FDA Flags Data Integrity Issues at Device Testing Labs

Last updated: July 7, 2026
FDA Flags Data Integrity Issues at Device Testing Labs

In This Article:

FDA data integrity concerns third-party medical device testing labs documentation review

The U.S. Food and Drug Administration (FDA) has issued notifications raising FDA data integrity concerns about medical device testing labs, signaling that the agency is scrutinizing the reliability of test data generated by third-party laboratories. The notifications, published on the FDA’s dedicated data integrity page for medical devices, identify specific testing facilities where the agency has found evidence of data manipulation, falsification, or other practices that undermine the credibility of submitted test results. 

For medical device manufacturers that rely on third-party labs for performance, biocompatibility, or electrical safety testing, the implications are immediate. Data from compromised labs could jeopardize pending premarket submissions, trigger the need for retesting, and create downstream compliance risk that extends well beyond the lab itself. 

What the FDA Found 

The FDA’s notifications identify laboratories where inspections uncovered practices that call into question the integrity of test data. These issues range from outright data falsification to subtler problems such as manipulation of test parameters, selective reporting of results, and failure to follow validated test methods. In several cases, the agency determined that data from these labs could not be relied upon to support regulatory submissions. 

Rather than issuing traditional warning letters or import alerts, the FDA chose to publish findings through a notification system designed to alert device manufacturers and the broader industry. The agency has also made clear that manufacturers bear ultimate responsibility for the data in their regulatory submissions, regardless of whether testing was performed in-house or outsourced.  

This is consistent with 21 CFR Part 820 quality system requirements, which hold manufacturers accountable for the quality of work performed by suppliers and contractors. 

Third-Party Testing and the Supply Chain Risk 

Third-party testing is deeply embedded in the medical device regulatory process. Many manufacturers, particularly small and mid-sized firms, rely on external laboratories for specialized testing such as biocompatibility evaluations under ISO 10993, electromagnetic compatibility testing, and sterilization validation. The economics and technical demands of these tests make outsourcing a practical necessity for most companies. 

The FDA’s recent actions highlight a key vulnerability in this model. When manufacturers submit data from third-party labs as part of a 510(k), De Novo, or PMA application, they are implicitly vouching for that data’s integrity. If the FDA later determines that a lab engaged in fraudulent or unreliable practices, the agency may refuse to accept data from that facility, leaving manufacturers to bear the consequences.  

These concerns also extend to post-market obligations: compromised test data in design history files can trigger findings during FDA inspections of the manufacturer’s own facility, even when the manufacturer had no knowledge of the lab’s practices. 

How the FDA Expects Manufacturers to Respond 

The FDA expects manufacturers to proactively monitor its data integrity notifications and assess whether any testing partners appear on the list. If a manufacturer identifies an affected lab, the agency recommends a thorough review of all data sourced from that facility. Depending on the findings, this may lead to retesting with a different accredited lab, supplemental submissions, or updates to design history files. 

Beyond reacting to specific notifications, the FDA’s messaging reinforces the importance of robust supplier qualification programs. Manufacturers should evaluate third-party labs not only for accreditation status but also for quality management practices, data handling procedures, and audit histories. Accreditation through programs such as the FDA’s Accreditation Scheme for Conformity Assessment (ASCA) or ILAC-signatory bodies provides a baseline level of assurance, but the FDA has made clear that accreditation alone does not guarantee data integrity. 

What This Means for Your Business 

Manufacturers that have used third-party testing labs should take three concrete steps. First, cross-reference the FDA’s published notifications against current and past testing partners. Any overlap should trigger an internal assessment of the scope and significance of affected data. 

Second, evaluate whether supplier qualification procedures are sufficient to detect integrity risks before they reach a regulatory submission. Quality agreements with testing partners should explicitly address data integrity obligations and the manufacturer’s right to audit. 

Third, for companies with pending premarket submissions, it may be prudent to confirm with the reviewing division whether any data originated from a flagged laboratory. Proactive communication with the FDA in these situations can help avoid delays and demonstrate good-faith compliance. 

Quality Smart Solutions works with device manufacturers to assess supplier qualification frameworks and ensure that third-party testing data meets FDA expectations for integrity and reliability. 

Frequently Asked Questions

Does the FDA require manufacturers to stop using a lab listed in its data integrity notifications?

The FDA’s notifications do not constitute a formal ban on using a listed lab, but they send a strong signal that data from those facilities may not be accepted in regulatory submissions. Manufacturers should treat a listing as a serious red flag and evaluate whether continued use of the lab is defensible given the identified concerns. In practice, most companies will need to identify alternative testing partners and determine whether previously submitted data requires supplementation or replacement. 

The FDA has not indicated that submissions will be automatically rejected, but reviewers may issue additional information requests or refuse to rely on specific test reports originating from a compromised facility. The impact depends on the nature of the data integrity findings and how central the affected test data is to the submission. Manufacturers with pending applications should consult their regulatory affairs teams to assess exposure and prepare supplemental data if necessary. 

Beyond confirming accreditation status, manufacturers should conduct periodic on-site audits of their testing partners, review the lab’s quality management system documentation, and examine how raw data is recorded, stored, and reported. Quality agreements should include specific provisions related to data integrity, record retention, and the manufacturer’s audit rights. The FDA’s expectations under 21 CFR Part 820 place responsibility for supplier oversight squarely on the manufacturer, making passive reliance on accreditation certificates insufficient. 

Key Takeaways 

  • The FDA has published data integrity notifications identifying third-party medical device testing labs where evidence of data manipulation or falsification was found. 
  • Manufacturers are responsible for the integrity of all data in their regulatory submissions, including data generated by external labs. 
  • Companies should cross-reference the FDA’s notification list against their current and past testing partners and conduct internal assessments where overlap exists. 
  • Supplier qualification programs should include on-site audits, quality agreements with data integrity provisions, and ongoing monitoring beyond initial accreditation checks. 
  • Proactive engagement with the FDA on pending submissions containing potentially affected data can help reduce regulatory delays. 

Looking Ahead 

The FDA’s creation of a dedicated notification system for data integrity issues reflects a broader regulatory focus on the reliability of data underlying device safety and performance claims. Manufacturers that treat supplier oversight as a compliance checkbox face growing exposure as the agency continues to expand its scrutiny of third-party labs. 

Quality Smart Solutions supports medical device manufacturers at every stage of the regulatory process, from supplier qualification and lab auditing to premarket submissions and compliance program development. If your testing data or supplier oversight practices need a closer look, contact us to connect with our medical device regulatory team. 

0/5 (0 Reviews)
Picture of Gautamee Choudry Thyagaraj
Gautamee Choudry Thyagaraj

Regulatory Affairs Solutions Specialist

Regulatory Affairs professional with a strong background in compliance, quality systems, and medical device regulatory strategy. At Quality Smart Solutions (QSS), Gautamee contributes to practical regulatory and quality support, helping clients navigate complex requirements with clarity and structure across global markets. An RCC-MDR professional and BSI-Certified ISO 13485/MDSAP Lead Auditor, she brings a grounded focus on real-world regulatory implementation, translating complex compliance topics into clear, actionable guidance for clients and teams. Outside of work, Gautamee enjoys travelling, cooking, and exploring different cultures and histories around the world.

Related Articles
We use cookies to display personalized content, analyze site traffic, provide recommendations, and ensure you have a great browsing experience. By continuing to use our site, you consent to our use of cookies. Privacy Policy.