Suppression & the unraised alarm
Software that decides what not to show a clinician has made a clinical decision on their behalf. Acknowledge & escalate designs the life of an alarm that was raised. This page designs the accountability for one that never was.
Overview
Alarm burden is real and this system has already argued it — see alarm burden. This page starts from the position that reduction is justified and asks the harder question: once the software is allowed to be silent, how does anyone check the silence?
Every other pattern here concerns something on screen. The whole subject matter of this one is something that is not, which changes what the interface is for. It stops presenting evidence for a decision the clinician is about to make and starts accounting for a decision already taken — by software, unattended, possibly hours ago.
A false alarm announces itself. A suppressed true alarm does not — and there is no moment at which anyone discovers it, because nothing appeared and nothing was dismissed. The failure mode of this class of software is invisible to exactly the people it affects, which is why the accountability has to be designed rather than assumed.
Silence is an output
Withholding is a decision the software made. It is logged, attributed to a rule, timed, and countable — exactly like an alarm that fired.
Deferred, never deleted
Nothing is discarded. A signal the software chose not to raise still exists, still has its priority, and can still be looked at.
One action to the whole
Recovery happens from the clinical surface where the alarm would have appeared — never by asking an administrator or opening a different system.
Three mechanisms, three different promises
"Suppression" is usually used to mean three quite different things. They carry different risk and must not share a rendering, because a clinician who believes an alarm was delayed will behave differently from one who knows it will never arrive.
| Mechanism | What it promises | What it must show |
|---|---|---|
| Defer | You will see this, later — if it is still true. A short hold to see whether a transient resolves itself. | A running count of what is currently held, and the maximum hold period. A deferral with no upper bound is a withholding wearing a friendlier word. |
| Group | You will see this, but once rather than forty times. Nothing is removed; repetition is. | The occurrence count and the time span. Twelve desaturation events in an hour is a different clinical picture from one, and the group must not flatten that. |
| Withhold | You will not see this unless you go looking. | The most accountability of the three: a persistent count on the clinical surface, the rule responsible, and one-action recovery. |
The most attractive-looking saving in this whole category is the transient that fixes itself during the hold — the software waited, the value came back, nobody was disturbed. It is a real saving and it is still a thing that happened. It stays in the record with its own count, because "how often does this patient briefly desaturate" is a clinical question, and a system that silently answers "never" is answering it wrongly.
Anatomy
The count of what was not shown sits on the same surface as what was, at all times — not on a settings page, not in a report nobody opens.
| Part | Rule |
|---|---|
| Active indicator | The clinical surface states that suppression is running, and which rule version. A clinician must never have to find out from a colleague that the ward is quieter than it would otherwise be. |
| Silence count | Persistent, not on demand. Broken down by mechanism, because deferred-and-resolved, currently-held and withheld are three different facts. |
| Attribution | Every suppressed item names the rule that suppressed it, in the rule's own words. A rule identifier is not attribution. |
| Recovery | One action, from here. Never a link into an administration console, and never a permission the bedside clinician does not have. |
| Group count | Occurrences and time span on the face of the grouped alarm — see Badge, and note that the alarm banner's own counter is the one place a count may carry an alarm hue. |
| Priority preserved | A suppressed item keeps its IEC priority. Suppression changes whether it was announced, never what it is. |
What may never be suppressed
High-priority alarms are not suppressible by any mechanism, at any threshold, under any rule. Not deferred, not grouped, not withheld. IEC 60601-1-8 reserves the high-priority signal for conditions requiring immediate operator response, and software that holds one for thirty seconds to see whether it resolves has substituted its judgement for the standard's.
- Technical alarms about the monitoring itself. A lead-off, a disconnected sensor, a dead battery — these look like noise and are the opposite. They mean you are not monitoring this patient, and suppressing them creates a bed that appears quiet because nothing is watching it.
- Anything a clinician has explicitly flagged on this patient. A human instruction outranks a population rule, always.
- Any alarm whose suppression rule was authored after it started firing. Rules apply forward; they do not reach back and quieten something already in progress.
- Anything during a declared clinical event — a resuscitation, a rapid response call. Suppression is a steady-state optimisation and has no business running during the minutes it was never evaluated for.
- Everything, when the rule set cannot be read. If QuietWard cannot confirm which rules are in force, it raises everything. The safe failure of an alarm-reduction system is to stop reducing.
Getting it back
The distinction between suppression and data loss is entirely a matter of recovery. If a clinician at the bedside cannot see what was withheld, in the moment they think to ask, then the signal was not suppressed — it was destroyed, and the interface merely delayed anyone finding out.
-
14:31:08Bed 12 · SpO₂ 86% — deferred 60 s, resolved at 14:32:04. Not raised.Rule: "transient desaturation under 90 s" · medium priority retained
-
14:18:44Bed 9 · heart rate 121 — grouped with 4 earlier occurrences into one alarm at 14:02.Rule: "repeat tachycardia, 30 min window" · medium priority retained
-
13:50:12Bed 12 · lead off — raised immediately. Technical alarms are never suppressed.No rule applied
Chronological, in clinical language, with the responsible rule quoted. The third entry is there deliberately: showing what was not suppressed is how a clinician calibrates what the system is doing.
- Reachable at the bedside, by bedside permissions. If seeing it requires an administrator, the design has moved accountability to the one person not present.
- Same view, patient-scoped and ward-scoped. "What did this system not tell me about this patient" is the question actually asked.
- Retained at least as long as the clinical record of the same period. Shorter retention makes an incident review impossible precisely when it matters.
- Exportable. The suppression log is evidence in a serious-incident investigation, and it must leave the system in a form somebody can read.
- Never filtered by default. The one screen whose entire purpose is showing what was hidden must not hide any of it — see Filter.
Supervising in aggregate
On-the-loop supervision means reviewing decisions you were not present for, in volumes that make case-by-case reading impossible. Eight hours of a ward might produce four hundred suppressed events. Nobody reads four hundred of anything at handover.
So the review is by sampling and exception, and the interface has to be honest that this is what it is:
| Surfaced for review | Why |
|---|---|
| Anything deferred that did not self-resolve | The deferral bet on a transient and lost. This is the population where harm concentrates. |
| Groups whose occurrence count crossed a stated threshold | Twelve events grouped into one is a trend the grouping made invisible. |
| Any suppressed signal on a patient who later deteriorated | Computed retrospectively. The single most useful view in the product, and the one nobody thinks to build. |
| A random sample of the rest | Stated as a sample, with its rate. "12 of 380 reviewed" is honest; an unlabelled list implies completeness it does not have. |
| Rule-level counts and trend | A rule whose suppression volume doubles this week has changed meaning, whether or not anyone edited it. |
A review screen showing twenty items out of four hundred, with no denominator, is read as "here is what happened". The rule from List & tree applies with more force here than anywhere else in the system: the numerator means nothing without the denominator, and a supervisor's sense of whether the system is behaving depends entirely on knowing which they are looking at.
States
| State | Rendering |
|---|---|
| Active | Named on the clinical surface with the rule version and the time it took effect. |
| Currently holding | A live count of items in deferral, with the maximum remaining hold. A clinician walking to a bed is entitled to know something is being held about it. |
| Disabled | Announced, not silent. The ward becomes louder; if nobody is told why, the change reads as a fault and someone will try to fix it. |
| Degraded | Rules unreadable or partially applied — everything is raised, and the surface says suppression is not running. |
| Rules changed mid-shift | Announced at the bedside with author and time. See Safety configuration. |
| Backlog on recovery | After an outage, held items are released as a summarised set with their original times — never replayed as a burst of live alarms. |
Do's and don'ts
The silence is countable and broken down by mechanism, on the surface where the alarms would have been.
Technically true and clinically misleading. Seventeen signals were handled by a rule and the surface presents a quiet ward.
Grouping removed the repetition and kept the count and the span. Twelve events in an hour is the finding.
Grouping flattened twelve events into one. The clinician now sees the same picture as a patient who desaturated once.
Bed 12 · lead off — raised immediately. Technical alarms are never suppressed.
A signal that means "nothing is watching this patient" is the last thing that should ever be quietened.
Bed 12 · lead off — deferred 5 min (rule: "nuisance technical alarms").
The bed now looks quiet because it is unmonitored. This is the failure mode that makes alarm-reduction software dangerous rather than merely annoying.
Reviewed 12 of 380 suppressed events · random sample plus all non-resolving deferrals
The denominator and the sampling rule. A supervisor knows exactly what they have and have not seen.
Suppressed events · last 8 hours
Twelve rows under a heading that implies all of them. The supervisor signs off on a shift they have seen three per cent of.
Accessibility
- The silence count is text on the clinical surface, in the accessible name of the region — not a subtle dimming, a smaller typeface, or an icon.
- Grouped alarms announce their count and span: "bed 9, desaturation, 12 occurrences, 14:02 to 15:00". A visual badge alone leaves a screen-reader user with a single event.
- Suppression state changes are announced politely
(
aria-live="polite"); alarms themselves remain assertive. The system becoming quieter is important and is not itself an emergency. - Neutral chips for suppression state. Being deferred is not a clinical priority — the alarm's own IEC priority is unchanged and rendered separately. See Colour.
- Recovery is keyboard-reachable from the alarm region, not only from a toolbar overflow — this is the control most likely to be needed in a hurry.
- The review log is a real list so its size is announced, and the sampling statement sits inside the same labelled region as the items.
- No reliance on audio to convey that suppression is running. This system specifies the visual half of IEC 60601-1-8 only — see Known gaps.
- Targets ≥ 24 px (SC 2.5.8) and readable at 320 px (SC 1.4.10); ward displays are often viewed at distance, so see Scaling & displays.
Outcomes of use
What this contributes to, in the terms of Usability & context of use. These are attributes believed to contribute to an outcome; the outcome itself is settled by observing real use in a specified context, not by this page.
- Effectiveness — no clinically significant signal is unavailable to the clinician who needs it. The measure that matters is suppressed events on patients who later deteriorated, and it is computable.
- Efficiency — the reduction is the point, and it is worth having: alarms per clinician-hour is the resource this software exists to protect. The cost side is the supervision it creates, which must stay small enough to actually happen.
- Satisfaction — trust in a quiet ward. A clinician who suspects the system is hiding things will start checking the monitors directly, at which point the product has made the workload worse while appearing to reduce it.
Clinical safety notes
Trace these in your risk file (ISO 14971) and usability engineering file (IEC 62366-1).
- High-priority alarms are never suppressed by any mechanism. Mitigates: a condition requiring immediate response being held, grouped or withheld.
- Technical alarms are never suppressed. Mitigates: an unmonitored patient presenting as a quiet bed.
- Suppression count persistently visible on the clinical surface. Mitigates: a clinician believing a ward is quiet when it is being quietened.
- One-action recovery with bedside permissions. Mitigates: suppression becoming data loss because retrieval required someone not present.
- Group counts and time spans preserved. Mitigates: a trend flattened into a single event.
- Deferrals bounded, and non-resolving deferrals surfaced. Mitigates: an unbounded hold functioning as a permanent withholding.
- Rules never applied retrospectively to a firing alarm. Mitigates: an in-progress alarm silenced by an edit made after it started.
- Suppression disabled during declared clinical events. Mitigates: a steady-state optimisation running during a resuscitation.
- Unreadable rule set raises everything. Mitigates: a degraded configuration service silently suppressing more than intended.
- Sampling rate and denominator stated on review screens. Mitigates: a supervisor signing off on a shift they saw a fraction of.
- Backlog released as a summary, not replayed. Mitigates: an alarm burst after recovery that is itself a safety hazard.
Related
- Acknowledge & escalate — the lifecycle of an alarm that was raised, and where alarm burden is argued.
- Safety configuration — who authors these rules, and what must happen before one takes effect.
- Triage worklist — proving a list is live, which is the same instinct at the level of a queue.
- Filter — the same "what am I not seeing?" problem when a human chose the narrowing.
- Alert Banner — priority rendering, and the occurrence counter that grouping relies on.
- QuietWard — the reference application and its position on the autonomy axis.