Clinical patterns

Clinician override

How a clinician disagrees with the software, what the system does about it, and why making disagreement easy is a safety requirement rather than a concession.

Stable · v1.0 Pattern Post-market surveillance ISO 14971 AcuteLine

Overview

AcuteLine is decision support. The clinician is the decision-maker, which means their disagreement is not an error condition — it is the system working. A tool that makes agreement one tap and disagreement a five-field form has not made itself safer; it has made its own performance data useless and trained its users to click through.

This pattern covers the moment of disagreement and everything downstream of it: the record, the audit trail, and the feedback into post-market surveillance.

Symmetric

Agreeing and disagreeing cost the same number of actions and carry the same visual weight. Any asymmetry biases the data the system collects about itself.

Attributable

Every override records who, when, and on what evidence. Not to police the clinician — to make the record defensible and the surveillance data real.

Non-obstructive

Disagreement never blocks care. The clinician acts first; the system records. Nothing about overriding delays the patient.

Anatomy

Override — the disagreement moment
STEMI pattern detected — anterior leads V2–V4
model v4.2 · confidence 0.94 · HARLAND, A. · MRN 44 812 907
Do you agree with this finding?
Your assessment is recorded against model v4.2 and used for post-market performance monitoring. It does not change or delay any clinical action.
Reason — optional, one tap
Recorded as S. Whitfield · 14:31 · from ECG review
ElementRule
Three options Agree · Disagree · Cannot assess. Identical styling — no primary variant on any of them.
"Cannot assess" A first-class answer. Forcing a binary produces false agreement from clinicians who lack the information to judge.
Reason Optional, one tap from a differential list. Free text is available but never required.
Attribution User, timestamp and originating screen, shown before submission so the clinician knows what is being recorded.
Why the reason is optional

A mandatory justification field is the most reliable way to stop clinicians disagreeing. Under time pressure the cheapest path becomes "Agree", and the system's measured agreement rate climbs while its real-world accuracy does not. The reason list exists because most disagreements have a common cause worth capturing — but the override is recorded with or without one.

The asymmetry trap

Do

Equal weight, equal cost. The resulting agreement rate means something.

Don't

A prominent accept and a buried, apologetic dissent. This measures how hard you made disagreement, not how often the model is right.

The record

An override produces a durable, human-readable entry. It is written once, never edited, and never deleted — a correction is a new entry referring to the previous one.

Audit trail · one case
  • 2026-08-13 14:26:38
    ECG acquired and analysed — STEMI pattern, anterior V2–V4
    AcuteLine model v4.2 · confidence 0.94 · trained to 2025-11
  • 2026-08-13 14:27:04
    Alert acknowledged
    S. Whitfield · Registrar · from triage worklist
  • 2026-08-13 14:31:12
    Clinician disagreed with finding — reason: early repolarisation
    S. Whitfield · Registrar · from ECG review · annotation was ON
  • 2026-08-13 14:33:47
    Serial ECG requested · repeat in 30 min
    S. Whitfield · Registrar
  • 2026-08-13 15:06:20
    Assessment revised — agrees with finding (supersedes 14:31:12)
    A. Bergström · Consultant · from ECG review · serial change confirmed

When the model and clinician disagree

What must not happen is as important as what does.

The system doesThe system never does
Record the override and continue Ask "are you sure?" — a confirmation that only ever appears on disagreement is a thumb on the scale
Leave the original finding visible and unaltered in the record Delete or hide the finding the clinician rejected
Stop re-alerting for the same finding on the same recording Keep re-raising an alarm a clinician has explicitly assessed
Continue analysing subsequent recordings normally Suppress future alerts for that patient — the next ECG is a new question
Escalate on new evidence, stating what changed Escalate on the same evidence, hoping for a different answer
Re-alerting after an override

An overridden finding must not re-fire on the same recording — that is nagging, and it trains clinicians to dismiss without reading. It must re-fire when new evidence arrives, and the new alert states what changed: "Serial ECG at 15:04 shows ST elevation increased 3.1 → 4.8 mm since the assessment at 14:31." Novel evidence, not repetition.

Escalation on new evidence, not repetition

Feeding surveillance

Overrides are the primary real-world signal about how the device performs after release, and the interface is what determines whether that signal is trustworthy.

Do's and don'ts

Do

Equal weight, equal cost, and “cannot assess” as a first-class answer.

Don't

Prominent accept, buried dissent. The agreement rate now measures friction, not accuracy.

Accessibility

Outcomes of use

What this contributes to, in the terms of Usability & context of use. These are attributes believed to contribute to an outcome; the outcome itself is settled by observing real use in a specified context, not by this page.

Clinical safety notes

Risk controls carried by this pattern

Trace these in your risk file (ISO 14971), usability engineering file (IEC 62366-1) and post-market surveillance plan.

NotJustAnyMed.Tech Design System · Clinician override · v1.0 · draft for review
Reference applications named in this system are fictional; all patient data shown is fabricated.