Clinical patterns

Suppression & the unraised alarm

Software that decides what not to show a clinician has made a clinical decision on their behalf. Acknowledge & escalate designs the life of an alarm that was raised. This page designs the accountability for one that never was.

Stable · v1.0 QuietWard IEC 60601-1-8 WCAG 2.2 AA

Overview

Alarm burden is real and this system has already argued it — see alarm burden. This page starts from the position that reduction is justified and asks the harder question: once the software is allowed to be silent, how does anyone check the silence?

Every other pattern here concerns something on screen. The whole subject matter of this one is something that is not, which changes what the interface is for. It stops presenting evidence for a decision the clinician is about to make and starts accounting for a decision already taken — by software, unattended, possibly hours ago.

Harm by omission

A false alarm announces itself. A suppressed true alarm does not — and there is no moment at which anyone discovers it, because nothing appeared and nothing was dismissed. The failure mode of this class of software is invisible to exactly the people it affects, which is why the accountability has to be designed rather than assumed.

Silence is an output

Withholding is a decision the software made. It is logged, attributed to a rule, timed, and countable — exactly like an alarm that fired.

Deferred, never deleted

Nothing is discarded. A signal the software chose not to raise still exists, still has its priority, and can still be looked at.

One action to the whole

Recovery happens from the clinical surface where the alarm would have appeared — never by asking an administrator or opening a different system.

Three mechanisms, three different promises

"Suppression" is usually used to mean three quite different things. They carry different risk and must not share a rendering, because a clinician who believes an alarm was delayed will behave differently from one who knows it will never arrive.

MechanismWhat it promisesWhat it must show
Defer You will see this, later — if it is still true. A short hold to see whether a transient resolves itself. A running count of what is currently held, and the maximum hold period. A deferral with no upper bound is a withholding wearing a friendlier word.
Group You will see this, but once rather than forty times. Nothing is removed; repetition is. The occurrence count and the time span. Twelve desaturation events in an hour is a different clinical picture from one, and the group must not flatten that.
Withhold You will not see this unless you go looking. The most accountability of the three: a persistent count on the clinical surface, the rule responsible, and one-action recovery.
A deferral that resolves is still an event

The most attractive-looking saving in this whole category is the transient that fixes itself during the hold — the software waited, the value came back, nobody was disturbed. It is a real saving and it is still a thing that happened. It stays in the record with its own count, because "how often does this patient briefly desaturate" is a clinical question, and a system that silently answers "never" is answering it wrongly.

Anatomy

The clinical surface carries its own silence
Ward 4B · alarms QuietWard active · rules v12 since 06:00
3
Bed 12 · SpO₂ below 88%
3 occurrences grouped, 14:02–14:31, longest 90 s
Grouped by rule "repeat desaturation, 30 min window"
Not raised on this ward 17 in the last 4 h
14 deferred and self-resolved · 3 currently held · 0 withheld

The count of what was not shown sits on the same surface as what was, at all times — not on a settings page, not in a report nobody opens.

PartRule
Active indicator The clinical surface states that suppression is running, and which rule version. A clinician must never have to find out from a colleague that the ward is quieter than it would otherwise be.
Silence count Persistent, not on demand. Broken down by mechanism, because deferred-and-resolved, currently-held and withheld are three different facts.
Attribution Every suppressed item names the rule that suppressed it, in the rule's own words. A rule identifier is not attribution.
Recovery One action, from here. Never a link into an administration console, and never a permission the bedside clinician does not have.
Group count Occurrences and time span on the face of the grouped alarm — see Badge, and note that the alarm banner's own counter is the one place a count may carry an alarm hue.
Priority preserved A suppressed item keeps its IEC priority. Suppression changes whether it was announced, never what it is.

What may never be suppressed

The rule that carries the risk

High-priority alarms are not suppressible by any mechanism, at any threshold, under any rule. Not deferred, not grouped, not withheld. IEC 60601-1-8 reserves the high-priority signal for conditions requiring immediate operator response, and software that holds one for thirty seconds to see whether it resolves has substituted its judgement for the standard's.

Getting it back

The distinction between suppression and data loss is entirely a matter of recovery. If a clinician at the bedside cannot see what was withheld, in the moment they think to ask, then the signal was not suppressed — it was destroyed, and the interface merely delayed anyone finding out.

One action, from the clinical surface
  • 14:31:08
    Bed 12 · SpO₂ 86% — deferred 60 s, resolved at 14:32:04. Not raised.
    Rule: "transient desaturation under 90 s" · medium priority retained
  • 14:18:44
    Bed 9 · heart rate 121 — grouped with 4 earlier occurrences into one alarm at 14:02.
    Rule: "repeat tachycardia, 30 min window" · medium priority retained
  • 13:50:12
    Bed 12 · lead offraised immediately. Technical alarms are never suppressed.
    No rule applied

Chronological, in clinical language, with the responsible rule quoted. The third entry is there deliberately: showing what was not suppressed is how a clinician calibrates what the system is doing.

Supervising in aggregate

On-the-loop supervision means reviewing decisions you were not present for, in volumes that make case-by-case reading impossible. Eight hours of a ward might produce four hundred suppressed events. Nobody reads four hundred of anything at handover.

So the review is by sampling and exception, and the interface has to be honest that this is what it is:

Surfaced for reviewWhy
Anything deferred that did not self-resolve The deferral bet on a transient and lost. This is the population where harm concentrates.
Groups whose occurrence count crossed a stated threshold Twelve events grouped into one is a trend the grouping made invisible.
Any suppressed signal on a patient who later deteriorated Computed retrospectively. The single most useful view in the product, and the one nobody thinks to build.
A random sample of the rest Stated as a sample, with its rate. "12 of 380 reviewed" is honest; an unlabelled list implies completeness it does not have.
Rule-level counts and trend A rule whose suppression volume doubles this week has changed meaning, whether or not anyone edited it.
Say the sampling rate out loud

A review screen showing twenty items out of four hundred, with no denominator, is read as "here is what happened". The rule from List & tree applies with more force here than anywhere else in the system: the numerator means nothing without the denominator, and a supervisor's sense of whether the system is behaving depends entirely on knowing which they are looking at.

States

StateRendering
Active Named on the clinical surface with the rule version and the time it took effect.
Currently holding A live count of items in deferral, with the maximum remaining hold. A clinician walking to a bed is entitled to know something is being held about it.
Disabled Announced, not silent. The ward becomes louder; if nobody is told why, the change reads as a fault and someone will try to fix it.
Degraded Rules unreadable or partially applied — everything is raised, and the surface says suppression is not running.
Rules changed mid-shift Announced at the bedside with author and time. See Safety configuration.
Backlog on recovery After an outage, held items are released as a summarised set with their original times — never replayed as a burst of live alarms.

Do's and don'ts

Do
Not raised on this ward 17 in the last 4 h
14 deferred and self-resolved · 3 currently held · 0 withheld

The silence is countable and broken down by mechanism, on the surface where the alarms would have been.

Don't
Ward 4B · alarms
No active alarms

Technically true and clinically misleading. Seventeen signals were handled by a rule and the surface presents a quiet ward.

Do
12
Bed 9 · desaturation ×12, 14:02–15:00

Grouping removed the repetition and kept the count and the span. Twelve events in an hour is the finding.

Don't
Bed 9 · desaturation

Grouping flattened twelve events into one. The clinician now sees the same picture as a patient who desaturated once.

Do

Bed 12 · lead off — raised immediately. Technical alarms are never suppressed.

A signal that means "nothing is watching this patient" is the last thing that should ever be quietened.

Don't

Bed 12 · lead off — deferred 5 min (rule: "nuisance technical alarms").

The bed now looks quiet because it is unmonitored. This is the failure mode that makes alarm-reduction software dangerous rather than merely annoying.

Do

Reviewed 12 of 380 suppressed events · random sample plus all non-resolving deferrals

The denominator and the sampling rule. A supervisor knows exactly what they have and have not seen.

Don't

Suppressed events · last 8 hours

Twelve rows under a heading that implies all of them. The supervisor signs off on a shift they have seen three per cent of.

Accessibility

Outcomes of use

What this contributes to, in the terms of Usability & context of use. These are attributes believed to contribute to an outcome; the outcome itself is settled by observing real use in a specified context, not by this page.

Clinical safety notes

Risk controls carried by this pattern

Trace these in your risk file (ISO 14971) and usability engineering file (IEC 62366-1).

NotJustAnyMed.Tech Design System · Suppression & the unraised alarm · v1.0 · draft for review
Reference applications named in this system are fictional; all patient data, rules and alarm volumes shown are fabricated and illustrative.