Evidence and argument map
Evidence boundary: This dossier explains the evidence and reasoning behind an Analysis article. It does not establish that DMICP caused harm, contains the civilian defects described, is unsafe, or fails DCB0129/DCB0160. Evidence cut-off: 15 July 2026.
This page maps the article's argument to its Vancouver references and the project's stable source records. It is a derivative traceability view, not a second source register. The source register remains the authority for source identity and reliability notes, while the manuscript remains the publication text.
Evidence-status labels
| Label | Meaning in this dossier |
|---|---|
| Publicly verified | Supported by an identifiable public source within that source's date and scope |
| Historical | Public evidence about an earlier version, configuration or service state; not assumed current |
| Author-supplied | Operational context supplied by the project owner but not independently published |
| Analytical inference | A testable interpretation derived from evidence, not a reported fact |
| Unknown | Evidence was not located or supplied; this does not mean absent or non-conformant |
Confidence below applies only to the permitted proposition stated in the row. It does not transfer the finding to DMICP.
Argument-to-evidence trace
| Argument step and article location | Manuscript refs | Project sources | Evidence status and scoped confidence | Boundary retained |
|---|---|---|---|---|
| Health-IT safety is sociotechnical: technology, interfaces, workflow, people and governance interact (Introduction). | 1–3 | SRC-162, SRC-163, SRC-164 | Publicly verified; high for the frameworks and reported US investigation series | Conceptual and US evidence; not UK Defence incidence |
| Connectivity does not guarantee trusted, visible or actionable information (Safety occurs at the seams). | 4–6 | SRC-029, SRC-165, SRC-166 | Publicly verified; moderate–high for mechanism plausibility | Heterogeneous evidence and a non-probability clinician survey; no DMICP finding |
| Military care adds mobility, infrastructure, security and deployment challenges. | 7 | SRC-027 | Publicly verified; moderate for cross-military context | Review findings cannot be transferred unchanged to UK Defence |
| UK Defence publications illustrate limitations in screening surveillance and coded EHR completeness. | 8–9 | SRC-167, SRC-168 | Publicly verified; high for the two publication-specific observations | Bounded reports; no product-wide or causal inference |
| DMICP remained a current MOD electronic medical record in the 2025/26 reporting period (Why Defence amplifies seam risk). | 10 | SRC-145 | Publicly verified; high for current use at the source date | Does not establish build, topology, interfaces or clinical-safety assurance |
| Public material supports dated EMIS DPCS/PCS lineage and historical central hosting. | 11–12 | SRC-146, SRC-139 | Publicly verified/historical; high for the dated lineage, moderate for vendor-described hosting | Not proof of the exact 2026 application or architecture |
| One current PDS connection is documented and four-nation interoperability is a CORTISONE driver. | 13–14 | SRC-148, SRC-138 | Publicly verified; high for the stated interface and programme intent | Neither source is a complete interface catalogue or evidence of delivered capability |
| CQC material shows hybrid records, access constraints and manual bridges at particular Defence services. | 15–18 | SRC-141, SRC-150, SRC-156, SRC-151 | Publicly verified; high for the inspection observations | Site-, date- and programme-bounded; not prevalence or proof of a software root cause |
| A critical result can be filed without sufficient salience or accountable closure (Coronial reports). | 19 | SRC-001 | Publicly verified; high for the coroner's stated concern | Interface, display, workload and workflow contributions are not isolated |
| A digital enquiry can enter an administrative route without clinical visibility or record incorporation. | 20 | SRC-014 | Publicly verified; high for the report-specific concern | The incident software supplier is not identified |
| An ambulance electronic record can remain outside the receiving handover workflow. | 21 | SRC-004 | Publicly verified; high for the report-specific concern | Proposed technical remedies are respondent evidence, not coronial findings |
| Registration or organisational boundaries can expose an incomplete recent-care or allergy view. | 22–23 | SRC-021, SRC-020 | Publicly verified; high for the two civilian scenarios | Analytical inference when translated into a Defence test |
| Screening safety depended on manual creation of a specific non-responder warning. | 24 | SRC-002, SRC-016, SRC-076 | Publicly verified; high for the report and response accounts | Generic smear-due alerts existed; only the specific non-responder status was missing |
| Amendment history can be present in an audit trail but absent from an exported summary. | 25 | SRC-003, SRC-017 | Publicly verified; high for the report and response accounts | The live audit trail retained prior content; the concern involved representation in export |
| DCB0129 and DCB0160 provide manufacturer and deploying-organisation lifecycle assurance benchmarks (Assurance agenda). | 26–28 | SRC-130, SRC-131, SRC-134 | Publicly verified; high for the standards and their current review status | Formal Defence applicability and DMICP conformity status are unknown |
| Record-transfer replacement and SystmOne rollout are planned, making coexistence and migration safety-relevant. | 29–30 | SRC-152, SRC-153 | Publicly verified; high for announced intent and schedule | Programme statements are not proof of deployment, integration or clinical-safety acceptance |
All 30 manuscript references are represented above. Recipient responses remain distinguishable from coronial reports throughout the canonical source register.
Controlled translation beyond the article
The article compresses the evidence into six safety-critical seams: visibility, work ownership, interoperability and identity, integrity and provenance, resilience, and governance. The project's fuller controlled translation continues through:
- the claims register, which preserves source-linked
CLM-statements; - the candidate Defence requirements, which remain Defence-unvalidated;
- the designed assurance tests, which remain unexecuted; and
- the two-page clinical and patient-safety thematic analysis, which maps the wider targeted corpus without converting recurrence counts into prevalence.
Knowledge deliberately kept outside the public argument
SRC-005 records author-supplied operational context, and SRC-142 records a sibling-project provenance audit. Neither is independent authority and neither is cited as evidential support in the public manuscript. Raw sibling-project paths and working notes remain repository-only; their safe, source-routed conclusions are represented in the Defence and DMICP evidence baseline.