A manufacturer sends an email on a Tuesday. It is polite, technical and short. A particular lot of cartridges, it says, may under certain conditions return results that read lower than the true value, and it should be quarantined and returned. There is a reference number, a lot number, and a line asking recipients to acknowledge receipt and take appropriate action. In a central laboratory that email triggers a well-worn drill. Someone walks to the fridge, pulls the affected lot, tapes a bag over the analyser's reagent bay if it needs it, and logs the action. Containment takes minutes because everything lives in one place, on one machine, under one team.

Now picture the same email landing on the desk of a point-of-care coordinator whose estate is a hospital plus fourteen wards, three community clinics, a prison healthcare unit, two GP practices and a homeless outreach van. The affected lot was ordered centrally eight months ago, split into part-boxes, and pushed out to wherever ran low. Some of it was couriered between sites by a friendly healthcare assistant who was helping out. Nobody wrote that down. Two of the devices that used it are not connected to anything and store their results on a memory that gets overwritten. And the numbers those devices produced over the past several weeks have already been read, acted on, and in some cases used to send a patient home.

My argument is this. When a reagent lot or a device is recalled, a laboratory can quarantine a concentrated stock and query connected results from one place, then work its look-back from a position of control. A distributed point-of-care service has to prove that every affected device, every affected lot, and every patient result produced while the fault was live has been found, acted on and documented, from stock and devices scattered across many sites. That is a categorically harder problem, and many services are not ready for it. The field safety notice is the moment your inventory, your connectivity and your governance are tested for real, with a regulator, a manufacturer and possibly a coroner watching.

757medical device field safety notices in the UK in 2010, up from 62 in 2006
1,220%rise in annual field safety notices across 2006 to 2010
44%of MHRA device alerts ended in a device withdrawn or recalled
3 to 7 daysof warm storage drifted a recalled i-STAT cartridge lot out of spec

Why containment is easy in a lab and brutal outside it

In the UK, manufacturers issue field safety notices when they need to take corrective action on a device or consumable already in the field, and the MHRA reviews those actions, can supplement or override the manufacturer's advice, and publishes the notices weekly (MHRA guidance for manufacturers; the running list sits at gov.uk drug and device alerts). The regulatory machinery is well established. What the notice cannot do is find your devices for you. The manufacturer is required to trace its product by batch and serial number as far as the customer it shipped to, and the responsibility to reach end users stays with the manufacturer, but in practice that traceability chain usually ends at your goods-in door. What happened to the stock after it entered your estate is your record to keep, or your gap to explain.

And this is not a rare event you can afford to improvise around. When researchers reviewed MHRA safety communications across 2006 to 2010, field safety notices rose from 62 a year to 757, a 1,220 percent increase over five years, and 44 percent of the formal device alerts in that window ended with a product withdrawn or recalled (Heneghan and colleagues, BMJ Open, 2011). Recalls have remained a routine feature of the device landscape since, with new notices published every week. A distributed service is not bracing for a once-a-decade shock. It is bracing for a steady stream, and the question is only whether any given notice touches a lot you happen to hold.

0200400600800Field safety notices62200616420075132008628200975720101,220% rise in five years
Figure 1. Medical device field safety notices published in the UK rose from 62 in 2006 to 757 in 2010, a 1,220 percent increase in five years. The point is not the exact count, it is the slope: recalls are a routine part of running devices, not an exceptional one. Data: Heneghan and colleagues, BMJ Open, 2011, a retrospective review of MHRA safety notices and alerts, 2006 to 2010.

The laboratory is the easy case for a reason worth naming. It has physical concentration: the reagents are in one room, the analysers on one bench. It has controlled inventory: goods-in logs the lot, the fridge holds it, the middleware ties every result to the instrument and the reagent pack. It has connectivity: results flow to the laboratory information system with a timestamp, an operator and a device identifier attached, so a look-back is a database query, not a search party. Containment is fast because traceability was already built in before anyone needed it.

Central laboratoryOne siteOne fridgeOne analyserquarantine in minutesDistributed estateevery device, lot and result to trace
Figure 2. The recall that takes minutes and the recall that takes weeks. A laboratory concentrates devices, consumables and results in one place, so one fridge and one analyser can be quarantined at once. A distributed estate scatters the same three things across many sites, and containment scales with the mess.

Point-of-care testing inverts every one of those advantages. The devices are everywhere, by design, because the whole point is to bring the test to the patient. The consumables are bought, split, shared and moved locally, often without a central record of which lot went where. Inventory is often a spreadsheet that was last accurate three reorders ago, or a cupboard that nobody counts. Connectivity is patchy: some devices upload every result with full metadata, others are effectively islands that print a slip and forget. National guidance is honest about this last point. NHS England's own advice for community and virtual ward diagnostics states plainly that not having the digital capability to automate upload of results should not be a barrier to using point-of-care testing (NHS England, integrating in vitro POCT). That is the right call for access. It also means unconnected devices are not an aberration to be designed out; they are an accepted feature of the estate you have to trace.

The four features that make POCT recalls uniquely hard

It is worth being precise about why this is harder than a laboratory recall, because each difficulty has a corresponding fix, and the fixes are the whole point.

Devices are everywhere and move

A laboratory analyser has an asset tag and a fixed location. A point-of-care device is portable by nature and portable in practice. Meters migrate between wards during surges, get borrowed, get left in a drawer, get replaced without the paperwork catching up. When a device fault is recalled, the first question, "where are all the affected units right now?", can genuinely be unanswerable for a service that has never kept a live register.

Consumables are bought and moved locally

Cartridges and strips are ordered in bulk, then dispersed. A part-box travels from a busy site to a quiet one. A locum brings their own stock. A ward runs short and raids the clinic down the corridor. NHS England guidance is clear that oversight of the devices, strips and cartridges used needs to be agreed in advance, in case of device or product recalls, and that this responsibility usually sits with pathology (NHS England, POCT in community pharmacies). That ownership matters precisely because, without it, lot-level traceability evaporates the moment a box is opened and split.

Inventory is usually weak

Ask many services to produce, on demand, a list of every site holding a named lot number, and you will often get a pause. The information exists somewhere: in delivery notes, in local cupboards, in people's heads. It is rarely in one queryable place, kept current. A recall turns that weakness from a background annoyance into an operational emergency, because the notice is lot-specific and your records are not.

Connectivity is patchy and results are already actioned

The look-back is the hardest part. A recall about results reading falsely low over a defined window forces the question: which patients were tested on an affected device with an affected lot during that window, and were any of them managed on the strength of a wrong number? For connected devices this is answerable, because the same guidance expects data recording with traceability to the device and the operator for audit. For unconnected ones it is archaeology: paper logs, printouts, memories. And unlike a laboratory result held in a queue, a point-of-care result has usually already done its work. Clinical review is not precautionary, it is remedial.

A recall tests the governance you already have, not the governance you meant to build. You cannot revise your inventory after the notice arrives; you can only find out how good it was.

What a real notice looks like on the bench

These faults are not exotic. In December 2020, Abbott Point of Care recalled specific lots of its i-STAT CG8+ and EG7+ cartridges because the ionized calcium result could read higher than expected if the cartridges had been stored at room temperature for longer than three to seven days, depending on the lot (Health Canada recall RA-74757). Read that carefully. The failure was triggered by ordinary warm storage, the kind that happens the moment a box leaves the cold chain and sits on a ward worktop over a weekend. The clinical answer was skewed on an electrolyte people act on quickly. And the affected units were, by design, wherever the testing was happening. That is the whole problem in one notice: a small, specific, storage-linked defect that a laboratory would contain in one fridge, scattered across an estate that may not know which lots went where or how warm they got.

The trace-back chain you have to complete

Strip away the panic and a recall is a chain of questions, each of which must be answered before the next fully makes sense. The chain is the same whether the recall is trivial or catastrophic. What changes is whether your service can walk it in hours or is reduced to walking it in weeks, by phone, one site at a time.

Field safetynoticeIdentifyaffected lotsLocate everydevice and siteFind affectedresults and windowAct andnotifyDocumentclosureHours, not weeks, is the standard to aim for
Figure 3. The trace-back chain a service must complete. From the field safety notice, identify the affected lots, locate every device and site that used them, isolate the affected patient results and the time window, act and notify, then document that closure. A break at any link stops the whole chain.

Read that chain honestly against your own service and the gaps announce themselves. Can you list every site holding the named lot without ringing round? Can you name every device that ran it, and where those devices are today? Can you pull the patient results those devices produced during the fault window, or are some of them on an island that prints and forgets? Can you tell, for each affected result, whether it was acted on and whether the action needs revisiting? And when it is all done, can you produce a single closure record that a regulator, or if it ever came to it a coroner, would accept as evidence, not just an assurance that you "dealt with it"?

Most services can complete part of the chain quickly and part of it not at all. The dangerous illusion is that the parts you can do fast reassure you, while the parts you cannot do at all are the ones that matter clinically. Quarantining the stock is the visible, satisfying bit. Finding the patient who was discharged on a falsely reassuring result is the bit that keeps you up at night, and it is exactly the bit that weak connectivity makes impossible.

Recall-readiness is just governance you can prove

A recall does not create these problems. It reveals them. A service that cannot answer a recall in hours could not, on any ordinary Tuesday, tell you where all its devices are, which lots are in play, or which results came from which instrument. The recall simply attaches a deadline and an audience to a weakness that was there all along. This is why I argue that recall-readiness is not a niche disaster-planning exercise. It is a stress test of whether your point-of-care governance is real or merely documented.

Under a single quality management system, the standards already expect you to control your equipment, your reagents and your records. ISO 15189:2022 does not use the word "recall" as a magic spell, but it expects traceability, inventory control, and the ability to identify and manage nonconforming work, and it now brings point-of-care testing inside the laboratory quality standard itself, superseding the withdrawn ISO 22870 (ISO 15189:2022). A recall is nonconforming work arriving from the outside at speed. If your management system genuinely delivers traceability, the recall is a bad afternoon. If it delivers only paperwork that describes traceability you do not actually have, the recall is the day the gap becomes visible to people who can act on it.

There is a wider payoff worth naming. Everything that makes a recall survivable, a live device register, lot-level inventory, connected results, defined roles, is the same infrastructure that makes ordinary quality management easier every other day of the year. You are not building a recall capability. You are building a governed service, and recall-readiness is the proof that you did.

What a service needs to answer a recall in hours

If you run, coordinate or advise on a distributed point-of-care service, do not wait for the notice to find out where you stand. Build the capability now, while the stakes are hypothetical.

  • Keep a live inventory of devices and lots. Maintain, and actually update, a register of every device, its location and its status, plus which consumable lots are held where. The test is simple: could you produce a list of every site holding a named lot number in minutes, without phone calls? If not, that is your first project, not your last.
  • Connect what you can, and know what you cannot. Connectivity so that results carry a device identifier, an operator and a timestamp turns a look-back from a search party into a query. Where devices genuinely cannot connect, know exactly which ones they are and treat them as your highest-effort manual look-back, not as an afterthought you discover mid-recall.
  • Define the roles before you need them. A recall has no time for ambiguity about who owns it. Name, in advance, who receives manufacturer and MHRA notices, who decides on quarantine, who leads the clinical look-back, who authorises patient recall, and who signs the closure. Vacant roles are found at the worst possible moment.
  • Have a look-back method, written down. Decide in advance how you will identify affected patient results and the time window, how you will assess clinical impact, and who reviews borderline cases. A rehearsed method executed calmly beats a brilliant improvisation executed in panic.
  • Rehearse it. Run a tabletop drill against a plausible, invented lot recall once a year. Walk the whole chain. The rehearsal will surface the unconnected device, the site that shares stock off the record, the role nobody owns. Better to find them in a drill than in a real notice with a clock running.
  • Document closure as evidence, not assurance. The end state of a recall is not "we handled it". It is a record that shows the notice received, the lots and devices identified, the results reviewed, the patients managed, and the actions signed off, with dates and owners. That record is what protects patients, and it is what protects you.

Our consultancy helps services build exactly this capability, the live register, the connectivity map, the roles and the rehearsed look-back, before a notice arrives rather than during one. Our training, including the POCT fundamentals course, builds the traceability and quality thinking that makes a recall a procedure rather than a crisis. And practical starting points, including inventory and look-back scaffolding you can adapt, live in our resources.

The recall you can actually close

A recall is never really about the reagent. It is about whether your service was telling itself the truth on every ordinary day that led up to it. The manufacturer's email is short and calm because the manufacturer has done its part: it found the fault and raised the alarm. What happens next is yours. The service that can name every affected device, pull every affected result and produce a closure record a regulator would accept did not get lucky. It built the plumbing while nothing was on fire. The one that cannot is not unlucky either. It is simply meeting, in public and under pressure, the state its governance was always in. Build so that when the notice comes, you can close the recall. Because the recall nobody can close is the one that was never closed at all, only survived.

Sources and notes

This article draws on published UK regulatory guidance and peer-reviewed data. The volume figures are from a retrospective review of MHRA safety communications covering 2006 to 2010, one of the most complete published datasets on UK device recalls; the MHRA has continued to publish field safety notices every week since. The recall example is a real 2020 Abbott i-STAT cartridge field safety corrective action. The two schematic figures, the laboratory-versus-distributed contrast and the trace-back chain, illustrate the argument rather than plot a measured dataset.

  1. GOV.UK, MHRA. Field safety notices: guidance for manufacturers of medical devices. Manufacturers issue field safety notices and corrective actions, keep traceability of devices by batch and serial number and to the customers they supply, and remain responsible for reaching end users; the MHRA reviews, may supplement or differ, and publishes notices weekly.
  2. GOV.UK. Alerts, recalls and safety information: medicines and medical devices. The MHRA's running list of field safety notices and device alerts.
  3. Heneghan C, Thompson M, Billingsley M, Cohen D. Medical-device recalls in the UK and the device-regulation process: retrospective review of safety notices and alerts. BMJ Open 2011;1:e000155. Field safety notices rose from 62 in 2006 to 757 in 2010 (a 1,220 percent rise); 197 of 447 device alerts (44 percent) involved a device withdrawn or recalled.
  4. NHS England. Point of care testing in community pharmacies: guidance for commissioners and providers (January 2022). "Who has oversight of the devices/strips/cartridges used needs to be agreed, in case of device/product recalls; usually this is pathology."
  5. NHS England. Integrating in vitro point of care diagnostics: guidance for urgent community response and virtual ward services. Requires data recording with traceability to the device and the operating clinician for audit, and notes that lack of automated result upload should not be a barrier to using point-of-care testing.
  6. Health Canada, Abbott Point of Care. Recall of i-STAT CG8+ and EG7+ cartridges (December 2020, RA-74757). Ionized calcium may read higher than expected after storage at room temperature beyond three to seven days depending on lot.
  7. International Organization for Standardization. ISO 15189:2022, Medical laboratories, requirements for quality and competence. Requires traceability, inventory control and management of nonconforming work, and brings point-of-care testing inside the laboratory quality standard, superseding the withdrawn ISO 22870.