[ HOW-TO GUIDE ]

How to Investigate a Data Integrity Breach

Scope a breach honestly, including what it means for product already released.

What a how-to is not

A how-to is SPEQ’s practitioner method, not a procedure. It does not replace your own SOP, it is not a validated approach, and the judgement calls in it belong to your quality unit.

A data integrity investigation differs from an ordinary deviation investigation in one decisive way: you cannot assume the records are true. The evidence you would normally reason from is the thing under question, and the scope is never the incident found — it is every record the same person, system or practice could have touched. Investigations that stay narrow are the ones that get reopened by an inspector.

THE STEPS
  1. 1

    Secure the evidence before anyone is interviewed

    Take control of the systems, audit trails, logs and paper records first. Evidence is most at risk in the interval between someone realising there is an investigation and the records being secured, and that interval is created by the investigator.

  2. 2

    Scope by what could have been affected, not by what was found

    The boundary is every record the same individual, system, instrument or practice could have touched over the plausible period. Scoping to the discovered instance is the defining failure of these investigations, and it is what causes them to be reopened later.

  3. 3

    Distinguish error from falsification without deciding in advance

    Poor practice, inadequate training, a system deficiency and deliberate falsification lead to very different responses, and the evidence has to determine which. Assuming error is comfortable and assuming falsification is unfair — both prejudge the finding.

  4. 4

    Assess the impact on product, patients and submissions

    Determine whether released product, clinical decisions, or data already submitted to a regulator were affected. This is the question that matters most and the one most often deferred, because its answer may require a field action or a notification.

  5. 5

    Address culture as well as the control

    Ask why the practice arose. Unrealistic targets, understaffing, a system that made the compliant route impossible, or fear of reporting a failure all produce data integrity problems that no additional control corrects. A technical fix on a cultural cause reproduces the problem elsewhere.

  6. 6

    Notify where the obligation or the circumstances require it

    Where submitted data or released product is affected, consider the reporting obligations and the case for voluntary disclosure. Regulators respond very differently to a firm that found and disclosed a problem than to one where they found it.

USE THE TEMPLATE
Data Integrity Breach Investigation Report
Skip the blank page — start from SPEQ’s structured, regulator-aligned template for this procedure. Open the template →
COMMON PITFALLS
  • !Interviews conducted before systems, audit trails and records were secured.
  • !Scope limited to the instance discovered rather than everything the same cause could have touched.
  • !Error assumed rather than determined, so a falsification investigation never happens.
  • !A technical control added over a cultural cause, which reproduces the problem in another area.

How to Investigate a Data Integrity Breach: frequently asked questions

Common questions on investigate a data integrity breach.

How wide should the scope be?

As wide as the cause could reach — every record the same person, system, instrument or practice could have affected, over the period it plausibly operated. Narrow scoping is the characteristic failure here, and an inspector who finds an instance outside your boundary will reopen the whole investigation.

What if the investigation points to deliberate falsification?

Then the response changes: the impact assessment widens considerably, human resources and legal involvement becomes appropriate, and disclosure needs serious consideration. What you cannot do is decide the answer in advance — assuming error is comfortable and assuming falsification is unfair, and both prejudge the evidence.

Should a regulator be told?

Where released product or submitted data is affected, reporting obligations may require it and voluntary disclosure is usually worth serious consideration regardless. The difference in regulatory response between a firm that found and disclosed a problem and one where the inspector found it is substantial and durable.