The recent HSJ article When safety does not sell lays out something uncomfortable but familiar.
We are very good at analysing harm. We are less good at redesigning the systems that allow predictable harm to continue
Medication errors are used as the example, but the underlying issue is broader. Digital systems are now embedded in almost every clinical workflow. Yet when things go wrong, the response still tends to be retrospective: investigate, learn, publish, move on.
The harder question is this: What would it look like to design preventability into the system itself?
Safety is now digital
Prescribing, requesting, results management, transfusion tracking, referral pathways. These are no longer primarily paper or human processes. They are digital workflows, configured locally, integrated across multiple systems, and often customised under time pressure.
We assume that once a system is implemented, it is “safe”. But what does that actually mean in practice?
- Was every high risk workflow tested end to end?
- Were integration points validated with real data?
- Were edge cases explored, or only the “happy path”?
- Did clinical reviewers see the actual evidence, or just a summary?
Too often, the answer is: it depends.
And in a world where prescribing safety, transfusion traceability, and referral management are digital, “it depends” is not good enough.
Learning from harm versus preventing it
The article highlights a cycle we all recognise. A serious incident is investigated. Guidance is updated. Training is reinforced.
But if the underlying digital configuration was never fully validated, if the decision support rules were not tested in realistic scenarios, if the integration between systems was assumed rather than evidenced, then we are relying again on human vigilance to compensate.
That is not prevention. That is resilience under strain.
The uncomfortable truth is that much of digital safety still relies on trust rather than visibility.
We trust that testing was thorough. We trust that defects were retested. We trust that configuration matches the agreed design.
Without structured validation visibility, those assurances are hard to evidence.
Safety must be measurable
If we are serious about treating safety as a productivity strategy, not an overhead, then validation cannot remain a spreadsheet exercise.
Safety in digital diagnostics and medicines management should be:
- Visible in real time
- Traceable from requirement to test evidence
- Transparent across organisations
- Measurable against defined coverage
This is not about adding bureaucracy. It is about removing uncertainty.
When programme boards can see exactly what has been tested, what has failed, what has been retested, and what remains outstanding, safety becomes a live metric, not a post event narrative.
When clinical reviewers can approve against structured evidence, not static documents, accountability strengthens.
When testing assets are reusable and standardised, we stop relearning the same lessons network by network.
Prevention does not sell, until it does
The article argues that safety struggles to compete with waiting lists and workforce pressure because the financial incentives are misaligned.
That may be true at a macro level.
But at a programme level, something else is happening. The hidden cost of weak validation shows up as:
- Delayed go lives
- Late defect discovery
- Increased change control
- Emergency fixes post deployment
- Clinical workarounds that create downstream risk
None of that appears in a single safety metric. But it drains time, money and trust.
Validation visibility is not glamorous. It does not make headlines. But it changes the conversation from “we think we are ready” to “we can show we are ready”.
If digital medicines safety, pathology networks, imaging registries and decision support tools are central to the NHS productivity and safety agenda, then the validation of those systems must be equally central.
Until safety is engineered into the build, not just analysed after harm, we will continue to tell the same story in slightly different words.
Visibility is not the whole answer. But without it, prevention remains theoretical. If we want a different safety conversation in five years’ time, the work starts at validation.




