Management of controlled medicines. Let’s imagine that tomorrow morning, in a hospital ward, the stock count doesn’t add up: two vials of an injectable opioid are missing. How long would it take to establish who had physical access to that medicine, during what period, under what authorisation, and with what record? If the answer can be established within a few hours using documents that already exist, it is a safety measure. If it takes days, involving questioning people and relying on their memory, it is a system that has passed a few inspections unscathed without ever having to withstand a real-life incident.
The question is more pressing today than it has been for years. The North American synthetic opioid crisis has shown that fentanyl and its analogues are not a problem confined to the illegal market: part of the problem originates within the legal healthcare system and finds its way out through theft, complacent prescribing and residues that are never properly disposed of. It is against this backdrop that the Ministry of Health has drawn up the National Prevention Plan against the misuse of fentanyl and other synthetic opioids, and against which the draft ministerial decree – not yet published – should be read; this updates the security, storage, traceability and management of these medicines in public and private healthcare facilities.
Those involved in healthcare safety are used to designing safeguards against error. But error is a predictable adversary: it does not study the defences nor does it deliberately circumvent them. Diversion, however, does. The diversion of medicines from the legal supply chain has an intentional element; those who carry it out know the procedure better than those who wrote it: they know what time the count takes place, they know which document nobody ever reconciles, they know that the excuse of an accidental break is difficult to verify. A barrier designed solely to prevent misappropriation – against her – serves little purpose.
There is also an aspect that receives less attention than it deserves. In a significant proportion of cases, the person involved is a healthcare professional, almost always someone who is competent and held in high regard by their colleagues: this is why the matter is sensitive on a human level too. Shortfalls tend to be interpreted as accounting errors precisely because the alternative is too unthinkable to contemplate, and this collective protection delays detection by months. A system of impersonal checks, applied consistently to everyone, does more than just uncover irregularities: it relieves individuals of the burden of having to suspect a colleague and intervenes before the damage becomes irreversible for the patient, the professional and the organisation.
Italian legislation on narcotics in hospitals has deep-rooted foundations: from Presidential Decree 309/1990 to subsequent implementing decrees, such as the introduction of the ward intake and discharge register (Ministerial Decree of 3 August 2001), the regulations governing purchase vouchers and computerised recording (Ministerial Decree of 18 December 2006 and Ministerial Decree of 3 August 2006) and the subsequent simplifications introduced by Law 38/2010.
The limitation of that framework was not its strictness, but its fragmentation: specific requirements, each of which was correct, without an organisational body to ensure their overall coherence. The draft addresses precisely this, and its greatest contribution is not an additional requirement: it is a change in approach.
The text requires organisations to have a single corporate procedure single, binding on all departments, approved by the healthcare management and validated by senior management, which brings together responsibilities and stand-ins, custody, credentials and access, handling, checks, emergencies, reporting and training; it calls for this to be reviewed not at the end of its natural term, but whenever something occurs: critical incidents, non-compliance, or the results of inspections. It is the shift from a document that describes to one that learns and its uniqueness, with validation at the highest level, is not a mere formality, because it is the coexistence of misaligned local instructions that ultimately makes the discrepancies irresolvable.
Everything else revolves around this central principle, and it is a system of safeguards rather than a list of obligations. The chain of responsibility is constructed without any gaps: the pharmacy manager — or, where there is no pharmacy, the medical director — are responsible for procurement, receipt, safekeeping, internal handling and stock management, together with the supervision of operational units, whilst within the ward, organisational responsibility remains with the head nurse and safekeeping is entrusted to the nursing coordinator. Delegation is permitted, but must be named, for individual activities, time-bound and traceable: generic delegations of supervision and custody are expressly invalid. Anyone with experience of litigation knows how significant this clarification is, because a generic delegation is the means by which, in retrospect, responsibility is spread amongst many and does not rest with any one person. The same logic underlies the transfer, by written document, of custody duties at shift change: responsibility is neither interrupted nor diluted; it is passed on — and this handover leaves a trace.
Physical barriers are described in detail — areas not accessible to the public, separation from other medicines, safe specifications, CCTV and controlled access in accordance with data protection regulations — but the part that most often fails in a hospital is not the steel: it is the keys and credentials, for which direct custody is required, along with a record of every handover including date, time, the person handing over and the recipient, and a ban on unauthorised copies and the sharing of personal credentials. The informal sharing of passwords almost never stems from any unlawful intent: it stems from urgency, from friction with the actual pace of work, and from authorisation profiles that have not been updated following a transfer. The problem is that it retroactively nullifies the entire traceability, because from that moment on, the system no longer identifies an individual but a group.
With regard to documentation, the draft consolidates the move towards electronic recording already provided for in the 2010 decree, mandating authentication, user profiling, archiving, traceability of amendments, operational continuity and backup copies, and requiring that any corrections to the register ensure the original data remains legible, including the author, date and reason. One seemingly minor provision deserves attention: in the event of system unavailability, a business continuity procedure is activated, followed by full reconciliation. This is where digitisation truly breaks down, because the downtime of the management system results in fallback paper records that nobody re-enters, or that are re-entered in bulk without individual attribution. It is advisable to define this form in advance: who completes it, within how many hours it must be reconciled, and who certifies the reconciliation.
Stock checks are where the risk management framework is most evident. The reconciliation of physical and book stock is carried out every forty-eight hours — seventy-two hours if the deadline falls on a public holiday — and, in continuous-operation units, coincides with each handover of custody responsibility. This is an elegant solution, because it aligns the moment when responsibility changes hands with the moment when the status of the goods is verified, eliminating the grey area where a shortfall could be attributed equally to either of two shifts. But these intervals must be understood for what they are: the window within which an event remains undetected. By counting every two days, the number of people who have had access in the meantime makes reconstruction almost impossible; by counting at every handover, the window is reduced to a single shift. The frequency of the count does not fulfil an obligation: it determines how reconstructible the event will be.
Consistent with this approach is the handling of anomalies. Any unjustified discrepancy, tampering, unauthorised access, suspected fraudulent entry, theft or misappropriation ceases to be a mere accounting matter and becomes a critical incident, to be reported to the person in charge within twelve hours, followed by an extraordinary audit, securing of premises and systems, preservation of documents and digital data, reconstruction of the chain of custody, filing of legal complaints and reporting to AIFA for inclusion in the European MEDI-THEFT database, which is also accessible to the Carabinieri Command for the Protection of Health and the Central Directorate for Anti-Drug Services. It is an incident response protocol: contain, preserve evidence, reconstruct, notify. And the twelve-hour deadline is not a mere formality, because access logs and CCTV footage have limited retention periods: a late report arrives when the evidence no longer exists. It is therefore advisable to link this channel to the incident reporting system within the organisation, so as not to create two parallel tracks that are bound to produce incompatible reconstructions.
The system is rounded off by supervision and training, which are still focused on continuous improvement rather than mere compliance. Inspections take place at least every six months and become at least quarterly where non-conformities have already been identified: supervision is based on the observed risk, not on a fixed schedule. The findings are recorded in a report, setting out the required actions, the person responsible for corrective action and the deadline, whilst monitoring is based on indicators of stock accuracy, timeliness of records, completeness of documentation, and discrepancies and anomalies in consumption — though these are only useful if they have a threshold, a designated person responsible and a consequence. As for training, the most significant decision is that access to medicines and systems is restricted to trained and authorised personnel, with verification of learning outcomes and a register of authorisations: no longer just a course, but a qualifying requirement. Those who are not authorised are denied access — which means that the register of authorisations and IT profiles must be kept up to date even when a shift needs to be covered at short notice.
The hospital pharmacy, in all this, is not the system’s warehouse: nor is it the control centre. It is the only point that has both an overview of aggregate consumption and a longitudinal view of the wards, and is therefore the only one capable of interpreting a request – which, taken in isolation, would seem plausible – as a signal. Checking that requests, consumption and stock levels match before delivery – barring documented clinical emergencies – acts as an upstream barrier, and costs infinitely less than any downstream investigation. This is linked to transport regulations, involving sealed containers and verification of the seal before opening: the numbered seal does not prevent anything, but it pinpoints when any tampering may have occurred and who was in possession of the container at that time. It is a barrier of attribution, exactly what is needed for reconstruction.
When the medicine leaves the pharmacy, the risk does not disappear: it simply changes location and becomes harder to detect. On the ward, the barriers are mainly organisational — who opens the packaging, who counts it, who records it, who hands it over at the end of the shift, who returns it — and the point of greatest tension is the operating theatre. The draft does not lay down specific rules for the operating theatre, and it would be incorrect to attribute such rules to it: it is the operating theatre’s organisational characteristics that make the organisational procedure more demanding. High volumes of opioid handling, multiple professionals working on the same patient, changes in responsibility during the same session, opened and split packs, residues, medicines dispensed but not used, and emergencies in which record-keeping necessarily follows the clinical procedure. The quantity dispensed, the dose recorded in the anaesthesia record, the residual amount disposed of and the quantity returned must balance, but they appear in different documents, completed at different times by different people. It is here that the procedure must specify, without any room for interpretation, who carries out the reconciliation, when, with what evidence of the disposal of the residue, and with which second signature: otherwise, the inherent difference between the dose withdrawn and the dose administered becomes a permanently unverifiable area.
The final provisions make explicit what was already established in the medico-legal context: the absence or inadequacy of procedures is significant in supervisory activities, and any breach of the provisions of the decree will also be assessed for the purposes of criminal liability. Failing to prevent an event that one has a legal duty to prevent is equivalent to causing it. Organisations are granted ninety days from the date of publication: enough time to rewrite a document, but barely enough to redesign a system.
It is therefore worth using those ninety days to ask the right question, which is not ‘are we compliant?’ but ‘if a discrepancy were to emerge tomorrow, would we be able to reconstruct what happened?’. Answering this means tracing the medicine’s journey from the moment it enters the pharmacy until it is administered or disposed of, asking at each stage what safeguards are in place and what happens when they fail. Because a medication procedure provides a snapshot of the process.


