Audit-Ready Wound Photo Metadata: Timestamps, Compression, and Chain of Custody
compliance
How image metadata — timestamps, compression, and chain of custody — determines whether a wound photo survives a Medicare audit.
In an audit, the photo is only half the exhibit. The metadata around it decides whether the image counts as evidence or gets thrown out.
The four attributes auditors look for
- Contemporaneous timestamp — captured at the point of care, not backfilled.
- Patient and encounter binding — image ID tied to MRN and visit, not a floating filename.
- Integrity — no post-hoc edits to pixels or measurements.
- Provenance — device, user, and location captured automatically.
Why raw phone photos fail
A JPEG in a camera roll strips or spoofs most of this. EXIF data can be edited, filenames are meaningless, and there is no cryptographic link back to the encounter. Auditors know this — which is why images pulled from personal devices are routinely disallowed.
What automated capture stores
Every WoundScribe capture is compressed server-side into a lossless clinical format, tagged with encounter ID, and time-stamped from a trusted clock rather than the phone's local time. The measurement polygon is stored alongside the pixels so any reviewer can recompute area from the original evidence.
Chain of custody for skin substitutes
Under the 2026 CMS rule for skin substitutes, coverage hinges on proving measurable non-healing over standard care. That proof is a sequence of images with unimpeachable metadata — not a folder of screenshots.
How this connects to claims
WISER claims and compliance packages the image, metadata, measurements, and coding evidence into a single defensible bundle at claim submission, so the audit response is already assembled the day the encounter closes.