07Governance and Safety

No party approvesits own work.

The pilot distributes decision rights so that no one party — including the program itself — can approve its own work.

Steering group and decision rights

Six roles, distributed authority.

RoleDecision rightMinimum documentation
Steering groupScope, budget, participating agencies, publication, expansion.Charter, minutes, conflict-of-interest disclosures.
Medical director / clinical panelClinical crosswalk, scope boundaries, assessment thresholds, adverse-event review.U.S. credentials, signed approvals, version history.
Agency operations leadsLocal policy, command, exercise safety, staffing, mutual-aid integration.Agency appointment letters, approved SOP and MOU.
Independent evaluatorEvaluation design, scoring audit, analysis, statement of limitations, final report.Statement of independence, protocol, analysis files.
Data governance leadData minimization, access, retention, sharing, incident response.Data-use agreement, data inventory, audit log.
Program proponentArchitecture, curriculum integration, training operations, documentation, corrective-action management.Defined scope, deliverables, progress evidence, partner attestations.

Separation rule

The program proponent holds no clinical approval right, no command authority, and no control over the evaluation or its findings.

Privacy and cybersecurity

Minimize first. Simulate first.

The pilot minimizes patient data and relies first on simulation and aggregate readiness records. If protected health information is ever used, covered entities and business associates must determine the applicable HIPAA pathway, contracts, and security controls. Cybersecurity governance is aligned to the NIST Cybersecurity Framework 2.0 — Govern, Identify, Protect, Detect, Respond, Recover.

  • Collect only fields tied to a defined measure; prohibit secondary use without governance approval.
  • Separate participant identity from performance data and restrict access by role.
  • Encrypt in transit and at rest; log access; define retention and deletion schedules.
  • Complete a privacy, security, and legal review before connecting to any operational system.
  • Publish only de-identified aggregate results, with small-cell suppression where required.
Quality assurance

Distributed training fails predictably. QA is embedded.

Instruction drifts, evaluators score differently, and sites optimize for the metric instead of the capability. T-EMRP embeds instructor observation, scenario fidelity checks, a dual-scored sample, data-quality monitoring, version control, and corrective coaching. A site that departs from the standard is supported back to fidelity and retested — not quietly excluded from the results.

Quality assurance in simulation trainingFidelity checks · Dual scoring