The second check is required.
Whether it happened is unknowable.
Insulin, heparin, chemotherapy, concentrated electrolytes — the drugs where a decimal point is the difference between a dose and an autopsy. The standard asks a second clinician to independently verify drug, dose, rate, route and patient. What gets recorded is a set of initials, which cannot distinguish a genuine independent check from a glance and a signature.
Two credentials · captured at the moment of verification · not reconstructed afterwards
Verification · sealed
● 2 of 2 signedHeparin infusion — 1,200 units/hr
Pump setting confirmed against order
D. Lang · administering
RN · TX-3310 · signed 14:22:04M. Prakash · verifying
RN · TX-7756 · signed 14:22:41Sealed — both signatures verify
Editing anything breaks it visiblyWhy the current double-check fails.
The clinicians are not cutting corners. The design of the check makes an honest one and a hollow one look identical on paper.
Confirmation bias defeats it
A second person shown someone else’s work tends to see what they expect. A truly independent check means calculating it separately, and nothing in the record shows whether that happened.
It is interrupted work
The verifier is pulled from their own patients. The check competes with everything else on the unit, and the fastest way through is initials.
Initials carry no time
A signature captured at the bedside and one added when charting catches up are indistinguishable afterwards.
What a real double-check seal looks like.
Both people sign the same record, at the moment it happens, each bound to their own credential. Neither can produce it alone.
Both clinicians sign the same computed values
Drug, dose, rate, route, patient and the actual pump setting are sealed as one record. Not two sets of initials in adjacent boxes — one fact, signed twice.
The licence is captured, not asserted
Each signature carries the signer’s credential and role as part of the sealed content. A credential typed in later is not a credential.
You cannot verify your own work
If both signatures resolve to the same credential the record refuses to seal. That refusal is the control, so it lives in the cryptography rather than in training.
Any edit breaks it, visibly
Change the dose, the rate or either name and the seal stops verifying. Not a flag someone has to notice — a broken record anyone can confirm independently.
Who this protects.
The nurse who checked properly
When an error is investigated, a sealed record they could not have altered is worth more than a colleague’s memory of a busy afternoon.
The safety officer
Double-check compliance becomes a measurable fact rather than an audit of initials, and gaps appear as broken seals.
The patient
The only reason any of this exists. A check that is provably independent is a check that actually caught something.
Where this actually stands.
We’d rather tell you plainly than let you find out on a call.
What exists today
- The two-person seal is built and tested in our signing library
- Self-witnessing is refused at the cryptographic layer, not by policy
- Tamper-evidence and independent verification already run in our live review product
- The signing key is published, so anyone can verify a sealed record without an account
What does not exist yet
- A clinician-facing verification flow at the point of administration
- Integration with any pump, eMAR or EHR
- Per-signer keys — credentials are captured, but signing runs on a service key today
- Any deployment in a live clinical setting
So this is a pilot conversation, not something you can buy this afternoon. If the problem is real where you work, that’s exactly who we want to build the first one with.
Talk to us about a pilot.
The founder reads every message and will tell you honestly whether this is ready for what you need.