Sample Chain of Custody: Why Your Lab Needs a Full Audit Trail
Why every diagnostic lab needs a complete specimen chain of custody — what to log at each handoff, how barcode tracking beats logbooks, and how to survive an MLSCN or ISO 15189 audit.
By Dr. Jethro Magaji
Duration
17 MINSA patient calls to dispute a result. A specimen turns up mislabeled at accessioning and nobody can say where the mix-up happened. An MLSCN inspector picks a random requisition number and asks you to walk them through that specimen's entire history — who collected it, when it left the collection point, who logged it in, who ran it, who verified the result. If the honest answer is "we'd have to ask around and check a few different logbooks," your lab doesn't have a defensible answer. It has a guess.
This isn't a forensic-lab problem or a legal-case problem. It's a problem for any diagnostic lab that processes specimens every day, because disputed results, mislabeling incidents, and accreditation audits happen in ordinary clinical labs far more often than court cases do.
Quick Answer
Chain of custody in a diagnostic lab is the complete, unbroken record of everyone who touched a specimen and everything that happened to it, from collection through disposal — who collected it, when it was received at accessioning, who tested it, and who released the result. A full audit trail matters beyond "good practice" because it's the only thing that lets a lab reconstruct what actually happened when a result is disputed, a mislabeling incident needs investigating, or an ISO 15189/MLSCN auditor asks for proof rather than an assurance. Without it, a lab is relying on staff memory and scattered paper logs to defend its own results — which usually means it can't defend them at all. Barcode-based specimen tracking makes a real-time, tamper-evident version of this record practical at normal sample volumes, in a way manual logbooks structurally cannot.
What "Chain of Custody" Actually Means in a Diagnostic Lab
Chain of custody sounds like a phrase borrowed from crime dramas — evidence bags, sealed envelopes, a courtroom exhibit number. In a diagnostic lab, it means something more mundane and far more common: every specimen has a path, and every point on that path is a handoff between people.
A typical specimen's path looks like this:
- Collection — a phlebotomist or collection staff member draws the sample and labels it.
- Transport — the sample moves from the collection point (a ward, a satellite centre, a home visit) to the lab.
- Accessioning — the lab receives the specimen, logs it in, and assigns it to a test workflow.
- Testing — a lab scientist or technician runs the analysis.
- Result entry and verification — a result is entered, reviewed, and released.
- Storage and disposal — the specimen is held for a retention period, then discarded per protocol.
Chain of custody is simply the record of who was responsible at each of those points, and when the handoff happened. It's not a specialized forensic concept bolted onto lab work — it's a description of what already happens to every specimen in every lab. The question is whether that path is actually recorded, or whether it only exists in the memory of whoever happened to be on duty that day.
The Real Scenarios Where This Matters
Labs that treat chain of custody as optional usually change their mind the first time one of these happens:
A disputed result. A patient or referring doctor questions a result — a value that doesn't match their clinical picture, or a positive result the patient insists is wrong. The first question in any credible investigation is: can you reconstruct exactly what happened to that specimen? Who collected it, was it the right patient, was it handled correctly in transit, who ran the test, was the result double-checked before release. Without a record, the lab is left saying "we believe our process is followed correctly" instead of "here is exactly what happened to this specimen."
A mislabeling incident. Specimen mix-ups are one of the most common — and most dangerous — failure modes in diagnostic labs. When one surfaces, the investigation isn't optional; it's how you find out whether it's an isolated error or a process gap that's mislabeling other specimens too. That investigation depends entirely on being able to trace exactly where in the collection-to-accessioning path the label was attached, and by whom.
An accreditation audit. MLSCN inspectors and ISO 15189 assessors don't just ask whether you have a process — they ask you to prove it, on a specimen they pick, not one you prepare in advance. "Walk me through this sample's history" is a standard audit question specifically because it's the fastest way to tell whether a documented process is actually followed or just written down.
A legal or insurance dispute. Less common day-to-day, but real: an insurer disputing a claim tied to a lab result, or a legal matter where a result is evidence. In these cases, an incomplete or informal record isn't just inconvenient — it can undermine the lab's credibility on a result that may otherwise be entirely correct.
In every one of these scenarios, the lab isn't being asked to prove it did nothing wrong in the abstract. It's being asked to reconstruct one specific specimen's actual history — and that's only possible if the history was captured as it happened, not reconstructed afterward from memory.
What a Proper Audit Trail Needs to Capture at Each Handoff
A chain-of-custody record that actually holds up needs three things at every single handoff point: who, when, and what action. Not a summary at the end of the day — a record created at the moment each step happens.
At minimum, that means:
- Collection: who collected the specimen, the exact date/time of collection, and the patient/specimen identifiers used to label it.
- Transport (if applicable): who handed the specimen off, who received it, and when — especially relevant for labs running collection centres or courier pickups.
- Accessioning: who logged the specimen into the lab system, the date/time it was received, and confirmation the specimen matches the request (right patient, right test, right container).
- Testing: who performed the test, on what equipment, and when.
- Result entry and verification: who entered the result, who reviewed/verified it (if your workflow requires a second check), and when it was released to the requesting clinician or patient.
- Storage and disposal: how long the specimen was retained and when/how it was disposed of, per your retention policy.
The point of capturing all of this isn't bureaucracy for its own sake. It's that any single gap — a step where "who" or "when" can't be answered — is exactly where a dispute, a mislabeling incident, or an audit finding tends to land. A record with five solid handoffs and one blank spot is only as strong as that blank spot.
Why Manual Logbooks Fall Short
Most labs that don't have a real audit trail don't have nothing — they have logbooks. A collection register, a specimen reception book, a results register. The problem isn't that logbooks capture zero information; it's that they capture information in a form that's easy to leave incomplete and hard to trust.
A few structural weaknesses show up in almost every paper-based system:
- Gaps are invisible until you need them. A skipped entry, an illegible handwriting sample, or a missing timestamp doesn't announce itself — it only becomes a problem the day you actually need that record for an investigation or an audit.
- Entries can be made after the fact. A logbook entry written at the end of a shift, from memory, isn't the same as a record created at the moment of the handoff — and there's usually no way to tell the difference after the fact.
- Cross-referencing is slow and manual. Reconstructing one specimen's full path across a collection register, a reception book, and a results register means physically pulling three different logs and matching entries by hand — for every specimen an auditor or investigator asks about.
- They're easy to alter. A paper entry can be corrected, rewritten, or a page can go missing, with no reliable way to prove it wasn't tampered with.
None of this means the staff running those logbooks are careless. It means the format itself doesn't support what a real chain of custody requires: a record that's created automatically at each step, that's hard to alter after the fact, and that can be pulled up for any one specimen in seconds rather than reconstructed from three separate books.
How Barcode-Based Specimen Tracking Makes This Practical
Barcode-based specimen tracking closes the gap between "we have a process" and "we can prove the process was followed," because it changes when and how the record gets created.
Instead of a handwritten entry made at convenience, each specimen gets a barcode label at collection. Every subsequent step — accessioning, assignment to a test, result entry, release — happens by scanning that barcode, which automatically timestamps the action and attributes it to the logged-in staff member performing it. The chain-of-custody record isn't written up afterward from memory; it's generated as a byproduct of doing the work.
This matters for three practical reasons:
- It's continuous, not spot-checked. Every specimen gets the same record, automatically — not just the ones someone remembers to log carefully.
- It's fast to pull up. For a disputed result or an audit question, the full specimen timeline is one lookup, not a manual cross-reference across multiple logbooks.
- It's harder to falsify after the fact. A scan-generated, timestamped record tied to a specific staff login is a fundamentally different kind of evidence than a handwritten line that anyone could add later.
See Chain of Custody in Action
How ClinikEHR Diagnostics Implements This
ClinikEHR Diagnostics builds chain of custody in as a core, named feature rather than an afterthought bolted onto reporting:
- Chain-of-custody timeline on every specimen — a full audit trail recording who handled the specimen and when, from sample registration through result release.
- Sample registration and accessioning with structured intake, so every specimen enters the system with a clear, logged starting point.
- Barcode and label printing, so each specimen carries a scannable identifier from the moment it's collected rather than a handwritten label alone.
- Full specimen tracking through the testing workflow, so a specimen's status and location in the process is always visible, not just its final result.
- Built toward MLSCN and ISO 15189 compliance readiness, so the audit trail is structured with accreditation requirements in mind rather than added on as an afterthought.
- Accreditation-ready audit-log exports on the Business Lab tier and above, for labs preparing formal accreditation documentation.
This sits alongside the rest of the platform — test workflow and result entry, branded digital reports, reagent and consumables inventory with batch/lot tracking, and Referring-Doctor and Patient Portals — so chain of custody isn't a separate system to maintain, it's built into the same workflow staff already use to process specimens.
Pricing: Starter Lab $48/month (₦75,000/month) — 5 staff, 1 lab. Professional Lab $76/month (₦120,000/month) — 12 staff, 2 collection centres. Business Lab $127/month (₦200,000/month) — 25 staff, 3 labs + 5 collection centres, includes accreditation-ready audit-log exports. Enterprise — custom pricing for larger networks.
Frequently Asked Questions
Is chain of custody only relevant for forensic or legal labs? No. While the term originated in forensic and legal contexts, any diagnostic lab that processes patient specimens can face a disputed result, a mislabeling incident, or an accreditation audit — all of which require reconstructing a specimen's history. A clinical lab that never touches a legal case still needs to be able to answer "who handled this specimen and when" for its own quality and patient-safety reasons.
What specifically gets logged at each step? At minimum: who performed the action, the exact date/time, and what the action was. That means who collected the specimen and when, who received and accessioned it, who tested it and on what equipment, who entered and verified the result, and when it was released. Any step where "who" or "when" is missing is a gap in the record.
Can an audit trail be edited or deleted after the fact? No — a proper chain-of-custody record should be tamper-evident and effectively immutable. Once a handoff is logged (a specimen is scanned in, a result is entered), that entry should stand as the record of what happened, rather than being something staff can quietly rewrite later. This is precisely what separates a real audit trail from a paper logbook, where entries can be corrected, rewritten, or lost.
How does this help during an MLSCN inspection specifically? MLSCN inspectors commonly ask a lab to trace a specific specimen's full history as part of an inspection — not to review your written procedures, but to confirm they're actually followed. A lab with a real audit trail can pull up that specimen's complete timeline in moments. A lab relying on logbooks has to manually cross-reference multiple registers and hope nothing was missed, which is a much weaker position to be in during an inspection.
Does chain-of-custody tracking slow down sample processing? In a barcode-based system, no — logging a handoff is a scan, which is faster than a handwritten logbook entry, not slower. The record is generated as a byproduct of the normal workflow (scanning a specimen in at accessioning, scanning it out to testing) rather than as an extra administrative step staff have to remember to do separately.
What happens if a specimen's chain of custody has a gap? A gap doesn't necessarily mean something went wrong with the specimen itself, but it does mean the lab can't prove what happened at that step if it's ever questioned. The practical fix is a tracking system that makes gaps unlikely in the first place — by generating the record automatically at each handoff rather than relying on staff to remember a separate logging step.
Does a small lab really need this, or is it only for large reference labs? Disputed results and mislabeling incidents aren't correlated with lab size — a small lab handling a handful of specimens a day faces the same basic risk as a large one, just at a smaller scale. Since barcode-based tracking is now available at entry-level pricing rather than requiring a large reference-lab budget, there's little reason for a smaller lab to rely on logbooks alone.
Is chain of custody the same thing as an audit log? They overlap but aren't identical. Chain of custody specifically tracks the physical/procedural path of a specimen (who collected it, transported it, tested it). An audit log is the broader system record of actions taken in the software — which can include chain-of-custody events alongside other system activity like user logins or report edits. A well-built LIMS captures chain of custody as part of its overall audit logging.
Conclusion
A lab's results are only as trustworthy as its ability to reconstruct how they were produced. When a result is disputed, when a mislabeling incident needs investigating, or when an MLSCN or ISO 15189 auditor asks you to walk through a specimen's history, "we believe our process works" isn't an answer — a complete, timestamped record is.
Key takeaways:
- Chain of custody covers every specimen's path — collection, transport, accessioning, testing, result release, and disposal — not just forensic or legal cases.
- A real audit trail captures who, when, and what action at every single handoff, with no gaps.
- Paper logbooks are structurally weak for this: entries can be incomplete, backdated, hard to cross-reference, and easy to alter.
- Barcode-based tracking generates the record automatically as a byproduct of normal workflow — faster than logbooks, not slower.
- A tamper-evident, immutable record is what separates a real audit trail from a logbook that anyone could rewrite.
Explore ClinikEHR Diagnostics to see chain-of-custody tracking, barcode accessioning, and accreditation-ready audit trails in action.
Want to walk through it for your lab? Talk to a consultant for free, personalized guidance.
Related Resources:
- MLSCN and ISO 15189 Readiness: How LIMS Software Helps You Pass Audits
- How to Reduce Turnaround Time in Your Diagnostic Lab
- Best Guide to Setting Up a Medical Laboratory in Nigeria
- Setting Up a Full Diagnostic Centre in Nigeria
- Top 5 Laboratory and Diagnostic Management Software in Nigeria
- Cost of Setting Up a Medical Laboratory in Nigeria
Stay in the loop
Subscribe to our newsletter for the latest updates on healthcare technology, HIPAA compliance, and exclusive content delivered straight to your inbox.