Use case
From the hospital's phone call to the field safety notice: vigilance reporting for medical devices as a workflow that meets every deadline of the regulation.
A manufacturer of infusion pumps, around 350 employees, hospital customers in eight countries. The vigilance officer also heads quality assurance. Wednesday, 11:20: a hospital writes that a pump stopped in intensive care without raising an alarm; the patient is stable. From this email, a clock is running whose length nobody knows yet: fifteen days if it is a serious incident, ten if the patient's condition deteriorates unexpectedly, two if there is a serious threat to public health. Which hospitals have pumps from the same batch is recorded in three systems. We supply the tool your vigilance officer uses to work through such cases and meet the deadlines. Deciding and submitting remain a matter for your company.

Duty
What the law requires
The Medical Device Regulation staggers the deadline according to the severity of the case. That makes classification the most important step, and it can change.
| Legal basis | Regulation (EU) 2017/745 on medical devices (Medical Device Regulation, MDR), Article 87 reporting, Article 88 trend reporting, Article 89 field safety corrective actions; in Germany also the German Medical Devices Implementation Act (MPDG) |
|---|---|
| Who is affected | Manufacturers of medical devices placed on the market in the EU, such as infusion pumps, patient monitors or software as a medical device |
| Trigger | A serious incident involving one of your own products that the manufacturer becomes aware of, or a field safety corrective action it intends to take |
| Deadlines | Report no later than 15 days after becoming aware; no later than 10 days in the event of death or an unanticipated serious deterioration in health; no later than 2 days in the event of a serious public health threat. If the investigation takes longer, an initial report is permitted. |
| Recipient and channel | The Federal Institute for Drugs and Medical Devices (BfArM), or for certain high-risk in vitro diagnostics and companion diagnostics the Paul-Ehrlich-Institut (PEI), via the European vigilance system in the EUDAMED database (Article 92), or via the national forms until EUDAMED becomes mandatory |
| Corrective action | A field safety corrective action (FSCA) must be reported before it is carried out. Users receive a field safety notice (FSN). |
| Trend | A statistically significant increase in incidents that are not serious must be reported as a trend (Article 88). |
| Legal position as of | October 2026. We build the workflow; the legal assessment of whether and how a case must be reported stays with your regulatory affairs department, legal department or law firm. |
Clock
The workflow, day by day
The tool takes in every report, proposes a classification, calculates the deadline and prepares every notification. Nothing goes out that has not been approved. Day zero is the day you become aware.
- Minute 0
The report arrives, whatever the channel
An email from a hospital, a call to the hotline, the complaints system, a report from the field service or a report from a subsidiary: every incoming report becomes a case. The workflow reads the text, in other languages too, and extracts the product, serial number, software version, time and consequences for the patient. Whatever is missing, it requests from the hospital with a draft.
- Hour 2
Classification with a proposal and reasons
The workflow checks the details against the criteria of your vigilance procedure: incident or not, serious or not, death or unanticipated serious deterioration, serious public health threat. For each criterion, it cites the passage in the report. Your vigilance officer confirms or changes the classification. The deadline counts from receipt, not from the decision.
- Day 1
Serial numbers and similar cases
From production, deliveries and service visits, the workflow determines where devices from the same batch or with the same software version are installed, hospital by hospital. It puts similar cases from the complaints system in front of the vigilance officer, because a second case can change the classification.
- by day 2, 10 or 15
Report to the authority, initial if need be
The case produces the draft report with all mandatory details. The clock sends reminders and escalates to management if nobody has approved it. If the investigation is not finished, the workflow proposes an initial report. If the hospital sends further information and the classification changes, the clock immediately recalculates the shorter deadline.
- Weeks 1 to 4
Investigation and follow-up report
Development and quality assurance investigate the cause. The workflow gathers the findings and writes the draft follow-up report: cause, serial numbers affected, risk, planned measures.
- before the action
Reporting the corrective action, sending the field safety notice
If you decide on a field safety corrective action, such as a software update or a replacement, the workflow prepares the report that must be received before it is carried out. It then produces the field safety notice in every language of your hospitals, with a reply form, and after approval sends it only to the hospitals with the serial numbers affected.
- afterwards
Replies, closure and trend
Every hospital confirms receipt. The workflow matches the replies to the serial numbers and follows up where nothing arrives. Alongside this, it analyses all complaints and flags when incidents that are not serious increase noticeably, as the basis for a trend report under Article 88.
Cascade
Who learns what has happened, and when
First your own company and the authority, then the hospitals with affected devices, then the partners in other countries. Each outgoing wave has a draft, a person who approves it and a point in time in the log; the internal alert goes out immediately.
| Wave | Recipient | Channel | Content | Approval |
|---|---|---|---|---|
| 1, on the same day | Vigilance officer, management, development, service | Teams or email, a call if a serious threat is suspected | Report, classification proposal, deadline | none, internal alert according to a fixed list |
| 2, within the deadline | BfArM or PEI, with the first report and later the follow-up report | EUDAMED or the national form | Mandatory details, status of the investigation, measures | Vigilance officer |
| 3, before the action | Hospitals with exactly the serial numbers affected | Field safety notice by email and letter in the local language, a call from the field service | What has happened, which devices, what users should do, reply form | Vigilance officer and management |
| 4, at the same time | Distributors and subsidiaries in the other countries, the notified body as your procedure requires | Email to the vigilance contacts on file | Their affected customers, field safety notice in their language | Vigilance officer |
| 5, until closure | Hospitals and partners that have not replied | Reminder by email, call list for the field service | Status per serial number, support with the changeover | Head of service |
You set the order, the templates per language and the contacts per hospital in the analysis. If a reply does not arrive, the hospital goes onto the field service's call list.
Approval
What stays with your people
- The classification. Whether an incident is serious and which deadline applies is decided by your vigilance officer. The workflow proposes, and shows when new information calls the classification into question.
- Every report to the authority. The first report, the initial report and the follow-up report only go out after approval.
- The corrective action. Whether an update or a replacement is needed is decided by development, quality assurance and management.
- The wording of the field safety notice. Your company approves the source version, and a person checks every translation.
- The conversation with the authority and the hospital. Your people handle questions from the BfArM and conversations with the hospital, with the case in front of them.
Integration
Which systems the workflow sits in
Vigilance lives in your quality management system under ISO 13485 and in the technical documentation. The workflow fits into their procedures, reads from your systems and writes back to them.
- IncomingVigilance inbox, hotline, field service, distributors and subsidiaries, enquiries from authorities
- ComplaintComplaints module of your quality management system, the service team's ticketing system
- Serial numbersERP with batches, deliveries and customers, device history from maintenance and service visits, CRM with contact persons per hospital
- DocumentationTechnical documentation, risk management file, instructions for use
- CommunicationEmail and letter with templates per language, Teams for escalation, call list
- AuthorityEUDAMED and the national forms. Authority portals rarely have an interface: the workflow pre-fills the report, a person enters it, and the timestamp goes into the log.
Evidence
The log is the evidence
When the authority or the notified body asks when you became aware and when you reported, the answer is an export. Every step is in the case with a timestamp: receipt, classification with reasons and every change to it, every report, every field safety notice, every reply per serial number.
The workflow also documents the reports that turned out not to be a serious incident after checking. That way you can show in the audit that you checked every complaint.
Twice a year a trial run with a made-up incident passes through the workflow without anything going out. It shows whether serial numbers and contacts are right and whether those who approve respond in time.
Experience
What we bring
The building blocks of this reporting chain have been running at our customers for years. For a fuel cell manufacturer we built the service portal with its returns process and maintain the service content in eleven languages with the customer's technical glossary, every version checked. There we also applied a set of rules to an entire text inventory, classifying every finding and giving reasons. Reading and assigning incoming items at scale is something we know from a technology distributor with twelve sites, where enquiries from twelve sites across Europe reach the right team according to rules. Cases with log and approval run every night in our own operations.
We put the vigilance chain with its three deadlines into operation together with your vigilance officer, and a made-up incident serves as the acceptance test. It shows whether the workflow finds every hospital with the serial numbers affected and whether the deadline restarts immediately when the classification becomes more severe. We show you the log of such a run as an example in the first call.
Price
Price and scope
The order of magnitude first: the workflow analysis costs €4,900 at a fixed price and takes three days. Based on our projects, a custom tool typically costs between €25,000 and €60,000, as a fixed price that becomes binding after the analysis; the first version is ready in about six weeks, longer with several duties and languages. Ongoing operation after that starts at €2,900 a month and can be cancelled monthly. A narrower figure in advance would be guesswork: one product family in one country and five product lines in eight countries do not need the same tool. What determines the price:
- number of incoming channels and countries that reports come from
- number of systems holding serial numbers and contacts
- number of languages for the field safety notice
- how far your quality management system already offers interfaces
- whether trend analysis is part of it
Data flow: reports contain health information. They stay on your server or in a German data centre, the AI components run on open models on your own servers or in EU data centres, and no model trains on them. Data flow per service.
Related
Related use cases
- Product safety: recall and market surveillance. The same cascade for products that are not medical devices.
- Cyber Resilience Act: reporting a vulnerability. Medical devices are excluded from it; their cybersecurity requirements are set out in the Medical Device Regulation itself.
- EU AI Act: reporting a serious incident. The same deadlines of two, ten and fifteen days under Regulation (EU) 2024/1689, when a high-risk AI system works inside your product.
- All use cases: reporting duties with deadlines, with the table of deadlines across all duties.
Further reading: Monitoring and maintaining an AI workflow and Texts at scale with AI and checks, in several languages too.
Questions
Questions about the reporting chain in medical device vigilance
What vigilance officers and quality assurance want to know before a tool becomes part of their procedure. More answers under Questions and answers.
Does the AI decide whether an incident is serious?
No. It proposes a classification and gives its reasons with the details from the report and the criteria of your vigilance procedure. The decision is made by your vigilance officer. The deadline still counts from receipt.
Does the workflow fit into our quality management system under ISO 13485?
It has to fit into it, not sit alongside it. In the analysis we read your vigilance procedure and map its steps. We plan the validation of the tool according to your procedure from the start.
Who is there at night and at the weekend, and who is liable for what?
If a hospital reports an incident on a Saturday, the workflow opens the case, calculates the possible deadlines and calls the people on your on-call list until someone confirms. As part of ongoing operation we monitor that the workflow is running, with response times on working days; round-the-clock standby is agreed separately. If it fails, the on-call list, templates and hospitals per serial number are ready as an export, and your vigilance officer carries on by hand. Your company remains responsible as the manufacturer for the deadlines; we are liable for the tool under our terms and conditions.
Who translates the field safety notice?
The workflow produces the language versions from the approved source version, using your technical glossary. Before sending, a person who knows the language checks every translation. No version goes to a hospital unchecked.
Handover
The first step is a 30-minute call.
You tell us about the workflow that costs you the most time. We tell you honestly whether AI pays off there and what the next step would be. Whether a workflow analysis follows is up to you.