9.3 CDS Governance, Alert Management, and Knowledge Maintenance
Key Takeaways
- A multidisciplinary CDS or clinical-content committee—not an IT change-advisory board alone—prioritizes, approves, measures, and retires knowledge objects.
- Fatigue metrics include fires per encounter, override, accept, and modify rates, time to dismiss, repeat fires, and whether the intended action occurred.
- Very high override is design evidence, not proof that clinicians are carefully declining. Sample overrides and change the build.
- A rule without an owner is a hazard. Assign an owner in a defined window or retire the object.
- Retirement is a success: keep the version for audit, do not keep dead rules just in case, and do not add new interrupts on top of an unreviewed siren.
9.3 CDS Governance, Alert Management, and Knowledge Maintenance
Quick Answer: Govern CDS like a formulary, not like a ticket queue. Measure alert fatigue with volume, override, acceptance, and time-to-dismiss. Review overrides as design data. Retire stale rules. A multidisciplinary committee assigns owners. A rule without an owner is a hazard.
Sections 9.1 and 9.2 gave you objects and types. Task A.6 still fails if nobody is allowed to say no, nobody looks at override data, and dead rules live forever. This section is the operating model: committee structure, fatigue metrics, override review, and knowledge maintenance.
Why governance is part of A.6
CDS accumulates. Every service line can justify one more interrupt. Without a gate, the EHR becomes a siren. Governance is how the organization decides which knowledge is allowed to spend clinician attention, how that knowledge is measured, and how it is taken out of production when it stops being true.
The exam will offer IT-only change advisory boards, “the vendor will maintain it,” and “high override means we need a harder stop.” Those are governance failures dressed up as action.
Committee structure
A CDS committee (sometimes a clinical-content or knowledge-management committee) is multidisciplinary on purpose:
- Medical staff who order
- Nursing who document and administer
- Pharmacy for medication knowledge
- Quality and patient safety for harm and measures
- Informatics for build, environments, and data
- HIM or compliance when the legal record or policy is in play
This is not an IT change-advisory board alone. A CAB can promote a tested object; it cannot decide whether a sepsis interrupt is the right standard of care. It is also not the board of trustees. Trustees set risk appetite; they do not tune BPAs.
The committee’s job:
- Intake and prioritize requests against harm, volume, and effort.
- Require a named owner, a success metric, and a review date before any interrupt goes live.
- Choose interruptive versus non-interruptive, or send the request back to fix the order set.
- Review dashboards on a standing agenda, not only after a sentinel event.
- Retire or retarget objects that no longer earn their keep.
- Escalate true conflicts: drug knowledge to P&T, privileging and practice standards to the medical executive committee, nursing standards to the appropriate council.
Two departments must not ship competing interrupts for the same click. The committee is the traffic cop. Vendor content drops still come through this gate. Vendor starter content is not local evidence in governance either; auto-promotion is how an unowned pack becomes an unowned siren.
Alert fatigue metrics
Fatigue is measurable. Do not argue about it in the abstract.
| Metric | What it tells you | How the exam uses it |
|---|---|---|
| Fires per encounter or per 100 orders | Burden | A “successful” rule that fires on everyone is a siren |
| Override, accept, and modify rates | Whether anyone uses the advice | Very high override is a retarget or retire candidate, not proof of careful thought |
| Time to dismiss | Whether anyone reads the text | Sub-second dismissals are not informed decline |
| Repeat fires in one encounter | Nagging | If the user already answered, stop asking |
| Intended action taken | Effectiveness | Did VTE prophylaxis actually get ordered? |
| Harm or near-miss tied to the rule | Safety | Missed because of noise, or harm because the rule was wrong |
A 94% override rate is not “clinicians thoughtfully declining.” It is evidence the rule is mistargeted, mistimed, or obsolete. Adding two more related alerts on top of that number is how you bury the one interrupt that still matters.
Leadership sometimes wants alert volume as a safety KPI. Refuse that framing. Volume without accept, override, and outcome is vanity. More alerts are not safer here either; governance is where you enforce that sentence with data.
Override review
Overrides are design data, not a disciplinary list.
Sample them. Read the reason codes. Cluster the stories: “already treated,” “not clinically relevant,” “wrong role,” “patient refused,” “duplicate of another alert.” Each cluster implies a different build change—narrow the criteria, change the person, downgrade to non-interruptive, fix the order set, or retire.
Forcing a reason-code pick-list that everyone completes with “OK” is not review. It is malicious compliance that dirties the metric.
Bring override samples to the committee with the owner in the room. The owner either defends the interrupt with evidence or agrees to change it. That conversation is the maintenance engine. If nobody will sit in that chair, you do not have a rule. You have a leftover.
Knowledge maintenance and retirement
Knowledge decays on a clock. Measures retire. Formularies change. Owners leave. Vendor packs ship new criteria. Links 404. A “core measures” BPA that still fires after CMS retired the measure is not conservative—it is false guidance.
Maintenance inventory for every production rule and content object:
- Owner and backup owner
- Evidence or policy citation and the date that citation was current
- Last review and next review
- Usage and override
- Version and effective dates
- Retirement condition written in advance
If interruptive and unused, retire. If used and wrong, version. If silent and unused, still review: a wrong default that nobody notices is a quieter hazard than a noisy BPA.
Retirement is a success. Document why, keep the version for audit and e-discovery, tell users if a familiar interrupt is going away, and watch for the quality gap the rule was covering. Do not keep a dead rule “just in case.” Just-in-case CDS is how fatigue starts.
A rule without an owner is a hazard
Repeat this until it is automatic. An orphan rule has nobody scheduled to notice that the measure died, the drug left the formulary, or the link is gone. Governance either assigns an owner in a defined window or retires the rule. Transferring ownership “automatically to the vendor” is not a policy; the vendor does not practice at your hospital.
The same sentence applies to notes, order sets, and flowsheets. CDS is simply where the hazard is loudest, because an orphan interrupt spends attention every hour it remains live.
What the committee says after a sentinel event
The wrong first move is a burst of new interrupts. The right first move is diagnosis: which five-rights failure occurred, which metric would have shown it, and whether the existing rule was ignored because it was lost in noise. Then version or replace one owned object. Governance that only adds, never subtracts, will fail the next event too.
Scenarios and exam traps
Scenario. The dashboard shows 18,000 interruptive fires last month and a 94% override on the transfusion BPA. Two services want related alerts. Review, retarget, or retire the existing rule before you spend more attention.
Scenario. A “core measures” alert still fires. CMS retired the measure. Nobody on the current committee requested it. Assign an owner or retire it the same week. Raising it to a hard stop so “someone notices” is not governance.
Scenario. The IT CAB approves a specialty BPA because the ticket was complete. Send it to the CDS committee. A completed ticket is not a clinical-content decision.
Watch these traps:
- Using alert volume as a safety score.
- Reading high override as clinician noncompliance.
- IT-only or board-only governance.
- No retirement pathway.
- Auto-promoting vendor packs (starter content is still not local evidence).
- Leaving orphan rules in production.
Task A.6 is a loop: own the content, choose the right CDS type, measure it, and take it out when it stops earning the interruption. That loop is what CPHIMS is scoring.
A dashboard shows 18,000 interruptive alerts last month and a 94% override rate on a transfusion BPA. The committee wants to add two more related alerts. What should happen first?
An old core-measures alert still fires after the CMS measure was retired. Nobody on the current CDS committee remembers who requested it. What is the governance action?
Who typically governs production CDS and clinical content, and what is their job?