Written and maintained by CASRAI Editorial Board
Last updated
Most vendor material on barcode medication administration (BCMA) describes the scanner and the alert screen. That is the easy part — every major eMAR and pharmacy system ships one. What actually determines whether BCMA reduces harm at your hospital is the work that happens around the scan: how the bedside workflow is redesigned so scanning is the fastest path rather than an obstacle, how override reasons are captured and reviewed rather than just clicked through, and whether anyone is reading the override data closely enough to tell a legitimate clinical exception from a workaround that has quietly defeated the safety check it was meant to run. This guide covers that work.
Scope. This is a guide to implementing and governing a BCMA programme — workflow redesign, override-reason structure, and the specific override patterns in your own data that indicate a problem. It is written for patient-safety officers, quality directors, medication-safety pharmacists, nurse informaticists and risk managers who own or oversee the programme, not as a procurement comparison of scanning hardware or eMAR vendors.
What BCMA Actually Checks, and What It Doesn’t
BCMA is the point-of-care step in a closed-loop medication process: the nurse scans the patient’s wristband, then scans the medication package, and the system compares both against the active order in the eMAR before the dose is documented as given. It is commonly described as automating the “rights” of medication administration long taught in nursing and pharmacy education — right patient, right drug, right dose, right route and right time, with many programmes now adding right documentation, right reason and right response to the list. BCMA does not verify all of these on its own: it confirms identity and product match reliably, but dose, route and time checks depend on how completely the order was built and how the barcode master file was populated, not on the scan event itself.
Two properties follow from that, and they drive most of the implementation decisions below:
- BCMA is only as good as the barcode data behind it. A scan that fails because a product isn’t in the barcode master file, or because a repackaged unit-dose barcode wasn’t remapped after a manufacturer change, is not a clinical near-miss — it’s a data-maintenance gap that will generate an override every time until it’s fixed.
- The safety check happens at the moment of the scan, not before or after it. A workflow that lets nurses scan a batch of wristbands at a station, or scan the medication after it has already been given, has kept the documentation step and lost the verification step — the two look identical in an audit unless you check the timestamps and sequence.
Redesigning the Bedside Workflow, Not Just Adding a Scanner
The programmes that struggle are the ones that bolted a scanner onto an unchanged paper-era workflow. A few dependencies have to be worked out before go-live, not discovered after it:
- Unit-dose packaging coverage. BCMA depends on every dose arriving at the bedside individually barcoded. Multi-dose vials, compounded IVs, oral liquids poured at the bedside, and split or crushed tablets routinely fall outside standard unit-dose packaging and need an explicit local procedure — usually pharmacy-applied secondary barcoding — or they become a predictable, recurring override.
- First-dose and floor-stock exceptions. A newly ordered medication that hasn’t yet been through pharmacy verification, or a floor-stock item pulled from an automated dispensing cabinet outside the normal fill cycle, may not have a scannable barcode tied to that specific order yet. Decide the sanctioned path (an emergency-override code, a pharmacy-generated interim label, or a hold until verification) before nurses invent one themselves.
- PRN and titratable infusions. A single scan event maps poorly onto a titrated drip rate change or a PRN given against a range order. Many systems handle this with a separate “verify” versus “document” step; whichever pattern you use, make sure nursing understands which action the scan is actually performing.
- High-alert medication double-checks. Where an independent double-check is required (insulin, anticoagulants, concentrated electrolytes, chemotherapy), BCMA is a complement to that check, not a replacement for it — a clean scan on a wrong-rate infusion pump programming error will still pass, because the barcode confirms product identity, not pump programming.
- Downtime procedure. A paper fallback with its own patient-identification step, tested before go-live rather than assumed. If downtime defaults to “give the medication and document later,” you have built a permanent override pathway that only activates during your highest-risk moments.
Override-Reason Tracking: Building the Escape Valve So It Doesn’t Swallow the Check
An override capability is necessary — a system that hard-stops every failed scan with no way forward will get worked around in ways you can’t see at all, which is worse than a tracked override. The design question is whether the override captures a real, reviewable reason or just a click that clears the screen.
A workable override-reason structure has a small number of properties:
- Structured reason codes, not a free-text box alone. A closed list — barcode unreadable or damaged, product not in the barcode master file, product repackaged with a mismatched barcode, patient wristband unreadable or unavailable, emergency/STAT administration, system downtime, patient refusal after a successful scan — turns override data into something you can aggregate. Free text alone produces a report nobody reads.
- A required reason before the override completes, not an optional field that can be skipped, and no generic “other” option that becomes the default because it’s fastest to select.
- The reason feeds a report, not just the chart. If override reasons live only in the individual patient’s eMAR and nobody pulls them into an aggregate view by medication, unit, shift and individual, the structure exists but the governance doesn’t — see the next two sections.
- A route back to pharmacy or informatics for data-quality overrides. A “barcode not in system” reason should generate a work item, not just a log entry — otherwise the same product keeps failing indefinitely and the override becomes the permanent workaround for a fixable data gap.
The Override Patterns That Signal a Workaround, Not a Legitimate Exception
A hospital-wide override rate on its own tells you very little — it mixes genuine emergencies, data-maintenance gaps and actual workarounds into one number. The signal is in how overrides are distributed once you stratify by medication, unit, shift and individual staff member at the same time, the same way an early-warning-score threshold has to be checked by ward rather than hospital-wide. The patterns below are what to look for, and each one points to a different fix:
| Pattern in the override data | What it usually means | Where the fix lives |
|---|---|---|
| A small number of products account for a disproportionate share of overrides | A barcode-master-file gap or a packaging/print-quality issue with that specific product, not a clinical exception | Pharmacy barcode data maintenance, relabeling |
| Patient-wristband scans logged in a tight time cluster at a station or cart, not spread across bedside timestamps through a shift | Nurses pre-scanning duplicated or photographed wristband barcodes away from the bedside — this defeats patient verification entirely while still producing a “scanned” record | Workflow redesign; this is the highest-severity pattern and warrants direct observation, not just a data pull |
| Medication scanned but patient identifier not scanned for the same administration, or the reverse | A partial-verification shortcut under time pressure — often a scanner range, wristband placement, or device-availability problem | Device/workflow ergonomics review on the affected unit |
| Override rate concentrated in specific units or specific shifts rather than spread evenly | A staffing ratio, device-availability, or workload problem specific to that unit or shift, not a training gap | Staffing and device-count review for that unit/shift |
| Override rate concentrated in a small number of individual staff, sustained over time and not explained by their unit assignment | Possibly a training gap or a habitual bypass — but only once the systemic causes above have been ruled out | Individual coaching, run through a Just Culture lens rather than a punitive one |
| A sudden system-wide spike in overrides after an EHR upgrade, formulary change, or new product introduction | An integration break — orders not mapping to barcodes correctly, or a new product added without its barcode entry | IT/pharmacy informatics root-cause review, treated as an incident, not a clinical trend |
The second row is worth dwelling on, because it is the pattern most likely to be missed by a report that only counts overrides. Batch or “cheat-sheet” scanning — where a nurse scans a photocopied sheet of patient wristband barcodes, or a barcode taped to a workstation or medication cart, instead of the wristband on the patient — does not show up as an override at all. It shows up as a fully “compliant” scan. This is the pattern most consistently described in the health-informatics literature on BCMA workarounds (an oft-cited 2008 study by Koppel, Wetterneck, Telles and Karsh in the Journal of the American Medical Informatics Association catalogued this and related workaround types across multiple hospitals) — it is a genuinely different category from a tracked override, because the record looks clean. Detecting it requires looking at scan-event timing and location clustering, not the override log, and often requires direct unit observation to confirm what a data pattern only suggests.
Setting and Monitoring a Scan-Compliance Target
Scan compliance is conventionally defined as the proportion of medication administrations verified by a successful patient-and-medication scan, out of all administrations recorded — with the numerator excluding administrations completed by override. Two things matter more than the exact target you pick:
- Define the denominator before you report the number. Whether downtime administrations, floor-stock pulls, and patient-refused doses count in the denominator changes the headline rate substantially, and different reports quietly using different rules is a common source of disputed numbers at the quality committee.
- Track override rate and scan-compliance rate as a pair, stratified the same way. A hospital-wide compliance percentage that looks acceptable can still be hiding one unit or one shift where the real number is far lower — the same reason the pattern table above stratifies by unit and shift rather than reporting one aggregate figure.
The Leapfrog Group’s Hospital Survey is the most visible external benchmark that grades hospitals specifically on BCMA — both on the rate at which administrations are verified by scan rather than overridden, and on whether the system has specific error-prevention functionality (for example, whether it distinguishes and hard-stops a wrong-patient or wrong-drug scan rather than only logging it). This guide deliberately does not restate Leapfrog’s current published compliance-percentage threshold as a number: a same-session attempt to pull Leapfrog’s current BCMA fact sheet returned a 404 rather than the live document, and reproducing a specific percentage from memory without being able to confirm it against the current published survey specification would risk stating a stale or incorrect figure as current fact. Confirm the current threshold directly against Leapfrog’s published Hospital Survey materials before citing it in an internal policy document.
Illustrative arithmetic — assumed inputs, not measured data from any hospital. The value of a worked example here is the shape of the calculation, not the specific numbers; replace every input with your own figures. Assume a unit administers 200 doses a day and scan compliance runs at 97%, meaning 6 doses a day complete by override. If four of those six overrides are concentrated on a single injectable product, that product — not the unit’s nursing practice — is very likely the fix, and a report that only shows “97% compliance, stable” would never surface it. The stratification is what turns an acceptable-looking aggregate rate into an actionable finding.
Governance: Reviewing Override Data Without Turning It Into a Punitive Metric
Override and scan-compliance data is most useful, and safest to act on, when it runs through the same accountability discipline your programme already uses for other safety events:
- Route individual-level findings through the Just Culture algorithm rather than treating a high individual override count as automatically a performance problem — the pattern table above exists specifically because several systemic causes look identical to an individual training gap until you’ve ruled them out.
- Bring recurring product- or unit-level findings to the same forum that owns medication-safety review. Where your organisation already runs a medication use evaluation process and reports to a P&T committee, override patterns concentrated on a specific product belong in that same review, not a separate, disconnected report.
- Name the BCMA programme as a tracked initiative in your QAPI plan, with scan-compliance rate and stratified override rate as standing measures, reviewed on a defined cadence rather than only when a survey is imminent.
- A BCMA-related event severe enough to reach a patient — a wrong-patient or wrong-drug administration that occurred despite, or because of, a bypassed scan — follows your existing serious-event machinery: the sentinel event definition and review requirements, with aggregate learning surfaced at the M&M conference and, where the privilege applies, protected as patient safety organization work product.
Complementary defenses are worth naming rather than treating BCMA as a stand-alone control: tall man lettering reduces look-alike/sound-alike selection errors upstream of the scan, and BCMA sits inside the broader accountability and systems-thinking frame covered in high reliability organization principles. For the wider programme context, see the patient safety pillar.
Implementation Pitfalls
- Treating a hospital-wide compliance percentage as sufficient reporting. It hides exactly the unit-, shift-, product- and individual-level concentration that makes the number actionable.
- An override reason list with a fast, generic “other” option. It becomes the default answer and the report stops meaning anything.
- No route from a data-quality override back to pharmacy or informatics. A “barcode not found” reason that just logs and closes leaves the same product failing indefinitely.
- No downtime procedure tested before go-live. The gap gets discovered during an actual outage, at the worst possible time to be improvising one.
- Reading override counts as an individual performance metric first. Most of the patterns in the table above are systemic; starting with individual blame both misses the real fix and teaches staff to stop reporting honestly.
- Never checking scan-event timing and location. Batch or cheat-sheet scanning produces a clean compliance number precisely because it isn’t captured as an override — the workaround that matters most is the one your standard report can’t see.
Frequently Asked Questions
What does BCMA actually verify?
At the point of administration, it confirms that the patient identifier scanned and the medication product scanned both match the active order in the eMAR. It automates the identity and product-match checks that sit underneath the traditionally taught “rights” of medication administration; it does not independently verify dose calculation, infusion-pump programming, or clinical appropriateness on its own.
Is a barcode override always a safety problem?
No. A structured, reviewed override for a genuine exception — an unreadable barcode, a product not yet in the barcode master file, a true emergency administration — is the system working as designed. The concern is an override pattern that repeats for a fixable reason (a specific product, a specific unit, a specific shift) without anyone stratifying the data to notice, or a workaround that avoids generating an override at all.
What’s the difference between an override and a workaround?
An override is a tracked, reason-coded exception the system records. A workaround — batch-scanning duplicated wristband barcodes, scanning a medication after it has already been given, or scanning a barcode taped to a cart rather than the patient — produces what looks like a compliant scan while defeating the actual verification step. Workarounds are the harder problem precisely because they don’t appear in the override log.
How do we know if our scan-compliance rate is good enough?
A single hospital-wide percentage is a starting point, not an answer. Stratify by unit, shift, product and individual before drawing conclusions, and treat the aggregate rate the way you would treat an unstratified early-warning-score trigger rate — useful for a trend line, not for finding the fix.
Who should own review of override data?
Most programmes route it through the same governance that owns other medication-safety review — typically pharmacy/medication-safety leadership with quality and nursing informatics, feeding the same forum that runs medication use evaluation and reports into the QAPI plan — rather than as a stand-alone report nobody is accountable for acting on.
Does BCMA replace independent double-checks for high-alert medications?
No. A clean scan confirms product identity, not pump programming, dose calculation, or clinical appropriateness. Where an independent double-check is required for a high-alert medication, BCMA is a complementary control, not a substitute for it.
Sources and Verification Notes
- The Leapfrog Group publishes an annual Hospital Survey that includes a specific evaluation area for bar code medication administration, covering both scan-compliance rate and system error-prevention functionality. This guide does not quote Leapfrog’s current specific compliance-percentage threshold; a same-session attempt to retrieve the current published fact sheet returned a 404, so the exact current figure should be confirmed directly against Leapfrog’s own published Hospital Survey materials.
- ISMP (Institute for Safe Medication Practices) has published extensively on safe BCMA implementation and on preventing the specific workaround patterns described above; consult ISMP’s current medication-safety guidance directly for implementation checklists, since specific ISMP document titles and publication dates were not independently re-verified this session.
- Koppel R, Wetterneck T, Telles JL, Karsh BT, “Workarounds to barcode medication administration systems: their occurrences, causes, and threats to patient safety,” Journal of the American Medical Informatics Association, 2008 — an oft-cited early empirical catalogue of BCMA workaround types across multiple hospitals, including batch/duplicated-barcode scanning. Exact volume, issue and page numbers were not independently re-confirmed this session (PubMed access returned a cookie-consent page rather than article content); verify the full citation against the live JAMIA/PubMed record before using it in a citation list that requires exact pagination.








