Everyone Did Their Job: A Systems Analysis of a Critical Lab Result That Followed the Wrong Map
Student Name
Doctor of Nursing Practice Program, Aspen University
DNP855: Organizational Leadership and Systems-Based Practice
Instructor Name
Month Day, Year
Everyone Did Their Job: A Systems Analysis of a Critical Lab Result That Followed the Wrong Map
When a patient is harmed, organizations often look for the person who made the error. Systems thinking asks a different question: what features of the system made the harm likely, regardless of who was working? This paper analyzes a composite event in which a critical laboratory result did not reach the clinicians caring for a patient, using Reason's model of human error and the principles of systems thinking, and it proposes changes aimed at the system rather than at individuals.
The Event
Mr. B., a 71-year-old whose kidneys work at about a third of normal capacity, came onto a medical unit with pneumonia. At 1:40 a.m., after an episode of low blood pressure, he was transferred to the step-down unit. Blood drawn at 12:50 a.m. on the medical unit came back at 2:05 a.m. showing potassium at 6.8 mmol/L. Following protocol, the laboratory technologist phoned the critical value to the location listed on the specimen, the medical unit. The nurse who answered read the value back, wrote it down, and, not recognizing the patient's name among her assignments, told the technologist the patient was not hers; the technologist, working through a queue of critical calls, marked the call as completed. The result appeared in the electronic record, but the step-down nurse was admitting another patient and did not open the results tab. At 3:20 a.m., Mr. B. developed a wide-complex rhythm and required resuscitation. He survived.
The Person Approach and Why It Fails Here
Reason (2000) sets two ways of thinking about error side by side. One looks for the careless or forgetful individual and answers with blame, retraining, or discipline. The other starts from the fact that people will always make mistakes and asks what about their working conditions made this one likely. Under the person approach, the medical unit nurse would be faulted for not forwarding the call, the technologist for closing it, and the step-down nurse for not checking results. Yet each acted reasonably given what they knew and the demands on them. Disciplining one of them would leave the conditions unchanged, and the next critical result sent to the wrong unit would meet the same fate.
Latent Conditions and the Holes in the Defenses
Reason (2000) describes an organization's defenses as layers, each with holes of two kinds: slips and mistakes by frontline staff in the moment, which he calls active failures, and latent conditions, flaws that sit quietly in designs, policies, and budgets until the day they combine with something else. Harm occurs when holes in several layers line up. In this event, the layers and their holes were these: the laboratory's callback process routed results by specimen location, not by the patient's current location; the electronic record updated the patient's location at transfer but the laboratory system did not receive the update for results already in process; the critical-result policy allowed a call to be closed once read back, without confirming that the responsible clinician received it; the step-down unit had no alert that fired when a new critical result posted for a patient; and night staffing left the receiving nurse admitting two patients at once. No single hole caused the arrest; the harm passed through five of them, each opened by a decision made long before that night.
Systems Thinking: Structure Drives Behavior
Senge (2006) argues that the structure of a system, its relationships, feedback loops, and delays, generates its behavior, and that people inside a system tend to see only their own part. Each person in this event saw only their segment: the technologist saw a completed call, the medical unit nurse a patient who was not hers, the step-down nurse a busy admission. No one could see the whole path the result was supposed to travel. The transfer created a delay between the patient's movement and the information's movement, a classic source of error. Seeing the event as a system makes clear that the problem lies in how information follows patients during transfer, a structure that will produce similar failures for other results and other transfers.
The Scale of the Problem
The landmark report on patient safety argued that most errors result from faulty systems, processes, and conditions that lead people to make mistakes or fail to prevent them, and that the solution lies in designing safer systems rather than blaming individuals (Kohn et al., 2000). Communication failures at transitions are among the most common of these system weaknesses, and critical result communication after transfer is a recurring example. Mr. B. survived, but the same conditions could produce a death on another night.
System-Level Changes
The changes follow from the latent conditions. The laboratory should route critical calls to the patient's current location, drawn in real time from the admission-transfer system, and the interface should update in-process specimens at transfer. The critical-result policy should require that a call be closed only when the responsible nurse or provider acknowledges it, with escalation to the charge nurse or house supervisor if not reached within 15 minutes. The record should generate an interruptive alert to the assigned nurse and provider when a critical result posts. Transfer handoff should include pending laboratory tests. And the organization should review night staffing on units that routinely receive transfers during admissions. Each change is designed to close a hole regardless of who is working.
Leading a Just Response
How leaders respond after the event shapes whether the system learns. If the medical unit nurse or the technologist is disciplined, staff will learn that reporting near misses and admitting uncertainty carries risk, and the next hole in the defenses will stay hidden. A just culture approach distinguishes honest human error, which calls for system redesign and support, from at-risk behavior, which calls for coaching, and from reckless disregard, which calls for accountability. None of the three nurses or the technologist acted recklessly. The DNP-prepared leader's role is to say so publicly, thank the staff who reported the event, involve them in designing the fixes, and report back to all units on what changed. That response turns one near-fatal night into evidence that speaking up is safe.
Conclusion
Mr. B.'s arrest was not caused by any one person. It passed through a series of weaknesses in routing, information systems, policy, alerts, and staffing, each the product of earlier design decisions. Reason's model and systems thinking show why blaming individuals would fail and where the system must change. For DNP-prepared nurse leaders, the task is to look past the sharp end to the structures that shape what happens there.
References
Kohn, L. T., Corrigan, J. M., & Donaldson, M. S. (Eds.). (2000). To err is human: Building a safer health system. National Academies Press. https://doi.org/10.17226/9728
Reason, J. (2000). Human error: Models and management. BMJ, 320(7237), 768-770. https://doi.org/10.1136/bmj.320.7237.768
Senge, P. M. (2006). The fifth discipline: The art and practice of the learning organization (Rev. ed.). Doubleday.
How this DNP 855 Module 1 example is structured
DNP855 Module 1 samples often introduce systems thinking through a failure that no individual caused. Aspen does not publish module deliverables, so check your classroom for the exact prompt. This example describes an event without blame, applies Reason's model and systems thinking to find latent conditions, places the event in the national safety context and recommends changes aimed at the system.
DNP855 Module 1 questions, answered
What does DNP855 Module 1 usually ask for?
The first module often introduces systems thinking through an adverse event or failure that no single person caused, asking you to analyze it at the system level. Aspen does not publish module deliverables, so your classroom's instructions govern.
What is the difference between active failures and latent conditions?
In Reason's model, active failures are unsafe acts by people at the sharp end, while latent conditions are weaknesses built into the system by design, policy and resource decisions. Harm occurs when holes in several layers of defense line up.
Why doesn't blaming individuals prevent errors?
Because the conditions that led competent people to err remain in place. The system approach changes those conditions, such as routing, alerts, policies and staffing, so the same failure is less likely whoever is working.
Write yours, or have the desk draft it
This paper is an original model document written by our desk, not a submitted student paper and not an official Aspen University document. Read it for the moves, then write your own to the instructions in your classroom. If you want one built to your exact prompt and rubric, the first custom sample is free and arrives in 24 to 48 hours.