Question Clearly sourced

Expert knowledge for digital decisions

What to do in case of security incidents and reportable events?

Short answer

A potential security incident must be immediately technically secured and assessed from a regulatory perspective. For manufacturers, the MDR Article 87 stipulates graduated maximum deadlines: generally 15 calendar days for serious incidents, 10 days in case of death or unexpected serious deterioration of health, and 2 days for a serious threat to public health. Missing details must not delay the timely initial report.

Patient Protection and Evidence Preservation First

In the event of a malfunction, incorrect software output, cyberattack, or failed interface, further damage must be prevented first. This may require a safe shutdown, isolation of a service, reverting to a validated procedure, or informing affected operators. At the same time, software version, configuration, logs, input data, timestamps, and any changes made must be secured against tampering. An unverified reinstallation can destroy important evidence.

Simultaneously, regulatory triage takes place. Article 2 number 64 MDR defines an incident among other things as a malfunction or deterioration in performance, ergonomically induced user error, insufficient manufacturer information, or adverse effect. According to number 65, it is serious if death, temporary or permanent serious deterioration of health, or a serious threat to public health has occurred, could have occurred, or could occur. Even a "near miss" without actual damage can therefore be reportable.

Deadlines According to Article 87 MDR

Manufacturers must report immediately upon becoming aware and no later than:

  • within 15 calendar days for other serious incidents,
  • within 10 calendar days for death or unexpected serious deterioration of health,
  • within 2 calendar days for a serious threat to public health.

MDCG 2023-3 Rev. 2 explains terms, awareness date, and deadline calculation. If there is uncertainty, the investigation should not delay the report: a timely initial report can initially be incomplete and supplemented by follow-up reports. In Germany, the BfArM provides the current reporting pathway for manufacturers and authorized representatives; responsibilities may also lie with the Paul-Ehrlich-Institut for certain IVDs.

Investigation, Correction, and Communication

An incident team should designate regulatory, clinical, technical, data protection, and communication roles. The investigation considers the cause, affected versions and installations, probability of occurrence, possible clinical consequences, and whether the event can occur systematically. Findings feed back into risk files, cybersecurity assessments, clinical evaluations, and post-market surveillance.

If risk reduction requires a safety corrective action in the field, Articles 87 paragraph 1(b) and paragraph 8 as well as Article 89 MDR also apply. Measures, communication with authorities, and safety information to customers must be coordinated, traceable, and effectiveness-tested. Technical troubleshooting, CAPA, and regulatory reporting are three connected but distinct work packages.

The specific reporting obligation depends on the product, role, event, and country. Therefore, internal escalation paths should be significantly shorter than the statutory maximum deadlines and involve responsible specialists or authorities early on.

Example from practice

An incorrect therapy recommendation is secured with version, inputs, and logs before troubleshooting. Meanwhile, the vigilance team examines possible consequences and deadlines; the technical root cause analysis continues without delaying the required initial report.

Key facts

Regulatory Deadline
No later than 15 calendar days
Death or unexpected serious deterioration
No later than 10 calendar days
Serious threat to public health
No later than 2 calendar days
Legal Basis
Article 2 number 64/65 and Article 87 MDR

Sources

All external claims are backed by traceable sources.
  1. 01
  2. 02
    MDCG 2023-3 Rev. 2 – Q&A on vigilance terms and concepts Medical Device Coordination Group / Europäische Kommission
  3. 03
    Vorkommnismeldung durch Hersteller und Bevollmächtigte Bundesinstitut für Arzneimittel und Medizinprodukte (BfArM)

Ready for your next project?

Free initial consultation - no sales pressure, just clear answers.

Request consultation