13.3 Implementation: Scope, Schedule, Budget, and Quality
Key Takeaways
- Task C.4 is implementation under four constraints: scope, schedule, budget, and quality. You can trade among them; you cannot pretend a slipped date has no effect on testing or harm.
- Quality is not leftover polish. Integrated testing, downtime rehearsal, identity, and medication-safety checks are the quality bar. Cutting them to hit a banner date is a C.4 fail.
- Cutover strategy (big bang, phased, pilot, parallel, staggered by unit) is chosen for clinical risk and recoverability, not only for consultant cost.
- Go-live is a mode of care: command center, extra staffing, reduced discretionary volume when needed, stop-the-line authority, and a back-out trigger written before first login.
- Scope creep is a change, not a favor. Adding a module mid-build re-baselines schedule, budget, or quality—or it is refused.
13.3 Implementation: Scope, Schedule, Budget, and Quality
Quick Answer: Task C.4 is implementation while managing scope, schedule, budget, and quality. Those four move together. A printed go-live date that forces you to skip integrated testing is not “on time.” It is a quality failure with a calendar. Choose cutover for clinical risk, and treat go-live as a mode of care with a command center and a back-out.
Selection (C.1) and change/training design (C.2–C.3) do not finish the job. C.4 is the period when build, conversion, testing, training, and first productive use either stay inside the charter or silently become a different project. Classic project language called this the triple constraint (scope, time, cost). Healthcare implementation adds quality as a first-class constraint because a cheap, on-time, in-scope system that drops allergies is a failed implementation.
Four constraints, not three plus leftover polish
Write all four on the charter and on every status slide.
| Constraint | What it means in HIT implementation | Typical pressure | Illegal-feeling but common “save” |
|---|---|---|---|
| Scope | In/out list: sites, modules, interfaces, data converted, roles live on day one | “Just add oncology,” “just add the other hospital” | Silent expansion with the same date and staff |
| Schedule | Milestone dates: integrated test, training complete, dress rehearsal, cutover | Board-promised date, contract penalty, fiscal year | Compress testing into the last weekend |
| Budget | Capital plus implementation services, overtime, backfill, devices, interfaces | Contingency already spent | Unpaid superusers and deferred interfaces |
| Quality | Safety, identity, downtime, conversion completeness, competency, defect bar | “Good enough for Friday” | Skip integrated, regression, or downtime drill |
Rules the exam rewards:
- If scope grows, re-baseline schedule, budget, or quality targets—or refuse the growth. “Just add it” is a C.2 change and a C.4 scope event.
- If schedule is immovable (a data-center exit, a legal sunset), shrink scope or add budget (staff, dual running). Do not shrink quality on medication, identity, or downtime.
- If budget is cut, name what leaves the release. Hidden cuts become production defects.
- Quality gates are dates that can slip the go-live: failed integrated test, failed dress rehearsal, incomplete conversion audit, untrained night shift. A gate that cannot fail is decoration.
Crashing adds resources to shorten duration (more analysts, extra test cycles). Fast-tracking overlaps phases that were sequential (training while a few defects remain). Both raise risk. Fast-tracking a medication-safety defect into production is not clever scheduling.
Cutover strategies
Cutover is how you switch from the old way to the new way. The strategy is a clinical and operational design, not a vendor preference.
| Strategy | What happens | When it can be honest | Typical failure |
|---|---|---|---|
| Big bang | Most users and sites switch in one window | Small, tightly coupled system; interfaces cannot be split; organization can staff a true command center | Entire enterprise learns together with no rollback island |
| Phased / modular | Modules or functions go live over time (results, then orders, then BCMA) | Dependencies allow a safe sequence; each phase has its own test and support | Half-old, half-new workflow that drops orders |
| Staggered by unit or site | One hospital, one service line, or one unit first | You can staff elbow support and learn; interfaces and identity still work for the mixed state | “Pilot” that is actually the busiest ED on a Monday |
| Pilot | A bounded population with kill criteria | Explicit success metrics and a stop rule | Pilot with no authority to stop |
| Parallel | Old and new run together for a defined period | Throughput allows dual documentation or dual claims; reconciliation is staffed | Dual documentation until staff collapse; nobody compares the two |
Choose by clinical coupling and recoverability. A laboratory analyzer that must share one patient identity with the EHR may force a tighter window. A consumer portal increment can phase. “Big bang is cheaper because we only pay consultants once” is a budget argument, not a safety argument. Write the back-out trigger (what defect or harm rate returns you to paper or the prior system) before first login.
Conversion is part of cutover: what historical data moves, what is archived, who audits a sample of allergies, meds, and problems, and what clinicians do when a migrated allergy is missing at 02:00. An un-audited conversion is a quality fail regardless of the strategy name.
Clinical safety during go-live
Go-live is a designed mode of care, closer to Chapter 12’s downtime thinking than to a software release party.
- Command center with clinical and technical authority in the same room (or a linked virtual room), not a help desk that pages an analyst at home.
- Stop-the-line. A named pair can halt a unit, freeze a function, or trigger back-out. Hierarchy that cannot stop a crashing BCMA is not a command structure.
- Staffing. Extra clinicians, superusers, and registrars. Reduce elective volume if the risk model says so. Do not run a full OR board on a first-ever EHR with half the usual nurses.
- Safety huddles. Frequent, short, and fed by tickets and unit reports—not only by green server dashboards.
- Known degraded modes. Which functions stay on paper, which orders are verbal-then-backload, how two identifiers still work.
- Communication that does not depend on the system you just turned off (overhead, radios, mass notification).
- Hypercare window with 24×7 coverage sized to the clinical day, then a written step-down—not a sudden “good luck.”
Harm during go-live is a quality signal, not noise to be trained through. A cluster of wrong-patient or missed-allergy events is a gate: fix, back out, or reduce scope. Celebrating “we are live” while the ED is on full paper is not C.4 success.
How to read a C.4 stem
- Name which constraint is being protected (usually the date or the champion’s extra module).
- Name which constraint is being silently sacrificed (usually quality or night-shift staffing).
- Prefer the answer that re-baselines in public or refuses the unsafe trade.
- If the stem is about cutover, pick the strategy that matches coupling and recoverability, not the cheapest consultant invoice.
- If the stem is about go-live chaos, pick command, stop-the-line, and back-out—not more banners.
Scenarios and exam traps
Scenario — testing as the slack. Integrated testing is still red on allergy and ADT. The banner is already printed. Sponsors say “train harder and go live; we will fix in hypercare.” C.4 says the quality gate failed. Slip the date or shrink scope (delay a non-safety module). Training cannot close a failed integrated path.
Scenario — free module. Mid-build, the CMO wants an extra oncology module “while the consultants are here.” Same date, same budget, same testers. That is scope creep. Open a change: extend time, add money, or put oncology in a later phase. Adding it silently steals quality from the original release.
Scenario — cheap big bang. A system with six hospitals and uneven interface readiness schedules one Friday cutover because the vendor discount expires. Several sites have not finished conversion audits. Stagger or pilot the ready site; do not buy a discount with six simultaneous first nights.
Scenario — go-live as an install. There is no command center, no stop-the-line, and the OR board is full. Tickets pile up in a general queue. Implementation quality includes the care model for the weekend, not only the code.
Watch these traps:
- Treating quality as optional polish after scope, time, and cost are locked.
- Cutting integrated, regression, or downtime tests to protect a banner.
- Silent scope growth.
- Choosing cutover only by consultant cost.
- Parallel operations with no one reconciling the two records.
- No back-out trigger, so “live” means “stuck.”
- Calling first login success while harm clusters are open.
Task C.4 is honest constraint management plus a clinically staffed cutover. Section 13.4 is what happens after the banners come down: operate, upgrade, and read the tickets as data.
Integrated testing is still failing allergy and ADT paths. The go-live banner is printed. Sponsors want to “train harder and fix in hypercare.” What is the CPHIMS-correct C.4 response?
A six-hospital system wants one Friday big-bang cutover because the vendor’s consultant discount expires. Two hospitals have not finished conversion audits. How should cutover be chosen?
Mid-build, the CMO asks to add an oncology module “while the consultants are on site,” keeping the same date, testers, and budget. What failed?