The Digital Health Networks forum is a great place to hang out and learn more about Digital Clinical Safety. Recently a key contributor and NHS CSO asked the question ‘How do we know if we are performing well in regards to Clinical Safety?’ It’s a great question, and one that we thought deserved a blog article in its own right. So, we canvassed Safehand’s hive-mind of 16 CSOs and set out below are their thoughts (in no particular order).

Has the organisation got a solid position with regards its assurance debt?

Assurance debt represents the mass of Health IT systems which have been deployed but have never received attention under DCB 0129 or DCB 0160. Every Trust, at the very least, needs to know the size and shape of that assurance debt. To quote one of our CSOs, tackling only those systems which are the crocodiles nearest the boat is not a strategic approach. Do you know what systems are out there? Do you know which have had a DCB 0160 assessment completed? If you’ve decided not to assess a product, is the rationale documented and the approach agreed by Top Management? At Safehand we’ve developed a strategic way of doing all this – assurance debt is something that cannot be ignored.

Is there a defined and working Clinical Risk Management Process in place?

Note that the key word here is ‘working’. It’s one thing having a document entitled ‘Clinical Risk Management Process/System’ but is it being implemented to the extent that an auditor could randomly pick a task from that process and ask you to show tangible evidence that it has been completed for a particular system? Can it be shown that the process is actually integrated into the fabric of the organisation rather than a document, built on a generic template, that sits on one person’s laptop never to be seen by the rest of the organisation?

Is there evidence of visible safety leadership?

It’s one thing claiming that a particular board or committee represents the role of Top Management in the standard, but can objective and tangible evidence of that governance actually be demonstrated? Do you have a named Safety Sponsor as a representative of Top Management who can be shown to be actively supporting the DCB 0129/0160 work, has read and indeed challenged the deliverables and who visibly promotes a culture of Digital Clinical Risk Management in the organisation?

Can the DCB 0129/0160 deliverables be shown to be of good quality?

We’ve talked before about good quality measures for Safety Cases and Hazard Logs. And a key characteristic is the presence of novel content rather than templated or inherited text – for example:

  • Deliverables where the author has taken the time to craft an analysis around a specific project
  • Documents which evidence that failure modes specific to the product/implementation in the local organisation have been identified
  • Hazards which are specific and granular and say more that ‘Data fails to save’, ‘Testing not conducted’ or ‘User makes mistake’.
  • Controls which are specific, actionable and can be evidenced – i.e. those which go beyond ‘Users have been trained’ or ‘The system has been rigorously tested’.

Is there a strategy to support on-going Clinical Risk Management?

All too often a Trust provides resources to undertake an initial risk assessment and construct the primary safety deliverables, but then hand the project over to their IT department with little or no consideration for ongoing safety work. Clinical Safety does not stop at the point where a Clinical Safety Case Report is issued – indeed it could be argued that that is just the start of the journey. A Trust needs a strategic approach in place so that individuals do not need to beg, borrow or steal support when an incident arises or a modification is made.

Is effective incident management in place?

For incident management to work effectively there needs to be a clearly defined and working process in place to ensure that the right incidents are forwarded to the CSO for review. Trust IT helpdesks receive hundreds of logged incidents, the art is in having a sensitive and specific filter in place to ensure that the small minority of important safety-related incidents are appropriately escalated to the CSO.

Another key indicator is the presence of a working system to ensure that the fix priority assigned to incidents is commensurate with the Clinical Risk they present. Oddly there is no specific requirement stating this in the standards yet it is fundamental for a well-oiled incident management process to be effective.

Is there effective integration with procurement processes?

There’s no point having a solid Clinical Risk Management Process in place if clinical departments are able to procure systems at the drop of a hat without any consideration as to whether the manufacturer has completed a quality DCB 0129 risk assessment. To do so simply builds a heavy rock for the Clinical Safety Team’s back. Every potential supplier should be subject to an objective review of their safety position – and that means far more than just asking them whether they comply with DCB 0129.

Is there tangible and specific evidence of control implementation and effectiveness?

A Safety Case only stacks up if the controls cited are evidenced, both in terms of presence and effectiveness. And as mentioned earlier, a control of ‘We test stuff’ does not evidence make. What *exactly* is being tested, and what is the identifier for the test script which details that test?


Did you notice the word that kept coming up when we asked the team this question? It’s ‘evidence’. If you can’t show tangible proof of a process in action, then to all intents and purposes – it ain’t happening. And if you’re looking for a single reference point from which to cite this evidence, what better than NHS England’s Compliance Assessment Template which breaks all the requirements down and provides an opportunity to say how they are being met.

So that’s it, Safehand’s collective view on ‘How do we know if we are performing well in regards to Clinical Safety?’ – what a great question that was.