128 - Data Integrity in QC (S9E8)
From Concept to Medicine - A Comprehensive Drug Development Journey
Uncover the high importance of data integrity in analytical labs, focusing on ALCOA+ principles and secure electronic systems. Learn what is meant by all of the above, the framework for quality and reliability, starting with attributable. Examine how it needs to be as trustworthy in systems, as it is to get it on paper, by securing controls. Gain insight into the purpose of audits, and look at how they prepare those responsible, along with reviewing potential consequences that would result from not fulfilling expectations.
Walk through practical tips on how to prevent data from disappearing, and how systems to prevent issues come about in the first place. Explore some areas and reasons that something could be problematic and why good and reliable practices are important for protecting the public. Gain insight into how all of this plays out into the work of the labs and helps to make sure that regulations are all fulfilled, while at the same time improving the quality for consumers.
Available Results
Generated results are saved to the knowledge database for reuse and search.
Extract Knowledge
Pick what you want extracted first. Model, scope, and chapter options appear after a template is selected.
Transcript
OK, so you've come to us with this idea for a deep dive. And this is a big one, right? Data integrity and analytical labs. So you shared some really interesting stuff with us. And I think our mission here is to really pull out. What matters most? Yeah, what are those like key things? You absolutely have to know about data integrity Yeah, especially when we're talking about quality control. Absolutely. So, you know, we'll dig into stuff like those ALCOA plus principles Everyone keeps talking about right? Yeah, and what about secure electronic systems? I mean those are everywhere now huge. Yeah, and Of course, we've got to talk about what the regulators expect because that's always top of mind, right? At the forefront. Yeah. And how labs stay audit ready. What does that even mean in practice? Yeah. And then, well, the big one, how do you actually prevent data from getting messed up or just disappearing? Oh, yeah. So that's kind of our roadmap for this deep dive. Yeah. And we're going to be focusing on a transcript. that digs specifically into QC Labs. So that's season nine, episode eight from a series you sent us, which was awesome by the way. Thank you. Yeah. So you ready to dive in? Let's do it. Okay. So let's start with like the really big picture here, right? Why is data integrity? I mean, that sounds kind of boring when you just say it like that. But why is it so crucial in these analytical labs? It's the foundation in everything. Yeah. Yeah. Like, what's actually at stake here? Well, think about it, especially in pharmaceuticals. The lab is basically the gatekeeper for quality. Right. I mean, everything they do, all that data they produce, it determines if a raw material is good to go, if a drug is potent enough, if a medicine stays stable on the shelf, you know, all that. It's way more than just like, you know, numbers on a page. Way more. It's about patient safety. OK, so that's a pretty powerful way to put it. So how do labs actually build that trust in their data? Like, how do they make sure it's rock solid? You always hear people talking about L -C -O -A plus bar, right? Yeah, L -C -O -A plus. It's not just a buzzword, it's the framework. Okay, so break it down for me. What does A -L -C -O -A plus actually mean? Okay, so each letter stands for a principle. Gotcha. Like a, you know, a quality check for your data. So first up, A, attributable. Basically, who did what and when. Makes sense. You need a clear record, like a trail you can follow right back to the person and the time. Okay, so like... A digital paper trail. Exactly. And, you know, regs like CFR 211 .28, they're all about that accountability. Right, right. CFR. Okay, so that's attributable. What's next? L is for legible. This one's pretty simple. Yeah, I think I can guess. The data has to be clear, right? Yeah. Easy to read, whether it's handwritten or on a computer. Yeah, no deciphering cryptic notes. Exactly. Then we have C, contemporaneous. OK, now that one sounds a little more complicated. It just means you record the data as it happens, right then and there. So no going back and filling things in later. Nope. The record has to reflect what happened in real time. No fudging the timeline, basically. Exactly. Then there's O, original. The data's got to be the first record, the source. Like the raw data, right? Exactly. No copies where mistakes can creep in. You got to stick with the source document. OK, that one makes a lot of sense. So we've got four down. What's the fifth one? Fifth is A. Accurate. This is kind of the heart of it all, right? Yeah, if the data is not accurate, what's the point? Exactly. Instruments got to be calibrated right. Methods followed perfectly. Calculations double checked. And if there is a mistake, you document it, investigate it, and correct it. No sweeping things under the rug. OK, so that covers ALCOA. But what about the plus? What does that add? Ah, the plus brings in some extra layers of making sure the data is really rock solid. OK, I'm intrigued. So the first C in the plus, that's complete. The record needs to tell the whole story, not just the final number. Oh, so it's like context, right? Exactly. You need the details, the parameters, the methods, any weird things that happened, everything. So you can really understand the entire picture. Yes. And then we have consistent. All the parts of the record need to make sense together, right? No contradictions or gaps. So it all lines up. It all flows logically. Exactly. Then there's enduring. This one's about the long game, keeping those records safe and sound for as long as you need them. So, no accidental deletions or lost files? Right. And then finally, available. You have to be able to actually find the data when you need it. So, good organization is key? Absolutely. Accessible, retrievable, all that good stuff. Okay, so LCOA plus phthors. That's pretty comprehensive. It covers everything from the initial recording to years down the line. Exactly. It's the gold standard. Now, labs are using electronic systems more and more these days for everything. What are some of the challenges or the things you really have to think about with data integrity when you're in that digital world? Well, electronic systems. They're great, right? Yeah, efficient. But they come with their own set of, you know, things you got to watch out for when it comes to data integrity. Yeah, like what kinds of things? Well, you need controls. You got to make sure that data is really secure. digital locks and keys. Exactly. Like, you know, who can access what? Who can change things? Who can delete stuff? Right, right. That makes sense. You know, it's kind of like, you remember in CFR 211 .28c how it talks about, you know, limited access areas? Yeah, yeah. It's kind of like that. But for computers, you know, logical security. Right, right. Digital security. So access control is a big one. What else is really important in these systems? Botta trails. Those are crucial. OK, now remind me, what's an audit trail exactly? So imagine like a detailed history of everything that happens to a data point. OK. Who changed it, what they changed, when they did it. It's all time stamped. So you can track every single change. Exactly. It's like a detective's dream, right? You leave a trail everywhere you go. And you can't really tamper with it. It's built into the system. OK, so that's a pretty powerful tool. Anything else that's really important for keeping things safe and sound in electronic systems? Yeah. Validation is huge. You've got to make sure those systems are actually doing what they're supposed to, you know, capturing data right, processing it right, storing it securely. And then, you know, just good old -fashioned backups, right? Yeah, everyone needs backups. And a plan for if things go really wrong, like a disaster recovery plan. So you can get back up and running quickly. Exactly. OK, so we've talked about LSEOA, plus we've talked about electronic systems. But who's actually setting the rules here? Like, who decides? what's good enough when it comes to data integrity in these labs. That's where the regulators come in, right? Yeah, the big guys. So, you know, in the U .S., you've got the FDA Food and Drug Administration. Right. They have very clear expectations and they don't mess around. Yeah, I bet. And there's this really important regulation, CFR Title 21 Part 11. Now, our transcript from season nine, episode eight, doesn't really get into part 11 specifically, but it's something you absolutely need to know about. Okay, so give me the rundown. What is part 11 all about? It's basically the rule book for electronic records and signatures. It lays out how to make sure those electronic records are just as trustworthy as a paper record. So it's bringing those old school paper rules into the digital age. Exactly. So whenever you think about electronic data in a regulated lab, think part 11. Got it. So part 11 is key. Now, what happens if a lab, you know, messes up? Like they don't follow the rules, they don't meet those expectations. What are the consequences? Well, let's just say the FDA has a whole toolbox, you know, depending on how bad things are. Oh, that doesn't sound good. Yeah, it can range from, you know, warning letters and extra scrutiny to full -blown product recalls, import alerts, stuff that can really hurt a company. Wow, so they're not playing around. Not at all. Because at the end of the day, if your data's not trustworthy, nobody's going to trust your products. Right, makes sense. So how do labs make sure they're always ready if the FDA comes knocking? That's audit readiness. Audit readiness. Okay. What does that actually mean in practice? It's not something you cram for, you know, the night before. Right. It's got to be a part of the culture. Exactly. It's all about having those procedures in place, clear, documented for every single thing you do. So everyone knows exactly what to do and how to do it. Right. And there's this thing called GXP. It stands for good practice. Okay. I've heard that GXP. It's like an umbrella term for all these guidelines, like, you know, GMP, good manufacturing practice. Right. Right. So, you know, the transcript mentions CFR 111 .8. It's specifically for dietary supplements, but the idea is the same everywhere. So clear instructions are key. What else is part of being audit ready? Well, you got to do your own internal audits, right? Check yourself before someone else checks you. Right. Find your own weak spots. Exactly. And maybe most importantly, train your people. Yeah. Make sure everyone's on the same page. Everyone needs to understand data integrity, why it matters, how to do it right. Okay, so it's procedures, it's self -checks, it's training. That makes a lot of sense. Now let's talk about prevention. Like, what can labs actually do to prevent data from getting messed up or lost in the first place? It's like a two -ponged approach. Procedural controls and technical controls. So like, what people do and what the systems do. Exactly. On the procedural side, you know, we've talked about SOPs, those clear instructions. Right. But there's also this thing called segregation of duties. Now that sounds interesting. What is that? So the idea is that no one person has complete control over, you know, a critical process or a data record. Okay. It's about checks and balances, right? Right. So you can't just, you know... go rogue and change everything without anyone noticing. Exactly. In CFR 211 .28, it talks about personnel responsibilities. It's all about making sure roles are clear and no one has too much power. Checks and balances. That's a good principle for a lot of things in life. Absolutely. Now, on the technical side, that's where you get into the nitty gritty of the system. OK, so what kind of stuff? Well, we've talked about access controls and audit trails. Those are big ones. But there's also electronic signatures, right? to make sure everything is properly authenticated. Right, like a digital fingerprint. Exactly. And then backups, backups, backups. You can't say it enough. You really can't. And that disaster recovery plan we talked about, that's crucial, too. So you're prepared for anything, basically. As much as you can be. OK, so you've got the procedures. You've got the technology. But what are some of the common traps, the things that labs... often get wrong even when they're trying to do things right. Oh, there are definitely some classic pitfalls. Okay, like what? Well, sometimes people try to take shortcuts, right? Yeah. Like backdating records or post -dating them, you know, to make things look like they happened when they didn't. Oh, to meet deadlines or, you know, make the data look better. Exactly. But that totally violates the contemporaneous principle of LCOA+. Right, right. So no fudging the timeline. No fudging. Another common one is copying and pasting data. Oh, yeah, that's tempting. Right. But it can introduce errors and it messes up the originality and accuracy of the data. So resist the urge to copy and paste. And then sometimes audit trails aren't detailed enough or they're just missing altogether. That's a big problem. Huge problem because then you can't track what happened. You know, you can't investigate if something looks suspicious. Right, right. And then another big one is lack of training. If people don't understand data integrity, they're going to make mistakes even if they're trying their best. Yeah, training is so important. Absolutely. And then you always have to worry about vulnerabilities in the systems themselves, right? Like hackers and stuff. Hackers, glitches, you name it. If someone can get in and mess with the data, that's a huge problem. So it's a mix of human error and system weaknesses that can really create a mess. Exactly. It's a constant battle. OK, so we've talked about all these principles and the potential pitfalls. Can you give me some, you know, some real world examples of how this actually plays out in a QC lab, like maybe a data integrity failure and then, you know, a successful fix? Sure. So our transcript doesn't have specific case studies from QC labs. OK. But let's imagine a scenario, right? You've got an analyst. They're testing a batch of raw material and the results don't meet the specs. Now, instead of following the procedure for out of spec results, They tweak the instrument settings and rerun the sample until it passes. So they're kind of, you know, making the data fit the requirements instead of the other way around. Exactly. And they don't document any of it. So the original data is gone and there's no record of the changes. That's a big no -no. Huge no -no. It violates accuracy, originality, completeness, the whole shebang. It could have real consequences, right, if that material ends up in a drug product. Absolutely. So now let's look at a lab that found a problem and fixed it. Let's say an FDA audit finds that their audit trails, while they exist, aren't being reviewed regularly enough. Oh, so they have the data, but they're not really using it. Exactly. So to fix this, they do a few things. They update their SOPs to make it clear who's responsible for reviewing audit trails and how often they build automatic reports into their system so the right people get those reports on a regular basis. So no one can, you know... forget to do it. Exactly. And they create a system for documenting the review process. So if they find a discrepancy, they document it, they investigate it, they fix it. So they're really closing the loop, making sure that data is actually being used. Exactly. That's how you build trust, right? Yeah. That makes a lot of sense. So as we wrap up this deep dive, what are those key takeaways you want our listeners to remember about data integrity? I think the most important thing is to remember that data integrity is not just about checking boxes for the FDA. Right. It's about doing good science. It's about making sure that the data you're producing is reliable, especially when it comes to, you know, things that affect people's health. Absolutely. LCOA plus Mo, that's your roadmap, right? You're guided. And secure electronic systems, those are crucial. Access controls, audit trails, all that stuff. And then, you know... Stay ahead of the game. Understand what the regulators expect. Be ready for audits. Have those procedures and systems in place. Be prepared. And train your people. Make sure everyone's on board with data integrity. It's a team effort. Absolutely. Because in the end, data integrity, it's about protecting product quality, and it's about keeping patients safe. That's a great way to put it. So we've covered a lot of ground here, and it really makes me think about... You know, what's next? Yeah, like technology is changing so fast. Analytical techniques are getting more complex. What's the future of data integrity? That's a great question. What about AI, right? Could AI help us monitor data in real time, you know, catch problems before they happen? That's definitely a possibility. Or blockchain, you know, to create those really secure. tamper -proof records. Blockchain is definitely making waves. Yeah, it's really fascinating to think about where all of this is going. So thanks so much for joining me for this deep dive. It's been really, really insightful. My pleasure. And for all of you listening out there, keep those questions coming. We'll keep digging into the stuff that matters. Absolutely. Until next time.