Skip to content

DPHC and Programme CORTISONE

This is a scoped DPHC/CORTISONE view of the canonical Defence requirements register and assurance test catalogue. The requirements are analytical translations for validation; they are not coronial directions to Defence, findings that DMICP has the same defects, or accepted CORTISONE requirements.

Strongest case-to-control chains

DPHC/CORTISONE question Civilian evidence Candidate controls Designed tests
Can the service enumerate everyone it currently supports when location, registration and care responsibility differ? Samuel Jordan and Rachelle Ross; CLM-010, CLM-002 and analytical CLM-007 REQ-001, REQ-002 AST-001 and AST-002
Does a receiving clinician see recent and safety-critical information across Defence and civilian sources, with omissions disclosed? Stephen Cassidy and Samuel Jordan; CLM-009 and CLM-010 REQ-003 AST-003
Do critical results become owned clinical work rather than merely available or filed data? Stephen Rhodes and Eric Thompson; CLM-001 and CLM-008 REQ-004, REQ-009 AST-004 and AST-009
Do messages, referrals and recommendations reach accountable clinical triage and the longitudinal record? Stephen Stringer, Rhodes and Thompson; CLM-005, CLM-001 and CLM-008 REQ-005 AST-005
Do evacuation and transfer records arrive in the receiving workflow with review and finalisation state? Morris Reddington and Cassidy; CLM-004 and CLM-009 REQ-006 AST-006
Are paper fallback, retrospective amendment and exported views safe and reconstructable? Audrey King and Alexander Braund; CLM-015 and CLM-003 REQ-007, REQ-008 AST-007 and AST-008

Priority candidate requirements

The case series most directly supports taking the following candidates into Defence discovery and hazard analysis:

  • REQ-001 and REQ-002: separate identity, physical support location, care responsibility, registration, record source and cohort membership; expose denominator and exclusions.
  • REQ-003 and REQ-006: define the minimum record and make transfer/source completeness, arrival, review and reconciliation visible.
  • REQ-004 and REQ-005: model results, messages, referrals and recommendations as owned work with acknowledgement, deadline, escalation and closure.
  • REQ-007 and REQ-008: preserve authority and provenance across paper, live, printed, exported and investigation views.
  • REQ-009: evaluate high-severity decision support as part of the whole workflow, including workload and downstream ownership.

REQ-010 and REQ-011 now have direct case-linked claims for safety-control migration and distributed transaction integrity, although their application to CORTISONE remains unvalidated. REQ-012 and REQ-013 deliberately retain partial-scope labels: their reports support fragile degraded workflows and missing cross-boundary risk signals, while conflict-safe offline synchronisation and the added Defence governance constraints remain analytical extensions.

Assurance questions

  1. Can every person physically or operationally supported by a practice be enumerated, including posted, attached, embarked, deployed, temporary and wrongly registered personnel?
  2. Do safety searches expose their denominator, exclusions, contributing sources and freshness?
  3. Can a receiving team identify missing recent care or a missing source instead of treating one record as complete?
  4. Are critical results and recommendations converted into owned work with acknowledgement, escalation and clinical closure?
  5. Do all supported message, referral and transfer channels expose destination, review, rejection, correction and finalisation?
  6. Do live, paper, printed and exported representations preserve provenance and prompt reconciliation?
  7. What happens during prolonged disconnection, staged reconnection, migration and partial endpoint failure?

The corresponding executable designs are AST-001 to AST-013.

Transferability limits

Civilian mechanisms are most useful as hazards to test, not as proof of Defence performance. Differences in population movement, operational authority, information governance, connectivity, coalition care, clinical roles, threat environment and system architecture could weaken or strengthen each analogy. The review is targeted rather than exhaustive and cannot estimate incidence or trend. Current product behaviour may also differ from that described in a historical report.

See the full transferability and limitations assessment.

DMICP evidence gaps

The present source set does not establish DMICP cohort completeness, interoperability, result routing, task closure, export provenance, offline behaviour or migration readiness. The project-sponsor concern behind CLM-007 is explicitly low-confidence and analytical.

The DMICP evidence-gap register defines the workflow, architecture, data-quality, incident, user-research and test evidence needed before any candidate can be described as a current-system finding or an accepted CORTISONE control.