HC-OPS-027 / CLINIVANTA VIRTUAL HEALTH
A telehealth platform learned to fail safely
One clinical escalation model replaced fragmented override and after-hours paths across 26 specialties.
Clinivanta Virtual Health
Rapid service growth created multiple rule paths, inconsistent escalation ownership, and operational workarounds that were invisible to the product backlog.
26 specialties · 48K monthly encounters · 2022–2023 · 8 months · managed service
The problem beneath the brief
The platform could route normal visits, but it could not reliably explain which safety rule fired, who could override it, or what the on-call team should do when identity, pharmacy, or clinical context was incomplete.
- 6
- safety layersclinical safety architecture
- 47
- clinical rule paths consolidatedversioned decision and rule register
- 18
- critical scenarios rehearsedrelease evidence matrix
Risk constraints
What could not be traded away.
- clinical override authority
- prescribing safety
- state and specialty variation
- after-hours continuity
- complete audit rationale
Findings
What inspection changed.
- three override paths produced different records
- an asynchronous message could bypass the intended escalation clock
- support and clinical operations used different incident taxonomies
Named team and role pattern
The people attached to this engagement.
- Maya Raines · senior delivery lead
- clinical informatics lead
- platform architect
- product operations lead
- quality engineer
- security reviewer
- support workflow analyst
Architecture
The operating system we installed.
- 01deterministic safety-rule servicesix-layer safety review
- 02clinician override with rationalered-flag routing
- 03single escalation clockoverride sampling
- 04operational event streamon-call rehearsal
- 05case-linked audit recordincident taxonomy
Delivery sequence
Four phases. Evidence at every gate.
- 01
Frame
Define the decision, outcome, work products, authority, dependencies, exclusions, and acceptance evidence.
A named sponsor and principal approve the bounded charter. - 02
Assemble
Inspect the operating reality, then assemble named specialists, context, access, controls, and a delivery plan around the actual work.
The client approves the named team, evidence plan, role boundaries, and stop conditions. - 03
Govern
Build and operate the smallest coherent change with versioned decisions, quality evidence, escalation, and acceptance attached.
The integrated state meets the agreed evidence threshold and every material exception has an owner. - 04
Transfer
Rehearse recovery, resolve exceptions, accept the work, remove temporary access, and transfer operating ownership.
The receiving owner signs the handoff with open limits visible.
Complications
Where the plan had to become more honest.
- A technically valid fallback created an unsafe operational delay.
- One specialty needed a stricter rule without forking the entire platform.
Outcomes
What changed—and what the record proves.
- Every safety intervention and override resolved to one traceable decision record.
- Clinical and support operations shared one severity and escalation model.
- The receiving team could rehearse a degraded identity scenario without bypassing clinical custody.
Lessons
What we would carry into the next system.
- A rule engine is incomplete without override authority and operations.
- The safest product behavior can still fail in the handoff around it.
- Clinical and support severity must describe the same event.
“Clinical operations and support finally acted from the same severity model and the same clock.”
Handoff
The engagement ended with an operating owner.
- 01versioned rule inventory
- 02override-review cadence
- 03on-call scenario pack
- 04audit queries
- 05incident and correction owners
Start with the decision
Bring the priority. We will help bound the work.
If the decisions or constraints look familiar, start with the operating reality—not a preselected solution.
Start a conversation.