Military EHR safety principles
This explanatory page groups the project’s Defence design principles. The canonical, machine-readable control statements are the Defence requirements register, and their designed verification scenarios are the assurance test catalogue.
The translation chain is:
Observed civilian mechanism → safety barrier → candidate Defence requirement → representative assurance test
The principles are analytical translations. They are not coronial recommendations, accepted Programme CORTISONE requirements, or evidence that a current Defence system lacks a control.
| Principle | Canonical requirements | Representative assurance |
|---|---|---|
| Make identity, location, registration and care responsibility independently visible | REQ-001 | AST-001 |
| Keep safety-search populations complete and explainable | REQ-002 | AST-002 |
| Disclose record-source completeness across boundaries | REQ-003 | AST-003 |
| Convert critical results into owned, time-bounded clinical work | REQ-004 | AST-004 |
| Make messages, referrals and tasks auditable from entry to closure | REQ-005 | AST-005 |
| Deliver transfer records into the receiving workflow and longitudinal record | REQ-006 | AST-006 |
| Preserve authority and ownership during hybrid paper–digital work | REQ-007 | AST-007 |
| Preserve provenance across live, printed, exported and investigation views | REQ-008 | AST-008 |
| Make decision support proportionate, actionable and owned | REQ-009 | AST-009 |
| Treat existing safety barriers as migration requirements | REQ-010 | AST-010 |
| Make multi-endpoint transaction state observable and reconcilable | REQ-011 | AST-011 |
| Preserve a safe minimum function and controlled recovery when degraded | REQ-012 | AST-012 |
| Govern minimum necessary information across clinical–operational boundaries | REQ-013 | AST-013 |
Human-factors rule
Do not classify the source cases as “user error”. Assurance must test the coupled system: interface, workload, staffing, policy, training, workarounds, interoperability, governance and fallback. A control that works only when every user remembers an invisible dependency is not a strong safety barrier.
Validation boundary
None of the candidate requirements is yet validated as a Defence programme requirement, and none of the assurance scenarios has been executed. Read the transferability assessment and DMICP evidence gaps before applying them.