Medical device data provenance written into each reading at capture
A reading in Kymolog names the device that took it, the device's own timestamp and, once matched, the patient and encounter. Each later change adds a version beside the original, so the reading's history can be read back step by step.
Device and UDI · device clock time · versioned audit trail
Fields recorded on each reading
An electrocardiogram (ECG) monitor reports a corrected QT interval (QTc) of 412 ms at 08:02:00.412. The Kymolog™ edge agent records what was measured as LOINC 8636-3, in ms. It also records which device measured it: the device record, its model, its serial number and its unique device identifier (UDI). The UDI's device identifier is the key to that model's entry in FDA's Global Unique Device Identification Database (GUDID).
Once the reading reaches the FHIR store, bed matching attaches the patient and the encounter. From then on each step the reading passes through is recorded with its user and time: validated, sent to the EHR, and the EHR's own id for the result. Kymolog stores these fields on the reading's own record, a Fast Healthcare Interoperability Resources (FHIR) Observation, and on the device record it points to, rather than in a separate log.
Figure 2 as a table
| Group | Field | This reading |
|---|---|---|
| What | code | LOINC 8636-3, Q-T interval corrected |
| What | value | 412 ms (UCUM) |
| Which device | device | Device/c19e, an ECG monitor |
| Which device | identifiers | UDI and serial, from the device record |
| When | taken | 2026-10-03 |
| For whom | patient | Patient/p-041 |
| For whom | encounter | Encounter/e-5531 |
| For whom | matched by | Bed 4W-12, at the reading’s time |
| Since | status | final |
| Since | validated | u-17 at 08:07 |
| Since | sent to EHR | 08:07, EHR result r-88213 |
Timestamps from the device clock
The device stamps 08:02:00 on a reading. The agent keeps that stamp, with its UTC offset, as the reading's effective time. Each later step gets its own time beside it: when the FHIR store saved it, when a nurse approved it, when it reached the EHR.
Bed matching uses the effective time, so a reading taken at 08:02 goes to the patient who was in that bed at 08:02. A continuous glucose monitor reports every five minutes, and each value keeps the time it was measured.
An audit trail of clinical data with a version for each change
A nurse opens a QTc reading held because bed 4W-14 was empty at 09:16, sets the patient to p-052 and approves it. Each of those actions adds a version to the reading and replaces none. A version records who made the change, when, and what changed. Every version keeps the value as the device reported it.
Only users whose role carries the edit-patient permission can reassign a reading. Switching off a device type deactivates it without deleting it, so its readings keep their history.
Figure 3 as a table
| No. | Who and when | Change, and the status after it |
|---|---|---|
| 1 | Edge agent, device d52c, 09:16:04 | Created: QTc 431 ms, LOINC 8636-3; registered |
| 2 | Automation, 09:16:05 | No patient in bed 4W-14 at 09:16, so held for review; preliminary |
| 3 | u-23, nurse, 09:24:40 | Patient set to p-052; preliminary |
| 4 | u-23, nurse, 09:24:51 | Approved; final |
| 5 | Automation, 09:24:52 | Sent to the EHR as result r-90417; final |
Medical device data integrity for clinical trials
A study monitor checks a QTc of 412 ms in a trial dataset against the record it came from. FDA's guidance Electronic Source Data in Clinical Investigations (September 2013) asks that source data be attributable, legible, contemporaneous, original and accurate (ALCOA). It names devices among the data originators, and treats the EHR record as the source when a device sends its data to an EHR automatically.
A Kymolog reading is attributable to its device and to each user who acted on it. It is contemporaneous because it carries the time the device recorded, and the original value survives every edit as the first version. A monitor doing source data verification can trace the 412 ms back through those versions to device c19e.
Data integrity in clinical trials also depends on how the sponsor and site validate their systems, which remains their responsibility. Sponsors running wearables in a study can read more on device data for trial sponsors.
See a reading's version history in a demo
Pick a device class. The demo opens one reading's fields and its full version history in a test install, from the device's timestamp to the EHR's result id. We reply within one business day with times to talk.