In a hospital, some defects cost money and some put patients at risk. These five turn up again and again on provider projects — and each one has a test that would have caught it.
1. The same patient, two records
A patient is registered twice with a small difference in name or date of birth, and now has two MRNs. Their history is split across two charts; a clinician may miss an allergy or a previous result.
Test: duplicate-search rules at registration (spelling variants, swapped day and month, missing fields), the merge process, unmerge, and what happens to orders, results and charges linked to each record.
2. A result on the wrong patient
A mapping change on an HL7 result (ORU) interface puts the wrong identifier in the patient field. Lab results start attaching to the wrong chart — a patient-safety event, not just a bug.
Test: interface regression with realistic messages after every mapping change, reconciliation of messages sent versus filed, and order-to-result traceability so every result matches an open order.
3. Care delivered, never billed
A new service, drug or supply is added to clinical workflows but not mapped to a charge. Nothing fails, nobody complains — the hospital simply never bills for it.
Test: charge capture for every orderable and service type, late charges after discharge, and a daily report comparing services documented with charges created.
4. Denials that start at the front desk
Registration captures the wrong member id, misses a plan change or doesn't flag a required referral. The claim denies weeks later, and the rework costs more than doing it right first time.
Test: eligibility (270/271) with inactive coverage, a subscriber who is not the patient, secondary insurance and a plan change — each followed through to the 837 and the 835.
5. Real patient data in a test environment
A production copy is restored into QA to "get realistic data", and protected health information is now visible to everyone with test access.
Test: automated masking for every refresh, a check that masking actually happened, role-based access tests (who can see what), and audit logs that show who opened which record.
The common thread
Most of these never show up on the screen you are testing. They live in interfaces, mappings, batch jobs and reconciliations. Trace one real encounter end to end, reconcile counts at every handoff, and treat anything that touches patient identity as safety-critical.