Why a validation cannot answer these questions
This is not a criticism of validation. It is what a measurement at rest is.
The sharpest formulation of it is not ours. Writing in the Belgian infection-control journal NOSO-info in 2019, Ludo Vereecken, Pascal De Waegemaeker and Frédéric Van Heuverswyn put it plainly: the tests for releasing a theatre are carried out at rest, the air quality is measured in a virtually empty theatre — and then only in the middle. They go on to ask openly whether the ultra-clean air required is in fact delivered in sufficient quantity during full operating activity.
Two things sit in that. The state — empty, at rest. And the place — only in the middle. Both return below as design choices.
And then there is the average. In a published series of 191 real hip and knee arthroplasties, with continuous pressure and door-position logging that the staff were unaware of, total door-open time had no measurable effect on the mean theatre pressure (p = 0.7). It did affect the minimum values (p < 0.02). And in 77 of the 191 procedures — over forty percent — positive pressure was defeated at some point, allowing airflow to reverse.
A sample measures the mean. The risk sits in the outliers. That is, in one sentence, the entire reason this design exists.
Add to that the fact that even the most favourable conditions fail more often than expected. Across 141 operating theatres in 33 hospitals, over eight years of control measurements, roughly 19 percent of measurements fell outside limits, and for differential pressure specifically about 7 percent. At rest, with the doors closed.
The five questions
Everything that follows derives from these. We fix them before installation, because a measurement point without a question produces only a graph.
- How often, for how long and at which point in the procedure does the pressure cascade fail — and which of the separations is it?
- Does the cascade recover fully each time, or does a residual deviation remain?
- How does the particle load during a procedure compare with the load at rest, per size class?
- Does an elevated value come from the theatre itself, or is it brought in from outside the zone?
- How long does recovery take after a disturbance, and does that recovery time change over the months?
Two quantities that say different things
This distinction is the core of the whole arrangement, and it is easily missed because both quantities appear on the same dashboard.
An elevated particle count may come from activity. People move, instruments are passed, trolleys are set up. That is a load, and whether it is a problem depends on how much and for how long.
A lost differential pressure means something else: that the separation itself was not there at that moment. Not that more came in, but that the mechanism which should have stopped anything coming in did not exist at that instant.
These are not gradations of the same thing. They are two different questions, and they need each other: the differential pressure says when the separation failed, the particle series says whether it made any difference at that moment.
Why there is no universal answer
Whether a door opening actually removes your cascade differs from theatre to theatre, and the literature is not ambiguous on this — it is clear.
In five Italian operating theatres, all five had a differential pressure, and all five fell to zero at every door opening. In six American theatres — empty, which belongs in the comparison — positive pressure was not defeated during any single door-opening event, and airflow recovered within fourteen to fifteen seconds; only when two doors were opened at once did outside air enter.
These are not contradictory findings. They are the observation that the outcome depends on the air volume, the door type, the setting and whether a second door is involved. And one counter-intuitive detail from the Italian series is worth noting: the ISO class deteriorated only in the laminar-flow theatres — there the baseline load was low enough for the difference to show. The better the theatre, the more visible the impact.
The conclusion is not that it always goes wrong. The conclusion is that you do not know this about your own theatre without measuring it.
Three particle measurement points
| Point | Space | Role | Placement | Which question |
|---|---|---|---|---|
| M1 | Operating theatre | Exposure | Against the wall, at working height, outside the direct plenum flow | Question 3 |
| M2 | Airlock or prep room | Source and transition | At working height, away from the supply grille | Questions 1 and 4 |
| M3 | Adjacent non-critical room | Reference | Outside the theatre's zone of influence | Question 4 |
Why M1 is not in the middle. A measurement taken in the downward plenum flow measures the supply air, not the theatre. It produces a handsome figure that says little about where people stand and work. This is exactly the point the authors quoted above were making with only in the middle.
Why M3 is the most important point and the one most often missing. Without a reference outside the zone of influence, an elevation is an observation. With a reference, it is attributable. If M3 moves simultaneously and by the same amount, it did not come from the theatre. If M3 stays flat while M1 climbs, it did. It is also the cheapest point in the arrangement, because it sits in a room where little happens.
All three measure the same parameters. Only then are the series comparable with each other, and that comparability is the whole reason there are three.
Why the coarse fractions are counted separately
The size classes 0.3 · 0.5 · 1 · 5 · 10 µm are each counted separately. The fine classes follow the behaviour of the air handling. The coarse classes follow people.
Organisms associated with human carriage are usually found on particles in the range of roughly four to twenty micrometres, with a centre of gravity around three to five. That is why 5 and 10 µm are tracked separately — not to count organisms, on which more below, but because that is the fraction in which human activity becomes visible.
And activity weighs more than presence. In thirty orthopaedic implant procedures, traffic flow in the theatre correlated strongly with microbial load; the number of people present correlated weakly. In a separate series across 28 operating theatres, each additional person present added on average 4.93 CFU/m³, but the phase of the operation weighed more heavily than occupancy. So we do not count people. We measure what people do to the air.
Two differential pressure measurements, and the rule behind them
The first difference is fixed: the theatre relative to the airlock or prep room. That is the separation most frequently opened during a procedure.
For the second, two options exist — the theatre relative to the adjacent room, or the airlock relative to that room. Arithmetically it makes no difference: from two of the three differences the third always follows. The choice is about measurement quality and about what a deviation means.
One measurement per separation
A pressure measurement must never span two doors at once. If it does, a deviation no longer says which separation failed, and the measurement is back to being an observation rather than a diagnosis.
Both measurements anchored in the theatre
The theatre is the space the statement is about, and it is the common reference point of both measurements. As a result, a simultaneous movement of both signals means something different from the movement of one. That distinction cannot be made when the two measurements are in series.
The standard choice is therefore theatre ↔ airlock and theatre ↔ adjacent room. That assumes the theatre has its own door to that adjacent room, which is the case in the common layout. If it does not, and the only route is through the airlock, that measurement would span two doors in series — and the second difference becomes airlock ↔ adjacent room, because that is the separation which actually exists. The rule stays the same: measure the separations that are there, each one separately.
One condition applies to the reference room itself: it must have a stable pressure regime. A room with its own control loop moving up and down makes the second difference unreadable.
What two signals together can distinguish
This is where the design earns its keep.
| What the two signals do | What that means |
|---|---|
| Both fall simultaneously and to roughly the same depth | The cause is in the theatre itself: supply volume, filter loading or the air handling unit. Not a door event |
| Only theatre ↔ airlock falls | The door to the airlock, or a change in the airlock |
| Only theatre ↔ adjacent room falls | The door to that room, or a change in that room |
| Both fall, but to unequal depths | Two separations open at once, or one door with a pressure response in the second room |
| Both fall and do not fully return | Not a door event but a change of state. This is the situation that alarms |
This is the difference from a door counter. A door counter records that a door opened. This arrangement records whether it made any difference, which separation was involved, and how long it lasted. A door that opens briefly without breaking the cascade does not count here. A cascade lost to two simultaneous doors or to the air handling unit does count — and a door counter cannot make that distinction in principle.
The measurements cover a range of −125 to +125 Pa with a response time below three milliseconds. That response time is not a specification boast but a necessity: the events that matter are short. A door is rarely open for more than a few tens of seconds.
Why nothing alarms for six weeks
The monitors record from day one. The alarming does not.
Thresholds set before the normal pattern of that theatre is known lead either to alarm fatigue or to a system that never triggers. Hence a baseline period of six weeks — roughly thirty operating days — before a single figure is fixed.
The door figures themselves show why this is necessary. In a meta-analysis covering 4,412 patients, the median was close to fourteen door openings per hour, with a spread from 3.4 to 31.7. Individual series run to over a hundred openings per procedure. Anyone who alarms on an individual door opening sends hundreds of notifications a day and has, within a week, a system nobody reads.
We therefore alarm on the state that does not recover, and report the events. An interruption of a few seconds that returns fully is a normal working day; it belongs in the quarterly report, not in a notification. A differential pressure that fails and stays failed is something else, and that should reach a named recipient within minutes.
Four levels, each with its own destination: a technical level for failure of the measurement system itself, an informative level that accumulates into a summary, an action level for a persistent deviation, and a critical level for a loss of separation that does not recover. Every active alarm rule presupposes a named recipient. Without an owner per rule, a notification is not followed up, and the alarming is decoration.
InsightAir provides continuous air quality monitoring in critical environments. What happens between two point measurements is usually the most interesting part.
If you want to know what an arrangement would produce in your operating theatre, a site visit is the usual first step: which doors the theatre has, which room can serve as a reference, and which second differential pressure follows from that — including the conclusion that this is not needed in your situation.