FreeStyle Libre 3 sensors report falsely low glucose
Some Libre 3 and 3 Plus continuous glucose sensors read lower than actual glucose; FDA classified the correction Class I after reports of 860 serious injuries and 7 deaths.[4,16]
how automated healthcare fails, how you'd know, and what to do at each tier — every claim sourced, reviewed continuously
The monitors, pumps, ventilators, sensors and analyzers that measure and act on patients, and the software and updates that run them.
This layer is the equipment at the bedside, in the lab and in the patient's home: physiologic monitors, pulse oximeters, infusion pumps, ventilators, continuous glucose monitors, point-of-care and lab analyzers, and the endpoint software (operating systems, security agents, interface adapters) that now runs on or beside them. Nearly all of it is software-driven, networked, and updated by a vendor after installation.
Devices fail in two ways. Loud failures stop the device, raise an alarm or crash the workstation; staff notice and fall back to another device or to manual care. Quiet failures keep producing numbers that look normal and are wrong: a pulse oximeter that reads high on darker skin, a glucose sensor that reads low, a lead analyzer that under-reports, a pump that loads a stale order. The quiet kind never triggers a downtime procedure.
In a paper-era hospital a device error reached one patient through one clinician who could see the device. In an automated hospital device outputs feed EHR flowsheets, early-warning scores, auto-programmed infusions and remote monitoring, and a single vendor update can reach every unit at once. The same connectivity that lets a pump receive an order from the EHR lets a faulty update or a compromised firmware image reach thousands of endpoints in minutes.
FailSystems viewA device that stops is a tier-2 problem you can plan for; a device that keeps reporting wrong numbers is the one that hurts people, because nothing in the system tells anyone to change tier. Automation makes this worse in two directions. It amplifies quiet error, because downstream scores, alerts and auto-programming consume the bad value without a human looking at the device. And it synchronizes loud failure, because fleet-wide updates (security agents, firmware, interface software) turn one vendor mistake into simultaneous failure across a hospital or a country. Defense in this layer is less about redundancy of boxes and more about independent cross-checks of values and control over when changes land.
A sensor is accurate on the population it was validated on and biased on others. Pulse oximeters overestimate saturation in patients with darker skin, so hypoxemia is missed and treatment thresholds are crossed later. The device reports normally and nothing alarms.[1,2,3]
Warning signs
Seen inPulse oximeters overestimate oxygen saturation in patients with darker skin
A batch or design flaw makes a device report values in the normal range that are wrong: glucose sensors reading low, blood lead analyzers reading low. Users act on the number. Detection depends on someone comparing against an independent method, and on the manufacturer reporting promptly, which can fail.[4,5]
Warning signs
Seen inFreeStyle Libre 3 sensors report falsely low glucose, LeadCare blood lead analyzers return falsely low results; malfunction concealed
A vendor pushes a software, firmware or content update to every installed endpoint at once. If the update is faulty, every device or workstation that takes it fails together, and recovery is limited by hands-on remediation per machine. Security agents with kernel access are the extreme case because they update often and without customer staging.[6,7,8]
Warning signs
Seen inCrowdStrike Falcon content update crashes Windows hosts, including hospital systems
When EHR-to-device integrations (infusion auto-programming, order interfaces) back up, a queued command can arrive late and be applied to the device as if it were current. The value looks legitimate on the pump screen.[9]
Warning signs
Seen inAlaris infusion interoperability backlog can load outdated pump orders
Alarms fail to sound (a low-battery alarm that does not fire, wrong priority), sound falsely (spurious power-loss alarms that stop therapy), or sound so often that staff tune them out. The Joint Commission counted 98 alarm-related sentinel events, 80 of them deaths, from 2009 to mid-2012.[10,11,12,13]
Warning signs
Seen inPhilips Respironics ventilator, BiPAP and CPAP recall over degrading sound-abatement foam, Alaris infusion interoperability backlog can load outdated pump orders
Devices that can connect to a network but no longer receive security updates, or that ship with hidden functions, provide a path to alter device behavior or reach the wider network. The only mitigation may be to disconnect, which removes remote monitoring.[14,15,16,17,18,19]
Warning signs
Seen inContec CMS8000 patient monitors: hidden remote-access function disclosed by CISA and FDA
A material or component degrades inside devices already in use, with no alarm. Once found, remediation depends on replacement supply, locating every unit (often in patients' homes) and clear communication, and can take years.[20,21,22]
Warning signs
Seen inPhilips Respironics ventilator, BiPAP and CPAP recall over degrading sound-abatement foam
Recalls are posted, but the notice does not reach the clinician, biomed team or home patient using the device, or arrives without clear action. FDA posting dates reflect classification, which can lag the firm's action.[16,23,20]
Warning signs
Seen inFreeStyle Libre 3 sensors report falsely low glucose, Philips Respironics ventilator, BiPAP and CPAP recall over degrading sound-abatement foam
Some Libre 3 and 3 Plus continuous glucose sensors read lower than actual glucose; FDA classified the correction Class I after reports of 860 serious injuries and 7 deaths.[4,16]
A grid collapse cut power to continental Spain and Portugal for about ten hours. Hospitals largely held on generators; care outside them did not.[24,25,26,27,28]
A Class I software correction found that backlogged EHR-to-pump automated programming requests could load stale rate, dose or volume parameters.[9,11]
CISA and FDA reported that a low-cost patient monitor's firmware contained hidden functionality that could allow remote access and sent patient data to an external address; independent researchers later judged it an insecure design rather than an intentional backdoor.[14,15,29,30]
A faulty Rapid Response Content update to CrowdStrike's Falcon sensor crashed about 8.5 million Windows devices worldwide. Outside-in measurement found disrupted services at 759 of 2,232 US hospitals studied.[6,7,31,8,32,33,34]
PathDevices → Connectivity & data → Human handoff
Philips recalled about 15 million breathing devices because PE-PUR foam could degrade into particles and chemicals the patient could inhale; remediation ran years and ended in a consent decree.[20,21,22,12]
Freezing weather knocked out generation and forced the largest controlled load shed in US history. Power loss spread to water systems and hospitals, and to patients at home on powered medical equipment.[35,36,37,38,39,40]
PathPower → Devices → Human handoff
Paired SpO2/SaO2 data showed occult hypoxemia missed by pulse oximetry about three times as often in Black as in White patients, delaying treatment decisions.[1,2,41,3]
A self-spreading ransomware worm infected 34 English trusts and 603 primary-care and other NHS organisations, and at least 46 more trusts were disrupted. Thousands of appointments were cancelled and five hospitals diverted ambulances.[42,43,44]
PathConnectivity & data → Devices → Human handoff
Magellan's LeadCare devices, used for more than half of US blood lead tests 2013-2017, gave falsely low results on venous samples; the company delayed telling FDA for 21 months.[5]
Storm surge flooded basements holding fuel tanks and pumps at two Manhattan hospitals whose generators sat on upper floors. Both hospitals evacuated.[45,46,47]
A patient on a cardiac monitor died after the monitor's crisis alarm had been left off; lower-level alarms sounded at the nurses' station but went unheeded.[48,49]
A 60-year-old ICU patient's monitor alarmed for rising heart rate and falling oxygen saturation; staff responded only after about an hour, when he had stopped breathing.[10]
What should already be in place at each degradation tier for this layer. Tier 0 is normal automated running; tier 3 is paper, batteries and judgement.
These are practices reported or recommended in the cited sources, gathered for reference. They are not a prescription for your organisation; judge what fits your setting, and check the current official text of any standard.
| Instrument | What it requires |
|---|---|
| ISO 14971:2019 (FDA recognition 5-125) | Manufacturers identify hazards, estimate and control risks, and monitor effectiveness of controls across the device life cycle, including post-production information.[55] |
| IEC 62304:2006+AMD1:2015 | Life cycle processes for development and maintenance of medical device software, including software safety classification, change control and problem resolution.[56] |
| IEC 60601-1-8:2006+AMD1:2012+AMD2:2020 | Requirements and tests for medical alarm systems: alarm priority categories, alarm signal characteristics and control states such as pausing and silencing.[13] |
| IEC 80001-1:2021 | The healthcare delivery organization applies risk management for safety, effectiveness and security before, during and after connecting devices or health software to its IT infrastructure.[53] |
| FD&C Act section 524B (21 U.S.C. 360n-2) | Cyber device sponsors must submit a postmarket vulnerability plan, maintain processes to assure cybersecurity, ship patches on a justified regular cycle and critical fixes out of cycle, and provide an SBOM.[17] |
| Joint Commission NPG.01.05.01 (2026) | Hospitals identify the most important alarm signals, set policies for managing them, and educate staff; replaces NPSG.06.01.01 from January 2026.[51] |
In the EU, the Medical Device Regulation (EU) 2017/745 makes information security part of the essential requirements: Annex I 17.2 requires software to be built under state-of-the-art life cycle and risk management including information security, and 17.4 requires manufacturers to state minimum hardware, network and IT security requirements, including protection against unauthorised access. In Great Britain, amended post-market surveillance rules in force from 16 June 2025 cut the serious-incident reporting deadline from 30 to 15 days and require manufacturers to submit Field Safety Notices to the MHRA before they go to users, which targets the recall-communication failure mode directly.[57,58]
FailSystems judgementJudgement: device faults reported to FDA are routine (Class I recalls on pumps, ventilators and sensors recur yearly), so likelihood is high. Blast radius is high because fleet updates and population-wide sensors (oximetry, CGMs, a dominant lead analyzer) spread one error across many patients. Detectability is scored hardest (5) because the most harmful mode is a plausible wrong value that triggers no alarm and no downtime procedure.
Each factor is scored 1–5 and multiplied, as in a classic FMEA risk priority number. This is our first-draft judgement, not a measurement; see how scoring works and how it will be revised.
These gaps drive what the nightly research pass looks for. If you have evidence, send it.
Cite this pageFailSystems. “Devices & electronics.” https://failsystems.health201.com/layers/devices/ (reviewed 2026-09-26). Health 201 / AstroNexus LLC. CC BY 4.0.
Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.