Phased Rollout Plan

Clinical deployment of HealthOS ICU follows a six-stage validation protocol. Each stage has defined entry criteria, exit criteria, and a formal sign-off gate. No stage is skipped.

Six-Stage Rollout Plan

Six-stage rollout plan Capture only, internal review, recommendation only, supervised write, restricted write, full governance — each transition requires formal sign-off from the clinical leadership. Captureonly Internalreview Recommendationonly Supervisedwrite Restrictedwrite Fullgovernance every arrow — formal sign-off from the deploying institution's clinical leadership
Capture only → internal review → recommendation only → supervised write → restricted write → full governance. See also the chain on the Safety Kernel page.

Stage overview

Stage Name Output visible Write path Gate
1 Capture only None None Internal data quality review
2 Internal review Implementation team only None Team sign-off
3 Recommendation only Clinical team None Clinical leadership approval
4 Supervised write Clinical team Yellow class Stage 3 outcome review
5 Restricted write Clinical team Red class (defined context) Ethics committee + clinical leadership
6 Full governance All All classes Multicenter validation data

Stage 1 — Capture only

The platform runs the full analysis pipeline but produces no output visible to the clinical team. The team operates normally. The system records shadow recommendations and compares them to clinical outcomes.

Exit criterion: Shadow recommendation quality metrics (sensitivity, specificity, alert rate) reviewed by implementation team; baseline established for stage 2 comparison.

Stage 2 — Internal review

Shadow recommendations become visible to the implementation team and designated clinical reviewers. Clinicians review recommendation logs in batch — not at bedside. Adjustments to the compiled bundle are made through the governed knowledge update process.

Exit criterion: Clinical reviewers confirm recommendation quality is appropriate for clinical team exposure.

Stage 3 — Recommendation only

Recommendations are surfaced to the bedside clinical team as alerts. No device write-back. The team evaluates recommendation relevance and alert fatigue. Formal feedback loop via refinement candidates.

Exit criterion: Alert fatigue metric within agreed threshold; clinical leadership formally approves progression to supervised write.

Stage 4 — Supervised write

Yellow-class (supervised) commands are enabled. Parameter suggestions within pre-validated clinical envelopes are presented for clinical acceptance. Silent acceptance within a timeout window; rejection always explicit.

Exit criterion: Acceptance rate and incident rate reviewed; ethics committee notified; clinical leadership approves stage 5.

Stage 5 — Restricted write

Red-class commands enabled in a defined clinical context (e.g., specific procedure type, specific device, specific parameter range). Requires explicit clinical acknowledgement for every action.

Exit criterion: Formal incident review; governance sign-off; data submitted for multicenter design.

Stage 6 — Full governance

Complete deployment with all command classes, multicenter validated. Ongoing governance: quarterly knowledge graph review, annual risk management update, continuous audit event log monitoring.


Documents

HealthOS ICU: Full Concept → · Safety Kernel and Device-Control Commands →

Discuss a phased rollout at your institution. Contact for pilot enrollment →