Anonymous and confidential are not synonyms.
An anonymous channel does not receive your identity. A confidential channel receives it but limits who may see it. An identity-shielded external report may omit your details from a submission to a manufacturer or authority even though the platform that prepared it knows who you are.
The distinction matters because a channel may need contact details to clarify evidence. Attachments can also reveal names, account identifiers, document authors, or workplace information even when a form leaves the name field blank.
This guide explains the published identity rules for key United States and European Union routes. It does not provide employment, whistleblower, privacy, or legal advice.
Start with the type of concern
Use the route that matches the problem:
| Concern | Typical route |
|---|---|
| Injury, malfunction, product-quality problem, or use error in the United States | FDA MedWatch voluntary report |
| Suspected unlawful medical-device marketing or regulatory misconduct in the United States | FDA CDRH allegation |
| Device incident or safety issue in an EU country | The national competent authority’s incident route |
| Broader suspected EU MDR non-compliance | The relevant national competent authority’s market-surveillance contact |
| Concern learned through work | Internal or external whistleblowing channel, with jurisdiction-specific advice where retaliation or evidence ownership is a concern |
If someone may be in immediate danger, contact local emergency services. For a device-related health concern, contact a qualified healthcare professional as well as the reporting authority.
United States routes
FDA CDRH allegations of regulatory misconduct
The FDA’s CDRH allegation page says anyone may report suspected misconduct and may choose to report anonymously. Examples include misleading promotion, marketing without required clearance or approval, failure to register and list, and quality-system concerns.
The same page says the FDA will not share a reporter’s identity or contact information outside the agency unless law, regulation, or a court order requires it. Providing contact details lets the FDA acknowledge the allegation, issue a reference number, and ask follow-up questions.
That is an FDA policy statement about its channel. It is not a promise that no detail in the evidence could identify you, and it does not create a general protection against workplace retaliation.
FDA MedWatch
Patients, consumers, and health professionals can use MedWatch for voluntary reports about adverse events and product problems.
The Form 3500 instructions explain a different identity boundary. The reporter section helps FDA obtain follow-up information. For serious cases, the reporter’s identity may be shared with the manufacturer unless the reporter specifically requests otherwise in the form’s confidentiality field. FDA says it does not disclose the reporter’s identity to the public under Freedom of Information Act requests.
Read the current form and instructions before relying on that option. Do not assume that every FDA reporting route has the same confidentiality rule.
European Union routes
There is no single public “EU MDR complaint form” for every concern. National competent authorities receive incident reports and market-surveillance information through their own channels. The European Commission maintains a medical-device authority contact directory.
Identity requirements vary. For example, the Irish HPRA public incident form requests reporter details, and the HPRA says it may contact the reporter and manufacturer. Other authorities use different forms and privacy notices. Check the actual authority page rather than relying on a country table copied from a third-party article.
The EU Whistleblower Protection Directive establishes minimum protections for people who learned about certain breaches in a work-related context, including product-safety and compliance matters. Protection depends on the Directive’s scope, the reporter’s reasonable grounds, the channel used, and the national law that transposes it. The Directive leaves Member States room to decide how anonymous reports are accepted and followed up.
If employment, retaliation, trade secrets, confidentiality duties, or possession of internal documents is a concern, obtain advice from a qualified lawyer, union, or authorised whistleblower support body in the relevant country before disclosing material.
The MD Watchdog identity boundary
MD Watchdog currently requires sign-in. The platform therefore knows the email address associated with the account and stores the report under that account. Administrators authorised through the application’s allow-list can access submitted evidence and any contact details supplied in the form.
The form’s identity preference asks MD Watchdog not to include the reporter’s contact details in an external report. It does not make the submission anonymous to MD Watchdog, erase identifying information from uploaded files, guarantee that the facts cannot identify the source, or override legal obligations.
MD Watchdog does not currently promise that a reviewer is available, that a report will be filed, or that an authority will act. Expedited review is not currently available for purchase.
Before uploading:
- remove personal information that is not necessary to understand the concern;
- check screenshots and documents for names, email addresses, account IDs, visible notifications, and document metadata;
- submit only material you are authorised to disclose;
- keep originals and record when and where the evidence was obtained; and
- state what you observed separately from what you infer.
Choosing between anonymity and follow-up
An anonymous report can reduce direct identity exposure, but it can also prevent an authority from clarifying dates, device identifiers, patient outcomes, or how the evidence was obtained. A confidential report may be easier to investigate, but it requires trust in the recipient’s published privacy and disclosure rules.
Ask four questions before choosing:
- Does this route accept a report without identity details?
- Who can access the identity if I provide it?
- Can the recipient share it with a manufacturer or another authority?
- Could the facts or attachments identify me anyway?
Save the relevant form, privacy notice, and submission confirmation. Policies can change, and a screenshot of the applicable terms may matter later.
A careful report is more useful than a dramatic one
Provide the product name, manufacturer if known, model or version, UDI if available, place and date, what happened, the direct evidence, and the possible harm. Mark uncertain points as uncertain. Do not label a company fraudulent, a device illegal, or a regulatory breach proven when the evidence supports only a concern.
The authority decides whether to investigate and what legal conclusion follows.
Last checked against FDA, European Commission, EUR-Lex, and HPRA public sources on 29 July 2026. This guide has not been approved by a lawyer or regulatory professional.