Safety Learning Series
Careful Is Not a System
Tell a veterinary team to be more careful and you will get almost nothing.
Every hospital has produced this document. It follows a bad event, it is written with real feeling, and it lands in everyone's inbox within about seventy-two hours.
"Following a recent incident, all staff are reminded to double-check medication doses before administration. Please be vigilant."
Then everyone reads it, agrees with it, and nothing changes. Eleven months later a structurally identical event happens, and someone writes a structurally identical email.
This is not because your team ignored you. It is because "be more careful" is not a change. It is a wish.
The people who erred were already trying
Start with the uncomfortable premise, because everything else follows from it.
The nurse who drew up the wrong concentration was already trying to be careful. So was the surgeon who marked the wrong side, the receptionist who booked the wrong patient, the overnight technician who missed the trend on the monitor at hour eleven. Not one of them woke up that morning intending to be casual about a life.
Careful people produce errors every single day. Not occasionally, but daily, in every hospital, in every industry, at rates that are stable enough to be predicted. Human attention is a finite resource that degrades under load, fatigue, interruption, and time pressure, and it does so regardless of how much the person cares about the outcome. Caring more does not add capacity.
Which means an intervention aimed at effort, such as try harder, focus more, be vigilant, is aimed at the one variable that was already maxed out. You are asking for more of the thing they were already giving you.
This is the shift that separates hospitals that improve from hospitals that just feel bad and repeat the same event: they stop asking who failed and start asking what let it happen.
Reason's slices
James Reason gave medicine the picture for this decades ago, and it remains the most useful mental model in patient safety, partly because you can draw it on a napkin.
Think of your defenses, the checks and protocols and second looks and labels and alarms, as slices of Swiss cheese stacked in a row. Each slice is a barrier standing between a hazard and a patient.
Every slice has holes.
The holes are not evidence of a broken hospital. They are the normal, permanent condition of any real system. A look-alike label. A count that gets interrupted because the phone is on the same counter. A handoff that drops a detail because it happens in a corridor. A staffing gap at 6 p.m. when day shift is leaving and night shift hasn't arrived. A drug fridge organized alphabetically, so that two very different concentrations sit side by side forever.
Most days the holes do not line up. Something is caught at the second slice, or the fourth. Nothing reaches the patient, and nobody notices that anything happened at all. This is precisely why near misses matter so much, and why a hospital that doesn't capture them is flying without instruments.
Once in a while, the holes line up all the way through.
And here is the part that reframes everything: the error at the sharp end is almost never the whole story. The wrong dose actually given is the last hole in a line of holes, and every one of the earlier holes was built into the system long before that shift started, by decisions about purchasing, staffing, layout, scheduling, and software that were made by people who were not in the room and will never be named in the incident report.
Reason called these latent conditions: the resident pathogens in a system, lying dormant, waiting for the right combination of circumstances. They can sit inactive for years. They are also, unlike human attention, entirely fixable.
This is not a way to excuse people
It is worth being direct about the most common objection, because it is raised in good faith and it deserves a real answer.
Systems thinking is sometimes heard as a sophisticated way of saying nobody is responsible. That is not what it is, and a hospital that uses it that way will get the worst of both worlds.
The distinction is about where the leverage is. Individual accountability for choices remains, and that is the whole subject of the just-culture line between error, at-risk behavior, and recklessness. What systems thinking adds is the recognition that after you have dealt with the person, you have not yet dealt with the problem. The conditions are still there. They will meet the next person, who will be equally careful and equally human, and the outcome will be the same.
You cannot patch human attention. You can absolutely:
- Redesign the vial storage so look-alike concentrations are not adjacent.
- Force the high-alert check so it is a hard stop rather than a cultural expectation.
- Protect the medication round from interruption with a designated zone, a visible signal, and a rule that the phone waits.
- Close the handoff gap with a structured format instead of a corridor conversation.
- Standardize the concentration so the calculation isn't needed at all.
Those changes hold at 3 a.m. They hold when the hospital is short-staffed, when the person is new, when everyone is exhausted. They hold long after today's tired, careful team has gone home, which is the entire point.
The hierarchy nobody teaches
There is a well-established ordering of how durable a fix is, and it explains why so much safety work produces so little.
Weakest: education, reminders, policies, warnings. These rely on the human to remember and comply, at the moment of highest pressure. This is where nearly all veterinary safety interventions land, because they are cheap and fast and feel like action.
Middle: checklists, double-checks, standardization, alerts. Better, because they add a barrier that doesn't depend purely on recall. Still defeatable under load, and prone to becoming ritual if nobody watches. The veterinary checklist literature is instructive here: perianesthetic and surgical safety checklists have been studied in practice, and the interesting findings are usually about implementation, whether the thing is actually used as intended, rather than whether the concept works.
Strongest: forcing functions, physical redesign, automation, removing the hazard entirely. The connector that physically cannot attach to the wrong port. The concentration you no longer stock. These work whether or not anyone remembers them.
The question to ask of any proposed fix is simple: does this depend on someone remembering, under pressure, at the worst possible moment? If yes, you have chosen a weak control, and you should expect the event to recur.
Emerging veterinary education work on human factors and systems thinking suggests this framing is still not routinely taught, which is why intelligent, well-intentioned teams keep reaching for the retraining email. It is not stupidity. It is the only tool most people were handed.
What to do this week
Take your last incident and list five conditions. Not five people. Five things about the environment that made the error easy to make or hard to catch. If you cannot get to five, you have not looked hard enough at layout, timing, staffing, labeling, or software.
Rank your last three "fixes" on the hierarchy. Be honest. If all three were reminders, you now know why the events keep recurring.
Pick one hole and close it physically. One storage change, one hard stop, one protected round. A single durable fix outperforms a year of vigilance requests.
Ask the sharp-end question in reviews. Not "what is wrong with this person?" but "what about this system made the error easy to make and hard to catch?" The wording matters more than it sounds like it should, because it changes what the room produces.
Good teams still have bad outcomes. When they do, the useful work starts after the apology.
A question for your team
The last time something went wrong, did you fix the person, or the conditions that will meet the next person?
