Reprioritisation & notification
Software whose entire output is a change to somebody else's order of work. It produces no report, makes no diagnosis, and owns none of the screen it acts on — and the harm it can do is not the study it moved up, but every study it quietly moved down.
Overview
A triage device sits between two systems it does not control. The images come from a scanner it did not configure; the worklist belongs to reporting software written by somebody else. Its only actuator is a message, and the message asks another product to change what a radiologist sees first.
That makes it unusual in this system in a specific way: almost none of the surface it affects is a surface it can design. What it can design is what the message says, what happens when it does not arrive, and whether anyone can tell afterwards what it did.
Promoting one study demotes every other study. A false positive that gets read early costs a radiologist ninety seconds and is immediately obvious. The true positive that got pushed down the list is invisible — nobody experiences it as a consequence of the device, because nothing on any screen connects the delay to the promotion that caused it.
Evaluating a triage device on how quickly it surfaces what it flagged measures only the half that announces itself. The other half is measurable too, and it is the number this pattern exists to keep visible.
The reorder is visible
A list that was rearranged says so, says by what, and can be returned to the order it would otherwise have had.
Not a diagnosis
The output changes when a study is read and nothing else. It never states a finding, never enters the report, and never reaches the reader mid-read.
Undelivered is a clinical state
A notification that did not arrive is a patient whose study was not prioritised while everyone believed it was. That is not a network event.
Anatomy
| Priority | Study | Waiting | Order |
|---|---|---|---|
| CT head, non-contrast Acc. 88-4412 · adult · 14:02 |
6 min | Moved up 9 places Forecall: suspected intracranial haemorrhage · prioritisation only, not a diagnosis |
|
| CT head, non-contrast Acc. 88-4390 · adult · 13:31 |
37 min | Clinical priority: urgent | |
| CT cervical spine Acc. 88-4381 · adult · 13:12 |
56 min | Moved down 1 place |
The third row is the point. Everything a promotion displaces is displaced by a stated number of places, on the same screen, so the cost of the reorder is legible.
| Part | Rule |
|---|---|
| The promotion | Stated as a movement — "moved up 9 places" — not as a badge. A label saying AI tells a radiologist nothing about what changed. |
| The disclaimer | Adjacent, not in a footer. "Prioritisation only, not a diagnosis" travels with the row, because the row is what gets read. |
| The displacement | Studies pushed down say so. This is the element most often omitted and the one that carries the risk. |
| Clinical priority | The order the study would have had is preserved and visible. A device's opinion never overwrites the referrer's stated urgency — it sits beside it. |
| Provenance | Which device, which version, what time it decided. A promotion whose origin is not identifiable cannot be audited or reverted. |
| No score | No confidence number on the worklist. A probability invites the reader to act on it, which is the one thing a triage device must not cause. See below. |
What this is not
Devices that mark findings and devices that reorder queues get built by the same teams, ship in the same products, and are regulated on different evidence. Conflating them in the interface is how a prioritisation claim quietly becomes a diagnostic one.
| Triage (this pattern) | Detection aid | |
|---|---|---|
| Output | A change in reading order | A mark on an image the reader sees |
| Seen during the read | No. Never | Yes, by design |
| Affects the report | No. It is not mentioned | Potentially — and must be disclosed |
| Failure mode | Delay to something else | Anchoring, and missed findings outside the marks |
| Reader behaviour | Unchanged. They read the study exactly as they would have | Changed — which is the point, and the risk |
A triage device's output is never visible to the person reading the study. It changes when the study appears and nothing else. The moment a radiologist opens the images and sees "suspected haemorrhage" from the device, it has stopped being a prioritisation tool and become an unvalidated detection aid — with all the anchoring consequences of one, and none of the evidence. See Reader paradigm.
- No finding language. "Suspected haemorrhage" on a worklist is acceptable because it explains the position; the same phrase on the viewer is not.
- Never in the report, and never pre-populating one. A structured report field pre-filled by a triage device is a diagnostic claim it is not licensed to make.
- Never a second worklist. A separate "AI findings" dashboard beside the real worklist is the standard failure: it competes with the primary queue, gets checked less over time, and splits attention across two lists neither of which is complete.
- Never suppresses. A triage device may raise a study's position. It may not lower one below where clinical priority placed it, and it may not remove anything — that would be suppression, under different rules and different evidence.
Undelivered is a clinical state
The device's whole value is the minutes it saves. If the message never lands, no minutes are saved and — worse — everyone downstream is operating on the belief that prioritisation is running.
Critical priority, because the consequence is clinical rather than technical: four people's scans are sitting in a queue that nobody has reordered.
- Positive confirmation, not absence of error. The device knows a promotion landed because the worklist said so, not because nothing threw an exception.
- Name the affected studies. "Delivery failing" is an IT alert; "these four studies were not promoted" is a clinical one, and it is actionable by the people on shift.
- Escalate to a human within a stated time. The device cannot retry its way out of an outage, and the fallback is somebody telephoning the reading room.
- Degrade to not-reordering. A device that cannot confirm delivery must stop promoting rather than promote unreliably — an intermittently reordered queue is worse than one that was never reordered, because its behaviour cannot be learned.
- Say when it comes back. Recovery is announced too, with the backlog handled explicitly rather than dumped as a burst of promotions.
What the promotion costs
Time-to-read for flagged studies is the number every triage device reports. It is half the picture, and it is the flattering half.
| Measure | Why it belongs on the same screen |
|---|---|
| Time to read, flagged studies | The intended benefit. Uncontroversial and always reported. |
| Time to read, displaced studies | The cost. If it has risen materially, the device has moved delay rather than removed it. |
| Longest wait in the queue | Repeated promotion can starve the bottom of a list indefinitely. Somebody must be watching the tail. |
| Promotion rate | A device promoting a third of everything has stopped prioritising and started re-sorting. |
| False promotions, adjudicated | Feeds post-market surveillance — see Clinician override. |
States
| State | Rendering |
|---|---|
| Analysing | The study is in the worklist at its clinical priority from the moment it exists. Nothing waits for the device — a queue that holds studies pending analysis has made the device a bottleneck on every scan. |
| Promoted | Movement stated, disclaimer adjacent, clinical priority still visible. |
| Not promoted | Silent and ordinary. A device that flags "nothing found" on every unremarkable study has made a negative claim it was not evaluated to make. |
| Analysis failed | Stated on the row — this study was not assessed. Distinct from assessed-and-not-flagged, which is the distinction Key–value pair exists to protect. |
| Delivery failing | Critical alert naming the affected studies; promotion stops. |
| Already read | A promotion arriving after the study was reported is discarded, not shown. Reordering completed work is noise that teaches people to ignore the mechanism. |
Do's and don'ts
Moved up 9
places
Forecall: suspected intracranial haemorrhage —
prioritisation only, not a diagnosis
The movement, the reason and the boundary, on the row. A reader can tell what happened and what it does not entitle them to conclude.
AI · 0.94
A badge and a probability. It states nothing about position, invites the reader to act on the number, and borrows an alarm hue for a queue decision.
CT cervical spine · 56 min
Moved down 1 place
The cost of somebody else's promotion, stated on the study that paid it. This is the row that makes a triage device honest.
CT cervical spine · 56 min
The list silently rearranged. Every displacement is invisible, so the device's only measurable effect is the one that flatters it.
Named studies, clinical framing, critical priority. Somebody on shift can act on this.
HL7 endpoint unreachable · retrying (attempt 41)
An integration message in a log nobody reads, describing a clinical state: four people's scans are not being prioritised.
One worklist. Promoted studies appear in it, in position, with the reason.
The radiologist works from the list they already work from. Nothing new has to be remembered or checked.
A separate AI findings dashboard beside the worklist.
Two incomplete lists competing for attention. Checking it becomes a discipline, and disciplines decay on a night shift.
Accessibility
- The movement is text, not position alone. A screen-reader user reading row by row has no sense of "near the top", so "moved up 9 places" is the only way the change is perceivable.
- The disclaimer is in the row's accessible name, not a visual caption beneath the table. It must be announced with the row that carries it.
- Priority stripes are never the only signal. The colour bar repeats what the clinical-priority text already says — see Colour.
- Reordering is announced politely and never moves rows under a travelling pointer or an open keyboard focus — the same rule as Triage worklist and Data grid.
- Focus survives a reorder. If the row a user was on moves, focus moves with the row, not with the position.
- No alarm hue on the promotion chip. A queue decision is not a clinical priority; the study's own priority is rendered separately.
- Delivery failure is an assertive announcement, because it is a clinical state with a time cost — unlike the promotions themselves.
- Targets ≥ 24 px and readable at 320 px (SC 2.5.8, SC 1.4.10); reading-room worklists are also opened on phones when someone is called from home.
Outcomes of use
What this contributes to, in the terms of Usability & context of use. These are attributes believed to contribute to an outcome; the outcome itself is settled by observing real use in a specified context, not by this page.
- Effectiveness — the study most likely to need urgent action is read sooner, and nothing else is delayed past its own clinical window. Only measuring the first half is how a triage device passes evaluation while moving harm around.
- Efficiency — minutes to read for flagged studies, against zero added reading effort. A triage device that requires the radiologist to do anything new has spent the time it was supposed to save.
- Satisfaction — a queue whose order can be explained. Radiologists work around mechanisms they cannot predict, and a list that rearranges for undisclosed reasons is one they will start re-sorting manually.
Clinical safety notes
Trace these in your risk file (ISO 14971) and usability engineering file (IEC 62366-1).
- Displacement stated on the studies that were moved down. Mitigates: delay to an unflagged study that nobody attributes to the device.
- Clinical priority preserved and visible. Mitigates: a device's opinion overwriting a referrer's stated urgency.
- Output never visible during the read. Mitigates: a prioritisation device functioning as an unvalidated detection aid, with its anchoring effects.
- No confidence score on the worklist. Mitigates: a reader acting on a probability the device was not evaluated to provide.
- Never enters or pre-populates the report. Mitigates: a triage output becoming a diagnostic claim in the record.
- Single worklist, no parallel dashboard. Mitigates: split attention across two incomplete queues, and decay of a checking discipline.
- Positive delivery confirmation; undelivered raised as clinical. Mitigates: studies believed prioritised that were not.
- Degrades to not-reordering. Mitigates: an intermittently reordered queue whose behaviour cannot be learned or trusted.
- Studies enter the queue before analysis completes. Mitigates: the device becoming a bottleneck on every scan, including the ones it never flags.
- Cannot demote below clinical priority or remove. Mitigates: suppression occurring under a prioritisation claim.
- Displaced-study read times monitored. Mitigates: queue starvation at the tail, and harm relocated rather than reduced.
Related
- Reader paradigm — why the output must stay out of the reading room, and what changes when it does not.
- Triage worklist — ordering by consequence, and never reordering under the reader.
- Suppression & the unraised alarm — the neighbouring capability this device must not acquire.
- Confidence disclosure — why a score belongs with a finding a clinician can weigh, and not on a queue.
- Data grid — live reordering rules.
- Forecall — the reference application, and why it is deliberately narrow.