“Software Flaws Risk Patient Safety”

… declares the table of contents for an article, subtitled Software problems are responsible for 20 recalls a month in IEEE’s Spectrum magazine December 2025 issue (the article is available without an IEEE account: https://spectrum.ieee.org/medical-device-recalls)

The article includes several summary charts about U.S. Food and Drug Administration (FDA) medical device recall data back to 2005, including a breakdown of software causes across 6 subcategories.

The largest software problem category by far – 82% – is “software design.”

There are at least two takeaways:

  1. It is not a good thing for medical device software issues to make the largest engineering professional association’s general publication.
  2. Just “slinging code” is not enough … good analysis and design is the foundation for reducing risk.

There are also at least two inferences we can make from the second observation above:

  • AI may help with originating, proofing, and testing code at a low level, but it cannot substitute (yet) for good human macro architecture and design. Cutting corners in processes other than coding has significant medical device risk implications, especially for causing future medical device software problems.
  • Cybersecurity is as much a software analysis and design effort as it is a software coding effort. The more cybersecurity risk that a device has, the more attention will be needed to integrate and initiate cybersecurity work across the entire software process, including operation in the market. This is also a regulatory expectation and another source for future medical device software problems.

Additional information about FDA recalls and causes can be found at:

If you need tailored assistance for your specific situation, contact us at https://www.softwarecpr.com/leave-a-message/

About the author

Succeeding despite relentless change is the goal of 21st century organizations. Mike helps achieve those successes by working with leaders of start-ups to Fortune 20 companies and national governments. His aim is to help them re-imagine and create adaptive, innovative enterprises that increase profitability and value across the quadruple bottom line: customers, employees, owners/shareholders, and communities.

SoftwareCPR Training Courses

ISO13485:2016 ISO 13485 Internal Audit(or) Training Course (Live, 3-day)

IEC 62304 and other Emerging Standards Impacting Medical Device Software (Live, 3-day)

Being Agile & Yet CompliantISO 14971 SaMD Risk Management

Software Risk Management

Medical Device Cybersecurity

Software Verification

IEC 62366 Usability Process and Documentation

Or just email training@softwarecpr.com for more info.

Corporate Office

15148 Springview St.
Tampa, FL 33624
USA
+1-781-721-2921
Partners located in the US (CA, FL, MA, MN, TX) and Canada.