Short answer
Patient Protection and Evidence Preservation First
In the event of a malfunction, incorrect software output, cyberattack, or failed interface, further damage must be prevented first. This may require a safe shutdown, isolation of a service, reverting to a validated procedure, or informing affected operators. At the same time, software version, configuration, logs, input data, timestamps, and any changes made must be secured against tampering. An unverified reinstallation can destroy important evidence.
Simultaneously, regulatory triage takes place. Article 2 number 64 MDR defines an incident among other things as a malfunction or deterioration in performance, ergonomically induced user error, insufficient manufacturer information, or adverse effect. According to number 65, it is serious if death, temporary or permanent serious deterioration of health, or a serious threat to public health has occurred, could have occurred, or could occur. Even a "near miss" without actual damage can therefore be reportable.
Deadlines According to Article 87 MDR
Manufacturers must report immediately upon becoming aware and no later than:
- within 15 calendar days for other serious incidents,
- within 10 calendar days for death or unexpected serious deterioration of health,
- within 2 calendar days for a serious threat to public health.
MDCG 2023-3 Rev. 2 explains terms, awareness date, and deadline calculation. If there is uncertainty, the investigation should not delay the report: a timely initial report can initially be incomplete and supplemented by follow-up reports. In Germany, the BfArM provides the current reporting pathway for manufacturers and authorized representatives; responsibilities may also lie with the Paul-Ehrlich-Institut for certain IVDs.
Investigation, Correction, and Communication
An incident team should designate regulatory, clinical, technical, data protection, and communication roles. The investigation considers the cause, affected versions and installations, probability of occurrence, possible clinical consequences, and whether the event can occur systematically. Findings feed back into risk files, cybersecurity assessments, clinical evaluations, and post-market surveillance.
If risk reduction requires a safety corrective action in the field, Articles 87 paragraph 1(b) and paragraph 8 as well as Article 89 MDR also apply. Measures, communication with authorities, and safety information to customers must be coordinated, traceable, and effectiveness-tested. Technical troubleshooting, CAPA, and regulatory reporting are three connected but distinct work packages.
The specific reporting obligation depends on the product, role, event, and country. Therefore, internal escalation paths should be significantly shorter than the statutory maximum deadlines and involve responsible specialists or authorities early on.
Example from practice
An incorrect therapy recommendation is secured with version, inputs, and logs before troubleshooting. Meanwhile, the vigilance team examines possible consequences and deadlines; the technical root cause analysis continues without delaying the required initial report.
Key facts
- Regulatory Deadline
- No later than 15 calendar days
- Death or unexpected serious deterioration
- No later than 10 calendar days
- Serious threat to public health
- No later than 2 calendar days
- Legal Basis
- Article 2 number 64/65 and Article 87 MDR
Sources
All external claims are backed by traceable sources.-
01
Verordnung (EU) 2017/745, insbesondere Artikel 2 und 87 bis 89 EUR-Lex / Europäische Union
-
02
MDCG 2023-3 Rev. 2 – Q&A on vigilance terms and concepts Medical Device Coordination Group / Europäische Kommission
-
03
Vorkommnismeldung durch Hersteller und Bevollmächtigte Bundesinstitut für Arzneimittel und Medizinprodukte (BfArM)