What the standards require

Ten components of what healthcare patient safety standards require for reporting and responding to patient safety events, drawn from the Medicare Conditions of Participation, the accreditation policy, the federal CANDOR process, state law, and the national safety bodies. Every assertion carries a numbered citation to the source.

The federal quality program names adverse events, and the governing body answers for it

42 CFR § 482.21 is the Condition of Participation for quality assessment and performance improvement, and it is specific rather than aspirational. The hospital “must develop, implement, and maintain an effective, ongoing, hospital-wide, data-driven quality assessment and performance improvement program,” and “must maintain and demonstrate evidence of its QAPI program for review by CMS.” The program “must measure, analyze, and track quality indicators, including adverse patient events, and other aspects of performance that assess processes of care, hospital service and operations,” and performance improvement activities “must track medical errors and adverse patient events, analyze their causes, and implement preventive actions and mechanisms that include feedback and learning throughout the hospital.” The data collected must be used to “monitor the effectiveness and safety of services and quality of care” and to “identify opportunities for improvement.” Accountability is assigned rather than diffuse: paragraph (f) makes the governing body, medical staff, and administrative officials responsible for ensuring that the program “including the reduction of medical errors, is defined, implemented, and maintained,” that “clear expectations for safety are established,” that “adequate resources are allocated,” and that the number of distinct improvement projects is determined annually. There is no fixed project count — the number “must be proportional to the scope and complexity of the hospital’s services and operations.” Note the current lettering: a November 27, 2024 amendment inserted a new paragraph (e) on maternal health QAPI activities effective January 1, 2027 and moved executive responsibilities to (f). A separate Condition, § 482.13(a)(2), requires a grievance process the governing body approves and is responsible for, with specified time frames and a written decision naming the contact person, the steps taken to investigate, and the results; CMS interpretive guidance treats any written complaint as a grievance, sets a 7-day response as the general expectation, and requires that patients be told they may go directly to the state agency instead.[4, 33, 34]

Reporting near misses is the design of a safety program, not a symptom of one in trouble

Healthcare organizations collect far more than the events that reach a claim. Occurrence reports — also called incident or safety event reports — capture near misses and no-harm events: the wrong medication almost given, the wrong medication given without injury, the patient who nearly fell. High-reliability industries collect these deliberately as precursor events, because they map where the next serious harm is likely to occur — an approach RCA² describes as “consistent with successful practices in many high-reliability industries, such as aviation.” RCA² treats them the same way, instructing that where the event is a close call, severity be assigned “based on a reasonable ‘worst case’ systems level scenario” so that a near miss can be prioritized before anyone is hurt, and that every event be scored on an explicit risk-based prioritization matrix within 72 hours. The record of a program that is working looks a particular way: reports arrive at volume, they are trended rather than filed, and the trends produce changes someone can point to. That record is informative to both sides, because it shows what an organization knew and what it did with what it knew before the event at issue. Under-capture is a known limitation of the method rather than a hidden one — in a 2012 follow-up study the HHS Office of Inspector General found that only 14 percent of the patient harm events it identified had been reported to hospitals’ incident reporting systems or other internal surveillance. Measurement of how often harm occurs has been attempted from several directions, and the figures differ because the instruments differ. The OIG’s 2010 study of 780 Medicare beneficiaries discharged in October 2008 found that 13.5 percent experienced an adverse event and a further 13.5 percent a temporary harm event, that physician reviewers judged 44 percent of those events clearly or likely preventable, and that associated care cost Medicare an estimated $324 million in that single month. Its 2022 study of 770 patients discharged in October 2018 reported 25 percent experiencing harm and 43 percent of those events preventable. A 2023 study of eleven Massachusetts hospitals, using a different instrument again, identified at least one adverse event in 23.6 percent of admissions. These are population measurements taken under different criteria and are not a trend line; they establish that the problem is large and measurable, not what happened to any one patient.[6, 7, 12, 20]

A clinician completing a report on a clipboard.
Occurrence reports are filed at volume in a working program, most of them for events that harmed no one.

Safety culture is measured with a published instrument, and just culture defines the response to the person

AHRQ's Surveys on Patient Safety Culture Hospital Survey, now in version 2.0, has ten composite measures — Teamwork; Staffing and Work Pace; Organizational Learning—Continuous Improvement; Response to Error; Supervisor, Manager, or Clinical Leader Support for Patient Safety; Communication About Error; Communication Openness; Reporting Patient Safety Events; Hospital Management Support for Patient Safety; and Handoffs and Information Exchange. The composite carrying the blame question is Response to Error, and its four items are stated plainly: whether staff “feel like their mistakes are held against them”; whether, when an event is reported, “it feels like the person is being written up, not the problem”; whether the unit “focuses on learning rather than blaming individuals”; and whether “there is a lack of support for staff involved in patient safety errors.” AHRQ maintains a comparative database — the 2024 database report covers 445 U.S. hospitals and more than 280,000 staff and providers — and states plainly that it “is not representative of all U.S. hospitals,” a limit worth reproducing rather than dropping. The framework for responding to an individual is just culture, which AHRQ’s own CANDOR materials set out as three rows adapted from David Marx’s 2001 monograph: human error is supported, at-risk behavior — where the person did not perceive the risk they were taking — is coached, and reckless behavior is sanctioned. It is not a blame-free policy; it has zero tolerance for the third category. What it asks for is consistency, and RCA² makes the same demand from the other direction, instructing that “each organization define blameworthy events and actions that fall outside the purview of the safety system and define how and under what circumstances they will be handled.” An organization that drew that line in advance, in writing, has met the standard and can show that it did.[7, 10, 17, 23, 36]

High reliability is a defined set of practices, and human factors supplies the method

AHRQ defines high reliability organizations as “organizations that operate in complex, high-hazard domains for extended periods without serious accidents or catastrophic failures,” and names five characteristics: preoccupation with failure, reluctance to simplify, sensitivity to operations, deference to expertise — “the people closest to the work are the most knowledgeable about the work” — and commitment to resilience. Chassin and Loeb, writing in the Milbank Quarterly in 2013, set out three preconditions for healthcare specifically: leadership commitment to zero patient harm, a safety culture whose “three central attributes” are “trust, report, and improve,” and robust process improvement. The engineering half is human factors, and AHRQ’s event analysis guide states the principle in James Reason’s words: “You cannot change the human condition. But you can change the conditions in which humans work.” People will make errors, predictably, so the system is designed to make the safe action the easy one. The published action hierarchy grades corrective measures on exactly this basis, which is why a plan built on design changes scores at the top of it and a plan built on reminders scores at the bottom.[7, 17, 24, 25]

A systems-based event review produces graded actions, and the grading scale is published

In 2015 the National Patient Safety Foundation convened a panel and renamed root cause analysis as RCA² — Root Cause Analyses and Actions — for a stated reason: “Prevention requires actions to be taken.” Accreditation makes the analysis mandatory for sentinel events: the Joint Commission's National Performance Goals for hospitals, effective January 2026, provide that “the hospital conducts thorough and credible comprehensive systematic analyses (for example, root cause analyses) in response to sentinel events.” Three features of RCA² are directly usable by either side. First, the Action Hierarchy grades corrective actions by strength, with Stronger Actions described as those that “require less reliance on humans to remember to perform the task correctly” — architectural change, forcing functions, simplification, standardization — and Weaker Actions as those that “require more reliance on humans,” namely double checks, warnings, a new policy or memorandum, and training. Teams “should identify at least one stronger or intermediate strength action for each RCA² review,” and weaker actions “are often necessary to establish proficiency and expectations, but when used alone are unlikely to be sufficient.” Second, there is a clock: a review “should be started within 72 hours of recognizing that a review is needed” and completion is expected within 30 to 45 days. Third, RCA² states its own limits — “the review is not to be used to focus on or address individual performance,” and team findings “must not be used to discipline or punish staff.” AHRQ’s own event investigation module, part of the CANDOR toolkit whose Expert Faculty included Dr. Krevat, goes further in the same direction and names each departure it makes: renaming the process “event investigation and analysis,” using “contributing factors” instead of “root causes,” and replacing the single meeting with a confirmation and consensus meeting followed by a solutions meeting. Its rationale is stated openly — most recommendations coming out of traditional reviews “focus on re-education, re-training, disciplinary actions, or the creation of new policies,” and “safety science shows that these types of recommendations do not consistently lead to sustained improvements.” Its framing rules are equally explicit: “the goal is fact finding, not fault finding,” interviewees “should not be accompanied by a supervisor,” and the patient and family are included in the interviews “because they often are the only people present throughout the entire course of events.” Follow-up meetings are set at 30, 60, and 90 days, with the patient and family updated on progress at each. Where a review is conducted under a listed Patient Safety Organization, the Patient Safety and Quality Improvement Act of 2005 makes the resulting patient safety work product privileged and confidential, and “subject to certain specific exceptions, PSWP may not be used in criminal, civil, administrative, or disciplinary proceedings.” That protection is one of three overlapping regimes — alongside state peer review and quality assurance privileges — and which applies depends on the forum and on how the work was actually organized.[7, 17, 32, 46]

Three clinicians conferring in a hospital corridor.
An event review is a team exercise: interviews, the timeline, and the difference between how the work was designed and how it was done.

CANDOR sets the sequence, the components, and the clock

CANDOR stands for Communication and Optimal Resolution. AHRQ describes it as “a process that health care institutions and practitioners can use to respond in a timely, thorough, and just way when unexpected events cause patient harm,” and contrasts it with a traditional “deny-and-defend” approach. It came out of the agency’s $25 million Patient Safety and Medical Liability Grant Initiative launched in 2009, which AHRQ calls “the largest Federal investment in research to test promising model programs to improve patient safety and reduce medical liability claims,” and was built by the Health Research & Educational Trust with the American Hospital Association and tested in 14 hospitals across three health systems. The process proper has five components: identification of a CANDOR event, system activation, response and disclosure, investigation and analysis, and resolution. A CANDOR event is defined as “an event that involves unexpected harm (physical, emotional, or financial) to a patient,” and such events “trigger the CANDOR process even when a cause for the event is not yet known.” The toolkit that teaches it has eight modules, running from organizational buy-in and gap analysis through care for the caregiver, resolution, and organizational learning. Two figures make the process checkable rather than rhetorical: “an initial disclosure conversation will occur within 60 minutes after the CANDOR event occurs,” and full disclosure follows the completed investigation, “which will take place within 30-45 days after the event occurred.” AHRQ tells adopting organizations that “it will take at least 12-18 months to implement the CANDOR process.” The distinction that decides matters is between an organization that has named CANDOR in a policy and one that has implemented it — the gap analysis, the disclosure communications, the event review files, and the qualifications of the person running the program all show which happened.[1, 2, 3, 16]

A physician and a nurse reviewing a chart together.
The CANDOR process runs from the first hours after an event through resolution and organizational learning.

What a full disclosure contains, and where state law requires it

Disclosure is not governed by the law of negligence, and the obligation does not come from one place. AHRQ states that “since 2001, the Joint Commission has required disclosure of unanticipated outcomes of care,” and that in 2010 the National Quality Forum endorsed disclosure of serious unanticipated outcomes as one of its 34 safe practices; accreditation manual text is revised between editions, so the current edition should be read rather than assumed. Where an organization has adopted a written disclosure policy of its own, that policy matters, because it is the institution’s own statement of what it believed it was required to do. On content, the research is consistent about what patients say a disclosure has to contain: disclosure of all harmful errors, an explanation of why the error occurred, how the error’s effects will be minimized, and the steps that will be taken to prevent recurrences — with “full disclosure” adding acknowledgement of responsibility and an apology. AHRQ is candid about the gap between agreement in principle and practice: “Many patients harmed by a medical error never learn of the error,” and physicians who agree errors should be disclosed often in practice “choose their words carefully” by failing to clearly explain the error and its effect on the patient’s health. Few physicians have had formal training in the conversation, and training improves their comfort with it. Five states require disclosure by law. Pennsylvania’s MCARE Act requires a medical facility to give a patient affected by a serious event written notification “within seven days of the occurrence or discovery of a serious event.” Nevada requires notice to each patient involved in a sentinel event “not later than 7 days after discovering or becoming aware of” it. Massachusetts requires a hospital, “within seven calendar days of the date of discovery” of a serious reportable event, to inform the patient orally or in writing. New Jersey’s Patient Safety Act, as enacted in 2004, requires a health care facility to assure that a patient affected by a serious preventable adverse event is informed “no later than the end of the episode of care.” Florida requires each licensed facility to inform the patient “in person about adverse incidents that result in serious harm to the patient.” Four other states took a different route, creating a voluntary communication-and-resolution process by statute: the provider or facility “may” initiate it, and the statute then supplies the clock and the confidentiality protections. Colorado’s is titled the Colorado CANDOR Act, C.R.S. Title 25, Article 51, effective July 1, 2019, with notice due “within one hundred eighty days after the date on which the health care provider knew, or through the use of diligence should have known, of the adverse health care incident,” and a requirement that the patient be told of the right to counsel throughout the process. Utah’s Medical Candor Act, Title 78B, Chapter 3, Part 4a, effective May 4, 2022, defines a four-step process — investigate, communicate what the investigation found, communicate the steps that will prevent recurrence, and determine whether to offer compensation — with notice due within 365 days. Iowa Code Chapter 135P, enacted in 2015, uses a one-year window and the same four steps. Oregon’s Early Discussion and Resolution statutes, ORS 31.260 to 31.278, route notices through the Oregon Patient Safety Commission, define the triggering incident more narrowly as one that is “unanticipated” and “usually preventable,” and, unlike the other three, expressly allow a discussion communication to be admitted where it contradicts later testimony and is material. In all four, open-discussion communications and offers of compensation do not constitute an admission of liability and are confidential and inadmissible. Outside these schemes the analysis is forum-specific: apology laws vary, and AHRQ notes that as of a 2008 survey only eight states explicitly barred admissions of fault from evidence at trial, while most exclude expressions of sympathy.[8, 15, 28, 29, 30, 31, 38, 39, 40, 41]

Resolution includes the bill, and the national standard says so in nine numbered lines

The Leapfrog Group’s Never Events Policy is voluntary — it binds no hospital by force of law — and it is the clearest written national statement of what a hospital should do when a serious reportable event occurs. A hospital meets the standard only if it commits to all nine: apologize to the patient and family; waive all costs directly related to the event; report the event to an external agency; conduct a root-cause analysis; interview patients and families, who are willing and able, to gather evidence for that analysis; inform the patient and family of the actions the hospital will take to prevent recurrence; have a protocol in place to support caregivers involved in never events and make it known to all caregivers and affiliated clinicians; perform an annual review of compliance with each element for each never event that occurred; and make a copy of the policy available to patients on request. Five were adopted in 2007 and four added in 2017 — interviewing patients and families, informing them of the prevention steps, the caregiver-support protocol, and the annual compliance review — and Leapfrog states the reason: AHRQ “developed, tested, and launched the CANDOR Toolkit,” and the National Patient Safety Foundation “gathered stakeholders to propose new approaches to performing root cause analysis.” Leapfrog’s fact sheet is more specific than the summary page: the hospital waives the costs directly related to the event “so that the patient and third-party payor do not receive a bill for those costs,” and external reporting is due within 15 business days of determining that a never event occurred. The underlying event list is the National Quality Forum’s 29 serious reportable events across seven categories. No federal statute prohibits the bill generally, but federal payment rules and one state reach part of it. Medicare does not cover a wrong surgical or other invasive procedure, surgery on the wrong body part, or surgery on the wrong patient, under national coverage determinations effective January 15, 2009, and CMS’s claims instructions state that “a provider cannot shift financial liability for the non-covered services to the beneficiary” without a valid advance notice — and that CMS “cannot envision a scenario in which HINNs or ABNs could be validly delivered in these NCD cases.” Federal Medicaid regulation requires that a state plan “provide that no medical assistance will be paid for ‘provider-preventable conditions,’” which include those three surgical events. Massachusetts goes furthest: a hospital “may not charge or seek reimbursement from a patient or responsible third-party payer” for services resulting from a serious reportable event on its premises that it determines was preventable and unambiguously the result of a system failure. CMS’s hospital-acquired conditions policy, enacted in the Deficit Reduction Act of 2005, provides that for discharges on or after October 1, 2008 hospitals “will not receive additional payment for cases in which one of the selected conditions was not present on admission,” across fourteen HAC categories — but the OIG found those lists narrow, with only 5 percent of the harm events it identified appearing on the HAC Reduction Program list and 2 percent on the Deficit Reduction Act list. Evidence on what a communication-and-resolution program does to liability exposure has accumulated in the same period and does not point where either side assumes: one academic health system’s claims rate fell from 7.03 to 4.52 per 100,000 patient encounters and its lawsuit rate from 2.13 to 0.75 after implementing full disclosure with offers of compensation, and a controlled study of four Massachusetts hospitals found that “none of the hospitals experienced worsening liability trends after CRP implementation.”[5, 6, 21, 22, 26, 27, 35, 37, 40, 42, 43, 44, 45]

Support for the clinicians involved is a formal component, not a courtesy

Albert Wu named the “second victim” phenomenon in 2000 to describe the clinician who is themselves harmed by involvement in an unanticipated adverse event. It is common rather than exceptional: in a survey of more than 3,000 physicians in the United States and Canada, 92 percent reported previous involvement in events ranging from near misses to serious errors, and 81 percent reported some degree of job-related stress linked to the event. The response has a published shape. Accreditation requires it: the Joint Commission's National Performance Goals for hospitals, effective January 2026, provide that “the leaders make support systems available for staff who have been involved in an adverse or sentinel event.” CANDOR makes Care for the Caregiver a formal module rather than an afterthought, and Leapfrog’s voluntary 2017 additions ask for a written support protocol that caregivers actually know about. AHRQ describes the University of Missouri three-tiered model as the reference design: unit-level support by colleagues and local leaders trained to recognize the response, expected to meet the needs of about 60 percent of involved clinicians; trained peer supporters embedded in high-risk units for about 30 percent; and facilitated access to professional counseling for about 10 percent. AHRQ is also candid that “the science behind interventions for second victims is in its infancy,” and that a study of Maryland hospitals found such services limited despite patient safety officers recognizing the need. An organization that supported the clinicians involved generally did so through a documented program, which makes this a checkable part of the response rather than a matter of impression.[2, 5, 9, 16, 35, 46]

A senior physician in a hospital corridor.
Care for the caregiver is a formal component of the standard, not a courtesy.

Diagnostic error often fails in the follow-up, not only in the reasoning

Diagnosis-related matters frequently turn on more than the differential. CRICO’s Diagnostic Process of Care framework finds follow-up and coordination failures — findings not communicated to the patient, follow-up testing not arranged, or follow-up not documented — in 46 percent of the diagnosis-related malpractice cases it analyzed, alongside initial assessment failures in 58 percent and testing and results-processing failures in 29 percent; a single case can fail at more than one step. Dr. Krevat’s study of closed malpractice claims found that of 122 claims in which the electronic health record was a potential contributing factor, 71.3 percent involved a missed or delayed diagnosis, 91.8 percent involved the testing stage of the diagnostic process, and 74.6 percent carried a documented judgment or settlement. The practical import is the same for both sides: these matters turn on the handoff, the result-routing configuration, the critical-value callback, and whether the loop was closed — questions a treating-specialty expert is rarely equipped to answer, and questions on which a well-run result-management system is equally capable of exonerating an organization.[11, 13]

Every assertion above is traced to its source

The Patient Safety Standards Project cites 46 primary sources. Each URL was checked before publication and is rechecked whenever these standards are revised. The numbered markers throughout this page link straight to the entry they rest on.

Request a Consultation