Clinical trial data management is the work of gathering, cleaning, querying, and locking study data so the file the statisticians open is accurate, attributable, and complete. It is the quality-control system behind “is this treatment safe and effective” — not the analysis itself.
If you meant analysing the locked dataset (stats / SAP / SDTM) → clinical trial data analysis. If you meant healthcare data management (EHR / silos) → healthcare data management. If you meant CRM → healthcare CRM solutions. If you meant APIs → API for healthcare. If you meant HIPAA transfer → HIPAA-compliant data transfer. If you meant clinical decision support → what is clinical decision support.
This page is the what-is / how-to-choose explainer. It is not a ranked CDMS / EDC / CTMS list. PYCAD does not sell a CTMS, an EDC, or a CDMS.
Four pillars
| Pillar | What it is | Goal |
|---|---|---|
| Collection | eCRFs, wearables, diaries, lab feeds | Complete raw data as the protocol specified |
| Validation and cleaning | Automated checks plus query resolution | A dataset free of correctable errors before lock |
| Storage and security | Central system, access control, audit trail | Confidentiality and GCP / 21 CFR Part 11 |
| Lock and hand-off | Final clean file, read-only, to biostats | A verifiable dataset for analysis and submission |
Query management, then lock
Data arrive messy: a blood pressure typed as 12/8, a follow-up dated before screening, a missing lab. Automated edit checks catch the obvious at entry. Query management is the formal loop for the rest: a data manager flags the problem, the site investigates against source, the correction (or a documented reason) comes back, the query closes. That conversation is the audit trail.
Before lock: a last review, SAE reconciliation against the safety database, MedDRA / WHODrug coding so “heart attack” and “MI” are the same term, and a check that every change is attributed.
Two lock states, stolen from the “in” skin of this same job:
- Soft lock — a temporary freeze so the team can do a final pass. Reversible if a last check finds a hole.
- Hard lock — the point of no return. Further edits need a formal, documented unlock. This is the file analysis uses.
RBQM, not 100% SDV
Not every field is worth the same inspection. Risk-based quality management (RBQM) puts the energy on data that can move safety or the primary endpoint, instead of a 100% source-data verification (SDV) pass that buries a real signal in trivia.
| Traditional | Risk-based | |
|---|---|---|
| Verification | 100% SDV on every point | Targeted SDV on critical data and primary endpoints |
| Review | Every field equal; query flood | Prioritised by safety and trial integrity |
| Monitoring | Mostly on-site, after the fact | Central + remote + targeted on-site |
| Risk | Informal, after something breaks | Named at protocol time, watched from day one |
KPIs that are not vanity
Query count alone is not a quality story. The useful numbers connect cleaning work to whether the trial can be believed and finished on the date you promised.
| KPI | What to watch | Why it matters |
|---|---|---|
| Critical-data error rate | Errors on primary-endpoint and safety fields | Those fields are what analysis and inspectors will use |
| Query cycle time | Entry → query → site resolution | A backlog here is a lock delay |
| Site query rate | Queries per data points, by site | Flags a site that needs training, not a louder dashboard |
| Timeline adherence | Actual lock vs the date you forecast | Predictability is what sponsors budget against |
GCP, 21 CFR Part 11, and the DMP
Good Clinical Practice is the international rule for trials in people: rights, safety, a reconstructable record. 21 CFR Part 11 is the FDA rule that makes electronic records and signatures as trustworthy as paper — access control, validated systems, a computer-generated time-stamped audit trail. GDPR (and HIPAA on the US care side) govern who may see the identifiers.
The data management plan (DMP) is the living blueprint: sources, validation rules, who queries what, how lock happens. Write it before first patient in. Standardise units, eCRF wording, and dictionaries so Boston and Berlin are the same dataset, not two dialects.
EDC vs CDMS vs CTMS
People mash the three names. They are not the same product.
An EDC (electronic data capture) is the front end: the eCRF the coordinator types into. A CDMS (clinical data management system) is the back end that stores, validates, queries, codes, and prepares the lock. The EDC is often a module of the CDMS — smartphone vs the cloud it syncs to, not two brands you must pick between.
A CTMS (clinical trial management system) is operations: enrolment, monitoring visits, supplies, budget, milestones. If the EDC is the factory floor where the data are made, the CTMS is the control tower. Connect them so logistics and clinical data share a picture. Neither is a PYCAD product.
| EDC | CTMS | |
|---|---|---|
| Job | Factory floor — capture the clinical data | Control tower — run the trial |
| Holds | eCRF values, queries, audit trail on those values | Sites, enrolment, visits, supplies, budget |
| Users | Coordinators, data managers, monitors on the data | Project managers, CRAs, sponsor ops |
Unified platform vs best-of-breed
One vendor suite (EDC + ePRO + eConsent in one login) vs a stack of specialists. Unified: data moves without a custom pipe, one support number, one UX. Best-of-breed: stronger at each job, more integration work, more contracts. Pick the one your team can actually operate. Scale (Phase I n=50 vs Phase III n=5,000) and mid-study protocol changes are the tests, not the demo.
DCT, wearables, RWE — one paragraph
Decentralised trials, wearables, and real-world evidence change the intake, not the job. You still validate, query, and lock. You now also ingest a continuous sensor stream and, sometimes, messy EHR or claims data that have to be harmonised with the protocol dataset. The DMP has to name those sources. Do not pretend a smartwatch feed is already analysis-ready, and do not turn this page into a hospital EHR article — that is the healthcare-data-management link above.
PYCAD builds custom web DICOM viewers and medical-imaging AI (annotation → model deployment). That is a connector / imaging stack inside a trial, not a trial EDC. Case studies.