Clinical patterns

Acknowledge & escalate

The full lifecycle of an alarm, from the moment it fires to the moment it is permanently resolved — including every way it can be silenced, and the ways it must not be.

Stable · v1.0 Pattern IEC 60601-1-8 Alarm fatigue AcuteLine

Overview

The Alert Banner specifies what an alarm looks like. This pattern specifies what it does over time: how it is acknowledged, when it comes back, when it escalates to someone else, and how it ends.

That lifecycle is where alarm safety is actually won or lost. Two failure modes sit at opposite ends and both are lethal: an alarm that nags until clinicians ignore the whole class, and an alarm that goes quiet while the patient is still deteriorating.

Answerable

Every alarm can be acknowledged in one action, from wherever it is seen. An alarm a clinician cannot answer is an alarm they learn to tune out.

Never silently ending

An alarm leaves the screen for exactly two reasons: a clinician answered it, or the condition resolved and that resolution was shown. Nothing else.

Escalating on evidence

Time alone escalates to a person. New clinical evidence escalates the alarm itself. The two are different mechanisms and are never conflated.

The lifecycle

Alarm state machine
Active Acknowledged (timed) Re-asserted timer lapses, condition persists
Active Acknowledged (indefinite) Resolved condition clears
Active Latched Resolved condition cleared before anyone saw it
Any state Escalated no response within the escalation window
StateVisualAudioExits to
ActiveFull priority chromaPriority tone Acknowledged, Resolved, Escalated
Acknowledged (timed) Chroma drops to rail; countdown visibleSilent Re-asserted, Resolved
Acknowledged (indefinite) Chroma drops to railSilentResolved, Escalated on new evidence
Re-assertedFull chroma returnsPriority tone returns Acknowledged, Resolved, Escalated
LatchedFull chroma retainedSilent after first cycle Resolved once acknowledged
EscalatedFull chroma; recipient namedPriority tone Acknowledged by the escalation recipient
ResolvedRemoved or replaced by confirmationSilent Terminal — persists in the event log

Acknowledging

Acknowledgement means "a qualified person has seen this." It does not mean the problem is solved, and the interface must never let those two blur.

Timed acknowledgement · countdown visible
STEMI pattern detected — anterior leads V2–V4
Acknowledged. This alarm will return if the condition persists.
S. Whitfield 14:27:04 · re-alerts in 09:12 · condition ongoing
ModeWindowUseAvailable at
TimedDocumented per alarm class; 10 min default for CriticalDefault for Critical — the clinician is acting, not dismissing Critical, Urgent
IndefiniteUntil the condition resolves The clinician has assessed and a plan is in place Urgent, Advisory
Audio pauseFixed, documented, non-extendable Managing noise during a procedure or conversation All — visual signal unaffected
Audio pause is not acknowledgement

Pausing audio silences the tone and changes nothing else. The banner keeps full chroma, the alarm keeps its state, and a separate indicator shows audio is paused with the time remaining. Pause is time-boxed, cannot be extended indefinitely, and never applies to a class of alarms — only the one in front of the clinician.

Do
STEMI pattern detected — anterior V2–V4
audio paused 01:47 · alarm still active

Audio off, visual signal at full strength, remaining pause stated.

Don't
Alarms muted
Sound is off for this session.

A global, open-ended mute that also drains the visual signal. The patient is still having a STEMI and the screen no longer says so.

Escalating

Two mechanisms, deliberately separate:

Time-based — escalates to a person

The alarm has not been answered within its window. The finding has not changed; the audience has. The alarm names who it has gone to, so the original recipient knows help is coming and the new recipient knows why they were called.

Unanswered — escalated to a second recipient

Evidence-based — escalates the alarm

New data has changed the clinical picture. This is the only mechanism permitted to re-raise an alarm a clinician has already assessed, and it must state what changed. See Clinician override.

What must never happen

NeverWhy
Auto-dismiss on a timer An alarm that disappears unseen is indistinguishable from one that never fired.
Dismiss on navigation or page change Moving to another screen is not an assessment.
Bulk "acknowledge all" Guarantees at least one alarm is answered without being read.
Acknowledge from a notification the alarm text is not fully visible in Answering something you have not read is not acknowledgement.
Silence a whole alarm class or an entire session Removes the signal for patients nobody has assessed.
Escalate on the same evidence, repeatedly Nagging. Trains clinicians to dismiss the class without reading.
Let a clinician disable an alarm class from within a clinical screen Alarm configuration is an administrative act with its own authority and audit.
"Acknowledge all" is a hazard, not a convenience

Every request for a bulk-acknowledge control is really a report that the system is over-alerting. The correct response is to fix the alarm burden — tune thresholds, coalesce duplicates, demote inflated priorities — never to add a control whose purpose is to answer alarms without reading them. Coalescing identical findings on the same patient is permitted and is a different mechanism entirely.

Alarm burden

Alarm fatigue is a system property, not a user failing. A product built on this system is expected to measure and publish its own burden.

This page owns raised alarms

Everything here concerns an alarm that fired. Software that reduces burden by deciding some alarms should never fire at all is making a different decision, with a different failure mode — one that announces itself to nobody. That is designed in Suppression & the unraised alarm, which starts from the position argued here and asks how the silence is held to account.

Do's and don'ts

Do
STEMI pattern detected — anterior V2–V4
audio paused 01:47 · alarm still active

Audio off, visual signal at full strength, remaining pause stated.

Don't
Alarms muted
Sound is off for this session.

A global, open-ended mute that also drains the visual signal. The patient is still having a STEMI.

Do
ST elevation increased since your assessment — 3.1 → 4.8 mm
Serial ECG at 15:04. You assessed this as early repolarisation at 14:31.

Re-alerts on new evidence, and says what changed.

Don't
STEMI pattern detected — anterior V2–V4
re-alert 4 of 11 · same recording

The same finding on the same recording, fired eleven times. This is how a clinician learns to dismiss red.

Accessibility

Outcomes of use

What this contributes to, in the terms of Usability & context of use. These are attributes believed to contribute to an outcome; the outcome itself is settled by observing real use in a specified context, not by this page.

Clinical safety notes

Risk controls carried by this pattern

Trace these in your risk file (ISO 14971) and usability engineering file (IEC 62366-1).

NotJustAnyMed.Tech Design System · Acknowledge & escalate · v1.0 · draft for review
Reference applications named in this system are fictional; all patient data shown is fabricated.