What is CANDOR?
CANDOR stands for Communication and Optimal Resolution. It is a process, developed and published by the federal Agency for Healthcare Research and Quality, that healthcare institutions use “to respond in a timely, thorough, and just way when unexpected events cause patient harm.” The process has five components — identification of a CANDOR event, system activation, response and disclosure, investigation and analysis, and resolution — and the toolkit that teaches it has eight modules covering organizational buy-in, gap analysis, event investigation, disclosure communication, care for the caregiver, resolution, and organizational learning. AHRQ built it with the Health Research & Educational Trust and the American Hospital Association out of a $25 million federal initiative, and tested it in 14 hospitals across three health systems. AHRQ tells adopting organizations to expect at least 12 to 18 months to implement it, which is why naming CANDOR in a policy and running the process are different things that the record distinguishes.[1, 2, 3, 16]
What is a sentinel event?
The Joint Commission defines a sentinel event as “a patient safety event (not primarily related to the natural course of a patient's illness or underlying condition) that reaches a patient and results in death, severe harm (regardless of duration of harm), or permanent harm (regardless of severity of harm).” Sentinel events are a subcategory of adverse events. Reporting one to The Joint Commission is voluntary — “organizations are not required to report sentinel events to Joint Commission” — but the analysis is not: “All sentinel events must undergo a comprehensive systematic analysis by the health care organization, regardless of whether the events are reported to Joint Commission,” and accredited organizations must have a policy detailing how they address them. The organization must prepare that analysis and a corrective action plan within 45 business days of the event or of becoming aware of it. The policy has been in place since 1996.[18, 19]
What is RCA²?
RCA² — read “RCA squared” — is Root Cause Analyses and Actions, the method published by the National Patient Safety Foundation in 2015 and now hosted by the Institute for Healthcare Improvement. The panel renamed root cause analysis for a stated reason: “Prevention requires actions to be taken.” Its central instrument is the Action Hierarchy, which grades corrective actions by strength — stronger actions “require less reliance on humans to remember to perform the task correctly” (architectural change, forcing functions, simplification, standardization), while weaker actions require more (double checks, warnings, a new policy, training) — and the method instructs that teams “should identify at least one stronger or intermediate strength action for each RCA² review.” It also sets a clock: start within 72 hours, complete in 30 to 45 days. And it sets a limit on its own use: “the review is not to be used to focus on or address individual performance.”[7]
Is a healthcare organization required to disclose a medical error to the patient?
Yes, though the obligation comes from accreditation, state law, and institutional policy rather than from the law of negligence. AHRQ states that “since 2001, the Joint Commission has required disclosure of unanticipated outcomes of care,” and the National Quality Forum endorsed disclosure of serious unanticipated outcomes as a safe practice in 2010. Five states require disclosure by law: Pennsylvania and Nevada within seven days, in writing in Pennsylvania; Massachusetts within seven calendar days; New Jersey by the end of the episode of care; and Florida in person. Four others — Colorado, Utah, Iowa and Oregon — have enacted voluntary communication-and-resolution statutes with defined notice windows and confidentiality protections. Where an organization has adopted its own written disclosure policy, that policy is the institution's own statement of its duty. What varies from state to state is the deadline, the required content, and the consequence of silence, so that analysis is forum-specific. What patients say a full disclosure must contain is consistent: what happened, why it happened, how the effects will be limited, and what will be done to prevent a recurrence.[8, 15, 28, 29, 30, 31, 38, 39, 40, 41]
Does a healthcare organization have to waive charges after a never event?
Sometimes by law, and everywhere as a national standard. Medicare does not cover wrong-procedure, wrong-body-part, or wrong-patient surgery, and CMS states that it cannot envision a valid notice that would shift that cost to the beneficiary; federal Medicaid rules bar state payment for the same events. Massachusetts prohibits a hospital from charging the patient or payer for a serious reportable event it determines was preventable and unambiguously the result of a system failure. Beyond those, no federal statute requires a waiver, but the national written standard says it should be done. The Leapfrog Group's Never Events Policy — voluntary, in place since 2007, and publicly reported — provides that a hospital meets the standard only if it waives all costs directly related to the event, and Leapfrog's never events fact sheet specifies that the costs are waived so that neither the patient nor the third-party payor receives a bill for them. Eight other commitments accompany it, including apologizing, reporting to an external agency within 15 business days, conducting a root-cause analysis, and telling the patient what will be done to prevent recurrence. Separately, CMS's hospital-acquired conditions policy has provided since October 1, 2008 that hospitals receive no additional payment for cases involving one of fourteen selected conditions not present on admission. That list is narrow: the OIG found that only 5 percent of the harm events it identified appeared on the HAC Reduction Program list.[5, 6, 22, 35, 40, 42, 43, 44, 45]
What is just culture in healthcare?
Just culture is a framework for responding to the person involved in a safety event according to the choice they made rather than the outcome that followed. AHRQ's CANDOR materials set it out in three rows: human error is supported, at-risk behavior — where the person did not perceive the risk they were taking — is coached, and reckless behavior is sanctioned. It is not a blame-free policy; it has zero tolerance for recklessness, and that is what distinguishes it from an amnesty. The demand it makes is consistency: where a shortcut was tolerated many times without harm, the response on the day harm occurs should be the response the standard called for on all the other days, and the conditions that made the shortcut sensible should be addressed alongside it. RCA² asks organizations to define blameworthy events in advance and say how they will be handled.[7, 10, 17]
What is an occurrence report, and why do healthcare organizations collect near misses?
An occurrence report — also called an incident or safety event report — is a staff-filed record of a safety event, including events that caused no harm at all: the wrong medication almost given, the wrong medication given without injury, the patient who nearly fell. Healthcare organizations collect these deliberately, as high-reliability industries do, because near misses are precursor events that map where the next serious harm is most likely to occur. RCA² instructs that a close call be scored on a “reasonable ‘worst case' systems level scenario” so it can be prioritized before anyone is hurt. Volume of reporting is therefore a sign of a functioning program rather than a troubled one; what matters is whether the reports are trended and whether the trends produced changes. Under-capture is the known weakness: the OIG found in 2012 that only 14 percent of the patient harm events it identified had reached a hospital's internal reporting system.[6, 7]
How is a patient safety expert different from a standard-of-care expert in the treating specialty?
They answer different questions from different bodies of authority. A treating-specialty expert addresses whether the clinician's care met the standard of that specialty — whether the cardiologist chose the right medication. A patient safety expert addresses how the institution ran its safety program: what it collected and reviewed, whether the event review was competently performed, what was communicated, and what changed as a result. The governing authority is different, the documents are different, and the witness is different. In many matters both are required, and asking one expert to carry both is how otherwise sound positions come apart on cross-examination.