MedART is Compliance-Ready — Architecture designed to support HIPAA, GDPR & regional regulatory requirements.
Back to Blog

When the IVF Record Doesn't Fit the Family

Same-sex couples, solo parents and donor arrangements break a single-patient record model. What the EMR has to hold — and where clinics improvise.

Preeti Pamecha Preeti Pamecha
August 14, 2026 8 min read

Most electronic medical records are built on an assumption so basic it is rarely stated: one record belongs to one patient, and that patient is the person being treated.

Fertility medicine breaks that assumption routinely. Two women where one provides the oocytes and the other carries the pregnancy. A single man with an egg donor and a surrogate. A couple using donor sperm whose donor also has records at the same clinic. In each case the treatment involves more people than the record model has room for — and what happens next is almost always improvisation.

Whose record is this?

In a donor or surrogacy cycle there is frequently no single correct answer — and that ambiguity, rather than any individual missing field, is the problem.

The single-patient model came from general medicine, where it works. One person presents, one person is treated, one chart follows them.

In IVF, the unit of treatment is not the patient. It is the cycle — and a cycle can involve two people contributing gametes, a third carrying the pregnancy, and two more who will be the legal parents. Some of those people are patients. Some are donors with their own separate records and their own consent. At least one may not exist yet.

Ask a clinic which record a donor-surrogacy cycle “belongs” to and the answer is usually a workaround: whichever chart the coordinator opened first.

Four family shapes the record has to hold

Four arrangements account for most of what a single-patient model cannot represent: two patients sharing one cycle, one patient with donor gametes, a surrogacy arrangement spanning several people, and a family returning years later. None of them is an edge case. They are ordinary weeks in a fertility clinic:

  • Two linked patients sharing one cycle. One partner stimulates and undergoes retrieval; the other receives the transfer. Both are patients. Both have clinical events. The cycle is one cycle.
  • A solo parent using donor gametes. One patient, one donor, and a consent structure that has to survive scrutiny years later.
  • Intended parents, a surrogate and donors as one arrangement. Four or five people, several of whom are patients at the same clinic, in a single treatment plan.
  • Families that return. A sibling attempt using stored embryos from the original cycle, or a donor who donated before and needs to be recognised as the same person.

The last one is the quiet failure. A returning donor recorded as a new donor breaks the genetic link between siblings — and nobody notices until someone asks.

What breaks when the model assumes one patient

When the record cannot represent the arrangement, the arrangement moves somewhere the record cannot read.

The partner becomes next-of-kin. A clinical participant is demoted to an emergency contact. Their own procedures, consent and results now have nowhere structured to live.

Duplicate charts appear. The surrogate gets a chart, the intended mother gets a chart, and nothing joins them. Two people, two records, one pregnancy that belongs to both differently.

Consent becomes ambiguous. A form signed by “the patient” does not say which patient, on whose behalf, for which use of which gametes.

Free text carries the load. The actual arrangement ends up described in a note — readable by a person, invisible to a report, and impossible to audit.

None of these is a data-entry mistake. They are what careful staff do when the software has no correct answer available.

The cost shows up later, and somewhere else. A clinic that cannot query its own donor arrangements cannot report on them either — not to a regulator asking how many cycles used donor gametes last year, not to a clinical governance meeting asking whether outcomes differ between donor and autologous cycles, and not to itself when a stored embryo needs to be matched back to the consent that authorised its creation. Each of those questions is answerable in minutes if the relationships are structured, and takes a week of chart review if they are not.

Registration is where it gets decided

The arrangement is fixed at intake, before a single clinical event is recorded. If the structure is not captured there, everything downstream inherits the gap.

MedART handles this with three distinct registration flows rather than one generic patient form:

  1. Couple — two linked patient records sharing cycles, which is what a shared or reciprocal cycle actually is.
  2. Surrogacy — intended parents, surrogate and donors held as a single entity rather than as unconnected charts.
  3. Family — multi-generational records linking sibling attempts and returning donors, so the same donor is recognised as the same donor.

Surrogacy & Donor Management then carries that structure forward: donor screening against the donor’s own file, configurable anonymous, open and known-donor flows, and surrogate health tracking across pre-pregnancy, antenatal and postnatal care on the same chart.

The distinction matters more than it sounds. A relationship captured as structured data can be reported on, audited and safety-checked. The same relationship captured as a custom field or a note cannot.

It is also close to impossible to add afterwards. Retrofitting structure onto historical records means reading every free-text note, inferring the arrangement from context, and hoping the inference is right — for cycles whose participants may no longer be contactable. Clinics that have attempted it generally conclude that the old records stay as they are and the new model starts from a cut-off date. That works, but it leaves the clinic with two answers to every question that spans the boundary.

A standard consent form has room for a patient and a witness. A donor-surrogacy cycle has neither of those things in the singular.

The MedART consent engine handles four-party signing — intended parent, partner, donor or surrogate, and witness — with tamper-evident audit hashes, and ships pre-loaded templates for donor-sperm, donor-egg, embryo-donation and surrogacy agreements that clinics customise per jurisdiction. It runs through MRD, so the signed record sits with the medical record rather than in a separate document store.

Anonymity is the part most often misunderstood. It is a permission model, not a deletion. European law makes the tension explicit: the identity of recipients and donors should not be disclosed to each other as a general principle, while legislation in individual member states may authorise lifting donor anonymity in exceptional cases, notably for gametes (EUR-Lex, Directive 2004/23/EC).

A record that satisfies anonymity by not storing the link satisfies nothing. It has destroyed traceability to protect privacy, when the requirement is to hold both — the linkage present, the identity restricted, the reveal controlled and logged.

Parentage and provenance have to outlast the cycle

The record has to remain answerable for decades after the cycle ends, to questions asked by people who were never patients. This is where the data model stops being an administrative preference.

Under the EU tissues and cells framework, data required for full traceability must be kept for a minimum of 30 years after clinical use, with a donor identification system assigning a unique code to each donation and to each product associated with it (EUR-Lex, Directive 2004/23/EC).

Thirty years is not a retention policy. It is a different question being asked of the same record, decades later, by people who were not in the room.

The United Kingdom shows what that looks like in practice. Donors registered after 1 April 2005 are not anonymous: donor-conceived people can request non-identifying information at 16 and their donor’s identifying details at 18. The first cohort became eligible in October 2023, and the regulator expects the number of eligible applicants to rise to over 11,000 by 2030 (HFEA).

Those applicants are not patients. They were not born when the cycle ran. The record has to answer them anyway.

Two things follow for the data model. Legal parentage has to be recorded, not inferred — MedART records the legal parent-of-record as part of the arrangement, because who authorises treatment and who receives results are point-of-care questions, not contract-folder questions. And embryo lineage has to be continuous, traceable across the donor to recipient to child chain, which is only possible if the donor, the cycle and the outcome were linked structurally in the first place.

This is why the architecture is designed to support local donor and surrogacy frameworks rather than a single jurisdiction’s rules. A clinic in Tbilisi treating international intended parents is running multi-party intake as standard practice, not as an exception.

What to check in your own system

Three questions, none of which needs a project to answer:

  • Open a donor-surrogacy case. Who is on the record? If the surrogate and the intended mother are two unconnected charts, the arrangement exists only in someone’s head.
  • Find a cycle with a returning donor. Is it the same donor record? If a new record was created, the sibling link is already gone.
  • Take any multi-party consent. Can you tell who signed for what without opening the PDF? If not, the consent is a document rather than data.

What these reveal is not whether staff are careful. It is whether the software ever gave them somewhere correct to put the answer.

For the wider case against retrofitting fertility workflows onto a general-purpose system, see MedART versus a traditional EMR. The governance side of the same problem is covered in data management in fertility clinics.

See the multi-party record model

Bring us your most complicated family arrangement

A 30-minute session on a real case — who is on the record, who signed what, and what your current system needs someone to write into a note field.

Topics

Donor Programmes Surrogacy Patient Records MedART Fertility Clinics
Preeti Pamecha — Product Head — MedART

Product Head — MedART

Preeti Pamecha is Product Head for MedART, the purpose-built IVF EMR platform powering fertility clinics across 25+ countries. She leads the product roadmap across MedART's 17+ modules — clinical documentation, embryology, andrology, laboratory, billing, patient-360, analytics, and beyond — translating how IVF care actually happens on the ground into what the platform does next. She works closely with fertility clinic leaders, embryologists, and lab directors to make sure every release reflects real clinic workflows, not assumptions about them.

Frequently Asked Questions

Can an IVF EMR handle same-sex couples sharing a cycle?
It depends entirely on the data model. A cycle where one partner provides the oocytes and the other carries the pregnancy involves two patients with two clinical roles in one treatment — not one patient with a next-of-kin. MedART supports shared cycles between linked patients, including reciprocal IVF, through a couple registration flow that links the two records at intake rather than relying on a note field.
How does an EMR record a surrogacy arrangement?
As a single arrangement containing several people, not as separate unconnected charts. MedART uses a surrogacy registration flow that holds intended parents, the surrogate and any donors as one entity, with the legal parent-of-record recorded correctly and the surrogate's pre-pregnancy, antenatal and postnatal care tracked on the same chart.
Who signs consent in a donor or surrogacy cycle?
More people than a two-signature consent form allows for. The MedART consent engine handles four-party signing — intended parent, partner, donor or surrogate, and witness — with tamper-evident audit hashes, and ships templates for donor-sperm, donor-egg, embryo-donation and surrogacy agreements that clinics customise per jurisdiction.
How is donor anonymity maintained in the patient record?
Through permissions rather than omission. MedART supports anonymous, open and known-donor flows with permission-based reveal, so recipient–donor linkage exists in the record for traceability while identity stays restricted where the jurisdiction requires it. Removing the link entirely would satisfy anonymity and destroy traceability at the same time.
Why does legal parentage belong in the EMR rather than the legal file?
Because clinical decisions reference it. Who authorises treatment, who receives results, and who consents on behalf of a resulting child are questions asked at the point of care, not in a contract folder. MedART records the legal parent-of-record as part of the arrangement, alongside embryo lineage across the donor to recipient to child chain.