Record Where Each of the Twelve Identities Comes From
Device Identity Matrix
Companion to Medical Device Connectivity · Updated 2026-09-29
Use this when you design the information model and every interface that carries a record, so that each identity the device touches is modeled on its own. Systems engineers and interoperability engineers fill it in; “Context Is a Safety Feature” works it on the bedside monitor. Which rows carry the most risk depends on the class: the specimen row for a laboratory analyzer, the patient and workflow-instance rows for an imaging system, and the workflow-instance and accessory rows for a washer-disinfector processing instrument sets.
Fill in every row. Write “not applicable” for an identity the device doesn’t touch, and never leave a row blank. For each association (patient, operator, location, consumable, accessory), write in “How the device learns it” how the association starts and ends. Write in “Which records carry it” where the device records the start, the end, and who made the association.
The Device Identity Matrix: twelve identities, each modeled separately.
| Identity | What it identifies | How the device learns it | Which records carry it | What goes wrong if it’s missing or wrong |
|---|---|---|---|---|
| Device | This unit, persistently, across repairs and software changes | |||
| Component | A replaceable module, board, or sensor inside the device | |||
| Patient | The person a record is about | |||
| Specimen | The sample a result describes | |||
| Operator | The person running the device at this moment | |||
| Clinician | The person responsible for the order or the care decision | |||
| Location | Where the device is now | |||
| Organization | The institution, facility, or unit that owns and governs the device | |||
| Consumable | The disposable, chemistry, or supply used, with its lot and expiration | |||
| Accessory | The probe, sensor, cable, or instrument attached to the device | |||
| Software version | The exact software and configuration running when the record was made | |||
| Workflow instance | The specific order, case, cycle, or task a record belongs to |
Location is never a substitute for patient identity: a monitor in bed 12 is not proof of who is in bed 12. Any row where patient identity is inferred from location without a person confirming it, or where two identities share one field, is a wrong-patient or wrong-device risk. Fix it in the model before any interface depends on it. Model the operator so that an unknown operator never blocks an essential clinical action: the device records the action as “operator not identified” and reconciles the identity later.
