Vaccine Adverse Event Reporting System — passive surveillance, signal detection, and the limits of a spontaneous-report database
An adverse event following immunization (AEFI) is any untoward medical occurrence after vaccination — it does not need to be proven, or even suspected, to have been caused by the vaccine. VAERS deliberately sets a low threshold: providers are legally required to report certain listed events, while anyone — providers, manufacturers, patients, or caregivers — may voluntarily report any other clinically significant event they observe following vaccination.
Federal regulation requires healthcare providers to report specific events listed on the VAERS Reportable Events Table — for example, particular reactions occurring within a defined interval of a specific vaccine. These mandated events were chosen because they are serious, rare, or biologically plausible enough to warrant systematic tracking regardless of individual clinical judgment.
Beyond the mandated list, providers and patients are strongly encouraged to report ANY other clinically significant event, even if they are uncertain whether the vaccine played a role. This intentionally broad net is a defining feature of passive surveillance: sensitivity is prioritized over specificity at the intake stage, because the filtering for true signals happens later, statistically, across the full dataset — not by a single clinician's judgment about a single patient.
Recognizing a reportable event means noting that something happened after vaccination — a fever, a rash, a fainting spell, a more serious event like anaphylaxis or Guillain-Barré syndrome. This is a purely descriptive, chronological observation.
It is critical to understand from the outset that "after" is not "because of." Millions of health events — heart attacks, strokes, seizures, infections — occur every day regardless of vaccination status, simply because people receive vaccines while living ordinary lives with ordinary background rates of illness. Some of these events will always, by chance, follow a vaccination within hours or days. Recognizing this distinction at Stage 1 sets up the reasoning that runs through the entire VAERS pipeline: report first, investigate causality later, and only when the data supports it.
A reportable event is a signal of "when," not a determination of "why." That distinction — obvious in principle, easy to lose in practice — is the single most important concept for interpreting any VAERS-derived statistic.
A VAERS report can be filed online, by mail, or by fax, by a healthcare provider, a vaccine manufacturer, or the patient/caregiver directly. The form captures structured and free-text data: which vaccine(s) were administered, the lot number and date, the date and description of the adverse event, the time elapsed between vaccination and onset, and relevant medical history — allergies, prior reactions, concurrent medications, and pre-existing conditions.
Every report captures several categories of information:
• Patient demographics: age, sex, state of residence • Vaccination details: vaccine type(s), manufacturer, lot number, route, anatomic site, and date administered — multiple vaccines given the same day are all recorded • Event details: date of onset, description of symptoms/diagnosis in the reporter's own words, whether the event was life-threatening, resulted in hospitalization, disability, or death • Medical history: pre-existing conditions, allergies, prior adverse reactions to vaccines, concurrent illnesses or medications • Reporter information: whether the reporter is a physician, nurse, pharmacist, manufacturer, or the patient/parent themselves
This structure allows the database to later be searched and stratified — for instance, isolating all reports of a specific event following a specific vaccine within a specific age band — which is the raw material for later signal-detection analysis.
Because VAERS accepts reports "as-is" from anyone, without requiring proof, it has well-documented data quality limitations that every downstream analysis must account for:
• Underreporting: only a fraction of true adverse events are ever reported, especially mild or delayed ones • Reporting bias / stimulated reporting: media attention or new safety warnings can cause a temporary surge in reports for a given event, independent of any true change in incidence • Inconsistent detail: free-text entries vary enormously in completeness and clinical precision • No unvaccinated comparison group: VAERS alone cannot tell you how often an event would occur without vaccination • Duplicate and incomplete reports: the same event may be reported by more than one party, or missing key fields
None of these limitations make VAERS reports useless — they simply mean raw report counts must never be read as rates or risks on their own.
CDC and FDA staff regularly follow up on serious reports to request medical records, autopsy results, or laboratory data — but the initial submission itself is never independently verified before it enters the public database.
"Passive" is a precise technical term in pharmacovigilance: it means the system relies on spontaneous, voluntary submissions rather than actively searching medical records or systematically following every vaccinated person. This design choice is deliberate — passive systems are inexpensive, cover the entire vaccinated population, and can catch very rare events that a smaller active study would never observe. Their trade-off is exactly the data-quality picture from Stage 2: no denominator, no control group, no verification at intake.
This is the single most repeated caveat in every official description of VAERS, and it is worth unpacking mechanistically. A raw VAERS report tells you only that a reporter observed, or believed they observed, an event occurring within some time window after vaccination for one specific person. It does not tell you:
• How many people received the vaccine without experiencing the event (no denominator) • How often the same event occurs in a comparable unvaccinated population (no control group) • Whether the event was medically confirmed by a clinician or record review • Whether other factors (concurrent illness, medication, genetics) actually caused the event
Because VAERS lacks a denominator and a comparison group, it is structurally incapable of calculating an incidence rate or a relative risk on its own. It can only count reports. Converting a count into a meaningful signal requires combining it with outside information — total doses administered, and an independent estimate of the background rate of that event in a similar unvaccinated population — which is exactly what Stage 4 does.
VAERS is deliberately paired with active surveillance systems that address its blind spots:
• V-safe: an opt-in smartphone-based active check-in system that proactively surveys vaccinated individuals about their symptoms, providing denominator-based data • Vaccine Safety Datalink (VSD): a collaboration with large healthcare systems that uses electronic health records to conduct rapid-cycle analyses with proper denominators and comparison groups • Clinical Immunization Safety Assessment (CISA) network: specialty clinical consultation for complex individual cases
VAERS functions as an early-warning "smoke detector" — sensitive to almost any signal, cheap to run at scale, but prone to false alarms. The active systems function as the fire inspection that follows: slower, more expensive, but far more precise about what is actually happening.
No credible public health agency treats a raw VAERS report count as evidence of vaccine harm. Its entire value lies in triggering — and then being confirmed or refuted by — the more rigorous, denominator-based methods used in Stage 4.
CDC and FDA statisticians and epidemiologists continuously mine the aggregate VAERS database using disproportionality analysis — comparing how often a specific event is reported after a specific vaccine relative to how often that event is reported after all other vaccines, and relative to its known background rate in the general population. An unexpected cluster or an elevated reporting ratio becomes a "signal": a formal trigger for deeper investigation, not a conclusion.
Signal detection asks a simple statistical question: is a given adverse event reported after Vaccine X more often than we would expect by chance, compared to (a) how often it's reported after other vaccines, and (b) how often it occurs in the general, unvaccinated population?
Common quantitative tools include:
• Proportional Reporting Ratio (PRR): compares the proportion of reports for a specific event among all reports for the vaccine of interest, versus that proportion among reports for a comparison set of vaccines • Empirical Bayesian Geometric Mean (EBGM) / Multi-item Gamma Poisson Shrinker (MGPS): statistical shrinkage methods that stabilize estimates for rare events and reduce false positives from small sample noise • Observed-vs-expected analysis: reported cases are compared against the number of cases statistically expected, based on independent background incidence rates and the number of doses distributed
A reporting-rate-to-background-rate ratio meaningfully above 1 — especially if it persists as more data accumulates and appears across multiple independent data sources — is what triggers formal signal status.
A statistical signal is a starting point for investigation, never an endpoint. Typical next steps include:
1. Case review: clinicians and epidemiologists manually review the medical details of flagged reports for diagnostic accuracy and biological plausibility 2. Chart-confirmed case series: verifying diagnoses against actual medical records, not just the free-text report 3. Denominator-based epidemiological studies: using systems like the Vaccine Safety Datalink to calculate a true incidence rate and relative risk with a proper unvaccinated (or differently-vaccinated) comparison group 4. Biological plausibility assessment: does the proposed mechanism make physiological sense given what is known about the vaccine's components and immune response?
The overwhelming majority of statistical signals generated by routine VAERS surveillance are ultimately not confirmed as true vaccine-caused effects once formal epidemiology is applied — reflecting exactly the noise inherent to passive, denominator-free counting. But the small minority that ARE confirmed have historically led to major, consequential safety actions.
Historical example: elevated VAERS reports of intussusception following the original rotavirus vaccine (RotaShield) in 1999 triggered exactly this pipeline — case review, then a Vaccine Safety Datalink cohort study confirmed an increased risk, leading to the vaccine's withdrawal from the market that same year.
When formal epidemiological investigation confirms that a signal reflects a real, vaccine-associated risk, public health agencies act on it — proportionate to the severity and frequency of the confirmed risk. Responses range from updated clinical guidance and label warnings, to restricting use in specific populations, to — in rare cases — withdrawing a product altogether. The entire VAERS pipeline exists to make this final step possible: continuous, real-world vaccine safety monitoring long after clinical trials end.
Not every confirmed signal results in the same action — the response is calibrated to the magnitude and severity of the confirmed risk relative to the vaccine's benefit:
• Updated clinical guidance: clinicians are advised on how to counsel patients, screen for risk factors, or monitor after vaccination • Label / prescribing information warnings: a new warning or precaution is added to the vaccine's official product information • Restricted use: the vaccine may be recommended only for certain age groups or contraindicated in patients with specific risk factors, while remaining available for others • Pause or withdrawal: in the most serious and clearly confirmed cases, use is paused pending further review, or the product is withdrawn entirely
Historical example: reports of thrombosis with thrombocytopenia syndrome (TTS) following certain adenovirus-vector COVID-19 vaccines were investigated, confirmed as a genuine rare risk through formal review, and led directly to updated warnings and, in some jurisdictions, revised recommendations restricting their use in specific age and sex groups.
Clinical trials before licensure are necessarily limited in size and duration — they can reliably detect common side effects but are statistically underpowered to detect very rare events (occurring in, say, 1 in 100,000 or fewer). VAERS and its partner surveillance systems exist precisely to extend safety monitoring across the full, much larger population that receives a vaccine after approval, for as long as it remains in use.
This makes vaccine safety monitoring a continuous cycle rather than a one-time gate: reports flow in, statisticians watch for signals, confirmed signals trigger rigorous epidemiology, and confirmed risks feed back into updated guidance — which in turn shapes how future events are recognized and reported at Stage 1. The system does not end; it circulates for as long as a vaccine is administered.
The existence of a robust, transparent adverse-event reporting system — one willing to surface and rigorously investigate rare signals, even ones that are ultimately not confirmed — is itself a core piece of evidence for a vaccine safety infrastructure that is actively looking, not looking away.