Phased Rollout Plan
Clinical deployment of HealthOS ICU follows a six-stage validation protocol. Each stage has defined entry criteria, exit criteria, and a formal sign-off gate. No stage is skipped.
Six-Stage Rollout Plan
Stage overview
| Stage | Name | Output visible | Write path | Gate |
|---|---|---|---|---|
| 1 | Capture only | None | None | Internal data quality review |
| 2 | Internal review | Implementation team only | None | Team sign-off |
| 3 | Recommendation only | Clinical team | None | Clinical leadership approval |
| 4 | Supervised write | Clinical team | Yellow class | Stage 3 outcome review |
| 5 | Restricted write | Clinical team | Red class (defined context) | Ethics committee + clinical leadership |
| 6 | Full governance | All | All classes | Multicenter validation data |
Stage 1 — Capture only
The platform runs the full analysis pipeline but produces no output visible to the clinical team. The team operates normally. The system records shadow recommendations and compares them to clinical outcomes.
Exit criterion: Shadow recommendation quality metrics (sensitivity, specificity, alert rate) reviewed by implementation team; baseline established for stage 2 comparison.
Stage 2 — Internal review
Shadow recommendations become visible to the implementation team and designated clinical reviewers. Clinicians review recommendation logs in batch — not at bedside. Adjustments to the compiled bundle are made through the governed knowledge update process.
Exit criterion: Clinical reviewers confirm recommendation quality is appropriate for clinical team exposure.
Stage 3 — Recommendation only
Recommendations are surfaced to the bedside clinical team as alerts. No device write-back. The team evaluates recommendation relevance and alert fatigue. Formal feedback loop via refinement candidates.
Exit criterion: Alert fatigue metric within agreed threshold; clinical leadership formally approves progression to supervised write.
Stage 4 — Supervised write
Yellow-class (supervised) commands are enabled. Parameter suggestions within pre-validated clinical envelopes are presented for clinical acceptance. Silent acceptance within a timeout window; rejection always explicit.
Exit criterion: Acceptance rate and incident rate reviewed; ethics committee notified; clinical leadership approves stage 5.
Stage 5 — Restricted write
Red-class commands enabled in a defined clinical context (e.g., specific procedure type, specific device, specific parameter range). Requires explicit clinical acknowledgement for every action.
Exit criterion: Formal incident review; governance sign-off; data submitted for multicenter design.
Stage 6 — Full governance
Complete deployment with all command classes, multicenter validated. Ongoing governance: quarterly knowledge graph review, annual risk management update, continuous audit event log monitoring.
Documents
HealthOS ICU: Full Concept → · Safety Kernel and Device-Control Commands →
Discuss a phased rollout at your institution. Contact for pilot enrollment →