Separating alerts from operational communications is a fundamental design principle
Multitone has always been a pioneer in critical communications, from pagers to a whole innovative suite of hardware, software and apps, so this may sound surprising coming from us: the device is the least interesting part of this decision. Instead, it is far more important to focus on what information a channel is carrying – not on the technology itself. After all, an alert and the information behind it are very different things, and they do not have to travel the same way. Furthermore, although many organisations hold a detailed inventory of their estate including their assets, they cannot say what patient- or client-identifiable data crosses which channel.
That is why we have prepared this self-assessment: asking five questions any hospital or emergency service should be able to answer about its own critical communications. Multitone believes that separating alerting from detailed and operational communication is a fundamental design principle. This self-assessment will consequently help organisations to gain a better understanding of where the gaps are and the action they need to take.
Take the test:
1. Do you know what’s actually moving across your network?
Most reviews start with the equipment and other infrastructure: for example, how many pagers an organisation holds, which type of handsets they use as well as contractual considerations. Although this is genuinely useful, it addresses the technology issues but not matters of information governance or data protection.
In reality, there are plenty of other ways staff will use to communicate and exchange information – a personal phone, group chat or even a whiteboard. These are all effectively invisible to anyone reviewing assets or equipment. For example, if a clinician photographs something on a personal device, where does that image live afterwards?
Self-assessment test #1: Name every channel carrying patient- or client-identifiable information and say who authorises each one. This should relate to which channels are in use – not only those that you have approved.
If the two lists differ, the gap is your actual risk position. It’s also the most useful thing you can take to a board, because it changes the conversation from ‘what you should buy’ to ‘what risks you are already exposed to’.
2. What information should be sent – or not sent – via different channels?
In a busy hospital ward, the pressure to communicate information quickly, especially in an emergency situation, is understandable. Often, a nurse needs to send a message and will use whatever channel is available. In this situation, what should have been a conversation can become a long text on an alerting system.
Organisations therefore need to decide what information belongs on each channel, and what does not. A crash call stating “adult cardiac arrest, Ward 7, Bay 3” is entirely appropriate on an unencrypted network, because it carries no patient-identifiable information at all. It tells the right people where they need to go, and nothing more. The same channel carrying a name, an NHS number and a treatment history is a different matter though – and the channel has not changed, only what you asked it to carry.
Who receives it matters as much as what it says. Sending to a named individual who may be off shift, or communicating to a team, exposes patient information far more widely than the task requires. Directing a message to whoever currently holds the role – the on-call medical registrar, the site manager, the duty consultant – puts the information in front of one person who needs it, and nobody who doesn’t.
Self-assessment test #2: Pick your three most sensitive message types and identify the route each one actually takes. Not the route your policy recommends – the one your staff use.
3. How do you know a critical message was received and acted upon?
Delivered, read and acted upon are three separate things, and most systems only evidence the first. A message leaving the transmitter tells you the network worked. It tells you nothing about whether anyone is on their way.
There are situations when this distinction is crucial. For example, a deterioration alert goes to the on-call registrar; the device receives it while the registrar is getting ready for a theatre operation, or it is on charge, in a locked office, at the end of a shift. Every log confirms successful delivery. Nobody is responding, and the ward has no way of knowing that until enough time passes for someone to chase. In these circumstances, every second truly counts.
Organisations therefore need to know that someone has received a message and is acting on it. If a critical message goes unacknowledged, it should escalate automatically to the next person holding that role, without anyone having to notice the silence first. An audit trail that shows what happened afterwards is valuable for review; it does nothing during the incident itself.
Self-assessment test #3: Take your last critical alert and produce a record of who received it, who read it and who acted. If you can evidence the first but not the third, you have a delivery log rather than an accountability trail.
4. Is a single communication channel enough for a critical incident?
Most organisations believe they already recognise the need for alternative channels; for example, they rely on a smartphone app for day-to-day messaging or an SMS if the app fails. This ensures that there are two systems, providing an element of resilience.
However, in these scenarios they both need a mobile network. If the app fails, it could be for many reasons: for instance, there is a system failure, a large public event using all available capacity or even a power cut.
Consider therefore the key factors which your communications rely on in the event of a critical incident. Detail every route your channel depends on: mains power, a mobile network, an internet connection, a data centre, a supplier’s cloud platform. Redundancy means your primary and backup options do not share those dependencies. If both routes rely on the same internet connection, you have one channel with two front doors.
This is where paging still earns its place. A private paging network runs on its own transmitter, its own frequency and its own power supply – which means it fails for entirely different reasons than a cloud-hosted app on a public mobile network. This is a clear example of when pagers can work. The question is therefore not whether pagers are outdated, but whether anything else in your estate fails independently of everything else.
Self-assessment test #4: Write down your primary channel together with any backup option. Underneath each, list what it depends on to function – power, network, internet, data centre, supplier. Then look for anything appearing in both columns.
5. How can organisations balance resilience with security?
This final question is often a tricky one for those working in the NHS, the emergency services or indeed any organisations relying on robust critical communications.
A good example is when the secure route is slow or unresponsive. A clinician urgently needs a second opinion on an image; however, the approved secure application is taking too long to load, and there is a patient in front of them. They photograph the screen and send it from a personal phone. Nobody involved has behaved unreasonably. The system was not working, requiring the clinician to use a different device. This is exactly how patient data can end up on WhatsApp.
This is not being critical; individuals are trying to do their job with the tools that they have.
In this instance, the answer is not to adopt a stricter policy. Instead, organisations should identify and authorise what the fallback situation is so that staff can use it during a critical incident.
Self-assessment test #5: Carry out a survey of clinical staff to determine what they actually do when the official route is slow or unavailable. Organisations must understand what staff do in practice, not what the policy says. This will help you balance security with resilience.
How to score the self-assessment
Few organisations will answer all five comfortably.
On average, most organisations can answer three. If you cannot answer all five questions, a thorough review is important to understand in which areas they need to take action.
None of this requires new technology. Most of it requires knowing what you already have, what it carries, and what happens when it fails.
If you would find it useful to work through these questions with the Multitone team, who have decades of experience working with the NHS and emergency services, please get in touch.