Healthcare patient safety standards require a defined response to suspected or actual patient harm.

There is a standard of care for delivering care, and a separate standard for responding when care does not go as intended. How a healthcare organization reports the event, reviews it, acts on what the review finds, tells the patient and family what happened, resolves the matter including the bill, and supports the clinicians involved is critical to recovering from a serious unanticipated outcome and to making sure the next patient is not harmed.

Published byVident Partners — expert witness referral, since 2005
Anchored bySeth A. Krevat, M.D., FACP
References46 primary sources, every URL checked

The Patient Safety Standards Project is an independent reference on what healthcare patient safety standards require of an organization before and after a patient is harmed — event and near-miss reporting, safety culture, high-reliability practice, a systems-based event review, communication and disclosure to the patient and family, resolution including the bill, and support for the clinicians involved. The authority is published and open: the Medicare Conditions of Participation, the accreditation manual, the federally developed CANDOR process, state law, and the national patient safety bodies. It is written to be equally usable by a patient's counsel and a healthcare organization's counsel, because a standard only one side trusts is not a standard.

Where this stands

What healthcare patient safety standards require.

Healthcare patient safety standards require an organization to do a defined set of things, and each of them is written down somewhere a reader can open. It collects reports of events and near misses and acts on them. It measures its own safety culture. When there is suspected or actual patient harm, it conducts a systems-based event review — a root cause analysis — that produces graded corrective action rather than a memo. It tells the patient and family what happened. It resolves the matter, including the bill. It supports the clinicians who were involved. And it learns from the event, so that the next patient is not harmed the same way. Federal regulation requires every Medicare-participating hospital to track adverse events, analyze their causes, and act to prevent them, and accreditation requires both the event review and support for the staff involved. Disclosure to the patient and family is the national expectation, and five states require it by law. The bill is the least uniform: Medicare does not cover wrong-procedure, wrong-body-part, or wrong-patient surgery, Massachusetts bars the charge for a preventable system failure, and elsewhere the cost waiver is a voluntary national standard. AHRQ published the sequence for the response as CANDOR — Communication and Optimal Resolution — and the National Patient Safety Foundation published the method for the review. For each of these, the organization either did it or did not, and the record shows which.

Two standards: delivering care, and responding when it does not go as intended

Two questions are frequently blurred together, and separating them is most of the value of this subject. The first is the clinical standard of care: whether the treating clinician's care met the standard in their own specialty — whether the cardiologist chose the right medication — answered by an expert in that specialty. The second is the standard for how the organization responds when care does not go as intended. A patient admitted for a knee replacement who suffers a cardiac arrest on the table has had a serious unanticipated outcome. Whether anyone did anything wrong may not be known for weeks, but there is an expected standard for what the organization does next: what it reports, how it reviews the event, what it tells the patient and family, how it resolves the matter, and what it changes. That second question exists whether or not the first is ever reached. It rests on different authority, it is answered by a different witness, and it is answered the same way for an organization defending its response as for a patient examining it. Harm response is one component of the larger safety program, not the whole of it, and this Center is organized accordingly.

Who anchors this Center

This Center is anchored by Seth A. Krevat, M.D., FACP. Dr. Krevat served for seven years as Assistant Vice President for Safety at a ten-hospital, $9 billion, self-insured integrated healthcare system in the Mid-Atlantic with more than 300 care locations and more than 37,000 associates. The system is known for a forward-thinking and comprehensive approach to patient safety, which Dr. Krevat implemented together with the system's Vice President of Risk Management. The approach was built on the national safety standards set out in the Agency for Healthcare Research and Quality's (AHRQ) Communication and Optimal Resolution (CANDOR) toolkit, together with The Joint Commission's and other regulatory requirements described elsewhere in this Center. Every serious unanticipated outcome in the system was reported to and managed by him and his team of safety professionals. Once reported, each event activated a process that held the patient's bills, completed a systems-based event review, provided open and honest communication with the patient and family (disclosure), and provided support for the healthcare workers involved. AHRQ names him on the CANDOR toolkit acknowledgments as a member of the Expert Faculty that led the design and teaching of the CANDOR curriculum, alongside Thomas Gallagher, Richard Boothman, and Timothy McDonald. In 2020 he became Senior Medical Director of the system's National Center for Human Factors in Healthcare, where he led and participated in patient safety science research, led an internal consulting team addressing system safety issues, and coauthored more than 30 additional papers on patient safety. He is an assistant professor of Clinical Medicine at Georgetown University School of Medicine, was board certified in internal medicine for 20 years, is currently board certified in hospice and palliative medicine, and continues to care for critically ill patients as part of the palliative care team at Georgetown University Hospital. He is first author of a study in JAMA Network Open analyzing closed malpractice claims to identify how the electronic health record contributes to diagnostic error.

A physician writing in a patient record.
The record is where the standard is made visible: the report, the review, and what was said to the patient are all written down. Photograph used for illustration; it does not depict a Vident Partners client or any facility described on this page.

The scale

What the record shows

Each figure below is reported with the source that produced it and the period it covers. Numbers describing a population are not findings about any individual case.

1 in 10

patients is harmed by the care they receive, on AHRQ's own estimate in the CANDOR toolkit[2]

25%

of Medicare patients experienced a harm event during their hospital stay in October 2018 — 12 percent adverse events, 13 percent temporary harm events[6]

56%

of those harm events were judged not preventable by physician reviewers, occurring even though providers followed proper procedures[6]

Nine

commitments in the national never-events standard — five adopted in 2007, four added in 2017 citing AHRQ's CANDOR toolkit and the NPSF root-cause work[5, 35]

45 business days

the accreditation deadline for a comprehensive systematic analysis and corrective action plan after a sentinel event[18]

2.13 → 0.75

lawsuits per 100,000 patient encounters before and after one academic health system implemented full disclosure with offers of compensation, 1995–2007[26]

The standards

What the standards require

Ten components of what healthcare patient safety standards require for reporting and responding to patient safety events, drawn from the Medicare Conditions of Participation, the accreditation policy, the federal CANDOR process, state law, and the national safety bodies. Every assertion carries a numbered citation to the source.

The federal quality program names adverse events, and the governing body answers for it

42 CFR § 482.21 is the Condition of Participation for quality assessment and performance improvement, and it is specific rather than aspirational. The hospital “must develop, implement, and maintain an effective, ongoing, hospital-wide, data-driven quality assessment and performance improvement program,” and “must maintain and demonstrate evidence of its QAPI program for review by CMS.” The program “must measure, analyze, and track quality indicators, including adverse patient events, and other aspects of performance that assess processes of care, hospital service and operations,” and performance improvement activities “must track medical errors and adverse patient events, analyze their causes, and implement preventive actions and mechanisms that include feedback and learning throughout the hospital.” The data collected must be used to “monitor the effectiveness and safety of services and quality of care” and to “identify opportunities for improvement.” Accountability is assigned rather than diffuse: paragraph (f) makes the governing body, medical staff, and administrative officials responsible for ensuring that the program “including the reduction of medical errors, is defined, implemented, and maintained,” that “clear expectations for safety are established,” that “adequate resources are allocated,” and that the number of distinct improvement projects is determined annually. There is no fixed project count — the number “must be proportional to the scope and complexity of the hospital’s services and operations.” Note the current lettering: a November 27, 2024 amendment inserted a new paragraph (e) on maternal health QAPI activities effective January 1, 2027 and moved executive responsibilities to (f). A separate Condition, § 482.13(a)(2), requires a grievance process the governing body approves and is responsible for, with specified time frames and a written decision naming the contact person, the steps taken to investigate, and the results; CMS interpretive guidance treats any written complaint as a grievance, sets a 7-day response as the general expectation, and requires that patients be told they may go directly to the state agency instead.[4, 33, 34]

Reporting near misses is the design of a safety program, not a symptom of one in trouble

Healthcare organizations collect far more than the events that reach a claim. Occurrence reports — also called incident or safety event reports — capture near misses and no-harm events: the wrong medication almost given, the wrong medication given without injury, the patient who nearly fell. High-reliability industries collect these deliberately as precursor events, because they map where the next serious harm is likely to occur — an approach RCA² describes as “consistent with successful practices in many high-reliability industries, such as aviation.” RCA² treats them the same way, instructing that where the event is a close call, severity be assigned “based on a reasonable ‘worst case’ systems level scenario” so that a near miss can be prioritized before anyone is hurt, and that every event be scored on an explicit risk-based prioritization matrix within 72 hours. The record of a program that is working looks a particular way: reports arrive at volume, they are trended rather than filed, and the trends produce changes someone can point to. That record is informative to both sides, because it shows what an organization knew and what it did with what it knew before the event at issue. Under-capture is a known limitation of the method rather than a hidden one — in a 2012 follow-up study the HHS Office of Inspector General found that only 14 percent of the patient harm events it identified had been reported to hospitals’ incident reporting systems or other internal surveillance. Measurement of how often harm occurs has been attempted from several directions, and the figures differ because the instruments differ. The OIG’s 2010 study of 780 Medicare beneficiaries discharged in October 2008 found that 13.5 percent experienced an adverse event and a further 13.5 percent a temporary harm event, that physician reviewers judged 44 percent of those events clearly or likely preventable, and that associated care cost Medicare an estimated $324 million in that single month. Its 2022 study of 770 patients discharged in October 2018 reported 25 percent experiencing harm and 43 percent of those events preventable. A 2023 study of eleven Massachusetts hospitals, using a different instrument again, identified at least one adverse event in 23.6 percent of admissions. These are population measurements taken under different criteria and are not a trend line; they establish that the problem is large and measurable, not what happened to any one patient.[6, 7, 12, 20]

A clinician completing a report on a clipboard.
Occurrence reports are filed at volume in a working program, most of them for events that harmed no one.

The remaining 8 standards

  1. Safety culture is measured with a published instrument, and just culture defines the response to the person
  2. High reliability is a defined set of practices, and human factors supplies the method
  3. A systems-based event review produces graded actions, and the grading scale is published
  4. CANDOR sets the sequence, the components, and the clock
  5. What a full disclosure contains, and where state law requires it
  6. Resolution includes the bill, and the national standard says so in nine numbered lines
  7. Support for the clinicians involved is a formal component, not a courtesy
  8. Diagnostic error often fails in the follow-up, not only in the reasoning
Read the full standards →
Occurrence reports are filed by the thousand for events that harmed no one. That is the design of a reporting program, not a failure of it.

Where it comes up

Matters that turn on these standards

  • Institutional and corporate claims about the safety program itself — what was reported, what was reviewed, what changed, and the qualifications of the people running it
  • Delayed and missed diagnosis matters turning on result routing, critical-value callback, and whether the loop was closed, rather than on the clinician's differential
  • Disclosure questions brought separately from the underlying negligence, where the institution's obligation to communicate is analyzed on its own authority
  • Adequacy-of-review questions: whether the event review was competently performed, whether its corrective actions clear the weakest tier of the Action Hierarchy, and whether the plan was implemented and measured
  • Billing and collection disputes over care necessitated by an event, including accounts handled while the event was under internal review
  • Defense evaluation of a program before positions harden — what the record will show about the response, which internal documents are discoverable in the jurisdiction, and where the organization's own policy sets a higher bar than the law does
  • Audit-trail and record-integrity questions, including who accessed a chart and when, evaluated for what the metadata does and does not establish
  • Serious safety events — medication error, wrong-site and wrong-procedure events, and other serious reportable events — where the question is what the organization did in the following seventy-two hours
  • Claims involving the treatment of clinicians after an event, including whether a documented support protocol existed and was made known to staff
  • Statute-of-limitations and tolling disputes turning on the existence and duration of a duty to speak — a doctrine that is state-specific and, in four states, overlaid by a communication-and-resolution statute
  • Regulatory and accreditation matters, including Conditions of Participation findings, immediate-jeopardy determinations, grievance-process compliance, and the relationship between a survey finding and the civil standard of care
  • Consulting engagements on either side to establish what actually happened — what to ask, which records to pull, and what the organization's own investigation did not cover

The bar

What to require of an expert in these matters

The same standard applies to the experts who anchor this Center. It is published so counsel can hold anyone — including us — to it.

  1. Operating responsibility for a safety program at the scale in dispute — someone who has run event reporting, review, and disclosure for a health system, not only published about them. The person who made these decisions in real cases evaluates them differently than a reviewer meeting them for the first time.
  2. The discipline to separate the two questions. Whether the treating physician met the standard of care in their specialty and how the institution ran its safety program are distinct issues with distinct bodies of authority. An expert who blends them will be impeached on the difference, and in most matters both experts are needed.
  3. Fluency in the actual documents: occurrence and incident reports, the event review file, the corrective action plan, the disclosure note in the chart, the organization's own disclosure and never-events policies, the safety culture survey results, accreditation survey findings, and the audit trail.
  4. A working command of what is privileged and where. Patient safety work product under the Patient Safety and Quality Improvement Act of 2005, peer review, and quality assurance protections vary substantially by state and by whether the work was performed under a listed Patient Safety Organization. An expert who does not know which protections apply in the forum will opine on documents that are not in evidence.
  5. Direct exposure to claims. Sitting on a claims review committee alongside risk management is a materially different qualification from clinical practice alone, and it is the experience that supports testimony about what an institution knew and when.
  6. Current clinical practice, or recent enough to be credible. Safety opinions from someone who has not been inside a hospital in a decade describe a different institution, with different technology and different staffing.
  7. Willingness to reach the defense conclusion. Federal reviewers judged 56 percent of hospital harm events not preventable. An expert who has never found that a program was adequate is an exhibit for the other side under amended Rule 702.
  8. A methodology stated before the opinion is formed — which records are required, in what order they are read, and what would have to appear in them to change the conclusion. In this subject the absence of a document is frequently the finding, and that argument only holds if the search protocol was defined in advance.

Writing

Published, and in preparation

Already published in Vident Partners Insights.

Planned for this Center. These are commissioned outlines, not published pages — there is nothing to read yet, and we would rather say so than link you somewhere that does not exist.

Not yet published

Primer

What a Hospital Safety Program Is Required to Do

The Medicare Condition of Participation at 42 CFR 482.21, the accreditation requirements layered on top of it, and the voluntary national standards that go further. Where each obligation comes from, and what each one actually says.

Not yet published

Method

Reading a Root Cause Analysis Against the Action Hierarchy

RCA² grades corrective actions by strength, from architectural change down to retraining. How to tell a review that changed something from one that produced a policy reminder.

Not yet published

The Process

The CANDOR Timeline: Sixty Minutes, Then Thirty to Forty-Five Days

AHRQ sets an initial disclosure conversation within an hour of the event and full disclosure after the completed investigation. What happens in between, and what the record shows about each step.

Not yet published

For Counsel

Peer Review, Quality Assurance, and Patient Safety Work Product

Three overlapping protections with different sources, different scopes, and different answers in different states. What the Patient Safety Act covers and what falls outside all three.

Not yet published

The Data

How Federal Reviewers Measure Hospital Harm

The OIG's method — a nurse trigger-tool screen followed by physician adjudication — and what its harm and preventability rates do and do not establish. Why the 2010 and 2022 figures are not directly comparable.

Not yet published

Resolution

The Never Events Policy and the Cost Waiver

Leapfrog's nine commitments, the 2017 additions and why they were made, and how CMS's hospital-acquired conditions policy interacts with them. What a hospital that meets the standard actually does with the account.

Questions counsel ask

Answers, with the citation attached

What is CANDOR?

CANDOR stands for Communication and Optimal Resolution. It is a process, developed and published by the federal Agency for Healthcare Research and Quality, that healthcare institutions use “to respond in a timely, thorough, and just way when unexpected events cause patient harm.” The process has five components — identification of a CANDOR event, system activation, response and disclosure, investigation and analysis, and resolution — and the toolkit that teaches it has eight modules covering organizational buy-in, gap analysis, event investigation, disclosure communication, care for the caregiver, resolution, and organizational learning. AHRQ built it with the Health Research & Educational Trust and the American Hospital Association out of a $25 million federal initiative, and tested it in 14 hospitals across three health systems. AHRQ tells adopting organizations to expect at least 12 to 18 months to implement it, which is why naming CANDOR in a policy and running the process are different things that the record distinguishes.[1, 2, 3, 16]

What is a sentinel event?

The Joint Commission defines a sentinel event as “a patient safety event (not primarily related to the natural course of a patient's illness or underlying condition) that reaches a patient and results in death, severe harm (regardless of duration of harm), or permanent harm (regardless of severity of harm).” Sentinel events are a subcategory of adverse events. Reporting one to The Joint Commission is voluntary — “organizations are not required to report sentinel events to Joint Commission” — but the analysis is not: “All sentinel events must undergo a comprehensive systematic analysis by the health care organization, regardless of whether the events are reported to Joint Commission,” and accredited organizations must have a policy detailing how they address them. The organization must prepare that analysis and a corrective action plan within 45 business days of the event or of becoming aware of it. The policy has been in place since 1996.[18, 19]

What is RCA²?

RCA² — read “RCA squared” — is Root Cause Analyses and Actions, the method published by the National Patient Safety Foundation in 2015 and now hosted by the Institute for Healthcare Improvement. The panel renamed root cause analysis for a stated reason: “Prevention requires actions to be taken.” Its central instrument is the Action Hierarchy, which grades corrective actions by strength — stronger actions “require less reliance on humans to remember to perform the task correctly” (architectural change, forcing functions, simplification, standardization), while weaker actions require more (double checks, warnings, a new policy, training) — and the method instructs that teams “should identify at least one stronger or intermediate strength action for each RCA² review.” It also sets a clock: start within 72 hours, complete in 30 to 45 days. And it sets a limit on its own use: “the review is not to be used to focus on or address individual performance.”[7]

Is a healthcare organization required to disclose a medical error to the patient?

Yes, though the obligation comes from accreditation, state law, and institutional policy rather than from the law of negligence. AHRQ states that “since 2001, the Joint Commission has required disclosure of unanticipated outcomes of care,” and the National Quality Forum endorsed disclosure of serious unanticipated outcomes as a safe practice in 2010. Five states require disclosure by law: Pennsylvania and Nevada within seven days, in writing in Pennsylvania; Massachusetts within seven calendar days; New Jersey by the end of the episode of care; and Florida in person. Four others — Colorado, Utah, Iowa and Oregon — have enacted voluntary communication-and-resolution statutes with defined notice windows and confidentiality protections. Where an organization has adopted its own written disclosure policy, that policy is the institution's own statement of its duty. What varies from state to state is the deadline, the required content, and the consequence of silence, so that analysis is forum-specific. What patients say a full disclosure must contain is consistent: what happened, why it happened, how the effects will be limited, and what will be done to prevent a recurrence.[8, 15, 28, 29, 30, 31, 38, 39, 40, 41]

Does a healthcare organization have to waive charges after a never event?

Sometimes by law, and everywhere as a national standard. Medicare does not cover wrong-procedure, wrong-body-part, or wrong-patient surgery, and CMS states that it cannot envision a valid notice that would shift that cost to the beneficiary; federal Medicaid rules bar state payment for the same events. Massachusetts prohibits a hospital from charging the patient or payer for a serious reportable event it determines was preventable and unambiguously the result of a system failure. Beyond those, no federal statute requires a waiver, but the national written standard says it should be done. The Leapfrog Group's Never Events Policy — voluntary, in place since 2007, and publicly reported — provides that a hospital meets the standard only if it waives all costs directly related to the event, and Leapfrog's never events fact sheet specifies that the costs are waived so that neither the patient nor the third-party payor receives a bill for them. Eight other commitments accompany it, including apologizing, reporting to an external agency within 15 business days, conducting a root-cause analysis, and telling the patient what will be done to prevent recurrence. Separately, CMS's hospital-acquired conditions policy has provided since October 1, 2008 that hospitals receive no additional payment for cases involving one of fourteen selected conditions not present on admission. That list is narrow: the OIG found that only 5 percent of the harm events it identified appeared on the HAC Reduction Program list.[5, 6, 22, 35, 40, 42, 43, 44, 45]

What is just culture in healthcare?

Just culture is a framework for responding to the person involved in a safety event according to the choice they made rather than the outcome that followed. AHRQ's CANDOR materials set it out in three rows: human error is supported, at-risk behavior — where the person did not perceive the risk they were taking — is coached, and reckless behavior is sanctioned. It is not a blame-free policy; it has zero tolerance for recklessness, and that is what distinguishes it from an amnesty. The demand it makes is consistency: where a shortcut was tolerated many times without harm, the response on the day harm occurs should be the response the standard called for on all the other days, and the conditions that made the shortcut sensible should be addressed alongside it. RCA² asks organizations to define blameworthy events in advance and say how they will be handled.[7, 10, 17]

What is an occurrence report, and why do healthcare organizations collect near misses?

An occurrence report — also called an incident or safety event report — is a staff-filed record of a safety event, including events that caused no harm at all: the wrong medication almost given, the wrong medication given without injury, the patient who nearly fell. Healthcare organizations collect these deliberately, as high-reliability industries do, because near misses are precursor events that map where the next serious harm is most likely to occur. RCA² instructs that a close call be scored on a “reasonable ‘worst case' systems level scenario” so it can be prioritized before anyone is hurt. Volume of reporting is therefore a sign of a functioning program rather than a troubled one; what matters is whether the reports are trended and whether the trends produced changes. Under-capture is the known weakness: the OIG found in 2012 that only 14 percent of the patient harm events it identified had reached a hospital's internal reporting system.[6, 7]

How is a patient safety expert different from a standard-of-care expert in the treating specialty?

They answer different questions from different bodies of authority. A treating-specialty expert addresses whether the clinician's care met the standard of that specialty — whether the cardiologist chose the right medication. A patient safety expert addresses how the institution ran its safety program: what it collected and reviewed, whether the event review was competently performed, what was communicated, and what changed as a result. The governing authority is different, the documents are different, and the witness is different. In many matters both are required, and asking one expert to carry both is how otherwise sound positions come apart on cross-examination.

References

Every figure in this Center, traced to its source

46 primary sources

Each URL was checked before publication and is rechecked whenever a page in The Patient Safety Standards Project is revised. The numbered markers throughout this Center link straight to the entry they rest on.

View the full reference list →

Working a healthcare patient safety matter?

Tell us the question at issue and we will identify qualified experts — for a patient's family and for a healthcare organization or its insurer alike. The consultation is complimentary and carries no obligation. Requests made here are tagged to The Patient Safety Standards Project.

Request a consultationWho publishes this
Request a Consultation