The Software Updated Successfully – did the Patient’s Alarm Settings Survive?

TL;DR

  • FDA issued an Early Alert involving GE HealthCare Portrait Core Services software.
  • During updates, monitored patients may be removed from the system and alarm settings may return to factory defaults.
  • FDA says affected systems can continue to be used; facilities should establish appropriate alternative monitoring before performing an update.
  • This is an Early Alert, not a final recall classification.
  • The broader lesson: technical update completion is not the same as clinical acceptance.

FDA says GE reported that during an update of Portrait Core Services software, some patients monitored using Portrait Mobile devices were discharged removed from the monitoring system. FDA also says alarm settings may reset to factory defaults following the update.

That creates the possibility that the hardware appears operational while the intended clinical monitoring configuration is no longer present.

Why This Is More Important Than a Typical Software Bug

In ordinary enterprise software, an update failure might inconvenience users.

In patient-monitoring software, configuration is part of the clinical risk-control system.

An alarm threshold is not merely a preference.

It may determine when clinical staff are warned that a patient’s condition is changing.

What FDA Says

FDA’s current communication is an Early Alert, meaning the agency is communicating potentially significant risk while its evaluation continues.

FDA says affected systems may continue to be used and instructs facilities to establish appropriate alternative monitoring before software updates.

That is different from saying the devices must be removed from service.

The Quality-System Lesson

A weak update process looks like:

Install → Version check → Done

A stronger clinical-device update looks like:

Identify affected patients → Establish backup monitoring → Capture configuration → Update → Verify patient enrollment → Verify alarms → Restore workflow → Document clinical acceptance

The update is not complete when IT says the software installed successfully.

It is complete when the clinical function has been demonstrated to be restored.

What Hospitals Should Check

Organizations using safety-critical device software should consider whether change-control procedures explicitly require:

  • pre-update configuration capture;
  • contingency monitoring;
  • post-update alarm verification;
  • user acceptance;
  • connectivity verification;
  • version recording;
  • rollback planning;
  • clinical engineering sign-off.

These are practical risk controls; they should not be misrepresented as new FDA requirements created by this alert.

Where Organizations Get Caught

The process often spans three owners:

IT installs the software.

Clinical engineering manages the device.

Nursing/clinical staff depend on its configuration.

When nobody owns the entire transition, each function can complete its task successfully while the overall clinical system remains unsafe.

Frequently Asked Questions

Is this a Class I recall?

FDA’s current communication is an Early Alert; it should not be described as a Class I recall unless FDA later classifies it that way.

Can affected systems still be used?

Yes. FDA says they may continue to be used.

What can happen during the update?

Patients may be removed from the monitoring system and alarm settings may reset to factory defaults.

What should facilities do before updating?

FDA advises establishing appropriate alternative monitoring first.

What should other device manufacturers learn?

Software-update validation should include preservation or restoration of clinically significant configuration, not merely installation success.

Source

FDA Early Alert: GE Portrait Core Services

Leave a Reply