Evidence explainer

Health policy, systems, and equity

How Post-Market Surveillance Works: Watching a Device After It Reaches Patients

Approval is a judgment made on the evidence available at one moment. Post-market surveillance is the system that keeps testing that judgment once the device reaches patients.

Fully reviewed by Jasaman (Jasmin) Tojjar, MD, PhD

On this page
  1. Key points
  2. Why one approval cannot settle the question
  3. The three jobs the system does
  4. Turning findings into action
  5. What surveillance can and cannot promise

Post-market surveillance is the organized system that keeps monitoring a medical device once it clears regulatory review and starts reaching patients. Approval or certification is a judgment made on the evidence available at one moment, and everyday use keeps adding information that no pre-market study can fully predict: rare complications, unusual failure modes, off-label habits, and how a device behaves across a population far broader than any trial enrolled. The rules here differ by country and by device class, and nothing below is legal advice.

Key points#

Why one approval cannot settle the question#

Think of a pre-market submission as answering one narrow, bounded question: does the evidence show that this device, used as intended, is safe and performs as claimed? Even a carefully run pivotal trial studies a defined group of people, over a defined stretch of time, under conditions tidier than ordinary care. That is a feature, not a flaw. It is simply not the whole story.

Once a device is in wide circulation, three things change at once. The number of uses climbs by orders of magnitude, follow-up stretches out over years, and the users now include people a trial would have screened out. A malfunction that shows up once in ten thousand uses might never appear in a study, yet it becomes visible across a national market. That is the gap surveillance exists to close. Surveillance is the machinery that turns this scattered, real-world experience into structured evidence a manufacturer and a regulator can actually act on.

The three jobs the system does#

Gathering and analyzing data, without pause#

The base layer is a standing routine rather than an occasional audit. A manufacturer is expected to keep a post-market surveillance plan that spells out what it will collect and how it will read the results. The inputs are deliberately mixed: complaints and returned units, service and repair logs, and the published literature. They also include registry entries and follow-up studies that keep collecting clinical evidence after launch. In the European framework this planned clinical follow-up carries its own label, post-market clinical follow-up, and it exists so the clinical evidence does not freeze on the day a certificate is issued.

Collection alone is not enough. Individual reports are noisy, and the real work is spotting patterns against a baseline of expected performance: a climbing complaint rate, a cluster of similar faults, a change in the kind of harm you are being told about. This is where statistical thinking earns its keep, because separating a genuine signal from ordinary variation is the central difficulty of the job.

Reporting serious incidents fast#

Some events cannot wait for a scheduled review. When a device may have contributed to a death, a serious decline in health, or a serious public-health threat, quicker reporting duties kick in. The European system, under its Medical Device Regulation and the parallel In Vitro Diagnostic Regulation, calls this vigilance: manufacturers notify the competent authorities of serious incidents and of any field safety corrective actions, such as a recall, a design change, or updated instructions, within set timeframes. In the United States, the comparable route is medical device reporting, through which manufacturers, importers, and certain facilities tell the FDA about deaths, serious injuries, and malfunctions that could recur with harm.

Two mechanisms give this teeth. The first is the field safety corrective action, the concrete step taken once a problem is confirmed and communicated to users through a field safety notice. The second is trend reporting, a duty to flag a statistically significant rise in non-serious events or expected side effects, so a slow drift does not slip by simply because no single event crossed the serious threshold.

Summarizing the picture on a schedule#

Between the urgent alerts and the constant collection sits the periodic review. Under the European regulation, makers of higher-risk devices assemble a periodic safety update report, often shortened to PSUR. It draws together the surveillance findings, the vigilance data, the trend analysis, and any corrective actions. It ends with a refreshed benefit-versus-risk conclusion. For the highest-risk classes this update is expected roughly yearly, with a longer gap allowed for lower-risk devices.

The value of the periodic report is synthesis. It forces a manufacturer to ask, in writing and on a fixed schedule, whether the accumulated real-world evidence still supports the benefit-risk balance that justified the device in the first place. That single question is the hinge between watching and acting, and it is the one worth looking for in any report.

Turning findings into action#

Surveillance only earns its cost if it changes something. A well-built system routes its findings back into the device's risk management file, the living record of known hazards and the controls meant to hold them in check. When post-market data expose a hazard that was underestimated, or a brand-new one, the expected response is to reassess the risk, tighten the controls, and, where needed, alter the product. That can look like revised instructions for use, a labeling update, or a software patch. It can look like a design change or added training. In the more serious cases, it can look like a recall.

Regulators keep levers of their own. In the United States, the FDA can order a manufacturer to run a post-market surveillance study under Section 522 of its governing statute, typically for devices whose failure could cause serious harm, implants meant to stay in the body beyond a year, or life-sustaining devices used outside a clinical setting. Authorities on both sides of the Atlantic have leaned harder into real-world evidence, pulled from registries and health records, to track long-term performance and support labeling decisions after launch.

What surveillance can and cannot promise#

It helps to be candid with you about the limits. Post-market surveillance is a signal-detection system, and signal detection is probabilistic by nature. Underreporting is real, and the true number of uses is often uncertain. Attribution, deciding whether a device caused an outcome or merely happened alongside it, is genuinely hard. The framework is built to catch important problems reliably over time, not to guarantee that every single event is captured the moment it occurs.

Seen that way, surveillance is less a verdict than a habit of continuous learning. A device enters the market on the strength of the evidence available then, and these systems exist to keep checking that judgment against reality and to change course when reality disagrees. If you are a patient or a clinician, the practical lesson is modest but real: approval is the start of the observation, not the end of it.

Sources and further reading

  1. WHO Guidance on Post-Market and Market Surveillance of Medical Devices
  2. GAO FDA Building Active Postmarket Surveillance for Devices
  3. Postmarket Surveillance of High-Risk Devices Needs Registries (PMC)

Questions and answers

Does a device get re-approved every year?

Not exactly. For higher-risk devices in the European system, the manufacturer periodically compiles a safety update that re-examines the benefit-risk balance, and regulators can require added studies or corrective steps. It is ongoing accountability rather than a fresh approval each cycle.

Who is supposed to report a problem with a device?

Duties fall mainly on manufacturers, importers, and certain healthcare facilities, who must notify the relevant authority about deaths, serious injuries, and malfunctions that could recur. Clinicians and patients can also report suspected problems, and those reports help feed the signal-detection process.

Why do some issues surface only years after launch?

Wider use, longer follow-up, and a more varied patient population reveal rare or slow-developing problems that a time-limited trial could not have shown. Surveillance is designed precisely to detect those later signals and act on them.