Skip to content

Defence application

This section translates civilian Regulation 28 evidence into candidate controls and tests for Defence Primary Healthcare (DPHC) and Programme CORTISONE. It is an analytical application layer: the civilian reports establish hazard mechanisms in their own settings, not defects in DMICP or requirements accepted by Defence.

Start here

  1. Read the transferability and limitations assessment to understand what can and cannot be inferred.
  2. Use the DPHC/CORTISONE view to see the most relevant case-to-control chains.
  3. Cite candidate controls by stable ID from the Defence requirements register.
  4. Cite designed scenarios by stable ID from the assurance test catalogue.
  5. Treat the DMICP evidence gaps as open questions requiring Defence evidence, not findings.

Authority and traceability

The machine-readable authorities are requirements.csv and assurance_tests.csv. They consolidate the earlier DPHC/CORTISONE table and the military EHR safety principles. The source principles remain useful explanatory material; new analysis should reference the canonical REQ- and AST- identifiers.

The trace runs in one direction:

Primary source → evidence claim → reviewer code and finding → candidate Defence requirement → designed assurance test

Every REQ- item exposes its case, claim, code, applicability and validation status. Requirements without a direct featured-case or claim trace are labelled hypotheses rather than silently presented as evidence-backed controls.

Current status

  • 13 candidate requirements are registered; none is validated as a Defence programme requirement.
  • 13 assurance scenarios are designed; none has been executed.
  • The strongest direct analogues concern mobile-population record sources, population safety searches, critical-result closure, transfer-record availability, message routing and amendment visibility.
  • Defence-specific workflow, incident, architecture, user-research and clinical-safety evidence remains outstanding.