If you have ever searched for how to locate recalled medical devices in a hospital, you already know what the first page of results tells you. An alert arrives. Your CMMS cross-references the manufacturer, model and serial range against the equipment inventory.
If you have ever searched for how to locate recalled medical devices in a hospital, you already know what the first page of results tells you. An alert arrives. Your CMMS cross-references the manufacturer, model and serial range against the equipment inventory. Matching units are flagged. Work orders go out. Four steps, and somewhere in the middle of them, almost every article uses the word “locating.”
That word is doing an enormous amount of hidden work. A database query is not a location. It tells you the device exists in your records and which department it was assigned to the last time anyone updated the field. A Class I recall requires something else entirely: a person physically reaching every affected unit, quarantining it or correcting it, and producing evidence that it happened. The gap between the number your system can flag and the number you can prove somebody touched is the actual job, and it is the part nobody writes about.
Everything in this article is sourced to GAO, FDA and the Code of Federal Regulations.
This piece is about who owns that gap, why the federal backstop behind you is thinner than most clinical engineering teams assume, and an honest ladder of ways to close it, ordered by cost, starting with the ones that are not RFID and cost nothing.
This is about durable capital equipment: infusion pumps, ventilators, monitors, beds, imaging accessories, therapy devices. The things that live in clinical use, move between units, go out for repair, and come back.
It is not about medication, kit and tray, or pharmacy consumables. Those are a genuinely different problem with a different workflow, a different owning department and an established set of vendors who solve it well. If your recall is a lot-numbered consumable in a supply room, the answer is a par-level and lot-tracking problem, and this is not the article for it.
Saying that out loud matters, because the reason the durable-equipment question is badly served online is that it keeps getting answered by people writing about one of the other two problems.
Look at what FDA actually posted over a recent stretch and the split is obvious.
Some actions are identified by lot or batch number. Convenience kits, catheters, breathing circuits, IV start kits. These sit in a stockroom or a supply cart, they are identified by a number printed on a box, and the search is a physical sweep of storage locations.
Some are shelf-stock removals of implantables. In August 2026, FDA designated Boston Scientific’s removal of unused Infinion CX spinal cord stimulator leads as a Class I action, dated August 5, 2026. Boston Scientific’s letter asked customers to stop use and segregate affected product, and FDA’s notice is explicit that the action does not affect devices already implanted. Boston Scientific reported 1,081 serious injuries and no deaths associated with the lead fracture issue as of May 27, 2026. Operationally this is still a stockroom search, just a higher-stakes one.
Then there is the third kind, and it is the one with no good playbook. The device is identified by model and software version rather than by lot, it is not in a stockroom, it is plugged in next to a patient, and the corrective action requires a technician to reach it.
The clearest current example is the Fresenius Kabi Ivenix large volume pump. FDA classified it as the most serious type of recall, and it is a correction, not a removal. Affected software is version 5.10.1 and earlier. The required action is to update the Infusion Management System to version 5.2.2 and the pump software to version 5.10.2. Fresenius Kabi’s customer letter, dated November 14, instructed facilities to keep pumps plugged in during use wherever possible until the update is done, to avoid programming an infusate with two leading zeros, and after updating to review battery health across the fleet and replace any battery at 70 percent or below. Two serious injuries and no deaths had been reported as of November 18.
Read that action list as a clinical engineering manager rather than as a headline. Every single item requires physical contact with an individual pump. Not with a record of a pump. With the pump. And the last item, reviewing battery health across the fleet, means you have to reach all of them, not just the ones a work order got assigned to.
That is what the word “locating” is covering for.
The regulation most people in this workflow have never read is 21 CFR Part 7, and it is short.
A recall, in FDA’s definition, is “a firm’s removal or correction of a marketed product.” A correction is “repair, modification, adjustment, relabeling, destruction, or inspection (including patient monitoring) of a product without its physical removal to some other location.” A consignee is “anyone who received, purchased, or used the product being recalled.” That is you.
Every recall runs against a recall strategy, defined as “a planned specific course of action to be taken in conducting a specific recall, which addresses the depth of recall, need for public warnings, and extent of effectiveness checks.”
Effectiveness checks are the part that lands on your desk. The regulation states their purpose plainly: “to verify that all consignees at the recall depth specified by the strategy have received notification about the recall and have taken appropriate action.” And it assigns them: “The recalling firm will ordinarily be responsible for conducting effectiveness checks, but the Food and Drug Administration will assist in this task where necessary and appropriate.”
The manufacturer runs the check. You are the one being checked. And the level of checking is set in the strategy, on a scale the regulation spells out:
Two things follow from that scale, and they point in opposite directions.
The first is that on a Level A Class I action, somebody is going to call you and ask what you did. Your answer needs to be a count of units touched, not a count of units flagged.
The second is the uncomfortable one. On a Level D strategy, there is a 98 percent chance nobody ever asks. The absence of a phone call is not evidence that the recall reached every unit. It is evidence about the sampling percentage.
This is where the December 2025 GAO report changes the calculation.
GAO-26-107619, “Medical Device Recalls: HHS and FDA Should Address Limitations in Oversight of Recall Process,” was published December 8, 2025 and publicly released December 12, 2025. Four findings from it matter to anyone running this workflow.
Volume. “From fiscal years 2020 to 2024, FDA oversaw the recall of 3,934 medical devices.” Every one of them was voluntary: “All were voluntarily recalled by manufacturers. FDA can mandate a recall, although it rarely does so.”
Speed. “From fiscal years 2020 to 2024, FDA couldn’t meet its 3-month goal of terminating recalls (meaning FDA determines all reasonable efforts were made by the manufacturer to remove or correct the device) due to resource constraints.” GAO’s own table puts the average time from initiation to termination for Class I device recalls at 632 business days, with a median of 610.
Verification. FDA has a separate mechanism beyond the manufacturer’s own effectiveness checks. GAO describes it: “For some recalls, FDA, or a third party with whom FDA contracts, may also conduct what is known as a ‘recall audit check’ to determine if the appropriate parties received notification of the recall and followed the instructions in the notification.”
And then the finding that should hold your attention. GAO reports that FDA officials named this among the oversight activities being skipped. In GAO’s words: “According to officials, examples of important oversight activities not conducted include reviewing manufacturer Recall Status Reports and conducting in-person recall audit checks.”
GAO recommended that HHS work with FDA to conduct workforce planning for device recalls, and to assess and seek additional authority for manufacturer-initiated recall strategies. HHS concurred with the first and took the second under consideration.
Put the four together. Thousands of recalls, all of them voluntary actions by manufacturers, terminating on a timescale measured in years rather than months, with the independent in-person verification step among the activities that are not being performed.
The practical translation for a clinical engineering department is not that the system is broken. It is that the system assumes you did it. Nobody is coming to check whether the flagged count and the touched count were the same number, which means the only party with both the ability and the reason to know is you.
None of this is a technology failure. It is a records problem with a physical tail, and it comes from four ordinary things.
Assignment drift. The inventory says Unit 4 West. Equipment moves during a code, during a transfer, during a surge, during a room turnover, and the record updates only if someone remembers to update it. The longer the interval since the last full physical inventory, the wider the drift. This is the single largest contributor and it has nothing to do with radios.
Devices that are legitimately not where any record would put them. In biomed for repair. Out at a vendor for service. Loaned to an affiliated site. On a rental or loaner agreement where the serial numbers in your system are not the serial numbers on the floor. Sitting in a discharge room nobody has cleared.
Devices that moved with a patient. Transport, a transfer to another facility, a home-going pump. These are the ones that turn a two-day sweep into an eleven-day one, because they have to be chased individually.
Fleets that were never serialized in the first place. This is the failure that quietly destroys the whole workflow. If the equipment record carries a model and a department but no serial number, a recall scoped to a serial range cannot be resolved against it at all. You do not get a flagged count at all. You get “all pumps of this model, quantity unknown, location approximate.” Every hour spent after that is spent rebuilding data you should already have had.
Notice what is common to all four. The first thing that fails is the record, not the search. Which is why the first rungs of the ladder below are not technology.
Work down this in order. Stop when the remaining exposure stops justifying the next rung. Most facilities should never reach the bottom.
1. Serialize the fleet. This is the whole ballgame. Every recall notice worth responding to is scoped by model and serial or lot range. If your equipment record does not carry a captured serial number for each unit, you cannot scope the response, and you will over-pull, over-touch and over-spend on every recall from now until you fix it. Capturing serials on an existing fleet is tedious and it is a one-time cost. It is also the difference between a targeted response and a building sweep. Nothing else on this list produces value until this is done.
2. Make the assignment field mean something. Decide what “assigned department” represents, write it down, and enforce a single moment when it changes. Most drift comes from a field that everyone interprets differently and nobody owns. This costs a policy memo and some enforcement, and it is the highest-return unpaid item after serialization.
3. Write the recall procedure before you need it, and make it name the touched count. The procedure should state explicitly that the deliverable is a reconciliation of flagged units against units physically verified, with a named owner for every unit in the difference. If your current procedure ends at “work orders issued,” it ends one step before the part that matters. Add the closing step and the evidence it produces, because that is what you hand somebody during an effectiveness check.
4. Pre-build the hard-to-reach list. You already know which categories will burn the days: units out for service, units on rental or loaner, units at off-site clinics, units that travel with patients. Maintain that list continuously rather than reconstructing it under time pressure. It is a report, not a purchase.
5. Run a real physical inventory on a cycle, and measure the drift. Not to satisfy an auditor. To measure the distance between your record and reality, so that when a recall lands you know whether you are working from a 5 percent error rate or a 30 percent one. That number changes how you staff the response. If you have never measured it, you are guessing.
6. Instrument location only after the five above, and only where the arithmetic works. This is the rung where RFID enters, and it should enter last, for a reason. Location technology attached to a poor inventory record produces a faster way to fail. Attached to a serialized, current record it shortens the physical sweep, because a fixed read point at a doorway or a handheld pass through a unit tells you which zone to walk into instead of which building.
Be specific about what this is worth to you before buying it. The honest test is three questions: how many recall actions actually touch your fleet in a year, how many hours does the physical phase currently consume, and what else does the same instrumentation pay for. If recalls are the only justification, the numbers rarely work. If the same read points also serve your periodic physical inventory, your rental and loaner reconciliation, and your equipment utilization questions, they often do. Recall response is a beneficiary of an asset tracking program. It is a weak reason to start one.
Since this is where most articles start overselling, here is the boundary in plain terms.
Passive UHF RFID, the EPC Gen2 kind operating in the 902 to 928 MHz US band, reads tags when they pass through an energized field. Fixed readers such as the Zebra FX9600, Zebra FXR90 or Impinj Speedway R420 connect over LLRP and cover a doorway, a corridor or a storage room. Handheld capture with a Zebra RFD40 sled paired to a TC22R lets a technician sweep a room. Typical read ranges run 5 to 20 feet depending on tag, antenna and environment.
What that gives you during a recall is a faster sweep and a set of last-seen read events, which narrows the search area. It is choke-point and sweep coverage, not continuous whereabouts. A tagged pump that has not passed a read point since Tuesday tells you where it was on Tuesday.
And the same caution from our previous piece applies here, because it applies to every audit-shaped use of this technology: a read event is evidence that something in radio range answered with the expected number. It is not proof that a person put hands on the device. For a recall closeout, the touched count has to come from a human confirming the corrective action, not from a radio. Use the technology to shorten the hunt. Do not use it to close the loop.
These are answerable today, by your own team, without a vendor in the room.
If question 5 has no answer, that is the place to start, and it costs nothing but an afternoon.
Plainly, because the alternative is a marketing claim: we do not ship a recall management product.
AssetWorx is an asset inventory and visibility platform. It records what readers and handhelds report, and it holds the equipment record, including serial numbers, that a recall response has to be reconciled against. That is a genuine and useful contribution to rungs one through six above, and it is also the entire contribution. There is no recall notice ingestion, no model and serial range matching against a recall feed, no effectiveness check documentation, and no closeout evidence workflow in the product today. Our own internal notes list recall reporting among the clinical workflow features the platform would need to build in order to compete on that ground.
We are publishing this anyway, because the part of the answer that helps the most people is free and does not involve us. Serialize the fleet, make the assignment field mean something, and write a recall procedure whose last step is a touched count rather than a work order count. Facilities that do those three things respond to recalls dramatically better than facilities that buy location technology first, and the order matters more than the budget.
If we ship something in this area later, it will be its own announcement with its own specifics.
How do you locate recalled medical devices in a hospital? In two phases that most write-ups collapse into one. First, scope: match the manufacturer, model and serial or lot range in the recall notice against your equipment inventory to produce a flagged list. That part is a database query and takes minutes. Second, retrieval: physically reach each flagged unit, apply the corrective action or quarantine it, and record that it happened. That part takes days to weeks, and its duration is set almost entirely by how accurate your equipment record was before the notice arrived.
Who is responsible for making sure a recall reaches every device in a hospital? The manufacturer conducts effectiveness checks under 21 CFR 7.42, which verify that consignees received notification and took appropriate action. The hospital is the consignee, and it is the party that has to have taken the action and be able to say so. FDA may also conduct a recall audit check, though GAO reported in December 2025 that in-person recall audit checks are among the oversight activities not being conducted, according to FDA officials.
What is a recall effectiveness check? Per 21 CFR 7.42, its purpose is “to verify that all consignees at the recall depth specified by the strategy have received notification about the recall and have taken appropriate action.” The recalling firm is ordinarily responsible for conducting it. The strategy sets the level, from Level A at 100 percent of consignees down to Level E, which is no effectiveness checks at all.
Does a CMMS locate recalled equipment? It identifies affected units and generates the work orders. That is scoping, not locating. What it can tell you about position is whatever the assignment field says, and the accuracy of that field is a function of how recently it was maintained, not of the software.
Why do device recalls take so long to close out? GAO’s December 2025 report gives the aggregate picture. Class I medical device recalls initiated in fiscal years 2020 through 2024 averaged 632 business days from initiation to termination, with a median of 610, and FDA was unable to meet its 3-month termination goal due to resource constraints. At the facility level, the delay is usually concentrated in a small number of units that are out for service, on loan, off-site, or travelling with patients.
Is a software correction really a recall? Yes. FDA’s definition of a recall covers removal or correction, and a correction includes “repair, modification, adjustment, relabeling, destruction, or inspection (including patient monitoring) of a product without its physical removal to some other location.” The Fresenius Kabi Ivenix large volume pump action is a correction classified at the most serious level, and it requires a technician to reach each pump rather than pull it from a shelf.
Will RFID solve our recall problem? It will shorten the physical search phase if, and only if, the equipment record it is attached to is serialized and current. It does not scope the recall, it does not document the corrective action, and a read event is not proof that a person touched the device. Treat it as an accelerator for one phase of the work, and justify it on the other things the same read points do, such as periodic physical inventory and loaner reconciliation.
What should we fix first if we can only fix one thing? Serial number capture on the existing fleet. Every recall notice is scoped by serial or lot range, and a record without serial numbers cannot be reconciled against one. Everything else on the ladder gets cheaper once that is done.
Products/Passive RFID/Passive RFID Overview.md. Source of all passive UHF hardware, frequency, protocol and read range references. Internal.