MedDeviceRepair: Keeping Loaner Exchanges Traceable When Serial Numbers Change
A three-asset chain-of-custody crosswalk for medical device loaner exchanges: preserve serial traceability across removal, placement, and return without slot-level record overwrites.

Three Serials, One Customer Slot: The Identity Job
When a manufacturer or distributor places a loaner while a capital device is removed for repair, the service record has one identity job: keep the original unit, the loaner, and the returned original from inheriting one another's history. The customer's installed location is a custody key, not a serial production identifier. This article is a three-asset, three-timepoint chain-of-custody and service-record crosswalk. It is not a depot intake-to-release quality system, not a software-log field-service guide, not a servicing-versus-remanufacturing classifier, and not a hospital computerized maintenance management system (CMMS) unique-identification survey guide.
Keep three identities, not one customer slot. The original unit, the loaner, and the returned original each keep their own serial production identifier, unique device identifier (UDI) or other device identification, custody, configuration if observed, evidence source, record owner, and unresolved status. Under the U.S. Food and Drug Administration (FDA) Quality Management System Regulation (QMSR) in 21 CFR Part 820, servicing-record fields attach to the device actually serviced. Copying the original serial onto the loaner ticket, or the loaner serial onto the return ticket, is not a completed 21 CFR 820.35(b) record. Copying files from one serial to another is not a device-release decision and is not permission to erase the original record. Placing a functional loaner does not make that unit clinically equivalent to the removed device's patient-specific configuration.
Hospital technology management (HTM) teams often keep a facility unique identification number on the installed location so scheduled inspection can stay continuous when a chassis is swapped. That hospital-inventory job is described in MedDeviceRepair's CMMS unique-identification inventory guide under CMS Tag A-0724 / QSO-25-24 and Joint Commission EC.02.04.01: a hospital unique identification number is not the OEM serial and is not the FDA UDI, and a depot chassis replacement can change the serial while the hospital asset key stays continuous. That page is adjacent hospital-survey background. It is not a manufacturer three-serial servicing crosswalk, and it is not an authority for QMSR duties, serial reassignment, device release, or clinical equivalence.
When a field engineer swaps a console, three serial-level events occur in sequence:
Event 1 — original unit removal. The original unit (serial A, if that production identifier was actually read) leaves the installed slot. Fault symptoms, if recorded, attach to that serial. Custody moves to transit or the depot. This is not yet a completed repair record.
Event 2 — loaner placement. A different physical unit (serial B, if read) moves from the loaner pool into temporary custody at the user facility. It keeps its own prior servicing history, configuration if observed, and unresolved status. The customer's slot does not become serial B.
Event 3 — repaired-device return and loaner extraction. The original serial, if that is the unit that returns, is re-read at swap-back. The loaner serial is re-read at extraction. Return events attach to the original serial; extraction and post-loan events attach to the loaner serial. Neither event is a clinical-equivalence finding.
Logging those three events under one continuous work ticket, with a single serial field overwritten at each swap, mixes identity. Later investigators need the serial that was actually present. Do not invent mix-up rates, and do not treat a mixed ticket as a completed Medical Device Report (MDR) decision.
What 21 CFR 820.35 Records on the Device Actually Serviced
The QMSR became effective on 2 February 2026. 21 CFR 820.7(b) incorporates ISO 13485:2016(E), Medical devices—Quality management systems—Requirements for regulatory purposes, Third edition, 1 March 2016, for §§ 820.1, 820.3, 820.10, 820.35, and 820.45. ISO's catalog page states that ISO 13485:2016 remains the published current edition and was last reviewed and confirmed in 2025; confirmation is not a new edition. The eCFR Title 21 display used here is unofficial and matches the 8 September 2026 issue. 21 CFR 820.35 adds record fields on top of ISO 13485 clause 4.2.5 (Control of records). For servicing activities, it sits on clause 7.5.4 (Servicing activities) as those clause titles are named in the CFR. This article does not paste paid ISO clause text.
In adhering to ISO 13485 clause 7.5.4, 21 CFR 820.35(b) requires the manufacturer to record, at a minimum, six fields for servicing activities. Those duties apply to a distributor only when that organization performs an operation listed in 21 CFR 820.1, such as servicing or installation; placing a manufacturer-owned loaner still requires distinct serial custody records, but logistics alone does not convert every partner into a 21 CFR 820 manufacturer. The six fields are:
The name of the device serviced. The name of the finished device actually serviced at that event.
Any UDI or UPC and any other device identification. Any unique device identifier or universal product code, and any other identification actually read on that unit, including a serial production identifier if present.
The date of service. The date of that servicing activity.
The individual or individuals who serviced the device. Who performed the activity.
The service performed. What servicing was actually performed on that serial. This field is not a repair-instruction set and is not a software-restore worksheet.
Any test and inspection data. Test and inspection data generated for that activity, when they exist. Missing data are unknown, not a pass.
The controlling phrase is the device serviced. The six fields attach to the hardware that was serviced, inspected, installed, or removed at that event. Removing serial A is an identity and custody event for serial A. Unboxing and placing serial B is an identity event for serial B. If the engineer logs serial B's placement only under a work order that names serial A, the 820.35(b) identification fields do not name the device actually serviced. A loaner that presents a different serial number is a new identity event, not a continuation of the removed device's history under the customer's installed slot.
Under 21 CFR 820.35(c), in addition to ISO 13485 clauses 7.5.1 (Control of production and service provision), 7.5.8 (Identification), and 7.5.9 (Traceability), the UDI must be recorded for each medical device or batch of medical devices. 21 CFR 820.10(b)(1) maps clause 7.5.8 Identification to a documented system that assigns unique device identification in accordance with 21 CFR part 830. 21 CFR 820.10(b)(2) maps clause 7.5.9.1 Traceability—General to documented procedures in accordance with 21 CFR part 821, if applicable. Those identification and traceability clauses attach history to product identity, not to a shipping manifest or customer account. Part 821 device-tracking procedures apply only when that part is applicable; do not treat every loaner as a tracked device under part 821.
Serial Is a Production Identifier, Not a Slot Key
Under 21 CFR 801.3, a unique device identifier is an identifier that adequately identifies a device through its distribution and use by meeting 21 CFR 830.20. A UDI is composed of two portions:
Device identifier (DI). A mandatory, fixed portion that identifies the specific version or model of a device and the labeler of that device.
Production identifier (PI). A conditional, variable portion that identifies one or more listed elements when included on the label: the lot or batch; the serial number of a specific device; the expiration date; the date a specific device was manufactured; or, for an HCT/P regulated as a device, the distinct identification code.
FDA's UDI Basics page restates the same DI/PI split and states that the Global Unique Device Identification Database (GUDID) contains only the device identifier, which serves as the key to obtain device information in the database, and does not include the production identifier. Unit-level serial history therefore lives in the manufacturer's own records, not in GUDID. A serial number is a unit-level production identifier, not the model-level device identifier and not a customer-slot or hospital-asset key.
Two units of the same model may share a device identifier and still have different serial production identifiers. In a labeled hypothetical, EXAMPLE-SN-101 and EXAMPLE-SN-202 can share one DI and must not inherit one another's service history. If a hospital CMMS keeps an internal unique identification number on the room, that facility key may stay continuous, as MedDeviceRepair's hospital equipment inventory identification overview describes for survey inventory. For the manufacturer, those two serials remain distinct. The facility room, the customer billing account, and the work-order header are custody coordinates, not substitutes for the serial production identifier.
Direct Marking Identifies the Physical Device; a Ticket Cannot Reassign It
Under 21 CFR 801.45(a), a device that must bear a UDI on its label must also bear a permanent marking providing the UDI on the device itself if the device is intended to be used more than once and intended to be reprocessed before each use. Direct marking applies only where that condition is met. Do not treat every capital loaner as a reprocessed reusable that must be directly marked. Record whether a direct mark was read, missing, or excepted.
Under 21 CFR 801.45(b), the direct-marked UDI may be identical to the labeled UDI or a different UDI used to distinguish the unpackaged device from any device package containing the device. 21 CFR 801.45(d) excepts a device if any type of direct marking would interfere with safety or effectiveness; if the device cannot be directly marked because it is not technologically feasible; if the device is a single-use device subjected to additional processing and manufacturing for an additional single use; or if the device has already been marked under 801.45(a). 21 CFR 801.45(e), as amended 4 December 2025 (90 FR 55979), requires a labeler that uses an exception to document the basis in the design and development files required by 21 CFR 820.10(c). That file location is not serial-reassignment permission.
Where direct marking applies, it identifies the physical device. A service ticket that overwrites the loaner's serial with the removed device's serial is not that marking, and 801.45 does not authorize reassigning serials. If a technician enters the original serial when commissioning the loaner, the database contradicts the physical identifier that was actually read—or records an identifier that was not read at all.
On the identity worksheet, record what was actually observed at each timepoint:
Physical read. Was the barcode, Data Matrix, or human-readable serial read from the rating plate or direct mark at removal, placement, and return? If not, record unknown—do not copy a dispatch note.
Missing or excepted mark. If a plate is illegible or a direct-mark exception is claimed, record that condition as unresolved. Do not invent a substitute serial.
No ticket overwrite. Swapping units is a new identity event for the serial actually present. Editing the serial field on an existing ticket so that one serial inherits the other's history is not a completed 820.35(b) record.
Mixed Serials Contaminate Later MDR Identity
Later manufacturer individual adverse-event reports still need device identity when that information is known or reasonably known. Mixing serials on the loaner ticket does not decide reportability, and this section does not recast the published complaint-handling encyclopedia.
Under 21 CFR 803.50(a), a manufacturer must report the information required by 21 CFR 803.52 no later than 30 calendar days after the day the manufacturer receives or otherwise becomes aware of information, from any source, that reasonably suggests a marketed device may have caused or contributed to a death or serious injury, or has malfunctioned and that device or a similar device marketed by the manufacturer would be likely to cause or contribute to a death or serious injury if the malfunction were to recur. This article does not decide whether any loaner event meets that threshold.
Under 21 CFR 803.52, manufacturer individual adverse-event reports must include the listed information if known or reasonably known, as described in 21 CFR 803.50(b). Those types of information correspond generally to the format of Form FDA 3500A. 21 CFR 803.52(c)(4) requires, for device information:
Model number, catalog number, serial number, lot number, or other identifying number; expiration date; and unique device identifier (UDI) that appears on the device label or on the device package.
Under 21 CFR 803.50(b), FDA considers reasonably known to include information obtainable by contacting a user facility, importer, or other initial reporter; information in the manufacturer's possession; and information obtainable by analysis, testing, or other evaluation of the device. If an event occurs while a loaner is installed, the serial and labeled UDI that belong on a later report—if the event is reportable and those fields are known or reasonably known—are the loaner's. Writing the loaner event onto the original serial, or the return event onto the loaner serial, contaminates that identity file. The crosswalk's job is to keep those identifiers distinct. An incomplete identity file is not a completed reportability decision.
What the mixed file can do, without deciding MDR outcome:
Wrong production identifier on a later 803.52(c)(4) field. If the service database stored the slot's original serial as the device present during the loan window, a later report can name the unit that was not there.
Investigation pointed at the wrong unit. Depot review of the original serial will not explain an event that occurred on the loaner serial, and the loaner's own unresolved status remains unlinked.
Trending attached to the wrong serial. Complaint or servicing frequency then follows the overwritten key rather than the physical device. That is a record-linkage failure, not a mix-up rate.
The chain-of-custody crosswalk keeps clinical events during the loan window linked to the loaner serial when that serial was the unit present. It does not close an MDR, and it does not convert unknown identity into a pass.
QMSR Scope: Finished Human-Use Devices, Not Every Capital Asset
QMSR servicing-record duties do not automatically cover every capital asset. 21 CFR 820.1 confines the part, including servicing, as follows:
The requirements in this part govern the methods used in, and the facilities and controls used for, the design, manufacture, packaging, labeling, storage, installation, and servicing of all finished devices intended for human use.
Separately, the provisions apply to any finished device intended for human use that is manufactured in any State or Territory of the United States, the District of Columbia, or the Commonwealth of Puerto Rico, or that is imported or offered for import into the United States. FDA's QMSR page, updated 2 February 2026, restates that the regulation applies to finished-device manufacturers who intend to commercially distribute medical devices. Do not merge that explainer sentence into the 820.1 quote.
Finished devices intended for human use. Exclusive animal-use capital equipment is not automatically inside 21 CFR part 820. Dual-market platforms remain unknown until human-use versus exclusive veterinary status is determined. Record that status; do not assume QMSR servicing-record duties apply to every veterinary asset.
Components or parts. 21 CFR 820.1 states that the provisions do not apply to manufacturers of components or parts of finished devices, while encouraging those manufacturers to consider the regulation as appropriate. FDA's QMSR page also notes that certain accessories, such as blood tubing and diagnostic x-ray components, are treated as finished devices because they are accessories to finished devices. A loaner printed-circuit assembly is not automatically a finished device or automatically a component; record whether the item in custody is a finished device or accessory subject to part 820, or whether that status is unknown.
Operation-specific compliance. If a manufacturer engages in only some operations subject to the part, that manufacturer need only comply with the requirements applicable to the operations in which it is engaged. A third-party courier that only transports a boxed loaner is not converted into a 21 CFR 820 manufacturer by that logistics step. If an authorized distributor's personnel perform installation or servicing, those operations must meet the applicable requirements, including 820.35 when servicing records are required.
FDA's QMSR page cites 21 CFR 820.3 for the finished-device definition: any device or accessory to any device that is suitable for use or capable of functioning, whether or not it is packaged, labeled, or sterilized. When the loaner is a finished human-use device subject to part 820, servicing-record duties attach to that serial. Capability of functioning does not make the loaner clinically equivalent, and it is not a release-to-service stamp.
Three-Asset Chain-of-Custody Crosswalk and a Labeled Fictional Swap
The original asset below is an identity worksheet, not a legally mandated form, not a depot-release QMS, and not a completed device-release decision. Fill each cell with what was actually observed. Mark unread or ungenerated fields as unknown—not as pass, equivalent, or released. Copying a record from one serial to another does not close a QMSR file.
Required columns: (1) timepoint and physical asset; (2) identity fields actually read; (3) custody, evidence source, and record owner; (4) unresolved status and record-linkage rule—which serial's service history this event may attach to, and what remains unknown.
| Timepoint and physical asset | Identity fields actually read | Custody, evidence source, and record owner | Unresolved status and record-linkage rule |
|---|---|---|---|
| Timepoint 1: original unit at removal | Model; serial production identifier; UDI or UPC if present; configuration if observed; direct-mark status if observed. Unread fields: unknown. | Custody: user facility to transit or courier, or unknown. Evidence: ticket, label scan, nameplate photo, or unknown. Record owner: the organization that owns this servicing record. | Unresolved: fault narrative attaches only if this serial was read. Linkage: this event may attach only to the original serial. Not a release decision. Do not copy this history onto the loaner. |
| Timepoint 2: loaner at placement | Loaner model; loaner serial production identifier; loaner UDI or UPC if present; configuration if observed. Unread fields: unknown. | Custody: loaner pool to user facility, or unknown. Evidence: placement ticket, label scan, or unknown. Record owner: the organization that owns this servicing record. | Unresolved: whether any test or inspection data were generated for this serial at this event is unknown unless the QMS generated them. Linkage: this event may attach only to the loaner serial. The customer slot is a custody key, not a serial. Not clinical equivalence. |
| Timepoint 3: original unit in depot custody | Original serial re-read at intake, or unknown. Configuration or replaced-part identity only if observed on this serial. | Custody: transit to depot, or unknown. Evidence: intake traveler, or unknown. Record owner: depot record owner for this serial. | Unresolved: any 820.35(b)(6) test and inspection data remain unknown until generated for this serial. Linkage: depot servicing attaches to the original serial. This row is identity and custody, not a depot-release QMS. Copying files is not permission to erase the original record. |
| Timepoint 4: loaner at extraction | Loaner serial re-read, or unknown. Configuration or operating-hour fields only if actually read. | Custody: user facility to transit or quarantine, or unknown. Evidence: extraction ticket, return receipt, or unknown. Record owner: the organization that owns this servicing record. | Unresolved: post-loan inspection data unknown unless generated for this serial. Linkage: extraction and post-loan events attach to the loaner serial. Do not write them onto the original serial. Not a fleet-release decision. |
| Timepoint 5: returned original at swap-back | Original serial and labeled UDI or direct mark re-read, or unknown. | Custody: transit to user facility, or unknown. Evidence: delivery receipt or on-site sheet, or unknown. Record owner: the organization that owns this servicing record. | Unresolved: on-site checks unknown unless generated for this serial. Linkage: return events attach to the original serial. Not a clinical-equivalence finding and not a completed device-release stamp. |
The diagram restates the same split: the installed location is a custody key; each serial keeps its own track. It is not a release workflow and does not classify servicing versus remanufacturing.
flowchart TD
subgraph Slot["Customer installed location (custody key, not a serial)"]
Loc["Installed slot"]
end
subgraph TrackA["Original serial"]
A1["Removal: record Serial A if read"] --> A2["Transit and depot custody"]
A2 --> A3["Return: re-read Serial A"]
end
subgraph TrackB["Loaner serial"]
B1["Placement: record Serial B if read"] --> B2["Temporary custody at the slot"]
B2 --> B3["Extraction: re-read Serial B"]
end
Loc -.-> A1
A1 -.-> B1
B1 -.-> Loc
A3 -.-> Loc
Loc -.-> B3
classDef primary fill:#f8feff,stroke:#2e282d,stroke-width:2px;
classDef secondary fill:#ffffff,stroke:#706b6e,stroke-width:1px;
class A1,A2,A3,B1,B2,B3 primary;
class Loc secondary;Hypothetical Worked Example: EXAMPLE-MODEL-400 Loaner Swap
EXAMPLE-FACILITY-NORTH reports an intermittent display fault on an EXAMPLE-MODEL-400 console in Procedure Room 3 on 10 September 2026. The hospital unique identification number HTM-EXAMPLE-04112 is recorded only as a customer custody coordinate.
Step 1 — removal (10 September 2026).
EXAMPLE-FSE-A reads the rating plate. Identity read: EXAMPLE-MODEL-400; serial
EXAMPLE-SN-ORIG-4188; labeled UDI(01)00000000000000(21)EXAMPLE-SN-ORIG-4188as a fictional production-identifier string; firmware observed as EXAMPLE-FW-3.1.2; direct mark on the rear bezel present. Work orderEXAMPLE-WO-Ais opened against that serial. Customer-reported fault text is recorded as stated. Custody transfers to EXAMPLE-COURIER under airbill EXAMPLE-992184. Test and inspection data for this removal event: not generated.Step 2 — loaner placement (10 September 2026).
The same engineer reads a different plate. Identity read: EXAMPLE-MODEL-400; serial
EXAMPLE-SN-LOAN-0821; labeled UDI(01)00000000000000(21)EXAMPLE-SN-LOAN-0821; firmware observed as EXAMPLE-FW-3.1.4. EXAMPLE-WO-A is not edited to name this serial. Child ticketEXAMPLE-LT-Bis opened against EXAMPLE-SN-LOAN-0821 and linked to EXAMPLE-WO-A by reference only. Placement activity is recorded as loaner placement. Pre-use test and inspection data: unknown / not generated on this worksheet. Hospital unique ID HTM-EXAMPLE-04112 remains a slot coordinate, not the serial.Step 3 — depot custody of the original (13–16 September 2026).
EXAMPLE-DEPOT-B re-reads
EXAMPLE-SN-ORIG-4188at intake against the RMA paperwork. Servicing of the original serial continues under EXAMPLE-WO-A. What was replaced, and any test and inspection data generated under 820.35(b)(6), belong on that serial's depot record if they exist. Those results are unknown on this identity worksheet and are not invented here. This step is custody and identity confirmation, not a depot-release QMS and not a numeric acceptance panel.Step 4 — loaner extraction (19 September 2026).
EXAMPLE-FSE-A re-reads
EXAMPLE-SN-LOAN-0821under EXAMPLE-LT-B. Operating hours, stored error codes, and post-loan inspection data: unknown. Custody returns toward the loaner pool. EXAMPLE-LT-B records loan complete / returned to quarantine as a custody status, not as fleet release.Step 5 — original unit return (19 September 2026).
EXAMPLE-FSE-A re-reads
EXAMPLE-SN-ORIG-4188and the labeled UDI, and places that unit in Procedure Room 3. On-site checks: unknown / not generated on this worksheet. EXAMPLE-WO-A remains attached to the original serial. No loaner history is copied onto it. This close-out is not a completed device-release stamp and does not claim clinical equivalence to the loaner that occupied the slot.
In this fictional sequence, EXAMPLE-SN-LOAN-0821 never becomes the device named on EXAMPLE-WO-A, and EXAMPLE-SN-ORIG-4188 never becomes the device named on EXAMPLE-LT-B. If an adverse event were later evaluated for Day 5 of the loan window, the serial that was present would be EXAMPLE-SN-LOAN-0821—if that identity had been read and retained. This example does not decide reportability, does not assign a mix-up rate, and does not authorize serial reassignment.
What the identity file still has to show
Before treating a loaner exchange file as complete, the record owner can ask the following. None of these questions is a software-procurement specification, a universal test panel, or a compliance guarantee.
Separate serial records. Does each timepoint name the serial actually read, instead of overwriting one slot-level ticket?
Physical identifier. Was the plate or direct mark read at removal, placement, and return, or is that field still unknown?
820.35(b) fields on the device serviced. For each servicing activity, are device name, UDI or other identification, date, individuals, service performed, and any generated test and inspection data attached to that serial?
Unknown rather than pass. Are ungenerated test data recorded as not generated or unknown, rather than as an assumed pass?
Later MDR identity. If a later 803.52(c)(4) field is still needed, can the file still distinguish the loaner serial from the original serial, or has a slot overwrite mixed them?
QMSR scope. Is this a finished human-use device subject to part 820, or is human-use versus veterinary versus component status still unknown?
Copying history from the original serial onto the loaner, or from the loaner onto the return, is not a release decision and is not permission to erase the original record. A loaner is not clinically equivalent by virtue of occupying the same slot. Adjacent jobs remain elsewhere: depot-repair QMS for intake-to-release process control; software-enabled field-service traceability for audit-trail logs; servicing versus remanufacturing for activity classification; right-to-repair servicing-evidence policy; ultrasound depot quality-agreement deliverables, which may mention a compatible loaner only as a contract clause; UDI system labeling; QMSR gap analysis against ISO 13485; and complaint handling. Those pages answer different questions. This page answers which serial's service history a loaner event may attach to.