This is a template, not a finished procedure. Caresoft supplies it so that no site has to start from a blank page. The hospital must adapt every bracketed item, approve it through its own clinical governance process, and issue it as a hospital document. A completed, approved and issued downtime procedure is a condition of go-live under the Master Services Agreement §4.
Print it. A downtime procedure that only exists inside the system that is down is not a downtime procedure.
THE GOVERNING PRINCIPLE: bedside monitors, ventilators and their alarms are unaffected by any eICU platform outage.
Patient safety during downtime is maintained by bedside monitoring, bedside alarms and direct clinical assessment — exactly as it was before the Platform existed. Care must be able to continue safely and indefinitely without it.
This procedure sets out what staff do when the Caresoft eICU platform, its data feeds, or the connectivity supporting them becomes unavailable, degraded or unreliable. It applies to all clinical, command centre, IT and biomedical staff in [units] at [hospital], at all hours.
It covers loss of the Platform. It does not replace the hospital's procedures for loss of bedside monitoring, loss of power, loss of the HIS, or major incident response, which remain in force alongside it.
| Role | Name | Contact | Hours |
|---|---|---|---|
| Clinical Owner (accountable for clinical use) | [ ] | [ ] | [ ] |
| Technical Owner (infrastructure, devices) | [ ] | [ ] | [ ] |
| Charge nurse / shift in charge — [ICU name] | [ ] | [ ] | 24×7 |
| Command centre lead | [ ] | [ ] | [ ] |
| Hospital IT on-call | [ ] | [ ] | 24×7 |
| Biomedical engineering on-call | [ ] | [ ] | [ ] |
| Duty intensivist | [ ] | [ ] | 24×7 |
| Caresoft support — S1 critical | — | [24×7 phone] | 24×7 |
| Caresoft — patient safety (S0) | — | [24×7 phone] + [email protected] | 24×7 |
| Caresoft status page | — | [status URL] | — |
| Type | What you see | Data at risk? |
|---|---|---|
| A — Platform unreachable | Cannot sign in; portal not loading, all users | No — edge agents keep buffering |
| B — Site network / internet down | Platform unreachable from the hospital; devices and edge agents running | No, while buffer capacity lasts |
| C — Edge agent / gateway down | One or more beds show no sync; others normal | Yes — data from those beds is not being captured |
| D — Single device interface down | One bed or one parameter missing | Yes — for that device |
| E — ADT feed down | New admissions not appearing; rising quarantined count | No, but attribution is degraded |
| F — Degraded / unreliable | Slow, partial, stale values, or values that look wrong | Treat as most serious — see below |
| G — Command centre unavailable | Remote oversight lost; bedside unaffected | No |
Type F is the most dangerous. A system that is clearly down is safe, because nobody trusts it. A system that is up but showing stale, partial or wrong data invites reliance.
If you suspect the Platform is displaying unreliable data, declare a downtime immediately and tell the unit to disregard the Platform. Do not wait for confirmation. It is always safer to run on the bedside unnecessarily than to trust a display that may be wrong.
| Type | Clinical action | Technical action | Escalate at |
|---|---|---|---|
| A Platform unreachable | Bedside monitoring + paper. Command centre stands down remote oversight and informs units | Status page; call Caresoft S1 | Immediately |
| B Network down | As A. Note buffer will hold data for approximately [x] hours | Restore link; confirm edge agents still running and buffering | Immediately; urgent if buffer limit is approaching |
| C Edge agent down | Affected beds on bedside + paper. Other beds continue normally | Check agent power, network, process; restart per runbook; call Caresoft if not resolved in [15] min | [15] minutes |
| D Device interface down | That bed on bedside + paper | Check cable, port, device output setting; biomedical to attend; check whether firmware or the device was recently changed | [30] minutes |
| E ADT feed down | Use manual admission entry so new patients are still tracked. Verify patient identity on every screen before interpreting data | Check HIS view/API; call Caresoft | [1] hour |
| F Degraded / unreliable | Declare downtime at once. Instruct unit to disregard the Platform entirely until cleared | Call Caresoft immediately; classify as S0 if any patient data may have been wrong | Immediately |
| G Command centre unavailable | Units continue on bedside. Restore the pre-eICU escalation path to the duty intensivist | Restore command centre access or relocate to [alternate location] | Immediately |
Absence of alerts is not absence of events. Loss of data flow is itself an escalation trigger.
| When | Who tells whom | How |
|---|---|---|
| On declaration | Charge nurse → unit staff | Verbal, whole unit |
| Within 5 min | Charge nurse → IT on-call, command centre, duty intensivist, Clinical Owner | Phone |
| Within 10 min | IT → Caresoft support | Phone, then ticket |
| Every [30] min | IT → charge nurse, Clinical Owner | Phone / [channel] |
| At shift change | Outgoing → incoming charge nurse | Handover, documented |
| On restoration | IT → all above | Phone / [channel] |
| Within 24 h | Clinical Owner → clinical governance | Written summary |
Do not communicate patient identifiers over personal messaging during downtime. Use hospital-approved channels or the phone.
Before standing down downtime, confirm all of the following:
Announce return to service to the whole unit and to the command centre. Record the time in the downtime log.
Buffered data arrives with its original timestamps and fills in the trend retrospectively. It may show deterioration that nobody saw live.
If downtime exceeds [4] hours, or is expected to:
| Field | Entry |
|---|---|
| Unit / beds affected | |
| Outage type (A–G) | |
| First noticed — date, time, by whom | |
| Downtime declared — time, by whom | |
| Bedside monitoring confirmed intact — time, by whom | |
| Caresoft notified — time, ticket ref, severity | |
| Additional staffing arranged? Details | |
| Service restored — time | |
| Return-to-service checks completed — time, by whom | |
| Total duration | |
| Data permanently lost? Which beds, which period | |
| Backfilled data reviewed — by whom, findings | |
| Paper records transcribed — by whom, when | |
| Any patient affected? Incident report raised? | |
| Problems with this procedure / kit | |
| Completed by — name, role, signature, date |