Wrong patient
Someone reads an ID off one screen and types it into the instrument. One transposed digit and the result belongs to somebody else. Manual re-matching in most systems is an overwrite with no trail.
Home / Platform / Results governance
Core platform
A transposed digit at the analyser, a duplicate record, a critical value nobody acknowledged: these are the failures that end up in incident reviews. Catenix governs how every result is matched, corrected, escalated and released, and keeps the evidence of each step.
Where it goes wrong
Someone reads an ID off one screen and types it into the instrument. One transposed digit and the result belongs to somebody else. Manual re-matching in most systems is an overwrite with no trail.
The analyser flags it, the phone call happens, and six weeks later nobody can prove who acknowledged it, when, or whether the patient report went out before the clinician knew.
A value is edited in place. The original disappears, the report is re-issued without a mark, and the audit trail shows a change with no reason attached.
Matching governance
Modelled on mature laboratory practice: no silent overwrites, reasons on every move, and both patient records carry the story.
An unsolicited result is matched to a patient by the signed-in user, and an audit row is written on that patient's record. A result that is already matched cannot be matched again; the only way to move it is Reassign.
Reassign is one transaction: removed from the wrong patient, attached to the right one, with a mandatory reason such as wrong patient selected, duplicate record, device sent wrong ID, sample mislabelled or identity verified. Unmatch returns the result to the unsolicited queue with the identifier the analyser originally sent.
If the result had already reached a LIS, GP system, patient link or the patient app, Catenix raises a wrong-patient incident in Quality Management (a near miss if it never reached the patient), revokes the old report link, queues a corrected message for the right patient and keeps the cancellation as a pending correction until the receiving system confirms it.
When automatic matching finds two or more plausible encounters, the result is flagged ambiguous with the candidate accessions recorded, instead of being matched to the newest. Ambiguous and unmatched results have their own filters, ageing signals in the Action Centre and a corrections queue.
Critical results
The summary tiles above are what the Results safety dashboard widget shows. Turnaround targets are set per test and reported as compliance, so a slow analyte shows up before a complaint does.
Amendments and identity
An amendment records the reason, keeps the original as superseded, links the corrected result and emits a result.amended event for connected systems. Reports print an AMENDED note with reason, who and when; superseded originals are hidden by default and available in the audit view.
Duplicate candidates are detected and scored, previewed before merging, and merged with a full history. Unmerge within 30 days restores the original rows exactly.
A name and date-of-birth confirmation is recorded at check-in and before a result is attached by hand, and NHS numbers are checked with the modulus 11 rule at registration with a soft warning.
Set a target per test, see compliance over time, and find the analyte or site that is quietly missing it.
A clear boundary
Catenix is connectivity, workflow, record-keeping and data display. It does not interpret results, calculate clinical values, classify or flag results clinically, or provide clinical decision support. Statistics describe methods, processes and datasets, never a patient. Any reference range or note shown is customer-authored content Catenix displays.
Questions, answered
It cannot be quietly overwritten. Moving a result means a Reassign with a coded reason, and the audit trail records the removal on the wrong patient and the attachment on the right one. If the result had already gone to a LIS, GP system, patient link or the patient app, Catenix opens a downstream correction: a wrong-patient incident in Quality Management, the old report link is revoked, and a corrected message is queued for the right patient.
No. Critical status comes from the customer-authored limits configured in the platform and the flags the analyser produces. Catenix records who was told, how, and the read-back, then holds patient-facing release until that acknowledgement exists. It does not interpret the value.
Yes. An amendment keeps the original, marks it superseded, links the corrected result and reason, and prints an AMENDED note on the report. Superseded originals stay in the audit view and can be shown on request.
The result is flagged as ambiguous rather than matched to the newest encounter. The candidate accessions are recorded for the person who resolves it, and ambiguous results have their own filter and Action Centre signal.
Duplicate candidates are detected and scored, previewed before merging, and merged with an audited history. A merge can be undone within 30 days with the original rows restored exactly.
A 30-minute walkthrough on a live tenant: match, reassign, downstream correction, critical acknowledgement and an amendment, end to end.