Skip to content

Patient-view and risks for inappropriate advice #503

Description

@bvdh

Some key CDS-Hooks use cases include:

  1. Show card based on FHIR data
  2. Show multiple cards relate to the same FHIR/context data, possibly from different CDS-Services

This makes the following scenario's possible:

  • When the CDS-Client decides to update information a CDS Sever depends upon, an update to the resource(s) will be present in the scratch-patch of the CDS-Client/EMR. Other cards are based on the old data and and no longer valid, they might even providing suggestions that can be potentially harm-full to the patient.
  • A Card is presented that provides a suggestion that solves an issue. The Suggestion is followed. Later, another change overrides that suggestion causing the original issue to re-appear. The current specification does not state the CDS-Service is recalled. It can also not access the information in the CDS-Client context. As a result, the practitioner cannot rely on the CDS-Service to provide guidance.

These scenario's both introduce significant and potentially dangerous situations. This raises the question of what use of the patient-view hook is justified that does not introduce these risks?
If none, we should not publish the hook.
If some, we should mention those, mention the risks and state that the patient-view SHALL not be used for such advice.

In practice this severely limits the use the patient-view. Addressing these issues might very well requiring new testing. As a result, one could even wonder whether the required changes are compatible with a maturity-level of 4.....

Activity

  1. added
    stu-updateIssue generated during STU Update and will be reviewed by CDS Wg.
    on Oct 9, 2019
  2. isaacvetter commented on Oct 9, 2019

    @isaacvetter
    Member

    Hey @bvdh,

    At root - you're struggling to define how different CDS clients implement workflow and UI as it relates to the display of external CDS.

    Should CDS Hooks really attempt to define this behavior? Our approach thus far has been to not prescribe cds client UI.

    Would non-normative track recommendations for cds client behavior address your concerns?

    Isaac

  3. isaacvetter commented on Oct 9, 2019

    @isaacvetter
    Member

    Bas,

    Do note that we do try to call out a related risk already in the spec:

    The risk that a CDS Service could return a decision based on outdated patient data, resulting in a safety risk to the patient.

    https://cds-hooks.org/specification/1.0/#security-and-safety

  4. brynrhodes commented on Oct 9, 2019

    @brynrhodes
    Contributor

    Add documentation to note: For more information on patient safety issues see Security & Safety.

  5. added a commit that references this issue on Oct 9, 2019
  6. added a commit that references this issue on Jul 28, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    stu-updateIssue generated during STU Update and will be reviewed by CDS Wg.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions