Medical device data provenance written into each reading at capture

A reading in Kymolog names the device that took it, the device's own timestamp and, once matched, the patient and encounter. Each later change adds a version beside the original, so the reading's history can be read back step by step.

Device and UDI · device clock time · versioned audit trail

Fig. 1. A reading on a recording strip, with a chain-of-custody tag attached.

Fields recorded on each reading

An electrocardiogram (ECG) monitor reports a corrected QT interval (QTc) of 412 ms at 08:02:00.412. The Kymolog™ edge agent records what was measured as LOINC 8636-3, in ms. It also records which device measured it: the device record, its model, its serial number and its unique device identifier (UDI). The UDI's device identifier is the key to that model's entry in FDA's Global Unique Device Identification Database (GUDID).

Once the reading reaches the FHIR store, bed matching attaches the patient and the encounter. From then on each step the reading passes through is recorded with its user and time: validated, sent to the EHR, and the EHR's own id for the result. Kymolog stores these fields on the reading's own record, a Fast Healthcare Interoperability Resources (FHIR) Observation, and on the device record it points to, rather than in a separate log.

The provenance fields on one readingA QTc reading of 412 ms on an ECG strip is tied to a tag listing what Kymolog records with it. What was measured: LOINC 8636-3, Q-T interval corrected, value 412 ms in UCUM. Which device: Device/c19e, an ECG monitor, with its UDI and serial. When: 2026-10-03T08:02:00.412-04:00, by the device’s clock. For whom: patient p-041 and encounter e-5531, matched by bed 4W-12 at the reading’s time. What happened to it: status final, validated by user u-17 at 08:07, sent to the EHR at 08:07 as result r-88213.ECG, BED 4W-12QTc 412 ms08:02:00.412WHAT WAS MEASUREDcodeLOINC 8636-3, Q-T interval correctedvalue412 ms (UCUM)WHICH DEVICEdeviceDevice/c19e, an ECG monitoridentifiersUDI and serial, from the device recordWHENtaken2026-10-03T08:02:00.412-04:00, by thedevice clockFOR WHOMpatientPatient/p-041encounterEncounter/e-5531matched bybed 4W-12, at the reading’s timeWHAT HAPPENED SINCEstatusfinalvalidatedu-17 at 08:07sent to EHR08:07, EHR result r-88213
The provenance fields on one readingA QTc reading of 412 ms on an ECG strip is tied to a tag listing what Kymolog records with it. What was measured: LOINC 8636-3, Q-T interval corrected, value 412 ms in UCUM. Which device: Device/c19e, an ECG monitor, with its UDI and serial. When: 2026-10-03T08:02:00.412-04:00, by the device’s clock. For whom: patient p-041 and encounter e-5531, matched by bed 4W-12 at the reading’s time. What happened to it: status final, validated by user u-17 at 08:07, sent to the EHR at 08:07 as result r-88213.ECG, BED 4W-12QTc 412 ms08:02:00.412WHAT WAS MEASUREDcodeLOINC 8636-3, Q-T intervalcorrectedvalue412 ms (UCUM)WHICH DEVICEdeviceDevice/c19e, an ECG monitoridentifiersUDI and serial, from the devicerecordWHENtaken2026-10-03T08:02:00.412-04:00,by the device clockFOR WHOMpatientPatient/p-041encounterEncounter/e-5531matched bybed 4W-12, at the reading’stimeWHAT HAPPENED SINCEstatusfinalvalidatedu-17 at 08:07sent to EHR08:07, EHR result r-88213
Figure 2 as a table
GroupFieldThis reading
WhatcodeLOINC 8636-3, Q-T interval corrected
Whatvalue412 ms (UCUM)
Which devicedeviceDevice/c19e, an ECG monitor
Which deviceidentifiersUDI and serial, from the device record
Whentaken2026-10-03T08:02:00.412-04:00, by the device clock
For whompatientPatient/p-041
For whomencounterEncounter/e-5531
For whommatched byBed 4W-12, at the reading’s time
Sincestatusfinal
Sincevalidatedu-17 at 08:07
Sincesent to EHR08:07, EHR result r-88213
Fig. 2. Each reading carries its code and unit, the device that took it, the device’s timestamp, the patient and encounter it was matched to, and every step it has been through since.

Timestamps from the device clock

The device stamps 08:02:00 on a reading. The agent keeps that stamp, with its UTC offset, as the reading's effective time. Each later step gets its own time beside it: when the FHIR store saved it, when a nurse approved it, when it reached the EHR.

Bed matching uses the effective time, so a reading taken at 08:02 goes to the patient who was in that bed at 08:02. A continuous glucose monitor reports every five minutes, and each value keeps the time it was measured.

An audit trail of clinical data with a version for each change

A nurse opens a QTc reading held because bed 4W-14 was empty at 09:16, sets the patient to p-052 and approves it. Each of those actions adds a version to the reading and replaces none. A version records who made the change, when, and what changed. Every version keeps the value as the device reported it.

Only users whose role carries the edit-patient permission can reassign a reading. Switching off a device type deactivates it without deleting it, so its readings keep their history.

The audit trail of one readingFive versions of one QTc reading of 431 ms from device d52c, oldest first. Version 1, 09:16:04: the edge agent creates it, coded LOINC 8636-3; status registered. Version 2, 09:16:05: automation finds no patient in bed 4W-14 at 09:16 and holds it; status preliminary. Version 3, in red, 09:24:40: nurse u-23 sets the patient to p-052; status preliminary. Version 4, 09:24:51: u-23 approves it; status final. Version 5, 09:24:52: automation sends it to the EHR as result r-90417. The value, 431 ms, is the same in every version.NO.TIMEBYCHANGESTATUS109:16:04edge agent d52ccreated: QTc 431 ms, LOINC 8636-3registered209:16:05automationno patient in bed 4W-14at 09:16; held for reviewpreliminary309:24:40u-23, nursepatient set to p-052preliminary409:24:51u-23, nurseapprovedfinal509:24:52automationsent to the EHR as result r-90417finalThe value, 431 ms, is the same in every version.
The audit trail of one readingFive versions of one QTc reading of 431 ms from device d52c, oldest first. Version 1, 09:16:04: the edge agent creates it, coded LOINC 8636-3; status registered. Version 2, 09:16:05: automation finds no patient in bed 4W-14 at 09:16 and holds it; status preliminary. Version 3, in red, 09:24:40: nurse u-23 sets the patient to p-052; status preliminary. Version 4, 09:24:51: u-23 approves it; status final. Version 5, 09:24:52: automation sends it to the EHR as result r-90417. The value, 431 ms, is the same in every version.1  09:16:04  edge agent d52ccreated: QTc 431 ms, LOINC 8636-3status registered2  09:16:05  automationno patient in bed 4W-14at 09:16; held for reviewstatus preliminary3  09:24:40  u-23, nursepatient set to p-052status preliminary4  09:24:51  u-23, nurseapprovedstatus final5  09:24:52  automationsent to the EHR as result r-90417status finalThe value, 431 ms, is the samein every version.
Figure 3 as a table
No.Who and whenChange, and the status after it
1Edge agent, device d52c, 09:16:04Created: QTc 431 ms, LOINC 8636-3; registered
2Automation, 09:16:05No patient in bed 4W-14 at 09:16, so held for review; preliminary
3u-23, nurse, 09:24:40Patient set to p-052; preliminary
4u-23, nurse, 09:24:51Approved; final
5Automation, 09:24:52Sent to the EHR as result r-90417; final
Fig. 3. An edit adds a version and never overwrites one. Every version keeps who made the change, when, and what changed, and the reading’s value is the same from the first version to the last.

Medical device data integrity for clinical trials

A study monitor checks a QTc of 412 ms in a trial dataset against the record it came from. FDA's guidance Electronic Source Data in Clinical Investigations (September 2013) asks that source data be attributable, legible, contemporaneous, original and accurate (ALCOA). It names devices among the data originators, and treats the EHR record as the source when a device sends its data to an EHR automatically.

A Kymolog reading is attributable to its device and to each user who acted on it. It is contemporaneous because it carries the time the device recorded, and the original value survives every edit as the first version. A monitor doing source data verification can trace the 412 ms back through those versions to device c19e.

Data integrity in clinical trials also depends on how the sponsor and site validate their systems, which remains their responsibility. Sponsors running wearables in a study can read more on device data for trial sponsors.

See a reading's version history in a demo

Pick a device class. The demo opens one reading's fields and its full version history in a test install, from the device's timestamp to the EHR's result id. We reply within one business day with times to talk.

Request a demo