No party approvesits own work.
The pilot distributes decision rights so that no one party — including the program itself — can approve its own work.
Six roles, distributed authority.
| Role | Decision right | Minimum documentation |
|---|---|---|
| Steering group | Scope, budget, participating agencies, publication, expansion. | Charter, minutes, conflict-of-interest disclosures. |
| Medical director / clinical panel | Clinical crosswalk, scope boundaries, assessment thresholds, adverse-event review. | U.S. credentials, signed approvals, version history. |
| Agency operations leads | Local policy, command, exercise safety, staffing, mutual-aid integration. | Agency appointment letters, approved SOP and MOU. |
| Independent evaluator | Evaluation design, scoring audit, analysis, statement of limitations, final report. | Statement of independence, protocol, analysis files. |
| Data governance lead | Data minimization, access, retention, sharing, incident response. | Data-use agreement, data inventory, audit log. |
| Program proponent | Architecture, curriculum integration, training operations, documentation, corrective-action management. | Defined scope, deliverables, progress evidence, partner attestations. |
Separation rule
The program proponent holds no clinical approval right, no command authority, and no control over the evaluation or its findings.
Minimize first. Simulate first.
The pilot minimizes patient data and relies first on simulation and aggregate readiness records. If protected health information is ever used, covered entities and business associates must determine the applicable HIPAA pathway, contracts, and security controls. Cybersecurity governance is aligned to the NIST Cybersecurity Framework 2.0 — Govern, Identify, Protect, Detect, Respond, Recover.
- → Collect only fields tied to a defined measure; prohibit secondary use without governance approval.
- → Separate participant identity from performance data and restrict access by role.
- → Encrypt in transit and at rest; log access; define retention and deletion schedules.
- → Complete a privacy, security, and legal review before connecting to any operational system.
- → Publish only de-identified aggregate results, with small-cell suppression where required.
Distributed training fails predictably. QA is embedded.
Instruction drifts, evaluators score differently, and sites optimize for the metric instead of the capability. T-EMRP embeds instructor observation, scenario fidelity checks, a dual-scored sample, data-quality monitoring, version control, and corrective coaching. A site that departs from the standard is supported back to fidelity and retested — not quietly excluded from the results.
Fidelity checks · Dual scoring