Skip to content
Nextriv

Blood Bank Temperature Monitoring — Ranges, Alarms and Evidence

Blood bank temperature monitoring requires component-specific ranges, qualified points, alarms and response. See what monitoring can prove — and what it cannot.

Zespół Nextriv6 min read

Article cover: Blood Bank Temperature Monitoring — Ranges, Alarms and Evidence

Blood bank temperature monitoring is not a matter of setting one alarm for “blood”. Different components require different storage conditions, equipment behaves with different dynamics, and every decision to release or discard a unit must follow an approved procedure. The monitoring system is there to provide a complete, credible record: where an excursion occurred, how long it lasted, who received the alarm and what was done. It does not make a clinical decision, replace component traceability or make a process compliant simply by being installed. The design therefore begins with processes and accountability, and only then moves to sensors.

There is no single blood storage temperature

Directive 2004/33/EC separates storage conditions by component. Whole blood and red blood cells are stored at +2 to +6°C. Platelets require +20 to +24°C together with the conditions specified for their continuous agitation. Granulocytes also have a +20 to +24°C range, but a different permitted storage time. Plasma and cryopreserved components form another category, with sub-zero conditions and storage periods determined by the method and applicable procedure.

These numbers explain why a shared “alarm above 8°C” cannot supervise an entire blood establishment. The same reading may be critical in a red-cell refrigerator, correct in a platelet incubator and irrelevant to a plasma freezer. Every chamber, item of equipment and zone therefore needs its own name, range, recipients and response procedure.

Current legislation, national good practice, the equipment instructions, component specification and the establishment's approved procedures always take precedence. This article explains monitoring architecture; it is not an instruction for deciding whether a component is suitable for transfusion.

From equipment qualification to the permanent monitoring point

A sensor should not be installed wherever mounting is easiest. The temperature distribution inside a refrigerator or freezer needs to be assessed during qualification and mapping under representative loading. The permanent monitoring point follows from the result: it should represent a location relevant to component safety, not the stream of cold air at the evaporator or a momentary temperature beside the door.

In practice, three functions should be distinguished:

  • equipment control — the sensor used by the refrigerator or freezer controller;
  • independent monitoring and recording — the path that provides evidence of storage conditions;
  • reference measurement — the equipment used for checks and calibration.

In this application, the minimum is not left to risk analysis. Section 4.1.8 of the 2026 Polish good-practice requirements states that every storage unit must have at least two independent temperature meters, distributed evenly so that temperature is controlled throughout the unit. They must be calibrated in line with the manufacturer's instructions and at least once every 12 months. Risk assessment cannot reduce that minimum; it may justify further separation of power, storage, communications and notifications. Two channels sharing one set of electronics can still lose both readings in one failure. Our guide to GxP monitoring validation covers the wider qualification principles, while a blood bank remains subject to its specific requirements.

Blood bank monitoring diagram with separate red-cell, platelet and frozen-component storage units, each fitted with at least two independent temperature meters, connected to central alarm supervision
Blood bank monitoring diagram with separate red-cell, platelet and frozen-component storage units, each fitted with at least two independent temperature meters, connected to central alarm supervision

What a credible record should contain

A temperature value without context is not enough. A record should identify the equipment and point, measurement time, unit, communication status and configuration history. When an excursion occurs, the evidence needs a timeline: the first out-of-range result, subsequent readings, alarm delivery and acknowledgement, return to range, and a comment describing the team's action.

Completeness matters just as much. A network failure must not create an invisible gap, so the monitoring device should retain readings locally with their original timestamps and restore them to history after communications recover. A separate offline alarm should make the loss of current supervision visible. The principles resemble those in our guide to GDP temperature monitoring, but a blood establishment's ranges and disposition decisions remain separate.

Raw measurements should be retained under an approved policy and the applicable documentation requirements. An hourly aggregate can be useful for a trend, but it should not erase a short excursion from the evidence. Our article on measurement data retention explains the difference between full history and averaged views.

An alarm starts a procedure; it does not deliver a verdict

An alarm rule should reflect the range for the specific component and the equipment dynamics. Nextriv evaluates every reported value immediately; it does not apply a pre-event trigger delay, debounce or hysteresis. Configurable timing concerns only subsequent escalation steps after the event exists. A brief door opening may change air temperature faster than component temperature, but that does not make every spike irrelevant. Qualification and the establishment's procedure define how duration and conditions are assessed from the history. If the storage unit's own alarm has a delay, the activation time required in its instructions under section 4.1.9 must be documented and verified separately — it is not a Nextriv threshold feature.

A rehearsed scenario answers these questions in advance:

  1. Who receives the first notification, and who takes over if it is not acknowledged?
  2. How is the temperature confirmed independently?
  3. Where can components be moved safely if the equipment fails?
  4. Who assesses the excursion and prevents release pending a decision?
  5. How are the intervention, service work and return to use recorded?

Testing should cover the high and low thresholds, communications loss, power loss and a failed escalation. Sending one test email does not demonstrate that the complete path will work at three in the morning.

Transport, replacement equipment and contingency response

Supervision does not end at the chamber door. Distribution and transport need to preserve component integrity and the conditions specified for that product, while the transport container requires its own qualification. A data logger should measure conditions representative of the load and retain data for the complete journey. Air temperature beside the lid does not necessarily represent component temperature inside, so the location and method are established during route and packaging validation.

The contingency plan should identify the replacement unit or space, its available capacity, the person authorised to move components and the method for maintaining traceability. Saying “we have a second refrigerator” is not enough when nobody has confirmed that it is qualified, has free capacity and remains under functioning monitoring.

It is also worth rehearsing a failure outside normal hours. The alarm needs to lead to a decision before the response time in the procedure expires, and transfer to the backup unit must leave a coherent record. After the exercise, review the times for detection, acknowledgement, arrival, transfer and restoration of supervision. Those figures are a better measure of readiness than a statement that “notifications work”.

When a journey logger is used, its clock, identifier, calibration status and assignment to the particular shipment also need control. On return, the data should enter the record without overwriting original timestamps. Manually copying only the minimum and maximum does not preserve the trend or the duration of a possible excursion.

Electronic monitoring and manual logs

The Polish Minister of Health's notice of 28 May 2026 concerns the “good-practice requirements for the storage and issue of blood and blood components by blood banks and for immunohaematology testing performed in healthcare establishments other than regional centres, the Military Centre or the Ministry of the Interior and Administration Centre” (Official Journal of the Minister of Health 2026, item 42). Section 4.3.2 says manual temperature logs are not required for storage equipment connected to a central monitoring system when blood-bank staff have continuous supervision and the printouts or electronic protocols remain under the quality system. This is not automatic approval for any data logger.

Before withdrawing paper records, an establishment should at minimum address system qualification and validation, data availability, access control, backup and restoration, calibration control, contingency procedures and staff training. A digital sensor calibration register can help track due dates and certificates. The quality system may require a shorter interval, but it cannot extend calibration of the section 4.1.8 meters beyond 12 months.

The role and limits of Nextriv

Nextriv can collect temperature from multiple items of equipment, present their status on a common dashboard, detect missing data, retain an event history and route alarms through an escalation. A wired-probe logger such as the Nextriv Probe Solo is technically relevant to a red-cell refrigerator, but one logger does not satisfy the two-independent-meter requirement. The number and independence of paths, their placement, installation and calibration must be established through qualification of the particular unit.

The platform is not a blood component management system: it does not assign donation numbers, maintain complete donor-to-recipient traceability, control a platelet agitator or decide whether a component can be released. We also do not claim that installing Nextriv by itself provides complete blood-bank compliance. It supplies an environmental monitoring layer that can become part of a process validated and controlled by the establishment.

For the wider healthcare context, see our healthcare monitoring solution. If you want to discuss measurement points, alarms and evidence without pretending the platform is a transfusion system, book a demo.

Sources

See data like this from your own sensors

FREE plan: 10 sensors, a gateway and a full year of measurement history — no credit card required.