Chain of Custody That Survives an Audit

Signatures, timestamps, exceptions. Confirm client SOP.

medcourierpath Editorial Team
10 min read

Medical Courier Launch Kit: the 90-day path, templates, scripts, and your state's filing agency, in one document.

See the kit →
In This Article

A defensible chain of custody connects each item to a documented handler, location, time, action, and decision. Use this field guide with the client’s approved standard operating procedure (SOP), applicable contract terms, and current local requirements. For health information and regulated environments, review guidance from the Centers for Disease Control and Prevention and the U.S. Department of Health and Human Services HIPAA resources. These sources do not replace a matter-specific legal, regulatory, or quality review.

An audit rarely turns on one missing signature alone. Auditors usually examine whether the complete record tells a consistent story. They want to know what was received, who controlled it, where it went, what happened to it, and whether any change, delay, damage, or deviation was identified and resolved.

That means chain of custody is more than a form. It is a controlled process supported by forms, labels, access records, system logs, photographs, storage controls, and exception reports. The objective is not to create paperwork for its own sake. The objective is to make the item’s history understandable, reproducible, and supported by contemporaneous evidence.

What does chain of custody actually prove?

Chain of custody is a chronological record of control over an item, specimen, document, device, image, sample, or other material. A complete record should show the item’s identity, condition, custody transfers, storage conditions, testing or handling, and final disposition.

The record should also show the limits of what can be proven. For example, a signature can establish that a person accepted an item at a stated time. It does not automatically prove that the person followed every handling instruction or that the item remained unchanged. Those conclusions require supporting controls such as sealed packaging, access restrictions, environmental monitoring, validated systems, or documented observations.

Which items require a formal chain-of-custody record?

Start with a risk-based inventory. Formal custody controls are commonly appropriate for items that may support a clinical, quality, safety, investigation, compliance, employment, insurance, or legal decision. Examples may include biological specimens, patient-related records, testing materials, evidence, electronic devices, photographs, controlled documents, and samples submitted to a laboratory.

Do not assume that every item needs the same level of control. The client’s SOP should define which items are covered, when the process begins, which records are required, and who may authorize an exception. If the client has no clear rule, pause and obtain written direction from the responsible quality, compliance, legal, laboratory, or records authority before changing the process.

When does the chain of custody begin?

Define the start point precisely. In some workflows, custody begins when an item is collected. In others, it begins when a courier or receiving employee accepts a sealed package. For electronic materials, it may begin when a device or account is identified and preservation is authorized.

Record the event that starts the chain, not merely the time someone later entered information into a system. If the collection time is unknown, record that fact rather than estimating. A later entry may be acceptable if it is clearly marked as a late entry and explains why it was made.

The opening record should identify the person, organization, location, date, time, item description, source, condition, and reason for collection or receipt. Use a consistent time zone and identify it where confusion is possible.

What information should the intake record contain?

A strong intake record answers five questions: What is it? Where did it come from? Who received it? When was it received? What condition was it in?

  • Unique identifier: Assign a barcode, case number, specimen number, exhibit number, or other controlled identifier.
  • Description: Record enough detail to distinguish the item from similar items.
  • Source: Identify the collection site, submitting organization, department, or authorized person.
  • Date and time: Use the actual event time when known, with time zone or system convention.
  • Condition: Note seals, packaging, labels, damage, leakage, temperature indicators, missing pages, visible alteration, or other relevant facts.
  • Purpose: State why the item was collected, transferred, stored, examined, or tested.
  • Initial handler: Record the name, role, and signature or approved electronic equivalent.

Avoid vague descriptions such as “documents” or “sample received” when the item could later be disputed. Use objective language. Record what was observed, not what you assume occurred.

How should signatures be captured?

Every signature should be attributable to a specific person and action. A signature block should identify the signer’s printed name, role, organization if relevant, date, time, and the event being acknowledged. “Signature” by itself is not enough if the form does not show what the person accepted or released.

Electronic signatures may be acceptable under the client’s system and SOP, but the control must be clear. The system should preserve the signer’s identity, the signed content, and the date and time of signing. If a shared account, generic login, copied signature, or unsigned checklist is used, the record may not reliably establish who acted.

Do not sign for another person unless the SOP expressly permits a documented proxy process. If a proxy is allowed, identify both the person performing the action and the person represented, and state the authority for the proxy entry. Never backdate a signature. If a correction is necessary, preserve the original entry and document the reason for the correction.

Which timestamps matter most?

Use timestamps to connect events, not to create an appearance of precision. Important times may include collection, receipt, sealing, transfer, storage, opening, examination, testing, resealing, release, and final disposition.

Keep clocks synchronized where practical. Document the system used to generate electronic timestamps and the time zone convention. If a manual record is created after the event, label it as a late entry and include the actual event time if known. Explain the delay without speculation.

Look for gaps that could affect the item. A short administrative delay may be harmless, while an unexplained period outside required storage conditions could be material. The client SOP should define escalation thresholds, acceptable transport windows, and required environmental conditions.

How can packaging and seals support the record?

Packaging should protect the item and make unauthorized access visible. Use packaging appropriate to the item and the client’s SOP. Record the package type, seal number, label, closure method, and condition at each relevant handoff.

A seal is evidence of closure, not proof that no one accessed the contents. To make the seal useful, record who applied it, when it was applied, and what occurred when it was opened. If the seal is broken, cut, loose, wet, damaged, or inconsistent with the record, treat the condition as an exception.

Photographs can support the record when permitted by the SOP. If photographs are taken, preserve the original files, identify the device or system used when required, and connect each image to the item identifier. Do not replace written observations with photographs alone.

What should every custody transfer document?

A transfer record should show a complete handoff from one accountable person or organization to another. It should identify the releasing party, receiving party, date, time, location, item identifier, condition, packaging or seal status, and purpose of the transfer.

The receiving person should inspect the item within the time and scope required by the SOP. If the package arrives damaged or the identifier does not match, the receiver should not silently accept it as normal. Record the discrepancy, notify the designated authority, and follow the disposition instruction.

For courier transfers, retain the approved shipping or delivery record and connect it to the item identifier. A delivery confirmation may show that a package arrived, but it may not show the package’s condition, storage history, or who controlled it between pickup and delivery.

How should storage conditions be recorded?

Storage records should establish where the item was kept, who could access it, and whether required conditions were maintained. Depending on the item, relevant controls may include restricted access, temperature, humidity, light exposure, vibration, contamination prevention, or protection from alteration.

Record the storage location using a level of detail that permits retrieval, such as facility, room, cabinet, shelf, bin, or system repository. Keep an access log when the risk or SOP requires it. For monitored environments, preserve the applicable monitoring record and document alarms, excursions, maintenance, and corrective actions.

Do not claim that conditions were acceptable merely because no one reported a problem. Confirm the available monitoring record. If monitoring was unavailable, record the limitation and escalate it under the client’s exception process.

What makes an exception record defensible?

An exception record explains what happened, when it happened, who discovered it, what was affected, and what was done next. Examples include a missing signature, broken seal, incorrect label, late transfer, temperature excursion, damaged container, duplicate identifier, system outage, or unexplained access.

Use facts and avoid blame-oriented language. A useful exception entry includes:

  1. A unique exception number or linked item identifier.
  2. Date and time discovered.
  3. Person who discovered or reported it.
  4. Objective description of the condition.
  5. Immediate containment action.
  6. Notification and escalation details.
  7. Impact assessment by an authorized reviewer.
  8. Final disposition or open action.
  9. Approval, signature, or electronic authorization.

Do not erase, overwrite, or quietly repair the original chain. Corrective entries should preserve the original information and create an auditable link to the resolution.

Who is allowed to make a chain-of-custody entry?

Define roles before work begins. The collector, receiver, courier, examiner, analyst, custodian, reviewer, and approver may have different responsibilities. A person should only record an event they performed or directly observed, unless the SOP permits a clearly identified secondary entry.

Training records should show that authorized personnel understood the applicable procedure. Training does not prove that a particular entry is accurate, but it supports the organization’s control environment. Maintain the current SOP version, effective date, change history, and acknowledgment records.

When contractors or external laboratories handle an item, confirm the allocation of responsibilities in the contract, work order, submission form, or other approved record. Do not assume that a vendor’s standard form meets the client’s requirements without review.

How should electronic records be handled?

Electronic chain-of-custody records need controls for identity, access, alteration, retention, and retrieval. Use individual accounts where required by the client’s system. Limit permissions according to job duties and review access when personnel change roles or leave.

Preserve an audit trail when the system supports one. The audit trail should help show what changed, who changed it, and when. If the system does not preserve prior values, use an approved correction process that retains the original record and documents the change.

For health information, follow the client’s privacy and security procedures and review applicable HIPAA resources from HHS. Do not place unnecessary protected information in email, filenames, photographs, or shared folders. Access should be limited to the minimum information and personnel permitted by the client’s procedures and applicable requirements.

How can an auditor test the chain from end to end?

Perform a mock trace before the audit. Select an item and move forward from collection to final disposition. Then work backward from the final record to the source. The two paths should meet without unexplained gaps.

Test whether:

  • The identifier remains consistent across forms, labels, systems, and reports.
  • Every custody transfer has a releasing and receiving record.
  • Timestamps follow a logical sequence.
  • Storage locations match access or inventory records.
  • Exceptions are linked to the affected item.
  • Corrections preserve the original entry.
  • Final disposition was authorized and documented.
  • Records can be retrieved within the client’s required retention period.

Sample both routine and difficult cases. Include an item with a transfer, an exception, a late entry, an electronic record, and a final disposition. Audits often reveal weaknesses in unusual scenarios rather than ordinary handoffs.

What should final disposition include?

Final disposition closes the chain. Record whether the item was returned, released, destroyed, archived, consumed in testing, transferred to another authority, or otherwise handled. Identify the authorization, date, time, person performing the action, and supporting record.

Destruction records should not simply state “destroyed.” Use the level of detail required by the SOP, such as method, date, location, witness, certificate, or vendor record. If an item is retained, document the new custodian and storage location.

Before closing the record, confirm that all open exceptions have an approved resolution. A final disposition entry does not cure an unresolved custody problem, but it can show that the organization recognized and controlled the issue.

How do you confirm the client’s SOP before using this guide?

Request the current, approved SOP before collecting or transferring anything. Confirm the document number, version, effective date, covered items, required fields, signature method, timestamp convention, storage conditions, exception process, retention period, and escalation contacts.

Ask the client to resolve conflicts between the SOP, forms, software, contract, and operational practice. Use the client’s approved form and terminology where available. If local rules, licensing requirements, court instructions, laboratory requirements, or contract provisions may apply, confirm them with the appropriate local authority or qualified adviser.

Finally, document the confirmation. Record who approved the workflow, which SOP was used, and any written deviation or limitation. A chain of custody is strongest when the process was authorized before the first handoff, followed consistently, and reviewed promptly when conditions changed.

Medical Courier Launch Kit

Build the file that wins medical routes.

A 90-day launch path, the credential and insurance stack labs screen for, printable chain-of-custody and temperature log templates, outreach scripts, a rate-floor worksheet, and a 50-state agency directory with guided fill-ins.

  • The 90-day launch path
  • Credential stack checklist
  • Insurance guide
  • Templates
  • Client outreach scripts and a one-page compliance packet outline
  • Rate-floor worksheet

$99 once · instant delivery · 30-day money-back guarantee

Disclaimer: MedCourierPath is an independent information publisher. We are not a courier company, law firm, insurance agency, or government agency, and nothing here is legal, financial, or medical advice. Requirements vary by state, county, and client, and they change; always confirm current requirements with the relevant agency, your insurance professional, and each client contract before acting. We make no promises about contracts, income, or business results.

Read our full disclaimer

medcourierpath Editorial Team

Researched and edited by the MedCourierPath Editorial Team. We are an independent publisher, not a courier company or government agency, and we cite the authority behind every requirement.

How we research and review our content

Related Guides

MedCourierPath
Get the Launch Kit for $99