Clinical safety at the seams: how UK Defence medical information systems may cause harm during digital transition
Article type: Analysis Running title: Clinical safety at Defence digital seams Evidence cut-off: 15 July 2026 Author details: To be completed by the accountable human author team before submission.
Abstract
UK Defence healthcare increasingly depends on digital information moving safely across primary care, occupational health, civilian providers, deployed settings and four national health systems. The principal risk is not simply that an electronic health record might fail. Harm can arise at the seams between records, interfaces, organisations and representations: information may exist but be unavailable to the clinician; a message may arrive without becoming owned work; registration may select an incomplete record or cohort; and paper, live, printed and exported views may disagree. Public sources document the long-lived Defence Medical Information Capability Programme (DMICP), historically describe central hosting and selective NHS connectivity, and show hybrid local workflows. They also document replacement by a SystmOne-based capability beginning from 2027. Civilian Prevention of Future Deaths reports illustrate credible mechanisms involving critical-result visibility, digital enquiry routing, handover, screening status, record-source selection and amendment provenance. These reports are hazard-discovery signals, not evidence that the same defects exist in DMICP or caused harm in Defence. This analysis argues for a whole-service, sociotechnical safety approach during transition: establish the current architecture and workflow baseline; assign responsibility across manufacturers, integrators and Defence users; test closed-loop work under realistic mobility, workload and degraded-operation conditions; monitor missingness and workarounds; and preserve safety controls through coexistence, migration and retirement. NHS clinical-risk standards DCB0129 and DCB0160 provide a useful benchmark, although their formal applicability to Defence and DMICP's present clinical-safety regime require confirmation.
Keywords: electronic health records; military medicine; patient safety; medical informatics; interoperability
Key messages
What is already known on this topic
- Health-information-technology harm is usually sociotechnical: software, interfaces, workflow, staffing, policy and local configuration interact. Military mobility, infrastructure and interoperability create additional implementation challenges.
What this analysis adds
- UK Defence risk can be framed around six safety-critical seams: visibility, work ownership, interoperability and identity, provenance, resilience, and governance. Coronial and regulator evidence provides credible scenarios to test, but does not prove a DMICP defect.
How this analysis might affect research, practice or policy
- DMICP and its successor should be assured as one end-to-end care service. Safety evidence should cover coexistence and migration, mobile populations, cross-boundary care, manual fallback and clinical closure—not only software conformance or interface availability.
Introduction
An electronic health record (EHR) is often discussed as a product. Clinically, it is a distributed care system comprising software, data, interfaces, people, organisational rules and workarounds. Sociotechnical models therefore treat hardware, clinical content, human–computer interaction, workflow, people, governance and monitoring as interdependent.[1] In one mature US health system, 70% of investigated EHR safety concerns involved at least two sociotechnical dimensions; display, transmission, upgrades and hidden dependencies predominated.[2] The Health IT Safety framework similarly distinguishes unsafe technology, unsafe use and technology-enabled detection of wider care risk.[3]
Incident analysis shows that interfaces can create safety events even within one provider, systematic-review evidence remains heterogeneous, and English clinicians report practical consequences from limited access to external records.[4–6] Digital maturity does not abolish clinical risk; it changes where risk becomes visible and who can control it.
This distinction matters in Defence. Care may move among a unit medical centre, civilian NHS services, deployed facilities and host-nation providers while administrative registration, physical location and clinical responsibility diverge. A military EHR review identified interoperability, infrastructure, security and the deployment environment as recurring challenges.[7] Recent BMJ Military Health reports describe limitations in digital surveillance of cervical-screening coverage at sea and under-recording of osteoarthritis burden in UK Armed Forces EHR data.[8,9] Both concern the dependability of the clinical picture, not merely data entry.
This Analysis draws on selected peer-reviewed literature, official programme and inspection publications, and illustrative coronial reports. It is not a systematic review, does not estimate incidence and does not report a new analysis of coronial data. OpenAI Codex assisted with literature triage, source-linked drafting and language refinement; accountable human authors must check the sources, interpretation, references and final wording.
Safety occurs at the seams
Interoperability is necessary but insufficient. Among 209 reported interoperability incidents, receiving information from pharmacy, laboratory and radiology systems featured more often than sending it.[4] A systematic review found probable benefits but heterogeneous evidence and uncertain effect estimates,[5] while an English NHS survey described perceived safety and efficiency consequences from limited access to external records.[6] The clinically relevant question is therefore not “is there an interface?” but “does the right information become trusted, visible and actionable for the right person, with failure apparent?”
The same logic applies inside one record. A filed result may not be acknowledged; a portal message may enter an administrative queue without clinical triage; a corrected entry may be visible in an audit log but not in an export. A technically available record can remain operationally absent. The unit of safety assurance should consequently be the complete pathway from clinical event to recognised, owned and completed action.
Why Defence amplifies seam risk
Official statistics identify DMICP as the current MOD electronic medical record.[10] A 2019 procurement notice identified its then underlying platform as EMIS DPCS, and a historical supplier account described an EMIS PCS-based, centrally hosted service adapted for Defence.[11,12] These sources establish lineage, not the exact 2026 build or configuration. Public documentation identifies a Spine Patient Demographic Service connection,[13] while Parliament describes four-nation interoperability as a driver for Programme CORTISONE.[14] Neither is a complete contemporary interface catalogue.
CQC's invited Defence Medical Services inspection programme does not exercise CQC's usual statutory powers, but its observations show why local work must be included in the system boundary. Its 2024/25 synthesis recorded incomplete or inaccurate records and variable coding at some Defence services, and listed difficulty using DMICP for searches, recall assurance and monitoring among common concerns across facilities unable to ensure effective care.[15] Site reports describe Scottish referral and pathology workflows using restricted access, paper, email, scanning and transcription; a Welsh workaround for faecal-immunochemical-test access alongside slow response and outages; and an overseas referral pathway spanning DMICP tasks, fax, email, paper and separate registers.[16–18] These are bounded observations, not product-wide prevalence estimates or proof of a software root cause. They nevertheless show that service safety depends on local configuration, access entitlement, workload and manual bridges as much as on the core record.
Mobility adds a denominator problem. A person can appear correctly in an individual record yet be absent from a practice's safety search if registration, current care responsibility and physical support location do not align. That is a credible Defence hazard requiring direct testing; the present public evidence does not establish that DMICP exhibits it.
Defence also creates a seam between clinical care and occupational decision-making. Information may need to support deployability, force health protection and command risk without dissolving clinical confidentiality or creating an incomplete parallel account. The safety question is two-sided: can an authorised clinician see enough to treat safely, and can any cross-boundary signal be limited to what the operational purpose requires? Identity, access and provenance controls must address both under-sharing and inappropriate disclosure.
Coronial reports as prospective threat intelligence
Prevention of Future Deaths (PFD) reports provide concrete failure scenarios. In Stephen Rhodes, a markedly abnormal result and recommended action were filed without the abnormality being sufficiently salient.[19] In Stephen Stringer, a digital enquiry entered an administrative route, did not enter the clinical record and was not seen by a doctor.[20] In Morris Reddington, an ambulance electronic record required a separate retrieval path and was routinely not reviewed during hospital handover.[21] Samuel Jordan concerned recent care omitted when registration selected a different record source,[22] while Stephen Cassidy concerned a known drug allergy stranded outside the receiving hospital workflow.[23] Rachelle Ross exposed dependence on manual creation of a specific screening non-responder warning,[24] and Alexander Braund concerned amendment provenance that was evident from audit evidence but not apparent in the exported summary examined at inquest.[25]
These reports should be used as hazard-discovery signals. They describe particular systems, configurations and times; some state a future risk without establishing digital causation. Civilian mechanisms cannot be imported as findings about DMICP. Their value is to make foreseeable Defence tests specific: can a critical result be closed when the recipient is absent; can a mobile cohort be reconciled; does a transfer record arrive and acquire an owner; and do live, printed and exported views preserve the same provenance?
Table 1. Safety-critical seams and the evidence Defence should seek
| Seam | Credible failure | Defence exposure | Minimum assurance evidence |
|---|---|---|---|
| Visibility | Critical information exists but is not salient | Dense records, separate portals and workload | Usability tests with high-severity results and missing-source indicators |
| Work ownership | Message, result or referral has no accountable closure | Distributed teams, absence and administrative entry points | Event traces showing destination, owner, deadline, acknowledgement, escalation and outcome |
| Interoperability and identity | The wrong source or cohort appears complete | Mobility, civilian and host-nation care, and registration changes | Interface inventory, synthetic mobile-cohort reconciliation, and explicit freshness and missingness |
| Integrity and provenance | Paper, live, printed and exported views diverge | Transfer, investigation, downtime and operational reporting | Controlled amendment, export and fallback-record comparison |
| Resilience | Outage or reconnection loses or duplicates action | Deployed connectivity, ageing endpoints and staged synchronisation | Degraded-operation, retry, conflict and reconciliation testing |
| Governance | Controls fall between supplier, integrator and user | Security boundaries, local configuration and programme transition | Named hazard owners, maintained safety evidence, incident monitoring and residual-risk acceptance |
An assurance agenda for transition
In NHS standards, clinical safety is freedom from unacceptable clinical risk. DCB0129 and DCB0160 require manufacturers and deploying health organisations respectively to manage that risk throughout a health-IT lifecycle.[26,27] Their 2018 editions remain current while NHS England reviews them.[28] They are a useful benchmark for Defence because they require qualified clinical-safety leadership, hazard logs, safety evidence, controlled change and post-deployment monitoring. This article does not assert that they legally apply to DMICP or CORTISONE. DMICP's present DCB or Defence-equivalent regime, Clinical Safety Officer, Hazard Log and Clinical Safety Case are not established in the open evidence reviewed here; their status should be recorded as unknown, not absent or non-conformant.
Five actions follow.
First, baseline the service as used: current components, configurations, interfaces, manual routes, user groups, trust boundaries and known failure modes. Second, allocate hazards across software manufacturer, adaptor, integrator, infrastructure provider and Defence health organisation; an interface crossing an organisational boundary must not create a responsibility gap. Third, test work as done. Scenarios should include posted or wrongly registered personnel, recent civilian care, an absent result recipient, simultaneous demand, loss of connectivity, paper fallback, staged reconnection and partial migration. Success means clinical closure and visible missingness, not merely successful message transmission.
Fourth, monitor weak signals: unresolved tasks, unreviewed results, cohort exclusions, duplicate or failed transfers, downtime, help-desk records, workarounds and user reports. These measures should be triangulated with incidents and clinical audit. Fifth, assure transition as a hazardous clinical state in its own right. MOD has announced replacement of current record-transfer processes and a SystmOne rollout from 2027.[29,30] The safety case must cover legacy and successor coexistence, data transformation, changed displays, altered alert and task behaviour, rollback, decommissioning and preservation of existing barriers. A successful go-live is not evidence of safe migration.
Conclusion
UK Defence medical information systems may cause harm when data, responsibility and representation separate across digital and organisational seams. Current evidence justifies targeted hazard analysis and testing, not a conclusion that DMICP is unsafe. The transition offers an opportunity to make the complete care pathway—not the EHR product—the object of clinical-safety assurance.
References
- Sittig DF, Singh H. A new sociotechnical model for studying health information technology in complex adaptive healthcare systems. Qual Saf Health Care 2010;19(Suppl 3):i68–i74. doi:10.1136/qshc.2010.042085.
- Meeks DW, Smith MW, Taylor L, et al. An analysis of electronic health record-related patient safety concerns. J Am Med Inform Assoc 2014;21:1053–1059. doi:10.1136/amiajnl-2013-002578.
- Singh H, Sittig DF. Measuring and improving patient safety through health information technology: the Health IT Safety Framework. BMJ Qual Saf 2016;25:226–232. doi:10.1136/bmjqs-2015-004486.
- Adams KT, Howe JL, Fong A, et al. An analysis of patient safety incident reports associated with electronic health record interoperability. Appl Clin Inform 2017;8:593–602. doi:10.4338/ACI-2017-01-RA-0014.
- Li E, Clarke J, Ashrafian H, et al. The impact of electronic health record interoperability on safety and quality of care in high-income countries: systematic review. J Med Internet Res 2022;24:e38144. doi:10.2196/38144.
- Li E, Lounsbury O, Hasnain M, et al. Physician experiences of electronic health record interoperability and its practical impact on care delivery in the English NHS: a cross-sectional survey study. BMJ Open 2025;15:e096669. doi:10.1136/bmjopen-2024-096669.
- Torab-Miandoab A, Basiri M, Dabbagh-Moghaddam A, et al. Electronic health record in military healthcare systems: a systematic review. PLoS One 2025;20:e0313641. doi:10.1371/journal.pone.0313641.
- Morris KAL, Taylor H, Griffin C, et al. Evaluating cervical screening coverage in Royal Navy personnel at sea (2016–2023): a case study on the limitations of digital surveillance. BMJ Mil Health 2026;172:281–282. doi:10.1136/military-2025-003019.
- O'Sullivan O. Electronic health records under-report the incidence and prevalence of osteoarthritis in the UK armed forces. BMJ Mil Health 2026;172:284. doi:10.1136/military-2025-003054.
- Ministry of Defence. UK armed forces mental health 2025/26 annual report. 2 July 2026. https://www.gov.uk/government/statistics/uk-armed-forces-mental-health-annual-statistics-financial-year-202526/uk-armed-forces-mental-health-202526-annual-report (accessed 15 Jul 2026).
- Ministry of Defence. Object code and source code for the underlying platform of DMICP—DPCS: contract award notice. 17 June 2019. https://ted.europa.eu/en/notice/279881-2019/pdf (accessed 15 Jul 2026).
- CGI. Defence Medical Services: Defence Medical Information Capability Programme case study. https://www.cgi.com/sites/default/files/2022-09/case-study_dmicp_approved_new.pdf (accessed 15 Jul 2026).
- NHS England. Commissioner Assignment Method 2025/26: accompanying guidance. https://www.england.nhs.uk/long-read/cam-flow-chart-2025-26-accompanying-guidance/ (accessed 15 Jul 2026).
- UK Parliament. Armed Forces: Health Services. Written question 47398. 29 April 2025. https://questions-statements.parliament.uk/written-questions/detail/2025-04-23/47398/ (accessed 15 Jul 2026).
- Care Quality Commission. Defence Medical Services 2024/25: key findings—medical centres. 17 July 2025. https://www.cqc.org.uk/publications/defence-medical-services/2024-25/key-findings/medical-centres (accessed 15 Jul 2026).
- Care Quality Commission. Redford Medical Centre inspection report. 16 December 2025. https://www.cqc.org.uk/sites/default/files/2025-12/Redford_Medical_Centre_good_16_December_2025.pdf (accessed 15 Jul 2026).
- Care Quality Commission. Brawdy Medical Centre inspection report. 5 January 2026. https://www.cqc.org.uk/sites/default/files/2026-01/Brawdy_Medical_Centre_good_05_January_2025.pdf (accessed 15 Jul 2026).
- Care Quality Commission. DPHC(O) Sennelager Medical Centre inspection report. 16 June 2026. https://www.cqc.org.uk/sites/default/files/2026-06/Sennelager_Medical_Centre_good_16_June_2026.pdf (accessed 15 Jul 2026).
- Courts and Tribunals Judiciary. Stephen Rhodes: Prevention of Future Deaths report 2026-0083. 6 February 2026. https://www.judiciary.uk/prevention-of-future-death-reports/stephen-rhodes-prevention-of-future-deaths-report/ (accessed 14 Jul 2026).
- Courts and Tribunals Judiciary. Stephen Stringer: Prevention of Future Deaths report 2024-0555. 15 October 2024. https://www.judiciary.uk/prevention-of-future-death-reports/stephen-stringer-prevention-of-future-deaths-report/ (accessed 14 Jul 2026).
- Courts and Tribunals Judiciary. Morris Reddington: Prevention of Future Deaths report 2021-0312. 21 May 2021. https://www.judiciary.uk/prevention-of-future-death-reports/morris-reddington-prevention-of-future-deaths-reports/ (accessed 14 Jul 2026).
- Courts and Tribunals Judiciary. Samuel Jordan: Prevention of Future Deaths report 2024-0056. 2 February 2024. https://www.judiciary.uk/prevention-of-future-death-reports/samuel-jordan-prevention-of-future-deaths-report/ (accessed 14 Jul 2026).
- Courts and Tribunals Judiciary. Stephen Cassidy: Prevention of Future Deaths report 2023-0337. 19 September 2023. https://www.judiciary.uk/prevention-of-future-death-reports/stephen-cassidy-prevention-of-future-deaths-report/ (accessed 14 Jul 2026).
- Courts and Tribunals Judiciary. Rachelle Ross: Prevention of Future Deaths report 2023-0067. 17 February 2023. https://www.judiciary.uk/prevention-of-future-death-reports/rachelle-ross-prevention-of-future-deaths-report/ (accessed 14 Jul 2026).
- Courts and Tribunals Judiciary. Alexander Braund: Prevention of Future Deaths report 2022-0407. 20 December 2022. https://www.judiciary.uk/prevention-of-future-death-reports/alexander-braund-prevention-of-future-deaths-report/ (accessed 14 Jul 2026).
- NHS Digital. DCB0129: Clinical Risk Management—its application in the manufacture of Health IT Systems. Specification v4.2. 2018. https://digital.nhs.uk/binaries/content/assets/website-assets/data-and-information/information-standards/standards-and-collections/dcb0129-clinical-risk-management-its-application-in-the-manufacture-of-health-it-systems/0129242018spec.pdf (accessed 15 Jul 2026).
- NHS Digital. DCB0160: Clinical Risk Management—its application in the deployment and use of Health IT Systems. Specification v3.2. 2018. https://digital.nhs.uk/binaries/content/assets/website-assets/data-and-information/information-standards/standards-and-collections/dcb0160/0160252018spec.pdf (accessed 15 Jul 2026).
- NHS England. National review of clinical risk management standards DCB0129 and DCB0160: supporting information. 29 June 2026. https://www.england.nhs.uk/long-read/national-review-of-clinical-risk-management-standardsdcb0129-and-dcb0160-supporting-information/ (accessed 15 Jul 2026).
- Ministry of Defence. New digital medical records to speed up Armed Forces recruitment. 23 January 2026. https://www.gov.uk/government/news/new-digital-medical-records-to-speed-up-armed-forces-recruitment (accessed 15 Jul 2026).
- UK Parliament. Armed Forces: Medical Records. Written question HL14105. 12 February 2026. https://questions-statements.parliament.uk/written-questions/detail/2026-01-29/HL14105/ (accessed 15 Jul 2026).
Statements and author confirmations
Contributors and guarantor: The human author team must record each author's contribution and name one human guarantor before submission. AI is not an author.
Funding: To be confirmed by the human author team before submission.
Competing interests: To be confirmed by every human author, including relevant MOD, Defence Medical Services, programme, supplier or advisory roles.
Patient consent for publication: Not applicable.
Ethics approval: This Analysis uses public literature and documents and did not involve research participants or confidential patient-level data. The corresponding author must confirm any institutional determination required before submission.
Data availability: No new data were generated for this Analysis. All public sources relied on are listed in the references.
Disclaimer: The views expressed are those of the authors and do not necessarily represent those of the Ministry of Defence.
MOD/publication clearance: Required clearance must be obtained and recorded before submission.
AI use: OpenAI Codex was used for literature triage, source-linked drafting and language refinement. Human authors defined and must approve the argument, check the source material and references, revise the manuscript and accept responsibility for the final text. AI was not used as an author.