Ask an embryologist what keeps them awake and almost nobody describes a dramatic failure. They describe a label that was ambiguous, a dish that sat unattended for a moment longer than protocol, a record entered from memory at the end of a long list.
The serious risks in an IVF laboratory are overwhelmingly administrative — questions of identity, documentation and traceability rather than technique. And administrative risk is a systems problem, which means it is also a software problem. The difficulty is that no single piece of software owns it.
Most lab errors are administrative, not catastrophic
The failure everyone imagines is a mix-up. It is also, mercifully, rare — and rare largely because labs have built layered defences against exactly that scenario.
What is not rare is the quieter category: an entry made after the fact rather than at the bench, a witness signature captured on paper and transcribed later, a consumable used without its lot recorded, a correction made to a record with no trace of what it replaced. None of these harms a patient on the day. All of them are the reason an audit finding gets written, and all of them make the serious event harder to investigate if it ever occurs.
Current guidance treats the record itself as a safety control. Every critical movement of sperm, oocytes, embryos, cryodevices or biopsy samples has to be traceable, including the dates, how each procedure was performed and the staff involved — and any handwritten or electronic edits to those records must themselves be traceable (ARCS 2024 guidelines).
That last clause is the one systems most often fail. Many can tell you what a record says now. Fewer can tell you what it said before.
Traceability is four systems, not one
Here is the thing nobody tells a lab director before they start evaluating software: laboratory traceability is not one system’s job. It spans four, and each is genuinely better at its own layer.
| Layer | What it owns | Typical system |
|---|---|---|
| Clinical record | Cycle, patient and couple identity, consent, clinical events, outcomes | EMR |
| Point-of-handling identity | Verifying the right sample at the bench, in real time | Electronic witnessing (RI Witness, Matcher) |
| Equipment and environment | Calibration, maintenance, qualification, environmental monitoring | Laboratory QMS |
| Consumables | Media, reagents, plastic-ware, lot and expiry | Inventory system |
Most traceability failures are not failures within a layer. They are failures between layers — and vendors rarely draw this map, because every vendor would prefer to describe their own layer as the whole picture.
What the EMR should own
The EMR’s proper territory is the clinical record and the events that belong to it: which cycle this is, who the patients are, what was consented to, what was performed, by whom, and what resulted.
For an embryology laboratory that means the chain-of-custody event log — the gamete-to-transfer trail with witness sign-off recorded at each step, from oocyte through fertilisation, biopsy, transfer and cryopreservation — plus embryo lineage, so that any straw in a tank can be traced back to the cycle that produced it and the consent that authorised it. That is what Embryology in MedART is built to hold, and it is the layer where an EMR genuinely belongs.
What the EMR should not claim is the other three layers. Which brings us to the useful part.
What witnessing systems own, and why integration beats replacement
Electronic witnessing works because it is physically present at the moment of handling. Tags on dishes and tubes are read by hardware at the bench, and a mismatch is caught in the second it matters rather than in a review afterwards.
An EMR cannot do this. It is not in the room, it does not read the tag, and it has no way to know that the dish now in the embryologist’s hand is the one the screen says it is. Any vendor claiming their EMR replaces electronic witnessing is describing something that is not witnessing — it is a checkbox recording that someone said they checked.
The correct relationship is integration, and MedART integrates with electronic witnessing systems including RI Witness and Matcher rather than substituting for them. The witnessing system asserts the identity match; the EMR records that the verified event occurred, against the right cycle, at the right step, so that the clinical record and the bench record agree without anyone retyping either.
This is worth being explicit about during procurement. “Do you replace our witnessing system?” is the wrong question. “How does the confirmed witnessing event reach the clinical record, and what happens when it does not?” is the right one.
Two-way batch audit: the requirement most systems half-meet
Consumables traceability is where the standards are more demanding than most labs expect.
The 2024 ARCS guidance asks for a robust batch control system covering all media, media components, reagents, plastic-ware and other consumables — specifically to allow a two-way audit and to support batch analysis or recall (ARCS 2024).
Two-way is the operative word, and it is the part that quietly fails:
- Forward. A lot has been recalled. Which patients were affected, and can you produce the list today rather than next week?
- Backward. A patient had an unexpected outcome. Which lots were used across their cycle?
Most labs can do one of these adequately. Very few can do both quickly, and the gap is usually only discovered during a real recall, which is the worst possible moment to find out.
MedART covers this pattern on the medication side: Pharmacy & Inventory records batch number and expiry at every dispensing event, maintains an expiry dashboard with 30/60/90-day warning windows, and documents batch receipts, while per-patient consumable consumption is tracked and linked through to billing via MRD. That is a genuine two-way trail for medications and dispensed consumables.
Culture media and laboratory reagents are a different matter. In most clinics that trail lives in the laboratory’s own inventory or QMS records, not in the EMR — and if you are relying on your EMR to produce it during a recall, check now rather than then.
Equipment and environment: not your EMR’s job
The fourth layer is the one where a software vendor is most tempted to overclaim, so let us be plain: equipment traceability does not belong in an EMR.
Accreditation expects equipment validation, calibration, maintenance and repair to be documented with records retained, and ESHRE guidance goes further for incubators — spatial and temporal temperature mapping as part of installation and operational qualification before the unit enters clinical service, with accepted ranges recorded and out-of-range readings corrected and the correction verified (ESHRE Recommendations on Good Practice in the IVF Laboratory).
That is continuous instrument data and a maintenance regime. It belongs in a laboratory quality management system built for it, alongside environmental monitoring. An EMR that offers to store your calibration certificates is offering you a filing cabinet, not a quality system — and a filing cabinet inside clinical software is a worse place for them than a purpose-built QMS.
The honest position is that this layer sits outside the EMR, and the integration question is whether an inspector can move between the two without a gap.
Where the handoffs fail an audit
Four systems means three seams, and seams are where findings come from. These are the ones worth checking before someone checks them for you:
- Witnessing to clinical record. If a witnessing event is confirmed at the bench but has to be manually entered into the EMR, the two records can disagree — and the version an inspector reads is whichever they open first.
- Consumable to patient. If media lots are logged in a lab book and clinical events in software, the two-way audit requires a person with both in front of them. That is not a control; that is a reconstruction.
- Equipment to incident. When an incubator excursion occurs, can you list the cycles that were inside it at the time? That answer needs the QMS and the EMR to share a timeline, and usually neither is designed to.
- Corrections. Every layer must show not just the current value but the history of changes. A layer that overwrites silently breaks traceability for all the others.
None of these needs a formal audit to test. Pick one completed cycle and try to assemble the full picture across all four systems. The time it takes is the finding.
What to do with this
The practical conclusion is not “buy more software.” It is that traceability should be designed as a set of boundaries rather than assumed as a feature.
Decide deliberately which system is the source of truth for each layer, make sure each seam has a defined mechanism rather than a person, and check that every layer preserves its own edit history. A clinic that can name the owner of each layer and describe each handoff will pass an inspection that a clinic with one very good system and three undefined ones will not.
For the wider argument about what purpose-built software changes in a fertility clinic, see why fertility clinics outgrow the systems they started on. On the laboratory side specifically, IVF lab management software covers the evaluation criteria in more depth, and why a specialised embryology module matters explains why the clinical layer cannot simply be a general EMR with lab fields added.
Topics
Product Implementation Lead · CSPO®, CSM®
Ravi Chhajed is a Product Implementation Lead specializing in healthcare SaaS, including EMR and IVF systems. He focuses on clinical workflow automation and AI-enabled product delivery. Ravi holds the Certified Scrum Product Owner (CSPO®) and Certified ScrumMaster (CSM®) certifications, bringing an agile approach to delivering and implementing clinical software.