The Swiss Cheese Model of Goal-Concordant Care

October 1, 2026

 

Clinical perspective

The Swiss cheese model of goal-concordant care

Why we tore down Koda’s own tech stack and rebuilt it to be AI-native.

Dr. Desh Mohan, Chief Medical Officer of Koda Health

I still remember a patient from early in my hospitalist career: end-stage COPD, admitted for the fourth time in six months, intubated in the ICU before anyone asked her what she actually wanted. Her daughter found a POLST in a kitchen drawer two days later. It said comfort-focused care only. Nobody in the hospital had seen it. Nobody had asked.

That case is one of the reasons I believe in advance care planning. Done well, it is one of the few interventions in medicine that gives people back control at the exact moment they’re most likely to lose it. When it works, a family isn’t guessing in a waiting room at 2 a.m. A physician isn’t defaulting to the most aggressive option because it’s the only one nobody has to justify. A patient’s own voice, captured while they still had one, is the thing making the decision instead of panic or protocol.

01

The economic case

This isn’t just a moral case. It’s an economic one, and the scale is easy to underestimate. Beneficiaries in their last year of life account for roughly a quarter of all Medicare spending, a share that has held steady for decades. That is one of the largest concentrations of dollars anywhere in the health care system, spent during the phase of care where a mismatch between what’s delivered and what a patient actually wanted is most likely and most costly.

And where ACP is done well, the numbers move. When Aledade ran a comprehensive ACP program through Iris Healthcare across practices in its ACO network, the results held up at the ACO level. Overall, the treatment led to a $994 per-member per-month lower cost compared with the control group. With a mean time receiving the service of 14 months, this meant a total of $13,916 in reduced costs per patient. A separate three-year, case-control study of an ACP program in a Medicare population found overall costs $9,500 lower per participant who went through the program, netting out to roughly a 2x return once program costs were included.

~25%Of Medicare spending in the last year of life
$994Savings per member per month
$9,500Lower cost per ACP participant

This is not a rounding error. It’s real money, moving in the direction patients actually asked for, in the single most expensive phase of the entire system.

So I want to be careful with what I say next, because it’s easy to hear it as an argument against ACP itself. It isn’t. It’s an argument about why so much of ACP, as currently built, doesn’t hold up, and it’s the reason we spent the better part of the past year tearing down Koda’s own product and rebuilding it from the ground up.

Not a redesign. Not a new feature. A rebuild of the tech stack itself, into something AI-native, because we came to believe the old architecture couldn’t do this work no matter how much we improved it. That rebuild is Compass, and it ended up teaching us something we didn’t expect about value-based care more broadly.

02

The Swiss cheese model

The best way I’ve found to explain why borrows from a model that has nothing to do with palliative care.

The Swiss cheese model, originally James Reason’s way of explaining how accidents happen in aviation and healthcare safety, pictures a system as a stack of defensive layers, each one full of holes. No single layer is expected to be perfect. Harm only gets through when the holes in every layer happen to line up at once. A missed medication check here, a fatigued resident there, a chart that didn’t sync, an alert nobody saw. Any one of those, caught by any other layer, and nothing bad happens. All of them lining up, and you get a sentinel event.

I’d argue advance care planning has the exact same structure. Call it the Swiss cheese model of goal-concordant care. The layers are the patient’s understanding, the family’s understanding, whether the decision-maker actually knows they’re the decision-maker, whether the document is current, whether it’s reachable in the EMR at 2 a.m., and whether anyone revisits it when the clinical picture changes. Every one of those layers has holes. That’s normal.

What actually produces a bad outcome, an unwanted intubation, a family blindsided in a hallway, is when several of those holes line up on the same day, for the same patient, with nobody positioned to see it happening across the whole stack.

03

What’s wrong with advance care planning?

In October 2021, three of the most respected names in palliative medicine, Sean Morrison, Diane Meier, and Bob Arnold, published a JAMA piece called “What’s Wrong With Advance Care Planning?” Their argument, backed by a review of 80 systematic reviews covering roughly 1,600 studies, was blunt: the scientific data don’t support the assumption that ACP improves end-of-life care, and its documentation doesn’t reliably reflect the quality of an end-of-life discussion. Diane Meier put it even more directly in an interview afterward: a great deal of time, money, and effort has gone into ACP, and the evidence doesn’t show it delivers what we hoped.

Sit with that for a second. The people who built the field, who trained a generation of palliative care clinicians, who have more bedside hours in this work than almost anyone, are telling health systems the core intervention doesn’t move the needle. When has that ever happened before? Cardiologists don’t publish papers saying stop measuring blood pressure. Oncologists don’t tell you chemotherapy protocols are a waste of time. It’s genuinely rare for a field’s own leadership to say, in its flagship journal, that the thing everyone gets paid to document isn’t working.

I don’t think they’re wrong about the evidence. I think they’re describing exactly what the Swiss cheese model predicts when you only build one layer. Most ACP today is a single thin defense: one conversation, sometimes with a form at the end, captured at intake and never revisited. That layer has holes, like every layer does. A directive signed two years ago describes a healthier person. A surrogate named in that moment may not remember they said yes. Nobody’s watching for the moment those holes need closing again. So of course the data looks unconvincing. You’re evaluating one slice of cheese and asking why it doesn’t stop everything on its own.

 

You’re evaluating one slice of cheese and asking why it doesn’t stop everything on its own.
Dr. Desh Mohan, Chief Medical Officer

This is exactly what we see when a health system decides to build this in-house instead of partnering with us. They build the layer they can see: a documentation workflow, a signature capture tool, maybe a nurse-led outreach program. It looks like ACP. It even hits a completion-rate metric in year one. And then, roughly a year later, we’re back in the room with them, because their readmission numbers haven’t moved, their hospice utilization hasn’t shifted, and nobody can explain why a fully “compliant” population still isn’t getting goal-concordant care. They built one good layer of cheese and assumed it was the whole wheel.

04

The missing accountability layer

Julie Yoo at a16z wrote something recently that I think names the deeper issue better than I could. Her framing is that healthtech value is shifting from intelligence plus automation to intelligence plus automation plus accountability, because as frontier models get better, being smart or being efficient stops being defensible on its own. The moat, she argues, sits in the parts of the work that live outside the model: licensure, credentialing, regulatory approval, real-world operations, actually being on the hook for the outcome.

Advance care planning might be the cleanest test case for that thesis I’ve seen. It was never an intelligence problem. A good conversation guide has existed for decades. It’s barely an automation problem either; you can automate outreach and still miss every hole lining up in the stack. What it has always needed is an accountability layer: something, or someone, watching every layer of the model simultaneously, in real time, and answerable for whether the document a patient signed two years ago still describes the person they are today.

05

Why we rebuilt Compass

Here’s the part I actually want to spend time on, because it’s the whole reason I’m writing this.

We didn’t rebuild Compass because our old system was broken in some obvious way. Completion rates were good. Advocates liked the tools. We drove significant savings for our clients by decreasing unwanted utilization for their patients. By the metrics most vendors report to a health plan, it looked like ACP was working. But we kept running into the same wall the JAMA authors were describing: a signed document sitting in a chart, a family blindsided anyway, a preference that was true eighteen months ago and nobody had checked since. We had built a good slice of cheese. We hadn’t built the thing that watches the whole stack.

 

We had built a good slice of cheese. We hadn’t built the thing that watches the whole stack.
Dr. Desh Mohan, Chief Medical Officer

So we went back to first principles and asked a harder question than “how do we make this workflow better.” We asked what a system would have to be able to do if it were actually accountable for an outcome, not just for documenting an intake conversation: watch every layer continuously, across an entire population, and act the moment the holes start lining up instead of waiting for a scheduled check-in. A linear, form-driven workflow can’t do that no matter how much you improve it. It moves one patient through one path at a time. What we needed was something that watches, reasons, and acts across every layer at once. That’s a different architecture, not a faster version of the old one, and that’s why the rebuild had to be a rebuild, not a redesign.

06

Beyond advance care planning

The part I didn’t expect going in: almost none of what came out of that rebuild turned out to be specific to advance care planning. Watching for the signal that a patient’s situation just changed, rather than waiting for the next scheduled outreach. Verifying that someone actually understood what they agreed to, instead of just logging that a call happened. Catching a caregiver whose understanding has quietly drifted from the patient’s own stated wishes, before that gap becomes a crisis. Making sure a human’s time goes to the conversation that needs a human, and everything else gets handled another way.

None of that is an ACP problem. It’s a value-based care problem. It shows up in chronic disease management just as much as end-of-life planning: a diabetic patient’s care plan goes stale the same way a directive does, a caregiver’s grasp of a medication regimen drifts the same way their grasp of a code status drifts, and a transitions-of-care program built on quarterly check-ins has the exact same architecture, and the exact same holes, as the ACP programs the JAMA piece was criticizing.

That’s the real reason we went AI-native rather than just adding AI on top of what we had. The old stack was built to move a patient through a workflow. What VBC actually requires, whether the outcome you’re accountable for is goal-concordant care, chronic condition management, or a successful care transition, is a system built to hold every layer of a population in view at once, continuously, and to act the moment those layers start to misalign.

We built Compass to do that for ACP first because it’s the hardest version of the problem: the most parties involved, the highest stakes, the least tolerance for a document that’s quietly gone stale. But the architecture underneath it isn’t an ACP architecture. It’s the one we think value-based care in general is going to need.

That’s also the piece of Julie Yoo’s framework I keep coming back to. Intelligence and automation get you a faster version of the same thin layer. Accountability is what makes you the system watching for holes lining up across all of them, and being on the hook when they do. Rebuilding Compass to be AI-native was our attempt to actually take on that accountability, for goal-concordant care and, we suspect, for a lot more of value-based care than we originally set out to solve.

 

Goal-concordant care was never a bad idea. A single slice of cheese was just never going to be enough to protect it, in this domain or in most of the others we work in.
Dr. Desh Mohan, Chief Medical Officer
References
1.Morrison RS, Meier DE, Arnold RM. What’s Wrong With Advance Care Planning? JAMA. 2021. pmc.ncbi.nlm.nih.gov/articles/PMC9373875
2.Yoo J. Be AI-Native and AI-Proof. Healthtech Builders (Substack). healthtechbuilders.substack.com/p/be-ai-native-and-ai-proof
3.Medicare Spending at the End of Life. Kaiser Family Foundation. kff.org/medicare/medicare-spending-at-the-end-of-life
4.Broome T, et al. End-of-Life Values and Value-Based Care. AJMC. ajmc.com/view/end-of-life-values-and-value-based-care
5.ACP and Palliative Care: Cost Savings Data. Iris, powered by Aledade. irishealthcare.com/acp-and-palliative-care
Dr. Desh Mohan
Dr. Desh MohanChief Medical Officer, Koda Health
Koda Compass

Reach the right patient at the right moment.

See how Compass coordinates advance care planning outreach across your organization and writes results back to your EHR.

Transform difficult conversations into actionable plans with Koda