Audit-Ready Wound Photos: Metadata, Timestamps, and Chain of Custody
compliance
What Medicare auditors actually look for in wound imaging — and how to make sure every photo holds up in a records request.
A wound photo is only useful if it survives an audit. Medicare and commercial payers increasingly expect verifiable capture time, unaltered pixels, and a clear chain of custody from the point of care to the chart.
What auditors look for in a wound image
- Capture timestamp that matches the encounter, not the upload time.
- Device and user attribution — who took the photo, on what device.
- Untouched original — no cropping, filters, or re-compression before chart entry.
- Anatomical location and laterality visible or tagged.
- Scale reference so measurements can be reproduced.
Why phone camera rolls fail
Consumer photo apps re-compress on upload, strip or rewrite EXIF, and sync through personal cloud accounts. The result: a JPEG with an ambiguous timestamp, no user attribution, and no defensible path from patient to record. That's the exact scenario denials get built on.
What a defensible capture pipeline looks like
- Photo is taken inside the clinical app, not the camera roll.
- Timestamp, GPS (if in-home), device ID, and user ID are written at capture.
- Image is hashed and stored as an immutable original; edits create a derivative, never overwrite.
- All views and exports are logged.
- Metadata travels with the image into the chart and the claim.
AI-powered wound imaging is built around this pipeline, and the full metadata and chain-of-custody deep dive walks through each layer.
How this pairs with claims defense
Image metadata is only half the audit story — the note, measurements, and codes have to line up. WISER claims and compliance reconciles image, note, and claim so a records request pulls a coherent packet, not a scavenger hunt.
The short version
If you can't prove when the photo was taken, who took it, and that no one touched the pixels, it's not audit-ready — regardless of image quality.