The order is the control point
Chemotherapy errors are rarely administration errors in the sense of a nurse connecting the wrong line. They are prescribing and preparation errors that pass through every subsequent step because nobody downstream had the information or the authority to stop them. A dose calculated on the wrong weight, a cycle given on the wrong day, a cumulative anthracycline limit quietly exceeded, an intrathecal drug prepared alongside an intravenous one. In each case the order was wrong and the system carried it faithfully to the patient.
That is why the order, not the infusion, is the control point worth engineering. Everything you want to prevent has to be prevented at or before the moment the order is released to pharmacy, because after that the drug exists, money has been spent, and the social pressure to proceed is enormous. A safety system that relies on a nurse refusing a compounded cytotoxic in front of a waiting patient is a system that has already failed.
This has an uncomfortable implication for how hospitals buy software. A generic e-prescribing module with an oncology label on it is not sufficient, because the controls that matter here are protocol-aware and cumulative, and generic modules are neither. Being clear-eyed about that at procurement saves a great deal of retrofitting, and it is a reasonable question to put to any vendor before signing.

A governed protocol library, not free-text orders
Free-text chemotherapy prescribing should stop, and the replacement is a protocol library where each regimen exists as a defined object: the drugs, the dose per square metre or per kilogram or by area under the curve, the day of cycle for each, the cycle length, the number of cycles, the mandatory pre-medication, the hydration, and the required baseline investigations. The prescriber selects a regimen and a cycle number, and the system builds the order.
The library needs an owner and a version history. Regimens change, references are updated, and a hospital that cannot say which version of a protocol a patient received in a given year cannot defend a clinical review. Governance usually sits with a pharmacy and therapeutics subcommittee or an oncology protocol group, with the pharmacist as custodian. Every change should carry an effective date, the approving body, and the source reference, and old versions must remain retrievable rather than being overwritten.
There will be legitimate cases outside the library, in trials, in rare tumours, and in dose-modified salvage. Design for them rather than pretending they do not exist. A non-formulary route with a named approver and mandatory second-consultant sign-off keeps those cases inside the system, which is much safer than driving them onto paper. If your off-protocol rate is above a small minority of orders, the library is incomplete rather than the clinicians being unreasonable.
What each protocol entry must carry
- Every drug with dose basis, unit, route, and day of cycle
- Cycle length, planned number of cycles, and the permitted delay window
- Mandatory pre-medication, hydration, and supportive drugs
- Baseline and pre-cycle investigations with validity periods
- Version number, effective date, approving committee, and source reference
Body surface area, dose calculation, and the arithmetic nobody checks
Body surface area is the most quietly dangerous number in oncology because it is computed from two measurements that are often stale, often estimated, and rarely re-taken. A patient who has lost eight kilograms since cycle one is being dosed on a body that no longer exists. The record should carry the height and weight used for the current calculation, the date each was measured, the formula applied, and the resulting surface area as a stored value rather than something recomputed silently on the fly.
Which formula the hospital uses should be a written decision, not a per-clinician preference. Du Bois, Mosteller, and the others give different answers, and the difference can be clinically meaningful at the extremes. Pick one, configure it, display it on the order, and note it in the protocol document. Also decide the policy on capping surface area for obese patients and on dosing in renal impairment, because those are the two areas where individual practice diverges most and where a system that silently accepts anything is not helping.
Then build the verification as an independent recalculation rather than a confirmation click. The pharmacist should see the height, weight, measurement dates, formula, computed area, protocol dose per square metre, and final dose, and the system should flag when the final dose differs from the protocol dose by more than a configured percentage without a recorded reason. A modification is often correct; an unexplained modification never is.

Dose banding and rounding rules
Dose banding groups calculated doses into pre-defined bands within an agreed tolerance so that standard preparations can be made in advance instead of each dose being compounded individually. The operational gain is substantial: compounding time falls, waiting time falls, wastage from part-used vials falls, and pharmacists spend less of the day at the cabinet. Several national health systems have used banding for years, and the practice is well described in the pharmacy literature.
Adopting it requires three decisions that must be written down. What tolerance is acceptable, usually expressed as a small percentage either side of the calculated dose. Which drugs are eligible, which usually excludes narrow therapeutic index agents and anything dosed by area under the curve. And who approves the band table, which should be the same body that owns the protocol library. Without those three, banding becomes an informal rounding habit at the bench, which is a different and much worse thing.
Be honest about what banding costs. It removes some individualisation, it requires stability data to support any pre-preparation, and it demands storage and expiry management for prepared products that a smaller unit may not have. A hospital doing twenty admixtures a day probably gains little; one doing a hundred and twenty gains a great deal. Sizing that judgement correctly matters more than the theoretical elegance of the approach.

Decisions to settle before banding any drug
- The permitted deviation from the calculated dose, as a fixed percentage
- The drug list included and, explicitly, the list excluded
- Stability and expiry data supporting any pre-prepared product
- Who approves and periodically reviews the band table
- How a prescriber records a deliberate refusal to band an individual dose
Cumulative dose tracking across the whole course
Some toxicities are functions of lifetime exposure rather than of the dose in front of you, and no single order looks wrong. Anthracycline cardiotoxicity is the classic example, with a recognised lifetime dose threshold expressed in doxorubicin equivalents; bleomycin pulmonary toxicity and cisplatin ototoxicity and nephrotoxicity follow similar cumulative logic. The order screen must therefore show the running total to date and the increment this order adds, before the prescriber signs.
The hard part is not the arithmetic. It is that the total has to include treatment the patient received elsewhere, often years earlier, at a hospital that no longer exists in an accessible form. Build a prior-treatment section into the initial oncology assessment that records regimen, cycles received, and cumulative exposure for the relevant agents, with the source of that information marked as documented or patient-reported. A patient-reported anthracycline history is not worthless, but the record should be clear about which it is.
Attach the surveillance obligation to the same object. If your policy requires an echocardiogram at defined cumulative thresholds, the system should raise the requirement rather than depending on a consultant remembering. Where ABDM linkage is functioning and the patient consents, prior records from another facility can be pulled into that assessment instead of relying wholly on recall, though in practice this remains partial and the manual history is still the primary source.
“The near miss that changed our practice was a transfer patient who told us he had had four cycles somewhere else. It was seven. Nothing in our system asked where that number came from, so nobody questioned it.”
The independent double check at three separate points
An independent double check means a second qualified person verifies the work without seeing the first person's conclusion first. Two people looking at the same screen and agreeing is not a double check; it is confirmation bias with two signatures. In chemotherapy the check is needed at three distinct points: at verification of the prescribed order, at completion of compounding against the worksheet, and at the bedside before administration.
Each has a different question. Order verification asks whether the regimen, cycle, day, dose, and pre-medication are right for this patient today given counts and organ function. Compounding verification asks whether the correct drug, diluent, volume, and label were used, checked against the order and not against the previous label. Bedside verification asks about patient identity, drug identity, dose, route, line integrity, and that the consent and pre-treatment checks are recorded. Route verification at the bedside is the last barrier against a wrong-route administration, and it deserves a distinct step rather than being folded into a general check.
Record each check as a discrete event with the checker's identity and the time, and audit compliance monthly. Units almost always find that compliance falls on the busiest days, which is the finding that justifies staffing rather than exhortation. HealUDoc can hold each check as a timestamped step against the order so the trail is auditable per administration instead of living in a signature column on a paper chart.
Bedside checks that must be individually recorded
- Two patient identifiers verified against the label and the order
- Drug, dose, diluent volume, and route confirmed against the order
- Cycle number and day of cycle confirmed as due today
- Vascular access checked and patency confirmed before starting
- Pre-medication given and observation period documented
Consent and pre-treatment checks before the order is released
Consent for chemotherapy is regimen-specific and cycle-aware. The patient consented to a named protocol with a described toxicity profile, and a change of regimen requires fresh consent rather than a note. The record should hold the consented regimen, the date, the clinician who took consent, the language used, and whether an interpreter or a witness was involved, because a consent document in English signed by a patient who reads only the state language is a weak record in any forum that later examines it.
Pre-treatment checks are the gate that releases the order. Counts within the validity window, renal and hepatic function where the protocol demands it, cardiac assessment where cumulative exposure requires it, pregnancy status where relevant, and confirmation that the previous cycle's toxicities were assessed and graded. Configure these against the protocol so the gate is regimen-specific, and make the release action explicit and attributable rather than something that happens by default when a form is saved.
Two practical cautions. First, resist adding hard stops for everything, because a system with fifteen mandatory overrides trains clinicians to override reflexively and you lose the alerts that matter. Reserve hard stops for the small set of things that must never proceed, and make everything else a visible warning with a recorded reason. Second, review the override log monthly. The pattern of what people override, and who overrides most, is the most useful safety data an oncology service generates about itself, and almost nobody looks at it.

