PRACTICAL
INNOVATIONS
← All articles
January 12, 2026 · 14 min read

Actionable Intelligence: What Health Tech Can Learn from Spycraft

In my last post, Why Health Technology Adoption Is So Complex I talk about "actionable intelligence at the moment it matters."

As I thought about it, this statement captures something essential about what health technology should deliver and so often fails to. The intelligence community has spent decades refining the art of transforming raw data into decisions. Health technology would do well to study its tradecraft.

The Intelligence Problem

Intelligence agencies face a challenge that will sound familiar to anyone in health technology: they are drowning in data. Satellites photograph every inch of the earth. Signals intelligence captures billions of communications. Human sources report observations from countless locations. The problem is usually not a lack of information. The problem is transforming that information into something a decision-maker can act upon before the moment for action passes.

This is precisely the problem facing a clinician monitoring thirty patients through a remote therapeutic monitoring program. It is the problem facing a family caregiver trying to keep tabs on an aging parent from three states away. It is the problem facing a hospital administrator trying to understand which quality initiatives are working and which are not.

Health technology has largely responded to this challenge by providing more data. More metrics. More dashboards. More alerts. This approach mirrors the early failures of the intelligence community, which learned through painful experience that more information does not equal better decisions. Often, it leads to information saturation that drowns out the relevant signals needed for sound judgment.

From Data to Intelligence: The Hierarchy of Understanding

There is a critical distinction between data, information, and intelligence. The intelligence community distinguishes between several levels of processed information, a hierarchy that health technology would benefit from adopting.

Data is raw, unprocessed observation. A sensor reading. A timestamp. A location coordinate. In health technology, this might be a single gait speed measurement, a blood pressure reading, or a record that a medication bottle was opened.

Information is data that has been organized and given context. The sensor reading is from a specific patient. The timestamp indicates morning versus evening. The location is the patient's home versus a clinical setting. Information answers basic questions: who, what, when, where.

Intelligence is information that has been analyzed, interpreted, and assessed for significance. This patient's gait speed has declined 15% over two weeks, which historically correlates with increased fall risk. This blood pressure pattern suggests medication non-adherence. This location data indicates reduced community mobility. Intelligence answers the question: what does this mean?

Actionable Intelligence is intelligence delivered to the right person, at the right time, in the right format, with sufficient context to enable a decision. The clinician receives an alert that this specific patient needs a fall risk reassessment, along with the three data points that triggered the alert and two evidence-based intervention options. The family caregiver sees a simple visual indicating Mom's mobility has changed enough to warrant a conversation with her doctor.

Most health technology stops at information. The better systems reach intelligence. Very few achieve actionable intelligence consistently.

The Daily Brief Model

Every morning, the President of the United States receives the President's Daily Brief (PDB), a document that represents the intelligence community's best effort to distill the entire world's complexity into what one person needs to know to make decisions that day. The PDB is not a data dump. It is not a comprehensive summary of all available information. It is a ruthlessly curated selection of what matters most, presented in a format designed for rapid comprehension and decision-making.

Health technology should aspire to create the clinical equivalent of the PDB. What does this clinician need to know about their patient panel this morning? Not everything that happened. Not every data point collected. Just the actionable intelligence that should shape today's decisions.

This requires a fundamental shift in design philosophy. Instead of asking "what data can we display?" designers must ask "what decisions does this user need to make, and what is the minimum information required to make them well?"

A clinician starting their day does not need to see that 847 gait measurements were collected from their RTM patients overnight. They need to see that three patients crossed clinical thresholds warranting intervention, ranked by urgency, with the specific threshold crossed and recommended next steps for each.

Indications and Warning: The Art of Early Detection

One of the intelligence community's core functions is Indications and Warning, the systematic monitoring for signs that something significant is about to happen. The goal is not to report events after they occur but to detect the precursors that enable preventive or preemptive action.

This concept translates directly to health technology. The value of monitoring is not in documenting that a fall occurred. It is in detecting the changes that precede falls, enabling intervention before the event. The value is not in recording that a patient was hospitalized. It is in identifying the trajectory toward hospitalization early enough to alter course.

Effective Indications and Warning requires three elements that health technology often lacks:

Defined indicators. The intelligence community maintains detailed lists of specific observable events that would signal an impending threat. Health technology needs equivalent rigor in defining what patterns, thresholds, and trends constitute clinically meaningful warning signs versus normal variation.

Baseline understanding. You cannot detect deviation without knowing what normal looks like. Intelligence analysts study adversaries for years to understand their patterns. Health technology must establish individual baselines for each patient, recognizing that population norms may not apply to specific individuals.

Synthesis across sources. A single data point rarely triggers an alert. It is the combination of multiple indicators that creates confidence. Health technology should fuse data from multiple sources and modalities rather than treating each metric in isolation.

The Problem of False Alarms and Alarm Fatigue

Intelligence failures come in two varieties: failing to warn when a threat exists, and warning when no threat exists. The intelligence community has learned that false alarms are not merely annoying but actively dangerous. Each false alarm degrades trust in the warning system. After enough false alarms, decision-makers begin to ignore warnings altogether.

Health technology struggles mightily with this balance, and the consequences have a clinical name: alarm fatigue. The phenomenon is so pervasive and dangerous that The Joint Commission has identified it as a national patient safety concern. Notably, alarm fatigue is also a significant problem in aviation, where similar dynamics have led to critical safety protocols.

Consider the reality facing a nurse on a medical-surgical unit. Cardiac monitors alarm. Infusion pumps alarm. Bed exit sensors alarm. Ventilators alarm. Pulse oximeters alarm. Studies suggest that clinicians in acute care settings may encounter hundreds of alarms per patient per day, with false alarm rates exceeding 80-90% in some environments. The human response to this onslaught is predictable and rational: clinicians begin to ignore, silence, or delay response to alarms. They have to. Cognitive bandwidth is finite. Attention is a depletable resource.

The tragedy is that buried within this cacophony are the genuine warnings, the alarms that signal actual deterioration requiring immediate intervention. When everything screams for attention, nothing receives it. Patients have died because critical alarms were missed among the noise. The technology designed to enhance safety became a threat to it.

The intelligence community faced an analogous crisis. During the Cold War, early warning systems were calibrated so sensitively that they generated frequent false alarms about incoming nuclear missiles. Each false alarm required massive response mobilization and created enormous stress. More dangerously, each false alarm made decision-makers slightly more likely to dismiss the next warning as another false positive. The same psychology that leads a nurse to silence a monitor operates across high-stakes decision environments.

The intelligence community's response offers guidance. Rather than binary alerts (threat/no threat), sophisticated systems use what is called a confidence assessment, which is a combination of the reliability of the data source and how many assumptions you need to make to understand the problem. An assessment might indicate "moderate confidence of increased fall risk based on gait speed decline, low confidence based on single data source." This allows decision-makers to calibrate their response to the strength of the evidence.

Health technology alerts should similarly convey not just the conclusion but the confidence behind it. "High confidence alert: Patient crossed fall risk threshold based on converging gait speed decline, reduced activity, and increased gait variability" warrants different attention than "Low confidence flag: Single gait speed reading below threshold, possibly due to measurement artifact."

But confidence levels alone are insufficient. The deeper lesson from both intelligence and clinical settings is that alert systems must be designed with alarm fatigue as a primary consideration, not an afterthought. This means:

Aggressive threshold tuning. Default thresholds are rarely appropriate for specific contexts. Systems must allow customization based on patient population, clinical setting, and individual patient baselines.

Tiered escalation. Not every deviation requires immediate human attention. Lower-level anomalies can be logged for trend analysis without generating real-time alerts. Only convergent evidence or severe single-point deviations should interrupt clinical workflow.

Intelligent suppression. If a patient's monitor has alarmed twelve times in the past hour for the same parameter, the thirteenth alarm adds no information. Smart systems should consolidate redundant alerts and escalate only when patterns suggest genuine change.

Alarm accountability. Every alert generated should be tracked for outcome. Did it lead to intervention? Was the intervention necessary? This data should feed back into threshold adjustment and algorithm refinement.

The goal is not to eliminate alerts but to restore their meaning. When an alert sounds, it should reliably indicate something that requires human judgment and potential action. The intelligence community calls this maintaining "warning credibility." Health technology must pursue the same standard. An alert system that cries wolf eventually protects no one.

The Dissemination Problem

The intelligence community learned long ago that generating excellent analysis means nothing if that analysis does not reach the right people in usable form. The 9/11 Commission documented how critical intelligence existed within the system but failed to reach decision-makers who could have acted on it. The failure was not in the collection or analysis but in the dissemination.

Health technology faces similar dissemination challenges. Who should receive this alert? How should it be formatted for different recipients? What communication channel will actually reach them? How do we confirm receipt and understanding?

Consider the stakeholders around a single patient enrolled in remote monitoring: the patient themselves, a family caregiver, a physical therapist, a primary care physician, a specialist, and a care coordinator. Each needs different information at different times in different formats through different channels. The physical therapist needs clinical detail. The family caregiver needs plain language reassurance or concern. The patient needs motivation and guidance. The physician needs a summary that integrates with their workflow.

Effective intelligence dissemination matches the product to the consumer. Health technology must do the same, which requires understanding not just what information exists but who needs it, when, and how.

The Feedback Loop

Intelligence is not a one-way transmission from collector to analyst to decision-maker. Effective intelligence operations include feedback loops where decision-makers communicate what was useful, what was missing, what was unclear, and what decisions they made. This feedback shapes future collection priorities and analytical focus.

Health technology systems rarely incorporate meaningful feedback mechanisms. Did the clinician find this alert useful? Did it change their clinical decision? Was the recommended intervention appropriate? Without this feedback, the system cannot learn and improve. Without knowing which alerts led to meaningful interventions, there is no way to refine the algorithms that generate them.

Building feedback loops into health technology requires humility. It means acknowledging that the initial system design will be imperfect and committing to iterative improvement based on real-world performance. It means treating clinicians and patients not as passive consumers of the technology's outputs but as active participants in refining its intelligence.

Human Intelligence Still Matters

The intelligence community categorizes sources by types such as signals intelligence (SIGINT), imagery intelligence (IMINT), and human intelligence (HUMINT). Despite massive advances in technical collection, human intelligence remains irreplaceable. Satellites can photograph a building but cannot hear or observe what is discussed inside it. Signals intercepts can capture communications but may miss context that changes their meaning.

Health technology has increasingly emphasized sensor data and algorithmic analysis while undervaluing human input. But the richest source of intelligence about a patient's condition often remains the patient themselves, along with family members and clinicians who know them.

A sophisticated gait analysis system might detect subtle changes in walking patterns. But a five-minute conversation might reveal that the patient started a new medication, had a poor night's sleep, or is anxious about an upcoming procedure. Without this human intelligence, the sensor data may be misinterpreted.

Effective health technology integrates technical and human intelligence rather than treating them as separate channels. The system that combines sensor data with patient-reported symptoms and clinician observations will generate better actionable intelligence than any single-source system.

Classification and Need to Know

The intelligence community operates on the principle of "need to know." Not everyone with a security clearance receives all classified information. Access is limited to those who need specific information to perform their duties.

Health technology faces a parallel challenge in determining who should see what. Privacy regulations provide a legal framework, but the design question is subtler. What information does each stakeholder actually need? Providing too little leaves them unable to make good decisions. Providing too much creates noise that obscures signal.

The family caregiver monitoring their mother remotely does not need access to raw accelerometer data. They need to know: Is Mom okay? Has something changed that requires attention? The physical therapist treating that same patient needs more detail, but still not raw data. They need processed intelligence: How is the patient progressing toward functional goals? Where are they struggling? What adjustments might help?

Designing for appropriate "need to know" requires understanding each user's role, decisions, and information requirements. It means resisting the temptation to provide "full transparency" by showing everyone everything, which paradoxically reduces understanding by overwhelming users with information they cannot process.

Intelligent Thresholds and SBAR-Style Analysis

When a health technology system detects a pattern suggesting potential harm, the system's response architecture matters enormously. The goal should not simply be to trigger an alarm but to provide structured, actionable communication that enables rapid clinical decision-making.

Consider adopting a framework similar to SBAR (Situation, Background, Assessment, Recommendation), the communication protocol used in healthcare to ensure critical information is conveyed clearly and completely. An intelligent dashboard might present: the immediate situation (gait speed declined 18% over 72 hours), relevant background (patient history of falls, current medications, recent changes), clinical assessment (converging indicators suggest elevated fall risk), and recommended next steps (consider physical therapy reassessment, medication review, environmental safety check).

This structured approach transforms raw alerts into clinically useful intelligence. Rather than simply flagging that a threshold was crossed, the system provides the context and options that enable a clinician to act decisively. The technology becomes a partner in clinical reasoning rather than merely a source of interruptions.

Effective threshold design also means building tiered escalation. A mild deviation might be logged for trend analysis without generating a real-time alert. A moderate deviation might trigger a low-priority notification for review at the clinician's convenience. Only significant, converging indicators should interrupt clinical workflow with an urgent alert demanding immediate attention.

Conclusion: From Surveillance to Intelligence

Health technology has excelled at surveillance. We can monitor patients with unprecedented granularity, collecting data points that were unimaginable a generation ago. But surveillance is not intelligence. Data is not insight. Monitoring is not understanding.

The intelligence community learned through decades of experience that the value of their enterprise lies not in collection but in the transformation of collected data into actionable intelligence delivered to decision-makers in time to shape outcomes. Health technology is still learning this lesson.

The path forward requires adopting an intelligence mindset: ruthless focus on what decisions users need to make, what information those decisions require, and how to deliver that information in usable form at the moment it matters. It means accepting that more data is not better, that false alarms have real costs, and that the goal is not comprehensive awareness but targeted understanding that enables action.

When health technology achieves this transformation, it will stop feeling like surveillance and start feeling like having a brilliant analyst working around the clock on your behalf, someone who watches everything so you do not have to, and tells you exactly what you need to know exactly when you need to know it.

Actionable intelligence at the moment it matters. That is the standard. Everything else is just noise.

Start a conversation

Keep reading

September 15, 2026

Technology Is a Substrate

September 8, 2026

The Perfect Mentor Does 3 Jobs: Coach, Consultant, and Connect

August 23, 2026

The Quiet Negotiation: Safety, Independence, and Compassion