Digital Twins in Systems Medicine: Validation Boundaries
Holding
A medical digital twin is not valid because it is detailed. It is valid only within a defined boundary of prediction, patient population, data freshness, and clinical decision support.
Authority
Medical device risk management and AI governance frameworks require intended use, performance evidence, and risk controls. A digital twin that influences care must therefore state what it is authorized to represent and what it cannot infer.
Issue
The failure mode is representational overreach. A simulation calibrated to one domain, such as hemodynamics, tumor response, or metabolic state, may be visually persuasive while unsupported for a different clinical question.
Resolution
The system should define model scope, input requirements, update cadence, uncertainty bounds, validation dataset, prohibited decisions, and escalation criteria. Interfaces should show confidence and missing inputs rather than presenting the twin as a complete patient duplicate.
Evidence Package
The record should include model assumptions, parameter provenance, calibration data, validation reports, sensitivity analysis, user instructions, and clinical boundary statements. A digital twin is deployable only when its limits are as inspectable as its predictions.