how automated healthcare fails, how you'd know, and what to do at each tier — every claim sourced, reviewed continuously
What counts as evidence, how the severity scores are built, and how the content keeps itself current.
Hospitals are becoming cognitive composite systems: people, AI models, agents, devices and infrastructure working as one. FailSystems splits the failure surface into five layers, each with its own mechanisms and defenses (power, connectivity and data, devices, models and agents, the human handoff), plus cascades, the pattern by which a fault in one layer propagates to the others.
Against those layers sit four degradation tiers, from full automation to analog fallback. The core claim: every clinical workflow should have a rehearsed answer at every tier, for every layer, before it is needed.
Every factual statement carries a numbered citation. Sources are graded:
Each incident needs at least two independent sources, at least one of them primary or secondary. One source is enough only when it is a primary source that is itself the record of the event or finding: an official investigation, a regulator's record, sworn testimony, or the peer-reviewed study that reports the finding. An incident that does not yet meet this rule shows a Single source marker until a second source is found.
Anything that is FailSystems' own interpretation (a classification, a score, a "FailSystems view", a practice with no source) is labelled as judgement and shown separately from sourced fact. Where numbers are disputed, we say so and cite both sides.
An entry is included when documented sources show a failure in one of the five layers (power, connectivity and data, devices, models and agents, the human handoff) that disrupted care delivery, put patients at risk, or, for a study, was measured in technology or practice in real clinical use. Each entry is one of four kinds, shown as a badge:
Not included: data breaches that exposed records without disrupting care; drug, food and supplement recalls; hypothetical scenarios, opinion pieces and vendor claims; and events that cannot be confirmed in a primary or secondary source.
An event's tier is the lowest degradation tier that the cited sources document care delivery falling to at an affected site, using the tier definitions. Tier 2 means clinical systems (EHR, order entry, interfaces) were unavailable and care ran on paper while power, phones and devices worked; most ransomware incidents sit here. Tier 3 needs documented loss of power without working backup, loss of both data and voice communications, loss of temperature control where it is required, or evacuation. Tier 1 means systems kept running but automation was switched off, distrusted or bypassed, or the failure hit a supporting function (such as claims) rather than clinical systems. Where sources do not document a drop, we do not infer one; each event page states the basis for its tier.
Some of the most dangerous failures never change tier: the automation stays up and produces wrong output, and nothing tells anyone to leave tier 0. These are marked No outage: wrong output. Studies, experiments and analogues have no tier.
Each layer is scored 1–5 on three factors and the factors are multiplied, following the risk-priority-number convention of failure mode and effects analysis (FMEA):
| Layer | Likelihood | Blast radius | Detectability | Score /125 |
|---|---|---|---|---|
| Power & infrastructure | 3 | 5 | 3 | 45 |
| Connectivity & data | 5 | 5 | 3 | 75 |
| Devices & electronics | 4 | 4 | 5 | 80 |
| Models & agents | 4 | 3 | 5 | 60 |
| The human handoff | 4 | 3 | 4 | 48 |
| Cascades | 4 | 5 | 4 | 80 |
These are first-draft judgements made from the evidence on each page, not measurements. Multiplied ordinal scales have known weaknesses (the same product can hide very different risks), so read the three factors, not just the total. Scores are revised when the evidence on a page changes, and each revision is recorded in the changelog.
A research pass runs every night. It collects leads from regulators' feeds (FDA recalls and device reports, CISA advisories, HHS breach reports), PubMed, news searches built from each page's open questions, and the AI Med Risk incident library. A local model scores the leads; the strongest go to a research agent that can only search and read the web. It verifies each lead against primary sources and proposes additions as structured data.
Proposals then pass fixed checks before anything is published: at least two sources on different sites, at least one primary or secondary, every link live, no duplicates. New incidents and sources that pass are added automatically and logged in the changelog. Changes to a page's explanatory text or scores are never automatic; they wait for human review. Every cited link is re-checked monthly.
Sources change: guidance is reissued, counts are revised, lawsuits settle, recalls close, articles are corrected. So every entry is re-checked on a schedule, not only when it is first written, in two steps.
Nightly, a few entries at a time: the sources cited by the entries that have gone longest without a check are fetched again, and a language model running on our own hardware compares every sourced statement with the source text. It must quote the passage that supports each statement, and the quote is checked against the fetched text, so a confirmation cannot be invented. The whole site is covered about every ten days.
Weekly, a deeper check: anything the nightly check could not confirm, and any incident that has been in the news again, is re-examined by a research agent that reads the sources and searches the web for later changes: reissued guidance, revised counts, settled lawsuits, closed recalls, corrections.
Nothing is rewritten automatically. Entries that pass show the date of their last fact-check. The nightly check never flags an entry publicly; it only passes it on to the weekly one. Proposed corrections go to human review. If a statement can no longer be confirmed, the entry shows an Under review notice straight away, until it is corrected or confirmed. Corrections are recorded in the changelog, and replaced sources stay in the evidence ledger marked as superseded.
Everything on this site is generated from open JSON: layers.json, tiers.json, incidents.json, sources.json and changelog.json. Changes are also published as RSS and Atom.
Text and data are licensed CC BY 4.0: reuse them freely with attribution to FailSystems / Health 201. Linked sources remain under their own terms.
What this is. FailSystems is a reference that aggregates and summarises published material: regulations, standards, guidance, research, official reports and news. It is provided for general information and education only.
What this is not. It is not consulting, engineering, clinical, legal, regulatory, compliance or medical advice, and it is not an assessment of any particular organisation, system or device. Reading or using it does not create a consulting, advisory or other professional relationship with Health 201 or AstroNexus LLC.
No one-size-fits-all answer. Healthcare organisations and their technology are complex and differ widely. Practices that worked, or were recommended, in one setting may be unsuitable, insufficient or harmful in another. The defenses, tier matrix and severity scores here are general summaries and draft judgements, not recommendations for your organisation. Any decision to adopt, adapt or reject them is yours, made on your own judgement and at your own risk, and should be made with qualified professionals who know your systems, patients and obligations.
Accuracy and currency. We work to cite accurately, but summaries can be incomplete or wrong, sources change, standards are revised and links break. Part of the content is gathered by an automated process and may contain errors before they are caught. Always rely on the current official text of any regulation or standard, and on the original source, not on our summary of it.
No warranty; limitation of liability. The content is provided "as is", without warranty of any kind, express or implied, including accuracy, completeness, fitness for a particular purpose or non-infringement. To the fullest extent permitted by law, Health 201, AstroNexus LLC and contributors accept no liability for any loss, harm or damage arising from use of, or reliance on, this site or its data.
Third parties. Organisations, products and incidents are named only as they appear in the cited sources. FailSystems is not affiliated with or endorsed by any organisation cited, and a link is not an endorsement.
Not for emergencies. This site is not an incident-response service. In an emergency, follow your organisation's emergency operations plan and contact the authorities listed at the foot of every page.
Information only, not advice. FailSystems is an aggregation and synthesis of published sources. It is not consulting, engineering, legal, regulatory or medical advice, and using it creates no professional relationship. Health systems are complex and no approach fits every organisation: anything you adopt is your own decision, at your own risk, and should be checked against the current official sources and by qualified people who know your setting. Full disclaimer.