There are new requirements for pharmacy drug management again.
Release date:
2020-07-03
Source: Pharmacy Manager
The National Medical Products Administration has issued a document outlining new requirements for pharmaceutical record-keeping and data management in pharmacies.
Pharmacy drug management has new requirements again.
To implement the relevant provisions of the *Drug Administration Law* and the *Vaccine Administration Law*, and to strengthen the recording and data management of activities related to drug research, production, distribution, and use, the National Medical Products Administration (NMPA) issued the *Requirements for Drug Records and Data Management (Trial)*—hereinafter referred to as the *Requirements*—on July 1. These requirements will come into effect on December 1, 2020.

(Image source: Screenshot from the National Medical Products Administration)
According to the "Requirements," records and data generated during pharmaceutical research, production, distribution, and use activities conducted within the territory of the People's Republic of China must be provided to the drug regulatory authorities and are subject to these requirements. Meanwhile, personnel responsible for managing these records and data should undergo necessary training to master the relevant management guidelines and operational skills, as well as adhere to professional ethical standards.
Data refers to information generated during the research, development, production, distribution, and use of pharmaceuticals, reflecting the status of these activities. This includes text, numerical values, symbols, images, audio, photographs, charts, barcodes, and more. Records, on the other hand, are documents formed by one or more data points recorded during the aforementioned activities, serving as evidence that captures both the process and outcomes of these related operations.
The "Requirements" clearly state that activities involving drug research, development, production, distribution, and use must, according to the needs of each activity, employ one or more types of records to ensure that all-process information remains authentic, accurate, complete, and traceable. Record formats may include paper-based, electronic, or hybrid systems—either individually or in combination—as specified below.
It should be noted that when using computerized systems to generate records or data, appropriate management measures and technical safeguards must be implemented to ensure the information produced is authentic, accurate, complete, and traceable.
Paper Record Management Requirements
1. The design and creation of record documents should meet practical purposes, with formats that are easy to identify, record, collect, store, trace, and utilize. Moreover, the content must be comprehensive, complete, and accurately reflect the corresponding activities.
2. Responsibilities for reviewing and approving documented records should be clearly defined, along with explicit management requirements for ensuring the effective version of each record is used, thereby preventing the use of invalid versions.
3. The printing and distribution of record documents should be carried out using controlled methods commensurate with the importance of the records, depending on their different purposes and types, to prevent substitution or tampering of the records.
4. The responsibility for clearly recording data must not be arbitrarily delegated to others, and approved tools or methods that ensure long-term preservation and resistance to removal must be used. Original data should be recorded directly onto the designated records, and no temporary notes or transcriptions on uncontrolled media are permitted.
5. Any changes made to the record should be annotated with the name of the person making the modification and the date of the change, while ensuring that the original information remains clear and legible. If necessary, the reason for the change should also be explained.
6. The collection time, archiving method, storage location, retention period, and management personnel for records should be clearly defined, and appropriate preservation or backup measures must be implemented. The retention period of records must comply with relevant regulatory requirements.
7. Appropriate measures should be taken when using and copying records to prevent loss, damage, or alteration. When duplicating records, procedures for approving, distributing, and controlling copies must be established, clearly distinguishing between original documents and photocopies.
8. Appropriate methods for record destruction should be identified, and corresponding destruction records should be established.
Electronic Record Management Requirements
1. Computerized systems that use electronic records should meet the following facility and configuration requirements:
(1) Install in an appropriate location to prevent interference from external factors;
(2) Servers or hosts that support the system's normal operation;
(3) A stable and secure network environment, along with a reliable information security platform;
(4) Establish a local network environment that enables information transmission and data sharing among relevant departments and between different job roles;
(5) Application software and related databases that comply with relevant legal requirements and regulatory needs;
(6) Terminal devices and associated equipment capable of performing recording operations;
(7) Technical documents such as operation manuals and drawings for the supporting systems.
2. Computerized systems that use electronic records should at least meet the following functional requirements:
(1) Ensure the authenticity, accuracy, and consistency of recorded time with system time;
(2) Capable of displaying all data from electronic records, with the generated data being readable and printable;
(3) System-generated data should be backed up regularly, and the backup and recovery procedures must be verified. Additionally, there should be corresponding records documenting both the backup and deletion of data.
(4) When the system undergoes changes, upgrades, or retirement, measures must be taken to ensure that original system data can be reviewed and traced within the prescribed retention period.
3. Electronic records should implement operation permission and user login management, including at least:
(1) Establish separate permissions for operations and system administration. The user permissions of business process owners should align with their assigned responsibilities and must not include administrative privileges for the system (including the operating system, applications, databases, etc.).
(2) Features user permission settings and allocation, enabling tracking and querying of permission modifications;
(3) Ensure the uniqueness and traceability of logged-in users; when using electronic signatures, such signatures must comply with the relevant provisions of the "Electronic Signature Law of the People's Republic of China."
(4) Relevant information regarding system operations should be recorded, including at a minimum the operator, operation time, operational process, and reason for the action; as well as details about data generation, modification, deletion, reprocessing, renaming, and transfer. Additionally, any changes or modifications made to the computerized system’s settings, configurations, parameters, and timestamps must also be documented.
4. The validation program for computerized systems employing electronic records should determine the scope and extent of validation based on multiple factors, including the system’s underlying architecture, system functionalities, business processes, as well as the system’s maturity level and complexity, ensuring that the system functions align with their intended purpose.
Data Management Requirements
1. For basic information data of the activity, as well as behavioral activity data generated through operations, inspections, verifications, manual calculations, and other actions, the relevant operating procedures and management systems shall specify requirements for recording personnel, recording time, recorded content, and the methods for confirmation and review.
2. When reading data from measuring instruments, the instruments must be verified or calibrated in accordance with the law.
3. Electronic data obtained through collection, processing, and reporting by computerized systems should be protected with necessary administrative measures and technical safeguards:
(1) Electronic data obtained through processing by application software after manual input should be protected against unauthorized changes to software functions and settings. Additionally, both the input data and the system-generated data must undergo thorough review, and the original data should be stored in accordance with relevant regulations.
(2) Electronic data generated after being collected and processed by a computerized system must comply with the relevant regulatory requirements. Metadata should also be properly preserved and backed up, and the backup and recovery procedures must undergo verification.
4. Other types of data refer to information stored in formats such as documents, images, audio files, pictures, and charts. Other types of data that meet the following conditions shall be deemed to satisfy the requirements specified herein:
(1) Able to effectively present the contained information and readily accessible for retrieval at any time;
(2) When data formats are converted, it must be ensured that the converted data remains consistent with the original data.