INSIDE THE LOOP · No. 19
Here is a definition. Read it and tell me what it describes.
“This pitfall can be caused by allowing events or the situation to control pilot actions. A constant state of surprise at what happens next may be exhibited...”
I have cut five words off the end. Put them back and it reads: “...when the pilot is getting behind the aircraft.”
That is the Federal Aviation Administration, in the Pilot’s Handbook of Aeronautical Knowledge, listing the operational pitfalls every pilot is trained to recognize and avoid. Getting Behind the Aircraft is one of twelve, sitting in a list with get-there-itis and scud running and flying outside the envelope. [1]
Now read it again and put a nurse in it. Allowing events to control your actions. A constant state of surprise at what happens next. I spent forty years in and around intensive care and I cannot think of a better description of a bad night on a busy unit. The difference is that aviation named it, taught it, tested for it, and built a profession around avoiding it.
We call it Tuesday.
Staying ahead of the airplane
The opposite has a name too, and it is not a technical term. Pilots call it staying ahead of the airplane. It means that at any moment you already know what the next three things are, you have the frequencies loaded, the approach briefed, the fuel figured, and the alternate picked, so that when something moves you are adjusting a plan rather than inventing one.
The failure mode is task saturation, and the FAA describes it better than I could:
“The first effect of high workload is that the pilot may be working harder but accomplishing less. As workload increases, attention cannot be devoted to several tasks at one time, and the pilot may begin to focus on one item. When a pilot becomes task saturated, there is no awareness of input from various sources, so decisions may be made without complete information.” [1]
Working harder but accomplishing less. Focusing on one item. Decisions made without complete information. Show that paragraph to a charge nurse at 4 a.m. and watch her face.
Aviation formalized the discipline in the 1990s as Threat and Error Management, developed at the University of Texas by Robert Helmreich and his group and endorsed by the International Civil Aviation Organization in 1999. [2] A threat is something outside your control that raises complexity, an error is something you do that shrinks your margin, and an undesired aircraft state is where you end up if you miss both.
The FAA’s Risk Management Handbook lists the defenses against all that. I want you to read the list in order, because the order is the argument. Checklists and standard procedures. A second person. External resources. Clear communication and briefings. Situational awareness. Planning for what comes next. Time management. Teamwork. Automation management. And then, last:
“Flying Skills (The Last Resort)” [3]
Last. In a federal handbook. The individual’s skill at the controls is the bottom of a list of eleven defenses, the thing you fall back on when everything upstream has already failed.
Now consider how we tell stories about ourselves. The brilliant intensivist who catches it at three in the morning. The nurse who just knew. Every one of those is a story about the last resort, and we tell them as triumphs. Aviation writes the same story up as a near miss and asks why it got that far.
Request deviation
Here is what proactive looks like in practice, and it is unglamorous.
A line of thunderstorms is building across the route. The FAA’s thunderstorm guidance is blunt about the geometry: “Do avoid by at least 20 miles any thunderstorm identified as severe or giving an intense radar echo.” [4] Twenty miles. At cruise that is about three minutes of flying, which means the decision has to be made long before the airplane is anywhere near it.
And nobody is going to make it for you. From the same document: “Don’t assume that ATC will offer radar navigation guidance or deviations around thunderstorms.” [4] The Aeronautical Information Manual is equally direct about timing: “It is very important, therefore, that the request for deviation or radar vector be forwarded to ATC as far in advance as possible.” [5]
So the proactive pilot asks. Center, request twenty degrees left for weather. And the reason to ask early is not politeness. It is that by the time the deviation is obvious to everybody, it is also unavailable, because the airspace you wanted is already full of aircraft whose crews asked before you did.
That is the whole discipline in one transaction. See it coming. Ask for room. Get it while there is still room to get.
The instrument is not the answer, and aviation says so in writing
If you think the fix here is a better display, aviation has already been where you are going. Modern cockpits have datalink weather. A moving map, color returns, the whole picture. And the National Transportation Safety Board felt strongly enough about how pilots were using it to issue a safety alert. The capital letters are theirs, not mine:
“Weather conditions depicted on the mosaic image will ALWAYS be older than the age indicated on the display... In extreme latency and mosaic-creation scenarios, the actual age of the oldest NEXRAD data in the mosaic can EXCEED the age indication in the cockpit by 15 to 20 minutes... Remember that the in-cockpit NEXRAD display depicts where the weather WAS, not where it IS.” NTSB Safety Alert SA-017 [6]
Onboard radar has its own problem, and the FAA names it: attenuation. A heavy cell absorbs the signal and the radar simply does not see what is behind it. The industry calls the result a radar shadow. [4] You are looking at a screen that appears to show clear air on the far side of the storm, and it is showing you nothing at all.
I have been staring at that alert for a week, because it is our problem exactly.
The electronic health record shows you where the patient was. The last chemistry panel was drawn two hours ago and resulted forty minutes ago. The blood pressure on the flowsheet is a point, not a trajectory. And the first storm hides the second one: the sepsis you are treating is absorbing all the attention in the room while the bleed behind it goes undetected. Radar shadow, with a chart instead of a screen.
Aviation did not answer that by buying a better radar. It answered it by teaching pilots that the instrument lies in known ways, then building a procedure that assumes it.
Storm to storm
Is critical care actually reactive? I think we can stop arguing about it, because it is measured.
Start with the metric. The Agency for Healthcare Research and Quality defines failure to rescue as a “failure or delay in recognizing and responding to a hospitalized patient experiencing unexpected deterioration.” [7] They measure it. The national observed rate for AHRQ’s Patient Safety Indicator 4, death among surgical inpatients with serious treatable complications, is 151.17 per 1,000. [8]
Roughly fifteen out of every hundred surgical inpatients who develop a serious complication that we know how to treat die of it. Read the word treatable again. That is not a metric about disease. It is a metric about attention.
Then look at what the attention is spent on. A 2014 study of five intensive care units at the University of California, San Francisco, counted every alarm for thirty-one days: 2,558,760 of them across 77 beds, including 187 audible alarms per bed per day. Of the arrhythmia alarms the investigators annotated, 88.8 percent were false positives. [9] If a flight deck generated that, the aircraft would be grounded and somebody would lose a certificate.
And then the part that should have humbled us and did not. In 2005 the Lancet published MERIT, a cluster randomized trial of medical emergency teams across twenty-three Australian hospitals. It is the closest thing we have to a real test of whether a rapid response system makes a hospital proactive. Calls to the emergency team rose from 3.1 to 8.7 per thousand admissions. Cardiac arrests, unplanned intensive care admissions and unexpected deaths did not change. [10]
We nearly tripled the number of times somebody shouted for help, and nothing happened. Activity is not anticipation. Twenty-one years later, the Agency for Healthcare Research and Quality’s own 2024 review of rapid response systems says the evidence for them is “low due to methodological weaknesses of the studies.” [7]
What actually changed in aviation, and it was not equipment
On 27 March 1977 two Boeing 747s collided on the runway at Tenerife and 583 people died. The Spanish investigators found that the KLM captain, the airline’s chief of flight training and the man in its own advertising, began the takeoff roll without clearance. Here is the finding, and I would like every chief of service in America to read it:
“Perhaps influenced by his great prestige, making it difficult to imagine an error of this magnitude on the part of an expert pilot, both the copilot and the flight engineer made no further objections.” Subsecretaria de Aviacion Civil, Spain, 1978 [11]
Twenty-one months later, on 28 December 1978, United Airlines Flight 173 circled Portland troubleshooting a landing gear indication until it ran out of fuel and came down in a suburb, eight miles from the runway. The National Transportation Safety Board added this to the probable cause: “Contributing to the accident was the failure of the other two flight crewmembers either to fully comprehend the criticality of the fuel state or to successfully communicate their concern to the captain.” [12]
Two people in a cockpit knew. Neither could make the senior man hear it. That is not a technology problem and no amount of instrumentation was ever going to fix it.
In 1979 NASA convened a workshop called Resource Management on the Flightdeck. [13] What came out of it became Crew Resource Management, and it is now federal law: under 14 CFR 121.404 no US air carrier may use a person as a flight crew member, flight attendant or dispatcher without it. [14] The FAA’s own advisory circular on the subject, in print since 2004, states the objective in a sentence I wish somebody would tape to a hospital wall:
“CRM should become an inseparable part of the organization’s culture.” FAA Advisory Circular 120-51E, 22 January 2004 [15]
Now the honest part, because I am not going to hand you a myth. I am not telling you that Crew Resource Management produced aviation’s safety record, and you should be suspicious of anyone who does. The same forty years brought ground proximity warning systems, TCAS, glass cockpits and routine flight data monitoring. The fatal accident rate for US scheduled carriers fell from roughly 0.08 per hundred thousand flight hours in the mid-1980s to five or six thousandths by the late 2000s, with several recent years at zero, and the honest attribution is all of the above together. [16] The best formal review of CRM training, published in Human Factors in 2006, concluded that its effect on organizational safety “remains unclear.” [17]
So here is the narrower claim, and I think it is the one that survives. The technology arrived in cockpits that had been taught how to use it. Ours arrived in units that had not.
A rule is not a culture
One more aviation story, because it is the one that keeps me honest about my own industry.
On 11 September 1974 an Eastern Air Lines DC-9 descended into the trees short of Charlotte while the crew discussed politics and used cars. Seventy-two of the eighty-two people aboard died. [18] In January 1981 the FAA adopted what everyone calls the sterile cockpit rule, 14 CFR 121.542: below ten thousand feet, no conversation, no reading, no activity that is not required to fly the airplane. [19]
On 12 February 2009 a Colgan Air turboprop crashed on approach to Buffalo. Fifty people died. Among the Safety Board’s findings: the flight crew’s failure to adhere to sterile cockpit procedures, the two pilots having held what the report calls an almost continuous conversation during the descent. [20]
Twenty-eight years after the rule. A rule is what you write down while you are hoping a culture will follow. Sometimes it does not, and then you write the rule again in a different report.
We copied the paperwork
Healthcare has been importing aviation’s methods for twenty years, and the results tell you precisely what we imported.
In 2009 the New England Journal published the World Health Organization surgical safety checklist study: eight hospitals on four continents, death rate down from 1.5 percent to 0.8 percent, complications from 11.0 to 7.0. [21] Everybody read it. Ontario read it, and made the checklist mandatory across the province.
In 2014 the same journal published what happened. One hundred and one hospitals, more than two hundred thousand procedures. Mortality 0.71 percent before, 0.65 percent after. Complications 3.86 percent before, 3.82 percent after. The authors’ conclusion: “Implementation of surgical safety checklists in Ontario, Canada, was not associated with significant reductions in operative mortality or complications.” [22]
Same nineteen lines of paper. In eight hospitals that chose to change how they worked, it saved lives. Across a province that was told to use it, it did nothing measurable. The variable was never the checklist.
To be fair in both directions, the 2009 study was a before-and-after design with no control group and heavy implementation support, which is exactly the point. Compare Peter Pronovost’s Keystone work in 103 Michigan intensive care units, published in 2006: a catheter checklist inside a full unit-based safety program, median bloodstream infection rate from 2.7 per thousand catheter days to zero. [23] Same tool. Wrapped in a culture it worked. Handed down as a mandate it did not.
As for team training, the Agency for Healthcare Research and Quality owns TeamSTEPPS, Crew Resource Management’s direct descendant in American medicine. Read its own evidence page. It says the research describes implementation approaches and evaluation efforts. It does not claim the program improves patient outcomes. [24] When the agency that built it will not say that, I am not going to say it for them.
Where the analogy breaks
If I only gave you the flattering half of this I would deserve the letters I would get, so here is the strongest case against everything above.
Two intensive care physicians published a piece in Critical Care this March making the objection better than I can. Their line is: “ICU work rarely has a true cruise phase.” [25] An airliner spends hours in a low workload state with the autopilot on, which is exactly when a crew briefs the arrival and studies the weather. A nurse with five patients has no cruise. The quiet hour in which to get ahead does not exist, so telling her to get ahead is telling her to do a thing the shift does not contain.
They make a second point I cannot argue with. Aviation manages fatigue structurally, with duty time limits and mandated rest written into federal regulation. Healthcare, in their words, has protections that “remain dangerously supple.” [25]
And Richard Cook and Jens Rasmussen described the deepest version of this two decades ago. A system under relentless efficiency pressure goes, in their phrase, solid: it operates with no spare capacity at all, and a system with no slack cannot anticipate anything, because anticipation is something you do with capacity you are not currently using. [26] The intensive care unit is chronically full. The airplane is not.
So let me put the uncomfortable version on the table. Aviation did not only change its culture. It changed its labor rules, it funded the rest periods, and it built a confidential reporting system a pilot can use without ending a career. We copied the posters and skipped the payroll.
If you want the proactive posture, you have to buy the conditions that make it possible. I do not know a hospital system that has.
Which is why I built the thing I built
AI MedAgent is not a product. I want to be clear about that, because I have spent a career watching a reasonable idea get turned into a SKU about eighteen months before it was ready, and I am not doing that now.
It is a concept, running on simulated patients and synthetic data, built to ask one question honestly. If the reasoning ran continuously rather than at the moment somebody happened to look, could you see the storm far enough out to ask for the deviation while there was still room to turn?
On a simulator the answer is often yes, and I am not claiming that as a discovery. The trend was always visible. The information was in the chart the whole time. What was missing was anybody continuously looking at it, and a reason to act on a signal that has not yet become an emergency.
But the demonstration is the easy half, and I know it, because I have just spent two thousand words explaining why. A model can see the trajectory. Whether anyone is permitted to act on it at three in the morning, whether the nurse who raises it is thanked or told she is being dramatic, whether the unit has enough slack in it to turn twenty degrees left, none of that is in the software. That is the culture, and there is no version of this where technology fixes it for us.
Ahead of the airplane
Pilots got there. It took Tenerife, and Portland, and a workshop at NASA, and a federal rule, and then thirty more years of a profession slowly changing the story it told about what a good pilot is. They did not get there because somebody shipped a better radar.
And I keep coming back to that list of defenses. Eleven of them, in order, with the individual’s own skill at the controls sitting at the bottom, labeled in the regulator’s own words as the last resort. That is a profession that decided, in writing, that being ahead of the airplane matters more than being brilliant behind it.
I would like to read a sentence like that about us one day. Right now the Federal Aviation Administration has the better description of our working conditions, and it files it under pilot error.
Daniel Pettus spent forty years in medical device and health IT leadership at Alaris, CareFusion and BD, contributed to IHE Patient Care Device interoperability standards, and is named on two United States patents. He writes Inside the Loop at insidetheloopdp.substack.com.
The serious version of the day job is a book. The Technology Was Never the Problem: forty years of trying to connect medical devices, what actually stopped it, and why the answer was never engineering. Paperback and ebook at pettusbook.com.
AI MedAgent is a research demonstration of a patent-pending method. Advisory only. Not a medical device. Not for clinical use. Simulated patients, synthetic data only. aimedagent.net
References
1] Federal Aviation Administration, Pilot’s Handbook of Aeronautical Knowledge, FAA-H-8083-25C, Chapter 2, Aeronautical Decision-Making, 2023 edition. Operational pitfalls list and the workload management passage.
[2] Merritt A, Klinect J. Defensive Flying for Pilots: An Introduction to Threat and Error Management. University of Texas Human Factors Research Project, 12 December 2006. ICAO Doc 9803, AN/761, Line Operations Safety Audit, first edition 2002.
[3] Federal Aviation Administration, Risk Management Handbook, FAA-H-8083-2A, Chapter 6, Threat and Error Management, 2022 edition.
[4] Federal Aviation Administration, Advisory Circular 00-24C, Thunderstorms, 19 February 2013, paragraph 10. Twenty mile avoidance, the caution not to assume ATC will offer a deviation, and radar attenuation and shadow.
[5] Federal Aviation Administration, Aeronautical Information Manual, ATC In-Flight Weather Avoidance Assistance. Paragraph numbering varies by edition.
[6] National Transportation Safety Board, Safety Alert SA-017, In-Cockpit NEXRAD Mosaic Imagery. Capitalization is in the original.
[7] Agency for Healthcare Research and Quality, Making Healthcare Safer IV, March 2024. Failure to rescue definition, and Winters BD, Rosen M, Sharma R, Zhang A, Bass EB, Failure To Rescue: Rapid Response Systems, for the evidence grade.
[8] Agency for Healthcare Research and Quality, Quality Indicators, Patient Safety Indicator Benchmark Data Tables v2024, July 2024. PSI-4, Death Rate among Surgical Inpatients with Serious Treatable Complications, national observed rate 151.17 per 1,000, computed from HCUP State Inpatient Databases 2019 to 2021.
[9] Drew BJ, Harris P, Zegre-Hemsey JK, et al. Insights into the Problem of Alarm Fatigue with Physiologic Monitor Devices. PLOS ONE 2014;9(10):e110274.
[10] Hillman K, Chen J, Cretikos M, et al. Introduction of the medical emergency team (MET) system: a cluster-randomised controlled trial. The Lancet 2005;365:2091-2097.
[11] Subsecretaria de Aviacion Civil, Spain. Report on the collision of KLM Flight 4805 and Pan American Flight 1736 at Tenerife, 27 March 1977, as reproduced in the FAA Lessons Learned library.
[12] National Transportation Safety Board, Aircraft Accident Report AAR-79-07, United Airlines Flight 173, Portland, Oregon, 28 December 1978.
[13] Helmreich RL, Merritt AC, Wilhelm JA. The evolution of Crew Resource Management training in commercial aviation. International Journal of Aviation Psychology 1999;9(1):19-32.
[14] 14 CFR 121.404, Crew and dispatcher resource management training.
[15] Federal Aviation Administration, Advisory Circular 120-51E, Crew Resource Management Training, 22 January 2004.
[16] Bureau of Transportation Statistics, National Transportation Statistics, Table 2-9, sourced to NTSB aviation accident statistics, US Part 121 fatal accidents per 100,000 flight hours.
[17] Salas E, Wilson KA, Burke CS, et al. Does Crew Resource Management Training Work? An Update, an Extension, and Some Critical Needs. Human Factors 2006;48(2):392-412.
[18] National Transportation Safety Board, Aircraft Accident Report AAR-75-09, Eastern Air Lines Flight 212, Charlotte, North Carolina, 11 September 1974.
[19] 14 CFR 121.542, Flight crewmember duties. Adopted 19 January 1981.
[20] National Transportation Safety Board, Aircraft Accident Report AAR-10/01, Colgan Air Flight 3407, Clarence Center, New York, 12 February 2009.
[21] Haynes AB, Weiser TG, Berry WR, et al. A surgical safety checklist to reduce morbidity and mortality in a global population. New England Journal of Medicine 2009;360:491-499.
[22] Urbach DR, Govindarajan A, Saskin R, Wilton AS, Baxter NN. Introduction of surgical safety checklists in Ontario, Canada. New England Journal of Medicine 2014;370:1029-1038.
[23] Pronovost P, Needham D, Berenholtz S, et al. An intervention to decrease catheter-related bloodstream infections in the ICU. New England Journal of Medicine 2006;355:2725-2732.
[24] Agency for Healthcare Research and Quality, TeamSTEPPS evidence base landing page, last reviewed July 2023.
[25] Lobo-Valbuena B, Alcantara Carmona S. Beyond the pilot analogy. Critical Care 2026;30:123.
[26] Cook R, Rasmussen J. Going solid: a model of system dynamics and consequences for patient safety. Quality and Safety in Health Care 2005;14(2):130-134.
#PatientSafety #CriticalCare #HumanFactors #AviationSafety #HealthIT



