In our previous blog articles, we talked about the forthcoming revision of the DCB 0129/0160 standards and a few nuances which, in our opinion, would benefit from a refresh. Let’s turn now to a couple of other issues, this time in relation to change management.

DCB 0129 contains an important set of requirements with regards what it calls ‘Modification’ of a Health IT system. Essentially, the standard requires that the risk assessment must be applied to any changes to the software - which is perfectly reasonable. In DCB 0160 there is an almost identical set of requirements, this time under a heading of ‘Maintenance’. It’s here that we note that the healthcare organisation appears only to be required to apply the clinical risk management system to “modifications or updates of the deployed Health IT System.” It’s our experience at Safehand that when use of a system is locally expanded, or is in some other way used differently, that new hazards are introduced – yet the system remains the same. It is short-sighted from a DCB 0160 perspective only to require a revisitation of the safety documentation when the software itself changes.

For example, we regularly see healthcare organisations undertake programmes of work to change:

  • The numbers of users operating a system (e.g. moving from a 10-user pilot to a 2000 user deployment)
  • The types of users (e.g. adding clinical users to a system previously used only by administrators)
  • The clinical setting (e.g. deploying a system in ITU that was previously only used on traditional wards)
  • The client technology (e.g. moving from a desktop-based computer to a mobile platform)
  • The local infrastructure (e.g. moving from wired client machines to Wi-Fi)
  • Local processes and policies (e.g. new ways of working or escalation routes)
  • Interfacing to new systems or technologies (e.g. receiving data from new electronic sources)
  • The system’s configuration (e.g. the use of new settings or configured content)

Any of these changes could introduce new hazards which would benefit from application of the clinical risk management process. We therefore propose that the existing requirement is modified accordingly:

“The Health Organisation MUST apply their clinical risk management process to any modifications or updates of the deployed Health IT System as well as for any changes to how the system is implemented.

Another challenge frequently encountered by healthcare organisations and occasionally by manufacturers is the detection of change. If the clinical safety team remain unaware of changes that are taking place or are planned to take place, it is difficult or impossible to practically undertake an assessment ahead of deployment. Some trusts have highly rigorous change management procedures in place whereby any change to a system or its configuration requires a formalised administrative process to be followed. Other organisations are, let’s say, a little more relaxed, and this places a significant burden on the clinical safety team to constantly poll stakeholders in the hope that changes will be surfaced.

Whilst the current requirement to apply the clinical risk management process to any changes is valid, the process could be strengthened by including an additional requirement such as:

“The Health Organisation/Manufacturer MUST establish and maintain a formal change management procedure that ensures the timely identification, communication, and assessment of safety-related changes to the software or its implementation.”

So that’s our thoughts on change management. Do you agree?