Mandated, not measured

Mandated, not measured

Healthcare, and the difference between requiring supervision and verifying it happened. A mandated safety standard nobody measured.

A Control You Can Skip ended with two supervisors standing inside a robotic cell, one of them close enough to have stopped what happened, and neither of them answerable for it in any way the system recognised.

The obvious reply is that Ajin was a factory with a binder. Supervision there rested on custom and enforcement, and both are soft. Put the same question to a domain where supervision is written into law, where the roles are named and the documents are required, and the problem should disappear.

So I did.

Stress test. Claim under test (Articles 3 and 5): a loop that issues commands without measuring the result is open-loop. Supervision requires feedback on whether it took effect. Domain: healthcare. The question: what happens when supervision is required by law and nothing verifies that it happened?

The most regulated domain in the series

Healthcare should be the hardest case for this thesis. Devices are regulated. Practitioners are licensed and can lose that licence. Incidents are investigated by a statutory body with powers of entry. And for the systems in question here, the standards are not guidance. DCB0129 and DCB0160 are published information standards issued under section 250 of the Health and Social Care Act 2012, and both statutory investigations described below call compliance with them mandatory. One sets requirements for manufacturers of health IT systems. The other requires a care organisation to establish a framework for managing the clinical risks of deploying a new or modified system, with a trained clinical safety officer appointed, a safety case arguing from evidence why the system is safe in that particular setting, and a hazard register kept.

If a legal mandate is what makes supervision binding, this is where the argument should stop.

Felicity

Felicity was four. She had a complex heart condition diagnosed at birth, had already had a stroke, and in March 2020 was on a paediatric cardiology ward recovering from a further procedure when a scan found a clot in her right leg.

The team agreed she should have dalteparin, an anticoagulant, at 100 units per kilogram twice a day. She weighed 15.2 kilograms. The doctor prescribing it did the arithmetic by hand, got 1,520 units, and rounded down to 1,500.

Then he opened the prescribing system. The list he could reach was the adult list, and he selected dalteparin 15,000 units in a pre-filled syringe, intending to overwrite the dose. The field auto-populated with 15,000 and he did not overwrite it. In the comment box he typed that this was as per discussion with haematology, which was true of the plan and not of the number on the screen.

Felicity received ten times the intended dose on five occasions over one weekend. A scan then showed a new bleed on the right side of her brain. Her family told the investigation that she has not been able to walk or speak since, and that she could do both before that admission.

Seven separate checks were performed on that prescription before it was caught.

Seven checks, one source

The prescription was checked by a specialist pharmacist, prepared by a technician, then checked by pairs of nurses before each of five administrations. Several noticed. One called it a whacking dose. They looked it up, found it out of range for a child of that weight, and gave it anyway.

The investigation's finding is the part worth carrying away. The checks were not independent, in part because they were made against the same source of information, the prescribing system itself. And what that source said, in a free-text box filled in to record a team discussion, was that the dose had been agreed with haematology. A note written to capture a conversation became, for everyone downstream, the authority that ended it.

Seven checks with a shared input are not seven checks. They are one measurement, taken seven times.

The nurse who found the error proves the point from the other side. She was working on a different patient when she noticed an unfamiliar purple-bannered box on the ward, then recalled that Felicity had blood in her nasogastric aspirate and had vomited blood. Three cues, all outside the system, none dependent on the note. She checked the dose herself and stopped it.

Nursing staff told the investigation they saw themselves as the final barrier and felt accountable for what happened. Answerability came to rest on the people with the least authority over the system that produced the number.

Where was the supervision?

The Article 8 reading of this is that a dose-range alert could have been configured and wasn't. True, and the least interesting thing in the report. That failure sits inside a mandated governance process which existed for precisely this situation.

The trust had done it properly once. Three clinical safety officers were in post and trained, and a clinical safety assessment was carried out for the first deployment in accordance with the standard. That was in 2012, on adult wards.

The system reached the paediatric cardiology ward in May 2019. The standard is explicit that where the scope of use changes, adults to children being the example given, it should be complied with. The investigation was unable to determine whether the trust went through a further assessment before that deployment.

Not that it was skipped. That nobody could establish, afterwards, whether a legally mandated safety process had taken place.

A manufacturer told the investigation the same thing from the other side. A trust using adult protocols in a paediatric environment would be expected to write that into a safety case, with the risk mitigated locally. The investigation found no evidence of one, and found local governance of these systems limited, with gaps in training and an absence of safety cases.

An obligation whose discharge cannot be observed is a command issued into the dark.

The systemic picture

In May 2026 the statutory investigator published a national investigation into these systems, using a control-based accident model that maps which organisations are responsible for fulfilling safety constraints and how they interact and gain feedback.

Its central finding is the one this article has been circling. There are legally mandated standards relating to digital clinical safety, there is variation in compliance with them, and there is no national oversight or enforcement of providers' compliance.

Underneath that, each link holds a piece of the obligation and none holds the whole of it. Manufacturers self-assess and declare compliance to join the national procurement framework, and the framework does not assure those declarations. Trusts are relied on to judge whether a manufacturer has correctly interpreted the device regulations, and some lack the expertise to make that judgement. Several manufacturers said their responsibility ends once the system is configured locally, after which the risk sits with the organisation. On that last point the investigator reaches for another domain, and reaches for the one this publication has been arguing from. In civil aviation, it observes, the manufacturer retains design authority over safety-critical software and must approve all changes, configuration included.

The clinical safety officer is accountable for articulating the risk and the executive team decides whether to proceed, and stakeholders described grey areas about where responsibility sits between them, with officers who may not be resourced adequately. Every party is nominally responsible and no party is positioned to verify.

Four years after Felicity, the Royal College of Paediatrics and Child Health and the Neonatal and Paediatric Pharmacy Group published a joint position statement concluding that for frontline prescribers and the patients they treat, nothing has materially changed. They describe it as systemic, and note that practical paediatric-specific standards remain undefined.

Have regard to

Which is why the current legal position repays reading slowly.

The framework is being tightened. Section 95 of the Health and Care Act 2022 came into force on 7 July 2025 and changed the duty attached to information standards from having regard to them to complying with them. Section 121 of the Data (Use and Access) Act 2025 followed on 5 February 2026, extending the regime to IT providers, who can now be required to evidence compliance and publicly censured for failing to. Financial penalties sit in a narrower place than is often reported, aimed at private providers rather than NHS bodies.

Then, in June 2026, NHS England published a consultation on revising these two standards. In its background section is the sentence that reframes everything above. As the standards stand, it says, bodies exercising a health and care function must continue to have regard to them, and future revisions are likely to leverage the enhanced powers.

Have regard to. Not comply with.

The standards Felicity's trust was operating under, the ones two statutory investigations call mandatory, are mandatory in the sense that they were formally issued as mandatory information standards. The duty they actually placed on the trust was to take them into account. The stronger duty exists now and does not yet attach to these standards, because they predate it and have not been revised.

That is not a gotcha, and nobody was being loose with language. It is a precise description of the gap. A supervisory regime can be mandatory in name, named in statute, staffed by appointed officers, documented in safety cases and hazard registers, and still rest on a duty to consider rather than a duty to do. The machinery for finding out which of those happened in any given deployment was never built, because for fifteen years it did not need to be.

NHS England's own consultation says as much. Across eleven focus groups with manufacturers, providers, clinical safety officers and industry experts, current compliance mechanisms were consistently identified as insufficient, with calls for stronger compliance tracking, clearer consequences for non-compliance, and better integration with regulatory inspection.

So the honest ending is not that nothing is being done. A review is under way, the powers have been strengthened, and the responsible body has published a document acknowledging that the mechanisms do not work well enough.

But note the order of operations. The command has been made more forceful and the revision that would attach that force to these standards has not happened. The legal loop is closing faster than the operational one, and until they meet, what exists is a stronger instruction with no reliable way to observe whether it was followed.

Regulation can compel a supervisor to exist. It cannot, by wording alone, produce evidence that the supervisor supervised.

Ajin's supervisors were present and not answerable. Here the accountability is real, named, statutory and documented, and it still does not reach the place where the decision was made. What is missing in both cases is not authority on paper. It is any way of knowing whether the authority was ever exercised.

Which at least assumes there is a settled regime to comply with.

Sources

  • Healthcare Safety Investigation Branch, Weight-based medication errors in children (2022)

  • HSSIB, Electronic prescribing and medicines administration: procurement and safety learning in acute hospitals (28 May 2026)

  • RCPCH and NPPG Joint Medicines Committee, position statement on safe and effective dose management in EPMA systems (2026)

  • DCB0129 and DCB0160, published information standards under section 250 of the Health and Social Care Act 2012

  • NHS England, National review of clinical risk management standards DCB0129 and DCB0160: supporting information, 29 June 2026

  • Health and Care Act 2022, section 95 (in force 7 July 2025); Data (Use and Access) Act 2025, section 121 (in force 5 February 2026)