Direct Action Briefings
Leadership, decision-making, and operational execution under pressure.
Direct Action Briefings
DA Briefing 0043: Navigate Obstacles Rapidly in Healthcare
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Capability Focus: Navigate Obstacles Rapidly
Industry Focus: Healthcare Operations
Tool Focus: Critical Intervention
Episode Focus: Moving affected ventilators from temporary safeguards into controlled correction without disrupting patient-care continuity.
The recall notice was real.
The hardware defect was active.
Replacement parts were limited.
And the affected ventilators could not all be removed at once.
In this Direct Action Briefing, Mikey K breaks down what happens when healthcare leaders must correct a known equipment failure while the affected devices are still supporting essential patient-care operations.
Certain ResMed Astral ventilators may enter a fail-safe state because of damage caused by a leaking component on the main board.
Backup ventilation can reduce the immediate exposure.
Monitoring can help teams recognize a failure.
Alarm-response preparation can protect continuity.
But none of those controls remove the hardware defect.
That creates two dangerous leadership responses.
Remove every affected ventilator immediately and create an equipment-capacity failure.
Or keep every affected ventilator under temporary controls and allow the workaround to become the permanent operating answer.
Both responses are trying to protect the patient.
Both can fail.
The leadership question is no longer:
How do we keep every affected device operating?
It becomes:
How do we move the known failure point into correction without removing support faster than the care system can replace it?
This episode examines why temporary protection is not the same as correction, how activity can create the appearance of progress, and why Critical Intervention requires direct action that is prioritized, contained, supported, and reassessed.
The backup was not the correction.
It was the reason the organization had enough time to make one.
Read the companion article:
https://www.direct-action-system.io/blog/when-backup-ventilation-is-carrying-a-hardware-defect
Get the healthcare-specific Direct Action starter resource:
https://www.direct-action-system.io/healthcare-starter
Read practical leadership and operations articles on the Direct Action Blog:
https://www.direct-action-system.io/blog
This briefing is part of the Direct Action Briefings series, where Mikey K breaks down practical decision systems for leaders operating under pressure.
Hey, welcome to the briefing. What I'm going to cover with you today is this. When backup ventilation is carrying a hardware defect, a temporary control can be working exactly as intended and still be the wrong permanent answer. And that is the tension inside this episode. Backup ventilation can protect a patient if the primary ventilator stops delivering therapy. Monitoring can help qualified personnel recognize a problem. Alarm response preparation can reduce delay. Alternate equipment can preserve continuity while a device moves into an approved inspection or service process. All of that matters. None of it corrects the hardware defect inside the ventilator. Certain ResMed Astral 100 and Astral 150 ventilators contain a supercapacitor that may leak over time. That leakage can damage circuitry on the main board and cause the ventilator to enter a fail-safe state. If the condition occurs while the ventilator is delivering therapy, therapy can stop. If it occurs while the ventilator is in standby, therapy may fail to start. In either case, the device can become unable to deliver therapy. The Food and Drug Administration classified the correction as a Class 1 recall, its most serious recall classification. As of June 23rd, ResMed had reported five serious injuries and no deaths associated with the issue. That establishes the seriousness. It does not give a healthcare leader one simple operating answer. The affected ventilators may be supporting patients inside hospitals, in home care environments, or during portable use. Some patients may have immediate access to trained personnel, monitoring, and replacement equipment. Others may be in environments where the backup path depends on caregiver readiness, service coordination, equipment delivery, and clear communication. Replacement mainboard availability is significantly constrained. The affected population cannot all be corrected at once. So the leader cannot responsibly say, remove every affected ventilator today, without first understanding what will provide appropriate ventilation after each device is removed. The leader also cannot say, we have backup equipment and alarm procedures so the problem is controlled, and then allow those temporary protections to become the permanent operating answer. No. Let me make that more accurate. Both reactions are trying to protect the patient, but each one protects only part of the operating picture. The leader has to protect both objectives without pretending they are the same objective. That is what makes this a critical intervention problem. The hardware condition requires direct correction. The surrounding patient care system requires control. The leader has to hold both at the same time. The first failure pattern is under response. The organization receives the notice. Risk management distributes it. Respiratory care reviews it. Clinical engineering begins identifying equipment. Home care operations checks device records. Staff confirm backup ventilation. Caregivers receive reminders. Alarm response expectations are reinforced. Those are responsible actions. The temporary response may be exactly what protects the patient while the organization prepares the direct correction. The problem begins when leadership treats that protection as proof that the hardware condition has been resolved. It has not been corrected. The supercapacitor is still inside the device. The affected mainboard is still inside the care path. The possibility of fail-safe operation remains. The organization is depending on backup equipment, monitoring, training, communication, service coordination, and human response to absorb the consequence if the primary device fails. That is stabilization. It may be necessary. It is not the end state. The workaround has already requested permanent office space. And ah, this is where temporary controls become dangerous in a very specific way. Not because they do not work, because sometimes they work well enough that people stop feeling the urgency of what remains underneath them. The temporary control starts feeling less temporary because nothing visibly failed while it was in place. It is still a weak operating read. The absence of another event is not evidence that the failure point has been removed. The second failure pattern is over-response. I respect the instinct to act. I do not respect acting so broadly that the response creates a new failure the organization should have seen coming. The problem is that an affected ventilator may still be supporting an essential patient care objective. Removing that ventilator without an appropriate alternative can create a more immediate continuity failure than continuing controlled use while the correction is prepared. The Food and Drug Administration specifically states that patients should not stop using an affected ventilator unless instructed by their clinician. It also states that an affected ventilator should not be removed unless an appropriate alternative means of ventilation is immediately available. That boundary matters. The intervention cannot be broader than the support system can carry. A leader cannot solve one equipment risk by creating a patient care continuity failure. The patient cannot be abandoned while the organization corrects it. Critical intervention exists for exactly this kind of operating pressure. It applies when the problem is active, postponement is no longer acceptable, temporary stabilization is not enough as the final answer, and the leader has enough information to act directly on the known failure point without creating unacceptable collateral impact. That does not mean the temporary controls disappear. Actually, let me separate those two things, because this is where people confuse the tool. Critical intervention does not mean stabilization failed in every sense. The temporary control may still be protecting the objective. What has failed is the idea that stabilization can serve as the final operating answer. The backup protects the patient care objective while correction moves forward. The mistake is allowing the backup to become the reason correction never does. Let's put a leader inside this situation. Dana is the director of respiratory care for a regional health care network. The network uses portable ventilators inside acute care facilities. It supports patients through home care operations. Clinical engineering manages maintenance records, equipment identification, and service coordination. Durable medical equipment teams support device delivery and replacement. Authorized service centers control the technical inspection and correction process. Her responsibility is the operating coordination required to keep the correction from fracturing across departments, facilities, service partners, patients, and caregivers. That distinction matters because leadership does not mean personally performing every task. It means making sure the right people have the information, authority, support, resources, sequence, and ownership required to perform the task correctly. Dana cannot hold respiratory care responsible for service center capacity it does not control. She cannot hold a caregiver responsible for a device status change that was never communicated. She cannot hold clinical engineering responsible for a field location that home care records never updated. She also cannot excuse a missed action when the owner had the information, authority, support, and opportunity to act. Justice requires both sides of that standard. Do not punish people for variables they did not control. Do not hide preventable failure behind the fact that the situation was difficult. The recall notice reaches the network on a Friday morning. Risk management sends the alert. Respiratory care checks active use. Clinical engineering reviews models and main boards. Home care teams check field locations. Supply chain checks replacement stock. Service partners warn that parts and repair slots are limited. Senior leaders ask the first hard question how many affected ventilators do we have? The answer is not immediately available, and uh that is not automatically evidence that somebody failed. The model name alone does not confirm the complete affected population. The main board currently installed in each ventilator matters. Some ventilators may still contain the original board. Others may have received a replacement board during prior service. Some spare printed circuit board assemblies may be sitting in service inventory. Those spare boards matter because an affected board that has not yet been installed is still part of the operating exposure if it remains available for future use. Device location matters too. Some ventilators are in hospital use, some are assigned to home care patients, some are available as portable or transport capable equipment. Some are sitting in inventory. Some may be at service locations. The first reports are incomplete because every group sees a different portion of the equipment picture. Respiratory care sees what is active in the hospital. Home care operations sees field assignments. Clinical engineering sees maintenance and repair records. Supply chain sees inventory and replacement availability. Service centers see inspection and correction capacity. Clinical leaders see the patient care requirement. No single group owns the complete picture by itself. Dana's first job is not to make the biggest decision. Her first job is to understand what decision is actually available. A decision made before the organization understands the affected population is not strong because it is fast. It is fast because the leader committed before the read was complete. The team begins assembling the operating picture. Clinical engineering identifies likely affected boards. Home care teams confirm device locations. Respiratory care checks backup coverage. Clinical leaders review patient needs through the approved process. No one group can do the full read alone, and the network cannot remove every potentially affected ventilator at the same time. The authorized correction path cannot process the entire population immediately. Some devices can move into the approved service process without interrupting support. Others cannot be removed until an appropriate alternative has been secured. Then Dana receives two competing recommendations. The first recommendation is direct. Remove every affected ventilator immediately. The argument is simple. The defect can stop therapy. The safest action appears to be immediate removal. The second recommendation is cautious. Keep the affected devices in place until replacement components become available. Confirm backup ventilation, increase monitoring, reinforce alarm response, continue operating under the temporary controls. That argument also makes sense. The devices are supporting real patient care requirements. Removing them without adequate replacements may create a more immediate problem. Both recommendations are trying to protect the patient. Both are incomplete. Removing every affected ventilator ignores the continuity requirement. Leaving every affected ventilator under the same temporary controls ignores the difference between stabilization and correction. Dana cannot choose one universal policy simply because one universal policy would be easier to communicate. Here's what that decision looks like once you stop pretending it is reasonable. Every affected ventilator is lined up at the same service door while the replacement shelf contains one alternate unit and a clipboard full of confidence. The visual is ridiculous. The capacity problem is not. The fleet is not one operating condition. Some boards are affected, some are not. Some devices can move to service now. Others need an alternate support path first. The intervention has to match the actual operating picture. That is where the first major leadership misread appears. Under pressure, leaders often confuse consistency with control, but equal treatment is not automatically accurate treatment when the underlying conditions are different. A universal removal order may be too broad, a universal delay may be too weak. And look, fairness does not mean pretending unequal conditions are equal. Fairness means applying the same decision standard to the actual condition each person, device, team, or environment is carrying. Dana needs the organization to stop treating the affected population as one undifferentiated fleet. The active problem is a known hardware condition that can cause a ventilator to stop therapy or fail to begin therapy. The temporary controls can reduce the risk. They cannot remove the affected mainboard. The intervention must occur through the approved inspection and correction process. The constraint is that replacement equipment, replacement components, and authorized service capacity are limited. The decision is how the organization moves affected devices into correction without weakening the support that must remain in place around the patient. A recall notice is communication, it is not correction. The email cannot repair a circuit board, but it can schedule three meetings about one. A backup device listed in a record may be part of the protection. It is not proof that the backup is immediately available, functional, appropriate, and understood by the people expected to use it. Dana begins shifting the organization from broad mitigation to controlled intervention. Backup ventilation remains available according to the approved clinical and operating requirements. Caregivers and qualified personnel remain prepared to respond, but those actions are now supporting an active correction effort. The team does not measure success only by how many notices were sent, how many acknowledgments came back, or whether backup equipment appears in the system. It begins measuring whether the affected population has been accurately identified, whether affected spare boards have been removed from available inventory, whether devices are moving through approved inspection and correction, whether alternative support is ready before removal, and whether corrected equipment is verified before unrestricted return to service. The measurement matters because activity can create the appearance of progress while the failure point remains active. A fleet percentage does not tell Dana which hard cases remain or what support is carrying them. The dashboard is doing cardio while the hard cases sit still. Dana does not perform the repair. She protects the operating sequence around it. That sequence matters because the intervention can fail before the device ever reaches the service center. A caregiver can receive a different message from the home care team than the provider received. A hospital department can believe a device has been cleared when clinical engineering still lists it as affected. A corrected ventilator can return to service without the status being updated across the systems and teams that depend on that information. The operating environment around it may still be fragmented. Critical intervention requires the leader to act at the failure point while keeping the surrounding system coherent. Backup ventilation, monitoring, and alarm response may hold the risk for a time. That is a necessary stabilization move. Then time passes. The organization can become more comfortable with the workaround than it is committed to the correction. That is where temporary protection becomes an indefinite dependency. I have made versions of this mistake. A temporary control works, the pressure comes down, the objective keeps moving. Then the difficult next action begins to feel like something that can wait because nothing failed today. That is a weak read. The work eventually teaches you that a controlled symptom is still attached to an unresolved cause, and the cost does not disappear because the workaround held for another shift. Somebody is still maintaining the backup, somebody is still monitoring the exposure, somebody is still carrying the additional coordination, somebody is still depending on the temporary path to work exactly when the primary path does not. The point is not confession. The point is recognizing the pattern before your organization starts calling, an indefinite dependency a stable process. The next problem is operating fatigue. Every temporary control has a human and organizational cost. Backup equipment has to remain available and reliable. Caregivers and qualified personnel have to remain prepared. Monitoring cannot drift. Alarm response expectations cannot become casual. Record shave to stay current. Service coordination has to continue. Communication has to reach hospital teams, home care teams, providers, patients, caregivers, and service partners. The longer the temporary control remains, the more opportunities exist for one part of that support structure to weaken. A temporary control is not free because it is already in place. It consumes attention, it consumes equipment, it consumes coordination, it creates additional points where the operation can fail. Then uneven correction begins. The easiest devices move through the service process first. Devices inside the hospital may be easier to identify and retrieve. Home care devices may require more coordination. Some patients may require a more complicated replacement path. Some service locations may have greater access to authorized correction capacity. Some records may be more complete than others. The organization reports progress because the number of corrected devices is increasing, but the most complicated cases remain under temporary controls. Those may also be the cases requiring the greatest operating discipline. Now the progress number can become misleading. The organization may have corrected a large portion of the fleet while leaving the most difficult exposure unresolved. That is why Dana cannot manage the correction only through percentage complete. She has to understand what remains. Which devices are still affected? Where are they? What patient care objective are they supporting? What temporary protections are carrying the risk? How reliable are those protections? What must be secured before the device can move into correction? Who owns the next action? What is the return point? You know, this is where leaders can become unfair. A report may show 80% complete and make the last 20% look like poor follow-through, but the last cases may need the most coordination, the least spare capacity, and the most field support. That is not a reason to leave them open. It is also not proof that the people who own them have failed. The leader has to ask, what is blocking the next move? Do they have the right device data? Do they have an alternate unit? Do they have a repair slot, clear authority, and a real sequence? If those conditions are missing, leadership owns part of the delay. If those conditions exist and the owner still will not act, accountability is fair. Then consider what happens if leadership overcorrects. The network removes units faster than alternate support can be placed. Hospital teams compete for spare devices. Home care teams wait for replacements. Service centers receive more units than they can inspect. Staff start moving equipment from site to site with no stable plan. The first harm is loss of usable capacity. Then the workload grows. Teams chase device locations, fix records, change plans, and explain mixed messages. Then trust drops. Patients, caregivers, and staff start to ask whether one plan exists at all. What began as a direct correction effort becomes a fight for scarce equipment. That is not decisive leadership. That is uncontrolled action dressed up as urgency. Critical intervention does not reward the broadest reaction. It requires the leader to identify the direct action point and contain the intervention around it. For Dana, the action point is not all respiratory equipment. It is not every ventilator, it is the affected mainboard population identified through the approved criteria. The direct intervention is not an improvised technical repair. It is movement through the authorized inspection and correction process. The limits are defined by the patient care objective, the availability of appropriate alternative ventilation, approved clinical judgment, manufacturer and regulatory guidance, service capacity, and the need to prevent affected spare boards from re-entering the equipment path. It is disciplined direct action. The better read is not that the backup solved the problem. The better read is that the backup created operating room for the problem to be corrected. The better read is that every affected device needs a controlled path toward correction, and that path must protect the patient, care objective while it moves. The better read is that constrained capacity requires prioritization, sequencing, ownership, and reassessment. It aims urgency at the actual failure point. Tactical resolution manages the effect of an active problem so the operation can continue. In this situation, backup ventilation, monitoring, alarm preparation, and temporary operating controls reduce the immediate exposure. Critical intervention becomes necessary when leadership recognizes that those controls cannot serve as the permanent answer. The defect itself must be acted on. Delay allows the defect to remain inside the care path. The intervention can be contained if the organization protects alternative ventilation, service capacity, communication, ownership, and reassessment. It does not replace clinical judgment. It does not replace food and drug administration direction. It does not give an unqualified person authority to inspect or repair a medical device. It gives the leader a disciplined way to recognize that stabilization has reached its limit as the final answer. The leadership question changes from are the temporary controls in place to are the temporary controls actively supporting removal of the known failure point? The temporary controls remain attached to the devices and patients that still require them. Affected spare boards are removed from available inventory through the approved process. Devices move through correction as alternate support, service, capacity, and clinical requirements allow. The status of each device is communicated across the groups that depend on it. Corrected devices are verified before returning to unrestricted service. The operating picture is reassessed as component availability, service throughput, device location, patient requirements, and backup readiness change. Every direct intervention changes the operating picture. The action is not complete until the leader knows whether it protected the objective. And what new risks it created. This is where the wider direct action system supports the tool. CSA improves the initial read. She needs to understand which devices are affected, where they are, what mainboards are installed, what patient care requirements they support, what backup capability exists, what service capacity is available, and what information remains uncertain. Without that read, the organization may act broadly against the wrong population or leave affected devices outside the correction plan. Deepen helps the leader distinguish the problem path. This is not identify and postpone because the defect cannot simply be scheduled for later while the organization acts as though no active condition exists. It is not only tactical resolution, because backup ventilation and monitoring control, the consequence, without removing the hardware defect. Critical intervention fits when leadership must act directly on the known failure point and can do so within controlled limits. Pro strengthens the collateral impact read. What happens if too many units leave at once? What happens if the hard cases wait too long? What happens if one site uses the last spare? What happens if a corrected unit returns before every team sees the new status? Those are not reasons to avoid intervention. They are the risks that define its boundaries. TMC protects direction, ownership, and communication. Respiratory care, clinical engineering, home care, supply chain, clinical leaders, and service teams need one shared status. Otherwise, the email chain becomes the respiratory command center. When those groups work from different plans, the correction creates new failure points. ALC closes the loop after each phase. It captures where records failed, where backup capacity was weak, where a handoff broke, and what should change before the next device alert. The point is to make the next response faster, clearer, and more controlled. Now bring this pattern into your environment. The issue may be a recalled device, a manual work path, a temporary staff plan, a second review, a backup call path, a service limit, or a workaround after a system failure? The control works, the pressure drops, the work keeps moving. Then leadership stops asking whether the source problem still exists. What temporary control is protecting an important objective right now? Who is carrying the additional work required to make the temporary control reliable? Is the organization using the temporary control to support correction or has the control quietly become the permanent answer? I am not telling you to turn those questions into unauthorized clinical or technical action. I am telling you to inspect the operating condition honestly. Separate protection from correction. Ask what the temporary control is protecting. Ask whether the original failure point still exists. Ask what continued dependence on the control is costing. Ask what must be protected before direct action can occur. Then ask whether the organization has reached the point where stabilization is no longer enough. Critical intervention begins when the leader recognizes that containment has done its job. It created room for a controlled correction. Now the organization has to use that room. Do not keep stabilizing around a problem that now requires direct action. When you are ready to go deeper with this tool, go to www.direct action system.io slash course dash directory. Open the course directory, find the course connected to critical intervention in the deepen module, and start there. That is where the deeper application belongs. Thanks for listening to the briefing.