I recently spent time with the point-of-care team of a university hospital department in central Europe. It was a good installation by any reasonable standard. Their devices were networked, results flowed into the laboratory information system with the patient attached, and clinicians trusted what they saw on screen.
Yet the quality control records were kept on paper, and so was the audit of who had used which device. Nothing about the department was careless. But the paper told a different story from the screen. The results were connected. The evidence that those results deserved to be trusted was not. If an assessor, a coroner or a worried consultant asked who ran a particular sample, whether that person was competent on that day, and whether the control run that morning had been reviewed and accepted, the answer lived in folders that could not talk to the data.
I hear the same idea from colleagues across the sector, usually phrased as a weary joke: connectivity is the easy part, governance is the real product. This piece takes that joke seriously. My argument is that linking point-of-care devices to the laboratory or patient record is the start of governance, not the end of it, and a service that stops at the cable has solved the transcription problem while leaving most of the data integrity problem untouched.
Why connectivity was worth fighting for: the transcription evidence
The case for connecting devices is strong, and I am not arguing against it. The evidence on manual transcription is consistent across settings and decades.
The cleanest early measurement came from Padova. Carraro and Plebani checked every glucose meter result recorded by nurses on two wards over 30 consecutive days, 1,966 determinations in all. The glucose value was written down incorrectly in 3.2 percent of results, the sampling time was recorded imprecisely in 7.2 percent, and 12.1 percent of results were never reported in the patient file at all.[1] The same group had earlier shown, in a three-month audit of 51,746 analyses in their stat laboratory, that 23.1 percent of confirmed laboratory errors arose after the analyser had done its job, in the post-analytical phase where results are communicated and recorded.[2]
A decade later, Mays and Mathias studied outpatient clinics at two academic centres in the United States. Because their meters were interfaced, they could compare each manually entered glucose value with the interfaced value for the same test. Of 6,930 paired results entered by 506 staff, 260 (3.7 percent) were discrepant, and 223 (3.2 percent) were true numerical mistranscriptions once entries containing stray non-numeric characters were set aside. Thirty-seven of the discrepant entries, 0.5 percent of all results, differed by more than 20 percent and fell outside zone A of the Clarke error grid. That includes zone B, where treatment is unlikely to change, but the authors noted several events with a risk of mistreatment.[3] Their chart review found no attributable harm, but it found five cases where the clinician copied the wrong value into the clinical note, which is how a clerical slip becomes part of the clinical record.
The mechanism is mundane. The authors describe digits being inverted, dropped or duplicated, so that 153 becomes 53, 1553 or 513.[3] In mmol/L the hazard is the decimal point: 15.3 written as 1.53 or 153. These are errors of attention rather than knowledge, which is why training alone cannot remove them.
Intensive care shows what happens when the transcribed number feeds a decision directly. Sowan and colleagues examined 5,049 glucose tests in a surgical trauma unit where values were copied into a paper log and an electronic flow sheet. Error rates were 2.21 percent of documented tests in the paper log and 8.11 percent in the flow sheet; 30 unique insulin dosing errors followed, affecting 25 of 234 patients (10.7 percent).[4] At Vanderbilt, 5.3 percent of 189,499 computerised insulin protocol instances contained a manually entered glucose value that did not match the meter, and those mismatches generated 93 false alerts and suppressed 170 alerts that should have prompted a call to a physician.[5] On Melbourne wards where meters were already networked but nurses still copied values onto paper charts, 558 of 4,391 glucose values (12.7 percent) were transcribed inaccurately and 7.4 percent were not recorded; 54 percent of the inaccurate values differed by 0.4 mmol/L or more.[21]
The denominators differ, so the bars are not directly comparable: the Vanderbilt figure counts any mismatch, however small, and the Texas flow sheet rate counts only tests that were documented at all. Across these studies, roughly 2 to 13 percent of hand-copied values were wrong under differing definitions and workflows, and a further share never arrived. Your own rate may be lower or higher; only measurement will tell you. Connectivity was the right answer to the problem.
Putting numbers on a manual service
Consider a hypothetical service recording 20,000 point-of-care glucose results a year by hand, roughly 55 a day across a group of wards or clinics. Apply the Mays and Mathias rates, which come from the largest paired dataset: a numerical mistranscription rate of 223 in 6,930 (3.2 percent, 95% confidence interval 2.8 to 3.7 percent by my Wilson calculation) gives about 644 wrong values a year, plausibly anywhere from 566 to 732. A marked discrepancy rate of 37 in 6,930 (0.53 percent, interval 0.39 to 0.74 percent) gives about 107 values a year that are more than 20 percent wrong and outside Clarke zone A, the zone in which treatment decisions remain clinically accurate, with a range of 78 to 148. That is about two a week, if the study rate held. If the omission rate from the Padova audit applied as well (12.1 percent), about 2,420 results would never reach the record at all.
Some cautions. Neither source study found harm attributable to these errors. And these rates come from North American mg/dL settings. The intervals describe sampling uncertainty within one study, not the uncertainty of transferring its rate to your service. Treat the result as a reason to measure: only reconciliation against device memory would show which values were wrong.
What the connectivity standard set out to do, and what it left to us
The industry recognised the problem a quarter of a century ago. In 2000 Gerald Kost called connectivity "the millennium challenge for point-of-care testing".[8] The Connectivity Industry Consortium, formed by device makers, information system vendors and users, was launched in October 1999 with a deadline of 15 months to produce a draft standard, after which its proposals were to pass to the formal standards bodies.[9] That work became the CLSI point-of-care connectivity standard, whose second edition, POCT1-A2, was published in 2006 and incorporates the consortium's specifications. Its purpose is to let different makes of point-of-care device talk in both directions to data managers and laboratory information systems, using HL7 for the exchange with those systems.[10]
That is why a modern connected device can send a result, its patient identifier, its operator identifier, its quality control runs and its device status in a structured way. But the standard is precise about its own boundaries. CLSI's own description states that it does not directly address point-of-care application and service level functions such as device lockout and operator list management, leaving those to vendors and customers.[10] The people who wrote the protocol told us plainly that deciding who may use a device was our job. Nichols, writing in 2003, put the wider point well: data management is fundamental to quality, because analysing point-of-care data can show quality trends before they affect results.[11] Moving the data is the precondition for that analysis. It is not the analysis.
Connected is not the same as correct
Once a device is connected, a different family of errors appears, some made worse by the confidence of an electronic feed. The most important is identity. A transcribed result with the wrong patient attached is at least visibly handwritten. A transmitted result with the wrong patient attached looks exactly like a right one.
At one health system in Massachusetts, where around 2,400 operators performed glucose testing, patient identification errors averaged 61.5 a month (0.319 percent) even with wristband barcoding. When meters were changed so that the patient identifier was checked against live admission, discharge and transfer data before testing could proceed, errors fell to 3 a month (0.015 percent).[6] That twenty-fold reduction came from a governance decision, to validate identity at the bedside and block testing until it was resolved, implemented through connectivity. A Canadian quality indicator programme later found that the share of point-of-care glucose tests performed without valid positive patient identification ranged from 0 to 87 percent between sites, with sites lacking admission feeds to their meters among the worst.[12]
The second error is time. Many connected devices are not continuously connected; they upload when docked. In the Texas intensive care study, the average time from test to docking was 8 hours, the median 5.5 hours, and some results took 56 hours to reach the system.[4] A result that arrives two days later is connected, but it is not contemporaneous in any meaningful sense, and every clinical decision made in between was made on something other than the interfaced value.
The third is configuration drift. In a Madrid network accredited to ISO 22870, Oliver and colleagues tracked key performance indicators monthly for more than three years. The deviations they caught included errors in connectivity and in the operator identification strategy, alongside strips, reagents, calibration and quality control.[13] Even a mature, accredited, connected service generates integrity failures; the difference is that it looks for them every month.
A transcribed result with the wrong patient attached is at least visibly handwritten. A transmitted result with the wrong patient attached looks exactly like a right one.
Data integrity, borrowed from the regulators who wrote the vocabulary
The most useful language for what is missing does not come from laboratory medicine. It comes from the medicines regulators. The MHRA's GXP Data Integrity Guidance and Definitions (revision 1, March 2018) defines data integrity as the degree to which data are complete, consistent, accurate, trustworthy and reliable, with those characteristics maintained throughout the data life cycle.[14] It sets out the ALCOA principles: data should be attributable to the person generating them, legible and permanent, contemporaneous, original (or a certified true copy) and accurate. The "plus" adds complete, consistent, enduring and available, and the MHRA is explicit that there is no difference in expectation whichever acronym is used.[14] The WHO's 2021 guideline on data integrity, Annex 4 of Technical Report Series 1033, uses the same ALCOA+ framing.[15]
A caveat: these documents are written for the medicines world, and a POCT service is not inspected against them. But their definitions were sharpened by years of inspection failures and map onto point-of-care work with uncomfortable accuracy. Three passages stand out.
The first concerns basic equipment. The MHRA notes that where simple electronic equipment stores data only up to a certain volume before overwriting, the data should be periodically reviewed, reconciled against paper records where necessary, and extracted electronically where the equipment allows.[14] That is a description of most unconnected glucose meters, coagulometers and urine readers in use today. The memory is the original record, and it is quietly overwriting itself.
The second concerns logins. Shared or generic user access should not be used where a system supports individual access, and where the design supports individual access, that function must be used.[14] Every device with an operator ID field and a shared "ward" code fails this test, however well it is connected.
The third concerns hybrid systems, where some records are electronic and some are paper. The WHO guideline accepts paper-based or add-on controls as a temporary mitigation where a system cannot support ALCOA+ by design, but expects the suitability of those controls to be justified, and states that, within its GxP scope, replacing hybrid systems should be a priority with a documented corrective and preventive action plan.[15] That is not a universal rule for clinical POCT, and paper QC beside electronic results is not in itself noncompliant. But the department I described at the start is a hybrid system, as is almost every point-of-care service I have worked with, and the integrity risks at the paper boundary need to be assessed and controlled.
| ALCOA+ attribute | What it means at the point of care | What a connection can give you | What still needs governing |
|---|---|---|---|
| Attributable | Every result, control and correction tied to one named, authorised person | Operator ID transmitted with each result | Individual IDs only, no shared codes; operator list kept current; leavers removed |
| Legible | Readable and permanent for the retention period | Structured values in the record | Paper QC logs, sign-in sheets and maintenance records |
| Contemporaneous | Recorded when the test was done | Device time stamp | Device clocks checked; docking frequency monitored; late uploads reviewed |
| Original | The first capture, or a verified true copy | Result taken directly from the device | Device memory reconciled before it overwrites; edits traceable in an audit trail |
| Accurate | The value is right for this patient | No transcription step | Patient ID validated before testing; QC accepted before patient use |
| Complete | Nothing missing, including failed and repeated tests | All transmitted tests visible | Unmatched and orphan results worked to closure; devices that never connect |
| Consistent | Same units, same names, same sequence | Mapped test codes | Mapping reviewed after any device, software or lot change |
| Enduring and available | Kept, retrievable and inspectable | Results in the long-term record | Competency, QC review, lot and storage records held for the same period and findable |
The MHRA defines an audit trail as a secure record of creation, modification or deletion that does not obscure the original and lets you reconstruct the who, what, when and why.[14] Few point-of-care services can reconstruct the "why" for an amended result or an overridden lockout.
What the standards and UK guidance actually ask for
The accreditation position has changed. ISO 15189:2022 incorporated the point-of-care requirements previously in ISO 22870:2016, and ILAC set a three-year transition from publication.[16] UKAS told accredited services that those who had not transitioned by 6 December 2025 would lose accreditation under the old standard, and that accredited point-of-care activities would now sit under ISO 15189:2022.[17] UKAS describes the standard as covering point-of-care testing in hospitals, clinics and organisations providing ambulatory care, and frames accreditation as demonstrating governance and risk management, internal quality control and external quality assessment, secure data capture and result reporting, and initial and ongoing training and competence assessment.[18] Notice that secure data capture is one item on that list, not the whole of it.
The MHRA's guidance on the management and use of IVD point-of-care test devices, most recently updated in July 2026, is more concrete. It says records of patient results should include the date, device type, batch numbers, result, operator identity and patient identity. It asks whether internal quality control is performed at an appropriate frequency and recorded, whether a maintenance record including faults and repairs is kept for each device, and states that only staff whose training and competence has been established and recorded should be permitted to carry out POCT. It recommends integration with laboratory and hospital information systems wherever possible, and records a cautionary case: when a pregnancy test had to be recalled, hospitals struggled to identify which patients to retest because central records of test distribution had not been kept and local records did not show who was tested, when, or with which batch.[19] The failure was patient and batch traceability; an interface capturing those fields with each result could have supported the recall.
The 2023 national strategic guidance from the IBMS, the Royal College of Pathologists and the Association for Clinical Biochemistry and Laboratory Medicine goes further on content. It says the result, reference range, reagent lot number, name of the user and action taken must be entered into the patient care record; that IT connectivity should be seen as mandatory whenever the option allows, but should not prevent access to testing where it is not possible; and that training should be supported alongside restricting access to those with current competency and in-date training.[20] I looked for a newer IBMS or RCPath report specifically on the governance of point-of-care testing outside hospitals published in 2025 or 2026 and did not find one that was not industry co-authored, so I have relied on the 2023 guidance.
The evidence that never travels down the cable
Put these sources side by side and a list emerges of governance evidence that a result feed, on its own, does not create. Some of it can travel over the same connection if configured; none of it is governed because the connection exists.
Quality control acceptance and review
A transmitted control value alone does not show that a failed control was followed by correct action, or that anyone reviewed the trend. Configured devices and data managers can hold that evidence, including QC lockout,[7] but only if the service sets the rules and someone signs the review. In the central European department I described, the results flowed but the quality control evidence was kept on paper.
Operator authorisation and lockout
CLSI left lockout and operator list management to services and vendors.[10] The national guidance asks for access restricted to those with current competency.[20] That requires an authoritative list of who is competent, on which device, until when, and a mechanism that turns that list into a locked device. One trust I know of has more than 200 glucose meter users trained by a mixture of cascade training and e-learning, and no central record of who is currently competent. Its meters may well be connected. Without that record, operator lockout cannot be configured, because there is nothing true to lock against.
Competency records
Training certificates, observed practice, reassessment dates and the link between a person and an operator ID sit entirely outside the data feed and have to be maintained by people. Lockout on the device or data manager can control access, as Fung describes, but only if the competency data behind it are current.[7]
Lot, expiry and storage
Strip and cartridge lots, expiry dates and temperature logs make a recall or field safety notice actionable, and both the national guidance and the MHRA expect lot traceability.[19][20] Some devices send the lot number with the result. Very few services can show the storage history of that lot.
Corrective action and external quality assessment
Investigations, decisions and evidence that a fix worked are records in their own right, as are EQA returns, the review of each report and action on poor performance. The MHRA guidance asks that EQA results be returned to the scheme and recorded as for internal quality control.[19] These records rarely live anywhere near the result feed.
The devices that never connect
Finally, there are the devices that cannot be connected at all. A distributor working in primary care told me recently that appetite for connectivity among their customers is low, and that many of the devices they supply have no means of connecting in the first place. The national guidance is realistic about this: connectivity is mandatory where the option allows, but it must not prevent testing where it does not.[20] For those devices every ALCOA+ attribute has to be delivered by procedure, and the transcription risk in Figure 1 remains.
What a service should do on Monday
The following is a minimum evidence set I would expect any point-of-care service to be able to produce, whether or not its devices are connected. It is a framework for what governance should ask, not a substitute for the manufacturer's instructions or your own validated procedures. For connected deployments in England, the software carrying results is a health IT system: where the NHS clinical safety standards apply, the manufacturer's DCB0129 and the deploying organisation's DCB0160 clinical risk management, with a hazard log and safety case, are separate obligations that laboratory accreditation does not replace.[22]
| Evidence | Connected device | Unconnected device |
|---|---|---|
| Result in the patient record with patient ID, operator ID, time, device and lot | Check that all fields map and arrive; work unmatched results daily | Second-person or periodic reconciliation of record against device memory |
| Positive patient identification | Validate against admission data before testing where the device allows | Two identifiers checked and recorded at the time of testing |
| Operator authorisation | Individual IDs; lockout driven by the competency register | Named authorised user list at the device; access control by procedure |
| QC acceptance and review | Rules configured; reviewer and date recorded | QC log with acceptance decision, reviewer and action |
| Competency register | One central list, linked to operator IDs, with reassessment dates | The same central list; the device does not change this |
| Lot, expiry and storage | Lot from device where sent; storage temperature records kept | Lot recorded per result or per session; storage records kept |
| Timeliness | Docking or upload delay monitored and reviewed | Time of test recorded at the point of testing |
| Corrective action, EQA, audit trail | Investigations, EQA reviews and amendments recorded with who, what, when and why | Same |
From that table, a short list of first moves:
- Ask the reconstruction question. Pick five results from last month, connected and unconnected, and try to reconstruct who ran each one, whether they were competent that day, which lot was used, and whether the controls that morning were accepted and reviewed. Note where the trail goes to paper.
- Count your shared IDs. A generic or ward-level code prevents individual attribution from the device record alone. Use individual access wherever the device supports it.
- Build the competency register before the lockout. If your operator list is not true, lockout will either block competent staff or let lapsed ones through. Fix the list first.
- Measure your docking delay and your unmatched results. Review them monthly as quality indicators, with the share of tests lacking valid patient identification.
- Assess your hybrid records. Write down which records are still on paper, what could go wrong at that boundary, and how it is controlled; replace the paper step where adequate control cannot be kept.
- Reconcile unconnected device memory. Before the memory overwrites, compare it with the record. A monthly sample gives you your real transcription and omission rates.
If you would like a second pair of eyes on that reconstruction exercise, it is the kind of work our consultancy does, and our training covers the competency side in more depth.
I keep coming back to that department in central Europe, because it had done the hard technical work and still could not answer the simplest governance question without opening a folder. Connectivity removed a class of error that distorted insulin protocols and consumed thousands of hours of nursing time, and it was worth every argument it took. But it moved the problem rather than ending it. The number now arrives cleanly. Whether anyone can show who produced it, under what control, with what competence, from which lot, is a question no cable answers, and it is the question a service will be asked on its worst day.
Sources and notes
The transcription error studies differ in setting (inpatient, outpatient, intensive care), units (mg/dL in the North American studies, mmol/L in the Australian one), and denominator (all tests versus documented tests only), so their rates are shown together to indicate a range, not to rank settings. Confidence intervals in Figure 1 and the worked example are my own Wilson 95 percent calculations from the counts the authors report; they reflect sampling uncertainty within each study, not transferability to other services. The worked example uses a hypothetical volume with published rates, and none of the source studies attributed patient harm to transcription error. The MHRA and WHO data integrity documents are written for GxP (medicines) settings and are used here for their definitions, not as requirements that apply to clinical POCT services. Field observations in the opening and later sections are anonymised and unquantified. Figures 1, 2 and 4 plot or are calculated from published data; Figure 3 is a schematic.
- Carraro P, Plebani M. Post-analytical errors with portable glucose meters in the hospital setting. Clinica Chimica Acta, 2009 (1,966 results over 30 days; 3.2% incorrectly reported, 7.2% imprecise sampling time, 12.1% not reported).
- Carraro P, Plebani M. Errors in a stat laboratory: types and frequencies 10 years later. Clinical Chemistry, 2007 (51,746 analyses; 160 confirmed errors, 23.1% post-analytical).
- Mays JA, Mathias PC. Measuring the rate of manual transcription error in outpatient point-of-care testing. Journal of the American Medical Informatics Association, 2019 (260 of 6,930 discrepant, 3.7%; 223 numerical, 3.2%; 37 more than 20% discrepant, 0.5% of all events, outside Clarke zone A).
- Sowan AK, Vera A, Malshe A, Reed C. Transcription errors of blood glucose values and insulin errors in an intensive care unit. JMIR Medical Informatics, 2019 (5,049 tests; 2.21% paper log and 8.11% flow sheet errors; 25 of 234 patients with insulin errors; docking delay mean 8 h, median 5.5 h, maximum 56 h).
- Campion TR, May AK, Waitman LR, Ozdas A, Gadd CS. Effects of blood glucose transcription mismatches on a computer-based intensive insulin therapy protocol. Intensive Care Medicine, 2010 (5.3% of 189,499 instances mismatched; 93 false alerts, 170 missed alerts).
- Alreja G, Setia N, Nichols J, Pantanowitz L. Reducing patient identification errors related to glucose point-of-care testing. Journal of Pathology Informatics, 2011 (61.5 errors a month, 0.319%, falling to 3 a month, 0.015%).
- Fung AWS. Utilizing connectivity and data management systems for effective quality management and regulatory compliance in point of care testing. Practical Laboratory Medicine, 2020 (operator and QC lockout functions).
- Kost GJ. Connectivity: the millennium challenge for point-of-care testing. Archives of Pathology and Laboratory Medicine, 2000.
- Paxton A. Clutter-free POC testing nearing reality. CAP Today, March 2001 (Connectivity Industry Consortium launched 20 October 1999, 15-month timetable for a draft standard).
- Clinical and Laboratory Standards Institute. POCT01, Point-of-care connectivity, second edition (POCT1-A2), 2006 (incorporates the Consortium's work; does not directly address device lockout and operator list management).
- Nichols JH. Quality in point-of-care testing. Expert Review of Molecular Diagnostics, 2003.
- Shaw JLV, Arnoldo S, Beach L, et al. Establishing quality indicators for point of care glucose testing. Clinical Chemistry and Laboratory Medicine, 2023 (tests without valid patient identification ranged 0 to 87% between sites).
- Oliver P, Fernandez-Calle P, Mora R, et al. Real-world use of key performance indicators for point-of-care testing network accredited by ISO 22870. Practical Laboratory Medicine, 2020.
- Medicines and Healthcare products Regulatory Agency. GXP data integrity guidance and definitions, revision 1, March 2018 (ALCOA+, raw data for basic equipment, audit trail, shared logins).
- World Health Organization. Guideline on data integrity. Annex 4, WHO Technical Report Series No. 1033, 2021 (ALCOA+; hybrid systems and mitigation).
- ILAC. ISO 15189:2022 for medical labs published, 2022 (POCT requirements of ISO 22870:2016 incorporated; three-year transition).
- UKAS. Technical bulletin: ISO 15189:2022 transition process guidance, January 2023 (transition deadline 6 December 2025; POCT accredited under ISO 15189:2022).
- UKAS. From bedside to board assurance: ISO 15189 POCT training, September 2025.
- Medicines and Healthcare products Regulatory Agency. Management and use of IVD point of care test devices, updated July 2026 (record contents, IQC and EQA records, competence, pregnancy test recall case).
- Institute of Biomedical Science, Royal College of Pathologists, Association for Clinical Biochemistry and Laboratory Medicine. Point of care testing: national strategic guidance for at point of need testing, 2023 (result, lot, user and action in the care record; connectivity mandatory where possible; access restricted to current competency).
- Hazara and colleagues (Barmanray, Wang, Kyi, Fourlanos). Lost in transcription: frequency of inaccurate manually documented point-of-care blood glucose and ketone measures in hospital. Endocrinology, Diabetes and Metabolism, 2026 (4,391 glucose values; 558, 12.7%, inaccurate; 7.4% not recorded; 54% of inaccurate values differed by 0.4 mmol/L or more).
- NHS England. Digital clinical safety assurance, updated March 2025 (DCB0129 for manufacturers, DCB0160 for deploying organisations; hazard log and clinical safety case).
