Require an evidence gate before spread begins
Treat pilot completion as an input to a scale decision, not as automatic permission to expand. The decision record should state which workflow version was tested, where it was tested, what evidence supports wider use, which uncertainties remain, and who accepts the residual operational and governance risks. IHI distinguishes testing changes from implementation and spread within the Model for Improvement. [1]
- The workflow is stable across routine, incomplete, delayed, duplicate, and unavailable-system paths.
- Review ownership, coverage, escalation, and authoritative records are explicit.
- Accessibility barriers and high-severity defects have an accepted disposition.
- Training, operational support, incident response, and change ownership have funded capacity.
- Baseline and monitoring definitions can be reproduced by every receiving team.
Separate core fidelity from local adaptation
A scale plan should state which elements must remain consistent and which may change locally. Core elements usually include the assessment version, assignment rules, deterministic scoring behavior, review responsibility, access controls, audit evidence, and record destination. Staffing patterns, invitation timing, training format, and support channels may be adaptable when the same safeguards and completion criteria remain intact.
- Name each core element, the reason it is protected, and the evidence that shows fidelity.
- Name each adaptable element and the local decision owner.
- Require an impact check before an adaptation touches access, interpretation boundaries, review, or records.
- Version adaptations so a team can explain which workflow it operated on any date.
CFIR's implementation process domain includes assessing context, planning, tailoring strategies, engaging, reflecting and evaluating, and adapting. Use that structure to make local fit deliberate without allowing undocumented divergence from core controls. [3]
The controlled spread sequence
A five-step sequence for extending a proven workflow while preserving capacity, fidelity, and recovery control.
- Gate
Confirm evidence, controls, capacity, and authority for wider use.
- Specify
Separate protected workflow elements from governed local adaptations.
- Prepare
Close readiness gaps and verify training and recovery with synthetic cases.
- Spread
Activate one supportable wave and hold until operations stabilize.
- Watch
Monitor drift and use explicit pause, rollback, or stop thresholds.
Sequence spread around readiness and support capacity
Expand in waves that are small enough to support and compare. Assess each receiving team's current workflow, leadership ownership, staffing, access needs, integration dependencies, training time, and fallback route before setting its start date. AHRQ's practical guide treats readiness, team formation, technology decisions, implementation, and maintenance as connected work when integrating patient-generated data. [2]
- Prepare: map local differences and close readiness gaps before activation.
- Train: verify role-specific competence with synthetic normal and failure scenarios.
- Support: forecast contacts, incidents, access requests, and configuration work by wave size.
- Stabilize: hold the next wave until queue age, failures, support demand, and governance actions settle.
- Transfer: move routine ownership only after the receiving team can operate and recover without project staff.
Monitor performance and drift by team
Aggregate totals can conceal a team whose assignments, completion route, review queue, or support process is failing. Keep common definitions and compare measures by wave, team, workflow version, and time since activation. AHRQ highlights burden, usability, workflow integration, and the risk of worsening inequities as implementation concerns for patient-generated data. [2]
- Workflow: eligible requests, delivery, starts, completion, review acknowledgement, and queue age.
- Reliability: duplicates, routing errors, unavailable periods, recovery time, and unresolved exceptions.
- Experience: support demand, accessible-route use, respondent feedback, and staff burden.
- Fidelity: protected elements changed, missing evidence, unapproved workarounds, and version mismatch.
- Governance: inappropriate access, incidents, overdue actions, and record discrepancies.
Review signals on a defined cadence and after material changes. Use run charts or another transparent time-based view where appropriate, but do not interpret operational movement as evidence of clinical effect without a design capable of supporting that claim. [1]
Keep pause, rollback, and stop routes usable
Define thresholds and authority before each wave. A pause stops further expansion while active teams continue under enhanced monitoring. A rollback returns a team to a tested prior workflow or controlled fallback. A stop ends the scaled workflow when its risks or operating burden cannot be acceptably controlled.
- Pause expansion when support capacity is exceeded, required evidence is missing, or drift is unexplained.
- Rollback a wave when review ownership, routing, access, records, or recovery cannot be restored within the agreed window.
- Stop when serious or repeated governance failures, unacceptable burden, or unresolved accessibility barriers outweigh the supported operational benefit.
- Resume only after the named authority reviews root cause, corrective evidence, capacity, and the revised monitoring plan.
AHRQ's workflow toolkit emphasizes assessing the effects of health IT on clinical and administrative work. Preserve a current map for each materially different context and rehearse the rollback path with synthetic cases before a wave activates. [4]
Sources and further reading
- Model for Improvement (opens in a new tab)Institute for Healthcare Improvement. Accessed 2026-07-13. Official framework for aims, measures, selecting changes, PDSA testing, implementation, and spread.
- Integrating Patient-Generated Health Data into Electronic Health Records in Ambulatory Care Settings: A Practical Guide (opens in a new tab)AHRQ-funded project team. Published 2021-12. Accessed 2026-07-13. AHRQ-funded practical guide covering readiness, burden, usability, equity, and sustainability; its findings do not necessarily represent official AHRQ or HHS views.
- Implementation Process Domain (opens in a new tab)Consolidated Framework for Implementation Research. Accessed 2026-07-13. Official CFIR guide to implementation-process constructs and their definitions.
- Workflow Assessment for Health IT Toolkit (opens in a new tab)Agency for Healthcare Research and Quality. Accessed 2026-07-13. Official workflow-assessment resources for planning and redesign around health IT.