Our own project · Meridian Hospital Group is a constructed operator; the instrument and its figures are real
Meridian Hospital Group · People
Bad actors
Two categories. Some people take money. Some people, having made an ordinary mistake, will go to considerable lengths to stop it being found, including things that harm the patient further. Both are rarely detected, which is not the same as rare and is frequently mistaken for it. Both do damage roughly in proportion to how long they run unfound, which makes early detection the whole design problem.
Everything on this site so far has argued that most harm in a hospital is structural. Nobody chooses to leave the patient waiting; the cost of waiting simply is not on any ledger, so it loses every argument it is never entered into. That is the honest account of the great majority of what goes wrong, and it is why the remedies proposed here are about instruments rather than about intentions.
It is also, on its own, naive. Some people do mean it. Healthcare has produced clinicians who killed patients, executives who falsified performance, and procurement staff who took money to buy things that did not work. A model that cannot accommodate them is a model that a bad actor can walk through without touching the sides.
And the two halves are connected, which is the point of this page. The same blindness that lets good people cause harm without knowing is exactly what lets a bad actor operate without being seen. Every unmeasured column is an opportunity.
There are two categories, and this page takes them in order of how much they are discussed rather than how much they matter. The first is money: fraud, kickbacks, billing for things that did not happen. The second is concealment, where somebody who has made an ordinary mistake acts to prevent it being found, and the acting causes more harm than the mistake did. The first is the one that gets discussed, audited and legislated for. The second is less examined, harder to find, and does more damage per occurrence, because concealment compounds and fraud mostly does not.
Chapter 1 · Why the two halves are one problem
The invisibility is the vulnerability
Go back to the three kinds of cost from the entity model. Measured and attributed. Measured but misattributed. Not measured at all. Now read them as an attacker would.
The first is hard to steal from, because somebody reconciles it. The second is where fraud hides comfortably, since the cost is real but arrives late and under a heading that names a symptom, so an unexplained variance looks like the workforce problem everybody already believes in. The third is where deliberate harm can continue indefinitely, because nothing is counting the thing being damaged.
This is why an organisation that cannot see the patient’s cost also cannot see somebody imposing it on purpose. It is not that the controls failed. It is that there was no instrument pointed in that direction at all, which is the same sentence this study has been writing since the first chapter, now with a different subject.
It follows that measuring the unmeasured column is not only an ethical improvement. It is a fraud control, and it is worth arguing for on that basis in rooms where the ethical argument does not land.
Chapter 2 · Which makes it predictable
Every payment model has its characteristic crime
Fraud is not random. It follows the incentive, so the way a provider is paid tells you in advance what the dishonest version of that provider will do. Fee for service produces overtreatment. Case payment produces upcoding. Block contracts produce queue manipulation. Capitation produces under-treatment.
That predictability is the good news, because a crime you can name is a crime you can design a check for. Each entry below states what it looks like, what it leaves in the data, and the check that finds it. Almost all of those checks are cheap. What they mostly require is somebody independent enough to run them and senior enough to be believed.
-
Fee for service
Overtreatment and phantom billing- What it looks like
- Procedures that were not necessary, investigations that were not indicated, follow-ups that exist to be billed, and occasionally items billed that never happened at all.
- Signal in the data
- Procedure rates per head far above peers for the same case mix, a small number of clinicians accounting for a large share of a profitable code, and follow-up ratios that do not vary with severity.
- The check that finds it
- Peer rate comparison by clinician, adjusted for case mix, published internally. It finds the outlier quickly and it is almost never run.
-
Case payment, DRG or tariff
Upcoding and patient selection- What it looks like
- Recording complications and comorbidities that are technically defensible and clinically marginal, so the episode groups into a better paid category. Also avoiding the complex patients whose true cost exceeds the tariff.
- Signal in the data
- Complication coding rising without any change in outcomes, case mix drifting upward faster than the population it serves, and a refusal rate for complex referrals that nobody has looked at.
- The check that finds it
- Coding audit against the clinical record by somebody who does not report to the people being paid, plus tracking who was turned away and why.
-
Block contract or global budget
Waiting list manipulation- What it looks like
- The queue is the only free variable, so it becomes the thing that is managed rather than reduced: clock stops that are not real, patients moved between lists, and definitions reinterpreted at the point where the target bites.
- Signal in the data
- A distribution of waits with a suspicious cliff immediately before the target threshold, and numbers that improve without any change in capacity or demand.
- The check that finds it
- Plot the whole distribution rather than the percentage hitting the target. Manipulation is visible as a shape and invisible as a headline.
-
Capitation
Under-treatment and cherry-picking- What it looks like
- Revenue arrives whether or not the patient is seen, so the profitable move is to enrol healthy people and provide less to everybody. Referral becomes a way of exporting cost.
- Signal in the data
- A registered population healthier than the area it sits in, low intervention rates with no corresponding outcome advantage, and outward referral rates rising.
- The check that finds it
- Compare the list against the local population and track outcomes rather than activity, because low activity looks identical to efficiency until you ask what happened to people.
-
Pay for performance
Gaming the indicator- What it looks like
- Effort moves to whatever is measured and away from everything else, and where the indicator is weakly defined, to the recording of the indicator rather than the thing it stands for.
- Signal in the data
- Indicator performance improving while related unmeasured measures deteriorate, and exception reporting rising conveniently.
- The check that finds it
- Always pair an incentivised measure with an unincentivised one that should move with it. Divergence between them is the entire alarm.
-
Direct payment by the patient
Selling treatment to people who do not need it- What it looks like
- No insurer reviews the claim and the patient cannot assess necessity, so the only check on whether a procedure was warranted is the conscience of the person recommending it.
- Signal in the data
- Conversion from consultation to procedure far above clinical norms, and a price list whose most promoted items are its most profitable ones.
- The check that finds it
- Independent second opinion required above a defined threshold, with the second opinion paid the same whether or not it agrees. This is the single most effective control in a cash market and the least popular.
-
Procurement, in any system
Kickbacks and substitution- What it looks like
- Awarding to a supplier for reasons other than merit, or accepting substandard and occasionally counterfeit product because the margin is shared.
- Signal in the data
- Single source awards without competition, specifications written so that only one supplier qualifies, and device failure or infection rates rising after a contract change.
- The check that finds it
- Separation of the person who specifies from the person who awards, declared interests that somebody actually reads, and clinical outcome tracked across supplier changes.
Chapter 3 · The governance blind spot
The instrument is self-reporting, and a bad actor does not report
Clinical governance in most hospitals rests on incidents being reported by the people involved in them. It is a reasonable design for error, which people will usually declare, and a hopeless design for intent, which they will not.
So the seat that answers for quality and safety sees a systematically incomplete account of what happened, and the gap is exactly the part where somebody meant it. A ward with no incidents is either exceptional or silent, and every serious inquiry into a healthcare scandal has found the same thing: the reporting rate was a measure of how safe people felt to speak, not of how safe the ward was.
Which means detection has to come from somewhere that does not depend on the perpetrator cooperating. Outcome data compared against peers. Mortality and complication rates by individual clinician. Prescribing and procedure patterns. Complaints read as a series rather than as isolated cases. None of it is difficult and all of it requires a decision to look.
The seat this lands on is set out on the head of quality and governance page, and the one that holds the outcome data on the chief medical officer page.
Chapter 4 · And could not be heard
In almost every case, somebody knew
The British cases that reshaped clinical governance share a pattern. Harold Shipman, convicted in 2000 of murdering patients in his care, and Ian Paterson, convicted in 2017 of wounding patients through operations they did not need, were both eventually stopped. In both, and in the service failures examined by public inquiry since, colleagues had raised concerns well before anything was acted on.
The actor model explains why that keeps happening, and it is worth being precise because the usual explanation, that institutions close ranks, is only the surface of it.
The person who notices is close to the patient. A nurse, a junior, a ward clerk, a mortuary technician. On the scale set out on the entity page, that position has almost complete sight and almost no power. The person who could act sits several steps away, with the authority and without the sight. So the concern has to travel the entire length of the axis along which sight decays and power accumulates, being reinterpreted at every step by someone slightly further from the evidence and slightly more invested in the institution.
That is not a conspiracy. It is a signal path with a poor signal to noise ratio and a strong incentive gradient, and it fails in the same way every time. Which also tells you what fixes it: a route that does not pass through the chain. A reporting line that reaches the board or the standards seat directly, a named person outside the management structure, and a rule that the person who raised it is told what happened. Organisations that do those three things find their problems earlier, and the reason is structural rather than cultural.
Chapter 5 · Concealment
The other side, where the cover-up is the harm
Fraud is a decision to take something. Concealment usually starts as a much smaller decision, taken by somebody frightened rather than greedy, and it does more damage precisely because it does not begin as wrongdoing.
The sequence is consistent enough to describe. An error occurs: a drug given late or not at all, an investigation not ordered, a deterioration not escalated, a complication that should have been disclosed. Most people, most of the time, report it, and the system works. But if disclosure looks career ending and concealment looks likely to succeed, a proportion of people will conceal, and having concealed once they are then committed, because every subsequent decision has to remain consistent with the first one.
That commitment is what turns a mistake into something else. The second decision is no longer clinical. The investigation that would reveal the error is not ordered. The record is amended to match the account rather than the events. The patient is discharged before somebody else notices. The family is told a version. Each of those is a clinical decision taken for a non-clinical reason, and each one costs the patient something.
It is worth being clear that the overwhelming majority of clinicians disclose errors, including ones that count against them, and that this is a minority behaviour. It is also worth resisting the next sentence everybody writes, which is that it is therefore rare. Nobody knows how often it happens, for reasons set out later on this page, and the consequences when it does are severe enough that an organisation has to be designed for it rather than hoping.
Chapter 6 · Why concealment escalates into harm
The patient is the evidence
Here is the difference between this and fraud, and it is the reason this half of the page exists.
In a financial fraud the victim is a payer and the evidence is a document. Falsify the document and the crime is complete. In a clinical concealment the evidence is the patient: their body, their notes, their account and their family. The mistake is recorded in their physiology and in a record other people can read. So concealing it means acting on the evidence, and the evidence is a person under your care.
That is the terrible logic of it. Not ordering the scan is both the concealment and a fresh clinical harm. Not recalling the patient protects the account and leaves the disease untreated. Amending the observation chart hides the missed deterioration and removes the information the next clinician needed. There is no version of clinical concealment that leaves the patient where they were, which is why the cover-up so reliably causes more damage than the original error, and why inquiries consistently find that the initial failure was survivable and the response was not.
It also explains a pattern that looks baffling from outside: why an institution facing a complaint sometimes behaves worse than the incident warranted. It is the same mechanism scaled up. Once a version has been given, everything afterwards has to be consistent with it, and the people defending the version are usually not the people who made the mistake.
Chapter 7 · The tells
Decisions that make no clinical sense and perfect narrative sense
Concealment is detectable, and not by catching somebody in a lie. It is detectable because it requires decisions that are hard to justify clinically and easy to explain if you know what is being protected.
That is the diagnostic, and it is usable by any reviewer willing to ask one question of a case: is there a decision here that would be odd on its own, and stops being odd if you assume somebody needed the record to say something? Below are the recurring forms.
-
The investigation that was not ordered
Omission- What it protects
- The fact that something was missed earlier, which the result would have dated.
- How it presents
- A test that would have been routine for this presentation is absent, with no recorded reason, and the absence is never discussed in the notes afterwards.
- What would confirm it
- Compare against what was ordered for comparable presentations by the same team in the same period. A single omission is noise. A pattern around one clinician or one incident is not.
-
The record amended after the event
Alteration- What it protects
- The account, by making the notes consistent with what was later said to have happened.
- How it presents
- Entries written or edited after the point at which somebody raised a concern, sometimes clarifying exactly the detail that is in dispute.
- What would confirm it
- Audit trail and timestamps, which is why an append-only record with visible amendments is a safety control and not merely an IT preference. Paper records cannot do this, which is one of the strongest arguments against them.
-
The discharge that is early for this patient and convenient for the account
Removal- What it protects
- Against a second pair of eyes noticing, by ending the episode before anybody else reviews it.
- How it presents
- A discharge that is defensible in isolation, out of pattern for the diagnosis, and closely timed to the point at which a concern was raised or a consultant was due.
- What would confirm it
- Length of stay against the distribution for that diagnosis, cross referenced with readmission. Concealment by discharge very often returns as a readmission within days.
-
The recall that was never made
Silence- What it protects
- Against the patient learning that a result was missed or misread.
- How it presents
- An abnormal result filed as seen with no action and no communication, and a patient who is never contacted.
- What would confirm it
- Reconcile abnormal results against documented actions and against patient contact. This is a routine and cheap audit that almost nobody runs continuously.
-
The observation chart that is too neat
Fabrication- What it protects
- Against a missed deterioration being visible in the trend.
- How it presents
- Readings recorded at implausibly regular intervals, values that do not move when the patient clearly did, or a set completed retrospectively in one hand.
- What would confirm it
- Compare charted observations against device data and staffing levels for that shift. Perfect observations on a shift that was two nurses short is a contradiction, not a record.
-
The complaint answered by describing the complainant
Discrediting- What it protects
- The institution, by shifting the question from what happened to who is asking.
- How it presents
- A response that addresses the person’s manner, history or state of mind at length and the specific factual allegation briefly or not at all.
- What would confirm it
- Read the complaint for checkable facts and check those first, before any characterisation is written. If the factual allegation was never tested, that is the finding.
Chapter 8 · The most effective concealment of all
Discrediting the patient is part of the method
The cheapest way to make an allegation disappear is to make the person making it not credible, and healthcare provides an unusually effective vocabulary for doing so.
Difficult. Anxious. Non-compliant. Drug seeking. Known to services. Every one of those is a legitimate clinical observation that is sometimes true and sometimes accurate and necessary to record. Every one of them also functions, once written, as an instruction to future readers about how much weight to give this person’s account. A patient characterised that way in the notes can report a real event and be read as a symptom.
This is why complaints data belongs in the same conversation as safety data, and why it matters that the seat holding it is the one without a budget. A complaint that alleges a specific, checkable fact, that a drug was not given, that a call bell went unanswered for an hour, that nobody came, should be checked against the record before anybody characterises the complainant. That sounds obvious. It is very frequently not what happens, and the inversion is the point: the account is assessed by reference to the person rather than the person by reference to the account.
The families in almost every major inquiry describe the same experience, and they describe it before they are believed rather than after. Being disbelieved is not a side effect of institutional failure. It is the mechanism by which the failure is sustained.
Chapter 9 · Time as the accomplice
Delay is not incompetence, it is a technique
An institution that wants an allegation to fail does not usually need to lie. It needs to be slow.
Delay degrades everything the complainant depends on. Memories become unreliable and therefore disputable. Staff rotate, retire and emigrate. Contemporaneous notes stop being contemporaneous. Complainants, who are usually ill or bereaved and always outmatched in resources, exhaust. None of that requires anybody to act dishonestly, which is exactly what makes it available to people who would not lie.
So speed is a control, and it is one of the few in this whole study that can be specified precisely. A statutory clock on investigation, a rule that the record is secured at the moment a concern is raised, and a requirement that the person who raised it is told what happened and when. Those three do more against concealment than any amount of values statement, because they remove the resource that concealment actually runs on, which is time.
Chapter 10 · The denominator nobody has
Rarely detected is not the same as rare
It is tempting to write that this is rare, and almost everybody does. It is worth being careful, because the sentence smuggles in a claim nobody can support.
What is actually known is how often it is detected. That is a property of the instrument, not of the world. And for this particular behaviour the two come apart further than for almost anything else a hospital measures, because concealment is by definition the act of preventing detection. A successful concealment is, by construction, absent from every dataset the organisation holds. The detection rate is therefore a measure of how bad people are at concealing, not of how often they try.
The selection is not random either, which makes it worse. Cases come to light when the concealment failed, and it fails for particular reasons: it was clumsy, or the patient died and somebody had to sign something, or a family refused to go away for eleven years. So the cases anybody has read about are drawn from the incompetent and the catastrophic tails. The skilful and the moderate are not underrepresented in that set. They are absent from it.
Which means an organisation that says this does not happen here is reporting on its own detection capability and mistaking it for a finding about its staff. It is the same error this study identified in the accounts: an empty column read as a zero rather than as an instrument pointed somewhere else.
There is an honest way to get at the size of the gap, and it does not involve estimating concealment directly. Independent review of a random sample of case records reliably finds harm that incident reporting did not, and the ratio between the two is a measurement of how much the reporting instrument misses in general. That ratio is a floor for what is being missed deliberately, and it is producible by any hospital willing to fund the review.
None of this changes the practical answer, and it sharpens the reason for it. Since the true rate is unknown and unknowable from reports, the design cannot be calibrated to an assumed frequency. It has to be continuous and cheap, so that it runs whether or not anybody currently believes there is a problem.
Chapter 11 · Detection latency
Found late, which is where the damage is
Whatever the true rate, the damage from any single instance is a function of how long it runs, because concealment compounds by construction. Every subsequent decision has to stay consistent with the first one, and each of those costs the patient something.
A concealment found in a fortnight has produced one harm. The same concealment found in three years has produced a sequence of them, and by then the record is contested, the staff have moved on and the family has spent years being disbelieved. Detection latency is not a performance measure sitting alongside the harm. It is the harm.
Infrequent detection makes that worse rather than better. Rare events build no institutional muscle: nobody becomes practised at finding something that seldom surfaces, the checks that would find it are not routine because they almost never fire, and when one finally does the organisation has no habit of response and reaches for an inquiry, which is the slowest instrument available.
So the design follows. Not a better investigation but a continuous, cheap, low drama signal running on data the hospital already produces, so that the first question is asked in weeks rather than the first inquiry commissioned in years. And because most signals will have an innocent explanation, the output has to be a question rather than an accusation. A check that accuses gets run once. A check that asks can run every week forever.
Chapter 12 · The only control that works upstream
Making disclosure survivable
Everything above is detection, and detection is the second best answer. The first is to change the calculation at the moment the error happens.
A frightened person decides between two futures. Disclose, and face an investigation, possible regulatory referral, and the reaction of colleagues and managers. Conceal, and probably get away with it. When those are the options, some proportion of people conceal, and the proportion is a property of the organisation rather than of the profession. Every organisation gets the disclosure rate its consequences deserve.
Which means the single most effective control against clinical concealment is not a policy about candour but the lived answer to a question every clinician already knows the answer to: what happened to the last person here who put their hand up. If the answer is that they were supported, the investigation looked at the system, and their career survived, disclosure is rational. If the answer is that they were suspended within a week and are no longer employed, concealment is rational, and no amount of published duty will change the arithmetic.
Three things make it survivable in practice. Separate the person who made the error from the person who investigates it, so that disclosure does not mean handing evidence to a judge. Treat concealment as far more serious than the underlying error, explicitly and in writing, so that the difference between the two futures reverses. And make the outcome of disclosures visible internally, because the calculation is made from what people have seen happen, not from what the policy says.
None of it is soft. Concealment is the more punishable offence precisely because the error is usually forgivable and what follows it is not.
Chapter 13 · Meridian specifically
Where this group is exposed
Three exposures follow from Meridian’s own model and its working hypothesis, and they should be named before anybody builds anything.
The first is the sale gate. A business that sells only mature, best in class assets has, by construction, a strong interest in an asset being declared mature. The control is the Director of Standards, published criteria and a reporting line to the board. Capture that seat, or let the criteria be written after the fact, and the group becomes precisely the kind of vendor its own brand page says it is not. The vulnerability is not hypothetical; it is the single most valuable thing for an insider to compromise.
The second is the direct pay market. In a system where the patient pays at the point of care, no insurer reviews the claim, no tariff constrains the price, and the person recommending a procedure is the person billing for it. Every check that exists in a third party payer system is absent by default. A group entering that market with values about taking waste rather than relief has to install its own controls, because the market will not supply them, and the honest version of that is expensive.
The third is credentials in a short labour market. Recruiting hard, at distance, in a market where demand exceeds supply, is the standard precondition for hiring somebody whose qualifications do not survive examination. Primary source verification of every registration, every time, is dull and slow and is the control that prevents the category of harm that is hardest to recover from.
Chapter 14 · Without insulting the majority who do not
Designing for the minority who mean it
The difficulty with controls is that they are written for a small number of people and experienced by everybody. Build them badly and the organisation spends its life proving its own honesty, which is demoralising, expensive and a reliable way to lose the staff you most want to keep.
Four principles keep that in proportion. Design controls that run on data the organisation should be producing anyway, so the honest majority never has to do anything extra. Separate the person who specifies from the person who awards and the person who is assessed from the person who assesses, because separation is cheap and suspicion is not. Make the independent route real rather than declared, since a whistleblowing policy that routes through the line manager is a policy about not being told. And publish what happens, because the strongest deterrent is the knowledge that somebody looks.
None of it conflicts with the rest of this study. The same instrument that shows a board what a decision costs a patient is the instrument that shows it when somebody is taking that cost deliberately. Build it once and it does both jobs, which is a better argument for building it than either job makes alone.