Risk Management, Verification

What a Heating-Pad Fold Test Reveals About Risk, Verification, and Supplier Control

A heating pad folded in half is a smaller radiating surface carrying the same power. That is a foreseeable use condition, and the chain from foreseeable use to a production test is exactly what a design file is supposed to contain.

June 2026 7 min read Bob Jordan

A heating pad is about as simple as a regulated electrical device gets. A flexible heating element, a controller, a temperature sensor, a fabric cover, a cord. Nothing about it suggests a complicated quality system.

Now fold it in half.

The same power is being delivered into half the radiating surface, with the two heated faces now insulating each other instead of shedding heat to the room. Local temperature rises. If the controller's sensor happens to sit outside the folded region, it reads a normal temperature and keeps supplying power to a spot that is no longer normal at all.

Users fold heating pads. They fold them around a knee, tuck them under a back, and bunch them up in a chair. This is not misuse in any meaningful sense. It is how the product is used.

This is not hypothetical. FDA has published a most-serious-category recall of a powered heating pad on exactly this mechanism: folding the pad during use increased power density in the folded area, causing excessive temperatures there; the device could not detect the elevated temperature and did not automatically shut off. Four serious injuries were reported. It is worth studying as a design-control case rather than as someone else's misfortune, because the chain it exposes is the chain every design file is supposed to contain.

It is also worth noting what the device's regulatory status did not do for anyone. A powered heating pad is Class II under 21 CFR 890.5740 and exempt from premarket notification. No submission was reviewed, and no submission would have been the control that caught this. The controls that catch it are the risk analysis, the verification test, and the production check, all of which live inside the quality system, which the exemption never touched.

The chain, one link at a time

  • Foreseeable use condition The device is folded, bunched, or covered during normal use. This belongs in your risk analysis as a use condition, not as an exclusion. The test of foreseeability is not whether the manual permits it. It is whether a reasonable person would do it.
  • Hazardous situation Reduced heat dissipation raises local surface temperature above the safe contact threshold, at a location the control system may not be measuring.
  • Harm Burns, including on users with reduced sensation, a population disproportionately likely to be using a therapeutic heating device in the first place. Severity is high, which drives everything downstream.
  • Risk control The design must either prevent the condition or detect and respond to it: distributed or redundant sensing, a positive-temperature-coefficient element that self-limits, an independent thermal cutoff, or a control strategy that recognizes an abnormal thermal signature and shuts down.
  • Design input The control becomes a written requirement with numbers in it. "Maximum contact surface temperature shall not exceed X°C under folded operation as defined in test method Y," not "the device shall be safe."
  • Design output The specific implementation: sensor type, placement, cutoff rating, firmware logic, and the schematic and layout that realize them.
  • Verification A test that folds the device in the worst-case configuration, powers it at maximum setting, and measures surface temperature over time at the hottest point. With defined acceptance criteria and a report.
  • Production control A test on every unit or lot confirming the protective feature is present and functional. A thermal cutoff installed but not connected passes visual inspection perfectly.
  • Change control When the factory proposes a different thermal cutoff, a different fabric, or a firmware update, this chain is re-examined and the verification is repeated where the change could affect the result.

Nine links. A failure at any one of them produces the same outcome in the field, and each represents a different organizational failure.

Where each link actually breaks

Links 1–3: the hazard was never written down

Risk analyses on consumer-adjacent devices are frequently written by someone thinking about electrical safety and component failure: short circuits, insulation breakdown, and cord strain. Those are real. But the folding hazard is not a failure at all. Every component is working perfectly. The hazard emerges from normal use of a correctly functioning device, and that class of hazard is the one most often missing.

Link 4: the control exists but nobody knows it is a control

Often the thermal cutoff is present because the original design engineer included it, or because a safety standard required one. It works. But nobody documented that it is the mitigation for a specific hazard, so nobody knows it is safety-critical. Which means when it becomes a cost-reduction target three years later, no document objects.

Links 5–6: the requirement is qualitative

"Shall have over-temperature protection" is not a requirement, because nothing can fail it. At what temperature, measured where, under what condition, with what response time? Without numbers there is no verification, only an assertion.

Link 7: the test does not reproduce the real condition

This is the subtle one. A device tested flat on a bench, in open air, at room temperature, will pass a surface temperature limit comfortably. The same device folded, under a blanket, against a body, will not. If your verification test does not reproduce the worst-case foreseeable condition, it verifies the wrong thing and produces a report that makes everyone feel confident.

Link 8: the protection is not verified in production

The design is sound and the verification passed. Then a unit ships with a cutoff from a different supplier, or one that was mounted without thermal contact, or with a connector that was never seated. Design verification proves the design works. Only production testing proves the unit in the box works.

Link 9: the change nobody told you about

The most common and most dangerous. The factory finds an equivalent thermal cutoff at lower cost. It is genuinely equivalent on the datasheet parameters the buyer compared. Its response time under the specific thermal mass of your assembly is different. No verification was repeated, because from the factory's perspective this was a routine component substitution. From your perspective it never happened, because nobody told you.

Why this is a supplier-control problem

Links 1 through 7 are yours. You define intended use, identify hazards, set requirements, and verify the design meets them. If you outsourced the engineering, you still own the acceptance of residual risk. That decision cannot be delegated to a supplier.

Links 8 and 9 belong to the factory, and this is where outsourced programs come apart. The production test happens at the factory. The change originates at the factory. Your design file can be exemplary and your device can still fail in the field because a substitution occurred that your quality system never saw.

Which is why supplier control is not an administrative activity. Designating critical components explicitly, requiring written approval before substitution, and having a mechanism through which the factory actually notifies you is the difference between a risk control that exists in a document and one that exists in the product.

Try this on your own device

Pick your highest-severity hazard. Not the most likely. The one that hurts someone most. Then try to produce, this week, without calling the factory:

  1. The risk analysis line identifying that hazard
  2. The design feature that controls it
  3. The requirement that specifies that feature, with numbers
  4. The verification report showing it performs, under realistic conditions
  5. Confirmation the report covers the design you ship today
  6. The production test that confirms it on every unit
  7. The change history for that feature and its components

Most companies can produce items 1 and 2 quickly, struggle at 3 and 4, and cannot answer 6 and 7 without a call to the factory that takes several days. That distribution is the point. The paperwork gap and the product risk are the same gap viewed from different ends.

Closing it is why we run a diagnostic that traces the critical chains end to end rather than counting documents, and why the on-site half of the work matters as much as the file review. Links 8 and 9 cannot be verified from California.

Working through this on a real product?

We help U.S. medical device companies control outsourced development and manufacturing in Asia: evidence, design transfer, and on-site supplier readiness. A short call is usually enough to tell whether we can help.

Book a discovery call Medical device services
Bob Jordan

Bob Jordan, Founder & CEO, AsianOPS

25+ years across product design, engineering, sourcing, manufacturing and operations, including Class II and Class III medical device programs and ten years living and working in Shenzhen. Previously PRTM Management Consultants, Cardinal Glass, Guardian Industries and BASF. MBA, University of Virginia Darden School of Business.