Track & Trace Systems – Good at Recording, Not Necessarily Good at Proving?

Brian Bandey profile image
18 min read

Article Summary

While modern healthcare track-and-trace systems excel at recording instrument histories and supporting compliance, they do not necessarily provide the evidential integrity required to prove those records in legal, regulatory, or patient safety investigations.

Introduction

The previous Articles in this series examined a progressively developing problem. First, that compliance data does not automatically become admissible evidence. Secondly, that evidential integrity involves more than operational functionality. Thirdly, that mature governance systems historically embedded evidential safeguards through what was described as “Evidential Friction”. 

This Article examines whether similar evidential questions may now be emerging within modern healthcare traceability systems and associated safety architectures. 

Throughout the research for this Article, we have relied extensively upon materials published by manufacturers and suppliers of healthcare traceability systems. 

The “Puff”

Now some readers may question whether marketing literature can properly form the basis of serious analysis. And that concern is perfectly understandable. 

English Law has long recognised that commercial parties frequently engage in what lawyers sometimes describe as ”advertising puff”’ or “commercial puffery”. Puffery might include statements such as: 

  • “market leading”
  • “best in class”
  • “industry leading”
  • “world class”

These are generally regarded by the Law as expressions of opinion rather than objectively verifiable statements of fact. The Law takes the view that a reasonable purchaser would ordinarily understand such descriptions as precise factual representations capable of independent verification. 

So let us collectively bear in mind the Law therefore distinguishes between Pufferies (“Advertising Puffs”) and statements concerning identifiable functionality. This distinction is important. 

What Happens When We Discard The Puffs

In the research for this Article we have examined public collateral published by companies that author computer software products that record Decontamination Events. Historically they have been referred to as “Track & Trace Systems”. 

Discarding the Puffs our research identified statements directed to the computer software product that includes sufficient operational descriptiveness and certainty to have sufficient evidential significance to analyse. 

Let us consider statements with respect to the supplier’s proprietary Track & Trace System. For when a supplier states that a system provides: “Years of instrument history at the touch of a button” or “Complete visibility across the instrument lifecycle” or “Full traceability from decontamination through to patient use” the position changes materially. As a matter of Law it is argued that these are not merely expressions of opinion – they are descriptions of capabilities. 

They communicate to prospective purchasers that the system performs identifiable functions and delivers identifiable outcomes. 

For the purposes of this Article, the significance of such statements is not that they prove those outcomes are always achieved. Rather, they reveal what suppliers themselves regard as important and what purchasers are being invited to value. 

Indeed, one of the most striking findings arising from our review was the consistency of the themes promoted throughout the sector. Repeated references were made to: 

  • complete histories
  • full traceability
  • visibility
  • governance
  • audit support
  • patient safety
  • reporting
  • compliance assurance

One supplier’s collateral went further still, describing its system as: “Audit-Ready: Creates a digital trail for compliance and traceability.” 

The issue examined in this Article therefore does not arise because suppliers make weak claims. Quite the opposite. The issue arises because the claims are frequently powerful and persuasive. 

The question explored in the remainder of this Article is whether the capabilities described by suppliers necessarily translate into evidential reliability when records are subsequently subjected to legal or regulatory scrutiny. 

That question deserves careful examination. Because Traceability/Auditability and Evidence may not be the same thing. In fact, as a matter of settled Law – they are not the same thing. 

What the Industry Says It Is Selling ~ Absent of Puffery

One of the most striking findings arising from our research was the consistency of the language used across the sector. A healthcare organisation described its ability to obtain: “Years of instrument history at the touch of a button.” 

The significant phrases are years of instrument history and at the touch of a button. The statement conveys an expectation that historical events can be rapidly reconstructed when required. But from a Law of Evidence perspective, is reconstruction the same thing as proof?

Elsewhere, a system was described as providing: “Complete visibility across the instrument lifecycle.” The phrase “complete visibility” is notable; for it suggests comprehensive oversight and awareness of relevant activities and events. 

Another organisation referred to the ability to obtain: “A complete history of an instrument from decontamination through to patient use.” The phrase “complete history” appears repeatedly throughout the materials reviewed during this research. 

Similarly, references to “full traceability”, “patient safety”, “governance”, “audit support”, “real-time reporting” and “compliance assurance” appeared with remarkable frequency. 

One supplier of a decontamination event recording and tracing computer software stated that its solutions: 

“track the whole surgical instrument and endoscope life cycle … to ensure regulatory tracking compliance and enhanced patient safety.” 

Another explained that its approach enables staff and departmental managers: “to be fully compliant with Standard Operating Procedures and Regulations. 

These are significant claims. And more importantly, they are valuable functional capabilities. For surely the ability of the User to identify potentially affected instruments, reconstruct processing histories and investigate operational anomalies undoubtedly supports patient safety objectives. 

Nothing in this Article should be understood as criticism of those capabilities. 

The issue lies elsewhere. Because a subtle assumption often accompanies them. 

Another contemporary example can be seen in software designed to assess the current status of medical devices before use. One supplier explains that its system: “…instantly checks against expiry data and usage logs“. The same system provides a: “Clear status alert: Green for safe, red for expired – no ambiguity. 

The assumption is that traceability and proof (i.e. legal evidential proof) are synonymous.  

But they are most certainly not. 

What the Law Actually Examines

When litigation, an inquest, a regulatory investigation or a patient safety inquiry arises, Courts are rarely concerned merely with the existence of records. 

The existence of a record is often the beginning rather than the end of the enquiry. As a matter of Legal Fact the Legal System is concerned with questions which include (this is not a comprehensive list) the following: 

  • Who created the record?
  • When was it created?
  • Has it been altered?
  • Can alterations be detected?
  • Can deleted information be identified?
  • Can historical versions be reconstructed?
  • Can provenance be demonstrated?
  • Can authenticity be established?
  • Can chronology be verified?
  • Can the organisation explain how the system itself operated at the relevant time?

These are not operational questions. They are evidential questions. The issue is not: “Does a record exist?” Rather, the issue is: “Why should the Court trust it and admit it as Evidence to be Legally Tested in Court?” 

That distinction is fundamental. 

A system may successfully record an event without necessarily demonstrating the evidential characteristics required to support that record when challenged years later. 

The Evidential Gap

It is at this point that an interesting gap begins to emerge. Throughout our review of supplier published collateral we encountered extensive consideration concerning: 

  • traceability
  • visibility
  • governance
  • reporting
  • compliance
  • patient safety

What we did not discover were discussions which (to any degree) included: 

  • evidential integrity
  • provenance
  • immutability
  • forensic preservation
  • chain of custody
  • legal admissibility

The distinction is important. Traceability seeks to answer operational questions. Evidence seeks to answer forensic questions. Traceability asks: “What happened?” Evidence asks: “Can it be proved?” Traceability asks: “Where did the instrument go?” Evidence asks: “Can the reliability of that account be demonstrated at the time it was created?” These are related disciplines. They are not identical disciplines. 

Yet much of the language used throughout the sector appears to assume that the successful achievement of one automatically produces the other. Whether that assumption is justified deserves closer examination. 

The Assumption Nobody Examines

Consider a patient safety incident occurring several years after the original event:

  • The organisation retrieves the relevant records. 
  • The traceability system functions exactly as intended. 
  • The sterilisation cycle is identified. 
  •  The operator is identified. 
  • The instrument history is displayed. 
  • The timestamps appear complete. 

At this point many organisations would reasonably conclude that the problem has been solved. 

The records exist. Yet a different (legal evidentiary) enquiry may now begin. Not: “What do the records say?” 

But: 

  • How do we know the records can be trusted? 
  • Can alterations be detected? 
  • Can deletions be identified? 
  • Can historical versions be reconstructed? 
  • Can administrative interventions be demonstrated? 
  • Can the provenance of the records be established? 
  • Can the integrity of the records be independently verified? 
  • How is the Chain of Custody proved? 

Remarkably, none of these latter questions concern decontamination. None concern workflow. None concern patient safety processes. They concern evidence. And they reveal a possibility that receives surprisingly little attention. 

A healthcare organisation may invest heavily in systems which successfully improve traceability, governance, visibility and patient safety whilst simultaneously possessing limited ability to demonstrate the evidential reliability of the resulting records. 

The Uncomfortable Possibility 

This observation leads to what may be the most uncomfortable conclusion arising from this research. Let us assume every supplier statement reviewed during this study is entirely accurate. 

Similarly, let us assume the systems genuinely provide: 

  • complete histories
  • full traceability
  • complete visibility
  • real-time reporting
  • patient safety support

Even then, a significant question remains unanswered: “Can those records survive evidential scrutiny?”. Indeed: “do any of these records possess the attributes necessary to be admitted as evidence by a Court of Law? 

Do any of these records have any of the attributes necessary to be Admitted by a Court of Law as Evidence? 

The existence of information does not automatically establish authenticity. 

The existence of history does not automatically establish provenance. 

The existence of traceability does not automatically establish evidential integrity. 

The result is a curious possibility. And that is Decontamination Event Recording Software Systems (aka Track and Trace) may have become exceptionally good at recording events whilst paying considerably less attention to proving those events. 

Endnote

Our review revealed a mature and increasingly sophisticated sector. 

We encountered repeated references to patient safety, full traceability, complete histories, visibility, governance, audit support and compliance assurance. 

What we encountered far less frequently were discussions concerning the evidential characteristics which may ultimately determine whether those records can withstand admission or challenge in a Court, Tribunal, Inquest or Regulatory Investigation. 

It is suggested that omission may matter. 

It may matter because when a patient safety incident eventually occurs, the issue is no longer whether information was recorded. The issue becomes whether what was recorded can be proved. 

If that proposition is correct, an important implication follows. 

The future governance question may not be whether healthcare organisations possess more data, more traceability or more automation than ever before. The question may be whether those systems preserve the evidential characteristics necessary to support proof when proof is required. 

And that is so because once operational systems become part of the safety architecture relied upon by clinicians, patients, regulators and healthcare institutions, the question may cease to be simply what the system recorded. 

Instead the ultimate question may become whether the organisation can demonstrate the reliability, integrity and provenance of the information upon which it seeks to rely sufficient for a Court of Law to admit it for examination. 

And that is no longer merely an operational question. 

It is an evidential one. 

Disclaimer. The views and opinions expressed in this article are solely those of the author and do not necessarily reflect the official policy or position of Test Labs Limited. The content provided is for informational purposes only and is not intended to constitute legal or professional advice. Test Labs assumes no responsibility for any errors or omissions in the content of this article, nor for any actions taken in reliance thereon.

Get It Done, With Certainty.

Contact us about your testing requirements, we aim to respond the same day.

Get resources & industry updates direct to your inbox

We’ll email you 1-2 times a week at the maximum and never share your information