Originally published on Medium.
The FDA Issued 54 Medical Device Warning Letters in 2025. The Same Three Violations Keep Leading the List.

By AEROZ Editorial September 2026
CAPA deficiencies. Design control failures. Complaint handling gaps. The FDA’s enforcement record for 2025 and early 2026 shows a pattern so steady it has stopped being a trend. It is a structural feature of how the medical device industry manages quality, and it points to the same missing link every time.
The FDA issued 54 medical device warning letters in calendar year 2025, according to enforcement data compiled by MedDeviceGuide, up from 46 the year before. The concentration of violations was striking. CAPA procedures under 21 CFR 820.100 accounted for 279 device-related Form 483 observations, 10.5 percent of all 2,660 device citations for the year. Complaint handling under 21 CFR 820.198 added another 211 observations, or 7.9 percent. Design controls appeared in 26 of the 54 warning letters.
A separate count from ECA Academy, which tallies 44 device warning letters for the fiscal year and 38 that cited the Quality System Regulation, lands on the same ranking. CAPA deficiencies appeared in 26 letters. Design controls in 25. Complaint files in 23. Read against the 38 letters that cited quality system failures at all, each of the three shows up in roughly six out of ten. Purchasing controls and process validation followed at 15 and 14.
The counts differ between trackers because they define the population differently. The order does not. These three categories have sat at the top of the list for more than two consecutive years. They are not random. They are the predictable output of a quality architecture that records events without connecting them to the manufacturing history that produced them.
“CAPA, design controls, and complaint handling have been the top three device QSR violations in every quarter since at least 2023. The pattern has been stable for years.” MedDeviceGuide, FDA Warning Letter Trends
What the first quarter of 2026 added
Cloudtheapp’s review of Q1 2026 enforcement describes the same failure repeating across multiple letters: complaints received, logged, and closed without investigation, without escalation to CAPA, and without integration into risk management. Its summary of the regulatory expectation is blunt. Complaint data is supposed to function as a safety signal that triggers risk assessment.
Two of the cases it cites make the point better than any aggregate.
In a January 28, 2026 warning letter to Beta Bionics, the review reports 56 hypoglycemia complaints closed without corrective action, while the firm’s own risk analysis classified the severity of that hazard as potentially fatal. In a March 25, 2026 letter to Medline Industries’ NAMIC division, complaint rates exceeded the firm’s own established threshold for three consecutive quarters with no remediation.
Neither of those firms lacked a procedure. One had a risk analysis that named the harm. The other had a threshold built for exactly the moment it was crossed. Both had the signal in their own files. What neither file could do was force the signal to travel from the place it was recorded to the place a decision gets made.
This is the same shape that surfaced at Fresenius Medical Care this August, where a risk matrix named peritonitis and a complaint record logged property damage for the same leaking dialysis bags. Different firm, different product, different regulation. Same gap between what the quality system knew and what it acted on.
Why the same three always travel together
It is tempting to read CAPA, design controls, and complaint handling as three separate compliance workstreams, each with its own owner, its own SOP, and its own audit checklist. That is how most organizations staff them. It is also why they fail together.
The three are one loop. A complaint is the field telling you something about a unit. A CAPA is the organization deciding whether that something is a cause. Design control is where the cause, once confirmed, is supposed to change the product. Break the loop at any point and the other two degrade with it. A complaint that is never escalated produces no CAPA. A CAPA that cannot identify a root cause produces no design input. A design history that cannot be linked to field performance produces no verification that the fix worked.
The piece that holds the loop together is evidence about specific units. Complaints are events. Production is history. An investigator who receives a complaint needs to answer a small number of questions quickly: which unit is this, what was different about how it was made, and which other units share that difference. Without a record that links the complaint event to the production history of the affected unit, each of those questions becomes a manual reconstruction across batch records, equipment logs, supplier certificates, and distribution data. Reconstructions are slow. Slow investigations get closed. Closed investigations are what the FDA cites.
So the root cause behind the root cause is rarely a missing procedure. Warning letters routinely note that written procedures exist. The failure is that the procedure assumes a data connection the system does not provide, and the people running it fill the gap with judgment, assumption, and time pressure.
The QMSR raises the bar without building the bridge
The Quality Management System Regulation took effect on February 2, 2026, incorporating ISO 13485:2016 by reference and aligning U.S. requirements with the international standard most device makers already follow. It does not soften the expectations around complaints and CAPA. It sharpens several of them.
Risk management now runs through the whole quality system rather than living mainly inside design control. Supplier controls carry more weight. Records of complaint investigations are expected to carry device identification, including the unique device identifier where one applies. And the citations themselves are changing shape, moving from familiar Part 820 section numbers toward the ISO 13485 clauses those sections now point to.
Early inspection data hints at the direction. MedDeviceGuide’s analysis of 93 device inspections conducted between February 4 and March 13, 2026 found the share closed as No Action Indicated fell from 52.7 percent before the QMSR to 48.8 percent after, with Voluntary Action Indicated rising to 51.2 percent. The findings clustered around risk management integration, supplier controls, complaint handling integration, design controls, and data integrity. It is a small sample from the first six weeks, and it should be read that way. But the vocabulary is telling. The word that keeps appearing is integration.
What the regulation cannot do by itself is supply the connection it now expects. A UDI tells you what a device is and, depending on how a manufacturer populates the production identifier, which lot or serial it belongs to. For many products that identifier resolves to a lot, which is a population, not a unit. Knowing a complaint came from lot 4471 is useful. Knowing it came from a unit produced on line two, during a specific window, after a tooling change, with material from a particular supplier shipment, is what turns an investigation from a search into a query.
The manufacturers who will handle QMSR inspections best are the ones who have already built unit-level identity into the moment of manufacture, so that complaint-to-production traceability is a live capability and not a post-hoc exercise. The 2025 enforcement data shows what happens when that capability is missing. The QMSR enforcement data, once there is enough of it, is likely to show the same thing under new clause numbers.
What an investigator needs in the first hour
Strip away the regulatory language and every warning letter in these three categories describes an investigation that could not answer a handful of questions in time. A quality team with unit-level production data can answer them the day the complaint arrives:
- Which unit is this, exactly. Not the product family, not the lot, but the individual unit and its record.
- What was true when it was made. Line, station, operator shift, equipment state, process parameters, component and material lots.
- Who shares that history. Every other unit produced under the same conditions, and where each one went.
- Has this happened before. Prior complaints, nonconformances, and returns that resolve onto the same conditions, even when they arrived months apart under different product names.
- Did the last fix work. Field performance for units built after a CAPA or design change, compared against units built before it.
Each of those answers maps to something the FDA keeps citing. The first three are the core of a complaint investigation. The fourth is trend detection, the step that turns isolated complaints into a CAPA. The fifth is effectiveness verification, where a large share of CAPA observations actually land, and the feedback loop that design controls depend on.
Where the argument stops
It is worth being precise about what better data does and does not change. Unit-level traceability does not make the severity call, write the risk assessment, or decide whether to open a CAPA. People do that, and people under schedule and cost pressure will sometimes downgrade a hazard or close a file early. No data system removes that.
What it changes is how long a weak decision survives. A severity downgrade is easy to defend when the counter-evidence is a scattered set of complaints with nothing in common but a product name. It is very hard to defend when the record shows those complaints resolving onto a narrow band of production conditions, and shows how many more units from that band are still in the field. Good infrastructure does not replace judgment. It makes bad judgment visible sooner, to more people, with less room to argue.
It is also true that no current regulation requires unit-level traceability for most devices. The FDA does not cite firms for failing to adopt a specific technology. It cites them for failing to investigate thoroughly, escalate appropriately, and verify effectiveness. The point is that each of those obligations has a data prerequisite, and for most of the industry that prerequisite is still being met by hand.
The Aeroz Angle
The three violations that drive the majority of FDA medical device warning letters share one infrastructure requirement: the ability to connect a quality event to the specific unit and production conditions behind it. Aeroz provides that connection at the moment of manufacture. Not as a retrospective reconstruction, but as a permanent, tamper-evident record created as each unit is made.
In practice, that changes four things for a quality team.
Every complaint arrives with a manufacturing fingerprint. The investigator starts from the unit’s actual production history rather than a lot number and a stack of batch records. A complaint becomes a query instead of a research project.
Trends surface while they are still small. Complaints that look unrelated by product name can resolve onto the same line, window, or material lot. The pattern that usually becomes visible only when an inspector assembles it becomes visible to the firm first.
CAPA scope is bounded by evidence. The affected population is an inventory with an answer, not an estimate, which is the difference between a targeted field action and one scoped to everything the firm cannot rule out.
Effectiveness is measured, not asserted. Units built after a corrective action or design change can be compared directly against units built before it, which closes the loop design controls are supposed to close and gives an inspector the objective evidence they ask for.
The FDA’s enforcement record for 2025 shows the cost of a quality system that stores events without connecting them. The QMSR makes that connection more central, not less. Aeroz exists so that the connection is already there when the complaint arrives.
Aeroz, Making Authenticity Undeniable. Visit aeroz.io to learn more & get in contact with our team via info@aeroz.io.
2026 AEROZ all rights reserved.
