A continuous glucose monitor (CGM) in routine hospital use reports a glucose value every five minutes, day and night. Each of those values is post-market data about the device: how it performs once patients rely on it outside a study. FDA's guidance on section 522 defines postmarket surveillance as "the active, systematic, scientifically valid collection, analysis, and interpretation of data or other information about a marketed device."
Section 522 orders and 21 CFR Part 822
Section 522 of the Federal Food, Drug, and Cosmetic Act lets FDA order a manufacturer to run post-market surveillance of a class II or class III device. 21 CFR Part 822 sets out the procedure. An order can cover a device that meets any of four criteria:
- its failure would be reasonably likely to have serious adverse health consequences;
- it is intended to be implanted in the body for more than one year;
- it is intended to support or sustain life and to be used outside a user facility;
- it is expected to have significant use in pediatric populations.
Deadlines run from the date of the order. The manufacturer submits a surveillance plan within 30 days of receiving it, and FDA reviews the submission within 60 days. Surveillance must begin no later than 15 months after the order was issued. FDA treats it as begun when the first subject is enrolled, or, for a plan without enrolment, when data starts to accrue.
FDA may order prospective surveillance lasting as long as 36 months, and anything longer needs the manufacturer's agreement. Interim and final reports follow the schedule in the approved plan, and the records are kept for 2 years after FDA accepts the final report. FDA publishes each study's status through its 522 Postmarket Surveillance Studies Program.
The post-market surveillance plan
Section 822.10 lists fifteen things the plan must discuss, from its objective to the content and timing of its reports. Seven of them concern data:
- the subject of the study;
- the variables and endpoints;
- sample size and units of observation;
- sources of data, where the rule's own example is "hospital records";
- the data collection plan and forms;
- the patient follow-up plan;
- the data analyses and statistical tests planned.
FDA's guidance adds that the plan should describe its data source on two counts. Relevance asks whether the source captures what the surveillance question needs, and reliability asks about the quality of its data.
Figure 2 as a table
| Plan element | What device readings supply |
|---|---|
| 822.10(b) The subject of the study | Every reading names its patient and encounter, matched by bed |
| 822.10(c) Variables and endpoints | Readings coded with LOINC and UCUM, so each variable is a code and a unit |
| 822.10(e) Sample size and units of observation | One reading is one Observation, with its device and time |
| 822.10(g) Sources of data, e.g., hospital records | Readings from the hospital’s own install, beside its records |
| 822.10(h) The data collection plan and forms | Captured at the device as each reading is taken; nothing retyped |
| 822.10(k) The patient followup plan | Readings continue for as long as the device is on the patient |
| 822.10(n) Data analyses and statistical tests | Run on the research store’s copy of the same records |
| 822.31(d) Keep all data collected | Every reading, and every version of it, is kept |
FDA post-approval studies
A device approved through premarket approval (PMA) can carry a different requirement. Under 21 CFR 814.82, FDA can make continuing evaluation and periodic reporting on the device's safety, effectiveness and reliability a condition of approval. These post-approval studies are a separate obligation from a 522 order, though both look at the device in real use.
Real-world data in a 522 plan
FDA's 522 guidance notes that an order can sometimes be met by analysing real-world data, prospectively or retrospectively, from sources such as device registries and electronic health records. Where real-world data of enough relevance and reliability already exists, and the manufacturer will analyse it promptly, FDA may decide not to issue an order at all.
FDA's guidance on using real-world evidence for device decisions, final since December 2025, covers how FDA judges the quality of real-world data before accepting evidence built on it. Both documents ask two things of a data source: whether it holds what the surveillance question needs, and whether each value can be traced and trusted.
Name one device and one hospital that uses it. A one-site pilot captures that device's readings there, coded at the bedside and traceable to the serial number of each device.
Plan a one-site post-market data pilotEU MDR post-market surveillance
In the EU, post-market surveillance is a standing duty under the Medical Device Regulation, Regulation (EU) 2017/745, rather than an order for selected devices. Article 83 requires every manufacturer to run a surveillance system proportionate to the device's risk class. That system actively and systematically gathers, records and analyses data on the device's quality, performance and safety throughout its lifetime. The data then updates the benefit-risk determination, risk management, the design, labelling and instructions, and the clinical evaluation, and shows where preventive or corrective action is needed.
Article 84 bases that system on a post-market surveillance plan, and Annex III lists what the plan covers. It includes a proactive and systematic process to collect information, and indicators and threshold values for reassessing benefit and risk. It also includes a post-market clinical follow-up (PMCF) plan, or a reason for not having one.
The findings go into a report whose form depends on the risk class. Class I devices have a post-market surveillance report, updated when necessary (Article 85).
Class IIa, IIb and III devices have a periodic safety update report (PSUR) under Article 86. It is updated at least every two years for class IIa, and at least once a year for class IIb and III. Our guide to the PMCF plan, its data and the evaluation report covers the clinical follow-up in detail.
Post-market surveillance data sources compared
A surveillance plan asks four things of each data source: what values it holds, how it identifies the device, when each value is dated, and which patients it counts.
Medical device reports under 21 CFR Part 803 describe events. A manufacturer files one when information reasonably suggests its device may have caused or contributed to a death or serious injury. A malfunction that could do so if it recurred is reported too. These reports count only patients with a reported event.
Registries collect the fields they define at enrolment and follow-up visits, for the patients they enrol. Values typed into hospital records by hand are dated when charted and carry no link to the device that produced them. Claims carry billing codes rather than measured values.
Readings captured from the device at the hospital hold the value with its LOINC code and UCUM unit. They also name the device and keep the time the device stamped on each value, for every patient on a connected device. This is proactive surveillance in the sense Annex III uses, because the data is collected while the device is in use rather than after someone files a report. These readings supplement complaint handling and event reporting and do not replace them.
Figure 3 as a table
| Source | What it records |
|---|---|
| Medical device reports (21 CFR 803) | Values: event descriptions, not readings. Device: as the reporter names it. Dated: the event date. Counted: patients with a reported event. |
| Registries | Values: the fields the registry defines. Device: recorded at enrolment. Dated: follow-up visits. Counted: enrolled patients. |
| Hospital records, charted by hand | Values: values a clinician typed in. Device: rarely kept with the value. Dated: when charted. Counted: every patient at the site. |
| Claims | Values: billing codes, no values. Device: a billing code, not the unit. Dated: the date of service. Counted: patients who were billed. |
| Device readings from the site’s install | Values: every reading, LOINC and UCUM coded. Device: device, UDI and serial on every reading. Dated: the device’s own timestamp. Counted: every patient on a connected device. |
Device readings from hospital sites
At a hospital running Kymolog™, an edge agent beside your device takes each reading as it is measured. It codes the reading once, with LOINC and UCUM, as a Fast Healthcare Interoperability Resources (FHIR) R4 Observation. Each reading carries the device's unique device identifier (UDI), its serial number and the time of measurement. Kymolog then matches it to the patient and encounter by bed.
Readings from a second or third site pool with the first, because every site codes the same measurement with the same LOINC code and UCUM unit. A plan can start at one hospital and add others without changing its variables.
Set against section 822.10, those readings supply coded variables, one Observation per unit of observation and a hospital data source. They are collected without retyping, and follow the patient for as long as the device stays on. Every version of every reading is kept, which serves the rule that all data collected for the plan be retained.
None of these readings reach your surveillance plan unless the hospital agrees, and the hospital chooses their form. It can share de-identified readings through the data network we run for consenting sites, or agree terms with you directly. More on how Kymolog works with device makers.