eDHR

Electronic Device History Record Software

eDHR. Every unit carries its manufacturing proof.

Execute the device master record with component genealogy, in-process inspection, UDI and labels, sterilization, nonconformance, and release attached to every lot or serial number.

eDHR / one serialized device, reconstructed
The unit is the spine; material, work, inspection, software, and label evidence branch into it.
Physical inputs
SN 001842 / as-built record spine
Execution evidence
CTRL-7721
lot · status · quantity
110
Controller installed
operator · equipment · actual time
Torque 4.2 N·m
method · source · reviewer
FW 3.8.1
lot · status · quantity
220
Firmware loaded
operator · equipment · actual time
Checksum 9F21
method · source · reviewer
INS-1044
lot · status · quantity
310
Final inspection
operator · equipment · actual time
18 / 18 passed
method · source · reviewer
UDI-DI 00884…
label version 12 · reconciled 1 / 1
QA disposition
Device released
complete genealogy
Forward trace
distribution · complaint · recall

An electronic device history record should prove that the physical device was built, inspected, labeled, and released against the approved definition in effect for that unit or lot. It is not a scanned traveler and it is not a folder assembled after production.

Seal turns the approved device master data into guided execution. Components, equipment, operators, process values, inspections, labels, software, sterilization evidence, exceptions, and release decisions accumulate around the actual serial or lot identity while work occurs.

01

The eDHR is the as-built product record

The approved definition describes what may be built. The eDHR records what was built. That distinction must survive revisions, substitutions, rework, split lots, outsourced operations, and serial-level variation.

For each released population, Seal preserves the effective product and process version, work order, dates, quantities, operators, equipment, component lots or serials, inspections, labels, acceptance evidence, and accountable release. Unit-level products can carry their own genealogy; true batch products can share evidence without copying it into thousands of records.

FDA's Quality Management System Regulation became effective on February 2, 2026 and incorporates ISO 13485:2016 by reference. The regulatory framework changed, but the operational need did not: the manufacturer must retain controlled evidence that production and acceptance followed the applicable specification and quality system.

eDHR / one serialized device, reconstructed
The unit is the spine; material, work, inspection, software, and label evidence branch into it.
Physical inputs
SN 001842 / as-built record spine
Execution evidence
CTRL-7721
lot · status · quantity
110
Controller installed
operator · equipment · actual time
Torque 4.2 N·m
method · source · reviewer
FW 3.8.1
lot · status · quantity
220
Firmware loaded
operator · equipment · actual time
Checksum 9F21
method · source · reviewer
INS-1044
lot · status · quantity
310
Final inspection
operator · equipment · actual time
18 / 18 passed
method · source · reviewer
UDI-DI 00884…
label version 12 · reconciled 1 / 1
QA disposition
Device released
complete genealogy
Forward trace
distribution · complaint · recall
Fig. 1 / Electronic device history from approved definition to released serial
02

A complete eDHR answers unit-level questions without reconstruction

For any serial or controlled lot, an authorized reviewer should be able to answer:

  • which product, revision, market, and approved route governed the build;
  • which component lots and serials were installed, removed, returned, or scrapped;
  • which people, equipment, fixtures, programs, and software executed each operation;
  • which measured values and source files supported in-process and final acceptance;
  • which labels and UDI identities were printed, applied, rejected, or replaced;
  • which nonconformances, concessions, rework steps, and re-inspections affected the unit;
  • which sterilization or outsourced-process population contained it; and
  • who released it, under which evidence state, and where it later shipped.

Those answers must come from connected source records, not a narrative assembled for an inspection. Seal stores shared order-level evidence once and unit-specific evidence at the unit, preserving both performance and exact traceability.

03

Device master data becomes executable behavior

Drawings and procedures remain controlled source documents, but production needs structured rules. A device configuration resolves the current bill of materials, routing, work instructions, tools, fixtures, equipment classes, software or firmware, inspection plans, sampling, labels, and signatures.

Effectivity can depend on date, site, line, market, model, revision, or serial range. Seal freezes the applicable configuration when execution begins. An engineering change identifies open orders, inventory, training, inspection programs, labels, validation evidence, service stock, and released populations before the new state becomes effective.

Traceability / requirement → output → verification → result
Requirement
Design output
Verification
Result
Status
REQ-047 / flow accuracy ±3%
DV-103 / impeller spec
VER-047 / bench protocol
RES / 2.1% across range
✓ Pass
REQ-112 / alarm within 30s
DV-208 / sensor loop
VER-112 / timing study
RES / 24s mean
✓ Pass
REQ-203 / battery 8h continuous
DV-312 / cell chemistry
VER-203 / life test
RES / 9.2h median
✓ Pass
Clickable chain / not a lookup puzzle
REQ → output → verification → result. Each step opens the evidence, not a folder.
Fig. 2 / Design input through manufacturing and post-market evidence
04

Work orders create the physical population

ERP can remain authoritative for demand and the work-order reference. Seal creates or receives the GMP execution identity and the planned product, revision, quantity, site, and due state.

Serialization may occur at order creation, at a controlled production step, or when the physical identifier is applied. The system distinguishes reserved, commissioned, built, accepted, rejected, scrapped, released, and shipped states. Split and merge events preserve which evidence applies to which physical units.

The eDHR therefore answers both directions: given a device, show every input and decision; given a component or process concern, show every affected device.

05

Components are verified at point of use

Each issue or scan checks part number, approved revision, supplier and internal lot, serial where applicable, status, expiry, quantity, and eligibility for the active device configuration. Alternate parts require an effective approved rule, not a free-text explanation.

Actual consumption remains distinct from planned consumption. Scrap, return, substitution, and partial use reconcile against the work order. A supplier nonconformance can trace forward through subassemblies and finished serials without relying on an exported ERP report.

Scan → six checks → hard stop / block, don't warn
Scan / material barcode
Cat# SC-ACS-500 / LOT-8811
Material
Sodium Chloride / matches step
Lot released
LOT-8811 / QA-released 2026-03-17
Not expired
Exp 2027-09 / within date
Not quarantined
Status available
Grade
Cat# SC-ACS-500 / expected SC-USP-500
Hard stop / workflow halted
Expected: Sodium Chloride USP (Cat# SC-USP-500)
Scanned: Sodium Chloride ACS (Cat# SC-ACS-500) — return to shelf
Three seconds of scanning instead of $400,000 in losses.
Fig. 3 / Point-of-use verification before consumption
06

Assembly records preserve sequence and workmanship

Guided steps expose only the effective instruction and required evidence. Barcode scans, torque values, cure conditions, setup confirmations, photographs, machine results, and witness signatures enter at the operation where they matter.

Dependencies control sequence while approved branches handle legitimate variation. A skipped operation, late entry, failed prerequisite, or out-of-range value remains an exception. The record retains the original value, correction, reason, user, timestamp, and downstream assessment rather than overwriting the build history.

07

Equipment, tools, and people gate execution

The selected asset must be qualified for the operation and current for calibration, maintenance, setup, and software state. The selected operator must hold the effective training and practical qualification for the task.

Tooling and fixtures can carry their own serial identity, calibration range, usage count, location, and product-contact history. A later calibration failure can identify every unit processed since the last acceptable condition and place that population into assessment.

08

Inspection belongs to the operation and device

Incoming, in-process, and final inspection records retain characteristic, method, instrument, sample or unit, specification, measured value, result, inspector, and review state. Machine vision or tester output can remain authoritative in its source while Seal receives the contextual result and evidence reference.

Sampling plans resolve from the effective configuration and risk. Failed inspection identifies the exact unit or bounded lot population and triggers the approved nonconformance path. Retest and resample remain separate, justified events.

09

Labels and UDI are generated from approved state

Label content should come from controlled product, market, manufacturing, expiry, and UDI data. Seal renders the approved template, verifies printer and stock, records the output identity, and confirms application to the correct physical device or packaging level.

Reprints retain reason and relationship to prior output. Commission, aggregation, decommission, scrap, and packaging events reconcile serial identities. A label change identifies affected configurations, inventory, open orders, markets, and validation before release.

Unit → case → pallet / serials aggregate up
Units (saleable)
12 commissioned
SN01
SN02
SN03
SN04
SN05
SN06
SN07
SN08
SN09
SN10
SN11
SN12
Cases
3 assembled
Case 01
4 × SN01–12
Case 02
4 × SN01–12
Case 03
4 × SN01–12
Pallet 001 / DSCSA-reportable
3 cases / 12 serials / transaction history sealed
Scan any serial → complete history. Counterfeit detection is a database query.
Fig. 4 / UDI and serialization carried across packaging levels
10

Rework creates a controlled branch, not a rewritten history

Nonconformance starts with the affected device, operation, characteristic, component, equipment, and evidence attached. Containment identifies the physical population. Review determines correction, rework, use-as-is where permitted, return, or scrap.

An approved rework instruction creates additional execution while preserving the original failed state. Re-inspection demonstrates the disposition outcome. The completed eDHR shows both the intended route and every authorized departure.

MRB opens the 6th case / the prior 5 are right there
Spec / Endotoxin NMT 0.25 EU/mL / Supplier A
6 exceedances in 18 months
NCR
When
Result
Decision
NCR-2023-114
18 mo ago
0.28 EU/mL
Use as is
NCR-2023-267
15 mo ago
0.31 EU/mL
Use as is
NCR-2024-042
12 mo ago
0.29 EU/mL
Use as is
NCR-2024-188
8 mo ago
0.33 EU/mL
Use as is
NCR-2024-301
4 mo ago
0.35 EU/mL
Use as is
NCR-2024-402
Current
0.35 EU/mL
Pending MRB
Normalized deviation / visible to the MRB
One use-as-is is reasonable. Six is a pattern. Same question, different answer.
Fig. 5 / Nonconformance, concession, and disposition remain connected
11

Software and firmware are manufactured configuration

For connected or software-containing devices, the installed software, firmware, configuration, cryptographic identity, installation tool, and verification result belong in the as-built record. A generic note that software was loaded is not sufficient genealogy.

Seal can verify the approved version and capture the device-reported identity. A patch or configuration change can trace from design approval through production effectivity and into the installed base requiring assessment or field action.

12

Sterilization and outsourced steps keep the device boundary

Sterilization loads, external processing, special processes, and contract operations may occur outside the assembly line. Their evidence must still resolve to the exact device population.

Shipment to the provider, custody, load composition, cycle or process identity, certificates, deviations, receipt, and acceptance attach to the eDHR. Pending external evidence remains pending; a document upload alone does not silently release units.

13

Release is review of an already complete record

Review by exception highlights missing steps, corrections, overrides, failed checks, open nonconformances, unreconciled materials or labels, overdue equipment, and pending external evidence. Reviewers can inspect the full underlying record.

The disposition records product and revision, device population, evidence state, open conditions, decision, accountable role, and signature meaning. Release changes the controlled state of the physical units; it does not merely complete a PDF.

After: review, not compilation1 screen
Unified batch view
Execution
Steps with timestamps
Operators identified
Materials linked
Progress tracked
Test results
Results inline
Specs auto-checked
OOS flagged
CoA builds live
Deviations
Linked to step
Full context shown
Resolution status
Impact assessed
Equipment
Calibration status
Usage logged
Quals verified
Training current
Minutes, not hours
Focus on judgment, not assembly
Fig. 6 / Device release as a live evidence decision
14

Complaints and field actions close the genealogy loop

The released serial or lot connects complaints, service, returns, adverse events, corrections, removals, and recalls to the original build evidence. A reported failure can expose configuration, components, suppliers, equipment, inspection history, and similar units.

Conversely, a component, process, or software finding can trace forward to the installed population. Post-market evidence can initiate CAPA or change without modifying the historical eDHR.

Post-market surveillance / detect proactively, not at audit
Complaints
47 / past 30d
Vigilance reports
2 / serious
Literature
3 relevant hits
Registry data
1,284 implants
PMCF studies
2 active / 146 subjects
Funnel from sources to signal
Signal / Alarm-related complaints / 2.1× baseline
Lot Y+141 through Y+144 / CE-marked EU + UK
Risk file
Occurrence rate auto-updated
FSCA draft
Pre-populated with affected lots
CAPA
Opened / owner assigned
Fig. 7 / Post-market signal back to the manufactured population
15

System boundaries preserve the authoritative source

PLM may own design structures, drawings, and engineering changes. ERP may own demand and financial inventory. Seal can own the effective manufacturing configuration, controlled execution, actual genealogy, inspections, exceptions, and disposition. Testers and machines can own acquisition; labeling and serialization platforms can own specialist identities and events; service systems can own field work.

Each interface needs more than a field map. It defines object identity, authoritative state, expected chronology, acknowledgement, correction, duplicate handling, outage behavior, reconciliation, and record retention. A firmware value reported by a tester must resolve to the same device and approved software definition used by the route. A component issue in ERP must not release a unit whose Seal genealogy remains incomplete.

This boundary design is part of validation because it determines which system a reviewer trusts when values disagree or messages arrive late.

16

Prove one serial from component receipt to release

The first implementation should execute one representative device through component receipt, serial assignment, assembly, automated and manual inspection, a failed check, approved rework, UDI labeling, external processing, review, and release.

Then perform a backward trace from the released serial and a forward trace from a component lot. Rehearse an equipment calibration failure, incorrect firmware, label reprint, missing supplier evidence, and field complaint. The system is ready when each scenario identifies the exact population and reconstructs the decision without manual compilation.

Capabilities

Approved configurations become guided routes, component rules, inspections, labels, signatures, and controlled branches.
Actual components, subassemblies, processes, software, labels, and evidence remain traceable to every device.
Characteristics, methods, instruments, results, limits, failures, retests, and review stay attached to the operation.
Approved content, serial data, printers, application, verification, aggregation, reprints, and reconciliation share one source.
Calibration, maintenance, qualification, setup, software, and use history gate the selected production asset.
Containment starts with the affected population and approved rework adds evidence without rewriting history.
Only people current for the effective instruction, operation, and practical qualification may execute or sign.
Sterilization and outsourced operations retain population, custody, cycle, certificate, exception, and acceptance state.
09BRnative controlReview by Exception
QA sees missing evidence, corrections, failures, open events, unreconciled labels, and pending external work before release.
Complaints, service, returns, field actions, and recalls resolve to the original device configuration and build record.

Entities

Entity
Description
Kind
C
Device Configuration
Approved model and revision with materials, routing, inspections, software, labels, and release rules.
type
C
Infusion Pump Model P4
Reusable approved device structure for the P4 product family.
template
C
P4 / Revision G
Effective configuration built by the representative order.
instance
C
Manufacturing Order
Planned physical population, configuration, quantity, site, dates, and execution status.
type
C
Serialized Device Build
Reusable order structure for serialized assembly and release.
template
C
MO-2026-0814
Live order for 240 Revision G devices.
instance
B
Device Unit
Serialized or lot-controlled physical device carrying its complete as-built state.
type
B
P4 Finished Unit
Serial-level genealogy and evidence pattern.
template
B
P4-26-001842
Released physical device with complete eDHR.
instance
B
Component Lot or Serial
Actual input with part, revision, supplier, status, quantity, and use genealogy.
type
B
Controller Board
Approved serialized electronics component pattern.
template
B
PCB-77 / SN 44871
Actual board installed in P4-26-001842.
instance
FR
Build Operation
Executed assembly, processing, inspection, or packaging activity.
type
FR
Final Assembly Route
Approved build, test, label, and packaging sequence.
template
FR
Operation 310 / Final Test
Executed final test with source data and result.
instance
C
Tool or Equipment
Qualified asset with calibration, maintenance, setup, and use state.
type
LT
Inspection Result
Characteristic, method, instrument, value, acceptance, and review evidence.
type
LT
Flow Accuracy Test
Controlled method, limits, equipment class, and sampling rules.
template
LT
FAT-P4-001842
Accepted device-level flow accuracy result.
instance
C
Installed Software
Firmware, software, configuration, installation source, and verification identity.
type

FAQ

eDHR software creates the as-built record for a medical device lot or serial population while manufacturing occurs. It connects the effective device definition, order, components, operations, equipment, people, inspections, software, labels, nonconformances, external processing, and release.
They share guided execution and data-integrity principles. An eDHR typically emphasizes device configuration, serial and component genealogy, DMR effectivity, in-process inspection, UDI, installed software, rework, and post-market traceability. A pharmaceutical EBR more often centers on formulas, unit operations, process parameters, samples, yields, and batch disposition.
FDA's QMSR became effective February 2, 2026 and incorporates ISO 13485:2016 by reference. Manufacturers should evaluate their terminology, procedures, and records against the current requirements. Seal supports controlled production and acceptance evidence; regulatory interpretation remains the manufacturer's responsibility.
Yes. Evidence can apply at order, lot, sublot, assembly, or individual serial level. The model avoids copying shared evidence while preserving unit-specific components, values, failures, labels, software, and disposition.
The active configuration defines eligible parts and alternates by effectivity. A scan verifies the actual component. An unapproved substitution is blocked; an approved deviation or change retains its scope, rationale, authorization, and affected devices.
Yes. The machine can remain authoritative for acquisition while Seal receives the device, operation, method or program, value, units, timestamp, result, source reference, and status. Interface acknowledgement and recovery prevent silent gaps or duplicates.
A nonconformance identifies and contains the affected population. The approved disposition creates controlled rework operations and required re-inspection. Original failures remain visible; rework does not overwrite the first execution.
Yes. Seal can generate controlled label output from approved product, market, manufacturing, expiry, and UDI data, verify application to the physical unit, retain printer and template versions, and reconcile reprints, scrap, and aggregation events.
The device population links to shipment, load, cycle or process, provider, custody, certificates, deviations, receipt, and acceptance. Release requirements remain pending until the configured evidence is complete and reviewed.
Not necessarily. ERP can own demand and financial inventory; PLM can own design structures and engineering change. Seal can own controlled manufacturing execution, actual genealogy, inspection, quality events, and release. Interfaces preserve one authority per object and state.
The reviewer sees corrections, overrides, failures, missing steps, open nonconformances, unreconciled components or labels, equipment issues, and pending external evidence. The complete record remains available underneath the exception view.
Prove one representative serial from component receipt through assembly, inspection, a failed check and rework, UDI labeling, any external process, review, and release. Then trace backward from the serial and forward from a component lot.

Go live in 48 hours.