GLI GLI Quality Tool
GLI Quality Tool — Version 2.0

Building A Resilient TB Laboratory Data Backup Plan

Electronic records are central to modern tuberculosis testing. A laboratory may rely on a laboratory information system, instrument middleware, shared drives, email, spreadsheets and cloud applications to manage specimens, results, quality control, staff training and reporting. If those systems become unavailable, the impact can extend from delayed patient care to lost evidence during an accreditation assessment.

A practical backup plan protects more than final test results. It should preserve the information needed to reconstruct what happened: specimen receipt times, culture and molecular testing data, antimicrobial susceptibility results, instrument logs, quality control trends, corrective actions and authorised reports. The plan also needs to work during power failures, ransomware attacks, hardware breakdowns, network outages and human error.

Australian laboratories face a wide range of operating conditions. A public pathology service in Sydney or Melbourne may have dedicated IT teams and high-speed connectivity, while a regional service in the Northern Territory or Western Australia may depend on slower links, limited local support and scheduled courier runs. A useful system must accommodate both settings rather than assume constant access to a central server.

The GLI Quality Tool offers a helpful quality management framework for this work. Its approach connects information management with equipment, personnel, documentation, assessment and continual improvement, making data protection part of routine laboratory practice rather than an isolated IT project.

Define Which Records Must Survive

Begin with an inventory of electronic information and assign each record a recovery priority. Patient identifiers, specimen accession numbers, test results and report histories normally require the highest protection. A laboratory should also identify quality control records, external quality assessment results, maintenance logs, calibration data, temperature records, stock registers, staff competency evidence, procedures, risk assessments and incident reports.

The inventory should show where each record lives, who owns it, how often it changes and how long it must be retained. Include information held on local computers, network folders, automated analysers, PCR platforms and removable media. Device-generated files can be easy to overlook, especially when an instrument stores runs internally or exports results in a proprietary format.

A checklist can help teams compare current controls with the quality system requirements. The GLI checklists provide a practical starting point for reviewing documentation, equipment, assessment and information-related processes. Adapt the review to the laboratory’s scope, whether it performs smear microscopy, culture, nucleic acid amplification testing, drug susceptibility testing or referral activities.

Do not rely on a single database export as the whole backup. A usable record may include the result, audit trail, report template, interpretation rules, operator identity and relevant quality control evidence. Retaining only a PDF report may protect communication with a clinician but leave the laboratory unable to investigate a disputed result or demonstrate how it was produced.

Map Risks And Recovery Needs

A risk assessment should examine realistic failure scenarios and the consequences of each one. Consider accidental deletion, malware, a failed server, a corrupted database, loss of internet access, fire or flood, theft of a laptop, power instability and an unavailable software supplier. Australian sites should also consider bushfire smoke, flooding and extreme heat, particularly where a small facility has limited alternative accommodation for instruments or servers.

For every critical system, define a recovery time objective and a recovery point objective. The first states how quickly the system must be available; the second states how much recent data the laboratory can afford to lose. A same-day reporting system may need recovery within hours, while archived training records may tolerate a longer interruption. These decisions should be made with laboratory management, clinical users, IT staff and the responsible pathologist.

The plan should include a manual fallback process for periods when electronic systems are offline. Use controlled paper forms or an approved downtime template to record patient and specimen identifiers, tests requested, results, authorisation and transfer details. Number the pages, restrict access and reconcile every handwritten entry with the electronic record after restoration. A simple downtime pack stored near specimen reception can be more useful than an elaborate plan that staff cannot access during an outage.

Remote facilities need special attention. If a service in Alice Springs, Broome or another regional location loses its network connection, staff may need local encrypted storage and a secure method for later synchronisation. The procedure should state who can approve temporary reporting, how urgent results are communicated and how duplicate records are prevented when the connection returns.

Build A Secure Backup Architecture

A robust arrangement usually follows the three-copy principle: retain the live record, create a separate backup and keep another copy in a different location or environment. At least one copy should be offline or protected from routine network access so that ransomware cannot encrypt every version at once. Backups should be automatic where possible, but automation must be monitored rather than assumed to be working.

Use more than one storage destination, such as a protected local backup appliance and an encrypted cloud repository hosted in an appropriate Australian region. The local copy can support rapid restoration after a software error, while the separate copy provides resilience after fire, flood or a major cyber incident. Review the provider’s retention, encryption, access control, service availability and data residency terms before approving a cloud service.

Apply role-based access and multi-factor authentication to backup administration. Separate backup operators from users who can delete or alter production records. Keep administrator accounts unique, review them regularly and remove access promptly when a staff member changes role. Encryption should protect data during transfer and storage, with recovery keys held under controlled governance rather than in the same system being protected.

Instrument data deserves a defined export format and schedule. For example, a TB laboratory might preserve raw run files, interpreted results and quality control summaries at the end of each reporting cycle. Microscopy records should include the method, reader, date, result and any measurement evidence. Guidance on calibrating microscope eyepieces can support consistent measurement records when ocular micrometers are used.

Test Restoration And Maintain Control

A backup is only valuable if the laboratory can restore it accurately. Schedule restoration tests using a representative sample of records, not merely a check that a file exists. Verify that restored data opens correctly, links to the right specimen, retains timestamps and audit information, and can be used by authorised staff. Test both a single-record recovery and a full-system recovery.

Record the outcome of every test, including the date, systems tested, data recovered, time taken, problems identified and corrective actions. A failed restoration should be treated as a quality incident, with an owner and due date. Repeat the exercise after major software upgrades, changes to the network, relocation of equipment or changes in the backup provider.

Procedures should make responsibilities clear. The laboratory manager may approve priorities, IT staff may restore systems, senior scientists may verify technical records, and authorised personnel may release delayed results. Include contact details for internal support, software vendors, telecommunications providers and relevant emergency services. Keep an offline copy of essential contacts because the laboratory may be unable to reach its normal directory.

Continual improvement matters as much as initial design. Review backup performance, unsuccessful jobs, restoration times, downtime incidents and staff feedback during management review. The GLI Quality Tool’s Phase 4 guidance is relevant here because sustained improvement depends on monitoring, corrective action and periodic reassessment rather than a one-off compliance exercise.

Practical Safeguards For Daily Operations

The following actions can turn a broad policy into an operational control system:

Staff should know what to do without waiting for an IT specialist to explain the first step. Place a concise outage procedure at specimen reception, in the molecular testing area and wherever results are authorised. Use plain language, identify escalation thresholds and specify when staff must stop reporting electronically or move to controlled manual records.

Australian privacy obligations should also shape the design. Patient information should be collected, stored, transmitted and destroyed in accordance with applicable organisational policy, the Privacy Act 1988 and relevant state or territory requirements. A laboratory purchasing a backup service should verify how the vendor handles subcontractors, support access, breach notification and deletion at the end of the contract. Keeping data in an Australian cloud region may assist governance, but location alone does not replace access controls or monitoring.

A backup plan should be visible during an assessment and useful during an emergency. Store approved procedures, test evidence, risk assessments and corrective actions in a controlled document system, while retaining a secure offline copy of the instructions needed to recover that system. Review the plan whenever the laboratory adds a platform, changes its information system, expands testing or moves to a new service model.

Protecting TB records is a patient safety activity as well as a technical task. A well-designed arrangement preserves the chain of evidence from specimen receipt to authorised result, supports continuity when infrastructure fails and gives staff a reliable path back to normal operations.

Start by listing the systems and records that would cause the greatest harm if lost today. Assign owners, set recovery priorities, create a protected second copy and schedule the first restoration test. Then bring the evidence into the laboratory’s quality management review so data resilience becomes a maintained part of routine TB service delivery.