Skip to main content
beginner Featured

Confidential and Anonymous Medical Device Reporting: Know the Difference

A practical guide to identity options when reporting a medical device concern to FDA, an EU authority, an employer, or MD Watchdog.

MD Watchdog Team
beginner
9 min read
January 31, 2025
whistleblower confidential reporting FDA MDR patient safety

Anonymous and confidential are not synonyms.

An anonymous channel does not receive your identity. A confidential channel receives it but limits who may see it. An identity-shielded external report may omit your details from a submission to a manufacturer or authority even though the platform that prepared it knows who you are.

The distinction matters because a channel may need contact details to clarify evidence. Attachments can also reveal names, account identifiers, document authors, or workplace information even when a form leaves the name field blank.

This guide explains the published identity rules for key United States and European Union routes. It does not provide employment, whistleblower, privacy, or legal advice.

Start with the type of concern

Use the route that matches the problem:

ConcernTypical route
Injury, malfunction, product-quality problem, or use error in the United StatesFDA MedWatch voluntary report
Suspected unlawful medical-device marketing or regulatory misconduct in the United StatesFDA CDRH allegation
Device incident or safety issue in an EU countryThe national competent authority’s incident route
Broader suspected EU MDR non-complianceThe relevant national competent authority’s market-surveillance contact
Concern learned through workInternal or external whistleblowing channel, with jurisdiction-specific advice where retaliation or evidence ownership is a concern

If someone may be in immediate danger, contact local emergency services. For a device-related health concern, contact a qualified healthcare professional as well as the reporting authority.

United States routes

FDA CDRH allegations of regulatory misconduct

The FDA’s CDRH allegation page says anyone may report suspected misconduct and may choose to report anonymously. Examples include misleading promotion, marketing without required clearance or approval, failure to register and list, and quality-system concerns.

The same page says the FDA will not share a reporter’s identity or contact information outside the agency unless law, regulation, or a court order requires it. Providing contact details lets the FDA acknowledge the allegation, issue a reference number, and ask follow-up questions.

That is an FDA policy statement about its channel. It is not a promise that no detail in the evidence could identify you, and it does not create a general protection against workplace retaliation.

FDA MedWatch

Patients, consumers, and health professionals can use MedWatch for voluntary reports about adverse events and product problems.

The Form 3500 instructions explain a different identity boundary. The reporter section helps FDA obtain follow-up information. For serious cases, the reporter’s identity may be shared with the manufacturer unless the reporter specifically requests otherwise in the form’s confidentiality field. FDA says it does not disclose the reporter’s identity to the public under Freedom of Information Act requests.

Read the current form and instructions before relying on that option. Do not assume that every FDA reporting route has the same confidentiality rule.

European Union routes

There is no single public “EU MDR complaint form” for every concern. National competent authorities receive incident reports and market-surveillance information through their own channels. The European Commission maintains a medical-device authority contact directory.

Identity requirements vary. For example, the Irish HPRA public incident form requests reporter details, and the HPRA says it may contact the reporter and manufacturer. Other authorities use different forms and privacy notices. Check the actual authority page rather than relying on a country table copied from a third-party article.

The EU Whistleblower Protection Directive establishes minimum protections for people who learned about certain breaches in a work-related context, including product-safety and compliance matters. Protection depends on the Directive’s scope, the reporter’s reasonable grounds, the channel used, and the national law that transposes it. The Directive leaves Member States room to decide how anonymous reports are accepted and followed up.

If employment, retaliation, trade secrets, confidentiality duties, or possession of internal documents is a concern, obtain advice from a qualified lawyer, union, or authorised whistleblower support body in the relevant country before disclosing material.

The MD Watchdog identity boundary

MD Watchdog currently requires sign-in. The platform therefore knows the email address associated with the account and stores the report under that account. Administrators authorised through the application’s allow-list can access submitted evidence and any contact details supplied in the form.

The form’s identity preference asks MD Watchdog not to include the reporter’s contact details in an external report. It does not make the submission anonymous to MD Watchdog, erase identifying information from uploaded files, guarantee that the facts cannot identify the source, or override legal obligations.

MD Watchdog does not currently promise that a reviewer is available, that a report will be filed, or that an authority will act. Expedited review is not currently available for purchase.

Before uploading:

  1. remove personal information that is not necessary to understand the concern;
  2. check screenshots and documents for names, email addresses, account IDs, visible notifications, and document metadata;
  3. submit only material you are authorised to disclose;
  4. keep originals and record when and where the evidence was obtained; and
  5. state what you observed separately from what you infer.

Choosing between anonymity and follow-up

An anonymous report can reduce direct identity exposure, but it can also prevent an authority from clarifying dates, device identifiers, patient outcomes, or how the evidence was obtained. A confidential report may be easier to investigate, but it requires trust in the recipient’s published privacy and disclosure rules.

Ask four questions before choosing:

  • Does this route accept a report without identity details?
  • Who can access the identity if I provide it?
  • Can the recipient share it with a manufacturer or another authority?
  • Could the facts or attachments identify me anyway?

Save the relevant form, privacy notice, and submission confirmation. Policies can change, and a screenshot of the applicable terms may matter later.

A careful report is more useful than a dramatic one

Provide the product name, manufacturer if known, model or version, UDI if available, place and date, what happened, the direct evidence, and the possible harm. Mark uncertain points as uncertain. Do not label a company fraudulent, a device illegal, or a regulatory breach proven when the evidence supports only a concern.

The authority decides whether to investigate and what legal conclusion follows.

Last checked against FDA, European Commission, EUR-Lex, and HPRA public sources on 29 July 2026. This guide has not been approved by a lawyer or regulatory professional.

Ready to structure the evidence?

Sign in to create a free submission. Reviewer availability, filing, timing, and authority action are not guaranteed.

Start a Submission

No credit card required • Free forever plan available