When the Pump Couldn't See the Leak: The Omnipod Cannula-Tear Class I Recalls Through an ISO 14971 and IEC 60601-2-24 Lens

An insulin pump has exactly one job: put the commanded dose inside the patient. The Omnipod's fault detection, like almost every infusion device's, is built to notice when insulin cannot get out — an occlusion raises back-pressure, back-pressure trips an alarm. A torn cannula is the mirror image of that fault: the path is more open, not less, insulin vents onto the skin, and every internal signal the Pod can see says delivery is proceeding normally. Two Class I recalls in three months, roughly 500 serious injuries between them, and the FDA telling users in plain language not to trust the alerts. That is not a bad-lot story. That is a detection architecture with a blind side, found the expensive way.


The public record

Two separate field actions, same platform, same physics.

March 12, 2026 — Insulet issued a voluntary Medical Device Correction for certain Omnipod 5 Pod lots in the U.S. after identifying that Pods from certain lots "may have a small tear in the internal tubing that delivers insulin," letting insulin leak inside the Pod instead of being infused. On April 10 Insulet expanded the affected-lot list and — this is the sentence worth re-reading — clarified "that the Pod defect may not be detectable by users." The FDA confirmed Class I classification on April 29. As of April 17, Insulet had reported 476 serious injuries and no deaths associated with the issue.

May 26, 2026 — Insulet issued a second, explicitly separate Medical Device Correction, this time covering Omnipod 5, Omnipod DASH, and Omnipod Eros Pods in the U.S. and international markets. The defect is a small tear in the cannula "just above the skin, between the Pod and the point where the cannula enters the body," letting insulin leak outside the body. The scope: approximately 7 million Pods, about 60% of which were already consumed or expired — roughly 8.5% of 2025 global Omnipod production. Globally, 24 reports of serious adverse events involving hospitalization and diabetic ketoacidosis (DKA), no deaths. The FDA issued an Early Alert on June 4 and classified the action as Class I on July 2, 2026.

The FDA's recall communication is unusually direct about the detection problem. If the leak occurs while an Omnipod 5 is running in Automated Mode, rising glucose could trigger an Automated Delivery Restriction alert advising the user to troubleshoot. But: "this issue may happen without triggering any alert, meaning you could receive less insulin than needed without realizing it. Do not rely only on Pod alerts to know if something is wrong." The user-observable cues the FDA offers instead are wetness on the skin or adhesive, and the smell of insulin — a fault annunciation channel with no requirement, no verification, and no guaranteed availability while the patient is asleep.

Insulet's press release contains the other sentence worth re-reading. The company "has further strengthened its in-process monitoring and quality controls designed to detect cannula tears of this nature." A control added in 2026, on a fluid path the platform has been mass-producing for over a decade, is a control that was not there — or not capable — when 7 million of these Pods shipped.

One more fact, because it matters for the requirements section later: Insulet is "sending targeted communications to users who activate a Pod from an impacted lot." The system, in other words, knows the lot number of every Pod at activation time. Hold that thought.

The standards lens

The right frame here is medical-device, not automotive, so let's use the right instruments.

ISO 14971 — the risk analysis that must interrogate its own detectability claims. A compliant risk file for this device unquestionably contains a hazardous situation called under-delivery of insulin with DKA as the harm; that row is table stakes for any infusion device. The question ISO 14971 §5.5 and §7 force is subtler: for each sequence of events leading to under-delivery, what is the probability that the situation persists undetected long enough to cause harm? Occlusion, air-in-line, empty reservoir, dislodged Pod — each has a detection mechanism or a user-observable state. A partial-flow leak through a tear in the cannula wall has neither, and — the March recall's language confirms this — the fluid-leak hazard alarm fires only "in some cases." When your P2 (probability that a hazardous situation leads to harm) silently depends on a patient smelling insulin, that assumption belongs in the risk file as an explicit, verifiable claim. Nothing in the public record suggests it was ever treated as one.

IEC 60601-2-24 — the particular standard whose alarm philosophy is one-sided by construction. The particular requirements for infusion pumps and controllers mandate protection against over-infusion, occlusion alarms with specified detection thresholds, and delivery-accuracy disclosure (the trumpet curve). What the standard family does not mandate — and what this recall exposes — is detection of an open-path fault downstream of the pumping mechanism. A positive-displacement micro-pump meters what leaves the reservoir; it has no intrinsic knowledge of what fraction arrives subcutaneously. The occlusion sensor watches for pressure rise; a vented path lowers pressure. Every safety mechanism the device carries is oriented toward the blocked failure mode, so the leaking failure mode traverses the architecture without touching a single monitor. Meeting the particular standard is necessary; it was never sufficient for this fault.

IEC 60601-1-10 — the closed loop that feeds its own leak. Omnipod 5 in Automated Mode is a physiologic closed-loop controller: CGM glucose in, insulin micro-boluses out. The collateral standard requires the manufacturer to analyze how the PCLC behaves under sensor faults, actuator faults, and — precisely this case — effector-path faults where the commanded output does not produce the expected physiological response. The failure behavior here is worth spelling out: glucose rises, the controller commands more insulin, the additional insulin vents through the same tear, glucose keeps rising. The loop's own corrective action masks the fault signature (the controller is "doing something") while amplifying wasted delivery. The Automated Delivery Restriction alert exists exactly because a divergence between commanded insulin and glucose response is detectable in principle — but per the FDA, it is not guaranteed to fire. A divergence detector that annunciates sometimes is a screen, not a safety mechanism, and no risk-file row should be crediting it with risk reduction unless its trigger conditions are deterministic and verified.

21 CFR 820.75 / ISO 13485 §7.5.6 — the process-validation gap. A cannula tear induced during manufacture (the insertion-mechanism assembly, cannula forming, or Pod final assembly) on two different fault locations across two recalls, at a scale of 8.5% of annual production, is a process-control escape, not a random defect. Where the results of a process cannot be fully verified by subsequent inspection — and a micro-tear in tubing sealed inside a disposable Pod is the textbook case — the process must be validated and monitored. Insulet's own corrective action, strengthened in-process monitoring "designed to detect cannula tears of this nature," is a description of the missing control written in the past tense.

IEC 62304 — the software that knew the lot number and asked politely. The Pod ecosystem reads and reports the lot of every Pod at activation; Insulet used that channel to send targeted communications to users who activated a recalled Pod. The same channel, with a Class C-appropriate design control behind it, could refuse to activate a recalled lot outright. A recall whose execution depends on patients cross-checking tray-lid lot numbers against a PDF, on a platform that already performs an automated lot check at activation, is leaving its most reliable risk control on the table.

A worked snippet — fluid-path FMEA

Severity, occurrence, and detection on 1–10 scales, Action Priority per the AIAG-VDA logic (High/Medium/Low). The point of the table is column D.

| ID | Fluid-path element | Failure mode | Local effect | End effect | Detection mechanism | S | O | D | AP | |---|---|---|---|---|---|---|---|---|---| | FM-01 | Cannula, subcutaneous segment | Occlusion (kink, site) | Back-pressure rises | Delivery stops, annunciated | Occlusion sensor + alarm (60601-2-24) | 8 | 4 | 3 | M | | FM-02 | Reservoir | Depleted / not filled | No fluid to meter | Delivery stops, annunciated | Volume tracking + alarm | 8 | 3 | 2 | L | | FM-03 | Internal tubing (inside Pod) | Tear; leak into Pod housing | Partial flow diverted internally | Silent under-delivery; DKA | Fluid-leak hazard alarm — fires only in some cases (March recall) | 9 | 5 | 8 | H | | FM-04 | Cannula, above-skin segment | Tear; leak outside body | Path vented at near-zero back-pressure | Silent under-delivery; DKA | None on-device. User cue: wetness / smell of insulin | 9 | 5 | 9 | H | | FM-05 | Pod adhesion / cannula seating | Dislodgement | Gross leak, Pod visibly loose | Under-delivery, usually noticed | User observation; site check | 8 | 4 | 5 | M |

Rows FM-01 and FM-02 are the faults the architecture was designed around: high-detectability, alarm-backed, closed. Rows FM-03 and FM-04 are the two recalls. Same severity, comparable occurrence once the process escape existed — and a detection score that collapses because every engineered monitor lives on the wrong side of the failure mode.

A worked snippet — fault tree

Top event: Prolonged hyperglycemia progressing to DKA
           (24 + 476 serious injuries across the two 2026 recalls)

    AND
    ├── G1. Sustained insulin under-delivery
    │       OR
    │       ├── E1. Cannula tear above skin — insulin vents externally
    │       │       (May 26 MDC; ~7M Pods; process escape at manufacture)
    │       └── E2. Internal tubing tear — insulin leaks inside Pod
    │               (March 12 MDC; 476 serious injuries reported)
    │
    └── G2. Under-delivery not annunciated within corrective-action window
            AND
            ├── E3. Occlusion monitor blind to open-path faults
            │       (senses pressure rise; tear lowers pressure)
            ├── E4. No delivered-volume vs. commanded-volume reconciliation
            │       (pump meters displacement, not subcutaneous arrival)
            ├── E5. Automated Delivery Restriction alert non-deterministic
            │       ("may happen without triggering any alert" — FDA)
            └── E6. User-cue channel unavailable or ineffective
                    (asleep; odor/wetness not noticed; DASH and Eros
                     users outside the closed loop entirely)

Note the structure: G2 is a four-way AND of independent detection failures — and E3 through E5 are not failures at all. They are design states. The tree's minimal cut set requires only one manufacturing escape (E1 or E2) because the entire right-hand branch is satisfied by the architecture as built. When a fault tree reaches its top event through gates that are true by design, the analysis is telling you the mitigation was never in the device; it was in the patient.

Derived requirements (excerpt)

Numeric bands are illustrative of the class of limit a compliant file would carry — they are not Insulet's internal values.

What the headline really tells us

Strip away the recall logistics and what remains is an asymmetry that was designed in, not manufactured in. The Pod can prove insulin left the reservoir; nothing on board can prove it arrived in the patient — and every alarm the device carries was pointed at the failure mode where the path closes, not the one where it opens. The manufacturing escape that tore the cannulas is real and Insulet has closed it, but the escape only mattered because the detection architecture turned a defect into a silent defect. The missing artifacts are ordinary ones: an ISO 14971 detectability claim treated as a verifiable requirement instead of an assumption, an FMEA detection column honest enough to score a 9, a closed-loop divergence alarm specified deterministically instead of hopefully, and an in-process integrity test promoted from corrective action to release gate. None of this is exotic. The physics was always going to find the tear; the only question was whether the risk file found it first.

Sources

Field Notes — Jherrod Thomas, The Lion of Functional Safety™. Written from the public record; no proprietary Insulet information is used or implied. Numeric requirement bands are illustrative of the class of limit, not the manufacturer's internal specifications.