Earlier quoted context omitted.
These two explanations seem entirely compatible to me. For better or for worse, in an environment where "root cause attribution" is such a preoccupation, it's not such a stretch to think that the agents acting in it would be strongly incentivized to minimize their opportunities to be the root cause - in other words, "be blamed if something goes wrong". I don't think that needs to be interpreted as nefarious. It might…
Yes. It is the "ensuring the manufacturer can't be blamed if something goes wrong" mindset that says, "it's necessary ... if somebody did something illegal or dumb, they can be sanctioned". Another approach would be to focus on patients and ignore punishments. Which is what the hackers are doing: ignoring rewards and punishments that are driving professionals in the field.
One of the things about testing drugs and medical devices is, you really can't cover all your bases. It would be too expensive to construct a clinical trial with the statistical power necessary to reliably detect very rare side effects. I don't think anyone wants to delay releasing all new drugs to the market by 40 years so that we can be sure about what happens if you take it over a lifetime. Even post-release monitoring for these things is potentially tricky, due to the poor interoperability of EHR systems and also, in many jurisdictions, unintended consequences of health care privacy laws.
Meaning that there is no amount of due diligence that will guarantee you can't get sued. Which is fine, you can always go for proportionality instead. But then, the amount of due diligence that's necessary is driven by what costs the legal system is willing and able to impose, and, at least in the legal regime I live under (USA), they've got their own entirely other set of procedures and incentive structures that they're working with.