Consider a community nurse sitting at a kitchen table on a Tuesday morning. The patient is on a hospital-at-home pathway after a short admission, the device in her bag gives a result in a few minutes, and the number on the screen is perfectly good. The analyser was in control this morning. The nurse is competent and recently assessed. The measurement is right. The question nobody in the room is asking is: whose record will this land in, and how will anyone know?
In a hospital that question is mostly answered before anyone thinks to ask it. There is a wristband with a barcode, an admission record and a request generated against an active encounter. Outside the hospital most of those anchors are gone. The device may hold a locally typed name and date of birth, or nothing at all. And the patient in front of the nurse is known to the system by several different numbers, depending on which part of the NHS last touched them.
The failure I worry about most is not a bad measurement. It is a good measurement that ends up in the wrong place. A correct result attached to the wrong person, or to nobody, is a patient-safety failure, and once point-of-care testing leaves the hospital the identifiers multiply faster than the controls that hold them together.
How often the right result reaches the wrong person
The best measured identification error in laboratory medicine is wrong blood in tube, because transfusion laboratories can catch it. A sample whose blood group disagrees with the group on file for the named patient is, almost certainly, blood from somebody else. In the international study led by Dzik for the ISBT BEST working party, 62 hospitals in ten countries contributed data on more than 690,000 samples. Outside Sweden and Finland, miscollected samples occurred at a median rate of 1 in every 1,986 samples (0.5 per 1,000; interquartile range under 0.3 to 0.9 per 1,000). Mislabelled samples, those failing local acceptance criteria, were far commoner at a median of 1 in 165 (6.1 per 1,000)[1]. The authors corrected for the errors that cannot be detected because the wrong patient happens to share the right ABO group, and the national patient identification systems in Sweden and Finland were associated with rates "too low to estimate"[1]. A single, universally used identifier is not a bureaucratic nicety. It shows up in the error rate.
The UK's own haemovigilance scheme, SHOT, gives the most current picture. In 2024 it received 899 wrong blood in tube reports, down from 986 in 2023, which was the highest in a decade[2][3]. The causes have barely moved in years. In 367 of the 899 (40.8%) the patient was not identified correctly at phlebotomy, and in 280 (31.1%) the sample was labelled away from the patient. Labels were handwritten in 733 cases (81.5%), against 108 (12.0%) printed electronically. Where both the patient's group and the intended component were known, 184 of 448 cases (41.1%) could have led to an ABO-incompatible red cell transfusion had the error not been caught, and 84.2% were caught only at laboratory testing or authorisation[2].
Notice what made those errors visible: transfusion has a built-in second check in the historical group and the confirmatory sample. Most point-of-care tests have nothing equivalent. A glucose or an INR that belongs to the person in the next chair looks like a plausible result for the person whose name is on it. Reported transfusion incidents also under-ascertain errors, and none of these figures tells us how often community point-of-care results go to the wrong person; that rate has not been measured.
Across general laboratory medicine the estimates vary with the definition. Lippi and colleagues put misidentification of general laboratory specimens at around 1%[4], while a later review by the same group gives the more commonly quoted range of 0.01 to 0.1% of specimens received, adding that 10 to 20% of those errors could translate into serious harm[5]. The College of American Pathologists Q-Probes study of 120 laboratories found 55 identification errors per million billable tests in results that had already been released, with 85% of errors caught before release and one adverse event for every 18 identification errors[6]. The spread is not a contradiction. It is the difference between errors at the point of collection, errors that survive to the laboratory, and errors that survive into the record.
The most directly relevant number for anyone running point-of-care testing comes from a health system where around 2,400 operators performed over 300,000 glucose tests a year. When patient identity was checked only after meters were docked and data uploaded, identification errors averaged 61.5 a month, 0.319% of tests. When the meters were given the registration feed so that identity was checked before testing, and testing was blocked until any mismatch was resolved, the rate fell to 3 a month, 0.015%[9]. That before and after comparison, which also introduced new meters, was associated with roughly twentyfold fewer detected identification errors; it cannot isolate the timing of the check from everything else that changed, but the direction is hard to ignore.
What a hospital does that a kitchen table cannot easily copy
The hospital's identification controls were built incident by incident. In 2007 the National Patient Safety Agency reported that in a single year it had received 24,382 reports of patients being mismatched to their care, of which more than 2,900 related to wristbands. Its safer practice notice standardised the band and its core identifiers: surname, first name, date of birth and NHS number, with compliance required from July 2008[11]. Those identifiers, and the barcode that encodes them, are now national information standards. Even with bands in place, a wristband is only as good as its presence on the patient: in the CAP Q-Tracks programme, phlebotomists inspecting more than 1.75 million wristbands found a mean error rate of 7.40% at the start, falling to 3.05% after two years of continuous monitoring, and 71.6% of errors were simply missing bands[7].
Behaviour matters as much as the band. When the EFLM preanalytical working group audited 336 phlebotomy episodes across twelve European countries, the median error rate against the CLSI guideline was 26.9%, and patient identification and tube labelling were the steps with the highest combination of probability and potential harm[8].
Outside the hospital, almost every one of these controls weakens. Patients at home do not wear identity bands. In SHOT's 2024 maternity data, 123 of 349 WBIT cases (35.2%) involved a patient with no identity band in place, and the reports included events in community hospitals and clinics, general practice and the patient's own home[2]. Staff working alone have no second person to challenge them. Requests are often verbal or generated on paper. Device patient-entry screens accept whatever is typed. And where results are transcribed by hand rather than transmitted, a separate error source opens up: in an outpatient study, 260 of 6,930 manually entered point-of-care glucose results (3.7%) were discrepant from the interfaced value, and the authors estimated clinically significant discrepancies at around 5 per 1,000 results[10]. That study compared the same patient's values, so it says nothing about wrong-patient entry; it simply shows how porous a manual hand-off is.
A wrong-patient glucose looks exactly like a plausible glucose. Nothing about the number itself is likely to tell you it belongs to someone else.
One patient, five numbers
Working with services that have tried to take point-of-care testing into community, virtual ward and hospital-at-home settings, I keep meeting the same pattern. In one large trust, results from community devices carried no hospital patient number at all, and there was no route from those devices into the electronic patient record. A hospital-at-home device pilot elsewhere stalled not on analytical performance but on connectivity. And partners across one local system described one person carrying a GP practice record number, an ambulance incident number, a mental health trust identifier, a hospital record number and an NHS number, each system confident that its own number was the one that mattered.
None of this is new. In 2008 the NPSA issued a second safer practice notice after receiving more than 1,300 incident reports in two years that arose from reliance on local numbering, many involving "two patients having the same number, or one patient having more than one number". NHS organisations were told to use the NHS number as the national identifier, and to act by 18 September 2009[12]. Since 2015 there has been a statutory duty in England: section 251A of the Health and Social Care Act 2012, inserted by the Health and Social Care (Safety and Quality) Act 2015, requires commissioners and providers of health services or adult social care to include the consistent identifier in information they process about an individual. It is a qualified duty: it applies where including the identifier is likely to facilitate care and is in the person's best interests, and it need not be followed where the identifier cannot reasonably be found, the person objects, the service is accessed anonymously, or there is another reason compliance is not reasonable[16].
The danger of many numbers goes well beyond inconvenience. Doidge and Harron describe the two ways linkage goes wrong in terms every POCT manager will recognise: records belonging to two people can be merged into one, and records belonging to one person can be split into two[24]. In a clinical record, merging means a result in the wrong chart, the classic wrong-patient event. Splitting means a result in no chart that anyone will look at: the patient's last potassium exists, but not where the clinician on the next shift is looking. Outside the hospital, separate service records make splitting an obvious risk, because a service that cannot find a matching record may create a new one, although the relative frequency of splitting and merging in community point-of-care testing has not been measured.
The NHS number and PDS: what they solve and what they do not
The NHS number is a ten-digit identifier in a 3-3-4 format, held by everyone registered with the NHS in England, Wales and the Isle of Man; the tenth digit is a check digit that confirms the number is valid[13]. The authoritative source is the Personal Demographics Service, the national master database of NHS patients in those three nations. It holds more than 80 million records, over 60 million of them for people currently registered with a GP, and supports over a billion transactions a month through system-to-system interfaces rather than direct access[14]. The NHS number standard, ISB 0149, sets out how systems must accept, store, display and transmit the number, and its scope explicitly includes community health, primary care, mental health and urgent and emergency care, not just hospitals[15]. The Professional Record Standards Body's Core Information Standard guidance says the NHS number is likely to be the primary identifier and that PDS should be the source of demographic information[17].
Three limits are worth being precise about. The check digit catches typing errors; it does not catch a valid number belonging to someone else. A PDS trace confirms that a set of demographics corresponds to a real person; it does not confirm that the person in front of you is that person. Only positive identification of the patient does that. And coverage is not uniform. In a study of English hospital episode records, the share of records missing an NHS number fell from 43.8% for the 1992 birth cohort to 0.7% for 2012, an enormous improvement, but missing numbers remained more likely for ethnic minority patients, overseas visitors and people of no fixed abode[22]. The people least likely to arrive with a traceable number are often the people community outreach, homeless health and mental health crisis services exist to reach.
Even so, when a result carries a verified NHS number, linking it to the right record is close to deterministic. When it does not, every downstream system must guess from names, dates and postcodes.
The statistics of matching: deterministic and probabilistic linkage
There are two families of record matching. Deterministic matching links two records when a defined set of fields agrees exactly, for example NHS number, date of birth and sex. It is transparent and easily automated. Probabilistic matching, formalised by Fellegi and Sunter in 1969, treats each comparison as evidence. For any pattern of agreement and disagreement it compares two probabilities: m, the probability of seeing that pattern if the records truly belong to the same person, and u, the probability of seeing it if they do not. Pairs above an upper threshold are linked, pairs below a lower threshold are not, and pairs in between are "possible links" for clerical review. The thresholds are set by choosing the error levels you are willing to accept: the rate of false links, which they called mu, and the rate of missed links, lambda[20].
In practice each field contributes a weight: log2(m/u) when it agrees and log2((1-m)/(1-u)) when it disagrees, and the weights are summed. Rare agreements are worth a lot, because u is tiny; common agreements, such as sex, are worth very little. Hagger-Johnson and colleagues published the values they used to add a probabilistic step to the English hospital episode linkage, which gives us real parameters to work with[22].
| Identifier | m (agree if same person) | u (agree by chance) | Weight if agrees | Weight if disagrees |
|---|---|---|---|---|
| Date of birth (day, month, year) | 0.95, 0.94, 0.91 | 0.03226, 0.08333, 0.05 | +12.56 (all three) | varies by part |
| Sex | 0.9 | 0.5 | +0.85 | -2.32 |
| Postcode | 0.68 | 0.00001 | +16.05 | -1.64 |
| NHS number | 0.9 | 0.00001 | +16.46 | -3.32 |
Table 1. Match weights computed from the m and u probabilities published by Hagger-Johnson and colleagues for English hospital episode data[22]. Weights are log base 2; disagreement weights are the author's calculation using the standard Fellegi-Sunter form.
Consider a community service whose patient lookup searches a catchment of 500,000 people (a hypothetical figure). Before any comparison, the prior odds that a given candidate record is the right person are about 1 in 500,000. Case A: a point-of-care result typed with date of birth, sex and postcode, all of which agree with a candidate record; no NHS number. The weight is 12.56 + 0.85 + 16.05 = 29.46, a likelihood ratio of 229.46, about 740 million. Posterior odds are 740 million divided by 500,000, about 1,480 to 1, an illustrative probability of 99.93% that this is the right person under the assumed prior and the model's assumption that the fields err independently. Case B: the patient moved house last year and the device holds the old postcode. Now the weight is 12.56 + 0.85 - 1.64 = 11.77, a likelihood ratio of about 3,480. Posterior odds are about 0.007, a probability of 0.7%. The same patient, the same result, and the match has collapsed. Case C: as Case B, but the NHS number was captured and agrees. Adding 16.46 gives 28.22, a likelihood ratio of about 313 million and a posterior probability of 99.84%. One verified field rescued the match that a stale postcode destroyed. These are illustrations of the mechanism, not validated clinical matching confidences.
The example is deliberately simple. Real algorithms add names, phonetic codes and partial date agreement, and real m and u values vary by population. But the mechanism is general, and the real-world data bear it out. When Harron and colleagues compared 30,000 hospital records with PDS using the NHS number as the reference, sex and date of birth disagreed or were missing in only 0.11% of records, but postcode disagreed or was missing in 53%[23]. Postcode is a powerful field when it is current and a treacherous one when it is not. Their work also showed that identifier error rates differed significantly by age, ethnicity and sex, which breaks the independence assumption the classic model relies on[23].
The threshold is a choice between two harms
Every matching rule trades false matches against missed matches, and moving the threshold only moves the error from one column to the other. The English hospital episode data show this cleanly. The deterministic algorithm, tested against a national paediatric intensive care registry, produced few false matches (176 of 77,810, 0.2%) but missed 3,609 of 88,596 true matches (4.1%), and so underestimated the true readmission rate by 3.8%[21]. Across 1998 to 2015 it missed 2.3% of matches overall (95% CI 2.2 to 2.4%), and 8.6% (95% CI 8.4 to 8.8%) in the earliest years[22]. Adding a probabilistic step reduced missed matches, and the sensitivity analysis shows the trade-off directly.
A research dataset can absorb a 1.8% false match rate with a sensitivity analysis. A clinical record cannot absorb a single result in the wrong chart without a risk of harm. That is why clinical matching should be set strict, with the ambiguous band routed to a named human. The missed matches do not disappear. They become orphan results.
There is also an equity point. In the paediatric intensive care study, missed matches were more common for younger patients, for Asian, Black and other ethnic groups, and for records with missing data, and false matches were also more likely for some of the same groups[21]. Linkage error concentrates in the patients whose identifiers are hardest to capture, often the patients outreach services were built for.
Orphan results: where unmatched results go
An orphan result is a valid measurement that cannot be attached to a known patient record. In a connected hospital system it usually sits in a holding queue in the data management software, because the identifier on the device did not match a registered patient. In the glucose study above, unmatched results were stopped at the interface rather than pushed into a record, and a daily review identified, tracked and where appropriate reconciled them[9]. That is good design: the system refused to guess. But a queue is only safe if someone works it. A result that is stopped and never reviewed may already have informed treatment at the point of care, but it is missing from the record that every later clinician relies on, and the clinician who ordered it may believe it was filed.
Outside the hospital the orphan problem is often invisible because there is no queue at all. The result stays on the device, on paper, or is typed into another system later, creating a split record or relying on fallible transcription[10]. In the community settings I described, the honest answer to "how many results from last month did not reach a record?" was that nobody could say.
The standards are clear about what is expected. ISO 15189:2022 now incorporates the point-of-care requirements that used to sit in ISO 22870, and UKAS has said accredited POCT services will in future be assessed against ISO 15189:2022 alone[18]. Its requirements, as set out in accreditation assessment checklists, include that a request provides "unequivocal traceability of the patient to the request and sample", that the primary sample is traceable to an identified individual, and that every report carries unique patient identification[19]. A result with no patient, or with a patient guessed later from a name typed on a keypad, does not meet that bar regardless of how good the measurement was.
A result that informed a decision at the bedside but never reached the record is invisible to every clinician who comes next.
What a community service should demand on Monday
None of what follows asks anyone to depart from the manufacturer's instructions or a locally validated procedure. It is what governance should ask before point-of-care testing goes out of the building, and keep asking afterwards.
- Positive identification with at least two identifiers, every time. Ask the patient to state their name and date of birth rather than confirming what you read to them, and check against the identifiers the result will carry. Where a patient cannot respond, the local procedure for confirming identity through a carer or record should be written down, not improvised.
- The NHS number at the point of test. Capture a verified NHS number on the device or the request before the test is run wherever one is available, from a verified source rather than memory; scanning a barcode or selecting from a worklist beats typing. Where it is not available, for an unidentified patient or during downtime, use a controlled temporary identifier with a documented reconciliation step, and never let identification delay urgent testing.
- A PDS-verified identity behind the worklist. Patient lists sent to community devices should be built from records whose NHS numbers have been traced against PDS, so that the identity check happens before the sample is taken. The glucose study verified identity against a local registration feed rather than PDS, so the benefit of PDS-traced worklists is a reasonable inference, not a measured result.
- Strict matching, with the grey zone routed to a person. Agree with your laboratory and digital teams how results are matched to records. Identifier agreement alone does not make filing safe, because picking the wrong person from a worklist copies both fields perfectly. Permit automatic filing only under locally validated rules that include positive patient identification, the provenance of the identifiers and checks for conflicting or duplicate records; anything less certain should not be auto-filed.
- An orphan-result queue with a named owner and a time limit. Every unmatched result goes to a visible queue. Someone is accountable for it, there is a defined maximum time to resolve or escalate, and clinically urgent values are escalated immediately rather than waiting for the daily sweep.
- No silent manual transcription. Where results must be entered by hand, require a second check and record who entered what. Treat each manual route as a temporary risk with an end date.
- Clinical safety assurance, not just accreditation. Any system that captures identity or files point-of-care results needs clinical risk management: DCB0129 applies to the manufacturer and DCB0160 to the organisation deploying and using it[25]. Ask to see both safety cases and check that identification hazards are in them. ISO 15189 accreditation does not replace this.
- Audit what you can count. Report monthly on unmatched results, time to resolution, results with no NHS number, and identification incidents. If you cannot produce those numbers, that is the first finding.
- Make the pathway reportable. Staff should know that a near miss in identification is worth reporting. The transfusion data exist because people report; point-of-care identification errors will stay invisible until someone does the same.
The nurse at the kitchen table did everything we usually measure: her device was in control, her competence was current, her technique was sound. Whether her result helps or harms the patient now depends on a dozen characters she may not even have been asked to enter. We spend a great deal of effort making point-of-care results accurate. Outside the hospital, we need to spend at least as much making sure they arrive, attached to the right person, in the place the next clinician will look.
Sources and notes
Identification error rates in this article come from studies with different definitions and denominators (per sample collected, per sample received, per test released, per wristband inspected), so Figure 2 shows orders of magnitude rather than a like-for-like comparison. Wrong blood in tube is the best measured identification error because transfusion has a built-in check; equivalent data for community point-of-care testing do not yet exist, and the hospital glucose figures are from a single US health system. SHOT is a voluntary, passive reporting scheme and under-reports. The m and u probabilities in the worked example are those published for English hospital episode data and will differ in other populations; the 500,000-person catchment is hypothetical and the calculation is illustrative. ISO 15189:2022 requirements are described as worded in a published accreditation assessment checklist rather than quoted from the paywalled standard. Field observations are from the author's work with NHS organisations and partners and are deliberately anonymised and unquantified. Figures 1, 2 and 4 plot published data; Figure 3 is a schematic.
- Dzik WH, Murphy MF, Andreu G, et al. An international study of the performance of sample collection from patients. Vox Sanguinis, 2003 (WBIT median 1 in 1,986 samples, 0.5 per 1,000; mislabelling 1 in 165; over 690,000 samples, 62 hospitals, 10 countries; national ID systems in Sweden and Finland associated with rates too low to estimate).
- Rosa V, Bolton-Maggs P, Molloy A, Hughes C. Near Miss: Wrong Blood in Tube (WBIT). Annual SHOT Report 2024, Chapter 15a, 2025 (899 WBIT; 40.8% patient not identified at phlebotomy; 31.1% labelled away from patient; 81.5% handwritten labels; 84.2% detected in the laboratory; 184 of 448 potential ABO-incompatible; 35.2% of maternity cases without an identity band).
- Rosa V. Near Miss (NM) Reporting. Annual SHOT Report 2024, Chapter 15, 2025 (Figure 15.1, WBIT reports 2015 to 2024).
- Lippi G, Blanckaert N, Bonini P, et al. Causes, consequences, detection, and prevention of identification errors in laboratory diagnostics. Clinical Chemistry and Laboratory Medicine, 2009 (misidentification of general laboratory specimens around 1%).
- Lippi G, Mattiuzzi C, Bovo C, Favaloro EJ. Managing the patient identification crisis in healthcare and laboratory medicine. Clinical Biochemistry, 2017 (0.01 to 0.1% of specimens; 10 to 20% of errors with serious harm).
- Valenstein PN, Raab SS, Walsh MK. Identification errors involving clinical laboratories: a College of American Pathologists Q-Probes study of patient and specimen identification errors at 120 institutions. Archives of Pathology and Laboratory Medicine, 2006 (55 errors per million released tests; 85% detected before release; 1 adverse event per 18 errors).
- Howanitz PJ, Renner SW, Walsh MK. Continuous wristband monitoring over 2 years decreases identification errors: a College of American Pathologists Q-Tracks study. Archives of Pathology and Laboratory Medicine, 2002 (wristband errors 7.40% falling to 3.05%; 71.6% missing bands).
- Simundic AM, Church S, Cornes MP, et al. Compliance of blood sampling procedures with the CLSI H3-A6 guidelines: an observational study by the EFLM working group for the preanalytical phase. Clinical Chemistry and Laboratory Medicine, 2015 (336 audits, 12 countries, median error rate 26.9%).
- Alreja G, Setia N, Nichols J, Pantanowitz L. Reducing patient identification errors related to glucose point-of-care testing. Journal of Pathology Informatics, 2011 (ID errors 61.5 a month, 0.319%, falling to 3 a month, 0.015%; unmatched results stopped at the interface and reviewed daily).
- Mays JA, Mathias PC. Measuring the rate of manual transcription error in outpatient point-of-care testing. Journal of the American Medical Informatics Association, 2019 (260 of 6,930 manual entries discrepant, 3.7%; clinically significant about 5 per 1,000).
- Mayor S. Hospitals must standardise patients' wristbands to reduce risk of wrong care. BMJ, 2007 (NPSA: 24,382 mismatch reports, over 2,900 wristband related; core identifiers including NHS number).
- Management in Practice. All patients to be identified by their NHS number. 2008 (NPSA safer practice notice: over 1,300 incidents from local numbering, June 2006 to August 2008; action by 18 September 2009).
- NHS England. NHS Number (ten digits in 3-3-4 format; tenth digit is a check digit; England, Wales and Isle of Man).
- NHS England. Personal Demographics Service (over 80 million records, over 60 million currently GP registered; over 1 billion transactions a month).
- NHS England. ISB 0149 NHS Number, information standard (scope includes community, primary care, mental health and urgent and emergency care).
- UK Parliament. Health and Social Care Act 2012, section 251A: consistent identifiers, inserted by the Health and Social Care (Safety and Quality) Act 2015 (England; qualified duty with exceptions in subsections 5 and 6).
- Professional Record Standards Body. Core Information Standard: implementation guidance (section 3.1: NHS number likely the primary identifier; PDS should be the source of demographic information).
- UKAS. Publication of ISO 15189:2022, technical bulletin (incorporation of ISO 22870:2016 POCT requirements).
- SADCAS. F134(b) Vertical assessment, ISO 15189:2022 for medical laboratories, 2024 (clauses 7.2.3.1, 7.2.6.1 and 7.4.1.6 on patient traceability and unique identification).
- Fellegi IP, Sunter AB. A theory for record linkage. Journal of the American Statistical Association, 1969 (link, possible link and non-link decisions; m and u probabilities; error levels mu and lambda).
- Hagger-Johnson G, Harron K, Fleming T, et al. Data linkage errors in hospital administrative data when applying a pseudonymisation algorithm to paediatric intensive care records. BMJ Open, 2015 (false matches 0.2%, missed matches 4.1%; readmission underestimated by 3.8%).
- Hagger-Johnson G, Harron K, Goldstein H, Aldridge R, Gilbert R. Probabilistic linkage to enhance deterministic algorithms and reduce data linkage errors in hospital administrative data. Journal of Innovation in Health Informatics, 2017 (missed matches 2.3% overall and 8.6% in 1998 to 2003; published m and u probabilities; Table 5 threshold sensitivity; missing NHS number 43.8% to 0.7%).
- Harron K, Hagger-Johnson G, Gilbert R, Goldstein H. Utilising identifier error variation in linkage of large administrative data sources. BMC Medical Research Methodology, 2017 (identifier errors or missing values in 0.11% of records for sex and date of birth, 53% for postcode).
- Doidge JC, Harron KL. Reflections on modern methods: linkage error bias. International Journal of Epidemiology, 2019 (merging and splitting of people through false and missed links).
- NHS England. Digital clinical safety assurance (DCB0129 for manufacturers of health IT systems; DCB0160 for organisations deploying and using them).
