Incident-Response First Hour
Pharmacy Buyer AI Guardrails, a RealActivity educational resource
What to do in the first hour after an AI tool produces a harmful, wrong, or suspicious output. Post this where the tool is used. Fill in the two lines below before you need them.
Report channel:
Incident owner:
Detect
- The error or near-miss is written down: what the tool produced, when, and who saw it.
- The affected output, screen, or record is preserved, not corrected away.
Contain
- The tool is paused for the affected workflow, or its outputs are held for human review.
- Any patient-facing consequence is checked and, if needed, clinically addressed first.
Report
- The incident is reported through the one known channel above, within the hour.
- The vendor is notified through the contractual reporting path, in writing.
Investigate
- The root cause is pursued, not just the symptom: input, model, integration, or workflow.
- Whether the same error could have happened elsewhere is asked and answered.
Remediate and learn
- The fix is made and documented, and the guardrail that should have caught it is updated.
- The lesson is shared with staff and reflected in the next approval-gate review of this tool.
Near-misses are free lessons. Capture them like errors. A near-miss that goes unrecorded will introduce itself again, with worse timing.