Methods are published before results, so the results can be judged against a design that did not move.
Four rules
- Inputs are named. Every figure names each source, the endpoint or series used, the access date and the filters applied. A snapshot manifest records the URL, access time, checksum and row count of every pull.
- Periods are aligned before combining. The analysis window is the newest period every input shares, never the newest of each.
- A missing input withholds the figure. Nothing is imputed and nothing defaults. A table that needs an absent input is not written, and the withholding is stated.
- History is recomputed, not appended. Every run rebuilds every table from the dated snapshot, because the source systems restate.
Sources
| Input | Source | Use |
|---|---|---|
| Medical device reports, product codes NAY, QNM, SAB, SAQ, plus a brand backstop for mis-coded reports | openFDA /device/event | The core corpus |
| Classification, 510(k) clearances, recalls, enforcement | openFDA | Clearance lineage; recalls tied to hazard categories |
| Public dashboard counts | FDA Adverse Event Monitoring System | Reconciliation against openFDA after the 2026 migration |
| Docket documents and public comments, this docket and five comparison dockets | regulations.gov API v4 | Who comments on device guidance |
| Registered robotic gynecologic trials with posted results | ClinicalTrials.gov API v2 | Adverse events in trials, compared in kind |
| Medicare Part B provider and service utilization, gynecologic minimally invasive procedure codes, 2013–2024 | data.cms.gov | Volume trend (robotic is not distinguishable from laparoscopic in Part B) |
| General payments from robotic-device manufacturers | CMS Open Payments | Industry relationships in the specialty, and the authors' own records |
| Manufacturer-reported US gynecology procedure volume | SEC filings, entered by hand with the filing cited | The only usable denominator |
Cohort
A report enters the cohort if it carries one of the four product codes or matches the brand backstop, and if its narrative names a gynecologic procedure. Reports are de-duplicated on the report key and then on manufacturer, event date, device lot or serial, and a normalized narrative hash, so manufacturer follow-ups collapse to the initial event. Reports marked insufficient information are kept and flagged as a data-quality measure rather than dropped. The window runs from 2010 to the snapshot date.
Coding schema
Every hazard category is annotated with the guidance section and line numbers it maps to, so each count corresponds to a specific ask in the comment:
- emergency removal or undocking (IV.A, IV.D(2)(b), IV.R)
- emergency and safety stops (IV.D(2)(c))
- unintended motion; motion scaling or tremor; haptic or force feedback (IV.D(1)(b), IV.E)
- software prompt or fault (IV.E, IV.J)
- power or connectivity loss (IV.I)
- instrument exchange or port switching, including bedside-team factors (IV.H, IV.I)
- arm collision (IV.I)
- instrument fracture or fragment; energy arcing or thermal; visualization loss
Procedure outcome (completed robotically, converted to laparoscopy, converted to open, aborted, rescheduled, unknown), patient outcome (none, injury by type, transfusion, reoperation, death), umbrella versus covered procedure, reporter type and a team-factor flag complete each record. Rules are deterministic and published, so the coding is reproducible from the snapshot. A stratified sample of 300 reports is coded by hand, Cohen's kappa is reported, and disagreements are adjudicated by the clinical co-author. Any AI-assisted step is disclosed as a method and never replaces the hand audit.
Analysis
Descriptive counts and shares by year, product code, hazard category and outcome, with exact Clopper–Pearson confidence intervals; annual trend with the manufacturer procedure-volume offset where the years align; reporter-type comparisons; and a Fisher exact test of whether death or transfusion differs between umbrella and covered procedures. No cross-platform rate comparisons: the surveillance data carry no per-system denominator. Reporting follows the RECORD extension of STROBE, and the analysis plan is pre-registered before the data are pulled.
Limitations, stated first
Passive surveillance, voluntary for users and mandatory for manufacturers; narratives often manufacturer-authored; no denominator; duplicates and follow-ups; procedure identification from narrative text; Medicare data skew older than the robotic gynecologic population; Open Payments identifies relationships, not influence.
Code and data
The extraction and analysis package, the coding schema, the audit sample template and the derived tables are released with the preprint under an MIT license for code and CC BY 4.0 for data.
