A health record is a series, and the whole value of a series is direction — whether a figure is rising, and how fast. That makes the failure that matters here a quiet one. It is not a system that breaks; it is a system that fills a gap with something plausible. A gap on a chart is visible to everyone who looks at it. A wrong point is visible to nobody, and it will be read by the next doctor.

Over two days, six of the changes that shipped went to the part of the product that turns an uploaded form — a photographed lab printout, a scanned protocol — into points in that series. Not one of them draws a new screen. Nearly all of them make the reader better at refusing, and the one that does not makes it better at recognising that two records are the same reading.

An empty heading does not stay empty

The extraction template listed the sections a report should have: method, findings, conclusion, recommendations. A list like that reads as an instruction, and an instruction to use a section leaves nothing to do with a section the form does not contain.

What came out of one instrumental protocol: the form's conclusion was a single line, and the stored text had seven points. The form had no recommendations section at all, and the stored text had three.

Two things changed, and the second is the one that mattered. The template stopped commanding: the sections are now the ones the form has, and the list gives their order rather than a quota. And for the two headings that carry a doctor's will — conclusion and recommendations — the reader was given a permitted way to say the section is missing: a fixed mark meaning not stated in the form. Elsewhere a section the form does not have simply does not appear.

A prohibition without a permitted empty form does not hold. Told not to invent, and not told what to write instead, any reader writes something plausible. For these two the mark is explicit rather than a silently dropped heading, because the absence is itself a medical fact: a section quietly removed is indistinguishable from one lost in transit.

“I could not read it” is not “it is not there”

A missing value was stored as null, and null meant two different things: the cell was blank because the indicator was never measured, and the number was printed but not read.

One stored value, two different facts
On the formStoredHow the series read it
blank cell, not measurednullskipped — correct
number printed, not readnullskipped — wrong

The cost is asymmetric, and that is the point. Reading “unread” as “not measured” does not merely fail to add a point — it withdraws one. A row treated as gone from the form lets the measurement beneath it be pruned. The chart does not gain a gap; it loses a point the form actually carries. A disappearance is quieter than a distortion and just as wrong.

So the reader now has a separate way to say the value exists but was not read. The flag is checked before the value, and it outranks any number printed beside it: a value delivered together with the flag is a guess, and a guess is indistinguishable from a measurement once it is on the chart.

The error that is a factor of a thousand

250.000. Two hundred fifty thousand, or two hundred fifty and no tenths. On its own the string cannot be resolved, and which reading is right depends entirely on what is printed beside it.

The witness is the unit. An indicator counted per volume is printed in thousands; the same indicator expressed with a multiplier in its unit is printed in ones. The ambiguity therefore lives in one place only: where the unit is a bare count divided by a volume, and the thing being counted carries no multiplier of its own. A concentration resolves itself; a count per field of view is never six digits.

So the reader stopped guessing and started refusing. The row travels the same path as an unread number: the point already in the series survives, and nothing new is invented. Better a gap in a series than a number that was never measured.

A trait recognised by listing cases is not a trait

The first version of that check asked whether a unit was ambiguous by looking it up in a list of spellings — collected by hand, and open by default: a unit absent from the list meant no ambiguity at all.

Such a list is complete exactly as far as the attention of whoever wrote it, and every gap in it restores the thousandfold error the check exists to prevent.

The question is now structural, and it is asked after the unit is normalised: is the denominator a volume, and does the numerator name a measured quantity or a multiplier? The default is inverted — an unfamiliar numerator over a volume means the order of magnitude is unknown to us, and unknown is ambiguous.

The list that remains is derived from the live catalogue rather than from memory. Every spelling in it is classified, with the count of rows recorded beside it so that a subset cannot pass for the whole. Add a spelling to the catalogue and you answer for it then — which is cheaper than learning the answer six months later from the shape of a curve.

Two readings that never compared notes

Documents are read twice, independently: once into the text a person reads, and once into the values that build the chart. Until this week the two halves were never compared with each other.

A disagreement between them was invisible from both sides. The patient sees one number in the text and a different one on the graph, and neither half knows the other disagrees.

The direction of the check was decided by measurement rather than by symmetry. Checking what the machine-read half asserts against the text half leaves 1.1% of numbers unmatched. The reverse direction leaves 8.1% unmatched — laboratory reference ranges and table layout that a summary legitimately does not repeat. An alarm that rings on almost every document is one people stop reading, so the check runs in the direction where a miss is dangerous: a number the chart will plot that the text does not contain.

One analyte, two alphabets

A smaller defect, with a long tail. Catalogue codes for the same analyte differed by a single character — a Latin letter and its Cyrillic twin, identical on screen. It had happened twice. Each code carried one point, and each of those series would have stayed one point long for ever.

Single-character tokens are now folded to one alphabet before names are compared. Single tokens only: folding letter by letter would rewrite the abbreviations laboratories print in Latin inside otherwise Cyrillic names, and the fix for one split would have manufactured others.

Why this is the work

None of the above adds anything a user asked for. What it buys is the product's ability to say that it does not know — in a specific place, for a specific row, without withdrawing what it does know.

That is the property that makes a longitudinal record worth keeping. A chart whose direction can be trusted is worth more than a chart with no gaps, because the gaps are the honest part: they mark where the form was unreadable, not where the reader quietly gave up.

Lonevi is the group's longevity and health-record product — lonevi.com.

Start a conversation