CLINICAL HANDOFF PLATFORM
NurseShift drafts the end-of-shift handoff from notes nurses already logged during care, so a shift change starts from something written, and the nurse’s job becomes correcting it, then confirming it under their own account.
TEAM
TIMELINE
TOOLS
Figma · ClickUp
RESEARCH
Secondary: literature + competitive benchmark
STATUS
Self-initiated, not deployed, no patient data
THE CHALLENGE
The fastest handoff is the one that leaves things out.
A handoff has to be fast enough to finish at the end of a shift and complete enough that nothing goes unsaid. Drafting it automatically resolves that and creates a harder problem: a nurse becomes accountable for a summary they didn’t write.
THE SOLUTION
Stop asking nurses to write the summary.
Assemble the draft from the notes, vitals and medications already captured and structure it into five sections. The receiving nurse confirms receipt, tying each received handoff to their name and a time.
roles
×
features
Every role checked against every feature. The blank cells decided what each interface contains.
platforms
×
capabilities
Epic, Cerner, MEDITECH, Vocera, TigerConnect, PerfectServe.
The handoff is the one moment when a patient has no nurse.
For twelve hours a nurse holds a running model of four to six patients: who’s deteriorating, which medication got held and why. At shift change that model has to move into another person’s head, out loud, in a few minutes. The Joint Commission estimates that 80% of serious medical errors involve miscommunication between caregivers when a patient is handed over (Joint Commission Perspectives, 2012).
Everything about the patient is already in the EHR, spread across notes, flowsheets and orders, in nothing like the shape of a handoff, so the outgoing nurse rebuilds from memory a summary the record could have produced.
What shift change actually looks like.
The product had to fit a ritual that already exists.
Historically at the nurses’ station. Increasingly at the bedside: both nurses walk into the room, give the report in front of the patient, and check lines, drains, pumps and skin. The patient can correct it. Three to five minutes a patient, twenty to forty in all, interrupted throughout.
That’s where Bedside Mode comes from. A note marked private, hide during bedside report only makes sense once you know the report happens in front of the family.
The benchmark split cleanly, and that split is what the product is built on.
I benchmarked six incumbent platforms across ten capabilities, three EHRs and three clinical communication tools. None of the six assembles the narrative from what’s already charted, so the outgoing nurse rebuilds it by hand at the end of every shift.
Epic has a handoff tool. The nurse still writes the part that matters.
Epic and Cerner, now Oracle Health, both ship a handoff activity. The structured half fills itself in: vitals, meds, allergies, lines. The assessment is a free-text box, and that box carries forward from one shift to the next. Nobody retypes the background every twelve hours, so old text stays in and the reader can’t tell what’s current.
Every line in NurseShift carries where it came from and when.
82%
of text in inpatient progress notes was copied or template-generated.
Wang et al., 2017
>50%
of progress-note text came from earlier notes.
Wrenn et al.
42%
of inpatient notes at one health system used copy-paste.
Geisinger, 2020 data
Figures as reported in ‘A Practical Approach for Monitoring the Use of Copy-Paste in Clinical Notes’, PMC8861699.
Epic fills the structured half. I went after the narrative half, assembled from what the nurse already charted, and then designed around the risk that creates.
Nurses want less to do at the end of a shift. Leadership wants more recorded about it.
How might we help nurses deliver complete, prioritized handoffs without adding documentation burden, while giving leadership the data they need to improve safety?
The loop the product has to fit inside
Figure 1. From a note logged at the bedside to a receipt from the incoming nurse. The two filled points on the loop carry a name.
Make the draft the starting point, and make the uncertainty visible.
An assembled draft creates a new risk. A nurse who trusts it stops reading it, and a confidently wrong summary is more dangerous than none. The draft is designed so the nurse has to check it.
Anything the assembly couldn’t determine gets listed as a low-confidence item above the summary, and it carries into the edit screen as a checklist the nurse clears before confirming.
What I rejected
Figure 2. The read view of an assembled draft, opened from a demo patient’s Handoff tab.
Figure 3. The note a nurse writes during care, with the four tags that route it. “Private (hide during bedside report)” keeps the note in the record and off the screen.
I wrote the prompt as a set of refusals.
The model invents nothing that isn’t clearly in the input, and it gives no “clinical advice, diagnoses, or treatment recommendations.”
Constructed from the prompt’s rules to show the three behaviors. The lines are illustrative and no model output was logged.
Five roles, and a receptionist who can admit a patient without reading a note.
A ward runs on five roles that need almost nothing in common. I mapped all five against the thirteen features, then designed from what each role has no reason to see.
A shift role, and tomorrow they may be back at the bedside. An experienced nurse runs the unit for the day: assigns patients, balances acuity, covers breaks, takes the first escalation.
The only ward-level view that exists in real time: a bedside nurse sees six rooms, the charge nurse sees forty.
Severity override, because acuity is comparative. The Unit Board, and sight of every handoff, so an unclaimed transfer gets noticed.
The unit secretary. Phones, admission and discharge paperwork, visitors, transport, supplies. Constant work, all of it outside the chart.
The role that proves the model. Everyone agrees a nurse should see the chart. The question is what happens to someone with business on the unit and none in the chart.
Two sidebar items and an admission form.
Four to six patients for twelve hours, and the handoff at the end. Gets My Shift, the assembled draft and the three handoff actions.
Runs the unit in months: hiring, the schedule, budget, survey readiness. Gets analytics and can’t open a nursing note.
Creates users, assigns roles, sets up units and shifts. Gets the admin panel and the audit log, with no route to a note or a handoff.
Take the receptionist. They have no clinical reason to read a nursing note, so they can’t, and the data layer enforces that.
The hollow cells are the features that role can’t reach.
The principle behind the matrix is HIPAA’s minimum necessary standard: access to protected health information limited to what the job needs. Role design here is a compliance obligation as much as a design choice.
The matrix produced two decisions the screens wouldn’t have. Charge nurses can override a patient’s severity level, because they see the ward and the bedside nurse sees six rooms. Every override and every role change is recorded against the person who made it: sixteen action types, each against a named actor.
Figure 5. A receptionist’s entire application: two sidebar items and an admission form.
Figure 6. The other end of the same model: rows from the unit board (demo data), with severity overrides and a Needs Support toggle per row.
Status a nurse can read in a corridor, and without color.
Severity drives triage on the unit board, and color alone can’t carry it. Color-vision deficiency is common, and a phone gets read at arm’s length in a corridor.
So each of the three levels carries a color, a word and a distinct shape: stable is a check, watch closely is an eye, high risk is a triangle. Any one channel is enough. The high-risk badge is the only element with continuous motion, so it’s findable in a scan.
One screen, three fidelities.
The handoff review screen as a sketch, a wireframe and the working build.
A working build, and no ward to put it in.
The three of us took it to a working application. The five roles, the draft-and-confirm handoff and the severity system are all built and running, and the permission boundaries sit in the data layer.
It has never run on a real ward, so I have no outcome numbers and I’m not going to estimate any. Software that mediates handoffs needs clinical governance and an IRB first.
What I’d measure, given a unit
Shift end → handoff complete
No data yet
Reviewing has to beat writing, measured against the current shift-end time.
Edit rate on assembled drafts
No data yet
A draft nobody edits means the assembly is excellent or nobody read it.
Unconfirmed transfers per shift
No data yet
The failure mode the design makes visible.
What I’d redo.
I designed a safety-critical product from reading and benchmarking. The permission matrix and the five-section structure hold up on paper. Starting again I’d spend two weeks in a break room with nurses before drawing a screen. Reading can’t answer what I most want to know: whether a nurse trusts a draft enough to correct it, or just confirms it.
The other thing I’d change is scope. Five roles and thirteen features was the right map and far too much to build first.
Project takeaways.
Anchal Nagdev














