Chapter 52 — The Easy Correction

Test One — What happens when the error is clear and correction should be easy?


Explore the Layers
Chapters

Move to another chapter in the book.

  1. Chapter 1 — The Record
  2. Chapter 2 — Forty-Five Geologists
  3. Chapter 3 — Behind the Chronicle
  4. Chapter 4 — Thursday
  5. Chapter 5 — Robert
  6. Chapter 6 — Janette
  7. Chapter 7 — The Melbourne Process
  8. Chapter 8 — Patrick Smith
  9. Chapter 9 — Canada
  10. Chapter 10 — When the Patient Meets the Record
  11. Chapter 11 — The Life That Followed
  12. Chapter 12 — Work, Roads and Country
  13. Chapter 13 — Building a Life
  14. Chapter 14 — What Memory Did With It
  15. Chapter 15 — When the Past Began Returning
  16. Chapter 16 — Making Connections
  17. Chapter 17 — Following the Records
  18. Chapter 18 — The Cost of Being Disbelieved
  19. Chapter 19 — Building the Evidence
  20. Chapter 20 — Reclaiming the Record
  21. Chapter 21 — Germaine
  22. Chapter 22 — Herbie
  23. Chapter 23 — Through the Glass
  24. Chapter 24 — What Happened to Herbie's Story
  25. Chapter 25 — The Adults Around Yea
  26. Chapter 26 — 2007
  27. Chapter 27 — A Diagnosis That Travelled
  28. Chapter 28 — Finding Julian Lim
  29. Chapter 29 — When Meditation Opened the Wrong Door
  30. Chapter 30 — The Tests
  31. Chapter 31 — When Hell Becomes a Threat
  32. Chapter 32 — The Child of Satan
  33. Chapter 33 — What Adults Called an Exorcism
  34. Chapter 34 — The God I Was Told About
  35. Chapter 35 — Another Idea of God
  36. Chapter 36 — Teaching Fear to Children
  37. Chapter 37 — What Children Are Taught Now
  38. Chapter 38 — When Religion Becomes Abuse
  39. Chapter 39 — Australia and the Child's Freedom of Thought
  40. Chapter 40 — Personal Sovereignty
  41. Chapter 41 — What the Creator Forgot to Tell Us
  42. Chapter 42 — When Mythology Comes Before Measurement
  43. Chapter 43 — Who Gets to Speak for Authority?
  44. Chapter 44 — When the Observer Becomes Part of the Event
  45. Chapter 45 — The Iatrogenic Loop
  46. Chapter 46 — When the Record Becomes More Powerful Than the Person
  47. Chapter 47 — Secular in Name
  48. Chapter 48 — Democracy, Representation and Who Holds Power
  49. Chapter 49 — Systems That Cannot Admit Error
  50. Chapter 50 — Authority Must Remain Answerable
  51. Chapter 51 — The System that Learns to Survive
  52. Chapter 52 — The Easy Correction
  53. Chapter 53 — When Reasonable People Disagree
  54. Chapter 54 — When the Same Thing Keeps Happening
  55. Chapter 55 — When Correction Becomes Costly
  56. Chapter 56 — What the Tests Found
All sections (14)

Browse the complete chapter.

Chapter 51 introduced four tests for a system that claims to be capable of correction. The first should be the easiest.

Test One — The Easy Correction ↑

Someone identifies a reasonably clear error. There is good evidence showing what went wrong. Nobody appears to have a substantial personal or institutional interest in preserving the mistake.

This gives us a baseline. If a system cannot correct itself under these circumstances, there is little reason to expect it to do so when correction becomes difficult.

But the easy case is useful for another reason. It allows us to ask what successful correction actually consists of.

Is the concern acknowledged? Is what the person originally said preserved accurately? Is the evidence examined? If an error is established, is the originating record corrected?

And then comes a question that is easily overlooked: what else did the error affect?

A wrong entry may have travelled. It may have influenced another record, another decision, another professional opinion or another institution. Correcting the first record while leaving its descendants untouched may create the appearance of correction without removing the consequences of the error.

This is what I have provisionally called correction propagation.

There is also the question of time. How long does a known error continue to influence the system after it has supposedly been corrected? That is the idea behind Correction half-life .

Then we reach the person affected by the error.

How much work did they have to perform merely to obtain the correction? How many times did they have to explain it? How much additional harm occurred while the system was deciding whether to recognise something that could ultimately be established?

That additional cost is what I am calling remedy burden.

A correction is not complete merely because a file now says “resolved”.

For this first test we can therefore begin with a practical sequence: challenge, acknowledgement, preservation, examination, correction where warranted, propagation of that correction, care or remedy where needed, and a later check that the correction actually worked.

That final step matters. A system may change a procedure immediately after an error and gradually return to its former behaviour. So we also need to ask about learning persistence.

The easy correction is therefore not trivial. It gives us the simplest environment in which to discover what we mean when we say that a system has learned.

When can everybody reasonably say: this has been corrected?

First, we need to know what correction means ↑

I thought the first test would be straightforward.

We begin with an error that can reasonably be established. Someone points it out. The organisation checks the evidence, discovers the mistake and corrects it.

That sounds like successful correction.

But is it?

Begin with the simplest case

Suppose a person's date of birth has been entered incorrectly in an institutional record.

The record says 12 May. Their birth certificate establishes that it should be 21 May. There is no dispute about their identity and no conflicting evidence.

They point out the error.

The institution checks the birth certificate, changes 12 May to 21 May and tells the person that the correction has been made.

For the moment, let us say that this is our simplest case.

The error was found and corrected.

But now change one thing.

The incorrect date had already been copied into another database.

The original record now says 21 May. The second database still says 12 May.

Has the error been corrected?

Not completely.

That tells us something useful. Correcting the place where an error began is not necessarily the same as correcting everywhere the error has travelled.

We have encountered Correction propagation.

The error and its footprint

The original error remains extremely simple. The correct date is not in dispute.

What has become more complicated is everything the error may have affected after it entered the system.

The incorrect information might have been copied into another record, used in an identity check, included in a referral, relied upon in a decision, or passed to another organisation.

The complexity of correction is therefore not necessarily proportional to the complexity of the original error.

A very simple error can develop a substantial Error footprint.

A simple error does not necessarily produce a simple correction.

Correcting the information may not correct its consequences

Now change the hypothetical again.

Both records are corrected, but while the incorrect date existed it caused an identity check to fail and the person was refused a service.

The information is now correct.

But has everything caused by the error been corrected?

No.

Correcting an error and remedying the consequences of an error are not necessarily the same thing.

Now suppose the records are corrected, the lost service is restored and the person is informed, but six months later the same process produces the same error for somebody else.

The first person's correction may have succeeded.

The organisation's correction of the process may not have.

We now have at least three different questions:

Was the error corrected?
Were its consequences corrected?
Was the process that produced it corrected?

Who has to find where the error went?

There is another difficulty.

In our hypothetical we know where the incorrect information travelled because we invented the system ourselves.

A real person usually does not have that advantage.

They may see one incorrect record without knowing that the information has been copied into another database, included in a report or relied upon in a later decision.

Once an institution accepts that information was wrong, it may be in a much better position than the affected person to discover where its own information travelled.

That suggests a proposition worth testing:

The burden of tracing an accepted error should ordinarily fall on the system that propagated it, rather than on the person affected by it.

But how far should that responsibility extend?

Preserved uncertainty:

At this point we have identified a question we cannot yet answer satisfactorily: once an error has been accepted, how far does responsibility extend for discovering and repairing its footprint?

Requiring too little tracing may leave the consequences of an accepted error in place. Requiring unlimited tracing may be disproportionate to a minor error with little prospect of consequence.

Rather than resolve that question prematurely, I am preserving it here. Later tests, particularly those involving recurrence and differences in institutional power, may provide evidence that changes how this boundary should be drawn.

When is correction finished?

We have followed the error outward. Now another question appears.

What evidence should be required before a system can reasonably say: “This has been corrected”?

Absolute certainty may sometimes be impossible.

Suppose an institution identifies that the incorrect information may have appeared in a historical system that is no longer available.

It explains that it has examined the records that remain available, corrected what it found, but cannot determine whether the information was also present in that lost system.

That can be a reasonable outcome.

An attempt has been made. The boundary of the available evidence has been identified and explained. Unless something changes, that particular line of enquiry can reasonably be regarded as complete.

That is different from an institution saying:

“We don't know whether the error travelled anywhere else because we didn't check.”

Both situations contain uncertainty, but they are not equivalent.

Preserved uncertainty should record what remains unknown after reasonable enquiry. It should not conceal what could reasonably have been established but was never examined.

Closure is not necessarily finality

A correction can therefore reach a reasonable point of closure without claiming that nothing could ever cause the question to be reopened.

On the evidence presently available, there may simply be no reasonable further action to take.

If new material evidence later appears, the reason for closure has changed and the question can be reopened.

A good correction process needs a way to close a question without sealing it permanently against new evidence.

What has Test One produced so far? ↑

We began with a deliberately simple question:

What does successful correction look like?

The hypothetical has already made that question considerably more interesting.

For the moment, a correction appears reasonably complete when:

  1. the error has been established and corrected at its source;
  2. its reasonably discoverable footprint has been examined;
  3. known downstream copies have been corrected where appropriate;
  4. identifiable consequences have been considered and remedied where warranted;
  5. the affected person has been told what was found and what was done;
  6. unresolved matters are identified rather than converted into false certainty;
  7. there is a reasonable explanation for anything that cannot presently be established;
  8. there is no reasonable corrective action presently left undone; and
  9. material new evidence remains capable of reopening the question.

This is not yet a standard.

It is the provisional result of the first test.

We arrived here by beginning with a deliberately simple error and changing one condition at a time. Some of these requirements may prove unnecessary. Others may be missing.

The test itself must remain open to correction.

Now take it into the real world ↑

Until now I have controlled the hypothetical. I decided where the error began, where it travelled and what information was available.

Real cases do not give us that luxury.

The next step is therefore to take this provisional model and apply it to a documented case without changing the questions simply because the answers become inconvenient.

There is one additional answer we must allow:

We don't know.

If the available evidence does not establish something, I will leave it unresolved rather than fill the gap with an assumption.

The purpose of the next stage is not to find an institution that fails our test. Nor is it to find one that proves the test correct.

It is to find out whether the test survives contact with reality.

And if reality shows that the test itself has something wrong, then the test must change.

Our first encounter with a real correction system ↑

A useful place to begin is with something remarkably close to the hypothetical we have just constructed: people finding errors in their own records.

The OpenNotes initiative gave patients access to clinical notes that had traditionally been much less visible to them.

That visibility created an opportunity that matters to this test.

Patients could see what had actually been recorded about them and, in some cases, say:

You've got this wrong.

In one published study involving 4,592 patients who had read at least one clinical note, 331 contacted their doctor's office about something in the note. Of those contacts, 29 per cent concerned a perceived error.

Of the patients who reported an error, 85 per cent said they were satisfied with its resolution.

Source: Bell SK et al., Frequency and types of patient-reported errors in electronic health record ambulatory care notes, BMJ Quality & Safety, 2017. View source

That sounds encouraging.

But our test now requires us to ask something more difficult.

Does satisfaction with the resolution establish that the correction itself was complete?

It does not necessarily do so.

The patient's satisfaction tells us something important about their experience of the correction. It does not, by itself, establish whether every downstream copy was corrected, whether earlier decisions had relied upon the error, or whether the same kind of error subsequently recurred.

This does not make the reported satisfaction unimportant.

It tells us that satisfaction and correction are related, but they are not necessarily the same measure.

A system that invited correction

A later OpenNotes study gives us another part of the picture.

Instead of merely allowing patients to read their notes, researchers provided a specific feedback mechanism through which patients could report possible mistakes and safety concerns.

Of 6,225 patients invited to participate, 2,736 read their notes and 260 submitted feedback.

Potential safety concerns appeared in 23 per cent of those reports. Clinicians reviewing them judged 64 per cent of the patient-reported items to be definite or possible safety concerns.

Among cases confirmed with patients, 57 per cent resulted in a change to the record or care.

After a year, 99 per cent of participating patients and care partners who provided feedback regarded the reporting tool as valuable.

Source: Bell SK et al., A patient feedback reporting tool for OpenNotes: implications for patient-clinician safety and quality partnerships, BMJ Quality & Safety, 2017. View source

There is something important here beyond the individual corrections.

The system did not merely wait for somebody to discover how to challenge it. It deliberately created a pathway through which the person described by the record could examine it and respond.

That gives us another characteristic worth watching:

A corrigible system does not merely tolerate correction. It makes correction possible to initiate.

Now apply our provisional model

What happens when we put this evidence through the questions developed in our hypothetical?

Question from Test One What the published evidence establishes
Could the affected person identify and challenge an error? Yes. Patients could read their notes and a later pilot provided a specific feedback mechanism.
Could the challenge result in correction? Yes. The studies document changes to records or care following some patient reports.
Could the person regard the resolution as satisfactory? Yes. In the earlier study, 85 per cent of patients reporting an error said they were satisfied with its resolution.
Was the full Error footprint traced? We don't know from this evidence.
Did Correction propagation reach every downstream record or decision? We don't know from this evidence.
Were all consequences of the errors identified and remedied? We don't know from this evidence.
Did the correction persist over time? The evidence considered here does not establish this sufficiently for our test.
Did the system learn sufficiently to prevent recurrence? The studies show a correction pathway and changes to some records or care, but they do not establish that the underlying classes of error ceased recurring.

The test has changed

Our first encounter with real-world evidence has exposed something that was missing from the hypothetical.

When we constructed the wrong-date-of-birth example, we gave the person knowledge that the system itself may not provide. They already knew that the record contained an error.

That assumption allowed us to begin with the challenge: "You've got this wrong."

But before a person can challenge an error, there is an earlier question:

Could they reasonably discover that the error existed?

The OpenNotes studies matter here for a reason that goes beyond the individual corrections they describe. Giving patients access to their clinical notes made information visible to the people it concerned, and the feedback mechanism gave them a means of responding when they believed something was wrong.

Our original model therefore began one step too late.

The emerging sequence is now:

visibility → detection → challenge → acknowledgement → preservation → examination → correction → propagation → remedy → verification → learning

That does not mean every correction will pass neatly through eleven separate stages. It gives us something more useful: a set of places at which a correction process can succeed, fail, become obstructed, or disappear from view.

Correcting the provisional model

We can now add another question to Test One:

Does the person affected have a reasonable means of discovering that the information or decision requiring correction exists?

This question was not in our provisional model before we examined the OpenNotes evidence.

That matters methodologically. We said that the test itself had to remain corrigible. At the first encounter with external evidence, it has already required correction.

The test has been subject to the test.

The first real case has already changed the test

This is useful.

The evidence has not allowed us to declare the correction system either a success or a failure.

Instead, it has shown us something more precise.

OpenNotes increased the visibility of information to the person whom that information described. It gave patients an opportunity to detect errors that might otherwise have remained unchallenged. The later feedback mechanism also created an identifiable pathway for reporting those concerns.

Those are observable features of a system capable of receiving correction.

But our provisional model asks questions that these studies were not designed to answer.

We therefore have several legitimate:

We don't know.

That is not a weakness in the test.

It is exactly why we allowed Preserved uncertainty.

The absence of evidence about the full footprint of an error cannot be turned into evidence that the footprint was completely repaired.

Nor should it be turned into evidence that it was not repaired.

We simply do not know from the evidence presently before us.

Something we had not included

There is also something in the OpenNotes example that our original hypothetical did not adequately capture.

Before a person can say, “You've got this wrong”, they may first need to be able to see what the system says about them.

Our hypothetical began with the person already knowing that their birth date was wrong.

The real example makes us step backwards.

Can the person affected by the information see enough of the system to discover that there is something to correct?

That question was missing from our provisional model.

Reality has therefore done exactly what we said it should be allowed to do.

It has corrected the test.

Source: Bell SK et al., A patient feedback reporting tool for OpenNotes: implications for patient-clinician safety and quality partnerships, BMJ Quality & Safety, 2017. View source

A second encounter: the two Grace Elliotts ↑

Our first real-world example showed us something our hypothetical had missed: before an error can be challenged, the person affected needs some reasonable means of discovering that it exists.

Now we can take the revised test somewhere more difficult.

In 2022, KFF Health News reported the case of two women named Grace Elliott. Grace E. Elliott, then 31 and living in San Francisco, received a bill for $1,170 for shoulder-replacement services at a hospital in Florida.

She had not received the treatment.

The treatment belonged to another patient, Grace A. Elliott, then 81. The hospital had previously treated both women. According to the reporting, a hospital employee had selected the younger Grace Elliott's account when the older Grace Elliott attended for treatment.

Source: Mark Kreidler, The Case of the Two Grace Elliotts: A Medical Billing Mystery, KFF Health News, 21 December 2022. View source

The error was discoverable

For the younger Grace Elliott, detection was relatively straightforward. She received a bill for treatment she knew she had never received.

So the first part of our revised sequence was present:

visibility → detection → challenge

She contacted the hospital. During the process, information available to the hospital showed that the date of birth associated with the shoulder-replacement patient was not hers, and she supplied identification.

After several weeks, according to KFF Health News, an administrator at the hospital's corporate office acknowledged that the hospital had made an error and promised to correct it.

At this point our original hypothetical might almost have ended.

The error had been detected. Evidence existed. The institution acknowledged the mistake. Correction had been promised.

But the case did not end.

The correction did not travel as far as the error

The debt subsequently reached a collection agency.

Grace E. Elliott challenged it there as well. Her first appeal was denied. A second appeal was also denied.

The collection agency had contacted the hospital and relied upon information that continued to identify the younger Grace Elliott with the account. According to the KFF reporting, material sent during the collection process also included identification and medical information belonging to the older Grace Elliott.

The original identification error had therefore acquired consequences outside the place where it began.

The error had propagated farther than the correction.

This gives Correction propagation a very concrete meaning.

Correcting information in one part of a system is not necessarily sufficient when the incorrect information has already travelled into another.

Apply the same questions

We should not change our test merely because this case is more complicated. We can ask the same questions we were developing before we encountered it.

Question from Test One What the available evidence establishes
Could the affected person discover that something was wrong? Yes. She received a bill for treatment she had not received.
Could she challenge the error? Yes. She contacted the hospital and later challenged the debt through the collection process.
Was the original error acknowledged? Yes. The hospital eventually acknowledged that it had made an error.
Did acknowledgement produce complete correction? No. The debt subsequently remained active in the collection process.
Did the correction propagate to a known downstream system? Not initially. The hospital later acknowledged that its correction had not been appropriately communicated to collections.
Was the full Error footprint traced? We don't know from the available evidence.
Were identifiable consequences addressed? Eventually, the hospital said the younger Grace Elliott's information had been removed from the other patient's account and from the collection agency's database, and confirmed that she had not been reported to credit agencies.
Did the system learn from the error? The hospital said the registration clerk received additional privacy education and that steps had been taken in response. The available evidence does not establish whether those measures prevented recurrence.

Source: Mark Kreidler, The Case of the Two Grace Elliotts: A Medical Billing Mystery, KFF Health News, 21 December 2022. View source

Something important has happened to our simple error

The underlying mistake was not particularly difficult to understand. Two people with similar names had been associated with the wrong record. Their ages, dates of birth, treatment histories and circumstances provided ways of distinguishing them.

Yet acknowledging the original mistake did not automatically repair what the mistake had subsequently caused.

That gives us a distinction we did not need in the original hypothetical:

acknowledgement of an error is not the same thing as containment of the error.

An institution may reach the correct conclusion about what happened while the consequences of its earlier conclusion continue operating elsewhere.

The question therefore changes from:

Has the error been corrected?

to something more demanding:

Has the correction travelled at least as far as the error?

And the burden matters

There is another feature of this case that our test needs to notice.

The younger Grace Elliott did not merely alert the institution to the error. She spent months attempting to establish and correct something she had not caused. She dealt with different parts of the system, challenged the debt, and continued pursuing the matter after being told that it had been fixed.

Eventually, after KFF Health News contacted ShorePoint Health, she received written confirmation that her information had been removed from the other patient's account and from the collection agency's database.

This raises another question for Test One:

Once an institution accepts that it created the error, who should bear the burden of finding and correcting what the error subsequently caused?

We already encountered this question when thinking about the Error footprint.

The Grace Elliott case now gives us a real example of why the question matters.

Preserved uncertainty

We still cannot establish everything.

The reporting tells us that the hospital eventually removed the younger Grace Elliott's information from the other patient's account and from the collection agency's database. It tells us that the hospital said she had not been reported to credit agencies.

It does not give us a complete map of every system into which the incorrect association may have travelled.

Nor does the available evidence establish whether the measures taken after the incident prevented another similar error.

Those are not reasons to declare that correction failed completely. They are also not reasons to assume that correction was complete.

We don't know.

That uncertainty remains part of the record.

Read the original case: The Case of the Two Grace Elliotts — KFF Health News

The invisible error ↑

So far, somebody has been able to see the error.

The OpenNotes example showed that visibility matters. The Grace Elliott case showed that an acknowledged error can travel farther than its correction.

But there is another possibility.

What if the error exists, but nobody looking at any one record can see it?

Imagine that three parts of an institution retain records of the same event.

Record What it says
A The person declined the service.
B The service was unavailable.
C The service was provided.

There is nothing obviously defective about any one of those records. Each might be properly dated, attributed and stored. Each department might look at its own record and find nothing requiring correction.

The problem appears only when the records are brought together.

The error may not be visible within a record. It may become visible only in the contradiction between records.

Who can see the contradiction?

This complicates what OpenNotes taught us about visibility.

Giving a person access to one record may allow them to discover an error contained within that record. But access to one part of a system cannot reveal a contradiction that becomes apparent only when several parts are compared.

Department A may see only A. Department B may see only B. Department C may see only C.

Each may accurately report:

"That is what our record says."

And yet the system, considered as a whole, contains accounts that cannot all describe the same event in the same way.

This is where Contradiction detection becomes important.

Access to a record is not necessarily access to the error.

When only part of the contradiction can be resolved

Now we can make the hypothetical slightly more difficult.

Suppose an independent record is found: a contemporaneous appointment log. It establishes that, at the relevant time, the service was unavailable.

We now have four pieces of information:

Record What it says
A The person declined the service.
B The service was unavailable.
C The service was provided.
Independent evidence The contemporaneous appointment log records that the service was unavailable.

The new evidence does not tell us everything that happened.

But it does tell us something.

Record C can no longer stand as an accurate account of the event. If the service was unavailable, the statement that it was provided is contradicted by the contemporaneous evidence.

Record A also requires examination. If the service was unavailable, what does it mean to say that the person declined it? Perhaps another interaction occurred. Perhaps the entry was copied from somewhere else. Perhaps somebody selected the wrong classification. We do not yet know.

And that distinction matters.

We have enough evidence to correct one part of the record without having enough evidence to explain the whole contradiction.

Must everything be resolved before anything can be corrected?

A system could respond by saying:

"Because we cannot yet explain all three records, we cannot make a correction."

That would preserve uncertainty, but it would also preserve something already shown to be wrong.

At the other extreme, the system could decide that because the appointment log supports Record B, Record B must explain everything that happened. It could delete or overwrite the other accounts and close the matter.

That would produce consistency, but at the cost of evidence.

Neither response seems satisfactory.

There is another possibility.

The system could correct what has been established, preserve the contradictory material, and continue examining what remains unresolved.

Record C could therefore be marked as incorrect rather than allowed to continue operating as fact.

Record A could remain visible, but its status could change. Instead of being treated as an established account of what happened, it could be marked as requiring examination because it conflicts with the contemporaneous evidence.

Record B and the appointment log could remain available with their Provenance intact.

Nothing needs to disappear in order for something to be corrected.

Correction does not require us to pretend that uncertainty has ended.

Preserved uncertainty does not mean preserved error

This exposes an important distinction.

Preserving uncertainty cannot mean leaving information that has already been shown to be wrong operating as though it remains equally credible.

Nor should correction require uncertain information to be converted into certainty merely because the system wants a final answer.

A corrigible response may therefore need to hold different conclusions at the same time:

This is wrong.
This is supported by the available evidence.
This remains unresolved.

Those are not contradictory positions.

They are different descriptions of what the evidence presently allows us to say.

The history should remain

There is another reason not simply to replace the contradictory records with one clean account.

The contradiction itself has become evidence.

If Record C is silently changed from "the service was provided" to "the service was unavailable", a later reader may see a perfectly consistent record and never know that the contradiction existed.

We would have corrected the information while destroying evidence about the system that produced the error.

A more transparent correction would preserve the original entry, record that it has been found to be incorrect, identify the evidence supporting that conclusion, and prevent the incorrect entry from continuing to operate as current fact.

The history can remain without the error retaining authority.

Now test our own conclusion

We should not accept this solution merely because it sounds reasonable.

What could be wrong with it?

If every contradiction remains permanently attached to every record, the record itself could become confusing or unusable.

If an incorrect statement remains visible without its corrected status being equally visible, somebody may later repeat the original error.

If an unresolved statement is marked too strongly, uncertainty may quietly become another form of accusation.

And if only specialists can understand the correction history, transparency may exist technically while failing in practice.

So preservation alone is not enough.

A correction must preserve the history without allowing the superseded error to continue exercising the authority of current information.

Our test has moved again

We began Test One by asking whether a clear error could simply be corrected.

We have now reached something more demanding.

A corrigible system may need to distinguish between what is established, what is supported, what has been disproved, and what remains unresolved. It may need to correct one part of a record while continuing to investigate another.

That suggests another question for our developing test:

Can the system correct what the evidence establishes without either preserving a known error or manufacturing certainty about what remains unknown?

For the moment, we will leave that question visible.

The next increase in complexity may tell us whether our proposed solution survives.

A real test of partial correction ↑

We have proposed that a corrigible system should be capable of correcting what the evidence establishes without manufacturing certainty about what remains unresolved.

Now we can take that proposition outside our hypothetical.

In 2009, the Queensland Office of the Information Commissioner considered an application concerning amendments to a person's medical records.

The applicant had made ten requests for amendment, arguing that information in the records was inaccurate or misleading.

The outcome was not simply "correct the record" or "do not correct the record".

During the external review, Queensland Health agreed to amend information covered by three of the requests, or parts of those requests, using alteration and notation.

Some of the remaining matters were found not to be requests to amend information at all, but criticisms concerning aspects of the medical care and record-keeping.

For the remaining requests that did seek amendment, the Assistant Commissioner found that there was insufficient evidence to establish that the information was inaccurate, incomplete, out of date or misleading.

Source: Queensland Office of the Information Commissioner, KLE and Department of Health, Application 210565, 19 May 2009. View source

The outcome was divided by the evidence

This is useful to our test because the process did not require every part of the application to have the same outcome.

Some information could be amended.

Some matters were outside the particular amendment question being decided.

For some requested amendments, the available evidence did not establish the statutory basis required for further amendment.

The unresolved parts did not prevent correction of the parts for which amendment could be made.

That is very close to the possibility our hypothetical produced.

But we should be careful not to make the real case say more than it does.

The decision does not establish that every amended statement was proven "wrong" in precisely the sense used in our hypothetical. Queensland Health agreed during the review to alterations and notations affecting three requests or parts of them.

Nor does a refusal to make the remaining amendments establish that the original records were necessarily true.

For the remaining amendment requests considered under the relevant provision, the decision was that sufficient evidence had not been provided to establish that the information met the grounds required for amendment.

"Not established as wrong" is not necessarily the same conclusion as "established as correct."

Apply the same questions

Question from Test One What the available evidence establishes
Could the affected person identify information she disputed? Yes. Ten amendment requests concerning parts of her medical records were made.
Was there a pathway for challenging the information? Yes. The matter proceeded through an amendment process and external review by the Information Commissioner.
Could part of the matter be corrected without resolving all of it? Yes. Queensland Health agreed to alter or annotate information covered by three requests, or parts of those requests.
Did every disputed statement have to receive the same outcome? No. Different parts of the application produced different outcomes.
Did insufficient evidence automatically establish that the existing information was correct? No such conclusion is established by the published decision. For the relevant remaining requests, the finding was that sufficient evidence had not been provided to establish the grounds required for amendment.
Was the complete Error footprint examined? We don't know from this decision.
Did the corrections propagate to every place where the disputed information may have been used? We don't know from this decision.
Did the process establish whether similar record problems recurred? We don't know from this decision.

The test survives, but becomes more precise

This real case has not forced us to abandon the solution produced by our hypothetical.

It demonstrates that a correction process can produce different outcomes within the same matter. One part can be altered or annotated while another part remains unchanged.

But it has made our language more precise.

We had been working with three broad possibilities:

This is wrong.
This is supported by the evidence.
This remains unresolved.

The KLE decision exposes another distinction that a correction system may need to preserve:

Not enough evidence to justify correction does not necessarily mean enough evidence to establish the existing account as true.

That distinction matters because otherwise a failed attempt to prove an error could quietly strengthen the authority of the original record.

The record might begin as an assertion.

It is challenged.

The challenge cannot be sufficiently established.

And unless the system is careful, the result may later be understood as: "the original record was proved correct."

But that is not necessarily what happened.

Sometimes the most accurate conclusion available to a corrigible system is simply:

The evidence presently available does not justify changing this information.

That is a narrower conclusion.

And preserving that distinction prevents uncertainty from being converted into certainty merely by the passage of a correction process.

Source: Queensland Office of the Information Commissioner, KLE and Department of Health, Application 210565, 19 May 2009. View source

What does the next reader see? ↑

KLE exposed an important distinction:

Not established as wrong is not necessarily the same thing as established as correct.

But that creates another problem.

A correction process may preserve that distinction carefully while the matter is being examined. What happens later, when somebody who was not involved in the correction opens the record?

They may know nothing about the disagreement, the evidence considered, or the limits of the conclusion that was reached.

They see the record.

Can a record preserve disputed or superseded information without allowing a later reader to mistake its continued presence for continuing authority?

Hayward-Brown and the problem of the next reader

A 2000 decision of the New South Wales Administrative Decisions Tribunal gives us a real example in which this problem was considered.

Helen Hayward-Brown sought amendment of entries in her daughter's hospital file. She alleged that statements made by medical and nursing staff were incorrect and misleading.

The health service agreed to place a copy of her letter and its attachment adjacent to the relevant records, but it would not delete or change the original entries.

During the subsequent review, Hayward-Brown proposed another approach: particular words and sentences could be struck through while remaining readable.

Read the original decision: Hayward-Brown v Chief Executive Officer, Wentworth Area Health Service — [2000] NSWADT 46

Preservation created another question

The Tribunal considered the proposed striking-through of the disputed material.

The difficulty was not simply whether the original words would remain available. They would.

The difficulty was what their altered appearance would communicate to somebody reading the record later.

The health service argued that striking through the words could create confusion. A later reader might not know whether the information was wrong, partly wrong, or whether it should still be taken into account.

The Tribunal considered that striking through disputed passages without an explanation or annotation could add to the existing confusion or misunderstanding. It considered that the disputed words could instead be identified while explanatory material was retained with the record.

Preserving the history is not enough. The status of that history must also be intelligible to the next reader.

Now test our solution

Our hypothetical produced this proposition:

The history can remain without the error retaining authority.

Hayward-Brown makes us examine the second half of that proposition more carefully.

Keeping the original entry preserves the history.

But merely preserving it does not tell the next reader what authority that entry should have.

Striking through it may appear to solve the problem, but the Tribunal identified another possibility: the mark itself may be ambiguous.

A later reader may still need to know:

Was this information established as wrong?
Was only part of it wrong?
Is it disputed but unresolved?
Has it been superseded by later evidence?
Where can I see the reason for its present status?

This suggests that a correction needs to communicate more than its existence.

It needs to communicate its meaning.

Apply the same questions

Question from Test One What the available evidence establishes
Was the original information preserved? Yes. The agency's approach retained the original record rather than deleting or changing its text.
Could the affected person place a challenge with the record? Yes. The agency determined that her letter and attachment would be filed adjacent to the relevant records.
Was simply marking the disputed words considered sufficient? No. The Tribunal considered that striking through passages without adequate explanation or annotation could itself create confusion.
Did the process recognise the needs of a later reader? Yes. The Tribunal expressly considered the possibility that a reader might otherwise be uncertain about the status of the disputed information.
Does the decision establish that every later reader actually understood the resulting record correctly? We don't know from this decision.
Does it establish whether the disputed information influenced later decisions? We don't know from this decision.

The correction itself must be legible

Our earlier model concentrated on preserving the original information, preserving the evidence and recording the correction.

Hayward-Brown exposes another requirement.

A correction that exists but whose meaning cannot be understood by the next person using the record may not be an effective correction.

That gives us another question for Test One:

Can a later reader distinguish what remains current, what has been corrected, what is disputed, and what remains unresolved?

This is not merely a question of keeping an audit trail.

It is a question of whether the correction survives being read by somebody who was not present when the correction was made.

The history can remain.

But the history, the correction and the remaining uncertainty must not become indistinguishable from one another.

Read the original decision: Hayward-Brown v Wentworth Area Health Service — NSW Administrative Decisions Tribunal

When the correction travels but the error survives ↑

Hayward-Brown made us consider what the next reader sees.

A correction may exist, yet still fail if somebody encountering the record later cannot understand what has been corrected, what remains disputed, and what remains current.

So let us remove that problem.

Imagine that the correction could not reasonably be clearer.

Record element What the later reader sees
Original statement The person declined the service.
Status Corrected — established inaccurate.
Corrected information The service was unavailable.
Basis for correction Contemporaneous appointment record establishing that the service was unavailable.

The original statement remains visible because we decided earlier that correction should not require destruction of the historical record.

But its status is equally visible.

There is no need for the next reader to reconstruct the dispute. They can see what was originally recorded, what was subsequently established, and which information is now current.

Then something happens.

A later decision-maker prepares a new assessment.

They reproduce the original statement:

The person declined the service.

The correction travelled.

The evidence supporting it travelled.

The original error travelled too.

And the next part of the system selected the error.

Something different has failed

We cannot explain this failure by saying that the person was unable to see the record.

We cannot say that the error had never been challenged.

We cannot say that the correction remained in the originating department.

And we cannot say that the status of the original statement was ambiguous.

All of those things have been dealt with.

The correction was available, intelligible and supported by evidence, but the superseded information was nevertheless reused.

That exposes a weakness in the way we have been thinking about Correction propagation.

Until now, we have largely asked whether the correction travelled as far as the error.

Perhaps travelling is not enough.

What does it mean for a correction to propagate?

Suppose both the original error and its correction reach another part of the system.

Technically, the correction has propagated.

But if the receiving system continues to treat the superseded information as current, very little has actually been corrected.

We therefore need to distinguish between two questions:

Did the correction reach the place where the error travelled?

Did the correction retain its authority when the information was used again?

The first is about transmission.

The second is about use.

A system could succeed at the first and fail at the second.

A correction that travels but can be silently ignored may leave the original error operational.

Preserving history creates a responsibility

Earlier we decided that the original record should not simply disappear.

That still seems important. The original statement may be necessary to understand what happened, how the error arose, and why a correction was made.

But retaining superseded information creates a risk.

The system now contains both the historical error and the correction.

If later processes cannot reliably distinguish their status, or are free to reuse either one without accounting for that status, preservation itself can allow an old error to acquire a new life.

The history can remain without the error retaining authority — but only if the system preserves the distinction when the information is used again.

Our test has moved again

We can now add another question to Test One:

When corrected information is subsequently used, does the correction retain its status and authority?

This is different from asking whether somebody can find the correction.

It asks whether the system behaves differently because the correction exists.

That gives us a useful distinction to carry into the next real case:

A correction can be visible without being operational.

When old information keeps coming back ↑

Our hypothetical deliberately made the next failure obvious.

The correction existed. It was visible and intelligible. A later decision-maker could see it, yet the superseded information was used again.

That gave us a question:

When corrected information is subsequently used, does the correction retain its status and authority?

We then went looking for a real case that might test that proposition.

What we found did not quite behave in the way our hypothetical predicted.

A correction that did not take hold

In its 2022–23 Annual Report, the Office of the Australian Information Commissioner described a privacy complaint concerning personal information about a marriage that had ended more than a decade earlier.

The individual had attended the organisation's local branch and supplied the documentation required to update their personal information.

But the old information did not disappear from the organisation's continuing use of its records.

The OAIC reported that the historical and now incorrect information continued to populate the person's existing accounts and also appeared in records associated with new accounts.

Source: Office of the Australian Information Commissioner, Annual Report 2022–23, APP complaint resolved through conciliation. View source

The person then used the organisation's complaints and feedback processes. According to the OAIC account, there was an initial acknowledgement but no further response.

The complaint subsequently reached the OAIC and raised issues under Australian Privacy Principle 10, concerning the quality of personal information, and Australian Privacy Principle 13, concerning correction of personal information.

The matter was referred to conciliation.

As a result, the organisation apologised, undertook to correct the person's personal information in both current and historical records, and provided compensation.

It is not quite the failure we imagined

We need to preserve an important distinction.

The published account does not establish that a later employee saw a clearly marked correction and deliberately chose the superseded information instead.

It also does not tell us precisely what happened inside the organisation's information systems after the documentation was supplied.

We therefore cannot use this case as evidence for either proposition.

What the published account does establish is narrower, but still important.

The individual supplied the documentation required to update the information, yet historical and now incorrect information continued to populate existing accounts and appeared in records associated with new accounts.

The information required for correction entered the system, but the old information continued to reproduce itself within that system.

The case changes our test

Our hypothetical had encouraged us to think about correction as a sequence.

The error travels.

The correction follows it.

We then ask whether the correction has travelled far enough and whether later users respect it.

But this case exposes another possibility.

The relationship may not always be that simple.

Old information may remain capable of appearing in other records even after the information required to correct it has been supplied.

That means our earlier question:

Has the correction travelled at least as far as the error?

may not be sufficient.

We also need to ask:

Can some part of the system continue to reproduce the error after correction has begun?

Correction is not necessarily a single event

This changes something else in our developing model.

We began by imagining correction as an event:

An error is identified. Evidence establishes the correct information. The record is changed.

The cases we have examined are making that description increasingly inadequate.

If information exists in multiple records, accounts or processes, correcting one point in the system may not establish what happens everywhere else.

A correction may therefore need to be understood not simply as a change to a record, but as something whose effects must survive movement through the system.

That gives us three progressively stronger questions:

Does the correction exist?

Does the correction travel?

Does the correction govern subsequent use?

The OAIC case now adds another:

Can the system recreate or continue reproducing the superseded information?

We should be careful with the word recreate. The OAIC report does not tell us the technical mechanism by which the old information continued to populate the records.

But that uncertainty is itself part of our test.

We do not need to invent an explanation for a process we cannot see.

We can record what the evidence establishes, preserve what remains unknown, and allow the test to change accordingly.

A correction that exists somewhere in a system is not necessarily a correction that controls what the system subsequently produces.

And the burden returned to the person

There is another feature we have encountered before.

The person supplied the required documentation.

When the incorrect information continued appearing, the person then used the organisation's complaint and feedback processes.

When that did not resolve the matter, the complaint proceeded to an external regulator.

Only through the subsequent conciliation did the organisation undertake to correct the information in both current and historical records.

That returns us to a question raised earlier in this test:

Once an institution has been given the information required to correct an error, who should bear the burden of discovering where that error continues to operate?

We do not yet need to answer that question.

But we now have another real case showing why the question exists.

The test has been corrected again

We went looking for an example in which a correction was visible but later ignored.

Instead, reality gave us a different problem.

The information necessary for correction had been supplied, but the old information continued appearing across the organisation's records.

We could force that case into the question we had already constructed.

Or we could allow the case to change the question.

Each time the test encounters reality, reality may expose something the test has failed to see.

For a test of corrigibility, there can really be only one acceptable response to that.

The test must remain corrigible too.

Read the original case: Office of the Australian Information Commissioner, Annual Report 2022–23, APP complaint resolved through conciliation. OAIC Annual Report 2022–23

The easy correction is becoming difficult ↑

We began with an error deliberately chosen because there seemed to be almost nothing difficult about it.

The evidence was clear. The correct information was available. There was no apparent conflict of interest and no obvious reason for anybody to preserve the mistake.

Yet the difficulty of establishing an error and the difficulty of correcting its effects have turned out to be different things.

Once incorrect information enters a system, correction may require us to consider where it travelled, what relied upon it, what consequences followed, whether contradictory records exist, what remains uncertain, what later readers understand, and whether superseded information can become operational again.

Complexity may not be an exceptional condition of correction. Once an error begins interacting with other records, people and decisions, complexity may be the ordinary condition.

That does not make correction impossible.

It changes what we should expect a system capable of correction to be able to do.

Two different kinds of difficulty

This also gives us a distinction that was not visible when we began.

An error can be easy to establish and difficult to correct.

The question:

Is this information wrong?

may have a clear answer.

But the question:

What would have to happen for this error to be reasonably regarded as corrected?

may require a much larger investigation.

The difficulty of establishing an error and the difficulty of correcting its effects are separate variables.

What the easy case has already required us to see

Our original hypothetical began with a wrong date of birth and a correct document.

Since then, the test has required us to consider:

  • whether the person can see enough of the system to discover the error;
  • whether the error has travelled into other records or decisions;
  • whether its consequences have been identified and remedied;
  • whether contradictory records reveal an error invisible within any one record;
  • whether part of a contradiction can be corrected while another part remains unresolved;
  • whether uncertainty can be preserved without preserving a known error;
  • whether failure to establish that something is wrong is mistakenly converted into proof that it is correct;
  • whether the status of corrected or disputed information remains intelligible to the next reader;
  • whether a correction that travels actually governs subsequent use of the information; and
  • whether superseded information can reappear after corrective information has entered the system.

None of those questions required us to introduce genuine disagreement about what happened.

None required us to establish a recurring institutional pattern.

And none required us to introduce an institution with a substantial interest in resisting correction.

And we are still examining the easy case.

The correction that doesn't last ↑

There is another condition we have not yet changed.

Time.

Suppose the institution does everything our developing test has so far asked of it.

An inaccurate statement is identified. The evidence is examined. The institution accepts that the information is wrong.

The source record is corrected.

The correction is clearly marked. Known downstream records are updated. The person affected is told what has been done.

If we examined the matter at that moment, we might reasonably conclude that the correction had succeeded.

Then three years pass.

An archived record, an older copy of the information, or another part of the institution's information system becomes the source for a new decision.

The superseded information appears again.

Nobody has necessarily decided to reverse the correction.

Nobody has necessarily seen the corrected information and deliberately ignored it.

The old information has simply become operational again.

The correction was real, but it was temporary.

Was it successfully corrected?

This presents our developing test with another problem.

If we had examined the system immediately after the correction, it might have passed.

If we examine exactly the same correction three years later, it may fail.

Nothing about the evidence establishing the original error has changed.

What has changed is our ability to see whether the correction survived.

That suggests that successful correction cannot be measured only at the moment when the record is changed.

Correction at a moment in time is not necessarily durable correction.

A real test of correction half-life ↑

Our hypothetical asked what happens when an error is corrected, appears to have been resolved, and then becomes operational again later.

A decision of the Housing Ombudsman concerning Bristol City Council gives us a remarkably direct real-world test.

The bath that wasn't there

The resident lived in a property with a wet room.

In October 2020, Bristol City Council stated in a formal complaint response that a bath had been fitted at the property.

It had not.

The resident pointed out the error on the same day.

Several days later, the council apologised for having misunderstood the situation and explained what had occurred.

The council subsequently repeated its apology and explanation.

At this point, the error had been identified.

The institution knew that its earlier statement was wrong.

The person affected had challenged it.

The institution had acknowledged the mistake and apologised.

If we had examined the correction at that moment, we might reasonably have concluded that this part of the matter had been resolved.

Source: Housing Ombudsman, Bristol City Council (202101013), decision dated 16 December 2021. View source

Then the error returned

Several months later, during further communications concerning works at the property, the council again referred to its records as showing that the resident had a bath installed.

The resident had to correct the council again.

This was not simply the resident's interpretation of what had happened.

In its assessment, the Housing Ombudsman specifically considered the recurrence.

The Ombudsman found that despite the council having already identified that its records concerning the bath were incorrect, its later communications again stated that the resident had a bath at the property.

The institution had discovered the error, acknowledged the error and apologised for the error — yet the error remained capable of becoming institutional information again.

The original correction was not imaginary

We need to be careful about what conclusion we draw from this.

The council's earlier acknowledgement and apology were real.

We do not need to pretend that no correction occurred simply because the incorrect information subsequently returned.

Instead, the later evidence tells us something that could not have been known from the earlier correction alone.

A correction can be genuine when it is made and still prove temporary when tested by subsequent use.

That gives practical meaning to Correction half-life.

We are no longer asking only whether a correction happened.

We are asking whether it persisted.

Who remembered the correction?

There is another feature of this case that matters.

When the incorrect information appeared again, it was the resident who had to identify and correct it again.

The institution had already been told.

The institution had already acknowledged the mistake.

Yet when its own information failed to preserve that correction, the burden of detecting the recurrence returned to the person affected.

When a correction fails to persist, the burden of institutional memory can be transferred back to the person affected.

The person then becomes, in effect, an external correction mechanism for the institution:

We have already dealt with this. Your information is wrong again.

That raises another question for our developing test:

After an institution accepts an error, should the person affected have to continue detecting the same error each time the institution uses the information again?

The next use becomes a test

This case also helps us answer the question we asked in our hypothetical:

How would we know whether a correction survived?

One answer is becoming visible.

The next use of the information is itself a test.

If the corrected information governs what happens next, the correction has demonstrated some persistence.

If the superseded information becomes operational again, we have evidence that the earlier correction did not persist sufficiently through the system.

That means verification need not occur only when the correction is made.

A correction can also be verified by observing what the institution does the next time it uses the information.

A correction may need more than acknowledgement

The Housing Ombudsman also emphasised the importance of accurate and detailed record keeping.

That matters to our test.

An apology can acknowledge an error.

An explanation can describe what went wrong.

Neither necessarily changes the information that another part of the institution will encounter later.

The Bristol case therefore gives us another distinction:

Acknowledgement tells us the institution recognised the error.

Persistence tells us whether the correction survived institutional use.

Those are not the same measure.

The test changes again

Our developing test can no longer stop with:

Was the error corrected?

We also need to ask:

When the institution next used the information, did the correction remain effective?

And where repeated use matters:

Does the correction continue to remain effective over time?

That gives Correction half-life something we may eventually be able to observe rather than merely describe.

Successful correction may therefore be partly longitudinal: some of its properties can only be demonstrated by what happens afterwards.

Read the original case: Housing Ombudsman, Bristol City Council (202101013). Housing Ombudsman decision

Correction half-life

We already have a concept capable of helping us examine this: Correction half-life.

Until now it has been largely theoretical.

This hypothetical gives it something practical to measure.

How long does a correction retain its authority before an earlier version, an old process, a copied record or some other part of the system allows the superseded information to become operational again?

A correction with a short half-life may look successful when measured immediately and unsuccessful when measured later.

That means the timing of our measurement matters.

The correction exists.

The correction travels.

The correction governs subsequent use.

The correction survives over time.

Our test has acquired another condition.

Correction persistence is not yet system learning

There is another distinction we need to preserve.

Suppose this particular correction survives perfectly.

The corrected information remains authoritative. The old information never becomes operational again.

That tells us something important about the persistence of this correction.

It does not necessarily tell us whether the institution learned anything that will change what happens in the next similar case.

Those are different questions.

The first asks:

Did this correction survive?

The second asks:

Did the institution retain what it learned sufficiently to change what happens next time?

That takes us toward Learning persistence.

But we should not move there yet.

For the moment, we are still testing the correction itself.

A temporary fix

This also changes how we should interpret our earlier idea of closure.

There may have been nothing unreasonable about declaring the original correction complete on the evidence available at the time.

The later reappearance of the error does not necessarily prove that the original decision to close the matter was unreasonable.

It does establish something that could not yet have been observed.

What appeared to be a completed correction has proven itself to have been a temporary fix.

That is an important distinction.

We do not need to rewrite the past and pretend that everybody should have known what would happen three years later.

We can instead allow later evidence to change our assessment of how effective the correction proved to be.

That is another form of corrigibility.

A system should be capable not only of correcting its information, but of revising its assessment of whether an earlier correction actually worked.

A new question for the test

We therefore need to add another question:

Does the correction remain effective when the information is used again over time?

And perhaps, eventually, an even more demanding one:

How would we know?

That question matters because a correction that is never examined again may appear permanent simply because nobody has looked to see whether it survived.

We began Test One by asking what successful correction looks like.

We are now discovering that the answer may not be visible at the moment the correction is made.

Some properties of a successful correction can only be demonstrated by what happens afterwards.