# IncidentKit: full text > Incident reporting and corrective-action software for healthcare and high-risk work. Free to start. Lauren, the AI assistant, drafts the report; a person signs. Generated from https://incidentkit.ai. Each section below is the markdown twin of one page. --- # IncidentKit: incident reporting that closes the loop > Free incident reporting for healthcare and high-risk work. Lauren drafts, a person signs. Investigations, fixes and audit-ready packets in one kit. Source: https://incidentkit.ai/ · Updated Oct 5, 2026 IncidentKit is incident reporting and corrective-action software for healthcare and high-risk work. Report it. Investigate it. Close it. Prove it. ## How it works 1. **Report.** Staff report by text, QR code or email (voice is rolling out). Lauren, the AI assistant, asks follow-up questions and drafts the report. A person reviews and signs. 2. **Investigate.** Contributing factors, five whys and a disposition on the same record. 3. **Correct.** Corrective actions with an owner, due date, evidence and an effectiveness check. 4. **Prove.** QAPI summaries, survey packets and audit trail from the record. OSHA 300, 300A and 301 are rolling out. ## Packs ### Healthcare - [Surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers): Log transfers and near misses between cases, and meet surveyors with every loop closed. - [Hospitals](https://incidentkit.ai/solutions/hospitals): Report fast, classify the same day, and show the board that every fix held. - [Skilled nursing](https://incidentkit.ai/solutions/skilled-nursing-facilities): Take a fall from first text to verified fix, with the abuse deadline flagged. - [Assisted living](https://incidentkit.ai/solutions/assisted-living): Log incidents and family calls the same shift, and keep a clean state record. - [Behavioral health](https://incidentkit.ai/solutions/behavioral-health): Capture elopement, restraint and self-harm events, route them fast, and show the fixes held. - [Hospice](https://incidentkit.ai/solutions/hospice): Nurses report from the driveway; the IDG takes each incident to a verified fix. - [Home health](https://incidentkit.ai/solutions/home-health): Report from the home and tie emergent care to a cause and verified fix. - [Urgent care and outpatient](https://incidentkit.ai/solutions/urgent-care-and-outpatient): Log EMS transfers between patients, then see the pattern and fix it across sites. ### Industry - [Manufacturing](https://incidentkit.ai/solutions/manufacturing): Report from the line, fix what caused it, and keep the OSHA log ready. (rolling out) - [Construction](https://incidentkit.ai/solutions/construction): A foreman texts a report from site, and safety sees every project and sub. (rolling out) - [Labs and pharma production](https://incidentkit.ai/solutions/laboratories-and-pharma-production): Technicians text in spills and exposures, and EHS and quality share one record. (rolling out) - [Warehousing and logistics](https://incidentkit.ai/solutions/warehousing-and-logistics): Workers text in near misses, strains and heat illness, and EHS spots patterns early. (rolling out) - [Food and beverage](https://incidentkit.ai/solutions/food-and-beverage-processing): Crews text in caught-in events and ammonia releases, and the plant closes each one. (rolling out) - [Chemical and process](https://incidentkit.ai/solutions/chemical-and-process-industries): Report from the unit, start the investigation within 48 hours, and close every fix. (rolling out) - [Utilities and energy](https://incidentkit.ai/solutions/utilities-and-energy): Crews text in incidents from the truck, and safety tracks every case across districts. (rolling out) ### Organizations - [Multi-site groups](https://incidentkit.ai/solutions/multi-site-groups): Every site reports and closes the same way, and corporate sees it all. - [Insurers and risk pools](https://incidentkit.ai/solutions/insurers-and-risk-pools): Insureds capture incidents early, so carriers get cleaner data and claims-ready files. (rolling out) - [Compliance consultants](https://incidentkit.ai/solutions/compliance-consultants): Keep every client survey-ready from one view, while each client owns its record. ### Roles - [EHS managers](https://incidentkit.ai/solutions/ehs-managers): Own the 300 Log with one record per injury and every deadline in view. - [Risk and quality leaders](https://incidentkit.ai/solutions/risk-and-quality-leaders): Event data that arrives structured and leaves as a QAPI committee packet. - [Directors of nursing](https://incidentkit.ai/solutions/directors-of-nursing): Complete reports, checked interventions and a QAA packet you present, not assemble. - [Facility administrators](https://incidentkit.ai/solutions/facility-administrators): Every report, deadline and action in one place, with numbers for your board. - [Plant managers](https://incidentkit.ai/solutions/plant-managers): Near misses, injuries and fixes in one record, tied to work orders. ## Pricing - **Open:** Free. For teams starting with workplace incidents and near misses. - **Regulated:** $750 per site, per month. For healthcare sites and any team that has to hold up in front of an auditor. - **Network:** Talk to us. For groups with 10 or more sites, health systems and management companies. Full details: https://incidentkit.ai/pricing --- # Incident reporting software pricing: free to start > IncidentKit is free for incidents without patient information. Pay per site for a BAA and audit-ready packets. No seats, modules or setup fee. Source: https://incidentkit.ai/pricing · Updated Oct 5, 2026 ## Open: Free For teams starting with workplace incidents and near misses. - Unlimited reporters - 50 incidents a month - Lauren intake, with a daily limit - Investigations and corrective actions - Standard PDF and CSV export ## Regulated: $750 per site, per month For healthcare sites and any team that has to hold up in front of an auditor. - Everything in Open - BAA, and patient information allowed - Lauren on a BAA-covered AI provider - QAPI summary packets (survey and OSHA packets rolling out) - Audit trail and retention controls - Done-for-you setup in 48 hours ## Network: Talk to us For groups with 10 or more sites, health systems and management companies. - Everything in Regulated - SSO and role templates - Organization-wide analytics - API and webhooks - Migration from your current system No seat fees, no module fees, no setup fee. Setup is included on Regulated and Network. List prices; annual and volume terms available. --- # About IncidentKit: built by survey-prep veterans > IncidentKit comes from the team behind PharmPro's consulting practice: 31 years in survey and inspection prep, and 250+ facilities taken through survey. Source: https://incidentkit.ai/about · Updated Oct 5, 2026 IncidentKit comes from the compliance team behind PharmPro's compliance consulting practice: 31 years in survey and inspection preparation and 250+ facilities taken through survey. --- # IncidentKit security overview > How IncidentKit protects incident data: access, audit logs, encryption and AI safeguards, with each control marked live, rolling out or planned. Source: https://incidentkit.ai/security · Updated Oct 5, 2026 Controls are marked Live, Rolling out or Planned on https://incidentkit.ai/security. We do not claim SOC 2 or HIPAA certification. Request the security packet at https://incidentkit.ai/security#packet. --- # HIPAA and BAA for incident reporting > What a BAA is, when an incident report needs one, how IncidentKit handles patient information and AI, and what we keep out of analytics. Source: https://incidentkit.ai/hipaa · Updated Oct 5, 2026 Incident reports at healthcare facilities often contain protected health information, so the vendor is a business associate and needs a signed BAA. IncidentKit signs a BAA on Regulated and Network plans, runs Lauren on a BAA-covered AI provider, and does not allow patient information on the free Open plan. There is no official HIPAA certification for software. --- # IncidentKit partner program > For compliance consultants, EHR and CMMS vendors, brokers and insurers: white-label packets, referral terms and early access to the carrier data feed. Source: https://incidentkit.ai/partners · Updated Oct 5, 2026 Open this page on the web: https://incidentkit.ai/partners --- # IncidentKit changelog > What shipped and what is rolling out at IncidentKit: new features, security work and fixes, each with a date and a plain description. Source: https://incidentkit.ai/changelog · Updated Oct 5, 2026 ## Shipped - **2026-10-05, New website and compliance library.** The site now has 23 solution pages and a sourced comparison matrix. It also has a cited compliance library, guides, templates and free calculators. Every page has a markdown copy for AI assistants. - **2026-09-22, MCP connector for AI assistants.** Assistants that support the Model Context Protocol can now work with incident records. The connector is scoped, and every action goes to the audit trail. - **2026-08-26, Self-service signup.** Teams can create an organization and a first site on their own. They can share a report link or QR code the same day. - **2026-08-25, One-time-code sign-in.** Reviewers and managers sign in with a code sent to their email. Sign-in is rate limited, and there are no shared passwords. - **2026-08-24, Restore drill and readiness review.** We ran a documented backup restore test. We also finished a readiness checklist for monitoring, secrets and access. Both came before we opened to customers. - **2026-08-21, Incident record v1.** One record now holds the report and the AI-drafted fields, with their approval state. It also holds the investigation, corrective actions and the audit trail. ## Rolling out - **Voice intake.** Report by talking to Lauren on a phone. You review the transcript before anything is saved. - **OSHA 300, 300A and 301 exports.** Build the logs and annual summary from the incident record. The recordability reasoning is shown. - **Spanish intake and reports.** Report in Spanish and review in English. Both versions stay on the record. - **Human-edited RCA templates.** Fishbone and five-whys templates for investigators. Lauren helps with drafts. - **Deeper integrations.** EHR, CMMS and HRIS connectors, SSO and a fuller API with signed webhooks. - **Industry packs beyond healthcare.** Packs for manufacturing, construction, labs, warehousing, food, chemicals and utilities. They ship one at a time. - **Insurer data feed.** An opt-in, aggregated feed for insurers and brokers, designed with early partners. --- # IncidentKit product: report, investigate, correct, prove > Fifteen parts that work off one incident record: AI intake, routing, investigations, corrective actions, compliance packets, audit trail and platform. Source: https://incidentkit.ai/product · Updated Oct 5, 2026 - [Lauren, the AI assistant](https://incidentkit.ai/product/lauren): Tell Lauren what happened. She asks, fills the form, and a person signs. - [Incident reporting](https://incidentkit.ai/product/incident-reporting): The full record holds who, what, where, harm, evidence and what happens next. - [Voice reporting](https://incidentkit.ai/product/voice-reporting): Talk instead of type. Built for busy hands and long shifts. - [QR and quick report](https://incidentkit.ai/product/quick-report): Scan a QR code, fill in three fields, and the incident is on record. - [Email-to-incident](https://incidentkit.ai/product/email-to-incident): Forward a complaint or vendor email and it becomes a draft incident. - [Mobile and offline](https://incidentkit.ai/product/mobile-and-offline): IncidentKit installs from the browser and is built for one-handed use. - [Routing and escalation](https://incidentkit.ai/product/routing-and-escalation): Severity decides who gets paged, and it escalates if nobody acts. - [Investigations and RCA](https://incidentkit.ai/product/investigations): A guided investigation: find causes, pick a disposition, and a person signs. - [Corrective actions (CAPA)](https://incidentkit.ai/product/corrective-actions): Every fix has an owner, a date and proof. Unverified fixes keep it open. - [Compliance packets](https://incidentkit.ai/product/compliance-packets): Records laid out the way surveyors and inspectors want them. - [Analytics](https://incidentkit.ai/product/analytics): See which rooms, shifts and equipment keep showing up in your incidents. - [Audit trail](https://incidentkit.ai/product/audit-trail): Every edit is logged, so you can show who changed what, and when. - [Multi-site and roles](https://incidentkit.ai/product/multi-site-and-roles): Run one program across many sites, with six roles and single sign-on. - [Integrations and API](https://incidentkit.ai/product/integrations-and-api): Read API, webhooks and SSO now. Deeper EHR, CMMS and HRIS links come later. - [Import and migration](https://incidentkit.ai/product/import-and-migration): Import past incidents from a spreadsheet, or we move them from your old system. --- # Product tour: one incident record, end to end > Follow a single incident from the first report to the audit packet, in four stages. The tour uses synthetic data and needs no signup. Source: https://incidentkit.ai/product/tour · Updated Oct 5, 2026 Open this page on the web: https://incidentkit.ai/product/tour --- # Incident reporting for healthcare and high-risk industries > Packs for surgery centers, hospitals, nursing homes, plants, job sites, labs and warehouses, plus multi-site groups, insurers and consultants. Source: https://incidentkit.ai/solutions · Updated Oct 5, 2026 ## Healthcare Reporting, QAPI and survey proof for every care setting. - [Surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers): Log transfers and near misses between cases, and meet surveyors with every loop closed. - [Hospitals](https://incidentkit.ai/solutions/hospitals): Report fast, classify the same day, and show the board that every fix held. - [Skilled nursing](https://incidentkit.ai/solutions/skilled-nursing-facilities): Take a fall from first text to verified fix, with the abuse deadline flagged. - [Assisted living](https://incidentkit.ai/solutions/assisted-living): Log incidents and family calls the same shift, and keep a clean state record. - [Behavioral health](https://incidentkit.ai/solutions/behavioral-health): Capture elopement, restraint and self-harm events, route them fast, and show the fixes held. - [Hospice](https://incidentkit.ai/solutions/hospice): Nurses report from the driveway; the IDG takes each incident to a verified fix. - [Home health](https://incidentkit.ai/solutions/home-health): Report from the home and tie emergent care to a cause and verified fix. - [Urgent care and outpatient](https://incidentkit.ai/solutions/urgent-care-and-outpatient): Log EMS transfers between patients, then see the pattern and fix it across sites. ## Industry Injury and OSHA records for plants and job sites. - [Manufacturing](https://incidentkit.ai/solutions/manufacturing): Report from the line, fix what caused it, and keep the OSHA log ready. - [Construction](https://incidentkit.ai/solutions/construction): A foreman texts a report from site, and safety sees every project and sub. - [Labs and pharma production](https://incidentkit.ai/solutions/laboratories-and-pharma-production): Technicians text in spills and exposures, and EHS and quality share one record. - [Warehousing and logistics](https://incidentkit.ai/solutions/warehousing-and-logistics): Workers text in near misses, strains and heat illness, and EHS spots patterns early. - [Food and beverage](https://incidentkit.ai/solutions/food-and-beverage-processing): Crews text in caught-in events and ammonia releases, and the plant closes each one. - [Chemical and process](https://incidentkit.ai/solutions/chemical-and-process-industries): Report from the unit, start the investigation within 48 hours, and close every fix. - [Utilities and energy](https://incidentkit.ai/solutions/utilities-and-energy): Crews text in incidents from the truck, and safety tracks every case across districts. ## Organizations One program for groups, insurers and consultants. - [Multi-site groups](https://incidentkit.ai/solutions/multi-site-groups): Every site reports and closes the same way, and corporate sees it all. - [Insurers and risk pools](https://incidentkit.ai/solutions/insurers-and-risk-pools): Insureds capture incidents early, so carriers get cleaner data and claims-ready files. - [Compliance consultants](https://incidentkit.ai/solutions/compliance-consultants): Keep every client survey-ready from one view, while each client owns its record. ## Roles What changes for the people who own incidents. - [EHS managers](https://incidentkit.ai/solutions/ehs-managers): Own the 300 Log with one record per injury and every deadline in view. - [Risk and quality leaders](https://incidentkit.ai/solutions/risk-and-quality-leaders): Event data that arrives structured and leaves as a QAPI committee packet. - [Directors of nursing](https://incidentkit.ai/solutions/directors-of-nursing): Complete reports, checked interventions and a QAA packet you present, not assemble. - [Facility administrators](https://incidentkit.ai/solutions/facility-administrators): Every report, deadline and action in one place, with numbers for your board. - [Plant managers](https://incidentkit.ai/solutions/plant-managers): Near misses, injuries and fixes in one record, tied to work orders. --- # Incident reporting use cases > How to run the jobs that incident data supports: near-miss reporting, survey readiness, CAPA closure, OSHA logs, falls, medication errors and more. Source: https://incidentkit.ai/use-cases · Updated Oct 5, 2026 - [How to replace paper incident forms](https://incidentkit.ai/use-cases/replace-paper-incident-forms): How to replace paper incident forms without losing reports: the fields to keep, how to pilot both side by side, and what changes for review and survey. - [How to build a near-miss reporting program](https://incidentkit.ai/use-cases/near-miss-reporting): How to run near-miss reporting people actually use: define it, keep the report short, triage by potential harm, fix the cause and tell the reporter. - [How to stay survey-ready every day](https://incidentkit.ai/use-cases/always-survey-ready): Stay survey-ready every day: what ASC and nursing home surveyors ask for first, the five records to keep current, and a 30-minute weekly routine. - [How to run QAPI committee meetings](https://incidentkit.ai/use-cases/qapi-committee-meetings): Run QAPI committee meetings that hold up in survey: who must attend, how often to meet, a standing agenda, the data to bring and minutes that show action. - [How to close corrective actions with proof](https://incidentkit.ai/use-cases/close-corrective-actions): How to close corrective actions properly: one owner and date, stronger fixes than retraining, evidence of completion and a dated check that the fix worked. - [How to report and review falls](https://incidentkit.ai/use-cases/fall-reporting): Fall reporting for nursing homes and hospitals: how CMS defines a fall, what to record after one, how to screen unwitnessed falls, and how to find patterns. - [How to report a medication error](https://incidentkit.ai/use-cases/medication-error-reporting): How to report a medication error: what to record, how to grade severity with the NCC MERP index, who to tell outside the facility, and how to fix the system. - [Abuse and neglect reporting deadlines for nursing homes](https://incidentkit.ai/use-cases/abuse-reporting-deadlines): Nursing home abuse reporting deadlines under 42 CFR 483.12: the 2-hour and 24-hour clocks, who to notify, injuries of unknown source, and the 5-day report. - [How to automate the OSHA 300 log without losing control of it](https://incidentkit.ai/use-cases/osha-300-log-automation): Keep the OSHA 300 log accurate year-round: the 7-day entry rule, a recordability path, the 300A summary, e-submission, and what is safe to automate. - [How to handle workplace injury reporting](https://incidentkit.ai/use-cases/workplace-injury-reporting): Workplace injury reporting step by step: set up a reporting procedure, decide OSHA reporting and recording, avoid discouraging reports, and fix the cause. - [How to run a root cause analysis that leads to action](https://incidentkit.ai/use-cases/root-cause-analysis): How to run root cause analysis that leads to action: when to do one, eight steps from timeline to fix, contributing factors, and why retraining rarely works. - [How to switch from legacy incident software](https://incidentkit.ai/use-cases/switch-from-legacy-incident-software): How to switch incident reporting software: what to export, contract checks, running old and new in parallel, importing history, and done-for-you migration. - [Contractor and visitor incidents: who reports and records what](https://incidentkit.ai/use-cases/contractor-and-visitor-incidents): Contractor and visitor incidents: who records an injury to a non-employee, how OSHA, patient safety and general liability differ, and what to log each time. - [How to set up workplace violence reporting](https://incidentkit.ai/use-cases/workplace-violence-reporting): Workplace violence reporting for hospitals, nursing homes, stores and plants: what to log, why incidents go unreported, and what OSHA, CMS and TJC ask. --- # Compliance library: CMS, accreditation and OSHA > Plain-language guides with sources on CMS QAPI, accreditation, nursing home F-tags, reporting deadlines, OSHA records and survey readiness. Source: https://incidentkit.ai/compliance · Updated Oct 5, 2026 ## CMS QAPI requirements by facility type QAPI is the quality program CMS requires of most providers, and the rule differs by facility type. - [What 42 CFR 416.43 requires of an ASC's QAPI program](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers): What 42 CFR 416.43 requires of an ASC's quality program, what surveyors ask to see, and how incident data and corrective actions feed it. - [Nursing home QAPI and the QAA committee under 42 CFR 483.75](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities): How 42 CFR 483.75 shapes a nursing home's QAPI plan and QAA committee: the five elements, what F865, F867 and F868 test, and what to show surveyors. - [Hospital QAPI under 42 CFR 482.21: what surveyors check](https://incidentkit.ai/compliance/cms-qapi/hospitals): What 42 CFR 482.21 requires of a hospital QAPI program, who is accountable, what surveyors sample, and how adverse event data and actions fit. - [Hospice QAPI under 42 CFR 418.58: requirements and evidence](https://incidentkit.ai/compliance/cms-qapi/hospice): What 42 CFR 418.58 requires of a hospice QAPI program, how to define and track adverse events, what surveyors review, and how incident data fits. - [Home health QAPI under 42 CFR 484.65: what an HHA must show](https://incidentkit.ai/compliance/cms-qapi/home-health): What 42 CFR 484.65 requires of a home health agency QAPI program: indicators and OASIS data, adverse events, projects, and what surveyors ask to see. ## Healthcare accreditation: AAAHC, Joint Commission Some accreditors can stand in for a state survey under CMS deemed status, and each works differently. - [AAAHC accreditation: what ASCs and ambulatory practices should know](https://incidentkit.ai/compliance/accreditation/aaahc): How AAAHC accreditation works for ASCs and ambulatory practices: Medicare deemed status, survey types, notice rules and the six-component QI study. - [Joint Commission accreditation: surveys, sentinel events and safety goals](https://incidentkit.ai/compliance/accreditation/joint-commission): How Joint Commission accreditation works: Medicare deemed status, unannounced surveys, tracers, the Sentinel Event Policy and the 2026 hospital goals. - [CIHQ accreditation: what hospitals and critical access hospitals should know](https://incidentkit.ai/compliance/accreditation/cihq): How CIHQ accreditation works for hospitals and critical access hospitals: CMS deemed status, three-year surveys and what CIHQ says it does not require. - [ACHC accreditation: programs, surveys and documentation](https://incidentkit.ai/compliance/accreditation/achc): How ACHC accreditation works for home health, hospice, ASCs and hospitals: CMS deemed status, unannounced surveys, timelines and what to keep on file. - [Quad A accreditation: surveys, standards and Patient Safety Data Reporting](https://incidentkit.ai/compliance/accreditation/quad-a): How Quad A accreditation works for office-based surgery and Medicare ASCs: three-year surveys, yearly self-surveys and quarterly safety data reports. - [DNV accreditation: CMS-approved programs, surveys and documentation](https://incidentkit.ai/compliance/accreditation/dnv): How DNV accreditation relates to CMS deemed status for hospitals, critical access hospitals and ASCs, what CMS checks, and what documentation to keep. - [CARF accreditation: what providers should know](https://incidentkit.ai/compliance/accreditation/carf): How CARF accreditation works for behavioral health, aging services and rehabilitation providers: announced peer surveys, the QIP and annual reporting. ## Nursing home F-tags: what each one means F-tags are CMS's numbered nursing home rules; these guides cover the ones incidents trigger, and the evidence you need. - [F689: free of accident hazards, supervision and devices](https://incidentkit.ai/compliance/f-tags/f689): F689 is the CMS nursing home tag for falls, hazards and supervision (42 CFR 483.25(d)). See what surveyors ask for, how severity is set and what to record. - [F600: free from abuse and neglect](https://incidentkit.ai/compliance/f-tags/f600): F600 is the CMS nursing home abuse and neglect tag under 42 CFR 483.12(a)(1). See what it covers, which records surveyors review and how severity is set. - [F609: reporting of alleged violations](https://incidentkit.ai/compliance/f-tags/f609): F609 sets nursing home reporting clocks for abuse, neglect and suspected crimes (42 CFR 483.12): 2 hours, 24 hours and 5 working days. See what to keep. - [F610: investigate, prevent and correct alleged violations](https://incidentkit.ai/compliance/f-tags/f610): F610 says nursing homes must investigate every abuse or neglect allegation, protect residents meanwhile and fix problems. See the clock and the evidence. - [F684: quality of care](https://incidentkit.ai/compliance/f-tags/f684): F684 is the CMS catch-all quality of care tag for nursing homes (42 CFR 483.25). See what it covers, how avoidable decline is judged, what to have ready. - [F760: residents are free of significant medication errors](https://incidentkit.ai/compliance/f-tags/f760): F760 says nursing home residents must be free of significant medication errors (42 CFR 483.45(f)(2)). See how significance is judged and what to keep. - [F880: infection prevention and control](https://incidentkit.ai/compliance/f-tags/f880): F880 is the most cited nursing home tag. See what 42 CFR 483.80 requires, what surveyors check, how severity is set and how to record incidents. - [F865: QAPI program and plan](https://incidentkit.ai/compliance/f-tags/f865): F865 requires a nursing home QAPI program and plan (42 CFR 483.75). See what surveyors ask for, what is protected from disclosure and the good faith rule. - [F867: QAPI/QAA improvement activities](https://incidentkit.ai/compliance/f-tags/f867): F867 requires nursing homes to track adverse events, find root causes, act on data and run an annual project (42 CFR 483.75(c)-(e)). See what to show. - [F868: the QAA committee](https://incidentkit.ai/compliance/f-tags/f868): F868 sets who must sit on a nursing home QAA committee and how often it meets (42 CFR 483.75(g), 483.80(c)). See the roster rules and what proof to keep. ## Incident reporting deadlines and obligations Some incidents start a clock; these pages say which ones, who must be told, and by when. - [Nursing home abuse and neglect reporting requirements](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting): Federal nursing home rules set a 2-hour or 24-hour clock to report abuse, neglect and suspected crimes, then 5 working days for investigation results. - [Joint Commission sentinel event policy: what to do and by when](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events): What the Joint Commission counts as a sentinel event, which events are reviewable, and the 45-business-day expectation for the analysis and action plan. - [ASC Quality Reporting Program (ASCQR): measures, deadlines and penalty](https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting): The ASC Quality Reporting Program cuts the Medicare payment update by 2.0 percentage points for non-reporting. See the 2026 measures and key deadlines. - [FDA medical device reporting for user facilities](https://incidentkit.ai/compliance/reporting-deadlines/device-adverse-event-reporting): Hospitals, ASCs and nursing homes must report device-related deaths and serious injuries within 10 work days and file an annual report by January 1. - [State adverse event and incident reporting: a verified overview](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview): A careful overview of state adverse event reporting in Pennsylvania, New York, Minnesota and Florida, and how to confirm your own state's rules. ## OSHA recordkeeping and workplace injury reporting Employers with more than ten employees keep injury records and report the most serious events within hours. - [OSHA recordkeeping: who keeps records, and what counts](https://incidentkit.ai/compliance/osha/recordkeeping-overview): Who must keep OSHA injury and illness records under 29 CFR Part 1904, who is partially exempt by size or industry, and what makes a case recordable. - [OSHA Form 300: the Log of Work-Related Injuries and Illnesses](https://incidentkit.ai/compliance/osha/osha-300-log): How to complete the OSHA Form 300 Log of Work-Related Injuries and Illnesses: one line per case, classification, privacy cases, day counts and updates. - [OSHA Form 301: the Injury and Illness Incident Report](https://incidentkit.ai/compliance/osha/osha-301-incident-report): What OSHA Form 301 asks, when it is due, which equivalent forms are accepted, and who is entitled to a copy of the injury and illness incident report. - [OSHA Form 300A: the annual Summary of Work-Related Injuries and Illnesses](https://incidentkit.ai/compliance/osha/osha-300a-summary): How to complete, certify and post the OSHA Form 300A summary: the February 1 to April 30 posting window, who may sign, hours worked and zero-case years. - [Recordable vs first aid: where OSHA draws the medical treatment line](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid): OSHA's first aid list is closed, and anything beyond it is medical treatment. See the list, the treatment line and worked examples of recordable cases. - [Reporting fatalities and severe injuries to OSHA (29 CFR 1904.39)](https://incidentkit.ai/compliance/osha/severe-injury-reporting): When and how to report a work-related death, in-patient hospitalization, amputation or loss of an eye to OSHA under 29 CFR 1904.39, with edge cases. - [Lockout/tagout (29 CFR 1910.147): the program and what to capture after an event](https://incidentkit.ai/compliance/osha/lockout-tagout): What a lockout/tagout program must include under 29 CFR 1910.147, how the annual inspection works, and what to capture after a hazardous energy event. - [Hazard communication (29 CFR 1910.1200): SDS, labels, training and incident records](https://incidentkit.ai/compliance/osha/hazard-communication): What OSHA's Hazard Communication Standard requires: written program, labels, safety data sheets and training, the 2026 to 2028 dates, and exposure records. - [Process safety incident investigation (29 CFR 1910.119(m))](https://incidentkit.ai/compliance/osha/process-safety-incident-investigation): What 29 CFR 1910.119(m) requires: which incidents, the 48-hour start, the team, report contents, documented resolution and five-year retention. - [Employee injury reporting and retaliation: 29 CFR 1904.35 and OSH Act section 11(c)](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation): What OSHA requires of an injury reporting system under 1904.35, what Section 11(c) bans, and how incentive programs and drug testing are treated. - [TRIR and DART rates: how to calculate them and what BLS 2024 national rates show](https://incidentkit.ai/compliance/osha/trir-and-dart-rates): How to calculate TRIR and DART with the 200,000-hour base, a worked example, and the BLS 2024 national incidence rates by industry, released January 2026. - [OSHA electronic submission (29 CFR 1904.41): who submits what, and when](https://incidentkit.ai/compliance/osha/electronic-submission): Who must send OSHA Forms 300A, 300 and 301 online, the March 2 deadline, size and industry thresholds, and how the Injury Tracking Application works. - [Construction recordkeeping: how OSHA Part 1904 applies to job sites and subcontractors](https://incidentkit.ai/compliance/osha/construction-recordkeeping): How 29 CFR Part 1904 applies to construction: job-site establishments, one log or many, subcontractors, work-zone reporting and electronic submission. ## Survey readiness: be ready every day The best survey prep never stops; these pages cover what surveys look like and the evidence to keep ready. - [ASC survey readiness: how to be ready every day](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness): How CMS, state and accreditor surveys of surgery centers work, what surveyors request on day one, and a checklist to stay ready every day. - [Nursing home recertification survey: what happens and what to have ready](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey): How CMS's standard health survey of a nursing home works, what incident and QAPI records surveyors request, and the new risk-based survey option. - [Plan of correction: what CMS requires and how to write one that is accepted](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction): How to answer a CMS-2567: the 10-calendar-day deadline, the five elements of an acceptable nursing home plan, ASC requirements and how to write one. - [Joint Commission survey readiness: unannounced surveys and tracers](https://incidentkit.ai/compliance/survey-readiness/joint-commission-survey-readiness): How Joint Commission surveys work: unannounced timing, tracer methodology, what changed under Accreditation 360 in 2026, and how to stay ready all year. --- # Compare incident reporting software: the full matrix > IncidentKit vs RLDatix, Origami Risk, VelocityEHS, Cority, Intelex, Mitti (ex-SafetyCulture) and more, feature by feature, with sources and dates. Source: https://incidentkit.ai/compare · Updated Oct 5, 2026 ## Feature matrix | Feature | IncidentKit | RLDatix | Origami Risk | Riskonnect | symplr | MedTrainer | Performance Health Partners | ASC WebQI | VelocityEHS | Cority | Intelex (Fortive) | SafetyCulture (now Mitti) | Benchmark Gensuite | EHS Insight | Safesite | Vector Solutions | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | Self-serve start | Yes | No | No | No | No | No | No | Partial | No | No | Partial | Yes | No | Partial | Yes | No | | Public pricing | Yes | No | No | No | No | No | No | No | No | No | Partial | Yes | No | Partial | Yes | No | | Free plan | Yes | No | Not stated publicly | Not stated publicly | Not stated publicly | No | Not stated publicly | No | No | No | No | Yes | No | No | Yes | No | | AI-assisted intake | Yes | Yes | Not stated publicly | Partial | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Partial | Partial | Yes | Yes | Yes | Partial | Not stated publicly | Partial | | Voice reporting | Rolling out | Partial | Not stated publicly | Partial | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Yes | Yes | Yes | Not stated publicly | Not stated publicly | Not stated publicly | | Mobile and QR reporting | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | | Investigation and RCA tools | Partial | Yes | Yes | Yes | Yes | Not stated publicly | Yes | Not stated publicly | Yes | Yes | Yes | Yes | Yes | Yes | Partial | Yes | | Corrective action (CAPA) workflow | Yes | Yes | Yes | Yes | Yes | Partial | Yes | Partial | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | | QAPI and accreditation reporting | Yes | Partial | Partial | Partial | Not stated publicly | Partial | Partial | Yes | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | | OSHA 300, 300A, 301 support | Rolling out | Not stated publicly | Yes | Yes | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Yes | Partial | Yes | Yes | Yes | Yes | Partial | Yes | | Multi-site and roles | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | Yes | | Open API | Partial | Yes | Yes | Partial | Not stated publicly | Partial | Not stated publicly | Not stated publicly | Partial | Yes | Yes | Yes | Yes | Yes | Not stated publicly | Partial | | HIPAA BAA available | Yes | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | "Not stated publicly" is not the same as no. Each vendor page lists sources and the date checked. ## Detailed comparisons - [IncidentKit vs RLDatix: honest comparison](https://incidentkit.ai/compare/rldatix): How IncidentKit and RLDatix differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs Origami Risk: honest comparison](https://incidentkit.ai/compare/origami-risk): How IncidentKit and Origami Risk differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs Riskonnect: honest comparison](https://incidentkit.ai/compare/riskonnect): How IncidentKit and Riskonnect differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs symplr: honest comparison](https://incidentkit.ai/compare/symplr): How IncidentKit and symplr differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs MedTrainer: honest comparison](https://incidentkit.ai/compare/medtrainer): How IncidentKit and MedTrainer differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs Performance Health Partners: honest comparison](https://incidentkit.ai/compare/performance-health-partners): How IncidentKit and Performance Health Partners differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs ASC WebQI: honest comparison](https://incidentkit.ai/compare/asc-webqi): How IncidentKit and ASC WebQI differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs VelocityEHS: honest comparison](https://incidentkit.ai/compare/velocityehs): How IncidentKit and VelocityEHS differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs Cority: honest comparison](https://incidentkit.ai/compare/cority): How IncidentKit and Cority differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs Intelex (Fortive): honest comparison](https://incidentkit.ai/compare/intelex): How IncidentKit and Intelex (Fortive) differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs SafetyCulture (now Mitti): honest comparison](https://incidentkit.ai/compare/safetyculture): How IncidentKit and SafetyCulture (now Mitti) differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs Benchmark Gensuite: honest comparison](https://incidentkit.ai/compare/benchmark-gensuite): How IncidentKit and Benchmark Gensuite differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs EHS Insight: honest comparison](https://incidentkit.ai/compare/ehs-insight): How IncidentKit and EHS Insight differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs Safesite: honest comparison](https://incidentkit.ai/compare/safesite): How IncidentKit and Safesite differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs Vector Solutions: honest comparison](https://incidentkit.ai/compare/vector-solutions): How IncidentKit and Vector Solutions differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. - [IncidentKit vs paper and spreadsheets: honest comparison](https://incidentkit.ai/compare/paper-and-spreadsheets): How IncidentKit and Paper and spreadsheets differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. --- # Incident reporting software alternatives > Alternatives to the major incident, risk and EHS platforms: who each option suits, what to look for, and how a switch works. Fair to the vendor you leave. Source: https://incidentkit.ai/alternatives · Updated Oct 5, 2026 - [RLDatix alternatives: what to weigh](https://incidentkit.ai/alternatives/rldatix): Considering a move from RLDatix? What to look for in an alternative, who each option suits, and how migration works. - [Origami Risk alternatives: what to weigh](https://incidentkit.ai/alternatives/origami-risk): Considering a move from Origami Risk? What to look for in an alternative, who each option suits, and how migration works. - [Riskonnect alternatives: what to weigh](https://incidentkit.ai/alternatives/riskonnect): Considering a move from Riskonnect? What to look for in an alternative, who each option suits, and how migration works. - [symplr alternatives: what to weigh](https://incidentkit.ai/alternatives/symplr): Considering a move from symplr? What to look for in an alternative, who each option suits, and how migration works. - [MedTrainer alternatives: what to weigh](https://incidentkit.ai/alternatives/medtrainer): Considering a move from MedTrainer? What to look for in an alternative, who each option suits, and how migration works. - [Performance Health Partners alternatives: what to weigh](https://incidentkit.ai/alternatives/performance-health-partners): Considering a move from Performance Health Partners? What to look for in an alternative, who each option suits, and how migration works. - [ASC WebQI alternatives: what to weigh](https://incidentkit.ai/alternatives/asc-webqi): Considering a move from ASC WebQI? What to look for in an alternative, who each option suits, and how migration works. - [VelocityEHS alternatives: what to weigh](https://incidentkit.ai/alternatives/velocityehs): Considering a move from VelocityEHS? What to look for in an alternative, who each option suits, and how migration works. - [Cority alternatives: what to weigh](https://incidentkit.ai/alternatives/cority): Considering a move from Cority? What to look for in an alternative, who each option suits, and how migration works. - [Intelex (Fortive) alternatives: what to weigh](https://incidentkit.ai/alternatives/intelex): Considering a move from Intelex (Fortive)? What to look for in an alternative, who each option suits, and how migration works. - [SafetyCulture (now Mitti) alternatives: what to weigh](https://incidentkit.ai/alternatives/safetyculture): Considering a move from SafetyCulture (now Mitti)? What to look for in an alternative, who each option suits, and how migration works. - [Benchmark Gensuite alternatives: what to weigh](https://incidentkit.ai/alternatives/benchmark-gensuite): Considering a move from Benchmark Gensuite? What to look for in an alternative, who each option suits, and how migration works. - [EHS Insight alternatives: what to weigh](https://incidentkit.ai/alternatives/ehs-insight): Considering a move from EHS Insight? What to look for in an alternative, who each option suits, and how migration works. - [Safesite alternatives: what to weigh](https://incidentkit.ai/alternatives/safesite): Considering a move from Safesite? What to look for in an alternative, who each option suits, and how migration works. - [Vector Solutions alternatives: what to weigh](https://incidentkit.ai/alternatives/vector-solutions): Considering a move from Vector Solutions? What to look for in an alternative, who each option suits, and how migration works. --- # Guides to incident reporting, QAPI, RCA and OSHA > In-depth guides with sources on incident reporting, QAPI, root cause analysis and CAPA, survey readiness, near misses, OSHA records and software choice. Source: https://incidentkit.ai/guides · Updated Oct 5, 2026 - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare): What a healthcare incident report is, what to report, who files it, which deadlines apply and how to build reporting that people actually use. - [QAPI program guide: surgery centers, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide): How the CMS QAPI requirement works for surgery centers, nursing homes and hospitals: elements, committees, data, projects, survey evidence and pitfalls. - [Root cause analysis and CAPA: a practical guide to strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide): How to run root cause analysis, pick a method, and write CAPA that works, using the action hierarchy of stronger, intermediate and weaker actions. - [Survey and accreditation readiness: a practical guide](https://incidentkit.ai/guides/survey-and-accreditation-readiness): How to stay survey-ready every day: survey frequency, what surveyors ask for first, evidence, mock surveys and how incident data helps. - [Near-miss reporting and safety culture: a practical guide](https://incidentkit.ai/guides/near-miss-reporting-and-safety-culture): Why near misses matter, how just culture and feedback loops raise reporting, and practical steps with healthcare and industrial examples. - [OSHA recordkeeping guide: the Part 1904 system, end to end](https://incidentkit.ai/guides/osha-recordkeeping-guide): How OSHA injury and illness recordkeeping works under 29 CFR Part 1904: who must keep records, recordability, forms, deadlines and electronic submission. - [Incident management software buyer's guide](https://incidentkit.ai/guides/incident-management-software-buyers-guide): How to evaluate incident reporting software: a requirements checklist, RFP and security questions, adoption, total cost and common pitfalls. - [AI for incident reporting: what it can and cannot safely do](https://incidentkit.ai/guides/ai-for-incident-reporting): What AI can and cannot safely do in incident intake and investigation: human review, hallucination risk, HIPAA, audit trails and vendor questions. --- # Incident reporting blog > Short, answer-first articles on incident reports, sentinel events, root cause methods, plans of correction, OSHA recordability and more. Source: https://incidentkit.ai/blog · Updated Oct 5, 2026 - [How AI intake changes incident reporting](https://incidentkit.ai/blog/how-ai-intake-changes-incident-reporting): AI intake swaps a long form for a conversation. See how it differs from forms, what the studies show, where human review fits and what to watch for. - [Incident reporting software pricing models: what each one does to your bill](https://incidentkit.ai/blog/incident-reporting-software-pricing-models): Incident reporting software is priced per seat, module, site, bed or by enterprise contract. See what each does to total cost and which questions to ask. - [What to put in a plan of correction](https://incidentkit.ai/blog/what-to-put-in-a-plan-of-correction): A plan of correction answers each CMS-2567 citation: what you will fix, how, who owns it, by when and how you will check. See the elements and a skeleton. - [First aid vs medical treatment: where OSHA draws the recordability line](https://incidentkit.ai/blog/first-aid-vs-medical-treatment-osha): OSHA's first-aid list is closed: anything not on it is medical treatment and makes an injury recordable. See the 14 items, real cases and other triggers. - [AAAHC vs Joint Commission for ASCs: a fair comparison](https://incidentkit.ai/blog/aaahc-vs-joint-commission-for-ascs): AAAHC and the Joint Commission both hold CMS deeming authority for ASCs. Compare survey style, standards focus, fee drivers and what stays the same. - [What is a sentinel event?](https://incidentkit.ai/blog/what-is-a-sentinel-event): A sentinel event is a patient safety event that reaches a patient and causes death, severe or permanent harm. See the definition, examples and first steps. - [How to get staff to report near misses](https://incidentkit.ai/blog/how-to-get-staff-to-report-near-misses): Staff report near misses when it is quick, safe and visibly useful. See the barriers, a just culture in practice, a 90-second report and what leaders say. - [Five whys vs fishbone vs fault tree: how to choose a root cause method](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree): Five whys, fishbone and fault tree answer different questions. See when each works, where it falls short, a worked example and how to get past human error. - [How to write an incident report](https://incidentkit.ai/blog/how-to-write-an-incident-report): Write an incident report as plain facts: what you saw, what you did, who was told. See the elements, a good and a poor example, and what to leave out. - [Incident report vs variance report vs occurrence report: what is the difference?](https://incidentkit.ai/blog/incident-report-vs-variance-report-vs-occurrence-report): Incident, variance and occurrence reports are mostly one document under different names. See what each captures and when the law cares about the label. --- # Incident reporting glossary > Plain, sourced definitions of adverse events, near misses, sentinel events, QAPI, CAPA, F-tags, OSHA recordables, TRIR, DART and more. Source: https://incidentkit.ai/glossary · Updated Oct 5, 2026 - [Adverse event](https://incidentkit.ai/glossary/adverse-event): An adverse event is patient harm caused by care, not by the illness. Groups define it a bit differently, so say which one you use. - [Near miss](https://incidentkit.ai/glossary/near-miss): A near miss is an event that could have hurt someone but did not. Someone caught it in time, or it missed by chance. OSHA calls it a close call. - [Sentinel event](https://incidentkit.ai/glossary/sentinel-event): A sentinel event is a patient safety event that reaches a patient and causes death, severe harm or permanent harm. That is the Joint Commission's meaning. - [Never event](https://incidentkit.ai/glossary/never-event): Never events are serious patient safety events that should never happen, like surgery on the wrong body part. The NQF list has 29 of them. - [Variance report](https://incidentkit.ai/glossary/variance-report): A variance report is a hospital's record of care that went off plan, like a wrong dose. Many places treat it as an incident report. - [Incident report](https://incidentkit.ai/glossary/incident-report): An incident report is a written record of an unplanned event that hurt, or could have hurt, a person or property. It starts the review. - [QAPI](https://incidentkit.ai/glossary/qapi): QAPI (quality assurance and performance improvement) is the quality program CMS requires. Providers use data to track harm and fix root causes. - [QAA committee](https://incidentkit.ai/glossary/qaa-committee): The QAA (quality assessment and assurance) committee runs a nursing home's QAPI quality program. It meets at least every quarter, as CMS requires. - [Performance improvement project](https://incidentkit.ai/glossary/performance-improvement-project): A performance improvement project (PIP) is a focused effort to fix one specific problem. It uses data to find causes, test changes and measure results. - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis): Root cause analysis (RCA) finds why a serious event happened, so fixes hit causes, not symptoms. It looks at the system, not at blame. - [Corrective and preventive action](https://incidentkit.ai/glossary/corrective-and-preventive-action): CAPA (corrective and preventive action) fixes the cause of a problem, then checks that the fix worked. Healthcare rules often say corrective action. - [Effectiveness review](https://incidentkit.ai/glossary/effectiveness-review): An effectiveness review checks that a fix worked and the problem did not return. A measure and a date set in advance let the action close. - [Just culture](https://incidentkit.ai/glossary/just-culture): Just culture is a safety approach that treats honest error, risky shortcuts and reckless acts differently. Staff can report mistakes without fear. - [Harm scale](https://incidentkit.ai/glossary/harm-scale): A harm scale ranks how much harm an event caused, from none up to death. No scale is universal. Common ones are the NCC MERP index and the CMS grid. - [Patient safety organization](https://incidentkit.ai/glossary/patient-safety-organization): A patient safety organization (PSO) is a group HHS lists to collect and study safety data. Data sent to it can be legally protected. - [F-tag](https://incidentkit.ai/glossary/f-tag): An F-tag is a code CMS uses to cite nursing home survey findings, like F689 for accidents. Each tag links to a rule in 42 CFR Part 483. - [Deficiency](https://incidentkit.ai/glossary/deficiency): A deficiency is a failure to meet a Medicare or Medicaid rule. A surveyor, or inspector, lists it on Form CMS-2567 and nursing homes get a score. - [Immediate jeopardy](https://incidentkit.ai/glossary/immediate-jeopardy): Immediate jeopardy (IJ) means a provider's failure has caused, or will likely cause, serious harm or death. It is the most serious kind of deficiency. - [CMS-2567](https://incidentkit.ai/glossary/cms-2567): Form CMS-2567 lists each Medicare or Medicaid rule a provider missed. The provider replies on it with a plan to fix them. The public can see it. - [Plan of correction](https://incidentkit.ai/glossary/plan-of-correction): A plan of correction (PoC) is a provider's written answer to survey findings. It says how and by when the facility will fix each problem and keep it fixed. - [Deemed status](https://incidentkit.ai/glossary/deemed-status): Deemed status means CMS lets a provider pass an outside group's survey in place of a state survey. The group must be one CMS has approved. - [Conditions for coverage](https://incidentkit.ai/glossary/conditions-for-coverage): Conditions for coverage (CfCs) are health and safety rules for some Medicare suppliers, like surgery centers. Hospitals have CoPs, the same idea. - [OSHA recordable injury](https://incidentkit.ai/glossary/osha-recordable): A recordable injury is a new, work-related injury or illness that OSHA says you must log. Care beyond first aid, or lost work time, usually makes it one. - [First aid (OSHA recordkeeping)](https://incidentkit.ai/glossary/first-aid): For OSHA recordkeeping, first aid is only the care on its closed list, like bandages or cleaning a wound. First aid alone is not recordable. - [DART rate](https://incidentkit.ai/glossary/dart-rate): The DART rate counts OSHA cases with days away, restricted work or job transfer per 100 full-time workers. The formula is cases × 200,000 ÷ hours worked. - [TRIR (total recordable incident rate)](https://incidentkit.ai/glossary/trir): TRIR (total recordable incident rate) counts recordable injuries and illnesses per 100 full-time workers a year. OSHA calls it the total case rate. - [LTIR (lost-time injury rate)](https://incidentkit.ai/glossary/ltir): LTIR (lost-time injury rate) counts injuries that cost workdays per set block of hours. OSHA does not use the term, so confirm the formula before you compare. - [Lost-time injury](https://incidentkit.ai/glossary/lost-time-injury): A lost-time injury is a work injury or illness that keeps a worker home past the day it happened. OSHA's term for it is a days-away case. - [PSIF (potential serious injury or fatality)](https://incidentkit.ai/glossary/psif): PSIF means potential serious injury or fatality: an event that could have caused death or life-changing harm. It is a safety term, not an OSHA category. - [Hierarchy of controls](https://incidentkit.ai/glossary/hierarchy-of-controls): The hierarchy of controls ranks ways to reduce a hazard, from strongest to weakest. NIOSH puts removing the hazard first and protective gear last. - [Lockout/tagout](https://incidentkit.ai/glossary/lockout-tagout): Lockout/tagout (LOTO) means cutting a machine's power and locking or tagging the switch before repairs. OSHA's standard is 29 CFR 1910.147. - [ASCQR (ASC Quality Reporting Program)](https://incidentkit.ai/glossary/ascqr): ASCQR is the CMS quality reporting program for surgery centers. Centers that do not report take a 2.0 point cut in their Medicare payment update. - [AAAHC](https://incidentkit.ai/glossary/aaahc): AAAHC is a group that accredits, or formally approves, outpatient care sites like surgery centers and endoscopy centers. It began in 1979. - [Joint Commission](https://incidentkit.ai/glossary/joint-commission): The Joint Commission is a US group that accredits hospitals, outpatient, nursing care and home care sites. It also sets the Sentinel Event Policy. - [Five whys](https://incidentkit.ai/glossary/five-whys): Five whys is a way to find a root cause. Ask why a problem happened, then why again for each answer, until you reach a cause you can fix. - [Fishbone diagram](https://incidentkit.ai/glossary/fishbone-diagram): A fishbone diagram maps the possible causes of one problem on branches, like fish bones. Teams also call it a cause-and-effect or Ishikawa diagram. - [Fault tree analysis](https://incidentkit.ai/glossary/fault-tree-analysis): Fault tree analysis (FTA) starts from a bad outcome and maps the combinations of failures that could cause it. OSHA lists it for process hazard analysis. - [Risk matrix](https://incidentkit.ai/glossary/risk-matrix): A risk matrix scores a hazard by crossing how bad the outcome could be with how likely it is. The score sets which problems to fix first. - [Safety data sheet](https://incidentkit.ai/glossary/safety-data-sheet): A safety data sheet (SDS) is a 16-section document on a chemical's hazards and safe handling. Employers must keep one for each hazardous chemical they use. - [Workers' compensation](https://incidentkit.ai/glossary/workers-compensation): Workers' compensation is insurance that pays medical care and lost wages for employees hurt or made ill by work. Each state runs it for private employers. - [FROI (First Report of Injury)](https://incidentkit.ai/glossary/froi): FROI, the First Report of Injury, is the first report of a work injury sent to the workers' compensation insurer. It opens the claim. - [Business associate agreement](https://incidentkit.ai/glossary/business-associate-agreement): A business associate agreement (BAA) is the contract HIPAA requires when a vendor handles patient health data for a provider. It sets the vendor's duties. - [Protected health information (PHI)](https://incidentkit.ai/glossary/phi): Protected health information (PHI) is health data that identifies a person. HIPAA covers it when a provider, plan or their vendor holds it. - [Medication error](https://incidentkit.ai/glossary/medication-error): A medication error is a preventable event that may lead to wrong medication use or harm (NCC MERP). CMS adds its own wording for nursing homes. - [Elopement](https://incidentkit.ai/glossary/elopement): Elopement is when a patient or resident slips out of a facility without staff knowing, when supervision is needed. CMS cites it at F689. - [Pressure injury](https://incidentkit.ai/glossary/pressure-injury): A pressure injury is skin and tissue damage from steady pressure, often over a bone. CMS treats it as the same as a pressure ulcer and cites F686. --- # Free incident report templates > Printable incident, fall, medication error, near-miss, RCA, CAPA and QAPI templates, ready to use and built on what surveyors expect. Source: https://incidentkit.ai/templates · Updated Oct 5, 2026 - [ASC incident report template](https://incidentkit.ai/templates/asc-incident-report): Printable incident report for ambulatory surgery centers: patient, phase of care, harm level, notifications and the first-pass review that feeds QAPI. - [Nursing home incident report template](https://incidentkit.ai/templates/nursing-home-incident-report): Printable nursing home incident report with physician and family notice, an abuse screen tied to the 2-hour and 24-hour clocks, and investigation steps. - [Fall incident report template](https://incidentkit.ai/templates/fall-incident-report): Printable fall incident report: witnessed or unwitnessed, pre-fall activity, footwear, assistive device, injury, notifications and a post-fall huddle. - [Medication error report template](https://incidentkit.ai/templates/medication-error-report): Printable medication error report: drug, dose and route, which rights were missed, NCC MERP harm category, contributing factors and who was notified. - [Workplace injury report template](https://incidentkit.ai/templates/workplace-injury-report): Workplace injury and illness report template covering the information OSHA Form 301 asks for, plus cause, treatment, recordability and corrective action. - [Near miss report template](https://incidentkit.ai/templates/near-miss-report): Short near miss report template for healthcare and industrial sites: what almost happened, what stopped it, how bad it could be, and a suggested fix. - [Root cause analysis worksheet](https://incidentkit.ai/templates/root-cause-analysis-worksheet): Root cause analysis worksheet with a timeline, five whys, contributing-factor categories and an action hierarchy so fixes are strong, owned and dated. - [Corrective action plan template](https://incidentkit.ai/templates/corrective-action-plan): Corrective action plan template with owner, due date, evidence of completion and an effectiveness check, so no action closes until it is verified. - [QAPI meeting agenda and minutes template](https://incidentkit.ai/templates/qapi-meeting-agenda-and-minutes): QAPI committee agenda and minutes template: attendance, data, PIPs, decisions with owners, and the governing body report for nursing homes and ASCs. --- # Free tools: TRIR calculator, ASCQR, survey check > Free calculators and checklists: TRIR and DART rates, ASCQR payment impact, the cost of an incident, and a survey-readiness check. Source: https://incidentkit.ai/tools · Updated Oct 5, 2026 - [TRIR and DART calculator](https://incidentkit.ai/tools/trir-dart-calculator): Work out your total recordable incident rate (TRIR) and DART rate with the OSHA formula, and learn how to read them. Free, no signup. - [ASCQR payment update calculator](https://incidentkit.ai/tools/ascqr-penalty-calculator): Estimate what a 2 percentage point cut to your ASC's annual Medicare payment update could cost if you miss quality reporting. Free, no signup. - [Incident reporting time and cost calculator](https://incidentkit.ai/tools/incident-cost-calculator): Estimate the staff hours and dollars your team spends filing, routing, investigating and reporting incidents, and what faster intake could save. - [Survey readiness check](https://incidentkit.ai/tools/survey-readiness-check): A 20-question self-check on the incident, QAPI and corrective-action evidence surveyors ask for. Score your readiness and see where to start. --- # Lauren asks until the report holds up. > Lauren is IncidentKit's AI assistant. She asks follow-up questions, fills in the report and drafts contributing factors. Every field she writes stays a draft until a person approves it. Source: https://incidentkit.ai/product/lauren · Updated Oct 5, 2026 **Lauren, the AI assistant** (report): Tell Lauren what happened. She asks, fills the form, and a person signs. ## What it does - **Follow-up questions, not a 14-field form** She asks one or two questions at a time, and stops when a reviewer would be satisfied. - **Fields filled as you talk** Date, time, place, people, harm, near-miss status and type fill in beside the chat. - **Drafts are marked as drafts** Every AI-written field and suggested action says “Lauren · draft” until a person approves it. - **A person signs** Nothing becomes the record until the reporter attests and a reviewer approves. Lauren's write actions need approval too. - **Investigation drafts** Lauren drafts contributing factors, a five-whys chain and corrective actions for the investigator to edit. - **Facility memory and weekly digests** Lauren can remember approved room names, equipment and routing choices, and send leaders a weekly risk digest. - **Voice and more languages** (rolling out) Voice intake and Spanish and other languages are rolling out. ## How it works 1. **Describe what happened** Type it in plain words. 2. **Answer two or three questions** Lauren asks for what is missing: place, harm, equipment, witnesses. 3. **Review and sign** Check the fields, fix any, and attest. 4. **Route and investigate** People are told by severity. Lauren drafts the investigation. ## What Lauren does. What she never does. **What she does** - **Asks like a risk manager.** One or two questions at a time, and only what is missing. - **Fills the report.** Date, time, place, people, harm and type, from what the reporter said. - **Drafts the investigation.** Contributing factors, a five-whys chain and corrective actions to edit. - **Marks her work.** Every field she writes says “Lauren · draft” until a person approves it. - **Remembers your site.** Approved room names, equipment and routing choices. - **Sends a weekly digest.** A short risk summary for the people who lead the site. **What she never does** - **Sign for a person.** The reporter attests. A reviewer approves. - **Change the record alone.** Her write actions need approval too. - **Decide what happened.** Her investigation drafts are suggestions, not conclusions. - **Close an action.** Closing takes a person and proof. - **Train on your data.** On Regulated and Network, her AI provider may not. - **Work in secret.** On Regulated and Network, her inputs and outputs go to the audit trail. ## Four steps from a text to a signed report. 1. **She reads what was said.** The reporter writes it the way they would say it. There is no form to learn. Example, T. Okafor · CNA: “Found Mrs. K on the floor between the bed and the bathroom at 2:47. She's awake and says her hip hurts.” 2. **She asks only what is missing.** She stops when a reviewer would be satisfied, not when a long form is full. Example, Lauren: “Is a nurse with her, and has she been assessed? Was the fall witnessed?” 3. **She drafts, and says so.** She fills fields only from what the reporter said. Each one is marked as a draft. Example, Draft fields: “Type: Fall, unwitnessed. Harm: possible injury, being assessed.” 4. **People review and sign.** Nothing becomes the record until the reporter attests and a reviewer approves. Example, Sign-off: “Attested by T. Okafor. Approved by R. Nguyen.” ## A draft is never the record until someone says so. Edit her words and the record keeps both versions, with the name of who changed what. Lauren's draft: “The bed alarm did not sound.” In the record: “The bed alarm was silenced during room cleaning.” Approved · R. Nguyen · 8:02 am. - 7:53 am: Lauren drafted “Contributing factor” from the report - 8:01 am: R. Nguyen edited the text - 8:02 am: R. Nguyen approved it ## A short path, with a contract on it. Your staff (Report by text or QR code.) to IncidentKit (Hosted in the United States.) to AI provider (Signs a BAA. May not train on your data.). - **Identifiers are minimized first.** Direct identifiers are reduced before text reaches the provider. - **Nothing you enter trains a model.** Her provider is not allowed to use it for training. - **Inputs and outputs are logged.** You can see what she was given and what she wrote. - **Open.** For incidents with no patient information. Patient information is not allowed in reports. - **Regulated and Network.** Patient information is allowed, under a BAA that covers the app and the AI provider. ## Plan for wrong. Plan for down. - **If she is wrong.** Language models can make things up. That is why a person reviews every draft before it counts, and why she fills fields only from what the reporter said. - **If you disagree.** Edit the draft or delete it. The record keeps your version and shows who approved it. - **If the AI service is down.** Reporting keeps working. Staff use the standard form or quick report, and Lauren's drafts pick up again later. Rolling out: Voice reporting, Spanish and other languages, Human-authored RCA templates. ## Frequently asked questions ### Does Lauren write the report, or does a person? Lauren drafts it, and a person signs it. Nothing she drafts becomes the record until someone approves it, and the audit trail shows who did. ### Can Lauren make things up? Language models can, which is why every draft is reviewed. Lauren fills fields only from what the reporter said, and marks drafts. Investigation drafts are suggestions, not conclusions. ### Is patient information sent to the AI? Only on the Regulated plan. There, Lauren's AI provider is under a BAA (a HIPAA contract) and direct identifiers are minimized first. The free Open plan does not allow patient information. See the [HIPAA page](https://incidentkit.ai/hipaa). ### What if the AI service is down? Reporting keeps working. Staff use the standard form or quick report, and Lauren's drafts resume later. ### Can I see what Lauren was given and what she wrote? Yes, on Regulated and Network. Her inputs and outputs go to the audit trail, next to the names of the people who edited and approved each field. ### Does Lauren replace the investigator? No. She drafts contributing factors, a five-whys chain and corrective actions for the investigator to edit. The investigator decides what happened. ## Related - [Incident reporting software: forms, drafts, workflow](https://incidentkit.ai/product/incident-reporting) - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [Incident audit trail: every change, who and when](https://incidentkit.ai/product/audit-trail) - [AI for incident reporting: what it can and cannot do](https://incidentkit.ai/guides/ai-for-incident-reporting) - [How AI intake changes incident reporting: forms vs chat](https://incidentkit.ai/blog/how-ai-intake-changes-incident-reporting) - [Incident reporting deadlines and obligations](https://incidentkit.ai/compliance/reporting-deadlines) --- # The complete incident record, in one place. > One record for patient, visitor, employee and property incidents, from draft to closed. Investigations, actions, packets and analytics all read from it. Source: https://incidentkit.ai/product/incident-reporting · Updated Oct 5, 2026 **Incident reporting** (report): The full record holds who, what, where, harm, evidence and what happens next. ## What it does - **One record for every type** Patient, visitor, employee and property incidents, near misses and equipment events, each with its own fields. - **Drafts survive interruptions** Start a report, get pulled away, finish later. Drafts save and open on any device. - **Severity and harm built in** Harm level and priority drive routing from the first minute, so a serious event never waits in an inbox. - **Who was told, and when** Record who was told, like the physician, family, administrator or a regulator, and when. - **Attachments with quarantine** Photos and documents attach to the record and pass a review before they count as clean. - **A status workflow** Draft, submitted, triaged, investigating, action in progress, closed, reopened. Closing requires verified corrective actions. ## How it works 1. **Start anywhere** Lauren, a quick report, an email or the full form. 2. **Complete the record** Add fields, narrative, people, attachments and notifications. 3. **Triage and route** Severity and type decide who is paged and who owns it. 4. **Work it to closed** Investigate, fix, verify and sign off. ## Frequently asked questions ### What types of incidents can staff report? Patient, visitor, employee and property incidents, plus near misses, equipment failures, medication, security and privacy events. Packs set the types and forms for each kind of site. ### Can staff report without a login? Quick report and email-to-incident cut login friction. The full record is for signed-in staff with the reporter role. ### How is this different from our EHR's event module? It runs alongside the EHR, so staff do not open a chart to report. It adds what an EHR module usually lacks: investigation, verified fixes, packets and trends. ## Related - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) - [Incident routing and escalation by severity](https://incidentkit.ai/product/routing-and-escalation) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Replace Paper Incident Forms: A Practical Switch Plan](https://incidentkit.ai/use-cases/replace-paper-incident-forms) - [Free incident report templates](https://incidentkit.ai/templates) - [F689 accidents and supervision: falls, hazards, devices](https://incidentkit.ai/compliance/f-tags/f689) - [Incident reporting deadlines and obligations](https://incidentkit.ai/compliance/reporting-deadlines) --- # Report by talking. > Voice reporting lets staff describe an incident out loud. Lauren asks follow-up questions and turns it into a report. It is rolling out in stages, with the same human review and audit trail as every other way to report. Source: https://incidentkit.ai/product/voice-reporting · Updated Oct 5, 2026 **Status: rolling out.** **Voice reporting** (report): Talk instead of type. Built for busy hands and long shifts. ## What it does - **Talk, then review** (rolling out) Speak the way you would tell a colleague. Lauren asks follow-ups and fills the fields. You review them on screen. - **Phone and browser** (rolling out) Start from quick report on a phone or from the web app. No special hardware. - **Same safeguards** (rolling out) Voice reports get the same human review, audit trail and access controls as typed ones. - **Built for noisy places** (rolling out) Made for hallways, loading docks and cabs, where typing gets in the way. ## How it works 1. **Tap and talk** Open quick report and describe the incident out loud. 2. **Lauren asks** A few follow-up questions, spoken or typed. 3. **Review the captured fields** Correct anything, then sign. ## Frequently asked questions ### Is voice reporting available now? It is rolling out. Text intake with Lauren, quick report and email-to-incident are available today. Ask about the voice rollout when you book a demo. ### Are recordings stored? Audio handling rules are not published yet. They are part of the rollout and will appear on the [security page](https://incidentkit.ai/security) before general availability. Reports always get human review. ### Does voice work in other languages? Not yet. Other languages, starting with Spanish, are on the roadmap alongside voice. ## Related - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) - [Mobile incident reporting that works offline](https://incidentkit.ai/product/mobile-and-offline) - [Construction incident reporting for job sites and subs](https://incidentkit.ai/solutions/construction) - [Warehouse and logistics incident reporting software](https://incidentkit.ai/solutions/warehousing-and-logistics) - [Injury reporting and retaliation: 29 CFR 1904.35 and 11(c)](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation) --- # Scan, say what happened, done. > Quick report is a three-field incident report that opens when someone scans a facility QR code. It works on any phone. With no signal, it queues the report and sends it later, so near misses get captured, not forgotten. Source: https://incidentkit.ai/product/quick-report · Updated Oct 5, 2026 **QR and quick report** (report): Scan a QR code, fill in three fields, and the incident is on record. ## What it does - **Three fields** What happened, how serious, where. Enough to start the record and route it. Details come later. - **A QR code per site** Print it and post it at the nurses' station, the dock door or the break room. A scan opens quick report for that site. - **Works without signal** No connection? The report waits on the phone and sends when the signal is back. - **Becomes a full record** A quick report opens an incident that Lauren and a reviewer can complete. ## How it works 1. **Scan the code** Any phone camera. No app to install. 2. **Say what happened** Three fields. Ten seconds for a near miss. 3. **It routes itself** The right owner is told, and the record opens for follow-up. ## Frequently asked questions ### Do staff need an account? Quick report is built to avoid login friction. After that, roles decide who can see and edit the record. ### What if there is no signal in the basement or on site? The phone queues the report and sends it when the connection returns. The queue has a limit, so report from a spot with signal when you can. ### Can quick report be used for near misses? Yes. Near misses are the point: quick reports are how they get captured. See [near-miss reporting](https://incidentkit.ai/use-cases/near-miss-reporting). ## Related - [Mobile incident reporting that works offline](https://incidentkit.ai/product/mobile-and-offline) - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Near-miss reporting and safety culture: a practical guide](https://incidentkit.ai/guides/near-miss-reporting-and-safety-culture) - [How to get staff to report near misses (and keep doing it)](https://incidentkit.ai/blog/how-to-get-staff-to-report-near-misses) - [Injury reporting and retaliation: 29 CFR 1904.35 and 11(c)](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation) --- # If it arrives by email, it still gets on record. > Each facility gets its own email address. Anything sent or forwarded there becomes a draft incident. Reports from supervisors, families and vendors then follow the same workflow as every other incident. Source: https://incidentkit.ai/product/email-to-incident · Updated Oct 5, 2026 **Email-to-incident** (report): Forward a complaint or vendor email and it becomes a draft incident. ## What it does - **An address per facility** Each site has its own address, tied to that site's routing and roles. - **Drafts, not lost threads** The email becomes a draft incident, with the message kept as written, ready to complete. - **Treated as sensitive** Inbound email can hold sensitive information, so it gets the same access controls as any incident. ## How it works 1. **Forward or send** To the facility's address. 2. **Draft created** The message and attachments become a draft incident. 3. **Complete and route** Lauren and a reviewer finish it like any other report. ## Frequently asked questions ### Is email-to-incident safe for patient information? Not by itself, because email is not a secure channel. On the Regulated plan, we suggest a policy that keeps patient identifiers out of the email body and in the record. Inbound messages are handled as sensitive. ### Can we turn it off? Yes. Email intake is set per facility. ## Related - [Incident reporting software: forms, drafts, workflow](https://incidentkit.ai/product/incident-reporting) - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [Migrate incident data from paper, Excel or legacy software](https://incidentkit.ai/product/import-and-migration) - [HIPAA and BAA for incident reporting](https://incidentkit.ai/hipaa) - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) --- # Phone-first, because that is where incidents happen. > IncidentKit is a web app you install from the browser on iOS or Android, with no app store. Quick reports queue offline and sync when the signal returns. Full offline forms and photo capture are rolling out. Source: https://incidentkit.ai/product/mobile-and-offline · Updated Oct 5, 2026 **Mobile and offline** (platform): IncidentKit installs from the browser and is built for one-handed use. ## What it does - **Install from the browser** Add it to your home screen on iOS or Android. Updates arrive on their own. - **Offline quick reports** Quick reports queue on the device and sync later. - **Fuller offline capture** (rolling out) Full forms, photos and equipment QR scanning offline are rolling out. - **Shared devices** (rolling out) A shared-device mode for hall tablets and plant-floor terminals is on the roadmap. ## How it works 1. **Install** Open the site on the phone and choose Add to Home Screen. 2. **Report anywhere** With or without signal. A quick report is three fields. 3. **Sync** Queued reports send themselves. ## Frequently asked questions ### Is there an app in the app store? No. IncidentKit is a progressive web app that installs from the browser. That avoids app-store review delays and keeps every device on the current version. ### How much works offline? Quick reports queue offline today. Fuller offline forms and photo capture are rolling out. ## Related - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) - [Voice incident reporting: talk, don't type](https://incidentkit.ai/product/voice-reporting) - [Construction incident reporting for job sites and subs](https://incidentkit.ai/solutions/construction) - [Home health incident reporting software for field staff](https://incidentkit.ai/solutions/home-health) - [Hospice incident reporting software for field teams](https://incidentkit.ai/solutions/hospice) --- # The right person hears first, and fast. > Every incident gets a priority from its severity and type. The right people are told their preferred way. If nobody acts, it escalates to the next person on a timer. Policies are set per facility, so a serious event never waits in an inbox. Source: https://incidentkit.ai/product/routing-and-escalation · Updated Oct 5, 2026 **Routing and escalation** (investigate): Severity decides who gets paged, and it escalates if nobody acts. ## What it does - **Priority from severity** Immediate, urgent or routine, set from harm level and incident type. - **Escalation timers** An immediate incident escalates after a short window. An urgent one waits longer. Each facility sets its windows. - **Role-based recipients** Medical director, director of nursing, EHS manager, plant manager, administrator: whoever your policy names. - **Notification preferences** Each person picks how to be told. Email carries a link to the portal, not patient details. - **Regulator clocks** (rolling out) Some types start a reporting clock, like abuse allegations and severe injuries. The record flags the deadline. Automated rules are rolling out. ## How it works 1. **Set the policy** Choose who is told for each priority, and when it escalates. 2. **Incident arrives** Priority comes from harm and type. 3. **Owner told** With a link to the record. 4. **Escalate if idle** The next person is told automatically. ## Frequently asked questions ### Can we route differently by site? Yes. Each facility sets its own routing and escalation windows. A surgery center and a plant in one organization can follow different policies. ### Do notifications contain patient information? No. Notifications link to the record in the portal. They carry no incident narrative or patient details. ### What happens if the owner is out? Escalation moves to the next role in the policy. An administrator can also reassign the owner at any time. ## Related - [Incident reporting software: forms, drafts, workflow](https://incidentkit.ai/product/incident-reporting) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Abuse Reporting Deadlines for Nursing Homes: 2 and 24 Hours](https://incidentkit.ai/use-cases/abuse-reporting-deadlines) - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) --- # Investigations that actually finish. > Investigations run on the incident record. Lauren drafts contributing factors and a five-whys chain. The investigator edits them, attaches evidence, picks a disposition and signs. Findings flow into corrective actions, so each root cause gets an owned fix. Source: https://incidentkit.ai/product/investigations · Updated Oct 5, 2026 **Investigations and RCA** (investigate): A guided investigation: find causes, pick a disposition, and a person signs. ## What it does - **Contributing factors** Pick a category for each factor: environment, equipment, procedure, people or communication. Later you can count patterns. - **Five whys, drafted and editable** Asking why again and again gets to the cause. Lauren drafts the chain. A person edits and signs it. - **A disposition for every case** The disposition is the decision. Change a process, repair equipment, train staff, refer to a committee or medical director, or open a quality study. - **Evidence on the record** Photos, work orders and documents stay attached to the investigation. - **Human-authored templates** (rolling out) Fishbone and fault-tree worksheets, and templates a facilitator leads, are rolling out. ## How it works 1. **Assign the investigator** Routing picks the owner by severity and type. 2. **Draft the analysis** Lauren proposes factors and a chain. 3. **Decide the disposition** What changes, and who owns it. 4. **Convert to actions** Findings become corrective actions with owners and dates. ## Frequently asked questions ### Does Lauren decide the root cause? No. Lauren drafts a possible chain from the record. A person decides what is true, edits it and signs. The draft marker stays until then. ### Which root cause methods are supported? Five whys and contributing-factor analysis today. Fishbone and fault-tree worksheets are rolling out. See [five whys vs fishbone vs fault tree](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree) to choose. ### Can a committee review an investigation? Yes. The disposition can send the case to a committee or the medical director. The review is recorded on the same record. ## Related - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Root cause analysis: definition and meaning](https://incidentkit.ai/glossary/root-cause-analysis) - [Root Cause Analysis Worksheet (5 Whys Template)](https://incidentkit.ai/templates/root-cause-analysis-worksheet) - [F610 investigate, prevent and correct alleged violations](https://incidentkit.ai/compliance/f-tags/f610) - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) --- # A fix is done when the evidence says so. > IncidentKit tracks corrective and preventive actions (CAPA) from investigation to verification. Each action has an owner, due date, required evidence and an effectiveness check. Reminders escalate when actions slip. An incident cannot close until its actions are verified. Source: https://incidentkit.ai/product/corrective-actions · Updated Oct 5, 2026 **Corrective actions (CAPA)** (correct): Every fix has an owner, a date and proof. Unverified fixes keep it open. ## What it does - **Owner, due date, evidence** All three are required before an action can be marked complete. - **Reminders and escalation** Overdue actions remind the owner, then escalate to the next person. - **Effectiveness check** A scheduled follow-up asks: did the problem come back in the window you set? - **Closure gate** The incident closes only when its actions are verified. “I think we did that” stops being an answer. - **Suggested actions are labeled** Lauren's suggestions are marked as suggestions until a person adopts them. - **Reporting across incidents** See open, overdue and verified actions by owner, site and type for your committee. ## How it works 1. **Create actions from findings** Each root cause gets an action. 2. **Assign owner and date** Say what evidence is required. 3. **Complete with evidence** Upload the proof. 4. **Verify effectiveness** Check at the interval you set, then close. ## Frequently asked questions ### What is the difference between corrective and preventive action? A corrective action fixes a problem that has happened. A preventive action removes a risk before it causes an incident. IncidentKit tracks both the same way. See [CAPA in the glossary](https://incidentkit.ai/glossary/corrective-and-preventive-action). ### How do surveyors and auditors use CAPA records? They check three things: did you find a cause, act on it, and verify the fix worked. An owner, evidence and an effectiveness review answer all three. See the [CAPA guide](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide). ### Can actions span more than one incident? Related incidents can share a pattern. Analytics shows repeats by location, shift, equipment and cause. You can see when an action did not hold. ## Related - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [QAPI, survey and OSHA compliance packets](https://incidentkit.ai/product/compliance-packets) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Corrective Action Plan Template (CAPA, Printable)](https://incidentkit.ai/templates/corrective-action-plan) - [Effectiveness review: definition and meaning](https://incidentkit.ai/glossary/effectiveness-review) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) --- # Packets an auditor accepts, built from the record. > Packets turn your incidents, actions, signatures and trends into the documents surveyors and inspectors ask for. QAPI summaries and incident PDFs are ready today. Survey packets and OSHA 300, 300A and 301 outputs are rolling out. Source: https://incidentkit.ai/product/compliance-packets · Updated Oct 5, 2026 **Compliance packets** (prove): Records laid out the way surveyors and inspectors want them. ## What it does - **QAPI summary packets** One PDF for your committee: the quarter's incidents, trends, actions and sign-offs. QAPI is the quality program CMS requires. - **Per-incident PDF** A printable report for one incident. It has the story, causes, actions and signatures. - **CSV and structured export** Take your data out in a structured form. Any period, any time. - **Survey packets** (rolling out) Document sets for the accreditor or CMS survey you are getting ready for. - **OSHA 300, 300A and 301** (rolling out) The log entry, the incident report and the annual summary, made from the same record. ## How it works 1. **Choose the packet** A QAPI quarter, a survey, an OSHA year or one incident. 2. **Check what is inside** Every item links to its record. 3. **Export** PDF for the committee or auditor. CSV for your own analysis. ## Frequently asked questions ### Which packets exist today? QAPI summary PDFs, incident PDFs and structured exports work today. Survey packets and OSHA 300, 300A and 301 outputs are rolling out. See the [changelog](https://incidentkit.ai/changelog). ### Does a packet replace our policies and procedures? No. Packets show what happened and what you did. Surveyors still want your written policies, training records and committee minutes. ### Can we export everything if we leave? Yes. PDF and CSV export work at any time, with no exit fee. ## Related - [Incident audit trail: every change, who and when](https://incidentkit.ai/product/audit-trail) - [Incident analytics: find the pattern before the next one](https://incidentkit.ai/product/analytics) - [Always Survey-Ready: Stay Prepared for Unannounced Surveys](https://incidentkit.ai/use-cases/always-survey-ready) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [OSHA 300 Log Automation: Keep It Accurate Year-Round](https://incidentkit.ai/use-cases/osha-300-log-automation) - [QAPI Meeting Agenda and Minutes Template (Printable)](https://incidentkit.ai/templates/qapi-meeting-agenda-and-minutes) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [CMS QAPI requirements by facility type](https://incidentkit.ai/compliance/cms-qapi) - [Survey readiness: be ready every day](https://incidentkit.ai/compliance/survey-readiness) --- # Find the pattern before the next incident does. > Analytics show where, when and why incidents cluster: by location, shift, equipment, medication and contributing factor. They surface repeats, track whether a problem came back after a fix, and prepare the numbers your QAPI or safety committee needs. Source: https://incidentkit.ai/product/analytics · Updated Oct 5, 2026 **Analytics** (prove): See which rooms, shifts and equipment keep showing up in your incidents. ## What it does - **Location heatmap** Which rooms, bays, lines and docks generate incidents. - **Shift and time of day** Find the hour and day when understaffing or handoffs matter. - **Equipment and medication clusters** Three falls on the same gurney model? Repeat issues with one drug or tool? It shows. - **Repeat patterns** Did a fix hold? See if the same problem came back after a corrective action. - **Committee prep** A QAPI or safety committee view with the numbers already assembled. - **Organization roll-ups** Compare sites across a group, with role-based access. ## How it works 1. **Pick the question** Where, when or why. 2. **See the cluster** Filter by site, shift, type or cause. 3. **Act on it** Open a corrective action from the finding. ## Frequently asked questions ### Do analytics need a lot of incidents to be useful? No. Even a small site sees repeat places and shifts. Patterns show up faster when near misses are reported, which is why quick intake matters. ### Can leaders see all sites? Yes, with role-based access. Organization-wide analytics is part of the Network plan. ### Does analytics use patient identifiers? Aggregate views do not need them. Analytics work on categories and counts. ## Related - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [QAPI, survey and OSHA compliance packets](https://incidentkit.ai/product/compliance-packets) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) - [TRIR and DART rate calculator (OSHA formula)](https://incidentkit.ai/tools/trir-dart-calculator) - [Hospital QAPI requirements: 42 CFR 482.21 explained](https://incidentkit.ai/compliance/cms-qapi/hospitals) --- # Every change, who made it, and when. > The audit trail logs changes to each incident: who changed what, when, and from which value to which. Approvals, AI-drafted fields and sign-offs are in the history, so a surveyor, auditor or attorney can follow the record from first report to closure. Source: https://incidentkit.ai/product/audit-trail · Updated Oct 5, 2026 **Audit trail** (prove): Every edit is logged, so you can show who changed what, and when. ## What it does - **Change history** Field-level changes with the person, the time, and the before and after. - **Approvals and signatures** Who attested, who approved and who closed it, with timestamps. - **AI use is visible** See which fields Lauren drafted and who approved them. - **Role-based access** Role and facility decide who can view or edit a record. - **Stronger record locks** (rolling out) Append-only protections (entries can be added, never changed) and closed-record locks are being strengthened on a published roadmap. ## How it works 1. **Work the record** Every edit is logged as it happens. 2. **Review the history** Filter by person, date or field. 3. **Export with the packet** The trail travels with the incident. ## Frequently asked questions ### Can records be edited after closure? An authorized role can reopen a closed record. The reopen and every later edit show in the history. Stronger closed-record locks are rolling out. ### Is the audit trail enough for HIPAA? No. An audit trail is one of several safeguards HIPAA expects. See the [HIPAA page](https://incidentkit.ai/hipaa) for how IncidentKit approaches the Security Rule. ## Related - [QAPI, survey and OSHA compliance packets](https://incidentkit.ai/product/compliance-packets) - [IncidentKit security overview](https://incidentkit.ai/security) - [HIPAA and BAA for incident reporting](https://incidentkit.ai/hipaa) - [Multi-site incident management with roles and SSO](https://incidentkit.ai/product/multi-site-and-roles) - [Survey and accreditation readiness: a continuous approach](https://incidentkit.ai/guides/survey-and-accreditation-readiness) - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) --- # One standard across every site. > An account is an organization with many facilities. Six roles, from viewer to super admin, control who can report, edit, approve and administer. Single sign-on is set per organization. Groups can mix packs, so a surgery center and a plant can share one account. Source: https://incidentkit.ai/product/multi-site-and-roles · Updated Oct 5, 2026 **Multi-site and roles** (platform): Run one program across many sites, with six roles and single sign-on. ## What it does - **Organization and facilities** Add sites as you grow. Each has its own staff, routing and pack. - **Six roles** Viewer, reporter, editor, supervisor, admin and super admin. Sixteen detailed permissions sit behind them. - **Single sign-on** SSO per organization, so staff sign in with the login they already have. - **Mixed packs** A pack sets incident types, forms and exports for a kind of site. Each site in an organization can use a different one. - **Org-wide analytics** Compare sites and see the group picture. - **SCIM provisioning** (rolling out) Automated user setup, called SCIM, is on the roadmap. ## How it works 1. **Create the organization** Add your first site and roles. 2. **Invite staff** By email or SSO. 3. **Add sites** Done-for-you setup per site on Regulated and Network. ## Frequently asked questions ### How fast can a new site be added? On Regulated and Network, we set up a new site in about 48 hours, with roles, routing and forms. Self-serve sites on the Open plan can start the same day. ### Can corporate see every site? Yes, with a role that gives organization-level visibility. Site staff see only their own facility. ### Do you support SCIM? Not yet. Single sign-on is available now. Automated provisioning through SCIM is on the roadmap. ## Related - [Incident reporting API, webhooks and integrations](https://incidentkit.ai/product/integrations-and-api) - [Incident analytics: find the pattern before the next one](https://incidentkit.ai/product/analytics) - [Multi-site incident reporting software for groups](https://incidentkit.ai/solutions/multi-site-groups) - [Incident reporting software pricing: free to start](https://incidentkit.ai/pricing) - [IncidentKit security overview](https://incidentkit.ai/security) --- # Runs alongside the systems you already have. > IncidentKit has a read API for incidents and signed webhooks for incident events (created, submitted, status changed, closed). It also offers SSO and email intake. It runs alongside your EHR, CMMS and HRIS, not in place of them. Deeper connections are rolling out. Source: https://incidentkit.ai/product/integrations-and-api · Updated Oct 5, 2026 **Integrations and API** (platform): Read API, webhooks and SSO now. Deeper EHR, CMMS and HRIS links come later. ## What it does - **Read API** List and fetch incidents with organization-scoped keys. Sensitive fields need a separate scope. - **Signed webhooks** Events for created, submitted, status changed and closed. Each is signed with HMAC and retried on failure. - **SSO** Single sign-on per organization. - **Email in** Create incidents by email. - **EHR, CMMS, HRIS connectors** (rolling out) Pre-built links to health record (EHR), maintenance (CMMS) and HR (HRIS) systems, including PointClickCare and MatrixCare, are rolling out. - **Write API** (rolling out) Creating and updating incidents through the API is on the roadmap. ## How it works 1. **Create an API key** Scoped to your organization. 2. **Subscribe to events** Point a webhook at your system. 3. **Build the workflow** Page a team, open a work order, update a dashboard. ## Frequently asked questions ### Do you replace our EHR or CMMS? No. IncidentKit runs alongside them. Staff report from a phone without opening a chart or work order, and the API and webhooks let other systems react to incidents. ### Are webhooks secure? Yes. Payloads are signed so your receiver can check they came from IncidentKit, and failed deliveries are retried. ### Is there an API for writing incidents? No. The API is read-only today, and a write API is on the roadmap. ## Related - [Multi-site incident management with roles and SSO](https://incidentkit.ai/product/multi-site-and-roles) - [Email-to-incident: forward it, it becomes a record](https://incidentkit.ai/product/email-to-incident) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) - [Incident reporting for insurers, TPAs and risk pools](https://incidentkit.ai/solutions/insurers-and-risk-pools) - [IncidentKit security overview](https://incidentkit.ai/security) --- # Start with your history, not a blank page. > IncidentKit imports past incidents from CSV with a guided column-mapping wizard. On paid plans, we migrate data for you from spreadsheets, paper logs and old incident software. With history in the system, trends, repeat checks and audit packets work from day one. Source: https://incidentkit.ai/product/import-and-migration · Updated Oct 5, 2026 **Import and migration** (platform): Import past incidents from a spreadsheet, or we move them from your old system. ## What it does - **CSV import wizard** Match your columns to IncidentKit fields, preview, then import. - **Done-for-you migration** On Regulated and Network we do the mapping and the load. - **From anywhere** Spreadsheets, scanned paper logs and exports from old systems. - **Run in parallel** Keep the old system read-only while staff start reporting in IncidentKit. - **Document extraction** (rolling out) Lauren-assisted extraction from PDFs and scans is rolling out for approved uses. ## How it works 1. **Export from the old system** CSV or the format you have. 2. **Map and preview** Match columns to fields. 3. **Import and verify** Spot-check, then go live. ## Frequently asked questions ### How do we leave our current incident software? Export your incidents, import them with the wizard or have us migrate them, run both systems for a short time, then retire the old one. See [switching from legacy software](https://incidentkit.ai/use-cases/switch-from-legacy-incident-software). ### Is migration free? Yes, on Regulated and Network plans. The CSV import wizard is on every plan. ## Related - [Switch From Legacy Incident Software: Migration Steps](https://incidentkit.ai/use-cases/switch-from-legacy-incident-software) - [Compare incident reporting software: the full matrix](https://incidentkit.ai/compare) - [Incident reporting software alternatives](https://incidentkit.ai/alternatives) - [Incident reporting software pricing: free to start](https://incidentkit.ai/pricing) - [Incident reporting API, webhooks and integrations](https://incidentkit.ai/product/integrations-and-api) --- # Incident reporting built for ambulatory surgery centers > Log transfers and near misses between cases, and meet surveyors with every loop closed. Source: https://incidentkit.ai/solutions/ambulatory-surgery-centers · Updated Oct 5, 2026 **Who:** Pre-op, PACU, anesthesia and sterile processing staff report. The clinical director investigates, the administrator owns the fixes, and the governing body reviews the trend. ## The problems - **Events live in four places:** A transfer sits in the EHR, an email and a binder tab. Before committee, someone rebuilds the list by hand and misses the near misses. - **Post-discharge events surface late:** A next-day call finds a patient who went to the ED. CMS measures hospital visits from claims, long after your call log shows the pattern. - **The loop has to close, and show it:** 42 CFR 416.43 asks you to track adverse events, find causes, improve and make it last. Signed forms prove only the first step. - **Ten centers, ten vocabularies:** One center logs a PACU fall as a slip, another as a safety event. The group's quality director cannot compare rates. ## Incident types in the pack - Wrong-site, wrong-patient or wrong-procedure event - Site-marking or laterality near miss - Unplanned transfer to a hospital - ED visit or admission after discharge - Fall in pre-op, the OR or PACU - Patient burn - Anesthesia event - Hypothermia on arrival to PACU - Retained item or count discrepancy - Medication error - Sterile processing event - Device or equipment malfunction ## Regulators and standards - **42 CFR 416.43, ASC QAPI:** A data-driven program that tracks adverse patient events, finds causes, makes improvements and keeps them in place. Each project is documented with its reasons and results. - **42 CFR 416.41(b), hospital transfer:** Have a working procedure to transfer patients who need emergency care you cannot give. Give the local hospital written notice of your operations. - **ASC Quality Reporting Program:** Web measures: burns (ASC-1), falls (ASC-2), wrong site, side, patient, procedure or implant (ASC-3), hospital transfer or admission (ASC-4). Missing them costs 2.0 percentage points off your annual payment update. - **AAAHC, Quad A and ACHC:** CMS-approved ASC accreditors. Each surveys your quality program. Quad A has required Patient Safety Data Reporting since 2001. - **The Joint Commission:** Wrong-site, wrong-patient or wrong-procedure surgery is a sentinel event whatever the outcome. A full analysis and action plan is expected within 45 business days. Reporting is encouraged, not required. - **21 CFR 803.30, FDA device reports:** An ASC is a device user facility. Report a device-related death to FDA and the manufacturer, and a serious injury to the manufacturer, within 10 work days of becoming aware. - **State licensure and adverse event rules:** State rules apply on top of federal ones and differ by state. Check yours; routing and escalation can be set per center. ## How it works 1. **Report between cases** Scan the QR code or text Lauren. She asks what a clinical director would: procedure, laterality, time-out status, anesthesia type. The reporter reviews and signs. Voice is rolling out. 2. **Route and investigate** Wrong-site events and transfers go to the administrator and clinical director at once. Lauren drafts likely causes and five whys; your clinical director edits and signs. 3. **Fix it with an owner** Each action has an owner, due date, evidence and effectiveness check, such as a 30-case time-out audit. Nothing closes until a person verifies the fix held. 4. **Prove it at QAPI and survey** The QAPI packet, incident PDFs and CSV counts come from the same records. The audit trail shows who changed what, and when. Survey packets are rolling out. ## Scenario: A laterality mismatch caught in pre-op An example near miss, not a customer story. - **07:42, Nurse catches mismatch, scans QR code.** In pre-op, a nurse sees the consent says left knee but the site mark and schedule say right. She holds the case and scans the QR code. - **07:44, Lauren asks follow-ups, drafts report.** Lauren asks whether the patient entered the OR, who marked the site, and which document was wrong. The draft says “Lauren · draft”. The nurse signs. - **07:46, Administrator and clinical director notified.** The report is classed as a near miss with no harm. The administrator and clinical director are told at once, and notice times are logged. - **10:30, Clinical director opens the investigation.** Lauren drafts likely causes: a consent from a stale scheduling template, and site marking before consent review. The director edits, adds the five whys and signs. - **Day 3, Three actions created, evidence required.** Build consents from the booking record, add a consent-to-mark check to pre-op, and audit the next 30 time-outs. Each action gets an owner, due date and evidence. - **Day 30, Audit sheets attached, actions close.** The clinical director verifies the check and the actions close. The audit sheets are attached as evidence, and the audit trail shows every step. - **QAPI meeting, QAPI committee reviews near misses.** The QAPI packet lists near misses by type and location, with cause, actions and verification. The committee records the project as sustained. - **Survey day, Surveyor asks, the record answers.** The surveyor asks how the center tracks adverse events and shows improvements held. The incident PDF and QAPI summary answer from the record. ## What is in the pack **Forms:** ASC incident report; Wrong site, patient or procedure event or near miss; Unplanned transfer to a hospital; Follow-up call log after discharge; Anesthesia event form; Fall form for pre-op, OR and PACU; Burn event form; Device event sheet for the FDA decision **Routing:** Wrong-site event or near miss: administrator and clinical director at once; Unplanned transfer: clinical director and anesthesia lead, same day; Device death or serious injury: administrator decides on the 10-work-day FDA report; Possible sentinel event: administrator, medical director and governing body chair; ED visit or admission after discharge: clinical director review **Exports:** QAPI summary packet for 42 CFR 416.43, one PDF; Yearly CSV counts of burns, falls, wrong-site events and transfers, for HQR; Incident PDF with investigation, actions and signatures; Survey packet for AAAHC, Joint Commission, Quad A or ACHC (rolling out) **Roles:** Reporter: any nurse, technician or contract provider; Editor: pre-op, PACU and sterile processing leads; Supervisor: clinical and medical directors; Admin: administrator, who owns the fixes; Super admin: corporate quality director; Viewer: governing body and consultants ## Outcomes - **A QAPI record that builds as events happen:** Each event, cause and fix is logged as it happens. The QAPI summary needs no hand rebuild. - **Near misses that count:** A near miss is quick to log between cases. It joins the trend with harm events, so patterns show early. - **You see post-discharge events first:** A follow-up call log feeds the same record. ED visits and admissions show in your analytics before CMS's claims-based measures can. - **One vocabulary across a group:** Every center uses the same event types and definitions. Corporate can compare falls, transfers and wrong-site near misses by center and shift. ## Frequently asked questions ### What does 42 CFR 416.43 require an ASC to track? An ongoing, data-driven QAPI program that tracks quality indicators, adverse patient events and infection control. You must find causes, improve and make the gains last, and document each project's reasons and results. See [QAPI for ASCs](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers). ### Which ASC Quality Reporting Program measures are really incidents? Four web-based measures count events: burn (ASC-1), fall (ASC-2), wrong site, side, patient, procedure or implant (ASC-3) and hospital transfer or admission (ASC-4). You submit through HQR; CY 2026 data is listed for January 1 to May 17, 2027 (confirm on QualityNet). ASCs with fewer than 240 Medicare fee-for-service claims a year need not participate. See [ASCQR](https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting). ### Does IncidentKit replace our EHR or submit to CMS? No. IncidentKit runs alongside your EHR and scheduling system. It keeps the incident record and gives you the counts and packets; you still submit through HQR. A read API and signed webhooks are available now, and deeper EHR links are rolling out. ### Does Lauren write the incident report? No. Lauren asks the follow-up questions and drafts fields from what the reporter said. Every drafted field says “Lauren · draft” until a person reviews, edits and signs. Text intake works today; voice is rolling out. ### How is it priced, and who built it? Surgery centers use the per-site Regulated plan: a BAA, patient information, compliance packets and done-for-you setup, with no seats, modules or setup fee. Groups of 10 or more sites use custom Network pricing. PharmPro's compliance consulting practice built it: 31 years in survey and inspection prep, 250+ facilities taken through survey. See [pricing](https://incidentkit.ai/pricing). ## Sources - [42 CFR 416.43, Quality assessment and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-B/part-416/subpart-C/section-416.43) - [42 CFR 416.41, Governing body and management (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-B/part-416/subpart-C/section-416.41) - [42 CFR 416.310, ASCQR data collection and submission (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-B/part-416/subpart-H/section-416.310) - [ASCQR Important Dates, CY 2026 reporting period (Quality Reporting Center)](https://qualityreportingcenter.com/globalassets/2025/12/asc/ascqr_2026_importantdates_final_508.pdf) - [ASCQR Program FAQs, January 2026 (Quality Reporting Center)](https://www.qualityreportingcenter.com/globalassets/2025/12/asc/qrc_asc_2026_faqs_final508.pdf) - [Joint Commission Sentinel Event Policy (CAMH Update 1, July 2026)](https://digitalassets.jointcommission.org/api/public/content/4035922bcc2f41bd83fbc1f55764a7b4?v=bf31f43b) - [21 CFR 803.30, Device user facility reporting (eCFR)](https://www.ecfr.gov/current/title-21/chapter-I/subchapter-H/part-803/subpart-C/section-803.30) - [21 CFR 803.3, Definitions, including device user facility (eCFR)](https://www.ecfr.gov/current/title-21/chapter-I/subchapter-H/part-803/subpart-A/section-803.3) - [CMS, Accreditation programs and approved accrediting organizations](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs) - [Quad A, About us](https://www.quada.org/about-us) - [AAAHC, Accreditation](https://www.aaahc.org/accreditation/) - [Federal Register, ACHC application for continued approval of its ASC program (88 FR 19645)](https://www.govinfo.gov/content/pkg/FR-2023-04-03/pdf/2023-06778.pdf) ## Related - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [QAPI, survey and OSHA compliance packets](https://incidentkit.ai/product/compliance-packets) - [Multi-site incident reporting software for groups](https://incidentkit.ai/solutions/multi-site-groups) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [ASC Incident Report Template for Surgery Centers](https://incidentkit.ai/templates/asc-incident-report) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [AAAHC accreditation: surveys, deemed status and QI studies](https://incidentkit.ai/compliance/accreditation/aaahc) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [Quad A accreditation: surveys, PSDR and Medicare ASCs](https://incidentkit.ai/compliance/accreditation/quad-a) - [ACHC accreditation: deemed status, surveys and standards](https://incidentkit.ai/compliance/accreditation/achc) - [ASCQR Program: measures, deadlines, 2.0-point penalty](https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting) - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) - [Medical device reporting for user facilities: 21 CFR 803](https://incidentkit.ai/compliance/reporting-deadlines/device-adverse-event-reporting) - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) --- # Event reporting that closes the loop in your hospital > Report fast, classify the same day, and show the board that every fix held. Source: https://incidentkit.ai/solutions/hospitals · Updated Oct 5, 2026 **Who:** Nurses, physicians, pharmacists and ancillary staff report. Unit managers investigate, risk and quality classify and sign, and the CNO and governing body review the trends. ## The problems - **Reporting is a chore, so it is rare:** A long form after a twelve-hour shift gets skipped. Serious events reach risk management; the near misses that predict them do not. - **Investigations end in a document, not a change:** A root cause analysis is filed. Six months later, nobody can say what was fixed, who checked it, or whether it came back. - **The sentinel event decision cannot wait:** Deciding if a fall with injury or procedure event is a sentinel event starts a 45-business-day analysis. Risk management must see it the same day. - **Units and the board see different pictures:** Quality committees get a slide deck built by hand. Clinics, behavioral units and affiliated sites use different forms. ## Incident types in the pack - Patient fall with or without injury - Medication event - Wrong-site or retained-item procedure event - Pressure injury - Restraint or seclusion event - Elopement or wandering - Patient self-harm or suicide attempt - Blood or blood product event - Device or equipment failure - Delay in care or handoff failure - Workplace violence against staff - Obstetric event ## Regulators and standards - **42 CFR 482.21, hospital QAPI:** A data-driven program that tracks medical errors and adverse events, analyzes causes, prevents repeats and checks that gains last. Multi-hospital systems may elect one program under 482.21(g). - **42 CFR 482.13(e) and (g), restraint and seclusion:** Violent or self-destructive behavior: orders, monitoring, face-to-face evaluation within 1 hour. A restraint or seclusion death goes to CMS by close of business the next business day after you know. - **Obstetric QAPI, effective January 1, 2027:** Hospitals with obstetric services must use QAPI to assess and improve outcomes and disparities, with at least one measurable improvement project a year. - **The Joint Commission:** Sentinel Event Policy: a full analysis and corrective action plan within 45 business days, with at least one stronger or intermediate-strength action. Self-reporting is encouraged, not required. - **CIHQ and DNV:** CMS-approved hospital accreditors. Their standards must meet or exceed Medicare's, so your QAPI program is tested against them. - **21 CFR 803.30, FDA device reports:** A hospital is a device user facility. Report a device-related death to FDA and the manufacturer, and a serious injury to the manufacturer, within 10 work days of becoming aware. - **State adverse event reporting:** States set their own rules for serious events. Check yours; routing and escalation can be set per hospital. ## How it works 1. **Report from the unit** Scan the QR code or text Lauren. Lauren asks what a risk manager would: harm, medication or device, who was told. The reporter signs. Voice is rolling out. 2. **Classify and investigate** Injury falls and procedure or restraint events go to risk and the unit manager at once. A person sets the harm level and sentinel call. Lauren drafts; your team signs. 3. **Correct with verification** Each action has an owner, due date, evidence and effectiveness check. The Joint Commission expects this in an acceptable plan. Nothing closes until a person verifies it. 4. **Prove it at committee and survey** Analytics cluster events by unit, shift, equipment and cause. A QAPI summary packet carries the quarter to your committee. The audit trail shows every edit and approval. ## Scenario: A fall with a hip fracture, from report to verified action plan An example, not a customer story: a possible sentinel event, from first text to verified plan. - **03:40, Nurse finds patient, texts Lauren.** The patient is on the floor; the nurse assesses, calls the provider and texts Lauren. Lauren asks about fall risk, bed alarm, rounding, sedatives and injury, and the nurse signs. - **08:30, Fracture triggers leader notifications.** Imaging shows a hip fracture. The nurse manager raises the harm level, and a fracture rule alerts the risk manager, CNO and patient safety officer. Family disclosure is logged. - **Day 1, Risk manager records sentinel decision.** The 45-business-day analysis window is noted. The risk manager records whether the event meets sentinel event criteria, and why. Joint Commission reporting stays a leaders' call. - **Day 3, RCA team opens the investigation.** Lauren drafts a timeline and likely causes. The root cause analysis team edits, adds the family's account where fitting, and completes the five whys. - **Day 20, Action plan names owners and measures.** At least one action is stronger or intermediate-strength, such as a standard bed-exit alarm setting. Each action has an owner, date, evidence, effectiveness measure and plan to sustain it. - **Business day 40, Analysis and plan approved, exported.** With the audit trail attached, the analysis and plan are approved and exported ahead of the 45-business-day mark. - **Day 120, Effectiveness check verified, actions close.** Falls with injury on the unit over the period are attached as the effectiveness check. The CNO verifies the check and the actions close. - **Quarterly, Quality committee reviews falls by unit.** Falls with injury by unit and shift reach the quality committee and the governing body. The QAPI packet lists the actions as verified. ## What is in the pack **Forms:** Patient safety event report with harm scale; Fall with injury form; Medication event form, with high-alert drugs; Procedure and retained item form; Restraint and seclusion form; Obstetric event form; Device event sheet for the FDA decision; Sentinel event review record **Routing:** Fall with injury, procedure event or unexpected death: risk and unit managers; Possible sentinel event: risk manager, CNO and patient safety officer; Restraint or seclusion death: risk manager, with the CMS deadline noted; Device death or serious injury: risk manager decides on the 10-work-day report; High-alert drug event: pharmacy and medication safety committee **Exports:** QAPI summary packet for 42 CFR 482.21, one PDF; Incident PDF with sentinel event analysis, action plan and signatures; CSV counts by unit, shift and event type; CSV of restraint and seclusion events, for the 482.13(g)(2) log; Survey packet for Joint Commission, CIHQ or DNV (rolling out) **Roles:** Reporter: any clinical or support staff member; Editor: unit educators and charge nurses; Supervisor: unit managers; Admin: risk manager and quality director; Super admin: system quality leader; Viewer: CNO, medical leaders, governing body and consultants ## Outcomes - **Reports that arrive because they are easy:** A short chat on the unit replaces the long form, so near misses and no-harm events reach risk management. - **Sentinel event decisions made the same day:** A rule flags events that match sentinel event criteria. A person classifies them and records why. - **Actions that carry a verification:** Every action has an owner, a date and an effectiveness check, and stays open until a person verifies it. - **One view across units and sites:** Departments, clinics and affiliated sites share event types, so the quality director sees the system and each unit in one view. ## Frequently asked questions ### What does 42 CFR 482.21 require hospitals to do with adverse events? Track quality indicators, medical errors and adverse patient events, then analyze causes, act to prevent repeats and measure whether gains last. Run and document performance improvement projects. See [hospital QAPI](https://incidentkit.ai/compliance/cms-qapi/hospitals). ### How does a hospital handle a possible sentinel event? Accredited hospitals are expected to finish a full analysis and action plan within 45 business days. The Joint Commission defines a sentinel event as a patient safety event that reaches a patient and causes death, severe harm or permanent harm. A fall with any fracture is one example. See [sentinel events](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events). ### We already have an event reporting system. Where does IncidentKit fit? It fits community and specialty hospitals, outpatient sites outside the main system, and teams whose current tool logs events but does not verify fixes. It runs alongside your EHR, and [import and migration](https://incidentkit.ai/product/import-and-migration) brings history across. Deeper EHR links are rolling out. ### What changes for obstetric services in 2027? From January 1, 2027, hospitals with obstetric services must use QAPI to assess and improve outcomes and disparities, with a measurable project each year. IncidentKit tracks obstetric events as their own category. Outcome and disparity analysis by patient group uses clinical data that stays in your EHR. ### Is patient information protected, and what is included? Yes, under a BAA. Hospitals use the per-site Regulated plan: a BAA, patient information, compliance packets and done-for-you setup, with no seats, modules or setup fee. Lauren runs on an AI provider covered by a BAA. See [security](https://incidentkit.ai/security) and [HIPAA](https://incidentkit.ai/hipaa). ## Sources - [42 CFR 482.21, Hospital QAPI (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-G/part-482/subpart-C/section-482.21) - [42 CFR 482.13, Patient rights, restraint and seclusion (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-G/part-482/subpart-B/section-482.13) - [Joint Commission Sentinel Event Policy (CAMH Update 1, July 2026)](https://digitalassets.jointcommission.org/api/public/content/4035922bcc2f41bd83fbc1f55764a7b4?v=bf31f43b) - [21 CFR 803.30, Device user facility reporting (eCFR)](https://www.ecfr.gov/current/title-21/chapter-I/subchapter-H/part-803/subpart-C/section-803.30) - [CMS, Accreditation programs and approved accrediting organizations](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs) - [Federal Register, CIHQ application for continued approval of its hospital program (2017)](https://www.govinfo.gov/content/pkg/FR-2017-02-24/pdf/2017-03556.pdf) - [DNV, NIAHO accreditation for hospitals](https://www.dnv.us/services/niaho-accreditation-for-hospitals2/) ## Related - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [Incident routing and escalation by severity](https://incidentkit.ai/product/routing-and-escalation) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Incident analytics: find the pattern before the next one](https://incidentkit.ai/product/analytics) - [Fall Reporting: What to Record and Review After a Fall](https://incidentkit.ai/use-cases/fall-reporting) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) - [Hospital QAPI requirements: 42 CFR 482.21 explained](https://incidentkit.ai/compliance/cms-qapi/hospitals) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [CIHQ accreditation for hospitals: surveys and standards](https://incidentkit.ai/compliance/accreditation/cihq) - [DNV hospital and ASC accreditation: CMS status and surveys](https://incidentkit.ai/compliance/accreditation/dnv) - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) - [Medical device reporting for user facilities: 21 CFR 803](https://incidentkit.ai/compliance/reporting-deadlines/device-adverse-event-reporting) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) - [Joint Commission survey readiness: tracers, unannounced](https://incidentkit.ai/compliance/survey-readiness/joint-commission-survey-readiness) --- # Incident reporting built for skilled nursing facilities > Take a fall from first text to verified fix, with the abuse deadline flagged. Source: https://incidentkit.ai/solutions/skilled-nursing-facilities · Updated Oct 5, 2026 **Who:** CNAs, nurses and charge nurses report. The director of nursing (DON) investigates, the administrator owns abuse reporting and fixes, and the QAA quality committee reviews trends. ## The problems - **Night shift writes it; day shift finds gaps:** A night fall is charted and phoned in. By morning, what nobody asked at the bedside is hard to fill in. - **The abuse clock will not wait for morning:** 42 CFR 483.12(c) sets a 2-hour or 24-hour clock for abuse allegations. It starts when staff first recognize one, often at the bedside. - **Falls, medication errors and wounds: separate logs:** Falls (F689), medication errors (F760) and wounds each get a spreadsheet. QAA sees three views and no pattern by unit, shift or cause. - **QAPI must show the loop, not the list:** QAPI is CMS's quality program. Surveyors ask how you find, report, investigate, analyze and prevent adverse events, and whether fixes held. ## Incident types in the pack - Resident fall or near-fall - Injury of unknown source - Alleged abuse, neglect or exploitation - Altercation between residents - Medication error - Elopement or wandering - New or worsened pressure injury - Skin tear or unexplained bruise - Choking or aspiration event - Transfer or lift injury - Missing or misappropriated property - Infection cluster or outbreak ## Regulators and standards - **F689, 42 CFR 483.25(d):** Free of accident hazards, with supervision and assistive devices. CMS counts a resident found on the floor as a fall, injury or not. Surveyors check that hazards are acted on. - **F600, F609 and F610, 42 CFR 483.12:** Allegations of abuse or serious bodily injury go to the administrator and State Survey Agency within 2 hours; others within 24. Investigate, protect residents, report results in 5 working days. - **F580, 42 CFR 483.10(g)(14):** After an accident that causes injury and may need physician intervention, immediately inform the resident, consult the physician and notify the resident representative. - **F760, 42 CFR 483.45(f)(2):** Residents must be free of significant medication errors. Under F759 the medication error rate must stay under 5 percent. - **F865, F867 and F868, 42 CFR 483.75:** QAA committee: DON, medical director or designee, three other staff and the infection preventionist, meeting at least quarterly. Show your QAPI plan at each annual recertification survey. - **State survey agency and state law:** States add their own reporting rules. Routing and escalation can be set per facility; check yours. ## How it works 1. **Report at the bedside** Scan the QR code or text Lauren. She asks what a DON would: witnessed or found, injury, alarm, footwear, anticoagulants, and whether any injury is unexplained. Voice is rolling out. 2. **See the clock, then investigate** The DON and administrator are told at once. Allegation and unknown-source types flag the reporting deadline; automated reportability rules are rolling out. Lauren drafts; the DON edits and signs. 3. **Change the plan, then check it** Scheduled toileting, a low bed or a pharmacist review each get an owner, due date and evidence. A person checks if the resident fell again before it closes. 4. **Give QAA a solid record** Analytics cluster falls, medication errors and wounds by unit, shift and cause. The QAPI summary packet and incident PDFs show the whole loop for each event. ## Scenario: A night fall, from first text to the QAA packet An example, not a customer story, from a night-shift fall to a verified care-plan change. - **02:07, CNA finds resident on floor.** The resident is on the bedroom floor and the CNA calls the charge nurse. The nurse starts the post-fall assessment under facility policy and makes the resident comfortable. - **02:20, Nurse scans QR, Lauren drafts report.** Lauren asks about head strike, anticoagulants, alarm, footwear, toileting, and whether the fall explains the injury. The draft says “Lauren · draft”. - **02:26, Nurse signs, DON and administrator notified.** The nurse edits two fields and signs. The DON and administrator are notified. Physician and resident representative notices are logged with times, for F580. - **02:28, Abuse reporting path does not apply.** The injury is explained and no one alleges mistreatment, so no abuse path applies. Had it been unexplained, the administrator would be alerted and the 2-hour clock flagged. - **07:30, DON opens the investigation.** Lauren drafts likely causes from the report and earlier falls. At the morning meeting, the DON edits: toileting pattern, a medication change, low light, footwear. - **Day 2, Care plan updated, three actions assigned.** Toileting at 01:30, a low bed with a floor mat and a pharmacist review of the new medication each get an owner and date. The team updates the care plan. - **Day 30, No repeat fall, actions close.** The DON attaches the toileting log, verifies the actions and closes them. The effectiveness check shows no repeat fall. - **Quarterly QAA, QAA committee finds night-shift cluster.** The committee sees falls by unit and shift. A cluster of night-shift falls on one hall becomes a performance improvement project, and the QAPI packet holds each event's record. ## What is in the pack **Forms:** Nursing home incident report; Fall report with post-fall checks; Injury of unknown source form (CMS's three criteria); Abuse, neglect or exploitation allegation form; Medication error report (F760); Elopement or wandering report; Pressure injury report; Notice record for physician and resident representative **Routing:** Fall or any injury: DON and charge nurse at once; Abuse, neglect or exploitation allegation, or unknown-source injury: administrator, 2-hour deadline flagged; Alleged violation without abuse or serious bodily injury: administrator, 24-hour deadline flagged; State Survey Agency report due in 5 working days: administrator, deadline flagged; Medication error: DON and consultant pharmacist **Exports:** QAPI summary packet for the QAA committee, one PDF per quarter; CSV counts of falls, medication errors and wounds by unit, shift, cause; Incident PDF with investigation, actions and signatures; Survey and plan of correction packets (rolling out) **Roles:** Reporter: CNA, nurse, therapist, dietary or housekeeping staff; Editor: charge nurses and unit managers; Supervisor: DON, who investigates and checks fixes; Admin: administrator, who decides abuse reporting; Super admin: corporate clinical or compliance lead; Viewer: QAA members, medical director and consultants ## Outcomes - **A fall asked about once, completely:** Lauren covers every post-fall question at the bedside, so the DON starts with facts, not a call-back list. - **The abuse deadline in view:** Questions about unexplained injury and allegations route to the administrator. The deadline is flagged and notice times are recorded. - **Actions that stay open until they work:** Each care-plan change has an owner and an effectiveness check. The incident closes only after a person verifies the fix. - **A QAA record in the order surveyors ask:** Events, investigations, actions and results are linked, so you can show each step for any event. ## Frequently asked questions ### What counts as a fall under F689? CMS defines a fall as unintentionally coming to rest on the ground, floor or a lower level, not from an overwhelming external force. A resident found on the floor counts, and so does a fall without injury or a loss of balance someone prevented. See [F689](https://incidentkit.ai/compliance/f-tags/f689). ### What are the abuse reporting deadlines for a nursing home? Report immediately, within 2 hours if an allegation involves abuse or serious bodily injury, and within 24 hours if not (42 CFR 483.12(c)(1)). This covers abuse, neglect, exploitation, mistreatment and injuries of unknown source. Investigation results go to the State Survey Agency within 5 working days. See [abuse reporting deadlines](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting). ### Can surveyors see our QAA committee records? Only as they relate to the committee's compliance with the rule. The rule says a State or the Secretary may not require disclosure of QAA committee records otherwise. The QAPI packet is built to show that compliance: meetings, data reviewed and plans of action. Ask your counsel how it applies to you. ### Does Lauren decide whether something is abuse? No. Lauren asks questions and flags answers that may point to an allegation or an injury of unknown source. The nurse, DON and administrator make every determination and sign. Spanish and other languages for reporters are rolling out. ### Who built IncidentKit, and what does it cost for a nursing home? PharmPro's compliance consulting practice built it: 31 years in survey and inspection prep and 250+ facilities taken through survey. Nursing homes use the per-site Regulated plan with a BAA, compliance packets and done-for-you setup, and no seats, modules or setup fee. See [pricing](https://incidentkit.ai/pricing). ## Sources - [CMS State Operations Manual, Appendix PP: Guidance to Surveyors for Long Term Care Facilities](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [42 CFR 483.12, Freedom from abuse, neglect, and exploitation (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-G/part-483/subpart-B/section-483.12) - [42 CFR 483.25, Quality of care (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-G/part-483/subpart-B/section-483.25) - [42 CFR 483.10, Resident rights, notification of changes (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-G/part-483/subpart-B/section-483.10) - [42 CFR 483.45, Pharmacy services (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-G/part-483/subpart-B/section-483.45) - [42 CFR 483.75, Quality assurance and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-G/part-483/subpart-B/section-483.75) ## Related - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [Incident routing and escalation by severity](https://incidentkit.ai/product/routing-and-escalation) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Fall Reporting: What to Record and Review After a Fall](https://incidentkit.ai/use-cases/fall-reporting) - [Abuse Reporting Deadlines for Nursing Homes: 2 and 24 Hours](https://incidentkit.ai/use-cases/abuse-reporting-deadlines) - [Medication Error Reporting: Steps, Severity and Follow-Up](https://incidentkit.ai/use-cases/medication-error-reporting) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [Nursing Home Incident Report Template (Printable)](https://incidentkit.ai/templates/nursing-home-incident-report) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [F689 accidents and supervision: falls, hazards, devices](https://incidentkit.ai/compliance/f-tags/f689) - [F600 free from abuse and neglect: what surveyors cite](https://incidentkit.ai/compliance/f-tags/f600) - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) - [F610 investigate, prevent and correct alleged violations](https://incidentkit.ai/compliance/f-tags/f610) - [F760 significant medication errors: how surveyors cite it](https://incidentkit.ai/compliance/f-tags/f760) - [F865 QAPI program and plan: what surveyors ask for](https://incidentkit.ai/compliance/f-tags/f865) - [F867 QAPI improvement activities: adverse event tracking](https://incidentkit.ai/compliance/f-tags/f867) - [F868 QAA committee: members, meetings and evidence](https://incidentkit.ai/compliance/f-tags/f868) - [Nursing home abuse reporting: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting) - [Nursing home recertification survey: process and prep](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) --- # Incident reporting for assisted living communities > Log incidents and family calls the same shift, and keep a clean state record. Source: https://incidentkit.ai/solutions/assisted-living · Updated Oct 5, 2026 **Who:** Caregivers, medication technicians and nurses report. The wellness director investigates, the executive director decides on state reporting and signs, and regional operators review trends across communities. ## The problems - **The family hears it from the resident first:** A fall at supper reaches the daughter as a worried call. Who called the family, and when, lives in someone's memory, not the record. - **State rules differ and change:** Which incidents your state wants reported, to whom and how fast depends on your license type. One policy binder rarely fits every community. - **Reports get written at shift end:** Details a wellness director needs, like footwear, last-seen time and medication times, fade before the form is filled in. - **Operators see incidents one community at a time:** A regional director learns of a pattern of evening falls or medication errors only after a licensing visit. ## Incident types in the pack - Resident fall with or without injury - Medication error - Elopement or exit-seeking in memory care - Altercation between residents - Alleged abuse, neglect or exploitation - Unplanned hospital or ER transfer - Unexplained bruise or skin injury - Choking event - 911 call or emergency response - Missing or damaged resident property - Infection cluster - Fire alarm, power loss or water leak ## Regulators and standards - **State assisted living licensure:** Assisted living is licensed and regulated by each state. Terms and rules differ. Check yours. - **State licensing agency:** Your state sets which incidents are reportable, to whom and how fast. Each community's routing can follow its own state's steps, and a person records every reporting decision. - **Adult protective services and law enforcement:** Where your state requires it, abuse, neglect or exploitation allegations go to adult protective services or law enforcement. Confirm who and how fast. - **Federal rules by funding and campus type:** Some federal rules may apply, depending on how a community is funded and organized. The National Center for Assisted Living publishes an annual Assisted Living State Regulatory Review. - **CARF, aging services:** Some communities pursue CARF accreditation. CARF says its standards cover service safety, ongoing performance improvement and risk management. ## How it works 1. **Report from the hallway** Scan the QR code or text Lauren. She asks what a wellness director would: activity, last seen, injury, medications, who was called. Voice, Spanish and more languages are rolling out. 2. **Route and decide** The wellness and executive directors are told at once. Every notice, family and physician included, is logged with a time. A person decides on state reporting and signs. 3. **Change the service plan** A service-plan update, therapy referral or night-light and bed-height check gets an owner, due date and evidence. An effectiveness check confirms the change held before the incident closes. 4. **Show a clean history at licensing** Incident history, notification record and corrective-action history export as PDF or CSV. Regional leaders see falls, medication errors and elopement across communities in one view. ## Scenario: An evening fall with a wrist injury, from text to closed action An example, not a customer story: one community handles a fall, the family call and the state decision. - **18:40, Fall found, resident sent to ER.** A caregiver finds a resident on the floor beside the bed. The medication technician assesses, follows emergency policy and arranges ER transport for a painful wrist. Afterward she texts Lauren. - **18:55, Lauren drafts, medication technician signs.** Lauren asks if the fall was witnessed, what the resident was doing, when last seen and which medications were given. The draft says “Lauren · draft”; the technician signs. - **19:00, Directors notified, state step flagged.** The incident type points the executive director and wellness director to the community's state reporting step and the family notice, and both are notified. - **19:20, Family call logged with time.** Who was reached on the family call is logged with the time. The audit trail records each entry. - **Next day 09:00, State decision recorded, investigation opens.** The executive director records whether to report to the state, and why. The wellness director opens the investigation. Lauren drafts likely causes, like evening medication timing; the director signs. - **Day 2, Service plan updated, actions assigned.** A therapy referral, a night-light and bed-height check, and a pharmacist review of evening doses get owners and dates. - **Day 30, No further falls, incident closes.** The effectiveness check, no further falls in the period, is attached. The wellness director verifies the actions and the incident closes. - **Month end, Quality meeting reviews falls by shift.** The regional director sees falls by shift and location across communities, the same view the community's quality meeting has. ## What is in the pack **Forms:** Resident incident report; Fall report with follow-up; Medication error report; Elopement report; Resident altercation report; Family and responsible party notice record; State reporting decision record; Investigation and action plan **Routing:** Fall with injury, 911 call or hospital transfer: executive and wellness directors; Abuse, neglect or exploitation allegation: executive director, plus state steps; Elopement or exit seeking: executive and memory care directors; Medication error: wellness director and pharmacy consultant; Every incident: family notice recorded with a time **Exports:** Quarterly packet by community, one PDF for the quality meeting; CSV incident history by community, date and type; Incident PDF with notices, investigation and signatures; Regional report across communities, with org-wide analytics on Network **Roles:** Reporter: caregiver, medication technician, nurse or other staff; Editor: shift leads; Supervisor: wellness director; Admin: executive director, who decides on state reporting; Super admin: regional director; Viewer: owners, consultants and quality advisors ## Outcomes - **Family calls with a time attached:** Every incident records who was notified and when, so the answer to the daughter's question is in the record. - **State steps set per community:** Each community has its own routing policy, and a person records every reporting decision with the reason. - **Details captured while they are fresh:** A short text chat asks what a wellness director would, so the report is complete before the shift ends. - **One view across communities:** Regional leaders compare falls, medication errors and elopement by community, shift and cause. ## Frequently asked questions ### Does IncidentKit know my state's assisted living reporting rules? No, it does not claim to encode every state's rules. Your state licensing agency sets what is reportable, to whom and how fast. At setup we write each community's routing policy from your policies, and a person records every reporting decision. Automated reportability rules are rolling out. ### How does family notification work? Every incident has a place to record who was notified and when, including family or responsible party and the physician. The caregiver or nurse logs who was reached and the time, and the audit trail keeps the entry. Whether and when to notify follows your policy and state rules. ### Is assisted living regulated by CMS? No, it is licensed and regulated at the state level. So there is no single federal incident-reporting rule for it. Some federal rules may apply depending on funding. The National Center for Assisted Living publishes an annual State Regulatory Review of requirements across states. ### Can we use it for memory care? Yes. The pack includes elopement and exit-seeking reports and incidents between residents, and routes them to the executive director and memory care director. Analytics cluster events by location and shift, which shows which door or hour is the problem. ### What is included in the plan? Communities that record resident health information use the per-site Regulated plan: a BAA, compliance packets and done-for-you setup. There are no seats, modules or setup fees. Operators with 10 or more communities use Network, which adds SSO, API, org-wide analytics and migration. See [pricing](https://incidentkit.ai/pricing). ## Sources - [ASPE, Compendium of Residential Care and Assisted Living Regulations and Policy, 2015 edition](https://aspe.hhs.gov/reports/compendium-residential-care-assisted-living-regulations-policy-2015-edition) - [NCAL, State regulation of assisted living and the State Regulatory Review](https://www.ahcancal.org/Assisted-Living/Policy/Pages/State-Regulations.aspx) - [CARF, Accreditation](https://carf.org/accreditation/) ## Related - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) - [Incident routing and escalation by severity](https://incidentkit.ai/product/routing-and-escalation) - [Fall Reporting: What to Record and Review After a Fall](https://incidentkit.ai/use-cases/fall-reporting) - [Medication Error Reporting: Steps, Severity and Follow-Up](https://incidentkit.ai/use-cases/medication-error-reporting) - [Abuse Reporting Deadlines for Nursing Homes: 2 and 24 Hours](https://incidentkit.ai/use-cases/abuse-reporting-deadlines) - [Multi-site incident reporting software for groups](https://incidentkit.ai/solutions/multi-site-groups) - [Elopement: definition and meaning](https://incidentkit.ai/glossary/elopement) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) - [Nursing home abuse reporting: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting) - [CARF accreditation: surveys, QIPs and the ASPIRE framework](https://incidentkit.ai/compliance/accreditation/carf) --- # Incident reporting for behavioral health programs > Capture elopement, restraint and self-harm events, route them fast, and show the fixes held. Source: https://incidentkit.ai/solutions/behavioral-health · Updated Oct 5, 2026 **Who:** Nurses, behavioral health technicians and counselors report. Program directors investigate, the patient safety officer or clinical director signs, and the quality committee and governing body review trends. ## The problems - **Restraint events need a story and a checklist:** Orders, the 1-hour evaluation, monitoring and debrief live in the chart. The incident report must match, and writing facts twice invites gaps. - **Elopement data hides in shift notes:** Doors, visiting hours and observation levels matter, but the report just says the patient left. The pattern by door and time stays hidden. - **Debriefs happen, follow-through does not:** After a restraint or self-harm event, the team meets and agrees on changes. No one owns the change or checks that it worked. - **Several reviewers, several formats:** The Joint Commission, CARF, the state and payers each want incident data differently, and programs in one organization use different forms. ## Incident types in the pack - Elopement or missing patient - Physical restraint event - Seclusion event - Drug or medication used as a restraint - Suicide attempt or self-harm - Suicide death, including within 7 days of discharge - Patient-to-patient assault - Assault on staff - Sexual safety event - Medication error - Contraband or search finding - Ligature or environment-of-care hazard ## Regulators and standards - **42 CFR 482.13(e), restraint and seclusion:** Violent or self-destructive behavior: orders last up to 4 hours for adults, 2 hours for ages 9 to 17, 1 hour under 9. Face-to-face evaluation within 1 hour. - **42 CFR 482.13(g), death reporting:** Report to CMS by close of the next business day after you know. Covers deaths in restraint or seclusion, within 24 hours after, or within 1 week if restraint contributed. - **42 CFR 483.374, psychiatric residential treatment facilities:** A death, serious injury or suicide attempt goes to the State Medicaid agency and Protection and Advocacy system by close of next business day. Guardians of minors: within 24 hours. - **The Joint Commission:** Sentinel events: death by self-harm in care or within 7 days of discharge. Also elopement from a 24-hour setting leading to death or severe harm. Analysis within 45 business days. - **CARF:** Accredits behavioral health programs and says its standards cover service safety, ongoing performance improvement and risk management. - **State licensing and reporting:** Residential and outpatient programs answer to state rules that differ by state and level of care. Check yours. ## How it works 1. **Report once, match the chart** Scan the QR code or text Lauren. She asks about the trigger, less restrictive steps tried, intervention and time, evaluation time and who was told. Voice is rolling out. 2. **Route by event type** Restraint, seclusion, elopement and self-harm go to the program director and safety officer at once. A death goes to the risk manager, with the CMS or state deadline noted. 3. **Close the debrief action** Debrief outcomes become actions with an owner, date and evidence, like a door-alarm repair or an observation-level audit. An effectiveness check confirms the change held before anything closes. 4. **Show reviewers the trend** Analytics cluster events by unit, location, shift and cause. The QAPI summary packet and incident PDFs come from the same records; survey packets are rolling out. ## Scenario: An elopement from an inpatient unit, from first text to verified fix An example, not a customer story: an elopement with no injury, from first report to a verified door fix. - **19:52, Patient missing at group check.** The charge nurse starts the elopement response under facility policy. IncidentKit joins only after the patient is safe. - **20:40, Police return patient, Lauren drafts report.** The nurse texts Lauren, who asks about observation level, exit route, door alarms and who was notified. The draft says “Lauren · draft”; the nurse signs. - **20:55, Three leaders notified at immediate priority.** Physician and guardian notices are logged with times, with any state notice your policy requires. The program director, patient safety officer and medical director are notified at once. - **Next morning, Investigation opens, door pattern surfaces.** Lauren drafts likely causes, and the analytics view shows two earlier door-alarm events at the same courtyard door. The program director edits and signs. - **Day 2, Three actions get owners and dates.** Repair the courtyard door alarm, with the work order attached. Audit observation notes for a month, and add a door-watch step to visiting hours. - **Day 60, Alarm test log verifies the fix.** The effectiveness check, no exits through that door, is attached with the alarm test log. The patient safety officer verifies it and the actions close. - **Quarter end, Committee reviews elopements by door.** Elopements and attempts by door and shift go to the quality committee. The QAPI packet holds the record for the next Joint Commission or CARF review. ## What is in the pack **Forms:** Behavioral health incident report; Elopement report with observation level and exit route; Restraint and seclusion report matched to the order and 1-hour evaluation; Self-harm and suicide attempt report; Assault report, patient to patient and on staff; Medication error report; Debrief record; Investigation and action plan **Routing:** Restraint or seclusion: program director and patient safety officer at once; Restraint or seclusion death: risk manager, with the CMS deadline noted; Residential treatment serious occurrence: administrator, State Medicaid and Advocacy deadlines noted; Elopement: program director and safety officer, plus facilities for doors or fences; Suicide attempt or death: clinical and medical directors, with sentinel event review **Exports:** CSV counts of restraint and seclusion events by unit, shift and intervention; QAPI summary packet for the quality committee, one PDF; Incident PDF with investigation, actions and signatures; Survey packet for Joint Commission or CARF review (rolling out) **Roles:** Reporter: nurse, behavioral health technician, counselor or therapist; Editor: charge nurses and shift leads; Supervisor: program director, who owns actions; Admin: patient safety officer and clinical director; Super admin: system quality lead; Viewer: governing body, medical director and consultants ## Outcomes - **A restraint report that matches the chart:** Questions follow the order, the 1-hour evaluation and monitoring record, so the report and chart tell the same story. - **Death and serious occurrence deadlines in view:** Routing sends the event to the right person with the deadline noted, so next-business-day reports do not rely on memory. - **Environment fixes that get checked:** A door-alarm repair or observation audit has an owner, a date, evidence and an effectiveness check. - **Patterns by door, unit and shift:** Analytics cluster elopements and restraint events by location, shift and cause, so the next debrief starts from the pattern. ## Frequently asked questions ### What are the restraint and seclusion rules for hospitals? Restraint or seclusion needs an order from a physician or licensed practitioner (42 CFR 482.13(e)). The order is never standing or PRN. For violent or self-destructive behavior, each order lasts 4 hours for adults, 2 for ages 9 to 17 and 1 under 9. Orders can renew up to 24 hours. States may be stricter. ### Which restraint-related deaths must a hospital report to CMS? Report these deaths to CMS by close of business the next business day after you know (42 CFR 482.13(g)). They are: each death in restraint or seclusion, within 24 hours after removal, or within 1 week where restraint reasonably contributed. If only soft wrist restraints were used and no seclusion, log the death internally within 7 days instead. ### Do these rules apply to residential or outpatient programs? The hospital rules apply to hospitals, including psychiatric hospitals. Psychiatric residential treatment facilities for people under 21 have their own serious occurrence rule at 42 CFR 483.374. Other residential and outpatient programs follow state licensing and their accreditor. Check which applies to each program; IncidentKit lets you mix packs across sites. ### How does the Joint Commission treat suicide and elopement? Its Sentinel Event Policy lists death by self-inflicted injurious behavior in a care setting or within 7 days of discharge from listed services. It also lists elopement from a setting staffed around the clock that leads to death, permanent harm or severe harm. See [sentinel events](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events). ### Who can see these records, and is a BAA included? Access follows role and facility, and every change is logged with who, when and what changed. The per-site Regulated plan includes a BAA, patient information, compliance packets and done-for-you setup. See [security](https://incidentkit.ai/security) and [HIPAA](https://incidentkit.ai/hipaa). ## Sources - [42 CFR 482.13, Patient rights, restraint and seclusion (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-G/part-482/subpart-B/section-482.13) - [42 CFR 483.374, PRTF facility reporting (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-G/part-483/subpart-G/section-483.374) - [Joint Commission Sentinel Event Policy (CAMH Update 1, July 2026)](https://digitalassets.jointcommission.org/api/public/content/4035922bcc2f41bd83fbc1f55764a7b4?v=bf31f43b) - [CARF, Accreditation](https://carf.org/accreditation/) ## Related - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [Incident routing and escalation by severity](https://incidentkit.ai/product/routing-and-escalation) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Workplace Violence Reporting: Healthcare, Retail, Industrial](https://incidentkit.ai/use-cases/workplace-violence-reporting) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Elopement: definition and meaning](https://incidentkit.ai/glossary/elopement) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [CARF accreditation: surveys, QIPs and the ASPIRE framework](https://incidentkit.ai/compliance/accreditation/carf) - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) - [Joint Commission survey readiness: tracers, unannounced](https://incidentkit.ai/compliance/survey-readiness/joint-commission-survey-readiness) --- # Incident reporting for hospice field teams and patient homes > Nurses report from the driveway; the IDG takes each incident to a verified fix. Source: https://incidentkit.ai/solutions/hospice · Updated Oct 5, 2026 **Who:** Nurses, aides, social workers and chaplains report from patient homes. The clinical director investigates, the administrator owns abuse reporting, and the interdisciplinary group (IDG) and QAPI committee review changes. ## The problems - **Incidents happen where there is no desk:** A fall, missed dose or failing oxygen concentrator turns up on a home visit. The report waits for a computer, if it is written. - **Much of the care is given by family:** A family caregiver's drug error is not a staff error. Still, 42 CFR 418.58 asks QAPI to track it as an adverse patient event. - **Allegations need an immediate path:** Under 42 CFR 418.52, alleged mistreatment, neglect, abuse or an injury of unknown source must reach the administrator immediately. - **The IDG hears stories, QAPI needs data:** Incidents are discussed at the IDG, then vanish into notes. QAPI asks you to track events, analyze causes, act, and show results last. ## Incident types in the pack - Patient fall at home or in a facility - Medication error, including caregiver errors - Controlled-substance discrepancy or suspected diversion - Equipment event (oxygen, bed, pump) - New or worsened pressure injury - Injury of unknown source - Alleged mistreatment, neglect or abuse - Missed or late visit - Unplanned hospital or ED transfer - Patient or family complaint - Staff safety event in the home - Infection event ## Regulators and standards - **42 CFR 418.58, hospice QAPI:** An ongoing, hospice-wide, data-driven program that tracks adverse patient events, analyzes causes, acts to prevent them and checks that gains last. The governing body names who runs it. - **42 CFR 418.52(b), alleged violations:** Alleged mistreatment, neglect, abuse, injuries of unknown source and misappropriation go to the administrator and are investigated immediately. Verified violations go to state and local bodies within 5 working days. - **42 CFR 418.52(b)(1), grievances:** Patients may voice grievances about care that is or is not furnished, and about respect for property. - **42 CFR 418.56, interdisciplinary group:** The IDG (physician, registered nurse, social worker, counselor) writes and updates the plan of care. That is where incident-driven changes land. - **ACHC and CHAP:** CMS-approved accreditors that survey hospices. ACHC says it has held hospice deeming authority since 2009. - **State licensure:** State rules for hospice incidents and abuse reporting differ. Check yours. ## How it works 1. **Report from the car or kitchen** Open quick report or text Lauren from the driveway. She asks what a clinical director would. Quick reports queue offline; fuller offline forms and voice are rolling out. 2. **Route to the right person** Unknown-source injuries and abuse or neglect allegations go to the administrator, with the deadline flagged. Falls and medication events go to the clinical director. Lauren drafts; a person signs. 3. **Take it to the IDG** Caregiver teaching, a bedside commode or a vendor equipment swap gets an owner and date and goes on the IDG agenda. Nothing closes until the effectiveness check is verified. 4. **Show QAPI the loop** Falls, medication events and equipment issues cluster by team, level of care and cause. The QAPI summary packet and incident PDFs come from the same records. ## Scenario: A fall at home found on a visit, from driveway to IDG An example, not a customer story: a home fall, an equipment question and a teaching action, through the IDG to a verified close. - **Fri 16:30, Nurse finds patient on floor.** On a routine visit, the nurse finds the patient on the floor with a bruised hip, an hour after a fall. After assessing and calling the physician, she texts Lauren. - **16:48, Lauren asks follow-ups, nurse signs.** Lauren asks if the fall was witnessed, whether a commode was in use and which medications were given. The draft says “Lauren · draft”; the nurse signs. - **16:55, Clinical director notified at urgent priority.** The injury is explained and no one alleges mistreatment, so no abuse path applies. Otherwise the administrator would be alerted at once. - **Mon 09:00, Clinical director opens the investigation.** Lauren drafts likely causes: an unassisted commode transfer, bed height and evening opioid timing. The clinical director edits and signs. - **Tue, IDG updates plan, three actions assigned.** Caregiver teaching on transfers (nurse), a bedside commode (vendor) and a medication-timing review (medical director) get owners and dates. - **Day 30, Teach-back documented, actions close.** The effectiveness check, no further falls and a documented caregiver teach-back, is attached. The clinical director verifies it and the actions close. - **Quarter end, QAPI committee reviews home falls.** Home falls by team and level of care go to the QAPI committee. The QAPI summary packet shows each event from report to verified action. ## What is in the pack **Forms:** Hospice incident report for homes and facilities; Fall report with equipment fields; Medication event report, including caregiver errors; Equipment event report with vendor details; Injury of unknown source and alleged violation form; Grievance record; Missed or late visit report; Investigation and action plan **Routing:** Alleged mistreatment, neglect or abuse, or unknown-source injury: administrator, 5-working-day report flagged; Fall or medication event: clinical director the same day; Equipment event: clinical director, with the vendor named on the record; Controlled substance discrepancy: clinical director and pharmacy contact; Every corrective action: listed for the next IDG meeting **Exports:** QAPI summary packet for 42 CFR 418.58, one PDF; CSV counts of falls, medication and equipment events by team and cause; Incident PDF with investigation, actions and signatures; Survey packet (rolling out) **Roles:** Reporter: nurse, aide, social worker, chaplain or volunteer coordinator; Editor: team managers; Supervisor: clinical director; Admin: administrator, who owns alleged violations; Super admin: compliance lead across locations; Viewer: medical director, governing body and consultants ## Outcomes - **Reports from where the incident happened:** A text chat from the driveway replaces an end-of-day form, so details are captured while the clinician remembers. - **A clear path for allegations:** An allegation or unknown-source injury reaches the administrator at once, with the reporting deadline flagged. - **Changes that reach the plan of care:** IDG review is part of the action, so caregiver teaching and equipment changes are owned, dated and verified. - **QAPI evidence on demand:** Adverse patient events, causes, preventive actions and verification sit in one record. ## Frequently asked questions ### What does 42 CFR 418.58 require of hospices? An effective, ongoing, hospice-wide, data-driven QAPI program. You must track quality indicators including adverse patient events, analyze their causes, act to prevent them and show gains last. You must run and document improvement projects, and the governing body must name who runs the program. See [hospice QAPI](https://incidentkit.ai/compliance/cms-qapi/hospice). ### What does the hospice rule say about alleged abuse or neglect? Report it to the hospice administrator immediately, and investigate immediately (42 CFR 418.52(b)). This covers alleged mistreatment, neglect, abuse, injuries of unknown source and misappropriation of property by anyone furnishing services. Act to prevent further violations. Verified violations go to state and local bodies within 5 working days. See [abuse reporting](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting). ### Can field staff report with weak cell signal? Yes. Quick report queues on the phone and sends when the connection returns, and IncidentKit installs from the browser with no app store step. Fuller offline forms and photo capture are rolling out. See [mobile and offline reporting](https://incidentkit.ai/product/mobile-and-offline). ### Does it connect to our hospice EHR? Pre-built EHR connectors are rolling out; today IncidentKit runs alongside your EHR and does not replace it. A read API and signed webhooks are available now. Staff report on a phone without opening a chart. ### How are family caregiver errors handled? As adverse patient events. A medication or equipment error by a caregiver in the home is tracked like any other. The pack has caregiver-administration fields and routes the report to the clinical director. Caregiver teaching is a typical corrective action, with an owner, a date and a teach-back as evidence. ## Sources - [42 CFR 418.58, Hospice QAPI (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-B/part-418/subpart-C/section-418.58) - [42 CFR 418.52, Patient's rights (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-B/part-418/subpart-C/section-418.52) - [42 CFR 418.56, Interdisciplinary group, care planning and coordination (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-B/part-418/subpart-C/section-418.56) - [ACHC, Hospice accreditation](https://achc.org/hospice/) - [CHAP, Community Health Accreditation Partner](https://www.chapinc.org/) - [CMS, Accreditation programs and approved accrediting organizations](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs) ## Related - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [Mobile incident reporting that works offline](https://incidentkit.ai/product/mobile-and-offline) - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Fall Reporting: What to Record and Review After a Fall](https://incidentkit.ai/use-cases/fall-reporting) - [Medication Error Reporting: Steps, Severity and Follow-Up](https://incidentkit.ai/use-cases/medication-error-reporting) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [Home health incident reporting software for field staff](https://incidentkit.ai/solutions/home-health) - [Hospice QAPI requirements: 42 CFR 418.58 explained](https://incidentkit.ai/compliance/cms-qapi/hospice) - [ACHC accreditation: deemed status, surveys and standards](https://incidentkit.ai/compliance/accreditation/achc) - [Nursing home abuse reporting: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) --- # Incident reporting for home health agencies and field clinicians > Report from the home and tie emergent care to a cause and verified fix. Source: https://incidentkit.ai/solutions/home-health · Updated Oct 5, 2026 **Who:** Field nurses, therapists, aides and intake staff report. The clinical manager investigates, the administrator owns complaints and abuse reporting, and the QAPI committee and governing body review trends. ## The problems - **Field staff work alone and on the move:** A clinician in a car has no event system nearby. Reports wait for the evening, when the details have blurred. - **The rule names emergent care and readmissions:** 42 CFR 484.65 names emergent care, hospital admissions and readmissions as QAPI outcomes. Without the incident behind each, a number has no cause. - **Complaints, abuse concerns and safety events blur together:** Complaints need an investigation and a record. Staff must report mistreatment, neglect or unknown-source injury at once. All arrive by phone, text and visit note. - **Branches keep their own logs:** Each branch has its own form and spreadsheet. The administrator cannot compare falls or medication events by branch, discipline or shift. ## Incident types in the pack - Patient fall in the home - Medication error or discrepancy - New or worsened wound or pressure injury - Emergent care or unplanned admission - Infusion, line or catheter event - Patient or caregiver complaint - Alleged mistreatment, neglect or abuse - Missed or late visit - Home equipment failure - Clinician safety event in the home - Clinician injury or needlestick - Privacy event (lost device or notes) ## Regulators and standards - **42 CFR 484.65, HHA QAPI:** An agency-wide, data-driven program focused on emergent care, admissions, readmissions and preventing medical errors. It tracks adverse patient events, fixes safety threats at once and documents improvement projects. - **42 CFR 484.50(e), complaints:** Investigate complaints from patients, representatives and caregivers. Document the complaint and its resolution. Prevent further violations, including retaliation, while you investigate. - **42 CFR 484.50(e)(2), staff reporting:** Staff must report mistreatment, neglect, abuse, an injury of unknown source or misappropriation of patient property. Reports go immediately to the agency and to other authorities under state law. - **21 CFR 803.30, FDA device reports:** FDA's outpatient treatment facility definition includes home health care groups. Report device-related deaths to FDA and the manufacturer, and serious injuries to the manufacturer, within 10 work days. - **ACHC and CHAP:** CMS-approved accreditors for home health. ACHC says it has held home health deeming authority since 2006. - **State licensure:** State home health licensing and abuse reporting rules differ. Check yours. ## How it works 1. **Report from the home** Open quick report or text Lauren. She asks what a clinical manager would: what happened, injury, medications, equipment, physician called, ED visit. Quick reports queue offline. Voice is rolling out. 2. **Route and investigate** Allegations and unknown-source injuries go to the administrator at once. Falls, medication events and emergent care go to the clinical manager. Lauren drafts the investigation; a person signs. 3. **Fix the cause and check it** A therapy order, a home safety check or a medication reconciliation change gets an owner, due date and evidence. Nothing closes until a person verifies the effectiveness check. 4. **Put a cause behind the numbers** Events cluster by branch, discipline, shift and cause, so emergent care and readmission numbers have an incident behind them. The QAPI summary packet comes from the same records. ## Scenario: A home fall ends in an ED visit and a QAPI project An example, not a customer story: a home fall tied to the emergent care indicator 42 CFR 484.65 asks you to track. - **21:15, Caregiver calls the on-call line.** The patient fell on the way to the bathroom and is going to the ED. The on-call nurse takes the call, then texts Lauren. - **21:35, Lauren asks about walker, medications.** Lauren asks about the last fall-risk assessment, medication changes in two weeks, therapy orders, which ED and the walker. The draft says “Lauren · draft”; the nurse signs. - **21:40, Manager notified, emergent care typed.** The physician notice is logged with a time. The clinical manager is notified at urgent priority and the event is typed as emergent care. - **Next day 09:00, Clinical manager opens the investigation.** Lauren drafts likely causes: a walker kept out of reach, a recent medication change and a pending therapy evaluation. The clinical manager edits and signs. - **Day 2, Therapy, home check, teaching assigned.** The therapy lead schedules the evaluation; a field nurse does a home safety check at the next visit and teaches the caregiver about walker placement. Each action gets an owner and date. - **Day 40, Fall-free 30 days, actions close.** The patient is home again and 30 days pass without a fall. The visit note and teaching record are attached. The clinical manager verifies the check and the actions close. - **Monthly QAPI, Committee finds cluster in one branch.** The committee sees falls that led to emergent care by branch and cause. A cluster in one branch becomes a documented performance improvement project, with progress tracked. ## What is in the pack **Forms:** Home health incident report; Fall report with fall risk and equipment fields; Medication discrepancy and error report; Wound or pressure injury report; Emergent care or unplanned admission report; Complaint record with resolution; Injury of unknown source and alleged violation form; Clinician safety event report; Investigation and action plan **Routing:** Abuse, neglect or mistreatment allegation, or unknown-source injury: administrator, plus state steps; Fall, medication or wound event: clinical manager the same day; Emergent care or unplanned admission: clinical manager and QAPI lead; Complaint: clinical manager, with the resolution recorded on the incident; Device death or serious injury: administrator decides on the 10-work-day FDA report **Exports:** QAPI summary packet for 42 CFR 484.65, one PDF; CSV of emergent care and admission events by branch and cause; CSV of complaints and their resolutions; Incident PDF with investigation, actions and signatures; Survey packet (rolling out) **Roles:** Reporter: nurse, therapist, aide, intake or scheduling staff; Editor: branch leads; Supervisor: clinical manager; Admin: administrator, who owns complaints and alleged violations; Super admin: QAPI or compliance lead across branches; Viewer: governing body and consultants ## Outcomes - **Reports from the field, between visits:** A text chat replaces a form at the desk, so details are captured while the clinician remembers. - **Indicators with a cause behind them:** Emergent care and admission events link to their incident, so QAPI sees why as well as how many. - **Complaints and allegations on a documented path:** Each complaint has an owner and a recorded resolution. An allegation reaches the administrator at once. - **Branch comparisons from one vocabulary:** Falls and medication events are comparable across branches, disciplines and shifts. ## Frequently asked questions ### What does 42 CFR 484.65 require? An agency-wide, data-driven QAPI program focused on outcomes such as emergent care, hospital admissions and readmissions, and on preventing medical errors. You must track quality indicators including adverse patient events, fix threats to patient safety at once, run documented improvement projects and show gains last. See [home health QAPI](https://incidentkit.ai/compliance/cms-qapi/home-health). ### Does IncidentKit read or submit OASIS data? No. IncidentKit runs alongside your EHR and OASIS workflow and does not submit OASIS. The QAPI rule says quality data can include OASIS-derived measures. IncidentKit holds the incident record beside them, such as the fall behind an emergent care event. Deeper EHR connections are rolling out. ### How should staff report an allegation of abuse or neglect? Immediately, to the agency and to other authorities under state law (42 CFR 484.50(e)(2)). This covers mistreatment, neglect, abuse, injuries of unknown source and misappropriation of patient property. IncidentKit routes these to the administrator at once and logs who was told and when. Check your state's rules for authorities and timing. ### Do home health agencies report device events to FDA? Possibly. FDA's outpatient treatment facility definition includes home health care groups, which makes them device user facilities. These report device-related deaths to FDA and the manufacturer, and serious injuries to the manufacturer, within 10 work days. Ask your compliance officer if your agency is covered; IncidentKit routes device events to the administrator and keeps the record. ### What input and languages are supported? Staff report by text today. Voice reporting is rolling out, as are Spanish and other languages. Lauren drafts and a person reviews, edits and signs; every drafted field is marked “Lauren · draft”. ## Sources - [42 CFR 484.65, Home health QAPI (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-G/part-484/subpart-B/section-484.65) - [42 CFR 484.50, Patient rights, investigation of complaints (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-G/part-484/subpart-B/section-484.50) - [21 CFR 803.30, Device user facility reporting (eCFR)](https://www.ecfr.gov/current/title-21/chapter-I/subchapter-H/part-803/subpart-C/section-803.30) - [21 CFR 803.3, Definitions, including outpatient treatment facility (eCFR)](https://www.ecfr.gov/current/title-21/chapter-I/subchapter-H/part-803/subpart-A/section-803.3) - [ACHC, Home health accreditation](https://achc.org/home-health/) - [CHAP, Community Health Accreditation Partner](https://www.chapinc.org/) - [CMS, Accreditation programs and approved accrediting organizations](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs) ## Related - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [Mobile incident reporting that works offline](https://incidentkit.ai/product/mobile-and-offline) - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) - [Incident analytics: find the pattern before the next one](https://incidentkit.ai/product/analytics) - [Fall Reporting: What to Record and Review After a Fall](https://incidentkit.ai/use-cases/fall-reporting) - [Medication Error Reporting: Steps, Severity and Follow-Up](https://incidentkit.ai/use-cases/medication-error-reporting) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [Hospice incident reporting software for field teams](https://incidentkit.ai/solutions/hospice) - [Home health QAPI requirements: 42 CFR 484.65 guide](https://incidentkit.ai/compliance/cms-qapi/home-health) - [ACHC accreditation: deemed status, surveys and standards](https://incidentkit.ai/compliance/accreditation/achc) - [Nursing home abuse reporting: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting) - [Medical device reporting for user facilities: 21 CFR 803](https://incidentkit.ai/compliance/reporting-deadlines/device-adverse-event-reporting) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) --- # Incident reporting for urgent care and outpatient clinics > Log EMS transfers between patients, then see the pattern and fix it across sites. Source: https://incidentkit.ai/solutions/urgent-care-and-outpatient · Updated Oct 5, 2026 **Who:** Providers, nurses, medical assistants and front-desk staff report. The practice manager or medical director investigates and signs, and a regional lead reviews trends across sites. ## The problems - **There are four minutes between patients:** A long form with a drop-down maze does not get filed. The event gets mentioned at day's end, or not at all. - **Each site is its own island:** One clinic reports a missed fracture, another a delayed chest-pain escalation. Nobody sees that both happened on Sunday evenings. - **Most events are early signals, not harm events:** Return visits, patients who left without being seen and EMS transfers sit in the EHR or a front-desk log, rarely together. - **Rules depend on each site's setup:** A physician office, an urgent care center and a hospital outpatient department answer to different rules. A group needs one record with per-site routing. ## Incident types in the pack - EMS transfer or 911 call from the clinic - Return visit for the same complaint - Delayed or missed diagnosis - Left without being seen - Medication or prescribing error - Injection, IV or procedural complication - Specimen, lab or imaging error - Patient fall in the clinic - X-ray, AED or autoclave failure - Aggressive patient or workplace violence - Needlestick or sharps injury - Privacy event ## Regulators and standards - **State licensing:** Urgent care and outpatient sites are licensed under state rules that depend on the type of site. Check which apply to each location. - **CAUCQ, Urgent Care Association:** The Commission on Ambulatory and Urgent Care Quality offers accreditation and other quality distinctions to urgent care centers. - **AAAHC:** Accredits many ambulatory settings, including primary care and community health centers, on a three-year cycle with ongoing improvement expectations. - **21 CFR 803, FDA device reports:** Device user facilities report device-related deaths and serious injuries. They include hospitals, ASCs, nursing homes and outpatient diagnostic and treatment facilities, but not physician offices. Coverage depends on site structure. - **Payer contracts and liability carriers:** Contracts and carriers may set their own reporting expectations. An insurer data feed is rolling out. ## How it works 1. **Report between patients** Scan the QR code and enter three fields, or text Lauren. She asks what a medical director would: complaint, triage level, times, actions, destination. Voice is rolling out. 2. **Route by site** EMS transfers, return-visit escalations and medication errors go to the practice manager and medical director. Lauren drafts the investigation; the medical director edits and signs. 3. **Fix it across sites** When a pattern spans sites, each site gets the same corrective action with its own owner and due date. An effectiveness check confirms the change worked before anything closes. 4. **See the pattern, show the record** Analytics cluster events by site, shift, day and cause, with org-wide roll-ups on Network. The same records give your accreditor, payer or board a summary packet. ## Scenario: A chest-pain transfer on a Sunday evening, fixed at three sites An example, not a customer story: fast intake between patients, then one fix across several sites. - **17:05, Low-acuity triage ends in EMS transfer.** A patient with indigestion has an ECG at 17:20 that shows changes. EMS is called at 17:28 and the patient leaves at 17:41. - **18:10, Medical assistant scans QR, provider signs.** Lauren asks for triage, ECG and EMS times, acuity and destination. The draft says “Lauren · draft”; the provider signs. - **18:15, Practice manager and medical director notified.** Every EMS transfer from a clinic goes to escalation review. The practice manager and medical director are notified at urgent priority. - **Next day, Hospital outcome added, investigation opens.** Lauren drafts likely causes: triage wording, ECG timing and Sunday staffing. The medical director signs. - **Day 4, Same action assigned at three sites.** Analytics show two other sites with Sunday evening EMS transfers this quarter. The regional medical director assigns one action at each site: a triage protocol update with owner and date. - **Day 45, Sites attach audit evidence, actions close.** The effectiveness check is an ECG at triage for the defined complaints, with audit evidence attached by each site. The regional medical director verifies each one and the actions close. - **Quarter end, Multi-site summary goes to leadership.** Where required, the accreditor or payer gets the multi-site summary as well as the leadership team. The insurer data feed is rolling out. ## What is in the pack **Forms:** Urgent care incident report; EMS transfer and escalation review form; Return visit review; Medication and prescribing error report; Delayed diagnosis follow-up report; Fall report; Aggressive patient report; Sharps injury report; Investigation and action plan **Routing:** EMS transfer: practice manager and medical director the same day; Return visit with an adverse outcome: medical director review; Medication or prescribing error: medical director and pharmacy contact; Aggressive patient or violence: practice manager and security lead; Device event: practice manager, for the decision on a device report **Exports:** QAPI summary packet by site and quarter, one PDF; CSV counts of events by site, shift, day and cause; Incident PDF with investigation, actions and signatures; Survey packet for an accreditor (rolling out) **Roles:** Reporter: provider, nurse, medical assistant or front desk staff; Editor: clinic leads; Supervisor: medical director; Admin: practice manager, who owns site actions; Super admin: regional quality lead; Viewer: executives and consultants ## Outcomes - **Reports that fit between patients:** Three fields from a QR code, then Lauren's follow-ups, replace a long form that waits until day's end. - **Early signals in one place:** Return visits, EMS transfers and patients who left unseen share one record, so patterns show before a serious outcome. - **One action, every site:** A regional lead can assign one corrective action at each affected clinic, with its own owner, date and effectiveness check. - **Per-site rules in one account:** Mix packs across sites, such as urgent care and a surgery center, in one account with routing set per site. ## Frequently asked questions ### Is urgent care required to have a QAPI program? It depends on how the site is licensed and accredited. The federal QAPI conditions in 42 CFR apply to certified provider types such as ASCs, hospitals, hospices and home health agencies. Ask your compliance officer. IncidentKit gives you the record either way, with routing and exports set per site. ### Can one account cover urgent care sites and a surgery center? Yes. A pack sets incident types, forms, exports and roles for a kind of site, and you can mix packs across sites in one organization. Groups of 10 or more sites use Network, which adds SSO, API, org-wide analytics and migration. A new site is set up in about 48 hours on Regulated and Network. ### How fast is reporting for a busy clinic? Staff scan a QR code and enter three fields, or text Lauren in plain language. Lauren asks only the follow-up questions a medical director would ask for that event type. The reporter reviews and signs. Voice reporting is rolling out. ### Do urgent care centers report device events to FDA? It depends on how the center is structured. FDA's device user facility definition covers hospitals, ambulatory surgical facilities, nursing homes and outpatient diagnostic and treatment facilities, but excludes physician offices. Ask your compliance officer. IncidentKit routes device events to the practice manager and keeps the record. ### What does it cost? Sites that record patient incidents use the per-site Regulated plan: a BAA, patient information, compliance packets and done-for-you setup. Incidents with no patient information are free on Open. There are no seats, modules or setup fees. See [pricing](https://incidentkit.ai/pricing). ## Sources - [Urgent Care Association, accreditation and quality distinctions (CAUCQ)](https://www.urgentcareassociation.org/) - [AAAHC, Accreditation](https://www.aaahc.org/accreditation/) - [21 CFR 803.3, Definitions, including device user facility and physician's office (eCFR)](https://www.ecfr.gov/current/title-21/chapter-I/subchapter-H/part-803/subpart-A/section-803.3) - [21 CFR 803.30, Device user facility reporting (eCFR)](https://www.ecfr.gov/current/title-21/chapter-I/subchapter-H/part-803/subpart-C/section-803.30) ## Related - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [Incident analytics: find the pattern before the next one](https://incidentkit.ai/product/analytics) - [Multi-site incident management with roles and SSO](https://incidentkit.ai/product/multi-site-and-roles) - [Multi-site incident reporting software for groups](https://incidentkit.ai/solutions/multi-site-groups) - [Incident reporting software for surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Medication Error Reporting: Steps, Severity and Follow-Up](https://incidentkit.ai/use-cases/medication-error-reporting) - [AAAHC accreditation: surveys, deemed status and QI studies](https://incidentkit.ai/compliance/accreditation/aaahc) - [Medical device reporting for user facilities: 21 CFR 803](https://incidentkit.ai/compliance/reporting-deadlines/device-adverse-event-reporting) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) --- # Manufacturing incident reporting, from floor to OSHA log > Report from the line, fix what caused it, and keep the OSHA log ready. Source: https://incidentkit.ai/solutions/manufacturing · Updated Oct 5, 2026 **Status: rolling out.** This pack is being released in stages. **Who:** Operators and leads report, and EHS coordinators investigate. The plant manager owns the fixes, and an executive certifies the OSHA 300A summary. ## The problems - **The form gets filled in a day later:** Shift-end reports lose whether a guard was open. OSHA's seven-day logging clock starts when you learn of the case. - **The 300 log lives in one spreadsheet:** One coordinator owns the file, so day counts drift and privacy cases get missed. An executive still certifies the 300A each February. - **Near misses and guard bypasses stay verbal:** An operator clears a jam with the interlock defeated and tells the next station. Nobody records it, so the pattern stays hidden. - **Corrective actions end at the safety huddle:** 'Discussed at the huddle' means no owner, no due date, no proof. The same jam and wet spot return next quarter. ## Incident types in the pack - Slip, trip or fall - Strain or sprain - Guarding failure or bypassed interlock - Caught-in or amputation - Lockout/tagout event - Struck by a tool or part - Forklift incident - Chemical splash or inhalation - Burn from heat or hot work - Fall from a ladder or platform - Near miss with serious injury potential ## Regulators and standards - **OSHA 29 CFR Part 1904 (recordkeeping):** The 300 log, 300A summary and 301 report. Log each recordable case within seven calendar days. Keep records five years after the year they cover (1904.29, 1904.33). - **OSHA 29 CFR 1904.39 (severe injury reporting):** Report a fatality within 8 hours. Report an inpatient hospitalization, amputation or loss of an eye within 24 hours. - **OSHA 29 CFR 1904.41 (electronic submission):** Establishments in set size and industry groups send data to OSHA's Injury Tracking Application by March 2 each year. Check your NAICS code. - **OSHA 29 CFR 1910.147 (lockout/tagout):** Covers servicing, cleaning and unjamming where a machine could start without warning. Each procedure needs a certified inspection at least yearly. - **OSHA 29 CFR 1910.212 and the amputations emphasis program:** General machine guarding. OSHA's National Emphasis Program on Amputations (CPL 03-00-027) began June 27, 2025 and runs five years. - **OSHA 29 CFR 1910.178 (powered industrial trucks):** Operators must be trained and evaluated. Refresher training follows an accident or near miss, and daily truck exam defects are reported at once. - **OSHA 29 CFR 1910.1200 (hazard communication):** Safety data sheets must be within reach every shift. Workers are trained when a new chemical hazard arrives. - **OSHA State Plans:** State Plan states run programs at least as effective as federal OSHA. The electronic submission rule applies there too. ## How it works 1. **Report: from the line, in one text** A QR code on the cell, or a text to the shift lead, starts it. Lauren asks which machine, whether energy was isolated and whether a guard was open. 2. **Investigate: one record across all shifts** Lauren drafts the timeline and contributing factors, marked 'Lauren · draft'. The investigator interviews every shift and runs the five whys. A person reviews, edits and signs. 3. **Correct: owner, due date, proof** Each action gets an owner, a due date and evidence, such as a photo of the new guard. Nothing closes until someone verifies it. 4. **Prove: the log, the 301 and the summary** Recordable cases carry what an OSHA 300 entry needs. Exports of the 300, 300A and 301 are rolling out. The audit trail logs every change. ## Scenario: A bypassed interlock on second shift A press operator clears a jam with the interlock propped open and cuts a hand. - **Tue 6:40 pm, Lead scans QR, texts the report.** The operator goes to the clinic. The lead scans the press QR code and texts what happened. - **6:44 pm, Lauren asks about lockout and guard.** Lauren asks if the press was running, lockout was applied and who opened the guard. The lead sends the draft. - **6:52 pm, Shift supervisor routes the report.** The supervisor routes it to the EHS and plant managers, with a note to update the case if it worsens. - **9:15 pm, Clinic sutures make the case recordable.** Under 29 CFR 1904.7, closing the wound with sutures is medical treatment beyond first aid, so the case is recordable. - **Wed 7:30 am, EHS manager interviews first-shift operators.** The same jam happens on that die weekly. The equipment view shows two earlier near misses on that press. - **Wed 4:00 pm, Case goes on the OSHA log.** Inside seven days, the case goes on the 300 log. Until exports roll out, some plants key it in by hand. - **Day 5, Three actions get owners and dates.** Fix the die feed, fit a tamper-resistant interlock and retrain on the jam-clearing lockout procedure. Each action gets an owner and date. - **Day 21 and 60, New interlock verified, actions close.** The EHS manager checks the interlock in person, attaches a photo and closes the action. At 60 days, no guard-open reports. ## What is in the pack **Forms:** Incident report with OSHA 301-equivalent fields; Near-miss and hazard report; Machine guarding and lockout/tagout supplement; Powered industrial truck supplement; Investigation worksheet and corrective action plan **Routing:** Reports go to the area supervisor and EHS coordinator; Severe injuries alert EHS and plant managers, with 8-hour and 24-hour clocks; Guarding, lockout and PSIF-potential events go to the plant manager; Overdue actions go to the owner's manager **Exports:** OSHA 300 log, 300A summary and 301 report (rolling out); Incident register by line, shift, equipment and cause; Investigation report as a PDF; Audit trail for an OSHA or insurer visit **Roles:** Reporter: any operator, lead or visitor; Supervisor: reviews and routes; Investigator: runs the investigation; EHS manager: classifies, assigns and closes; Executive: certifies the 300A; Read-only: corporate, insurer or auditor ## Outcomes - **Detail survives the shift change:** Reports are written at the machine, so the next shift reads them before the job starts. - **Near misses become evidence:** A guard bypass takes a minute to report. Equipment views then show which press or aisle keeps appearing. - **Actions that finish:** Each action has a name, date and proof. Nothing closes on a promise, and a later check shows if the fix held. - **A log you can show:** The log, 301 details and annual summary come from the same records, so the 300A signer can trace each entry. ## Frequently asked questions ### Can IncidentKit replace our OSHA 300 log spreadsheet? It is built to. Each recordable case carries what a 300 entry needs, and exports of the 300, 300A and 301 are rolling out. Until they reach you, keep your current log and use IncidentKit for reporting, investigation and actions. ### Do near misses go on the OSHA 300 log? No. Part 1904 covers only injuries and illnesses that meet its recording criteria. Still, 29 CFR 1910.178(l)(4) calls for refresher training after a truck operator's near miss, and a kit that captures near misses gives you that record. ### How does it handle OSHA's 8-hour and 24-hour reporting? IncidentKit does not call OSHA. It alerts the people who decide, with the 8-hour and 24-hour limits shown. A person then reports to the nearest area office, at 1-800-321-6742 or at osha.gov/report. ### We run several plants. Does each need its own log? Yes. Under 29 CFR 1904.30, you keep a separate 300 log for each establishment expected to operate a year or longer. A multi-site account keeps each plant separate while corporate sees all of them. ### What does it cost, and when should a plant stay with its current system? Non-patient incident reporting is free on the Open plan, with no seats, modules or setup fee. A per-site Regulated plan adds compliance packets and setup. If you need permits, training matrices and audits in one system today, a full EHS suite does more. IncidentKit runs alongside it. ## Sources - [eCFR: 29 CFR 1904.29, forms](https://www.ecfr.gov/current/title-29/section-1904.29) - [eCFR: 29 CFR 1904.30, multiple business establishments](https://www.ecfr.gov/current/title-29/section-1904.30) - [eCFR: 29 CFR 1904.32, annual summary](https://www.ecfr.gov/current/title-29/section-1904.32) - [eCFR: 29 CFR 1904.33, retention and updating](https://www.ecfr.gov/current/title-29/section-1904.33) - [eCFR: 29 CFR 1904.39, reporting fatalities, hospitalizations, amputations and loss of an eye](https://www.ecfr.gov/current/title-29/section-1904.39) - [eCFR: 29 CFR 1904.41, electronic submission](https://www.ecfr.gov/current/title-29/section-1904.41) - [eCFR: 29 CFR 1904.7, general recording criteria](https://www.ecfr.gov/current/title-29/section-1904.7) - [eCFR: 29 CFR 1910.147, control of hazardous energy](https://www.ecfr.gov/current/title-29/section-1910.147) - [eCFR: 29 CFR 1910.178, powered industrial trucks](https://www.ecfr.gov/current/title-29/section-1910.178) - [eCFR: 29 CFR 1910.212, general requirements for all machines](https://www.ecfr.gov/current/title-29/section-1910.212) - [eCFR: 29 CFR 1910.1200, hazard communication](https://www.ecfr.gov/current/title-29/section-1910.1200) - [OSHA: National Emphasis Program on Amputations in Manufacturing, 2025 renewal](https://www.osha.gov/news/newsreleases/osha-national-news-release/20250626) - [OSHA: Injury Tracking Application](https://www.osha.gov/injuryreporting) - [OSHA: Severe injury reporting](https://www.osha.gov/severeinjury) - [OSHA: State Plans](https://www.osha.gov/stateplans) - [OSHA: Incident investigation](https://www.osha.gov/incident-investigation) ## Related - [Incident reporting software: forms, drafts, workflow](https://incidentkit.ai/product/incident-reporting) - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [QAPI, survey and OSHA compliance packets](https://incidentkit.ai/product/compliance-packets) - [OSHA 300 Log Automation: Keep It Accurate Year-Round](https://incidentkit.ai/use-cases/osha-300-log-automation) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Replace Paper Incident Forms: A Practical Switch Plan](https://incidentkit.ai/use-cases/replace-paper-incident-forms) - [IncidentKit vs paper and spreadsheets: honest comparison](https://incidentkit.ai/compare/paper-and-spreadsheets) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [OSHA 301 incident report: the 18 fields and deadlines](https://incidentkit.ai/compliance/osha/osha-301-incident-report) - [OSHA 300A summary: who signs, when to post, how long](https://incidentkit.ai/compliance/osha/osha-300a-summary) - [Lockout/tagout 29 CFR 1910.147: program and event data](https://incidentkit.ai/compliance/osha/lockout-tagout) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [OSHA electronic submission: 29 CFR 1904.41 and the ITA](https://incidentkit.ai/compliance/osha/electronic-submission) --- # Incident reporting for construction, built for the job site > A foreman texts a report from site, and safety sees every project and sub. Source: https://incidentkit.ai/solutions/construction · Updated Oct 5, 2026 **Status: rolling out.** This pack is being released in stages. **Who:** Foremen, superintendents and subcontractor crews report. Project safety managers investigate, and the safety director owns the fixes and the OSHA records for each establishment. ## The problems - **The report lives in the truck:** Binder forms get filled in at the trailer, hours later. The scaffold photo, the sub's name and the height are gone by then. - **Subs, temps and who records what:** Workers from three companies share one hazard. The employer that supervises day to day records the case (29 CFR 1904.31), and the companies coordinate. - **Short-lived projects, one OSHA log:** One 300 log can cover all short-term sites, but each case is still due in seven days (1904.30). A tab per project is year-end archaeology. - **Toolbox talks with no trail:** A fall near miss is covered at Monday's toolbox talk. The sign-in sheet goes in a folder, with no owner and no due date. ## Incident types in the pack - Fall from a roof, scaffold or ladder - Struck by a falling object or vehicle - Caught in or between equipment - Electrical contact or arc flash - Equipment contact with a power line - Scaffold, ladder or fall protection defect - Crane, rigging or lifting event - Vehicle incident in a work zone - Heat illness - Hand or power tool laceration - Near miss with serious injury potential ## Regulators and standards - **OSHA Construction Focus Four hazards:** OSHA names falls, struck-by, caught-in or -between, and electrocution as the four leading causes of construction deaths, the 'Fatal Four'. - **OSHA 29 CFR 1926.501 (fall protection):** Protect workers at an unprotected edge 6 feet or more above a lower level with guardrails, safety nets or personal fall arrest (1926.501(b)(1)). - **OSHA 29 CFR 1904.30 and 1904.46 (establishments):** Establishments expected to run a year or more keep their own 300 log. Short-term ones can share one. The establishment is the office or base that supervises the work. - **OSHA 29 CFR 1904.31 (covered employees):** Day-to-day supervision decides who records cases for temporary, leased and contractor employees. The employers coordinate so each case is recorded once. - **OSHA 29 CFR 1904.39 (severe injury reporting):** Report a fatality within 8 hours, and an inpatient hospitalization, amputation or loss of an eye within 24 hours. Work-zone crashes are reportable. - **OSHA 29 CFR 1904.41 (electronic submission):** Qualifying establishments send data to OSHA's Injury Tracking Application by March 2 each year. Check your NAICS code. - **OSHA heat National Emphasis Program (CPL 03-00-024):** Covers construction, general industry, maritime and agriculture. It prioritizes an on-site response to employer-reported heat hospitalizations. ## How it works 1. **Report: a few texts from the site** Anyone texts from a phone or scans a QR code. Lauren asks height, surface, tie-off, and who employs and supervises. See [mobile and offline](https://incidentkit.ai/product/mobile-and-offline) for weak signal. 2. **Investigate: across companies and sites** Lauren drafts what happened and the contributing factors, marked 'Lauren · draft'. The project safety manager adds photos and statements, confirms the day-to-day supervisor, and signs. 3. **Correct: actions that reach the next site** Actions go to named owners, including sub contacts, with due dates and evidence such as a photo of the new anchor point. Nothing closes until verified. 4. **Prove: by project, trade and establishment** Cases roll up to the right establishment. Analytics show Focus Four events by project, trade, sub and week. Exports of the 300, 300A and 301 are rolling out. ## Scenario: A fall from a scaffold on a short-lived project A framing sub's worker falls about eight feet from a scaffold on a general contractor's site. - **Thu 10:05 am, Foreman calls 911, texts report.** The worker lands on the slab below. The general contractor's foreman calls 911, then texts the report. - **10:09 am, Lauren asks about height and tie-off.** Lauren asks whether rails were in place, who employs and supervises, and the height and tie-off. The foreman attaches two photos. - **10:15 am, Report routes, 24-hour limit shown.** The project safety manager and safety director get the report. Ambulance transport triggers escalation and shows the 24-hour OSHA limit. - **1:30 pm, Sub reports hospitalization to OSHA.** The hospital admits the worker. The sub, as the employer, reports the hospitalization to OSHA. The safety manager notes the time. - **Fri 8:00 am, Safety manager walks the scaffold.** The tag, daily inspection and toolbox talk record are attached. Factors: a missing end rail and a plank gap left by another trade. - **Fri 3:00 pm, Companies confirm who records the case.** Day-to-day supervision decides who records the case (1904.31). The case goes on the right 300 log within seven days. - **Day 4, Scaffold actions get owners and dates.** Re-inspect every scaffold, add an end-rail check to the daily inspection, and hold a toolbox talk on every site. - **Day 14, Safety director verifies, closes action.** The last site attaches a photo of the re-signed scaffold tag. The director verifies, closes the action and schedules a 60-day check. ## What is in the pack **Forms:** Incident report with OSHA 301-equivalent fields; Near-miss and hazard report; Fall and Focus Four supplement: height, anchor point, protection; Subcontractor and visitor incident form; Investigation worksheet and corrective action plan **Routing:** Reports route by project to the superintendent and safety manager; Severe injuries alert the safety director, with 8-hour and 24-hour clocks; Reports about a sub's employee copy the sub's safety contact; Overdue actions go to the project manager **Exports:** OSHA 300 log, 300A summary and 301 report by establishment (rolling out); Incident register by project, trade, sub and hazard; Investigation report as a PDF for owners and insurers; Audit trail **Roles:** Reporter: any worker, sub or visitor; Foreman or superintendent: reviews and routes; Project safety manager: investigates; Safety director: classifies and closes; Executive: certifies the 300A; Read-only: owner, insurer or auditor ## Outcomes - **A report while the scene is intact:** Started on site, with photos, in the foreman's words, before the crew moves on. - **One record across companies:** The employer, day-to-day supervisor and sub's safety contact share one case, so who records and who reports is settled early. - **Trends across short-lived sites:** Projects end but the history stays. See falls, struck-by events or heat illness by trade and sub. - **Actions that follow the crew:** A fix from one site becomes a checked action on the next, with an owner, a date and a photo. ## Frequently asked questions ### What are OSHA's Fatal Four in construction? They are falls, struck-by, caught-in or -between, and electrocution, the four leading causes of construction deaths in OSHA's construction training. The pack has incident types and follow-up questions for each, so reports capture height, protection, trench depth or power line details. ### Who records an injury to a subcontractor's employee? The employer that supervises the work day to day records it (29 CFR 1904.31). If a contractor supervises its own employees, it records the case. The two coordinate so each case is recorded once. IncidentKit asks who employs and who supervises in every report. ### How do we keep OSHA logs across many short projects? You may keep one 300 log for all short-term establishments, or one per division or region (1904.30(b)(1)). A short-term establishment is one expected to exist less than a year. A worker hurt away from your establishments goes on the log where they normally work. ### Is a vehicle crash in a work zone reportable to OSHA? Yes. A fatality, hospitalization, amputation or loss of an eye from a crash in a construction work zone must be reported. A crash on a public road outside a work zone is not reported but is still recorded (1904.39(b)(3)). ### What does it cost, and does it work with weak signal? Non-patient incident reporting is free on the Open plan, with no seats, modules or setup fee, so sub crews can report without a license each. A per-site Regulated plan adds compliance packets and setup. The mobile and offline page explains how weak signal is handled. ## Sources - [OSHA: Construction Focus Four hazards](https://www.osha.gov/training/outreach/construction/focus-four) - [OSHA Quick Card: Top Four Construction Hazards](https://www.osha.gov/sites/default/files/publications/construction_hazards_qc.pdf) - [eCFR: 29 CFR 1926.501, duty to have fall protection](https://www.ecfr.gov/current/title-29/section-1926.501) - [eCFR: 29 CFR 1904.30, multiple business establishments](https://www.ecfr.gov/current/title-29/section-1904.30) - [eCFR: 29 CFR 1904.31, covered employees](https://www.ecfr.gov/current/title-29/section-1904.31) - [eCFR: 29 CFR 1904.39, reporting fatalities, hospitalizations, amputations and loss of an eye](https://www.ecfr.gov/current/title-29/section-1904.39) - [eCFR: 29 CFR 1904.41, electronic submission](https://www.ecfr.gov/current/title-29/section-1904.41) - [eCFR: 29 CFR 1904.46, definitions](https://www.ecfr.gov/current/title-29/section-1904.46) - [OSHA: Heat exposure overview](https://www.osha.gov/heat-exposure) - [OSHA: Severe injury reporting](https://www.osha.gov/severeinjury) - [BLS: How to compute your firm's incidence rate](https://www.bls.gov/iif/overview/compute-nonfatal-incidence-rates.htm) ## Related - [Mobile incident reporting that works offline](https://incidentkit.ai/product/mobile-and-offline) - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) - [Contractor and Visitor Incidents: Who Reports What](https://incidentkit.ai/use-cases/contractor-and-visitor-incidents) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [OSHA 300 Log Automation: Keep It Accurate Year-Round](https://incidentkit.ai/use-cases/osha-300-log-automation) - [IncidentKit vs Safesite: honest comparison](https://incidentkit.ai/compare/safesite) - [Construction recordkeeping: OSHA Part 1904 for job sites](https://incidentkit.ai/compliance/osha/construction-recordkeeping) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [TRIR and DART rates: formula, example and BLS 2024 rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates) - [Injury reporting and retaliation: 29 CFR 1904.35 and 11(c)](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation) - [OSHA electronic submission: 29 CFR 1904.41 and the ITA](https://incidentkit.ai/compliance/osha/electronic-submission) --- # Incident reporting for labs and pharma production > Technicians text in spills and exposures, and EHS and quality share one record. Source: https://incidentkit.ai/solutions/laboratories-and-pharma-production · Updated Oct 5, 2026 **Status: rolling out.** This pack is being released in stages. **Who:** Scientists, technicians and operators report. Lab managers, EHS and quality investigate, and the EHS or chemical hygiene officer owns fixes and exposure records. ## The problems - **Two paper trails for one event:** A spill makes an EHS form, a quality deviation and a facilities email. Nobody sees all three, so the cause is investigated twice or never. - **The exposure that never gets a consult:** After a spill or leak that makes exposure likely, the employee gets a medical consultation offer (1910.1450(g)(1)(iii)). A hallway report makes it hard to prove. - **Needlesticks and the sharps log:** The sharps injury log needs device type and brand, work area and how it happened (1910.1030(h)(5)). Those facts vanish when the first report is spoken. - **Equipment failures filed as maintenance tickets:** A silent fume hood alarm or freezer excursion becomes a maintenance work order. The pattern across rooms never reaches EHS. ## Incident types in the pack - Chemical spill or release - Skin or eye chemical splash - Inhalation or fume hood failure - Needlestick or sharps injury - Exposure to blood or infectious material - Compressed gas or cryogen event - Fire, flash or small explosion - Equipment failure - Process deviation with a safety impact - Biological containment breach - Repetitive strain - Near miss ## Regulators and standards - **OSHA 29 CFR 1910.1450 (laboratory standard):** A written chemical hygiene plan. After a spill, leak or explosion that makes exposure likely, employees get a medical consultation offer, and records are kept (1910.1450(e), (g), (j)). - **OSHA 29 CFR 1910.1200 (hazard communication):** Applies to labs in part: incoming labels stay intact, safety data sheets stay accessible, employees are trained. Non-laboratory chemical use follows the other standards, even in a lab. - **OSHA 29 CFR 1910.1030 (bloodborne pathogens):** Employers with a Part 1904 log keep a confidential sharps injury log: device type and brand, work area, how it happened. Retention follows 1904.33. - **OSHA 29 CFR 1904.8 (needlesticks and sharps):** Work-related needlesticks and cuts from sharps contaminated with blood or other potentially infectious material go on the 300 log as privacy cases, with no name. - **OSHA 29 CFR Part 1904 and 1904.39:** Log recordable cases within seven calendar days. Report a fatality within 8 hours, and an inpatient hospitalization, amputation or loss of an eye within 24 hours. - **FDA 21 CFR 211.192 (production record review):** Drug makers must fully investigate unexplained discrepancies and failed specifications, and record conclusions and follow-up. That is a quality-system duty. IncidentKit is not a quality system. ## How it works 1. **Report: from the bench, in one text** A technician texts what happened or scans the QR code on the room door. Lauren asks which chemical, how much, who was exposed and whether the hood worked. 2. **Investigate: a deviation-style record** The record has the shape quality teams know: description, containment, impact, root cause and disposition. Lauren drafts it, marked 'Lauren · draft', and you add the deviation number. 3. **Correct: CAPA with an owner and proof** Each corrective and preventive action has an owner, a due date and evidence, such as a hood service report or a revised SOP. Nothing closes until verified. 4. **Prove: exposure, sharps and OSHA together** The consultation offer, sharps details and any recordable case sit in one record. Exports of the OSHA 300, 300A and 301 are rolling out. ## Scenario: A solvent spill and a silent hood alarm A technician spills about a liter of solvent and notices the hood alarm never sounded. - **Mon 2:10 pm, Technician texts report before cleanup.** The transfer was outside the hood in Lab 3. The technician texts a report before cleanup starts. - **2:14 pm, Lauren asks questions, SDS attached.** Lauren asks the chemical, quantity, ventilation, PPE, containment and symptoms. The SDS is attached. - **2:25 pm, Lab manager offers medical consultation.** After confirming containment, the lab manager offers medical consultation to the two people nearby. The report routes to EHS. - **Tue 9:00 am, Investigation finds hood monitor fault.** The hood's airflow monitor had been in fault three weeks, its ticket stuck in maintenance. Two earlier alarm reports appear in other labs. - **Tue 11:00 am, Quality opens a linked deviation.** The room hosted a controlled step that day, so quality opens a deviation. Each record carries the other's number. - **Day 3, Four actions get owners and dates.** Recertify the hood, add alarm faults to the daily start-up check, route them to EHS too, and retrain on transfers. - **Day 12, Service report attached, actions close.** EHS verifies the service report and revised checklist and closes the actions. No one was hurt, so there is no OSHA 300 entry. - **Day 90, Effectiveness check covers all labs.** A review of alarm-fault reports across all labs shows faults now reach EHS the same day, and none has sat unresolved. ## What is in the pack **Forms:** Spill or exposure report: chemical, quantity, SDS, PPE, ventilation; Sharps supplement: device, work area, how it happened; Medical consult record: offered, accepted, physician's opinion; Equipment failure report; Deviation-style investigation worksheet and CAPA plan **Routing:** Reports go to the lab or area manager and EHS; Spills with possible exposure prompt the consultation offer; GMP-area events also notify the quality unit; Sharps injuries go to occupational health, name kept confidential **Exports:** OSHA 300 log, 300A summary and 301 report (rolling out); Sharps injury log view; Incident register by room, equipment and chemical; Investigation report as a PDF for the quality file; Audit trail **Roles:** Reporter: any scientist, technician or operator; Lab or area manager: reviews and routes; Investigator: EHS or quality; Chemical hygiene or EHS officer: classifies and closes; Executive: certifies the 300A; Read-only: auditor or insurer ## Outcomes - **One event, one record:** The EHS incident and the quality deviation point to each other, so both teams see the same facts and investigate once. - **The exposure trail exists when asked:** The consultation offer, the chemical and the conditions are captured at the time, not rebuilt from memory. - **Equipment patterns reach EHS:** Hood alarms, freezer excursions and centrifuge faults cluster by room and equipment, so a repeating failure stands out. - **CAPA that is checked:** Actions carry an owner, date and evidence. Nothing closes until verified, and an effectiveness check shows if the fix held. ## Frequently asked questions ### Is IncidentKit a replacement for our quality management system? No. It handles incidents, investigations and corrective actions for safety events. GMP deviations, batch impact, change control and regulatory submissions stay in your quality system. Put the deviation number on the incident, and the incident number on the deviation. ### Does the OSHA laboratory standard require an incident report? Not as such. 29 CFR 1910.1450 does not prescribe an incident form. It does require an opportunity for medical consultation after a spill, leak or explosion that makes exposure likely, with records. An incident record that captures the offer makes that easy to show. ### How are needlesticks recorded? A work-related needlestick or sharps cut contaminated with blood or other potentially infectious material goes on the OSHA 300 log as a privacy case, with no name (29 CFR 1904.8). Update the entry if a bloodborne disease is later diagnosed. Keep the separate sharps injury log too. ### Does a pharma production area follow the lab standard? Not necessarily. The laboratory standard covers laboratory use of hazardous chemicals, and other uses follow the relevant OSHA standards even in a lab (1910.1450(a)(3)). Production areas usually follow hazard communication in full. Ask your EHS officer how each area is classified. ### What does it cost, and can a clinical lab use the free plan? Non-patient incident reporting is free on the Open plan, with no seats, modules or setup fee. A clinical lab that touches patient information needs the per-site Regulated plan, with a business associate agreement and compliance packets. Research, QC and production labs fit Open. ## Sources - [eCFR: 29 CFR 1910.1450, occupational exposure to hazardous chemicals in laboratories](https://www.ecfr.gov/current/title-29/section-1910.1450) - [eCFR: 29 CFR 1910.1200, hazard communication](https://www.ecfr.gov/current/title-29/section-1910.1200) - [eCFR: 29 CFR 1910.1030, bloodborne pathogens](https://www.ecfr.gov/current/title-29/section-1910.1030) - [eCFR: 29 CFR 1904.8, needlestick and sharps injuries](https://www.ecfr.gov/current/title-29/section-1904.8) - [eCFR: 29 CFR 1904.29, forms and privacy cases](https://www.ecfr.gov/current/title-29/section-1904.29) - [eCFR: 29 CFR 1904.39, reporting fatalities, hospitalizations, amputations and loss of an eye](https://www.ecfr.gov/current/title-29/section-1904.39) - [eCFR: 21 CFR 211.192, production record review](https://www.ecfr.gov/current/title-21/section-211.192) - [OSHA: Incident investigation](https://www.osha.gov/incident-investigation) ## Related - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Incident audit trail: every change, who and when](https://incidentkit.ai/product/audit-trail) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Hazard communication 29 CFR 1910.1200: SDS, labels, training](https://incidentkit.ai/compliance/osha/hazard-communication) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [Recordable vs first aid: OSHA's medical treatment test](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [Injury reporting and retaliation: 29 CFR 1904.35 and 11(c)](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation) --- # Incident reporting for warehouses and logistics, peak season included > Workers text in near misses, strains and heat illness, and EHS spots patterns early. Source: https://incidentkit.ai/solutions/warehousing-and-logistics · Updated Oct 5, 2026 **Status: rolling out.** This pack is being released in stages. **Who:** Associates, leads and temporary workers report. Shift managers and EHS investigate, the site manager owns fixes, and staffing partners see cases about their people. ## The problems - **Peak season outruns the paper:** Hundreds of temps arrive in weeks, each with a different lead and shift. Names are spelled three ways, and the agency hears days later. - **Forklift near misses nobody writes down:** OSHA requires refresher training after an accident or near-miss incident (1910.178(l)(4)). A spoken 'watch that corner' leaves nothing to act on. - **Strains recorded after the fact:** A strain arrives as a day-three clinic visit and a supervisor's memory. Load, rack height and pace go uncaptured, so the fix is a poster. - **Heat is a trend, not a text thread:** OSHA's heat emphasis program (CPL 03-00-024, effective April 10, 2026) lists warehousing among its targets. Each case still lives in a group chat. ## Incident types in the pack - Strain or sprain - Forklift or truck collision - Pedestrian struck by a truck - Fall from a dock edge or trailer - Slip, trip or fall - Rack, stack or load collapse - Conveyor pinch or caught-in - Robot or automated vehicle near miss - Heat illness - Cold stress in a cooler or freezer - Vehicle incident in the yard or on the road - Near miss with serious injury potential ## Regulators and standards - **OSHA 29 CFR 1910.178 (powered industrial trucks):** Operators are trained and evaluated at least every three years. Refresher training follows an accident or near miss. Trucks are examined daily, and defects are reported at once. - **OSHA warehousing hazards:** OSHA's warehousing page lists ergonomics, trucks, rack collapse, slips and falls, chemicals, electrical hazards, heat, cold stress, lockout/tagout and automation. - **OSHA 29 CFR 1910.22 (walking-working surfaces):** Fix spills and leaks before employees use the surface again, or guard the area until you do. - **OSHA 29 CFR 1904.31 and the Temporary Worker Initiative:** Whoever supervises a temporary worker day to day records the injuries. Agency and host coordinate so each case is recorded once. OSHA treats them as sharing responsibility for safety. - **OSHA 29 CFR 1904.39 and 1904.41:** 8-hour and 24-hour reporting applies. For annual electronic submission, seasonal and temporary workers you employ count toward the headcount thresholds (1904.41(b)(2)). - **OSHA heat National Emphasis Program (CPL 03-00-024):** Prioritizes an on-site response to employer-reported heat hospitalizations. OSHA also proposed a heat standard in 2024 (89 Fed. Reg. 70698). Check OSHA's heat page for current status. ## How it works 1. **Report: from the aisle, in one text** A QR code at the aisle end, or a text to the shift lead, starts it. Lauren asks which truck, who was on foot and who employs them. 2. **Investigate: pattern first** Lauren drafts the timeline and contributing factors, marked 'Lauren · draft'. The investigator checks the same location, shift and equipment for earlier reports, then signs. 3. **Correct: owner, due date, proof** Each action has an owner, a due date and evidence, such as a photo of a new mirror. Operator refresher training is tracked as an action. Nothing closes until verified. 4. **Prove: logs, rates and a trail** Recordable cases carry what an OSHA 300 entry needs. Exports of the 300, 300A and 301 are rolling out. Analytics group events by dock, aisle, shift and equipment. ## Scenario: A forklift near miss in week three of peak season A reach truck stops short of a temporary associate who steps out from behind a pallet stack. - **Tue 11:20 pm, Night lead texts the near miss.** Nobody is hurt. The night lead scans the QR code at the aisle end and texts what happened. - **11:23 pm, Lauren asks about truck, associate, aisle.** Lauren asks about the truck's speed, horn and mirrors, who employs the associate and whether this aisle has had similar events. - **11:35 pm, Report routes, staffing agency copied.** The night shift and EHS managers get the report. A staffing agency placed the associate, so its safety contact is copied. - **Wed 7:00 am, EHS manager opens the investigation.** The location view shows three earlier near misses at that aisle end in six weeks, all on nights. - **Wed 1:00 pm, Operator scheduled for refresher training.** After a near-miss incident, 1910.178(l)(4) requires refresher training and evaluation, so the operator is scheduled. The truck's daily exam record is attached. - **Day 3, Aisle actions get owners and dates.** Add a convex mirror and stop line at the aisle end, pedestrian-lane training in seasonal onboarding with staffing partners, and a night-shift safety huddle. - **Day 10, EHS manager verifies the aisle changes.** The EHS manager walks the aisle, photographs the mirror and stop line, and closes the physical actions. - **Day 45, Effectiveness check finds no repeats.** The onboarding change is live for the next hiring wave, and the effectiveness check finds no new near misses at that aisle end. ## What is in the pack **Forms:** Incident report with OSHA 301-equivalent fields; Near-miss report; Truck supplement: truck type, speed, pedestrians, daily exam; Manual handling supplement: load, task, rack height, pace; Heat and cold illness supplement, and agency worker form; Investigation worksheet and corrective action plan **Routing:** Reports go to the shift manager and EHS manager; Agency worker reports copy the agency's safety contact; Severe injuries alert EHS and site managers, with 8-hour and 24-hour clocks; Repeat heat reports in one area and shift escalate **Exports:** OSHA 300 log, 300A summary and 301 report (rolling out); Incident register by dock, aisle, shift, equipment and cause; Agency-specific case list for staffing partners; Audit trail **Roles:** Reporter: any associate, lead, driver or temp; Shift manager: reviews and routes; Investigator: EHS coordinator; Site EHS manager: classifies and closes; Executive: certifies the 300A; Read-only: staffing partner, insurer or auditor ## Outcomes - **Temp workers report on day one:** A QR code at the aisle end starts a report from any phone, so a temp reports like a ten-year employee. - **Near misses point to a place:** Close calls logged by aisle and shift show the problem aisle early. The fix is a mirror, not a poster. - **Staffing partners in the loop:** Reports about agency workers reach the agency's safety contact, and the report asks who supervises day to day. - **Heat and strain patterns visible:** Events by area, shift and task show clusters, so heat controls and handling changes go where the reports are. ## Frequently asked questions ### Who records an injury to a temp worker from a staffing agency? The employer that supervises the temporary worker day to day records it (29 CFR 1904.31). Where the host's leads direct the work, that is often the host. The agency and host coordinate so the case is recorded once. IncidentKit asks who employs and who supervises in each report. ### Does peak-season hiring change our OSHA electronic submission duties? It can. Under 29 CFR 1904.41, headcount thresholds count everyone employed at the establishment at any time in the year, including part-time, seasonal and temporary workers. A seasonal surge can push you past 20, 100 or 250 employees. Check the industry appendices for your NAICS code. ### Does OSHA want forklift near misses recorded? Not on the 300 log, because no injury occurred. But 29 CFR 1910.178(l)(4) calls for refresher training after an accident or near-miss incident, and OSHA encourages investigating close calls. A near-miss record shows the training followed. ### How should we handle heat illness and vehicle incidents? Report every heat event, even mild ones, so patterns show by area and shift. A heat illness that leads to inpatient hospitalization needs the 24-hour report. A crash on a public road outside a construction work zone is recorded, not reported (1904.39(b)(3)). ### What does it cost for a distribution center? Non-patient incident reporting is free on the Open plan, with no seats, modules or setup fee, so temps and staffing partners report without a license each. A per-site Regulated plan adds compliance packets and setup. See the pricing page for current details. ## Sources - [eCFR: 29 CFR 1910.178, powered industrial trucks](https://www.ecfr.gov/current/title-29/section-1910.178) - [eCFR: 29 CFR 1910.22, walking-working surfaces](https://www.ecfr.gov/current/title-29/section-1910.22) - [eCFR: 29 CFR 1904.31, covered employees](https://www.ecfr.gov/current/title-29/section-1904.31) - [eCFR: 29 CFR 1904.39, reporting fatalities, hospitalizations, amputations and loss of an eye](https://www.ecfr.gov/current/title-29/section-1904.39) - [eCFR: 29 CFR 1904.41, electronic submission](https://www.ecfr.gov/current/title-29/section-1904.41) - [OSHA: Warehousing hazards and solutions](https://www.osha.gov/warehousing/hazards-solutions) - [OSHA: Temporary workers](https://www.osha.gov/temporaryworkers) - [OSHA: Heat exposure overview](https://www.osha.gov/heat-exposure) - [OSHA: National Emphasis Program on outdoor and indoor heat-related hazards, CPL 03-00-024](https://www.osha.gov/sites/default/files/enforcement/directives/CPL_03-00-024_0.pdf) - [OSHA: Severe injury reporting](https://www.osha.gov/severeinjury) ## Related - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) - [Incident routing and escalation by severity](https://incidentkit.ai/product/routing-and-escalation) - [Incident analytics: find the pattern before the next one](https://incidentkit.ai/product/analytics) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Contractor and Visitor Incidents: Who Reports What](https://incidentkit.ai/use-cases/contractor-and-visitor-incidents) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) - [OSHA 300 Log Automation: Keep It Accurate Year-Round](https://incidentkit.ai/use-cases/osha-300-log-automation) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [Recordable vs first aid: OSHA's medical treatment test](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [TRIR and DART rates: formula, example and BLS 2024 rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates) - [OSHA electronic submission: 29 CFR 1904.41 and the ITA](https://incidentkit.ai/compliance/osha/electronic-submission) --- # Incident reporting for food and beverage processing plants > Crews text in caught-in events and ammonia releases, and the plant closes each one. Source: https://incidentkit.ai/solutions/food-and-beverage-processing · Updated Oct 5, 2026 **Status: rolling out.** This pack is being released in stages. **Who:** Line operators and sanitation crews report. Supervisors and the plant EHS lead investigate, the plant manager owns fixes, and corporate reads trends across plants. ## The problems - **Sanitation runs overnight and nobody hears about it:** A caught-in near miss at a conveyor is told to the lead and forgotten by morning. Lockout/tagout covers cleaning and unjamming (1910.147). - **An ammonia smell is a report, not rumor:** A small leak lands in the operator's notebook, if anywhere. At 10,000 pounds or more of anhydrous ammonia, PSM adds a formal investigation duty. - **A fingertip and the 24-hour clock:** OSHA counts a fingertip amputation, with or without bone loss, as reportable within 24 hours. Avulsions and degloving are excluded (1904.39(b)(11)). On nights, who decides? - **Wet floors and changing chemicals:** Wet processes need drainage and dry standing places where feasible (1910.22(a)(2)). A new sanitation chemical means new hazard training (1910.1200(h)(1)). Both need a record. ## Incident types in the pack - Caught-in or amputation at a machine - Lockout/tagout event during cleaning - Ammonia release or refrigeration alarm - Sanitation chemical splash or inhalation - Slip or fall on a wet floor - Laceration from a knife or slicer - Strain from repetitive cutting or packing - Forklift incident in a cooler or on a dock - Burn or scald from steam or hot water - Cold stress in a freezer or cooler - Confined space event in a tank or vat - Near miss with serious injury potential ## Regulators and standards - **OSHA National Emphasis Program on Amputations (CPL 03-00-027):** Effective June 27, 2025 for five years. It targets sites by NAICS code, including meat, poultry, dairy, bakeries, soft drinks and bottled water. Check yours. - **OSHA 29 CFR 1910.147 (lockout/tagout):** Servicing includes cleaning and unjamming where a machine could start unexpectedly. Each procedure needs a certified inspection at least once a year. - **OSHA 29 CFR 1904.39 (severe injury reporting):** Report amputations and inpatient hospitalizations for care or treatment within 24 hours. Report fatalities within 8 hours. Observation or diagnostic testing alone is not reportable. - **OSHA 29 CFR 1910.119 (process safety management):** Appendix A lists anhydrous ammonia at 10,000 pounds and ammonia solutions above 44 percent at 15,000 pounds. A covered process starts an incident investigation within 48 hours (1910.119(m)). - **EPA 40 CFR 68.81 (risk management program):** A parallel duty for covered facilities: start within 48 hours, document, resolve findings, keep records five years. - **OSHA 29 CFR 1910.22 and 1910.1200:** Keep walking-working surfaces clean and, where feasible, dry. Keep safety data sheets within reach each shift, and train workers on new chemical hazards. - **OSHA 29 CFR Part 1904 (recordkeeping):** Log recordable cases within seven calendar days. Sites in covered size and industry groups send data to OSHA's Injury Tracking Application by March 2. ## How it works 1. **Report: from the line or the engine room** A QR code or a text to the supervisor starts it. Lauren asks if it was locked out, who applied the lock and whether a guard was off. 2. **Investigate: production and sanitation in one record** Lauren drafts the timeline and factors, marked 'Lauren · draft'. The investigator interviews both crews and runs the five whys. A covered ammonia process shows the 48-hour start. 3. **Correct: lock points, procedures, training** Each action has an owner, due date and evidence, such as a photo of a new lock point. Nothing closes until verified on the floor. 4. **Prove: the log and the trend** Recordable cases carry what the OSHA 300 entry needs. Exports of the 300, 300A and 301 are rolling out. Analytics group events by line, machine, shift and task. ## Scenario: A fingertip caught in a conveyor during overnight sanitation A sanitation worker cleaning a packaging conveyor catches a fingertip in a pinch point. - **Wed 1:50 am, Technician loses fingertip, goes to ER.** The sanitation lead sends the technician to the emergency room. - **1:54 am, Lead texts, Lauren asks about lockout.** The lead scans the conveyor's QR code and texts it in. Lauren asks if it was locked out and whether a guard was off. - **2:05 am, Report routes, hospital confirms the loss.** The night supervisor and on-call EHS manager get the report, with the 24-hour limit shown. The hospital confirms part of the fingertip was lost. - **6:30 am, Amputation reported to OSHA, time recorded.** A fingertip amputation is reportable even without bone loss. A person reports it at osha.gov/report and records the time on the incident. - **Wed 9:00 am, Investigation finds lockout step missing.** The procedure never listed the cleaning step, and the lock point sits behind the guard. Two earlier overnight near misses show on that line. - **Day 4, Lockout fixes get owners and dates.** Add cleaning to the lockout procedure, add a lock point at sanitation access, retrain staff, and inspect the line. - **Day 7, Entry added to the OSHA log.** Inside seven days, the case goes on the OSHA 300 log. Until exports roll out, some plants key it into their current log. - **Day 30, Sanitation shift observed, action closed.** The EHS manager watches a sanitation shift use the new procedure, attaches the checklist and closes the action. ## What is in the pack **Forms:** Incident report with OSHA 301-equivalent fields; Near-miss report; Machine and lockout supplement: machine, task, energy, lock applied; Ammonia release supplement: where, how long, alarm, readings, evacuation; Chemical exposure and wet floor supplements; Investigation worksheet and corrective action plan **Routing:** Reports go to the line supervisor and EHS lead, plus sanitation manager; Severe injuries alert EHS and plant managers, with 8-hour and 24-hour clocks; Ammonia releases escalate; covered processes start the 48-hour timer; Overdue actions go to the owner's manager **Exports:** OSHA 300 log, 300A summary and 301 report (rolling out); Incident register by line, machine, shift and task; Investigation report as a PDF; Audit trail for an OSHA or insurer visit **Roles:** Reporter: any operator, sanitation worker or lead; Supervisor: reviews and routes; Investigator: plant EHS; Plant EHS manager: classifies and closes; Executive: certifies the 300A; Read-only: corporate, insurer or auditor ## Outcomes - **Sanitation events reach production:** An overnight caught-in event is on record before the morning shift starts the line, so both crews see one history per machine. - **The reportable question is answered fast:** A possible amputation reaches the on-call person with the 24-hour limit and the facts already collected. - **Ammonia events tracked from first smell:** A small release logged when it happens gives process safety the history an investigation or audit will ask for. - **Fixes that reach the procedure:** Lock points, procedures and training rosters are attached as evidence. An action closes when the change is verified on the floor. ## Frequently asked questions ### Is a fingertip injury an amputation OSHA wants reported? Often, yes. OSHA defines an amputation as the traumatic loss of a limb or other external body part. That includes fingertips, with or without bone loss. Avulsions, degloving, scalpings, severed ears, and broken or chipped teeth are not amputations. OSHA says it is generally better to report than not. ### Does our ammonia system fall under process safety management (PSM)? It depends on the quantity in the process. Appendix A of 29 CFR 1910.119 lists anhydrous ammonia at 10,000 pounds and ammonia solutions above 44 percent at 15,000 pounds. If it is covered, paragraph (m) investigation rules apply. See the chemical and process industries page. ### Does lockout/tagout apply to cleaning a machine? Yes, when a worker could be hurt by a machine starting up or releasing stored energy unexpectedly. The standard counts lubrication, cleaning and unjamming as servicing. During normal production it applies only when a guard is removed or a body part enters the danger zone (1910.147(a)(2)). ### Does IncidentKit replace our food safety system? No. It covers worker safety incidents. That means injuries, near misses, releases and exposures. Product safety, HACCP, allergen controls and recalls stay in your food safety and quality systems. Where one event touches both, record each system's reference number on the other. ### What does it cost, and how does it handle overnight shifts? Non-patient incident reporting is free on the Open plan, with no seats, modules or setup fee. A per-site Regulated plan adds compliance packets and setup. Reports start from a phone at any hour, and routing sends a possible severe injury to the on-call person. ## Sources - [OSHA: National Emphasis Program on Amputations in Manufacturing, 2025 renewal](https://www.osha.gov/news/newsreleases/osha-national-news-release/20250626) - [OSHA: Ammonia refrigeration](https://www.osha.gov/ammonia-refrigeration) - [OSHA: Severe injury reporting](https://www.osha.gov/severeinjury) - [eCFR: 29 CFR 1910.147, control of hazardous energy](https://www.ecfr.gov/current/title-29/section-1910.147) - [eCFR: 29 CFR 1904.39, reporting fatalities, hospitalizations, amputations and loss of an eye](https://www.ecfr.gov/current/title-29/section-1904.39) - [eCFR: 29 CFR 1910.119, process safety management of highly hazardous chemicals](https://www.ecfr.gov/current/title-29/section-1910.119) - [eCFR: 40 CFR 68.81, incident investigation](https://www.ecfr.gov/current/title-40/section-68.81) - [eCFR: 29 CFR 1910.22, general requirements for walking-working surfaces](https://www.ecfr.gov/current/title-29/section-1910.22) - [eCFR: 29 CFR 1910.1200, hazard communication](https://www.ecfr.gov/current/title-29/section-1910.1200) - [eCFR: 29 CFR 1904.29, forms](https://www.ecfr.gov/current/title-29/section-1904.29) - [OSHA: Injury Tracking Application](https://www.osha.gov/injuryreporting) ## Related - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) - [Incident routing and escalation by severity](https://incidentkit.ai/product/routing-and-escalation) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) - [OSHA 300 Log Automation: Keep It Accurate Year-Round](https://incidentkit.ai/use-cases/osha-300-log-automation) - [Process safety incident reporting and investigation](https://incidentkit.ai/solutions/chemical-and-process-industries) - [Lockout/tagout 29 CFR 1910.147: program and event data](https://incidentkit.ai/compliance/osha/lockout-tagout) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [PSM incident investigation: 29 CFR 1910.119(m) explained](https://incidentkit.ai/compliance/osha/process-safety-incident-investigation) - [Hazard communication 29 CFR 1910.1200: SDS, labels, training](https://incidentkit.ai/compliance/osha/hazard-communication) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) --- # Incident reporting for chemical and process plants > Report from the unit, start the investigation within 48 hours, and close every fix. Source: https://incidentkit.ai/solutions/chemical-and-process-industries · Updated Oct 5, 2026 **Status: rolling out.** This pack is being released in stages. **Who:** Operators, techs and contractors report. Process safety engineers lead the investigation, and plant managers own each fix and sign off. ## The problems - **Near misses are radio calls, not records:** A weeping seal lives in a logbook. OSHA's process safety management (PSM) rule also covers near misses that could have caused a catastrophic release. - **The 48-hour clock and the missing paper trail:** An investigation must start within 48 hours. The team needs a process-knowledgeable person and any involved contractor (1910.119(m)(2), (m)(3)). Start times are hard to reconstruct. - **Recommendations that die in the report:** Paragraph (m)(5) requires a system to promptly resolve findings and recommendations. Resolutions must be documented. A PDF on a shared drive is not that system. - **Incidents and changes live in separate files:** A leak traces to a change that skipped management of change (MOC), and the incident file never says so. Paragraph (l) requires written MOC procedures. ## Incident types in the pack - Loss of primary containment - Relief valve or rupture disk activation - Near miss with catastrophic release potential - Fire or explosion - Overpressure or runaway reaction - Safety system, alarm or interlock failure - Mechanical integrity failure - Change made without MOC review - Bypassed or defeated safeguard - Contractor incident in a covered process - Chemical exposure or inhalation - Injury or fatality ## Regulators and standards - **OSHA 29 CFR 1910.119(m) (PSM incident investigation):** Investigate any incident that did or could reasonably have caused a catastrophic release. Start within 48 hours. Resolve findings, review with staff, keep the report five years. - **OSHA 29 CFR 1910.119(l) (management of change):** Written procedures for changes to chemicals, technology, equipment and procedures, except replacements in kind. Train affected employees before startup and update process safety information. - **OSHA 29 CFR 1910.119(a) and Appendix A (coverage):** Generally covers processes with listed chemicals at or above threshold amounts, or 10,000 pounds or more of a Category 1 flammable gas or flammable liquid below 100 degrees F flashpoint. - **EPA 40 CFR 68.81 (risk management program):** A parallel duty for covered stationary sources, with the same 48-hour start, team, report, resolution and five-year retention. EPA adds provisions for some incidents. Check the current text. - **Chemical Safety Board 40 CFR 1604.3 (release reporting):** A covered source must report an accidental release to air that causes a death, an inpatient hospitalization or $1,000,000 or more of property damage. The deadline is eight hours. - **OSHA 29 CFR Part 1904 and 1904.39:** Injury recordkeeping still applies. Report a fatality within 8 hours. Report an inpatient hospitalization, amputation or loss of an eye within 24 hours. ## How it works 1. **Report: from the unit, with the equipment tag** Anyone texts what happened: unit, tag, material, quantity. Lauren asks if it was contained, whether a relief device was involved, and what recent maintenance or change came before. 2. **Investigate: built around paragraph (m)** The record has fields for the incident date, investigation start date, team (including any contract employee), description, factors and recommendations. Lauren drafts, marked 'Lauren · draft'. 3. **Correct: recommendations as tracked actions** Each recommendation becomes an action with an owner, due date and evidence. Link the MOC number or work order from your own systems. Nothing closes until verified. 4. **Prove: review, retention and repeats** Record that the report was reviewed with affected personnel and contractors, and keep it five years. Analytics show repeat events by unit, equipment and cause. ## Scenario: A seal leak that could have been worse A transfer pump seal weeps flammable liquid onto the pad overnight, and nobody is hurt. - **Sat 3:15 am, Field operator contains leak, texts report.** The low-level alarm sounds. A field operator shuts the pump down, isolates the area and contains the liquid, then texts a report. - **3:22 am, Lauren asks about recent maintenance.** Lauren asks for the material, amount, ignition sources, gas reading, recent maintenance and changes. The seal was replaced two weeks earlier. - **3:40 am, Process safety engineer flags PSM event.** The shift supervisor and on-call process safety engineer get the report, and the engineer flags it as a PSM event. The 48-hour start shows. - **Sat 11:00 am, Team convenes, start time recorded.** The investigation starts about eight hours in, with a contract employee on the team because contractors did the seal job. Start time and team are recorded. - **Mon 2:00 pm, Different seal spec, MOC skipped.** The lead investigator edits Lauren's draft and signs the findings: the replacement seal had a different specification, and the change skipped MOC. - **Day 9, Recommendations become actions with owners.** Each gets an owner and a date: review seal specs on every pump in that service, add a spec check to the job plan, and add an MOC trigger for seal replacements. - **Day 12, Report reviewed with operators and contractors.** Attendance is recorded for the operators, maintenance staff and contractor crew involved. - **Day 40, Field verification closes the actions.** The report enters the five-year record. ## What is in the pack **Forms:** Incident and near-miss report: unit, tag, material, amount; Loss of containment supplement; PSM investigation report and team record, with contract employees; Recommendation tracker with MOC and work order references; Injury report with OSHA 301-equivalent fields **Routing:** Reports go to the shift supervisor and process safety engineer; Possible catastrophic releases show the 48-hour deadline; Contractor events copy the contractor's safety contact; Severe injuries alert EHS; covered sources also get a CSB report prompt **Exports:** PSM investigation report as a PDF; Open recommendations report for reviews and audits; OSHA 300 log, 300A summary and 301 report (rolling out); Incident register by unit, equipment and cause; Audit trail **Roles:** Reporter: any operator, tech or contractor; Shift supervisor: reviews and routes; Investigator: process safety engineer or team lead; Process safety manager: approves and closes; Executive: certifies the 300A; Read-only: insurer, corporate or auditor ## Outcomes - **Near misses captured at the source:** A weeping seal or lifted relief valve takes a minute to report, so it is on record before shift handover. - **The 48 hours stay visible:** The deadline, team, contract employee and start time are recorded as they happen, not rebuilt for an audit. - **Recommendations that reach closure:** Each recommendation has an owner, due date and evidence, and links to the MOC or work order in your own systems. - **Repeats show up by equipment:** Leaks, alarms and bypasses clustered by unit and equipment show a repeating failure before it becomes a bigger event. ## Frequently asked questions ### What does OSHA PSM require after a near miss? It requires an investigation. Paragraph (m) of 29 CFR 1910.119 covers each incident that resulted in, or could reasonably have resulted in, a catastrophic release. It must start within 48 hours and use a process-knowledgeable team. Findings are resolved and documented. The report is reviewed with affected personnel and kept five years. ### Does IncidentKit manage our whole PSM program? No. It tracks incidents, investigations and recommendations. It links to the MOC, PHA and mechanical integrity records you keep elsewhere. It works beside your maintenance and document systems. ### How does EPA's 40 CFR 68.81 compare with the PSM rule? It reads much like paragraph (m): investigate any incident that did or could reasonably have caused a catastrophic release, start within 48 hours, form a team, write a report, resolve findings and keep it five years. EPA adds provisions for some incidents, so check the current text. ### Do we need to tell the Chemical Safety Board about a release? Possibly. The CSB's rule at 40 CFR 1604.3 covers accidental releases to air from stationary sources that cause a fatality, a serious injury or $1,000,000 or more of property damage. Report within eight hours, or send the NRC number within 30 minutes of an NRC report. A person decides, and IncidentKit flags the possibility. ### Can contractors report, and what does it cost? Yes. A contractor reports by QR code or text like any employee, and a contract employee can sit on the investigation team. Non-patient incident reporting is free on the Open plan, with no seats, modules or setup fee. A per-site Regulated plan adds compliance packets and setup. ## Sources - [eCFR: 29 CFR 1910.119, process safety management of highly hazardous chemicals](https://www.ecfr.gov/current/title-29/section-1910.119) - [eCFR: 40 CFR 68.81, incident investigation](https://www.ecfr.gov/current/title-40/section-68.81) - [eCFR: 40 CFR 1604.2, definitions (Chemical Safety Board)](https://www.ecfr.gov/current/title-40/section-1604.2) - [eCFR: 40 CFR 1604.3, reporting an accidental release](https://www.ecfr.gov/current/title-40/section-1604.3) - [eCFR: 29 CFR 1904.39, reporting fatalities, hospitalizations, amputations and loss of an eye](https://www.ecfr.gov/current/title-29/section-1904.39) - [OSHA: Process safety management](https://www.osha.gov/process-safety-management) - [OSHA: Incident investigation](https://www.osha.gov/incident-investigation) ## Related - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Incident audit trail: every change, who and when](https://incidentkit.ai/product/audit-trail) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Contractor and Visitor Incidents: Who Reports What](https://incidentkit.ai/use-cases/contractor-and-visitor-incidents) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [PSM incident investigation: 29 CFR 1910.119(m) explained](https://incidentkit.ai/compliance/osha/process-safety-incident-investigation) - [Hazard communication 29 CFR 1910.1200: SDS, labels, training](https://incidentkit.ai/compliance/osha/hazard-communication) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [Lockout/tagout 29 CFR 1910.147: program and event data](https://incidentkit.ai/compliance/osha/lockout-tagout) --- # Incident reporting for utilities and energy field crews > Crews text in incidents from the truck, and safety tracks every case across districts. Source: https://incidentkit.ai/solutions/utilities-and-energy · Updated Oct 5, 2026 **Status: rolling out.** This pack is being released in stages. **Who:** Crews, plant operators and tree-trimming contractors report. District safety coordinators investigate, and the safety director and managers own fixes. ## The problems - **The crew is forty miles from a desk:** Incidents happen at a pole or a substation. The form waits in the truck, and clearance and briefing details thin out with every hand-off. - **Which establishment is this?:** The establishment is the office or base that supervises a crew (1904.46). Contractors and visiting crews make the right 300 log a real question. - **The job briefing is verbal:** 1910.269(c) requires a briefing before each job on hazards, procedures, energy controls and PPE. Spoken briefings get rebuilt from memory. - **Storm response runs on adrenaline:** Long shifts, mutual-aid crews and hourly changes make reporting slip. The only form that works from a truck at 3 am is a text. ## Incident types in the pack - Contact with an energized conductor - Arc flash or arc blast - Fall from a pole or aerial lift - Vehicle incident - Struck by a falling limb or pole - Unplanned energization or backfeed - Clearance or switching error - Confined space or manhole event - Heat or cold stress in storm work - Tree trimming contact - Dog bite on a service call - Near miss with serious injury potential ## Regulators and standards - **OSHA 29 CFR 1910.269:** Covers operation and maintenance of electric power generation, transmission and distribution. Also covers line-clearance tree trimming. It does not generally apply to construction work. - **OSHA 29 CFR 1910.269(c) (job briefing):** The employee in charge briefs the crew before each job on hazards, procedures, energy controls and PPE, at least once per shift for repetitive work, and again after significant changes. - **OSHA 29 CFR 1910.269(d) and (m), and 1910.147:** General lockout/tagout (1910.147) leaves out utility power installations under the utility's exclusive control. 1910.269 has its own energy control rules. - **OSHA 29 CFR 1904.46 and 1904.30 (establishments):** For crews not at one location, the establishment is the office, terminal or station that supervises them or is their base. Each employee links to one establishment. - **OSHA 29 CFR 1904.39 (severe injury reporting):** Report a fatality within 8 hours. Report an inpatient hospitalization, amputation or loss of an eye within 24 hours. Public-road crashes outside construction work zones are recorded, not reported. - **OSHA State Plans and public employers:** Federal OSHA does not cover state and local government workers in states without a State Plan. Municipal and public power utilities should check which program applies. - **OSHA heat National Emphasis Program (CPL 03-00-024):** The program's industry list includes electric power generation, transmission and distribution. It prioritizes an on-site response to employer-reported heat hospitalizations. ## How it works 1. **Report: from the truck, in a few texts** The foreman texts from the cab or scans a QR code. Lauren asks voltage class, who gave the clearance, and what tests, grounds and tailboard were in place. 2. **Investigate: with the briefing in the record** Lauren drafts the timeline and factors, marked 'Lauren · draft'. The district coordinator adds statements and photos and records what the briefing covered. A person reviews, edits and signs. 3. **Correct: owners, due dates, proof** Actions go to line supervisors with due dates and evidence, such as a revised tailboard form or a retraining roster. Nothing closes until verified, and overdue actions escalate. 4. **Prove: the right log, the trend, the trail** Each case lands on the right establishment's records. Exports of the 300, 300A and 301 are rolling out. Analytics group events by district, crew type, task and equipment. ## Scenario: An electrical contact burn during storm restoration A groundman touches a conductor the crew had been told was de-energized. - **Fri 2:40 am, Groundman shocked, foreman texts report.** The groundman has a hand burn and goes to the ER. The foreman texts the report from the truck. - **2:44 am, Lauren asks about clearance and tests.** Lauren asks the circuit, who gave the clearance, what tests and grounds were used and what the tailboard covered. - **2:50 am, Report routes, circuit crews warned.** The on-call safety coordinator, operations manager and system operator get the report. Other crews on the circuit are warned. - **6:30 am, ER releases worker, no admission.** The ER treats the burn and the worker leaves with a prescription. No inpatient admission means no 24-hour OSHA report is due. - **Fri 3:00 pm, Investigation finds customer generator backfeed.** The clearance matched utility records, but a customer generator back-fed the line. The restoration tailboard did not cover backfeed or test-before-touch. - **Day 3, Case goes on the establishment's log.** Prescription medication is medical treatment beyond first aid, and the worker misses two days. The case goes on the supervising establishment's log, inside seven days. - **Day 6, Backfeed actions get owners and dates.** Add a backfeed prompt to the tailboard in every district. Add test-before-touch to mutual-aid orientation. Send a safety bulletin. - **Day 18, Safety director verifies tailboard form.** In two districts, the safety director checks the updated form, attaches evidence and closes the actions. The next storm's briefings serve as the effectiveness check. ## What is in the pack **Forms:** Incident report with OSHA 301-equivalent fields; Near-miss report; Electrical contact supplement: voltage class, clearance, tests, grounds, tailboard; Vehicle incident and storm response supplements; Investigation worksheet and corrective action plan **Routing:** Reports go to the crew supervisor and district safety coordinator; Electrical contact and unplanned energization alert the safety director; Severe injuries alert the safety director, with 8-hour and 24-hour clocks; Contractor and visiting-crew reports copy the contractor's safety contact **Exports:** OSHA 300 log, 300A summary and 301 report by establishment (rolling out); Incident register by district, crew type, task and equipment; Investigation report as a PDF for a commission or insurer; Audit trail **Roles:** Reporter: any crew member, contractor or visiting crew; Foreman: reviews and routes; District safety coordinator: investigates; Safety director: classifies and closes; Executive: certifies the 300A; Read-only: commission, insurer or auditor ## Outcomes - **A report from the cab, not the office:** It starts at the pole, in the foreman's words, with photos, before the crew moves on. - **The briefing is part of the record:** Each investigation notes what the job briefing covered, so lessons go into the next tailboard, not only into a report. - **Cases on the right log:** The establishment question is asked at the start, so cases from crews and contractors reach the right OSHA records. - **Storm response under control:** Text-first reporting, on-call escalation and one shared record keep reporting going when conditions are worst. ## Frequently asked questions ### Does OSHA 1910.269 require an incident report? No. 1910.269 sets requirements for job briefings, energy control, training and more, but no incident form. Part 1904 recordkeeping and 1904.39 reporting still apply. IncidentKit captures what the briefing covered, the clearance and the conditions while the crew still remembers them. ### Which OSHA log do field crew injuries go on? The log of the establishment that supervises the crew (1904.46, 1904.30). Hurt at one of your establishments, the case goes on that log. Hurt away from all of them, it goes on the log where the employee normally works. ### Are vehicle crashes on public roads reportable to OSHA? Not if the crash is on a public street or highway outside a construction work zone. A fatality, hospitalization, amputation or loss of an eye from such a crash must still be recorded on your OSHA logs if you keep them (29 CFR 1904.39(b)(3)). ### We are a municipal or public power utility. Does this apply? The reporting and investigation parts work for any employer. For OSHA rules, check which program covers you. Federal OSHA does not cover state and local government workers in states without a State Plan, and State Plan states vary. ### What does it cost, and how does it work in a big storm? Non-patient incident reporting is free on the Open plan, with no seats, modules or setup fee. Reporting starts by text, routing sends a possible severe injury to the on-call person, and visiting crews report by QR code with no extra seats. Groups of ten or more sites can ask about Network. ## Sources - [eCFR: 29 CFR 1910.269, electric power generation, transmission and distribution](https://www.ecfr.gov/current/title-29/section-1910.269) - [eCFR: 29 CFR 1910.147, control of hazardous energy](https://www.ecfr.gov/current/title-29/section-1910.147) - [eCFR: 29 CFR 1904.30, multiple business establishments](https://www.ecfr.gov/current/title-29/section-1904.30) - [eCFR: 29 CFR 1904.46, definitions](https://www.ecfr.gov/current/title-29/section-1904.46) - [eCFR: 29 CFR 1904.39, reporting fatalities, hospitalizations, amputations and loss of an eye](https://www.ecfr.gov/current/title-29/section-1904.39) - [eCFR: 29 CFR 1904.7, general recording criteria](https://www.ecfr.gov/current/title-29/section-1904.7) - [OSHA: State Plans](https://www.osha.gov/stateplans) - [OSHA: Heat exposure overview](https://www.osha.gov/heat-exposure) - [OSHA: Severe injury reporting](https://www.osha.gov/severeinjury) ## Related - [Mobile incident reporting that works offline](https://incidentkit.ai/product/mobile-and-offline) - [Incident routing and escalation by severity](https://incidentkit.ai/product/routing-and-escalation) - [Multi-site incident management with roles and SSO](https://incidentkit.ai/product/multi-site-and-roles) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Contractor and Visitor Incidents: Who Reports What](https://incidentkit.ai/use-cases/contractor-and-visitor-incidents) - [Multi-site incident reporting software for groups](https://incidentkit.ai/solutions/multi-site-groups) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [Lockout/tagout 29 CFR 1910.147: program and event data](https://incidentkit.ai/compliance/osha/lockout-tagout) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [Injury reporting and retaliation: 29 CFR 1904.35 and 11(c)](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation) - [TRIR and DART rates: formula, example and BLS 2024 rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates) --- # One incident standard across every site you run > Every site reports and closes the same way, and corporate sees it all. Source: https://incidentkit.ai/solutions/multi-site-groups · Updated Oct 5, 2026 **Who:** Site staff report, and each site leader signs. A COO, VP of quality or risk, or head of EHS buys and reviews across sites without reading every incident. ## The problems - **Every site built its own process:** One site uses paper, another a spreadsheet, a third an inherited tool. Corporate retypes a monthly roll-up, so patterns show up a quarter late. - **Regulators judge each site on its own:** OSHA wants a 300 Log per establishment open a year or longer. CMS expects a QAPI quality program at each nursing home and surgery center. - **An acquisition arrives with unknown open items:** You inherit the seller's incident history and open actions in a format you did not choose. You cannot set a standard until you see them. - **Corporate needs visibility, not every report:** Corporate cannot read every incident, and sites should not need permission to run theirs. Set rules for what escalates, to whom, and how fast. ## Incident types in the pack - Serious events needing same-day corporate notice - The same incident repeating at two or more sites - Overdue corrective actions by site and owner - Reporting clocks running at several sites - Quarterly QAPI and board quality packets - OSHA 300A summaries for each establishment - Survey results with plans of correction in flight - Incidents at a newly acquired site - Contractor, visitor and agency-staff incidents - Carrier questions at renewal - A new leader inheriting open items - A policy change that must land everywhere ## Regulators and standards - **CMS: skilled nursing QAPI, 42 CFR 483.75:** Each long-term care facility, even in a multiunit chain, runs its own QAPI program, and its QAA committee meets at least quarterly. The evidence lives at the facility. - **CMS: multi-hospital systems, 42 CFR 482.21(g):** A health system's governing body can elect one QAPI program for two or more separately certified hospitals, if each shows its local issues are considered. - **CMS: surgery centers, 42 CFR 416.41 and 416.43:** Each surgery center's governing body oversees its QAPI program and must provide staff, time, systems and training. - **OSHA: multiple establishments, 29 CFR 1904.30:** Keep a separate 300 Log for each establishment expected to run a year or longer. Central records are allowed if case data reaches that location within seven calendar days. - **OSHA: electronic submission, 29 CFR 1904.41:** Covered establishments submit 300A data once a year, by March 2. A corporate office that controls establishments may collect and submit for them. - **HIPAA: business associates, 45 CFR 160.103:** A vendor that maintains patient information for a covered entity is a business associate. Regulated plans include a business associate agreement (BAA); see [HIPAA](https://incidentkit.ai/hipaa). ## How it works 1. **Set the standard once** Set incident types, severity levels and escalation rules, with a pack for each kind of site. A surgery center, a nursing home and a plant can share one account. 2. **Bring each site live in 48 hours** Our team does the setup: facilities, users, QR codes, role templates, SSO on the Network plan, and import of the site's history. Staff report in their own words by text. 3. **Let each site run its own incidents** Lauren drafts the form from the site's answers. The reviewer edits and signs, and drafted fields are marked 'Lauren · draft' until approved. Severity rules notify corporate. 4. **See every site in one place** Org-level analytics cluster incidents by site, shift, equipment and cause. Overdue actions sort by site and owner. Each facility's QAPI summary or survey packet builds from its own record. ## Scenario: Adding a nursing home to two surgery centers and a plant A group with two surgery centers and a plant on a rolling-out industry pack buys a nursing home on a Monday. - **Monday, 09:00, Quality lead adds the nursing home.** The deal closes. The quality lead adds the facility and assigns the nursing home pack. The other sites stay on their own packs. - **Monday, 14:00, Seller's incident log is imported.** Setup starts. The seller's incident log arrives as a spreadsheet and is imported. Open items keep their original dates and get new owners. - **Tuesday, Staff get roles through single sign-on.** QR codes go up at the nurse stations, and a nurse texts a test report. Leaders get role templates through single sign-on. - **Wednesday, 09:00, Facility goes live in 48 hours.** Corporate sees the facility's open actions, some already overdue, next to the other three sites, 48 hours after kickoff. - **Day 9, 02:40, Night nurse reports an unexplained bruise.** A resident has a bruise of unknown source. The night nurse texts it in. It routes to the administrator at once, with the 42 CFR 483.12(c) reporting windows noted. - **Day 9, 08:15, Administrator signs the draft report.** The administrator corrects two fields and signs. The regional vice president is alerted under the severity rule. The director of nursing opens the investigation. - **Day 9, same week, Plant near miss routes separately.** In the same organization, a forklift near miss at the plant routes to the plant manager and EHS lead. Corporate filters both by pack. - **Day 75, QAA committee reviews the QAPI summary.** The nursing home's QAA committee meets. Its QAPI summary builds from the facility's own incidents and actions, and corporate sees the same data. ## What is in the pack **Forms:** Group-wide form template with site-level additions; Nursing home report: falls, unknown-source injuries, abuse allegations; Surgery center report: patient events, near misses, equipment; Plant injury and near-miss report; Contractor, visitor and agency-staff incident form **Routing:** Severity rules notify the site leader first, corporate by threshold; Site-specific recipients and backups for each kind of event; Same-day alerts for events with a reporting clock; Open items reassign when a site leader leaves **Exports:** QAPI summary per facility; Survey packet per facility; OSHA 300, 300A and 301 per establishment (rolling out); Org-wide analytics by site, shift, equipment and cause; Read API and signed webhooks for your own reporting **Roles:** Group administrators: sites, packs, SSO and role templates; Corporate reviewers: read and analyze across sites; Site administrators and plant managers: review, sign, assign and close; Investigators and action owners: scoped to their own site ## Outcomes - **One standard, site-level evidence:** Every site shares incident types, severity levels and action rules, and each keeps its own record for surveyors. - **Patterns across sites while they are small:** Because every site codes incidents the same way, the same near miss at two plants is one trend, not two anecdotes. - **New sites on the standard in days:** Done-for-you setup and import put an acquired site on the group's system within 48 hours, with inherited open items visible and owned. - **Packets for every site without a monthly retype:** QAPI summaries and survey packets build from the record, so corporate reviews them instead of assembling them. See [compliance packets](https://incidentkit.ai/product/compliance-packets). ## Frequently asked questions ### Can one IncidentKit account hold surgery centers, nursing homes and plants together? Yes. A pack sets incident types, forms, regulator exports and roles for a kind of site, and you can mix packs across sites in one organization. Corporate sees all of them. Industry packs beyond healthcare are rolling out. ### How does pricing work for a group? No seats, modules or setup fees. Non-patient incidents are free on the Open plan. Healthcare and audit-ready work is a per-site Regulated plan with a BAA, patient information, compliance packets and setup. Groups of 10 or more sites get the custom Network plan, adding SSO, the API, org-wide analytics and migration. See [pricing](https://incidentkit.ai/pricing). ### Can corporate keep OSHA records in one place? Yes, but each establishment expected to operate a year or longer still needs its own 300 Log. Under 29 CFR 1904.30(b)(2) the central location must receive case information within seven calendar days and send records back within OSHA's access deadlines. IncidentKit keeps each establishment's record separate. OSHA 300, 300A and 301 exports are rolling out. ### How do we bring in a site we just acquired? We set up the facility, import the seller's incident history, and assign owners to open items. Setup takes 48 hours per site. See [import and migration](https://incidentkit.ai/product/import-and-migration). ### Does IncidentKit replace our EHR, CMMS or HRIS? No. It runs alongside them. Deeper EHR, CMMS and HRIS integrations are rolling out. Today the platform offers signed webhooks and a read API so your own systems can use incident data. See [integrations and API](https://incidentkit.ai/product/integrations-and-api). ## Sources - [29 CFR 1904.30, Multiple business establishments (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.30) - [29 CFR 1904.41, Electronic submission of injury and illness records (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.41) - [29 CFR 1904.46, Definitions, establishment (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.46) - [42 CFR 483.75, Quality assurance and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/part-483/section-483.75) - [42 CFR 482.21, Hospital QAPI program (eCFR)](https://www.ecfr.gov/current/title-42/part-482/section-482.21) - [42 CFR 416.43, ASC QAPI (eCFR)](https://www.ecfr.gov/current/title-42/part-416/section-416.43) - [42 CFR 416.41, ASC governing body and management (eCFR)](https://www.ecfr.gov/current/title-42/part-416/section-416.41) - [45 CFR 160.103, HIPAA definitions, business associate (eCFR)](https://www.ecfr.gov/current/title-45/part-160/section-160.103) - [CMS State Operations Manual, Appendix PP (F865 and the multiunit chain intent)](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) ## Related - [Multi-site incident management with roles and SSO](https://incidentkit.ai/product/multi-site-and-roles) - [Incident analytics: find the pattern before the next one](https://incidentkit.ai/product/analytics) - [Migrate incident data from paper, Excel or legacy software](https://incidentkit.ai/product/import-and-migration) - [Incident reporting API, webhooks and integrations](https://incidentkit.ai/product/integrations-and-api) - [Incident reporting software pricing: free to start](https://incidentkit.ai/pricing) - [IncidentKit security overview](https://incidentkit.ai/security) - [HIPAA and BAA for incident reporting](https://incidentkit.ai/hipaa) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [Always Survey-Ready: Stay Prepared for Unannounced Surveys](https://incidentkit.ai/use-cases/always-survey-ready) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [Hospital QAPI requirements: 42 CFR 482.21 explained](https://incidentkit.ai/compliance/cms-qapi/hospitals) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA electronic submission: 29 CFR 1904.41 and the ITA](https://incidentkit.ai/compliance/osha/electronic-submission) - [F865 QAPI program and plan: what surveyors ask for](https://incidentkit.ai/compliance/f-tags/f865) --- # A structured incident record, from report to claim file > Insureds capture incidents early, so carriers get cleaner data and claims-ready files. Source: https://incidentkit.ai/solutions/insurers-and-risk-pools · Updated Oct 5, 2026 **Status: rolling out.** This pack is being released in stages. **Who:** The insured reports, investigates and signs. The carrier, third-party administrator (TPA), pool or captive receives; this path is early, and the page says where. ## The problems - **The first report arrives late and thin:** A claim can start with an email weeks later, from someone who was not there. Facts arrive in the order the insured recalls them. - **Notice timing can decide how a policy responds:** Claims-made policies respond when a claim is reported in force or in an extended reporting period (NAIC). An incident nobody captured may never be reported. - **Loss control works from lagging data:** IRMI defines loss control as reducing the chance or severity of loss. Without early data, it sees the loss run, not the near misses. - **Every insured reports in a different shape:** Workers' compensation first reports follow state forms and deadlines, such as Texas's eight days. Liability notices have no common intake. ## Incident types in the pack - First notice of a possible claim - Notice of circumstances under a claims-made form - Workers' compensation first report of injury - Medication errors and wrong-site events - Falls with injury in senior living - Abuse and neglect allegations with a reporting clock - Employee injuries that are OSHA recordable - Equipment failures and property damage - Repeat events at one insured - Corrective actions after a serious event - Contractor and visitor injuries - Incident files requested by an adjuster or counsel ## Regulators and standards - **IAIABC EDI Claims standard:** IAIABC publishes the standard for first and subsequent reports of injury (FROI, SROI) sent to jurisdictions. Release 3.1 is current. Our integration is rolling out, with no conformance claimed today. - **State workers' compensation agencies:** Each state sets its own first-report rules. Texas uses DWC Form-001, due within eight days after an employee cannot work for over a day, or immediately for disease or death. - **OSHA recordkeeping forms, 29 CFR 1904.29:** An insurance form can replace the OSHA 301 if it is as readable, carries the same information and follows the same instructions. Names may be shared to process a claim. - **NAIC: claims-made forms, risk retention groups, captives:** Risk retention groups are liability insurers owned by their members (Liability Risk Retention Act of 1986). Captives are owned by the insured. Claims-made and occurrence forms respond differently. - **AHRQ Patient Safety Organization program:** Patient safety work product reported to a listed PSO can carry federal protections when requirements are met. The insured and its counsel decide what goes to a carrier. - **HIPAA:** A carrier is separate from the insured provider. The insured's privacy officer and counsel decide what patient information flows to it, and on what basis. See [HIPAA](https://incidentkit.ai/hipaa). ## How it works 1. **Live: the insured captures the incident when it happens** Staff text what happened to Lauren, or use QR or email. Lauren drafts the form, marked 'Lauren · draft' until a person approves it. Every change is logged. 2. **Live: the insured investigates and closes the loop** Contributing factors, five whys and disposition, then corrective actions with an owner, due date, evidence and effectiveness check. Nothing closes until verified. 3. **Live: the insured sends a claims-ready packet** When an incident may become a claim, the insured exports the narrative, timeline, investigation, actions and audit trail as a packet. Nothing leaves unless the insured sends it. 4. **Rolling out: a structured feed for carriers and TPAs** A data feed and API for carriers and TPAs to receive incident records in one structure, plus workers' compensation first-report integration. We name no supported carriers or TPAs today. ## Scenario: From an unplanned transfer to a claims-ready file A surgery center transfers a patient; every step through day 40 works today, and the last is rolling out. - **Tuesday, 15:10, Circulating nurse texts Lauren.** From recovery, the circulating nurse texts Lauren that the patient's condition changed 20 minutes ago and an ambulance is on the way. - **Tuesday, 15:12, Lauren drafts the transfer report.** Lauren asks when it started, what was done, who was told and whether the family knows. The draft is marked 'Lauren · draft'. - **Tuesday, 15:40, Escalation notifies administrator and risk lead.** The charge nurse reviews, edits and signs. Rules notify the administrator and risk lead, because the insured treats transfers as possible claims. - **Wednesday, 09:00, Administrator opens the investigation.** The administrator lists the causes. The risk lead reads the policy's notice conditions and decides whether to notify the carrier. That decision stays with the insured. - **Wednesday, 10:30, Packet reaches carrier claims intake.** The insured exports a packet with the narrative, timeline, investigation and audit trail. It goes to claims intake. The adjuster starts from a record, not an email chain. - **Day 10, Investigation closes with two actions.** Each of the two corrective actions has an owner and a due date. - **Day 40, Effectiveness check closes the actions.** If the insured shares the file, loss control sees the fix held. Evidence is attached and the effectiveness check is done before the actions close. - **When the feed ships, Structured feed reaches the carrier.** Rolling out: the same event reaches a participating carrier or TPA as a structured record when the insured sends it, not as a document someone retypes. ## What is in the pack **Forms:** The insured's incident form for its setting, from any pack; Investigation record with causes, five whys and disposition; Action plan with owner, due date, evidence, effectiveness check; Workers' comp first-report data set (rolling out) **Routing:** Possible claims alert the risk lead and administrator at once; Severity rules for loss-control events; Reminders for open actions after serious events **Exports:** Claims-ready file: narrative, investigation, audit trail (live); QAPI summaries and survey packets (live); OSHA 300, 300A and 301 exports (rolling out); Carrier and TPA data feed and API (rolling out); Workers' comp first-report integration (rolling out) **Roles:** The insured's reporters, reviewers and action owners; The insured's administrators decide what is shared; Carrier and TPA access: packets today, direct feed rolling out ## Outcomes - **Earlier first notice, by design:** Incidents are recorded when they happen, with a time and an author. Whether to notify a carrier stays the insured's call. - **Cleaner data at the source:** Same questions per event type, with structured fields behind the narrative. Structure at intake is what makes a later feed possible. - **Loss-control visibility:** A loss-control team can see repeat events, overdue actions and unchecked fixes, with the insured's agreement. - **A claims-ready file from day one:** The packet carries the narrative, investigation and audit trail, so an adjuster starts from a record. See [audit trail](https://incidentkit.ai/product/audit-trail) and [compliance packets](https://incidentkit.ai/product/compliance-packets). ## Frequently asked questions ### Can an insurer or TPA use IncidentKit today? Not as a carrier product. Today the insured is the customer. It reports, investigates and closes incidents in IncidentKit. It can send a claims-ready packet to a carrier, TPA or counsel. The carrier-side data feed and first-report integration are rolling out. ### How does this relate to workers' compensation first reports? IncidentKit captures the data a first report of injury (FROI) needs. The integration that sends it onward is rolling out. Claims administrators use the IAIABC EDI standard, now Release 3.1, to send FROI and later reports (SROI) to jurisdictions. See [FROI](https://incidentkit.ai/glossary/froi). ### Does sharing incident data with a carrier waive privilege? That is a question for the insured's counsel, because answers differ by state and program. Federal protections can apply to patient safety work product reported to a listed PSO. IncidentKit does not decide what the insured shares. ### Will a carrier see our incidents automatically? No. Today nothing leaves the organization unless the insured exports it. Our intent for the feed is that the insured controls what is shared and with whom. ### How can a carrier, TPA or pool take part? Tell us what a feed would need to contain for your claims or loss-control team. Early input shapes what we build. Use [contact](https://incidentkit.ai/contact) or see the [partners](https://incidentkit.ai/partners) page. ## Sources - [IAIABC, EDI Claims standards (FROI and SROI)](https://www.iaiabc.org/edi-claims) - [Texas Department of Insurance, Employer FAQ (DWC Form-001 deadline)](https://www.tdi.texas.gov/wc/employer/employerfaq.html) - [29 CFR 1904.29, Forms (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.29) - [NAIC, Risk retention groups](https://content.naic.org/insurance-topics/risk-retention-groups) - [NAIC, Captive insurance companies](https://content.naic.org/insurance-topics/captive-insurance-companies) - [NAIC, Medical malpractice insurance (claims-made and occurrence forms)](https://content.naic.org/insurance-topics/medical-malpractice-insurance) - [IRMI, Loss control definition](https://www.irmi.com/term/insurance-definitions/loss-control) - [AHRQ, Patient Safety Organization (PSO) Program](https://pso.ahrq.gov/) ## Related - [QAPI, survey and OSHA compliance packets](https://incidentkit.ai/product/compliance-packets) - [Incident reporting API, webhooks and integrations](https://incidentkit.ai/product/integrations-and-api) - [Incident audit trail: every change, who and when](https://incidentkit.ai/product/audit-trail) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [FROI (First Report of Injury): definition and meaning](https://incidentkit.ai/glossary/froi) - [Workers' compensation: definition and meaning](https://incidentkit.ai/glossary/workers-compensation) - [Patient safety organization: definition and meaning](https://incidentkit.ai/glossary/patient-safety-organization) - [Multi-site incident reporting software for groups](https://incidentkit.ai/solutions/multi-site-groups) - [IncidentKit partner program](https://incidentkit.ai/partners) - [HIPAA and BAA for incident reporting](https://incidentkit.ai/hipaa) - [OSHA 301 incident report: the 18 fields and deadlines](https://incidentkit.ai/compliance/osha/osha-301-incident-report) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) --- # One view across every client you keep survey-ready > Keep every client survey-ready from one view, while each client owns its record. Source: https://incidentkit.ai/solutions/compliance-consultants · Updated Oct 5, 2026 **Who:** Client staff report, and at each client the administrator, director of nursing or EHS lead signs. The consultancy buys; you advise, review and assemble, and the client owns the record. ## The problems - **Every client has a different tracker:** One client keeps a spreadsheet, another a binder. Before each visit you rebuild what happened, what is open and what a surveyor would ask first. - **Your advice lives outside their system:** You find the pattern and write it in a report. Nothing makes the client assign, date or check it, so the same finding returns. - **Packets are hand-built for each client:** QAPI (CMS's quality program) summaries, committee packets and survey binders are assembled by hand, in your template, from whatever data the client could export. - **Access to patient information needs structure:** HIPAA treats consultants who receive protected health information as business associates, as it does their subcontractors. You need an agreement, a scope and a log. ## Incident types in the pack - Mock-survey findings needing an owner and date - Plans of correction after a CMS-2567 - Quarterly QAA and QAPI committee packets - Repeat falls, medication events or abuse allegations - Reporting-clock questions - OSHA 300A summaries and submissions by establishment - Corrective actions closed with no evidence - Performance improvement projects needing a reason and result - New-client onboarding and baseline readiness - Accreditation preparation - A client leadership change leaving open items - Board and owner quality reports ## Regulators and standards - **CMS-2567 and plans of correction, 42 CFR 488.402(d):** Most deficiencies need a plan of correction (isolated, minimal-harm ones are excepted). CMS's nursing home guidance says an acceptable plan is due within 10 calendar days of receiving the CMS-2567. - **CMS QAPI: 42 CFR 483.75, 482.21 and 416.43:** A nursing home presents its QAPI plan at each annual survey and shows the program runs. Its QAA committee meets at least quarterly. Hospitals and surgery centers have parallel duties. - **HIPAA business associates, 45 CFR 160.103:** Consulting and accreditation services that involve disclosure of protected health information fall within the business associate definition, as do subcontractors. Regulated plans include a business associate agreement (BAA). - **OSHA 29 CFR 1904.29(b)(10):** An employer may share unredacted 300 and 301 forms with a consultant hired to evaluate its safety and health program. Other voluntary disclosures must remove names and identifying details. - **Accreditors: AAAHC, Joint Commission, DNV, ACHC, CIHQ, CARF and Quad A:** Each sets its own standards and survey cycle. Your packets follow the accreditor the client uses. ## How it works 1. **Give each client its own organization** Each client keeps its own organization, with its own users, facilities, packs and audit trail. You get a consultant view across the clients you serve. 2. **Run the engagement inside the record** Mock-survey findings, QAPI project tasks and corrective actions become actions with an owner, due date and evidence, assigned to client staff. Nothing closes until verified. 3. **See all clients at once** One view shows open and overdue actions, repeat clusters and packet status across clients, so you walk into each visit knowing where to start. 4. **Send packets under your name** QAPI summaries and survey packets build from the client's record. White-label packets carry your branding. The client's administrator reviews and signs. ## Scenario: One consultant, three clients, one quarter A consultancy supports a surgery center, a nursing home and a home-health agency, and the nursing home's annual survey window is open. - **Monday, 08:30, Cross-client view shows overdue work.** Fall-prevention actions at the nursing home are overdue, and a surgery center project has no result documented. - **Monday, 10:00, Consultant opens the falls cluster.** Most falls in the nursing home's cluster are unwitnessed, on nights, near two rooms. Two actions closed with no evidence attached. - **Tuesday, on site, Mock survey findings become actions.** With the administrator and director of nursing, a mock survey yields three findings, logged as actions with owners and dates. F689 is noted for the fall-supervision gap. - **Wednesday, Staff close actions with evidence.** Of the two actions, the older one's effectiveness check is set 30 days out. It stays open until verified. - **Thursday, Quarterly QAPI summary builds from record.** For the surgery center, the project's reason and result are documented, as 42 CFR 416.43(d)(2) asks. - **Friday, Packets go out under firm branding.** Each of the three administrators reviews, edits and signs, and Lauren's drafts stay marked until approved. - **Six weeks later, Survey ends with one deficiency.** The CMS-2567 arrives and the 10-day plan of correction clock starts. The record shows who did what, when, and whether it was checked. ## What is in the pack **Forms:** The client's own pack forms for its kind of site; Corrective action plan with owner, due date, evidence, effectiveness check; QAPI improvement project record with reason and result **Routing:** Findings go to the client's administrator or director of nursing, not you; Overdue actions escalate to client leadership and show in your view; Client-set severity rules decide what notifies you **Exports:** QAPI summaries and committee packets; Survey packets; White-label packet branding; OSHA 300, 300A and 301 exports (rolling out); Cross-client view of open and overdue work **Roles:** Consultant users, scoped to the clients they serve; Client administrators, who own the record and sign; Client reviewers, investigators and action owners ## Outcomes - **One start line for every visit:** The cross-client view shows overdue work, repeat clusters and packet status, so preparation starts from what is open, not a rebuild. - **Advice that becomes owned work:** Each finding becomes an action with an owner, date and evidence, and closes only when verified, so it does not return. - **Packets that carry your name:** QAPI summaries and survey packets build from the client's record and can carry your branding. See [compliance packets](https://incidentkit.ai/product/compliance-packets). - **Built by people who have done this work:** Built by the team behind PharmPro's consulting practice: 31 years in survey and inspection prep, and more than 250 facilities through survey. ## Frequently asked questions ### Do my clients keep their own data? Yes. Each client is its own organization with its own users, facilities and audit trail, and the record belongs to the client. You see across clients through the consultant view. ### How does pricing work if I support many clients? There are no seats, modules or setup fees. Non-patient incidents are free on the Open plan. Healthcare work is a per-site Regulated plan with a BAA, patient information, compliance packets and done-for-you setup. Partner terms are on the [partners](https://incidentkit.ai/partners) page. ### Do I need a business associate agreement? If you handle protected health information for a covered entity, HIPAA's business associate definition includes your consulting services and your subcontractors. Regulated plans include a BAA. Which agreement structure fits an engagement is for your counsel and the client's privacy officer. See [HIPAA](https://incidentkit.ai/hipaa). ### Can I put my firm's branding on packets? Yes. White-label packets are part of the partner program. The client's administrator still reviews and signs, and anything Lauren drafted is marked 'Lauren · draft' until a person approves it. ### Where did IncidentKit come from? It was built by the compliance team behind PharmPro's compliance consulting practice: 31 years in survey and inspection prep, and more than 250 facilities taken through survey. See [about](https://incidentkit.ai/about). ## Sources - [45 CFR 160.103, HIPAA definitions, business associate (eCFR)](https://www.ecfr.gov/current/title-45/part-160/section-160.103) - [29 CFR 1904.29, Forms and disclosure to an auditor or consultant (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.29) - [42 CFR 488.402, Remedies, plan of correction requirement (eCFR)](https://www.ecfr.gov/current/title-42/part-488/section-488.402) - [CMS, Nursing home enforcement FAQ (plan of correction timing)](https://www.cms.gov/medicare/provider-enrollment-and-certification/surveycertificationenforcement/downloads/nh-enforcement-faq.pdf) - [CMS, Form CMS-2567 Statement of Deficiencies and Plan of Correction](https://www.cms.gov/medicare/cms-forms/cms-forms/downloads/cms2567.pdf) - [42 CFR 483.75, Quality assurance and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/part-483/section-483.75) - [42 CFR 416.43, ASC QAPI (eCFR)](https://www.ecfr.gov/current/title-42/part-416/section-416.43) - [CMS State Operations Manual, Appendix PP (F689)](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) ## Related - [IncidentKit partner program](https://incidentkit.ai/partners) - [Multi-site incident management with roles and SSO](https://incidentkit.ai/product/multi-site-and-roles) - [QAPI, survey and OSHA compliance packets](https://incidentkit.ai/product/compliance-packets) - [Always Survey-Ready: Stay Prepared for Unannounced Surveys](https://incidentkit.ai/use-cases/always-survey-ready) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [Survey and accreditation readiness: a continuous approach](https://incidentkit.ai/guides/survey-and-accreditation-readiness) - [Survey readiness self-check for healthcare facilities](https://incidentkit.ai/tools/survey-readiness-check) - [HIPAA and BAA for incident reporting](https://incidentkit.ai/hipaa) - [About IncidentKit: built by survey-prep veterans](https://incidentkit.ai/about) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) - [Nursing home recertification survey: process and prep](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) --- # Incident reporting built around your OSHA calendar > Own the 300 Log with one record per injury and every deadline in view. Source: https://incidentkit.ai/solutions/ehs-managers · Updated Oct 5, 2026 **Who:** Workers and supervisors report; you classify, investigate and keep the log. A company executive certifies the annual summary. ## The problems - **One injury, four systems:** Notes sit in a binder, an email, HR and the carrier's file. You rebuild the case to decide if it is recordable. - **The clocks run before you know the case:** Log a recordable case within seven calendar days of learning of it. Report a death within 8 hours; hospitalization, amputation or eye loss within 24. - **Reporting must not discourage employees:** Your reporting procedure must not discourage a reasonable employee. Employees must be told they cannot face retaliation for reporting. - **Corrective actions drift:** Retraining is easy to assign. Engineering fixes need downtime, so they wait. No one checks if the fix worked. ## Incident types in the pack - Recordable or first-aid calls (29 CFR 1904.7) - Near misses and floor hazard reports - Deaths, hospital stays, amputations, eye loss - 300 Log and 301 requests, due by the end of the next business day - Privacy concern cases and the confidential name list - Contractor and temporary-worker injuries: whose log? - Workers' comp first reports that match the OSHA record - 300A review, certification, posting, electronic submission - Lockout/tagout and machine-guarding incidents - Chemical exposures and hazard communication - Workplace violence reports - Corrective actions due, overdue or awaiting a check ## Regulators and standards - **OSHA recordkeeping, 29 CFR 1904:** Recordable: death, days away, restricted work or transfer, treatment beyond first aid, loss of consciousness, or a significant diagnosed injury or illness. Log within seven calendar days; keep five years. - **Severe injury reporting, 29 CFR 1904.39:** Report a work-related death within 8 hours, and an inpatient hospitalization, amputation or loss of an eye within 24 hours. Call the nearest Area Office or 1-800-321-OSHA, or report online. - **Annual summary and electronic submission, 29 CFR 1904.32 and 1904.41:** A company executive certifies the 300A. Post it from February 1 through April 30. Covered establishments submit data to OSHA by March 2. - **Employee involvement, 29 CFR 1904.35:** Tell employees how to report, and never punish them for it. Employees and their representatives get 300 Log copies by the end of the next business day. - **NIOSH hierarchy of controls:** Controls rank from best to worst: elimination, substitution, engineering controls, administrative controls, then personal protective equipment. - **BLS incidence rates:** Rate is cases times 200,000, divided by employee hours worked. The 200,000 equals 100 full-time employees for a year. DART counts only days away, restricted or transferred cases. ## How it works 1. **Employees report in their own words** A worker or supervisor texts what happened, scans a QR code or emails it in. Lauren asks what an EHS manager would ask: the task, the equipment, the body part, whether treatment went beyond first aid and whether anyone left the shift. Voice reporting is rolling out. 2. **You classify, and the record carries the clock** Lauren drafts the fields and surfaces the questions that decide recordability. You review, edit and sign. Escalation rules alert you the moment a report mentions a hospitalization or an amputation. 3. **Investigate and assign** Record contributing factors, run the five whys and set a disposition. Corrective actions carry an owner, a due date, evidence and an effectiveness check. Nothing closes until verified. 4. **Read the pattern across the site** Analytics cluster incidents by location, shift, equipment and cause. OSHA 300, 300A and 301 exports are rolling out. Until they ship you transfer entries to your existing forms from a record that already holds the facts. ## Scenario: A hand injury on second shift A cut hand on a packaging line runs from the floor to the 300 Log and an effectiveness check. - **19:20, Supervisor texts the injury to Lauren.** An operator cuts a hand clearing a jam on line 4. The supervisor texts Lauren from the floor. - **19:22, Lauren drafts the incident report.** Lauren asks about the task, lockout, guards and where the operator is now. The draft is marked 'Lauren · draft'. - **19:50, Clinic sutures make the case recordable.** Sutures are medical treatment beyond first aid under 29 CFR 1904.7 (Steri-Strips are first aid), so the case is recordable. - **20:10, EHS manager reviews and signs.** An alert tells the EHS manager about the clinic visit. She reviews the draft, fixes the cause field and signs. - **Next day, 07:30, EHS manager opens the investigation.** Clearing jams was routine, and that spot had no lockout point. The EHS manager starts the action list. - **Day 3, Two actions assigned with engineering first.** An interlocked door (engineering) and a new clearing procedure (administrative) get owners and due dates. Engineering ranks higher in the hierarchy of controls. - **Day 7, Case recorded on the 300 Log.** Inside the seven-day window, the case goes on the 300 Log. The workers' compensation first report comes from the same record. - **Day 60, Effectiveness check closes the action.** The check reviews jam events on line 4 since the door went in. The action closes only after the EHS manager verifies the evidence. ## What is in the pack **Forms:** Injury report with recordability questions; Near miss and hazard report, with QR quick report; Contractor and visitor incident form; Corrective action plan: owner, due date, evidence, check **Routing:** Instant alert for hospitalization, amputation, eye loss, fatality; Supervisor and plant manager alerts by severity; HR and workers' compensation path set by site **Exports:** OSHA 300, 300A and 301 (rolling out); Analytics by location, shift, equipment and cause; Corrective action and effectiveness report; Read API and signed webhooks **Roles:** EHS manager: classifies, investigates, signs; Supervisor: reviews first-line reports; Action owners: close with evidence; Plant leadership: reads across the site ## Outcomes - **One record per case:** The report, clinic note, investigation, actions and audit trail live together. - **Deadlines in front of you, not in your head:** Severe injuries alert you as they are reported. Open and overdue actions sort by owner and age. - **Corrective actions that prove themselves:** An action closes only after evidence and an effectiveness check are verified. See [corrective actions](https://incidentkit.ai/product/corrective-actions). - **A reporting procedure employees will use:** A text or QR code is faster than a form, which supports the reporting procedure OSHA expects. See [near-miss reporting](https://incidentkit.ai/use-cases/near-miss-reporting). ## Frequently asked questions ### Does IncidentKit produce the OSHA 300, 300A and 301? Not yet. OSHA 300, 300A and 301 exports are rolling out. Today IncidentKit holds the incident record, investigation and corrective actions. OSHA accepts equivalent forms with the same information (29 CFR 1904.29), and the exports follow that standard. Industry packs beyond healthcare are rolling out too. ### How do I decide whether a case is recordable? A case is recordable if it involves death, days away from work, restricted work or job transfer, treatment beyond first aid, loss of consciousness, or a significant diagnosed injury or illness. Lauren asks the key questions; you make the call. See [recordable vs first aid](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid). ### How are TRIR and DART calculated? Multiply cases by 200,000, then divide by total hours worked by all employees. The 200,000 equals 100 full-time employees working a year. TRIR counts all recordable cases; DART counts only days away, restricted work or transfer. Try the [TRIR and DART calculator](https://incidentkit.ai/tools/trir-dart-calculator). ### When do I have to report an injury to OSHA? Within 8 hours of learning of a work-related fatality, and within 24 hours of learning of an inpatient hospitalization, amputation or loss of an eye. A hospital stay for observation or testing only does not count. See [severe injury reporting](https://incidentkit.ai/compliance/osha/severe-injury-reporting). ### Who can ask to see the 300 Log? Employees, former employees, their personal representatives and authorized employee representatives. Give them the log by the end of the next business day, with names left on except for privacy concern cases. An employee's own 301 is due by then too. ## Sources - [29 CFR 1904.7, General recording criteria (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.7) - [29 CFR 1904.29, Forms (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.29) - [29 CFR 1904.31, Covered employees (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.31) - [29 CFR 1904.32, Annual summary (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.32) - [29 CFR 1904.33, Retention and updating (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.33) - [29 CFR 1904.35, Employee involvement (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.35) - [29 CFR 1904.39, Reporting fatalities, hospitalizations, amputations and loss of an eye (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.39) - [29 CFR 1904.41, Electronic submission (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.41) - [BLS, How to compute your firm's incidence rate](https://www.bls.gov/iif/overview/compute-nonfatal-incidence-rates.htm) - [CDC NIOSH, Hierarchy of controls](https://www.cdc.gov/niosh/hierarchy-of-controls/about/index.html) - [OSHA, Recordkeeping](https://www.osha.gov/recordkeeping) ## Related - [OSHA 300 Log Automation: Keep It Accurate Year-Round](https://incidentkit.ai/use-cases/osha-300-log-automation) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Incident analytics: find the pattern before the next one](https://incidentkit.ai/product/analytics) - [TRIR and DART rate calculator (OSHA formula)](https://incidentkit.ai/tools/trir-dart-calculator) - [OSHA recordkeeping guide: Part 1904 for employers](https://incidentkit.ai/guides/osha-recordkeeping-guide) - [Workplace Injury Report Template (OSHA 301 Aligned)](https://incidentkit.ai/templates/workplace-injury-report) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [OSHA 301 incident report: the 18 fields and deadlines](https://incidentkit.ai/compliance/osha/osha-301-incident-report) - [OSHA 300A summary: who signs, when to post, how long](https://incidentkit.ai/compliance/osha/osha-300a-summary) - [Recordable vs first aid: OSHA's medical treatment test](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [OSHA electronic submission: 29 CFR 1904.41 and the ITA](https://incidentkit.ai/compliance/osha/electronic-submission) - [TRIR and DART rates: formula, example and BLS 2024 rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates) - [Injury reporting and retaliation: 29 CFR 1904.35 and 11(c)](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation) --- # Every adverse event investigated, closed and in the committee packet > Event data that arrives structured and leaves as a QAPI committee packet. Source: https://incidentkit.ai/solutions/risk-and-quality-leaders · Updated Oct 5, 2026 **Who:** Staff report, and you sort, investigate and present. The governing body answers for the QAPI program. ## The problems - **Reports arrive in any shape:** No time, no harm level, no note of who was told. You phone the unit to fill gaps. Nobody records the call. - **The committee packet is a monthly build:** Before each QAPI meeting you export, clean, sort and chart. The data is a month old. Nothing proves an action worked. - **Actions close because someone said so:** A surgery center must track adverse events and study causes. Fixes must last. A nursing home must check that corrective actions worked. - **Many audiences, many clocks:** State, accreditor, family and carrier each have a clock. The NAIC says report timing is part of how a claims-made policy responds. ## Incident types in the pack - Patient safety events by harm level, with near misses - Possible sentinel events: same-day alerts, root cause analysis - Medication events and high-alert near misses - Falls with injury - Pressure injuries and conditions acquired in care - Infection control events and clusters - Wrong-site, wrong-patient and retained-item events - Abuse, neglect and mistreatment allegations on state clocks - Unplanned transfers and returns to the operating room - Events that may become claims - Performance improvement projects and measures - Corrective actions awaiting a check ## Regulators and standards - **CMS hospitals, 42 CFR 482.21:** QAPI must track medical errors and adverse events, and act on causes. The governing body, medical staff and administrators answer for it. Multi-hospital systems may elect one program, paragraph (g). - **CMS surgery centers, 42 CFR 416.43:** The ASC must measure, analyze and track quality indicators and adverse patient events. It documents each project's reasons and results. - **CMS nursing homes, 42 CFR 483.75:** Find, report, track, investigate and analyze adverse events. Use the data to prevent more. The QAA committee meets at least quarterly. - **The Joint Commission and other accreditors:** Accreditors set their own sentinel event rules and timelines. Check your accreditor's policy. See [sentinel events](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events). - **AHRQ Patient Safety Organization program and Common Formats:** Patient safety work product sent to a listed PSO can carry federal protection when rules are met. AHRQ's Common Formats let you combine data. IncidentKit is not a PSO. - **Carrier notice under claims-made policies:** A claims-made policy responds to claims reported while it is in force or in an extended reporting period, the NAIC says. Read your notice terms with counsel. ## How it works 1. **Capture it structured, the first time** Lauren asks the questions you would ask: when, where, what level of harm, who was told and what was done. The reporter reviews the draft, and fields Lauren drafted are marked 'Lauren · draft' until a person approves them. 2. **Triage by rule, not by inbox** Type and severity route to you, the administrator, the medication safety lead or the infection preventionist as your rules say. Events that carry state or federal clocks alert you at once. 3. **Investigate with a method** Contributing factors, five whys and a disposition. A person always reviews, edits and signs. Human-authored RCA templates are rolling out. 4. **Close it, prove it, present it** Corrective actions need an owner, due date, evidence and an effectiveness check. The QAPI summary builds from the record: events by type, location and cause, projects with reasons and results, and whether the actions held. ## Scenario: A medication near miss reaches the committee A surgery center nurse catches a wrong anesthetic concentration, and the case goes from a text to the governing body's packet. - **Tuesday, 10:05, Nurse texts about wrong concentration.** Lauren asks about the drug and concentration. She asks who drew it up, where it was caught and about the label read-back. The draft is marked 'Lauren · draft'. - **Tuesday, 10:30, Signed report routes to risk manager.** The charge nurse signs. Routing sends the report to the risk manager and the medication safety lead. - **Wednesday, Risk manager opens the investigation.** Contributing factors include look-alike vials stored side by side and similar labels. - **Thursday, Three actions set with owners.** One action separates storage, one asks the supplier to change the label and one sends similar items to pharmacy review. All three get owners and due dates. - **Day 20, Second near miss joins the case.** The cluster view shows two events in three weeks, both in the same drug family and room. The risk manager links them. - **Day 45, Storage audit closes the actions.** The effectiveness check, a storage audit by observation, is verified. Evidence is attached and the actions close. - **Quarterly meeting, Governing body sees the QAPI summary.** The QAPI summary lists events by type, the project's reason and result, and each action's check. This shows improvements were evaluated, as 42 CFR 416.43(e)(2) expects. ## What is in the pack **Forms:** Patient safety event report with harm level prompts; Near miss and unsafe condition report; Serious event and sentinel event form; Corrective action plan: owner, due date, evidence, check; Improvement project record: reason, measure, result **Routing:** Rules route by type and severity to risk, pharmacy and infection prevention; Same-day alerts for events on a state, federal or accreditor clock; Escalation for events you class as possible claims **Exports:** QAPI summary for the committee; Survey packet; Event trends by type, location, shift and cause; Claims-ready incident file for a carrier or counsel **Roles:** Risk and quality leaders: triage, investigate, present; Administrators and department heads: review, sign, own actions; Governing body and committee: read summaries and packets; Reporters: any staff member, by text, QR, email or web ## Outcomes - **Complete reports without the phone chase:** Lauren asks follow-up questions as the event happens. Reports arrive with times, harm level and notifications. - **A committee packet that builds from the record:** The QAPI summary draws on incidents, projects and actions already in the system. Prep becomes review. See [QAPI committee meetings](https://incidentkit.ai/use-cases/qapi-committee-meetings). - **Proof that improvements held:** Actions close only after evidence and a check are verified. Committees and surveyors ask for exactly that. See [investigations](https://incidentkit.ai/product/investigations). - **One record for several audiences:** The same incident supports the committee, accreditor, state and, if you choose, the carrier. ## Frequently asked questions ### How does IncidentKit support the QAPI committee? It builds the QAPI summary from the incident record. The summary shows events by type, location and cause, improvement projects with reasons and results, and actions with effectiveness checks. A person reviews and signs it. See [compliance packets](https://incidentkit.ai/product/compliance-packets). ### Does IncidentKit replace our PSO relationship? No. IncidentKit is not a Patient Safety Organization. Protections for a listed PSO apply only when federal rules are met. Decide with your PSO and counsel what you report and how. ### What is the difference between an incident report, a variance report and an occurrence report? They are mostly names for the same thing. Hospitals often say patient safety event. CMS says adverse event. Some say variance or occurrence. IncidentKit uses incident as the standard word. See the [glossary entry for incident report](https://incidentkit.ai/glossary/incident-report). ### Can IncidentKit handle sentinel events? Yes. It alerts the right people to a possible sentinel event on your rules. It holds the investigation, root cause analysis and actions. Your accreditor and state set the definitions and timelines, so confirm both. See [what is a sentinel event](https://incidentkit.ai/blog/what-is-a-sentinel-event). ### Does IncidentKit work with the EHR? It runs alongside the EHR and does not replace it. Deeper EHR integrations are rolling out. Today the platform offers signed webhooks and a read API. ## Sources - [42 CFR 482.21, Hospital QAPI program (eCFR)](https://www.ecfr.gov/current/title-42/part-482/section-482.21) - [42 CFR 416.43, ASC QAPI (eCFR)](https://www.ecfr.gov/current/title-42/part-416/section-416.43) - [42 CFR 483.75, Nursing home QAPI (eCFR)](https://www.ecfr.gov/current/title-42/part-483/section-483.75) - [AHRQ, Patient Safety Organization (PSO) Program](https://pso.ahrq.gov/) - [NAIC, Medical malpractice insurance (claims-made and occurrence forms)](https://content.naic.org/insurance-topics/medical-malpractice-insurance) ## Related - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Incident analytics: find the pattern before the next one](https://incidentkit.ai/product/analytics) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Patient safety organization: definition and meaning](https://incidentkit.ai/glossary/patient-safety-organization) - [Patient safety event reporting software for hospitals](https://incidentkit.ai/solutions/hospitals) - [Hospital QAPI requirements: 42 CFR 482.21 explained](https://incidentkit.ai/compliance/cms-qapi/hospitals) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [F867 QAPI improvement activities: adverse event tracking](https://incidentkit.ai/compliance/f-tags/f867) --- # From the 24-hour report to the QAA meeting, in one record > Complete reports, checked interventions and a QAA packet you present, not assemble. Source: https://incidentkit.ai/solutions/directors-of-nursing · Updated Oct 5, 2026 **Who:** Nurses and aides report; you review, investigate and lead the response. The administrator signs state reports and the QAA committee reviews trends. ## The problems - **The report arrives incomplete at the morning meeting:** A 03:00 fall reaches the 24-hour report as one line. Rounding, footwear, bed height and the care plan all need chasing. - **Allegations run on short clocks:** Allegations are due within 2 hours if abuse or serious bodily injury is involved, otherwise 24 hours. Results are due in 5 working days. - **Interventions do not get checked:** Interventions go on the care plan. No one checks if they worked until the next fall. CMS expects monitoring for effectiveness. - **The rules define your role:** You sit on the QAA committee. You may be charge nurse only if average daily occupancy is 60 or fewer. You answer for every shift. ## Incident types in the pack - Falls, witnessed or not, with or without injury - Injuries of unknown source - Resident-to-resident altercations - Abuse, neglect and mistreatment allegations - Medication errors and significant medication errors - Pressure injuries and skin changes found on checks - Elopement and wandering events - Choking, aspiration and dining events - Infection clusters and outbreak signals - Changes in condition and hospital transfers - Staff injuries, including resident-handling injuries - Care plan interventions awaiting a check ## Regulators and standards - **Nursing services, 42 CFR 483.35(b):** An RN must work 8 consecutive hours a day, 7 days a week. A full-time RN serves as director of nursing unless waived. - **Abuse, neglect and exploitation, 42 CFR 483.12 (F600, F609, F610):** Report allegations at once, within 2 hours if abuse or serious bodily injury is involved, otherwise 24. Investigate, prevent more harm and report results within 5 working days. - **Accidents, F689 (42 CFR 483.25(d)):** Keep the environment as free of accident hazards as possible, with adequate supervision and assistive devices. Surveyors check hazard identification, evaluation, interventions and monitoring. - **Quality of care and medication errors, F684 and F760:** F684 covers quality of care under 42 CFR 483.25. F760 requires that residents are free of significant medication errors, 42 CFR 483.45(f)(2). - **Infection control, F880 (42 CFR 483.80):** Keep an infection prevention and control program. The infection preventionist sits on the QAA committee, so outbreaks reach the same table as falls and errors. - **QAPI, 42 CFR 483.75 (F865, F867, F868):** You are a required QAA committee member. The committee meets at least quarterly, reviews data and acts on it. ## How it works 1. **The nurse describes what happened** A nurse or aide texts the event, scans a QR code at the station or emails it in. For a fall, Lauren asks when the resident was last seen, rounding, call light, footwear, bed height and alarms, recent medication changes and any injury. Voice reporting is rolling out. 2. **Allegations route to the administrator at once** Abuse, neglect and injury-of-unknown-source reports route to the administrator and to you immediately, with the 2-hour, 24-hour and 5-working-day windows noted on the record. 3. **You investigate and set interventions** Contributing factors, five whys and a disposition, then actions with an owner, a due date, evidence and an effectiveness check. Nothing closes until verified. You review, edit and sign. 4. **The QAA packet builds from the record** Falls by shift, location and cause, medication events and open actions flow into the QAA summary, and you present from the data. ## Scenario: An unwitnessed fall at 03:00 A resident is found on the floor during night rounds, and the case runs from the first text to the quarterly QAA meeting. - **03:05, Nurse texts Lauren after the fall.** An aide finds the resident on the floor. The nurse assesses the resident and texts Lauren from the hallway. - **03:08, Lauren drafts the fall report.** Lauren asks when the resident was last seen, and about the call light, footwear, bed height and alarm. The draft is marked 'Lauren · draft'. - **03:30, Form raises the allegation question.** The resident has a skin tear and hip pain. The form asks the reviewer if this unwitnessed fall with injury raises an allegation under 42 CFR 483.12(c). - **06:45, Director of nursing classifies the fall.** The director of nursing reads the complete 24-hour report. She classifies it as a fall with injury, not an allegation, and records her reason. - **09:00, Morning meeting turns interventions into actions.** The team adds a lower bed, a toileting schedule and a pharmacist medication review. Each becomes an action with an owner and a due date. - **Day 3, Care plan updated and evidence attached.** The care plan is updated and evidence is attached to each action. - **Day 30, Effectiveness check shows no repeat fall.** The director of nursing verifies the check and the actions close. A second fall would have kept them open. - **Quarterly QAA meeting, QAA meeting reviews the falls pattern.** Falls by shift, location and cause appear in the packet. The director of nursing presents the pattern, the interventions and proof that they held. ## What is in the pack **Forms:** Fall report: witnessed or not, injury, interventions; Resident incident report: altercation, elopement, choking, skin; Abuse and neglect form with reporting windows and 5-working-day result; Medication error report; Corrective action plan: owner, due date, evidence, check **Routing:** Allegations to the administrator and you at once; Falls with injury and medication errors to you and unit managers; Infection signals to the infection preventionist; Overdue actions to the owner, then you **Exports:** Incident summary for the 24-hour report; QAPI summary for the QAA committee; Survey packet; Falls and medication trends by shift, location, cause **Roles:** Director of nursing: reviews, investigates, signs; Unit managers and charge nurses: first-line review; Aides and nurses: report by text, QR, email or web; Administrator: receives allegations, signs state reports ## Outcomes - **Reports that arrive complete:** Lauren asks follow-up questions at the bedside. The 24-hour report starts with times, rounding and care plan facts. - **Short clocks in front of the right people:** Allegations reach the administrator and you as they are reported, with the windows noted. No one has to remember the clock. - **Interventions that prove themselves:** An intervention closes after its evidence and check are verified. That mirrors F689's focus on monitoring. See [fall reporting](https://incidentkit.ai/use-cases/fall-reporting). - **A QAA packet you present, not assemble:** Trends by shift, location and cause come from the record, so the meeting starts with analysis. See [QAPI committee meetings](https://incidentkit.ai/use-cases/qapi-committee-meetings). ## Frequently asked questions ### What are the deadlines for reporting an abuse allegation? Report immediately, and within 2 hours if the allegation involves abuse or results in serious bodily injury; otherwise within 24 hours (42 CFR 483.12(c)). This covers alleged abuse, neglect, exploitation or mistreatment, including injuries of unknown source. Send results to the administrator and State Survey Agency within 5 working days. See [abuse reporting deadlines](https://incidentkit.ai/use-cases/abuse-reporting-deadlines). ### What does F689 expect after a fall? It expects an environment as free of accident hazards as possible, with adequate supervision and assistive devices. Surveyor guidance lists four steps: identify hazards, evaluate them, set interventions, then monitor effectiveness and change what is not working. See [F689](https://incidentkit.ai/compliance/f-tags/f689). ### Does Lauren decide whether something is abuse? No. Lauren asks questions and drafts the form. A person always reviews, edits and signs, and the facility decides how to classify and report an event. Every drafted field is marked 'Lauren · draft' until approved. ### Can aides and nurses use it without training on a new form? Yes. They describe what happened in their own words by text, scan a QR code or email it in, and Lauren asks the follow-up questions. There is no multi-page form to learn. See [Lauren](https://incidentkit.ai/product/lauren). ### Does IncidentKit replace our electronic health record? No. It runs alongside your EHR, and deeper EHR integrations are rolling out. The incident record, investigation and actions live in IncidentKit. The care plan stays where you keep it. ## Sources - [42 CFR 483.35, Nursing services (eCFR)](https://www.ecfr.gov/current/title-42/part-483/section-483.35) - [42 CFR 483.12, Freedom from abuse, neglect and exploitation (eCFR)](https://www.ecfr.gov/current/title-42/part-483/section-483.12) - [42 CFR 483.75, Quality assurance and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/part-483/section-483.75) - [CMS State Operations Manual, Appendix PP (F600, F609, F610, F684, F689, F760, F865, F867, F868, F880)](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) ## Related - [Fall Reporting: What to Record and Review After a Fall](https://incidentkit.ai/use-cases/fall-reporting) - [Medication Error Reporting: Steps, Severity and Follow-Up](https://incidentkit.ai/use-cases/medication-error-reporting) - [Abuse Reporting Deadlines for Nursing Homes: 2 and 24 Hours](https://incidentkit.ai/use-cases/abuse-reporting-deadlines) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) - [Fall Incident Report Template for Healthcare (Printable)](https://incidentkit.ai/templates/fall-incident-report) - [Nursing Home Incident Report Template (Printable)](https://incidentkit.ai/templates/nursing-home-incident-report) - [F689 accidents and supervision: falls, hazards, devices](https://incidentkit.ai/compliance/f-tags/f689) - [F600 free from abuse and neglect: what surveyors cite](https://incidentkit.ai/compliance/f-tags/f600) - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) - [F610 investigate, prevent and correct alleged violations](https://incidentkit.ai/compliance/f-tags/f610) - [F684 quality of care: what it covers and how it is cited](https://incidentkit.ai/compliance/f-tags/f684) - [F760 significant medication errors: how surveyors cite it](https://incidentkit.ai/compliance/f-tags/f760) - [F880 infection prevention and control: survey guide](https://incidentkit.ai/compliance/f-tags/f880) - [Nursing home abuse reporting: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting) --- # One record you can stand behind when the surveyor asks > Every report, deadline and action in one place, with numbers for your board. Source: https://incidentkit.ai/solutions/facility-administrators · Updated Oct 5, 2026 **Who:** Staff report and department heads investigate. You sign state reports, answer to the governing body and own survey readiness. ## The problems - **You find out last:** Nursing home allegations must reach you at once, and within 2 hours for abuse or serious bodily injury. A phone tree cannot promise that. - **Survey readiness is a scramble:** A nursing home must show its QAPI plan and proof it works at each annual recertification survey. Binders mean a scramble when the team arrives. - **The plan of correction deadline is short:** CMS says a plan of correction is due 10 calendar days after the CMS-2567. It covers affected residents, others at risk, system changes and monitoring. - **The governing body asks for numbers:** The governing body answers for QAPI (42 CFR 483.70(d) in nursing homes, 42 CFR 416.41 in surgery centers). It wants trends and proof fixes worked. ## Incident types in the pack - Abuse, neglect and exploitation allegations, reportable in 2 or 24 hours - Falls with injury and injuries of unknown source - Resident and patient complaints and grievances - Events that need a call to the family or responsible party - State filings for reportable events - Medication errors - Staff injuries and workers' compensation claims - Infection outbreaks and public health notices - Survey findings, CMS-2567s and plans of correction in progress - Quarterly QAA committee agendas and minutes - Carrier notices and renewal questions on incident history - Overdue corrective actions, by department and owner ## Regulators and standards - **Administration, 42 CFR 483.70(d):** The governing body appoints the administrator. The administrator manages the facility and answers to it. The governing body answers for the QAPI program. - **Abuse and neglect reporting, 42 CFR 483.12(c):** Report alleged violations at once to the administrator and State Survey Agency. Allow 2 hours for abuse or serious bodily injury, otherwise 24. Results are due in 5 working days. - **QAPI, 42 CFR 483.75 (F865, F868):** Present the QAPI plan at each annual recertification survey. Show the program is running. The QAA committee includes the administrator, owner, a board member or another leader. - **Plans of correction, 42 CFR 488.402(d):** Deficiencies need a plan of correction, except isolated ones with potential for minimal harm and no actual harm. CMS says it is due within 10 calendar days of the CMS-2567. - **Surgery centers, 42 CFR 416.41 and 416.43:** The governing body has full legal responsibility for the ASC's policies and for its QAPI program. That program must track adverse patient events and document improvement projects. - **State licensing and reportable events:** States add their own reportable-event rules and timelines. Check yours. See [state reporting overview](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview). ## How it works 1. **You hear first, by rule** Allegations and serious events route to you the moment they are reported, with the 2-hour, 24-hour and 5-working-day windows noted on the record. Lauren drafts the report as the nurse describes what happened. 2. **You see every open clock and action** One view shows open incidents, reporting windows, overdue actions by department and owner, and plans of correction in progress. 3. **You sign what is complete** You review the draft, edit it and sign. Fields Lauren drafted stay marked 'Lauren · draft' until a person approves them, and every change goes into the audit trail with who, when and what. 4. **You are ready before the survey** QAPI summaries and survey packets build from the record. When a CMS-2567 arrives, the investigation, the evidence and the effectiveness checks are already in one place. ## Scenario: A survey exit and the 10-day plan of correction A nursing home survey cites one falls deficiency, and the administrator has 10 calendar days from receiving the CMS-2567 to return a plan. - **Survey day 4, 15:00, Exit conference cites F689 deficiency.** The administrator opens the records for the residents named in the deficiency tied to F689. - **Survey day 4, 16:00, Resident records show the full trail.** Each record shows the incident, investigation, interventions, and the evidence and checks for each action. - **Day 5, Deadline set, plan sections assigned.** The CMS-2567 arrives. The administrator sets the 10-calendar-day deadline. Plan sections go to the director of nursing and unit managers. - **Day 6, Plan of correction takes shape.** The plan covers affected residents and how others at risk are found. It states what systems change and how the facility will monitor. - **Day 8, Corrective actions created, audit scheduled.** New corrective actions get owners, dates and evidence requirements. A monitoring audit is scheduled. Results go to the QAA committee. - **Day 9, Signed plan carries an evidence index.** The administrator reviews the draft plan, edits it and signs. The evidence index attaches to the signed plan. - **Day 40, Effectiveness checks reach the QAA agenda.** The effectiveness checks come due, and the administrator reports results to the governing body. ## What is in the pack **Forms:** Incident report for your setting: nursing home, surgery center and others; Abuse and neglect form with reporting windows and 5-working-day result; Complaint and grievance record; Corrective action plan: owner, due date, evidence, check **Routing:** Allegations and serious events go to you at once; Department-head routing by event type; Alerts to the corporate office by severity; Overdue actions remind the owner, then you **Exports:** QAPI summary for the QAA committee and governing body; Survey packet; Plan of correction evidence index; Timestamped reportable-event record for your state filing **Roles:** Administrator: receives, reviews and signs; Director of nursing and department heads: investigate, own actions; Corporate office: reads across facilities; Reporters: any staff member, by text, QR, email or web ## Outcomes - **Hear first:** Routing rules put allegations and serious events in front of you as they are reported, not after the phone tree. - **Survey evidence in one place:** Incidents, investigations, actions and checks sit together, so QAPI evidence is a view, not a binder. See [always survey-ready](https://incidentkit.ai/use-cases/always-survey-ready). - **A plan of correction built on fact:** When a CMS-2567 arrives, the record shows what was done, by whom and whether it was checked. A credible plan needs that. - **Numbers for the governing body:** Trends by shift, location and cause, plus open and verified actions, go to the governing body as a signed summary. ## Frequently asked questions ### Who has to be told within two hours of an abuse allegation? The administrator and other officials, including the State Survey Agency, must be told immediately. Allow 2 hours if abuse is involved or serious bodily injury results (42 CFR 483.12(c)(1)), otherwise 24 hours. This covers alleged abuse, neglect, exploitation or mistreatment, including injuries of unknown source. See [abuse reporting deadlines](https://incidentkit.ai/use-cases/abuse-reporting-deadlines). ### What does a surveyor ask to see for QAPI? Your QAPI plan at each annual recertification survey. On request, also proof that the program is running. That includes systems to find, report, investigate and prevent adverse events, plus corrective actions you evaluated. See the [QAPI requirements for nursing homes](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities). ### How long do we have to submit a plan of correction? Within 10 calendar days of the date you receive the statement of deficiencies, form CMS-2567, CMS says. See [plan of correction](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction). ### Does IncidentKit file state reports for me? No. IncidentKit holds the record and shows the reporting windows. State filing channels differ. The final submission is the administrator's job. Check your state's rules. ### What if I run a surgery center, assisted living community, hospice or home-health agency? Each setting has its own pack, forms and regulations. See [surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers) and [assisted living](https://incidentkit.ai/solutions/assisted-living). State licensing rules apply on top of federal ones, so check yours. ## Sources - [42 CFR 483.70, Administration (eCFR)](https://www.ecfr.gov/current/title-42/part-483/section-483.70) - [42 CFR 483.12, Freedom from abuse, neglect and exploitation (eCFR)](https://www.ecfr.gov/current/title-42/part-483/section-483.12) - [42 CFR 483.75, Quality assurance and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/part-483/section-483.75) - [42 CFR 488.402, Remedies, plan of correction requirement (eCFR)](https://www.ecfr.gov/current/title-42/part-488/section-488.402) - [CMS, Nursing home enforcement FAQ (plan of correction timing)](https://www.cms.gov/medicare/provider-enrollment-and-certification/surveycertificationenforcement/downloads/nh-enforcement-faq.pdf) - [CMS, Form CMS-2567 Statement of Deficiencies and Plan of Correction](https://www.cms.gov/medicare/cms-forms/cms-forms/downloads/cms2567.pdf) - [42 CFR 416.41, ASC governing body and management (eCFR)](https://www.ecfr.gov/current/title-42/part-416/section-416.41) - [42 CFR 416.43, ASC QAPI (eCFR)](https://www.ecfr.gov/current/title-42/part-416/section-416.43) - [CMS State Operations Manual, Appendix PP (F689, F865, F868)](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) ## Related - [Always Survey-Ready: Stay Prepared for Unannounced Surveys](https://incidentkit.ai/use-cases/always-survey-ready) - [Abuse Reporting Deadlines for Nursing Homes: 2 and 24 Hours](https://incidentkit.ai/use-cases/abuse-reporting-deadlines) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [Incident routing and escalation by severity](https://incidentkit.ai/product/routing-and-escalation) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) - [Incident reporting software for surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers) - [Incident reporting software for assisted living](https://incidentkit.ai/solutions/assisted-living) - [Incident reporting software pricing: free to start](https://incidentkit.ai/pricing) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) - [Nursing home recertification survey: process and prep](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [F865 QAPI program and plan: what surveyors ask for](https://incidentkit.ai/compliance/f-tags/f865) - [F868 QAA committee: members, meetings and evidence](https://incidentkit.ai/compliance/f-tags/f868) --- # Know about the near miss before it becomes the injury > Near misses, injuries and fixes in one record, tied to work orders. Source: https://incidentkit.ai/solutions/plant-managers · Updated Oct 5, 2026 **Who:** Operators and supervisors report; the EHS lead investigates. You own the site's results and often certify the OSHA 300A. ## The problems - **A report competes with the schedule:** A report that takes a supervisor off the floor loses to the production plan. So near misses stay unreported until one becomes an injury. - **Four owners, four records:** Safety has the injury, maintenance the work order, quality the nonconformance and HR the claim. Each tells a different story. - **Fixes wait for downtime:** The right fix needs the line down, and downtime needs approval. Weeks pass. Nobody checks if the fix worked. - **You sign for the plant:** You may be the top official on site, who can certify the 300A. Where process safety management applies, an investigation must start within 48 hours. ## Incident types in the pack - Near misses: pinch points, forklift and pedestrian conflicts, dropped loads - Injuries that need a recordable decision - Lockout/tagout events and bypassed interlocks - Machine guarding incidents and unexpected startups - Chemical releases and near-miss releases - Fires and smoke events - Contractor injuries on site - Forklift and powered industrial truck incidents - Equipment failures that stopped the line - Slips, trips and falls - Workplace violence and threats - Corrective actions waiting on downtime or a work order ## Regulators and standards - **OSHA recordkeeping, 29 CFR 1904:** Keep a separate 300 Log for each establishment and enter recordable cases within seven calendar days. A company executive certifies the 300A. Post it February 1 through April 30. - **Severe injury reporting, 29 CFR 1904.39:** Report a fatality within 8 hours and an inpatient hospitalization, amputation or loss of an eye within 24 hours. - **Lockout/tagout, 29 CFR 1910.147:** Inspect each energy control procedure at least annually to make sure the procedure and the standard are being followed. - **Process safety management, 29 CFR 1910.119(m):** Where covered, investigate any incident that did or could have caused a catastrophic release of a highly hazardous chemical. Start within 48 hours, document findings and keep reports five years. - **NIOSH hierarchy of controls:** Elimination, substitution, engineering controls, administrative controls, then personal protective equipment, from most to least effective. - **BLS incidence rates:** Rate equals cases times 200,000 divided by employee hours worked. The DART rate counts days away, restricted or transferred cases. ## How it works 1. **Operators report from the floor** Scan a QR code on the machine or text Lauren from a phone, including where signal is poor. See [mobile and offline](https://incidentkit.ai/product/mobile-and-offline). Voice reporting is rolling out. 2. **Lauren asks what the investigator would ask** Equipment, task, lockout step, guard status, shift and who restarted. The supervisor reviews, edits and signs, and drafted fields stay marked 'Lauren · draft' until approved. 3. **Investigations start inside the clock** Routing alerts you and the EHS lead by severity and equipment. An investigation records the team, the date it began, the description, contributing factors and recommendations, which are the elements a PSM report requires. 4. **Actions carry a work order and a check** Each action has an owner, a due date, evidence and an effectiveness check. Record your CMMS work order number on the action. Deeper CMMS integration is rolling out. ## Scenario: A conveyor near miss on third shift The line restarts while an operator clears a jam, nobody is hurt, and the report still matters. - **02:10, Supervisor scans QR and texts Lauren.** The operator's hand is clear when the conveyor restarts. The supervisor scans the QR code on the conveyor and texts Lauren. - **02:12, Lauren asks about the lockout step.** Lauren asks for the equipment ID, task, lockout step, who restarted the line and whether a guard was in place. The draft is marked 'Lauren · draft'. - **02:30, Signed report routes to EHS lead.** The supervisor edits and signs. Routing sends it to the EHS lead and plant manager because it is a near miss involving energy control. - **07:00, EHS lead starts the investigation.** At shift handoff the plant manager opens the report. The EHS lead starts an investigation with the team lead and a maintenance technician. - **Day 2, Investigation finds no lockout point.** The cluster view shows a similar near miss on the sister line five weeks earlier. The jam-clearing procedure had no lockout point on this line. - **Day 5, Engineering and procedure actions created.** An engineering action adds a lockout point and interlocked door on both lines. An administrative action revises the procedure. Maintenance adds the work order number to each action. - **Day 40, Effectiveness check closes both actions.** The check finds no jam-clearing events with energy exposure on either line. The EHS lead verifies the evidence and the actions close. - **Annual lockout/tagout inspection, Annual inspection uses the record.** The periodic inspection under 29 CFR 1910.147(c)(6) uses the record: the near miss, the finding, the fix and the check. ## What is in the pack **Forms:** Near miss and hazard report, with QR quick report on equipment; Injury and illness report with recordability questions; Equipment and process incident report; Contractor incident form; Corrective action plan with work order and effectiveness check **Routing:** Alerts to EHS and plant manager by severity and equipment; Instant alert for hospitalization, amputation, eye loss or fatality; Maintenance notice when an action needs a work order; Overdue-action reminders to the owner, then the plant manager **Exports:** OSHA 300, 300A and 301 (rolling out); Analytics by equipment, shift, location and cause; Investigation report: team, contributing factors, recommendations; Read API and signed webhooks **Roles:** Plant manager: reads across the site, certifies the record; EHS lead: classifies, investigates and signs; Supervisors: first-line review; Maintenance, quality and operations: close actions with evidence ## Outcomes - **Near misses that get reported:** A text or QR code takes less time than a form, so reports compete less with the schedule. See [near-miss reporting](https://incidentkit.ai/use-cases/near-miss-reporting). - **One record, not four:** The report, investigation, actions and work order reference sit together, so the shift meeting starts with the same facts. - **Fixes that prove themselves:** An action closes only after evidence and an effectiveness check are verified, so a failed fix stays open. See [close corrective actions](https://incidentkit.ai/use-cases/close-corrective-actions). - **Patterns across lines and sites:** Clusters by equipment, shift, location and cause show where the same event happens twice, even across plants. ## Frequently asked questions ### Is the plant pack available today? Industry packs beyond healthcare are rolling out, and healthcare packs are available now. OSHA 300, 300A and 301 exports are also rolling out. [Contact us](https://incidentkit.ai/contact) to see what is ready for your site. ### Does IncidentKit replace our CMMS? No. It runs alongside your CMMS, EHR and HRIS. You can record a work order number on an action today. Deeper CMMS integrations are rolling out; the platform offers signed webhooks and a read API. ### Does it support PSM incident investigations? Yes. It gives an investigation the structure PSM asks for: a team, description, contributing factors, recommendations, documented resolutions and an audit trail. Whether process safety management covers your process depends on the chemicals and quantities, so check 29 CFR 1910.119. See [process safety incident investigation](https://incidentkit.ai/compliance/osha/process-safety-incident-investigation). ### Who certifies the OSHA 300A at a plant? A company executive: an officer of the corporation, the highest-ranking company official at the establishment, or that official's immediate supervisor. At many plants that is the plant manager. Post the summary from February 1 through April 30. See [OSHA 300A](https://incidentkit.ai/compliance/osha/osha-300a-summary). ### How do contractor injuries work? Whoever supervises the worker day to day records the injury: the contractor if it does, you if you do (29 CFR 1904.31). The same test applies to temporary and leased workers. Contractor and visitor incidents have their own form and routing. See [contractor and visitor incidents](https://incidentkit.ai/use-cases/contractor-and-visitor-incidents). ## Sources - [29 CFR 1910.119(m), Incident investigation (eCFR)](https://www.ecfr.gov/current/title-29/part-1910/section-1910.119) - [29 CFR 1910.147(c)(6), Periodic inspection (eCFR)](https://www.ecfr.gov/current/title-29/part-1910/section-1910.147) - [29 CFR 1904.30, Multiple business establishments (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.30) - [29 CFR 1904.31, Covered employees (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.31) - [29 CFR 1904.32, Annual summary (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.32) - [29 CFR 1904.39, Reporting fatalities, hospitalizations, amputations and loss of an eye (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.39) - [BLS, How to compute your firm's incidence rate](https://www.bls.gov/iif/overview/compute-nonfatal-incidence-rates.htm) - [CDC NIOSH, Hierarchy of controls](https://www.cdc.gov/niosh/hierarchy-of-controls/about/index.html) ## Related - [Manufacturing incident reporting and OSHA 300 software](https://incidentkit.ai/solutions/manufacturing) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Contractor and Visitor Incidents: Who Reports What](https://incidentkit.ai/use-cases/contractor-and-visitor-incidents) - [Mobile incident reporting that works offline](https://incidentkit.ai/product/mobile-and-offline) - [Incident reporting API, webhooks and integrations](https://incidentkit.ai/product/integrations-and-api) - [Hierarchy of controls: definition and meaning](https://incidentkit.ai/glossary/hierarchy-of-controls) - [Lockout/tagout 29 CFR 1910.147: program and event data](https://incidentkit.ai/compliance/osha/lockout-tagout) - [PSM incident investigation: 29 CFR 1910.119(m) explained](https://incidentkit.ai/compliance/osha/process-safety-incident-investigation) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [OSHA 300A summary: who signs, when to post, how long](https://incidentkit.ai/compliance/osha/osha-300a-summary) - [TRIR and DART rates: formula, example and BLS 2024 rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates) --- # How to replace paper incident forms > Replace paper with a short form that opens where the event happened and goes straight to an owner. Run it beside paper on one unit for about 30 days, check counts weekly, then cut over. Keep a one-page downtime form for outages. Source: https://incidentkit.ai/use-cases/replace-paper-incident-forms · Updated Oct 5, 2026 For: Administrator or director of nursing still using paper forms ## What should replace a paper incident form? A short form that opens where the event happened and routes itself to an owner. A scanned PDF in a shared inbox is still paper. Build from what reviewers use, not from the old form. Cut any field no one has used in a review. A first report should take about a minute. Reviewers can add detail later. *Minimum fields for a replacement form* | Field | Why you need it | | --- | --- | | What happened, in the reporter's words | First accounts are the most accurate. | | Date, time and exact location | Shows patterns by shift and place. | | Who was involved: resident, patient, employee, visitor, contractor | Decides which rules apply. | | Harm or injury, and care given | Sets severity. | | Who was notified, and when | Proves notices were on time. | | Witnesses and equipment involved | Starts the investigation. | | Reporter and time of report | Shows how fast events arrive. | The [ASC incident report](https://incidentkit.ai/templates/asc-incident-report) and [nursing home incident report](https://incidentkit.ai/templates/nursing-home-incident-report) templates show these fields filled in. ## What paper does well, and what to keep Paper works in an outage. Keep a one-page downtime form at each station and in the medication room. Enter those reports in the same shift once systems return. Never run paper as a second live system. Two systems mean two counts. ## Where paper fails in practice Paper fails at three jobs: capturing every event, tracking events over time and producing a list on demand. | Paper reality | What the rules expect | What to require of the replacement | | --- | --- | --- | | Reports filed late | Nursing homes report alleged abuse within 2 or 24 hours (42 CFR 483.12(c)(1)). | A timestamp and instant routing. | | No running totals | ASCs must track adverse patient events (42 CFR 416.43(c)(2)). Nursing homes must identify, report, track, investigate and analyze events (42 CFR 483.75(c)(4)). | Counts by type, location, shift. | | Hunting for folders | Surveyors ask ASCs for surgeries from the past 6 months, and transfers or deaths from the past year. CMS says produce them in 1 to 2 hours. | A dated list in minutes. | | Handwritten OSHA entries | Log cases on the OSHA 300 log and 301 within 7 calendar days. Computer records work if they can produce equivalent forms (29 CFR 1904.29). | Fields that match OSHA forms. | ## How to switch in five steps Pilot beside paper on one unit, then cut over. 1. **List every form in use** Collect each version, even from desk drawers. 2. **Set the fields and incident types** Start with the minimum fields. Add only what a regulator or insurer requires. 3. **Name an owner for each queue** Use a role and a backup. No owner means digital looks like paper. 4. **Pilot on one unit for about 30 days** Run both and check counts weekly. A paper form with no digital twin is a gap. Fix the form if digital stays lower for two weeks. 5. **Cut over and keep the downtime form** Announce a date and stop issuing paper. Import old paper so trends run past cutover. ## Mistakes to avoid Five habits cause most failed switches. - Copying a four-page form onto a screen. Length stops reports, not format. - Making reporters pick a category first. Let them describe, then classify. - Switching on a Friday with nobody watching the queue. - Ranking people by reports filed. It teaches them to stop. - Throwing out paper history. Keep the 300 log, annual summary and 301 reports five years after the year they cover (29 CFR 1904.33). ## How IncidentKit changes the job Staff report by text, [QR code](https://incidentkit.ai/product/quick-report), email or web form. [Lauren](https://incidentkit.ai/product/lauren) asks the follow-ups and fills the form, marked Lauren · draft. A person reviews, edits and signs. [Routing and escalation](https://incidentkit.ai/product/routing-and-escalation) sends each report to its owner at once. The [audit trail](https://incidentkit.ai/product/audit-trail) records every change. [Import](https://incidentkit.ai/product/import-and-migration) keeps old history, so counts do not restart. The same flow covers plant and job-site injuries and near misses. Industrial packs are rolling out. Non-patient reporting is free on the Open plan. Healthcare sites with patient information use the Regulated plan, which includes a BAA. ## Before and after - **Before:** Forms get filled out after the shift, from memory. **After:** Report by text or QR code where it happened. Lauren asks the follow-ups. - **Before:** Pages sit in a binder until someone retypes them. **After:** Each report reaches its owner at once, with a timestamp. - **Before:** Last quarter's falls need a hand count. **After:** Counts by type, location and shift come from the data. - **Before:** A surveyor's list of cases means a morning of pulling folders. **After:** A dated list of cases is one export away. ## Frequently asked questions ### Is a digital incident report as valid as a paper one? Yes. Regulators ask for the records, not a medium. OSHA allows computer-kept injury records that can produce equivalent forms (29 CFR 1904.29). Check your accreditor and state for stricter rules. ### How long should paper and digital run side by side? About 30 days on one unit. Treat each paper form with no digital twin as a defect, and stop paper once counts match for two weeks. Run longer on a quiet unit. ### What happens during a power or network outage? Use the one-page downtime form at each station, then enter those reports in the same shift. IncidentKit also works in [mobile and offline](https://incidentkit.ai/product/mobile-and-offline) mode, but paper never needs a battery. Test downtime yearly. ### Can staff still report on paper if they prefer it? During the pilot and on downtime, yes. After cutover, someone enters each paper form and attaches the original. If staff keep choosing paper, the digital form is too long or too slow. ## Sources - [OSHA: 29 CFR 1904.29, forms](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.29) - [OSHA: 29 CFR 1904.33, retention and updating](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.33) - [eCFR: 42 CFR 416.43, ASC quality assessment and performance improvement](https://www.ecfr.gov/current/title-42/section-416.43) - [CMS: State Operations Manual Appendix L, guidance for surveyors of ASCs](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_l_ambulatory.pdf) - [CMS: State Operations Manual Appendix PP, long term care facilities (F867)](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) ## Related - [ASC Incident Report Template for Surgery Centers](https://incidentkit.ai/templates/asc-incident-report) - [Nursing Home Incident Report Template (Printable)](https://incidentkit.ai/templates/nursing-home-incident-report) - [Incident reporting software: forms, drafts, workflow](https://incidentkit.ai/product/incident-reporting) - [Migrate incident data from paper, Excel or legacy software](https://incidentkit.ai/product/import-and-migration) - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) - [Switch From Legacy Incident Software: Migration Steps](https://incidentkit.ai/use-cases/switch-from-legacy-incident-software) --- # How to build a near-miss reporting program > Near-miss reporting works when reports are short, nobody is blamed and the reporter hears what changed. Define a near miss, triage by how bad it could have been, investigate the high-potential ones and share the fixes. Source: https://incidentkit.ai/use-cases/near-miss-reporting · Updated Oct 5, 2026 For: Quality lead, safety officer or EHS manager who wants close calls reported ## What counts as a near miss? A near miss is also called a close call. At a plant, think of a load that lands where nobody stands. AHRQ's patient safety network defines a near miss as an event that "did not produce patient injury, but only because of chance." Count hazards too, such as a frayed cord or wet floor reported before anyone slips. OSHA's safety management guidance says to investigate near misses, not only injuries. - **Include:** errors caught in time, unsafe conditions and equipment failures that hurt no one. - **Leave out:** events that caused harm. They get full review, through the same door. > **What CMS says to surveyors** CMS's ASC survey guidance expects ASCs to identify errors that result in near misses, because they can lead to future adverse events. ## Why people do not report close calls Mostly because nothing visible happens after they report. - **Time.** A long form loses to a full shift. - **Blame.** CMS's nursing home guidance says a safety culture does not blame staff for reporting risks and hazards. - **Silence.** No one hears the result. - **Rewards.** Bonuses for injury-free months can make people hesitate. OSHA says rewarding reports of hazards or near misses is always permissible. ## How to build the program in six steps Six steps cover it. 1. **Define it in one sentence** Give three examples from your own site. 2. **Make the first report short** What happened, where, what stopped it, how bad it could have been. 3. **Accept every channel** Text, a QR code on the unit, email and a web form. 4. **Triage by potential, not outcome** Use three levels (see below). Look within one business day. 5. **Investigate the high-potential ones** Use the same method as for harm events ([root cause analysis](https://incidentkit.ai/use-cases/root-cause-analysis)). Review the rest monthly. 6. **Tell the reporter what changed** Two lines: what was found, what will change, by when. A good reply: "Thanks for reporting the mixed-up chart. From Monday the scheduler separates same-procedure cases. Owner: surgical services manager." It takes a minute. ## How to triage close calls Triage by what could have happened, not by what did. | Level | Meaning | Response | | --- | --- | --- | | High potential | Could have caused death or permanent harm | Same-day look, then a root cause review | | Moderate | Could have caused an injury needing treatment | Review within a week, with similar reports | | Minor | Unlikely to cause harm | Count it. Review monthly | Each month, group reports by location, shift, equipment and cause. A close call that repeats is a pattern, so investigate it as if harm occurred. Many harm events but few close calls signals under-reporting. ## Examples by setting The close calls differ, but the questions are the same. | Setting | Close call | What to look for | Stronger fix | | --- | --- | --- | --- | | Surgery center | Two patients' records mixed up, caught at the time-out | Back-to-back scheduling, similar names | Schedule look-alike cases apart | | Nursing home | Wrong resident's medication pulled, caught before given | Look-alike names, shared carts | A cart scan that blocks a mismatch | | Plant or warehouse | Forklift passes close to a pedestrian at an aisle crossing | Blind corner, shared aisle, shift change | Separate walkways or reroute traffic | Training and new policies are weak actions in the patient safety action hierarchy. Pair them with a design or process change. ## Mistakes to avoid These habits quietly kill a program. - Investigating every report in full. It buries the team. - Making names mandatory without saying who sees them. - Scoring units by report counts. A rising count usually means rising trust. - Answering with a reminder email. Education alone is weak. - Closing the report when the fix is made, not when it is shown to work. ## How IncidentKit changes the job A [QR quick report](https://incidentkit.ai/product/quick-report) on the unit opens a short report. [Lauren](https://incidentkit.ai/product/lauren) asks what stopped the event and how bad it could have been. The form it fills is marked Lauren · draft until a person approves it. [Routing](https://incidentkit.ai/product/routing-and-escalation) sends high-potential reports to the right owner. [Analytics](https://incidentkit.ai/product/analytics) group close calls by location, shift, equipment and cause. [Corrective actions](https://incidentkit.ai/product/corrective-actions) carry an owner, due date and evidence, and nothing closes until a person verifies it. ## Before and after - **Before:** Staff report only injuries. Close calls die at the huddle. **After:** A close call is a short text or QR scan. - **Before:** The form is so long people save it for harm events. **After:** Lauren asks the follow-ups. No long form. - **Before:** Reporters never hear back, so they stop filing. **After:** Each report has an owner, so replying to the reporter is a task. - **Before:** Near misses sit in a spreadsheet nobody sorts. **After:** Clusters by location, shift, equipment and cause show repeats. ## Frequently asked questions ### What is the difference between a near miss and an incident? A near miss could have caused harm but did not, only by chance. An incident is the wider record: near misses, harm events and unsafe conditions. Keep them in one system. ### Do regulators require near-miss reporting? It depends on the setting. CMS's ASC survey guidance expects ASCs to identify errors that result in near misses, and OSHA's guidance says to investigate them. Accreditors and states may add more. ### Can we reward staff for reporting near misses? Yes. OSHA's 2018 memo treats rewards for reporting hazards or near misses as always permissible. Rewards tied to zero injuries can discourage injury reports, so add safeguards. ### How many near misses should we expect? There is no right number. Few reports usually mean a quieter site, not a safer one, a point OSHA's retail violence guidance also makes. Track reports per unit and ask why quiet units are quiet. ## Sources - [AHRQ PSNet: Adverse events, near misses, and errors](https://psnet.ahrq.gov/primer/adverse-events-near-misses-and-errors) - [OSHA: Recommended practices, hazard identification and incident investigation](https://www.osha.gov/safety-management/hazard-identification) - [OSHA: Safety incentive programs and post-incident drug testing under 1904.35(b)(1)(iv), October 11, 2018](https://www.osha.gov/laws-regs/standardinterpretations/2018-10-11) - [CMS: State Operations Manual Appendix L, guidance for surveyors of ASCs (near-miss example)](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_l_ambulatory.pdf) - [CMS: State Operations Manual Appendix PP, F689 culture of safety](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [AHRQ PSNet: RCA2 and the evolution of root cause analysis](https://psnet.ahrq.gov/perspective/conversation-jessica-behrhorst-about-evolution-root-cause-analysis) - [OSHA 3153: Recommendations for workplace violence prevention programs in late-night retail establishments](https://www.osha.gov/sites/default/files/publications/OSHA3153.pdf) ## Related - [Near-miss reporting and safety culture: a practical guide](https://incidentkit.ai/guides/near-miss-reporting-and-safety-culture) - [How to get staff to report near misses (and keep doing it)](https://incidentkit.ai/blog/how-to-get-staff-to-report-near-misses) - [Near miss: definition and meaning](https://incidentkit.ai/glossary/near-miss) - [Near Miss Report Template (Free, Printable Form)](https://incidentkit.ai/templates/near-miss-report) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) --- # How to stay survey-ready every day > CMS surveys of ASCs and nursing homes are unannounced, so readiness is a weekly habit, not a project. Keep five records current: the incident log, transfers and deaths, QAPI minutes with data, a corrective-action log with verification, and training records. Source: https://incidentkit.ai/use-cases/always-survey-ready · Updated Oct 5, 2026 For: Administrator or quality director at a surgery center or nursing home ## What does it mean to be survey-ready? You can answer a surveyor's first requests within an hour or two, any day. CMS says ASC and nursing home surveys are unannounced. A nursing home standard survey may come within 15 months of the last. | | ASC | Nursing home | | --- | --- | --- | | Survey notice | Unannounced | Unannounced | | QAPI rule | 42 CFR 416.43 | 42 CFR 483.75 | | Where surveyors look | Appendix L, tags Q-0080 to Q-0084 | Appendix PP, tags F865, F867, F868 | Accreditors set their own rules. ## What do surveyors ask for first? Lists of cases, quality data and proof that fixes worked. | Request | Setting | Source | | --- | --- | --- | | Surgeries from the past 6 months | ASC | CMS Appendix L | | Transfers to a hospital or deaths in the past year | ASC | CMS Appendix L | | Infection control and quality self-assessment papers | ASC | CMS Appendix L | | Quality and adverse event data, with causes | ASC | CMS Appendix L, 42 CFR 416.43 procedures | | QAA minutes, data reviewed and action plans | Nursing home | 42 CFR 483.75(g); F867, F868 | | Proof that actions worked and held | Nursing home | 42 CFR 483.75(d)(1) | CMS tells ASC surveyors an ASC should generally supply the first lists within 1 to 2 hours. ASC quality indicators should include hospital transfers, surgery and infection control measures, and a system for tracking adverse patient events. ## Five records to keep current Keep five linked records current and you can answer most first requests. 1. **Incident log with disposition** Every event: date, type, severity, who was told, outcome. 2. **Transfers and deaths list** A filtered view of the log, not a second sheet. 3. **QAPI minutes with data** Data, decisions and owners. 4. **Corrective-action log** Owner, due date, evidence and a dated check. 5. **Training tied to actions** Show who was retrained, when and on what. ASC rules expect all staff to know the preventive strategies (42 CFR 416.43(c)(3)). Keep them as one chain: incident, investigation, action, verification, QAPI minutes. A surveyor should follow one case unaided. ## What to have ready on survey day Surveyors ask for a private workspace and a phone, and expect copies of records promptly. This works for state, validation and complaint surveys. - A point person and a backup. - A runner who pulls records. - A private room with a phone. - A request log: what was asked, when, what was handed over. - Dated lists made fresh from live records. ## A 30-minute weekly routine Thirty minutes a week keeps the five records honest. | Task | Minutes | Result | | --- | --- | --- | | Review new incidents for gaps | 5 | Every case complete | | Check overdue actions, call owners | 10 | No silent overdue items | | Run and check the dated lists | 5 | Lists ready | | Spot-check one closed action | 5 | Proof it held | | Note items for the next QAPI meeting | 5 | An agenda starter | Record who ran the routine each week. A dated sign-off shows the program is ongoing, as ASC and nursing home QAPI rules ask. ## What surveyors cite, and mistakes to avoid CMS examples of F867 citations are record failures. At Level 1, a facility planned monthly monitoring for three months but had no evidence of it in month two. At the most serious level, it collected hot-water temperatures and never analyzed them. A nursing home QAA committee must meet at least quarterly (42 CFR 483.75(g)(2)(i)) and act on its data. Collecting is not enough. - Making readiness one person's job. Name an owner and backup per record. - Building survey binders. They go stale the day they are finished. - Keeping transfers in a spreadsheet nobody updates. - Closing actions at completion, with no check they worked. - Skipping the routine in busy weeks. - Tracking only outcomes. Near misses show problems earlier. ## How IncidentKit changes the job Reports are filed as events happen, so the log stays current. [Compliance packets](https://incidentkit.ai/product/compliance-packets) build QAPI summaries and survey packets from the same records. A person reviews each one. [Corrective actions](https://incidentkit.ai/product/corrective-actions) keep owner, due date, evidence and effectiveness check. The [audit trail](https://incidentkit.ai/product/audit-trail) shows who changed what and when. The [survey readiness check](https://incidentkit.ai/tools/survey-readiness-check) tests your records for free. ## Before and after - **Before:** Prep starts when a stranger with a badge walks in. **After:** The log is current because reports come in live. - **Before:** Log, minutes and actions live in three formats. **After:** QAPI data, minutes and actions share one record. - **Before:** Actions are marked done, never shown to work. **After:** Each action shows owner, due date, evidence, check. - **Before:** A list of transfers or deaths takes half a day. **After:** Lists by date, type and outcome export in minutes. ## Frequently asked questions ### Are all surveys unannounced? Yes. CMS says all ASC and nursing home surveys, including standard, complaint and revisit surveys, are unannounced. Accreditors set their own policy, so check yours. ### How far back should the incident log go? Keep six months of surgeries and a year of transfers and deaths for ASC surveyors. OSHA requires the 300 log, annual summary and 301 reports for five years after the year they cover. Your state or accreditor may require longer. ### Who should own survey readiness? One named leader per site, with a backup, usually the administrator or quality lead. Give each record an owner too. A nursing home QAA committee reviews results at least quarterly. ### What is the difference between readiness and a mock survey? A mock survey tests your answers on one day. Readiness is the weekly routine behind them. Do both, and run the [survey readiness check](https://incidentkit.ai/tools/survey-readiness-check) yearly. ## Sources - [CMS: State Operations Manual Appendix L, guidance for surveyors of ASCs](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_l_ambulatory.pdf) - [CMS: State Operations Manual Chapter 7, survey and enforcement for nursing homes (sections 7205, 7207)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107c07pdf.pdf) - [CMS: State Operations Manual Appendix PP, F867 and F868](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [eCFR: 42 CFR 483.75, nursing home QAPI](https://www.ecfr.gov/current/title-42/section-483.75) - [eCFR: 42 CFR 416.43, ASC QAPI](https://www.ecfr.gov/current/title-42/section-416.43) - [OSHA: 29 CFR 1904.33, retention](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.33) ## Related - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) - [Nursing home recertification survey: process and prep](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) - [Survey readiness self-check for healthcare facilities](https://incidentkit.ai/tools/survey-readiness-check) - [Survey and accreditation readiness: a continuous approach](https://incidentkit.ai/guides/survey-and-accreditation-readiness) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [QAPI, survey and OSHA compliance packets](https://incidentkit.ai/product/compliance-packets) --- # How to run QAPI committee meetings > A nursing home QAA committee meets at least quarterly. It needs the director of nursing, the medical director or designee, the infection preventionist and three other staff including a leader. A good meeting reviews data, tracks actions and checks that fixes worked. Source: https://incidentkit.ai/use-cases/qapi-committee-meetings · Updated Oct 5, 2026 For: Quality director or administrator who runs the QAA or QAPI committee ## Who must be on the committee, and how often? For nursing homes, 42 CFR 483.75(g) sets both. Members: the director of nursing, the medical director or designee, the infection preventionist and at least three other staff. One is a leader: administrator, owner or board member. Meetings: at least quarterly and as needed. It reports to the governing body. Per F868, review data often enough to know if improvement is needed or happening. ASCs differ. 42 CFR 416.43 makes the governing body responsible and sets data collection methods and frequency (416.43(e)), but no committee. Put your cadence in the QAPI plan. Hospitals (42 CFR 482.21) must also track adverse patient events and analyze causes. ## A standing agenda Use the same eight items, in order, every meeting. 1. **Attendance and roles** Record who came, by role. 2. **Last meeting's actions** Mark each done, verified or overdue. Start here. 3. **Incident data** Trends by type, severity, location and shift. 4. **High-severity events** Findings and actions. 5. **Improvement projects** Status of each. Nursing homes must run at least one a year on a high-risk or problem-prone area (42 CFR 483.75(e)(3)). 6. **Survey, complaint and reporting items** Citations, plans of correction, late reports. 7. **New actions** Owner, due date, success measure. 8. **Report to the governing body** Agree what goes up. ## Data to bring Bring trends, not case lists. | Data | Cut by | Why the committee needs it | | --- | --- | --- | | Incidents by type and severity | Month, unit, shift | Nursing homes must prioritize high-risk, high-volume or problem-prone areas (483.75(e)(1)). | | Falls with and without injury | Location, time of day | F689 guidance names both as trends to review. | | Medication errors | Stage, severity, unit | Separates catches from harm. | | Abuse and neglect allegations | On time? Closed in 5 working days? | Timeliness can be audited (483.12(c)). | | Corrective actions | Open, overdue, verified effective | Measure success and sustain improvements (483.75(d)(1)). | | Hospital transfers and deaths (ASC) | Date range | Asked in ASC surveys. | Use rates, such as events per 1,000 resident days or per 100 cases, so units compare fairly. ## Minutes that show action Minutes record the date, attendees by role, data and decisions. Each action has an owner, due date and measure, plus the next review date. For ASCs, CMS wants the QAPI program written down, as in minutes, with proof it is in use. Attach the data page, action list and project charts. | Weak | Strong | | --- | --- | | Falls discussed. | Falls on one unit cluster between 6 and 8 am. Action: toileting rounds at 5:45 am. Owner: unit manager. Check: falls over 8 weeks. | | Medication errors reviewed. | Two wrong-strength catches from one shelf. Action: separate and relabel. Owner: pharmacy lead. Check: audit at 30 days. | ## Prepare the packet and choose projects from data Pull data a week ahead, send a one-page summary two days before, and assign a presenter to each open action. Pick projects from data, not favorites: the highest-rate unit, shift or process. Set a measure, baseline and end date. ASCs must document each project's reasons and results (42 CFR 416.43(d)), and project scope should fit the facility. - **Measure:** what will move, and which way. - **Baseline:** the last three months. - **Owner and end date:** one person, one date. - **Review points:** when to look again. ## Mistakes to avoid These habits turn a committee into a calendar entry. - Reading the incident list aloud. Bring trends. - Counts with no denominator. - Actions with no owner, or a department as owner. - The same data every quarter, with no questions. - Projects chosen from a list, not the data. - Skipping last meeting's actions when rushed. - Letting the same two people do all the talking. ## How IncidentKit changes the job The QAPI summary in a [compliance packet](https://incidentkit.ai/product/compliance-packets) pulls from the incident and action records, so the packet is built, not typed. A person reviews and approves it. [Analytics](https://incidentkit.ai/product/analytics) show clusters by location and cause. [Corrective actions](https://incidentkit.ai/product/corrective-actions) show what is open, overdue or verified. The [audit trail](https://incidentkit.ai/product/audit-trail) shows who changed what. [Roles and multi-site views](https://incidentkit.ai/product/multi-site-and-roles) let each site run its committee on its own data. ## Before and after - **Before:** Meetings satisfy the calendar. Data is pulled last minute. **After:** Trends come from live data by type, severity and location. - **Before:** Minutes say a topic came up, not what was decided. **After:** Minutes list decisions. Every action has an owner and due date. - **Before:** Last meeting's actions go unreviewed. **After:** Overdue actions come first, with proof of what worked. - **Before:** The governing body report is written from memory. **After:** The governing body report uses the same record. ## Frequently asked questions ### How often must a QAPI committee meet? Nursing home QAA committees: at least quarterly and as needed (42 CFR 483.75(g)(2)(i)). The ASC rule, 42 CFR 416.43, sets no meeting count, so set yours in the QAPI plan. ### Who has to attend a nursing home QAA committee? The director of nursing, the medical director or designee, the infection preventionist and at least three other staff (42 CFR 483.75(g)(1)). One is the administrator, owner, board member or another leader. Record attendance by role. ### Do ASCs need a QAPI committee? The federal ASC rule requires an ongoing, data-driven QAPI program run by the governing body, but no committee. Most ASCs use one. Minutes should show the program defined and acted on. ### Are QAA committee records confidential? Mostly. Under 42 CFR 483.75(h), a state or the Secretary may not require disclosure of QAA committee records except as related to the committee's compliance. Good-faith efforts to correct deficiencies are not grounds for sanctions (483.75(i)). Ask counsel about state privilege laws. ## Sources - [eCFR: 42 CFR 483.75, nursing home QAPI](https://www.ecfr.gov/current/title-42/section-483.75) - [CMS: State Operations Manual Appendix PP, F867 and F868](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [eCFR: 42 CFR 416.43, ASC QAPI](https://www.ecfr.gov/current/title-42/section-416.43) - [CMS: State Operations Manual Appendix L, guidance for surveyors of ASCs (Q-0080 to Q-0084)](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_l_ambulatory.pdf) - [eCFR: 42 CFR 482.21, hospital QAPI](https://www.ecfr.gov/current/title-42/section-482.21) ## Related - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [F868 QAA committee: members, meetings and evidence](https://incidentkit.ai/compliance/f-tags/f868) - [F867 QAPI improvement activities: adverse event tracking](https://incidentkit.ai/compliance/f-tags/f867) - [QAPI Meeting Agenda and Minutes Template (Printable)](https://incidentkit.ai/templates/qapi-meeting-agenda-and-minutes) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) --- # How to close corrective actions with proof > A corrective action is closed only when the change is in place and a dated check shows it worked. Give each action one owner, a due date, a success measure and a check date. Prefer design changes to retraining. Source: https://incidentkit.ai/use-cases/close-corrective-actions · Updated Oct 5, 2026 For: Quality or EHS manager who owns the corrective-action log ## When is a corrective action closed? It is closed when the change is in place and a dated check shows it worked. Done is not closed. CMS's nursing home rule wants improvements measured and sustained (42 CFR 483.75(d)(1)). The ASC (surgery center) rule agrees: improvements must be sustained (42 CFR 416.43(c)(2)) and evaluated for effectiveness (416.43(e)(2)). Use four statuses: open, done (evidence attached), verified (a second person checked) and closed. A failed check reopens the action. ## The parts of a good corrective action Every action needs eight parts. Miss one and it stays open or closes with no proof. | Part | What good looks like | Weak version | | --- | --- | --- | | Link to cause | Names the factor it answers | Fix the problem | | Action | One concrete change | Be more careful | | Strength | Design change, not a reminder | Retrain staff | | Owner | One named role | Nursing | | Due date | A calendar date | ASAP | | Evidence | Photo, work order, procedure | Done | | Success measure | A count or visible result | Improved | | Check date | A review at 30, 60 or 90 days | None | ### What counts as evidence | Type of action | Evidence that counts | Not enough | | --- | --- | --- | | Equipment or layout change | Work order, dated photo, test record | A verbal yes | | Procedure change | Signed procedure and a use audit | An email announcing it | | Training | Competency check and observed-practice audit | A sign-in sheet alone | | Monitoring plan | Each check recorded on its date | A plan with blanks | ## Choose stronger actions RCA2, the patient safety guide from the National Patient Safety Foundation (now part of IHI), ranks actions by strength. Forcing functions and standard equipment are strong; education is weak. Industry uses the NIOSH hierarchy of controls. | Strength | Healthcare | Industrial | | --- | --- | --- | | Stronger | A scan that blocks a wrong-drug pick | Eliminate the hazard; add a guard or interlock | | Middle | Fewer steps that rely on memory | Procedures, rotation, access limits | | Weaker | Education, new policies, reminders | Protective equipment, which needs steady use | Pair a weaker action with a stronger one, or use it when it is all you control. ## Two worked examples One action from each setting, as logged. | | Healthcare | Industrial | | --- | --- | --- | | Event | Wrong-strength vial caught at a scan | Machine guard left off after cleaning | | Contributing factor | Two strengths shelved together | No guard check before restart | | Action | Store them apart, labelled differently | Fit an interlock that stops the machine | | Owner and due date | Pharmacy lead, within 14 days | Maintenance manager, within 30 days | | Evidence | Photo of the new shelving | Work order and test record | | Success measure | No mixed strengths in monthly audits | Zero bypass events on the line | | Check | Shelf audit at 30 and 90 days, by a second pharmacist | Interlock test and event review at 60 days, by EHS | These are illustrations, not data from any facility. A second person runs each check. A few strong actions beat a long list of weak ones. ## A close-out routine Five weekly steps keep actions honest. 1. **Assign at sign-off** Create each action at sign-off: owner, due date, success measure, check date. 2. **Review overdue items weekly** Take ten minutes on late items. Escalate to the owner's manager after 7 days overdue, to the QAPI or safety committee after 30. 3. **Attach evidence at completion** The owner uploads proof: a photo, work order or revised procedure. 4. **Run the check on the date** A second person compares the measure to the baseline, such as falls before and after. 5. **Close or reopen** If the measure moved, close it. If not, reopen with a stronger action and a new date. ## Mistakes to avoid These habits flatter the log. - Closing at completion. An email does not show the problem stopped. - Retraining as the only action. It is the weakest. - Shared ownership. Pick one owner; list helpers separately. - Moving due dates without a note. Keep the original date and reason. - Owners verifying their own fix. Use a second person. - Monitoring that fades. CMS's F867 example: monthly checks for three months, no evidence for month two. - Vague actions. If you cannot say what would show failure, rewrite it. ## How IncidentKit changes the job [Corrective actions](https://incidentkit.ai/product/corrective-actions) carry an owner, due date, evidence and effectiveness check. Nothing closes until a person verifies it. Each links to its [investigation](https://incidentkit.ai/product/investigations). The [audit trail](https://incidentkit.ai/product/audit-trail) records every change, date moves included. [Analytics](https://incidentkit.ai/product/analytics) show whether the cluster shrank. ## Before and after - **Before:** Actions say "educate staff" and close when the email goes out. **After:** One owner, one due date, one success measure. - **Before:** Several people own an action, so no one does. **After:** Nothing closes until evidence is attached and a person verifies. - **Before:** Due dates slip while the log stays green. **After:** Date changes stay in the audit trail. - **Before:** No one can show a surveyor, insurer or board that a fix worked. **After:** Effectiveness checks are set up front. ## Frequently asked questions ### What is the difference between a correction, a corrective action and a preventive action? A correction fixes the problem in front of you. A corrective action removes the cause. A preventive action acts on a risk before an event. Programs often track all three as CAPA. ### How long should an effectiveness check wait? Long enough for the event to recur if the fix failed: 30 days for frequent events, a proxy such as audit results for rare ones. Set the date when you create the action. ### Who should verify that an action worked? Someone other than the owner, such as a quality lead or a supervisor from another area, who checks evidence. ### What should happen when an action is overdue? Escalate by a set rule, such as to the owner's manager after 7 days and the QAPI committee after 30. Record the new date and reason, and keep the original. ## Sources - [CMS: State Operations Manual Appendix PP, F867 (42 CFR 483.75(c)-(e), (g))](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [eCFR: 42 CFR 416.43, ASC QAPI](https://www.ecfr.gov/current/title-42/section-416.43) - [AHRQ PSNet: RCA2 and the evolution of root cause analysis](https://psnet.ahrq.gov/perspective/conversation-jessica-behrhorst-about-evolution-root-cause-analysis) - [IHI: RCA2, Improving Root Cause Analyses and Actions to Prevent Harm](https://www.ihi.org/library/tools/rca2-improving-root-cause-analyses-and-actions-prevent-harm) - [CDC NIOSH: Hierarchy of controls](https://www.cdc.gov/niosh/hierarchy-of-controls/about/index.html) ## Related - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Corrective Action Plan Template (CAPA, Printable)](https://incidentkit.ai/templates/corrective-action-plan) - [Effectiveness review: definition and meaning](https://incidentkit.ai/glossary/effectiveness-review) - [Corrective and preventive action: definition and meaning](https://incidentkit.ai/glossary/corrective-and-preventive-action) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Hierarchy of controls: definition and meaning](https://incidentkit.ai/glossary/hierarchy-of-controls) --- # How to report and review falls > Report every fall, with or without injury. CMS counts a resident found on the floor as a fall. Record time, place, activity, footwear, call light and medication changes, screen unwitnessed falls with injury, and review patterns. Source: https://incidentkit.ai/use-cases/fall-reporting · Updated Oct 5, 2026 For: Director of nursing or hospital nurse manager who reviews every fall ## What counts as a fall? Report every fall, injury or not. CMS's F689 guidance defines a fall as unintentionally coming to rest on the ground, floor or other lower level, not from an overwhelming external force. A resident found on the floor counts as fallen unless evidence shows otherwise. A near-fall counts too: the resident lost balance and would have fallen without help. The CDC reports over 14 million older adults, about 1 in 4, report falling each year (2020-2021 data). Falls are the leading cause of injury for adults 65 and older. ## What to do in the first hour Treat, notify, preserve the facts, report the same shift, screen unexplained injury. 1. **Assess and treat** Call for help. Do not move a suspected injury until assessed. 2. **Notify** Tell the physician and the family or representative, per policy and state rules. 3. **Preserve the scene facts** Note floor, lighting, bed height, brakes, alarms, footwear and equipment. 4. **File the report before shift end** Details fade fast. 5. **Screen the injury** If no one saw how it happened, use the unknown-source test below. ## What to record Record the circumstances that explain the fall, as facts. | Field | Why it matters | | --- | --- | | Time, place, activity (toileting, transfer, walking) | CMS names time of day and location as trends. | | Witnessed or found | Unwitnessed falls need extra screening. | | Injury and treatment | Sets severity and who must be told. | | Footwear, lighting, floor, equipment, alarms | Hazards the facility controls. | | Call light, last toileting, rounding | Shows supervision level. | | Recent medication or condition changes | A common contributing factor. | | Care plan interventions in place | Shows if planned steps were used. | | Changes made after the fall | Links the fall to the care plan. | ### Write facts and conditions, not judgments Compare these two entries for the same event. | Weak | Strong | | --- | --- | | Resident found on floor. No injury. Resident non-compliant with call light. | Found on floor beside bed at 05:40, not witnessed. Says she was going to the bathroom. Call light clipped to rail, out of reach. Bed high. Non-slip socks on. Last toileting offered at 02:00. No injury. Physician and daughter notified at 06:05. | The second entry names three fixable conditions: call light, bed height, toileting schedule. ## Unwitnessed falls and injuries of unknown source An injury of unknown source meets all three CMS conditions: no one saw the cause, the resident cannot explain it, and the injury is suspicious by extent, location or number. Treat it as an alleged violation. Then the clock starts: immediately, and within 2 hours if abuse is alleged or the event causes serious bodily injury, otherwise within 24 hours (42 CFR 483.12(c)(1)). See [abuse reporting deadlines](https://incidentkit.ai/use-cases/abuse-reporting-deadlines). ## Review the pattern, not just the fall F689 asks for four steps: identify hazards, evaluate them, put interventions in place and monitor whether they work. Review prior accidents, root causes, time of day and location. Include nursing, therapy, pharmacy and maintenance. - Group falls by unit, room, shift and hour each month. - List repeat fallers and check their interventions were in place. - Compare falls with and without injury. - Take patterns to the QAPI committee (the quality program CMS requires). Nursing homes must track adverse events and analyze causes (42 CFR 483.75(e)(2)). The same fields work in hospitals and for employees. For a worker's fall on a plant floor, swap the care plan for surface, footwear, housekeeping and ladder use. See [workplace injury reporting](https://incidentkit.ai/use-cases/workplace-injury-reporting). ## Mistakes to avoid These habits hide patterns. - Reporting only falls with injury. - Blaming the resident. Ask what the system missed. - Re-education as the only action. - Skipping the screen for unwitnessed falls with injury. - Care plan changes not linked to the fall. - Leaving the narrative to the next shift. - Treating hospital and plant falls as different. ## How IncidentKit changes the job Staff text the fall. [Lauren](https://incidentkit.ai/product/lauren) asks the follow-up questions a risk manager would ask and fills the form. A person reviews and signs. [Routing](https://incidentkit.ai/product/routing-and-escalation) can alert the administrator. The fall links to its [investigation](https://incidentkit.ai/product/investigations) and [corrective actions](https://incidentkit.ai/product/corrective-actions), each with an owner, due date and effectiveness check. [Analytics](https://incidentkit.ai/product/analytics) show patterns by unit and shift. ## Before and after - **Before:** Only falls with injury get a report. **After:** Every fall gets a short report that shift. - **Before:** Unwitnessed falls say found on floor, cause blank. **After:** Lauren asks about footwear, call light and toileting. - **Before:** Care plans change, but not linked to the fall. **After:** Unwitnessed falls with injury can route to the administrator. - **Before:** No one reviews falls by time or room. **After:** Analytics show falls by unit, room, shift and time of day. ## Frequently asked questions ### Does a fall without injury need an incident report? Yes. A fall without injury is still a fall under CMS's F689 guidance, and it shows the hazard before anyone is hurt. ### How soon after a fall should the report be filed? Before the shift ends; your policy sets the exact time. An injury of unknown source can start the 2- or 24-hour abuse clock on its own. ### What falls data should go to the QAPI committee? Falls by unit, time of day and location, with and without injury; repeat fallers; and whether post-fall interventions were in place. Nursing home QAPI must track adverse events and analyze their causes (42 CFR 483.75(e)(2)). ### Are hospital falls handled the same way? Mostly; the fields are the same but the rules differ. F689 is a nursing home tag. Hospitals follow their own QAPI condition (42 CFR 482.21), and your state and accreditor may add reporting rules for falls with serious injury. ## Sources - [CMS: State Operations Manual Appendix PP, F689 accidents and F609 injuries of unknown source](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [eCFR: 42 CFR 483.25(d), accidents](https://www.ecfr.gov/current/title-42/section-483.25) - [eCFR: 42 CFR 483.12(c), response to allegations](https://www.ecfr.gov/current/title-42/section-483.12) - [CDC: Older adult falls data](https://www.cdc.gov/falls/data-research/index.html) - [eCFR: 42 CFR 482.21, hospital QAPI](https://www.ecfr.gov/current/title-42/section-482.21) ## Related - [F689 accidents and supervision: falls, hazards, devices](https://incidentkit.ai/compliance/f-tags/f689) - [Fall Incident Report Template for Healthcare (Printable)](https://incidentkit.ai/templates/fall-incident-report) - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) - [Abuse Reporting Deadlines for Nursing Homes: 2 and 24 Hours](https://incidentkit.ai/use-cases/abuse-reporting-deadlines) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) --- # How to report a medication error > Report every medication error, even catches. Record what was ordered, what happened, the stage and the harm. Grade severity with the NCC MERP index, A to I. In nursing homes, CMS counts a significant error apart from the overall error rate. Source: https://incidentkit.ai/use-cases/medication-error-reporting · Updated Oct 5, 2026 For: Director of nursing, pharmacy lead or ASC nurse manager who reviews medication errors ## What counts as a medication error? A medication error is any preventable event that may lead to inappropriate medication use or patient harm (NCC MERP). CMS's nursing home rule (F760) is narrower: preparation or administration that departs from the order, the manufacturer's specifications or professional standards. Catches count: they are the cheapest data you will ever collect. ## What to record Record the order, what happened, which step failed and how it was found. | Field | Detail | | --- | --- | | Medication as ordered | Drug, dose, route, frequency, prescriber | | What actually happened | What was given and how it differed | | Stage | Prescribing, transcribing, dispensing, administering or monitoring | | Reached the patient? | Yes or no: the line between B and C | | Harm and care needed | Monitoring, treatment, hospital care, outcome | | What caught it | Scan, pharmacist check, second nurse, patient | | Conditions around the event | Interruptions, look-alikes, storage, unclear order, staffing, handoff | | Notifications | Prescriber, patient or family, pharmacy, with times | ### A useful report > **Example report** 08:10, 3 East. Warfarin 5 mg was prepared for a resident ordered 2.5 mg. A second nurse caught it at the cart. The strengths sit side by side, and the nurse was interrupted twice. Category B. ## Grade severity with the NCC MERP index NCC MERP, the national council on medication error reporting and prevention, publishes an index that sorts errors by outcome, A to I. Use the current version, revised in October 2022. | Category | Meaning | | --- | --- | | A | Circumstances that could cause an error | | B | Error did not reach the patient | | C | Reached the patient, no harm | | D | Reached the patient and needed monitoring or intervention to confirm or prevent harm | | E to F | Temporary harm needing intervention (E), or initial or prolonged hospitalization (F) | | G to H | Permanent harm (G), or intervention needed to sustain life (H) | | I | Error that may have contributed to or resulted in death | ## What to ask at each stage Review each stage for the conditions that make an error likely. | Stage | Conditions that often contribute | Question to ask | | --- | --- | --- | | Prescribing | Unclear or verbal order, similar drug names, missing allergy or weight | Could the order be read two ways? | | Transcribing | Manual copying or copy-forward | Did a person retype anything? | | Dispensing | Look-alike or sound-alike products, crowded storage | Are two products easy to confuse? | | Administering | Interruptions, scan overrides, high-alert drugs, wrong patient | What was happening around the person? | | Monitoring | Labs not followed up, narrow therapeutic index drugs | Who owned the follow-up? | ## Nursing homes: significant errors and the 5 percent rate CMS calls an error significant if it causes the resident discomfort or jeopardizes health and safety. The call weighs the resident's condition, the drug (warfarin or lithium weigh more) and repeats. An omitted dose of metoprolol succinate 100 mg daily is significant; an omitted multivitamin is not. Condition or repeats can change either call. A significant error can be cited at F760 at any error rate. F759 needs a rate of 5 percent or more: errors observed divided by opportunities for error, times 100. CMS does not round 4.6 percent up to 5. ## Steps after an error, and mistakes to avoid Care first, then report, grade and fix the system, not the person. 1. **Care first** Assess, treat and notify the prescriber. 2. **Report in the same shift** Fill in the fields above while details are fresh. 3. **Grade it** Use the NCC MERP category. Send C and above to the nurse manager. 4. **Look at the system** CMS tells ASC surveyors that blaming and removing staff is not the systems approach its quality program (QAPI) requires. Ask about storage and orders. 5. **Choose a stronger action** Change storage, labelling or scanning, not just reminders. See [corrective actions](https://incidentkit.ai/use-cases/close-corrective-actions). 6. **Report outside where required** Check state rules. ISMP runs a voluntary, confidential error program; FDA MedWatch takes product problem reports. - Counting only errors that caused harm. - Grading severity in free text. - Reviewing only the administering stage. - Leaving barcode overrides unreviewed. - Ignoring repeats: the same drug twice in a month. ## How IncidentKit changes the job [Lauren](https://incidentkit.ai/product/lauren) asks about the drug, dose, route, stage and catch, then drafts the fields, marked Lauren · draft. A person reviews, edits and signs. Forms can carry your own severity scale. The [investigation](https://incidentkit.ai/product/investigations) records contributing factors. [Corrective actions](https://incidentkit.ai/product/corrective-actions) carry an owner, due date and evidence. [Analytics](https://incidentkit.ai/product/analytics) show repeats. ## Before and after - **Before:** Only harm gets reported; catches are lost. **After:** Catches and errors use one short report. - **Before:** The report says wrong dose, not which step failed. **After:** Lauren asks about drug, dose and stage, then drafts for review. - **Before:** Severity is free-text opinion. **After:** Severity is recorded on a defined scale. - **Before:** The fix is a reminder, so the error returns elsewhere. **After:** Actions tie to the error; analytics show repeats. ## Frequently asked questions ### Do we report medication errors outside the facility? Sometimes, depending on harm, setting and state, so check yours. Voluntary routes are ISMP's confidential National Medication Errors Reporting Program and FDA MedWatch. ### What is the difference between a near miss and a medication error? A near miss is an error caught before it reached the patient, or a circumstance that could cause one (NCC MERP B and A). Errors that reached the patient are C through I. ### What is a significant medication error under CMS rules? In nursing homes, F760 defines it as an error that causes discomfort or jeopardizes health and safety. Surveyors weigh condition, drug and repeats. ### Should the person who made the error be named in the report? Record the role and the facts; names belong in the investigation file. Analyze the system, not the person. ## Sources - [NCC MERP: About medication errors and the Index for Categorizing Medication Errors](https://www.nccmerp.org/types-medication-errors) - [NCC MERP: Index for Categorizing Medication Errors (2022)](https://www.nccmerp.org/sites/default/files/index-bw-2022.pdf) - [CMS: State Operations Manual Appendix PP, F760 significant medication errors](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [CMS: State Operations Manual Appendix L, systems approach to a medication error](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_l_ambulatory.pdf) - [ECRI and ISMP: Report an error](https://home.ecri.org/pages/report-an-error) - [FDA: MedWatch safety reporting program](https://www.fda.gov/safety/medwatch-fda-safety-information-and-adverse-event-reporting-program) ## Related - [Medication Error Report Template (Printable Form)](https://incidentkit.ai/templates/medication-error-report) - [F760 significant medication errors: how surveyors cite it](https://incidentkit.ai/compliance/f-tags/f760) - [Medication error: definition and meaning](https://incidentkit.ai/glossary/medication-error) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Incident reporting software for surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers) --- # Abuse and neglect reporting deadlines for nursing homes > Nursing homes must report alleged abuse, or an event with serious bodily injury, immediately and within 2 hours. Other allegations are due within 24 hours. Results are due within 5 working days. Check your state for shorter deadlines. Source: https://incidentkit.ai/use-cases/abuse-reporting-deadlines · Updated Oct 5, 2026 For: Nursing home administrator or abuse coordinator who reports alleged abuse on a clock ## What are the federal deadlines? Two clocks run, plus one for results. This is the federal nursing home rule, 42 CFR 483.12. | Situation | Deadline | Report to | Rule | | --- | --- | --- | --- | | Alleged abuse, or serious bodily injury | Immediately, within 2 hours of the allegation | The administrator, State Survey Agency and other officials, per state law | 483.12(c)(1) | | Neglect, exploitation, mistreatment, misappropriation of property or injury of unknown source, with no abuse or serious injury | Within 24 hours | Same officials | 483.12(c)(1) | | Reasonable suspicion of a crime against a resident, with serious bodily injury | Immediately, within 2 hours of forming the suspicion | The State agency and local law enforcement | 483.12(b)(5) | | Reasonable suspicion of a crime, no serious injury | Within 24 hours | Same | 483.12(b)(5) | | Results of the investigation | Within 5 working days of the incident | The same officials | 483.12(c)(4) | ## Who must report, and what starts the clock? Every owner, operator, employee, manager, agent and contractor must report under the crime-reporting rule, and the facility must notify them of it yearly. CMS counts any allegation, even before it is investigated. The clock starts at the allegation or when suspicion forms, not when the investigation ends. An injury is of unknown source when all three are true. No one saw the cause. The resident cannot explain it. It is suspicious by extent, location or number. See [fall reporting](https://incidentkit.ai/use-cases/fall-reporting). ## A step-by-step response Protect the resident, note the time, report, investigate and report the result. 1. **Protect the resident** Separate, assess and treat. Prevent further potential abuse (483.12(c)(3)). 2. **Write down the time** Record when the allegation was made and who got it. 3. **Tell the administrator at once** Use a number that is always answered. Name a backup. 4. **Make the external report** Report to the State Survey Agency, adult protective services and law enforcement as state law requires. 5. **Investigate** Interview witnesses and the resident, review records, keep the evidence. 6. **Report the results** Send the findings within 5 working days of the incident. 7. **Correct and monitor** If verified, correct it and check the fix holds. ### An illustrative 2-hour timeline *Example only. Times are invented to show the sequence.* | Time | What happens | Why | | --- | --- | --- | | 06:40 | A resident tells an aide a staff member struck them. | The allegation is made. The 2-hour clock starts. | | 06:45 | The resident is assessed and kept apart. | Rule: prevent further potential abuse. | | 06:50 | The administrator is called, then the backup. | Reporting cannot wait for one person. | | By 08:40 | Reports go to the State Survey Agency and other officials. Each call is logged. | 2-hour deadline: abuse alleged. | | Within 5 working days | Results go to the same officials. | 483.12(c)(4). | ## What the investigation file should hold All alleged violations must be thoroughly investigated. A good file holds these. - Timeline from allegation to reports made. - Separate statements from the resident, witnesses and staff on duty. - The resident's assessment, injury notes, care changes. - Staffing and assignment sheets. - Steps taken to protect residents. - Findings, corrective action and the check it held. States add agencies, forms and shorter deadlines. Keep a state card with each agency's phone, portal and form. See [state reporting overview](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview). ## Mistakes to avoid These habits cause late or missing reports. - Starting the clock when the investigation ends. - Waiting for one person. Name a backup with authority to report. - Skipping the screen because a fall is the likely cause. - Leaving contractors, agency staff and volunteers out of the annual notice. - Voicemail with no record of who was told. - Forgetting the 5-working-day result report. ## Why timely reporting matters beyond the deadline CMS can cut a civil money penalty by 50 percent if a facility reports a problem itself and fixes it promptly. It must report before CMS, the State or a complaint finds it, and meet its mandatory reporting duties. The problem must not be a pattern of harm, widespread harm, immediate jeopardy or a death. Other conditions apply, including waiving the right to a hearing. Do not plan around this. ## How IncidentKit changes the job The allegation time is recorded from the first report. [Lauren](https://incidentkit.ai/product/lauren) asks who saw what and whether the resident can explain an injury. A person reviews and signs. [Escalation](https://incidentkit.ai/product/routing-and-escalation) alerts the administrator. Each notification is logged on the [investigation](https://incidentkit.ai/product/investigations). Track the five-day report as an action with a due date. The [audit trail](https://incidentkit.ai/product/audit-trail) records changes; [corrective actions](https://incidentkit.ai/product/corrective-actions) stay open until verified. ## Before and after - **Before:** The clock starts when someone tells the administrator. **After:** The allegation time is recorded from the first report. - **Before:** Calls are made, but the time is not logged. **After:** Each notification is logged: who, when, how. - **Before:** Injuries of unknown source are charted as falls. **After:** Unwitnessed injuries get a documented screen. - **Before:** The five-day report is tracked on a sticky note. **After:** The investigation has a due date. ## Frequently asked questions ### What is the difference between the 2-hour and 24-hour deadline? 2 hours applies to abuse or serious bodily injury; 24 hours applies when neither is involved (42 CFR 483.12(c)(1)). Both run from the allegation. If unsure, use the shorter clock. ### Do these deadlines apply to assisted living, home health or hospice? No. 42 CFR 483.12 covers nursing homes. Other settings follow state law and license rules, with their own deadlines. If a state clock is shorter, use it. ### Does a fall with an unexplained bruise need an abuse report? Maybe: screen it. If no one saw the cause, the resident cannot explain it, and the injury is suspicious by extent, location or number, it is an alleged violation and the clock applies. Document the screen either way. ### Who must be told besides the State Survey Agency? The administrator and officials your state names, such as adult protective services. For a suspected crime, covered individuals report to the State agency and local law enforcement. ## Sources - [eCFR: 42 CFR 483.12, freedom from abuse, neglect and exploitation](https://www.ecfr.gov/current/title-42/section-483.12) - [CMS: State Operations Manual Appendix PP, F609 and F610](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [CMS: State Operations Manual Chapter 7, section 7516.4, penalty reduction for self-reporting](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107c07pdf.pdf) ## Related - [Nursing home abuse reporting: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting) - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) - [F610 investigate, prevent and correct alleged violations](https://incidentkit.ai/compliance/f-tags/f610) - [F600 free from abuse and neglect: what surveyors cite](https://incidentkit.ai/compliance/f-tags/f600) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) --- # How to automate the OSHA 300 log without losing control of it > Each recordable injury goes on the OSHA 300 log and a 301 report within 7 calendar days. Post the 300A February 1 through April 30 and keep records 5 years. Software captures and totals; a person decides and certifies. IncidentKit's OSHA exports are rolling out. Source: https://incidentkit.ai/use-cases/osha-300-log-automation · Updated Oct 5, 2026 For: EHS manager or HR lead who keeps the OSHA 300 log ## What does automating the OSHA 300 log mean? Automating means capturing facts once and generating the forms from them. A person, not the software, decides what is recordable. OSHA accepts computer records that produce equivalent forms (29 CFR 1904.29). > **Rolling out** IncidentKit's OSHA 300, 300A and 301 exports are rolling out. Capture, investigations, corrective actions and the audit trail work today. ## The deadlines that drive the work Seven clocks govern the OSHA log, from 8 hours to 5 years. | Task | Deadline | Rule | | --- | --- | --- | | Report a fatality | Within 8 hours (if death is within 30 days) | 29 CFR 1904.39 | | Report an inpatient hospitalization, amputation or eye loss | Within 24 hours | 29 CFR 1904.39 | | Enter a recordable case on the 300 and 301 | Within 7 calendar days of learning of it | 29 CFR 1904.29 | | Certify the annual summary | After year end, by an owner, officer or top site official | 29 CFR 1904.32 | | Post the 300A | By February 1, through April 30 | 29 CFR 1904.32 | | Submit electronically, if required | By March 2 | 29 CFR 1904.41 | | Keep the records | 5 years after the calendar year | 29 CFR 1904.33 | ## Capture the facts, then decide recordability Capture the facts once, then decide in order. ### What the 301 asks Capture these Form 301 fields at first report, while memory is fresh. | Form 301 asks | Capture at the scene | | --- | --- | | What was the employee doing before? | Activity, tools and materials | | What happened? | How the injury occurred | | What was the injury or illness? | Body part and effect | | What harmed the employee? | The floor, machine, chemical or patient | | Emergency room visit? Overnight inpatient stay? | Both answers, with times, for the 24-hour call | | Start of work and time of event? | Both times | | If the employee died, when? | The date, for the 8-hour and 30-day limits | ### Then decide, in order 1. Is it your employee, or a worker you supervise day to day (29 CFR 1904.31)? 2. Is it work-related (1904.5)? OSHA has no general exception for violence at work. 3. Is it new, not one already logged? 4. Does it meet a recording rule (1904.7)? Death, days away, restricted work or transfer, more than first aid, or loss of consciousness. Or a significant injury or illness diagnosed by a licensed health care professional. 5. Only first aid? Not recordable. First aid is a closed list: bandages, tetanus shots, wound cleaning. 6. If recordable, enter it on the 300 log and complete the 301 within 7 calendar days. Privacy concern cases keep the name off the log: intimate body part injuries, sexual assault, mental illness, HIV, hepatitis or tuberculosis. Names also stay off for needlesticks and sharps cuts contaminated with another person's blood, and when an employee asks. ## What to automate, and what a person decides Automate capture, counting and totals. A person keeps decisions and certification. | Task | Automate? | Why | | --- | --- | --- | | Capture facts at first report | Yes | Fewer retyped errors | | Count days away and restricted | Yes, a person confirms | Dates change | | Flag hospitalization, amputation, eye loss | Prompt a person | A person makes the 24-hour call | | Decide recordable or first aid | No, a person decides | It needs a written reason | | Total the log and 300A | Yes | Arithmetic is not hand work | | Certify and post the summary | No, an executive does | The rule names who certifies | | Prepare the electronic filing | Prepare it, a person submits | The site stays accountable | ## A six-step year-end routine Review in December. Post by February 1. Submit by March 2. 1. **Review the log in December** Check each case: completeness, classification, day counts. 2. **Update changed cases** Add new cases. Line out old entries to show changes (1904.33). 3. **Prepare the 300A** Build it from the log totals. 4. **Certify** A company executive signs after examining the log. 5. **Post and submit** Post by February 1 through April 30. Submit electronically by March 2 if required. 6. **Retain** Keep the 300, 300A and 301 for 5 years after the calendar year. Send the 300A if you have 20 to 249 employees in a listed industry, or 250 or more. Send 300 and 301 data too if you have 100 or more in a smaller list of industries (29 CFR 1904.41). ## Mistakes to avoid These habits cause log errors. - Waiting until January. Review monthly. - Logging visitors. The log covers your employees and workers you supervise. - Changing the log silently. Show every change. - Letting software decide recordability with no written reason. - Making a report count against a supervisor. OSHA bars discrimination for reporting (29 CFR 1904.35). ## What IncidentKit does today, and what is rolling out Today, [Lauren](https://incidentkit.ai/product/lauren) takes injury reports by text and a person signs. The [audit trail](https://incidentkit.ai/product/audit-trail) logs every change. [Compliance packets](https://incidentkit.ai/product/compliance-packets) cover QAPI and survey packets, with OSHA 300, 300A and 301 exports rolling out. ## Before and after - **Before:** Entries are retyped into a spreadsheet days later. **After:** The report captures the facts the 300 and 301 need. - **Before:** Days away and restricted days are counted by hand and drift. **After:** Each case has a signed decision and a written reason. - **Before:** The 300A is built in January from a log nobody has reviewed. **After:** Totals and the 300A come from case records. The OSHA exports are rolling out. - **Before:** Recordability calls live in one person's head. **After:** Every edit is in the audit trail, so you can trust the log. ## Frequently asked questions ### How long do I have to enter an injury on the OSHA 300 log? Within 7 calendar days of learning of it (29 CFR 1904.29). Enter it on the 300 log and 301 report, and update the log if dates change. ### Who has to submit OSHA injury data electronically? Covered establishments, set by size and industry (29 CFR 1904.41). They submit by March 2 through OSHA's Injury Tracking Application. ### Is IncidentKit's OSHA 300 export available now? Not yet. OSHA 300, 300A and 301 exports are rolling out. Capture, investigations, corrective actions and the audit trail work today. ### Can software decide whether an injury is recordable? No, a person decides. Software can prompt the right questions and keep the decision on record. ## Sources - [OSHA: Recordkeeping overview](https://www.osha.gov/recordkeeping) - [OSHA: 29 CFR 1904.29, forms](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.29) - [OSHA: 29 CFR 1904.32, annual summary](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.32) - [OSHA: 29 CFR 1904.33, retention and updating](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.33) - [OSHA: 29 CFR 1904.39, reporting fatalities and severe injuries](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.39) - [OSHA: 29 CFR 1904.41, electronic submission](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.41) - [OSHA: 29 CFR 1904.7, general recording criteria and first aid](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.7) - [OSHA: Recordkeeping forms package (Forms 300, 300A and 301)](https://www.osha.gov/sites/default/files/OSHA-RK-Forms-Package.pdf) - [OSHA: 29 CFR 1904.31, covered employees](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.31) - [OSHA: 29 CFR 1904.35, employee involvement](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.35) - [OSHA: Recordkeeping FAQ 5-2, workplace violence and work-relatedness](https://www.osha.gov/faq/5-2) ## Related - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [OSHA 300A summary: who signs, when to post, how long](https://incidentkit.ai/compliance/osha/osha-300a-summary) - [OSHA 301 incident report: the 18 fields and deadlines](https://incidentkit.ai/compliance/osha/osha-301-incident-report) - [OSHA electronic submission: 29 CFR 1904.41 and the ITA](https://incidentkit.ai/compliance/osha/electronic-submission) - [Recordable vs first aid: OSHA's medical treatment test](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) - [OSHA recordkeeping guide: Part 1904 for employers](https://incidentkit.ai/guides/osha-recordkeeping-guide) --- # How to handle workplace injury reporting > Employers need a reasonable way for employees to report injuries, and must tell them. After a report, decide three things. Does OSHA need a call (8 or 24 hours)? Is it recordable (7 days)? What goes to workers' compensation? Retaliation for reporting is prohibited. Source: https://incidentkit.ai/use-cases/workplace-injury-reporting · Updated Oct 5, 2026 For: Supervisor, EHS manager or HR lead who takes the first call after an injury ## What must employers set up for injury reporting? Set a reasonable way for employees to report injuries promptly, and tell every employee. It must not discourage reports. Employees must know they cannot be discharged or discriminated against for reporting (29 CFR 1904.35 and 1904.36). Hospitals: Joint Commission standard EC.04.01.01, element 1, expects a process to monitor, report and investigate occupational illnesses and staff injuries. ## Who does what, and by when Care comes first, then a same-shift report, then three decisions. | Step | Who | When | | --- | --- | --- | | Get care | Anyone present | Right away | | Report to a supervisor | The employee | The same shift | | Write the report | The supervisor | The same shift | | Decide if OSHA must be told | EHS or manager | Fatality: 8 hours. Hospitalization, amputation, eye loss: 24 hours | | Decide if it is recordable, then log it | EHS | Within 7 calendar days of learning of it | | File the workers' compensation first report | HR or EHS | Your state sets the deadline | | Find the cause | Supervisor, EHS, employee rep | Start promptly | ### What the supervisor's report should hold - What the employee was doing, and with what. - What happened, in order, in the employee's words. - The injury: body part and effect. - The object or substance that harmed the employee. - When work began, when it happened, who saw it. - ER visit, or overnight admission as an in-patient. These mirror OSHA's Form 301, so the report is a first draft of the 301. ## When must OSHA be told? Report a work-related fatality within 8 hours, if death is within 30 days of the incident. Report an in-patient hospitalization, amputation or loss of an eye within 24 hours. Call the nearest OSHA area office or 1-800-321-OSHA, or report online (29 CFR 1904.39). Temp workers: the employer that supervises day to day reports. A motor vehicle crash on a public street outside a construction work zone is not reportable, though it may be recordable. ### Four quick cases *Examples, not legal advice.* | Case | Tell OSHA? | Record on the 300 log? | | --- | --- | --- | | A worker gets stitches and returns the same day | No | Yes. Stitches go beyond first aid | | A worker slips, gets a bandage, returns to work | No | No. First aid only | | Overnight in-patient stay after a ladder fall | Yes, within 24 hours | Yes | | A worker dies 10 days after a work incident | Yes, within 8 hours of the death | Yes | ## First aid or medical treatment beyond first aid? That line decides if a case is logged. OSHA's first aid list is complete. Anything else is treatment beyond first aid, and recordable if work-related (29 CFR 1904.7). | First aid | Medical treatment beyond first aid | | --- | --- | | Cleaning a wound, applying a bandage | Stitches or staples | | Non-prescription medication at non-prescription strength | Prescription medication | | Tetanus shot | Physical therapy or a rigid cast | | Hot or cold therapy, elastic wraps | Days away or restricted duty, whatever the treatment | ## How to avoid discouraging reports OSHA's 2018 memo allows incentives and post-incident drug testing, but not to penalize reporting. After an incident, test everyone whose conduct could have contributed, not just the reporter. - Tell staff how to report, and that reporting is protected. - Reward hazard and near-miss reports, not a zero count. - Treat a report as data, not a mark against anyone. ## Mistakes to avoid These habits delay reports and hide causes. - Telling employees to wait. Report the same shift. - Missing the 24-hour clock. It runs from the in-patient hospitalization. - Judging first aid from memory. Use the closed list. - Fixing the person, not the cause. - Leaving the report to HR on Monday. - Losing a contractor's or temp's injury between employers. See [contractor and visitor incidents](https://incidentkit.ai/use-cases/contractor-and-visitor-incidents). ## How IncidentKit changes the job Report by text or [QR code](https://incidentkit.ai/product/quick-report). [Lauren](https://incidentkit.ai/product/lauren) asks the follow-up questions and fills the form. A person reviews, edits and signs. [Routing](https://incidentkit.ai/product/routing-and-escalation) sends the case to EHS and the supervisor's manager. The [investigation](https://incidentkit.ai/product/investigations) and [corrective actions](https://incidentkit.ai/product/corrective-actions) keep an owner and date. Industrial packs and OSHA 300, 300A and 301 exports are rolling out ([OSHA 300 log automation](https://incidentkit.ai/use-cases/osha-300-log-automation)). ## Before and after - **Before:** The employee tells a supervisor, who tells HR Monday, who files it Friday. **After:** The employee or supervisor reports from the scene, with a time stamp. - **Before:** Nobody can say whether a hospital stay started the 24-hour clock. **After:** Lauren asks early about admission and amputation, so a person can make the 24-hour call. - **Before:** First aid versus medical treatment is argued later. **After:** The recordability decision is written down with its reason. - **Before:** Injury-free bonuses make people think twice about reporting. **After:** Reports route to EHS and the supervisor's manager. Every follow-up has an owner and a date. ## Frequently asked questions ### How soon must an employee report a work injury? OSHA sets no number of hours; it requires a reasonable procedure for prompt reporting. States set workers' compensation notice deadlines. Tell employees to report the same shift. ### Do I report an injury to OSHA if the worker is treated and released? Usually not. Only fatalities, in-patient hospitalizations, amputations and losses of an eye are reportable. Check OSHA's in-patient definition (29 CFR 1904.39). Recording is a separate decision. ### Can we give safety bonuses? Yes, with care. OSHA's 2018 memo says rewarding hazard and near-miss reports is always allowed. Rewarding injury-free periods is allowed only if it does not discourage reporting. ### Who reports a temporary worker's injury? The employer that directs the work day to day: its details, means, methods and processes. It records the injury and makes any report. Agree this with the staffing agency. ## Sources - [OSHA: 29 CFR 1904.35, employee involvement](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.35) - [OSHA: 29 CFR 1904.36, prohibition against discrimination](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.36) - [OSHA: 29 CFR 1904.39, reporting fatalities, hospitalizations, amputations and loss of an eye](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.39) - [OSHA: 29 CFR 1904.7, general recording criteria and first aid](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.7) - [OSHA: Safety incentive programs and post-incident drug testing, October 11, 2018](https://www.osha.gov/laws-regs/standardinterpretations/2018-10-11) - [OSHA: Recordkeeping FAQ 39-9, temporary worker reporting](https://www.osha.gov/faq/39-9) - [The Joint Commission: Workplace violence prevention resource compendium (EC.04.01.01 EP 1)](https://digitalassets.jointcommission.org/api/public/content/ebf48f21371341808e962e09dd363dbd) ## Related - [Workplace Injury Report Template (OSHA 301 Aligned)](https://incidentkit.ai/templates/workplace-injury-report) - [Injury reporting and retaliation: 29 CFR 1904.35 and 11(c)](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation) - [Recordable vs first aid: OSHA's medical treatment test](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [OSHA 300 Log Automation: Keep It Accurate Year-Round](https://incidentkit.ai/use-cases/osha-300-log-automation) - [Incident reporting software for EHS managers and leads](https://incidentkit.ai/solutions/ehs-managers) --- # How to run a root cause analysis that leads to action > Run a root cause analysis by building a timeline, finding contributing factors and asking why until you reach a system cause. Rank actions by strength and scale effort to severity. CMS tells surveyors to check whether a facility stops at staff error or digs into causes. Source: https://incidentkit.ai/use-cases/root-cause-analysis · Updated Oct 5, 2026 For: Risk manager, quality lead or EHS investigator who runs the review ## What a root cause analysis is, and when A root cause analysis finds the system causes behind an event and ends in actions that stop a repeat. Match depth to severity. OSHA says to investigate close calls, ask why, and include managers and workers. | Trigger | Depth | | --- | --- | | Death, permanent harm, severe temporary harm or a serious process release | Full team review at once. Sentinel events have accreditor and state deadlines | | Harm with a temporary effect | Focused review: timeline, factors, five whys | | Near miss with high potential | Focused review | | A repeat of a known event | Full review: the old fix failed | ## Eight steps from event to action Eight steps, from secured facts to verified actions. 1. **Secure facts** Preserve equipment, records and the scene. Collect first accounts that day. 2. **Form a team** Include a worker, an outsider and a facilitator. 3. **Build the timeline** List events in order, with times. Mark where reality differed from the plan. 4. **Find factors** Use the table below. 5. **Ask why** Keep asking until you reach something you control, like a layout or a missing check. 6. **State causes** Write each cause and its effect, without blame. 7. **Rank actions** Prefer design changes to reminders. 8. **Assign and verify** One owner and a check date each. Share findings with managers, supervisors and workers. ### Interview for facts, not fault - Interview people one at a time, away from supervisors. - Start open: walk me through what happened. - Ask what normally happens and how that day differed. - Ask what would make the task safer. Workers often know. - Save why for the system: ask what led to the step, not who skipped it. OSHA stresses objectivity and open-mindedness. That starts with how you ask. ## Contributing factor categories Look across seven categories, not just the person closest to the event. | Category | Healthcare example | Industrial example | | --- | --- | --- | | Task and process | No standard handoff | Lockout step missing | | Equipment | Look-alike vials, pump defaults | Guard off, interlock bypassed | | Environment | Poor lighting, wet floors | Noise, heat, blind corner | | Communication | Verbal order not read back | Handover misses open permit | | Staffing and workload | Understaffed medication pass | Overtime, thin crew | | Training and supervision | Unoriented agency staff | Contractor skipped site induction | | Policy and leadership | Conflicting procedures | Targets discourage stopping the line | ## Write causal statements, not blame Name a cause the organization can change, its effect and the event. CMS's ASC guidance gives the model: dismissing the nurse who made a medication error is not a systems approach. Ask about storage, orders and training. | Weak | Strong | | --- | --- | | The nurse failed to verify the dose. | Two strengths of one drug sat side by side with similar labels, so a wrong pick was likely. | | The operator did not follow the procedure. | The job card left out the guard check, so the step relied on memory during a rushed changeover. | Both strong statements are illustrations, not real findings. ## Pick actions by strength RCA2 guidance in patient safety ranks actions by strength. Forcing functions are strong. Education and new policies are weak: they rely on memory. Industry uses the hierarchy of controls. One cause, three actions. The cause: two strengths of one drug sit side by side. - **Weak:** remind staff to check the strength. - **Middle:** add a read-back step. - **Strong:** store the strengths apart, in marked places. Use a weak action alongside a stronger one, never in place of it. See [closing corrective actions](https://incidentkit.ai/use-cases/close-corrective-actions). ## Mistakes to avoid These habits turn a review into paperwork. - Stopping at human error. Ask what made it likely. - Asking who instead of why. - Running one five-whys chain for several causes. - Investigating alone. A team sees more. - Keeping findings from workers. OSHA says share results with managers, supervisors and workers. - Calling the review done before anyone checks the fix worked. ## How IncidentKit changes the job [Lauren](https://incidentkit.ai/product/lauren) drafts the [investigation](https://incidentkit.ai/product/investigations): timeline, contributing factors and five whys, marked Lauren · draft. A person reviews, edits and signs. Human-authored RCA templates are rolling out. [Corrective actions](https://incidentkit.ai/product/corrective-actions) link to the factors they answer. The [audit trail](https://incidentkit.ai/product/audit-trail) shows every edit. [Analytics](https://incidentkit.ai/product/analytics) show whether a cause keeps appearing. ## Before and after - **Before:** The review stops at the first person involved. **After:** The first account and timeline are captured at report. - **Before:** Interviews are written up days later from memory. **After:** Lauren drafts, marked Lauren · draft. A person reviews, edits and signs. - **Before:** The report ends with retraining, and the event repeats on another shift. **After:** Each action has a strength, an owner, a due date and evidence. - **Before:** Findings sit in a document nobody can search. **After:** Causes are searchable and trend by location, shift, equipment and cause. ## Frequently asked questions ### How is root cause analysis different from an incident report? An incident report records what happened. A root cause analysis asks why. Every serious event needs a report; only some need a full analysis. ### How long should a root cause analysis take? It depends on severity. Gather facts the same day and finish a full analysis while evidence is fresh. Accreditors set sentinel event deadlines; your state or CMS may add others. ### Which method should I use: five whys, fishbone or fault tree? Use five whys for simple events, a fishbone to list factors with a team, and a fault tree for complex failures. See [five whys vs fishbone vs fault tree](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree). ### Can software do the root cause analysis for me? No. People decide. Lauren drafts, marked Lauren · draft, and a person reviews, edits and signs. The conclusions are the team's. Human-authored RCA templates are rolling out. ## Sources - [OSHA: Recommended practices, hazard identification and incident investigation](https://www.osha.gov/safety-management/hazard-identification) - [CMS: State Operations Manual Appendix L, QAPI systems approach (Q-0082)](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_l_ambulatory.pdf) - [AHRQ PSNet: RCA2 and the evolution of root cause analysis](https://psnet.ahrq.gov/perspective/conversation-jessica-behrhorst-about-evolution-root-cause-analysis) - [IHI: RCA2, Improving Root Cause Analyses and Actions to Prevent Harm](https://www.ihi.org/library/tools/rca2-improving-root-cause-analyses-and-actions-prevent-harm) - [CMS: State Operations Manual Appendix PP, F867 (42 CFR 483.75(d)(2))](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) ## Related - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Root Cause Analysis Worksheet (5 Whys Template)](https://incidentkit.ai/templates/root-cause-analysis-worksheet) - [Five whys vs fishbone vs fault tree: how to choose](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree) - [Root cause analysis: definition and meaning](https://incidentkit.ai/glossary/root-cause-analysis) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) --- # How to switch from legacy incident software > Switch in five moves. Confirm export rights. Export everything, including attachments and audit history. Map old categories to a shorter list. Run both systems 30 to 60 days, then make the old one read-only. Keep records as long as rules require, such as 5 years for OSHA logs. Source: https://incidentkit.ai/use-cases/switch-from-legacy-incident-software · Updated Oct 5, 2026 For: Risk or quality leader with an old incident system and a renewal date coming ## Can you switch without losing history? Yes, if you secure the export before your notice date. OSHA wants the 300 log, annual summary and 301 reports kept 5 years after the year they cover (29 CFR 1904.33). ASC surveyors ask for 6 months of surgeries and a year of transfers and deaths. QAPI expects adverse events tracked over time. As a rule of thumb, start at least 90 days before the contract ends. ## What to export Export everything in this table, then check it. | Data | Why it matters | Ask your vendor for | | --- | --- | --- | | Incident records, all fields | Core history | Full export | | People, roles, locations | Right unit and site | User and location lists | | Investigations and notes | Proof of analysis | Investigation fields | | Corrective actions, evidence | Proof of fixes | Action records, files | | Attachments: photos, statements, PDFs | Evidence | Bulk files by record ID | | Audit and change history | Who changed what | Audit log export | | Forms, categories, routing rules | Rebuild your setup | Configuration documents | | State reports and OSHA logs | Retention duties | Copies of all filed | Exports usually arrive as spreadsheets plus a folder of files. Check the record ID appears in both. If rules cannot be exported, photograph each screen. ### Check the export before you rely on it - Compare yearly totals by incident type with the old reports. - Open ten records with attachments and compare to the screen. - Check dates and times for time zone shifts. - Check names and notes for broken characters. - Confirm the audit history shows who changed what. ## Check the contract before you give notice Check these points before you give notice. - Your right to export, the format, any fee. - The notice period and any automatic renewal. - Access after the contract ends. - When the vendor deletes your data, and whether it certifies deletion. - For healthcare, the business associate agreement and patient information at the end. - Whether the vendor will run a test export first. ## An example plan for one site One site can move in about 12 weeks. *A suggestion, not a promise.* | When | What happens | | --- | --- | | Weeks 1 to 2 | Confirm export rights. Request the export. List forms, rules, users, integrations. | | Weeks 3 to 4 | Check a sample. Map old categories to incident types. | | Weeks 5 to 6 | Set up forms, routing, roles. Import history. Train users. | | Weeks 7 to 12 | Go live. Run both systems. Reconcile weekly. | | After | Go read-only. Keep a verified archive. | ## Run both systems in parallel Run both for 30 to 60 days. Reconcile weekly. 1. **Pick a go-live date** Use the first of a month or quarter. 2. **New events go in the new system only** From go-live, nobody files in the old one. 3. **Decide the rule for open cases** Finish them in the old system, or import and close them in the new. Pick one. 4. **Reconcile weekly** Compare counts by type for 30 to 60 days. Check every difference. 5. **Brief staff once** One page: which system, where QR codes point, who to ask. 6. **Retire the old system to read-only** After two clean weeks, make it read-only. Keep a verified archive. ## Import and done-for-you migration Import brings history into IncidentKit, so trends span the cutover. Mapping starts from a pack, which sets incident types, forms, regulator exports and roles for a site type. See [import and migration](https://incidentkit.ai/product/import-and-migration). Old categories become fewer incident types. These examples are invented. | Old categories | Mapped to | | --- | --- | | Fall: witnessed, Fall: unwitnessed, Fall: no injury | One fall type with fields for witnessed, injury, location | | Med error: wrong dose, Med error: omission, Med error: wrong time | One medication error type; error kind is a field | | Misc, Other, Unknown | Reviewed, not carried forward | Regulated plans include done-for-you setup. Network plans, for groups of 10 or more sites, include migration. IncidentKit runs alongside your EHR, CMMS and HRIS; deeper integrations are rolling out. ## Mistakes to avoid These habits cause most migration problems. - Retyping open cases. Import them or finish them in place. - Carrying over 200 categories. Map to a short list first. - Exporting without attachments or audit history. - Switching off the old system before counts match. - Letting the contract end date set the schedule. - Forgetting QR codes and email addresses for intake. - Skipping integrations such as HR feeds or work order links. ## Before and after - **Before:** Nobody knows how to get the data out. **After:** You ask for a full export in writing, then check it. - **Before:** Hundreds of categories mean miscoded reports and noisy trends. **After:** History imports into cleaner incident types, so trends carry across. - **Before:** The renewal arrives before anyone checks export rights. **After:** Old and new systems run side by side until counts match. - **Before:** Fear of losing history keeps you on an old tool. **After:** Regulated plans get done-for-you setup; Network plans get migration. ## Frequently asked questions ### How long does it take to switch incident reporting software? Weeks, not days. Do export and mapping first, then a 30 to 60 day parallel run per site. Ask any vendor for a written plan and named owners. ### Do I need to import old incidents at all? Not always. If you only need an archive, keep a verified read-only export as long as rules require. Import the period you trend and survey against, and archive the rest. ### Can we keep using our EHR, CMMS or HRIS? Yes. IncidentKit runs alongside them and does not replace them. Deeper EHR, CMMS and HRIS integrations are rolling out; see [integrations and API](https://incidentkit.ai/product/integrations-and-api) for what is live. ### What does done-for-you migration include? Regulated plans include done-for-you setup. Network plans, for 10 or more sites, include migration. Ask for the scope in writing. ## Sources - [OSHA: 29 CFR 1904.33, retention and updating](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.33) - [CMS: State Operations Manual Appendix L, entrance conference requests for ASCs](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_l_ambulatory.pdf) - [CMS: State Operations Manual Appendix PP, F867 adverse event tracking (42 CFR 483.75(c)(4), (e)(2))](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [eCFR: 42 CFR 416.43, ASC QAPI](https://www.ecfr.gov/current/title-42/section-416.43) ## Related - [Migrate incident data from paper, Excel or legacy software](https://incidentkit.ai/product/import-and-migration) - [Incident reporting software alternatives](https://incidentkit.ai/alternatives) - [Compare incident reporting software: the full matrix](https://incidentkit.ai/compare) - [Incident management software buyer's guide: how to choose](https://incidentkit.ai/guides/incident-management-software-buyers-guide) - [Multi-site incident reporting software for groups](https://incidentkit.ai/solutions/multi-site-groups) - [Incident reporting software pricing: free to start](https://incidentkit.ai/pricing) --- # Contractor and visitor incidents: who reports and records what > Sort a non-employee incident by who was hurt and who supervised the work. OSHA logs cover employees and workers you supervise day to day. An injured visitor never goes on the 300 log. Patient-safety events go to QAPI. Premises claims go to your carrier. One incident can be all three. Source: https://incidentkit.ai/use-cases/contractor-and-visitor-incidents · Updated Oct 5, 2026 For: Administrator or risk manager responsible for sites with contractors, temps and visitors ## Who records a contractor, temp or visitor injury? The employer that supervises the worker day to day. You record your own employees and workers you supervise, once, on your log or the other employer's (29 CFR 1904.31). An injured visitor is not an OSHA log entry. Day-to-day supervision means control over the details, means, methods and processes of the work. That employer also reports a death, in-patient hospitalization, amputation or loss of an eye (OSHA FAQ 39-9). ## Where each person's incident goes The table shows where each case lands. | Person | OSHA log and reports | Patient safety and QAPI | Liability and premises | | --- | --- | --- | --- | | Your employee | Your 300 log | If a patient was involved | Workers' compensation | | Temp you supervise day to day | Your log | If care was involved | Agency contract | | Contractor's worker, directed by contractor | Contractor's log | If a patient was affected | Contract, insurance | | Visitor or family member | None | Only if a patient was involved | Tell your carrier | | Patient hurt by contractor's work | None for the patient | Yes, adverse event | Maybe, with the contractor | ## Three questions for every incident Ask three questions in order. Who is the person? What harm resulted? Who controlled the hazard? OSHA's multi-employer policy names four roles: creating, exposing, correcting and controlling. A host or controlling employer can be cited for not taking reasonable care to find and fix hazards. That duty is lighter than for its own staff. CMS counts contractors, volunteers and per diem staff as staff for training. The nursing home crime-reporting rule covers contractors. *Examples of the supervision test, not legal advice.* | Scenario | Who records and reports | What you still do | | --- | --- | --- | | A contractor's electrician, supervised by the contractor, falls from a ladder in your building | The contractor, who supervises | Document it, check your hazard, tell your carrier | | An agency nurse, directed by your charge nurse, is hurt by a patient | You, if you control how the work is done | Treat as a staff injury; agree process with agency | | A visitor slips on a wet floor and fractures a wrist | No OSHA entry or report | Tell your carrier, fix the hazard, brief the safety committee | | A delivery driver is hurt on your loading dock | Usually the driver's firm | Document it; check your dock for hazards | ## What to log for every non-employee incident Log these six things every time. 1. **Who** Name, employer, role, contact. For a contractor, add the supervising employer and site contact. 2. **What and where** Task and exact location. 3. **Who supervised, who controlled the area** These answers decide the OSHA and multi-employer questions. 4. **Harm and care** Harm, care given, any admission. 5. **Notifications** Contractor's firm, your carrier, any agency, with times. 6. **Follow-up owner** Who checks your hazard, and who owns any contractor action. ### Visitors and temporary staff For a visitor, record name, contact, whether they came with a patient, the harm, witnesses and the condition behind it. Offer first aid. Say nothing about fault. Settle in writing with the staffing agency who directs the work day to day. OSHA looks at control, not the contract label. ## Contracts and liability Settle reporting duties in the contract before work starts. > **Not legal advice** Ask your counsel and carrier how these points apply to you. - Set reporting speed and contacts in contractor agreements. - Keep insurance certificates on file. - Read your liability policy's notice terms and meet them. - Keep evidence, such as photos and camera footage, until resolved. - Agree who investigates what before a contractor starts work. - Give each contractor a one-page orientation: how to report, emergency numbers, who to tell. ## Mistakes to avoid These habits leave incidents unreported or unowned. - Entering a visitor on the OSHA 300 log. - Assuming the contractor will tell you. - Using a form that demands an employee ID. - Assigning corrective actions to a contractor with no contract term. - Treating visitor falls as claims only. They show hazards patients share. ## How IncidentKit changes the job One intake covers employees, contractors, visitors and patients, by [QR codes](https://incidentkit.ai/product/quick-report), [email-to-incident](https://incidentkit.ai/product/email-to-incident) or web form. [Lauren](https://incidentkit.ai/product/lauren) asks who the person is and who supervised. A person reviews and signs. [Routing](https://incidentkit.ai/product/routing-and-escalation) sends each case to the right owners. [Roles and facilities](https://incidentkit.ai/product/multi-site-and-roles) limit who sees patient information. The Open plan is free for incidents without it. Patient information needs the Regulated plan, which includes a business associate agreement (BAA). ## Before and after - **Before:** Visitor and contractor incidents get another form, or none. **After:** One intake covers everyone and asks who supervised. - **Before:** Nobody knows whose OSHA log applies. **After:** Routing sends each case to the right owners. - **Before:** The contractor's firm hears days later. **After:** Telling the contractor's firm is a logged task. - **Before:** A visitor's fall misses the safety committee. **After:** Visitor events feed the same trends by place. ## Frequently asked questions ### Does a contractor's injury go on my OSHA 300 log? Only if you supervise that worker day to day. Otherwise the contractor's employer records it, once only (29 CFR 1904.31). ### Do I have to report a visitor's injury to OSHA? No. OSHA's rules in 29 CFR Part 1904 cover employees. An injured visitor can still involve your carrier, state license rules and safety committee. ### Is a visitor's fall a patient-safety event? Not by itself, since QAPI tracks patients. But a visitor's fall can show a hazard patients share, such as a wet floor. Record it and trend it by location. ### Who investigates a contractor injury at my facility? Best case: both firms work it together. The contractor's firm handles its own incident and OSHA duties. You investigate the hazard you control. ## Sources - [OSHA: 29 CFR 1904.31, covered employees](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.31) - [OSHA: Recordkeeping FAQ 31-1, meaning of supervised](https://www.osha.gov/faq/31-1) - [OSHA: Recordkeeping FAQ 39-9, who reports for a temporary worker](https://www.osha.gov/faq/39-9) - [OSHA: CPL 2-0.124, Multi-Employer Citation Policy](https://www.osha.gov/enforcement/directives/cpl-02-00-124) - [CMS: QSO-23-04-Hospitals, workplace violence memo, November 28, 2022](https://www.cms.gov/files/document/qso-23-04-hospitals.pdf) - [CMS: State Operations Manual Appendix PP, F609 covered individuals](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) ## Related - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) - [Fall Reporting: What to Record and Review After a Fall](https://incidentkit.ai/use-cases/fall-reporting) - [Incident reporting software for facility administrators](https://incidentkit.ai/solutions/facility-administrators) - [Construction incident reporting for job sites and subs](https://incidentkit.ai/solutions/construction) --- # How to set up workplace violence reporting > Report every act or threat of workplace violence, even with no injury, because most programs see only part of it. OSHA has no violence standard and uses its General Duty Clause. Accredited hospitals face Joint Commission rules. Use one short report, protect the reporter, review monthly. Source: https://incidentkit.ai/use-cases/workplace-violence-reporting · Updated Oct 5, 2026 For: Safety, security or nurse leader building a violence reporting process ## What counts as workplace violence? OSHA defines it as any act or threat of physical violence, harassment, intimidation or other threatening behavior at work. It runs from verbal abuse to assault and can involve employees, clients, customers and visitors. Ask staff to report all of it, including close calls such as a thrown object that missed. Record the first account in the reporter's own words. ## Why violence goes unreported, and the fixes OSHA and GAO (2016) say healthcare violence goes underreported. BLS counted healthcare and social assistance as 73 percent of nonfatal violence cases in 2018. Its rate was 10.4 per 10,000 full-time workers against 2.1 for all private industry, on days-away cases only. | Barrier or mistake | What fixes it | | --- | --- | | Seen as part of the job | Say all acts and threats count, from anyone | | Reporting takes too long | Short report by text or QR code first | | Nothing happens afterward | A named owner and a reply | | Fear of blame | Ask about the setting, not the worker | | Patient behavior excused as illness | Report anyway, so care plans and staffing can change | | Few reports read as proof of safety | Treat low counts as a question, not an answer | ## What to capture Capture these in a short first report. | Field | Why it matters | | --- | --- | | Role: patient, resident, visitor, customer, co-worker | Sets the response path | | Type: physical, threat, verbal, sexual, weapon | Shows severity | | Where, when, what staff were doing | Finds hot spots | | Trigger, warning signs, earlier alert | OSHA's retail form asks about earlier threats | | Staffing at the time | Shows if coverage mattered | | Injury, care given, time lost | Feeds the recordability check | | Security or police response, support offered | Shows follow-up happened | ### A simple severity scale to adapt | Tier | Example | Response | | --- | --- | --- | | 1 | Threat or verbal abuse, no contact | Report; review monthly | | 2 | Physical contact, no injury | Same-day manager review and support | | 3 | Injury needing treatment | Recordable? Investigate. | | 4 | Serious injury, weapon or sexual assault | Security or police now, leaders told, OSHA 24-hour check | ## After an incident, in order Five steps, in this order. 1. **Make people safe** Separate, call for help, secure the area. 2. **Care and support** Medical care first, then support and counseling for victim and witnesses. 3. **Report and preserve** Report the same shift. Keep footage, notes and any weapon or object. 4. **Check OSHA** Is it work-related and recordable? OSHA has no general exception for violence. Sexual assault is a privacy concern case: keep the name off the log. 5. **Investigate and fix** Fix the setting and process, not just reminders. Report patterns to the safety committee or governing body. ## What OSHA, the Joint Commission and CMS ask OSHA has no standard, but hospitals face clear expectations. | Source | What it asks | Who | | --- | --- | --- | | OSHA General Duty Clause | No violence standard. Keep work free of recognized hazards | All employers | | Joint Commission LD.03.01.01 EP 9 | Designated leader, incident analysis, victim support, governing body reports | Accredited and critical access hospitals, from January 1, 2022 | | Joint Commission EC.02.01.01 EP 17 | Annual worksite analysis that includes investigating violence | Same | | Joint Commission EC.04.01.01 EP 1 and EP 6 | Track and investigate safety and security incidents, violence included | Same | | Joint Commission HR.01.05.03 EP 29 | Training that covers reporting | Same | | CMS QSO-23-04-Hospitals | Assess patients for risk of harm to others; train staff. CMS recommends refreshers at least every two years | Hospitals | Check your state and accreditor too. ## Retail and industrial sites OSHA names higher-risk work: working alone or in isolated areas, handling money with the public, and high-crime areas. For late-night retail, require reports of all assaults and threats and keep logs. OSHA's retail controls include drop safes with limited-cash signs, ties with local police, and training in conflict resolution and nonviolent response. Plants and warehouses see co-worker and outsider threats; route to HR and security. Assaults go on the OSHA 300 log if they qualify. ## How IncidentKit changes the job Staff report by text or [QR code](https://incidentkit.ai/product/quick-report). [Lauren](https://incidentkit.ai/product/lauren) asks the follow-up questions, then drafts the form. A person reviews and signs. [Routing](https://incidentkit.ai/product/routing-and-escalation) sends it to security, the manager and the safety lead. [Analytics](https://incidentkit.ai/product/analytics) show hot spots by location, shift and cause. [Corrective actions](https://incidentkit.ai/product/corrective-actions) carry an owner, due date and evidence. Industrial packs and OSHA exports are rolling out. ## Before and after - **Before:** Staff treat violence as part of the job. **After:** A short text or QR code report takes minutes. - **Before:** Reports go to security, HR or a supervisor's notebook. **After:** One record routes every report to the right people. - **Before:** Nobody knows which units or shifts have the most incidents. **After:** Patterns by place, shift and trigger show where to act. - **Before:** Reporters hear nothing back, or get blamed. **After:** Each report gets an owner and a reply. ## Frequently asked questions ### Is there an OSHA standard for workplace violence? No specific one. OSHA enforces through the General Duty Clause and publishes guidance. Some states and accreditors add rules. ### Is workplace violence recordable on the OSHA 300 log? Yes, when the injury is work-related and meets the recording criteria. OSHA has no general exception for violence. A threat with no injury is not recordable. ### What does the Joint Commission require for workplace violence? Since January 1, 2022, accredited and critical access hospitals need a violence prevention program. It needs a designated leader and team, incident analysis, victim and witness support, and governing body reports (LD.03.01.01 EP 9). ### Should staff report violence from patients who cannot control their behavior? Yes. Excusing it removes the data needed to protect staff and adjust care. CMS expects training, enough staff and ongoing assessment of patients for aggressive behavior. Report the behavior, trigger and what helped. ## Sources - [OSHA: Workplace violence](https://www.osha.gov/workplace-violence) - [OSHA: Workplace violence in healthcare](https://www.osha.gov/healthcare/workplace-violence) - [OSHA 3153: Recommendations for workplace violence prevention programs in late-night retail establishments (2009)](https://www.osha.gov/sites/default/files/publications/OSHA3153.pdf) - [OSHA: Recordkeeping FAQ 5-2, workplace violence and work-relatedness](https://www.osha.gov/faq/5-2) - [BLS: Workplace violence in healthcare, 2018](https://www.bls.gov/iif/factsheets/workplace-violence-healthcare-2018.htm) - [GAO-16-11: Additional efforts needed to help protect health care workers from workplace violence](https://www.gao.gov/products/gao-16-11) - [The Joint Commission: Workplace violence prevention resource compendium for hospitals](https://digitalassets.jointcommission.org/api/public/content/ebf48f21371341808e962e09dd363dbd) - [CMS: QSO-23-04-Hospitals, workplace violence, November 28, 2022](https://www.cms.gov/files/document/qso-23-04-hospitals.pdf) ## Related - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [Injury reporting and retaliation: 29 CFR 1904.35 and 11(c)](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) - [Incident reporting software for behavioral health](https://incidentkit.ai/solutions/behavioral-health) - [Patient safety event reporting software for hospitals](https://incidentkit.ai/solutions/hospitals) --- # CMS QAPI requirements by facility type > What 42 CFR requires of surgery centers, nursing homes, hospitals, hospice and home health for quality assessment and performance improvement. Source: https://incidentkit.ai/compliance/cms-qapi QAPI is the quality program CMS requires of most providers, and the rule differs by facility type. - [What 42 CFR 416.43 requires of an ASC's QAPI program](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers): What 42 CFR 416.43 requires of an ASC's quality program, what surveyors ask to see, and how incident data and corrective actions feed it. - [Nursing home QAPI and the QAA committee under 42 CFR 483.75](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities): How 42 CFR 483.75 shapes a nursing home's QAPI plan and QAA committee: the five elements, what F865, F867 and F868 test, and what to show surveyors. - [Hospital QAPI under 42 CFR 482.21: what surveyors check](https://incidentkit.ai/compliance/cms-qapi/hospitals): What 42 CFR 482.21 requires of a hospital QAPI program, who is accountable, what surveyors sample, and how adverse event data and actions fit. - [Hospice QAPI under 42 CFR 418.58: requirements and evidence](https://incidentkit.ai/compliance/cms-qapi/hospice): What 42 CFR 418.58 requires of a hospice QAPI program, how to define and track adverse events, what surveyors review, and how incident data fits. - [Home health QAPI under 42 CFR 484.65: what an HHA must show](https://incidentkit.ai/compliance/cms-qapi/home-health): What 42 CFR 484.65 requires of a home health agency QAPI program: indicators and OASIS data, adverse events, projects, and what surveyors ask to see. --- # Healthcare accreditation: AAAHC, Joint Commission > How the major accreditors work, how they relate to CMS deemed status, and what they expect from your incident and quality program. Source: https://incidentkit.ai/compliance/accreditation Some accreditors can stand in for a state survey under CMS deemed status, and each works differently. - [AAAHC accreditation: what ASCs and ambulatory practices should know](https://incidentkit.ai/compliance/accreditation/aaahc): How AAAHC accreditation works for ASCs and ambulatory practices: Medicare deemed status, survey types, notice rules and the six-component QI study. - [Joint Commission accreditation: surveys, sentinel events and safety goals](https://incidentkit.ai/compliance/accreditation/joint-commission): How Joint Commission accreditation works: Medicare deemed status, unannounced surveys, tracers, the Sentinel Event Policy and the 2026 hospital goals. - [CIHQ accreditation: what hospitals and critical access hospitals should know](https://incidentkit.ai/compliance/accreditation/cihq): How CIHQ accreditation works for hospitals and critical access hospitals: CMS deemed status, three-year surveys and what CIHQ says it does not require. - [ACHC accreditation: programs, surveys and documentation](https://incidentkit.ai/compliance/accreditation/achc): How ACHC accreditation works for home health, hospice, ASCs and hospitals: CMS deemed status, unannounced surveys, timelines and what to keep on file. - [Quad A accreditation: surveys, standards and Patient Safety Data Reporting](https://incidentkit.ai/compliance/accreditation/quad-a): How Quad A accreditation works for office-based surgery and Medicare ASCs: three-year surveys, yearly self-surveys and quarterly safety data reports. - [DNV accreditation: CMS-approved programs, surveys and documentation](https://incidentkit.ai/compliance/accreditation/dnv): How DNV accreditation relates to CMS deemed status for hospitals, critical access hospitals and ASCs, what CMS checks, and what documentation to keep. - [CARF accreditation: what providers should know](https://incidentkit.ai/compliance/accreditation/carf): How CARF accreditation works for behavioral health, aging services and rehabilitation providers: announced peer surveys, the QIP and annual reporting. --- # Nursing home F-tags: what each one means > Plain-language guides to the F-tags that incident reporting touches most: falls, abuse reporting, medication errors, infection control and QAPI. Source: https://incidentkit.ai/compliance/f-tags F-tags are CMS's numbered nursing home rules; these guides cover the ones incidents trigger, and the evidence you need. - [F689: free of accident hazards, supervision and devices](https://incidentkit.ai/compliance/f-tags/f689): F689 is the CMS nursing home tag for falls, hazards and supervision (42 CFR 483.25(d)). See what surveyors ask for, how severity is set and what to record. - [F600: free from abuse and neglect](https://incidentkit.ai/compliance/f-tags/f600): F600 is the CMS nursing home abuse and neglect tag under 42 CFR 483.12(a)(1). See what it covers, which records surveyors review and how severity is set. - [F609: reporting of alleged violations](https://incidentkit.ai/compliance/f-tags/f609): F609 sets nursing home reporting clocks for abuse, neglect and suspected crimes (42 CFR 483.12): 2 hours, 24 hours and 5 working days. See what to keep. - [F610: investigate, prevent and correct alleged violations](https://incidentkit.ai/compliance/f-tags/f610): F610 says nursing homes must investigate every abuse or neglect allegation, protect residents meanwhile and fix problems. See the clock and the evidence. - [F684: quality of care](https://incidentkit.ai/compliance/f-tags/f684): F684 is the CMS catch-all quality of care tag for nursing homes (42 CFR 483.25). See what it covers, how avoidable decline is judged, what to have ready. - [F760: residents are free of significant medication errors](https://incidentkit.ai/compliance/f-tags/f760): F760 says nursing home residents must be free of significant medication errors (42 CFR 483.45(f)(2)). See how significance is judged and what to keep. - [F880: infection prevention and control](https://incidentkit.ai/compliance/f-tags/f880): F880 is the most cited nursing home tag. See what 42 CFR 483.80 requires, what surveyors check, how severity is set and how to record incidents. - [F865: QAPI program and plan](https://incidentkit.ai/compliance/f-tags/f865): F865 requires a nursing home QAPI program and plan (42 CFR 483.75). See what surveyors ask for, what is protected from disclosure and the good faith rule. - [F867: QAPI/QAA improvement activities](https://incidentkit.ai/compliance/f-tags/f867): F867 requires nursing homes to track adverse events, find root causes, act on data and run an annual project (42 CFR 483.75(c)-(e)). See what to show. - [F868: the QAA committee](https://incidentkit.ai/compliance/f-tags/f868): F868 sets who must sit on a nursing home QAA committee and how often it meets (42 CFR 483.75(g), 483.80(c)). See the roster rules and what proof to keep. --- # Incident reporting deadlines and obligations > The clocks that matter: abuse and neglect reporting, sentinel events, ASC quality reporting, device adverse events and state reporting. Source: https://incidentkit.ai/compliance/reporting-deadlines Some incidents start a clock; these pages say which ones, who must be told, and by when. - [Nursing home abuse and neglect reporting requirements](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting): Federal nursing home rules set a 2-hour or 24-hour clock to report abuse, neglect and suspected crimes, then 5 working days for investigation results. - [Joint Commission sentinel event policy: what to do and by when](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events): What the Joint Commission counts as a sentinel event, which events are reviewable, and the 45-business-day expectation for the analysis and action plan. - [ASC Quality Reporting Program (ASCQR): measures, deadlines and penalty](https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting): The ASC Quality Reporting Program cuts the Medicare payment update by 2.0 percentage points for non-reporting. See the 2026 measures and key deadlines. - [FDA medical device reporting for user facilities](https://incidentkit.ai/compliance/reporting-deadlines/device-adverse-event-reporting): Hospitals, ASCs and nursing homes must report device-related deaths and serious injuries within 10 work days and file an annual report by January 1. - [State adverse event and incident reporting: a verified overview](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview): A careful overview of state adverse event reporting in Pennsylvania, New York, Minnesota and Florida, and how to confirm your own state's rules. --- # OSHA recordkeeping and workplace injury reporting > OSHA 300, 301 and 300A forms, recordability, severe injury reporting, lockout/tagout, hazard communication, process safety and injury rates. Source: https://incidentkit.ai/compliance/osha Employers with more than ten employees keep injury records and report the most serious events within hours. - [OSHA recordkeeping: who keeps records, and what counts](https://incidentkit.ai/compliance/osha/recordkeeping-overview): Who must keep OSHA injury and illness records under 29 CFR Part 1904, who is partially exempt by size or industry, and what makes a case recordable. - [OSHA Form 300: the Log of Work-Related Injuries and Illnesses](https://incidentkit.ai/compliance/osha/osha-300-log): How to complete the OSHA Form 300 Log of Work-Related Injuries and Illnesses: one line per case, classification, privacy cases, day counts and updates. - [OSHA Form 301: the Injury and Illness Incident Report](https://incidentkit.ai/compliance/osha/osha-301-incident-report): What OSHA Form 301 asks, when it is due, which equivalent forms are accepted, and who is entitled to a copy of the injury and illness incident report. - [OSHA Form 300A: the annual Summary of Work-Related Injuries and Illnesses](https://incidentkit.ai/compliance/osha/osha-300a-summary): How to complete, certify and post the OSHA Form 300A summary: the February 1 to April 30 posting window, who may sign, hours worked and zero-case years. - [Recordable vs first aid: where OSHA draws the medical treatment line](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid): OSHA's first aid list is closed, and anything beyond it is medical treatment. See the list, the treatment line and worked examples of recordable cases. - [Reporting fatalities and severe injuries to OSHA (29 CFR 1904.39)](https://incidentkit.ai/compliance/osha/severe-injury-reporting): When and how to report a work-related death, in-patient hospitalization, amputation or loss of an eye to OSHA under 29 CFR 1904.39, with edge cases. - [Lockout/tagout (29 CFR 1910.147): the program and what to capture after an event](https://incidentkit.ai/compliance/osha/lockout-tagout): What a lockout/tagout program must include under 29 CFR 1910.147, how the annual inspection works, and what to capture after a hazardous energy event. - [Hazard communication (29 CFR 1910.1200): SDS, labels, training and incident records](https://incidentkit.ai/compliance/osha/hazard-communication): What OSHA's Hazard Communication Standard requires: written program, labels, safety data sheets and training, the 2026 to 2028 dates, and exposure records. - [Process safety incident investigation (29 CFR 1910.119(m))](https://incidentkit.ai/compliance/osha/process-safety-incident-investigation): What 29 CFR 1910.119(m) requires: which incidents, the 48-hour start, the team, report contents, documented resolution and five-year retention. - [Employee injury reporting and retaliation: 29 CFR 1904.35 and OSH Act section 11(c)](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation): What OSHA requires of an injury reporting system under 1904.35, what Section 11(c) bans, and how incentive programs and drug testing are treated. - [TRIR and DART rates: how to calculate them and what BLS 2024 national rates show](https://incidentkit.ai/compliance/osha/trir-and-dart-rates): How to calculate TRIR and DART with the 200,000-hour base, a worked example, and the BLS 2024 national incidence rates by industry, released January 2026. - [OSHA electronic submission (29 CFR 1904.41): who submits what, and when](https://incidentkit.ai/compliance/osha/electronic-submission): Who must send OSHA Forms 300A, 300 and 301 online, the March 2 deadline, size and industry thresholds, and how the Injury Tracking Application works. - [Construction recordkeeping: how OSHA Part 1904 applies to job sites and subcontractors](https://incidentkit.ai/compliance/osha/construction-recordkeeping): How 29 CFR Part 1904 applies to construction: job-site establishments, one log or many, subcontractors, work-zone reporting and electronic submission. --- # Survey readiness: be ready every day > How to prepare for surgery center, nursing home and Joint Commission surveys, and how to write a plan of correction that surveyors accept. Source: https://incidentkit.ai/compliance/survey-readiness The best survey prep never stops; these pages cover what surveys look like and the evidence to keep ready. - [ASC survey readiness: how to be ready every day](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness): How CMS, state and accreditor surveys of surgery centers work, what surveyors request on day one, and a checklist to stay ready every day. - [Nursing home recertification survey: what happens and what to have ready](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey): How CMS's standard health survey of a nursing home works, what incident and QAPI records surveyors request, and the new risk-based survey option. - [Plan of correction: what CMS requires and how to write one that is accepted](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction): How to answer a CMS-2567: the 10-calendar-day deadline, the five elements of an acceptable nursing home plan, ASC requirements and how to write one. - [Joint Commission survey readiness: unannounced surveys and tracers](https://incidentkit.ai/compliance/survey-readiness/joint-commission-survey-readiness): How Joint Commission surveys work: unannounced timing, tracer methodology, what changed under Accreditation 360 in 2026, and how to stay ready all year. --- # What 42 CFR 416.43 requires of an ASC's QAPI program > An ASC must run QAPI, the quality program CMS requires. It tracks quality indicators, adverse patient events and infection control, finds causes and proves fixes last. The governing body owns it. Incident reports feed it, and corrective actions prove it. Source: https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers · Updated Oct 5, 2026 ## Key facts - **Rule:** 42 CFR 416.43, condition for coverage - **Survey guidance:** State Operations Manual Appendix L, tags Q-0080 to Q-0084 - **Who owns it:** The governing body (42 CFR 416.41 and 416.43(e)) - **Projects:** At least one improvement project a year, more for larger ASCs - **Infection control:** Must be an integral part of QAPI (416.51(b)(2)) - **Survey type:** All ASC surveys are unannounced - **State survey interval:** No more than 6 years for non-deemed ASCs (CMS FY2027 priorities) - **Citation:** 42 CFR 416.43 - **Authority:** CMS - **Applies to:** Medicare-certified ambulatory surgery centers surveyed by a state agency, Deemed ASCs accredited by a CMS-approved accrediting organization ## What does 42 CFR 416.43 require? Measure what happens, find out why, fix it and prove the fix held. This is a condition for coverage, a rule an ASC must meet to be paid by Medicare. It has five standards. *42 CFR 416.43 in plain language* | Standard | What it asks for | | --- | --- | | (a) Program scope | Show gains in outcomes and patient safety. Measure, analyze and track quality indicators, adverse patient events, infection control and other performance. | | (b) Program data | Use quality and patient care data to check that care works and is safe, and to find what to change. | | (c) Program activities | Set priorities in high-risk, high-volume and problem-prone areas. Track adverse patient events, find causes, improve and keep the gains. Use preventive strategies facility-wide so all staff know them. | | (d) Improvement projects | Run projects that fit the ASC's size and complexity. Record why each was done and what resulted. | | (e) Governing body | Define and maintain the program. Set what data to collect and how often. Set safety goals, evaluate every improvement, and fund staff, time, information systems and training. | Also see 42 CFR 416.41 and 42 CFR 416.51(b)(2). The first makes the governing body accountable for QAPI. The second makes infection control an integral part of it. ## Who does what in ASC QAPI? The governing body owns the program. Others feed it or act on it. - **Governing body:** defines the program and picks the data and how often to collect it. It sets safety goals and reviews results. - **QAPI lead and analysts:** collect data and study causes. CMS expects them to be qualified. A contractor may help, but leaders stay responsible. - **Clinical and support staff:** report events and near misses. They know the preventive strategies, such as wrong-site and wrong-patient safeguards and safe injection practices. - **Infection control professional:** runs the infection program, which feeds QAPI. ## What do surveyors look for? Surveyors ask one thing. Does the ASC have an effective, ongoing system to find problems, act and check the result? They do not judge whether problems occurred. CMS guidance: State Operations Manual Appendix L, tags Q-0080 to Q-0084. All ASC surveys are unannounced. - Leaders describe the program, who runs it and what indicators it tracks. - At a minimum, indicators include hospital transfers, surgical and infection control measures, and a way to track adverse patient events. - Who studies the data, and whether they find root causes. - A case where QAPI data led to a change, and proof it worked and lasted. - How staff are trained to prevent adverse events. > **Your own QAPI data** CMS says surveyors generally should not use an ASC's own QAPI data to prove violations of other conditions. It keeps that for egregious (the most serious) cases. ## What should an ASC show? - The written program and the governing body minutes that created it - Indicators, why each was chosen, and how often data is collected - Dated data and analyses at regular intervals - A log of adverse patient events and near misses, with analysis and action for each - Hospital transfers and how each was reviewed - Project records: why each ran and what resulted - Training records for the preventive strategies - Proof that planned staff, time and systems were provided ## Where do ASCs fall short? CMS's own examples show these patterns. - **Analysis stops at a person.** A drug error review that ends with who gave the drug is not a systems approach. Check storage, order clarity and training first. - **Indicators that do not measure care.** Billing speed says nothing about patient outcomes. - **A one-time effort.** Data collected once, with no regular intervals or re-measuring. - **A fix in one room only.** After an event tied to emergency drug storage, check every room. - **No proof it lasted.** For hand hygiene, show ongoing data, not one audit. - **Projects with no reason or result.** Both are required. ## How do incident reports feed QAPI? Incident reports feed 416.43(c)(2): track adverse patient events, examine causes, improve and keep the gains. CMS also expects near misses to be found. 1. **Capture every event and near miss** Caught wrong-site errors, medication errors, falls, burns, unplanned transfers and infections all count. [IncidentKit intake](https://incidentkit.ai/product/incident-reporting) takes reports by text, QR code, email or web form. 2. **Investigate for system causes** Record contributing factors and the five whys, not a name. Lauren drafts each [investigation](https://incidentkit.ai/product/investigations). A person reviews, edits and signs. 3. **Fix it everywhere and train** Each [corrective action](https://incidentkit.ai/product/corrective-actions) has an owner, due date and evidence. Nothing closes until it is verified. 4. **Re-measure and report** [Analytics](https://incidentkit.ai/product/analytics) show whether the cluster went away. A [compliance packet](https://incidentkit.ai/product/compliance-packets) gives the governing body a QAPI summary. Infection surveillance and patient experience data come from your other systems. IncidentKit runs alongside them. ## How often is an ASC surveyed? CMS's fiscal year 2027 priorities ask states to allow no more than six years between surveys of any non-deemed ASC. That is an ASC the state surveys, not an accreditor. They also set targeted surveys of 25 percent of non-deemed ASCs in each state. They favor those not surveyed in over four years. An ASC can use a CMS-approved accreditor instead and be deemed compliant: [AAAHC](https://incidentkit.ai/compliance/accreditation/aaahc), the [Joint Commission](https://incidentkit.ai/compliance/accreditation/joint-commission), [Quad A](https://incidentkit.ai/compliance/accreditation/quad-a), [ACHC](https://incidentkit.ai/compliance/accreditation/achc) or [DNV](https://incidentkit.ai/compliance/accreditation/dnv). They must cover 416.43. When CMS approved DNV's ASC program, it required DNV to revise its standards. The revision covers tracking adverse patient events and staff awareness of preventive strategies. The [ASC Quality Reporting Program](https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting) is separate. Not reporting under it cuts the annual payment update by 2.0 percentage points. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | 416.43(a)(2), (c)(2): measure, analyze and track adverse patient events | Intake by text, QR code, email or web form, plus routing. Analytics cluster events by cause. | | 416.43(c)(2): examine causes | Investigations record contributing factors and five whys. Lauren drafts. A person reviews and signs. Human-authored RCA templates are rolling out. | | 416.43(c)(2), (e)(2): implement improvements, sustain them and evaluate effectiveness | Corrective actions with owner, due date, evidence and an effectiveness check. Nothing closes until verified. | | 416.43(c)(3): preventive strategies facility-wide, known to all staff | Each action has an owner, due date and evidence, such as a training sign-off. | | 416.43(d): document each project's reason and results | Analytics trends and closed actions go into a compliance packet. Project charters stay in your QAPI documents. | | 416.43(e): governing body oversight | A compliance packet gives the governing body a QAPI summary. The audit trail logs every change. Minutes stay yours. | ## Frequently asked questions ### Does an ASC need a written QAPI plan? The rule does not say plan, but CMS guidance says the program should be defined in writing. Governing body minutes can serve. CMS sets no template, committee or indicator list. ### How many improvement projects must an ASC complete each year? At least one. CMS guidance says every ASC must undertake one or more projects each year. Larger ASCs, with more rooms, procedure types or volume, should run more or harder ones. ### Are near misses part of ASC QAPI? Yes. CMS guidance expects ASCs to track all adverse events and spot errors that cause near misses. Near misses can lead to future harm. Its example is a records mix-up between two patients, caught at the time-out. ### Does the ASC Quality Reporting Program replace QAPI? No. They are separate. QAPI is a condition for coverage at 42 CFR 416.43. The ASC Quality Reporting Program pays for reporting: not reporting cuts the annual payment update by 2.0 percentage points. ## Sources - [42 CFR 416.43, Quality assessment and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/section/416.43) - [42 CFR 416.41, Governing body and management (eCFR)](https://www.ecfr.gov/current/title-42/section/416.41) - [42 CFR 416.51, Infection control (eCFR)](https://www.ecfr.gov/current/title-42/section/416.51) - [CMS State Operations Manual, Appendix L: Guidance to Surveyors, Ambulatory Surgical Centers](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/Downloads/som107ap_l_ambulatory.pdf) - [CMS Fiscal Year 2027 Mission and Priorities Document](https://www.cms.gov/files/document/fy-27-mpd.pdf) - [Federal Register: approval of DNV's ASC accreditation program, December 8, 2025](https://www.federalregister.gov/documents/2025/12/08/2025-22203/medicare-and-medicaid-programs-approval-of-application-by-dnv-healthcare-inc-for-initial-cms) - [42 CFR 416.300, ASC Quality Reporting Program basis and scope (eCFR)](https://www.ecfr.gov/current/title-42/section/416.300) - [CMS: Accrediting organizations](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs) ## Related - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) - [ASCQR Program: measures, deadlines, 2.0-point penalty](https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting) - [AAAHC accreditation: surveys, deemed status and QI studies](https://incidentkit.ai/compliance/accreditation/aaahc) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [Incident reporting software for surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers) - [QAPI: definition and meaning](https://incidentkit.ai/glossary/qapi) - [QAPI Meeting Agenda and Minutes Template (Printable)](https://incidentkit.ai/templates/qapi-meeting-agenda-and-minutes) --- # Nursing home QAPI and the QAA committee under 42 CFR 483.75 > Every nursing home needs a written QAPI plan, the quality program CMS requires. It also needs a QAA committee that meets at least quarterly. The committee tracks adverse events, finds causes, runs at least one improvement project a year and proves fixes last. Surveyors check QAPI last, then ask if the committee already knew about the problems. Source: https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities · Updated Oct 5, 2026 ## Key facts - **Rule:** 42 CFR 483.75 - **Tags:** F865, F867, F868 (State Operations Manual Appendix PP) - **QAA meetings:** At least quarterly and as needed - **Committee minimum:** Director of nursing, Medical Director or designee, infection preventionist, three other staff with a leader - **Projects:** At least one a year on a high-risk or problem-prone area - **QAPI plan:** Presented at each annual recertification survey - **Survey interval:** At least every 15 months, statewide average 12.9 months or less - **Risk-based survey:** Nationwide since September 8, 2026 for higher-performing homes - **Citation:** 42 CFR 483.75 - **Authority:** CMS - **Applies to:** Medicare- and Medicaid-certified skilled nursing facilities and nursing facilities, Each facility in a multiunit chain ## What does 42 CFR 483.75 require? An effective QAPI program that runs on data. It covers care outcomes and quality of life in every home. CMS's guide sorts it into five elements. The guide is not required. The regulation is what gets cited. *The five QAPI elements and where they sit in the rule* | Element (CMS) | Rule | What it means in practice | | --- | --- | --- | | 1. Design and scope | 483.75(b) | Ongoing and broad. Covers all care systems and management practices, clinical care, quality of life and resident choice. | | 2. Governance and leadership | 483.75(f) | The governing body or top leaders keep the program funded through staff turnover. They check that corrective actions fix system gaps. | | 3. Feedback, data systems and monitoring | 483.75(c) | Written policies for feedback from staff, residents and their representatives. Data from all departments, performance indicators and adverse event monitoring. | | 4. Performance improvement projects | 483.75(e) | Set priorities on high-risk, high-volume or problem-prone areas. Run distinct projects, at least one a year on a high-risk or problem-prone area found through data. | | 5. Systematic analysis and systemic action | 483.75(d) | A set way to find underlying causes. Corrective actions that change systems. Monitoring to confirm gains hold. | ## Who sits on the QAA committee? Under 483.75(g), the quality assessment and assurance (QAA) committee must include these members. It reports to the governing body. - The director of nursing - The Medical Director or a designee. The designee cannot be another required member. CMS expects proof the Medical Director got and acknowledged what was discussed. - At least three other staff, one of them the administrator, owner, a board member or another leader - The infection preventionist, who should attend each meeting and report The committee meets at least quarterly and as needed. It carries out action plans for quality problems. It regularly reviews data, including drug regimen review data. It need not review every data set each time. Residents and families may join, but need not. ## What do surveyors look for? Surveyors review QAPI and QAA last, after all other investigation, so they find concerns on their own. Three tags split the work (State Operations Manual Appendix PP, Rev. 225). | Tag | What it tests | | --- | --- | | [F865](https://incidentkit.ai/compliance/f-tags/f865) | A working QAPI program and plan, governing body oversight, and showing proof to surveyors | | [F867](https://incidentkit.ai/compliance/f-tags/f867) | Feedback, data, adverse event monitoring, priorities, corrective action and improvement projects | | [F868](https://incidentkit.ai/compliance/f-tags/f868) | Committee members, quarterly meetings and reports to the governing body | The plan must be shown at each annual recertification survey and on request. Say the QAA committee already found the problem and tried in good faith to fix it. Then the home is not cited for QAA. It can be cited elsewhere. Good faith is judged on the home's actions as a whole. > **Data collected but not used** CMS's own immediate jeopardy example (the most serious citation level): residents burned by hot water. The home collected water temperature data but never reviewed it or acted on it. ## What should a nursing home show? - A written QAPI plan tailored to the facility assessment - QAA minutes with attendance, and proof the Medical Director took part - Performance indicators with goals, methods and review dates - An adverse event and near miss log, with investigations - Written corrective actions: problem, measurable goals, steps, monitoring plan - Project records, including one a year on a high-risk or problem-prone area - Feedback channels and what changed because of them - Infection preventionist reports and QAPI training records ## Are incident reports protected from surveyors? Mostly no. CMS says incident and accident reports, wound logs, infection control logs and similar adverse event tracking records are not protected from disclosure. *What surveyors can ask for, per CMS guidance* | Record | Disclosure rule | | --- | --- | | Incident and accident reports, wound logs, infection logs | Not protected. Surveyors may ask for them in any investigation. | | QAA committee minutes and internal papers | Usually protected, but must be shown if they hold proof needed to judge QAPI compliance. | | Patient safety work product in a patient safety organization's evaluation system | Surveyors must not demand it. The home still needs separate proof of compliance. | CMS says nothing bars keeping duplicate systems. But keeping all QAPI proof in a patient safety system alone may leave a home unable to show compliance. ## How do incident reports fit? Directly. F867 requires methods to identify, report, track, investigate and analyze adverse events (483.75(c)(4)). Homes must use the data to prevent them. CMS defines a corrective action as a written plan that is carried out. It is not a plan of correction. - Treat a high-risk event as a trigger for corrective action. One example is elopement: a resident with cognitive impairment wandering off. - CMS requires no set method for finding causes. Root cause analysis is one choice. - Fix at the systems level and monitor until the gain lasts. CMS cites skipped monitoring as a deficiency example. [IncidentKit](https://incidentkit.ai/product/corrective-actions) keeps each action's owner, due date, evidence and effectiveness check in one record. See [QAPI committee meetings](https://incidentkit.ai/use-cases/qapi-committee-meetings). ## How often are nursing homes surveyed? State agencies must complete a standard recertification survey at least every 15 months. CMS sets a statewide average of 12.9 months or less. Since September 8, 2026, higher-performing homes may get a risk-based survey. It reviews all required areas with fewer activities and a smaller resident sample. Nursing homes are not on CMS's list of programs that accreditation can deem. So the state survey is the route. [Recertification survey guidance](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) covers the rest. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | 483.75(c)(4): identify, report, track, investigate and analyze adverse events | Intake, routing and structured investigations make each event one traceable record. | | 483.75(d)(2)(i): a systematic approach to underlying causes | Investigations record contributing factors and five whys. Lauren drafts. A person signs. Human-authored RCA templates are rolling out. | | 483.75(d)(2)(ii)-(iii), (f)(5): systems-level corrective action, monitored and evaluated | Corrective actions with owner, due date, evidence and an effectiveness check. Nothing closes until verified. | | 483.75(g)(2)(iii): the committee regularly reviews data and acts on it | Analytics cluster incidents by cause. A compliance packet gives each quarterly meeting a QAPI summary. | | 483.75(a)(1): documentation of how adverse events are identified, investigated, analyzed and prevented | The audit trail logs every change. Survey packets gather incident and action records. | | 483.75(e)(3): a yearly project on a high-risk or problem-prone area found in data | Trends point to candidate projects. Charters stay in your QAPI plan. | | 483.75(c)(1): feedback from direct care and other staff | QR quick report and email-to-incident make reporting easy. Resident surveys stay in your process. | ## Frequently asked questions ### How often must the QAA committee meet? At least quarterly, and as often as needed to find and fix quality problems. Data must be reviewed often enough to tell whether improvement is needed or happening. ### Is a QAPI plan required? Yes. Present it at each annual recertification survey, on request during other surveys, and to CMS. It is the written process for tracking performance, finding causes, acting and checking results. ### How many performance improvement projects are required? It depends on the facility's scope, complexity and resources. At least one project a year must focus on a high-risk or problem-prone area found through data. ### Can a nursing home use a patient safety organization and still meet QAPI? Yes, but protected material alone is not enough. Surveyors may not demand patient safety work product. They must still see proof of compliance, so keep a separate record. ## Sources - [42 CFR 483.75, Quality assurance and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/section/483.75) - [CMS State Operations Manual, Appendix PP: Guidance to Surveyors for Long Term Care Facilities (Rev. 225)](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [CMS: QAPI at a Glance, a step-by-step guide for nursing homes](https://www.cms.gov/medicare/provider-enrollment-and-certification/qapi/downloads/qapiataglance.pdf) - [CMS memo QSO-26-14-NH: Nursing Home Risk-Based Survey National Implementation (revised September 29, 2026)](https://www.cms.gov/files/document/qso-26-14-nh-revised-2026-09-29.pdf) - [CMS Fiscal Year 2027 Mission and Priorities Document](https://www.cms.gov/files/document/fy-27-mpd.pdf) - [CMS: Accrediting organizations and deemed programs](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs) ## Related - [F865 QAPI program and plan: what surveyors ask for](https://incidentkit.ai/compliance/f-tags/f865) - [F867 QAPI improvement activities: adverse event tracking](https://incidentkit.ai/compliance/f-tags/f867) - [F868 QAA committee: members, meetings and evidence](https://incidentkit.ai/compliance/f-tags/f868) - [Nursing home recertification survey: process and prep](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) - [QAA committee: definition and meaning](https://incidentkit.ai/glossary/qaa-committee) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [QAPI Meeting Agenda and Minutes Template (Printable)](https://incidentkit.ai/templates/qapi-meeting-agenda-and-minutes) --- # Hospital QAPI under 42 CFR 482.21: what surveyors check > A hospital must run a hospital-wide QAPI program, the quality program CMS requires. It tracks medical errors, near misses and adverse events, finds causes and checks that fixes last. The governing body, medical staff and administrators are accountable. CMS's March 2026 guidance tells surveyors to sample at least three tracked events. Source: https://incidentkit.ai/compliance/cms-qapi/hospitals · Updated Oct 5, 2026 ## Key facts - **Rule:** 42 CFR 482.21, condition of participation - **Survey guidance:** State Operations Manual Appendix A, A-0263 and related tags, Rev. 238 (March 20, 2026) - **Accountable:** Governing body, medical staff and administrators - **Project count:** Proportional to services and decided each year - **Survey sample:** At least three tracked events or errors - **Records:** CMS guidance: keep records of projects completed in the previous six years - **Obstetric QAPI:** Effective January 1, 2027 - **Deemed options:** Joint Commission, DNV, CIHQ, ACHC - **Citation:** 42 CFR 482.21 - **Authority:** CMS - **Applies to:** Medicare-participating hospitals, including every campus and service under the provider agreement, Multi-hospital systems that elect a unified and integrated QAPI program ## What does 42 CFR 482.21 require? An effective, ongoing QAPI program that runs on data in every department and service, even contracted ones. It is a condition of participation, a rule a hospital must meet to take part in Medicare. The hospital must show CMS proof that it runs. *42 CFR 482.21 in plain language* | Standard | What it asks for | | --- | --- | | Program scope | Show gains in indicators tied to outcomes. Measure, analyze and track quality indicators, including adverse patient events. | | Program data | Use quality data, including Medicare reporting on readmissions and hospital-acquired conditions. The governing body sets how often and how much data is collected. | | Program activities | Prioritize high-risk, high-volume and problem-prone areas. Track medical errors and adverse events, analyze causes, act, then measure and sustain results. | | Improvement projects | Run projects in proportion to the hospital's services. Record each project's purpose and measurable progress. | | Executive responsibilities | The governing body, medical staff and administrators define the program, set safety goals and fund it. They decide how many projects to run each year. | | Unified program | A system governing body may run one combined program for several certified hospitals if each hospital's needs are met. | ## Who does what in hospital QAPI? Three groups are named: the governing body, the medical staff and administrative officials. CMS says administrative officials include at least the chief executive, chief operating officer and chief nurse executive. - **Governing body:** approves how often and how much data is collected, approves the yearly project count and reviews results. - **Medical staff:** may hand its QAPI role to the medical staff executive committee. - **Administrative officials:** fund the program and show up in the minutes. - **Contractors:** contracted services must be inside the program. Their quality data goes to leaders, and QAPI roles go into contracts. CMS names this proof: budget documents, minutes with QAPI as a standing item, attendance rosters, and signatures on yearly QAPI project reviews. ## What do surveyors look for? Surveyors ask whether the hospital has an effective system to find problems, act and follow up. They also ask whether gains last. They do not judge which measures it chose. CMS revised the guidance in State Operations Manual Appendix A, Rev. 238, issued March 20, 2026, covering tags A-0263, A-0273, A-0283, A-0286, A-0297, A-0309 and A-0315. - Show the error and adverse event reporting policy and demo the system. Can it sort data by type, date, shift and unit? - Show training on what to report and how, with records. Staff in various units are interviewed. - For at least three tracked events or errors, show the systematic analysis and the changes. Show the later data and proof the gain lasted. - Show governing body minutes that set how often and how much data is collected. > **When material is called privileged** Privileged means legally protected from disclosure. Surveyors ask if the hospital can give other proof that is not protected. If it gives none, or too little, CMS says a deficiency must be cited. ## What should a hospital show? - The QAPI program document, covering all locations and services - Governing body minutes: QAPI as a standing item, data frequency, yearly project count - Indicators tracked, including adverse events - The reporting policy, with a demo of the system - Root cause analyses, resulting changes and later data - Current projects, with the reason and measurable progress for each. Keep records of projects completed in the previous six years, per CMS guidance. - Quality data from contracted services - Budget lines for QAPI staff, time, systems and training ## Where do hospitals fall short? - **Events tracked, no action.** CMS's example: three wrong-site surgeries and five near misses in a year. No analysis and no change to pre-surgical verification. - **Near misses ignored.** CMS says they must be tracked and analyzed. - **Indicators that show no gains.** CMS wants several analyses over time, not one data point. - **Non-clinical measures.** Employee satisfaction used in place of clinical indicators such as infection rates. - **Contracted services left out.** The hospital stays responsible for their quality and safety. - **No proof the governing body set data frequency and detail.** - **A one-time fix with no follow-up data.** ## How do incident reports fit? CMS does not set the reporting method. It expects one that lets the hospital track and analyze errors and adverse events meaningfully. Preventive actions include policy changes, repaired equipment and staff training, with proof of each. CMS adopts the QuIC (federal quality task force) definition of an error. It treats a near miss as an error. Sentinel-level events carry extra accreditor expectations. See [sentinel events](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) and the [Joint Commission](https://incidentkit.ai/compliance/accreditation/joint-commission). Surveyors ask whether data can be sorted by type, date, shift and unit. [IncidentKit analytics](https://incidentkit.ai/product/analytics) use the same cuts. [Corrective actions](https://incidentkit.ai/product/corrective-actions) keep the owner, evidence and effectiveness check CMS asks to see. ## What changes for hospitals with obstetric services? Starting January 1, 2027, a hospital with obstetrical services must use QAPI to assess and improve outcomes and disparities among obstetrical patients. The eCFR, current through October 1, 2026, shows this. | Requirement | What it means | | --- | --- | | Subpopulation analysis | Analyze QAPI data by the subpopulations the hospital finds among its obstetrical patients. | | Measure and track | Track outcomes and disparities in processes of care, services and operations. | | Act and sustain | Prioritize outcomes and disparities, act, measure results and track that gains last. | | Annual project | At least one measurable improvement project a year on obstetrical outcomes and disparities. | | State review data | If a maternal mortality review committee exists, build its public data and recommendations into QAPI. | CMS's fiscal year 2027 priorities say the obstetric organization and staffing rules took effect January 1, 2026. Hospitals with a CMS-approved accreditor are surveyed by the [Joint Commission](https://incidentkit.ai/compliance/accreditation/joint-commission), [DNV](https://incidentkit.ai/compliance/accreditation/dnv), [CIHQ](https://incidentkit.ai/compliance/accreditation/cihq) or [ACHC](https://incidentkit.ai/compliance/accreditation/achc). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | 482.21(a)(2), (c)(2): measure, analyze and track errors, near misses and adverse events | Intake by text, QR code, email or web form, plus routing. A pack sets incident types for each site. | | A-0286: the system can organize data by type, date, shift and unit | Analytics cluster incidents by location, shift, equipment and cause. | | 482.21(c)(2): analyze causes with a systemic approach | Investigations record contributing factors and five whys. Lauren drafts. A person signs. Human-authored RCA templates are rolling out. | | 482.21(c)(3): measure success and keep improvements in place | Corrective actions with owner, due date, evidence and an effectiveness check. Nothing closes until verified. | | 482.21(d): document each project's reason and measurable progress | A compliance packet carries the trends and closed actions behind a project. | | Executive oversight and contracted services | The audit trail and compliance packets give leaders a record to review. Contractors use the same intake. | | 482.21(b)(4): obstetric subpopulation analysis from 2027 | Not an IncidentKit measure. Obstetric outcome data comes from your clinical systems. | ## Frequently asked questions ### Does CMS require specific quality measures for hospitals? No. A hospital may use its own measures. It must track them, analyze the data and show measurable improvement. CMS sets no threshold. ### How many performance improvement projects must a hospital run? The number must fit the hospital's services, with no fixed ratio. The governing body decides it each year. A patient safety IT project can count, and joining a QIO (quality improvement organization) project is not required. ### Do near misses count under hospital QAPI? Yes. CMS says a near miss is an error from a patient safety view. Hospitals must track, analyze and work to prevent near misses. ### Who is accountable for hospital QAPI? The governing body, medical staff and administrators share it. They must oversee it: review the program, approve yearly projects, judge improvement actions and fund staff, time, systems and training. ## Sources - [42 CFR 482.21, Quality assessment and performance improvement program (eCFR)](https://www.ecfr.gov/current/title-42/section/482.21) - [CMS Transmittal 238: State Operations Manual Appendix A, Hospitals (March 20, 2026)](https://www.cms.gov/files/document/r238soma.pdf) - [CMS Fiscal Year 2027 Mission and Priorities Document](https://www.cms.gov/files/document/fy-27-mpd.pdf) - [CMS: Accrediting organizations](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs) - [Federal Register: CMS approval of the Joint Commission's hospital accreditation program, 2025](https://www.federalregister.gov/documents/2025/06/23/2025-11451/medicare-and-medicaid-programs-application-from-the-joint-commission-for-continued-cms-approval-of) ## Related - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [Patient safety event reporting software for hospitals](https://incidentkit.ai/solutions/hospitals) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) - [Adverse event: definition and meaning](https://incidentkit.ai/glossary/adverse-event) - [Near miss: definition and meaning](https://incidentkit.ai/glossary/near-miss) - [Performance improvement project: definition and meaning](https://incidentkit.ai/glossary/performance-improvement-project) - [Medication Error Reporting: Steps, Severity and Follow-Up](https://incidentkit.ai/use-cases/medication-error-reporting) --- # Hospice QAPI under 42 CFR 418.58: requirements and evidence > A hospice must run a hospice-wide QAPI program, the quality program CMS requires. It measures palliative (comfort care) outcomes, tracks adverse patient events using its own definitions and completes improvement projects. The governing body evaluates it every year and names who runs it. CMS tags L559 through L576 cover each standard. Source: https://incidentkit.ai/compliance/cms-qapi/hospice · Updated Oct 5, 2026 ## Key facts - **Rule:** 42 CFR 418.58, condition of participation - **CMS tags:** L559 to L576, State Operations Manual Appendix M - **Governing body:** Approves data frequency, designates who runs QAPI, evaluates the program annually - **Projects:** No set number, documented in writing - **Adverse events:** The hospice may define its own, then must follow it - **Survey interval:** No more than 36.9 months between completed surveys (CMS FY2027) - **Citation:** 42 CFR 418.58 - **Authority:** CMS - **Applies to:** Medicare-certified hospices surveyed by a state agency, Deemed hospices accredited by a CMS-approved accrediting organization ## What does 42 CFR 418.58 require? An effective, ongoing QAPI program that covers all hospice services, even those given under contract or arrangement. Indicators tie to palliative outcomes. It is a condition of participation, a rule a hospice must meet to bill Medicare. The hospice must show CMS proof that it runs. *42 CFR 418.58 in plain language* | Standard | What it asks for | | --- | --- | | (a) Program scope | Be able to show measurable gains in palliative outcomes and hospice services. Measure, analyze and track quality indicators, including adverse patient events. | | (b) Program data | Use quality indicator and patient care data to design the program, check that it works and is safe, and set priorities. The governing body approves how often and how much data is collected. | | (c) Program activities | Focus on high-risk, high-volume or problem-prone areas. Track adverse patient events, analyze causes, act, share what was learned across the hospice, then measure and sustain results. | | (d) Improvement projects | Develop, carry out and evaluate projects that fit the hospice's scope and past performance. Record each project's purpose and measurable progress. | | (e) Executive responsibilities | The governing body makes sure the program is defined, maintained and evaluated every year. It makes sure improvement actions are checked for effect. It names one or more people to run the program. | ## Who does what in hospice QAPI? - **Governing body:** approves how often and how much data is collected. It names the people who run the program and makes sure it is evaluated every year. - **Named QAPI people:** run the program day to day and report results to the governing body. - **All disciplines and contracted services:** are part of the program, not outside it. CMS says the governing body may take hands-on control or appoint people to run the program. It keeps final responsibility either way. ## What do surveyors look for? See State Operations Manual Appendix M, tags L559 to L576 (Rev. 210, February 3, 2023). CMS expects a written plan. It also expects objective data showing gains in care outcomes, processes of care, patient and family satisfaction, operations or other indicators. It describes a blame-free approach that fixes systems, not single problems. The plan should cover: - Program objectives and all patient care disciplines - How the program is run and coordinated - Ways to monitor and evaluate quality of care - Priorities for resolving problems - Monitoring to confirm that actions worked - Reports to the governing body - A written review of the hospice's own QAPI program ## What should a hospice show? - The written plan and minutes approving data frequency and detail - The hospice's definition of adverse event and the log built on it - Data from every service, not only patient assessments - Dated analyses showing change over time, with actions and results - Written project records: what, why and measurable progress - Names of the people who run QAPI - Proof of the yearly evaluation and results sent to the governing body ## How should a hospice track adverse events? CMS lets the hospice choose. It may write its own definition of an adverse event or use one from an accreditor or industry group. It must then follow it when tracking, analyzing and acting. In general, an adverse event is any action or inaction by the hospice that harmed a patient. Hospices are not bound to that wording. Data must reach beyond patient assessments. CMS lists physician, nursing, social work and counseling services, clinical records, infection control, pharmaceutical services, durable medical equipment, patient rights, administrative services, contract services, volunteers, hospice aides and adverse events. Sources include clinical records, incident reports, complaints, satisfaction surveys, direct observation and interviews. When monitoring shows a problem, the hospice must change the process hospice-wide. It must show the change reduced the event. [IncidentKit](https://incidentkit.ai/product/incident-reporting) turns the hospice's definition into incident types, severity levels and routing. [Corrective actions](https://incidentkit.ai/product/corrective-actions) record the change and the check that it worked. ## Where do hospices fall short? Gaps measured against CMS guidance: - Using only patient assessment data - Defining adverse events, then not tracking to that definition - Fixes applied to one team or site, not hospice-wide - No objective data showing improvement over time - Project notes missing the written elements the standard lists - A governing body that does not evaluate the program yearly or name who runs it ## How often is a hospice surveyed? CMS's fiscal year 2027 priorities set a maximum of 36.9 months between completed recertification surveys for any hospice. A hospice may choose a CMS-approved accreditor instead of a state survey. CMS requires accreditors to survey at least every 36 months. ACHC says it has held hospice deeming authority (CMS approval to survey in place of the state) since 2009. It also says its deemed surveys are unannounced. See [ACHC](https://incidentkit.ai/compliance/accreditation/achc). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | 418.58(a)(2), (c)(2): track adverse patient events | Intake by text, QR code, email or web form. Your own definition becomes incident types, severity levels and routing. | | 418.58(c)(2): analyze causes | Investigations record contributing factors and five whys. Lauren drafts. A person signs. Human-authored RCA templates are rolling out. | | 418.58(c)(3): change the process hospice-wide, measure success and sustain it | Corrective actions with owner, due date, evidence and an effectiveness check. Analytics show whether the cluster went away. | | 418.58(b)(1): data beyond patient assessments | Incident data from any service sits in one record set. Infection, satisfaction and clinical data stay in their own systems. | | 418.58(e)(1)-(2): annual evaluation and results to the governing body | A compliance packet gives the governing body a QAPI summary. The audit trail logs every change. | | 418.58(e)(3): designated individuals run the program | Roles control who reviews, investigates and signs. Naming the QAPI lead is the governing body's call. | ## Frequently asked questions ### Does a hospice have to complete a set number of performance improvement projects? No. CMS guidance sets no number. The hospice picks the number and topics from its monitoring and survey results. Each project must be written up, with why it began and measurable progress. ### Can a hospice write its own definition of an adverse event? Yes. A hospice may write its own definition or adopt one from an accreditor or industry group. It must then apply it consistently. ### Who is responsible for running hospice QAPI? The governing body. It must name one or more people to run the program, or take hands-on control. It keeps final responsibility either way. ### How often must a hospice evaluate its QAPI program? Every year. The governing body must ensure the program is evaluated annually under 42 CFR 418.58(e)(1). CMS also expects a documented review of the hospice's own QAPI program. ## Sources - [42 CFR 418.58, Quality assessment and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/section/418.58) - [CMS Transmittal 210: State Operations Manual Appendix M, Hospice (February 3, 2023)](https://www.cms.gov/files/document/r210soma.pdf) - [CMS Fiscal Year 2027 Mission and Priorities Document](https://www.cms.gov/files/document/fy-27-mpd.pdf) - [ACHC: Hospice accreditation](https://achc.org/hospice/) - [Federal Register: CMS approval of the Joint Commission's hospital accreditation program, 2025 (36-month survey rule)](https://www.federalregister.gov/documents/2025/06/23/2025-11451/medicare-and-medicaid-programs-application-from-the-joint-commission-for-continued-cms-approval-of) ## Related - [Hospice incident reporting software for field teams](https://incidentkit.ai/solutions/hospice) - [ACHC accreditation: deemed status, surveys and standards](https://incidentkit.ai/compliance/accreditation/achc) - [Adverse event: definition and meaning](https://incidentkit.ai/glossary/adverse-event) - [QAPI: definition and meaning](https://incidentkit.ai/glossary/qapi) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) - [Performance improvement project: definition and meaning](https://incidentkit.ai/glossary/performance-improvement-project) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) --- # Home health QAPI under 42 CFR 484.65: what an HHA must show > A home health agency (HHA) must run an agency-wide QAPI program, the quality program CMS requires. It tracks adverse patient events and runs improvement projects. It uses measurable indicators, including OASIS (patient assessment data) measures, and fixes any threat to patient safety at once. A governing body oversees it, and CMS tags G640 through G660 cover it. Source: https://incidentkit.ai/compliance/cms-qapi/home-health · Updated Oct 5, 2026 ## Key facts - **Rule:** 42 CFR 484.65, condition of participation - **CMS tags:** G640 to G660, State Operations Manual Appendix B (Rev. 219) - **Data:** Quality indicators including OASIS-derived measures where applicable - **Projects:** At least one in development, ongoing or completed each calendar year (CMS guidance) - **Immediate correction:** Required for problems that threaten patient health and safety - **Governing body:** Approves data frequency and detail, addresses fraud and waste - **Survey interval:** No more than 36.9 months between completed surveys (CMS FY2027) - **Citation:** 42 CFR 484.65 - **Authority:** CMS - **Applies to:** Medicare-certified home health agencies surveyed by a state agency, Deemed home health agencies accredited by a CMS-approved accrediting organization ## What does 42 CFR 484.65 require? An effective, ongoing QAPI program that runs on data across all services, even those under contract. It focuses on outcomes such as emergent care use, hospital admissions and readmissions. It also aims to prevent medical errors. It is a condition of participation, a rule an agency must meet to bill Medicare. *42 CFR 484.65 in plain language* | Standard | What it asks for | | --- | --- | | (a) Program scope | Be able to show measurable gains in indicators tied to outcomes, safety and quality. Measure, analyze and track quality indicators, including adverse patient events. | | (b) Program data | Use quality indicator data, including measures from OASIS where they apply. The governing body approves how often and how much data is collected. | | (c) Program activities | Focus on high-risk, high-volume or problem-prone areas. Fix at once any problem that directly or potentially threatens patient health and safety. Track adverse patient events, analyze causes, act, then measure and sustain results. | | (d) Improvement projects | Run projects that fit the agency's scope, complexity and past performance. Document each project, why it was done and the measurable progress. | | (e) Executive responsibilities | The governing body makes sure the program is defined and maintained. It covers priorities and evaluates every improvement action. It sets clear patient safety expectations and addresses any findings of fraud or waste. | ## Who does what in home health QAPI? - **Governing body:** approves how often and how much data is collected. It ensures every improvement action is evaluated and addresses any findings of fraud or waste. If it is unclear who the governing body is, surveyors may check ownership and managing control data on the CMS-855A enrollment form. - **Agency staff:** report adverse patient events and near misses, often from the field. - **Infection control:** the infection program must be an integral part of QAPI under 42 CFR 484.70(b). ## What do surveyors look for? The guidance is State Operations Manual Appendix B, Rev. 219, issued April 12, 2024. Each standard has its own tag. | Tag | Standard | Focus | | --- | --- | --- | | G640 | Condition | The program as a whole. A condition-level citation is possible | | G642 | Program scope | Indicators that data can measure, with a set frequency of measurement and analysis | | G644 | Program data | Quality indicator data, OASIS-based measures, governing body approval | | G646 | Program activities | High-risk, high-volume and problem-prone priorities, immediate correction | | G654 | Adverse patient events | Tracking events and analyzing causes | | G656 | Measure and sustain | Success measured and gains sustained | | G658 | Projects | Project records and results | | G660 | Executive responsibilities | Governing body oversight, including meeting minutes | CMS guidance says the agency should have at least one project in development, ongoing or completed each calendar year. Surveyors ask for records of current and prior-year projects, with the reason for each and the results. If a project failed, they ask what the agency did next. ## What should an HHA show? - The written QAPI program, with indicators data can measure - Measure and analysis frequency, approved by the governing body - OASIS-based measures and other quality data in use - An adverse patient event log with analyses and actions - Records of immediate fixes made for safety threats - Project records for this and last year, with reasons and results - Governing body minutes showing ongoing oversight - Infection control data built into QAPI ## How do adverse events and immediate correction work? CMS describes adverse patient events as negative and unexpected. They affect the patient's plan of care and can cause a decline in condition. The agency must track all of them and analyze whether preventable errors caused them. It should also think about how to identify near misses. The rule goes further. Improvement work must lead to immediate correction of any problem that directly or potentially threatens patient health and safety. CMS gives no deadline in days. Reports often start in a patient's home. [IncidentKit intake](https://incidentkit.ai/product/incident-reporting) accepts a text from the field. [Routing and escalation](https://incidentkit.ai/product/routing-and-escalation) sends a serious event to the right owner at once. Voice reporting is rolling out. ## Where do HHAs fall short? Gaps measured against CMS guidance: - Indicators that data cannot measure, so a change in procedure cannot be evaluated - No stated frequency for measurement and analysis - No project in development, ongoing or completed in the calendar year - Project files with no reason, or no follow-up when a project failed - Safety threats left open while analysis continues - Infection data kept apart from QAPI - A governing body that cannot show ongoing oversight ## How often is an HHA surveyed? CMS's fiscal year 2027 priorities set a maximum of 36.9 months between completed recertification surveys for any home health agency. An agency may choose a CMS-approved accreditor instead. ACHC says it has held home health deeming authority (CMS approval to survey in place of the state) since 2006. It also says CMS no longer lets accreditors warn an organization before an unannounced deemed survey. See [ACHC](https://incidentkit.ai/compliance/accreditation/achc). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | 484.65(a)(2), (c)(2): track adverse patient events | Intake by text, QR code, email or web form, plus routing and escalation. Voice reporting is rolling out. | | 484.65(c)(1)(iii): immediate correction of safety threats | Routing and escalation put a serious event in front of its owner at once. A corrective action carries a due date. | | 484.65(c)(2): analyze causes | Investigations record contributing factors and five whys. Lauren drafts. A person signs. Human-authored RCA templates are rolling out. | | 484.65(c)(3), (e)(2): measure success and evaluate every improvement action | Corrective actions with owner, due date, evidence and an effectiveness check. Analytics show whether the cluster went away. | | 484.65(b)(1): OASIS-derived measures | Not an IncidentKit measure. OASIS data stays in your home health system. IncidentKit adds incident and corrective action data. | | 484.65(d)(2), (e): project documentation and governing body oversight | Compliance packets give the governing body a QAPI summary. The audit trail logs every change. Charters stay in your QAPI documents. | | 484.70(b): infection program integral to QAPI | Infection incidents are recorded like any other event. Surveillance data stays in your infection control system. | ## Frequently asked questions ### How many performance improvement projects must a home health agency do? At least one project in development, ongoing or completed each calendar year, per CMS guidance. The agency decides which fit, based on its QAPI data. ### What counts as an adverse patient event for a home health agency? CMS describes negative, unexpected events that affect the patient's plan of care and could cause a decline in condition. The agency must track them all and analyze whether preventable errors caused them. ### What does immediate correction mean in the QAPI rule? Under 42 CFR 484.65(c)(1)(iii), improvement work must lead to immediate correction of any problem that directly or potentially threatens patient health and safety. CMS gives no deadline in days. ### What data must a home health agency use in QAPI? Quality indicator data, including OASIS-based measures where they apply, plus other relevant data. The governing body approves how often and how much data is collected. ## Sources - [42 CFR 484.65, Quality assessment and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/section/484.65) - [CMS Transmittal 219: State Operations Manual Appendix B, Home Health Agencies (April 12, 2024)](https://www.cms.gov/files/document/r219soma.pdf) - [CMS Fiscal Year 2027 Mission and Priorities Document](https://www.cms.gov/files/document/fy-27-mpd.pdf) - [ACHC: Home health accreditation](https://achc.org/home-health/) - [ACHC: Frequently asked questions](https://achc.org/faqs/) ## Related - [Home health incident reporting software for field staff](https://incidentkit.ai/solutions/home-health) - [ACHC accreditation: deemed status, surveys and standards](https://incidentkit.ai/compliance/accreditation/achc) - [Adverse event: definition and meaning](https://incidentkit.ai/glossary/adverse-event) - [QAPI: definition and meaning](https://incidentkit.ai/glossary/qapi) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) --- # AAAHC accreditation: what ASCs and ambulatory practices should know > AAAHC accredits surgery centers and other outpatient sites for three years. CMS has granted it deemed status for ASCs, so its survey can replace the state's. Medicare surveys are unannounced. Surveyors score each QI study on six parts. Source: https://incidentkit.ai/compliance/accreditation/aaahc · Updated Oct 5, 2026 ## Key facts - **Accreditation term:** Three years (1,095-day cycle) - **CMS deemed status:** ASCs, plus HMOs and PPOs in Medicare Advantage - **Medicare Deemed Status survey:** Unannounced - **Regular survey notice:** Public Notice of Survey at least 30 calendar days before - **Random survey:** 9 to 30 months after a survey, unannounced, one surveyor - **Standards version:** v44 effective December 16, 2025; v45 released August 18, 2026 - **QI study model:** Six components - **Citation:** AAAHC Standards (v44 effective December 16, 2025; v45 released August 18, 2026) - **Authority:** AAAHC (Accreditation Association for Ambulatory Health Care) - **Applies to:** Ambulatory surgery centers, including Medicare deemed ASCs, Office-based surgery and endoscopy centers, Medical and dental group practices, community and student health centers ## Who does AAAHC accredit? AAAHC was founded in 1979. It says it has accredited more than 6,800 organizations. Its settings include ambulatory surgery centers, office-based surgery facilities, endoscopy centers, student and community health centers, medical and dental group practices, employer and retail clinics, and Indian and tribal health centers. It also accredits health plans and offers certifications such as Patient-Centered Medical Home. ## How does AAAHC relate to CMS deemed status? CMS has granted AAAHC deemed status for ASCs, and for HMOs and PPOs in Medicare Advantage. Deemed status means CMS accepts the accreditor's survey in place of a state survey. An ASC picks a standard accreditation survey or a Medicare Deemed Status survey, which adds review of the Medicare requirements. Accreditation is voluntary. A deemed ASC must still meet the QAPI condition in [42 CFR 416.43](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers). *AAAHC survey types and notice* | Survey type | Purpose | Notice | | --- | --- | --- | | Initial and reaccreditation | First accreditation, or renewal after a three-year term | Public Notice of Survey posted at least 30 calendar days before | | Medicare Deemed Status | Deemed ASC: accreditation plus review of Medicare requirements | Unannounced; dates and surveyor names are not provided | | Random | Picked 9 to 30 months after a survey. One surveyor, may last one day, no fee | Unannounced | | Discretionary | For cause, when concerns are raised about compliance | Any time, without advance notice | | Early Option | Organizations under six months old that must be accredited to open or be reimbursed | Dates set after AAAHC reviews the application | ## How do AAAHC surveys work? AAAHC awards accreditation for three years, a 1,095-day cycle, when it finds substantial compliance with its Standards. It may require intracycle activities between surveys. It can deny or revoke accreditation at any time. It calls its method peer-based and educational. It sets survey length and surveyor numbers from the application. v44 of the Standards took effect December 16, 2025. AAAHC released v45 on August 18, 2026. Check which version applies to your survey date. This page cites no AAAHC standard numbers because numbering changes by version. ## What quality work does AAAHC expect? AAAHC expects a quality management and improvement program that draws on many disciplines. It rests on analysis of clinical needs, risk levels and chances to improve, and joins performance indicators with risk management. AAAHC prescribes no QI method. Surveyors judge a QI study against six components. *AAAHC six-component QI study and where incident data fits* | Component | AAAHC asks | Incident data supplies | | --- | --- | --- | | 1. Purpose | Quantify the gap and why it matters | The trend that showed the problem | | 2. Goal | A number and a date, informed by benchmarks | The baseline rate | | 3. Gap | Why the gap exists | Investigation findings and contributing factors | | 4. Corrective action | Targeted actions with a timeline | Actions with owner, due date and evidence | | 5. Remeasure | Confirm the goal was met and sustained; repeat if not | The rate after the change | | 6. Communicate | Share results and plan further remeasurement | A summary for leadership and staff | ## What documentation should an AAAHC-accredited organization keep? - QI studies that document all six components, including remeasurement - The incident and indicator data behind each study - The posted Notice of Survey. For Medicare Deemed Status surveys, post it when the invoice packet arrives. Keep it up at least 30 calendar days, even past the end of the survey. - Records of any intracycle activities - For a deemed ASC, the QAPI evidence CMS asks for under 416.43 - The handbook for your program and version. For deemed status, that is the Accreditation Handbook for Medicare Deemed Status. ## AAAHC vs Joint Commission for ASCs | Item | AAAHC | Joint Commission | | --- | --- | --- | | CMS-approved ASC program | Yes | Yes | | Deemed survey notice | Unannounced | Unannounced or short notice for most surveys | | Non-deemed survey notice | Public notice at least 30 calendar days before | Seven business days for resurveys of ASCs not using deemed status | | Event expectations | Six-component QI study | Sentinel Event Policy with a 45-business-day analysis | See [AAAHC vs Joint Commission for ASCs](https://incidentkit.ai/blog/aaahc-vs-joint-commission-for-ascs) and the [Joint Commission](https://incidentkit.ai/compliance/accreditation/joint-commission) page. ## Where do incident reports fit? A study needs a baseline, a cause and a re-measurement. Structured incident records give all three. Free text does not. [IncidentKit](https://incidentkit.ai/product/incident-reporting) captures the event. [Investigations](https://incidentkit.ai/product/investigations) record the cause. [Corrective actions](https://incidentkit.ai/product/corrective-actions) hold the check that it worked. IncidentKit runs alongside AAAHC's own accreditation platform. It does not file anything with AAAHC. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | A multidisciplinary quality program based on analysis of clinical needs and risk | Structured incident records, clustered by location, shift, equipment and cause, are the starting data. | | QI study component 3: why the gap exists | Investigations record contributing factors and five whys. Lauren drafts. A person signs. Human-authored RCA templates are rolling out. | | QI study component 4: targeted corrective actions with a timeline | Corrective actions with owner, due date and evidence. Nothing closes until verified. | | QI study component 5: remeasure to confirm and sustain | An effectiveness check on each action, and analytics that show the rate before and after. | | QI study component 6: communicate results | A compliance packet gives a plain summary of events, actions and results for leadership and staff. | | Medicare Deemed Status: CMS conditions, including 42 CFR 416.43 | The same records serve the QAPI evidence CMS asks for. See the ASC QAPI page. | ## Frequently asked questions ### Are AAAHC surveys unannounced? Medicare Deemed Status, random and for-cause surveys are unannounced. Regular initial and reaccreditation surveys are announced, with a public Notice of Survey at least 30 calendar days ahead. ### How long does AAAHC accreditation last? Three years, a 1,095-day cycle, if AAAHC finds substantial compliance. It can deny or revoke accreditation at any time. ### Does AAAHC require a specific QI method? No. AAAHC sets no QI method. Surveyors judge studies on six components: purpose, goal, gap, corrective action, remeasurement and communication. AAAHC publishes a template. ### Can an ASC meet Medicare requirements through AAAHC? Yes, with the Medicare Deemed Status survey, which stands in for a state survey. A deemed ASC must still meet 42 CFR 416.43. ## Sources - [AAAHC: Survey types](https://www.aaahc.org/1095-engage/pre-survey/survey-types/) - [AAAHC: Medicare Deemed Status accreditation](https://www.aaahc.org/accelerated-readiness/program-overview/medicare-deemed/) - [AAAHC: Documenting a quality improvement study using the six-component criteria](https://www.aaahc.org/uploads/2024/04/240411_IQI_DOC_Documenting-QI-Using-6-Component-Criteria.pdf) - [AAAHC: v44 Standards press release (August 18, 2025)](https://www.aaahc.org/uploads/2025/08/AAAHC-v44-Standards-Press-Release_FINAL.pdf) - [AAAHC: v45 Standards release (August 18, 2026)](https://www.aaahc.org/news/aaahc-releases-v45-standards-to-elevate-artificial-intelligence-ai-governance-in-ambulatory-care/) - [CMS: Accrediting organizations](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs) - [Joint Commission: Ambulatory Care Survey Activity Guide 2026](https://digitalassets.jointcommission.org/api/public/content/2f21045af9d84f5fbc9bfef10d620469) ## Related - [AAAHC: definition and meaning](https://incidentkit.ai/glossary/aaahc) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [AAAHC vs Joint Commission for ASCs: how they compare](https://incidentkit.ai/blog/aaahc-vs-joint-commission-for-ascs) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) - [Deemed status: definition and meaning](https://incidentkit.ai/glossary/deemed-status) --- # Joint Commission accreditation: surveys, sentinel events and safety goals > The Joint Commission accredits hospitals, surgery centers, home care and more. CMS accepts its accreditation as proof of Medicare compliance for several of them. Most surveys are unannounced. A sentinel event needs a full analysis and action plan within 45 business days. Source: https://incidentkit.ai/compliance/accreditation/joint-commission · Updated Oct 5, 2026 ## Key facts - **Survey notice:** Unannounced or short notice for most surveys - **CMS rule for accreditors:** Survey at least every 36 months (42 CFR 488.5(a)(4)(i)) - **Sentinel event analysis:** Analysis and action plan within 45 business days - **Self-reporting:** Encouraged, not required - **Hospital standards:** 14 National Performance Goals from January 2026 - **Safety program standard:** NPG.02.03.01 in the hospital program - **Deemed programs:** Hospitals, critical access hospitals, ASCs, home health, hospice - **Citation:** Joint Commission accreditation standards, Sentinel Event Policy and National Performance Goals (hospitals, effective January 2026) - **Authority:** The Joint Commission - **Applies to:** Hospitals and critical access hospitals, Ambulatory care organizations, including ambulatory surgery centers, Home care, nursing care center, assisted living and telehealth programs ## Who does the Joint Commission accredit? Its manuals cover hospitals, critical access hospitals, ambulatory care, home care, nursing care centers, assisted living communities and telehealth. Ambulatory care includes ASCs, diagnostic imaging, diagnostic sleep centers and urgent care. ## How does it relate to CMS deemed status? The Joint Commission is on CMS's list of approved accreditors. Deemed status means CMS accepts its survey in place of a state survey. CMS Federal Register notices cover its programs for hospitals, critical access hospitals, ambulatory surgery centers, home health and hospice. Accreditation is voluntary. The alternative is a state survey. Nursing homes are not on CMS's list of deemed programs, so nursing care center accreditation does not replace the state survey. CMS requires accreditors to survey at least every 36 months under 42 CFR 488.5(a)(4)(i). The Joint Commission has agreed to resurvey by unannounced survey within 36 months of the prior accreditation effective date. > **New oversight rule** In June 2026 CMS finalized a rule to tighten oversight of accreditors. It covers conflicts of interest, validation and performance standards. It takes effect June 16, 2027 (91 FR 36370). ## How do Joint Commission surveys work? For most surveys, surveyors arrive unannounced or with short notice. The first hour is planning, using documents the organization supplies. If they are not ready, surveyors begin with an individual tracer. A tracer follows a patient's experience through the organization. A typical individual tracer block is 60 to 120 minutes. System tracers examine topics such as data management. A deemed ASC survey includes clinicians and a Life Safety Code surveyor. *Notice for ambulatory care surveys* | Survey | Notice | | --- | --- | | Most surveys, including deemed ASC surveys | Unannounced or short notice | | Initial and early-option surveys not used for deemed status | 30 days | | Resurveys of ASCs not using accreditation for deemed status | Seven business days | ## What does the Sentinel Event Policy require? *Joint Commission Sentinel Event Policy, July 2026 manuals* | Topic | What the policy says | | --- | --- | | Definition | A patient safety event that reaches a patient and results in death, severe harm or permanent harm | | Reporting | Self-reporting is encouraged, not required. Accredited providers must have a sentinel event policy. | | Analysis | A comprehensive systematic analysis, most commonly a root cause analysis, plus a corrective action plan within 45 business days of the event or of becoming aware of it | | Corrective action plan | Responsible people, timelines, how effectiveness will be checked and how change will last. At least one action must be intermediate or stronger on the VA action hierarchy. | | At survey | Surveyors do not search for sentinel events or judge reported analyses. They may note a recommendation for improvement if no analysis was done in time. | | Accreditation effect | Having a sentinel event does not affect the decision. Willful failure to respond appropriately could. | See [sentinel events](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) and [what is a sentinel event](https://incidentkit.ai/blog/what-is-a-sentinel-event). ## What safety and incident-reporting expectations apply? For hospitals and critical access hospitals, a National Performance Goals chapter took effect in January 2026. The hospital program has 14 goals. Ambulatory and home care materials from 2026 still refer to National Patient Safety Goals. In the hospital chapter, NPG.02.03.01 covers the safety program. *NPG.02.03.01 elements of performance (hospital program)* | Element | Requirement in short | | --- | --- | | EP 1 | A hospital-wide safety program covering every department, from close calls to sentinel events | | EP 4 | Internal reporting of system failures without risk of retaliation | | EP 5 | Full analyses of sentinel events | | EP 7 | At least every 18 months, a proactive risk assessment of one high-risk process | | EP 8-9 | Analyze failures and share lessons learned with all affected staff | | EP 11 | Regularly evaluate the culture of safety with valid and reliable tools | ## What documentation should an accredited organization keep? The 2025 and 2026 survey guides ask for these items, depending on the program: - Performance or quality improvement data from the past 12 months, plus project records with reasons and measurable progress - Infection control surveillance data from the past 12 months - An analysis of a high-risk process and the most recent culture of safety evaluation data - For a deemed ASC: surgeries from the past six months, and cases in the past 12 months where a patient was transferred to a hospital or died - Full analyses and corrective action plans for sentinel events - Proof of the incident and error reporting system. Survey data sessions list it by name. ## How do incident reports help at survey? A tracer follows what really happened. A data session asks how errors, close calls and adverse events are found and used. [IncidentKit](https://incidentkit.ai/product/incident-reporting) keeps each event, [investigation](https://incidentkit.ai/product/investigations) and [corrective action](https://incidentkit.ai/product/corrective-actions) in one record, with an [audit trail](https://incidentkit.ai/product/audit-trail) of who changed what. See also [Joint Commission survey readiness](https://incidentkit.ai/compliance/survey-readiness/joint-commission-survey-readiness). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | NPG.02.03.01 EP 1, 4: hospital-wide safety program. Internal reporting without retaliation | Intake by text, QR code, email or web form. Near misses become full records. Lauren drafts. A person signs. | | Sentinel Event Policy: full analysis within 45 business days | Investigations with contributing factors, five whys and a disposition. Human-authored RCA templates are rolling out. | | Corrective action plan: owners, timelines, effectiveness and lasting change | Corrective actions with owner, due date, evidence and an effectiveness check. Nothing closes until verified. | | NPG.02.03.01 EP 8-9: analyze failures and share lessons learned | Analytics cluster incidents by cause. Compliance packets summarize results for staff and leaders. | | Survey document list: 12 months of improvement data; ASC transfers and deaths | A survey packet gathers incident, investigation and action records for the period. | | NPG.02.03.01 EP 11: culture of safety evaluation | Not an IncidentKit feature. Culture surveys use validated tools. Reporting volume and time to close are useful companion data. | ## Frequently asked questions ### Is reporting a sentinel event to the Joint Commission mandatory? No. Self-reporting is encouraged, not required. You must still have a sentinel event policy and complete an analysis and action plan for each event. ### How long do we have to complete a root cause analysis after a sentinel event? 45 business days from the event or from becoming aware of it. An unacceptable response gets 15 more business days to resubmit. ### Are Joint Commission surveys unannounced? Most are, unannounced or with short notice. Initial surveys not used for deemed status get 30 days' notice. ASC resurveys not using deemed status get seven business days. ### What replaced the National Patient Safety Goals for hospitals? National Performance Goals replaced them for hospitals and critical access hospitals in January 2026. The hospital program has 14 goals. Ambulatory and home care still used the old goals in 2026 materials. ## Sources - [Joint Commission: Sentinel Event Policy, Comprehensive Accreditation Manual for Home Care (July 2026 update)](https://digitalassets.jointcommission.org/api/public/content/8e9d0e7ede064bc78c643a819e93ea69) - [Joint Commission: National Performance Goals, effective January 2026 for the Hospital Program](https://digitalassets.jointcommission.org/api/public/content/9ca80055182b4274842a5780a94f2c82) - [Joint Commission: Ambulatory Care Survey Activity Guide 2026](https://digitalassets.jointcommission.org/api/public/content/2f21045af9d84f5fbc9bfef10d620469) - [Joint Commission: Critical Access Hospital Survey Activity Guide 2025](https://digitalassets.jointcommission.org/api/public/content/670edfd912b04aa9a428c4f713e310e5) - [Federal Register: CMS approval of the Joint Commission's hospital accreditation program, 2025](https://www.federalregister.gov/documents/2025/06/23/2025-11451/medicare-and-medicaid-programs-application-from-the-joint-commission-for-continued-cms-approval-of) - [Federal Register: Strengthening Oversight of Accrediting Organizations, June 16, 2026](https://www.federalregister.gov/documents/2026/06/16/2026-12069/medicare-program-strengthening-oversight-of-accrediting-organizations-aos-and-preventing-ao) - [CMS: Accrediting organizations](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs) - [The Joint Commission](https://www.jointcommission.org/) ## Related - [Joint Commission: definition and meaning](https://incidentkit.ai/glossary/joint-commission) - [Joint Commission survey readiness: tracers, unannounced](https://incidentkit.ai/compliance/survey-readiness/joint-commission-survey-readiness) - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) - [Sentinel event: definition and meaning](https://incidentkit.ai/glossary/sentinel-event) - [What is a sentinel event? Definition, examples, response](https://incidentkit.ai/blog/what-is-a-sentinel-event) - [AAAHC vs Joint Commission for ASCs: how they compare](https://incidentkit.ai/blog/aaahc-vs-joint-commission-for-ascs) - [Hospital QAPI requirements: 42 CFR 482.21 explained](https://incidentkit.ai/compliance/cms-qapi/hospitals) - [Survey and accreditation readiness: a continuous approach](https://incidentkit.ai/guides/survey-and-accreditation-readiness) --- # CIHQ accreditation: what hospitals and critical access hospitals should know > CIHQ accredits acute care, critical access and acute psychiatric hospitals for CMS. Its standards follow the Medicare Conditions of Participation. Full surveys run every three years. It does not require sentinel event or root cause analysis submissions. Source: https://incidentkit.ai/compliance/accreditation/cihq · Updated Oct 5, 2026 ## Key facts - **Programs:** Hospitals, critical access hospitals, acute psychiatric hospitals - **CMS deemed status:** Yes, for those three hospital programs - **Full survey cycle:** Every three years - **Typical hospital survey:** 2 to 4 days, 2 to 4 surveyors including a facilities specialist - **Follow-up survey:** Within 45 days of a condition-level deficiency (per CIHQ) - **Standards basis:** Medicare Conditions of Participation and CMS interpretive guidelines - **Sentinel events:** No submission required (per CIHQ FAQ, March 2023) - **Hospital standards:** Listed as effective 1.26, or January 2026, on CIHQ's site - **Citation:** CIHQ Hospital Accreditation Standards, Participating in Medicare (effective January 2026) - **Authority:** CIHQ (Center for Improvement in Healthcare Quality) - **Applies to:** Acute care hospitals participating in Medicare, Critical access hospitals, Acute psychiatric hospitals ## Who does CIHQ accredit? CIHQ is a member-based group set up in 1999 and based in Mexia, Texas. Its main programs cover acute care hospitals, critical access hospitals and acute psychiatric hospitals, with versions for hospitals that do and do not take part in Medicare. It also has programs for free-standing emergency centers, congregate living health facilities and substance use disorder treatment centers, plus disease-specific certifications. It lists no program for ambulatory surgery centers, hospice, home health or nursing homes. ## How does CIHQ relate to CMS deemed status? CIHQ is on CMS's list of approved accreditors. It says CMS gave it deeming authority for hospitals, critical access hospitals and acute psychiatric hospitals. Deeming means CMS accepts its survey in place of a state survey, as proof a hospital meets the Conditions of Participation (the rules for taking part in Medicare). Accreditation is voluntary. The hospital must still meet the QAPI condition in [42 CFR 482.21](https://incidentkit.ai/compliance/cms-qapi/hospitals). Other options are the [Joint Commission](https://incidentkit.ai/compliance/accreditation/joint-commission), [DNV](https://incidentkit.ai/compliance/accreditation/dnv) and [ACHC](https://incidentkit.ai/compliance/accreditation/achc). ## How do CIHQ surveys work? *CIHQ survey facts from its published FAQ (updated March 2023)* | Item | What CIHQ says | | --- | --- | | Frequency | Full accreditation surveys every three years | | Length and team | An average-size hospital: 2 to 4 days with 2 to 4 surveyors, including a facilities specialist | | Surveyors | Full-time clinicians with hospital experience, nationally certified | | Scope | All services and sites on the hospital license and billed under its Medicare number, plus contract services performed in the hospital | | Follow-up | A follow-up survey within 45 days when a condition-level deficiency is cited, which CIHQ says CMS requires | | Notice | Not stated in the FAQ. CMS reviews accreditors' policies to ensure deemed surveys are unannounced. Confirm with CIHQ. | ## What does CIHQ expect for incident reporting? CIHQ says its standards rest on the Medicare Conditions of Participation. Specific requirements come from CMS's interpretive guidelines, plus a modest set of added patient safety and quality standards. In practice, CMS's QAPI guidance, including tags A-0263 to A-0321, is the benchmark. *CIHQ and the Joint Commission differ on event reporting* | Topic | CIHQ | Joint Commission | | --- | --- | --- | | Sentinel event reports and root cause analyses | Not required to be submitted | Self-reporting encouraged; analysis and action plan required within 45 business days | | Standards basis | Medicare conditions and CMS interpretive guidelines, plus modest additions | Own standards, including National Performance Goals for hospitals | CIHQ also says it does not require core measure submissions, ISO certification or annual internal assessments. Hospitals must still meet CMS reporting rules. This comes from an FAQ updated March 2023, so confirm current policy. ## What documentation should a CIHQ-accredited hospital keep? Because the standards track CMS guidance, keep the proof CMS surveyors ask for: - The QAPI program document and governing body minutes setting data frequency and detail - A demo of the error and adverse event system, sortable by type, date, shift and unit - At least three sample events with the analysis, the changes and the follow-up data - Performance improvement project records. CMS guidance says to keep those completed in the previous six years. - Quality data from contracted services - Plans of correction and follow-up evidence for any condition-level finding ## Where does IncidentKit fit? CIHQ does not ask hospitals to submit root cause analyses, but CMS still expects them for QAPI. [IncidentKit](https://incidentkit.ai/product/investigations) keeps them as internal records, and [corrective actions](https://incidentkit.ai/product/corrective-actions) with due dates and evidence support a plan of correction. See [hospital QAPI](https://incidentkit.ai/compliance/cms-qapi/hospitals). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Standards track CMS QAPI guidance: track errors and adverse events, analyze, act | Intake by text, QR code, email or web form, structured investigations and corrective actions: the same records used for the hospital QAPI condition. | | A sample event traced from report to analysis to action to follow-up data | Each incident links its investigation, corrective actions and verification in one record with an audit trail. | | Root cause analysis expected by CMS, though not submitted to CIHQ | Investigations stay internal. Lauren drafts. A person signs. Human-authored RCA templates are rolling out. | | Follow-up survey within 45 days of a condition-level finding | Corrective actions with owners, due dates and evidence support the plan of correction response. | | Governing body oversight evidence | Compliance packets give a QAPI summary. Meeting minutes remain yours. | ## Frequently asked questions ### Does CIHQ require hospitals to report sentinel events? According to CIHQ's FAQ (March 2023), no. CMS still expects you to track adverse events, analyze causes and act. Confirm current policy. ### How often does CIHQ survey, and for how long? Every three years, CIHQ says. An average-size hospital should expect two to four days with two to four surveyors, including a facilities specialist. CMS requires accreditors to survey at least every 36 months. ### Can CIHQ accredit an ASC, hospice or home health agency? No. It lists programs for hospitals, free-standing emergency centers, congregate living health facilities and substance use disorder treatment, not ASCs, hospice or home health. Look at AAAHC, Quad A, ACHC or the Joint Commission. ### Are CIHQ standards the same as the CMS Conditions of Participation? They are built on them. CIHQ adds a modest set of patient safety and quality standards. Meeting CIHQ standards should track meeting CMS guidance such as the QAPI tags. ## Sources - [CIHQ: Frequently asked questions (updated March 2023)](https://www.cihq.org/acc-faq.asp) - [CIHQ: Hospital accreditation program and standards](https://www.cihq.org/acc-default-exe.asp?publicACC-TYPE=HOS) - [CIHQ: About our services](https://www.cihq.org/corp-our-services.asp) - [CIHQ: About our organization](https://www.cihq.org/corp-about-us.asp) - [CMS: Accrediting organizations](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs) - [CMS Transmittal 238: State Operations Manual Appendix A, Hospitals (March 20, 2026)](https://www.cms.gov/files/document/r238soma.pdf) - [Joint Commission: Sentinel Event Policy, Comprehensive Accreditation Manual for Home Care (July 2026 update)](https://digitalassets.jointcommission.org/api/public/content/8e9d0e7ede064bc78c643a819e93ea69) ## Related - [Hospital QAPI requirements: 42 CFR 482.21 explained](https://incidentkit.ai/compliance/cms-qapi/hospitals) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [DNV hospital and ASC accreditation: CMS status and surveys](https://incidentkit.ai/compliance/accreditation/dnv) - [ACHC accreditation: deemed status, surveys and standards](https://incidentkit.ai/compliance/accreditation/achc) - [Patient safety event reporting software for hospitals](https://incidentkit.ai/solutions/hospitals) - [Deemed status: definition and meaning](https://incidentkit.ai/glossary/deemed-status) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) --- # ACHC accreditation: programs, surveys and documentation > ACHC accredits home health, hospice, surgery centers, hospitals and more. It says CMS gave it deeming authority for nine programs, so its survey can replace the state's. Deemed surveys are unannounced. Other surveys are scheduled with the provider. Source: https://incidentkit.ai/compliance/accreditation/achc · Updated Oct 5, 2026 ## Key facts - **Deemed survey notice:** Unannounced - **CMS deeming authority (per ACHC):** Nine programs, including home health, hospice, ASC, hospital and critical access hospital - **Home health:** Deeming authority since 2006 - **Hospice:** Deeming authority since 2009 - **ASC:** Deeming authority since 2003. Survey typically two days with two surveyors - **After the survey:** Final report within 10 business days. Plan of correction within 30 days - **Accreditation period:** Three years for programs such as office-based surgery and sleep. Confirm for yours - **Citation:** ACHC accreditation standards (program-specific) - **Authority:** ACHC (Accreditation Commission for Health Care) - **Applies to:** Home health agencies and hospices, Ambulatory surgery centers and office-based surgery practices, Acute care and critical access hospitals, Pharmacy, DMEPOS, home infusion, behavioral health and other programs ## Who does ACHC accredit? ACHC says it has CMS deeming authority for nine programs: acute care hospitals, ambulatory surgery centers, clinical laboratories, critical access hospitals, DMEPOS, home health, home infusion therapy, hospice and renal dialysis. Other programs are accreditation only. They include assisted living, behavioral health, dentistry, home care (private duty), office-based surgery, palliative care, pharmacy and sleep. It also offers certifications such as telehealth, stroke and wound care. ## How does ACHC relate to CMS deemed status? *ACHC programs and Medicare status, as ACHC describes them* | Program | Medicare status | | --- | --- | | Home health | Deeming authority since 2006. A deemed survey results in accreditation and a recommendation for CMS approval. | | Hospice | Deeming authority since 2009 | | Ambulatory surgery center | Deeming authority since 2003 | | Hospital and critical access hospital | Deeming authority for both programs | | Office-based surgery, behavioral health, sleep | Accreditation only. Not a substitute for Medicare certification. | ACHC is also on CMS's list of approved accrediting organizations. Accreditation is voluntary. The alternative is a state survey. ## How do ACHC surveys work? | Item | Detail | | --- | --- | | Deemed status surveys | Unannounced. CMS no longer lets accreditors alert organizations beforehand. ACHC used to give community-based programs 30 minutes' notice. | | Non-deemed surveys | Scheduled with the organization. Office-based surgery, behavioral health and sleep surveys are announced. | | ASC survey | Typically two days with two surveyors. The ASC must have served at least 10 patients, so a surveyor can review 10 closed records and one open record. | | Home health | Usually one surveyor. A surveyor in training, a manager or a CMS surveyor overseeing the accreditor may join. | | Hospice | Record reviews and home visits scale with the number of unduplicated admissions | | Method | Observation, interviews and document review, with opening and closing conferences. Surveyors do not make the accreditation decision. | ACHC publishes a three-year accreditation period for programs such as office-based surgery and sleep. Confirm the cycle for your program with your account advisor. ## What happens after an ACHC survey? ACHC's hospice page lists these steps. Ask your account advisor whether the same timeline applies to your program. 1. **Final survey report** Provided within 10 business days of the last survey day. 2. **Plan of correction** Submitted within 30 days of the final report. ACHC accepts or asks for revisions, then sends it to its review committee. 3. **Decision letter** Sent within five business days of the review committee's decision. ACHC recommends submitting a renewal application six months before expiration to avoid a lapse. See the [plan of correction](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) guidance. ## What quality work does ACHC expect? ACHC says it presents regulatory requirements as a framework for quality that supports continuous improvement through self-assessment, data analysis and corrective action. Deemed programs must also meet CMS's own QAPI rules: | ACHC program | CMS QAPI rule | Page | | --- | --- | --- | | Home health | 42 CFR 484.65 | [Home health QAPI](https://incidentkit.ai/compliance/cms-qapi/home-health) | | Hospice | 42 CFR 418.58 | [Hospice QAPI](https://incidentkit.ai/compliance/cms-qapi/hospice) | | Ambulatory surgery center | 42 CFR 416.43 | [ASC QAPI](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) | | Hospital | 42 CFR 482.21 | [Hospital QAPI](https://incidentkit.ai/compliance/cms-qapi/hospitals) | ACHC's compliance date is the date an organization attests it meets ACHC standards. It does not apply to the Medicare conditions, which apply from the start of patient care. ## What documentation should an ACHC-accredited organization keep? - Self-assessment or mock survey results. ACHC offers a free self-assessment tool. - The QAPI proof for your CMS rule: adverse event tracking, analyses and project records - Records available for surveyor sampling, including closed ASC records - The plan of correction and evidence of each correction - For first-time community-based applicants, the signed Preliminary Evidence Checklist - Your renewal application timeline [IncidentKit](https://incidentkit.ai/product/corrective-actions) tracks each plan-of-correction item with an owner, due date and evidence, and keeps the packet current for an [unannounced survey](https://incidentkit.ai/use-cases/always-survey-ready). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Deemed programs must meet the CMS QAPI rules: 416.43, 418.58, 482.21 and 484.65 | Intake, structured investigations and corrective actions produce the record set each rule asks for. See the matching CMS QAPI page. | | Adverse event tracking, as each CMS rule defines it | A pack sets incident types, so the hospice's own definition or the home health adverse event categories become structured record types. | | Plan of correction within 30 days of the final report | Corrective actions with owner, due date, evidence and an effectiveness check, so each correction is provable. | | Self-assessment, data analysis and corrective action as the quality framework | Analytics cluster incidents by location, shift, equipment and cause, and effectiveness checks close the loop. | | Readiness for an unannounced deemed survey | Survey packets and the audit trail keep proof current, so there is nothing to assemble on the day. | ## Frequently asked questions ### Are ACHC surveys unannounced? Deemed status surveys are unannounced, because CMS no longer lets accreditors alert organizations. Other surveys are scheduled. Office-based surgery, behavioral health and sleep surveys are announced. ### What happens after an ACHC survey? A final survey report within 10 business days of the last survey day. A plan of correction within 30 days of the report. A decision letter within five business days of the review committee's decision. ### What is the ACHC compliance date? The date an organization attests it meets ACHC standards. It does not apply to the Medicare Conditions of Participation or state rules, which apply from the start of patient care. ### How many patients must a new home health agency or hospice have before survey? Initial Medicare home health: at least 10 patients needing skilled care, at least seven receiving it at survey time unless the area is rural or medically underserved. Initial hospice: at least five patients, at least three receiving care. ## Sources - [ACHC: Frequently asked questions](https://achc.org/faqs/) - [ACHC: Accreditation 101](https://achc.org/accreditation-101/) - [ACHC: Home health accreditation](https://achc.org/home-health/) - [ACHC: Hospice accreditation](https://achc.org/hospice/) - [ACHC: Ambulatory surgery center accreditation](https://achc.org/ambulatory-surgery-center/) - [ACHC: Hospital accreditation](https://achc.org/hospital/) - [CMS: Accrediting organizations](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs) ## Related - [Home health QAPI requirements: 42 CFR 484.65 guide](https://incidentkit.ai/compliance/cms-qapi/home-health) - [Hospice QAPI requirements: 42 CFR 418.58 explained](https://incidentkit.ai/compliance/cms-qapi/hospice) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [Hospital QAPI requirements: 42 CFR 482.21 explained](https://incidentkit.ai/compliance/cms-qapi/hospitals) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) - [Deemed status: definition and meaning](https://incidentkit.ai/glossary/deemed-status) - [Always Survey-Ready: Stay Prepared for Unannounced Surveys](https://incidentkit.ai/use-cases/always-survey-ready) --- # Quad A accreditation: surveys, standards and Patient Safety Data Reporting > Quad A, formerly AAAASF, accredits office-based surgery sites, Medicare surgery centers and related programs. Facilities self-survey yearly, get an onsite survey every three years and must meet 100 percent of the standards. Quarterly Patient Safety Data Reporting is required, including every unanticipated sequela. Source: https://incidentkit.ai/compliance/accreditation/quad-a · Updated Oct 5, 2026 ## Key facts - **Survey cycle:** Annual self-survey; onsite survey every three years - **Initial survey:** 100 percent compliance required, with a plan of correction - **Correction window:** 30 days after the survey - **PSDR:** Quarterly: three random cases per surgeon plus all unanticipated sequelae - **PSDR deadlines:** April 15, July 15, October 15, January 15 - **Late PSDR:** 60-day probation and $100 per noncompliant physician - **Medicare programs:** ASC, outpatient physical therapy, rural health clinic - **Medicare ASC recognition:** Since 1998, per Quad A - **Citation:** Quad A accreditation standards (program standards manuals) - **Authority:** Quad A (formerly AAAASF) - **Applies to:** Office-based surgery and office-based procedural facilities, Medicare-certified ambulatory surgery centers, Oral maxillofacial surgery and pediatric dentistry facilities, Outpatient physical therapy and rural health clinics (Medicare programs) ## Who does Quad A accredit? Quad A is a non-profit, physician-founded group that began in 1980. It became Quad A in a 2022 rebrand of AAAASF. Outpatient programs cover office-based surgery, office-based procedural care, oral maxillofacial surgery and pediatric dentistry. Medicare programs cover ambulatory surgery centers, outpatient physical therapy and rural health clinics. Quad A requires licensed and credentialed staff, board-certified surgeons with hospital privileges for their procedures, and anesthesia professionals for deeper levels of anesthesia. ## How does Quad A relate to CMS deemed status? Quad A is on CMS's list of approved accreditors and says it has been a Medicare-recognized authority for ASCs since 1998. That means CMS accepts its survey in place of a state survey. An ASC applicant files CMS form 855B before applying. A deemed ASC must still meet the QAPI condition in [42 CFR 416.43](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers). Quad A sends final survey decisions to the right state or federal agencies. ## How do Quad A surveys work? *The Quad A survey path* | Step | What happens | | --- | --- | | Preparation | A dedicated accreditation specialist confirms survey availability, schedules the survey and provides an outline. | | Onsite survey | Surveyors are board-certified physicians, dentists, licensed nurses or physical therapists. They judge each standard compliant or noncompliant, using the standards manual as a checklist. | | Initial standard | A facility must show 100 percent compliance at the initial survey. | | Deficiencies | Each gets a Statement of Deficiency. The facility has 30 days to correct and submit evidence under a plan of correction. | | Decision | New facilities go to an accreditation committee for approval. | | Ongoing | An annual self-survey and an onsite survey every three years, with continuous compliance between. | ## What is Patient Safety Data Reporting? Patient Safety Data Reporting, or PSDR, is Quad A's required quality control process, introduced in 2001. It applies to the office-based surgery, office-based procedural, oral maxillofacial, pediatric dentistry, international surgical and Medicare ASC programs. An unanticipated sequela is an unexpected bad outcome after a procedure. | Item | Requirement | | --- | --- | | What | Three random cases per surgeon or proceduralist each quarter, including the first case each month, plus all unanticipated sequelae | | Deadlines | April 15, July 15, October 15 and January 15 for the quarter just ended | | How | Entered directly in Quad A's online system. No paper forms. Sequelae can be entered as they happen. | | Fewer than three cases | Report the exemption on Quad A's form and enter every case performed | | Late | A 60-day probation and a $100 late fee per noncompliant physician | ## What quality work does Quad A expect? Quad A uses PSDR data to monitor trends such as complications and mortalities and to revise its standards. Its surveyor materials include condition-level deficiency guidance and templates for immediate jeopardy reporting and removal plans. A Medicare ASC also needs the QAPI proof CMS asks for: tracked adverse events, root causes, fixes that last and project records. ## What documentation should a Quad A facility keep? - Each PSDR submission and the internal case record behind it - Every unanticipated sequela with its review and outcome - The annual self-survey checklist - Plan of correction evidence for every deficiency - Credentials, board certification, hospital privileges and anesthesia provider records - The accreditation certificate, displayed in public view - For a Medicare ASC, the QAPI records under 416.43 ## Where does IncidentKit fit with PSDR? IncidentKit does not submit to Quad A's portal. It keeps the internal record: the sequela as [reported](https://incidentkit.ai/product/incident-reporting), the [investigation](https://incidentkit.ai/product/investigations) and the [corrective action](https://incidentkit.ai/product/corrective-actions). The PSDR entry and your internal review then match. PSDR random cases come from your case records, not from incident data. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | PSDR: all unanticipated sequelae, entered as they happen | The event is recorded when reported, with its review. You make the PSDR entry in Quad A's portal from that record. IncidentKit does not submit to the portal. | | PSDR: three random cases per surgeon each quarter | Not an IncidentKit feature. Random cases come from your case records and go straight into Quad A's portal. | | Plan of correction: 30 days to correct and submit evidence | Corrective actions with owner, due date and attached evidence. Nothing closes until verified. | | Medicare ASC: QAPI under 42 CFR 416.43 | Investigations and corrective actions produce the cause and fix records. See the ASC QAPI page. | | Continuous compliance between surveys | Analytics and the audit trail show recurring problems and who changed what, so readiness does not depend on survey week. | ## Frequently asked questions ### How often does Quad A survey a facility? A self-survey every year and an onsite survey every three years. After a survey, a facility has 30 days to correct deficiencies and submit evidence. ### What must be reported in Patient Safety Data Reporting? Each quarter: three random cases per surgeon or proceduralist, including the first case each month, plus all unanticipated sequelae. Enter them in Quad A's online system. ### What happens if PSDR is late? Probation for 60 calendar days after the extension period ends, plus a $100 late fee per noncompliant physician. A physician with fewer than three cases uses the exemption form. ### Is a Quad A survey unannounced? Quad A's guidance describes scheduling with an accreditation specialist and a survey outline in advance. It does not state its notice policy for Medicare ASC surveys. CMS expects deemed surveys to be unannounced, so confirm with Quad A. ## Sources - [Quad A: What is accreditation?](https://www.quada.org/what-is-accreditation) - [Quad A: Patient Safety Data Reporting](https://www.quada.org/patient-safety-data-reporting) - [Quad A: Medicare programs](https://www.quada.org/medicare-programs) - [Quad A: Interested facilities](https://www.quada.org/prospective-facilities) - [Quad A: Surveyors](https://www.quada.org/surveyors) - [Quad A: About us](https://www.quada.org/about-us) - [CMS: Accrediting organizations](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs) ## Related - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [AAAHC accreditation: surveys, deemed status and QI studies](https://incidentkit.ai/compliance/accreditation/aaahc) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) - [Incident reporting software for surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers) - [Deemed status: definition and meaning](https://incidentkit.ai/glossary/deemed-status) --- # DNV accreditation: CMS-approved programs, surveys and documentation > DNV is a CMS-approved accreditor for hospitals, critical access hospitals, psychiatric hospitals and, since December 2025, surgery centers. CMS checks that its standards meet Medicare rules and its surveys are unannounced. Confirm DNV's own survey cycle with DNV. Source: https://incidentkit.ai/compliance/accreditation/dnv · Updated Oct 5, 2026 ## Key facts - **Hospital approval term:** September 26, 2026 through September 26, 2032 - **Critical access hospital term:** December 23, 2024 through December 23, 2028 - **ASC approval term:** December 8, 2025 through December 10, 2029 - **CMS rule for accreditors:** Survey at least every 36 months (42 CFR 488.5(a)(4)(i)) - **Unannounced surveys:** CMS reviews each accreditor's policy to ensure deemed surveys are unannounced - **ASC survey team:** At least one RN or physician with hospital or ASC survey experience - **Not restated here:** DNV's own survey cycle and standards numbering. Confirm with DNV - **Citation:** DNV Healthcare accreditation requirements for hospitals, critical access hospitals, psychiatric hospitals and ASCs - **Authority:** DNV Healthcare USA Inc. - **Applies to:** Hospitals, critical access hospitals and psychiatric hospitals, Ambulatory surgery centers (CMS-approved program from December 2025) ## Which DNV programs does CMS approve? *DNV programs and CMS approval terms* | Program | CMS decision | | --- | --- | | Hospital | Continued approval effective September 26, 2026 through September 26, 2032 | | Critical access hospital | Continued approval effective December 23, 2024 through December 23, 2028 | | Psychiatric hospital | Approved; CMS reviewed DNV's application for continued approval in 2024 | | Ambulatory surgery center | Initial approval effective December 8, 2025 through December 10, 2029 | CMS says accreditation is voluntary and not required for Medicare participation. CMS may approve an accreditor for up to six years, and generally no more than four for a new program type. ## What does CMS check about DNV? - That its standards meet or exceed the Medicare conditions - That its surveys are comparable to state surveys, including team makeup and reporting of deficiencies - That its policies ensure surveys are unannounced - That it answers plans of correction on time - Its conflict-of-interest policies for surveyors and decision-makers - Its agreement to give CMS current survey reports and corrective action plans > **New oversight rule** A CMS final rule to tighten oversight of accreditors takes effect June 16, 2027. It covers conflicts of interest, validation and performance standards. ## What did CMS make DNV change? Approval notices list the revisions DNV completed. They show what a deemed program must cover. | Program | Examples of required revisions | | --- | --- | | ASC | Measure, analyze and track adverse patient events (416.43(a)(2), (c)(2)). Staff familiar with preventive strategies (416.43(c)(3)). Investigate all grievances (416.50(d)(5)). Infection plan of action with immediate corrective and preventive measures (416.51(b)(3)). An infection control worksheet at survey to confirm safe injection practices | | Critical access hospital | An active facility-wide infection prevention and antibiotic stewardship program (485.640). Reporting of withdrawals from accreditation within three business days. | | Hospital (2026) | Fire Safety Evaluation System guidance and defined testing and maintenance frequencies | ## How do DNV surveys work? CMS requires accreditors to survey at least every 36 months under 42 CFR 488.5(a)(4)(i), and allows more often. DNV gives accredited organizations its own survey cycle, activities and standards numbering. This page does not restate them, so check your DNV agreement. For ASCs, CMS required DNV's survey team to include at least one RN or physician with hospital or ASC survey experience. For ASCs that CMS selects for validation, the state agency surveys no later than 60 days after the accreditor's survey. Anyone may still file a complaint with the state agency about a deemed facility. ## What documentation should a DNV-accredited organization keep? - QAPI proof for your CMS rule: [hospital QAPI](https://incidentkit.ai/compliance/cms-qapi/hospitals) or [ASC QAPI](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - Plans of correction and the evidence of each correction - ASC infection control and safe injection practice monitoring records - Life safety inspection, testing and maintenance records at the frequencies CMS requires - Copies of survey reports - Grievance files showing each grievance investigated ## Where does IncidentKit fit? [IncidentKit](https://incidentkit.ai/product/incident-reporting) produces the same records CMS made DNV require: tracked adverse events, preventive strategies and infection corrective actions. [Corrective actions](https://incidentkit.ai/product/corrective-actions) hold the proof. The [Joint Commission](https://incidentkit.ai/compliance/accreditation/joint-commission) and [CIHQ](https://incidentkit.ai/compliance/accreditation/cihq) pages cover the other hospital accreditors. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | ASC 416.43(a)(2), (c)(2): measure, analyze and track adverse patient events | Intake by text, QR code, email or web form, plus routing. Analytics cluster events by location, shift, equipment and cause. | | ASC 416.43(c)(3): staff familiar with preventive strategies | Corrective actions carry attached evidence such as a training sign-off. | | ASC 416.51(b)(3): infection plan of action with immediate corrective and preventive measures | Routing and escalation put an infection event in front of its owner at once. The corrective action carries a due date and evidence. | | ASC 416.50(d)(5): investigate all grievances | A grievance can come in through any intake path and go to an owner, with the investigation and resolution in one record. | | Hospital and critical access hospital QAPI | The same record set supports the hospital QAPI condition. See the hospital QAPI page. | | Plans of correction answered in time | Corrective actions with owners, due dates and evidence, so each response is provable. | ## Frequently asked questions ### Is DNV approved by CMS for ambulatory surgery centers? Yes, since December 2025, effective December 8, 2025 through December 10, 2029. CMS required DNV to revise standards to cover tracking adverse patient events and staff knowledge of preventive strategies. ### Does DNV accreditation replace a state survey? For Medicare purposes it can. CMS treats a facility accredited under an approved DNV program as meeting the Medicare conditions. Anyone can still file a complaint with the state, and CMS may pick facilities for a validation survey. ### How often does DNV survey? At least every 36 months under CMS rules. DNV sets its own survey cycle, so check your DNV agreement. Deemed surveys must be unannounced. ### How long does CMS approval of DNV last? It depends on the program. Hospital: September 26, 2026 through September 26, 2032. Critical access hospital: December 23, 2024 through December 23, 2028. ASC: December 8, 2025 through December 10, 2029. CMS may approve an accreditor for up to six years. ## Sources - [Federal Register: continued CMS approval of DNV's hospital accreditation program, September 17, 2026](https://www.federalregister.gov/documents/2026/09/17/2026-19061/medicare-and-medicaid-programs-application-from-dnv-healthcare-usa-inc-dnv-for-continued) - [Federal Register: initial CMS approval of DNV's ASC accreditation program, December 8, 2025](https://www.federalregister.gov/documents/2025/12/08/2025-22203/medicare-and-medicaid-programs-approval-of-application-by-dnv-healthcare-inc-for-initial-cms) - [Federal Register: continued CMS approval of DNV's critical access hospital program, December 11, 2024](https://www.federalregister.gov/documents/2024/12/11/2024-29075/medicare-and-medicaid-programs-approval-of-application-by-the-dnv-healthcare-usa-inc-for-continued) - [Federal Register: Strengthening Oversight of Accrediting Organizations, June 16, 2026](https://www.federalregister.gov/documents/2026/06/16/2026-12069/medicare-program-strengthening-oversight-of-accrediting-organizations-aos-and-preventing-ao) - [Federal Register: CMS approval of the Joint Commission's hospital program, 2025 (36-month survey rule)](https://www.federalregister.gov/documents/2025/06/23/2025-11451/medicare-and-medicaid-programs-application-from-the-joint-commission-for-continued-cms-approval-of) - [CMS State Operations Manual, Appendix L: Ambulatory Surgical Centers](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/Downloads/som107ap_l_ambulatory.pdf) - [CMS: Accrediting organizations](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs) - [DNV (accreditor site; standards and survey cycle are published to accredited organizations)](https://www.dnv.com/) ## Related - [Hospital QAPI requirements: 42 CFR 482.21 explained](https://incidentkit.ai/compliance/cms-qapi/hospitals) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [CIHQ accreditation for hospitals: surveys and standards](https://incidentkit.ai/compliance/accreditation/cihq) - [Deemed status: definition and meaning](https://incidentkit.ai/glossary/deemed-status) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) --- # CARF accreditation: what providers should know > CARF is a nonprofit accreditor of health and human services, founded in 1966. CMS does not list it, so CARF does not give Medicare deemed status. Surveys are peer reviews announced at least 30 days ahead. Providers send a Quality Improvement Plan within 90 days. Source: https://incidentkit.ai/compliance/accreditation/carf · Updated Oct 5, 2026 ## Key facts - **Founded:** 1966, as the Commission on Accreditation of Rehabilitation Facilities - **Medicare deemed status:** No; CARF is not on CMS's approved accreditor list - **Survey notice:** Written notice of dates at least 30 days before - **Decisions:** Three-Year, One-Year, Provisional, Nonaccreditation; Five-Year for CCRCs - **Quality Improvement Plan:** Due within 90 days of the decision - **Annual report:** Annual Conformance to Quality Report - **Quality framework:** ASPIRE to Excellence, Section 1 of each standards manual - **Citation:** CARF standards manuals (Section 1, ASPIRE to Excellence, plus program standards) - **Authority:** CARF International - **Applies to:** Behavioral health and opioid treatment programs, Aging services, including assisted living, person-centered long-term care communities and CCRCs, Medical rehabilitation, child and youth, employment and community, and vision rehabilitation services ## Who does CARF accredit? CARF began in 1966 as the Commission on Accreditation of Rehabilitation Facilities and says it serves more than 9,600 providers. Its standards manuals cover seven areas: - Behavioral health, including residential treatment, crisis programs and certified community behavioral health clinics - Aging services: assisted living, person-centered long-term care communities (nursing homes), home and community services and CCRCs - Medical rehabilitation, such as inpatient and outpatient rehabilitation programs - Child and youth services - Employment and community services - Opioid treatment programs - Vision rehabilitation services CARF says it is the only accreditor of CCRCs. ## Does CARF accreditation give Medicare deemed status? No. Deemed status means CMS accepts an accreditor's survey in place of a state survey. CMS's list of approved accreditors names ACHC, Quad A, AAAHC, CIHQ, CHAP, DNV, the Joint Commission, NDAC and The Compliance Team, not CARF. States, payers and regulators use CARF in other ways. CARF says many jurisdictions recognize or require it. It has turned the SAMHSA 2023 criteria for certified community behavioral health clinics into ratable standards. A nursing home accredited under CARF's long-term care standards still takes the state survey and must meet [42 CFR 483.75](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities). ## How do CARF surveys work? CARF surveyors are industry peers. They consult rather than inspect. The team observes services, interviews persons served and other stakeholders, reviews documents and consults with staff. The provider picks a two-month window on its application. CARF gives written notice of the specific dates at least 30 days ahead. *CARF survey and follow-up timeline* | Step | Timing | | --- | --- | | Written notice of survey dates | At least 30 days before the survey | | Survey team coordinator call | About three weeks before | | Accreditation decision and written report | About six to eight weeks after the survey | | Certificate of accreditation | Within 60 days of the decision | | Quality Improvement Plan (QIP) | Within 90 days of being notified of the decision | | Annual Conformance to Quality Report (ACQR) | Annually after accreditation. Form sent about ten weeks before due | Decisions are Three-Year, One-Year or Provisional Accreditation, or Nonaccreditation. CCRCs can receive Five-Year Accreditation. ## What quality work does CARF expect? Section 1 of every standards manual is ASPIRE to Excellence, a framework for business practices and quality improvement. CARF also publishes a Performance Management Workbook. This page cites no standard numbers. Use your manual. *ASPIRE to Excellence and where incident data fits* | Step | CARF's meaning | Incident data supplies | | --- | --- | --- | | Assess the environment | Analyze the legal, regulatory and competitive setting | Event types and risks seen in the setting | | Persons served and stakeholders | Obtain input from everyone affected | Reports and concerns raised by staff and others | | Review results | Set measurable goals and indicators, then review and analyze them | Trends and rates by cause and location | | Effect change | Turn analysis into focused action | Corrective actions and effectiveness checks | ## What documentation should a CARF-accredited provider keep? - Self-evaluation and pre-survey workbook results, plus the plan of action built from them - The Survey Notice Poster, displayed once survey dates are set - Documents showing conformance for each standard, and the names of people who can explain them - The QIP and proof of each action in it - Each year's ACQR - Performance and outcome data, and records of incidents and the actions taken ## How is CARF different from CMS-approved accreditors? | Item | CARF | Joint Commission, ACHC (deemed programs) | | --- | --- | --- | | Medicare deemed status | No | Yes, for CMS-approved programs | | Survey notice | Written notice at least 30 days ahead | Deemed surveys are unannounced | | Style | Consultative peer review | Survey against standards plus Medicare conditions | See the [Joint Commission](https://incidentkit.ai/compliance/accreditation/joint-commission) and [ACHC](https://incidentkit.ai/compliance/accreditation/achc) pages. [IncidentKit](https://incidentkit.ai/product/corrective-actions) tracks QIP items with an owner, due date and evidence. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | ASPIRE Review results: measurable goals and indicators, analyzed | Analytics cluster incidents by location, shift, equipment and cause, giving trends and rates as one input to performance management. | | ASPIRE Effect change: turn analysis into focused action | Corrective actions with owner, due date, evidence and an effectiveness check. Nothing closes until verified. | | QIP within 90 days of the decision | Each QIP item becomes a corrective action with an owner, due date and attached evidence. | | Annual Conformance to Quality Report | A compliance packet summarizes the year's events, actions and results to support the report. | | Risk management: safety and protection of persons served | Intake, routing and escalation, and structured investigations. Lauren drafts. A person reviews and signs. | ## Frequently asked questions ### Is CARF accreditation recognized by CMS for deemed status? No. CARF is not on CMS's list of approved accreditors, so it does not replace a state survey or Medicare certification. Providers must still meet CMS rules such as QAPI. ### How long does CARF accreditation last? Three-Year, One-Year or Provisional Accreditation, or Nonaccreditation. CCRCs can get Five-Year Accreditation. The decision comes about six to eight weeks after the survey, and the certificate within 60 days. ### What is the CARF Quality Improvement Plan? It is due within 90 days of the accreditation decision. It lists actions taken or planned for the areas for improvement in the survey report. Opioid treatment programs also send an implementation report within 180 days. ### What is the Annual Conformance to Quality Report? A report providers submit each year after they achieve accreditation. CARF sends the form about ten weeks before it is due. It sits alongside the QIP. ## Sources - [CARF: Steps to accreditation](https://carf.org/accreditation/steps-accreditation/) - [CARF: Survey preparation for accreditation](https://carf.org/accreditation/survey-preparation-accreditation/) - [CARF: Our standards and the ASPIRE to Excellence framework](https://carf.org/accreditation/our-standards/) - [CARF: About CARF](https://carf.org/about/) - [CARF: Behavioral Health programs](https://carf.org/accreditation/programs/behavioral-health/) - [CARF: Aging Services programs](https://carf.org/accreditation/programs/aging-services/) - [CARF: Value for payers and regulators](https://carf.org/accreditation/payers/) - [CMS: Accrediting organizations](https://www.cms.gov/medicare/health-safety-standards/accreditation-programs) ## Related - [Incident reporting software for behavioral health](https://incidentkit.ai/solutions/behavioral-health) - [Incident reporting software for assisted living](https://incidentkit.ai/solutions/assisted-living) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [Deemed status: definition and meaning](https://incidentkit.ai/glossary/deemed-status) - [Survey and accreditation readiness: a continuous approach](https://incidentkit.ai/guides/survey-and-accreditation-readiness) --- # F689: free of accident hazards, supervision and devices > F689 is the CMS nursing home tag for accidents. The facility must keep the resident environment as free of accident hazards as possible and give each resident enough supervision and assistive devices. CMS cites falls, elopement, burns and unsafe equipment. A fall alone is not a deficiency; an avoidable one is. Source: https://incidentkit.ai/compliance/f-tags/f689 · Updated Oct 5, 2026 ## Key facts - **Tag title:** Free of Accident Hazards/Supervision/Devices - **Regulation:** 42 CFR 483.25(d)(1) and (d)(2) - **Guidance relied on:** Appendix PP Rev. 232 (issued 07-23-25, in use since 04-28-25); F689 section Rev. 225 (08-08-24) - **Severity note:** Level 1 does not apply. Immediate jeopardy examples: chemical access, unsupervised overdose - **Reporting clock:** None of its own. F580 notice and abuse clocks can apply - **How often cited:** 3,393 citations nationally in the first half of 2026, second only to F880 (Wisconsin DHS summary) - **Often cited with:** F580, F600, F604, F656, F700, F867 - **Citation:** F689 · 42 CFR 483.25(d) - **Authority:** CMS - **Applies to:** Medicare-certified skilled nursing facilities, Medicaid-certified nursing facilities ## What F689 covers F689 enforces 42 CFR 483.25(d). CMS cites falls, elopement, scalds, unsafe smoking, chemical access, transfer and lift injuries, and hazardous equipment here. The test is whether the accident was avoidable. It was avoidable if the facility missed one of four steps. The steps: identify the hazard or the resident's risk, evaluate and reduce it, put interventions in place, and monitor whether they worked. Bed rails go to F700 and physical restraints to F604. F689 covers other hazardous devices, such as defective, misused, removed or poorly fitted ones. Resident-to-resident altercations (fights between residents) go to [F600](https://incidentkit.ai/compliance/f-tags/f600) first; F689 applies if the act was not deliberate. ## What surveyors check and ask for Surveyors use the Accidents Critical Element Pathway. They walk the building for hazards and review the assessment, care plan and orders for residents with a concern. For anyone in the building under 14 days, they also review the baseline care plan (due within 48 hours). | Surveyors ask for | Have ready | | --- | --- | | Incident or accident report | Date, time, place, what the resident was doing, injuries, who was told, response | | Fall risk assessment and the care plan in force that day | Risk factors, interventions, owners | | Proof the plan changed after the event | Care plan revision dated after the event, with the reason | | Supervision and staffing on that shift | Assignment sheets, supervision plan, call light and alarm response | | Environment and equipment checks | Rounds logs, device inspections, hot water temperature logs, repair orders | | QAA committee review of accidents | Trends by location, shift and time, and the action plans | Incident and accident reports are open to surveyors; see [F865](https://incidentkit.ai/compliance/f-tags/f865). CMS also tracks falls with major injury as a quality measure (MDS item J1900C). ## What makes an F689 deficiency more severe Severity rises with harm, and scope rises with the number of residents and staff involved. Level 4 is immediate jeopardy: noncompliance that has caused or is likely to cause serious injury, harm, impairment or death. | Level | Example from CMS guidance | | --- | --- | | 4: immediate jeopardy | Corrosive cleaner within reach of residents with dementia; one drank drain opener. A resident with known substance use disorder was away about five hours, unassessed for hours after return, then found unresponsive from an overdose. | | 3: actual harm | The care plan's two-person transfer was not used; the resident fell and needed sutures. The care plan's smoking apron was not applied; the resident had a second-degree burn. | | 2: potential for more than minimal harm | Clutter and building materials beside a walkway residents use. No consistent process to know when a resident with substance use disorder leaves. | Once immediate jeopardy is removed, surveyors lower what remains at that tag to level 2, or to harm if other residents were also harmed. Section 483.25 findings can count as substandard quality of care, a CMS category for serious findings. This happens at immediate jeopardy, pattern or widespread harm, or widespread potential for more than minimal harm. ## Reporting clocks that apply after a fall F689 has no reporting clock of its own. Three others apply. - **Notify now.** After an accident that causes injury and may need a physician, the facility must act immediately. It must inform the resident, consult the physician and notify the representative (42 CFR 483.10(g)(14), F580). - **Unexplained injury.** If nobody saw the cause, the resident cannot explain it and it looks suspicious, it is an injury of unknown source. The [F609](https://incidentkit.ai/compliance/f-tags/f609) clocks run: 2 hours if abuse is alleged or serious bodily injury results, otherwise 24 hours. - **State rules.** Some states require every fall to be reported to the state agency; check yours. ## Documentation gaps that lead to citations - The report says what happened, not what the resident was doing. - The same intervention (non-skid socks, call light in reach) follows every fall. - A position-change alarm is the only intervention; CMS says alarms should not be the primary or sole one. - The care plan calls for a two-person assist, but no record shows it happened. - Hazards staff notice are not logged, so nobody owns the fix. - Nobody checks whether the new intervention worked. ## Show a good investigation and corrective action After a fall, CMS lists these steps: treat any injury, find the cause, address risk factors, and revise the care plan or practice. Record each step with a time and an owner. 1. **Examine and treat** Assess, treat, and notify the physician and representative. Record the times. 2. **Retrace the event** Where, when, what the resident was doing, footwear, equipment, staff on the unit. 3. **Name contributing factors** Check CMS's list: environment, medications, acute change, continence, cognition, pain. 4. **Change the plan** Give the change an owner and start date. Set an interim measure if it cannot start today. 5. **Check that it worked** Set a review date. Check falls and near misses for that resident, place and shift. Close only with evidence. ## How IncidentKit supports F689 IncidentKit runs alongside your EHR and does not replace clinical assessment. Staff report by text, QR quick report, email or web form (voice reporting is rolling out). [Lauren](https://incidentkit.ai/product/lauren) asks follow-up questions and drafts the investigation. A person always reviews, edits and signs; drafted fields read "Lauren · draft" until approved. [Investigations](https://incidentkit.ai/product/investigations) record contributing factors and disposition. [Corrective actions](https://incidentkit.ai/product/corrective-actions) carry an owner, due date, evidence and an effectiveness check. [Analytics](https://incidentkit.ai/product/analytics) show clusters for the QAA committee. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Identify hazards and each resident's accident risk | QR quick report, text, email and web form capture hazards and near misses. | | Evaluate and analyze hazards and risks | Investigations record contributing factors and five whys. Analytics show clusters by location, shift and cause. | | Implement interventions with adequate supervision and devices | Corrective actions carry an owner, due date and evidence. | | Monitor effectiveness and modify the plan | Each corrective action has an effectiveness check. Nothing closes until verified. | | Notify the physician and representative after an injury (F580) | Routing and escalation alerts the roles you set, such as the DON. The audit trail logs each notification. | | Show the QAA committee accident trends (F867) | Compliance packets include a QAPI summary built from incident and corrective action data. | ## Frequently asked questions ### Is every resident fall an F689 deficiency? No. CMS says a fall does not necessarily mean deficient practice (failing the rule), because not every fall can be avoided. An avoidable fall, where the facility missed a step, is what gets cited. ### Do bed or chair alarms satisfy F689? No. CMS says alarms should not be the primary or sole intervention and do not replace supervision. If you use them, document why and check that they work. ### Which records do surveyors usually ask for after a fall? The incident report, fall risk assessment, care plan before and after the event, physician orders, shift staffing and QAA reviews of accident trends. Incident reports are not shielded from surveyors. ### When is a resident injury an abuse or neglect issue instead of F689? When the act was deliberate. A deliberate resident-to-resident altercation is reviewed as potential abuse at F600, even when a resident has dementia. A non-deliberate act stays at F689. Neglect at F600 needs evidence the facility knew or should have known and did not act. ## Sources - [eCFR, 42 CFR 483.25 (quality of care, including (d) accidents), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-483.25) - [CMS State Operations Manual, Appendix PP, Guidance to Surveyors for Long Term Care Facilities (Rev. 232, issued 07-23-25; revised guidance used on surveys since 04-28-25): F689 section (Rev. 225, issued 08-08-24, implementation 08-08-24)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [eCFR, 42 CFR 483.10 ((g)(14) notification of changes), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-483.10) - [CMS State Operations Manual, Chapter 7, Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities (Rev. 244, issued 06-26-26): scope and severity matrix, immediate jeopardy, substandard quality of care](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107c07pdf.pdf) - [CMS memo QSO-25-14-NH (revised 2025-03-10): Revised Long-Term Care Surveyor Guidance, effective April 28, 2025](https://www.cms.gov/files/document/qso-25-14-nh-revised-2025-03-10.pdf) - [Wisconsin Department of Health Services, Top Ten Federal Health Citations, First Half 2026 (national, state and CMS Region 5 citation counts)](https://www.dhs.wisconsin.gov/regulations/nh/2026-h1-dqa-bnhrc-top-citations-region.pdf) - [CMS, MDS 3.0 Quality Measures User's Manual v16.0 (effective October 1, 2023): falls with major injury, item J1900C](https://www.cms.gov/files/document/mds-30-qm-users-manual-v160pdf.pdf) ## Related - [F600 free from abuse and neglect: what surveyors cite](https://incidentkit.ai/compliance/f-tags/f600) - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) - [F867 QAPI improvement activities: adverse event tracking](https://incidentkit.ai/compliance/f-tags/f867) - [Fall Reporting: What to Record and Review After a Fall](https://incidentkit.ai/use-cases/fall-reporting) - [Fall Incident Report Template for Healthcare (Printable)](https://incidentkit.ai/templates/fall-incident-report) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) - [Immediate jeopardy: definition and meaning](https://incidentkit.ai/glossary/immediate-jeopardy) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) --- # F600: free from abuse and neglect > F600 protects every nursing home resident's right to be free from abuse and neglect. This covers harm by staff, another resident or a visitor. CMS says the facility can be cited if abuse occurred, even if it screened, trained and acted promptly. Reporting and investigation duties sit in F609 and F610. Source: https://incidentkit.ai/compliance/f-tags/f600 · Updated Oct 5, 2026 ## Key facts - **Tag title:** Free from Abuse and Neglect - **Regulation:** 42 CFR 483.12(a)(1) - **Guidance relied on:** Appendix PP Rev. 232 (issued 07-23-25, in use since 04-28-25). F600 section Rev. 211 (02-03-23) - **Reporting clocks:** In F609: 2 hours for abuse or serious bodily injury. 24 hours otherwise. Results within 5 working days - **Severity note:** Level 1 does not apply. Abuse can be cited at harm or immediate jeopardy with no documented injury - **How often cited:** 406 citations in CMS Region 5 (IL, IN, MI, MN, OH, WI) in the first half of 2026 (Wisconsin DHS summary) - **Related tags:** F602, F603, F607, F609, F610, F656, F689 - **Citation:** F600 · 42 CFR 483.12(a)(1) - **Authority:** CMS - **Applies to:** Medicare-certified skilled nursing facilities, Medicaid-certified nursing facilities ## What F600 covers F600 enforces 42 CFR 483.12(a)(1). The facility may not use verbal, mental, sexual or physical abuse. It may not use corporal punishment or involuntary seclusion. Misappropriation and exploitation go to F602, and involuntary seclusion to F603. CMS defines abuse as willful infliction of injury, unreasonable confinement, intimidation or punishment. The result is harm, pain or mental anguish. Abuse also covers deprivation of needed goods or services. Abuse through technology counts too, such as demeaning photos shared on social media. Willful means the act was deliberate, not that harm was intended. Neglect is a failure to provide the goods and services needed to avoid physical harm, pain, mental anguish or emotional distress. At F600, neglect is about structures and processes: the facility's systems for staffing, supplies, training and oversight. One missed task is usually cited at the care tag, such as F686 or [F689](https://incidentkit.ai/compliance/f-tags/f689). Staff includes employees, the medical director, consultants, contractors, volunteers and students. The person responsible can also be another resident or a visitor. A resident-to-resident altercation is reviewed as potential abuse. Cognitive impairment does not rule out a deliberate act. ## What surveyors check and ask for Surveyors use the Abuse Critical Element Pathway (CMS-20059) or the Neglect pathway (CMS-20130). They establish what happened, what protected the resident, and what the facility did next. | Type | Surveyors ask for | Have ready | | --- | --- | --- | | Staff to resident | Shift roster and timecards. Abuse-prevention training logs. Personnel record of the person involved. | Screening, discipline and training dates. Who supervised the unit. | | Resident to resident | Behavior history. Mood, behavior and cognition assessments. Care plan interventions. | Proof each intervention happened. Proof supervision was adequate. | | Visitor to resident | Social history. Visitor access policy and any restriction. | Evidence the facility acted on earlier concerns. | | Neglect | Policies. Staffing and supply records. How leadership monitors care. | How leadership responded to staff concerns. | Surveyors also check that the care plan was revised after the event (F656). CMS says physical or sexual abuse by staff or residents always requires corrective action and tracking by the QAA committee. ## What makes an F600 deficiency more severe CMS tells surveyors to weigh psychosocial (emotional) harm with a reasonable-person test. The question: what would a person in this resident's position be expected to feel? Abuse can be cited at harm or immediate jeopardy (level 4, the top level) without a documented injury or visible reaction. CMS lists these as likely immediate jeopardy: sexual assault and unwanted sexual touching. Any staff-to-resident physical, sexual, mental or verbal abuse is also listed. So are staff sharing demeaning photos or video and threats to withhold care as punishment. So is resident-to-resident physical abuse likely to cause fear or anxiety. A resident-to-resident incident that would likely harm a reasonable person is not cited below level 3. *CMS examples of F600 severity* | Level | Example from CMS guidance | | --- | --- | | 4: immediate jeopardy | A resident with known sexually inappropriate behavior was found with a severely cognitively impaired resident. There was no assessment or care plan revision. In another case, a resident who needed 1:1 supervision pushed a resident, who fractured an arm, while unsupervised. | | 3: actual harm | A resident slapped another in the face after earlier aggressive remarks to others. The one nurse aide present was transferring a third resident. | | 2: potential for more than minimal harm | A resident verbally abused another at a shared table. Staff did not intervene. No altercation was documented. | Past noncompliance can also be cited. The facility may have corrected the problem before the survey. Then surveyors record its corrective actions on the CMS-2567, and no plan of correction is required. ## Reporting clocks F600 has no clock of its own. The clocks sit in [F609](https://incidentkit.ai/compliance/f-tags/f609) and [F610](https://incidentkit.ai/compliance/f-tags/f610). They run in real time, not business hours. | Step | Deadline | | --- | --- | | Report abuse to the administrator and State Survey Agency. This includes any allegation that results in serious bodily injury. | Immediately. No later than 2 hours after the allegation is made. | | Report neglect, exploitation, mistreatment or misappropriation. This is for cases with no abuse and no serious bodily injury. | No later than 24 hours | | Report the investigation results. Include corrective action if the allegation is verified. | Within 5 working days of the incident | ## Documentation gaps that lead to citations - A confused resident's report goes unrecorded. CMS says not to dismiss allegations because of cognitive impairment. - The record says altercation. It never says whether the act was deliberate. - Interim protection is undocumented: who was separated, what supervision was added, who checked. - Neither resident's care plan is revised after the event. - No record shows abuse-prevention training before the event, or agency staff orientation. - Incident reports sit in a folder. The QAA committee sees a monthly count. ## Show a good investigation and corrective action 1. **Protect first** Separate the people involved, assess the resident, and record what changed and who is watching. 2. **Report on the clock** Notify the administrator and State Survey Agency. Record the clock time and any report to law enforcement. 3. **Investigate with evidence** Interview, observe, review records. Keep the proof together. See [F610](https://incidentkit.ai/compliance/f-tags/f610). 4. **Correct at the system level** If verified, fix what allowed it: staffing, supervision, training, care plan, policy. Name an owner and a date. 5. **Track it** Take it to the QAA committee. Check the fix held. Close only with proof. ## How IncidentKit supports F600 IncidentKit is the record, not the decision-maker. [Lauren](https://incidentkit.ai/product/lauren) asks who was involved and what protected the resident, then drafts the incident for a person to review and sign. [Routing and escalation](https://incidentkit.ai/product/routing-and-escalation) alerts the roles you set. The [audit trail](https://incidentkit.ai/product/audit-trail) logs who did what and when. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Protect residents from abuse and neglect by anyone | QR quick report, text, email and web form let staff report on the spot. Routing and escalation alerts the roles you set. | | Show what protected the resident after an allegation | The incident record holds interim protections and their owners. The audit trail logs every change. | | Identify behavior that raises risk between residents | Analytics group incidents by location, shift and cause. | | Revise care plans and correct systems after a verified event | Corrective actions carry an owner, due date, evidence and an effectiveness check. Nothing closes until verified. Care plan edits stay in your EHR. | | QAA committee tracking of abuse cases | Compliance packets include a QAPI summary drawn from incidents and corrective actions. | ## Frequently asked questions ### Can a nursing home be cited at F600 even if it did everything right? Yes. The resident has a right to be free from abuse. CMS rejects the argument that screening, training and prompt reporting mean abuse could not be foreseen. If surveyors find abuse occurred, they may cite current or past noncompliance. ### Is every resident-to-resident altercation abuse? No. Surveyors treat it as potential abuse, then ask whether the act was willful (deliberate). Normal social arguments are not abuse. A resident with dementia can still act deliberately. If the act was not willful, they review supervision and hazards at F689. ### What counts as neglect at F600? Neglect is a failure of the facility's systems, such as too few staff, missing supplies, no training or weak oversight. A single missed task usually goes to the care tag. Surveyors need evidence that leadership knew or should have known and did not act. ### Are staff photos of residents covered by F600? Yes. CMS counts abuse through technology, including keeping or sharing demeaning or humiliating photos and recordings, with or without the resident's consent. Staff sharing such images is likely immediate jeopardy. ### Which tag covers reporting an abuse allegation late? F609 covers late or missing reports. F610 covers weak investigations and lapses in protecting the resident during one. One event can draw citations at all three. ## Sources - [eCFR, 42 CFR 483.12 (freedom from abuse, neglect, and exploitation), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-483.12) - [CMS State Operations Manual, Appendix PP, Guidance to Surveyors for Long Term Care Facilities (Rev. 232, issued 07-23-25; revised guidance used on surveys since 04-28-25): F600 section (Rev. 211, issued 02-03-23, effective 10-21-22, implementation 10-24-22)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [CMS State Operations Manual, Chapter 7, Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities (Rev. 244, issued 06-26-26): scope and severity matrix, immediate jeopardy, substandard quality of care](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107c07pdf.pdf) - [eCFR, 42 CFR 488.301 (definitions: immediate jeopardy, substandard quality of care), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-488.301) - [CMS memo QSO-25-14-NH (revised 2025-03-10): Revised Long-Term Care Surveyor Guidance, effective April 28, 2025](https://www.cms.gov/files/document/qso-25-14-nh-revised-2025-03-10.pdf) - [Wisconsin Department of Health Services, Top Ten Federal Health Citations, First Half 2026 (national, state and CMS Region 5 citation counts)](https://www.dhs.wisconsin.gov/regulations/nh/2026-h1-dqa-bnhrc-top-citations-region.pdf) ## Related - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) - [F610 investigate, prevent and correct alleged violations](https://incidentkit.ai/compliance/f-tags/f610) - [F689 accidents and supervision: falls, hazards, devices](https://incidentkit.ai/compliance/f-tags/f689) - [Nursing home abuse reporting: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting) - [Abuse Reporting Deadlines for Nursing Homes: 2 and 24 Hours](https://incidentkit.ai/use-cases/abuse-reporting-deadlines) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) - [Immediate jeopardy: definition and meaning](https://incidentkit.ai/glossary/immediate-jeopardy) - [Nursing Home Incident Report Template (Printable)](https://incidentkit.ai/templates/nursing-home-incident-report) --- # F609: reporting of alleged violations > F609 covers reporting of alleged abuse, neglect, exploitation, mistreatment, injuries of unknown source and misappropriation. Allegations of abuse, or that result in serious bodily injury, must be reported within 2 hours. Others must be reported within 24 hours, and investigation results within 5 working days. Covered individuals must also report suspected crimes to the state agency and law enforcement. Source: https://incidentkit.ai/compliance/f-tags/f609 · Updated Oct 5, 2026 ## Key facts - **Tag title:** Reporting of Alleged Violations - **Regulation:** 42 CFR 483.12(b)(5), (c)(1) and (c)(4), with section 1150B of the Social Security Act - **Guidance relied on:** Appendix PP Rev. 232 (issued 07-23-25, in use since 04-28-25). F609 section Rev. 211 (02-03-23) - **Initial report:** Immediately, no later than 2 hours for abuse or serious bodily injury. No later than 24 hours otherwise - **Results report:** Within 5 working days of the incident - **Clock type:** Real clock time, not business hours - **Severity note:** Level 1 does not apply. CMS gives examples at levels 2, 3 and 4 - **How often cited:** 385 citations in CMS Region 5 (IL, IN, MI, MN, OH, WI) in the first half of 2026 (Wisconsin DHS summary) - **Citation:** F609 · 42 CFR 483.12(b)(5), (c)(1) and (c)(4) - **Authority:** CMS - **Applies to:** Medicare-certified skilled nursing facilities, Medicaid-certified nursing facilities ## What F609 covers F609 holds two reporting duties in 42 CFR 483.12. The facility reports every alleged violation and its investigation results ((c)(1) and (c)(4)). Each covered individual also reports a reasonable suspicion of a crime against a resident. That duty comes from section 1150B of the Social Security Act ((b)(5)). A covered individual is any owner, operator, employee, manager, agent or contractor. An alleged violation is a situation anyone observes or reports, before it is investigated. It could be abuse, neglect, exploitation, mistreatment, an injury of unknown source or misappropriation. The reporter need not say the word abuse. The duty applies if staff could reasonably conclude noncompliance might exist. An injury of unknown source meets all three tests. Nobody saw the cause. The resident cannot explain it. It is suspicious because of its extent, location, number or recurrence. For abuse, the facility should not judge credibility before it reports. ## The reporting clocks *F609 reporting requirements* | What is reported | Who reports | To whom | Deadline | | --- | --- | --- | --- | | Alleged abuse. Or any alleged violation that results in serious bodily injury. | The facility | Administrator, State Survey Agency, adult protective services (where state law gives it jurisdiction) and other officials under state law | Immediately, no later than 2 hours after the allegation is made | | Alleged neglect, exploitation, mistreatment or misappropriation. No abuse and no serious bodily injury. | The facility | Same recipients | No later than 24 hours | | Investigation results. Corrective action if verified. | The facility | Administrator and officials, including the State Survey Agency | Within 5 working days of the incident | | Reasonable suspicion of a crime. With serious bodily injury. | Each covered individual | State Survey Agency and local law enforcement | Immediately, no later than 2 hours after forming the suspicion | | Reasonable suspicion of a crime. Without serious bodily injury. | Each covered individual | State Survey Agency and local law enforcement | No later than 24 hours | A state may add recipients or shorter clocks. It may not drop a reportable category or lengthen a federal clock. > **Personal duty** Under 42 U.S.C. 1320b-25, a late report can bring a civil money penalty of up to $200,000, or $300,000 if the delay worsens harm. Both are adjusted annually. Exclusion from federal health programs is also possible. The facility cannot stop anyone reporting directly to law enforcement. ## What surveyors check and ask for *What surveyors ask for and what to have ready* | Surveyors ask for | Have ready | | --- | --- | | The initial report to the State Survey Agency | What was reported and when, accurate to the best of the facility's knowledge. Also how residents are protected. | | The sequence of times | Clock times: when staff first knew, when the administrator was told, when each report was sent | | The follow-up report | Investigation results and corrective action within 5 working days, plus updates to the first report | | Annual notice to covered individuals | A notice or sign-in for every covered individual, contractors included. In a language each understands. | | Policies | Who is a covered individual. Which crimes. Serious bodily injury. The clocks and the recipients. | | Staff answers | Staff can say who they report to, how fast, and that they will not be punished. The employee rights notice is posted. | CMS publishes sample initial and five-day report forms (Exhibits 358 and 359 in the State Operations Manual). A deliberately misleading report can itself be cited, such as one that omits facts or downplays an event. ## What makes an F609 deficiency more severe Severity follows what the failure to report allowed to happen. CMS says level 1 does not apply to F609. *CMS examples of F609 severity (crime reporting)* | Level | Example from CMS guidance | | --- | --- | | 4: immediate jeopardy | A cognitively impaired resident said she was touched and named the person. Staff judged her confused. Nobody reported, the person kept access, and the resident developed a sexually transmitted infection. | | 3: actual harm | A nurse aide saw a nurse take a resident's opioid dose. The aide did not report, out of fear of causing trouble. Other staff did not know their duty to report suspected drug diversion. | | 2: potential for more than minimal harm | No annual notice of reporting duties and no employee rights sign. Five staff had no notice. Two new hires did not know their duties. | ## Documentation gaps that lead to citations - The record has dates but no clock times, so the 2-hour clock cannot be shown. - A supervisor decides an event does not qualify. CMS says not to pre-judge whether an abuse allegation is credible. - An injury found at shift change is logged as a fall. Nobody asks if it fits the unknown-source test. - The initial report is filed. The 5-working-day results report is missing or has no corrective action. - The annual crime-reporting notice reaches employees, not contractors or agency staff. - The facility assumes the administrator told law enforcement. Surveyors verify a report was made. ## Show good reporting and follow-through 1. **Time-stamp discovery** Record the clock time staff first learned of the event and who they told. 2. **Escalate at once** Get it to the administrator at once. Never spend the 2-hour clock waiting. 3. **File and keep proof** Report to the State Survey Agency and others required. Keep what was sent, the time and the confirmation. 4. **Finish by day 5** Send investigation results and corrective action within 5 working days. See [F610](https://incidentkit.ai/compliance/f-tags/f610). 5. **Notify every year** Tell every covered individual each year, contractors and agency staff included. Keep the proof. ## How IncidentKit supports F609 IncidentKit helps you prove timing. The State Survey Agency report still goes through your state's channel. [Routing and escalation](https://incidentkit.ai/product/routing-and-escalation) alerts the roles you set. The [audit trail](https://incidentkit.ai/product/audit-trail) logs who did what and when. [Lauren](https://incidentkit.ai/product/lauren) drafts the narrative from staff answers, marked "Lauren · draft" until a person reviews, edits and signs. Reporting in Spanish and other languages is rolling out. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Report abuse or serious bodily injury within 2 hours; other allegations within 24 hours | Routing and escalation alerts the administrator and other roles you set. The audit trail logs each hand-off. | | Keep proof of what was reported and when | Keep the state report confirmation and any law enforcement case number on the incident record. | | Send investigation results within 5 working days | The investigation record holds findings and disposition. Corrective actions carry an owner, due date and evidence. | | Reports that are accurate and complete | Lauren asks the follow-up questions a risk manager would ask. A person reviews, edits and signs. Drafted fields read "Lauren · draft" until approved. | | Annual notice to covered individuals | IncidentKit runs alongside your HR and training systems and does not run the annual notice. Spanish and other-language reporting is rolling out. | ## Frequently asked questions ### What are the F609 reporting deadlines for a nursing home? Alleged abuse, or any allegation that results in serious bodily injury: no later than 2 hours after the allegation is made. Other alleged violations: no later than 24 hours. Investigation results: within 5 working days of the incident. The clocks use real time. ### Who must the nursing home report to? The facility reports to its administrator and other officials under state law. These include the State Survey Agency and, where state law gives it jurisdiction, adult protective services. Each covered individual also reports a reasonable suspicion of a crime. They report it to the State Survey Agency and local law enforcement. ### What is an injury of unknown source? An injury nobody saw happen. The resident cannot explain it. It is suspicious because of its extent, location, number or recurrence. CMS examples include unexplained fractures, patterned bruises, unexplained genital-area injuries and injuries needing a hospital visit. Report these as alleged violations. ### Does a resident-to-resident altercation have to be reported? Yes, if a willful action caused physical injury, pain or mental anguish. Also yes for unwanted or non-consensual sexual contact, bullying, threats or similar conduct. Cognitive impairment does not rule out a deliberate act. Non-targeted outbursts and light taps with no injury, pain or distress generally need no report. ## Sources - [eCFR, 42 CFR 483.12 (freedom from abuse, neglect, and exploitation), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-483.12) - [CMS State Operations Manual, Appendix PP, Guidance to Surveyors for Long Term Care Facilities (Rev. 232, issued 07-23-25; revised guidance used on surveys since 04-28-25): F609 section (Rev. 211, issued 02-03-23, effective 10-21-22, implementation 10-24-22)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [42 U.S.C. 1320b-25 (Social Security Act section 1150B): reporting of crimes in federally funded long-term care facilities](https://www.law.cornell.edu/uscode/text/42/1320b-25) - [Example CMS-2567 (Indiana Department of Health, 2024) printing the F609 title and citation as 483.12(b)(5)(i)(A)(B)(c)(1)(4)](https://www.in.gov/health/reports/QAMIS/ltccr/ow8911_2567.pdf) - [CMS State Operations Manual, Chapter 7, Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities (Rev. 244, issued 06-26-26): scope and severity matrix, immediate jeopardy, substandard quality of care](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107c07pdf.pdf) - [CMS memo QSO-25-14-NH (revised 2025-03-10): Revised Long-Term Care Surveyor Guidance, effective April 28, 2025](https://www.cms.gov/files/document/qso-25-14-nh-revised-2025-03-10.pdf) - [Wisconsin Department of Health Services, Top Ten Federal Health Citations, First Half 2026 (national, state and CMS Region 5 citation counts)](https://www.dhs.wisconsin.gov/regulations/nh/2026-h1-dqa-bnhrc-top-citations-region.pdf) ## Related - [F600 free from abuse and neglect: what surveyors cite](https://incidentkit.ai/compliance/f-tags/f600) - [F610 investigate, prevent and correct alleged violations](https://incidentkit.ai/compliance/f-tags/f610) - [Nursing home abuse reporting: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) - [Abuse Reporting Deadlines for Nursing Homes: 2 and 24 Hours](https://incidentkit.ai/use-cases/abuse-reporting-deadlines) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) - [Adverse event: definition and meaning](https://incidentkit.ai/glossary/adverse-event) --- # F610: investigate, prevent and correct alleged violations > F610 covers alleged abuse, neglect, exploitation and mistreatment. The home must keep evidence that it thoroughly investigated each allegation. It must protect residents meanwhile and correct verified problems. Results go to the administrator and State Survey Agency within 5 working days. Source: https://incidentkit.ai/compliance/f-tags/f610 · Updated Oct 5, 2026 ## Key facts - **Tag title:** Investigate/Prevent/Correct Alleged Violation (Appendix PP also lists it as Alleged Violations-Investigate/Prevent/Correct) - **Regulation:** 42 CFR 483.12(c)(2), (c)(3) and (c)(4) - **Guidance relied on:** Appendix PP Rev. 232 (issued 07-23-25, in use since 04-28-25); F610 section Rev. 173 (11-22-17) - **Protection clock:** Right away, until the investigation ends - **Results clock:** Within 5 working days of the incident - **Method:** None required - **Severity note:** No examples in the tag. Follows the harm and the F600 event - **Citation:** F610 · 42 CFR 483.12(c)(2)-(4) - **Authority:** CMS - **Applies to:** Medicare-certified skilled nursing facilities, Medicaid-certified nursing facilities ## What F610 covers Under 42 CFR 483.12(c), the home must keep evidence that it thoroughly investigated each alleged violation. It must prevent further potential abuse, neglect, exploitation or mistreatment while it investigates. If the allegation is verified, it must take appropriate corrective action. F610 also covers injuries of unknown source and misappropriation of resident property. A police report does not replace the home's own investigation. The home must still investigate to the extent possible, in consultation with the police. ## What thorough means to surveyors CMS prescribes no process. It expects enough evidence for the administrator to decide how to protect residents. *What to have ready* | Surveyors ask for | Have ready | | --- | --- | | Proof an investigation started | Start time, who led it, who was told | | Interviews | Dated notes. Include the alleged victim, representative, accused (person alleged to be responsible), witnesses and practitioner. | | Record review | Progress notes. Medication administration records. Incident reports. Hospital and emergency room records. Lab and x-ray reports. Photos. | | Protection while investigating | What changed that day: separation, more supervision, room move, access removed, check-ins | | The conclusion | The administrator's finding and why | | Corrective action and follow-through | Actions with owners and dates, a check they worked, QAA committee review | Do not disturb evidence. CMS says washing linens or clothing, destroying documents and bathing the resident before an exam impede investigations. So does skipping an emergency room exam, including a rape kit where appropriate. ## Protecting residents while you investigate Protection must start right away, before the facts are settled. CMS lists these failures. The accused keeps access to residents. A resident who reports is retaliated against. A resident who touches others is moved but keeps doing it. A resident with a history of striking is left unsupervised with a past target. Protections end because the investigation was inadequate. - Assess and treat the alleged victim at once. - Tell the practitioner and the family or representative. - Remove access by the accused; confirm ongoing safety. - Ask whether the resident feels safe. If not, move rooms or add supervision. - Make unannounced management visits on different shifts to check on residents at risk. - Tell law enforcement and other agencies as required, and involve the administrator. ## Timelines | Duty | Timing | | --- | --- | | Put protective measures in place | Right away, until the investigation is complete | | Report results to the administrator and State Survey Agency (an [F609](https://incidentkit.ai/compliance/f-tags/f609) duty) | Within 5 working days of the incident | | Corrective action if the allegation is verified | No fixed number of days. The home should oversee the action and check that it works | ## What makes an F610 deficiency more severe The F610 guidance gives no severity examples, so surveyors use the CMS scope and severity matrix. Section 483.12 counts toward substandard quality of care, CMS's label for serious findings. It applies at immediate jeopardy (serious harm happened or is likely). It also applies at pattern or widespread actual harm, or widespread potential for more than minimal harm. - **Continued access.** The accused keeps access and a resident is harmed again. - **No investigation.** None was done, so the home cannot show safety. - **Lapsed protection.** Safeguards ended early and a resident was affected. - **Pattern.** Several allegations, shifts or units show the same gap, raising scope. Facts like these move a finding up. F600 gives an immediate jeopardy example: staff did not report or protect a resident who said she was touched. If the home removes immediate jeopardy, surveyors lower what remains at the tag to level 2. If other residents were harmed, they lower it to harm. ## Documentation gaps that lead to citations - The investigation is one paragraph with no interviews. - Interviews are missing or undated, including the accused. - No record shows who protected the resident the first night or what changed. - The conclusion says unsubstantiated, with no reasons. - Corrective action is staff re-education with no check that practice changed. - The 5-working-day report was never sent. - The home stopped investigating when police got involved. ## How to show a good investigation and fix 1. **Secure and protect** Keep proof safe, protect the resident, and record the time and steps. 2. **Collect evidence** Interview, observe and review records. Date and file each item. 3. **Decide and explain** The administrator or designee records the finding and why, even if unsubstantiated. 4. **Correct the system** If verified, fix what allowed it. Assign an owner and due date. Report within 5 working days. 5. **Verify and review** Check the change held. Take the case to the QAA committee and close it with evidence. See [F867](https://incidentkit.ai/compliance/f-tags/f867). ## How IncidentKit supports F610 [Investigations](https://incidentkit.ai/product/investigations) hold the evidence file, contributing factors and disposition. A person signs the conclusion. [Lauren](https://incidentkit.ai/product/lauren) drafts the investigation from staff answers, marked "Lauren · draft" until approved. [Corrective actions](https://incidentkit.ai/product/corrective-actions) carry an owner, due date, evidence and an effectiveness check. Nothing closes until verified. IncidentKit does not conduct the investigation. Your team adds interviews and notes. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Evidence that each allegation was thoroughly investigated | Investigations hold the evidence file. Your team adds interviews and notes; a person signs. | | Prevent further harm while the investigation runs | Record interim protections and owners. Routing and escalation alerts the roles you set. | | Report results within 5 working days | The record holds what the follow-up report needs. The report goes through your state's channel. | | Corrective action when an allegation is verified | Each action carries an owner, due date, evidence and an effectiveness check. Nothing closes until verified. | | Prove the sequence of events | The audit trail logs each change with who, when and what changed. | ## Frequently asked questions ### Must the home follow a set investigation method? No. CMS sets no specific process. The home must collect enough evidence for the administrator to decide what is needed to protect residents. ### If police are investigating, can the home stop its own investigation? No. The home must still investigate to the extent possible, in consultation with the authority. It must not impede the police and must preserve potential evidence, such as clothing and linens, as instructed. ### How soon must residents be protected after an allegation? Right away. Protective measures must start at once and last while the investigation is in progress. ### When are investigation results due? Within 5 working days of the incident. Send them to the administrator or designee and other officials under state law, including the State Survey Agency. The F609 guidance covers timing and a sample report form. ### What is the difference between F609 and F610? F609 covers reporting: the 2-hour and 24-hour initial reports, the 5-working-day results report and crime reporting. F610 covers the investigation, protecting residents and fixing problems. One event can be cited at both. ## Sources - [eCFR, 42 CFR 483.12 (freedom from abuse, neglect, and exploitation), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-483.12) - [CMS State Operations Manual, Appendix PP, Guidance to Surveyors for Long Term Care Facilities (Rev. 232, issued 07-23-25; revised guidance used on surveys since 04-28-25): F610 section (Rev. 173, issued 11-22-17, effective 11-28-17); F600 and F609 cross-references (Rev. 211)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [Example CMS-2567 (Indiana Department of Health, 2024) printing the F610 title and citation as 483.12(c)(2)-(4)](https://www.in.gov/health/reports/QAMIS/ltccr/ow8911_2567.pdf) - [CMS State Operations Manual, Chapter 7, Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities (Rev. 244, issued 06-26-26): scope and severity matrix, immediate jeopardy, substandard quality of care](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107c07pdf.pdf) - [eCFR, 42 CFR 488.301 (definitions: immediate jeopardy, substandard quality of care), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-488.301) - [CMS memo QSO-25-14-NH (revised 2025-03-10): Revised Long-Term Care Surveyor Guidance, effective April 28, 2025](https://www.cms.gov/files/document/qso-25-14-nh-revised-2025-03-10.pdf) - [Wisconsin Department of Health Services, Top Ten Federal Health Citations, First Half 2026 (national, state and CMS Region 5 citation counts)](https://www.dhs.wisconsin.gov/regulations/nh/2026-h1-dqa-bnhrc-top-citations-region.pdf) ## Related - [F600 free from abuse and neglect: what surveyors cite](https://incidentkit.ai/compliance/f-tags/f600) - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) - [F867 QAPI improvement activities: adverse event tracking](https://incidentkit.ai/compliance/f-tags/f867) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Nursing Home Incident Report Template (Printable)](https://incidentkit.ai/templates/nursing-home-incident-report) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) --- # F684: quality of care > F684 is the nursing home quality of care tag. It covers care that no other section 483.25 tag covers. Care must meet professional standards, the person-centered care plan and the resident's choices. Surveyors use it for non-pressure wounds, end-of-life and hospice care, and a missed change in condition. Source: https://incidentkit.ai/compliance/f-tags/f684 · Updated Oct 5, 2026 ## Key facts - **Tag title:** Quality of Care - **Regulation:** 42 CFR 483.25 (opening paragraph); used when no other 483.25 tag fits - **Guidance relied on:** Appendix PP Rev. 232 (issued 07-23-25, in use since 04-28-25); F684 section Rev. 229 (04-25-25, implementation 04-28-25) - **Core test:** Avoidable or unavoidable decline - **Reporting clock:** None of its own. Immediate physician and representative notice of significant change (F580); immediate hospice contact - **Severity note:** CMS says level 1 does not apply - **How often cited:** 2,660 citations nationally in the first half of 2026, fourth most cited (Wisconsin DHS summary) - **Citation:** F684 · 42 CFR 483.25 - **Authority:** CMS - **Applies to:** Medicare-certified skilled nursing facilities, Medicaid-certified nursing facilities ## What F684 covers 42 CFR 483.25 says quality of care applies to all treatment and care. Residents must get care based on the comprehensive assessment. It must meet professional standards of practice, the comprehensive person-centered care plan and their choices. F684 covers concerns no other tag fits. Most care topics have their own tag. Vision and hearing are F685, pressure ulcers F686, accidents [F689](https://incidentkit.ai/compliance/f-tags/f689), continence F690 and enteral feeding F693. IV fluids are F694, respiratory care F695, pain F697 and bed rails F700. CMS says to use F684 only when no other rule covers the problem, such as assessment, care planning or physician supervision. Examples in the guidance: non-pressure skin ulcers and wounds (arterial, diabetic neuropathic and venous), and end-of-life and hospice care. ## How surveyors judge avoidable decline When a resident declines or fails to improve, surveyors ask if it was avoidable. It is unavoidable only if the home did all four of these: 1. Did an accurate, comprehensive assessment of condition and risks. 2. Built a person-centered care plan with the resident or representative, with interventions that fit needs, goals and standards. 3. Carried out the plan and watched the response. 4. Reviewed and revised the plan as needed. If one is missing and the resident declined, CMS treats the decline as avoidable. A resident who refuses care must be told the risks and benefits, offered alternatives and helped to limit decline. ## What surveyors investigate and ask for Surveyors use the General Critical Element Pathway. If it applies, they use the Hospice and End of Life Care and Services pathway. For a resident in the building under 14 days, they review the baseline care plan, due within 48 hours. | Surveyors ask for | Have ready | | --- | --- | | Recent comprehensive assessment, care plan and orders | Proof the need was seen and the order matched the care plan | | Proof orders were followed | Monitoring at the ordered frequency, such as daily weights or wound measurements | | Change in condition | When it was noticed, who assessed it, and physician and representative notice (F580) | | Care plan revision | A dated revision after the resident's response to interventions | | Resident refusal of care | Risk and benefit talk, alternatives offered, steps to limit decline | | Hospice residents | The written agreement, coordinated care plan and a log of communication with the hospice | ## What makes an F684 deficiency more severe F684 sits in section 483.25, which counts toward substandard quality of care, CMS's label for serious findings. It applies at immediate jeopardy (serious harm happened or is likely). It also applies at pattern or widespread actual harm, or widespread potential for more than minimal harm. Surveyors also look for signs of psychosocial distress. | Level | Example from CMS guidance | | --- | --- | | 4: immediate jeopardy | No prompt action on an acute change in a resident's heart failure. The family called 911 and the resident was admitted with respiratory distress and pulmonary edema. Repeated failure to carry out care-planned comfort measures led to uncontrolled vomiting and nausea | | 3: actual harm | A stasis ulcer care plan was not followed and the wound grew. A coordinated plan said no hospital transfer, but the resident was sent without contacting hospice. A symptom plan was not followed and the resident was too drowsy to talk with family | | 2: potential for more than minimal harm | No daily weights on three consecutive weekends for a resident with heart failure. A bowel plan in the coordinated care plan was not consistently carried out | CMS says level 1 does not apply to F684. ## Notification clocks F684 has no reporting clock of its own. Under 42 CFR 483.10(g)(14) (F580), the home must immediately inform the resident, consult the physician and notify the representative. It must do so after an accident with injury, a significant change in condition, or a transfer or discharge decision. It must also do so when treatment needs to change significantly. For a hospice resident, also tell the hospice immediately about significant changes. Examples are sudden decline or a fall with a suspected fracture. ## Documentation gaps that lead to citations - An aide notices a change, but it never reaches a nurse or physician. - Physician and representative notice is not time-stamped. - An order, such as daily weights, was missed until the resident worsened. - The care plan is unchanged after the resident worsened. - A resident declined care with no record of risks or alternatives discussed. - Hospice communication is verbal and undocumented. - Unexpected hospital transfers are never reviewed, so patterns stay hidden. ## How to show a good investigation and fix When a resident worsens or goes to the hospital unexpectedly, test the case against the four steps above. The record should show when the change was noticed, who was told and when, and whether the care plan was followed. Fix the process, not just one chart: aide reporting, handoffs, order tracking or monitoring. Then check the fix held. Take the pattern to the QAA committee. ## How IncidentKit supports F684 IncidentKit runs alongside your EHR and does not hold the clinical record. It records events behind F684 citations: an unexpected transfer, a missed order, a change in condition not escalated. [Lauren](https://incidentkit.ai/product/lauren) drafts the incident for a person to review and sign. [Investigations](https://incidentkit.ai/product/investigations) and [corrective actions](https://incidentkit.ai/product/corrective-actions) track the fix to a verified close, and [analytics](https://incidentkit.ai/product/analytics) show clusters by location, shift and cause. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Recognize and act on a change in condition | Staff report by text, QR quick report, email or web form. Routing and escalation alerts the roles you set. | | Show when staff noticed, assessed and notified | The incident record and audit trail log who recorded what and when. Your EHR keeps the clinical record. | | Find why a plan was not followed | Investigations record contributing factors and five whys. Human-authored RCA templates are rolling out. | | Revise the plan and monitor the response | Corrective actions carry an owner, due date, evidence and an effectiveness check. Nothing closes until verified. | | See patterns the committee should act on | Analytics show clusters by location, shift, equipment and cause. | ## Frequently asked questions ### When does CMS use F684 instead of a specific tag? Only when no other section 483.25 tag fits a concern that could cause a negative outcome. Topics with their own tag, such as pressure ulcers, falls, pain and catheters, are cited there. ### What is an avoidable decline? A decline is avoidable when the home missed one or more of four steps. The steps are assessment, care plan, carrying it out and review. It is unavoidable only when all four were in place. ### Does F684 apply to residents on hospice? Yes. The home must keep a coordinated plan with the hospice, immediately communicate significant changes in condition, and keep the written agreement. Surveyors may ask for the agreement and communication records. Hospice failures go to the state agency that oversees hospices. ### Which clinical records do surveyors look at first? The latest comprehensive assessments, comprehensive care plan and orders, to see if the home recognized the need. For a resident in the building fewer than 14 days, they review the baseline care plan, due within 48 hours. ### Is there a reporting deadline attached to F684? Not of its own. The related duty is immediate notice, not a set number of hours. The home must inform the resident, consult the physician and notify the representative. This applies after a significant change in condition, an accident with injury, a treatment change or a transfer decision. ## Sources - [eCFR, 42 CFR 483.25 (quality of care), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-483.25) - [CMS State Operations Manual, Appendix PP, Guidance to Surveyors for Long Term Care Facilities (Rev. 232, issued 07-23-25; revised guidance used on surveys since 04-28-25): F684 section (Rev. 229, issued 04-25-25, effective 04-25-25, implementation 04-28-25)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [eCFR, 42 CFR 483.10 ((g)(14) notification of changes), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-483.10) - [CMS State Operations Manual, Chapter 7, Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities (Rev. 244, issued 06-26-26): scope and severity matrix, immediate jeopardy, substandard quality of care](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107c07pdf.pdf) - [eCFR, 42 CFR 488.301 (definitions: immediate jeopardy, substandard quality of care), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-488.301) - [CMS memo QSO-25-14-NH (revised 2025-03-10): Revised Long-Term Care Surveyor Guidance, effective April 28, 2025](https://www.cms.gov/files/document/qso-25-14-nh-revised-2025-03-10.pdf) - [Wisconsin Department of Health Services, Top Ten Federal Health Citations, First Half 2026 (national, state and CMS Region 5 citation counts)](https://www.dhs.wisconsin.gov/regulations/nh/2026-h1-dqa-bnhrc-top-citations-region.pdf) ## Related - [F689 accidents and supervision: falls, hazards, devices](https://incidentkit.ai/compliance/f-tags/f689) - [F760 significant medication errors: how surveyors cite it](https://incidentkit.ai/compliance/f-tags/f760) - [F867 QAPI improvement activities: adverse event tracking](https://incidentkit.ai/compliance/f-tags/f867) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) - [Adverse event: definition and meaning](https://incidentkit.ai/glossary/adverse-event) --- # F760: residents are free of significant medication errors > F760 requires that residents are free of any significant medication errors. CMS cites it for any significant error, whatever the facility's overall error rate. An error is significant if it causes discomfort or jeopardizes health or safety. Source: https://incidentkit.ai/compliance/f-tags/f760 · Updated Oct 5, 2026 ## Key facts - **Tag title:** Residents Are Free of Significant Med Errors - **Regulation:** 42 CFR 483.45(f)(2). Companion F759 covers 483.45(f)(1), the error rate - **Guidance relied on:** Appendix PP Rev. 232 (issued 07-23-25, in use since 04-28-25); F759/F760 section Rev. 173 (11-22-17) - **Rate rule (F759):** Cited at an observed error rate of 5 percent or greater, with no rounding up. Rate is errors over opportunities (doses given plus doses ordered but not given) - **Wrong-time rule:** Counts at 60 or more minutes early or late, only if it can cause discomfort or jeopardize health. Before-meal and after-meal orders always count - **Reporting clock:** None of its own. Physician and representative notice at once (F580). Drug diversion has crime-reporting clocks (F609) - **Severity note:** No examples in the tag. Section 483.45(f) is in the substandard quality of care group - **Citation:** F760 · 42 CFR 483.45(f)(2) - **Authority:** CMS - **Applies to:** Medicare-certified skilled nursing facilities, Medicaid-certified nursing facilities ## What F760 covers F760 enforces 42 CFR 483.45(f)(2): residents are free of any significant medication errors. Companion F759 enforces (f)(1), an error rate under 5 percent. F760 applies to any significant error, even at a lower rate. A medication error is a preparation or administration that departs from the prescriber's order, the manufacturer's specifications (not recommendations) or accepted professional standards. It is significant if it causes the resident discomfort or jeopardizes health or safety. ## How surveyors judge significance Significance is professional judgment. Three factors guide it: the resident's condition, the drug category and how often the error happens. Narrow therapeutic index drugs carry more risk, since they leave little room between a safe and a harmful dose. Examples are warfarin, digoxin, phenytoin and lithium. A laxative missed for one day may cause little or no discomfort. Constipation lasting more than three days may be significant, CMS says. *CMS examples: significant (S) or not (NS)* | Type | Order | What happened | Rating | | --- | --- | --- | --- | | Omission | Metoprolol succinate 100 mg daily | Dose not given | S | | Omission | Multivitamin one daily | Dose not given | NS | | Wrong dose | Digoxin 0.125 mg daily | 0.25 mg given | S | | Wrong route | Ear drops to left ear | Given in the left eye | S | | Unauthorized drug | No order for warfarin | Warfarin 4 mg given | S | | Wrong time | Oxycodone 20 minutes before a painful treatment | Given after the treatment | S | | Wrong time | Losartan 50 mg at 8 a.m. | Given at 9:30 a.m. | NS | ## What surveyors investigate and ask for Surveyors use the Medication Administration Observation task. They watch several medication passes and compare them with the orders: right resident, time, dose, route and standard of practice. They ask the nurse about any apparent error. *What to have ready* | Surveyors ask for | Have ready | | --- | --- | | Current orders and the signed recap | Orders that match what was prepared, with stopped orders clearly marked | | The medication administration record | An entry for every scheduled dose, and a reason for any dose not given. Blanks raise questions but do not prove an error | | Explanation of an apparent omission | Interviews. A dose count if possible: doses on hand against days in use and directions | | Records beyond the observation | Change-in-condition notes, family reports and MAR discrepancies can support an F760 citation | | Manufacturer or standard-of-practice support | Why a drug was crushed, held or timed as it was. Sources: prescriber, pharmacist or literature | | Follow-up on frequency | Whether an error repeated, since repetition can make it significant | A dose count only works if the number received and the start date are charted. ## What makes an F760 deficiency more severe The F760 guidance has no severity examples, so surveyors use the CMS scope and severity matrix. Section 483.45(f) counts toward substandard quality of care, CMS's label for serious findings. It applies at immediate jeopardy (serious harm happened or is likely). It also applies at pattern or widespread actual harm, or widespread potential for more than minimal harm. One 2024 state-posted CMS-2567 (survey findings form) cited F760 at level J (isolated immediate jeopardy) and as substandard quality of care. A resident got another resident's medications, including an antipsychotic. The immediate jeopardy began on 02/17/24 and was removed on 02/20/24. Once it is removed, surveyors lower what remains at the tag to level 2. If other residents were harmed, they lower it to harm. ## Notification and reporting clocks No federal timer attaches to a medication error. Three nearby duties apply: - **Notify the physician and family.** Right away, inform the resident, consult the physician and notify the representative (42 CFR 483.10(g)(14), F580). This applies to a significant change in condition or a need to change treatment significantly. - **Diversion is a crime report.** CMS treats missing or diverted resident medication as reportable misappropriation. It treats drug diversion for personal use as a likely crime. See [F609](https://incidentkit.ai/compliance/f-tags/f609): 24 hours, or 2 hours if abuse or serious bodily injury is involved. - **State rules.** Some states have their own medication error reporting. Check your state's rules. ## Documentation gaps that lead to citations - An omission is noticed but not recorded or reported to the physician. - Blanks with no reason hide whether a dose was missed or not charted. - Fixes target one person, never the system: transcription, look-alike drugs, handoffs, interruptions, pharmacy delivery. - No one checks frequency, so repeat omissions are never linked. - The consultant pharmacist and medical director are left out of the review. - Errors are counted, not trended by shift, unit or drug class. The QAA committee never sees drug regimen review data. ## How to show a good investigation and fix 1. **Assess and notify** Check the resident, tell the physician and representative, record the times. 2. **Describe the error precisely** Record the drug, order, what was given, route, time and the resident's condition. Rate significance with CMS's three factors. 3. **Find the system cause** Walk order to administration with the pharmacist and nurses. Look at the system, not one person. 4. **Correct and assign** Change the process. Give each action an owner and due date. 5. **Verify and trend** Audit the change. Bring error data to the QAA committee. See [F867](https://incidentkit.ai/compliance/f-tags/f867). ## How IncidentKit supports F760 IncidentKit runs alongside your EHR and medication record. Deeper EHR integration is rolling out, so reference the entry in the incident. [Lauren](https://incidentkit.ai/product/lauren) drafts the report for a person to review and sign. [Investigations](https://incidentkit.ai/product/investigations) record contributing factors. [Corrective actions](https://incidentkit.ai/product/corrective-actions) track the fix to a verified close. [Analytics](https://incidentkit.ai/product/analytics) show clusters by shift, location and cause. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Residents free of significant medication errors | Staff report by text, QR quick report, email or web form. A person reviews and signs Lauren's draft. | | Judge significance and find the cause | Investigations record contributing factors and five whys. Human-authored RCA templates are rolling out. | | Notify the physician and representative | Routing and escalation alerts the roles you set. The audit trail logs each notice. Orders and the MAR stay in your EHR. | | Correct the process and show it held | Corrective actions carry an owner, due date, evidence and an effectiveness check. Nothing closes until verified. | | QAA committee review of errors and drug regimen review data | Analytics cluster errors by shift, location and cause. Compliance packets include a QAPI summary. | ## Frequently asked questions ### What is the difference between F759 and F760? F759 is the error rate: it is cited when observed errors, significant or not, reach 5 percent or greater of opportunities. F760 is cited for any significant error, whatever the overall rate. ### What makes a medication error significant? It causes the resident discomfort or jeopardizes health or safety. CMS says to weigh the resident's condition, the drug category and how often it recurs. The same omission can be minor for one resident and significant for another. ### Do late doses count as medication errors? Only if given 60 or more minutes early or late and the timing can cause discomfort or jeopardize health. Before-meal and after-meal orders always count. A long half-life drug given 15 minutes late does not. ### Can an F760 citation come from records instead of observation? Yes. CMS prefers observation. Errors can also come from record review, a change in condition tied to an error, family reports or record discrepancies. Blanks alone do not prove an error. ## Sources - [eCFR, 42 CFR 483.45 ((f) medication errors), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-483.45) - [CMS State Operations Manual, Appendix PP, Guidance to Surveyors for Long Term Care Facilities (Rev. 232, issued 07-23-25; revised guidance used on surveys since 04-28-25): F759 and F760 section (Rev. 173, issued 11-22-17, effective 11-28-17)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [Example CMS-2567 (North Carolina DHHS, 2024) printing the F760 title and citation 483.45(f)(2), cited at level J and as substandard quality of care](https://info.ncdhhs.gov/DHSR/facilities/nh/2024/20240506-923265.pdf) - [eCFR, 42 CFR 483.10 ((g)(14) notification of changes), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-483.10) - [CMS State Operations Manual, Chapter 7, Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities (Rev. 244, issued 06-26-26): scope and severity matrix, immediate jeopardy, substandard quality of care](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107c07pdf.pdf) - [eCFR, 42 CFR 488.301 (definitions: immediate jeopardy, substandard quality of care), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-488.301) - [CMS memo QSO-25-14-NH (revised 2025-03-10): Revised Long-Term Care Surveyor Guidance, effective April 28, 2025](https://www.cms.gov/files/document/qso-25-14-nh-revised-2025-03-10.pdf) ## Related - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) - [F684 quality of care: what it covers and how it is cited](https://incidentkit.ai/compliance/f-tags/f684) - [F867 QAPI improvement activities: adverse event tracking](https://incidentkit.ai/compliance/f-tags/f867) - [Medication Error Reporting: Steps, Severity and Follow-Up](https://incidentkit.ai/use-cases/medication-error-reporting) - [Medication Error Report Template (Printable Form)](https://incidentkit.ai/templates/medication-error-report) - [Medication error: definition and meaning](https://incidentkit.ai/glossary/medication-error) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) --- # F880: infection prevention and control > F880 is the CMS tag for infection prevention and control. A nursing home must run a program that prevents, finds, reports, investigates and controls infections. It needs written policies, surveillance, an incident record, safe laundry handling and an annual review. It is the most cited tag. Source: https://incidentkit.ai/compliance/f-tags/f880 · Updated Oct 5, 2026 ## Key facts - **Tag title:** Infection Prevention & Control - **Regulation:** 42 CFR 483.80(a)(1), (a)(2), (a)(4), (e) and (f). Antibiotic stewardship is F881; the infection preventionist is F882 - **Guidance relied on:** Appendix PP Rev. 232 (issued 07-23-25, in use since 04-28-25); F880 section Rev. 229 (04-25-25, implementation 04-28-25) - **How often cited:** 4,146 citations nationally in the first half of 2026, the most cited tag (Wisconsin DHS summary) - **Review clock:** At least annually. CMS's level 1 example is a review at 14 months - **Reporting clock:** Set by state and local public health rules, not CMS. Policy must say when and to whom - **Recent change:** Enhanced Barrier Precautions guidance used on surveys from April 28, 2025 - **Citation:** F880 · 42 CFR 483.80(a)(1)-(2), (a)(4), (e) and (f) - **Authority:** CMS - **Applies to:** Medicare-certified skilled nursing facilities, Medicaid-certified nursing facilities ## What F880 covers F880 enforces the infection prevention and control program (IPCP) in 42 CFR 483.80. It must cover residents, staff, volunteers, visitors and contractors. It must follow accepted national standards and rest on the facility assessment. Written policies must cover surveillance, when and to whom to report, precautions, isolation and hand hygiene. They must keep staff with a communicable disease or infected skin lesions from direct contact. The home must also record IPCP incidents and corrective actions ((a)(4)), handle linens safely ((e)) and review the program at least annually ((f)). [F867](https://incidentkit.ai/compliance/f-tags/f867) can apply when the QAA committee should have caught a systemic problem. [F868](https://incidentkit.ai/compliance/f-tags/f868) covers the infection preventionist's seat on that committee. ## What surveyors check Surveyors use the Infection Prevention, Control and Immunizations Facility Task. One surveyor leads, but the whole team watches practice: hand hygiene, PPE, enhanced barrier precautions, residents on transmission-based precautions and laundry. They interview staff and review documents. | Surveyors ask for | Have ready | | --- | --- | | The written IPCP and policies | Current policies tied to national standards, annual review dated | | Surveillance data | A data tool using national criteria, such as CDC NHSN long-term care or updated McGeer criteria: site, pathogen, symptoms, location | | Analysis and follow-up | Trends shared with the DON, medical director and QAA committee; follow-up on key findings | | Record of incidents and corrective actions | Each incident, the investigation, the fix, monitoring and staff feedback | | Outbreak response | When the signal was seen, precautions started, who was told, public health report | | Staff practice checks | Hand hygiene and PPE audits, and what happened when practice fell short | ## Outbreaks and when to act An outbreak is more cases of a disease than expected in one place and time. CMS says not to wait for the formal definition: one laboratory-confirmed influenza case should start an outbreak investigation. The home must manage cases, apply precautions, prevent spread, track follow-up and meet public health rules. Surveyors use Appendix Q to decide if a cited outbreak is immediate jeopardy. ## What raises F880 severity Severity rises with harm and with the number of residents exposed. Immediate jeopardy (level 4) means noncompliance has caused, or is likely to cause, serious injury, harm, impairment or death. F880 is outside the substandard quality of care list in 42 CFR 488.301, which names only paragraph (d) of section 483.80. Immediate jeopardy and harm citations still apply. *CMS examples of F880 severity* | Level | Example from CMS guidance | | --- | --- | | 4: immediate jeopardy | Fingerstick devices reused between residents. A gastrointestinal outbreak not investigated or tracked left residents on the next unit seriously ill and dehydrated. A nurse left a contact-precaution room for a multidrug-resistant germ (MDRO) without hand hygiene and went to another resident. An uninvestigated COVID-19 unit outbreak sent residents next door to hospital | | 3: actual harm | A scabies case not diagnosed, treated or put on precautions; several residents got a rash with severe itching. A resident with COVID-19 symptoms was not tested before sharing a room, and the roommate caught it | | 2: potential for more than minimal harm | The same gloves worn between two residents' medication passes. Contaminated linens carried against a uniform. Wound supplies put on a bed and returned to the cart | | 1: minimal potential for harm | The IPCP was last reviewed at 14 months instead of 12, with no other findings | ## Reporting clocks F880 sets no hour or day count. Policy must say when and to whom to report a communicable disease or infection. State and local public health rules set the deadlines and vary by place, so check yours. ## Gaps that lead to citations - A line list of infections is never analyzed or shared with the QAA committee. - Infections in nursing notes never reach the infection preventionist, so clusters go unseen. - No record shows when an outbreak signal was seen or what was done. - Practice audits find lapses, but no corrective action is recorded. - Surveillance criteria are not named, so cases are defined inconsistently. - No system records IPCP incidents and corrective actions, as (a)(4) requires. - The annual review is undated or late. ## How to show a good investigation CMS says the incident system should collect reports from residents, families and staff. It should investigate, set prevention measures, correct, check that changes work and give feedback. 1. **Record the incident** Note what happened, where, when and who was exposed. 2. **Investigate** Compare practice with policy. Find the cause. 3. **Correct** Give each fix an owner and a due date. 4. **Monitor** Audit the practice. Check cases or exposures afterward. 5. **Report up** Take results to the DON, medical director and QAA committee. ## How IncidentKit supports F880 IncidentKit is not an infection surveillance, line list or public health reporting system. It runs alongside your EHR and covers the incident record: practice lapses, exposures and outbreak signals. [Lauren](https://incidentkit.ai/product/lauren) drafts each report for a person to review and sign. [Routing and escalation](https://incidentkit.ai/product/routing-and-escalation) sends it to the infection preventionist. [Investigations](https://incidentkit.ai/product/investigations) and [corrective actions](https://incidentkit.ai/product/corrective-actions) track the fix to a verified close, and [compliance packets](https://incidentkit.ai/product/compliance-packets) add a QAPI summary. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | A system for recording incidents and corrective actions (483.80(a)(4)) | Incident reporting and corrective actions, each with an owner, due date, evidence and effectiveness check. Nothing closes until verified. | | Report possible incidents to the right people | Routing and escalation alerts the infection preventionist, DON and administrator. Public health reports go through their own channels. | | Investigate failures in practice | Investigations record contributing factors and five whys. The audit trail logs who did what, when. | | Report incidents to the QAA committee | Analytics cluster incidents by location, shift and cause. Compliance packets add a QAPI summary. | | Surveillance, line lists and NHSN reporting | Not provided by IncidentKit. It runs alongside your EHR and surveillance tools. | ## Frequently asked questions ### What does F880 require a nursing home to have? An infection prevention and control program with written policies, surveillance, an incident record, safe laundry handling and an annual review. ### What surveillance criteria does CMS expect? Nationally recognized criteria and a data collection tool, such as the CDC's National Healthcare Safety Network long-term care criteria or the updated McGeer criteria. The home must analyze the data, share it and document follow-up on important findings. ### When is an infection cluster an outbreak? When there are more cases than expected for a place and time. For a rare or serious condition, one case can count. CMS says one laboratory-confirmed influenza case should start an investigation. ### Does F880 set a deadline for reporting infections? No. The home's policy must say when and to whom it reports. State and local public health authorities set the deadlines, so confirm yours with them. ### What is the incident record F880 asks for? A system for recording incidents found under the infection program and the corrective actions taken (paragraph (a)(4)). CMS says to report failures in infection control practice to the director of nursing, medical director and QAA committee. ## Sources - [eCFR, 42 CFR 483.80 (infection control), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-483.80) - [CMS State Operations Manual, Appendix PP, Guidance to Surveyors for Long Term Care Facilities (Rev. 232, issued 07-23-25; revised guidance used on surveys since 04-28-25): F880 section (Rev. 229, issued 04-25-25, effective 04-25-25, implementation 04-28-25)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [CMS memo QSO-25-14-NH (revised 2025-03-10): Revised Long-Term Care Surveyor Guidance, effective April 28, 2025](https://www.cms.gov/files/document/qso-25-14-nh-revised-2025-03-10.pdf) - [CMS State Operations Manual, Chapter 7, Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities (Rev. 244, issued 06-26-26): scope and severity matrix, immediate jeopardy, substandard quality of care](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107c07pdf.pdf) - [eCFR, 42 CFR 488.301 (definitions: immediate jeopardy, substandard quality of care), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-488.301) - [Wisconsin Department of Health Services, Top Ten Federal Health Citations, First Half 2026 (national, state and CMS Region 5 citation counts)](https://www.dhs.wisconsin.gov/regulations/nh/2026-h1-dqa-bnhrc-top-citations-region.pdf) ## Related - [F867 QAPI improvement activities: adverse event tracking](https://incidentkit.ai/compliance/f-tags/f867) - [F868 QAA committee: members, meetings and evidence](https://incidentkit.ai/compliance/f-tags/f868) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [Nursing home recertification survey: process and prep](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) - [Immediate jeopardy: definition and meaning](https://incidentkit.ai/glossary/immediate-jeopardy) --- # F865: QAPI program and plan > F865 requires every nursing home to run an effective, comprehensive, data-driven QAPI program and keep the records to prove it. The home presents its QAPI plan at each annual recertification survey and shows proof of use on request. Leaders are accountable. Good faith attempts to find and fix problems cannot be used for sanctions. Source: https://incidentkit.ai/compliance/f-tags/f865 · Updated Oct 5, 2026 ## Key facts - **Tag title:** QAPI Program/Plan, Disclosure/Good Faith Attempt - **Regulation:** 42 CFR 483.75(a), (b), (f), (h) and (i) - **Guidance relied on:** Appendix PP Rev. 232 (issued 07-23-25, in use since 04-28-25); F865 section Rev. 211 (02-03-23) - **Plan presented:** Each annual recertification survey, and on request at other surveys - **Survey timing:** QAPI review comes last. Surveyors may not use it to find new deficiencies or widen scope or severity - **Not protected:** Incident and accident reports, wound logs and infection control logs - **Refusal to produce evidence:** Cited at F865; plan of correction required; remedies up to termination of the provider agreement - **Citation:** F865 · 42 CFR 483.75(a), (b), (f), (h) and (i) - **Authority:** CMS - **Applies to:** Medicare-certified skilled nursing facilities, Medicaid-certified nursing facilities, Facilities that are part of a multiunit chain ## What F865 covers F865 enforces the program-level parts of 42 CFR 483.75, paragraphs (a), (b), (f), (h) and (i). These cover the program, its design, governing body accountability, limits on disclosing committee records and good faith protection. The program must be ongoing, comprehensive, data-driven and focused on outcomes of care and quality of life. It must cover all systems of care. CMS moved the old F866 requirements into [F867](https://incidentkit.ai/compliance/f-tags/f867). Committee membership and meetings are at [F868](https://incidentkit.ai/compliance/f-tags/f868). The home must also keep records and proof of its program, including adverse event systems and corrective action records. Governing body or executive leadership must keep the program going through staff changes. It must give the program staff time, equipment and training, and check that corrective actions work. ## What surveyors check Surveyors use the Facility Task Pathway for QAPI and QAA Review. They do it after investigating every other area, so their findings stand on their own. *What to have ready* | Surveyors ask for | Have ready | | --- | --- | | The QAPI plan | A written plan based on the facility assessment: how problems are tracked, analyzed and corrected | | Proof the program runs | Regular data, analysis, and corrective actions with results | | Adverse event and problem tracking | Reports, logs and analysis showing identification, investigation and prevention | | Governing body involvement | Reports to the governing body or its designee, priorities set, resources assigned | | Proof of a good faith attempt | A dated record of data, analysis, cause, action and monitoring for the issue the survey team found | ## What QAPI records are protected Committee minutes and internal papers are generally protected. That ends when they hold the proof needed to decide whether the home meets the QAPI rules. Then the home must let surveyors review and copy them. Incident and accident reports, wound logs and infection control logs are not protected, and surveyors may request them at any point. If QAPI material is patient safety work product held with a patient safety organization (PSO), surveyors must not ask to see it. They ask to see the PSO agreement. CMS warns of a trap. If all QAPI proof sits in the protected system, the home may be unable to show compliance without a separate non-confidential record. ## How to show a good faith attempt If the committee already found the issue and made a good faith attempt to correct it, the home is not cited for QAPI. Other tags may still apply. Surveyors ask when the home should have known, what it did, and whether enough time has passed to judge the result. 1. **Collect data** From incidents, complaints, MDS and audits, on high-risk, high-volume or problem-prone issues. 2. **Analyze** Find where results fall short of what is expected. 3. **Study the cause** Find underlying causes and contributing factors. 4. **Act** Start a corrective action with an owner and a date. 5. **Monitor** Check whether the fix holds. Revise it if not. ## What raises F865 severity The F865 guidance has no severity examples. If the home refuses to produce proof of QAPI compliance, surveyors cite F865 and require a plan of correction. Remedies can run up to termination of the provider agreement. QAPI sections are not on the substandard quality of care list in 42 CFR 488.301. Harm links to other tags. At scope and severity level E or higher, or with substandard quality of care, the QAPI reviewer asks if monitoring should have caught it. Issues likely to cause serious harm, impairment or death must be answered immediately. [F867](https://incidentkit.ai/compliance/f-tags/f867) shows QAPI findings at immediate jeopardy. ## Cadence and clocks | Item | Timing | | --- | --- | | Present the QAPI plan | Each annual recertification survey; on request at any other survey | | QAPI documentation and evidence of implementation | On request of the State Survey Agency, a federal surveyor or CMS | | QAA committee meeting | At least quarterly and as needed. See [F868](https://incidentkit.ai/compliance/f-tags/f868) | | Performance improvement project | At least annually on a high-risk or problem-prone area. See [F867](https://incidentkit.ai/compliance/f-tags/f867) | ## Gaps that lead to citations - The plan is generic, not tailored to this home. - Nothing links the plan to the facility assessment. - No record shows governing body review of QAPI results or priorities. - Minutes list topics with no data, decisions, owners or dates. - All QAPI proof sits in a protected PSO system, with no separate record. - A good faith attempt is claimed, but no dated actions exist. ## How IncidentKit supports F865 IncidentKit keeps the non-confidential record surveyors can ask for: incidents, investigations, corrective actions and an [audit trail](https://incidentkit.ai/product/audit-trail) of who did what and when. [Compliance packets](https://incidentkit.ai/product/compliance-packets) assemble QAPI summaries and [analytics](https://incidentkit.ai/product/analytics) support setting priorities from data. It does not write your QAPI plan or replace your governing body's review. See the [QAPI guide](https://incidentkit.ai/guides/qapi-program-guide). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Documentation and evidence of an ongoing QAPI program | Incidents, investigations and corrective actions form a record with an audit trail, and compliance packets assemble QAPI summaries. | | Systems that identify, report, investigate, analyze and prevent adverse events | Intake, routing, investigations and analytics cover the identify-to-analyze steps. | | Corrective actions evaluated for effectiveness | Corrective actions carry an owner, due date, evidence and effectiveness check. Nothing closes until verified. | | Evidence of a good faith attempt | Dated records of data, analysis, cause, action and monitoring, from the audit trail and analytics. | | QAPI plan and governing body oversight | IncidentKit does not write your plan or replace governing body review. Attach both to the compliance packet. | ## Frequently asked questions ### What does a surveyor review under F865? Whether the home keeps proof of an ongoing QAPI program, can present its plan, and has governing body oversight. They check at the end of the survey. ### Are incident reports protected from surveyors? No. CMS says incident and accident reports, wound logs and infection control logs are not protected, and surveyors may request them at any time. ### Can a nursing home put all QAPI records in a patient safety organization? Yes, but CMS warns that keeping every QAPI record there may leave the home unable to show compliance. A second, non-confidential system is allowed. ### What counts as a good faith attempt? Proof that the QAA committee found the issue and acted: data, analysis, causes, corrective action and monitoring. A claim alone is not enough. ### What happens if a home will not provide QAPI proof? It is cited at F865 and needs a plan of correction. Remedies can go up to termination of the provider agreement under 42 CFR 489.53. ## Sources - [eCFR, 42 CFR 483.75 (quality assurance and performance improvement), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-483.75) - [CMS State Operations Manual, Appendix PP, Guidance to Surveyors for Long Term Care Facilities (Rev. 232, issued 07-23-25; revised guidance used on surveys since 04-28-25): F865 section (Rev. 211, issued 02-03-23, effective 10-21-22, implementation 10-24-22)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [LeadingAge, List of Revised F-tags in New RoPs Guidance 2022 (tag titles as listed for CMS's June 2022 revisions)](https://leadingage.org/sites/default/files/List%20of%20Revised%20F-Tags.pdf) - [CMS memo QSO-25-14-NH (revised 2025-03-10): Revised Long-Term Care Surveyor Guidance, effective April 28, 2025](https://www.cms.gov/files/document/qso-25-14-nh-revised-2025-03-10.pdf) - [CMS State Operations Manual, Chapter 7, Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities (Rev. 244, issued 06-26-26): scope and severity matrix, immediate jeopardy, substandard quality of care](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107c07pdf.pdf) - [eCFR, 42 CFR 488.301 (definitions: immediate jeopardy, substandard quality of care), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-488.301) - [CMS, Revision History for LTC Survey Process Documents and Files (updated 08-13-2026): confirms the official Appendix PP version posted 05/21/25](https://www.cms.gov/files/document/revision-history-ltc-survey-process-documents-files-updated-08-13-2026.pdf) ## Related - [F867 QAPI improvement activities: adverse event tracking](https://incidentkit.ai/compliance/f-tags/f867) - [F868 QAA committee: members, meetings and evidence](https://incidentkit.ai/compliance/f-tags/f868) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [QAPI: definition and meaning](https://incidentkit.ai/glossary/qapi) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) --- # F867: QAPI/QAA improvement activities > F867 is where QAPI becomes visible. The home must track medical errors and adverse events, find their causes and set priorities. It must fix problems at the system level and measure whether fixes hold. It must also run at least one improvement project a year. Source: https://incidentkit.ai/compliance/f-tags/f867 · Updated Oct 5, 2026 ## Key facts - **Tag title:** QAPI/QAA Improvement Activities - **Regulation:** 42 CFR 483.75(c), (d), (e) and (g)(2)(ii)-(iii). The old F866 was folded into F867 - **Guidance relied on:** Appendix PP Rev. 232 (issued 07-23-25, in use since 04-28-25); F867 section Rev. 229 (04-25-25, implementation 04-28-25) - **Improvement project:** At least one distinct project a year on a high-risk or problem-prone area found through data - **Data frequency:** Set by the home. High-risk data is collected more often (daily, weekly or monthly) until performance is satisfactory - **New in the 2025 guidance:** Health equity. Feedback, sub-population data and factors such as race, language and socioeconomic status in error analysis - **Severity note:** CMS gives examples at levels 1 through 4 - **Citation:** F867 · 42 CFR 483.75(c), (d), (e) and (g)(2)(ii)-(iii) - **Authority:** CMS - **Applies to:** Medicare-certified skilled nursing facilities, Medicaid-certified nursing facilities ## What F867 covers F867 enforces four parts of 42 CFR 483.75. Paragraph (c) covers policies for feedback, data and adverse event monitoring. Paragraphs (d) and (e) cover analysis, systemic action, priorities and improvement projects. Paragraph (g)(2)(ii)-(iii) covers the QAA committee's duty to act on quality deficiencies and review data, including drug regimen review data. The home must track medical errors and adverse resident events, find causes and prevent repeats. CMS defines an adverse event as an unwanted and usually unexpected event that causes death or serious injury, or the risk of it. A near miss is a serious error that did not become an adverse event, by chance or interception. Priorities should follow high-risk, high-volume and problem-prone areas. CMS examples: tracheostomy care, pressure injury prevention and high-risk drugs (anticoagulants, insulin, opioids) are high-risk. Transcribing orders and giving medications are high-volume. Call bell response, staff turnover and lost laundry are problem-prone. ## Events CMS expects you to track CMS and AHRQ list potentially preventable events. They cite a 2014 HHS Office of Inspector General finding. About one in three Medicare beneficiaries was harmed by an adverse or temporary harm event within 35 days of a nursing home stay. Nearly 60 percent of those events were potentially preventable. *CMS examples of potentially preventable events* | Category | Examples | | --- | --- | | Medication | Delirium with opiates or psychotropics. Hypoglycemia with antidiabetic drugs. Bleeding with antithrombotics. Drug toxicity (digoxin, phenytoin, lithium). Constipation or impaction with opiates | | Care | Falls, skin tears and other care-related trauma. Avoidable pressure injuries. Dehydration. Feeding tube complications. Elopement. Abuse, neglect, misappropriation and exploitation | | Infection | Pneumonia and influenza. Urinary tract infections, including catheter-associated. C. difficile and norovirus. Skin and wound infections | CMS says an adverse event, such as a cognitively impaired resident eloping, is a high-risk problem needing corrective action. ## What surveyors check Surveyors use the QAPI and QAA Review pathway at the end of the survey. Repeat deficiencies the committee never identified or prioritized suggest it is not doing its job. *What to have ready* | Surveyors ask for | Have ready | | --- | --- | | Policies for feedback and data | How staff, resident and representative feedback is gathered and used, plus each department's data | | Adverse event and error tracking | A log with causes analyzed and preventive action for each, not only counts | | Performance indicators | Thresholds, goals and how often each is reviewed | | A systematic method | Root cause analysis, reverse tracker, failure modes review or similar. The cause it found | | Corrective action plans | Problem definition with contributing causes, measurable goals, step-by-step interventions, tracking plan | | Results and the annual project | Data showing the fix held, and the year's project with its findings | ## What raises F867 severity Severity follows what the missing QAPI work allowed. Each CMS example is a problem the committee should have caught. *CMS examples of F867 severity* | Level | Example from CMS guidance | | --- | --- | | 4: immediate jeopardy | Residents had third-degree burns the month before. Hot water data was collected but never reviewed. The committee did not track how residents' code status reached staff | | 3: actual harm | Repeat deficiencies on two surveys about discharge needs. A resident left without diabetes education and was rehospitalized. The committee was unaware and did not monitor discharge | | 2: potential for more than minimal harm | A quality deficiency about inaccurate weight measurement from the prior survey was not corrected or tracked | | 1: minimal potential for harm | A plan to check monthly for three months. No proof of checks in the second month | ## Clocks and frequency F867 has no deadline for reporting an event. Collect data on the home's schedule, and more often for high-risk issues. The committee reviews at least quarterly under [F868](https://incidentkit.ai/compliance/f-tags/f868). CMS expects issues likely to cause serious harm, impairment or death to be answered immediately. Abuse and neglect clocks sit in [F609](https://incidentkit.ai/compliance/f-tags/f609). ## Gaps that lead to citations - Events are logged and counted, but no one analyzes cause. - The same corrective action, usually an in-service, repeats for every event. - Goals are not measurable, so success cannot be shown. - A tracking plan has missing months. - The improvement project came from a list, not home data. - The committee does not know about a repeat survey deficiency. - Data is not split by sub-population, and error analysis skips equity factors. ## How to show a good investigation CMS says a corrective action fixes the cause at the systems level, not just the symptom. Tests of change or Plan-Do-Study-Act cycles are allowed until goals are met. 1. **Capture** Log the event or near miss when it happens. 2. **Analyze** Find the cause with a systematic method. 3. **Act on the system** Set a measurable goal, an owner and a date. 4. **Measure** Check as planned and keep proof for every period. 5. **Report** Bring results to the committee. Close only when the fix held. ## How IncidentKit supports F867 [Incident reporting](https://incidentkit.ai/product/incident-reporting) with [Lauren](https://incidentkit.ai/product/lauren) captures events and near misses, and a person reviews and signs. [Investigations](https://incidentkit.ai/product/investigations) record contributing factors and five whys. [Corrective actions](https://incidentkit.ai/product/corrective-actions) carry an owner, due date, evidence and an effectiveness check. Nothing closes until verified. [Analytics](https://incidentkit.ai/product/analytics) show where events cluster, and [compliance packets](https://incidentkit.ai/product/compliance-packets) include a QAPI summary. Choosing priorities and running the committee remain your team's work. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Track medical errors and adverse events and analyze their causes | Incident reporting with Lauren. Investigations with contributing factors and five whys. Analytics by location, shift, equipment and cause. | | Corrective actions that change the system | Corrective actions carry an owner, due date and evidence, tied back to the investigation. | | Measure success and show improvements were sustained | Each corrective action has an effectiveness check. Nothing closes until verified. The audit trail keeps the history. | | Set priorities from data | Analytics show where incidents cluster, so the committee can choose high-risk and problem-prone areas. | | QAA committee reviews data and acts on it | Compliance packets include a QAPI summary for each meeting. | | Equity analysis of errors and events | Analytics cluster by location, shift, equipment and cause. Breakdowns by language or race come from your own data and committee review. | ## Frequently asked questions ### What events must a nursing home track under F867? Medical errors and adverse resident events, plus near misses. The program must track them, find causes and prevent repeats. ### How many performance improvement projects are required? At least one distinct project a year on a high-risk or problem-prone area found through the home's own data. The number should reflect the home's services and facility assessment. ### What should a corrective action plan contain? A problem definition with contributing causes, measurable goals, step-by-step interventions and a tracking plan. It should fix the underlying cause at the systems level. ### What changed in the 2025 F867 guidance? CMS added health equity guidance. Homes should consider equity feedback and monitor outcomes for sub-populations. Error analysis should include factors such as race, sexual orientation, socioeconomic status and preferred language. Surveyors have used it since April 28, 2025. ### Can monitoring gaps alone be cited at F867? Yes. CMS's level 1 example is a plan for monthly checks for three months, with no proof the second month's checks happened. Higher levels cover unreviewed data or an unmonitored high-risk system. ## Sources - [eCFR, 42 CFR 483.75 (quality assurance and performance improvement), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-483.75) - [CMS State Operations Manual, Appendix PP, Guidance to Surveyors for Long Term Care Facilities (Rev. 232, issued 07-23-25; revised guidance used on surveys since 04-28-25): F867 section (Rev. 229, issued 04-25-25, effective 04-25-25, implementation 04-28-25)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [CMS memo QSO-25-14-NH (revised 2025-03-10): Revised Long-Term Care Surveyor Guidance, effective April 28, 2025](https://www.cms.gov/files/document/qso-25-14-nh-revised-2025-03-10.pdf) - [HHS Office of Inspector General, Adverse Events in Skilled Nursing Facilities: National Incidence Among Medicare Beneficiaries (OEI-06-11-00370, February 27, 2014)](https://oig.hhs.gov/reports/all/2014/adverse-events-in-skilled-nursing-facilities-national-incidence-among-medicare-beneficiaries/) - [LeadingAge, List of Revised F-tags in New RoPs Guidance 2022 (tag titles as listed for CMS's June 2022 revisions)](https://leadingage.org/sites/default/files/List%20of%20Revised%20F-Tags.pdf) - [CMS State Operations Manual, Chapter 7, Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities (Rev. 244, issued 06-26-26): scope and severity matrix, immediate jeopardy, substandard quality of care](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107c07pdf.pdf) ## Related - [F865 QAPI program and plan: what surveyors ask for](https://incidentkit.ai/compliance/f-tags/f865) - [F868 QAA committee: members, meetings and evidence](https://incidentkit.ai/compliance/f-tags/f868) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Performance improvement project: definition and meaning](https://incidentkit.ai/glossary/performance-improvement-project) --- # F868: the QAA committee > F868 requires a quality assessment and assurance committee. Members are the director of nursing, the medical director or a designee, the infection preventionist and at least three other staff. One of those three is the administrator, owner, board member or another leader. It meets at least quarterly and reports to the governing body. Source: https://incidentkit.ai/compliance/f-tags/f868 · Updated Oct 5, 2026 ## Key facts - **Tag title:** QAA Committee - **Regulation:** 42 CFR 483.75(g)(1) and (g)(2)(i); 483.80(c) for the infection preventionist's role - **Guidance relied on:** Appendix PP Rev. 232 (issued 07-23-25, in use since 04-28-25); F868 section Rev. 225 (08-08-24) - **Minimum members:** DON, medical director or designee, infection preventionist, and three others including a leader - **Meeting clock:** At least quarterly, and as needed - **Reporting line:** Reports its activities to the governing body, or whoever acts as one - **Severity note:** The tag has no severity examples. QAPI sections are not on the substandard quality of care list - **Citation:** F868 · 42 CFR 483.75(g)(1), (g)(2)(i) and 483.80(c) - **Authority:** CMS - **Applies to:** Medicare-certified skilled nursing facilities, Medicaid-certified nursing facilities ## What F868 covers F868 covers the committee itself. It sets who is on it, how often it meets and whom it reports to. [F867](https://incidentkit.ai/compliance/f-tags/f867) covers what the committee does with data. [F865](https://incidentkit.ai/compliance/f-tags/f865) covers the program and plan. The committee must include the director of nursing, the medical director or a designee, the infection preventionist and at least three other staff members. One of the three must be the administrator, owner, board member or another leader. That leader needs knowledge of facility systems and authority to change them. Departments such as maintenance, housekeeping and laundry should be able to take part when their data is discussed. Section 483.80(c) requires the infection preventionist, or at least one of them, to be a member. The infection preventionist reports on the infection prevention and control program regularly. CMS reads that as the same frequency as committee meetings. ## Roster rules surveyors check *What CMS expects and what to keep* | Member | What CMS expects | Proof to keep | | --- | --- | --- | | Director of nursing | Required member | Attendance on every meeting record | | Medical director or designee | The designee cannot be another required member such as the DON. It may be a nurse practitioner, clinical nurse specialist or physician assistant who knows the home's policies. The medical director stays responsible for the role | Attendance, plus proof the medical director received and acknowledged the meeting content | | Infection preventionist | Should attend each meeting and report on the IPCP, outbreaks, healthcare-associated infections and antibiotic stewardship. If absent, another staff member reports, but the IP's duty stays | The IP's report in the minutes | | Three others, including a leader | At least one is the administrator, owner, board member or other leader with authority to change systems | Names and roles on the roster | ## What surveyors check Surveyors use the QAPI and QAA Review pathway at the end of the survey. CMS's F868 guidance does not list specific documents. Surveyors also interview staff and leaders about how the committee works. *What to have ready* | Surveyors look for | Have ready | | --- | --- | | The roster with roles | Every required seat filled, with the medical director's designee, if any, named and qualified | | Meeting dates over the past year | At least four, with extra meetings when issues needed them | | Attendance and minutes | Who attended, what data was reviewed, what was decided, owners and dates | | Report to the governing body | A dated report, or for a small home with no governing body, proof the administrator is a member and briefed | | Medical director involvement | Proof of meaningful participation, such as reporting on trends from the medication regimen review | ## What raises F868 severity The F868 guidance gives no severity examples. QAPI sections are not on the substandard quality of care list in 42 CFR 488.301. A missing seat or a skipped quarter is usually a process finding. The risk is indirect. A committee that did not meet, or lacked the right people, may miss problems that harm residents. F867 examples show this can reach immediate jeopardy. ## Meeting and reporting clocks | Duty | Timing | | --- | --- | | Committee meets | At least quarterly, and as needed to do its QAPI work | | Data review | Often enough that the committee knows whether improvement is needed or happening. Not every data set at every meeting | | Report to the governing body | Activities and QAPI implementation. The regulation sets no fixed interval | | Infection preventionist reports | Same frequency as the committee meets | ## Gaps that lead to citations - One of the four named roles is missing, or the infection preventionist rarely attends. - The medical director's designee is the DON, who is already a required member. - The medical director gets no minutes and nothing records acknowledgement. - A quarter's meeting is skipped with no catch-up meeting. - Minutes list topics but not data, decisions, owners or dates. - Nothing shows the governing body received the committee's report. ## How to show a committee that works Show the loop, not only the meeting. Data comes in, the committee reviews it, assigns corrective actions with owners and dates, and checks results later. Each meeting's minutes should point back to the last and forward to the next. ## How IncidentKit supports F868 IncidentKit does not schedule your committee or keep your official minutes. Attendance and minutes stay in your records. [Compliance packets](https://incidentkit.ai/product/compliance-packets) include a QAPI summary for each meeting. [Analytics](https://incidentkit.ai/product/analytics) show where incidents cluster. Open [corrective actions](https://incidentkit.ai/product/corrective-actions) show what is owed and to whom. Roles and sites are managed under [multi-site and roles](https://incidentkit.ai/product/multi-site-and-roles). See the [QAPI meeting use case](https://incidentkit.ai/use-cases/qapi-committee-meetings) and the [agenda and minutes template](https://incidentkit.ai/templates/qapi-meeting-agenda-and-minutes). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Committee with the required members | Roles and sites are managed in the platform, so the right people see the same data. The roster stays in your records. | | Meet at least quarterly and review data | Compliance packets include a QAPI summary for each meeting. Analytics show clusters by location, shift, equipment and cause. | | Develop and implement plans of action to correct quality deficiencies | Corrective actions carry an owner, due date, evidence and an effectiveness check, so open items go into each agenda. | | Infection preventionist reports on the IPCP | Routing and escalation sends infection-related incidents to the infection preventionist, who can bring them to the meeting. | | Attendance, minutes and governing body report | Not run by IncidentKit. Attach your minutes and sign-in to the compliance packet. | ## Frequently asked questions ### Who must be on a nursing home QAA committee? The director of nursing, the medical director or a designee, the infection preventionist and at least three other staff. One of the three must be the administrator, owner, board member or another leader. ### How often must the QAA committee meet? At least quarterly, and as often as needed to coordinate and evaluate QAPI activities. Data must be reviewed often enough to know whether improvement is needed or happening. ### Can the medical director send a designee? Yes. The designee cannot be another required member, such as the DON, and must know the home's policies. The medical director stays responsible and must receive and acknowledge the meeting content. ### What does the infection preventionist do on the committee? The IP must be a member and report regularly on the infection program, including outbreaks, healthcare-associated infections and antibiotic stewardship. If absent, another staff member can report, but the IP stays responsible. ### Does the committee have to report to a governing body? Yes. The committee reports its activities, including QAPI implementation, to the governing body or whoever acts as one. In a small home with no separate governing body, an administrator who is a required member is already briefed. ## Sources - [eCFR, 42 CFR 483.75 ((g) quality assessment and assurance), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-483.75) - [eCFR, 42 CFR 483.80 ((c) infection preventionist participation on the QAA committee), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-483.80) - [CMS State Operations Manual, Appendix PP, Guidance to Surveyors for Long Term Care Facilities (Rev. 232, issued 07-23-25; revised guidance used on surveys since 04-28-25): F868 section (Rev. 225, issued 08-08-24, effective 08-08-24, implementation 08-08-24)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [LeadingAge, List of Revised F-tags in New RoPs Guidance 2022 (tag titles as listed for CMS's June 2022 revisions)](https://leadingage.org/sites/default/files/List%20of%20Revised%20F-Tags.pdf) - [CMS memo QSO-25-14-NH (revised 2025-03-10): Revised Long-Term Care Surveyor Guidance, effective April 28, 2025](https://www.cms.gov/files/document/qso-25-14-nh-revised-2025-03-10.pdf) - [eCFR, 42 CFR 488.301 (definitions: immediate jeopardy, substandard quality of care), current through 2026-10-01](https://www.ecfr.gov/current/title-42/section-488.301) - [CMS, Revision History for LTC Survey Process Documents and Files (updated 08-13-2026): confirms the official Appendix PP version posted 05/21/25](https://www.cms.gov/files/document/revision-history-ltc-survey-process-documents-files-updated-08-13-2026.pdf) ## Related - [F865 QAPI program and plan: what surveyors ask for](https://incidentkit.ai/compliance/f-tags/f865) - [F867 QAPI improvement activities: adverse event tracking](https://incidentkit.ai/compliance/f-tags/f867) - [F880 infection prevention and control: survey guide](https://incidentkit.ai/compliance/f-tags/f880) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [QAPI Meeting Agenda and Minutes Template (Printable)](https://incidentkit.ai/templates/qapi-meeting-agenda-and-minutes) - [QAA committee: definition and meaning](https://incidentkit.ai/glossary/qaa-committee) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) --- # Nursing home abuse and neglect reporting requirements > Federal rules give nursing homes two clocks. Report alleged abuse, or any allegation that causes serious bodily injury, immediately and within 2 hours. Report other alleged violations within 24 hours. Send investigation results within 5 working days of the incident. Source: https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting · Updated Oct 5, 2026 ## Key facts - **Abuse or serious bodily injury:** Immediately, and no later than 2 hours after the allegation is made - **Other alleged violations:** No later than 24 hours (for example neglect, exploitation, mistreatment, misappropriation of property) - **Investigation results:** To the administrator and the State Survey Agency within 5 working days of the incident - **Suspected crime:** Each covered individual reports to the State Survey Agency and local law enforcement, on the same clocks - **Who is a covered individual:** Any owner, operator, employee, manager, agent or contractor - **Clock type:** Real clock time. The 5-day results deadline counts working days - **Annual duty:** Tell covered individuals of the duty every year; keep proof - **Surveyor tags:** F609 (reporting and annual notice), F610 (investigation and protection), F607 (written policies) - **Citation:** 42 CFR 483.12(b)(5) and (c); section 1150B of the Social Security Act; F607, F609, F610 - **Authority:** CMS - **Applies to:** Medicare-certified skilled nursing facilities, Medicaid-certified nursing facilities, Owners, operators, employees, managers, agents and contractors of those facilities ## What do federal rules require? Two federal duties apply, and both run on short clocks. Under 42 CFR 483.12(c), the **facility** must report every alleged violation involving abuse, neglect, exploitation or mistreatment. That includes injuries of unknown source and misappropriation of resident property. Under 42 CFR 483.12(b)(5), every **covered individual** must report a reasonable suspicion of a crime against a resident. This rule carries out section 1150B of the Social Security Act. Surveyors cite reporting duties, including the annual notice to covered individuals, at [F609](https://incidentkit.ai/compliance/f-tags/f609). They cite investigation and protection duties at [F610](https://incidentkit.ai/compliance/f-tags/f610). F607 covers the written policies behind both. ## What are the 2-hour and 24-hour clocks? The clock depends on what happened, not on what the report is called. Alleged abuse and any event that causes serious bodily injury get 2 hours. Everything else gets 24 hours. *Federal timing under 42 CFR 483.12. Where a state sets a shorter time, the shorter time applies.* | What happened | Deadline | Clock starts | Rule | | --- | --- | --- | --- | | Alleged violation involves abuse, or results in serious bodily injury | Immediately, no later than 2 hours | When the allegation is made | 483.12(c)(1) | | Alleged violation does not involve abuse and does not result in serious bodily injury | No later than 24 hours | When the allegation is made | 483.12(c)(1) | | Reasonable suspicion of a crime, with serious bodily injury | Immediately, no later than 2 hours | When the individual forms the suspicion | 483.12(b)(5)(i)(B) | | Reasonable suspicion of a crime, without serious bodily injury | No later than 24 hours | When the individual forms the suspicion | 483.12(b)(5)(i)(B) | | Results of the investigation | Within 5 working days | Of the incident | 483.12(c)(4) | > **Clock time, not business hours** CMS says the 2-hour and 24-hour limits run on real clock time. The 5 working days for results count from the incident, not from the day you filed the first report. ## Who must report, and to whom? The facility and each covered individual have separate duties. A covered individual is anyone who is an owner, operator, employee, manager, agent or contractor of the facility. | Duty | Who reports | Reports to | | --- | --- | --- | | Suspected crime against a resident | Each covered individual | The State Survey Agency and one or more law enforcement entities where the facility is located | | Alleged abuse, neglect, exploitation or mistreatment | The facility | The administrator and other officials under state law, including the State Survey Agency and adult protective services where state law gives them jurisdiction | | Investigation results | The facility | The administrator or designee and other officials under state law, including the State Survey Agency | An administrator may coordinate one report for staff who ask, as long as it goes out on time. Each covered individual still owns their own duty. A facility cannot stop anyone from reporting directly to law enforcement. ## What counts as an alleged violation? An alleged violation is something staff, a resident, a relative, a visitor or another provider sees or reports that has not yet been investigated. The reporter does not need to say the word abuse. If staff could reasonably conclude abuse, neglect, exploitation or mistreatment might exist, it is reportable. - **Injury of unknown source:** nobody saw the cause, the resident cannot explain it, and the injury looks suspicious from its extent, location or frequency. - **Serious bodily injury:** extreme physical pain, substantial risk of death, protracted loss or impairment of a body part or function, or an injury that needs surgery, hospitalization or physical rehabilitation. Injury from criminal sexual abuse counts. - **Resident-to-resident incidents:** willful actions that cause physical injury, mental anguish or pain are reportable. Examples: bullying, threats of violence, unwanted sexual contact. Ordinary disagreements are not, unless they reach that level. If an allegation meets the definition of abuse, neglect, exploitation or mistreatment, CMS says do not judge whether it is credible before reporting it. ## What must the reports say? The first report must describe the alleged violation and show how residents are being protected. It must be accurate to the best of your knowledge at that moment. Leaving out facts or making the event look smaller can itself draw a deficiency at F609. Keep records of what you reported and the date and time it reached the State Survey Agency. The follow-up report is due within 5 working days of the incident. It gives the investigation results and any corrective action if the allegation was verified. CMS publishes sample forms as Exhibits 358 and 359. Your state may require its own. ## What must the investigation show? F610 asks for evidence of three things. Each allegation was thoroughly investigated. Residents were protected while the investigation was open. Corrective action followed if it was verified. CMS does not require one investigation method. - Observations of the alleged victim, the location and staff and resident interactions. - Interviews with the resident and representative, the alleged perpetrator, witnesses, the practitioner and outside agencies. - Record review: progress notes, incident reports, hospital and medication records, and photographs. A report to law enforcement does not replace your own investigation. Preserve possible evidence, such as clothing and linens, as law enforcement instructs. The QAA committee is expected to monitor reporting and investigation. ## What do surveyors check, and what is at stake? Surveyors check that your policies name the covered individuals, the reportable crimes, what serious bodily injury means, the time limits and who receives the report. They look for proof that every covered individual was told each year, in a language they understand. They also review facility-reported incidents filed since your last survey. A covered individual who fails to report on time faces a civil money penalty of up to $200,000, as adjusted annually. Exclusion from federal health care programs is also possible. If the failure worsens harm to the victim or harms someone else, the limit is $300,000, as adjusted annually. ## How to run it every time 1. **Protect the resident and tell the administrator** Make sure the resident is safe and examined. Separate the alleged perpetrator from residents. Tell the administrator at once. 2. **Pick the clock** Does it involve abuse? Did it cause serious bodily injury? Yes to either means 2 hours. 3. **File with each required office** The State Survey Agency, local law enforcement for a suspected crime, and adult protective services where required. Note the time of each report. 4. **Investigate and keep the evidence** Observations, interviews and record review, ending in a written conclusion. 5. **Send the results within 5 working days** Count from the incident. Include corrective action if the allegation was verified. 6. **Review it at QAA** Bring the case, the timing and the corrective action to the next meeting. See [abuse reporting deadlines](https://incidentkit.ai/use-cases/abuse-reporting-deadlines). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Report each alleged violation within 2 or 24 hours (42 CFR 483.12(c)(1)) | Staff report by text, QR code, email or web form. Lauren asks if abuse is alleged and if there was serious bodily injury. Routing alerts the administrator. Your designated person files with the State Survey Agency. IncidentKit does not file for you. | | Keep documentation of what was reported and when | The audit trail logs who did what and when. Record the time of each outside report on the incident. | | Thorough investigation with evidence (F610) | The investigation workspace holds interviews, record review, contributing factors and a disposition. Lauren drafts. A person signs. | | Protect residents while the investigation is open | Protective steps are logged as corrective actions with an owner and due date. | | Report results within 5 working days and take corrective action if verified | The investigation record supports the results report. Nothing closes until verified. | | QAA committee monitors reporting and investigation (F610, F867) | Analytics cluster incidents by cause. Compliance packets include a QAPI summary. | | Annual written notice to covered individuals (483.12(b)(5)(i)) | Not an IncidentKit feature. Keep the notice and proof of receipt in your training or HR records. | ## Frequently asked questions ### Does the 2-hour deadline count nights and weekends? Yes. The 2-hour and 24-hour limits run on real clock time, not business hours. Only the 5-day results deadline counts working days. ### Can a state set a longer deadline than the federal rule? No. A state may add recipients or event types, but it cannot allow more time than 42 CFR 483.12(c). A shorter state time applies. ### When does the 5-working-day clock for investigation results start? At the incident, not at the first report or the start of the investigation. The rule says within 5 working days of the incident. ### Who counts as a covered individual? Any owner, operator, employee, manager, agent or contractor of the nursing home. Each must be told of the duty every year, in a language they understand. ### Do resident-to-resident arguments have to be reported? Not every one. Willful actions that cause physical injury, mental anguish or pain must be reported. Outbursts not aimed at anyone and ordinary disagreements are not. ## Sources - [42 CFR 483.12, Freedom from abuse, neglect, and exploitation (eCFR)](https://www.ecfr.gov/current/title-42/chapter-IV/subchapter-G/part-483/subpart-B/section-483.12) - [CMS State Operations Manual, Appendix PP, guidance to surveyors for long-term care facilities (F607, F609, F610)](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [CMS nursing home regulations and guidance page, including sample report Exhibits 358 and 359](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/nursing-homes) - [CMS Long-Term Care Survey Process (LTCSP) Procedure Guide, effective July 14, 2026 (Survey Resources package)](https://www.cms.gov/files/zip/survey-resources-updated-09-08-2026.zip) ## Related - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) - [F610 investigate, prevent and correct alleged violations](https://incidentkit.ai/compliance/f-tags/f610) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) - [Abuse Reporting Deadlines for Nursing Homes: 2 and 24 Hours](https://incidentkit.ai/use-cases/abuse-reporting-deadlines) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [Nursing home recertification survey: process and prep](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) - [Nursing Home Incident Report Template (Printable)](https://incidentkit.ai/templates/nursing-home-incident-report) --- # Joint Commission sentinel event policy: what to do and by when > A sentinel event is a patient safety event that reaches a patient and results in death, severe harm or permanent harm. Reporting it to Joint Commission is encouraged, not required. Each one needs a full analysis and action plan within 45 business days of the event or of becoming aware of it. Source: https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events · Updated Oct 5, 2026 ## Key facts - **Definition:** A patient safety event that reaches a patient and results in death, severe harm or permanent harm - **Report to Joint Commission:** Encouraged, not required. Accredited organizations must still analyze every sentinel event - **Analysis and action plan:** Within 45 business days of the event or of becoming aware of it - **If the response is unacceptable:** 15 more business days beyond the original submission period to resubmit - **Action plan strength:** At least one stronger or intermediate-strength action - **Follow-up:** May be a measure of success tracked for at least 120 days - **Confidentiality:** Submissions should not name staff or patients or include protected health information - **At survey:** Surveyors do not search for sentinel events or judge the analysis - **Citation:** Joint Commission Sentinel Event Policy (SE chapter, Comprehensive Accreditation Manual for Hospitals, July 2026 update) - **Authority:** The Joint Commission - **Applies to:** Joint Commission-accredited hospitals, Other Joint Commission-accredited organizations (confirm the policy text in your program's manual) ## What is a sentinel event? Joint Commission defines a sentinel event as a patient safety event that reaches a patient and results in death, severe harm or permanent harm. It is not primarily related to the natural course of the patient's illness. Severe harm counts whatever its duration. Permanent harm counts whatever its severity. Sentinel events are a subcategory of adverse events. They are not limited to clinical care: violence, abductions and power failures can also be sentinel events. See the [sentinel event glossary entry](https://incidentkit.ai/glossary/sentinel-event) and [what is a sentinel event](https://incidentkit.ai/blog/what-is-a-sentinel-event). > **Which policy text this page follows** This page follows the policy as printed in the July 2026 update of the hospital accreditation manual. Other programs may differ in detail, so check your own manual. ## Which events are sentinel events? The policy gives a list of examples and says the list is not comprehensive. Some listed events are unlikely in certain settings, such as a surgery center. *Examples drawn from the Sentinel Event Policy, July 2026 update. The policy text controls.* | Category | Examples from the policy | | --- | --- | | Self-harm | Death by self-inflicted injury in a health care setting, or within 7 days of discharge from inpatient services or an emergency department | | Surgery and procedures | Wrong site, wrong patient or wrong procedure, whatever the outcome. Unintended retention of a foreign object after an invasive procedure | | Violence and abuse | Homicide; sexual abuse or assault; physical assault leading to death, permanent harm or severe harm, of a patient, staff member, visitor or vendor | | Safety and security | Abduction of a patient. Elopement from a staffed-around-the-clock setting leading to death, permanent harm or severe harm. Discharge of an infant to the wrong family | | Maternal and newborn | Intrapartum maternal death. Severe maternal morbidity leading to permanent or severe harm. Unanticipated death of a full-term infant. Severe neonatal hyperbilirubinemia (bilirubin above 30 mg/dL) | | Blood and radiation | ABO or non-ABO blood incompatibility. Radiotherapy to the wrong patient or body region, or more than 25 percent above the planned dose. Fluoroscopy causing permanent tissue injury when practice parameters were not followed | | Fire and falls | Fire, flame or unanticipated smoke or heat during direct patient care caused by equipment in use. A fall causing any fracture, surgery, casting or traction, required care for a neurological or internal injury, or death or permanent harm | If you are unsure whether an event meets the definition, Joint Commission presumes it needs a full analysis. ## What does an appropriate response include? The policy lists seven parts of an appropriate response: - A formalized team response that stabilizes the patient, discloses the event to the patient and family, and supports the family and the staff involved. - Notification of organization leaders. - Immediate investigation. - A comprehensive systematic analysis that finds causal and contributory factors. - Strong corrective actions that eliminate or control system hazards and last over time. - A timeline for putting the actions in place. - Systemic improvement with measurable outcomes. ## What is the analysis, and when is it due? A comprehensive systematic analysis finds the basic or causal factors behind a sentinel event. A root cause analysis is the most common kind. You choose your own method and tools. Joint Commission expects the analysis and corrective action plan within 45 business days. The clock runs from the event or from becoming aware of it. *Source: Joint Commission Sentinel Event Policy, July 2026 update.* | Step | Timing | Notes | | --- | --- | --- | | Respond to the event | Right away | Stabilize, disclose, notify leaders, begin investigating | | Self-report to Joint Commission | Encouraged, not required | A patient safety specialist is assigned when you report | | Submit the analysis and action plan | Within 45 business days of the event or of becoming aware of it | Submit electronically or by an approved method | | Resubmit if the response is unacceptable | 15 business days beyond the original submission period | Joint Commission consults with you first | | Follow-up measure of success | Tracked for at least 120 days if used | Agreed with Joint Commission after the plan is accepted | | Late response | No analysis within a further 45 days after the due date | The accreditation decision may be affected | ## What makes an analysis thorough, credible and acceptable? Joint Commission reviews each response against three tests. - **Thorough:** keeps asking why until it reaches system causes. It focuses on systems and processes, not only individual performance, and looks at risk points and possible redesign. - **Credible:** clear, accurate, precise, relevant, complete and systematic, with depth and breadth. It draws on diverse perspectives, such as a process owner and, when appropriate, a patient or family member. - **Acceptable action plan:** names who is responsible by title and when each action happens. It says how effectiveness will be judged and how the change will be sustained. It says when alternatives will be considered if targets are missed. It includes at least one stronger or intermediate action. Submissions should not include the names of staff or patients or other protected health information. See the [root cause analysis worksheet](https://incidentkit.ai/templates/root-cause-analysis-worksheet) for a starting structure. ## How do surveyors treat sentinel events? Surveyors are told not to search for sentinel events or ask about ones already reported. They check that you have a response process. They assess your performance improvement practices. They interview leaders and staff about identifying, reporting and responding to events. They do not judge whether an analysis is credible. A surveyor may note a Recommendation for Improvement if an analysis and action plan were not completed within 45 days of the event, as the policy words it. Having a sentinel event does not affect an accreditation decision. Willful failure to respond appropriately could. See [Joint Commission survey readiness](https://incidentkit.ai/compliance/survey-readiness/joint-commission-survey-readiness). ## What other clocks can the event start? Other duties have their own clocks. A device-related death or serious injury is reportable within 10 work days under [21 CFR Part 803](https://incidentkit.ai/compliance/reporting-deadlines/device-adverse-event-reporting). Some states require reports in hours or days, such as Pennsylvania's 24 hours for a serious event and Minnesota's 15 working days. See the [state reporting overview](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) and confirm your own state's rules. ## How to run the first 45 business days 1. **Stabilize, disclose and notify** Care for the patient, tell the patient and family, support the staff involved and tell your leaders. 2. **Decide whether it is a sentinel event** Compare it with the policy. If you are unsure, treat it as one. 3. **Decide about self-reporting** It is optional. Early contact brings a patient safety specialist who can help with the analysis. 4. **Run the analysis** Build a team with diverse perspectives and ask why until you reach system causes. 5. **Write the action plan** Owner by title, dates, effectiveness measure and a plan to sustain the change, with at least one stronger or intermediate action. 6. **Prove it worked** Track a measurable result for at least 120 days if that is your follow-up. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Formal team response, disclosure and notification of leaders | Routing and escalation alert the roles you name. The audit trail records who was notified and when. Disclosure is a clinical conversation you document in the investigation. | | Immediate investigation and a comprehensive systematic analysis | The investigation workspace holds contributing factors, five whys and a disposition. Lauren drafts. A person signs. Human-authored RCA templates are rolling out. | | Action plan with an owner by title, dates and an effectiveness measure | Corrective actions carry an owner, due date, evidence and an effectiveness check. Nothing closes until verified. | | A measure of success tracked for at least 120 days | Analytics and the effectiveness check give you the counts to track. You choose the measure and report it to Joint Commission yourself. | | Submission to Joint Commission without names or health information | IncidentKit does not submit to Joint Commission. You complete the submission in Joint Commission Connect, drawing on the investigation record. | ## Frequently asked questions ### Do we have to report a sentinel event to Joint Commission? No. Self-reporting is encouraged, not required. You must still complete a full analysis and action plan for each event. ### What is the difference between an adverse event and a sentinel event? An adverse event that reaches a patient and results in death, severe harm or permanent harm. Less harmful adverse events still belong in your incident reporting. ### Does every fall count as a sentinel event? No. A fall is a sentinel event only with a fracture, surgery, casting or traction, care for a neurological or internal injury, or death or permanent harm. ### Should the analysis include staff names? No. Submissions should not include names of staff or patients or other protected health information. ### How long do we have if the analysis is rejected? 15 more business days to resubmit. If it is still unacceptable, your accreditation decision may be affected. ## Sources - [Joint Commission, Sentinel Event Policy (SE), Comprehensive Accreditation Manual for Hospitals, CAMH Update 1, July 2026](https://digitalassets.jointcommission.org/api/public/content/4035922bcc2f41bd83fbc1f55764a7b4?v=bf31f43b) - [Joint Commission, Sentinel Event Policy and Procedures (policy page named in the manual)](https://www.jointcommission.org/en-us/knowledge-library/support-center/standards-interpretation/sentinel-event-policy-and-procedures) - [FDA, 21 CFR 803.30 user facility reporting requirements (eCFR)](https://www.ecfr.gov/current/title-21/section-803.30) - [Pennsylvania Act 13 of 2002, MCARE Act, section 313](https://www.palegis.us/statutes/unconsolidated/law-information/view-statute?txtType=PDF&SessYr=2002&ActNum=0013.&SessInd=0) - [Minnesota Statutes 144.7065, facility requirements to report, analyze and correct](https://www.revisor.mn.gov/statutes/cite/144.7065) ## Related - [Sentinel event: definition and meaning](https://incidentkit.ai/glossary/sentinel-event) - [What is a sentinel event? Definition, examples, response](https://incidentkit.ai/blog/what-is-a-sentinel-event) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [Joint Commission survey readiness: tracers, unannounced](https://incidentkit.ai/compliance/survey-readiness/joint-commission-survey-readiness) - [Root Cause Analysis Worksheet (5 Whys Template)](https://incidentkit.ai/templates/root-cause-analysis-worksheet) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) - [Root cause analysis: definition and meaning](https://incidentkit.ai/glossary/root-cause-analysis) --- # ASC Quality Reporting Program (ASCQR): measures, deadlines and penalty > The ASC Quality Reporting Program is a CMS pay-for-reporting program. An ASC that misses its requirements gets a 2.0 percentage point cut to its Medicare annual payment update. Data for 2026 are due January 1 to May 17, 2027 and affect 2028 payment. OAS CAHPS survey data are due quarterly. Source: https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting · Updated Oct 5, 2026 ## Key facts - **Penalty:** 2.0 percentage point reduction in the annual payment update - **2026 data affects:** Medicare payment from January 1 to December 31, 2028 (CY 2028 payment determination) - **Web-based measures due:** January 1 to May 17, 2027, for events in calendar year 2026 - **OAS CAHPS Q2 2026 due:** October 14, 2026. Q3 is due January 13, 2027 and Q4 April 14, 2027 - **Case-volume exemption:** Fewer than 240 Medicare claims a year (primary and secondary payer) - **Voluntary measures:** ASC-11 (cataract visual function) and ASC-21 (THA/TKA patient-reported outcome) for 2026 - **Claims-based measures:** ASC-12, ASC-17, ASC-18 and ASC-19 come from Medicare claims. Nothing to submit - **Where to submit:** Hospital Quality Reporting (HQR) with a HARP account and a Security Official - **Citation:** 42 CFR 416.300 through 416.320; section 1833(i)(7) of the Social Security Act - **Authority:** CMS - **Applies to:** Medicare-participating ambulatory surgical centers paid under the ASC payment system, ASCs with at least 240 Medicare claims a year (primary and secondary payer) ## What is the ASC Quality Reporting Program? ASCQR is a CMS pay-for-reporting program set up by the Tax Relief and Health Care Act of 2006. It applies to ASCs paid under Medicare Part B fee-for-service that meet a claims threshold. CMS posts submitted data publicly after the ASC has had about 30 days to preview it. The rules are at 42 CFR 416.300 through 416.320, and CMS changes the measure set each year in the OPPS/ASC payment rule. See the [ASCQR glossary entry](https://incidentkit.ai/glossary/ascqr) for a short definition. ## What is the penalty for not reporting? An ASC that misses program requirements gets a 2.0 percentage point cut to its annual Medicare payment update for that payment year. The statute is section 1833(i)(7) of the Social Security Act. The rule is 42 CFR 416.300(a). The cut applies to the facility's NPI, so every facility billing under that NPI is affected. | Situation | Result | | --- | --- | | Required data not submitted, or a required measure left blank | 2.0 percentage point reduction for that payment determination year | | ASC withdraws from the program (allowed through August 31 of the year before the payment determination) | 2.0 percentage point reduction for that year and each later year it stays withdrawn | | Fewer than 240 Medicare claims in a year (primary and secondary payer) | Not required to report for the next period. For example, fewer than 240 claims in 2025 means no 2026 reporting | | Extraordinary circumstance such as a hurricane | Request an exception within 60 calendar days. CMS may exempt the ASC or extend the deadline | | Notified that you will not receive the full update | Reconsideration request due March 17 of the payment determination year | To estimate what the cut means for your center, use the [ASCQR penalty calculator](https://incidentkit.ai/tools/ascqr-penalty-calculator). ## Which measures apply to the 2026 reporting period? CMS's January 2026 guide lists these measures for the CY 2026 reporting period, which sets the CY 2028 payment determination. | Measure | How it is reported | Status | | --- | --- | --- | | ASC-1 Patient Burn; ASC-2 Patient Fall; ASC-3 Wrong Site, Wrong Side, Wrong Patient, Wrong Procedure, Wrong Implant; ASC-4 All-Cause Hospital Transfer/Admission | Web-based, entered in HQR | Required | | ASC-9 Appropriate Follow-Up Interval for Normal Colonoscopy in Average Risk Patients; ASC-13 Normothermia; ASC-14 Unplanned Anterior Vitrectomy | Web-based, entered in HQR | Required | | ASC-11 Cataracts: Improvement in Patient's Visual Function within 90 Days | Web-based, entered in HQR | Voluntary | | ASC-15a to ASC-15e OAS CAHPS patient experience survey | Through a CMS-approved survey vendor, quarterly | Required | | ASC-12, ASC-17, ASC-18, ASC-19 hospital visit measures | Calculated from Medicare claims | Nothing to submit | | ASC-21 Total Hip and Total Knee Arthroplasty patient-reported outcome measure | Submitted by the ASC (pre- and post-procedure data) | Voluntary for 2026 | CMS finalized the removal of ASC-20 (COVID-19 vaccination coverage among healthcare personnel), ASC-22 and ASC-23 (social drivers of health) and ASC-24 (facility commitment to health equity) in the CY 2026 OPPS/ASC final rule. ## What are the deadlines right now? As checked on October 5, 2026, the next date is the Q2 2026 OAS CAHPS submission on October 14, 2026. HQR must accept submissions by 11:59 p.m. Pacific Time on the due date. CMS advises leaving at least 15 calendar days before a deadline to fix errors. Always confirm dates on QualityNet. | Item | Period covered | Deadline | | --- | --- | --- | | OAS CAHPS, Q1 2026 | January 1 to March 31, 2026 | July 8, 2026 (passed) | | OAS CAHPS, Q2 2026 | April 1 to June 30, 2026 | October 14, 2026 | | OAS CAHPS, Q3 2026 | July 1 to September 30, 2026 | January 13, 2027 | | OAS CAHPS, Q4 2026 | October 1 to December 31, 2026 | April 14, 2027 | | Web-based measures (ASC-1, -2, -3, -4, -9, -13, -14, and voluntary -11) | January 1 to December 31, 2026 | Submission window January 1 to May 17, 2027 | | Claims-based measures | ASC-12: January 1, 2024 to December 31, 2026. ASC-17 to ASC-19: January 1, 2025 to December 31, 2026 | No submission | ## Who must participate? - ASCs paid under Medicare fee-for-service with at least 240 Medicare claims a year must participate. An ASC newly designated as open must be open in iQIES at least four months before data collection starts. - ASCs that share one NPI report for all facilities under that NPI. - Register a HARP account and name a Security Official in HQR. CMS recommends two. Log in at least every 60 days to keep an account active. - Contract with a CMS-approved OAS CAHPS survey vendor. ## Where do the adverse event numbers come from? ASC-1 to ASC-4 are counts from your own records. For each you enter a numerator, such as ASC admissions with a burn before discharge, and a denominator of all ASC admissions. If you had no events, you still enter zeros. A blank required measure counts as not reporting. Your incident log is the source of the numbers you attest to. An event filed under another category, or never entered, changes them. Reconcile the log against the measure definitions in the ASCQR Specifications Manual each quarter, not in April. The same data feeds your QAPI program, because 42 CFR 416.43 requires an ASC to track adverse patient events. See [ASC QAPI requirements](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers). ## How to avoid a missed submission 1. **Name two Security Officials** One primary and one backup, both with active HQR logins. 2. **Calendar the dates** The four OAS CAHPS quarterly dates and the January to May window for web-based measures. 3. **Reconcile each quarter** Match incident log counts to the measure definitions and fix miscoded events early. 4. **Submit early and check** Use the submission requirements dashboard in HQR, and leave at least 15 calendar days to correct errors. 5. **Keep the record** File the reconciliation sheet and a copy of what you submitted with your QAPI minutes. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | ASC-1 to ASC-4 counts from your own records: burns, falls, wrong site, side, patient, procedure or implant, and hospital transfers | Intake captures each event once with its type, date and outcome. Analytics counts by type and period, so you can reconcile before you enter numbers in HQR. | | Complete data, with zeros where there were no events | A pack sets incident types per site, so categories stay the same. A person still reviews the counts before submission. | | Hospital transfer tracking (ASC-4 and the QAPI indicators surveyors look for) | Transfers to a hospital are recorded as incidents with the investigation attached. | | QAPI: track adverse events, examine causes, sustain improvements (42 CFR 416.43) | Investigations lead to corrective actions with an effectiveness check. Compliance packets summarize the data for QAPI meetings. | | Submitting data and running the patient survey | IncidentKit does not submit to HQR or run OAS CAHPS. Your Security Official enters the web-based data, and your survey vendor submits survey data. | ## Frequently asked questions ### How much is the ASCQR payment reduction? 2.0 percentage points off the annual Medicare payment update for the affected year. It applies to the NPI, so every facility under that NPI is affected. ### What if we have no events to report for a measure? Enter zeros, or choose the option confirming no data. Required measures cannot be left blank, and a blank brings the 2.0 percentage point reduction. ASC-11 is voluntary. ### Can we withdraw from the program to avoid the work? Yes, through August 31 of the year before a payment determination. But it triggers the 2.0 percentage point reduction for that year and each later year. ASCs with fewer than 240 Medicare claims are exempt without withdrawing. ### What if a hurricane or other disaster stops us from reporting? Request an extraordinary circumstances exception within 60 calendar days. CMS may exempt you, extend the time or grant a blanket exception to a region. Keep records of the event. ### Does the ASC run the OAS CAHPS survey itself? No. Use a CMS-approved OAS CAHPS vendor. An ASC with fewer than 60 survey-eligible patients in the period may request a participation exemption through December 31 of the reporting period. ## Sources - [42 CFR 416.300, basis and scope of the ASCQR Program (eCFR)](https://www.ecfr.gov/current/title-42/section-416.300) - [42 CFR 416.305, participation and withdrawal requirements (eCFR)](https://www.ecfr.gov/current/title-42/section-416.305) - [42 CFR 416.310, data collection and submission requirements (eCFR)](https://www.ecfr.gov/current/title-42/section-416.310) - [CMS, Guide to Successful Reporting in the ASCQR Program, January 2026](https://qualityreportingcenter.com/globalassets/2025/12/asc/ascqr_2026_successful_guide_final_508.pdf) - [CMS, ASCQR Important Dates, CY 2026 Reporting Period / CY 2028 Payment Determination](https://w.qualityreportingcenter.com/globalassets/2025/12/asc/ascqr_2026_importantdates_final_508.pdf) - [CMS, CY 2026 OPPS/ASC final rule and ASCQR Program highlights, January 2026](https://www.qualityreportingcenter.com/globalassets/oqr-2026-events/asc-012126/asc--final-rule_vfinal508u2.pdf) ## Related - [ASCQR (ASC Quality Reporting Program): definition and meaning](https://incidentkit.ai/glossary/ascqr) - [ASC Quality Reporting payment update impact calculator](https://incidentkit.ai/tools/ascqr-penalty-calculator) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) - [Incident reporting software for surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers) - [ASC Incident Report Template for Surgery Centers](https://incidentkit.ai/templates/asc-incident-report) --- # FDA medical device reporting for user facilities > Under 21 CFR Part 803, a device user facility must report a device-related death to FDA and the manufacturer. The deadline is 10 work days from becoming aware. It reports a serious injury to the manufacturer, or to FDA if the manufacturer is unknown, in the same time. A facility that filed any reports also sends FDA an annual report on Form FDA 3419 by January 1. Source: https://incidentkit.ai/compliance/reporting-deadlines/device-adverse-event-reporting · Updated Oct 5, 2026 ## Key facts - **Death:** Report to FDA and the manufacturer (if known) as soon as practicable, no more than 10 work days after you become aware - **Serious injury:** Report to the manufacturer within 10 work days. To FDA if the manufacturer is not known - **Annual report:** Form FDA 3419, due January 1. Not required if you filed no reports - **Malfunctions:** Not required for user facilities. Voluntary reports go through MedWatch - **Work day:** Monday through Friday, except Federal holidays - **Report form:** Form FDA 3500A on paper, or an electronic format FDA can process - **Records:** Keep each MDR event file for 2 years from the date of the event - **Not covered:** Physician offices, school nurse offices and employee health units - **Citation:** 21 CFR Part 803, Subpart C (803.30, 803.32, 803.33), with 803.17 and 803.18 - **Authority:** FDA (Center for Devices and Radiological Health) - **Applies to:** Hospitals, Ambulatory surgical facilities, Nursing homes, including hospice and rehabilitation providers, Outpatient diagnostic and outpatient treatment facilities, including home health care groups ## Who is a device user facility? A device user facility is a hospital, ambulatory surgical facility, nursing home, outpatient diagnostic facility or outpatient treatment facility. It is not a physician's office. The definitions are broad. Nursing homes include hospice and rehabilitation providers. Outpatient treatment facilities include home health care groups and ambulance providers. Physician offices, school nurse offices and employee health units are not user facilities. A facility is covered whether or not it is licensed or accredited. ## What must a user facility report? *21 CFR 803.30 and 803.33. A work day is Monday through Friday, except Federal holidays.* | Event | Report to | Deadline | Form | | --- | --- | --- | --- | | A device may have caused or contributed to a death | FDA and the manufacturer, if known | As soon as practicable, no more than 10 work days after you become aware | Form FDA 3500A | | A device may have caused or contributed to a serious injury | The manufacturer; FDA if the manufacturer is not known | No later than 10 work days after you become aware | Form FDA 3500A | | A device malfunction with no death or serious injury | Not required for user facilities | None. You may report voluntarily through MedWatch | Form FDA 3500 (voluntary) | | All reports filed during the year | FDA | Annual report by January 1 | Form FDA 3419 | Caused or contributed is broad. It covers a death or serious injury that was or may have been attributed to a device. It also covers one in which a device was or may have been a factor. That includes failure, malfunction, improper design, manufacture or labeling, and user error. ## When does the 10-work-day clock start? The count runs from the day after you become aware. A facility becomes aware when medical personnel get information that reasonably suggests a reportable event. These are people employed by or formally affiliated with the facility. Medical personnel includes licensed, registered or certified clinicians, people with a diploma or degree in a professional or scientific field, employees who receive medical complaints or adverse event reports, and their supervisors. Report what is reasonably known: the information in your documents and what reasonable follow-up inside the facility turns up. You need not investigate to gather information you do not reasonably have. > **Awareness can come from any source** The rule counts information from any source. A patient complaint, a chart note or a call from a nurse can start the clock. Route possible device events to the person who decides reportability the day they surface. ## What counts as a serious injury? A serious injury is an injury or illness that meets any of three tests. It is life-threatening. It results in permanent impairment of a body function or permanent damage to a body structure. Or it needs medical or surgical intervention to prevent that impairment or damage. Permanent means irreversible. It excludes trivial impairment or damage. ## What goes in each report? Each report carries a user facility report number. It is built from your 10-digit CMS provider number, the year and a four-digit sequence, such as 1234560000-2011-0001. Reports go on Form FDA 3500A if on paper, or in an electronic format FDA can process. The annual report, Form FDA 3419, is due by January 1 each year. It lists each reportable event from the year. For each, give the report number, manufacturer name and address, device brand and common name, model, catalog, serial and lot numbers and UDI, a brief description, and where the report went. You may attach copies of the reports instead. If you filed no reports, you file no annual report. ## What written procedures and files are required? Every user facility must develop, maintain and implement written MDR procedures. They must provide for: - timely identification, communication and evaluation of events that may be reportable; - a standard review process for deciding whether an event meets the reporting criteria; - timely transmission of complete reports to manufacturers or FDA; and - documentation and records, including the information evaluated to decide if an event was reportable. Keep an MDR event file for each event for 2 years from the date of the event. It holds your record of how you decided whether the event was reportable, including events you chose not to report. It also holds copies of every report and FDA's electronic acknowledgments. Authorized FDA staff may access, copy and verify these records at reasonable times. ## What should intake capture? The annual report needs device details that are easy to lose. They are brand and common name, manufacturer, model, catalog, serial and lot numbers, and UDI. Capture them when the incident is first reported, with the date and time medical personnel learned of it. The reportability decision, and who made it, belongs in the incident record. It must be in the MDR event file. A device-related death or serious injury may also be a [sentinel event](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) and may start a state reporting clock. See the [state reporting overview](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview). ## A repeatable path from event to filing 1. **Flag the possible device event at intake** Ask whether a device was involved and record its identifiers. 2. **Note when medical personnel became aware** That date starts the 10-work-day count. 3. **Decide reportability under your written procedure** Record the decision and who made it, including a decision not to report. 4. **File on time** Death: FDA and the manufacturer. Serious injury: the manufacturer, or FDA if the manufacturer is unknown. 5. **Keep the MDR event file for 2 years** Include reports, acknowledgments and your deliberations. 6. **File the annual report by January 1** Only needed if you filed any reports during the year. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Written MDR procedures with a standard review process (803.17) | Routing and escalation sends a possible device event to the person your procedure names. The investigation records the reportability decision. You write the procedure itself. | | Report within 10 work days of becoming aware, from any source | Intake by text, QR code, email or web form timestamps the report. The audit trail logs who acted and when. Lauren asks whether a device was involved. | | MDR event file kept for 2 years (803.18) | The incident, the investigation and the audit trail stay together in one record with every change logged. | | Annual report details: device identifiers, event description, where reported | Incident fields hold device details. Analytics groups incidents by equipment, so you can list the year's device-related events before you complete Form FDA 3419. | | Submitting reports to FDA and manufacturers | IncidentKit does not file with FDA or manufacturers. Submit through FDA's electronic reporting or on Form FDA 3500A. | ## Frequently asked questions ### Do user facilities have to report device malfunctions? No. User facilities report only deaths and serious injuries a device may have caused or contributed to. Malfunction reports are voluntary, through MedWatch. ### Who gets the report when a patient is seriously injured? The device manufacturer, or FDA if the manufacturer is unknown. A death goes to FDA and the manufacturer. Both are due within 10 work days of becoming aware. ### What is a work day? Monday through Friday, except Federal holidays. Counting starts the day after you become aware. For a death, file as soon as practicable, well before the last day. ### Is a surgery center covered by the device reporting rule? Yes. An ambulatory surgical facility is a user facility, whether independent or run by another entity, licensed or not. Physician offices are excluded. ### How long do we keep device reporting records? 2 years from the date of the event. The file holds your reportability decision record, every report and FDA's electronic acknowledgments. ## Sources - [21 CFR 803.3, definitions (eCFR)](https://www.ecfr.gov/current/title-21/section-803.3) - [21 CFR 803.30, user facility reporting requirements (eCFR)](https://www.ecfr.gov/current/title-21/section-803.30) - [21 CFR 803.33, user facility annual report (eCFR)](https://www.ecfr.gov/current/title-21/section-803.33) - [21 CFR 803.17, written MDR procedures (eCFR)](https://www.ecfr.gov/current/title-21/section-803.17) - [21 CFR 803.18, MDR files and records (eCFR)](https://www.ecfr.gov/current/title-21/section-803.18) - [FDA, Mandatory reporting requirements: manufacturers, importers and device user facilities](https://www.fda.gov/medical-devices/postmarket-requirements-devices/mandatory-reporting-requirements-manufacturers-importers-and-device-user-facilities) ## Related - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) - [Adverse event: definition and meaning](https://incidentkit.ai/glossary/adverse-event) - [ASC Incident Report Template for Surgery Centers](https://incidentkit.ai/templates/asc-incident-report) - [Patient safety event reporting software for hospitals](https://incidentkit.ai/solutions/hospitals) - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) --- # State adverse event and incident reporting: a verified overview > Most states run their own adverse event reporting system. Rules differ on who reports, what counts and how fast. This page covers four verified systems, not every state: Pennsylvania, New York, Minnesota and Florida. Confirm yours with your licensing agency. Source: https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview · Updated Oct 5, 2026 ## Key facts - **Federal floor for nursing homes:** 2 hours or 24 hours to report, 5 working days for results. States cannot allow longer - **Pennsylvania:** Serious events reported within 24 hours of confirmation (MCARE Act) - **New York:** NYPORTS, run by the State Department of Health, for Article 28 hospitals and diagnostic and treatment centers - **Minnesota:** Listed events within 15 working days of discovery. Root cause analysis within 60 days - **Florida:** Listed adverse incidents to the state agency within 15 calendar days (hospitals, ASCs, nursing homes) - **Scope of this page:** Only systems verified on official sources. Not every state, and not every requirement - **Citation:** State statutes and regulations (vary by state); federal floor for nursing homes at 42 CFR 483.12 - **Authority:** State health departments and designated state agencies - **Applies to:** Hospitals, Ambulatory surgical centers, Nursing homes ## How do state reporting systems differ? State systems differ on four things: which facility types report, which events count, the deadline, and who receives the report. They sit on top of federal rules. They do not replace them. For nursing homes, CMS says a state may add recipients and event types. It may not remove a federally required report or allow a longer time than the federal rule. *Systems verified on official state sources, 2026-10-05. Confirm current rules with your state agency before you rely on this table.* | State | System and governing body | Facility types | Verified timing | | --- | --- | --- | --- | | Pennsylvania | PA-PSRS, Patient Safety Authority with the Department of Health, under the MCARE Act (Act 13 of 2002) | Hospitals, ambulatory surgical facilities, birth centers. Nursing homes report healthcare-associated infections | Serious events: 24 hours after confirmation. Written patient notice within 7 days | | New York | NYPORTS, State Department of Health, under Public Health Law 2805-l and 10 NYCRR 405.8 and 751.10 | Article 28 hospitals and diagnostic and treatment centers | Check the Department of Health for events and timing | | Minnesota | Adverse Health Events Reporting Law, Minnesota Department of Health, Minn. Stat. 144.7065 | Hospitals and licensed ambulatory surgical centers | 15 working days after discovery. Root cause analysis and corrective action plan within 60 days | | Florida | Agency for Health Care Administration, Fla. Stat. 395.0197 and 400.147 | Hospitals and ambulatory surgical centers (395). Nursing homes (400) | Listed incidents: 15 calendar days. Nursing homes: investigation begins within 1 business day of the risk manager's report | ## Pennsylvania: Patient Safety Authority and PA-PSRS The MCARE Act created the Patient Safety Authority. It defines a medical facility as an ambulatory surgical facility, birth center, hospital or abortion facility. A serious event is an event in clinical care that results in death or compromises patient safety and results in an unanticipated injury needing additional health care services. An incident could have injured the patient but did not. A medical facility must report a serious event to the Department of Health and the Authority within 24 hours of confirming it. The patient gets written notice within 7 days of the occurrence or discovery. Health care workers who believe a serious event or incident occurred report it under the facility's patient safety plan within 24 hours of occurrence or discovery. Reports to the Authority leave out patient names and other identifiable information. ## New York: NYPORTS NYPORTS, the New York Patient Occurrence Reporting and Tracking System, is a mandatory adverse event reporting system. The State Department of Health runs it under Public Health Law 2805-l and 10 NYCRR 405.8 and 751.10. Designated staff of Article 28 hospitals and diagnostic and treatment centers report through the Health Commerce System. Check the Department of Health for current reportable events and timing. ## Minnesota: Adverse Health Events Reporting Law Minnesota Statutes 144.7065 requires hospitals and licensed ambulatory surgical centers to report listed adverse health care events to the Department of Health. Reports are due as soon as reasonably and practically possible, and no later than 15 working days after discovery. The categories are surgical, product or device, patient protection, care management, environmental, potential criminal and radiologic events. The facility must also do a root cause analysis that considers staffing levels. It must then carry out a corrective action plan or tell the Department why it will not. If the analysis and plan are not finished when the event is reported, they are due within 60 days of the event. Reports must not identify patients, professionals or employees. Use the Department's current event list, because its publications have cited different counts over time. ## Florida: adverse incident reporting Florida licenses hospitals and ambulatory surgical centers under Chapter 395. Section 395.0197 requires each licensed facility to report certain adverse incidents to the Agency for Health Care Administration. Reports are due within 15 calendar days after the incident occurs. The list includes the death of a patient, brain or spinal damage, surgery on the wrong patient, the wrong site or the wrong procedure, medically unnecessary surgery, surgical repair of damage from a planned procedure, and removal of unplanned foreign objects. The agency may grant extensions on written request. Section 400.147 covers nursing homes. Staff must report adverse incidents to the facility risk manager within 3 business days. The nursing home must begin an investigation within 1 business day after the risk manager receives the report. It must send a report to the agency within 15 calendar days after the incident occurred. Abuse, neglect and exploitation have their own reporting rules. ## What about nursing homes in other states? Every certified nursing home follows the federal clocks in 42 CFR 483.12. It has 2 hours or 24 hours to report an alleged violation, and 5 working days to report results. Reports go to the administrator and to other officials under state law, including the State Survey Agency. CMS notes that some states go further. For example, some require every fall to be reported. Read [abuse and neglect reporting](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting) for the federal rule. ## Which reporting clocks have we verified? *A cross-section, not a complete list. Confirm your own state's rules.* | Clock | Applies to | Source | | --- | --- | --- | | 2 hours or 24 hours to report; 5 working days for results | Nursing home allegations of abuse, neglect, exploitation and mistreatment | 42 CFR 483.12(c) | | 10 work days | Device-related death or serious injury at any device user facility | 21 CFR 803.30 | | 45 business days to submit the analysis and action plan | Joint Commission sentinel events at accredited organizations | Joint Commission Sentinel Event Policy | | 24 hours after confirmation | Serious events at Pennsylvania medical facilities | MCARE Act, section 313 | | 15 working days | Listed events at Minnesota hospitals and ASCs | Minn. Stat. 144.7065 | | 15 calendar days | Listed adverse incidents at Florida hospitals and ASCs, and Florida nursing homes | Fla. Stat. 395.0197 and 400.147 | One event can start several clocks at once. A wrong-site surgery at a Minnesota surgery center, for example, is a listed state event. It is also a Joint Commission sentinel event for an accredited center. It also counts toward ASC-3 in the [ASC Quality Reporting Program](https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting). See also [sentinel events](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) and [device adverse event reporting](https://incidentkit.ai/compliance/reporting-deadlines/device-adverse-event-reporting). ## How to confirm your own state's rules 1. **Find your licensing agency** Usually the state department of health. Look for the licensure rules for your facility type and any adverse event or incident reporting page. 2. **Read the statute and regulation, not only a summary** Note who reports, what is reportable, the deadline, the form and who receives it. 3. **Ask the agency about edge cases** Call or email your licensing contact about cases such as falls or events found after discharge. 4. **Check your accreditor and insurers** They may add expectations of their own. 5. **Write it into policy and routing rules** One page per facility type: the event, the clock, the recipient and the owner. 6. **Review once a year** Rules change. Note the date you last checked. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Know which reports your state requires, to whom, and by when | You supply the rules. IncidentKit does not interpret state law. Packs set incident types, forms, regulator exports and roles for a kind of site. Routing rules name the owner and recipients. | | Reach the right person immediately when a reportable event occurs | Routing and escalation notifies the roles you name the moment an incident is flagged. | | Consistent facts across several reports for one event | One incident record holds the timeline, and the audit trail logs every change with who, when and what changed. | | Root cause analysis and action plan where required, such as Minnesota's 60 days | Investigations hold contributing factors and five whys. Corrective actions carry an owner, a due date and an effectiveness check. | | Different states and facility types in one organization | Organizations, facilities and six roles let you mix packs across sites in one account, so each site can follow its own state's routing. | ## Frequently asked questions ### Do state reporting rules replace federal requirements? No. They sit alongside them. No state can override the federal duty to report alleged violations under 42 CFR 483.12(c). States can add recipients, event types or shorter deadlines, not longer ones. ### Is my state listed on this page? Only if we verified it: Pennsylvania, New York, Minnesota and Florida. Many other states have systems. Ask your state licensing agency, and do not read a gap as an exemption. ### Does reporting to the state satisfy my accreditor? Not automatically. Joint Commission, for example, does not require sentinel event reports, but accredited organizations must analyze every sentinel event. Check both. ### Do state reports include patient names? It depends. Minnesota's statute says reports identify the facility but not professionals, employees or patients. Pennsylvania reports to the Authority exclude patient names. ### What should we do when two reports are due for one event? File each on its own clock and keep one timeline in a single record. Do not wait for one report to finish before starting another. ## Sources - [Pennsylvania Patient Safety Authority, PA-PSRS reporting requirements](https://patientsafety.pa.gov/PA-PSRS) - [Pennsylvania Act 13 of 2002, MCARE Act, sections 302, 308 and 313](https://www.palegis.us/statutes/unconsolidated/law-information/view-statute?txtType=PDF&SessYr=2002&ActNum=0013.&SessInd=0) - [New York State Department of Health, NYPORTS](https://www.health.ny.gov/facilities/hospital/nyports/) - [Minnesota Statutes 144.7065, facility requirements to report, analyze and correct](https://www.revisor.mn.gov/statutes/cite/144.7065) - [Minnesota Department of Health, Adverse Health Events fact sheet](https://www.health.mn.gov/facilities/patientsafety/adverseevents/docs/adverse29events.pdf) - [Florida Statutes 395.0197, internal risk management program](http://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&URL=0300-0399/0395/Sections/0395.0197.html) - [Florida Statutes 400.147, internal risk management and quality assurance program (nursing homes)](http://www.leg.state.fl.us/statutes/index.cfm?App_mode=Display_Statute&URL=0400-0499/0400/Sections/0400.147.html) - [CMS State Operations Manual, Appendix PP, F609 guidance on state law and timeframes](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) ## Related - [Nursing home abuse reporting: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting) - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) - [Medical device reporting for user facilities: 21 CFR 803](https://incidentkit.ai/compliance/reporting-deadlines/device-adverse-event-reporting) - [ASCQR Program: measures, deadlines, 2.0-point penalty](https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting) - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) - [Multi-site incident reporting software for groups](https://incidentkit.ai/solutions/multi-site-groups) - [Adverse event: definition and meaning](https://incidentkit.ai/glossary/adverse-event) --- # ASC survey readiness: how to be ready every day > Every CMS or state survey of an ambulatory surgery center is unannounced. Surveyors watch at least one surgical case, tour the building, interview people and review records. In the first hours they ask for surgery lists, transfers, policies and QAPI documents. Keep those records current every day. Source: https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness · Updated Oct 5, 2026 ## Key facts - **Notice:** All CMS and state ASC surveys are unannounced - **Standard team:** Usually two health surveyors (at least one RN) and one Life Safety Code surveyor, about 2 days on site - **Case observation:** At least one surgical case, often followed from registration to discharge - **Record sample:** At least 20 closed records if over 50 cases a month, 10 below that; always deaths and hospital transfers - **Day-one lists:** Surgeries from the past 6 months, transfers or deaths from the past year; usually due in 1 to 2 hours - **After the survey:** Form CMS-2567 within 10 working days; plan of correction within 10 calendar days of receipt - **Deemed ASCs:** Surveyed by their accreditor; CMS validates a sample - **Citation:** 42 CFR Part 416, Subparts B and C; CMS State Operations Manual, Appendix L - **Authority:** CMS and state survey agencies; CMS-approved accrediting organizations - **Applies to:** Medicare-certified ambulatory surgical centers surveyed by a state agency, ASCs accredited by a CMS-approved organization for deemed status ## Who surveys an ASC? The state survey agency surveys a non-deemed ASC for CMS. If a national accreditor gives CMS reasonable assurance, CMS may deem its ASCs compliant with the Conditions for Coverage (the federal ASC rules). The accreditor then surveys them, and CMS samples them for validation. | Survey type | Who conducts it | Scope | | --- | --- | --- | | Initial or recertification | State survey agency (non-deemed ASCs) | All Conditions for Coverage, including Life Safety Code | | Accreditation survey | The accrediting organization (deemed ASCs) | The accreditor's standards, which CMS found meet its conditions | | Validation | State agency, when CMS selects a deemed ASC. Finished within 60 days after the accreditor's survey | All Conditions for Coverage | | Complaint or revisit | State agency, or the CMS Location for deemed ASCs | Conditions tied to the complaint or to earlier deficiencies | Refusing surveyors access can lead to exclusion from federal health care programs. See [deemed status](https://incidentkit.ai/glossary/deemed-status) and [conditions for coverage](https://incidentkit.ai/glossary/conditions-for-coverage). ## What do surveyors look at? Surveyors use observation, interviews and document review. They pick at least one surgical case to watch, preferably on day one. They may follow the patient from pre-operative assessment to recovery or discharge. They also tour the building and complete a CMS infection control tool. Interviews use open questions, such as what a staff member would do if they smelled smoke. A written policy alone never proves compliance. Surveyors check that daily practice matches it, and sample closed records from the past six months. ## What will surveyors ask for on day one? The team asks for these at the entrance conference. CMS says an ASC should usually produce the case lists within 1 to 2 hours. - Today's scheduled surgeries (and tomorrow's for a 2-day survey): patient name, age, procedure, surgeon. - All surgeries from the past 6 months. - All cases in the past year where a patient was transferred to a hospital or died. - Names of the director of nursing, active medical staff, allied health professionals and other patient care staff. - An organizational chart and a floor plan. - Selected policies, procedures and personnel records. - Written infection control and ongoing quality self-assessment programs. - A list of contracted services, and a private room with a telephone. ## What should be ready for each condition? This is our reading of what surveyors review under each condition. It is not a CMS form. | Area | 42 CFR | Have ready | | --- | --- | --- | | Governing body and management | 416.41 | Current policy manuals, outside service contracts, organizational chart | | Surgical services | 416.42 | Pre-operative assessment and risk documentation, anesthesia assessment, informed consent in each record | | Quality assessment and performance improvement | 416.43 | Indicators, adverse event log, hospital transfers, cause analyses, projects with reasons and results, proof staff know prevention strategies | | Environment | 416.44 | Maintenance and equipment records, any Life Safety Code waivers in effect | | Medical staff | 416.45 | Privileging and credentialing files that follow your policy and state law | | Nursing service | 416.46 | Personnel files showing education, training, licensure and credentials | | Medical records | 416.47 | H&P and update, consent, operative findings and complications, signed medication orders, post-surgical assessment, transfer reason, discharge notes, signed discharge order | | Infection control | 416.51 | Program documents, surveillance, and visible hand hygiene and sterilization practice | | Emergency preparedness | 416.54 | Your emergency preparedness program (surveyed under Appendix Z) | ## How do surveyors test your QAPI program? Under 42 CFR 416.43 an ASC must track adverse patient events, examine their causes, make improvements and make them last. Surveyors ask what data you collect, who analyzes it, and how you find causes. CMS gives an example: blaming a staff member for a medication error and firing them is not a systems approach. A good analysis asks how medications were stored, whether orders were clear and whether others made similar errors. They also ask for examples where data led to a change, and proof it held. See [ASC QAPI requirements](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers). ## How do you stay ready every day? 1. **Keep the case lists current** Produce six months of surgeries and a year of transfers and deaths within an hour or two. 2. **Make every adverse event traceable** Each has a record, a cause analysis, an action and a check that the fix held. 3. **Walk the building like a surveyor** Check medication storage, expiration dates, room cleaning between cases and patient identity checks. 4. **Ask staff open questions** What do you do before surgery starts? What would you do if you saw a breach in sterile technique? 5. **Rehearse the entrance** Decide who greets the team and who pulls records if the surgeon is in a case. Surveyors wait up to about 15 minutes for leadership. 6. **Run the self-check** Use the [survey readiness check](https://incidentkit.ai/tools/survey-readiness-check) and the [survey and accreditation readiness guide](https://incidentkit.ai/guides/survey-and-accreditation-readiness). ## What happens after the survey? At the exit conference surveyors share preliminary findings, without tag numbers or ratings. The state prepares Form CMS-2567 within 10 working days. If it lists deficiencies (findings of noncompliance), send a written [plan of correction](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) within 10 calendar days of receiving it. CMS makes the 2567 public no later than 90 calendar days after the survey. Surveyors cite all noncompliance they find, even if you fix it on site. The one exception is a problem the ASC found and fixed before the survey. The fix must be effective, and nothing else may show current noncompliance. See the [CMS-2567 glossary entry](https://incidentkit.ai/glossary/cms-2567). ## How do accreditor surveys differ? Accreditors use their own standards and cycles. AAAHC describes a 1,095-day accreditation cycle and a Medicare deemed status program. Its on-site review is peer-based and educational. Joint Commission says CMS-deemed surveys are unannounced. It lists ASCs not using accreditation for deemed status among those that get 7 days' notice. A deemed ASC can still face a CMS validation survey. See [AAAHC](https://incidentkit.ai/compliance/accreditation/aaahc), [Joint Commission](https://incidentkit.ai/compliance/accreditation/joint-commission) and [AAAHC vs Joint Commission for ASCs](https://incidentkit.ai/blog/aaahc-vs-joint-commission-for-ascs). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Track adverse patient events, examine causes, sustain improvements (42 CFR 416.43) | Each incident flows into an investigation, then a corrective action with an owner, due date, evidence and effectiveness check. Nothing closes until verified. | | Produce case lists, hospital transfers and deaths on request | Filter the incident log by type and date. Compliance packets build a survey packet from it. | | Show that a pre-survey fix addressed the systemic cause and held | The audit trail and effectiveness check give dated evidence of what changed and whether it worked. | | QAPI data and improvement project documentation | Analytics cluster incidents by location, shift, equipment and cause. Compliance packets include QAPI summaries. | | Policies, personnel files, maintenance records and the rest of the survey binder | Not an IncidentKit function. IncidentKit runs alongside your EHR, HRIS and CMMS and does not replace them. | ## Frequently asked questions ### Is an ASC survey announced? No. CMS directs that all ASC surveys be unannounced. Surveyors arrive in business hours and hold an entrance conference. Joint Commission also surveys deemed ASCs without notice. Some accreditation surveys of non-deemed ASCs get notice, such as 7 days at Joint Commission, so check your accreditor. ### Can surveyors watch surgery? Yes, with the patient's permission. CMS requires surveyors to observe at least one surgical case, and the patient's consent must be added to the informed consent. The operating physician's consent is not needed. An ASC cannot require signed documents or proof of vaccination. Denying access is a deficiency. ### What if we fix a problem during the survey? Surveyors still cite it. All noted noncompliance is cited, even if fixed on site. The exception is a problem the ASC found and fixed before the survey. The ASC needs evidence the fix addressed the causes and worked, and nothing else may show current noncompliance. ### How many medical records will surveyors review? At least 20 closed records if the ASC does more than 50 cases a month. At least 10 below that. Records come from the past six months. The sample includes Medicare and other patients, and all deaths and hospital transfers. The team may review more. ### What shows surveyors that our QAPI program works? Data, examples and proof. Surveyors ask what quality and adverse event data you collect, who analyzes it, and how you find root causes, not just staff error. They ask for cases where data led to lasting improvement, and how staff learn prevention strategies. Indicators should cover at least hospital transfers and infection control. ## Sources - [CMS State Operations Manual, Appendix L, guidance for surveyors: ambulatory surgical centers (Rev. 215)](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_l_ambulatory.pdf) - [CMS, Ambulatory surgery centers: certification and compliance](https://www.cms.gov/medicare/health-safety-standards/certification-compliance/ambulatory-surgery-centers) - [42 CFR 416.43, quality assessment and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/section-416.43) - [42 CFR 416.26, qualifying for an agreement, deemed compliance (eCFR)](https://www.ecfr.gov/current/title-42/section-416.26) - [AAAHC, Accreditation](https://www.aaahc.org/accreditation/) - [Joint Commission, Unannounced survey process](https://www.jointcommission.org/en-us/knowledge-library/support-center/survey-or-review-preparation/unannounced-survey-process) ## Related - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) - [AAAHC accreditation: surveys, deemed status and QI studies](https://incidentkit.ai/compliance/accreditation/aaahc) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [Survey readiness self-check for healthcare facilities](https://incidentkit.ai/tools/survey-readiness-check) - [Survey and accreditation readiness: a continuous approach](https://incidentkit.ai/guides/survey-and-accreditation-readiness) - [Always Survey-Ready: Stay Prepared for Unannounced Surveys](https://incidentkit.ai/use-cases/always-survey-ready) - [Incident reporting software for surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers) --- # Nursing home recertification survey: what happens and what to have ready > A nursing home's standard recertification survey is unannounced and runs at least two days in a row on site. It must happen no later than 15 months after the last one. Surveyors sample residents, observe care, and ask for incident, abuse-policy and QAPI records. Since September 8, 2026, higher-performing homes may get a shorter risk-based survey. Source: https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey · Updated Oct 5, 2026 ## Key facts - **Frequency:** Within 15 months of the last standard survey; statewide average at most 12 months - **Notice:** Unannounced; at least 10 percent are off-hours (weekend, before 6 a.m., after 5 p.m.) - **On-site time:** At least 5 hours in a row after entry, and at least 2 calendar days in a row - **Team:** Multidisciplinary, with at least one registered nurse - **Offsite review:** Last survey, repeat deficiencies, closed complaints, facility-reported incidents, staffing data - **Four-hour request:** QAPI plan, QAA committee information, abuse prohibition policy, facility assessment, infection control program - **Risk-based survey:** Nationwide from September 8, 2026 for eligible homes; CMS estimates about 12 percent qualify - **After the survey:** Form CMS-2567 by the 10th working day. Plan of correction within 10 calendar days of receipt. - **Citation:** 42 CFR 488.308; 42 CFR Part 483, Subpart B; CMS State Operations Manual Chapter 7 and Appendix PP; LTCSP Procedure Guide - **Authority:** CMS and state survey agencies - **Applies to:** Medicare-certified skilled nursing facilities, Medicaid-certified nursing facilities ## How does the standard health survey work? The standard survey is a periodic, resident-centered inspection. It checks whether a home meets the federal requirements for participation in 42 CFR Part 483. It uses a sample of residents that reflects the home's case mix. Surveyors observe, interview and review records. They follow the Long-Term Care Survey Process (LTCSP) and Appendix PP of the State Operations Manual. A state must survey each home within 15 months of the last standard survey. Surveys are unannounced. The team stays on site at least two calendar days in a row, and includes a registered nurse. ## What happens during the survey? 1. **Offsite preparation** The team coordinator reviews your last survey, repeat deficiencies and closed complaints. They also review incidents you reported since then and payroll-based journal staffing data. 2. **Entrance** The team asks for the census, resident lists and other items on CMS's entrance conference worksheet. Then it screens residents. 3. **Initial pool** Surveyors observe, interview and review limited records for residents in the initial pool. 4. **Sample selection** After the first-day team meeting, the team picks closed records. It sets the resident sample and assigns investigations. 5. **Investigations and facility tasks** Surveyors investigate sampled residents. They also complete facility tasks: dining, infection control, kitchen, medication administration and storage, resident council, staffing, environment and QAPI/QAA. 6. **Decisions and exit** The team decides on potential citations and holds the exit conference with preliminary findings. The state issues Form CMS-2567 after supervisory review. ## What do you hand over, and how fast? CMS's Entrance Conference Worksheet (LTCSP, September 2026) sets the timing. These are selected items; the worksheet has more. | Due | Selected items | | --- | --- | | Immediately | Census. Matrix for residents admitted in the last 30 days. Alphabetical resident list. List of residents who smoke. | | Within 1 hour | Mealtimes and menus. Medication pass times. Number and location of medication carts and storage rooms. Actual staff schedules by department. Key personnel and contract staff contacts. Infection preventionist name and training. | | Within 4 hours | Matrix for all other residents. Admission packet. Infection prevention and control policies and surveillance plan. QAA committee information. QAPI plan. Abuse prohibition policy and procedures. Facility assessment. Nurse staffing waivers. | | By the end of day 1 | Read-only electronic health record access for each surveyor. Include a guide to where pressure ulcers, falls, hospitalization, elopement and change of condition are found. | | Within 24 hours | Completed Medicare/Medicaid application (CMS-671). List of residents discharged from a Medicare Part A stay in the last six months. | ## What incident and QAPI evidence do surveyors look for? Surveyors read your incident history before they arrive and test your systems on site. If a complaint is linked to the survey, they investigate abuse at the facility level. That includes your policies and your QAA system for monitoring reported allegations. The QAPI and QAA review comes late, so there is time to investigate concerns. | Evidence | Tag | What surveyors look for | | --- | --- | --- | | Abuse prevention policies | F607 | Written policies, including training and coordination with QAPI | | Reports of alleged violations, annual notice to covered individuals, results reports | [F609](https://incidentkit.ai/compliance/f-tags/f609) | First report within 2 or 24 hours. Results within 5 working days. Date and time sent. Proof of annual notice. | | Investigations and protection | [F610](https://incidentkit.ai/compliance/f-tags/f610) | A thorough investigation, protection while it was open, corrective action if verified | | QAPI program and plan | [F865](https://incidentkit.ai/compliance/f-tags/f865) | Systems that identify, report, investigate, analyze and prevent adverse events, and the corrective actions taken | | Adverse event monitoring and QAA activities | [F867](https://incidentkit.ai/compliance/f-tags/f867) | Data and feedback systems, including adverse event monitoring, used to find high-risk, high-volume or problem-prone areas | | QAA committee | [F868](https://incidentkit.ai/compliance/f-tags/f868) | Committee composition, meeting frequency and the action it takes | If a surveyor cites [F600](https://incidentkit.ai/compliance/f-tags/f600), the QAPI step checks whether the QAA committee had already found the issue. It also checks whether the committee made a good faith attempt to correct it. ## What is the risk-based survey? CMS began a nationwide risk-based survey (RBS) on September 8, 2026 for eligible homes. The source is memo QSO-26-14-NH (revised September 29, 2026). The RBS is a modified standard recertification survey. It reviews all required areas in a more focused way. It takes roughly half the time and uses fewer surveyors. CMS estimates about 12 percent of homes will qualify. It plans an icon on Nursing Home Care Compare for them starting October 8, 2026. A home does not qualify if it has any of these, among other listed criteria: - an overall rating below 5 stars or a staffing rating below 3 stars; - a citation for actual harm, immediate jeopardy or substandard quality of care in the last survey cycle; - more than 18 months without a standard survey, or a change in ownership since the last one; - a nurse staffing waiver, or a failed payroll-based journal or MDS audit. States can still use the full process in a qualified home, and CMS may require it. Ask your state agency which process applies to you. ## What happens after the exit conference? Citations are not final at the exit conference. After supervisory review, the state sends Form CMS-2567 by the 10th working day after the last day of the survey. An acceptable plan of correction is due within 10 calendar days of your receipt of the 2567. A request for informal dispute resolution is due in the same 10 days. See [plan of correction](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction). ## How do you stay ready between surveys? This list is our practical advice, drawn from what CMS asks for: - Practice the four-hour document pull. Gather the QAPI plan, QAA roster, abuse prohibition policy, facility assessment and infection control program. - Match your incident log to what you reported to the state. - Keep QAA minutes that show an issue, an action and a follow-up measure. - Keep proof of the annual notice to covered individuals. - Run the [survey readiness check](https://incidentkit.ai/tools/survey-readiness-check) and review [abuse and neglect reporting](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Four-hour document request: QAPI plan, QAA information, abuse prohibition policy | Compliance packets assemble QAPI summaries and survey packets. Your policies stay in your own document system. | | Facility-reported incidents match your own records | The incident record keeps timestamps, your logged reporting steps and the investigation. The audit trail records every change. | | Abuse allegations reported, investigated and corrected (F609, F610) | Investigations and corrective actions give the evidence F610 asks for. Staff report by text, QR code, email or web form, and routing alerts the administrator. | | QAA monitors reporting and investigations, and shows a good faith attempt to fix issues (F600, F867) | Analytics cluster incidents by location, shift and cause. Corrective actions with effectiveness checks give the committee follow-up items. | | Electronic health record access, resident matrix and staffing schedules | Not an IncidentKit function. IncidentKit runs alongside your EHR and HRIS and does not replace them. | ## Frequently asked questions ### How often are nursing homes surveyed? No later than 15 months after the last standard survey. The statewide average interval must not exceed 12 months. Homes with excellent compliance histories may be surveyed less often, but never less often than every 15 months. Complaint surveys can happen at any time. ### Can a survey start at night or on a weekend? Yes. At least 10 percent of standard surveys must be off-hour surveys. They start on a weekend, or before 6 a.m. or after 5 p.m. on a weekday. At least half of those must start on a weekend day. ### Do surveyors review facility-reported incidents? Yes. The team coordinator reviews closed complaints and facility-reported incidents since the last survey. They look for repeated issues. A linked complaint also triggers a review of your abuse policies and QAA monitoring of reported allegations. ### How long will the survey team be in the building? At least five hours in a row after entry. At least two calendar days in a row on site, weekends and holidays included. Total time varies with the home's size, layout and concerns to investigate. ### What is the risk-based survey, and will my home get one? A shorter, more focused standard survey for higher-performing homes, begun nationwide on September 8, 2026. CMS gives each state a quarterly list of qualified homes. A home stays eligible for six months after the state gets the list. A disqualifying event ends that. A state may still use the full process. ## Sources - [CMS State Operations Manual, Chapter 7: survey and enforcement process for skilled nursing facilities and nursing facilities (Rev. 244)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107c07pdf.pdf) - [CMS State Operations Manual, Appendix PP, guidance to surveyors for long-term care facilities](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [CMS LTCSP Procedure Guide and Entrance Conference Worksheet, September 2026 (Survey Resources package)](https://www.cms.gov/files/zip/survey-resources-updated-09-08-2026.zip) - [CMS memo QSO-26-14-NH (revised September 29, 2026): Nursing home risk-based survey national implementation](https://www.cms.gov/files/document/qso-26-14-nh-revised-2026-09-29.pdf) - [CMS, Nursing homes: regulations and guidance](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/nursing-homes) ## Related - [Nursing home abuse reporting: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [F865 QAPI program and plan: what surveyors ask for](https://incidentkit.ai/compliance/f-tags/f865) - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) - [Always Survey-Ready: Stay Prepared for Unannounced Surveys](https://incidentkit.ai/use-cases/always-survey-ready) - [Survey readiness self-check for healthcare facilities](https://incidentkit.ai/tools/survey-readiness-check) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) --- # Plan of correction: what CMS requires and how to write one that is accepted > A plan of correction is the facility's written answer to the deficiencies on Form CMS-2567. It is due within 10 calendar days of receiving the form. A nursing home plan must cover residents affected, residents at risk, systemic change, monitoring and completion dates. It is the facility's allegation of compliance. Source: https://incidentkit.ai/compliance/survey-readiness/plan-of-correction · Updated Oct 5, 2026 ## Key facts - **Form:** CMS-2567, Statement of Deficiencies and Plan of Correction - **Due:** 10 calendar days from receipt of the CMS-2567 (nursing homes and ASCs) - **Nursing home elements:** Residents affected, residents at risk, systemic change, monitoring, completion dates - **ASC elements:** Seven items, including monitoring, completion dates and the responsible person's title - **Signature:** Nursing home: facility official, usually the administrator. ASC: administrator, page 1 - **Not required:** Nursing home deficiencies at scope and severity level A, and past noncompliance - **If no acceptable plan:** State recommends remedies; termination required if a nursing home never submits one - **Citation:** 42 CFR 488.402(d); CMS State Operations Manual Chapter 7, section 7317 (nursing homes) and Appendix L (ASCs) - **Authority:** CMS and state survey agencies - **Applies to:** Medicare- and Medicaid-certified nursing homes, Medicare-certified ambulatory surgical centers ## What is a plan of correction? Form CMS-2567 records a survey's findings, and the facility uses it to answer them. The plan of correction (POC) says how and when the facility will correct each deficiency (a rule it did not meet). CMS calls it the facility's allegation of compliance. Without one, CMS and the state cannot verify compliance. Nursing homes follow 42 CFR 488.402(d), applied through Chapter 7 of the State Operations Manual. ASCs follow Appendix L. See the [plan of correction glossary entry](https://incidentkit.ai/glossary/plan-of-correction) and [what to put in a plan of correction](https://incidentkit.ai/blog/what-to-put-in-a-plan-of-correction). ## What are the deadlines? | Step | Nursing homes | Ambulatory surgery centers | | --- | --- | --- | | State sends Form CMS-2567 | By the 10th working day after the last day of the survey | Prepared and mailed within 10 working days | | Plan of correction due | 10 calendar days after the facility receives the 2567 | 10 calendar days after receiving the written statement of deficiencies | | Disputing findings | Written request for informal dispute resolution within the same 10 calendar days | Record objections on the 2567 and choose one of three options below | | If no acceptable plan arrives | State recommends remedies. CMS rules require termination if a nursing home never submits an acceptable plan | Failure to submit an acceptable plan may result in termination of the supplier agreement | For ASCs, CMS says the 2567 is made public no later than 90 calendar days after the survey. ## What are the five elements for a nursing home? An acceptable nursing home plan must do all five of these: 1. Say how corrective action will be done for residents affected by the deficient practice. 2. Say how the facility will find other residents who could be affected by the same deficient practice. 3. Say what measures or systemic changes will keep the deficient practice from happening again. 4. Say how the facility will monitor its performance to make sure solutions last. 5. Give dates when corrective action will be completed. The state must accept them. No plan is needed for deficiencies at scope and severity level A, or for past noncompliance corrected when cited. ## What must an ASC plan of correction contain? - The action that will correct each specific deficiency. - How the actions will improve the processes that led to the deficiency. - The procedure for putting the actions in place. - A completion date for each deficiency. - Monitoring and tracking to confirm the plan works and compliance continues. - The title of the person responsible for carrying out the plan. - The administrator's signature and date on page 1 of Form CMS-2567. An ASC has three options. One: accept the deficiencies and submit a plan. Two: record objections and still submit a plan. Three: record objections, skip the plan and submit written arguments and documented evidence that the deficiencies are invalid. CMS considers objections to the factual accuracy of findings, not to its judgment on level, extent, scope or severity. If CMS disagrees with the objections, an acceptable plan is still required. ## How do you write a plan that gets accepted? The first two steps follow CMS's published expectations. The rest is our practical advice. 1. **Answer each deficiency on its own** Match each part of the plan to the tag or requirement cited. An unacceptable plan is returned for revision. 2. **Fix the system, not only the people involved** CMS tells surveyors to ask if corrective action fixes underlying, systemic causes and was evaluated for effectiveness. 3. **Reach beyond the example** Nursing homes must say how they will find other residents at risk. ASCs should do the same for other cases and rooms. 4. **Write monitoring that can be audited** Name what you will measure, how often, who collects it and where results go, such as the QAA committee. 5. **Set dates you can meet** The state must accept the dates. Keep dated evidence for each fix. 6. **Name an owner by title and sign** Use a title, not only a name. The administrator or another authorized official signs. *Illustrative wording only. The numbers are examples, not CMS thresholds.* | Element | Weak wording | Stronger wording | | --- | --- | --- | | Monitoring | The director of nursing will monitor. | The director of nursing audits 10 records a week for 8 weeks, then monthly for 3 months. Results go to the QAA committee, which acts if the target is missed. | | Other residents | No other residents were affected. | Records of all residents with the same risk were reviewed within 7 days, and each was reassessed. | | Completion date | Ongoing. | Completed by the stated date. Evidence: revised policy, sign-in sheets, first audit results. | ## What happens after you submit? The state reviews the plan and tells the facility in writing if it is unacceptable. If it is acceptable, notice may come by phone or email. The facility is still accountable for its own compliance, even if notice is late. A revisit may be on site or a paper review. The date of substantial compliance depends first on credible written evidence for the date you allege. It can be earlier than your plan date if you can prove it. Show when actions happened, how they fixed the noncompliance and how they prevent it from recurring. Surveyors look for proof the plan was carried out. They do not assume that means compliance. See [always survey-ready](https://incidentkit.ai/use-cases/always-survey-ready) and [close corrective actions](https://incidentkit.ai/use-cases/close-corrective-actions). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Identify residents affected and others at risk | Records show who was affected. Analytics group similar events by location, shift and cause to find others at risk. | | Systemic change that prevents recurrence | Corrective actions come from the investigation and carry an owner, due date and evidence. | | Monitoring that shows the fix held | Each corrective action has an effectiveness check. Nothing closes until it is verified. | | Dated evidence for a revisit | The audit trail logs who changed what and when. Compliance packets gather the evidence. | | Writing, signing and submitting the plan | You write, sign and send the response to your state agency. IncidentKit supplies the records behind it and does not file it. | ## Frequently asked questions ### How long do we have to submit a plan of correction? Ten calendar days from the day the facility receives Form CMS-2567, for nursing homes and ASCs. Count calendar days, not working days. A nursing home's written request for informal dispute resolution is due in the same 10 days. ### Do we need a plan for every deficiency? For nursing homes, yes, except deficiencies at scope and severity level A, or past noncompliance already corrected when cited. For ASCs, a written plan is required, and it must address each cited deficiency. ### Who signs the plan of correction? Nursing home: a facility official with management authority and responsibility, normally the administrator. The director of nursing or a corporate representative may sign instead. ASC: the administrator signs and dates page 1. Some states use electronic signatures. ### What if the state says our plan is not acceptable? The state tells you in writing, and the plan goes back for revision. If no acceptable plan arrives in 10 days, the state recommends remedies, which can take effect once notice requirements are met. CMS rules require termination of a nursing home that never submits one. ### Is the plan of correction public? For ASCs, yes. CMS makes Form CMS-2567 with the plan public no later than 90 calendar days after the survey. Resident and patient names are not used. Surveyors use identifiers instead. ## Sources - [CMS State Operations Manual, Chapter 7, sections 7316 and 7317: key dates and acceptable plan of correction (Rev. 244)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107c07pdf.pdf) - [CMS State Operations Manual, Appendix L: ASC exit conference, acceptable plan of correction and options](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_l_ambulatory.pdf) - [CMS State Operations Manual, Appendix PP: plan of correction elements restated from Chapter 7, section 7317](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [CMS, Nursing homes: regulations and guidance](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/nursing-homes) ## Related - [Nursing home recertification survey: process and prep](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) - [What to put in a plan of correction (CMS-2567)](https://incidentkit.ai/blog/what-to-put-in-a-plan-of-correction) - [CMS-2567: definition and meaning](https://incidentkit.ai/glossary/cms-2567) - [Plan of correction: definition and meaning](https://incidentkit.ai/glossary/plan-of-correction) - [Corrective Action Plan Template (CAPA, Printable)](https://incidentkit.ai/templates/corrective-action-plan) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) --- # Joint Commission survey readiness: unannounced surveys and tracers > Joint Commission surveys without notice, on a three-year cycle. That covers hospitals, critical access hospitals and CMS-deemed organizations. Surveyors use tracers, which follow real patients through the care process. Hospital standards were rewritten in 2026 (Accreditation 360), so show daily practice, not a binder. Source: https://incidentkit.ai/compliance/survey-readiness/joint-commission-survey-readiness · Updated Oct 5, 2026 ## Key facts - **Notice:** Unannounced unless not feasible (always for hospitals, critical access hospitals, CMS-deemed) - **Notice for some ASCs:** 7 days if not using accreditation for deemed status - **Cycle:** Triennial; Accreditation 360 did not change it - **Tracer types:** Individual, system and program-specific - **Accreditation 360:** Hospitals and critical access hospitals first, in 2026; other dates to be determined - **National Performance Goals:** 14 goals replace the Patient Safety Goals (hospitals, critical access hospitals) - **Sentinel events at survey:** Surveyors do not search for them or judge the analysis - **Citation:** Joint Commission accreditation standards, National Performance Goals and Survey Process Guide - **Authority:** The Joint Commission - **Applies to:** Joint Commission-accredited hospitals and critical access hospitals, Other accredited programs, including ambulatory surgery centers (check the manual for your program) ## How does a Joint Commission survey work? Accreditation runs on a three-year cycle. Surveyors check compliance through observation, interviews and tracers. They use the Survey Process Guide (SPG), which accredited organizations can also get. Under Accreditation 360 the SPG replaced the older Survey Activity Guide. It also aligns with the Medicare State Operations Manual. ## Are Joint Commission surveys announced? Joint Commission surveys without notice unless that is not feasible or logical. Hospital, critical access hospital and CMS-deemed surveys are unannounced. *From Joint Commission's unannounced survey process page. Confirm your program's policy with your account executive.* | Program or situation | Notice | | --- | --- | | Hospitals and critical access hospitals | Unannounced | | Any survey used for CMS deemed status | Unannounced | | Ambulatory surgery centers not using accreditation for deemed status | 7 days | | Office-based surgery practices, telehealth services and sleep centers | 7 days | | Laboratories | 14 calendar days | | Behavioral health and human services (nearly all settings) | 7 days | | First survey by Joint Commission | Announced, except for hospitals, critical access hospitals, laboratories and surveys required for deemed status | ## What is the tracer methodology? Tracers use your own information. They follow the care, treatment or services of several patients through the whole care process. That helps surveyors find problems in one step or in the handoffs between steps. - **Individual tracers** follow one patient's care. Patients are likely chosen from high-risk areas, or for a diagnosis, age or services that allow an in-depth look. - **System tracers** check how a process works across departments, including how disciplines coordinate. Topics include data management, medical staff and human resources. - **Program-specific tracers** look for risk points in your services and in high-risk, high-volume patient populations. ## What changed with Accreditation 360? Accreditation 360 reached hospitals and critical access hospitals in 2026. Joint Commission says the cycle is still triennial. It also says there are no new documentation expectations and the survey process has not changed. - The manual separates CMS Conditions of Participation from Joint Commission requirements that go beyond regulation. - Fourteen National Performance Goals replace the National Patient Safety Goals. Workplace violence requirements for these hospitals sit in NPG 2, Culture of Safety. - Joint Commission removed 714 hospital requirements, on top of the 400 announced in 2023. - Surveyors score areas for improvement with the SAFER matrix and note strengths through the new SAFEST program. - Continuous Engagement is optional for these hospitals, with touchpoints between surveys. Other programs, including ambulatory care, get Accreditation 360 later, with dates still to be set. If you are accredited under another program, ask your account executive which manual applies. ## How do surveyors look at events and improvement? Surveyors assess your performance improvement practices. They look at how you respond to safety events, adverse events, hazardous unsafe conditions, close calls and sentinel events. They review your sentinel event response process. They also interview leaders and staff. Surveyors are told not to search for sentinel events or ask about ones reported to Joint Commission. They do not judge a root cause analysis. They may note a Recommendation for Improvement if a sentinel event analysis and action plan were not completed within 45 days. See [sentinel events](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events). ## How do you stay survey-ready all year? These steps are our practical advice, based on what surveyors assess. 1. **Read the Survey Process Guide for your program** The surveyors' own guide. Accredited organizations can get it. 2. **Run mock tracers** Follow a recent patient's care end to end, with staff from different departments. 3. **Trace the incident loop** Take an incident from three months ago. Show who reviewed it, what changed and that the change held. 4. **Prepare leaders and staff** They are interviewed on identifying, reporting and responding to events. Practice describing the system, not one case. 5. **Close corrective actions with evidence** Track every action to verified closure. Keep the proof. 6. **Consider the optional touchpoints** Hospitals and critical access hospitals can choose Continuous Engagement between surveys. *Our checklist, from the Sentinel Event Policy and survey process pages. Not a Joint Commission document.* | Area | Be able to show | | --- | --- | | Safety event process | A recent event from report to review to action, with an owner and a date | | Sentinel event policy | Your policy, plus any analysis and action plan finished inside 45 business days | | Performance improvement | Data on a measure you chose, the analysis and what changed | | Leadership | Leaders can explain how events are identified, reported and handled | | Surveyor support | Who accompanies surveyors and who can pull records quickly | See the [survey and accreditation readiness guide](https://incidentkit.ai/guides/survey-and-accreditation-readiness) and the [survey readiness check](https://incidentkit.ai/tools/survey-readiness-check). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Show a safety event moving from report to review to action | Incidents flow into investigations, then corrective actions. Each has an owner, due date, evidence and effectiveness check. The audit trail logs every change. | | Sentinel event response and analysis within 45 business days | Investigations hold contributing factors and five whys. Corrective actions track the plan. | | Leaders and staff can describe how events are reported | Staff report by text, QR code, email or web form. Lauren asks the follow-up questions. A person reviews, edits and signs. | | Safety data for performance improvement | Analytics cluster incidents by location, shift, equipment and cause. | | Survey documents on request | Compliance packets assemble survey packets. IncidentKit does not submit to Joint Commission Connect or make Joint Commission-specific forms. | ## Frequently asked questions ### Does Joint Commission announce surveys? Usually not. Surveys are unannounced unless that is not feasible or logical. Some get notice. ASCs not using accreditation for deemed status get 7 days. Laboratories get 14 calendar days. ### Does Accreditation 360 apply to surgery centers? Not yet, as far as the FAQ we reviewed says. Hospitals and critical access hospitals come first, in 2026. Dates for other programs are to be determined, so check with your account executive. ### What is a tracer? A tracer follows actual patients, or a cross-department system, through the organization. Individual tracers follow a patient. System tracers evaluate a process such as data management. Program-specific tracers focus on your high-risk services and populations. ### Do surveyors ask about our sentinel events? Not directly. Surveyors are told not to search for sentinel events. They do not ask about ones reported to Joint Commission, and they do not judge your root cause analysis. They may note a Recommendation for Improvement if it was not finished within 45 days. ### Did the National Patient Safety Goals go away? For hospitals and critical access hospitals, yes, they were replaced. 14 National Performance Goals took over in 2026. The former goals were folded in. Other programs may still use existing goals, so check your manual. ## Sources - [Joint Commission, What is the tracer methodology?](https://www.jointcommission.org/en-us/knowledge-library/support-center/survey-or-review-preparation/tracer-methodology) - [Joint Commission, Unannounced survey process](https://www.jointcommission.org/en-us/knowledge-library/support-center/survey-or-review-preparation/unannounced-survey-process) - [Joint Commission, Accreditation 360: The New Standard](https://www.jointcommission.org/en-us/accreditation/accreditation-360) - [Joint Commission, Accreditation 360 FAQs](https://www.jointcommission.org/en-us/accreditation/accreditation-360/faqs) - [Joint Commission, Sentinel Event Policy (SE), CAMH Update 1, July 2026](https://digitalassets.jointcommission.org/api/public/content/4035922bcc2f41bd83fbc1f55764a7b4?v=bf31f43b) ## Related - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) - [Joint Commission: definition and meaning](https://incidentkit.ai/glossary/joint-commission) - [Survey and accreditation readiness: a continuous approach](https://incidentkit.ai/guides/survey-and-accreditation-readiness) - [AAAHC vs Joint Commission for ASCs: how they compare](https://incidentkit.ai/blog/aaahc-vs-joint-commission-for-ascs) - [Survey readiness self-check for healthcare facilities](https://incidentkit.ai/tools/survey-readiness-check) - [Always Survey-Ready: Stay Prepared for Unannounced Surveys](https://incidentkit.ai/use-cases/always-survey-ready) - [Patient safety event reporting software for hospitals](https://incidentkit.ai/solutions/hospitals) --- # OSHA recordkeeping: who keeps records, and what counts > If you had more than 10 employees at any time last year, 29 CFR Part 1904 requires OSHA Forms 300, 300A and 301. A case is recordable if it is work-related, new, and meets a criterion such as days away, restricted work or treatment beyond first aid. Every employer must still report fatalities and severe injuries. Source: https://incidentkit.ai/compliance/osha/recordkeeping-overview · Updated Oct 5, 2026 ## Key facts - **Rule:** 29 CFR Part 1904, Recording and Reporting Occupational Injuries and Illnesses - **Size test:** More than 10 employees at any time last year, company-wide - **Industry test:** By establishment NAICS code, against the partially exempt list - **Forms:** OSHA 300 Log, 300A summary, 301 report (or equivalents) - **Entry clock:** 7 calendar days from learning of a case - **Retention:** 5 years after the year covered - **Always required:** Fatality and severe injury reporting (1904.39), even if exempt - **Verified:** eCFR through 2026-10-01; OSHA pages read October 2026 - **Citation:** 29 CFR Part 1904 - **Authority:** OSHA - **Applies to:** Private-sector employers under federal OSHA jurisdiction with more than 10 employees, Employers in State Plan states, which must adopt substantially identical recording rules, Establishments outside the partially exempt industry list, such as hospitals, nursing homes, home health, plants, warehouses and construction ## Who must keep OSHA injury and illness records? Any employer covered by the OSH Act that had more than 10 employees at any time last year must keep records, unless the establishment is in a partially exempt industry. Size counts the whole company. Industry is judged one establishment at a time. *The tests in 29 CFR 1904.1, 1904.2, 1904.39 and 1904.42* | Test | How it works | Section | | --- | --- | --- | | Company size | Peak employment for the whole company last year. If it never passed 10, no routine records. | 1904.1 | | Industry | Each establishment gets a NAICS code (the standard industry code). One company can have both kinds. | 1904.2 | | Written request | OSHA, BLS or a state agency can ask an exempt employer in writing to keep records or answer a survey. | 1904.1, 1904.2, 1904.42 | | Severe injury reporting | Applies to every employer, including exempt ones. | 1904.39 | Self-employed people are not covered, nor are owners or partners of a sole proprietorship or partnership. Part-time, seasonal and migrant workers on your payroll are covered. So are temporary workers you supervise day to day (1904.31). ## Which settings are partially exempt? Offices of physicians and dentists, outpatient care centers and medical laboratories are on the exempt list. Hospitals, nursing homes, home health and most industrial sites are not. *Examples from Appendix A to Subpart B* | Setting | NAICS group | Keeps OSHA 300 records? | | --- | --- | --- | | Offices of physicians, dentists and other health practitioners | 6211, 6212, 6213 | Partially exempt | | Outpatient care centers, including freestanding ambulatory surgical centers (621493) and dialysis centers | 6214 | Partially exempt | | Medical and diagnostic laboratories | 6215 | Partially exempt | | General medical and surgical hospitals | 6221 | Yes | | Nursing care facilities and assisted living | 6231, 6233 | Yes | | Home health care services | 6216 | Yes | | Manufacturing, warehousing, utilities, construction | 31-33, 493, 22, 23 | Yes | The exemption covers the 300, 300A and 301 forms and routine electronic submission, not the 8-hour and 24-hour reports. A listed 2007 NAICS code stays exempt even if newer editions dropped it (FAQ 2-4). State Plan states can require records from exempt employers (FAQ 37-2), so check your state. ## What makes a case recordable? A case must be work-related, be new, and meet a recording criterion (1904.4). - **Work-related:** an event or exposure at work caused or added to the condition, or made an existing one significantly worse. This is presumed unless an exception applies. Examples are a member of the public who is hurt, a voluntary wellness activity, eating personal food, and the common cold or flu (1904.5). - **New:** no earlier recorded case of the same type in the same body part. Or the employee had fully recovered before a workplace event brought it back (1904.6). - **A criterion:** death, days away from work, restricted work or job transfer, medical treatment beyond first aid, loss of consciousness. A significant diagnosis also counts (cancer, chronic irreversible disease, a fractured or cracked bone, a punctured eardrum). Needlesticks and sharps, medical removal, hearing loss and tuberculosis have their own rules (1904.7 to 1904.11). Recording a case does not mean anyone was at fault, that a standard was violated or that workers' compensation applies (1904.0). See [recordable vs first aid](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid). ## Which forms do you complete, and by when? Each item has its own clock. *Forms, clocks and access rights* | Item | What it is | Clock | | --- | --- | --- | | [OSHA 300 Log](https://incidentkit.ai/compliance/osha/osha-300-log) | One line per recordable case, per establishment | Enter within 7 calendar days of learning of the case | | [OSHA 301 report](https://incidentkit.ai/compliance/osha/osha-301-incident-report) | Incident report for each logged case, or an equivalent form | Complete within 7 calendar days | | [OSHA 300A summary](https://incidentkit.ai/compliance/osha/osha-300a-summary) | Year-end totals, certified by a company executive | Post February 1 to April 30 | | Retention | 300 Log, privacy case list, 300A and 301 forms | Five years after the year covered | | Employee and representative access | Copies of the 300 Log and the employee's own 301 | By the end of the next business day | | Government request | Copies of your Part 1904 records | Within 4 business hours | ## How do recording, reporting and submission differ? Recording is the log, summary and incident report. Reporting is the call to OSHA. The clock is 8 hours for a work-related death and 24 hours for an in-patient hospitalization, amputation or loss of an eye ([severe injury reporting](https://incidentkit.ai/compliance/osha/severe-injury-reporting)). Electronic submission is an annual upload due March 2 that only some establishments owe ([electronic submission](https://incidentkit.ai/compliance/osha/electronic-submission)). You must also tell employees how to report, that they may report, and that retaliation is prohibited ([employee reporting and retaliation](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation)). See the [OSHA recordkeeping guide](https://incidentkit.ai/guides/osha-recordkeeping-guide). ## What changed recently, and what did we check? The eCFR showed Title 29 current through October 1, 2026, and we read OSHA's own pages in October 2026. The criteria in 1904.4 to 1904.11 show no substantive amendment since 2019 in the eCFR history. - **July 21, 2023:** the final rule Improve Tracking of Workplace Injuries and Illnesses (88 FR 47254) took effect January 1, 2024. It changed electronic submission, not recording. - **January 13, 2025:** OSHA's directive CPL 02-00-172 took effect. It replaced the 2004 recordkeeping manual. - **July 1, 2025:** OSHA withdrew a proposal to add a musculoskeletal disorder column to the 300 Log (90 FR 28257). The Log keeps its columns. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Record each new, work-related case that meets a criterion (1904.4) | Lauren asks follow-ups and drafts fields, marked 'Lauren · draft'. A person reviews, edits and signs. Recordability stays a human call. | | Enter cases on the 300 Log and 301 within 7 calendar days (1904.29) | Incidents are time-stamped when reported and routed to a named owner, so the clock has a clear start. OSHA 300 and 301 exports are rolling out; for now, use the per-incident PDF and CSV export. | | Keep a separate Log for each establishment (1904.30) | Each establishment is a facility with its own staff, routing and pack. | | Update entries and keep records five years (1904.33) | The audit trail logs who changed what and when, with before and after values. That fits the duty to update the Log. | | Summarize the year on the 300A (1904.32) | OSHA 300A generation from the same record is rolling out. Until then, use CSV export and your own summary. A company executive still certifies. | | Report fatalities and severe injuries (1904.39) | Incident types that start a reporting clock flag the deadline. Automated reportability rules are rolling out. | ## Frequently asked questions ### Do I need OSHA records if I have 10 or fewer employees? Not routinely. If you never had more than 10 employees last year, you need no OSHA 300, 300A or 301 unless OSHA or BLS asks in writing. Always report a work-related fatality, in-patient hospitalization, amputation or loss of an eye under 29 CFR 1904.39. ### Does a surgery center have to keep an OSHA 300 Log? Often not. Outpatient care centers (NAICS 6214) are partially exempt, and freestanding ambulatory surgical centers are NAICS 621493. Confirm your six-digit code. A State Plan can still require records. You must report fatalities and severe injuries either way. ### Does recording a case mean we were at fault? No. Recording a case does not mean anyone was at fault, that an OSHA rule was violated or that workers' compensation applies. Recordability only tests work-relatedness, newness and outcome. ### Are part-time and temporary workers included? Yes. Record cases for everyone on your payroll, including part-time and seasonal workers, and for temporary or contract workers you supervise day to day. Electronic submission counts each person employed at the establishment at any time that year. ## Sources - [eCFR: 29 CFR Part 1904, Recording and Reporting Occupational Injuries and Illnesses (current through 2026-10-01)](https://www.ecfr.gov/current/title-29/part-1904) - [OSHA: Recordkeeping requirements](https://www.osha.gov/recordkeeping) - [OSHA: Partially exempt industries, Appendix A to Subpart B of Part 1904](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904SubpartBAppA) - [OSHA: Part 1904 recordkeeping frequently asked questions](https://www.osha.gov/laws-regs/interlinking/standards/1904/faq) - [OSHA: Part 1904 Recordkeeping Policies and Procedures Directive, CPL 02-00-172 (effective 2025-01-13)](https://www.osha.gov/sites/default/files/enforcement/directives/CPL-02-00-172.pdf) - [Federal Register: Improve Tracking of Workplace Injuries and Illnesses, 88 FR 47254 (2023-07-21)](https://www.federalregister.gov/documents/2023/07/21/2023-15091/improve-tracking-of-workplace-injuries-and-illnesses) - [Federal Register: Occupational Injury and Illness Recording and Reporting Requirements; Withdrawal, 90 FR 28257 (2025-07-01)](https://www.federalregister.gov/documents/2025/07/01/2025-11624/occupational-injury-and-illness-recording-and-reporting-requirements-withdrawal) - [U.S. Census Bureau: 2022 NAICS six-digit code list](https://www.census.gov/naics/2022NAICS/6-digit_2022_Codes.xlsx) ## Related - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [Recordable vs first aid: OSHA's medical treatment test](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [OSHA electronic submission: 29 CFR 1904.41 and the ITA](https://incidentkit.ai/compliance/osha/electronic-submission) - [OSHA recordkeeping guide: Part 1904 for employers](https://incidentkit.ai/guides/osha-recordkeeping-guide) - [OSHA 300 Log Automation: Keep It Accurate Year-Round](https://incidentkit.ai/use-cases/osha-300-log-automation) - [OSHA recordable injury: definition and meaning](https://incidentkit.ai/glossary/osha-recordable) --- # OSHA Form 300: the Log of Work-Related Injuries and Illnesses > The OSHA 300 Log lists each recordable work-related injury and illness at one establishment. Enter each case on its own line within 7 calendar days, marked by its most serious outcome. Show 'privacy case' instead of a name for a short list of sensitive cases. Keep each Log five years after the year it covers. Source: https://incidentkit.ai/compliance/osha/osha-300-log · Updated Oct 5, 2026 ## Key facts - **Form:** OSHA Form 300, Log of Work-Related Injuries and Illnesses (Rev. 04/2004) - **Rule:** 29 CFR 1904.29 (forms) and 1904.30 (multiple establishments) - **Entry clock:** Within 7 calendar days of learning of the case - **One box only:** Columns G to J: death, days away, job transfer or restriction, other - **Day count:** Starts the day after the injury; capped at 180 days - **Retention:** 5 years after the year covered, with updates - **Employee copy:** By the end of the next business day, names left on - **Citation:** 29 CFR 1904.29 and 1904.30 - **Authority:** OSHA - **Applies to:** Employers required to keep OSHA injury and illness records, EHS managers, HR and safety coordinators who maintain the Log for each establishment, Contractors and general contractors with short-term job sites ## What is the OSHA 300 Log? The Log records every recordable injury and illness at one establishment. Keep a separate Log for each establishment expected to operate for a year or longer (1904.30). The year at the top is the calendar year the cases belong to. *Which Log a case goes on (29 CFR 1904.30 and 1904.46)* | Situation | Which Log | | --- | --- | | Establishment expected to operate a year or longer | Its own Log | | Short-term establishment, under a year | One Log may cover all short-term sites, or one per division or region | | Employee at several locations or none | Linked to one establishment, recorded there | | Injury at another of your establishments | That establishment's Log | | Injury away from any establishment | Log where the employee normally works | | Telecommuter | The linked establishment; a home is not an establishment | You may store Logs at headquarters if the information reaches it within 7 calendar days. You must also be able to send copies to the establishment in the time the rules require. ## What goes in each column? Identify the person, describe the case, classify it, count the days, and mark the type of injury or illness. *OSHA Form 300 columns (Rev. 04/2004)* | Column | What to enter | | --- | --- | | A | Case number | | B | Employee name, or 'privacy case' (see below) | | C | Job title | | D | Date of injury or start of illness | | E | Where the event occurred | | F | Injury or illness, body part, and the object or substance that directly harmed the person | | G, H, I, J | Check one box, the most serious outcome: death, days away, job transfer or restriction, or other recordable case | | K, L | Days away from work, and days of job transfer or restriction | | M | Injury, or one illness type: skin disorder, respiratory condition, poisoning, hearing loss, all other illnesses | ## How do you classify a case with two outcomes? Pick one box in columns G to J: the most serious outcome. Death is most serious and 'other recordable' is least. If the outcome gets worse, change the entry. Illustrative example: sutures close a hand laceration (medical treatment), then the employee spends 3 days on restricted duty. Record it once, as job transfer or restriction, with 3 restricted days. - **Counting days:** start the day after the injury. Count calendar days, including weekends, holidays and vacation days the employee could not have worked. - **Still away at year end:** estimate, then update when the actual number is known. - **The 180-day cap:** you may enter 180 when days away or restricted exceed 180. - **Leaving the company:** you may stop counting if the employee leaves for an unrelated reason. OSHA treats firing after a post-accident drug test as related, so keep estimating (FAQ 7-9). - **One year only:** record a case once, on the Log for the year it happened, even if days continue into the next year. ## Which cases show 'privacy case' instead of a name? Only the cases on OSHA's complete list. You may not add others. Keep a confidential list of case numbers and names, to update cases and to give the government on request (1904.29). - An injury or illness to an intimate body part or the reproductive system. - An injury or illness resulting from a sexual assault. - Mental illness. - HIV infection, hepatitis or tuberculosis. - Needlestick injuries and cuts from sharp objects contaminated with another person's blood or other potentially infectious material. - Any other illness, if the employee voluntarily asks that the name be left off. If the person could still be identified, use discretion, such as 'injury from assault' or 'lower abdominal injury'. Still show the cause and general severity. ## When must entries be made, updated and shared? Seven calendar days to enter, five years to keep, and short clocks for access. *Log timing and access (29 CFR 1904.29, 1904.33, 1904.35, 1904.40)* | Duty | Clock | | --- | --- | | Enter a new recordable case | Within 7 calendar days of learning of it | | Update an old case | Within the five-year retention period: line out the old entry, enter the new information | | Copy for an employee, former employee or representative | By the end of the next business day, free the first time, names left on | | Copies for OSHA, NIOSH or a State Plan agency | Within 4 business hours | | Keep the Log | 5 years after the end of the year it covers | ## What does a usable entry look like? Keep it short and specific. The row below is invented for illustration. *Illustrative Log line* | Field | Illustrative entry | | --- | --- | | A, C | Case 14, packaging line worker | | D, E | 3/12, packaging area, line 2 | | F | Laceration, left forearm, from a box cutter; closed with sutures | | G to J | Job transfer or restriction (after the sutures, restricted to non-cutting tasks) | | K, L | 0 days away, 3 days restricted | | M | Injury | At year end the Log feeds the [300A summary](https://incidentkit.ai/compliance/osha/osha-300a-summary). Each line needs a matching [301 incident report](https://incidentkit.ai/compliance/osha/osha-301-incident-report) or equivalent. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | One line per recordable case, entered within 7 calendar days | The incident record holds the same facts. OSHA 300 export is rolling out; for now, use CSV export and the per-incident PDF. | | Classify by the most serious outcome | Lauren drafts outcome fields, marked 'Lauren · draft'. The reviewer decides the classification and signs. | | Update cases as outcomes change | The audit trail keeps field-level history, so a changed day count or reclassification is traceable. | | Keep privacy cases confidential | Access is set by role and facility, so names can be limited. Deciding a case is a privacy case stays a person's call. | | A separate Log for each establishment | Each site is a facility with its own staff, routing and pack. Group short-term sites as your OSHA area office expects. | ## Frequently asked questions ### Do first aid cases go on the OSHA 300 Log? No. A case that needs only first aid and meets no other criterion is not recordable. The first aid list in 29 CFR 1904.7(b)(5)(ii) is closed, so anything beyond it is medical treatment. See [recordable vs first aid](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid). ### Can I keep the Log in a spreadsheet or software? Yes, if you can produce equivalent forms when needed. An equivalent form has the same information, is as readable and understandable, and follows the same instructions. Any file format works, such as Excel or CSV (FAQ 29-8). ### Can a third party maintain our Log? Yes. An insurer, accountant or safety consultant may complete and keep the forms. The employer stays responsible for accuracy, and a company executive must still certify the annual summary (FAQ 29-7). ### Whose Log does a temporary or contract worker's injury go on? The employer that supervises the worker day to day records the case, on payroll or not. If a staffing agency or contractor provides that supervision, it goes on its Log. Coordinate so each case is recorded once (1904.31). ## Sources - [eCFR: 29 CFR 1904.29, Forms; 1904.30, Multiple business establishments](https://www.ecfr.gov/current/title-29/part-1904) - [OSHA: Forms for recording work-related injuries and illnesses, including Form 300](https://www.osha.gov/recordkeeping/forms) - [OSHA: Recordkeeping forms package with instructions (Forms 300, 300A, 301)](https://www.osha.gov/sites/default/files/OSHA-RK-Forms-Package.pdf) - [OSHA: Part 1904 recordkeeping frequently asked questions](https://www.osha.gov/laws-regs/interlinking/standards/1904/faq) - [OSHA: Part 1904 Recordkeeping Policies and Procedures Directive, CPL 02-00-172](https://www.osha.gov/sites/default/files/enforcement/directives/CPL-02-00-172.pdf) ## Related - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA 301 incident report: the 18 fields and deadlines](https://incidentkit.ai/compliance/osha/osha-301-incident-report) - [OSHA 300A summary: who signs, when to post, how long](https://incidentkit.ai/compliance/osha/osha-300a-summary) - [Recordable vs first aid: OSHA's medical treatment test](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) - [OSHA 300 Log Automation: Keep It Accurate Year-Round](https://incidentkit.ai/use-cases/osha-300-log-automation) - [Workplace Injury Report Template (OSHA 301 Aligned)](https://incidentkit.ai/templates/workplace-injury-report) - [OSHA recordkeeping guide: Part 1904 for employers](https://incidentkit.ai/guides/osha-recordkeeping-guide) --- # OSHA Form 301: the Injury and Illness Incident Report > OSHA Form 301 is the incident report for one recordable case. Complete it within 7 calendar days of learning of the case, and keep it five years. A workers' compensation report with the missing information added can stand in. An employee must get their own 301 by the end of the next business day. Source: https://incidentkit.ai/compliance/osha/osha-301-incident-report · Updated Oct 5, 2026 ## Key facts - **Form:** OSHA Form 301, Injury and Illness Incident Report (Rev. 04/2004) - **Rule:** 29 CFR 1904.29(b)(2) - **Deadline:** Within 7 calendar days of learning of the case - **Fields:** 18: employee, health care professional, the case - **Retention:** 5 years after the year covered - **Employee copy:** By the end of the next business day - **Union representative copy:** Within 7 calendar days, case section only - **Citation:** 29 CFR 1904.29(b)(2) and 1904.35(b)(2)(v) - **Authority:** OSHA - **Applies to:** Employers required to keep OSHA injury and illness records, EHS managers, HR and supervisors who complete incident reports, Establishments with 100 or more employees in designated industries that submit 301 data electronically ## What is the 301 and when is it due? You need a 301, or an equivalent form, for each recordable case on the 300 Log. Complete it within 7 calendar days of learning of the case. Keep it five years after the year it covers (1904.29, 1904.33). Copy the Log's case number into field 10. Cases that are not recordable, and near misses, need no 301. Many employers still write an internal report for every event, because the 301 is thin on causes. See the [workplace injury report template](https://incidentkit.ai/templates/workplace-injury-report). ## What does the form ask? Eighteen fields in three groups. The form is revision 04/2004 under OMB control number 1218-0176. *OSHA Form 301 fields* | Group | Fields | | --- | --- | | The employee | 1 full name, 2 address, 3 date of birth, 4 date hired, 5 sex | | The physician or other health care professional | 6 name. 7 where treated, if away from the worksite. 8 treated in an emergency room. 9 hospitalized overnight as an in-patient. | | The case | 10 case number from the Log. 11 date of injury or illness. 12 time the employee began work. 13 time of event. 14 what the employee was doing just before. 15 what happened. 16 the injury or illness and body part. 17 the object or substance that harmed the employee. 18 date of death. | Fields 14 to 17 are the narrative. The form says to leave out worker names, phone numbers and Social Security numbers. ## Can another form stand in for the 301? Yes, if it is an equivalent form. It needs the same information, must be as readable and understandable, and must follow the same instructions as the OSHA form (1904.29(b)(4)). - A workers' compensation or insurance first report can serve if you add the missing OSHA information (FAQ 29-4). - Equivalent forms can be kept in any file format, such as Excel or CSV (FAQ 29-8). - Computer records are fine if they can produce equivalent forms when needed (1904.29(b)(5)). ## Who is entitled to a copy, and how fast? Three groups can ask, each with its own clock. *Access to the 301 (29 CFR 1904.35 and 1904.40)* | Requester | What they get | Deadline | | --- | --- | --- | | Employee, former employee or personal representative | The 301 for that employee's case | End of the next business day, free the first time | | Authorized employee representative (a collective bargaining agent) | Only the case information section ('Tell us about the case') of each 301 for the establishment; everything else removed | Within 7 calendar days | | OSHA, NIOSH or a State Plan agency | The records you keep under Part 1904 | Within 4 business hours | A personal representative is someone the employee names in writing, or the legal representative of a deceased or legally incapacitated employee. The form holds health information, so it carries a confidentiality notice. If you share it voluntarily, remove names and other identifiers. Exceptions: an auditor or consultant hired to evaluate your safety and health program. A workers' compensation or insurance claim. A public health or law enforcement agency, as HIPAA allows (1904.29(b)(10)). ## What makes a 301 narrative useful? Specific activity, specific object, specific outcome. The examples below are invented for illustration. *Illustrative narrative fields* | Field | Thin | Useful | | --- | --- | --- | | 14 Before the incident | Working | Pulling a loaded pallet jack backward over a raised door threshold | | 15 What happened | Hurt back | The front wheel caught on the threshold and the load stopped; the employee felt a pull in the lower back | | 16 Injury | Back | Strained lower back | | 17 Object or substance | Equipment | Pallet jack and door threshold | ## How does the 301 connect to electronic submission? Establishments with 100 or more employees in Appendix B industries must submit 300 and 301 data to OSHA each year. The submission leaves out the employee's name and address, the health care professional's name, and any treatment facility's name and address (1904.41(b)(9)). OSHA posts most of it, minus identifiers, so write narratives a stranger can read ([electronic submission](https://incidentkit.ai/compliance/osha/electronic-submission)). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Complete a 301 for each recordable case within 7 calendar days | Lauren asks the narrative questions and fills matching fields, marked 'Lauren · draft'. A person reviews and signs. OSHA 301 export is rolling out; for now the per-incident PDF carries the facts. | | Equivalent forms are acceptable if complete | One incident record serves the investigation and, once exports roll out, the OSHA form. | | Employee copy by the end of the next business day | The per-incident PDF is a printable report. Role-based access controls who may generate and share it. | | Narratives without personal identifiers in fields 14 to 17 | Reviewers see every Lauren-drafted field before approval, so identifiers can be removed first. | | Keep for five years | Records and change history stay in the audit trail, with CSV export for your own archive. | ## Frequently asked questions ### Do I need a 301 for every incident? No. You need one for each recordable injury or illness on the 300 Log. First aid cases and near misses need no 301. Many employers still keep an internal report, because minor events show patterns. ### Can I use my workers' compensation first report? Yes, if it holds all the information the 301 asks for, is as readable and understandable, and follows the same instructions. You may add missing information to an insurance or workers' compensation form. ### Does the 301 have to be signed? Not by the rule. The signature duty applies to the 300A annual summary, which a company executive must certify. The 301 asks who completed it, with title, phone and date. Keep your own review step. ### Do I have to update a 301 when the case changes? No. You must update the 300 Log when a case's outcome or description changes, but not the 301 or the 300A. You may if you wish. Keep the 301 for five years after the year it covers (1904.33). ## Sources - [eCFR: 29 CFR 1904.29, Forms; 1904.33, Retention and updating; 1904.35, Employee involvement](https://www.ecfr.gov/current/title-29/part-1904) - [OSHA: Recordkeeping forms package with instructions, including Form 301 (Rev. 04/2004)](https://www.osha.gov/sites/default/files/OSHA-RK-Forms-Package.pdf) - [OSHA: Forms for recording work-related injuries and illnesses](https://www.osha.gov/recordkeeping/forms) - [OSHA: FAQ 29-4, supplementing insurance or workers' compensation forms](https://www.osha.gov/faq/29-4) - [OSHA: Injury Tracking Application frequently asked questions](https://www.osha.gov/injuryreporting/faqs) ## Related - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [OSHA 300A summary: who signs, when to post, how long](https://incidentkit.ai/compliance/osha/osha-300a-summary) - [OSHA electronic submission: 29 CFR 1904.41 and the ITA](https://incidentkit.ai/compliance/osha/electronic-submission) - [Workplace Injury Report Template (OSHA 301 Aligned)](https://incidentkit.ai/templates/workplace-injury-report) - [Near Miss Report Template (Free, Printable Form)](https://incidentkit.ai/templates/near-miss-report) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) --- # OSHA Form 300A: the annual Summary of Work-Related Injuries and Illnesses > The OSHA 300A totals the year's 300 Log for one establishment. A company executive certifies it. Post it where employee notices go from February 1 through April 30, even with no cases, and keep it five years. An intranet posting alone does not satisfy the rule. Source: https://incidentkit.ai/compliance/osha/osha-300a-summary · Updated Oct 5, 2026 ## Key facts - **Form:** OSHA Form 300A, Summary of Work-Related Injuries and Illnesses (Rev. 04/2004) - **Rule:** 29 CFR 1904.32 - **Posting window:** February 1 to April 30 of the year after - **Zero cases:** Still complete, certify and post, with zeros - **Signer:** A company executive: owner (sole proprietor or partner), corporate officer, top on-site official or that official's supervisor - **Retention:** 5 years after the year covered; no duty to update - **Electronic posting:** Not enough on its own (OSHA FAQ 32-3) - **Citation:** 29 CFR 1904.32 - **Authority:** OSHA - **Applies to:** Employers required to keep an OSHA 300 Log, including those with no recordable cases in the year, Company executives who certify the summary for each establishment, EHS and HR staff who prepare, post and archive the form ## What is Form 300A and when is it due? The 300A is the year-end summary of the 300 Log, one per establishment. After the year ends, review the Log, total it, certify it and post it. Posting runs February 1 to April 30 of the next year (1904.32). Zero recordable cases does not remove the duty. Enter zeros in the column totals, then certify and post (1904.32(b)(2)(i); FAQ 32-2). ## What does the 300A contain? Log totals, establishment and employment details, and an executive's certification. *OSHA Form 300A sections (Rev. 04/2004)* | Section | Contents | | --- | --- | | Number of cases | Deaths (G), days away from work (H), job transfer or restriction (I), other recordable cases (J) | | Number of days | Days away from work (K) and days of job transfer or restriction (L) | | Injury and illness types | Injuries, skin disorders, respiratory conditions, poisonings, hearing loss, all other illnesses (M) | | Establishment information | Name, address, industry description and NAICS code | | Employment information | Annual average employees and total hours worked by all employees last year | | Certification | Company executive's signature, title, phone and date | An equivalent form is allowed. It must carry the employee access and employer penalty statements from the 300A, and be certified and posted like the original (1904.32(b)(2)(iii); FAQ 32-4). ## How do you prepare it? Six steps. 1. **Review the Log** Check every entry for completeness and accuracy. Correct problems before you total anything (1904.32(a)(1)). 2. **Total the columns** Add each column from the Log. Enter zeros if there were no cases. 3. **Enter employment information** Use the annual average number of employees and total hours worked. Count salaried, hourly, part-time and seasonal workers, and others you supervise, such as temporary staff. Leave out paid time not worked, such as vacation, sick leave and holidays. If you track only hours paid, estimate hours worked (FAQ 32-1). 4. **Get it certified** A company executive examines the Log and signs (see below). 5. **Post it** Post the 300A, not the Log, where employee notices are customarily posted, from February 1 to April 30. 6. **Keep it** Save it for five years after the year it covers. ## Who can sign the certification? A company executive certifies that they examined the Log and reasonably believe the summary is correct and complete (1904.32(b)(3)). The belief rests on knowing how the information was recorded. The rule names who qualifies. *Who is a company executive under 29 CFR 1904.32(b)(4)* | Person | When they qualify | | --- | --- | | An owner of the company | Only in a sole proprietorship or partnership | | An officer of the corporation | Any corporation | | The highest ranking company official working at the establishment | Any company, for that establishment | | The immediate supervisor of the highest ranking company official working at the establishment | Any company, for that establishment | A consultant, insurer or software vendor can prepare the forms, but the employer answers for accuracy and an executive still certifies (FAQ 29-7). The form warns that knowingly falsifying it may result in a fine. ## Where and how must it be posted? In every establishment, in person, February 1 to April 30. - In each establishment, in a conspicuous place or places where notices to employees are customarily posted (1904.32(b)(5)). - Unaltered, undefaced and not covered by other material. - Physically. OSHA says electronic posting does not satisfy the rule (FAQ 32-3). - At every establishment where you keep a 300 Log, even if records are stored at headquarters (FAQ 30-1). - Only the 300A. The Log is not posted. Plan backward: certify in January, post by February 1, keep it up through April 30. ## What happens after the posting period? Keep the 300A for five years after the year it covers. You need not update it when a case changes later, though you may. The Log must be updated (1904.33). Some establishments also owe OSHA the same 300A data by March 2, through the Injury Tracking Application. OSHA says this is separate from posting, so neither replaces the other. Both come from the same Log. See [electronic submission](https://incidentkit.ai/compliance/osha/electronic-submission) and the [OSHA 300 Log](https://incidentkit.ai/compliance/osha/osha-300-log) page. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Review the Log for completeness and accuracy before summarizing (1904.32(a)(1)) | Status workflow and reporting show open and overdue items by site. The audit trail shows what changed, so year-end review starts from a list. | | Total the Log and produce the 300A | OSHA 300A generation from the same record is rolling out. Until then, use CSV export and total in your own form. | | A company executive certifies the summary | A person always reviews, edits and signs inside IncidentKit. Certifying the 300A is the executive's own act. IncidentKit does not certify for you. | | Enter average employees and total hours worked | Take these from payroll or your HRIS. Deeper HRIS integrations are rolling out. | | Post February 1 to April 30 and keep five years | Posting is physical. Attach the signed copy to the record as evidence. The audit trail and CSV export support the five-year archive. | ## Frequently asked questions ### Do we post a 300A if we had no recordable cases? Yes. Enter zeros in each column total, have a company executive certify the form, and post it February 1 to April 30. OSHA says employers with no recordable cases must still do this. ### Can we post the 300A only on our intranet? No. OSHA says electronic posting alone does not satisfy the rule. Post it in each establishment where employee notices are customarily posted, unaltered and uncovered, from February 1 to April 30. Computer records are fine, but posting is physical. ### What if an employee is still away from work when we total the Log? Estimate the days you expect and use that number. Update the Log entry when the actual count is known or hits the 180-day cap. Record the case once, on the Log for the year of injury (1904.7(b)(3)(ix)). ### Does submitting 300A data to OSHA replace posting? No. OSHA says electronic submission is separate from the posting rule in 1904.32, so a covered establishment must do both. OSHA does not accept paper or emailed copies, so posting never replaces submission. ### Who signs if the plant manager is the top official on site? The highest ranking company official working at the establishment may sign, and the plant manager often fills that role. An officer of the corporation, or that official's immediate supervisor, can also sign. An owner may sign only in a sole proprietorship or partnership. ## Sources - [eCFR: 29 CFR 1904.32, Annual summary; 1904.33, Retention and updating](https://www.ecfr.gov/current/title-29/part-1904) - [OSHA: Recordkeeping forms package with instructions, including Form 300A (Rev. 04/2004)](https://www.osha.gov/sites/default/files/OSHA-RK-Forms-Package.pdf) - [OSHA: FAQ 32-2, no recordable cases and the 300A](https://www.osha.gov/faq/32-2) - [OSHA: FAQ 32-3, electronic posting of the 300A](https://www.osha.gov/faq/32-3) - [OSHA: FAQ 32-1, calculating total hours worked](https://www.osha.gov/faq/32-1) - [OSHA: Injury Tracking Application frequently asked questions](https://www.osha.gov/injuryreporting/faqs) ## Related - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [OSHA 301 incident report: the 18 fields and deadlines](https://incidentkit.ai/compliance/osha/osha-301-incident-report) - [OSHA electronic submission: 29 CFR 1904.41 and the ITA](https://incidentkit.ai/compliance/osha/electronic-submission) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [TRIR and DART rates: formula, example and BLS 2024 rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates) - [OSHA 300 Log Automation: Keep It Accurate Year-Round](https://incidentkit.ai/use-cases/osha-300-log-automation) --- # Recordable vs first aid: where OSHA draws the medical treatment line > OSHA's first aid list is closed. A work-related injury needing only that care is not recordable on that basis. Anything else, such as prescription medication, sutures, rigid immobilization or most vaccines, is medical treatment and makes a new work-related case recordable. What was done matters, not who did it. Source: https://incidentkit.ai/compliance/osha/recordable-vs-first-aid · Updated Oct 5, 2026 ## Key facts - **Rule:** 29 CFR 1904.7(b)(5), medical treatment beyond first aid - **First aid list:** 14 items (A to N), stated to be a complete list - **Provider:** Who gives the treatment does not matter - **Not treatment:** Observation or counseling visits, diagnostic procedures, first aid - **Significant diagnoses:** Cancer, chronic irreversible disease, fractured or cracked bone, punctured eardrum; recordable at diagnosis - **Prescription strength:** More than the single dose on the over-the-counter label (FAQ 7-8) - **Citation:** 29 CFR 1904.7(b)(5) - **Authority:** OSHA - **Applies to:** Employers required to keep OSHA injury and illness records, Occupational health nurses, EHS managers and HR staff who decide recordability, Sites with an on-site clinic or first aid room ## How does OSHA tell first aid from medical treatment? OSHA uses a closed list of 14 first aid treatments (1904.7(b)(5)(ii)), and states that it is complete (1904.7(b)(5)(iii)). Medical treatment is the management and care of a patient to combat disease or disorder. It excludes first aid, visits solely for observation or counseling, and diagnostic procedures. The treatment decides, not the provider's title. Care on the list is first aid even when a physician gives it. Care beyond the list is medical treatment even when a non-clinician gives it (1904.7(b)(5)(iv)). ## What is first aid, and what crosses the line? Fourteen treatments are first aid. Everything else is medical treatment. The table shows the nearest treatment that crosses the line. *First aid versus medical treatment under 29 CFR 1904.7(b)(5)* | Category | First aid (not recordable on its own) | Medical treatment (recordable) | | --- | --- | --- | | Medication | Non-prescription medication at non-prescription strength | Prescription medication, or a non-prescription drug recommended at prescription strength: more than the single dose on the over-the-counter label (FAQ 7-8) | | Immunization | Tetanus immunization | Other immunizations, such as hepatitis B or rabies vaccine | | Wounds | Cleaning, flushing or soaking surface wounds. Bandages, gauze, butterfly bandages, Steri-Strips. | Sutures, staples, surgical glue and other closing devices (FAQ 7-5, 7-26) | | Support | Non-rigid support (elastic bandages, wraps, non-rigid back belts). Temporary splints, slings, neck collars and back boards while transporting a victim. | Devices with rigid stays or designed to immobilize a body part | | Therapy | Hot or cold therapy; massage | Physical therapy or chiropractic treatment | | Heat stress | Drinking fluids | Intravenous fluids (FAQ 7-6) | | Eyes and splinters | Eye patches. Removing an eye foreign body with only irrigation or a cotton swab. Removing splinters by irrigation, tweezers, cotton swabs or other simple means. | Anything not on the list | | Nails and blisters | Drilling a nail to relieve pressure. Draining fluid from a blister. Finger guards. | Anything not on the list | ## What is not medical treatment either? Three things are not medical treatment (1904.7(b)(5)(i)). They are visits to a physician or other licensed health care professional solely for observation or counseling, diagnostic procedures, and first aid. Diagnostic procedures include x-rays, blood tests and prescription medication used only for diagnosis, such as pupil-dilating drops. > **A diagnosis can still make a case recordable** An x-ray is not treatment. But a work-related fractured or cracked bone, cancer, chronic irreversible disease or punctured eardrum is a significant diagnosis. It is recordable at diagnosis, even if no treatment or restriction follows (1904.7(b)(7)). ## How do the rules apply to realistic cases? These scenarios are invented for illustration. Each assumes the case is work-related and new. Real cases turn on the facts and what the clinician did. *Illustrative recordability calls* | Scenario | Recordable? | Why | | --- | --- | --- | | Hand cut cleaned and covered with an adhesive bandage; full duty continues | No | Cleaning and a bandage are first aid. | | The same cut is closed with Steri-Strips | No | Steri-Strips and butterfly bandages are on the list. | | The same cut is closed with sutures or surgical glue | Yes | Other closing devices are medical treatment. | | Sore shoulder: pain reliever from the first aid kit at the label dose | No | Non-prescription medication at non-prescription strength. | | Same complaint: a clinician prescribes more than the label dose | Yes | Prescription strength is medical treatment. | | Ankle x-ray shows no fracture; elastic wrap applied | No | A diagnostic procedure plus non-rigid support. | | Ankle x-ray shows a hairline fracture; no treatment ordered | Yes | A fractured or cracked bone is recordable at diagnosis. | | Heat illness: drinking water in a cool area, versus intravenous fluids | No, then yes | Only drinking fluids is on the list. | | Chemical vapor exposure; oxygen given as a precaution; no symptoms | No | Precautionary oxygen with no symptoms is not recordable. With symptoms, it is (FAQ 7-15). | | Emergency room visit for observation only; released with no treatment | No | Observation is not medical treatment. | ## Can a first aid case still be recordable? Yes, if it meets another criterion. Restricted work counts when a worker cannot do a routine function (one done at least once a week). It also counts when they cannot work the full shift, other than on the day of the injury. Slower work alone is not a restriction (FAQ 7-4). Days away, job transfer and loss of consciousness also count. If a clinician recommends treatment and the worker declines it, record the case anyway (1904.7(b)(5)(v)). ## What should the record show? OSHA gives no form for this decision. Keep what a reviewer would ask for. These are practice suggestions, not rule text. - What was done, step by step, and by whom. - Whether any medication was prescription, and how the dose compared with the label. - Whether a wound closing device or immobilization was used. - Clinician advice on restrictions, with dates. - Any diagnosis, especially a fracture, and its date. - Who made the recordability decision, and when. See also [first aid vs medical treatment](https://incidentkit.ai/blog/first-aid-vs-medical-treatment-osha) and the glossary entries for [first aid](https://incidentkit.ai/glossary/first-aid) and [OSHA recordable](https://incidentkit.ai/glossary/osha-recordable). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Decide whether treatment went beyond the first aid list (1904.7(b)(5)) | Lauren asks what treatment was given, by whom, and whether any drug was prescription. It drafts fields marked 'Lauren · draft'. A person decides recordability. | | Capture clinician restrictions and day counts | Dates, notes and clinician paperwork stay attached to the record. | | Show how a call was made | The audit trail records who changed a classification and when, with before and after values. | | Enter the case on the 300 Log in the right column | Capture the outcome facts now. OSHA 300 export from the same record is rolling out. | | Learn from minor events that never reach the Log | Analytics cluster incidents by location, shift, equipment and cause, first aid cases and near misses included. | ## Frequently asked questions ### Does treatment by a doctor automatically make a case recordable? No. Care on OSHA's first aid list is first aid whoever gives it, even a physician. Care beyond the list is medical treatment even from a non-clinician. Document what was done, not the provider's credentials. ### Is a tetanus shot recordable? Not by itself. Tetanus immunization is on the first aid list. Other immunizations, such as hepatitis B or rabies vaccine, are medical treatment. The case can still be recordable for another reason, such as sutures or days away. ### Is surgical glue first aid? No. OSHA says surgical glue is a wound closing device. All such devices except butterfly bandages and Steri-Strips are medical treatment, so sutures, staples and glue make a laceration recordable. ### Do x-rays make a case recordable? No. X-rays and other diagnostic procedures are not medical treatment. But an x-ray that shows a work-related fractured or cracked bone makes the case recordable at diagnosis, even with no treatment. ### What if the employee refuses recommended treatment? Record the case anyway, whether or not the worker follows the advice. The same applies to recommended days away and work restrictions. Encourage the worker to follow treatment a physician or other licensed health care professional recommends. ## Sources - [eCFR: 29 CFR 1904.7, General recording criteria (current through 2026-10-01)](https://www.ecfr.gov/current/title-29/section-1904.7) - [OSHA: 29 CFR 1904.7 regulation text](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.7) - [OSHA: FAQ 7-5, surgical glues](https://www.osha.gov/faq/7-5) - [OSHA: FAQ 7-6, intravenous fluids and heat stress](https://www.osha.gov/faq/7-6) - [OSHA: FAQ 7-8, prescription strength](https://www.osha.gov/faq/7-8) - [OSHA: FAQ 7-15, oxygen given as a precaution](https://www.osha.gov/faq/7-15) - [OSHA: FAQ 7-27, x-rays and diagnostic procedures](https://www.osha.gov/faq/7-27) ## Related - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [First aid vs medical treatment: the OSHA recordability line](https://incidentkit.ai/blog/first-aid-vs-medical-treatment-osha) - [First aid (OSHA recordkeeping): definition and meaning](https://incidentkit.ai/glossary/first-aid) - [OSHA recordable injury: definition and meaning](https://incidentkit.ai/glossary/osha-recordable) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) --- # Reporting fatalities and severe injuries to OSHA (29 CFR 1904.39) > Every employer must report a work-related death to OSHA within 8 hours. Report an in-patient hospitalization, amputation or loss of an eye within 24 hours, if it happens within 24 hours of the incident. Call the nearest OSHA office or 1-800-321-6742, or use the online form. Emergency room treatment alone, or observation alone, is not reportable. Source: https://incidentkit.ai/compliance/osha/severe-injury-reporting · Updated Oct 5, 2026 ## Key facts - **Rule:** 29 CFR 1904.39, last amended 2014 (79 FR 56187) - **Fatality:** Within 8 hours, if the death is within 30 days of the incident - **Hospitalization, amputation, eye loss:** Within 24 hours, if it is within 24 hours of the incident - **Phone:** 1-800-321-6742 or the nearest area office - **Online:** Reporting form on osha.gov - **Who reports:** Every covered employer, even exempt ones; for temp workers, the supervising employer - **Not reportable:** Emergency room only, observation only, public-road crashes outside construction zones, public transportation - **Verified:** eCFR through 2026-10-01; OSHA page read October 2026 - **Citation:** 29 CFR 1904.39 - **Authority:** OSHA - **Applies to:** Every employer under federal OSHA jurisdiction, including employers exempt from routine recordkeeping, Employers in State Plan states, which may set shorter deadlines, EHS, HR and operations leaders who make the call to OSHA ## What must you report to OSHA, and how fast? A death has an 8-hour clock. An admission, amputation or eye loss has a 24-hour one. *Reportable events and deadlines under 29 CFR 1904.39* | Event | Deadline | Condition | | --- | --- | --- | | Work-related fatality | Within 8 hours of the death | Death within 30 days of the incident | | In-patient hospitalization | Within 24 hours of the admission | Admitted within 24 hours of the incident | | Amputation | Within 24 hours | Within 24 hours of the incident | | Loss of an eye | Within 24 hours | Within 24 hours of the incident | This applies to every employer, even those exempt from injury records by size or industry. State Plan states, which run their own OSHA programs, may set shorter deadlines (FAQ 37-2), so check yours. ## How do you make the report? Call or use the online form, at any hour. 1. **Choose a channel** Call or visit the nearest OSHA area office, call 1-800-321-6742 (OSHA's 24-hour line), or use the online form on osha.gov. 2. **After hours** A voicemail, fax or email to a closed area office does not count (1904.39(b)(1)). 3. **Give eight facts** Give the establishment name, location, time and event type. Add the number of employees and their names, a contact person with phone, and a brief description. 4. **Count from when you know** If you learn late, the clock starts when you or any of your agents learn of it, or learn it was work-related (1904.39(b)(7), (b)(8)). 5. **Record it too** If you keep OSHA records, the case still goes on the 300 Log and 301. ## What do OSHA's terms mean? OSHA's definitions are narrower than everyday use. - **In-patient hospitalization:** formal admission to the in-patient service of a hospital or clinic for care or treatment. The hospital or clinic decides if the person was admitted (FAQ 39-8). An overnight stay does not settle it (FAQ 39-10). Emergency room treatment alone is not reportable. Any care or treatment counts, even if it is limited to first aid list items (FAQ 39-11). - **Amputation:** the traumatic loss of a limb or other external body part. It includes fingertip amputations with or without bone loss, medical amputations after irreparable damage, and reattached parts. It excludes avulsions, enucleations, deglovings, scalpings, severed ears, and broken or chipped teeth. Rely on a health care professional's diagnosis (FAQ 39-5). - **Loss of an eye:** physical removal of the eye, including enucleation and evisceration. Loss of sight alone is not reportable, unless it leads to in-patient hospitalization within 24 hours of the incident (FAQ 39-3, 39-4). ## What is not reportable? Four situations fall outside the rule. - A motor vehicle crash on a public street or highway, unless in a construction work zone. - An event on a commercial or public transportation system, such as an airplane, train, subway or bus. - A hospital stay for observation or diagnostic testing only. - A hospitalization, amputation or eye loss more than 24 hours after the incident, or a death more than 30 days after it. Still record these cases on your OSHA 300 Log if you keep one and they are recordable. A work-related heart attack death or hospitalization is reportable. The local area office director decides whether to investigate. ## How do real situations play out? These examples are illustrative and assume a work-related incident under federal OSHA. *Illustrative reporting calls* | Scenario | Report to OSHA? | Why | | --- | --- | --- | | A worker loses a fingertip at a conveyor | Yes, within 24 hours | Fingertip amputations count. | | A nurse is treated in the emergency room and goes home | No | Emergency room treatment alone is not reportable. | | A technician is admitted as an in-patient 3 hours after a fall | Yes, within 24 hours of the admission | Within 24 hours of the incident. | | Scheduled surgery 3 days after a workplace injury | No | The stay is more than 24 hours after the incident (FAQ 39-7). | | An employee dies 12 days after a workplace fall | Yes, within 8 hours of the death | Death within 30 days of the incident. | | A delivery driver is hurt in a public highway crash | No | Not in a construction work zone. Record if recordable. | | A road worker is admitted after a crash in a highway construction work zone | Yes | Construction work zone crashes are reportable. | | A staffing-agency worker you supervise is hospitalized | Yes, you report | The employer that supervises day to day reports (FAQ 39-9). | ## What should the record hold before you call? OSHA asks for eight facts. The extra items below are practice suggestions, not rule text. - The eight required facts from step 3. - When you or your agent first learned of the event. - Whether the person was formally admitted, and when. - Who reported to OSHA, when, how, and any case reference. - A link to the investigation. The clock does not wait for the investigation, so report with what you know. For recording, see [recordable vs first aid](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) and the [OSHA recordkeeping overview](https://incidentkit.ai/compliance/osha/recordkeeping-overview). ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Report a fatality in 8 hours; a hospitalization, amputation or eye loss in 24 hours | Severity sets priority. Event types that start a clock flag the deadline. Escalation timers move unacknowledged events to the next person. Automated reportability rules are rolling out. | | Give OSHA eight specific facts | Lauren asks follow-up questions that capture time, place, people and description. The reporter and reviewer confirm each field. | | Make the report by phone or online form | IncidentKit does not file with OSHA. A named person reports. The record keeps who was notified and when. | | Record the case on the 300 Log and 301 as well | OSHA 300 and 301 exports are rolling out. The same incident record is the source for both. | | Learn of the event quickly, wherever it happens | Quick report takes three fields from a phone, works without signal and becomes a full incident record. | ## Frequently asked questions ### Do I report an emergency room visit to OSHA? No. Emergency room treatment alone is not reportable. The employee must be formally admitted as an in-patient. The case may still be recordable on your OSHA 300 Log. ### When does the 24-hour clock start? It runs from the hospitalization, if the admission is within 24 hours of the incident. If you learned late, it runs from when you or your agents learned of the event or its link to work. ### Does a fingertip injury count as an amputation? Yes, if it is an amputation. OSHA counts fingertip amputations with or without bone loss. It excludes avulsions such as deglovings, scalpings and severed ears. Rely on a health care professional's diagnosis. If the diagnosis is avulsion, no report is needed. ### Do small employers have to report? Yes. Employers exempt from routine injury records must still report. A company with 10 or fewer employees reports a death within 8 hours and a qualifying hospitalization, amputation or eye loss within 24 hours. ## Sources - [eCFR: 29 CFR 1904.39, Reporting fatalities, hospitalizations, amputations, and losses of an eye (current through 2026-10-01)](https://www.ecfr.gov/current/title-29/section-1904.39) - [OSHA: Report a fatality or severe injury](https://www.osha.gov/report) - [OSHA: 29 CFR 1904.39 regulation text](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.39) - [OSHA: Part 1904 recordkeeping frequently asked questions (items 39-1 to 39-11)](https://www.osha.gov/laws-regs/interlinking/standards/1904/faq) - [OSHA: FAQ 39-5, amputations and avulsions](https://www.osha.gov/faq/39-5) - [OSHA: FAQ 39-11, in-patient hospitalization and first aid care](https://www.osha.gov/faq/39-11) ## Related - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [Recordable vs first aid: OSHA's medical treatment test](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [Incident routing and escalation by severity](https://incidentkit.ai/product/routing-and-escalation) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) - [PSIF (potential serious injury or fatality): definition and meaning](https://incidentkit.ai/glossary/psif) - [Incident reporting software for EHS managers and leads](https://incidentkit.ai/solutions/ehs-managers) --- # Lockout/tagout (29 CFR 1910.147): the program and what to capture after an event > 29 CFR 1910.147 requires an energy control program: documented procedures, worker training and inspections at least once a year. Machines must stay isolated and inoperative while people service them. Construction and agriculture are not covered. A lockout event still triggers recording, possible OSHA reporting, retraining and a procedure review. Source: https://incidentkit.ai/compliance/osha/lockout-tagout · Updated Oct 5, 2026 ## Key facts - **Standard:** 29 CFR 1910.147, The control of hazardous energy (lockout/tagout) - **Program:** Procedures, training and periodic inspections - **Periodic inspection:** At least annually, by an authorized employee who does not use the procedure - **Not covered:** Construction, agriculture, shipyards, marine terminals, longshoring, electric utility installations, oil and gas well drilling and servicing - **Enforcement:** Fourth most frequently cited standard in fiscal year 2025 (OSHA list updated 2026-04-15) - **Retraining trigger:** Inspection findings, or reason to believe employees deviate from or misunderstand the procedure - **Citation:** 29 CFR 1910.147 - **Authority:** OSHA - **Applies to:** General industry employers whose employees service or maintain machines where unexpected start-up or stored energy could cause injury, Manufacturing, warehousing, laboratory, pharmaceutical production, food and chemical plants, and maintenance teams in other general industry settings, Not construction, agriculture, shipyards, marine terminals, longshoring or electric utility generation, transmission and distribution installations, which have their own rules ## What does 1910.147 require? You need three things: energy control procedures, worker training and periodic inspections. Before anyone services a machine, isolate it from its energy source and make it inoperative (1910.147(c)(1)). This applies where unexpected energizing, start-up or release of stored energy could cause injury. It covers servicing and maintenance, such as lubricating, cleaning, unjamming and adjusting. Normal production is not covered unless a worker must remove or bypass a guard. It is also covered if a worker must reach into the point of operation or danger zone (1910.147(a)(2)). ## What are the five program elements? Five elements make up the program. Each has a paragraph to check. *Program elements in 29 CFR 1910.147* | Element | What it requires | Paragraph | | --- | --- | --- | | Energy control procedures | Documented and specific: scope, purpose, authorization, rules and techniques. Steps to shut down, isolate, block and secure. Placing, removing and transferring locks and tags. Tests to verify isolation. | (c)(4) | | Devices | Provided by you. They must be singularly identified, durable, standardized and substantial. Use a lock where a device can be locked, unless tagout gives equal protection. | (c)(2), (c)(5) | | Training | For authorized employees, affected employees and others in the area. Retrain when jobs, machines or procedures change, or when gaps show. Certify each worker's name and training dates. | (c)(7) | | Periodic inspection | At least annually, by an authorized employee who does not use that procedure. Then certify it. | (c)(6) | | Contractors and groups | On-site and outside employers tell each other their procedures. Group lockout gives each person protection equal to a personal lock. | (f)(2), (f)(3) | ## How does the periodic inspection work? Inspect each energy control procedure once a year. The inspector must be an authorized employee other than the person or people using the procedure. The aim is to find and correct deviations and inadequacies (1910.147(c)(6)). For lockout, the inspector reviews each authorized employee's duties with that employee. For tagout, the review also covers affected employees and the limits of tags. Then certify it, naming the machine or equipment, the date, the employees included and the inspector. ## What does a lockout event trigger? The standard has no incident report. An injury or near miss tied to hazardous energy still sets off several duties. - **Recording:** an injury that meets the criteria goes on the [OSHA 300 Log](https://incidentkit.ai/compliance/osha/osha-300-log). - **Reporting:** a death, in-patient hospitalization, amputation or eye loss must be reported on the [8-hour and 24-hour clocks](https://incidentkit.ai/compliance/osha/severe-injury-reporting). - **Retraining:** required when an inspection shows workers do not follow the procedure or know it poorly ((c)(7)(iii)(B)). It is also required if you have reason to believe so. An event is a strong reason. - **The documentation exception:** you can skip a written procedure for simple equipment only if eight conditions hold. One is no past accident from unexpected activation or re-energization during servicing or maintenance ((c)(4)(i) note). An event can end the exception for that machine. - **Lock removal:** if someone other than the person who applied a lock removed it, check the exception in (e)(3). You must confirm the employee is not at the facility and make reasonable efforts to reach them. ## What should you capture after a lockout event? These are practice suggestions tied to the standard. Capture them while memories and the machine are still fresh. *Suggested lockout event data* | Capture | Why it matters | Rule hook | | --- | --- | --- | | Equipment and energy sources: electrical, hydraulic, pneumatic, stored | What needed isolating | (d)(3), (d)(5) | | Task: servicing or production, such as jam clearing | Decides if the standard applies | (a)(2) | | Procedure used, or single-source exception claimed | Gaps in the procedure | (c)(4) | | Isolation steps and the verification test | Where the sequence broke | (d)(4) to (d)(6) | | Locks and tags: type, owner, group lock, removal | Missing, shared or removed devices | (c)(5), (e)(3), (f)(3) | | Roles involved and training dates | Training records versus reality | (c)(7) | | Contractors and last periodic inspection date | Were procedures shared; was the gap missed | (f)(2), (c)(6) | | Injury, treatment and days away | Drives recording and reporting | 1904.7, 1904.39 | | Corrective actions: procedure, retraining, device or equipment change | Closes the loop with an owner and date | (c)(7)(iii) | ## What applies where 1910.147 does not? Construction, utilities and some other sectors follow different rules. *Hazardous energy rules outside 1910.147* | Setting | Where to look | | --- | --- | | Construction | Not covered by 1910.147. 1926.417 requires tags on controls being deactivated and on deenergized equipment or circuits wherever they can be energized. | | Electric power generation | 1910.269(d), hazardous energy control (lockout/tagout) procedures | | Electric power transmission and distribution | 1910.269(m), deenergizing lines and equipment | | Electrical hazards in utilization installations | Subpart S of Part 1910 | | Shipyards, marine terminals, longshoring, agriculture, oil and gas well drilling and servicing | Excluded from 1910.147. Check the standards for those industries. | ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Energy control program: procedures, training and periodic inspection ((c)(1)) | IncidentKit is not your procedure library or training system. It records what happened and the corrective actions that follow. Attach your procedures and certificates as evidence. | | Capture the facts of a hazardous energy event | Lauren asks about the equipment, task, people involved and injury. Fields she fills read 'Lauren · draft' until a person approves them. | | Retrain and revise the procedure when events show gaps ((c)(7)(iii)) | Corrective actions have an owner, due date and evidence, and close after an effectiveness check. Overdue actions remind the owner and escalate. | | Spot repeat problems before they injure someone | Analytics cluster incidents by equipment, location, shift and cause, so repeat near misses stand out. | | Record and report resulting injuries | OSHA 300, 300A and 301 exports, automated reportability rules and plant packs are rolling out. Severity routing and reporting-clock flags help the right person act. The core incident workflow runs now. | ## Frequently asked questions ### Does lockout/tagout apply to clearing a jam during production? Only if the task needs a guard removed or bypassed. Also if it puts part of the body into the point of operation or danger zone. If a worker reaches in to clear a jam, lock out. Minor tool changes can be excluded. They must be routine, repetitive, integral to production and covered by other effective protection. ### How often must the energy control procedure be inspected? At least annually, by an authorized employee other than the person or people using the procedure. It must correct deviations or inadequacies, and be certified. Retrain if it reveals gaps. ### Is a written procedure always required? No, but the exception is narrow. You may skip it only if all eight conditions are met. They include no stored energy and one readily identified energy source. They include one lock under the worker's exclusive control and no hazards to others. They also include no past accident from unexpected activation or re-energization. ### Who may remove another person's lock? Normally only the employee who applied it. The employer may order removal only if procedures and training are documented in the program. It must confirm the employee is not at the facility and make reasonable efforts to tell them before they resume work. ### Does lockout/tagout apply on construction sites? No. 1910.147 excludes construction and agriculture. On construction sites, 1926.417 requires tags on controls and on deenergized equipment or circuits. Other hazards fall under other Part 1926 standards. ## Sources - [eCFR: 29 CFR 1910.147, The control of hazardous energy (lockout/tagout) (current through 2026-10-01)](https://www.ecfr.gov/current/title-29/section-1910.147) - [OSHA: Control of hazardous energy (lockout/tagout) topic page](https://www.osha.gov/control-hazardous-energy) - [OSHA: Top 10 most frequently cited standards, fiscal year 2025](https://www.osha.gov/top10citedstandards) - [eCFR: 29 CFR 1926.417, Lockout and tagging of circuits](https://www.osha.gov/laws-regs/regulations/standardnumber/1926/1926.417) - [OSHA: 29 CFR 1910.269, Electric power generation, transmission, and distribution](https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.269) ## Related - [Lockout/tagout: definition and meaning](https://incidentkit.ai/glossary/lockout-tagout) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [Manufacturing incident reporting and OSHA 300 software](https://incidentkit.ai/solutions/manufacturing) - [Incident reporting software for plant managers](https://incidentkit.ai/solutions/plant-managers) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) --- # Hazard communication (29 CFR 1910.1200): SDS, labels, training and incident records > The Hazard Communication Standard requires a written program, labels and worker training. It also requires a safety data sheet (SDS) for each hazardous chemical, readily accessible every shift. It applies wherever workers may be exposed to a hazardous chemical. Revised provisions have staged compliance dates from May 19, 2026 to May 19, 2028. Source: https://incidentkit.ai/compliance/osha/hazard-communication · Updated Oct 5, 2026 ## Key facts - **Standard:** 29 CFR 1910.1200, Hazard communication - **Core duties:** Written program, labels, safety data sheets, training - **Revised rule:** Published 2024-05-20 (89 FR 44144), effective 2024-07-19 - **Extension:** Compliance dates moved four months by 91 FR 1695 (2026-01-15) - **Next employer date:** 2026-11-20 for substances; 2028-05-19 for mixtures - **Exposure records:** At least 30 years under 1910.1020 - **Enforcement:** Second most frequently cited standard in fiscal year 2025 - **Citation:** 29 CFR 1910.1200 - **Authority:** OSHA - **Applies to:** Employers with hazardous chemicals in the workplace, including manufacturers, laboratories, warehouses, utilities, chemical and food processors, and healthcare facilities, Chemical manufacturers, importers and distributors, who also classify hazards and prepare labels and safety data sheets, Construction employers, through 29 CFR 1926.59 ## What must employers do? Four duties apply: a written program, labels, safety data sheets (SDSs) and training. They cover any chemical known to be present where workers may be exposed in normal use or a foreseeable emergency (1910.1200(b)(2)). If you do not make or import chemicals, focus on the program and worker information. *Employer duties in 29 CFR 1910.1200* | Duty | What it asks | Paragraph | | --- | --- | --- | | Written program | Kept at each workplace. Lists hazardous chemicals by a product identifier shown on the SDS. Says how you will inform workers of non-routine task hazards and chemicals in unlabeled pipes. | (e) | | Labels | Shipped containers need a product identifier, signal word, hazard and precautionary statements, pictograms and supplier details. Workplace containers need the same. Or they need a product identifier plus words, pictures or symbols giving general hazard information. Leave incoming labels on. Portable containers for immediate use by the person who filled them are exempt. | (f) | | Safety data sheets | One SDS for each hazardous chemical used, readily accessible in the work area each shift. Electronic access is allowed if it creates no barrier to immediate access. | (g)(1), (g)(8) | | Training | At initial assignment and whenever a new chemical hazard is introduced. Covers detecting releases, hazards, protective measures, and reading labels and SDSs. | (h) | ## Which SDS sections matter in an incident? An SDS has sixteen sections in a fixed order (1910.1200(g)(2)). OSHA does not enforce sections 12 to 15. Early sections cover identification, hazards, composition, first aid, fire-fighting, spills, handling and exposure controls. Later ones cover physical properties, toxicology, ecology, disposal, transport, regulatory information and the revision date. - **Section 4, first-aid measures:** what to do for exposure, and what to tell the clinician. - **Section 6, accidental release measures:** spill response and containment. - **Section 8, exposure controls and personal protection:** the protective equipment and controls to use. - **If a shipment arrives without an SDS,** get one as soon as possible. If you prepare an SDS, add significant new hazard information within three months ((g)(6)(iii), (g)(5)). ## What are the 2026 to 2028 compliance dates? A rule published January 15, 2026 (91 FR 1695) moved each compliance date of the revised standard back four months. As of October 2026, the first date has passed. November 20, 2026 is next. *Compliance dates in 29 CFR 1910.1200(j)* | Date | Who | What | | --- | --- | --- | | May 19, 2026 | Manufacturers, importers and distributors evaluating substances | Comply with all modified provisions | | November 20, 2026 | Employers, for substances | Update alternative workplace labeling, the program and training for newly identified hazards | | November 19, 2027 | Manufacturers, importers and distributors evaluating mixtures | Comply with all modified provisions | | May 19, 2028 | Employers, for mixtures | Same updates as above | Until those dates, you may follow the current text, 1910.1200 as revised July 1, 2023, or both (1910.1200(j)(4)). ## What to document after an exposure or spill The standard has no incident report form. These are practice suggestions. An exposure or spill tests your labels, SDSs and training, so record how each performed. *Suggested chemical incident data* | Capture | Why it matters | | --- | --- | | Product identifier and SDS version in use | Links the event to SDS sections 4, 6 and 8 | | Container and label status: shipped label, workplace label, secondary container, unlabeled pipe | A missing or unclear label is a finding under (f) and (e)(1)(ii) | | Task, routine or non-routine | Non-routine tasks need hazard information in the program | | Who was exposed, how long, what symptoms | Drives recordability and any severe injury report | | Controls in use: ventilation, protective equipment, first aid given | Compare with SDS section 8 and the first aid versus medical treatment line | | Air or biological monitoring results | Employee exposure records, kept a long time | | Training of those involved and any exposed contractor workers | Tests (h) and the multi-employer duties in (e)(2) | ## How long must exposure and incident records be kept? OSHA 300 records are kept five years. Exposure records are kept at least thirty. *Retention periods that touch chemical incidents* | Record | Retention | Source | | --- | --- | --- | | OSHA 300 Log, privacy case list, 300A and 301 | 5 years after the year covered | 1904.33 | | Employee exposure records, including monitoring results | At least 30 years. Lab worksheets can go after 1 year, but keep results, sampling plan and methods 30 years | 1910.1020(d)(1)(ii) | | SDSs for chemicals no longer in use | No set period. Keep a record of the chemical's identity and where and when it was used for 30 years | 1910.1020(d)(1)(ii)(B) | | Employee medical records | Employment plus 30 years. Exceptions include minor on-site first aid records kept separately | 1910.1020(d)(1)(i) | | SDSs for chemicals in current use | Keep in the workplace and readily accessible | 1910.1200(g)(8) | A chemical incident can also be a Part 1904 case. If it causes a death, in-patient hospitalization, amputation or eye loss, it is also a [severe injury report](https://incidentkit.ai/compliance/osha/severe-injury-reporting). Release-prevention rules for covered processes are in [process safety incident investigation](https://incidentkit.ai/compliance/osha/process-safety-incident-investigation). ## Does it apply in construction, laboratories and warehouses? Yes, with variations for each setting. *Scope variations in 29 CFR 1910.1200(b) and 1926.59* | Setting | What applies | | --- | --- | | Construction | 1926.59 says construction requirements are identical to 1910.1200 | | Laboratories | Partial: keep incoming labels intact. Keep the SDSs you receive and give access. Give information and training. Training need not cover where the written program is kept. | | Sealed containers (warehousing, retail, marine cargo) | Partial: do not remove or deface labels. Keep SDS copies accessible. Train as needed for a spill or leak. | | Multi-employer workplaces | Your program says how other employers' workers reach SDSs and learn the precautions and labeling system | ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | A safety data sheet for each hazardous chemical, readily accessible each shift ((g)(8)) | IncidentKit runs alongside your SDS and EHS systems and does not host your SDS library. Attach SDS pages and label photos as evidence. | | Train workers on hazards and protective measures ((h)) | Investigations record contributing factors, so a training or labeling gap counts as a cause. | | Document exposure and spill incidents | One record covers every incident type. Lauren asks what chemical, where, who was exposed and what was done. Drafted fields read 'Lauren · draft' until a person approves them. | | Fix labeling, program and training gaps found | Corrective actions have an owner, due date, evidence and an effectiveness check before closing. | | Record and report resulting injuries | OSHA 300, 300A and 301 exports and automated reportability rules are rolling out. Types that start a reporting clock flag the deadline. | ## Frequently asked questions ### Do I have to label a secondary container? Usually yes, with a workplace label. A portable container is exempt if the person who filled it from a labeled container uses it right away. ### When must workers be trained on hazardous chemicals? At initial assignment, and whenever a new chemical hazard is introduced into their work area. Training covers detecting a release, the hazards, protective measures, and using labels and SDSs. Labels and SDSs must always make chemical-specific information available. ### Is a chemical spill reportable to OSHA? Only through the severe injury rule: a work-related death, in-patient hospitalization, amputation or loss of an eye, on the 8-hour and 24-hour clocks. The standard has no spill report. Check environmental release rules too. ### What does the 2026 extension change? It moved each compliance date back four months, to May 19, 2026, November 20, 2026, November 19, 2027 and May 19, 2028. Until then, you may follow the revised text or the July 2023 version. ## Sources - [eCFR: 29 CFR 1910.1200, Hazard communication (current through 2026-10-01)](https://www.ecfr.gov/current/title-29/section-1910.1200) - [Federal Register: Hazard Communication Standard, compliance date extension (91 FR 1695, 2026-01-15)](https://www.federalregister.gov/documents/2026/01/15/2026-00653/hazard-communication-standard) - [Federal Register: Hazard Communication Standard final rule (89 FR 44144, 2024-05-20)](https://www.federalregister.gov/documents/2024/05/20/2024-08568/hazard-communication-standard) - [OSHA: Hazard communication topic page](https://www.osha.gov/hazcom) - [eCFR: 29 CFR 1910.1020, Access to employee exposure and medical records](https://www.ecfr.gov/current/title-29/section-1910.1020) - [OSHA: 29 CFR 1926.59, Hazard communication (construction)](https://www.osha.gov/laws-regs/regulations/standardnumber/1926/1926.59) - [OSHA: Top 10 most frequently cited standards, fiscal year 2025](https://www.osha.gov/top10citedstandards) ## Related - [Safety data sheet: definition and meaning](https://incidentkit.ai/glossary/safety-data-sheet) - [Laboratory and pharma production incident reporting](https://incidentkit.ai/solutions/laboratories-and-pharma-production) - [Process safety incident reporting and investigation](https://incidentkit.ai/solutions/chemical-and-process-industries) - [Warehouse and logistics incident reporting software](https://incidentkit.ai/solutions/warehousing-and-logistics) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [PSM incident investigation: 29 CFR 1910.119(m) explained](https://incidentkit.ai/compliance/osha/process-safety-incident-investigation) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) --- # Process safety incident investigation (29 CFR 1910.119(m)) > Covered employers must investigate every incident that resulted in, or could reasonably have resulted in, a catastrophic release of a highly hazardous chemical (29 CFR 1910.119(m)). Start as promptly as possible, no later than 48 hours after the incident. Use a team with someone who knows the process. Write a report, resolve the findings and keep it five years. Source: https://incidentkit.ai/compliance/osha/process-safety-incident-investigation · Updated Oct 5, 2026 ## Key facts - **Rule:** 29 CFR 1910.119(m), Incident investigation - **Trigger:** An incident that resulted in, or could reasonably have resulted in, a catastrophic release - **Start:** As promptly as possible, no later than 48 hours after the incident - **Team:** One person who knows the process, plus a contract employee if contractors were involved - **Report:** Incident and start dates, description, contributing factors, recommendations - **Retention:** 5 years - **Near miss:** Not in the rule text; only in nonmandatory Appendix C - **Citation:** 29 CFR 1910.119(m) - **Authority:** OSHA - **Applies to:** Employers with a process involving a highly hazardous chemical at or above its Appendix A threshold quantity, Employers with 10,000 pounds or more of a Category 1 flammable gas or a flammable liquid with a flashpoint below 100 °F in one location, subject to the exceptions, Chemical, food processing, water treatment, utility, laboratory and pharmaceutical production sites that exceed those thresholds ## What does 1910.119(m) require? Seven paragraphs cover which incidents to investigate through how long to keep the report. *Incident investigation requirements in 29 CFR 1910.119(m)* | Paragraph | Requirement | | --- | --- | | (m)(1) | Investigate each incident that resulted in, or could reasonably have resulted in, a catastrophic release of a highly hazardous chemical in the workplace | | (m)(2) | Start the investigation as promptly as possible, and no later than 48 hours after the incident | | (m)(3) | Set up a team with at least one person who knows the process, and others with the right knowledge and experience. Include a contract employee if the incident involved contractor work. | | (m)(4) | Write a report at the end. It must include at least the incident date, the date the investigation began, a description, contributing factors and recommendations. | | (m)(5) | Have a system to promptly address and resolve findings and recommendations. Document the resolutions and corrective actions. | | (m)(6) | Review the report with affected personnel whose tasks are relevant, including contract employees | | (m)(7) | Keep investigation reports for five years | The rule sets a deadline to start the investigation. It sets none to finish it. ## Which employers are covered? Employers with a covered process under 1910.119(a). A process is covered if it involves either of these. - A chemical at or above its Appendix A threshold quantity. Examples are 10,000 pounds of anhydrous ammonia or 1,500 pounds of chlorine. - 10,000 pounds or more of a Category 1 flammable gas or a flammable liquid with a flashpoint below 100 °F, on site in one location. Hydrocarbon fuels used solely as a workplace fuel are excepted. So are flammable liquids in atmospheric tanks kept below their normal boiling point. The standard does not apply to retail facilities, oil or gas well drilling or servicing, or normally unoccupied remote facilities. ## What about near misses? The rule never uses the words 'near miss'. It uses a test: an incident that 'could reasonably have resulted' in a catastrophic release. OSHA's nonmandatory Appendix C notes that such events are sometimes called near misses. A near miss that meets the test needs a full investigation, not a log entry. A catastrophic release is a major uncontrolled emission, fire or explosion involving one or more highly hazardous chemicals. It presents serious danger to employees in the workplace (1910.119(b)). Screen each event against that definition and write down the decision. See [near-miss reporting](https://incidentkit.ai/use-cases/near-miss-reporting) and [near miss](https://incidentkit.ai/glossary/near-miss). ## Who must be on the investigation team? The team needs at least one person who knows the process. OSHA's PSM directive (CPL 02-01-065, effective January 26, 2024) allows an operator or maintenance person who knows how the process works. It also allows a process engineer or operations supervisor who knows how it is designed to work. An hourly employee is not required. Knowledge and experience count, not pay. Appendix C recommends a team from several fields, trained to interview witnesses, document facts and write reports. It says to focus on facts, not blame. If the incident involved contractor work, include a contract employee. ## What happens after the report is written? Findings and recommendations must be resolved promptly, and the resolution documented ((m)(5)). OSHA's directive says a recommendation is resolved when the employer adopts it or justifiably declines it. - **Declining a recommendation** needs a written record based on adequate evidence. Valid grounds: material factual errors in the analysis, no need to protect employees, an alternative that protects enough, or infeasibility. - **Accepting one** needs documentation of the actions and a written schedule. Finish as soon as possible and tell affected operating and maintenance staff. - **Then** review the report with affected personnel, including contract employees, and keep it for five years. ## Which events trigger an investigation? These examples assume a covered process. The right call depends on the facts and your screening record. *Illustrative screening calls* | Scenario | Investigate under (m)? | Why | | --- | --- | --- | | A fire starts in a covered process unit | Yes | A fire involving a highly hazardous chemical can be a catastrophic release. | | Pressure goes past safe limits and damages a vessel, but nothing is released | Likely yes | It could reasonably have resulted in a catastrophic release. Document the reasoning. | | A small pump seal leak is caught and contained within minutes | Screen and document | Decide if it could reasonably have become catastrophic. Keep the screening record. | | A person slips on a plant stairway, with no process involvement | No | Not a process safety event. It may still be recordable under Part 1904. | The same event can also be a Part 1904 case. If anyone is badly hurt, it is also a [severe injury report](https://incidentkit.ai/compliance/osha/severe-injury-reporting). PSM adds the 48-hour start, the written report and the documented resolution. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Investigate each qualifying incident ((m)(1)) | Near misses are incident types with the same record, routing and review as injuries. A person makes and documents the screening decision. | | Start the investigation within 48 hours ((m)(2)) | Immediate-priority incidents escalate after a window you set per facility. An unacknowledged event reaches the next owner. An investigation opens from the incident record. | | Team with a person knowledgeable in the process ((m)(3)) | Investigations are assigned to named people. Photos, work orders and documents stay attached as evidence. | | Write the report ((m)(4)) | Structured contributing factors and a five-whys chain. Lauren drafts them, and the investigator edits and signs. Every case gets a disposition. | | Resolve and document recommendations ((m)(5)) | Corrective actions need an owner, due date and evidence. The incident closes only when actions are verified. Record the reason when a recommendation is declined. | | Review with affected personnel and keep five years ((m)(6), (m)(7)) | The audit trail shows who approved what and when. The per-incident PDF and CSV export support the file. Plant packs are rolling out; the core workflow runs now. | ## Frequently asked questions ### When does the 48-hour clock start? It runs from the incident, not from when you find out. Start as promptly as possible, and no later than 48 hours after the incident. Name the team early. ### Is the investigation report due within 48 hours? No. Only the start of the investigation has a 48-hour limit. The report is written at the end, and the rule sets no completion deadline. ### Does a near miss need a PSM investigation? Yes, if it meets the test: it could reasonably have resulted in a catastrophic release. OSHA's Appendix C notes such events are sometimes called near misses. Screen each event and document the decision. ### Can we reject an investigation recommendation? Yes, if you justify it in writing with adequate evidence. Grounds are material factual errors in the analysis, no need to protect your or your contractors' employees, an alternative that protects enough, or infeasibility. ### How long must investigation reports be kept? Five years. Paragraph (m)(7) requires you to keep incident investigation reports for five years. ## Sources - [eCFR: 29 CFR 1910.119, Process safety management of highly hazardous chemicals (current through 2026-10-01)](https://www.ecfr.gov/current/title-29/section-1910.119) - [OSHA: 29 CFR 1910.119 regulation text, including nonmandatory Appendix C](https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.119) - [OSHA: Process Safety Management of Highly Hazardous Chemicals, directive CPL 02-01-065 (effective 2024-01-26)](https://www.osha.gov/sites/default/files/enforcement/directives/CPL_02-01-065.pdf) - [OSHA: Process safety management topic page](https://www.osha.gov/process-safety-management) ## Related - [Near miss: definition and meaning](https://incidentkit.ai/glossary/near-miss) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Process safety incident reporting and investigation](https://incidentkit.ai/solutions/chemical-and-process-industries) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Hazard communication 29 CFR 1910.1200: SDS, labels, training](https://incidentkit.ai/compliance/osha/hazard-communication) --- # Employee injury reporting and retaliation: 29 CFR 1904.35 and OSH Act section 11(c) > Employers must give workers a reasonable way to report injuries and illnesses, promptly and accurately. Every worker must be told how to use it, and that reporting is safe from retaliation. A way to report is not reasonable if it would deter a reasonable employee. Section 11(c) adds a 30-day window to file a complaint. Source: https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation · Updated Oct 5, 2026 ## Key facts - **Rules:** 29 CFR 1904.35, 1904.36 (informational) and OSH Act section 11(c) - **Test:** Not reasonable if it would deter a reasonable employee from reporting accurately - **Must tell employees:** How to report, that they may, and that retaliation is prohibited - **11(c) deadline:** Complaint within 30 days after the violation occurs - **OSHA determination:** Within 90 days of receiving an 11(c) complaint - **2018 memorandum:** Incentive programs and post-incident drug testing are not banned outright - **Inspector directive:** CPL 02-00-172, effective 2025-01-13 - **Citation:** 29 CFR 1904.35 and OSH Act section 11(c) - **Authority:** OSHA - **Applies to:** Employers required to keep Part 1904 records (1904.35), All employers covered by the OSH Act (section 11(c)), EHS, HR and operations leaders who design reporting procedures, incentives and post-incident practices ## What must an employer's injury reporting system do? An employer must offer a reasonable way to report. It must tell every worker about it and their rights. It must never retaliate. *Employee involvement duties in 29 CFR 1904.35* | Duty | Paragraph | | --- | --- | | Offer a reasonable way to report work-related injuries and illnesses promptly and accurately | (b)(1)(i) | | Make sure it would not deter or discourage a reasonable employee from reporting accurately | (b)(1)(i) | | Tell each worker how to report | (a)(1), (b)(1)(ii) | | Tell each worker they may report, and that discharge or discrimination for it is prohibited | (b)(1)(iii) | | Never discharge or discriminate against a worker for reporting | (b)(1)(iv) | | Give workers and their representatives access to the injury and illness records | (b)(2) | OSHA names no method. Its FAQ says workforce size, language, literacy, culture and other factors decide what works (FAQ 35-1). ## What must a reporting system not do? Four things. - **Deter or discourage accurate reporting.** This is the test for an unreasonable system. - **Hide the system or the rights.** Workers must know how to report and that retaliation is banned. - **Penalize the report.** Discharge or discrimination for reporting is prohibited. Section 11(c) also protects other rights under the Act. - **Let incentives suppress reports.** Inspectors must document policies that may discourage reporting. OSHA's example is an award tied to recorded injury counts (CPL 02-00-172). ## How does OSHA treat incentive programs and drug testing? OSHA's October 11, 2018 memorandum says 1904.35(b)(1)(iv) does not ban safety incentive programs or post-incident drug testing. The current recordkeeping directive cites it. The rule is broken only if the action punishes a worker for reporting. *OSHA's stated positions in the 2018 memorandum* | Practice | OSHA's position | | --- | --- | | Rewards for reporting near misses or hazards | Always allowed | | A rate-based incentive, such as a prize for an injury-free month | Allowed if it does not discourage reporting | | Withholding a prize or bonus because an injury was reported | No citation under 1904.35(b)(1)(iv) if adequate precautions let workers feel free to report. Saying reporting is encouraged may not be enough | | Precautions that can balance a rate-based program | Rewards for finding unsafe conditions; training on reporting rights; a way to evaluate willingness to report | | Random testing; testing unrelated to an injury report; testing required by workers' compensation law or other federal law | Allowed | | Post-incident testing to find the root cause | Allowed; test everyone whose conduct could have contributed | | Firing or disciplining someone for reporting an injury | Prohibited | ## What does section 11(c) add? Section 11(c) of the OSH Act (29 U.S.C. 660(c)) bars retaliation against workers. It protects filing a complaint, starting or testifying in a proceeding, and using any right the Act gives. The recordkeeping rule adds three more: reporting a fatality, injury or illness; filing a safety and health complaint; and asking for Part 1904 records (1904.36). - **Deadline:** file with the Secretary of Labor within 30 days after the violation occurs. OSHA notes its whistleblower laws set deadlines from 30 to 180 days. - **Process:** if the Secretary finds a violation, the Secretary sues in federal district court. Relief can include rehiring or reinstatement with back pay. - **Timing:** the Secretary must notify the complainant of the determination within 90 days of receiving the complaint. - **Filing:** oral or written, never anonymous. It must allege protected activity, employer knowledge and an adverse action. It must also allege that the activity motivated or contributed to the action. > **Which provisions can be cited** OSHA's inspector directive says 1904.36 is informational only, not a citable provision. 1904.35(b)(1)(iv) is citable. Section 11(c) is enforced through OSHA's whistleblower process. ## How should a reporting system be designed? These are practice tips, not OSHA rules. They follow the rule's test: would this deter a reasonable employee? - Let workers report on any shift, from a phone, with no sign-off first. - Show the right to report and the no-retaliation line where people report. - Acknowledge each report and show what happened next. - Keep reporting separate from discipline. Record why anyone is disciplined. - Watch reporting patterns, not just injury rates. A site where reports suddenly fall needs a look. - Offer reporting in your workforce's languages. Language support in IncidentKit is rolling out. For the culture side, read [how to get staff to report near misses](https://incidentkit.ai/blog/how-to-get-staff-to-report-near-misses) and the [near-miss reporting and safety culture guide](https://incidentkit.ai/guides/near-miss-reporting-and-safety-culture). ## What evidence shows the system works? Keep proof of what workers were told, what they reported and how you responded. - The written procedure, and when and how each worker was told (onboarding, posting, training). - Reports as first submitted, with a log of who edited what and when. - Incentive program rules and their precautions. - Your response to each complaint or concern, with dates. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | A reasonable procedure for prompt, accurate reporting ((b)(1)(i)) | Quick report takes three fields from a phone and works offline. Email-to-incident gives each site its own address. Voice reporting and other languages are rolling out. | | Tell each employee how to report and about their rights ((b)(1)(ii), (iii)) | Post a QR code per site at the dock door, break room or nurses' station. Put your right-to-report wording beside it. | | Do not discriminate for reporting; keep evidence | Role-based access limits who can view and edit a report. The audit trail shows who changed what and when. | | Notice practices that discourage reporting | Analytics cluster incidents by location, shift, equipment and cause. Roll-ups compare sites, so a quiet site stands out. | | Show that reporting leads to a fix | Routing sends each report to a named owner. Corrective actions close only when verified. | ## Frequently asked questions ### Can we run an injury-free-days incentive? Yes, if it does not discourage reporting. OSHA suggests balancing it with rewards for finding hazards, training on reporting rights, and a way to evaluate willingness to report. ### How long does an employee have to file a section 11(c) complaint? Thirty days after the violation occurs, filed with the Secretary of Labor. Other whistleblower laws OSHA administers allow 30 to 180 days, so file promptly. ### Can we drug test after an injury? Often yes. OSHA's 2018 memorandum says most post-incident drug testing is permissible, including to evaluate the root cause. Test everyone whose conduct could have contributed. Testing used to penalize a report would violate the rule. ### Does reporting through a supervisor satisfy the rule? It can, but the rule names no method. The route must not deter or discourage a reasonable employee. A supervisor-only route workers avoid out of fear could fail. ### What counts as retaliation? Discharging or in any manner discriminating against a worker for reporting an injury or illness, or for using other OSH Act rights. A complaint must allege protected activity, employer knowledge, an adverse action, and that the activity motivated or contributed to the action. ## Sources - [eCFR: 29 CFR 1904.35, Employee involvement; 1904.36, Prohibition against discrimination (current through 2026-10-01)](https://www.ecfr.gov/current/title-29/section-1904.35) - [OSHA: OSH Act section 11, including 11(c) (29 U.S.C. 660)](https://www.osha.gov/laws-regs/oshact/section_11) - [OSHA: Memorandum, Clarification of OSHA's position on workplace safety incentive programs and post-incident drug testing (2018-10-11)](https://www.osha.gov/laws-regs/standardinterpretations/2018-10-11) - [OSHA: Part 1904 Recordkeeping Policies and Procedures Directive, CPL 02-00-172](https://www.osha.gov/sites/default/files/enforcement/directives/CPL-02-00-172.pdf) - [OSHA: Online whistleblower complaint form and filing instructions](https://www.osha.gov/whistleblower/WBComplaint) - [OSHA: FAQ 35-1, informing employees how to report](https://www.osha.gov/faq/35-1) ## Related - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA 301 incident report: the 18 fields and deadlines](https://incidentkit.ai/compliance/osha/osha-301-incident-report) - [Near-miss reporting and safety culture: a practical guide](https://incidentkit.ai/guides/near-miss-reporting-and-safety-culture) - [How to get staff to report near misses (and keep doing it)](https://incidentkit.ai/blog/how-to-get-staff-to-report-near-misses) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Just culture: definition and meaning](https://incidentkit.ai/glossary/just-culture) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) --- # TRIR and DART rates: how to calculate them and what BLS 2024 national rates show > TRIR is recordable cases times 200,000, divided by hours worked. The 200,000 is 100 full-time workers at 40 hours for 50 weeks. DART counts only cases with days away, restricted work or transfer. BLS reported 2024 private industry rates of 2.3 total recordable cases and 1.4 DART cases per 100 full-time workers (release dated January 22, 2026). Source: https://incidentkit.ai/compliance/osha/trir-and-dart-rates · Updated Oct 5, 2026 ## Key facts - **TRIR formula:** Recordable cases x 200,000 / total hours worked - **DART formula:** Days-away, restriction or transfer cases x 200,000 / total hours worked - **The 200,000 base:** 100 full-time workers x 40 hours x 50 weeks - **BLS private industry, 2024:** 2.3 total recordable cases and 1.4 DART cases per 100 full-time workers - **BLS release:** Table 1, Survey of Occupational Injuries and Illnesses, released 2026-01-22 - **Latest year available:** 2024, checked 2026-10-05; 2025 data not yet published - **Citation:** OSHA Forms 300 and 300A; BLS Survey of Occupational Injuries and Illnesses, Table 1 (2024) - **Authority:** OSHA and BLS - **Applies to:** Employers that keep OSHA 300 Logs and 300A summaries, EHS and risk leaders who report rates to leadership, customers, insurers or prequalification forms, Groups comparing sites against national industry rates ## What are TRIR and DART? TRIR, the total recordable incident rate, is recordable cases per 100 full-time workers. DART is the same rate for cases with days away from work, restricted work or job transfer. OSHA calls TRIR the total case rate. BLS calls it total recordable cases. Both use a 200,000-hour base: 40 hours a week for 50 weeks for 100 full-time employees (BLS Handbook of Methods). It lets you compare a 50-person site with a 5,000-person group. ## How do you calculate them? Rate = (number of cases x 200,000) / total hours worked by all employees in the calendar year. The example below is invented for illustration. *Illustrative calculation for one establishment* | Input or result | Value | | --- | --- | | Hours worked in the year | 612,400 | | Recordable cases on the Log | 14 | | Days-away cases (column H) | 4 | | Job transfer or restriction cases (column I) | 5 | | Other recordable cases (column J) | 5 | | TRIR | 14 x 200,000 / 612,400 = 4.6 | | DART rate | (4 + 5) x 200,000 / 612,400 = 2.9 | As a cross-check, OSHA's own example uses 22 DART cases and 645,089 hours: (22 / 645,089) x 200,000 = 6.8. The free [TRIR and DART calculator](https://incidentkit.ai/tools/trir-dart-calculator) does the math. ## Which cases and hours count? Count all recordable cases for TRIR, only days-away, restricted and transferred cases for DART, and hours actually worked. - **Cases:** OSHA's data notes for the Injury Tracking Application define the total case rate as columns H, I and J of the 300 Log or 300A. DART is columns H and I. Deaths go in column G. Some forms count deaths in rates and some do not, so use the definition the form asks for. - **Hours:** count salaried, hourly, part-time and seasonal workers, plus workers you supervise, such as temps. Skip paid time not worked: vacation, sick leave, holidays. If you do not track hours, estimate them (FAQ 32-1). - **One establishment at a time:** the Log is kept per establishment, so rates start there. A company-wide rate is total cases over total hours across all establishments. ## What were the BLS national rates for 2024? BLS published 2024 estimates on January 22, 2026, in Employer-Reported Workplace Injuries and Illnesses, 2023-2024. It was the latest year available when we checked on October 5, 2026. For private industry, BLS reported 2.3 total recordable cases per 100 full-time equivalent workers, down from 2.4 in 2023, from about 2.5 million cases. BLS publishes yearly, so check for a newer release. *BLS Table 1. Incidence rates of nonfatal occupational injuries and illnesses by industry and case types, 2024, per 100 full-time equivalent workers (as published, rounded)* | Industry (NAICS) | Total recordable cases (TRIR basis) | Days away, job restriction or transfer (DART basis) | | --- | --- | --- | | Private industry | 2.3 | 1.4 | | Construction (23) | 2.2 | 1.3 | | Specialty trade contractors (238) | 2.3 | 1.4 | | Manufacturing (31-33) | 2.7 | 1.7 | | Food manufacturing (311) | 3.3 | 2.3 | | Chemical manufacturing (325) | 1.6 | 1.0 | | Utilities (22) | 1.9 | 1.2 | | Warehousing and storage (493) | 4.8 | 4.1 | | Couriers and messengers (492) | 8.0 | 6.6 | | Ambulatory health care services (621) | 2.0 | 0.7 | | Hospitals (622) | 5.1 | 2.1 | | Nursing care facilities (6231) | 6.3 | 4.5 | | Home health care services (6216) | 1.6 | 1.0 | ## How should you use these benchmarks? Carefully: compare like with like and read small samples with caution. - **Compare like with like:** same NAICS group, same measure, same year. BLS rates are survey estimates. - **Watch small denominators:** 100 full-time workers (200,000 hours) and 2 recordable cases give a TRIR of 2.0. One more case makes it 3.0. This is an invented example. - **Do not rank on rates alone:** OSHA does not validate submitted counts. It calls it inappropriate to label an establishment the most or least dangerous solely from rates. - **Pair rates with leading signals:** near-miss reports and corrective-action closure show risk before anyone is hurt. OSHA publishes establishment-level data from covered sites' electronic submissions. Customers and the public can see rates built from your 300A. See [electronic submission](https://incidentkit.ai/compliance/osha/electronic-submission). ## Where do the inputs come from? Cases come from the [OSHA 300 Log](https://incidentkit.ai/compliance/osha/osha-300-log). Hours and average employees come from payroll. Totals come from the [300A summary](https://incidentkit.ai/compliance/osha/osha-300a-summary). A misclassified case throws off every rate built on it. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Total hours worked and annual average employees on the 300A | Take these from payroll or your HRIS. Deeper HRIS integrations are rolling out. | | Classify cases consistently so rates are comparable | The incident record holds the outcome facts. A person classifies. The audit trail shows any reclassification, who and when. | | Compute and compare rates by establishment | Each site is a facility, and roll-ups compare sites. The free TRIR and DART calculator does the math. | | Look past the rate to causes | Analytics cluster incidents by location, shift, equipment and cause. Repeat patterns show whether a fix held. | | Produce the Log totals that feed the rate | OSHA 300 and 300A exports from the same record are rolling out. Today, CSV export carries the case data. | ## Frequently asked questions ### What is a good TRIR? There is no universal good number. Compare your rate with the BLS rate for your industry and year. For 2024, BLS reported 2.3 for all private industry, 2.2 for construction and 5.1 for hospitals. A rate far below peers may mean under-reporting. ### Is DART the same as LTIR? No. DART counts days-away, restricted-work and job-transfer cases. A lost-time injury rate counts only days-away cases, so it is never higher than DART. Check which one a customer asks for, because the names are used loosely. ### Why is the base 200,000 hours? It is the hours commonly regarded as worked by 100 full-time employees in a year: 40 hours a week for 50 weeks. It puts sites of any size on the same scale. ### Do contractor hours count in my rate? Only if you supervise them day to day, the same test used for recording their injuries. Include temporary staff you supervise. Leave out contractors under their own supervision. ### Where can I find the BLS rate for my industry? In Table 1 of the BLS Survey of Occupational Injuries and Illnesses, published yearly. BLS also offers a calculator at data.bls.gov/iirc. Match your NAICS code, year and measure. BLS rates are rounded estimates. ## Sources - [BLS: Employer-Reported Workplace Injuries and Illnesses, 2023-2024 (news release, 2026-01-22)](https://www.bls.gov/news.release/osh.nr0.htm) - [BLS: Table 1. Incidence rates of nonfatal occupational injuries and illnesses by industry and case types, 2024](https://www.bls.gov/iif/nonfatal-injuries-and-illnesses-tables/table-1-injury-and-illness-rates-by-industry-2024-national.htm) - [BLS: Handbook of Methods, Survey of Occupational Injuries and Illnesses, calculation of rates](https://www.bls.gov/opub/hom/soii/calculation.htm) - [BLS: Incidence Rate Calculator](https://data.bls.gov/iirc/) - [OSHA: Injury Tracking Application data, including rate calculation and data quality notes](https://www.osha.gov/itadata) - [OSHA: Part 1904 Recordkeeping Policies and Procedures Directive, CPL 02-00-172 (incidence and DART rate definition)](https://www.osha.gov/sites/default/files/enforcement/directives/CPL-02-00-172.pdf) - [OSHA: FAQ 32-1, calculating total hours worked](https://www.osha.gov/faq/32-1) ## Related - [TRIR and DART rate calculator (OSHA formula)](https://incidentkit.ai/tools/trir-dart-calculator) - [TRIR (total recordable incident rate): definition and meaning](https://incidentkit.ai/glossary/trir) - [DART rate: definition and meaning](https://incidentkit.ai/glossary/dart-rate) - [LTIR (lost-time injury rate): definition and meaning](https://incidentkit.ai/glossary/ltir) - [OSHA 300A summary: who signs, when to post, how long](https://incidentkit.ai/compliance/osha/osha-300a-summary) - [OSHA recordkeeping guide: Part 1904 for employers](https://incidentkit.ai/guides/osha-recordkeeping-guide) - [Incident reporting software for EHS managers and leads](https://incidentkit.ai/solutions/ehs-managers) --- # OSHA electronic submission (29 CFR 1904.41): who submits what, and when > Some establishments must send injury data to OSHA by March 2 each year, through the Injury Tracking Application. Form 300A covers 20 to 249 employees in Appendix A industries, and 250 or more employees. Forms 300 and 301 are added at 100 or more employees in Appendix B industries. Most small or partially exempt sites do not submit. Source: https://incidentkit.ai/compliance/osha/electronic-submission · Updated Oct 5, 2026 ## Key facts - **Rule:** 29 CFR 1904.41, as amended by the 2023 rule (88 FR 47254), effective 2024-01-01 - **Deadline:** March 2 of the year after the year covered; latest was 2026-03-02 for 2025 data - **Form 300A:** 20 to 249 employees in Appendix A industries, or 250 or more employees - **Forms 300 and 301:** 100 or more employees in Appendix B industries - **Late filing:** ITA accepts late data through December 31 - **Method:** Web form, CSV or API; Login.gov and ITA account; no paper or email - **Verified:** eCFR through 2026-10-01; OSHA ITA pages read October 2026 - **Citation:** 29 CFR 1904.41 - **Authority:** OSHA - **Applies to:** Establishments with 20 to 249 employees in the industries listed in Appendix A to Subpart E, Establishments with 250 or more employees that are required to keep records, Establishments with 100 or more employees in the industries listed in Appendix B to Subpart E, Any establishment OSHA notifies for an individual data collection ## Who must submit to OSHA electronically? Only three kinds of establishment submit routinely. Each establishment is tested alone, by its headcount at any time in the previous calendar year. *Routine electronic submission under 29 CFR 1904.41(a)* | Establishment | Submits | Paragraph | | --- | --- | --- | | Appendix A industry, 20 to 249 employees | Form 300A data | (a)(1)(i) | | 250 or more employees, and required to keep records | Form 300A data | (a)(1)(ii) | | Appendix B industry, 100 or more employees | Form 300 and 301 data, plus Form 300A | (a)(2) | | Any establishment notified by OSHA | The requested part 1904 records | (a)(3) | Count everyone employed at the establishment in the year, including part-time, seasonal and temporary workers (1904.41(b)(2)). Partially exempt establishments submit only if OSHA tells them in writing ((b)(6)). The rules also apply in State Plan states ((b)(7)). OSHA does not usually notify establishments, so check coverage yourself. ## What are the dates? March 2 each year. Late filing is accepted through December 31. *Electronic submission dates (verified against OSHA pages read in October 2026)* | Item | Date or rule | | --- | --- | | Annual deadline | March 2 of the year after the year the forms cover (1904.41(c)) | | Collection window | January 2 to March 2, as OSHA describes it | | Most recent deadline | March 2, 2026, for calendar year 2025 data | | Late filing | Still required. The ITA accepts it through December 31 | | Next deadline | March 2, 2027, for calendar year 2026 data | | Forms 300 and 301 | Collected since the 2024 submission cycle, under the 2023 rule | Posting the 300A is a separate duty. ITA submission does not replace posting it from February 1 to April 30 ([300A summary](https://incidentkit.ai/compliance/osha/osha-300a-summary)). ## How do you submit through the Injury Tracking Application? Use OSHA's free portal. There are six steps. 1. **Check coverage** Use OSHA's ITA Coverage Application or the criteria above. State Plan establishments should ask their State Plan. 2. **Create the accounts** Get an active Login.gov account and an ITA account with the same email address. 3. **Create each establishment** Enter the six-digit NAICS code for the activity that earns the most revenue or employs the most people (2012, 2017 and 2022 codes work). Add the employer identification number and the company name. 4. **Enter the 300A data** Use the web form, a CSV upload or the API. Report zeros if there were no recordable cases. 5. **Add 300 and 301 case data if you are in Appendix B** The same three methods apply. 6. **Submit and keep a record** OSHA accepts no paper or email, and PDF forms cannot be uploaded. You may edit data through December 31 of the year you submitted it. The portal is free. A corporate office or third party may submit for you. The employer stays responsible for completeness and accuracy. ## Which settings are in Appendix A and Appendix B? Hospitals, nursing homes, warehouses and plants are on at least the 300A list. Surgery centers and home health agencies are on neither. *Examples checked against Appendices A and B to Subpart E of Part 1904* | Setting (NAICS) | Form 300A at 20 to 249 employees | Forms 300 and 301 at 100 or more employees | | --- | --- | --- | | Hospitals (6221, 6222, 6223) | Yes | Yes | | Nursing care facilities (6231) and assisted living (6233) | Yes | Yes | | Home health care services (6216) | No, not listed | No, not listed. At 250 or more employees, Form 300A only | | Outpatient care centers, including ambulatory surgical centers (6214) | No, partially exempt | No, partially exempt | | Chemical manufacturing (325) | Yes, as part of manufacturing 31-33 | No | | Animal slaughtering and processing (3116) | Yes | Yes | | Warehousing and storage (4931) | Yes | Yes | | Construction (23) | Yes, all of NAICS 23 | Only foundation, structure and building exterior contractors (2381) | | Utilities (22) | Yes, all of NAICS 22 | Only water, sewage and other systems (2213) | OSHA's ITA FAQ says Appendix B status does not change when a NAICS code is renumbered. Check both appendices for your code, or use the coverage tool. ## What is submitted, left out and made public? For Forms 300 and 301, you submit everything except a few fields (1904.41(b)(9)). Leave out the employee name on the Log. On the 301, leave out the employee name and address. Leave out the name of the physician or other health care professional. Leave out the treatment facility's name and address if care was away from the worksite. OSHA says it makes most submitted data public on its ITA data website. It withholds worker age, sex, date hired, emergency room treatment and in-patient admission. Automated tools and some manual review remove other identifiers, such as names and Social Security numbers. Its data page already carries 2025 data submitted January 1 to March 15, 2026. On the [301](https://incidentkit.ai/compliance/osha/osha-301-incident-report), write narrative fields 14 to 17 with no names or other identifiers. ## What changed, and which version did we check? We checked the eCFR, current through October 1, 2026. Section 1904.41 reflects the final rule Improve Tracking of Workplace Injuries and Illnesses (88 FR 47254). It was published July 21, 2023 and took effect January 1, 2024. We found no later substantive change to 1904.41 or its appendices. - Added yearly Forms 300 and 301 for 100 or more employees in Appendix B industries. - Kept Form 300A for 20 to 249 employees in Appendix A industries and for 250 or more. - Updated Appendix A NAICS codes, added Appendix B, and required the company name. - OSHA first collected Form 300A data through the ITA in 2016. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | Submit Form 300A data by March 2 ((a)(1)) | IncidentKit does not submit to the ITA. OSHA 300A generation is rolling out. Today, CSV export gives you case data for your own submission. | | Submit 300 and 301 case data without names and identifiers ((b)(9)) | Lauren drafts narrative fields from the account ('Lauren · draft'). A reviewer approves them and removes identifiers. OSHA 300 and 301 exports are rolling out. | | One submission per establishment, with EIN and company name | Each site is a facility, so establishment data stay apart from group roll-ups. A read API and CSV export feed your own pipelines. | | Correct submitted data through December 31 | The audit trail logs each change with who, when, and before and after. | | Keep the Log, the posted 300A and the submission consistent | One record feeds all three once the OSHA exports roll out, so numbers agree. | ## Frequently asked questions ### Is the March 2 deadline the same for Forms 300 and 301? Yes. Forms 300 and 301 go in the same annual collection as Form 300A, due March 2 of the year after the year they cover. ### We have 250 or more employees but are in a partially exempt industry. Do we submit? No, not routinely. The 250-employee category applies only where Part 1904 requires the establishment to keep records. A partially exempt establishment submits only if OSHA tells it in writing, and then it must keep the records. ### What if we missed the March 2 deadline? Submit anyway. The ITA accepts late data until December 31, but OSHA takes no mail or email. Once a new collection period starts, you cannot edit or add data for years before last year. ### Does submitting to OSHA replace posting the 300A? No. ITA submission is separate from the posting rule in 1904.32, so a covered establishment does both. Post the 300A from February 1 to April 30 of the year after the year it covers. ## Sources - [eCFR: 29 CFR 1904.41, Electronic submission of EIN and injury and illness records to OSHA (current through 2026-10-01)](https://www.ecfr.gov/current/title-29/section-1904.41) - [OSHA: Injury Tracking Application (ITA) information and coverage](https://www.osha.gov/injuryreporting) - [OSHA: Injury Tracking Application frequently asked questions](https://www.osha.gov/injuryreporting/faqs) - [OSHA: Appendix A to Subpart E of Part 1904, designated industries for Form 300A submission](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904SubpartEAppA) - [OSHA: Appendix B to Subpart E of Part 1904, designated industries for Form 300 and 301 submission](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904SubpartEAppB) - [OSHA: Injury Tracking Application data (public datasets)](https://www.osha.gov/itadata) - [Federal Register: Improve Tracking of Workplace Injuries and Illnesses, 88 FR 47254 (2023-07-21)](https://www.federalregister.gov/documents/2023/07/21/2023-15091/improve-tracking-of-workplace-injuries-and-illnesses) - [OSHA: Recordkeeping requirements overview](https://www.osha.gov/recordkeeping) ## Related - [OSHA 300A summary: who signs, when to post, how long](https://incidentkit.ai/compliance/osha/osha-300a-summary) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [OSHA 301 incident report: the 18 fields and deadlines](https://incidentkit.ai/compliance/osha/osha-301-incident-report) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [TRIR and DART rates: formula, example and BLS 2024 rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates) - [OSHA 300 Log Automation: Keep It Accurate Year-Round](https://incidentkit.ai/use-cases/osha-300-log-automation) - [OSHA recordkeeping guide: Part 1904 for employers](https://incidentkit.ai/guides/osha-recordkeeping-guide) --- # Construction recordkeeping: how OSHA Part 1904 applies to job sites and subcontractors > Construction is not partially exempt, so contractors with more than 10 employees keep OSHA records. A job site that will last a year or longer is its own establishment with its own 300 Log. Shorter jobs can share one log. The employer that supervises a worker day to day records and reports that worker's injuries, whatever the contract says. Source: https://incidentkit.ai/compliance/osha/construction-recordkeeping · Updated Oct 5, 2026 ## Key facts - **Rules:** 29 CFR 1904.30 (multiple establishments), 1904.31 (covered employees), 1904.46 (establishment) - **Exemption:** Construction (NAICS 23) is not partially exempt - **Long projects:** A site expected to last a year or more keeps its own 300 Log - **Short projects:** One Log may cover all sites under a year, or those of a division or region - **Who records:** The employer giving day-to-day supervision, whatever the contract says - **Work zones:** Public-road crashes are reportable only in a construction work zone - **BLS 2024 rate:** Construction 2.2 total recordable cases and 1.3 DART cases per 100 full-time workers - **Citation:** 29 CFR 1904.30, 1904.31 and 1904.46 - **Authority:** OSHA - **Applies to:** General contractors, specialty trade contractors and construction managers with more than 10 employees, Contractors with temporary or multi-state job sites, Subcontractors and staffing agencies that supply workers to job sites ## How does Part 1904 apply to construction contractors? It applies as it does to any employer, with special rules for job sites that move. Construction (NAICS 23) is not on the partially exempt list. A contractor with more than 10 employees at any time last year keeps Forms 300, 300A and 301 (1904.1, 1904.2). The reporting duties in 1904.39 apply to every contractor, even those with 10 or fewer employees. State Plan states must use the same recordability rules. They may be stricter elsewhere, such as on reporting deadlines (FAQ 37-2). See the [recordkeeping overview](https://incidentkit.ai/compliance/osha/recordkeeping-overview). ## What is an establishment on a job site? For work with no single location, such as construction, the establishment is the office or other base. It is the base that supervises the work or sends people out (1904.46). Whether a temporary job site is its own establishment depends on how long it will last (CPL 02-00-172). *Which 300 Log covers a job site (29 CFR 1904.30 and CPL 02-00-172)* | Situation | Which Log | Where it can be kept | | --- | --- | --- | | Project expected to last a year or more | A separate 300 Log for that site | On site or at a central location, if the 7-day and prompt-access conditions below are met | | Project expected to last under a year | One 300 Log may cover all short-term sites, or those of a company division or region | On site or at a central location, on the same conditions | | Employee who works across several sites | Linked to one establishment. A case at another of your establishments goes on that one's Log. A case away from any establishment goes on the Log where the employee normally works | As above | OSHA's example: a multi-state contractor might keep a Log per state for short-term projects. It would also keep a separate Log for each project expected to last more than a year. ## Who records subcontractor and temporary workers' injuries? The employer that supervises the work day to day, whatever the contract says. That means supervising the details, means, methods and processes of the work. Specifying the output is not enough (1904.31; FAQ 31-1). OSHA's directive says the actual facts decide, not contract language. Employers should coordinate so each case is recorded once. *Illustrative supervision calls* | Situation | Who records and reports | | --- | --- | | A subcontractor's crew works under its own foremen | The subcontractor | | Laborers from a staffing agency are directed task by task by your superintendent | You, as the supervising employer | | A general contractor sets the result and schedule, but the subcontractor controls how the work is done | The subcontractor. Specifying the result alone is not day-to-day supervision | | Agency workers are supervised by the agency's own site lead | The agency, even if the host is not covered by the recordkeeping rule (FAQ 31-2) | The same supervising employer makes the 8-hour and 24-hour reports under 1904.39 (FAQ 39-9). See [contractor and visitor incidents](https://incidentkit.ai/use-cases/contractor-and-visitor-incidents). ## What changes for severe injury reports and the 300A? Work-zone crashes are reportable, and posting follows each establishment that keeps a Log. - **Work zones:** a crash on a public street or highway is not reportable, unless it happens in a construction work zone (1904.39(b)(3)). The zone runs from the first warning sign or vehicle lights. It ends at the END ROAD WORK sign or last temporary traffic control device (FAQ 39-2). - **Posting the 300A:** post it at each establishment where you keep a Log, from February 1 to April 30 (FAQ 30-1). For one Log covering several short-term sites, ask your OSHA area office or State Plan how to post. - **Central records:** you may keep Logs at the home office if cases reach it within 7 calendar days. Produce records within 4 business hours for the government. Produce them by the end of the next business day for employees and representatives. The full deadlines are in [severe injury reporting](https://incidentkit.ai/compliance/osha/severe-injury-reporting). ## Which other standards work differently on a job site? Lockout/tagout and hazard communication follow Part 1926 rules. *Related standards for construction* | Topic | Construction rule | | --- | --- | | Lockout/tagout | 1910.147 excludes construction. 1926.417 covers tagging of controls and of deenergized equipment or circuits | | Hazard communication | 1926.59 says the construction requirements are identical to 1910.1200. A host employer's program must tell other employers' workers how to reach SDSs, what precautions apply and how containers are labeled (1910.1200(e)(2)) | | Construction standards on OSHA's overall top 10 most cited list, fiscal year 2025 | Fall protection (1926.501), ladders (1926.1053), scaffolding (1926.451), fall protection training (1926.503) and eye and face protection (1926.102) | ## How do electronic submission and national rates apply? All of NAICS 23 is in Appendix A. Construction establishments with 20 to 249 employees submit Form 300A. So do those with 250 or more. Only NAICS 2381, foundation, structure and building exterior contractors, is also in Appendix B. Only those establishments with 100 or more employees also submit Forms 300 and 301. Count each establishment alone, using everyone employed there at any time in the year. Ask your area office or OSHA's ITA help form how to count temporary sites. See [electronic submission](https://incidentkit.ai/compliance/osha/electronic-submission). *BLS Table 1, 2024, per 100 full-time equivalent workers* | Industry | Total recordable cases | Days away, restriction or transfer | | --- | --- | --- | | Construction (23) | 2.2 | 1.3 | | Specialty trade contractors (238) | 2.3 | 1.4 | | Private industry | 2.3 | 1.4 | The formula and more industries are on the [TRIR and DART rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates) page. ## What the rule asks for, and how IncidentKit supports it | Requirement | IncidentKit | | --- | --- | | A separate Log for each long project and a shared Log for short-term sites | Model each project of a year or longer as its own facility. Group short-term projects under a regional facility. Each facility has its own staff, routing and pack. | | The day-to-day supervisor records and reports | Capture who directed the work in the incident record, so the right employer logs and reports it. Contractor and visitor incidents are a supported use case. | | Report from the field quickly | Post a QR code per site at the gate or trailer. Quick report takes three fields from a phone, works without signal and becomes a full incident record. | | 8-hour and 24-hour reports, including work-zone crashes | Severity sets priority, and types that start a reporting clock flag the deadline. Escalation timers move unacknowledged events on. Automated reportability rules are rolling out. | | Forms 300, 300A and 301 | OSHA 300, 300A and 301 exports are rolling out, and so are construction packs. The core incident workflow runs now. | | Find patterns across projects | Analytics cluster incidents by location, shift, equipment and cause. Organization roll-ups compare projects. | ## Frequently asked questions ### Do I need a separate OSHA 300 Log for every job site? Only for sites expected to last a year or more. Shorter sites need records but not a separate Log. One Log can cover all short-term sites, or those of a division or region. Link every employee to one establishment. ### Who records an injury to a subcontractor's employee on my site? The employer that supervises the worker day to day. If the subcontractor's own foremen direct the work, the subcontractor records it. If you supervise the details, means, methods and processes, you do, whatever the contract says. Coordinate so the case is recorded once. ### Is a crash in a highway work zone reportable to OSHA? Yes, if it results in a fatality, in-patient hospitalization, amputation or loss of an eye within the usual windows. Crashes on public streets and highways are normally exempt. Crashes in a construction work zone are not. ### Does lockout/tagout apply to construction? Not under 1910.147, which excludes construction and agriculture. On construction sites, 1926.417 requires tagging of controls and of deenergized equipment or circuits where they can be energized. Other Part 1926 standards cover other hazards, so confirm which apply. ## Sources - [eCFR: 29 CFR 1904.30, Multiple business establishments; 1904.31, Covered employees; 1904.46, Definitions (current through 2026-10-01)](https://www.ecfr.gov/current/title-29/part-1904) - [OSHA: Part 1904 Recordkeeping Policies and Procedures Directive, CPL 02-00-172 (temporary worksites, multi-employer circumstances)](https://www.osha.gov/sites/default/files/enforcement/directives/CPL-02-00-172.pdf) - [OSHA: FAQ 31-1, day-to-day supervision](https://www.osha.gov/faq/31-1) - [OSHA: FAQ 39-2, construction work zone](https://www.osha.gov/faq/39-2) - [OSHA: Appendix A to Subpart E of Part 1904 (includes NAICS 23)](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904SubpartEAppA) - [OSHA: Appendix B to Subpart E of Part 1904 (includes NAICS 2381)](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904SubpartEAppB) - [BLS: Table 1. Incidence rates of nonfatal occupational injuries and illnesses by industry and case types, 2024](https://www.bls.gov/iif/nonfatal-injuries-and-illnesses-tables/table-1-injury-and-illness-rates-by-industry-2024-national.htm) - [OSHA: Top 10 most frequently cited standards, fiscal year 2025](https://www.osha.gov/top10citedstandards) ## Related - [Construction incident reporting for job sites and subs](https://incidentkit.ai/solutions/construction) - [Contractor and Visitor Incidents: Who Reports What](https://incidentkit.ai/use-cases/contractor-and-visitor-incidents) - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [TRIR and DART rates: formula, example and BLS 2024 rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates) - [Mobile incident reporting that works offline](https://incidentkit.ai/product/mobile-and-offline) --- # IncidentKit vs RLDatix: honest comparison > How IncidentKit and RLDatix differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/rldatix · Updated Oct 5, 2026 **RLDatix**: RLD360, a healthcare platform that joins safety and risk with provider management, compliance and patient experience. RLDatix sells RLD360, a modular platform for hospitals and health systems. It pairs safety and risk tools (event reporting, root cause analysis, risk registers, claims) with credentialing, policy management, audits and patient experience. In the UK the incident product is DatixCloudIQ. KLAS lists its products as RL6 and PolicyStat. In August 2025 it announced Smart Entry, an AI tool that turns a written account into a pre-filled report. **Best for:** Hospitals, health systems and delivery networks, plus public health and aged-care bodies elsewhere. No surgery center or nursing home package was found. **Ownership:** Private-equity backed. In January 2022 RLDatix said Five Arrows and TA Associates kept a majority stake and Nordic Capital took a minority stake. No later change was found. **Scale (company-reported):** RLDatix's About page (read 2026-10-05) says it serves more than 10,000 organizations in 30+ countries, with team members in 8 countries. A January 2022 announcement cited more than 5,000 customers in 20+ countries. The figures are from different dates. ## Pricing - **Model:** Priced by quote and sold through sales. Modular, with RLDatix consultants leading setup. - **Published:** no - No North American price list was found. The UK G-Cloud 15 listing for DatixCloudIQ (public sector buyers) shows 2.21 to 32.41 GBP per licence per year, an implementation service with a three-month hand-hold after go-live, and no free trial. That is a UK listing, not a US quote. ## Feature comparison | Feature | IncidentKit | RLDatix | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | No: Buyers go to a demo. The UK listing describes setup led by consultants, training and user acceptance testing. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | No: None on the North American site. A UK G-Cloud listing shows a per licence range for public sector buyers. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | No: The UK G-Cloud listing says no free trial. No free plan is advertised in North America. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Yes: Smart Entry (announced 2025-08-18) turns a written account into a pre-filled, classified report. RLDatix says it cuts reporting time by up to 70 percent. It does not say whether a person reviews AI-filled fields. | | Voice reporting | Rolling out: Voice intake is rolling out. | Partial: The UK listing says the Datix Anywhere app turns speech into text. North American pages and the Smart Entry announcement do not mention voice. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: Per the UK listing, Datix Anywhere works offline, takes photos and opens forms by QR code. North American pages say any device can capture events. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Yes: Built-in root cause tools with healthcare templates and evidence tracking. Sold as a separate module. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Yes: Event management is described as closed-loop, with owners and timelines. Root cause tools assign owners, track fixes and report whether they worked. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Partial: The Audits and Standards module lists 400+ standards (CMS, Joint Commission, DNV, ACHC, CIHQ), with rounds and mock surveys. QAPI committee reporting is not described. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Not stated publicly: OSHA 300, 300A and 301 are not described on the event, root cause or audit pages reviewed. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: The event reporting page describes setup for many sites and countries. The North American page targets health systems. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Yes: The UK listing describes REST and GraphQL APIs, a sandbox and Active Directory sign-in. No North American API documentation was found. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: A business associate agreement is not mentioned on the public pages reviewed. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## RLDatix strengths - One vendor covers event reporting, root cause, risk register, claims and feedback on one data model, RLDatix says. - KLAS surveyed 69 organizations about RLDatix in 2025, the largest sample in its table. RLDatix reports Duke Health's monthly events rose from 1,900 to 2,300 in three years. - Already ships AI intake (Smart Entry), which few established suites describe publicly. - Accreditation content beside incident data: 400+ standards for CMS, Joint Commission, DNV, ACHC and CIHQ. - Highly configurable: a local admin or RLDatix consultants can change forms, workflows, reports and alerts (UK listing). ## Trade-offs to weigh - Buying is by quote through sales, with no published North American price. - Modular platform (credentialing, scheduling, contracts, surveys). Teams that only need incidents must scope it with care. - North American focus is hospitals and health systems. No surgery center, nursing home or home health package was found. - Per the UK listing, consultants lead setup, a heavier start than a tool you set up yourself. - Public detail on OSHA recordkeeping, BAA terms and human review of Smart Entry output is thin. ## Choose RLDatix if - You are a health system that wants incident, risk, claims, credentialing and policy tools from one vendor. - You want accreditation standards and mock surveys beside incident data. - You work in several countries, or need UK-hosted options or public sector contract vehicles. - You want many large health-system references and setup led by consultants. ## Choose IncidentKit if - You run surgery centers, nursing homes, home health, hospice or behavioral health sites and want a pack for that setting. - You want published per site pricing, a BAA on the regulated plan, and no seats, modules or setup fee. - You want staff to tell [Lauren](https://incidentkit.ai/product/lauren) what happened, with every AI draft marked until a person approves. - You want actions that cannot close until verified, and QAPI and survey packets from the same records. ## Switching - You need incident reporting, not claims and credentialing. - Small groups want public per site pricing and easy setup. - Long forms are slow, and the team wants guided intake a person signs. Ask RLDatix for exports of incidents, investigations, actions and attachments, with dates and record IDs intact. The UK listing says exports come as CSV, Excel, PDF or XML, and help beyond built-in tools may be charged. IncidentKit imports CSV history and offers migration done for you. See [import and migration](https://incidentkit.ai/product/import-and-migration). ## Frequently asked questions ### How does RLDatix price its software? RLDatix does not publish North American prices. Buyers get a quote after a demo, and the total depends on the modules and facilities you add. A UK public sector listing for DatixCloudIQ shows 2.21 to 32.41 GBP per licence per year, a different market. ### Does RLDatix offer AI incident reporting? Yes. Announced 18 August 2025, Smart Entry pre-fills and classifies an event report from a written account. RLDatix says it cuts reporting time by up to 70 percent. It does not say whether a person reviews AI-filled fields, which languages it supports or its price. ### Is RLDatix a fit for a surgery center or nursing home? RLDatix's North American pages speak mainly to hospitals and health systems, and no surgery center or nursing home package was found. It publishes an ambulatory case study with ChristianaCare, a health system. A single site should ask what setup includes and costs. ### Who owns RLDatix? RLDatix is private equity backed. In January 2022 it said Five Arrows and TA Associates kept a majority stake and Nordic Capital took a minority stake. Ownership may have changed since, so confirm it. Its press page lists the 2025 acquisition of IPeople Healthcare. ### How does KLAS rate RLDatix? In KLAS's 2025 ranking for healthcare safety, risk and compliance, RLDatix (RL6 and PolicyStat) scored 84.6 out of 100 from 69 organizations, third of six, above the 83.9 market average. KLAS scores reflect customer interviews, not features, and sample sizes differ. ## Sources - [RLDatix: About us (scale, customers by country)](https://www.rldatix.com/en-nam/company/about-us/) - [RLDatix: Risk and Safety event reporting (North America)](https://www.rldatix.com/en-nam/risk-and-safety-on-rld360/event-reporting/) - [RLDatix: Event reporting module overview (multi-site, multi-country)](https://www.rldatix.com/en-mea/solution/event-reporting/) - [RLDatix: Root cause analysis module](https://www.rldatix.com/en-nam/module/root-cause-analysis/) - [RLDatix: Audits and standards module](https://www.rldatix.com/en-nam/module/audits-standards/) - [RLDatix: Smart Entry AI launch announcement (2025-08-18)](https://www.rldatix.com/en-nam/company/news/rldatix-launches-ai-smart-entry-to-advance-event-reporting-and-risk-management/) - [RLDatix: Nordic Capital investment announcement (January 2022)](https://www.rldatix.com/en-nam/?p=4384) - [RLDatix: Press releases](https://www.rldatix.com/en-nam/company/press-releases/) - [RLDatix: ChristianaCare ambulatory case study](https://www.rldatix.com/en-nam/resources/rldatix-solution-helped-program-boost-ambulatory-safety-quality/) - [UK Digital Marketplace: DatixCloudIQ listing (G-Cloud 15)](https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/831100385216385) - [UK Digital Marketplace: DatixCloudIQ governance, risk and compliance listing](https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/144884631471733) - [KLAS: 2025 Best in KLAS, Healthcare Safety, Risk and Compliance Management](https://klasresearch.com/best-in-klas-ranking/healthcare-safety-risk-and-compliance-management/2025/420) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs Origami Risk: honest comparison > How IncidentKit and Origami Risk differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/origami-risk · Updated Oct 5, 2026 **Origami Risk**: A configurable cloud platform for risk, safety and insurance, with a healthcare line for patient safety and claims. Origami Risk is a cloud platform that grew out of risk management systems. It covers claims and policy administration, environmental health and safety, compliance, and a healthcare line for patient safety, claims, peer review and employee health. Staff can report by app, QR code, portal or anonymous link. Origami says its AI features are opt in. **Best for:** Health systems, surgery centers, senior living, insurers, third party administrators, risk pools, public entities and employers. Strongest where incidents connect to claims and insurance. **Ownership:** Privately held. The latest ownership news found is a 2018 minority investment from Spectrum Equity. No later change was found. ## Pricing - **Model:** Priced by quote and sold through sales. Scope depends on solutions, sites and integrations. - **Published:** no - No prices are published; the public path is a demo request. Origami sells incidents, claims, EHS, GRC and insurance as solutions on one platform. Ask for healthcare pieces and EHS pieces, such as OSHA recordkeeping, itemized. ## Feature comparison | Feature | IncidentKit | Origami Risk | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | No: Public calls to action are demo requests. You cannot sign up on your own. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | No: No prices or plan tiers on the public site. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | Not stated publicly: No free plan or trial is mentioned on the pages reviewed. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Not stated publicly: AI appears across the platform, such as workflow summaries, claims summaries and analytics, and in routing for healthcare events. Intake that turns a narrative into a report is not described. | | Voice reporting | Rolling out: Voice intake is rolling out. | Not stated publicly: Voice reporting is not mentioned on the pages reviewed. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: A mobile app for incidents and audits. Reports also come in by QR code, secure portal or anonymous link, with photos, video and files. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Yes: Investigations include root cause analysis. The healthcare page lists it under patient safety and quality. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Yes: Investigations can assign corrective actions and track progress. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Partial: The healthcare page cites compliance workflows for CMS, Joint Commission, OSHA and HIPAA. QAPI summaries are not described. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Yes: The EHS solution lists OSHA 300, 300A and 301 forms and electronic submission. It is separate from patient safety, so confirm it is in your quote. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: The healthcare page describes risk and compliance across 50+ locations, with benchmarking. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Yes: REST APIs, developer docs and Databricks Delta Sharing are described. Okta lists SAML and OIDC single sign-on (SSO). | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: BAA terms are not stated on the public pages reviewed. Origami's trust center could not be read without scripts. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## Origami Risk strengths - Incident data can feed claims, insurance and EHS in one system, which suits groups that self insure or run captives. - Origami says it earned the top client satisfaction score in Redhand Advisors' 2025 RMIS Report (net promoter score 64). KLAS gives its loyalty an A. - An Epic link lets a care provider launch an incident from the patient record, with patient and encounter details carried over. - Many ways to report: app, QR code, portal and anonymous link, with forms that prefill from HR and payroll. - Covers staff injury recordkeeping through EHS (OSHA 300, 300A, 301) beside patient safety events. ## Trade-offs to weigh - No published pricing and no way to start without sales. - A broad platform, so teams that only need incidents buy into more. - Public AI material centers on claims and analytics. AI at incident intake is not described. - No setting packs are published for surgery centers or senior living, so expect to configure. - BAA terms and SSO setup details are not visible without sales. ## Choose Origami Risk if - You are a system with many hospitals, or one that self insures, and want incidents tied to claims and insurance. - You use Epic and want clinicians to launch incidents from the chart. - You need OSHA records and patient safety events on one platform and can staff its setup. - You want analyst recognition and a broad suite to grow into. ## Choose IncidentKit if - You run surgery centers, nursing homes, home health, hospice or behavioral health sites and want packs for them. - You want per site pricing you can read, a BAA on the regulated plan and setup done for you. - You want [Lauren](https://incidentkit.ai/product/lauren) to take a plain account and draft the report for a person to sign. - You want incident reporting through verified corrective action without claims or insurance software. ## Switching - You outgrew spreadsheets but not into a risk platform. - Sites need healthcare packs set up for them. - The team wants public pricing and a lighter start. Origami does not publish export formats for incident records. Ask your administrator for incidents, investigations, actions and attachments with dates and IDs kept. IncidentKit imports CSV history and sets up migration for you. See [import and migration](https://incidentkit.ai/product/import-and-migration). ## Frequently asked questions ### How does Origami Risk price its software? Origami Risk does not publish prices. Buyers get a quote after a demo. It depends on the solutions, sites and integrations you include, so ask for healthcare modules and any EHS OSHA tools itemized. ### Does Origami Risk integrate with Epic? Origami describes an Epic link for Patient Safety and Quality. A care provider launches an incident from the patient record, and name, birth date and encounter details carry over. Confirm which Epic versions and fields apply. ### Does Origami Risk have AI for incident reporting? Origami describes AI across its platform, but intake that turns a narrative into a report is not described. It cites workflow summaries, Email Assist, claims summaries, analytics and routing. Origami says AI is opt in. ### Can Origami Risk handle OSHA logs and patient safety events together? Yes, if both are in your quote. OSHA 300, 300A and 301 forms sit in EHS, and event reporting and root cause analysis sit in healthcare, on one platform. Ask for them scoped together, with roles that keep injury records apart from patient events. ### How does KLAS rate Origami Risk? In KLAS's 2025 ranking, Origami Risk Platform scored 82.1 out of 100 from 17 organizations, fourth of six, against an 83.9 market average, with a loyalty grade of A. Origami also cites the Redhand Advisors 2025 RMIS Report for client satisfaction. ## Sources - [Origami Risk: home page](https://www.origamirisk.com/) - [Origami Risk: healthcare solutions](https://www.origamirisk.com/industries/healthcare/) - [Origami Risk: incidents and events management](https://www.origamirisk.com/risk/incident-management-systems) - [Origami Risk: environment, health and safety](https://www.origamirisk.com/risk/ehs/) - [Origami Risk: API access and integrations](https://www.origamirisk.com/platform/api-access/) - [Origami Risk: Epic EMR-to-incident launch](https://www.origamirisk.com/resources/insights/solution-showcase-epic-emr-origami-incident-launch-reducing-manual-entry) - [Origami Risk: AI sell sheet (August 2025)](https://www.origamirisk.com/wp-content/uploads/2023/08/OrigamiRisk_SellSheet_Origami-Risk-AI_20250829.pdf) - [Origami Risk: Spring 2026 release](https://www.origamirisk.com/platform/innovation-spring-2026) - [Origami Risk: private equity and the RMIS market (Spectrum Equity investment)](https://www.origamirisk.com/resources/news/private-equity-and-rmis-market) - [Origami Risk press release on the 2025 RMIS Report (2025-05-05)](https://www.silicon.co.uk/press-release/origami-risk-earns-top-client-satisfaction-score-in-annual-rmis-report-for-sixth-consecutive-year) - [Okta Integration Network: Origami Risk](https://www.okta.com/integrations/origamirisk/) - [KLAS: 2025 Best in KLAS, Healthcare Safety, Risk and Compliance Management](https://klasresearch.com/best-in-klas-ranking/healthcare-safety-risk-and-compliance-management/2025/420) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs Riskonnect: honest comparison > How IncidentKit and Riskonnect differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/riskonnect · Updated Oct 5, 2026 **Riskonnect**: Integrated risk software to start anywhere and expand, with a healthcare line for patient safety and claims. Riskonnect sells integrated risk software in three families. They are insurable risk (claims, policy, health and safety), governance risk and compliance, and business continuity. Its healthcare line covers patient safety event reporting, root cause analysis with fishbone diagrams, provider quality and compliance. It has versions for ambulatory and long term care. It has added AI that classifies events, forecasts severity and summarizes reports. A customer says it runs on the Salesforce Force platform. **Best for:** Hospitals and health systems, plus companies with insurable risk, such as hotels, restaurants and transport firms. The ambulatory and long term care fact sheets date from 2020 and 2021. **Ownership:** Private equity backed. A January 2024 press release names TA Associates as majority investor. No later change was found. **Scale (company-reported):** Riskonnect's About page (read 2026-10-05) says it serves more than 2,000 organizations on six continents with 800+ team members. A July 2026 fact sheet cites 2,700+ customers and 1,500+ risk experts, so its own counts differ. No healthcare-only count was found. ## Pricing - **Model:** Modular licensing priced by quote ('start anywhere, expand everywhere'), plus a separate setup package. - **Published:** no - No healthcare prices are published. The GoLive page lists Essentials (under 2 months, fixed fee), Pro Configuration (2 to 6 months, fixed fee) and Tailored Configuration (4 to 10+ months, time and materials). A UK G-Cloud 15 price document from January 2026 covers a different product, Active Risk Manager. ## Feature comparison | Feature | IncidentKit | Riskonnect | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | No: Public path is a demo and sales contact. Setup runs through GoLive packages. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | No: No healthcare pricing is published. A UK public sector listing prices a different product. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | Not stated publicly: No free plan or trial is mentioned on the pages reviewed. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Partial: Described: predictive classification, severity forecasts, one click summaries, intake automation, and a Patient Event Assessment agent on Agentforce. Intake that turns a narrative into a report is not described. | | Voice reporting | Rolling out: Voice intake is rolling out. | Partial: The 2020 and 2021 ambulatory and long term care fact sheets mention dictation. Current healthcare pages do not. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: Events can be captured from any device, anonymously or identified. Complaints can come in by QR code, hotline or link. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Yes: Standard root cause analysis with a fishbone diagram, linking claim, incident, occurrence and cause data. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Yes: The patient safety page lists corrective and preventive action workflow. The Health and Safety product lists CAPA management. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Partial: Audit status views for accreditation, environment of care, infection control and hand hygiene. It also tracks HIPAA and state and federal reporting. QAPI summaries are not described. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Yes: The Health and Safety product (July 2026 fact sheet) lists OSHA compliance, recordable tracking and submission. It is separate from the patient safety line. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: Multiple facilities are supported, per the patient safety event reporting page. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Partial: An 'APIs and Integration Solutions' offering is listed, and a fact sheet cites Epic and Cerner links. Single sign-on (SSO) was not described. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: A BAA is not mentioned on the pages reviewed. The security page lists SOC 2 Type 2, SSAE 16 and ISAE 3401. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## Riskonnect strengths - Healthcare event reporting with ambulatory and long term care versions, plus Epic and Cerner links. - AI is already described for patient safety. It classifies events, forecasts severity and gives one click summaries. - Room to grow: claims, third party risk, business continuity and a Health and Safety product with OSHA tools. - A vendor story reports a 322 percent first year rise in reporting at one suburban health group. KLAS ranks it second of six in 2025. - Published attestations: SOC 2 Type 2, SSAE 16 Type 1 and 2, and ISAE 3401, with AES-256 encryption at rest. ## Trade-offs to weigh - No published pricing. Riskonnect's own setup estimate runs from under two months to ten or more. - An enterprise platform with many product families, so incident reporting is a small part. - The ambulatory and long term care fact sheets date from 2020 and 2021. Check what ships today. - Its own customer and employee counts differ. No healthcare-only count was found. - BAA terms and SSO are not stated, and QAPI summaries are not described. ## Choose Riskonnect if - You are a health system that wants patient safety, claims, provider quality and enterprise risk in one platform. - You use Epic or Cerner and want incident entry tied to the record. - You want an OSHA capable Health and Safety product from the same vendor. - You want predictive classification and have budget for an enterprise rollout. ## Choose IncidentKit if - You run surgery centers, nursing homes, home health, hospice or behavioral health sites and want packs for them. - You want published per site pricing, a BAA on the regulated plan and setup done for you, not months of rollout. - You want staff to tell [Lauren](https://incidentkit.ai/product/lauren) what happened, with AI drafts marked until a person signs. - You want QAPI summaries and survey packets from the same records. ## Switching - You need incident reporting, not a full risk platform. - Setup scope is hard to justify for single sites. - Pricing by quote only slows budgeting. Riskonnect does not publish export formats for incident records. Ask for incidents, investigations, actions and attachments with dates and IDs kept. IncidentKit imports CSV history and sets up migration for you. See [import and migration](https://incidentkit.ai/product/import-and-migration). ## Frequently asked questions ### How does Riskonnect price its software? Riskonnect does not publish healthcare prices. Buyers get a quote for modular licensing after a demo. Setup options are published: Essentials (under two months), Pro Configuration (two to six months) and Tailored Configuration (four to ten or more months). A UK G-Cloud price list covers a different product. ### Does Riskonnect use AI for patient safety events? In part. Riskonnect describes predictive classification, severity forecasts, one click summaries and a Patient Event Assessment agent on Agentforce. Intake that turns a narrative into a report is not described, so ask what is live. ### How long does a Riskonnect implementation take? Riskonnect's GoLive page lists three setup options. Essentials takes under two months and needs no configuration. Pro Configuration takes two to six months and tailors within best practices. Tailored Configuration takes four to ten or more months and adds custom functions. ### Does Riskonnect support surgery centers and nursing homes? Riskonnect publishes ambulatory and long term care fact sheets, but both date from 2020 and 2021, and the main healthcare page speaks to hospitals. Ask for a current demo and a single site price. ### Does Riskonnect support OSHA recordkeeping? Yes, through a separate product. A July 2026 fact sheet says its Health and Safety product covers OSHA compliance, recordable tracking and submission. Confirm it is in a healthcare quote. ## Sources - [Riskonnect: home page](https://riskonnect.com/) - [Riskonnect: About us](https://riskonnect.com/about-us/) - [Riskonnect: healthcare risk management](https://riskonnect.com/who-we-serve/healthcare-risk-management/) - [Riskonnect: patient safety event reporting](https://riskonnect.com/who-we-serve/healthcare-risk-software/patient-safety-event-reporting/) - [Riskonnect: patient safety fact sheet (PDF)](https://go.riskonnect.com/hubfs/Riskonnect/Healthcare__Patient_Safety_Fact_Sheet.pdf) - [Riskonnect: ambulatory care event reporting fact sheet (PDF, 2020)](https://go.riskonnect.com/hubfs/Riskonnect/Healthcare___Ambulatory_Care_Event_Reporting.pdf) - [Riskonnect: long-term care event reporting fact sheet (PDF, 2021)](https://go.riskonnect.com/hubfs/Riskonnect/Healthcare___Long_Term_Care_Event_Reporting_.pdf) - [Riskonnect: Health and Safety software fact sheet (PDF, July 2026)](https://go.riskonnect.com/hubfs/Riskonnect/Riskonnect_Health___Safety_software.pdf) - [Riskonnect: GoLive implementation options](https://riskonnect.com/en-gb/golive/) - [Riskonnect: platform security](https://riskonnect.com/en-gb/platform-security/) - [Riskonnect: Agentforce for Riskonnect AI agents](https://riskonnect.com/?p=150453) - [Riskonnect: acquisition of Ventiv Technology (2024-01-11, ownership statement)](https://riskonnect.com/press/riskonnect-acquires-ventiv-technology/) - [UK Digital Marketplace: Riskonnect Active Risk Manager G-Cloud 15 pricing document (PDF)](https://assets.applytosupply.digitalmarketplace.service.gov.uk/g-cloud-15/documents/702567/887663409111894-pricing-document-2026-01-21-2020.pdf) - [KLAS: 2025 Best in KLAS, Healthcare Safety, Risk and Compliance Management](https://klasresearch.com/best-in-klas-ranking/healthcare-safety-risk-and-compliance-management/2025/420) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs symplr: honest comparison > How IncidentKit and symplr differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/symplr · Updated Oct 5, 2026 **symplr**: Enterprise operations software for hospitals, health systems and health plans, with symplr Safety for incident reporting. symplr sells enterprise operations software to hospitals, health systems and health plans: workforce and scheduling, provider data and credentialing, compliance, and quality and safety. symplr Safety is its incident and event reporting product. It sits beside Midas Health Analytics for quality. The public Safety page describes incident capture, root cause analysis, corrective and preventive actions, mobile submission, dynamic forms, committee support and claims integration. **Best for:** Hospitals and health systems, with deployment across many facilities. No surgery center, nursing home or home health package was found. **Ownership:** Backed by Clearlake Capital Group and Charlesbank Capital Partners, per symplr's April 2026 announcement of a new chief executive. **Scale (company-reported):** symplr's home page (read 2026-10-05) says it is trusted in 9 of 10 hospitals and by 400+ health plans. That covers all symplr products, not symplr Safety alone. ## Pricing - **Model:** Priced by quote and sold through sales. Calls to action are 'see it in action' and 'schedule a conversation'. - **Published:** no - No pricing appears on the symplr Safety page. symplr sells workforce, credentialing, compliance and quality as separate lines, so ask what a Safety quote includes. ## Feature comparison | Feature | IncidentKit | symplr | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | No: The public path is a demo or a sales conversation. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | No: No prices or plan tiers on the Safety page. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | Not stated publicly: No free plan or trial is mentioned on the pages reviewed. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Not stated publicly: The Safety page links to symplrAI and mentions AI in its workflows. AI help at incident intake is not described. | | Voice reporting | Rolling out: Voice intake is rolling out. | Not stated publicly: Voice reporting is not mentioned on the pages reviewed. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: The Safety page describes mobile access so staff can submit incidents at any hour. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Yes: Root cause analysis is listed alongside incident capture. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Yes: Corrective and preventive action management, with owners and real time tracking from report to resolution. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Not stated publicly: Committee management and documentation support are listed, and the Joint Commission is a resource topic. QAPI or CMS reporting is not described. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Not stated publicly: OSHA recordkeeping is not mentioned on the Safety page. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: Deployment across multiple facilities is described. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Not stated publicly: Claims integration is mentioned. Single sign-on (SSO) and an API are not described on the Safety page. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: A business associate agreement is not mentioned on the public pages reviewed. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## symplr strengths - One vendor for much of hospital operations (workforce, credentialing, compliance, quality) beside safety. - A full incident lifecycle is described, from capture and root cause analysis to corrective actions and committee reports. - Claims integration and deployment across many facilities are stated capabilities. - KLAS surveyed 36 organizations about symplr Quality Suite (Midas Health Analytics) in 2025, the second largest sample after RLDatix. - Positions reporting as blame free, with dynamic forms that change based on what the reporter selects. ## Trade-offs to weigh - Little public detail on Safety: SSO, API, BAA, OSHA, AI at intake and QAPI reporting are not described. - No published pricing. Buying goes through sales. - Enterprise hospital focus. No package for surgery centers, nursing homes, home health or hospice was found. - Safety is one of many product lines. No satisfaction data for symplr Safety by name was found in the KLAS table. - Positioned on its broader operations platform, so an incident only team should confirm scope. ## Choose symplr if - You are a health system already using, or moving to, symplr for workforce, credentialing or compliance. - You want incident data tied to Midas quality analytics and committee reports. - You want deployment across many facilities from one operations vendor. - You prefer a large, established vendor and an evaluation led by sales. ## Choose IncidentKit if - You run surgery centers, nursing homes, home health, hospice or behavioral health sites and want packs for them. - You want published per site pricing, a BAA on the regulated plan and no seats, modules or setup fee. - You want conversational intake with [Lauren](https://incidentkit.ai/product/lauren), where a person signs every AI draft. - You want to read what a product does, including SSO and API, before a sales call. ## Switching - You want incident reporting without a wider operations suite. - Small sites find an enterprise hospital product heavy. - The team wants public pricing and specifics before a demo. symplr does not publish export formats for incident data. Ask for incidents, investigations, actions and attachments with dates and IDs kept. IncidentKit imports CSV history and sets up migration for you. See [import and migration](https://incidentkit.ai/product/import-and-migration). ## Frequently asked questions ### How does symplr price its safety software? symplr does not publish pricing for symplr Safety. The product page offers a demo and a sales conversation. It also sells workforce, credentialing, compliance and quality as separate lines, so ask what your quote bundles. ### What is symplr Safety, and how does it relate to Midas? symplr Safety is symplr's incident and event reporting product. It covers incident capture, root cause analysis, corrective actions and committee support. The home page also lists Midas Health Analytics under quality. The pages do not say how the two fit together. ### Does symplr have AI for incident reporting? symplr describes AI across its platform and links to symplrAI from the Safety page. AI help at incident intake, such as turning a narrative into a filled report, is not described. Ask what is live and whether a person reviews it. ### Who owns symplr? symplr is private equity backed. Its April 2026 announcement of a new chief executive names Clearlake Capital Group and Charlesbank Capital Partners as backers. Ownership can change, so confirm it when you buy. ### How does KLAS rate symplr? In KLAS's 2025 ranking, symplr Quality Suite (Midas Health Analytics) scored 78.9 from 36 organizations and symplr Compliance 77.2 from 17, against an 83.9 market average. symplr Safety is not listed by name. KLAS scores reflect customer interviews, not features. ## Sources - [symplr: home page](https://www.symplr.com/) - [symplr: symplr Safety product page](https://www.symplr.com/products/symplr-safety) - [symplr: About](https://www.symplr.com/about) - [Charlesbank: symplr names Venkat Kavarthapu chief executive officer (2026-04-13)](https://www.charlesbank.com/news/symplr-names-venkat-kavarthapu-chief-executive-officer/) - [KLAS: 2025 Best in KLAS, Healthcare Safety, Risk and Compliance Management](https://klasresearch.com/best-in-klas-ranking/healthcare-safety-risk-and-compliance-management/2025/420) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs MedTrainer: honest comparison > How IncidentKit and MedTrainer differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/medtrainer · Updated Oct 5, 2026 **MedTrainer**: All in one workforce compliance software for healthcare: training, credentialing and a compliance suite with incident reporting. MedTrainer is a healthcare compliance suite with three modules. Learning covers training. Credentialing covers provider files, enrollment, privileging and exclusion checks. Compliance covers policies, incident reporting, contracts, accreditation, safety data sheets and safety plans. Incident reporting is one module of compliance, not a stand alone safety system. It has mobile forms with photos, an anonymous option, routing, up to ten severity levels and location trend reports. **Best for:** Surgery centers (listed first on its industry pages), health centers, hospitals, long term care and behavioral health. Best for one compliance officer who wants it all under one login. **Ownership:** Investor-backed: MedTrainer announced a USD 43 million Series B led by Vista Equity Partners in April 2022, with Telescope Partners as an earlier investor. Later changes were not found. **Scale (company-reported):** MedTrainer's company page (read 2026-10-05) lists 3,000 clients, 32,000+ healthcare sites, 800,000 users and 300+ employees. Its incident page says 99.8 percent of customers passed all surveys or inspections in the past year. This is company reported, not independently verified. ## Pricing - **Model:** Three tiers priced by quote (essential, advanced, comprehensive), by users, modules and content. Incident reporting can be bought as part of compliance. - **Published:** no - The pricing page shows no prices and promises a custom quote within 24 to 48 hours. It mentions flexible contract terms. A free trial is not mentioned. The incident page says customers pay only for what they need. ## Feature comparison | Feature | IncidentKit | MedTrainer | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | No: Public path is a demo and a custom quote. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | No: Tier names and a quote process are shown, but no prices. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | No: The pricing page lists three paid tiers and a quote path. No free plan or trial is mentioned. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Not stated publicly: AI tools include Course Expert, Upload Assistant and Compliance Coach (available), and Form Mapping and Policy Guardian (upcoming). None is described for incident intake. Users must accept AI suggestions. | | Voice reporting | Rolling out: Voice intake is rolling out. | Not stated publicly: Voice reporting is not mentioned on the pages reviewed. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: Mobile-friendly forms from any device, with photo attachments. No native app is claimed for incident reporting. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Not stated publicly: Severity and trend reports are described. A root cause tool such as five whys or fishbone is not. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Partial: Follow-up can assign training or link a policy, and the audit log shows who reviewed it. A corrective action plan with effectiveness checks is not described. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Partial: ASC pages cite ASCQR and accreditation tracking, and courses for AAAHC, Quad A and the Joint Commission. QAPI summaries are not described. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Not stated publicly: Safety data sheets and safety plans are listed. OSHA 300, 300A and 301 recordkeeping is not described. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: Many locations run in one system, with consistent templates and location trend views. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Partial: A public API gives read and write access to practitioner, division and location data. Incident records are not mentioned. Single sign-on (SSO) works with Google, Okta, Microsoft Entra ID, ADP and UKG Dimensions. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: MedTrainer's security page says PHI is not stored in the platform and does not mention a BAA. A customer testimonial describes patient details in incident reports, so confirm in writing. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## MedTrainer strengths - One login for training, credentialing, policies and incident reports. An action can assign training or link a policy. - A quote within 24 to 48 hours, and incident reporting can be scoped without every module. - Mobile forms with photos, anonymous reports with no IP capture, ten severity levels and escalation when deadlines pass. - Built for outpatient and ASC work (also rural and critical access hospitals, assisted living), with accreditation courses and ASCQR tracking. - Security: SOC 2 Type 2 and SOC 3, TLS 1.3, AES-256 at rest, US only Azure hosting. AI can be turned off and stays out of model training by default. ## Trade-offs to weigh - Incident reporting is one module in a compliance suite. No root cause tool, benchmarking or effectiveness check is described. - MedTrainer says PHI is not stored in its platform, which may limit patient detail in reports. Confirm how it handles patient events. - No published pricing and no trial mentioned. Buying starts with a call. - Its AI tools target training, credentialing and policies. - OSHA recordkeeping and BAA terms are not described publicly. ## Choose MedTrainer if - You are a surgery center or outpatient group whose bigger need is training, credentialing and policies. - You want one platform for staff training, provider files, policies and basic incident tracking. - Your incident reports rarely need patient identifiers or formal root cause work. - You want a quick quote and a vendor many ASCs and health centers already use. ## Choose IncidentKit if - Incident reporting, investigations and corrective actions are the main job. Patient information must go in the report under a BAA. - You want investigations with contributing factors and five whys, and actions that cannot close until verified. - You want [Lauren](https://incidentkit.ai/product/lauren) to draft reports from plain accounts, with a person signing. - You want QAPI summaries and survey packets from incident records, and published per site pricing. ## Switching - Incident reports need patient detail or action tracking. - The team wants a focused incident tool and keeps training elsewhere. - Leaders want trends by cause, shift and equipment. MedTrainer does not publish export formats for incident records, though admins can build filtered reports. Ask for incidents, notes, attachments and the activity log with dates intact. Many teams keep MedTrainer for training and move only incidents. IncidentKit imports CSV history and sets up migration for you. See [import and migration](https://incidentkit.ai/product/import-and-migration). ## Frequently asked questions ### How does MedTrainer price its software? MedTrainer does not publish prices. Its pricing page describes three tiers priced by quote, with a custom quote in 24 to 48 hours. No free trial is mentioned. Ask whether incident reporting can be quoted alone. ### Can MedTrainer store patient information in incident reports? MedTrainer's security page says PHI is not stored in its platform, and it does not mention a BAA. A customer testimonial describes patient details, so practice may vary. Ask in writing, and ask about a BAA, before using it for patient events. ### Does MedTrainer support anonymous incident reporting? Yes. MedTrainer says admins can mark a form as anonymous. That removes the signature field and captures no personal data or IP address. Anonymous reports still follow normal routing and escalation. ### Is MedTrainer a replacement for dedicated incident reporting software? It depends on the job. MedTrainer covers intake, routing, severity levels, escalation and trend reports. It does not publicly describe a root cause tool, effectiveness checks, benchmarking or OSHA recordkeeping. ### Who owns MedTrainer? MedTrainer is investor backed. In April 2022 it announced a USD 43 million Series B led by Vista Equity Partners, with Telescope Partners as an earlier investor. Ownership may have changed, so confirm it when you buy. ## Sources - [MedTrainer: home page](https://www.medtrainer.com/) - [MedTrainer: incident reporting software](https://medtrainer.com/products/compliance-overview/incident-reporting/) - [MedTrainer: pricing](https://medtrainer.com/pricing/) - [MedTrainer: AI in MedTrainer](https://medtrainer.com/ai/) - [MedTrainer: data security overview](https://medtrainer.com/security-overview) - [MedTrainer: integrations and API](https://medtrainer.com/products/integrations/) - [MedTrainer: company page (scale)](https://medtrainer.com/company/) - [MedTrainer: compliance software for ambulatory surgery centers](https://medtrainer.com/who-we-serve/industries/ambulatory-surgery-centers/) - [Healthcare IT Today: MedTrainer Series B led by Vista Equity Partners (2022-04-18)](https://www.healthcareittoday.com/2022/04/18/medtrainer-announces-43-million-series-b-funding-round-led-by-vista-equity-partners/) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs Performance Health Partners: honest comparison > How IncidentKit and Performance Health Partners differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/performance-health-partners · Updated Oct 5, 2026 **Performance Health Partners**: Event reporting and quality software for healthcare, with rounding, audits, peer review and surveys, plus high touch service. Performance Health Partners (PHP) sells software for incident and event reporting, digital rounding, compliance audits, peer review and patient surveys. Event Reporting is its core product. Its site lists settings that overlap with surgery centers and post acute care: ASCs, long term care, skilled nursing, home health, hospice, behavioral health, community health centers and hospitals. KLAS ranked PHP first in its category in 2026, the fourth year running. PHP joined Sentact in December 2025. **Best for:** Hospitals (including critical access), community health centers, ASCs, long term care, home health, hospice and behavioral and addiction treatment. Also government and correctional settings. **Ownership:** Acquired in December 2025 by Sentact, which also bought the Vizient Patient Safety Organization. Sentact's own ownership is not disclosed in the announcement. **Scale (company-reported):** PHP's home page (read 2026-10-05) says more than 100,000 healthcare professionals use its incident software. Sentact's December 2025 announcement says the Vizient PSO bought with PHP has 332 participating organizations. That is a PSO figure, not PHP's customer count. ## Pricing - **Model:** Priced by quote and sold through sales. Training is described as included, with no extra fees. - **Published:** no - No prices are published. A February 2025 announcement says PHP joined CommonWealth Purchasing Group's network of 800+ member organizations, with no discounts stated. In KLAS's 2025 interviews, 100 percent of PHP customers asked (n=29) said it avoids charging for every little thing. That is opinion, not a price list. ## Feature comparison | Feature | IncidentKit | Performance Health Partners | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | No: Public path is a demo request. PHP describes tailored training and onboarding. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | No: No prices or plan tiers on the public site. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | Not stated publicly: No free plan or trial is mentioned on the pages reviewed. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Not stated publicly: No AI features are described on the pages reviewed. | | Voice reporting | Rolling out: Voice intake is rolling out. | Not stated publicly: Voice reporting is not mentioned on the pages reviewed. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: Reporting works on desktop, mobile and tablet. PHP says a report can be filed in under two minutes. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Yes: Built in root cause analysis with drill through reporting is listed for its incident software. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Yes: Due dates, corrective actions and next steps can be assigned and tracked, with notification routing and automated workflows. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Partial: Compliance and audit tools support Joint Commission and CMS accreditation readiness, with audit templates. QAPI summaries are not described. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Not stated publicly: The site describes employee and patient safety software, but OSHA recordkeeping is not mentioned. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: PHP says it suits large health systems and private providers with many sites. A case study describes rounds across 17 sites. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Not stated publicly: EHR interoperability is mentioned; single sign-on and an API are not described. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: A BAA is not mentioned on the pages reviewed. PHP links to a trust page that could not be read without scripts. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## Performance Health Partners strengths - Best in KLAS for the fourth year in 2026. In 2025 it scored 96.0 from 30 organizations against an 83.9 market average. - Setting coverage close to IncidentKit's, with case studies that include a surgery center. - Fully configurable forms and workflows. PHP says reports take under two minutes. - Training is described as included, and PHP says support responds within 24 hours. - Tools for rounding, audits, peer review and surveys, and a parent that owns the Vizient Patient Safety Organization (332 participating organizations). ## Trade-offs to weigh - No published pricing and no way to start without a demo. - The 2025 Sentact acquisition means roadmap, packaging and support may change. PHP says its platform is being merged with Sentact's. - Public pages do not describe AI, voice, SSO, an API, a BAA or OSHA recordkeeping. - No setup timeline is published. - Claims and enterprise risk tools are not listed. ## Choose Performance Health Partners if - You value independent satisfaction data and a vendor KLAS has ranked first four years running. - You are a health center, behavioral health provider, hospital or ASC and want incidents plus rounding, audits and peer review from one vendor. - You want fully configurable forms and high touch service. - You want a vendor tied to a Patient Safety Organization through its parent, and will confirm how that applies. ## Choose IncidentKit if - You want prices you can read on a page, a BAA on the regulated plan and no seats, modules or setup fee. - You want conversational intake with [Lauren](https://incidentkit.ai/product/lauren), where a person signs every AI draft. - You want actions that cannot close until verified, and QAPI and survey packets from the records. - You run mixed sites in one account, such as a surgery center and a plant, with packs for each. ## Switching - A new owner prompts a fresh look at roadmap and pricing. - The team wants AI intake and public pricing. - Leaders want one account for healthcare and other sites. PHP does not publish export formats. Ask for incidents, investigations, action plans and attachments with dates and IDs kept. IncidentKit imports CSV history and sets up migration for you. See [import and migration](https://incidentkit.ai/product/import-and-migration). ## Frequently asked questions ### How does Performance Health Partners price its software? PHP does not publish prices. Buyers get a quote after a demo. PHP says training is included with no extra fees. Ask what changed in pricing after the Sentact acquisition. ### Who owns Performance Health Partners? Sentact bought PHP in December 2025, along with the Vizient Patient Safety Organization. PHP's founder and chief executive, Heidi Raines, joined Sentact as chief strategy officer. The announcement did not give deal terms or Sentact's own backers. ### Does Performance Health Partners work for surgery centers and nursing homes? Its site names both settings, plus home health, hospice, behavioral health, community health centers and hospitals. Case studies include a surgery center and community health centers. Ask which forms and reports come ready for your setting. ### How does KLAS rate Performance Health Partners? KLAS named PHP the top provider in its category in 2026, the fourth year in a row. In 2025 it scored 96.0 out of 100 from 30 organizations, first of six and well above the 83.9 market average. KLAS scores reflect customer interviews, not features. ### Does Performance Health Partners use AI for incident reporting? The public pages reviewed do not describe AI, voice or conversational intake. PHP stresses configurable forms, fast reporting, dashboards and support. If AI intake matters, ask PHP and Sentact what exists today. ## Sources - [Performance Health Partners: home page](https://www.performancehealthus.com/) - [Performance Health Partners: incident and event reporting](https://www.performancehealthus.com/incident-and-event-reporting) - [Performance Health Partners: compliance and audit tools](https://www.performancehealthus.com/compliance-audit) - [Performance Health Partners: case studies](https://www.performancehealthus.com/resources-case-studies) - [Performance Health Partners: about us](https://www.performancehealthus.com/about-us) - [Sentact: acquires Performance Health Partners and Vizient PSO (2025-12-15)](https://www.sentact.com/?p=22188) - [HIT Consultant: Sentact acquires Performance Health Partners and Vizient PSO (2025-12-15)](https://hitconsultant.net/2025/12/15/ma-sentact-acquires-performance-health-partners-and-vizient-pso/) - [Sentact and PHP: Best in KLAS 2026 press release (2026-02-04)](https://www.sentact.com/wp-content/uploads/2026/03/PHP_Best-in-KLAS.pdf) - [Chinook Observer: CommonWealth Purchasing Group and PHP partnership (2025-02-19)](https://chinookobserver.com/2025/02/19/commonwealth-purchasing-group-announces-strategic-partnership-with-performance-health-partners-to-enhance-healthcare-safety-and-compliance) - [KLAS: 2025 Best in KLAS, Healthcare Safety, Risk and Compliance Management](https://klasresearch.com/best-in-klas-ranking/healthcare-safety-risk-and-compliance-management/2025/420) - [KLAS: 2026 Best in KLAS, Healthcare Safety, Risk and Compliance Management](https://klasresearch.com/best-in-klas-ranking/healthcare-safety-risk-and-compliance-management/2026/420) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs ASC WebQI: honest comparison > How IncidentKit and ASC WebQI differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/asc-webqi · Updated Oct 5, 2026 **ASC WebQI**: A cloud platform for quality and compliance in surgery centers, with incident reporting as one module. ASC WebQI, from ASCistus, is a cloud quality system built only for ambulatory surgery centers, surgical hospitals and clinics. Incident reporting is one module. Others cover audits, logs and checklists, surveys, credentialing, staff tracking, contracts, QI studies, policies and meeting minutes. It also benchmarks against other ASCs. ASCistus says it supports QAPI programs rather than replacing them. **Best for:** ASCs with one or many specialties, surgical hospitals and clinics. Also ASC companies, management firms and consultants who want combined reporting across centers. **Ownership:** Developed and sold by ASCistus, LLC. Ownership beyond that is not disclosed on its site. **Scale (company-reported):** ASCistus says hundreds of ASCs in 40+ states and the Virgin Islands use ASC WebQI (enterprise page, read 2026-10-05). A 2025 Healthcare Tech Outlook profile cites more than 400 sites in 44 states and the USVI. ## Pricing - **Model:** One monthly subscription with unlimited users, training, support and upgrades included. Modules can be chosen singly or as a full platform, with volume discounts for companies with many centers. - **Published:** no - No price list is published. The site shows a banner for a 'Jumpstart' launch offer of ten dollars per license, and the pages reviewed do not explain its terms. ASCistus says a site can be set up within 24 hours of subscribing, with content set up for you. ## Feature comparison | Feature | IncidentKit | ASC WebQI | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | Partial: Signup runs through a contact form and demo. ASCistus says a site is ready within 24 hours of subscribing. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | No: No price list; only a promotional banner whose terms are not explained. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | No: The site describes one paid monthly subscription. No free plan is mentioned. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Not stated publicly: No AI features are described on the pages reviewed. | | Voice reporting | Rolling out: Voice intake is rolling out. | Not stated publicly: Voice reporting is not mentioned on the pages reviewed. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: A mobile app for iOS and Android is listed (version 15.6, updated December 2025 on Android). It added two factor authentication. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Not stated publicly: QI Studies use templates to measure, analyze, improve and control. A root cause tool is not described. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Partial: Users can record each action taken during investigation and follow-up. A corrective action plan with effectiveness checks is not described. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Yes: Built around QAPI work: logs and audits tied to indicators, committee reports and benchmarking. ASCistus says it supports a QAPI plan, not replaces it. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Not stated publicly: OSHA recordkeeping is not mentioned. The incident module lists employee events among those it can track. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: Enterprise features: corporate user roles, combined reporting, benchmarking by center, group and company, and remote review. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Not stated publicly: An API and single sign-on (SSO) are not described on the pages reviewed. A business intelligence tool with dashboards is offered. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: The site says the product is HIPAA compliant. A BAA is not mentioned. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## ASC WebQI strengths - Built only for ASCs: ASC specific content for incidents, logs, audits (such as time out and hand hygiene) and credentialing. - Benchmarking by specialty against other ASCs and national measures, such as falls, burns, retained objects and wrong site events. - One subscription for a wide ASC quality workbench, which replaces binders. - Simple pricing: unlimited users, with training, support and upgrades included. - Features for ASC companies with many centers. Vendor published testimonials praise support, including one from an anesthesia group that covers 70+ ASCs. ## Trade-offs to weigh - ASC only scope: not aimed at hospitals, nursing homes, home health, hospice or industrial sites. - The incident module is record and track. AI intake, voice, a root cause tool and effectiveness checks are not described. OSHA recordkeeping is not mentioned. - An API, SSO and BAA terms are not described publicly. - No price list. The promotional banner leaves the per site cost unclear. - No independent satisfaction ranking was found, and it is not in KLAS's safety, risk and compliance table. ## Choose ASC WebQI if - You run only surgery centers and want logs, audits, credentialing, staff tracking and QI studies in one subscription. - You want benchmarking by specialty against other ASCs. - You manage many ASCs and want combined reporting and remote oversight. - You want ASC specific content set up for you by a vendor that works only in this segment. ## Choose IncidentKit if - You run more than ASCs, such as nursing homes, home health, hospice, behavioral health or industrial sites, and want mixed packs in one account. - You want [Lauren](https://incidentkit.ai/product/lauren) to draft reports from plain accounts, plus email-to-incident and QR quick report. - You want actions with an owner, due date, evidence and effectiveness check, and nothing closes until verified. - You want SSO, a read API and signed webhooks on the network plan, and a BAA on the regulated plan. ## Switching - You are adding sites that are not ASCs. - The team wants investigations, verified actions and AI intake. - Leaders want links such as SSO and an API. ASCistus does not publish export formats. Ask for incident records, investigation notes, follow-up actions and attachments with dates and IDs kept. Quality logs and audits can stay in ASC WebQI while incident reporting moves. IncidentKit imports CSV history and sets up migration for you. See [import and migration](https://incidentkit.ai/product/import-and-migration). ## Frequently asked questions ### How does ASC WebQI price its software? ASCistus describes one monthly subscription. It includes unlimited users, training, support and upgrades. No price list is published. A site banner mentions a launch offer of ten dollars per license without explaining its terms. ### Does ASC WebQI replace our QAPI program? No. ASCistus says the software helps manage a QAPI plan, not replace it. It swaps paper forms for electronic entry and gives managers a view of logs, audits and incidents. Customers describe preparing QAPI and AAAHC survey materials from its reports. ### What quality measures can ASC WebQI benchmark? ASCistus says users can benchmark by specialty, across a company, against other ASC WebQI centers and against national measures such as ASC Quality Collaboration and CMS. Examples are falls, burns, infections, medication errors, retained objects and wrong site, side, patient, procedure or implant events. ### Can ASC WebQI manage multiple surgery centers? Yes. ASCistus describes enterprise features for chains, management firms and consultants. They include corporate user roles, combined reporting, benchmarking by center, group and company, and remote data review. ### Can ASC WebQI be used outside surgery centers? ASCistus builds the product for ambulatory surgery centers, surgical hospitals and clinics. Its modules and benchmarks are ASC specific. Its public pages do not describe packages for nursing homes, home health, hospice or industrial sites. ## Sources - [ASCistus: ASC WebQI home page](https://www.ascistus.com/) - [ASCistus: incident reporting module](https://www.ascistus.com/product-incidents.html) - [ASCistus: quality measure benchmarking](https://www.ascistus.com/product-benchmarking.html) - [ASCistus: enterprise features](https://www.ascistus.com/enterprise.html) - [ASCistus: module overview and pricing model](https://www.ascistus.com/products.html) - [ASCistus: about](https://www.ascistus.com/about.html) - [ASCistus: audits module](https://www.ascistus.com/product-audits.html) - [ASCistus: testimonials](https://www.ascistus.com/testimonials.html) - [App Store: ASCMobileQI (ASCistus LLC)](https://apps.apple.com/co/app/ascmobileqi/id1483889660) - [APKCombo: ASCWebQI Android app listing](https://apkcombo.com/ascwebqi-quality-management-to/com.ascistus.ascqipmobileapp/) - [Healthcare Tech Outlook: ASC WebQI profile (2025)](https://www.healthcaretechoutlook.com/asc-webqi) - [KLAS: 2025 Best in KLAS, Healthcare Safety, Risk and Compliance Management (category table checked)](https://klasresearch.com/best-in-klas-ranking/healthcare-safety-risk-and-compliance-management/2025/420) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs VelocityEHS: honest comparison > How IncidentKit and VelocityEHS differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/velocityehs · Updated Oct 5, 2026 **VelocityEHS**: An EHS and sustainability platform (Accelerate) with an AI assistant, Vēlo, aimed at preventing serious injuries. VelocityEHS sells EHS products on its Accelerate platform. They cover safety, ergonomics, chemicals and operational risk. Its Incident Management product records injuries, illnesses, near misses and hazards. It tracks corrective actions. It creates OSHA Forms 300, 300A and 301 and exports to OSHA's Injury Tracking Application (ITA). The Vēlo AI assistant detects potential serious injuries or fatalities (PSIF). **Best for:** EHS and safety directors at mid size and large industrial employers with many sites. They want incident management as one module in an EHS suite. **Ownership:** CVC Growth Funds (majority) and Partners Group (minority), per the company's August 2022 announcement **Scale (company-reported):** The company states more than 10 million users and 15,000+ EHS teams (ehs.com and a June 16, 2026 press release, checked 2026-10-05). An August 2022 release cited over 18,000 customers. The figures are not directly comparable. ## Pricing - **Model:** Annual subscription priced by quote, sold by module through the sales team - **Published:** no - No price list is published on ehs.com. The vendor does not confirm third party estimates, so none are used. September 2025 launch coverage put the hazard, root cause and corrective action AI inside a Vēlo subscription for Safety. SSO setup and pricing go through an account manager. Ask for AI and SSO to be itemized. ## Feature comparison | Feature | IncidentKit | VelocityEHS | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | No: Public calls to action are demo requests. The vendor describes guided onboarding by its own team. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | No: No prices are published on the vendor site. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | No: No free tier or self signup is listed. Access starts with a demo. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Partial: AI tools review reports as they are completed: Description Analyzer, Hazard Analyzer and Root Cause Identifier. A conversational intake that asks follow up questions is not described. | | Voice reporting | Rolling out: Voice intake is rolling out. | Not stated publicly: Voice reporting is not mentioned on the incident pages reviewed. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: Offline mobile reporting. QR codes let workers and contractors submit without logging in (30 languages, per a June 2026 release). | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Yes: AI Root Cause Identifier suggests likely root causes as a report is completed. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Yes: Corrective actions are assigned and tracked with escalating notices. An AI Corrective Action Advisor suggests controls. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Not stated publicly: No QAPI, CMS or survey readiness content on the incident pages. The healthcare page centers on staff safety, chemicals and ergonomics. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Yes: Creates OSHA Forms 300, 300A and 301 and supports electronic submission through the ITA. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: One location tree is shared across products. Incident data is centralized across locations. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Partial: Help documentation lists Data Share and standard integrations. A public API reference was not located. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: No HIPAA or business associate agreement statement appears on the pages reviewed. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## VelocityEHS strengths - Broad platform: the vendor says 24+ products share one set of users, roles and locations. - AI at several steps: PSIF detection, description review, and root cause and hazard ideas. The vendor says PSIF detection cuts manual triage time by 30 to 50 percent (company figure, July 2025). - Clear OSHA records: Forms 300, 300A and 301, ITA reporting, and 25+ pre built reports. - Offline mobile, and QR codes with no login in 30 languages, plus 15+ platform languages. - SOC 2 Type II and ISO 27001 (June 2026 release), plus SAML SSO. ## Trade-offs to weigh - Pricing is by quote only, so you cannot compare budgets before a sales call. - Some AI was described at launch as part of a separate Vēlo subscription. Confirm what is included. - SSO setup and pricing go through an account manager. - Healthcare content centers on worker safety, not patient safety events, QAPI or HIPAA. - A multi product suite may be more than an incident only team needs. ## Choose VelocityEHS if - You are an industrial employer with many sites and want incidents inside a full EHS suite. - You need OSHA 300, 300A and 301 records and ITA submission today. - You want PSIF detection and AI ideas, with onboarding led by the vendor. - SOC 2 Type II, ISO 27001 and SAML SSO are buying requirements. ## Choose IncidentKit if - Your incidents involve patients or residents. You need a BAA, QAPI summaries and survey packets. - You want one flat price per site, with no seats, modules or setup fee, and a free plan for non patient incidents. - You want Lauren to ask the follow up questions, with a person signing every record. - You want a focused tool for reporting, investigation and corrective actions. ## Switching - Care setting incidents that a worker safety suite skips. - A wish for flat per site pricing, not quotes by module. - Incident tools without the rest of a suite. - A preference for intake that asks follow up questions. Export incident history and open corrective actions with VelocityEHS's advanced reports and export tools. IncidentKit imports CSV files and sets up migration for you. Keep archived OSHA 300 logs and ITA submissions for the retention period. OSHA 300, 300A and 301 exports are rolling out, so confirm timing if you file through the ITA. ## Frequently asked questions ### Does VelocityEHS publish its prices? No. The public site shows demo requests and no price list. Pricing is by quote, by module. Ask for AI and SSO as separate lines, because launch coverage put some AI inside a separate Vēlo subscription. ### Does VelocityEHS support OSHA 300, 300A and 301 forms? Yes. Its May 2026 capability sheet says the product creates Forms 300, 300A and 301. It also supports electronic reporting through OSHA's Injury Tracking Application. ### What AI does VelocityEHS offer for incident reporting? Its Vēlo assistant, powered by VelocityAI, has AI PSIF Insights, Description Analyzer, Hazard Analyzer, Root Cause Identifier and Corrective Action Advisor. A help guide covers confirming AI PSIF flags, so a person reviews flagged cases. ### Can workers report an incident without logging in? Yes. Administrators can create QR codes that open an incident, near miss or hazard form with no login. A June 2026 press release says the form supports 30 languages. ### Is VelocityEHS suitable for a hospital or surgery center? VelocityEHS serves healthcare employers with worker safety products, such as ergonomics and chemicals. The pages reviewed do not describe patient safety events, QAPI or a HIPAA BAA. Ask for its BAA position in writing. ## Sources - [VelocityEHS: Incident Management product page](https://www.ehs.com/solution/incident-management/) - [VelocityEHS: Incident Management capability sheet (May 2026)](https://www.ehs.com/wp-content/uploads/2026/05/VelocityEHS_Capability-Sheet_Safety_Incident-Management.pdf) - [VelocityEHS: QR Codes for Incident Management release (June 16, 2026)](https://www.ehs.com/press_releases/velocityehs-launches-qr-codes-for-incident-management-to-streamline-safety-reporting-and-improve-risk-visibility/) - [VelocityEHS help center: QR codes in incident reporting](https://help.ehs.com/docs/incident-management/qr-codes-in-incident-management/qr-codes-in-incident-reporting/) - [GlobeNewswire: VelocityEHS launches AI PSIF Insights (July 1, 2025)](https://www.globenewswire.com/news-release/2025/07/01/3108237/0/en/VelocityEHS-Launches-New-PSIF-AI-to-Identify-the-Next-Serious-Injury-or-Fatality-Before-It-Happens.html) - [ISHN: VelocityEHS unveils Vēlo AI assistant (September 16, 2025)](https://www.ishn.com/articles/114922-velocityehs-unveils-vlo-new-ai-assistant-aims-to-break-the-workplace-safety-plateau) - [VelocityEHS help center: single sign-on](https://help.ehs.com/knowledge-base/single-sign-on-sso) - [VelocityEHS: Accelerate platform](https://www.ehs.com/accelerate) - [VelocityEHS: Accelerate platform solution sheet](https://www.ehs.com/wp-content/uploads/2025/01/VelocityEHS_Solution-Sheet_Introducing-the-Accelerate-Platform.pdf) - [VelocityEHS: healthcare industry page](https://www.ehs.com/industries/healthcare/) - [VelocityEHS: Partners Group minority investment release (August 2022)](https://www.ehs.com/press_releases/partners-group-to-acquire-a-significant-minority-stake-in-velocityehs-a-leading-environmental-health-safety-and-sustainability-software-platform/) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs Cority: honest comparison > How IncidentKit and Cority differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/cority · Updated Oct 5, 2026 **Cority**: An enterprise platform (CorityOne) for safety, worker health, environment, quality and sustainability, with Cortex AI agents. Cority sells CorityOne, an enterprise platform for safety, worker health, environment, quality and sustainability. Its Incident Management product logs incidents, near misses, observations and hazards. It standardizes investigations and corrective actions across sites. Cortex AI, launched December 4, 2025, adds task agents. One agent sorts incident photos to pre-fill reports. Cority also sells occupational health software to hospitals for their own staff. **Best for:** Large and mid size regulated employers in energy, chemicals, manufacturing, utilities and hospitals. They want safety, occupational health and compliance on one platform. **Ownership:** Thoma Bravo (majority investor since 2019, per the company's announcement) **Scale (company-reported):** The company says more than 1,500 organizations trust it after 40 years (December 4, 2025 release). Its hospital page claims 1 in 3 U.S. healthcare workers use Cority. It cites 150+ enterprise hospital clients (checked 2026-10-05). ## Pricing - **Model:** Enterprise subscription priced by quote, with a setup project - **Published:** no - No pricing appears on cority.com. The calls to action are Get a Demo and contact. A Cority UK G-Cloud listing (for Cortex AI) describes a staged setup project. Extra needs are scoped and priced as follow on phases. ## Feature comparison | Feature | IncidentKit | Cority | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | No: Calls to action are demo and contact requests. The vendor describes a staged setup project. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | No: No prices are published on the vendor site. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | No: No free tier or self-signup is listed. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Partial: Cortex AI has an Incident Image Analysis Agent that sorts photos to pre-fill reports. Narrative intake with follow up questions is not described. | | Voice reporting | Rolling out: Voice intake is rolling out. | Not stated publicly: Voice reporting is not described for incidents. A separate Medical Scribe Agent targets clinical visits. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: The myCority mobile web app works offline and syncs later. It covers incidents, inspections and observations. QR code reporting is not described. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Yes: Guided investigation methods, plus Cortex AI root cause and CAPA suggestions. The vendor says a person validates them. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Yes: Corrective and preventive actions are assigned, tracked and verified in automated workflows. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Not stated publicly: No QAPI or CMS survey content was found. The hospital offering centers on staff health. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Partial: Pages name OSHA reporting and recordkeeping on mobile. Forms 300, 300A and 301 are not itemized. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: Investigations and workflows are standard across sites and business units. Dashboards cover the enterprise. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Yes: A Cority UK G-Cloud listing says its API is the one its own apps use. It has Open API (Swagger) docs. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: HIPAA and a BAA are not stated on the security or hospital pages reviewed. Ask directly if patient information is involved. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## Cority strengths - Depth for large programs: standard investigations, verified actions and dashboards across sites. - Cortex AI has a Control Center. Admins manage model choice, privacy, audit trails and costs (December 2025). - Documented security: FedRAMP authorized hosting, ISO 27001 and 27018 alignment, encryption, role based access and audit logs. - A hospital offering for staff health covers clinic visits, screening and billing. - Cority says Verdantix named it a Leader in its 2026 Green Quadrant for EHS Software for the seventh year running. ## Trade-offs to weigh - No self serve path or public price. A setup project sets scope and cost. - A UK G-Cloud listing says mobile supplements the desktop service. Confirm which workflows work fully offline. - Healthcare coverage is staff health. Patient safety events, QAPI, survey packets and a BAA are not described. - OSHA support is described at a high level. Ask for a demo of Forms 300, 300A and 301 and ITA export. - SSO is not stated on the pages reviewed. MFA, role based access and audit logs are. ## Choose Cority if - You are a large, regulated or global employer wanting many safety programs on one platform. - Your hospital needs staff health software alongside EHS. - You need FedRAMP authorized hosting or a central AI control center. - You have IT staff and budget for a configured setup project. ## Choose IncidentKit if - Your incidents involve patients or residents. You need a BAA, QAPI summaries and survey packets. - You want one flat price per site, with no seats, modules or setup fee, and a free plan for non patient incidents. - You want Lauren to ask follow up questions and a person to sign, with every AI draft marked until approved. - You want a focused tool that runs beside your EHR, CMMS and HRIS. ## Switching - Care setting incidents that an enterprise suite skips. - A wish for a lighter product and flat pricing. - Needing only incident and corrective action tools. - A preference for a self serve start with a free plan. Cority's UK G-Cloud listing says reports export data at no cost. Full database backups or data extracts cost extra. Get the export option in writing before you give notice. IncidentKit imports CSV files and sets up migration for you. OSHA 300, 300A and 301 exports are rolling out, so keep your current OSHA records until then. ## Frequently asked questions ### Does Cority publish pricing? No. The public site shows Get a Demo and contact buttons but no prices. A Cority UK G-Cloud listing describes a staged setup project. Extra scope is priced as follow on phases. ### What AI does Cority offer for incident management? Cortex AI, launched December 4, 2025, is built into CorityOne. For incidents, an agent sorts photos to pre-fill reports. Cority also describes root cause and CAPA recommendations that a person validates. ### Does Cority work offline on mobile? Yes. Cority's mobile EHS page describes offline capture that syncs when connectivity returns. It covers incidents, inspections and observations. A UK G-Cloud listing says mobile supplements the desktop service, so check your workflows. ### Can a hospital use Cority for patient incident reporting? Cority's hospital offering is occupational health for a hospital's own staff. It covers clinic visits, vaccination tracking, fit testing and screening. The pages reviewed do not describe patient safety event reporting, QAPI or a HIPAA BAA. ### Who owns Cority? Thoma Bravo, a private equity firm, announced a majority investment in Cority in May 2019. Norwest Venture Partners and Georgian Partners kept stakes. Ownership may have changed, so check during due diligence. ## Sources - [Cority: Incident Management solution page](https://www.cority.com/solutions/incident-management) - [Cority: CorityOne incident management software](https://go.cority.com/corityone/incident-management-software/) - [Cority: Cortex AI launch release (December 4, 2025)](https://www.cority.com/?p=96044) - [Cority: mobile EHS software](https://go.cority.com/health-cloud/mobile-ehs-solution) - [Cority: security and governance](https://www.cority.com/corityone/security-governance/) - [Cority: hospital and medical center EHS software](https://go.cority.com/industries/hospital-and-medical-ehs-software/) - [Cority: Thoma Bravo growth investment announcement (May 2019)](https://www.cority.com/?p=19249) - [UK Digital Marketplace: Cority Cortex AI service listing (G-Cloud; Cority withdrew the listing on September 9, 2026)](https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/139621189660989) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs Intelex (Fortive): honest comparison > How IncidentKit and Intelex (Fortive) differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/intelex · Updated Oct 5, 2026 **Intelex (Fortive)**: A cloud EHSQ platform for incidents, audits, risk, quality and ESG, plus a lower cost Safety Essentials package. Intelex is a Toronto based EHSQ platform that calls itself an operating company of Fortive. Its incident app captures injuries, illnesses, near misses, spills, property damage, vehicle and security events. Partner tools such as TapRooT and COMET help with deeper investigations. Recent releases added AI feedback on descriptions, serious injury or fatality (SIF) classification, and AI that fills fields from dictation. Safety Essentials has a published starting price. The full platform is sold by quote. **Best for:** Mid market and enterprise EHS teams in manufacturing, construction, energy, chemicals and mining that want modular EHSQ apps. Small teams can start with Safety Essentials. **Ownership:** Fortive Corporation **Scale (company-reported):** Company states 1,400 customers and 3.5 million users (incident reporting page, checked 2026-10-05). Its July 15, 2026 release also cites 1,400 customers and more than 30 years in business. ## Pricing - **Model:** Published starting price for Safety Essentials (from $44 USD per user per month, minimum 25 users, billed annually); full platform by quote - **Published:** yes - At the 25 user minimum, the published price works out to about $13,200 a year (our arithmetic). The pricing page describes Essentials as self serve with immediate deployment. Intelex's own comparison rates its flexibility as low. Full platform pricing is requested through a form. Add-ons, such as Training Management and Document Control, are listed apart. ## Feature comparison | Feature | IncidentKit | Intelex (Fortive) | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | Partial: Safety Essentials is immediate and self serve. The full platform is sold through demos and sales. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | Partial: A starting price is published for Safety Essentials only. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | No: Pages offer a free trial request form, but no free plan is listed. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Yes: Auto Populate lets a worker dictate an event, and AI extracts fields for review. Input AI gives live feedback on description quality. Follow up questioning is not described. | | Voice reporting | Rolling out: Voice intake is rolling out. | Yes: A July 2026 release describes dictating event descriptions with the phone microphone. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: Intelex Mobile records incidents at the scene and works offline on the full platform. Essentials has responsive web mobile. QR code reporting is not described. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Yes: Built in checklists, 5 Whys and Fishbone; TapRooT; and partner COMET, with an AI assistant for timelines and actions. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Yes: CAPA tasks tie to investigations, and mobile users can carry them out. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Not stated publicly: No QAPI or CMS content was found. Industry pages list manufacturing, construction, energy, chemicals, mining and logistics. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Yes: Pages describe automating OSHA Form 300, 300A and 301 records. Electronic submission is not itemized. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: A central system of record with company wide dashboards and benchmarks such as DART and LTIR. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Yes: REST API with JSON, partner connectors for HR, ERP and learning systems, SSO, and bulk Excel import for history. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: Intelex lists HIPAA among the standards it meets, but no business associate agreement statement was found. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## Intelex (Fortive) strengths - Publishes a starting price for Safety Essentials, with self serve setup for small teams. - Cause analysis choices: 5 Whys, Fishbone, TapRooT, and COMET. COMET has an AI assistant for timelines and actions, with investigator approval (July 2026). - AI helps at capture. Input AI scores description quality, SIF classification is built in, and dictation fills fields for review. - OSHA Forms 300, 300A and 301 automation, plus WCB, RIDDOR and ISO alignment. - Public enterprise basics: SSO, REST API, translation workbench, offline mobile. ## Trade-offs to weigh - Essentials is limited. It has responsive web mobile, low flexibility by Intelex's own comparison, and a 25 user minimum. - Full platform pricing is by form request, with no list price. - AI root cause help comes through partner COMET. Confirm how it is licensed. - Healthcare is not among its listed industries, and no QAPI or BAA statement was found. - Per user pricing grows with headcount, which matters if every frontline worker needs a login. ## Choose Intelex (Fortive) if - You want modular EHSQ apps from one vendor, with enterprise controls. - You run TapRooT or COMET investigations tied to incident records. - You want a published starting point that can grow into the full platform. - Your reporting spans OSHA, RIDDOR, WCB and ISO duties. ## Choose IncidentKit if - Your incidents involve patients or residents, and you need a BAA, QAPI summaries and survey packets. - You want one flat price per site, not per user pricing with a 25 user minimum. - You want Lauren to ask follow up questions and draft the investigation, with a person signing. - You want to start free for non patient incidents. ## Switching - Per user pricing does not fit many reporters. - Care setting needs fall outside an industrial catalog. - A wish for one focused incident tool. - Wanting AI intake in the core product. Intelex offers reports, a REST API and bulk Excel tools. Export incidents, investigations and open CAPA tasks as spreadsheets. IncidentKit imports CSV files and sets up migration for you. Archive COMET or TapRooT files and OSHA logs for the retention period. OSHA 300, 300A and 301 exports are rolling out, so keep your OSHA records until then. ## Frequently asked questions ### Does Intelex publish prices? Partly. Its pricing page shows Safety Essentials from $44 USD per user per month, with a minimum of 25 users and annual billing. The full platform and enterprise pricing are quoted through a form. ### Does Intelex offer a free trial? Intelex pages show a request form for free trial access. No free plan is listed, and the pages do not say whether a trial is instant or reviewed by sales first. ### What AI does Intelex have for incident reporting? Intelex describes Input AI, which scores incident descriptions. Auto Populate fills fields from dictation for review. SIF classification is also built in. Partner COMET adds an AI assistant for timelines and actions, with investigator approval. ### Is Intelex owned by Fortive? In July 2026 Intelex calls itself an operating company of Fortive Corporation. Its website footer names Intelex Technologies ULC as the legal owner. ### Does Intelex support OSHA 300, 300A and 301 forms? Yes. Intelex's OSHA Reports page says it automates Form 300, 300A and 301 records. Electronic submission to OSHA's Injury Tracking Application is not itemized. Ask for a demo. ## Sources - [Intelex: incident reporting software](https://www.intelex.com/landing/incident-reporting-software/) - [Intelex: pricing information](https://www.intelex.com/request-price) - [Intelex: Q3 2026 product launch (July 15, 2026)](https://www.intelex.com/about/press-room/intelex-announces-q3-2026-product-launch-advancing-visual-risk-management-and-ai-powered-workflows/) - [Intelex: Q3 2025 product launch](https://www.intelex.com/about/press-room/intelex-announces-q3-2025-product-launch-delivering-ai-powered-data-quality-enhanced-safety-intelligence-and-streamlined-user-experience-for-ehsq-operations/) - [Intelex: EHS platform (mobile, API, SSO, security)](https://intelex.com/ehs-platform) - [Intelex: OSHA reports application](https://www.intelex.com/products/applications/osha-reports) - [Intelex: OSHA injury reporting software](https://www.intelex.com/products/applications/osha-injury-reporting/) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs SafetyCulture (now Mitti): honest comparison > How IncidentKit and SafetyCulture (now Mitti) differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/safetyculture · Updated Oct 5, 2026 **SafetyCulture (now Mitti)**: An inspection app with issues, actions, investigations and training, rebranded from SafetyCulture to Mitti in August 2026. SafetyCulture, rebranded as Mitti in August 2026, is a mobile first operations platform built around digital inspections and checklists. Issue reporting, actions, investigations and training sit beside them. The company says AI is now in every plan. Teams can report an issue from a photo or voice note. They can scan a QR code to report without an account. They can download OSHA Forms 300A, 300 and 301 as CSV and PDF files for ITA submission. **Best for:** Frontline teams in manufacturing, construction, retail, hospitality and facilities. They start with inspections and want issues, actions and basic investigations in one app. **Scale (company-reported):** Press coverage of the August 11, 2026 rebrand reports the company's figures as more than two million frontline workers across 80,000 organizations. ## Pricing - **Model:** Subscription per seat with a free plan; pricing per location for operations with many sites; Enterprise by quote - **Published:** yes - As shown on the pricing page on 2026-10-05: Free for up to 10 seats; Premium $24 per seat per month billed annually ($29 monthly), excluding taxes; Enterprise custom. Operators with many sites can ask for a fixed price per location with unlimited users. AI Assistant use draws on monthly credits per full seat (300, 500 or 800 by plan, more for sale); AI issue creation does not. The help center says pricing may change. Onboarding services are quoted separately. ## Feature comparison | Feature | IncidentKit | SafetyCulture (now Mitti) | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | Yes: Free sign up and a Premium trial are self serve. Onboarding services on paid plans are quoted separately. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | Yes: Free, Premium and per location pricing are on the pricing page. Enterprise is custom. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | Yes: A Free plan covers up to 10 seats with 5 active inspection templates and basic issue, task and investigation features. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Yes: AI issue creation turns a photo, description or voice note into a drafted issue that the reporter reviews. It is on the Free plan and uses no credits. | | Voice reporting | Rolling out: Voice intake is rolling out. | Yes: Voice notes can be turned into issues for review. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: iOS and Android apps work offline and sync later. Issue QR codes let anyone report without an account. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Yes: Investigations collect evidence and support root cause analysis. They are on every plan. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Yes: Actions can be assigned and tracked from issues and from an investigation. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Not stated publicly: No QAPI, CMS or patient-event content was found in the pages reviewed. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Yes: OSHA reporting exports Forms 300A, 300 and 301 as CSV and PDF files for ITA submission, with TRIR, DART and LTIR calculated. Plan availability is not itemized. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: Sites, permissions and per location pricing for operations with many sites, plus benchmarking (early access on some plans). | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Yes: API on Premium (up to 50K calls a month) and Enterprise (up to 500K). Single sign-on (SSO) on Premium; SSO enforcement and SCIM on Enterprise. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: The security page lists ISO 27001:2022 and SOC 2 Type II. HIPAA and a BAA are not stated. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## SafetyCulture (now Mitti) strengths - Public prices and a real free plan with self serve sign up: Free for up to 10 seats and Premium at $24 per seat per month billed annually. - Easy for frontline staff: QR codes work without an account, the apps work offline, and AI turns photos or voice notes into drafts. - Investigations, actions and OSHA exports live in the same app as inspections and training. - ISO 27001:2022 and SOC 2 Type II, AES-256 and TLS 1.2 or later, and contracts that bar AI subprocessors from training on customer data. - The company reports more than two million frontline workers in 80,000 organizations (press, August 2026). ## Trade-offs to weigh - It centers on inspections and checklists. Incident management is one workflow among many. - Per seat pricing grows with headcount unless you negotiate pricing per location. The Free plan stops at 10 seats and 5 active templates. - AI Assistant use draws on monthly credits, and the help center says credit pricing may change. - SSO is on Premium, but SSO enforcement, SCIM, a sandbox and 24/7 support need Enterprise. - No HIPAA, BAA, QAPI or patient event content was found, and names are mid change from SafetyCulture to Mitti. ## Choose SafetyCulture (now Mitti) if - You want one app for inspections, checklists, issues, actions and training, with incidents as one workflow among several. - You need a free or low cost start with public prices. - Your workforce is mostly frontline and mobile, and QR reporting without an account matters. - You want OSHA 300, 300A and 301 CSV export for the ITA today. ## Choose IncidentKit if - Your incidents involve patients or residents, and you need a BAA, QAPI summaries and survey packets. - You want one flat price per site, not per seat pricing that rises with headcount. - You want Lauren to ask follow up questions and mark every AI draft until a person approves it. - You need corrective actions that cannot close until an effectiveness check is verified. ## Switching - Seat costs rise as more staff report. - Care setting needs go beyond an inspections first app. - Wanting investigations and action closure at the center. - Product and brand changes from SafetyCulture to Mitti. Export reports (PDF, Word or Excel), use the API on Premium or Enterprise for bulk data, and download OSHA forms as CSV or PDF. Export before you downgrade, because the Free plan limits analytics to 30 days. IncidentKit imports CSV files and sets up migration for you. OSHA 300, 300A and 301 exports are rolling out, so keep your OSHA records until then. ## Frequently asked questions ### Is SafetyCulture now called Mitti? Yes. Press coverage dated August 11, 2026 reports the rebrand to Mitti. The site safetyculture.com now redirects to mitti.com. The help center and pricing page say 'Mitti (by SafetyCulture)'. ### How much does SafetyCulture cost? The pricing page shows a Free plan for up to 10 seats and Premium at $24 per seat per month billed annually ($29 monthly), excluding taxes. Enterprise is custom, and operators with many sites can ask for a fixed price per location. ### Does SafetyCulture support OSHA 300, 300A and 301 forms? Yes. Its OSHA reporting help article says you can record cases by establishment and complete Forms 300A, 300 and 301. You can download CSV or PDF files for ITA submission. The plan comparison does not say which plans include it. ### Can workers report issues without an account? Yes. Issue QR codes let anyone scan, pick a category, add a description and photos or videos, and submit without an account. Admins create the codes in the web app. ### What AI does SafetyCulture have for incident reporting? AI issue creation turns a photo, description or voice note into a drafted issue for the reporter to review, and uses no credits. The AI Assistant answers questions about your data and drafts reports using monthly credits, and Agents run background tasks. ## Sources - [SafetyCulture (Mitti): pricing](https://safetyculture.com/pricing/) - [SafetyCulture (Mitti): AI platform](https://safetyculture.com/ai) - [SafetyCulture (Mitti): security](https://safetyculture.com/security) - [Help center: investigations](https://help.safetyculture.com/005065) - [Help center: OSHA reporting](https://help.safetyculture.com/005371) - [Help center: what uses your AI credits](https://help.safetyculture.com/007451) - [Help center: create issue QR codes](https://help.safetyculture.com/000165) - [Startland News: SafetyCulture rebrands to Mitti (August 11, 2026)](https://startlandnews.com/2026/08/safetyculture-mitti/) - [Startland News: SafetyCulture funding round (May 3, 2021)](https://startlandnews.com/2021/05/safetyculture-valuation/) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs Benchmark Gensuite: honest comparison > How IncidentKit and Benchmark Gensuite differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/benchmark-gensuite · Updated Oct 5, 2026 **Benchmark Gensuite**: A configurable EHS and sustainability platform with Genny AI built in, aimed at global enterprises. Benchmark Gensuite is a founder led enterprise platform for EHS, sustainability, quality and operational risk. It runs on one architecture. Its Incident Management app records incidents by type. It supports root cause analysis and corrective and preventive actions. It also handles injury and illness records. Genny AI adds voice to text, image analysis, description coaching, and suggested root causes and corrective actions. **Best for:** Global enterprises in manufacturing, chemicals, pharma, automotive, and food and beverage. They run EHS and compliance programs across many sites. **Ownership:** Benchmark Digital Partners LLC; Vista Equity Partners is a minority investor (2023) **Scale (company-reported):** Company states 8M+ workers served globally, 20+% of the Fortune 500, 95% retention and 25+ years in business (homepage, checked 2026-10-05). A 2023 release cited over 400 customers and three million users. ## Pricing - **Model:** Subscription priced by quote; AI is described as included in every subscription - **Published:** no - No pricing appears on benchmarkgensuite.com. An August 2025 HSE Network article quotes the company saying Genny AI is built into every subscription. Confirm that in writing. The vendor does not confirm third party estimates, so none are used. ## Feature comparison | Feature | IncidentKit | Benchmark Gensuite | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | No: Calls to action are demo requests. The vendor markets fast adoption but through a vendor led setup. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | No: No prices are published on the vendor site. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | No: No free tier or self-signup is listed. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Yes: Workers can speak a report or attach a photo. Genny AI's Image Helper writes hazard descriptions. Key fields fill in on their own. Describe-It AI coaches the description as it is written. | | Voice reporting | Rolling out: Voice intake is rolling out. | Yes: Voice to text reporting is described for Anvl Mobilize AI and Concern Capture Voice AI. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: Mobile forms work offline and in many languages. Anvl can turn paper or PDF forms into digital ones. QR code reporting is not described. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Yes: Structured root cause analysis. A 5 Why AI Helper drafts a first analysis from the incident narrative. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Yes: CAPA tracking with automated notices and escalations. Suggestion AI drafts corrective action plans for review. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Not stated publicly: No QAPI or CMS content was found. 'Pharma & Healthcare' on the homepage refers to quality systems and rules. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Yes: An Injury and Illness Recordkeeping function creates OSHA reports, with updates for the 2024 electronic reporting changes. Specific forms are not itemized. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: One architecture and data layer across sites, with Tableau and Power BI analytics built in. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Yes: More than 20 APIs for HR directory data, hours worked feeds, IoT devices and external sharing. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: SOC 1 and SOC 2 audits were completed in August 2023. HIPAA and a BAA are not stated. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## Benchmark Gensuite strengths - AI helps at many steps: voice to text, images, description coaching, 5 Why drafts, action ideas, a significant incident draft and a serious incident advisor. - The company reports 20+% of the Fortune 500 as customers. Incidents, CAPA, inspections and sustainability share one data layer. - Flexible frontline capture: offline mobile, many languages, anonymous reports, paper forms made digital. - More than 20 APIs for HR, hours worked and IoT data, plus Power BI and Tableau. - SOC 1 and SOC 2 audits completed in August 2023 with A-LIGN, and 25+ years in EHS. ## Trade-offs to weigh - No public pricing, and every path starts with a demo. - The EHS suite has six solutions, and the platform also covers sustainability, quality and supply chain. An incident only team may not need that much. - SSO, QR code reporting and a BAA are not stated on the pages reviewed. - Healthcare coverage is limited to pharma quality and on site clinic records for worker care. Patient safety events and QAPI are not described. - Several AI outcomes are company reported, so ask for references that match your industry and size. ## Choose Benchmark Gensuite if - You are a global manufacturer or process company that wants a full EHS suite on one data layer. - You want AI help with descriptions, 5 Why drafts and action ideas, included in the subscription. - You need OSHA records linked to HR, occupational health and workers' compensation systems. - You want a large enterprise customer base and many APIs. ## Choose IncidentKit if - Your incidents involve patients or residents. You need a BAA, QAPI summaries and survey packets. - You want one flat price per site, with no seats, modules or setup fee, and a free plan for non patient incidents. - You want a smaller product for reporting, investigation and verified corrective actions. - You want every AI draft marked 'Lauren · draft' until a person reviews, edits and signs. ## Switching - Care setting needs that a manufacturing suite skips. - A wish for public, flat per site pricing. - Needing incident tools without a long setup. - A preference for self serve evaluation over demos. Export incident records, root cause notes and open CAPA items through Gensuite's reports or APIs. IncidentKit imports CSV files and sets up migration for you. Keep archived injury and illness records for the retention period. OSHA 300, 300A and 301 exports are rolling out, so keep your OSHA records until then. ## Frequently asked questions ### Does Benchmark Gensuite publish pricing? No. The site offers demo requests and no price list. An August 2025 trade article quotes the company saying Genny AI is built into every subscription. Confirm in writing which AI tools your quote includes. ### What is Genny AI? Genny AI is the AI layer. For incidents it has Describe-It AI (description coaching), a 5 Why AI Helper, Suggestion AI (corrective actions), Significant Incident Communication AI, Image Helper, voice to text, and a PSI AI Advisor that flags potentially serious incidents. ### Does Benchmark Gensuite support voice and offline reporting? Yes. Its blog says Anvl Mobilize AI lets field teams complete incident forms offline. They can speak a report or attach a photo that Genny AI analyzes. Key fields fill in on their own. A person still reviews the draft. ### Does Benchmark Gensuite handle OSHA recordkeeping? Yes. Its incident page describes injury and illness records built around OSHA compliance. A company post covers the 2024 electronic reporting changes. Forms 300, 300A and 301 are not itemized. ### Who owns Benchmark Gensuite? Benchmark Gensuite is operated by Benchmark Digital Partners LLC. In 2023 Vista Equity Partners made a minority growth investment through its Endeavor Fund, the first outside capital. A Vista executive joined its board. The founder stayed CEO at the time. ## Sources - [Benchmark Gensuite: incident management software](https://benchmarkgensuite.com/incident-management-software/) - [Benchmark Gensuite blog: AI automates frontline incident reporting](https://benchmarkgensuite.com/ehs-blog/ai-automates-frontline-incident-reporting/) - [Benchmark Gensuite: homepage](https://benchmarkgensuite.com/) - [Benchmark Gensuite: EHS software suite](https://benchmarkgensuite.com/solutions/environmental-health-safety-software/) - [Benchmark Gensuite: system interoperability and APIs](https://benchmarkgensuite.com/app/system-interoperability-apis/) - [Benchmark Gensuite: Vista Equity Partners minority investment release](https://benchmarkgensuite.com/press-release/benchmark-gensuite-receives-minority-growth-investment-from-vista-equity-partners/) - [Benchmark Gensuite: SOC 1 and SOC 2 audits release](https://benchmarkgensuite.com/press-release/benchmark-gensuite-successfully-completes-soc-1-soc-2-audits/) - [HSE Network: an introduction to Genny AI (August 5, 2025)](https://hse-network.com/benchmark-gensuite-an-introduction-to-genny-ai/) - [Benchmark Gensuite blog: incident management category](https://benchmarkgensuite.com/ehs-blog/category/incident-management/) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs EHS Insight: honest comparison > How IncidentKit and EHS Insight differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/ehs-insight · Updated Oct 5, 2026 **EHS Insight**: A modular EHS and ESG platform with offline mobile, a published starting price and an AI assistant connector. EHS Insight is an EHS and ESG platform from StarTex Software. It has 32 modules, including incident management with built in 300, 300A and 301 form support, investigation tools, corrective action tracking and offline mobile reporting. Its AI reviews incident descriptions, analyzes photos and detects serious injury and fatality precursors. A Model Context Protocol connector lets customers query their data from Claude, ChatGPT or Microsoft Copilot. **Best for:** Small to large employers in construction, manufacturing, energy, logistics, chemicals and government. They want a modular EHS system they can onboard themselves. **Ownership:** StarTex Software LLC **Scale (company-reported):** Company states over 500,000 users (incident management page, checked 2026-10-05) and says it has operated since 2009. ## Pricing - **Model:** Annual subscription priced by modules and by the number of employees and contractors; Enterprise license bundle and support packages - **Published:** yes - The pricing page shows the small and medium business solution 'starting at $5k per year'. Final quotes depend on modules and headcount. Terms are annual by default. An Enterprise bundle includes every module. Enterprise Support adds 40 onboarding hours and four dedicated support hours a month; a one time Rapid Success Package is lighter. ## Feature comparison | Feature | IncidentKit | EHS Insight | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | Partial: A free trial, an instant demo with no sales call and self onboarding are advertised. Larger rollouts buy onboarding hours and support. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | Partial: The pricing page shows $5k per year as a starting point for small and medium businesses. The final price depends on modules and headcount. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | No: A free trial is offered; no free plan is listed. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Partial: AI reviews incident descriptions for missing concepts and analyzes photos, and the AI Copilot can draft reports. Conversational follow up is not described. | | Voice reporting | Rolling out: Voice intake is rolling out. | Not stated publicly: Voice reporting is not described on the pages reviewed. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: A native app works with or without a connection and syncs later. QR codes and links open forms, with anonymous submissions. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Yes: Built-in investigation tools help identify underlying causes and prevent repeat incidents. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Yes: Tasks, deadlines and follow up actions are tracked until incidents close. AI suggests actions from photos on an investigation. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Not stated publicly: No QAPI or CMS content was found in the pages reviewed. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Yes: Built in 300, 300A and 301 form support, with tracking of OSHA, WCB, RIDDOR and MSHA needs. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: Reporting by facility, region and business entity across an organization. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Yes: RESTful API, SSO, a Power BI connector, and an MCP connector over OAuth for Claude, ChatGPT and Microsoft Copilot. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: The security page lists ISO 27001, AWS hosted SOC 2 and SOC 3 reports, GDPR and EU US data privacy. HIPAA and a BAA are not stated. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## EHS Insight strengths - A published starting price, free trial, instant demo and self onboarding make evaluation easier than with quote only vendors. - Mobile first: offline mode, QR codes with anonymous submissions, and 30 language options. - AI beyond writing help: description review, photo analysis, SIF precursor detection and an MCP connector to AI assistants. - OSHA 300, 300A and 301 support plus WCB, RIDDOR and MSHA tracking. - Start with one module and add more, or take an Enterprise bundle with all 32. ## Trade-offs to weigh - Price depends on employees and contractors as well as modules. The published figure is a starting point. - Enterprise support (onboarding hours, dedicated reps) is a separate paid package. - The vendor calls itself standard out of the box, which may limit tailoring. - Healthcare is not among the industries on the homepage, and no QAPI or BAA statement was found. - Voice reporting is not described. The MCP connector moves live data into outside AI tools, which needs a data review. ## Choose EHS Insight if - You want a modular EHS system with a published starting price and a free trial before you talk to sales. - You need offline mobile, QR reporting and OSHA 300, 300A and 301 support in construction, energy, logistics or manufacturing. - You want to query EHS data from Claude, ChatGPT or Copilot through a supported connector. - You expect to add modules over time. ## Choose IncidentKit if - Your incidents involve patients or residents, and you need a BAA, QAPI summaries and survey packets. - You want one flat price per site, not pricing by employees, contractors and modules. - You want Lauren to ask follow up questions and mark each draft field until a person signs off. - You want a free plan for non patient incidents and one focused product. ## Switching - Pricing tied to staff and contractors, not sites. - Care setting needs fall outside an industrial EHS catalog. - Wanting a smaller product focused on incidents. - A preference for AI intake with follow up questions. Export incidents, investigations and open corrective actions from EHS Insight using its reports, Power BI connector or API. IncidentKit imports CSV files and sets up migration for you. Keep archived OSHA 300 logs for the required retention period. OSHA 300, 300A and 301 exports are rolling out, so keep your current OSHA records until then. ## Frequently asked questions ### How much does EHS Insight cost? The pricing page says the small and medium business solution starts at $5k per year. Final pricing depends on modules and the number of employees and contractors, with annual terms by default. ### Does EHS Insight have a free trial? Yes. The site advertises a free trial and a free instant demo with no sales call. It does not list a permanent free plan. ### Does EHS Insight work offline? Yes. The mobile app lets field teams run audits, complete inspections and file incident reports with or without a connection, and syncs when connectivity returns. ### What AI does EHS Insight have for incident reporting? Its AI reviews incident descriptions for missing concepts, analyzes photos, suggests corrective actions and detects serious injury and fatality precursors. A separate connector exposes live data to Claude, ChatGPT and Microsoft Copilot. ### Does EHS Insight support OSHA 300, 300A and 301 forms? Yes. The incident management page says the module has built in 300, 300A and 301 form support and tracks needs such as OSHA, WCB, RIDDOR and MSHA. ## Sources - [EHS Insight: incident management module](https://www.ehsinsight.com/solutions/modules/incident-management-software) - [EHS Insight: pricing](https://www.ehsinsight.com/solutions/platform/pricing) - [EHS Insight: AI solutions](https://www.ehsinsight.com/solutions/platform/ehs-insight-ai-solutions) - [EHS Insight: platform overview](https://www.ehsinsight.com/solutions/platform) - [EHS Insight: cloud security](https://www.ehsinsight.com/solutions/cloud-security) - [EHS Insight: about us](https://www.ehsinsight.com/about-us) - [EHS Insight: QR codes update](https://www.ehsinsight.com/blog/ehs-insight-introduces-qr-codes) - [EHS Insight: homepage](https://www.ehsinsight.com/) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs Safesite: honest comparison > How IncidentKit and Safesite differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/safesite · Updated Oct 5, 2026 **Safesite**: A field safety app for inspections, hazards and incidents, with a free plan and ties to a workers' compensation insurer. Safesite is a mobile safety app, used mainly in construction, agriculture and manufacturing, for inspections, hazards, incident reports, safety meetings and observations. It has a free plan with unlimited members and guests. Premium adds unrestricted reporting and a recordable incident log for OSHA 300. Safesite is part of Foresight Group, whose workers' compensation insurer uses the policy year average Safesite Score at renewal. **Best for:** Small and mid size contractors, agriculture and manufacturing teams that want a low cost field safety app. Some pair it with Foresight workers' compensation coverage. **Ownership:** Foresight Group **Scale (company-reported):** Company says thousands of companies use Safesite and reports 21,000+ hazards closed yearly (safesitehq.com, undated, checked 2026-10-05). ## Pricing - **Model:** Free plan; Premium priced per member per month; a tier tied to insurance, sold through brokers - **Published:** yes - The pricing page shows Premium at $16 per member per month billed annually ($20 billed monthly), with a 30 day trial. Free includes the app, dashboard and unlimited members and guests, but limits reporting to 30 days. The Foresight tier is sold through insurance brokers and adds coaching, loss analysis and a compliance review. ## Feature comparison | Feature | IncidentKit | Safesite | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | Yes: Sign up free with no credit card. Assisted onboarding belongs to the insurance linked tier. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | Yes: Free and Premium prices are shown on the pricing page. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | Yes: Free includes the mobile app, the risk dashboard and unlimited members and guests, with reporting limited to the last 30 days. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Not stated publicly: No AI features are described on the pages reviewed. | | Voice reporting | Rolling out: Voice intake is rolling out. | Not stated publicly: Voice reporting is not described on the pages reviewed. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: iOS and Android apps. All core features work offline and sync later, in English, Spanish, French and Portuguese. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Partial: Incident data supports root cause trend review. A structured method such as five whys is not described. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Yes: Hazard resolution and corrective actions with priority, assignment and notices. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Not stated publicly: No QAPI or CMS content was found in the pages reviewed. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Partial: Premium adds a recordable incident log that makes an OSHA 300 log in one click (US only). Forms 300A and 301 are not mentioned. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: Projects, groups and divisional reporting, with group level reporting on Premium. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Not stated publicly: No API or SSO documentation was found on the product pages or help center index reviewed. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: HIPAA and a BAA are not mentioned in the pages reviewed. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## Safesite strengths - A free plan with unlimited members and guests, and Premium at $16 per member per month billed annually. - All core features work offline, and the app comes in four languages. - Incident capture covers injuries, near misses, theft, property damage and equipment failure, with images and witness statements. - Hazard management with priority, assigned corrective actions, leading indicator analytics and a Safesite Score. - Optional pairing with Foresight workers' compensation, and a safety success coach for the first 30 days. ## Trade-offs to weigh - The Free plan limits reporting to the last 30 days, so full history needs Premium. - OSHA support is a 300 log on Premium (US only). Forms 300A and 301 and ITA submission are not mentioned. - No AI intake, SSO or API is described publicly. - Aimed at field safety. Investigation depth (root cause methods, effectiveness checks) is not described. - Safety Success and the Safesite Score tied to premium credits connect to Foresight insurance policies. ## Choose Safesite if - You are a contractor or small industrial employer that wants a free or low cost field safety app. - Offline use on job sites and a Spanish, French or Portuguese interface matter. - You may place workers' compensation through Foresight and want the Safesite Score to count at renewal. - A simple OSHA 300 log is enough for you. ## Choose IncidentKit if - Your incidents involve patients or residents, and you need a BAA, QAPI summaries and survey packets. - You need a structured investigation with contributing factors and corrective actions that cannot close until verified. - You want staff to describe an event in plain text, and Lauren to ask follow up questions, with a person signing. - You want SSO and a read API when you reach a group of sites, or one flat price per site. ## Switching - Outgrowing a checklist app and needing real investigations. - Care setting needs that a construction app skips. - Needing OSHA 300A and 301 support. - Wanting SSO and API access for a growing group. Export incident and hazard reports in PDF, CSV or XLS (full history needs Premium) and download the OSHA 300 log as Excel. IncidentKit imports CSV files and sets up migration for you. Export before you cancel or downgrade. OSHA 300, 300A and 301 exports are rolling out, so keep your OSHA records until then. ## Frequently asked questions ### Is Safesite free? Yes, there is a free plan with the mobile app, the risk dashboard and unlimited members and guests, but reporting is limited to the last 30 days. Premium is $16 per member per month billed annually ($20 monthly), with a 30 day trial. ### Does Safesite support the OSHA 300 log? Yes, on Premium. Recordable incidents can be added to a log with one click and downloaded as an Excel file for US customers. The pages reviewed do not mention OSHA Forms 300A or 301 or electronic submission to the ITA. ### Does Safesite work offline? Yes. Its offline mode page says all core features work offline, and saved work syncs to the dashboard when connectivity returns. ### Who owns Safesite? Safesite's press page says Safesite and Foresight, a workers' compensation insurer, are part of Foresight Group. Foresight's page says it takes the policy year average Safesite Score into account for renewal premium credits. ### Does Safesite have AI features for incident reporting? None are described on the pages reviewed. Safesite lists incident reporting, hazard management and leading indicator analytics, but its public pages mention no AI intake, description analysis or root cause suggestions. ## Sources - [Safesite: pricing](https://safesitehq.com/pricing/) - [Safesite: incident reporting](https://safesitehq.com/features/real-time-incident-reports/) - [Safesite: OSHA 300 form integration](https://safesitehq.com/features/osha-300-form-integration/) - [Safesite: offline mode](https://safesitehq.com/features/offline-mode/) - [Safesite: press page](https://safesitehq.com/press/) - [Safesite: Foresight insurance page](https://safesitehq.com/foresight/) - [Safesite: about](https://safesitehq.com/about-safesite/) - [Safesite: features overview](https://safesitehq.com/features/) - [Safesite: homepage](https://safesitehq.com/) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs Vector Solutions: honest comparison > How IncidentKit and Vector Solutions differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/vector-solutions · Updated Oct 5, 2026 **Vector Solutions**: Training software with an EHS Management product that ties incidents to corrective actions, training and OSHA records. Vector Solutions began in online continuing education in 1999. It now sells training, workforce readiness and EHS software to industrial, education and public safety customers. Its Vector EHS Management product records injuries, illnesses, near misses, vehicle and contractor incidents. Each report links to corrective actions, claims and assigned training. It can generate OSHA Forms 300, 300A and 301, with CSV export for electronic submission. **Best for:** Safety teams in construction, manufacturing, government, higher education and K-12. They also buy training and want it linked to incidents and claims. **Scale (company-reported):** The company states more than 24,000 customers across all its products and industries (about page, checked 2026-10-05). EHS specific counts are not published. ## Pricing - **Model:** Subscription priced by quote, requested through a demo; no public price list - **Published:** no - No pricing appears on the EHS pages reviewed; the calls to action are Request a demo and an interactive product tour. The anonymous public web form is an add-on, and the page does not say whether it is priced separately. ## Feature comparison | Feature | IncidentKit | Vector Solutions | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | No: Calls to action are demo requests and an interactive product tour. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | No: No prices are published on the EHS pages reviewed. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | No: No free tier or self signup is listed for the EHS product. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | Partial: The EHS Incident Assistant gives real time prompts on incident descriptions and flags missing detail. Follow up questioning of the reporter is not described. | | Voice reporting | Rolling out: Voice intake is rolling out. | Not stated publicly: Voice reporting is not described for the EHS product (Vector mentions AI voice only in separate public sector products). | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Yes: An iOS and Android incident app works without a connection and uploads later. An anonymous public web form is an add-on. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Yes: Configurable forms and workflows with root cause analysis, and links to claims, assets and attachments. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Yes: Corrective actions and corrective training assignments are tracked to completion in one workflow. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Not stated publicly: No QAPI or CMS content was found. The incident page names healthcare among industries. It describes no healthcare specific incident features. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Yes: Generates OSHA Forms 301, 300 and 300A. Exports CSV files for electronic submission. Helps decide if a case is recordable. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | Yes: Manages complex organization structures, with dashboards for KPIs and incident rates. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | Partial: The vendor says it integrates with HR, payroll and third party claims administrators. No API reference or SSO statement was found. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: HIPAA and a BAA are not mentioned on the pages reviewed. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## Vector Solutions strengths - Corrective training can be assigned inside the corrective action workflow, and the same vendor sells the courses. - OSHA Forms 301, 300 and 300A with recordable and reportable checks and CSV export. - An AI Incident Assistant flags missing detail before the report is submitted. - Mobile reporting works offline, and an anonymous web form is an add-on. - Links to HR, payroll and third party claims administrators, plus a claims module. ## Trade-offs to weigh - No public pricing, and every path starts with a demo. - Vector's homepage is built around training. EHS Management is one product among many. - SSO, a public API reference, a BAA, QAPI and patient event reporting are not stated on the pages reviewed. - The anonymous reporting form is an add-on, not part of the base product. - Voice reporting for incidents is not described. ## Choose Vector Solutions if - You already use or plan to buy Vector's training courses and want incident driven retraining. - You need OSHA 300, 300A and 301 generation with CSV export for electronic submission today. - You are a government, higher education or K-12 safety team. - You want incidents linked to workers' compensation claims and third party administrator data. ## Choose IncidentKit if - Your incidents involve patients or residents, and you need a BAA, QAPI summaries and survey packets. - You want one public flat price per site, with no seats, modules or setup fee, and a free plan for non patient incidents. - You want Lauren to ask follow up questions and draft the investigation, with a person signing every record. - You want a product built for reporting, investigation and verified corrective actions, not training. ## Switching - Care setting needs that a training led product skips. - A wish for public, flat per site pricing. - Wanting a product centered on incidents, apart from training. - A preference for AI intake that asks follow up questions. Export incident records, claims links and open corrective actions from Vector EHS through its reports and CSV exports. IncidentKit imports CSV files and sets up migration for you. If you keep Vector for training, assigned training records stay there. OSHA 300, 300A and 301 exports are rolling out, so keep your OSHA records until then. ## Frequently asked questions ### Does Vector Solutions publish EHS pricing? No. The EHS pages reviewed offer a demo request and an interactive tour, and no price list. The anonymous public web form is described as an add-on, so ask whether it is priced separately. ### What AI does Vector EHS have for incident reporting? Vector describes an EHS Incident Assistant. It reviews an incident description while the report is still open and flags what is missing. Its about page also lists a safety training recommendation engine as a separate AI feature. ### Does Vector EHS support OSHA 300, 300A and 301? Yes. The incident page says it generates OSHA forms 301, 300 and 300A and exports data to CSV files for electronic submission. It also says it helps decide whether a case is recordable and reportable. ### Can employees report incidents anonymously in Vector EHS? Yes, through the Incident Public Web Form, which Vector offers as an add-on. It lets people report through a web link without a username or password. The incident mobile app is separate and works offline. ### Does Vector EHS work for hospitals and healthcare? The incident page names healthcare among the industries that use the product. It describes worker safety incidents, OSHA records and corrective training. It does not describe patient safety events, QAPI or a HIPAA BAA, so ask the vendor directly. ## Sources - [Vector Solutions: incident reporting software (Vector EHS)](https://www.vectorsolutions.com/solutions/vector-ehs-management-software/incidents/) - [Vector Solutions: EHS management software](https://www.vectorsolutions.com/solutions/vector-ehs-management-software/) - [Vector Solutions: about us](https://www.vectorsolutions.com/about-us/) - [Vector Solutions: homepage](https://www.vectorsolutions.com/) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # IncidentKit vs paper and spreadsheets: honest comparison > How IncidentKit and Paper and spreadsheets differ on intake, corrective actions, compliance packets, pricing and fit. Sources and dates included. Source: https://incidentkit.ai/compare/paper-and-spreadsheets · Updated Oct 5, 2026 **Paper and spreadsheets**: Paper variance forms, a binder, a shared drive and an Excel log. Most small facilities and many plants start with paper incident forms, a binder or filing cabinet, and a spreadsheet log. It costs nothing in software. It works until volume, turnover or a survey exposes the gaps. Forms get filled in days later, from memory. Incidents never reach the right person. Corrective actions have no owner. Staff scramble to assemble evidence. **Best for:** Very small sites with few incidents and one person who owns the process. ## Pricing - **Model:** No software cost; staff time - **Published:** yes - The real cost is staff hours: rebuilding incidents, chasing owners and building survey and audit packets. ## Feature comparison | Feature | IncidentKit | Paper and spreadsheets | | --- | --- | --- | | Self-serve start | Yes: Start free and report your first incident the same day. | Yes: Nothing to buy or set up. | | Public pricing | Yes: Free Open plan; Regulated listed per site per month; Network by quote. | Yes: No licence fee. | | Free plan | Yes: Open plan: unlimited reporters, 50 incidents a month, for non-patient incidents. | Yes: No software cost. | | AI-assisted intake | Yes: Lauren asks follow-ups and drafts the report; a person always reviews and signs. | No: A person types or writes everything. | | Voice reporting | Rolling out: Voice intake is rolling out. | No: Not available. | | Mobile and QR reporting | Yes: Installable web app, QR quick report, offline queue for quick reports. | Partial: Photos of paper forms and shared drive files on a phone, with no workflow. | | Investigation and RCA tools | Partial: Contributing factors and five whys today; fishbone and fault-tree templates rolling out. | Partial: Worksheets can be printed. Nothing links them to the incident. | | Corrective action (CAPA) workflow | Yes: Owner, due date, evidence, effectiveness check; closure requires verification. | Partial: Possible in a spreadsheet. Owners, reminders and verification depend on discipline. | | QAPI and accreditation reporting | Yes: QAPI summary and per-incident packets; survey packets rolling out. | Partial: Possible by hand in a binder; assembling it is manual. | | OSHA 300, 300A, 301 support | Rolling out: OSHA 300, 300A and 301 outputs are rolling out. | Partial: OSHA publishes blank 300, 300A and 301 forms. Completing them is manual. | | Multi-site and roles | Yes: Organizations, facilities, six roles, SSO. | No: Each site keeps its own files. Roll ups are manual. | | Open API | Partial: Read API and signed webhooks; write API on the roadmap. | No: Not applicable. | | HIPAA BAA available | Yes: BAA included on Regulated and Network plans. | Not stated publicly: Not applicable. Paper and shared drives carry their own privacy risks. | "Not stated publicly" means the vendor does not say either way. It is not the same as no. Verified Oct 5, 2026. ## Paper and spreadsheets strengths - Zero licence cost and no setup time. - Everyone already knows a form and a pen. - Works with no signal and no login. - A fair stopgap for a very small site with a handful of incidents a year. ## Trade-offs to weigh - Forms are often filled in hours or days later, from memory, so details are lost. - No routing: a serious incident reaches the right person only if someone walks it over. - Corrective actions have no owner, date or check unless someone builds that habit. - Trends stay hidden until someone retypes the data into a spreadsheet. - Survey and audit prep means gathering evidence by hand, usually under time pressure. ## Choose Paper and spreadsheets if - You are a very small site with a few incidents a year and one owner who reviews each. - You need a stopgap this week and will revisit tools next quarter. ## Choose IncidentKit if - Staff report late, skip near misses, or hand the form to a supervisor to file. - You cannot say which corrective actions are open, overdue or verified without asking around. - Survey or audit season means a week of binder building. - You run more than one site and want one standard. ## Switching - Reporting takes seconds on a phone, not a desk later. - Severity routes the incident to the right person at once. - Packets, logs and trends come from one record, so nothing is retyped. Import past incidents from your spreadsheet with the CSV wizard, or send us the file and we will map and load it. Scanned paper logs can be keyed in or extracted. Keep the binder until the new records cover a full survey cycle. ## Frequently asked questions ### Is paper incident reporting compliant? Paper can meet the requirement. Regulators care that incidents are recorded, investigated and acted on, not whether the record is paper. The risk is gaps, delays and missing evidence. See [replacing paper incident forms](https://incidentkit.ai/use-cases/replace-paper-incident-forms). ### What does paper actually cost? There is no licence fee. The cost is staff time: completing forms, retyping logs, chasing corrective actions and assembling survey or OSHA evidence. Teams often miss it because the hours are spread across many people. ### When should a facility move off spreadsheets? Common triggers are a second site, a missed reporting deadline, a survey or audit scramble, a recurring incident nobody connected, or staff avoiding the form. Any one is a fair reason to move. ### Can we keep our spreadsheet during the transition? Yes. Many teams run both for a few weeks, import the history, and retire the spreadsheet once reporting has moved. ## Sources - [OSHA: Recordkeeping forms (300, 300A, 301)](https://www.osha.gov/recordkeeping/forms) - [OSHA: Injury and illness recordkeeping and reporting requirements](https://www.osha.gov/recordkeeping) Spot an error? Email hello@incidentkit.ai and we will correct it. --- # Incident reporting in healthcare: the complete guide > Incident reporting records events that harmed, or nearly harmed, a patient, resident or worker. A good system takes reports from anyone, includes near misses and escalates serious events within hours. Every report ends in verified corrective action and feedback to the reporter. Source: https://incidentkit.ai/guides/incident-reporting-in-healthcare · Updated Oct 5, 2026 ## An incident report records harm or near harm A healthcare incident report is a structured record of an event that harmed, or could have harmed, a patient, resident, visitor or staff member. It captures the facts while they are fresh, so someone can respond, find causes and prevent a repeat. The name changes by setting. Hospitals say patient safety event. Surgery centers and nursing homes say adverse event or occurrence. Older systems say variance report. See [incident report vs variance report vs occurrence report](https://incidentkit.ai/blog/incident-report-vs-variance-report-vs-occurrence-report). A report is a learning tool, not a chart entry, a disciplinary file or a regulator submission. Mixing those uses teaches staff that reporting puts them at risk. ## Confidentiality depends on how you create the report The federal Patient Safety and Quality Improvement Act protects patient safety work product that a provider assembles to report to a [patient safety organization](https://incidentkit.ai/glossary/patient-safety-organization). It does not protect records kept separately to meet an outside requirement. Ask counsel how your state's privilege rules apply. ## Report harm, near misses and unsafe conditions Report anything that harmed someone, reached someone without harm, or was caught in time. Add conditions that make an event likely. The Joint Commission's hospital standards run from no-harm errors (close calls, near misses, good catches) up to sentinel events. *Categories a healthcare reporting form should accept* | Type | What it is | Example | | --- | --- | --- | | Harm event | Reached the person and caused injury | Wrong dose given; fall with a fracture | | No-harm event | Reached the person, no injury | Medication given late, no effect | | Near miss | Caught before it reached the person | Wrong-patient label caught at the time-out | | Unsafe condition | Likely to cause an event | Look-alike vials stored together | | Staff injury or exposure | Harm to a worker | Contaminated needlestick | | Allegation or complaint | Concern about abuse, neglect or rights | Injury of unknown source | | Equipment problem | Malfunction or use error | Infusion pump alarm that did not sound | ## Staff miss most events that should be reported Staff cannot report what they do not see as reportable. In a 2012 HHS Office of Inspector General (OIG) study, hospital incident systems captured an estimated 14 percent of the harm events Medicare patients experienced. Administrators said staff did not see about 61 percent of harm events as reportable. Another 25 percent were events staff usually report but did not that time. OIG asked AHRQ and CMS to publish a list of reportable events. Do the same locally: a short list, with examples from your setting. ## Each regulator uses its own words for events The definitions are not interchangeable. Pick one internal vocabulary and map it to each outside term. The best split is what happened to the person: harm, no harm, or caught in time. | Term | Where you will see it | What it means | | --- | --- | --- | | Adverse event | CMS rules, HHS OIG, QAPI | Harm from medical care, not the condition. See [adverse event](https://incidentkit.ai/glossary/adverse-event). | | Error and near miss | CMS surveyor guidance, surgery centers | An error is a planned action not done as intended. A near miss is an error with no adverse event. | | Sentinel event | Joint Commission | A safety event that reaches a patient and causes death, severe harm or permanent harm. See [sentinel event](https://incidentkit.ai/glossary/sentinel-event). | | Serious reportable event | NQF list; 30+ states and DC | The 2025 NQF list has 28 events in four categories. The Joint Commission plans to adopt it in January 2027. | | Serious event and incident | Pennsylvania MCARE Act | A serious event causes death or unexpected injury needing more care. An incident could have, but did not. | | Temporary harm event | HHS OIG | Needed action, but no lasting harm. | | Recordable injury | OSHA | A work-related case meeting Part 1904 criteria. See [OSHA recordable](https://incidentkit.ai/glossary/osha-recordable). | ## Anyone who sees an event should report it The first report usually comes from the person closest to the event. Physicians file less often than nurses and allied staff, so ask them directly. - **Clinical staff**, including float, agency and night staff. - **Support staff** in cleaning, dietary, maintenance and transport. - **Contractors, volunteers and visitors**, by a short form or email with no login. - **Patients and families**, who raise what staff did not see. Some states make reporting a personal duty. Under Pennsylvania's MCARE Act, a health care worker who reasonably believes a serious event or incident occurred must report it. Reporters are protected from retaliation. Offer confidential reporting by default, and anonymous where fear of blame is high. Anonymous reports cannot get follow-up questions. A [QR quick report](https://incidentkit.ai/product/quick-report) or [email-to-incident](https://incidentkit.ai/product/email-to-incident) address helps people with no login. ## Report inside the shift; outside deadlines vary Internally, aim for the same shift. Outside deadlines depend on the event, your setting and your state. The clock starts when your organization learns of the event. For OSHA, that means you or any of your agents. | Event | Deadline | Report to | Source | | --- | --- | --- | --- | | Any serious event or incident (Pennsylvania) | Immediately; within 24 hours of occurrence or discovery | Facility, per its patient safety plan | MCARE Act section 308(a) | | Confirmed serious event (Pennsylvania) | Within 24 hours of confirmation | State health department, Patient Safety Authority | MCARE Act section 313(a) | | Alleged abuse or neglect in a nursing home | 2 hours if abuse or serious bodily injury; otherwise 24 hours | Administrator, State Survey Agency, others per state law | 42 CFR 483.12(c)(1) | | Results of that investigation | Within 5 working days of the incident | Administrator and State Survey Agency | 42 CFR 483.12(c)(4) | | Hospital death tied to restraint or seclusion | Close of business next business day after learning of it | CMS | 42 CFR 482.13(g)(1) | | Device-related death | As soon as practicable, within 10 work days | FDA, manufacturer | 21 CFR 803.30(a)(1) | | Device-related serious injury | Within 10 work days | Manufacturer (FDA if unknown) | 21 CFR 803.30(a)(2) | | Sentinel event analysis and action plan | Within 45 business days of the event or learning of it | Joint Commission (reporting is voluntary; analysis is not) | Sentinel Event Policy | | Employee death; hospitalization, amputation, eye loss | 8 hours; 24 hours | OSHA | 29 CFR 1904.39 | **Example.** At 2 p.m. an aide reports a bruise of unknown source. If staff suspect abuse, or the injury is serious, the report is due by 4 p.m. Otherwise the limit is 24 hours. Results are due within 5 working days. State deadlines vary. See the [state reporting overview](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview), [abuse and neglect reporting](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting) and [sentinel events](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events). ## Every report follows the same six steps Scale the depth of review to the risk. The sequence stays the same. 1. **Acknowledge and secure** Make sure the person is safe. Keep devices, lot numbers, logs and photos. Tell the reporter the report arrived. 2. **Triage by risk** Rate severity and likelihood. Many use the VA's Safety Assessment Code matrix, which scores 1, 2 or 3. 3. **Notify and disclose** Escalate by severity and make the outside reports. For serious events, the Joint Commission expects disclosure to the patient and family, and support for staff. 4. **Investigate in proportion** Quick review for low risk, team analysis for serious events. RCA2 says start in 72 hours, finish in 30 to 45 days. See the [root cause analysis and CAPA guide](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide). 5. **Act and verify** Give each corrective action one named owner and a date. Check later that it worked. 6. **Close the loop** Tell the reporter and staff what changed. Feed the pattern into your [QAPI program](https://incidentkit.ai/guides/qapi-program-guide). > **Feedback is not optional** The VA triage handbook reproduced in RCA2 requires timely feedback to every known reporter, whatever the risk score. A report that disappears teaches people to stop filing. ## People report when it is safe, quick and useful Fix those three and volume follows. Fix only volume and you get noise. **Safe.** The Joint Commission's hospital standards expect internal reporting systems "without the risk of retaliation." They add that this does not prevent accountability for negligence. Define blameworthy behavior in advance and keep it out of the reporting channel. See [just culture](https://incidentkit.ai/glossary/just-culture). **Quick.** A report should take minutes, work on a phone and let people use their own words. Long forms with required fields teach staff to skip it. **Useful.** AHRQ's PSNet lists four attributes of an effective system: a supportive environment, reports from many roles, timely summaries, and a structured review of reports. No feedback is a common barrier. See [near-miss reporting and safety culture](https://incidentkit.ai/guides/near-miss-reporting-and-safety-culture) and [getting staff to report near misses](https://incidentkit.ai/blog/how-to-get-staff-to-report-near-misses). ## Track whether reports lead to action PSNet notes that event reports give a numerator without a denominator. They show how many events were reported, not how many patients were exposed or how many went unreported. A rise or drop means little alone. *Suggested measures. These are recommendations, not regulatory requirements.* | Measure | How to calculate | How to read it | | --- | --- | --- | | Reports per 1,000 patient days (or 100 cases) | Reports divided by exposure, times the base | Compare to your own trend. A rise after a culture push is healthy. A flat line is a warning. | | Share that are near misses or no-harm | Those reports divided by all reports | Mostly harm events means you learn late. | | Hours from event to report, and to triage | Median, by unit and severity | Long gaps mean staff cannot file in-shift, or reports sit in a queue. | | Reporter feedback rate | Reports where the reporter heard back, divided by all | The strongest lever on future reporting. | | Serious-event analyses on time | Done within 45 days, divided by all | Matches RCA2 and Joint Commission timeframes. | | Actions closed on time and checked | Verified actions divided by actions due | Shows whether findings change anything. | | Repeat events | Same type and location within 90 days | The test of whether actions worked. | ## Six mistakes that weaken incident reporting - **Blame in the fields.** Ask what happened and what conditions were present. - **One giant form.** Start short and branch by type, so near misses stay quick. - **Reports that vanish.** If nobody owns triage, nothing happens. - **One system per regulator.** Separate logs force re-keying and drift apart. - **No link to QAPI or survey evidence.** See the [survey readiness guide](https://incidentkit.ai/guides/survey-and-accreditation-readiness). - **One file for everything.** CMS tells surveyors not to demand patient safety work product. ## How IncidentKit handles incident reporting IncidentKit is incident reporting and corrective-action software for regulated and high-risk work. Staff describe what happened by text. Voice is rolling out. [Lauren](https://incidentkit.ai/product/lauren) asks the follow-up questions, fills the form and drafts the investigation. A person always reviews, edits and signs. Reports route by type and severity through [routing and escalation](https://incidentkit.ai/product/routing-and-escalation). Corrective actions need an owner, due date and evidence, and nothing closes until verified. Every change is in the [audit trail](https://incidentkit.ai/product/audit-trail). IncidentKit runs alongside your EHR, CMMS and HRIS. See [incident reporting](https://incidentkit.ai/product/incident-reporting). ## Frequently asked questions ### What is the difference between an incident report and a sentinel event? An incident report records any event, including near misses. A sentinel event is the most serious kind: a safety event that reaches a patient and causes death, severe harm or permanent harm. Every sentinel event needs an incident report, a full analysis and a corrective action plan. ### Should near misses be reported? Yes. CMS surveyor guidance for surgery centers expects facilities to find errors that cause near misses, because they can lead to adverse events. The Joint Commission's hospital standards put close calls inside the safety program. Near misses show the same weaknesses as harm events, without the harm. ### Who is allowed to file an incident report? Anyone who sees an event: clinical staff, support staff, contractors, volunteers and visitors. A short form with no login makes that practical. Some states, such as Pennsylvania, make reporting a personal duty and protect reporters from retaliation. ### How soon must an incident be reported? Internally, within the shift. Outside deadlines vary: 2 hours for some nursing home abuse allegations, the next business day for some hospital restraint deaths, 10 work days for device deaths and serious injuries, and 8 or 24 hours for OSHA events. Check your state's rules too. ### Are incident reports confidential or privileged? It depends. The federal Patient Safety and Quality Improvement Act protects patient safety work product assembled to report to a patient safety organization. It does not protect records kept separately for an outside requirement. State privilege laws vary, so ask counsel. ### How many incident reports should a facility expect? There is no valid universal benchmark. HHS OIG found hospital systems captured an estimated 14 percent of patient harm events in one study, so low counts usually signal under-reporting, not safety. Track your own rate per 1,000 patient days, plus near-miss share and feedback rate. ## Sources - [HHS OIG, Hospital Incident Reporting Systems Do Not Capture Most Patient Harm (OEI-06-09-00091, 2012)](https://oig.hhs.gov/oei/reports/oei-06-09-00091.asp) - [HHS OIG, Adverse Events in Hospitals: A Quarter of Medicare Patients Experienced Harm in October 2018 (2022)](https://oig.hhs.gov/reports/all/2022/adverse-events-in-hospitals-a-quarter-of-medicare-patients-experienced-harm-in-october-2018/) - [AHRQ PSNet, Patient Safety Event Reporting primer](https://psnet.ahrq.gov/primer/reporting-patient-safety-events) - [Joint Commission, Sentinel Event Policy (SE chapter, CAMH Update 1, July 2026)](https://digitalassets.jointcommission.org/api/public/content/4035922bcc2f41bd83fbc1f55764a7b4?v=bf31f43b) - [Joint Commission, National Performance Goals effective January 2026, Hospital Program (NPG.02.03.01)](https://digitalassets.jointcommission.org/api/public/content/9ca80055182b4274842a5780a94f2c82) - [Joint Commission and NQF, Aligning Patient Safety Event Reporting: 2025 Updates to Sentinel Events and Serious Reportable Events (May 2026)](https://digitalassets.jointcommission.org/api/public/content/b4e8988066e74717ae9801edb2bfb9de?v=071ea64a) - [CMS State Operations Manual, Appendix L: Guidance for Surveyors, Ambulatory Surgical Centers](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_l_ambulatory.pdf) - [Pennsylvania MCARE Act (Act 13 of 2002), sections 302, 308, 313](https://www.legis.state.pa.us/WU01/LI/LI/US/PDF/2002/0/0013..PDF) - [42 CFR 483.12, Freedom from abuse, neglect, and exploitation (eCFR)](https://www.ecfr.gov/current/title-42/section-483.12) - [42 CFR 482.13, Condition of participation: Patient's rights (eCFR)](https://www.ecfr.gov/current/title-42/section-482.13) - [21 CFR 803.30, User facility reporting requirements (eCFR)](https://www.ecfr.gov/current/title-21/section-803.30) - [29 CFR Part 1904, Recording and reporting occupational injuries and illnesses (eCFR)](https://www.ecfr.gov/current/title-29/part-1904) - [42 CFR 3.20, Patient safety work product definitions (eCFR)](https://www.ecfr.gov/current/title-42/part-3) - [IHI and NPSF, RCA2: Improving Root Cause Analyses and Actions to Prevent Harm](https://www.ihi.org/library/tools/rca2-improving-root-cause-analyses-and-actions-prevent-harm) ## Related - [Near-miss reporting and safety culture: a practical guide](https://incidentkit.ai/guides/near-miss-reporting-and-safety-culture) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) - [Incident report: definition and meaning](https://incidentkit.ai/glossary/incident-report) - [Near miss: definition and meaning](https://incidentkit.ai/glossary/near-miss) - [Incident report vs variance report vs occurrence report](https://incidentkit.ai/blog/incident-report-vs-variance-report-vs-occurrence-report) - [Incident reporting software: forms, drafts, workflow](https://incidentkit.ai/product/incident-reporting) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) --- # QAPI program guide: surgery centers, nursing homes and hospitals > QAPI is the CMS-required program in which a facility collects data, finds problems, fixes root causes and proves the fixes lasted. Surgery centers, hospitals, nursing homes, home health agencies and hospices each have their own rule. Surveyors look for an ongoing system led by leaders, not a perfect record. Source: https://incidentkit.ai/guides/qapi-program-guide · Updated Oct 5, 2026 ## QAPI is the quality program CMS requires QAPI stands for quality assessment and performance improvement. CMS requires certified providers to run it, so quality is managed with data. The program must be ongoing, data-driven and led by the governing body. See [QAPI](https://incidentkit.ai/glossary/qapi). It joins two approaches. Quality assurance checks care against standards. Performance improvement studies and fixes processes. Nursing homes call their oversight group the quality assessment and assurance committee. See [QAA committee](https://incidentkit.ai/glossary/qaa-committee). *QAPI requirements by setting* | Setting | Rule | Who is accountable | Project requirement | Surveyor guidance | | --- | --- | --- | --- | --- | | Surgery centers | 42 CFR 416.43 | Governing body; sets aside staff, time and training | Fits the ASC's size and complexity; document why and the results | SOM Appendix L, Q-0081 to Q-0084 | | Hospitals | 42 CFR 482.21 | Governing body, medical staff, administrators | Fits scope and complexity; a patient-safety IT system can count | SOM Appendix A, A-0263 | | Nursing homes | 42 CFR 483.75 | Governing body or executive leadership; QAA committee meets at least quarterly | At least one project a year on a high-risk or problem-prone area | SOM Appendix PP, F865, F867, F868 | | Home health | 42 CFR 484.65 | Governing body | Required since July 13, 2018; document measurable progress | SOM Appendix B | | Hospice | 42 CFR 418.58 | Governing body names who runs it and reviews it yearly | Required since February 2, 2009 | SOM Appendix M | > **Coming in 2027 for hospitals with obstetric services** In the current eCFR, these hospitals must add QAPI work on January 1, 2027. They must analyze data by diverse subpopulations, track outcome disparities, and run one measurable obstetric project a year (42 CFR 482.21(b)(4) and (e)). Confirm the date with CMS. ## CMS frames QAPI around five elements CMS says its QAPI at a Glance guide is not mandated for compliance. The nursing home rule follows the same structure. Other settings ask for the same things in shorter lists. | Element | What it means | Nursing home rule | | --- | --- | --- | | Design and scope | An ongoing program covering all systems of care, with a written plan | 42 CFR 483.75(b) | | Governance and leadership | Leaders set goals, name owners, give resources and sustain the work | 42 CFR 483.75(f) | | Feedback, data systems and monitoring | Data from every department, input from staff, residents and families, adverse event tracking | 42 CFR 483.75(c) | | Performance improvement projects | Focused projects on priority problems | 42 CFR 483.75(e)(3) | | Systematic analysis and systemic action | Root cause analysis and system fixes that are measured and sustained | 42 CFR 483.75(d) | ## Only nursing homes must have a QAA committee Surgery centers, hospitals, home health agencies and hospices rely on the governing body to define and oversee the program. A nursing home QAA committee has the director of nursing, the Medical Director or a designee, the infection preventionist and at least three other staff. One is the administrator, owner, a board member or another leader. It meets at least quarterly. CMS adds details that trip facilities up: - The Medical Director's designee cannot be another required member. - Show the Medical Director got the meeting content, with acknowledgment. - The infection preventionist attends, or another staff member reports for that role. - Residents and families may join but do not have to. - Review data often enough to show if improvement is needed or happening. A surgery center governing body defines the program in writing, such as in minutes. It records the staff time and resources set aside. If a contractor analyzes data, leadership keeps responsibility. Hospitals decide each year how many projects to run. A system governing body may adopt one QAPI program for several certified hospitals. Each must show its own needs were considered. ## Incident reports show problems before outcomes do Incident and near-miss reports are the only data that shows problems before they appear in outcome measures. Every setting's rule asks you to track adverse events and analyze their causes. QAPI draws on every department: - **Incident, near-miss and adverse event reports.** Nursing homes must track and analyze them. - **Infection surveillance.** CMS expects surgery center infection control to be part of QAPI. - **Quality measures.** Hospital QAPI must include Medicare quality program data. Home health uses OASIS. - **Staff, resident and family feedback.** Required input in nursing homes. - **Drug regimen review results.** The nursing home QAA committee must review pharmacist reports. - **Contracted services.** Hospitals must show how lab, imaging and similar services are included. Indicators must relate to quality. CMS's surgery center guidance says how fast a center produces error-free billing claims has no direct link to care quality. The timing of antibiotic prophylaxis does. Other examples: burns, hospital transfers, falls, and wrong-site, wrong-side, wrong-patient, wrong-procedure or wrong-implant events. Surveyors ask whether indicators include transfers, surgery and infection control measures, and a way to track adverse events. ## A project fixes one problem and proves it held A performance improvement project (PIP) fixes one problem, with a baseline, a goal, an action and a re-measure. Focus on high-risk, high-volume and problem-prone areas. Weigh how often, how widespread and how severe. See [performance improvement project](https://incidentkit.ai/glossary/performance-improvement-project). 1. **Pick from data** Use incident trends and indicator results, not opinion. One severe event, such as a hospital transfer, can justify a project. 2. **State the baseline** Say why the gap matters. Write today's performance as a number. 3. **Set a numeric goal and date** For example, from X to Y by a named date. 4. **Find the cause** Stop at a system cause, not at the person. See the [root cause analysis guide](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide). 5. **Act on the cause** Favor actions that change the process. Pilot in one area first. 6. **Re-measure and sustain** If you missed the goal, return to the cause. After success, keep monitoring. 7. **Communicate** Document the governing body's review. Tell the staff who do the work. This matches AAAHC's six-part model for quality studies: purpose, goal, data analysis, corrective action, re-measure and communicate. CMS says one very complex multi-year project could be a center's only project in a year. Records show why, the data, and the result. ## Surveyors judge whether your system works Surveyors do not expect zero problems. CMS's hospital and surgery center guidance says the focus is an effective, ongoing system for finding problem events, acting on them and checking that the actions worked. | Setting | What surveyors ask to see | | --- | --- | | Surgery centers | Leaders explaining each indicator. Who analyzes the data. How causes are found. Proof fixes held. Project records, this year and last. Governing body minutes. | | Hospitals | The formal QAPI program. Continuous data collection, analysis, change and monitoring. Governing body oversight of all services, including contracted ones. | | Nursing homes | The QAPI plan, shown at each annual recertification survey and on request at others. Committee members and meeting frequency. | > **A worked example from CMS** CMS hospital guidance describes a facility with three wrong-site surgeries in twelve months and five near misses. It had no analysis and no change to pre-surgical verification. CMS says those records suggest current noncompliance. Logging events is not enough. The action trail is the evidence. Surveyors are told to handle QAPI records with care. In surgery centers and hospitals, they should generally not use QAPI data as evidence of other violations. In nursing homes, they may not use QAPI documents to find new concerns or widen scope or severity (F865). Under 42 CFR 483.75(h), committee records are disclosed only as needed to show compliance. Section 483.75(i) says good-faith efforts to find and fix problems are not a basis for sanctions. Show good faith through actions, not claims. ## Keep a separate record outside your PSO Patient safety work product is protected when assembled for a patient safety organization (PSO) inside a patient safety evaluation system. The federal definition names root cause analyses. It excludes information that exists separately. CMS's nursing home guidance says surveyors must never demand patient safety work product. A facility with all QAPI evidence inside the protected system may be unable to show compliance. Nothing bars keeping both. Decide what goes where, and ask counsel. See [patient safety organization](https://incidentkit.ai/glossary/patient-safety-organization). ## Seven QAPI pitfalls to avoid - **Meetings with no changes.** Minutes with no action list look like logging, not fixing. - **Stopping at the immediate cause.** CMS says blaming staff is not a systems approach. - **Indicators unrelated to quality.** See the billing example above. - **No proof of sustainment.** CMS expects ongoing data after a fix. - **A fix in one room.** Review all three operating rooms, not just one. - **Staff cannot describe the program.** Surveyors ask them. - **Leadership is not visible.** Surveyors ask governing body members how they use the program. ## A steady cadence builds evidence as you go Nursing homes must meet at least quarterly. Other settings set no frequency, so choose one and keep it. This cadence is a suggestion, not a regulatory requirement. - **Monthly.** Review new incidents, overdue actions and indicator trends. Keep a dashboard snapshot. - **Quarterly.** Hold the committee. Report to the governing body. Keep minutes. - **Yearly.** Refresh indicators, set project numbers, update the plan. - **Each project.** Check baseline, action and re-measure against the goal date. ## Incident data is where QAPI evidence starts Every QAPI rule asks you to track adverse events, analyze causes and show fixes held. An incident system is where those facts start. A tool does not satisfy QAPI alone. Leadership does. A good tool makes evidence a by-product of daily work. IncidentKit [analytics](https://incidentkit.ai/product/analytics) cluster incidents by location, shift, equipment and cause. [Corrective actions](https://incidentkit.ai/product/corrective-actions) hold the owner, due date, evidence and effectiveness check, and nothing closes until verified. [Compliance packets](https://incidentkit.ai/product/compliance-packets) assemble QAPI summaries. See [QAPI committee meetings](https://incidentkit.ai/use-cases/qapi-committee-meetings). Rule pages: [surgery centers](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers), [nursing homes](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) and [hospitals](https://incidentkit.ai/compliance/cms-qapi/hospitals). Nursing home tags: [F865](https://incidentkit.ai/compliance/f-tags/f865), [F867](https://incidentkit.ai/compliance/f-tags/f867), [F868](https://incidentkit.ai/compliance/f-tags/f868). ## Frequently asked questions ### What is QAPI? QAPI is quality assessment and performance improvement: an ongoing, data-driven program a CMS-certified provider runs to find problems, fix root causes and show improvements last. Rules: 42 CFR 416.43 for surgery centers, 482.21 for hospitals and 483.75 for nursing homes. ### Which providers must have a QAPI program? CMS requires QAPI for ambulatory surgical centers, hospitals, skilled nursing and nursing facilities, home health agencies and hospices. Each has its own regulation, so use the rule for your setting, not a generic template. ### How often must the QAA committee meet? In nursing homes, at least quarterly and as needed, under 42 CFR 483.75(g). Other settings have no set committee schedule, but their governing bodies must keep the program ongoing. Pick a cadence and document it. ### How many performance improvement projects do we need? Nursing homes must run at least one a year on a high-risk or problem-prone area. Other settings run a number that fits their size and complexity. All must document the reason and measurable progress. ### Can surveyors see our QAPI records? Yes, as needed to show compliance. In nursing homes, 42 CFR 483.75(h) limits disclosure to that purpose. CMS tells surveyors never to demand patient safety work product, so keep a separate compliance record if you use a patient safety organization. ### What is the difference between QA and QAPI? Quality assurance checks whether care meets standards. Performance improvement studies a process and changes it. QAPI combines both: it monitors continuously, investigates drift, acts on root causes and measures whether the change held. ## Sources - [42 CFR 416.43, Quality assessment and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/section-416.43) - [42 CFR 482.21, Hospital QAPI program (eCFR)](https://www.ecfr.gov/current/title-42/section-482.21) - [42 CFR 483.75, Quality assurance and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/section-483.75) - [42 CFR 484.65, Home health QAPI (eCFR)](https://www.ecfr.gov/current/title-42/section-484.65) - [42 CFR 418.58, Hospice QAPI (eCFR)](https://www.ecfr.gov/current/title-42/section-418.58) - [CMS State Operations Manual, Appendix L: Ambulatory Surgical Centers](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_l_ambulatory.pdf) - [CMS State Operations Manual, Appendix A: Hospitals (A-0263)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_a_hospitals.pdf) - [CMS State Operations Manual, Appendix PP: Long-Term Care Facilities (F865, F867, F868)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [CMS State Operations Manual, Appendix B: Home Health Agencies](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_b_hha.pdf) - [CMS State Operations Manual, Appendix M: Hospice](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_m_hospice.pdf) - [CMS, QAPI at a Glance](https://www.cms.gov/medicare/provider-enrollment-and-certification/qapi/downloads/qapiataglance.pdf) - [42 CFR 3.20, Patient safety work product definitions (eCFR)](https://www.ecfr.gov/current/title-42/part-3) - [AAAHC, Documenting a Quality Improvement Study Using the Six-Component Criteria](https://www.aaahc.org/uploads/2025/08/03-250801_IQI_DOC_Documenting-QI-Using-6-Component-Criteria_v44.pdf) ## Related - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [Hospital QAPI requirements: 42 CFR 482.21 explained](https://incidentkit.ai/compliance/cms-qapi/hospitals) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [QAPI: definition and meaning](https://incidentkit.ai/glossary/qapi) - [Performance improvement project: definition and meaning](https://incidentkit.ai/glossary/performance-improvement-project) - [QAPI Meeting Agenda and Minutes Template (Printable)](https://incidentkit.ai/templates/qapi-meeting-agenda-and-minutes) - [Survey and accreditation readiness: a continuous approach](https://incidentkit.ai/guides/survey-and-accreditation-readiness) --- # Root cause analysis and CAPA: a practical guide to strong actions > Root cause analysis finds the system conditions behind an event. CAPA, corrective and preventive action, changes them and checks the change worked. Stronger actions redesign the process, while training alone rarely lasts. Every action needs one owner, a date and a measure. Source: https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide · Updated Oct 5, 2026 ## Root cause analysis finds causes; CAPA fixes them Root cause analysis (RCA) finds the system reasons an event happened. An OSHA and EPA fact sheet calls a root cause a fundamental system reason that points to correctable failures. Fixing only the immediate cause removes a symptom, not the problem. See [root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis). Corrective and preventive action (CAPA) is what you do with the findings. A corrective action removes the cause of this event. A preventive action stops the same weakness elsewhere. See [corrective and preventive action](https://incidentkit.ai/glossary/corrective-and-preventive-action). CMS gives a surgery center example. Confusing emergency drug storage in one operating room is corrected in that room, and prevented by reviewing the others. The patient safety field calls the process RCA2 (root cause analyses and actions), because analysis without action prevents nothing. The CAPA label comes from manufacturing. FDA's device rule is now the quality management system regulation, which incorporates ISO 13485. The old section 820.100 is gone from the current eCFR. The logic carries over unchanged. ## Match investigation depth to risk Triage every event. A full team analysis of every near miss would collapse under its weight. A five-minute review of a serious event would miss the point. A common triage tool is the VA National Center for Patient Safety's Safety Assessment Code matrix, reproduced in RCA2. It pairs severity with probability and returns 3 (highest risk), 2 or 1. It covers actual events and close calls. *Safety Assessment Code matrix (VA National Center for Patient Safety, as reproduced in RCA2)* | Probability | Catastrophic | Major | Moderate | Minor | | --- | --- | --- | --- | --- | | Frequent | 3 | 3 | 2 | 1 | | Occasional | 3 | 2 | 1 | 1 | | Uncommon | 3 | 2 | 1 | 1 | | Remote | 3 | 2 | 1 | 1 | Some analyses are required. The Joint Commission expects a comprehensive analysis of every sentinel event. For events reported to it, the analysis and action plan are due within 45 business days of the event or of becoming aware of it. RCA2 recommends starting within 72 hours, using 4 to 6 people not involved in the event, and finishing in 30 to 45 days. OSHA's process safety standard requires covered employers to investigate any incident that did, or could reasonably have, caused a catastrophic release. Start within 48 hours. A near miss can trigger this duty. *Suggested tiers. These are recommendations, not regulatory requirements.* | Level | When | Method | Timing | | --- | --- | --- | --- | | Quick review | Score 1, one-off | Manager-led five whys | Same week | | Focused review | Score 2, or a repeating pattern | Small group, timeline, cause-and-effect diagram | Within 30 days | | Full analysis | Score 3, sentinel event, or a near miss that could have been catastrophic | RCA2-style team, interviews, flow diagram, action hierarchy | Start in 72 hours; finish in 30 to 45 days | ## Use the simplest method that finds the cause Combine methods for complex events. OSHA and EPA say their listed tools are ideally combined. Brainstorming and checklists may do for simple incidents. Complicated ones need logic trees backed by timelines and causal factor analysis. | Method | Best for | Watch out for | | --- | --- | --- | | [Five whys](https://incidentkit.ai/glossary/five-whys) | Simple events with one clear thread | Stops at the first plausible answer, often a person. Misses parallel causes. | | [Fishbone diagram](https://incidentkit.ai/glossary/fishbone-diagram) | Many contributing factors; group brainstorming | Lists causes without ranking them. Pair with a timeline. | | Timeline and flow diagram | Rebuilding what happened and where the process drifted | Needs interviews and records. Build it before debating causes. | | [Fault tree analysis](https://incidentkit.ai/glossary/fault-tree-analysis) | High-consequence events where several failures combined | Needs skill and time. Overkill for routine events. | | Barrier analysis | Which defenses failed or were missing | Easy to stop at the barrier and skip why it failed. | | Failure mode and effects analysis | Reviewing a high-risk process before harm occurs | Joint Commission hospital standards require a proactive risk assessment of one high-risk process every 18 months. | OSHA and EPA build every analysis on four questions: what happened, how, why, and what needs correcting. See [five whys vs fishbone vs fault tree](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree). ## Write causes that point to systems, not people Write each cause as a chain: something led to something, which made the event more likely. RCA2 and the VA use five rules, adapted from an FAA study of maintenance errors. | Rule | Weak statement | Stronger statement | | --- | --- | --- | | 1. Show cause and effect | Fatigue. | Back-to-back double shifts raised fatigue, which made a skipped double check more likely. | | 2. Use specific words, not poor, bad, careless or failed | The handoff was poor. | Handoffs had no standard format and happened in a hallway, so allergy status was missed. | | 3. A human error needs a preceding cause | Wrong vial selected. | Look-alike vials were stored side by side. | | 4. A violation needs a preceding cause | Time-out not followed. | The schedule left no pause between cases, so time-outs started after draping. | | 5. Failure to act is causal only if there was a duty to act | Alarm log not checked. | No role was assigned to check the alarm log, so overnight alarms went unreviewed. | Human error is not an acceptable root cause, says RCA2. If a well-trained person erred in a typical setting, system factors helped. Retraining one person does nothing for the next. Define blameworthy events, such as deliberately unsafe acts, in advance and route them to HR, not RCA. ## Stronger actions change the system, not memory Rank every action by how little it relies on memory. Stronger actions change the system. Weaker ones ask people to try harder. The ranking comes from the VA National Center for Patient Safety (2001) and follows NIOSH's hierarchy of controls. See [hierarchy of controls](https://incidentkit.ai/glossary/hierarchy-of-controls). *Action hierarchy as shown in RCA2, Figure 3* | Strength | Action categories | Examples from RCA2 | | --- | --- | --- | | Stronger | Physical plant changes; usability-tested devices; forcing functions; simpler processes; standardized equipment or process; visible leadership involvement | Sliding doors instead of revolving doors to cut falls; tubing that connects only one way; bar-coded medication administration | | Intermediate | Redundancy; staffing or workload changes; software alerts; fewer distractions; simulation training with refreshers; checklists; no look-alike or sound-alike items; read-back; enhanced documentation | Two nurses independently calculating high-risk doses; quiet rooms for programming infusion pumps; pre-incision checklists | | Weaker | Double checks; warnings; new procedure or policy; training | Caution labels; a reminder to check IV sites every two hours; demonstrating hard-to-use equipment | Two points surprise people. Double checks are weaker, because they rely on someone remembering to look. Training and policy are weaker too, though they are the most common fixes. RCA2 says they are often needed to set expectations but unlikely to be enough alone. IHI's action hierarchy tool shows one case. A patient slid off a shower chair. The stronger action: a chair with secure straps. The intermediate action: find patients at risk of falling and add staff for showering. The weaker action: retrain staff. > **The minimum bar** The Joint Commission says an acceptable corrective action plan includes at least one stronger or intermediate action. RCA2 asks for one in each review. The IHI toolkit says one for each cause. Weaker actions can run as interim measures. ## Seven steps to a CAPA that works 1. **Tie each action to one cause** An action that answers no stated cause is a good idea, not a corrective action. 2. **Choose the strongest action you can do** Log a weaker action as interim if the stronger one needs time or capital. 3. **Name one owner and a date** RCA2 says assign a person, not a committee, with authority and resources. 4. **Write the measure now** State what, who, target and date. Use a process measure (was it done) and, where possible, an outcome measure (did it work). 5. **Get leadership approval** RCA2 recommends the CEO or another top leader approve or reject each action. Record why if rejected. 6. **Pilot before rollout** CMS advises testing in one area first. Some changes have unintended effects. 7. **Extend the fix** Ask where else the weakness exists: other rooms, units, shifts, sites. That is the preventive half of CAPA. The Joint Commission says an acceptable plan names the responsible title, the start date including any pilot, how effectiveness will be evaluated and sustained, and when alternatives apply if targets are missed. The [corrective action plan template](https://incidentkit.ai/templates/corrective-action-plan) and [root cause analysis worksheet](https://incidentkit.ai/templates/root-cause-analysis-worksheet) follow that structure. ## Prove the action worked with two measures An effectiveness check is a planned re-measure that shows the problem is smaller and stays smaller. Closing the task is not closing the loop. See [effectiveness review](https://incidentkit.ai/glossary/effectiveness-review). RCA2 gives a worked pair for new hand-hygiene technology. Process measure: watch 100 staff-patient encounters over seven days, expecting 95 percent compliance. Outcome measure: a 20 percent drop in hospital-acquired infections spread by staff contact. Process data comes fast. Outcome data takes longer. Use both. *Illustrative effectiveness checks* | Action | Process measure | Outcome measure | | --- | --- | --- | | Bar-code scanning at the bedside | Scan rate across 100 observed administrations at 30 days | Wrong-drug reports at 90 days | | Strapped shower chairs in every shower room | Audit confirms every room is equipped | Falls during bathing per 1,000 resident days at 90 days | Sustainment matters as much as the first result. CMS tells surgery centers to keep collecting data after a fix. AAAHC's model says plan more than one re-measure and return to the cause if the goal is missed. IncidentKit does not close a corrective action until it is verified. ## Six signs of a weak analysis RCA2 lists conditions that mean a review needs redoing. The Joint Commission reviews each sentinel event analysis for thoroughness, credibility and acceptability. - No contributing factors, or factors with no supporting data. - Individuals named as the cause, or causes that point to blame. - No stronger or intermediate actions. - Causal statements that break the five rules. - No actions, or actions that miss the stated vulnerabilities. - Follow-up assigned to a committee, not a person. The Joint Commission also expects a credible analysis to be precise, complete, systematic, and deep and broad enough to cover systemic factors. It should include a process owner, a patient or family member when fitting, and people close to the process. A sentinel event alone does not affect the accreditation decision. Willful failure to respond appropriately could. ## Industrial and OSHA context The same logic works on the plant floor. In OSHA and EPA's example, a worker slips on oil. A traditional investigation says oil was spilled, cleans it up and tells the worker to be careful. Root cause analysis asks why the oil was there, where it came from, why it stayed, and whether anyone reported it. It may find a missing mechanical integrity program, a system cause. OSHA's process safety standard (29 CFR 1910.119(m)) also requires covered employers to: - Use a team that includes someone who knows the process. - Report the date, description, contributing factors and recommendations. - Resolve and document findings, and review them with affected staff. - Keep the report for five years. See [process safety incident investigation](https://incidentkit.ai/compliance/osha/process-safety-incident-investigation). NIOSH's hierarchy of controls runs from elimination and substitution through engineering and administrative controls to personal protective equipment. RCA2 modeled its action hierarchy on it, so safety and risk managers can share the same logic. ## How IncidentKit supports RCA and CAPA [Lauren](https://incidentkit.ai/product/lauren) drafts the investigation from what reporters and others said, with a timeline and a first pass at contributing factors and five whys. Every drafted field shows "Lauren · draft" until a person reviews, edits and signs. The team decides the root cause. Human-authored RCA templates are rolling out. [Investigations](https://incidentkit.ai/product/investigations) hold contributing factors, five whys and the disposition. [Corrective actions](https://incidentkit.ai/product/corrective-actions) carry an owner, due date, evidence and effectiveness check, and nothing closes until verified. See the [root cause analysis](https://incidentkit.ai/use-cases/root-cause-analysis) and [close corrective actions](https://incidentkit.ai/use-cases/close-corrective-actions) use cases. ## Frequently asked questions ### What is the difference between root cause analysis and CAPA? Root cause analysis finds the system conditions behind an event. CAPA is the follow-through: corrective actions that remove those causes, preventive actions that stop similar problems elsewhere, and a check that they worked. RCA without CAPA changes nothing, which is why RCA2 adds "actions." ### How long should a root cause analysis take? RCA2 recommends starting within 72 hours and finishing in 30 to 45 days. The Joint Commission expects the analysis and action plan for a reported sentinel event within 45 business days. OSHA's process safety standard requires starting an incident investigation within 48 hours. ### Is training a good corrective action? Training is a weaker action in the VA and RCA2 hierarchy. It sets expectations and builds skill, but alone it relies on memory and rarely lasts. Pair it with at least one stronger or intermediate action that changes the process or equipment. ### What are stronger, intermediate and weaker actions? Stronger actions need little human memory: physical changes, forcing functions, simpler or standard processes. Intermediate actions give people tools: checklists, alerts, redundancy, read-back. Weaker actions rely on memory: double checks, warnings, policies, training. Plans need at least one stronger or intermediate action. ### How do you measure whether a corrective action worked? Set a process measure and an outcome measure before the action starts. The process measure shows it was done, such as an observed compliance rate. The outcome measure shows the problem shrank, such as fewer events. Name one person, set a date, and plan a later re-measure. ### Who should be on a root cause analysis team? RCA2 recommends 4 to 6 people: process experts plus others from different levels, with a patient representative considered. Interview the people directly involved, but keep them off the team. Give staff protected time, and have leadership review the result. ## Sources - [IHI and NPSF, RCA2: Improving Root Cause Analyses and Actions to Prevent Harm (full report)](https://www.ihi.org/sites/default/files/RCA2_ImprovingRootCauseAnalysesandActionstoPreventHarm.pdf) - [IHI, Patient Safety Essentials Toolkit: Action Hierarchy Tool](https://www.ihi.org/sites/default/files/SafetyToolkit_ActionHierarchy.pdf) - [Joint Commission, Sentinel Event Policy (SE chapter, CAMH Update 1, July 2026)](https://digitalassets.jointcommission.org/api/public/content/4035922bcc2f41bd83fbc1f55764a7b4?v=bf31f43b) - [Joint Commission, National Performance Goals effective January 2026, Hospital Program (NPG.02.03.01)](https://digitalassets.jointcommission.org/api/public/content/9ca80055182b4274842a5780a94f2c82) - [CMS, QAPI at a Glance (Steps 11 and 12)](https://www.cms.gov/medicare/provider-enrollment-and-certification/qapi/downloads/qapiataglance.pdf) - [CMS State Operations Manual, Appendix L: Ambulatory Surgical Centers](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_l_ambulatory.pdf) - [OSHA and EPA, The Importance of Root Cause Analysis During Incident Investigation (fact sheet)](https://www.osha.gov/sites/default/files/publications/OSHA3895.pdf) - [29 CFR 1910.119, Process safety management of highly hazardous chemicals (eCFR)](https://www.ecfr.gov/current/title-29/section-1910.119) - [CDC NIOSH, Hierarchy of Controls](https://www.cdc.gov/niosh/hierarchy-of-controls/about/index.html) - [21 CFR 820.10, Requirements for a quality management system (eCFR)](https://www.ecfr.gov/current/title-21/section-820.10) - [AAAHC, Documenting a Quality Improvement Study Using the Six-Component Criteria](https://www.aaahc.org/uploads/2025/08/03-250801_IQI_DOC_Documenting-QI-Using-6-Component-Criteria_v44.pdf) ## Related - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Root cause analysis: definition and meaning](https://incidentkit.ai/glossary/root-cause-analysis) - [Corrective and preventive action: definition and meaning](https://incidentkit.ai/glossary/corrective-and-preventive-action) - [Root Cause Analysis Worksheet (5 Whys Template)](https://incidentkit.ai/templates/root-cause-analysis-worksheet) - [Corrective Action Plan Template (CAPA, Printable)](https://incidentkit.ai/templates/corrective-action-plan) - [Five whys vs fishbone vs fault tree: how to choose](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) --- # Survey and accreditation readiness: a practical guide > Survey readiness means you can show on any day that your processes work, using proof from daily operations. Most surveys are unannounced. Surveyors ask first for lists, indicator data and proof that adverse events were analyzed and fixed. Source: https://incidentkit.ai/guides/survey-and-accreditation-readiness · Updated Oct 5, 2026 ## Readiness means proof on any day, not a scramble Survey readiness is the ability to show surveyors, on any day, that your systems work and that you find and fix problems yourself. It is a daily state, not a project that starts when a notice arrives. Most surveys give no notice. CMS says every surgery center survey is unannounced. Joint Commission ambulatory surveys are unannounced or short notice for most. Initial surveys of sites not seeking deemed status get 30 days' notice. Some re-surveys, such as office-based surgery, get seven business days. AAAHC takes the same view. It aims to keep organizations ready across a 1,095-day, three-year cycle. ## Survey frequency depends on setting and accreditor CMS sets yearly survey targets for state agencies in its Mission and Priorities Document. These are fiscal year 2027 targets. They are priorities subject to funding, and complaint surveys can happen at any time. | Setting | CMS target | Notes | | --- | --- | --- | | Nursing homes | 15.9 months at most between standard surveys; 12.9-month statewide average; at least 10% off-hours (weekends, before 6 a.m., after 5 p.m.) | Special Focus Facilities: at least every 186 days. | | Surgery centers, not deemed | Six years at most; targeted surveys of 25% of non-deemed centers, mainly those not surveyed in over four years | Deemed centers: surveyed by their accreditor. | | Hospitals, not deemed | Four or five years at most, by priority tier; 5% targeted sample | Deemed hospitals: surveyed by their accreditor. | | Home health | 36.9 months at most | Accredited agencies follow their accreditor's cycle. | | Accredited (deemed) providers | Accreditor cycle, plus CMS validation and complaint surveys | A state validation survey of a deemed surgery center must finish within 60 days of the accreditor's survey. | States run a tenth of nursing home surveys off-hours, so nights and weekends are surveyed too. Readiness must hold on every shift. Compare accreditors in [AAAHC vs Joint Commission for ASCs](https://incidentkit.ai/blog/aaahc-vs-joint-commission-for-ascs). ## Use continuous readiness, plus mock tracers Build on continuous readiness. Add mock tracers on a calendar and a short binder as an index. None of the three is enough alone. | Approach | What it gives you | Limit | | --- | --- | --- | | Evidence binder | Everything in one place | Shows effort, not whether systems work. Stale by survey day. | | Mock survey or tracer | Practice; gaps in one process | Periodic. Staff act differently when rehearsed. | | Continuous readiness | Evidence from daily work: incident records, closed actions, minutes | Needs tools that record evidence as work happens. | The Joint Commission's survey guide offers mock tracer tips. Pick patients tied to infection control or medication management, patients who move between services, and patients recently admitted or due for discharge. A simple tracer: 1. **Pick one recent case** Choose a patient tied to a high-risk process, such as a medication or surgery. 2. **Walk the path** Follow the case from admission to discharge. Ask staff at each point what they would do and why. 3. **Compare record to practice** Check the record against what you saw and heard. 4. **Log the gaps as work** Enter each gap as an action with an owner and a date. ## Surveyors ask for lists and data first Expect lists and data in the first hour. These requests come from published surveyor guidance. **CMS, surgery centers.** CMS says an ASC should produce these lists in one to two hours: - Surgeries scheduled that day (and the next, if two days), with patient, age, procedure, physician. - All surgeries in the past six months. - All cases in the past year with a hospital transfer or death. - Org chart, policies, personnel records, contracted services, floor plan. - Infection control and quality self-assessment records. **Joint Commission, ambulatory.** Expect: - Past 12 months of quality improvement and infection surveillance data. - Infection control and environment of care plans, contracts, schedules, culture of safety data. - Deemed surgery centers add the six-month surgery list and 12-month transfer and death list. **CMS, nursing homes.** The QAPI plan at every annual recertification survey, and proof of the ongoing program on request. > **If documents are late, surveyors start with a patient** The Joint Commission says that when documents are not ready at the planning session, surveyors begin with an individual tracer. They follow one patient's care in real time. Ready lists buy you control of the first hour. ## Your incident system answers surveyors' questions Surveyors judge whether you find and fix problems. Your incident system holds that proof if it keeps the whole trail from report to verified fix. | Surveyor question | Evidence from your incident system | | --- | --- | | How did you analyze your adverse events? | Investigations with contributing factors and a disposition | | Do you stop at the immediate cause? | System causes, with each action ranked by strength | | What did you change, and did it work? | Corrective actions with owner, evidence and effectiveness check | | Who was transferred or died in the past year? | A list filtered by incident type and date | | How does the governing body oversee QAPI? | Committee packets and minutes tied to incident data | | Show me 12 months of quality data. | Trends by location, shift and cause | The same data cuts both ways. CMS hospital guidance describes a year with three wrong-site surgeries and five near misses, and no analysis or change. CMS says that suggests current noncompliance with the QAPI condition. See the [QAPI program guide](https://incidentkit.ai/guides/qapi-program-guide). CMS also tells surveyors to use a facility's QAPI data with care, and generally not as evidence of other violations. ## Keep one evidence set with an index Keep one organized set, ideally live in your system, with a short index for the entrance conference. | Evidence | Refresh | | --- | --- | | QAPI plan and indicator list | Yearly | | Committee agendas, attendance, minutes, action lists | Each meeting | | Project records | Each project | | Incident log: severity, outcome, closure dates | Live | | Serious-event investigations; action tracker with checks | Per event; live | | Infection data and plan | Monthly | | Governing body minutes on QAPI | Yearly | | Contracted services list | Yearly | > **Keep protected and compliance records apart** With a patient safety organization, keep a separate, non-confidential compliance record. CMS tells surveyors never to demand patient safety work product. If all QAPI proof sits in the protected system, you may be unable to show compliance. ## A survey day runs in six steps 1. **Arrival** Greet the team and check photo ID. Have a base room with power, phone and internet. The Joint Commission asks for a safety briefing of five minutes or less. 2. **Entrance conference** A CMS surgery center team usually has two health standards surveyors and one Life Safety Code surveyor for two days. CMS tells surveyors to make requests, not demands. 3. **Information gathering** Observation, interviews and document review. One surveyor follows at least one patient from registration to discharge or early recovery. 4. **Daily briefings** Surveyors meet at least daily. Informal conferences let you add context to early findings. 5. **Exit conference** CMS surveyors present facts and do not rank findings. They discuss any immediate jeopardy: noncompliance likely to cause serious harm or death. See [immediate jeopardy](https://incidentkit.ai/glossary/immediate-jeopardy). 6. **After the survey** For a surgery center, CMS mails Form CMS-2567 within 10 working days. Your plan of correction is due 10 calendar days after you get it. The 2567 is public within 90 days. You may accept the deficiencies and submit a plan, object and submit a plan, or object with evidence and no plan. An acceptable plan states the action, how it improves the process, how it will be done, a completion date, monitoring, and the responsible title. See [plan of correction](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction), [what to put in a plan of correction](https://incidentkit.ai/blog/what-to-put-in-a-plan-of-correction) and [CMS-2567](https://incidentkit.ai/glossary/cms-2567). ## Joint Commission and AAAHC set their own expectations **Joint Commission.** Hospital standards changed on January 1, 2026, under Accreditation 360, which added National Performance Goals. Goal 2, culture of safety, covers incident reporting: - A safety program that covers close calls and good catches, not only sentinel events. - Internal reporting without retaliation. - One proactive risk review of a high-risk process at least every 18 months. - Regular safety culture checks with valid tools. Hospitals can also opt into Continuous Engagement. These check-ins do not monitor compliance. Reporting a sentinel event is voluntary, but every event needs a full analysis. For reported events, the analysis and plan are due in 45 business days. An event alone does not affect accreditation. See [Joint Commission survey readiness](https://incidentkit.ai/compliance/survey-readiness/joint-commission-survey-readiness). **AAAHC.** AAAHC judges quality studies on six parts: purpose, goal, data analysis, corrective action, re-measure and communicate. Its v45 standards add AI governance expectations. They apply to surveys on or after December 15, 2026. See [AAAHC](https://incidentkit.ai/compliance/accreditation/aaahc). ## A weekly-to-yearly readiness routine *Suggested routine. These are recommendations, not regulatory requirements.* | When | Task | | --- | --- | | Weekly | Review open incidents, overdue actions and running reporting clocks | | Monthly | Run one mock tracer on a high-risk process; check indicator trends | | Quarterly | Hold the QAPI committee; refresh the evidence index | | Yearly | Review the plan, indicators and environment plans; run a culture survey | | After any survey or complaint | Track each plan-of-correction item until verified | ## How IncidentKit helps, and what it does not do IncidentKit [compliance packets](https://incidentkit.ai/product/compliance-packets) assemble QAPI summaries and survey packets from records your staff already keep. The [audit trail](https://incidentkit.ai/product/audit-trail) shows who changed what and when. See [always survey-ready](https://incidentkit.ai/use-cases/always-survey-ready). It does not replace your accreditor's standards, a mock survey or someone who knows your regulations. Try the [survey readiness check](https://incidentkit.ai/tools/survey-readiness-check) to see where your evidence is thin. ## Frequently asked questions ### How often are healthcare facilities surveyed? CMS fiscal year 2027 targets for state agencies: no more than 15.9 months between nursing home standard surveys, six years for non-deemed surgery centers, and 36.9 months for home health. Accredited providers are surveyed by their accreditor. Complaints can bring a survey any time. ### Are healthcare surveys announced in advance? Usually not. CMS says all surgery center surveys are unannounced. The Joint Commission surveys most ambulatory sites unannounced or on short notice. Some initial surveys get 30 days' notice, and some re-surveys seven business days. Plan as if every survey comes without warning. ### What documents will a surveyor ask for first? At a surgery center, CMS asks for the day's surgery list, six months of surgeries, a year of hospital transfers and deaths, plus policies and quality records. The Joint Commission asks for 12 months of improvement and infection control data and culture of safety results. ### What is the difference between a mock survey and continuous readiness? A mock survey is a periodic rehearsal that finds gaps in one process. Continuous readiness means daily work creates the proof: incident records, closed actions, minutes. A rehearsal tests your people. Daily proof tests your systems. ### What happens after a survey finds deficiencies? CMS sends Form CMS-2567 listing them. For surgery centers it is mailed within 10 working days. Your written plan of correction is due within 10 calendar days of receipt, with actions, dates, monitoring and a responsible title. The 2567 is public within 90 days. ### Do accredited surgery centers still get CMS surveys? Deemed surgery centers are off the routine state cycle, but CMS picks some for validation surveys, which a state agency finishes within 60 days of the accreditor's survey. A complaint alleging serious noncompliance can also bring a CMS-authorized survey. ## Sources - [CMS State Operations Manual, Appendix L: Guidance for Surveyors, Ambulatory Surgical Centers](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_l_ambulatory.pdf) - [CMS State Operations Manual, Appendix A: Hospitals (A-0263)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_a_hospitals.pdf) - [CMS State Operations Manual, Appendix PP: Long-Term Care Facilities (F865)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [CMS, Fiscal Year 2027 Mission and Priorities Document](https://www.cms.gov/files/document/fy-27-mpd.pdf) - [Joint Commission, Ambulatory Care Accreditation Organization Survey Activity Guide (2026)](https://digitalassets.jointcommission.org/api/public/content/2f21045af9d84f5fbc9bfef10d620469) - [Joint Commission, National Performance Goals effective January 2026, Hospital Program](https://digitalassets.jointcommission.org/api/public/content/9ca80055182b4274842a5780a94f2c82) - [Joint Commission Perspectives, November 2025 (Accreditation 360: Continuous Engagement)](https://digitalassets.jointcommission.org/api/public/content/ac1009e032dc4632a317c35e5ddc86fe) - [Joint Commission, Sentinel Event Policy (SE chapter, CAMH Update 1, July 2026)](https://digitalassets.jointcommission.org/api/public/content/4035922bcc2f41bd83fbc1f55764a7b4?v=bf31f43b) - [AAAHC, v45 Standards press release (August 18, 2026)](https://www.aaahc.org/uploads/2026/08/260817_MBD_DOC_AAAHC-v45-Standards-Press-Release_FINAL.pdf) - [AAAHC, Documenting a Quality Improvement Study Using the Six-Component Criteria](https://www.aaahc.org/uploads/2025/08/03-250801_IQI_DOC_Documenting-QI-Using-6-Component-Criteria_v44.pdf) ## Related - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) - [Nursing home recertification survey: process and prep](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) - [Joint Commission survey readiness: tracers, unannounced](https://incidentkit.ai/compliance/survey-readiness/joint-commission-survey-readiness) - [Always Survey-Ready: Stay Prepared for Unannounced Surveys](https://incidentkit.ai/use-cases/always-survey-ready) - [Survey readiness self-check for healthcare facilities](https://incidentkit.ai/tools/survey-readiness-check) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) - [What to put in a plan of correction (CMS-2567)](https://incidentkit.ai/blog/what-to-put-in-a-plan-of-correction) --- # Near-miss reporting and safety culture: a practical guide > A near miss could have caused harm but was caught or reached no one. It shows the same system weakness as an injury, without the injury. Staff report more when reports lead to fixes, not blame. Use a just culture, make filing quick, and tell reporters what changed. Source: https://incidentkit.ai/guides/near-miss-reporting-and-safety-culture · Updated Oct 5, 2026 ## Near misses expose weaknesses before anyone is hurt A near miss is an error or hazard that was caught, or never reached anyone, before it caused harm. The Joint Commission calls these close calls or good catches. OSHA and EPA say near miss. OSHA's process safety rule covers incidents that "could reasonably have resulted" in a catastrophic release. See [near miss](https://incidentkit.ai/glossary/near-miss). The cause is the same whether or not someone was hurt. CMS gives a surgery center example. Records for two patients booked for the same foot procedure, on opposite feet, get mixed up. The time-out catches it. CMS says centers should find such errors, because they can cause adverse events. Surveyors read near misses as proof of how a system behaves. CMS hospital guidance describes a year with three wrong-site surgeries and five near misses, and no action. CMS says that suggests noncompliance with the QAPI condition. ## Most harm events go unreported In a 2012 HHS Office of Inspector General study, hospital incident systems captured an estimated 14 percent of the harm events Medicare patients experienced. Administrators said staff did not see about 61 percent of harm events as reportable. Harm is common. A 2022 OIG study found 25 percent of Medicare patients had harm during hospital stays in one month: 12 percent adverse events and 13 percent temporary harm. Physician reviewers judged 43 percent of those events preventable. Near misses are harder to see, because nothing visible happens. AHRQ's PSNet notes that reports do not show how many near misses occurred. Physicians generally do not use voluntary systems. No feedback is a commonly cited reason people stop. ## Just culture holds people accountable without blame A just culture keeps people accountable for choices and treats most errors as symptoms of the system. AHRQ's PSNet describes a culture of safety as one where people report errors and near misses without fear of reprimand. See [just culture](https://incidentkit.ai/glossary/just-culture). *The three categories as commonly described* | Category | What it looks like | Where the response belongs | | --- | --- | --- | | Human error | A slip, lapse or mistake in a system that allowed it | System review: design, workload, tools, communication | | At-risk behavior | A shortcut that seems safe or saves time | Find out why it makes sense and fix the conditions | | Reckless behavior | Knowingly taking a significant risk | Administrative or HR process, outside root cause analysis | A simple test, following RCA2: if a well-trained person in typical conditions made the error, others could too. Look for the system factor. Discipline would change one person and leave the next exposed. RCA2 says to define blameworthy events in advance, such as criminal or deliberately unsafe acts, and handle them through HR. That protects the analysis and the reporter. > **Protection from retaliation is also a legal matter** The Joint Commission expects reporting systems "without the risk of retaliation," but accountability for negligence remains. OSHA's recordkeeping rule bars discharging or discriminating against an employee for reporting a work injury or illness. Pennsylvania's MCARE Act protects health care workers who report. See [employee reporting and retaliation](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation). ## Six barriers to reporting, and what fixes them | Barrier | What you hear | What helps | | --- | --- | --- | | Fear of blame | It will end up in my file. | A written just culture policy. Reports kept out of discipline. Leaders who thank the reporter. | | No feedback | Nothing ever happens. | Acknowledge within a day. Tell the reporter the outcome. | | Not seen as reportable | That is just how it is here. | A short list of examples per unit. OIG found staff did not see most harm events as reportable. | | Too slow | I do not have time. | A phone-friendly form that takes the story in plain words. | | Unclear route | Where do I send this? | One door: a QR code, a link or an email address. | | Counts that punish | Reporting hurts our safety numbers. | Make sure no bonus, contest or discipline rule discourages reports. OSHA treats a procedure that would deter a reasonable employee as unreasonable. | ## Eight steps to raise near-miss reporting 1. **Define a near miss in plain words** Give five examples per unit, drawn from your own events. 2. **Make the first report take two minutes** Allow a phone, QR code, link or email, in the person's own words. 3. **Accept reports from everyone** Contractors, volunteers and visitors see what employees miss. Skip the login. 4. **Acknowledge within a day** Even an automatic message shows someone received it. 5. **Triage by risk** Rate severity and likelihood, not who filed. See the [root cause analysis and CAPA guide](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide). 6. **Fix cheap things fast** Quick wins show reports work. Post what changed where staff will see it. 7. **Recognize good catches** Thank the person and explain what the catch taught the team. 8. **Review monthly by unit** Look at trends, repeat near misses and open actions. Keep it short. > **Three questions that turn a near miss into a lesson** What was the worst plausible outcome? What stopped it, design or luck? Where else could the same thing happen? The third question is the preventive half of CAPA. See [how to get staff to report near misses](https://incidentkit.ai/blog/how-to-get-staff-to-report-near-misses). The [near-miss report template](https://incidentkit.ai/templates/near-miss-report) is a short form to start with. ## Healthcare examples show the work after the catch **Surgery center.** The time-out caught the mixed-up records. The useful work comes next. Why were two same-day cases with opposite sides scheduled so they could be confused? Is the catching check reliable on a busy day? **Nursing home (illustrative scenario).** A nursing assistant finds a bed-exit alarm unplugged during rounds. The resident is fine. The report asks why, and finds a shared charger across rooms. A second outlet and a charging check fix it. Nobody would have found that after a fall. ## Lessons from industry and aviation **Process safety.** OSHA's standard requires covered employers to investigate any incident that did, or could reasonably have, caused a catastrophic release. Start within 48 hours. A near miss can create a legal duty. In OSHA and EPA's example, earlier non-lethal releases were blamed on operator error, when funding cuts had weakened mechanical integrity. **BP Texas City.** The 2005 refinery explosion killed 15 workers and injured 180. The U.S. Chemical Safety Board found safety deficiencies at all levels. BP had put personal injury measures ahead of process safety indicators. The board urged reporting of incidents and near misses without fear of retaliation. A low injury rate does not prove a safe process. See [TRIR and DART rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates). **Aviation.** NASA's Aviation Safety Reporting System takes voluntary reports through NASA, not the regulator. Reports are de-identified. The FAA will not use them in enforcement except for criminal offenses and accidents. A reporter who files within 10 days of an inadvertent violation may qualify for a penalty waiver. The lesson: separate reporting from discipline, and publish what you learn. ## Feedback keeps reporting alive A feedback loop runs from report to acknowledgment, triage, action, verification and a message back to the reporter. Without the last step, reporting decays. PSNet lists missing feedback as a common barrier. The VA triage rules in RCA2 require timely feedback to every known reporter, whatever the risk score. *Suggested targets. These are recommendations, not regulatory requirements.* | Stage | Target | | --- | --- | | Acknowledge | Same business day | | Triage | Serious events same day; others within three days | | Action decided | Low risk within two weeks; serious on the analysis timeline | | Verify | On the date set in the measure | | Tell the reporter and unit | Within a week of the decision; monthly unit summary | A "you said, we did" board or monthly message closes the loop for everyone, not only the person who filed. ## Measure trust, not report volume The Joint Commission's hospital standards expect leaders to evaluate safety culture regularly with valid, reliable tools. Its ambulatory survey guide lists culture of safety data among documents surveyors expect. AHRQ's Surveys on Patient Safety Culture cover hospitals, medical offices, nursing homes, pharmacies and surgery centers. Also watch for signs of trust: - Near-miss share of reports, as a trend, not a quota. - Hours from event to report; days from report to feedback. - Share of reports that led to a verified action. - Repeat near misses by location. PSNet cautions that some organizations celebrate more reports and others fewer, and both can be wrong. A count needs a denominator and an outcome. ## How IncidentKit supports near-miss reporting Staff can report through a [QR quick report](https://incidentkit.ai/product/quick-report), [email-to-incident](https://incidentkit.ai/product/email-to-incident) or a web form, and describe what happened by text. Voice is rolling out. [Lauren](https://incidentkit.ai/product/lauren) asks the follow-up questions, and a person reviews and signs. IncidentKit has no seats, so adding every employee, contractor and visitor costs nothing extra. Non-patient incidents are free on the Open plan. See [near-miss reporting](https://incidentkit.ai/use-cases/near-miss-reporting) and [pricing](https://incidentkit.ai/pricing). ## Frequently asked questions ### What is a near miss? A near miss is an error or hazard that did not cause harm, either because it was caught in time or because it reached no one. CMS gives the example of mixed-up surgery records caught at the time-out. Hospitals also call near misses close calls or good catches. ### Should near misses be investigated? Yes, in proportion to risk. Triage by severity and likelihood. Investigate high-risk ones with a team and review low-risk ones quickly. OSHA and EPA urge root cause analysis after any near miss. OSHA's process safety standard requires investigating incidents that could reasonably have caused a catastrophic release. ### What is just culture? Just culture balances accountability with a focus on systems. It separates human error, at-risk behavior and reckless conduct, and responds to each differently. Most errors lead to system fixes. Deliberate or reckless acts go through HR, outside root cause analysis. ### How do you encourage staff to report near misses? Make reporting safe, quick and useful. Write a just culture policy, accept reports by phone, QR code or email, acknowledge each within a day, and tell reporters what changed. PSNet names missing feedback as a common barrier, so closing the loop matters more than incentives. ### Can near-miss reports be anonymous? Yes, with a trade-off. PSNet says most systems are confidential: the reporter is known but protected. Some, like the ICU Safety Reporting System, are fully anonymous. Anonymous reports cannot get follow-up questions. Offer confidentiality by default, and anonymity where fear is high. ### What is a good ratio of near misses to incidents? There is no valid universal ratio. PSNet notes that event reports lack a denominator and miss unreported near misses. Track the near-miss share of your own reports over time, with feedback speed and repeat events. A rising share after a culture push is a good sign. ## Sources - [CMS State Operations Manual, Appendix L: Ambulatory Surgical Centers (QAPI near-miss example)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_l_ambulatory.pdf) - [CMS State Operations Manual, Appendix A: Hospitals (A-0263)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_a_hospitals.pdf) - [HHS OIG, Hospital Incident Reporting Systems Do Not Capture Most Patient Harm (OEI-06-09-00091, 2012)](https://oig.hhs.gov/oei/reports/oei-06-09-00091.asp) - [HHS OIG, Adverse Events in Hospitals: A Quarter of Medicare Patients Experienced Harm in October 2018 (2022)](https://oig.hhs.gov/reports/all/2022/adverse-events-in-hospitals-a-quarter-of-medicare-patients-experienced-harm-in-october-2018/) - [AHRQ PSNet, Patient Safety Event Reporting primer](https://psnet.ahrq.gov/primer/reporting-patient-safety-events) - [AHRQ PSNet, Culture of Safety primer](https://psnet.ahrq.gov/primer/culture-safety) - [Joint Commission, National Performance Goals effective January 2026, Hospital Program (NPG.02.03.01)](https://digitalassets.jointcommission.org/api/public/content/9ca80055182b4274842a5780a94f2c82) - [Joint Commission, Ambulatory Care Accreditation Organization Survey Activity Guide (2026)](https://digitalassets.jointcommission.org/api/public/content/2f21045af9d84f5fbc9bfef10d620469) - [IHI, Action Hierarchy Tool (RCA2 and blameworthy events)](https://www.ihi.org/sites/default/files/SafetyToolkit_ActionHierarchy.pdf) - [IHI and NPSF, RCA2: Improving Root Cause Analyses and Actions to Prevent Harm](https://www.ihi.org/sites/default/files/RCA2_ImprovingRootCauseAnalysesandActionstoPreventHarm.pdf) - [29 CFR Part 1904, including 1904.35 employee involvement (eCFR)](https://www.ecfr.gov/current/title-29/part-1904) - [Pennsylvania MCARE Act (Act 13 of 2002), section 308](https://www.legis.state.pa.us/WU01/LI/LI/US/PDF/2002/0/0013..PDF) - [OSHA and EPA, The Importance of Root Cause Analysis During Incident Investigation (fact sheet)](https://www.osha.gov/sites/default/files/publications/OSHA3895.pdf) - [29 CFR 1910.119, Process safety management of highly hazardous chemicals (eCFR)](https://www.ecfr.gov/current/title-29/section-1910.119) - [U.S. Chemical Safety Board, BP America Refinery Explosion](https://www.csb.gov/bp-america-refinery-explosion/) - [NASA Aviation Safety Reporting System, Immunity Policies (FAA Advisory Circular 00-46F)](https://asrs.arc.nasa.gov/overview/immunity.html) ## Related - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [How to get staff to report near misses (and keep doing it)](https://incidentkit.ai/blog/how-to-get-staff-to-report-near-misses) - [Near miss: definition and meaning](https://incidentkit.ai/glossary/near-miss) - [Just culture: definition and meaning](https://incidentkit.ai/glossary/just-culture) - [Near Miss Report Template (Free, Printable Form)](https://incidentkit.ai/templates/near-miss-report) - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Injury reporting and retaliation: 29 CFR 1904.35 and 11(c)](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation) --- # OSHA recordkeeping guide: the Part 1904 system, end to end > Under 29 CFR Part 1904, many employers with more than 10 employees log each recordable injury or illness on Form 300, file a Form 301 for each, and post a Form 300A yearly. Keep records five years. Report deaths within 8 hours, and hospitalizations, amputations and eye losses within 24. Source: https://incidentkit.ai/guides/osha-recordkeeping-guide · Updated Oct 5, 2026 ## Most employers over 10 employees must keep records You must keep records if you had more than 10 employees at any time last year, unless the establishment is in a partially exempt industry. The size test counts the whole company's peak employment. The industry test applies to each establishment, by NAICS code. The exempt list is Appendix A to Subpart B of Part 1904. In healthcare it includes offices of physicians (6211), dentists (6212) and other health practitioners (6213), outpatient care centers (6214), and medical and diagnostic laboratories (6215). Hospitals (6221 to 6223) and nursing care facilities (6231) are not on it. Freestanding surgery centers generally fall under NAICS 621493, inside 6214, so many are partially exempt. Confirm your code with the Census Bureau lookup the rule points to. > **Partial exemption is not full exemption** Every covered employer must still report a work-related death, inpatient hospitalization, amputation or loss of an eye. Exempt employers must keep records if OSHA or BLS asks in writing, and complete a BLS survey if selected. See [recordkeeping overview](https://incidentkit.ai/compliance/osha/recordkeeping-overview). Recording a case does not mean anyone was at fault, that a rule was broken, or that workers' compensation applies. ## Three forms: 300 log, 301 report, 300A summary | Form | Name | What it holds | When | | --- | --- | --- | --- | | OSHA 300 | Log of Work-Related Injuries and Illnesses | One or two lines per recordable case | Within 7 calendar days of learning of the case | | OSHA 301 | Injury and Illness Incident Report | Details of each case. An equivalent form, such as an insurance form with the missing fields, is allowed | Within 7 calendar days | | OSHA 300A | Summary of Work-Related Injuries and Illnesses | Totals, average employees and hours worked, certified by a company executive | After year end; post February 1 to April 30 | Keep a separate log for each establishment expected to run a year or longer. Short-term sites may share one. You may keep records centrally if you can send case information to the central office within 7 days. Electronic records are fine if they can produce equivalent forms. The certifier is an owner, a corporate officer, the top official at the establishment, or that person's immediate supervisor. Keep the log, privacy case list, summary and 301 forms five years after the year they cover. Update the log, but not the 300A or 301. The injury rate most employers quote is cases times 200,000, divided by hours worked. BLS says 200,000 equals 100 full-time employees working 40 hours for 50 weeks. See the [TRIR and DART calculator](https://incidentkit.ai/tools/trir-dart-calculator). ## Five questions decide if a case is recordable 1. **Is the person a covered employee?** Anyone on your payroll, plus agency or leased workers you supervise daily. Self-employed people and owners of sole proprietorships and partnerships are not covered. 2. **Is it work-related?** Something at work caused or added to it. Work events are presumed work-related unless an exception applies. Examples: a visit as a member of the public, voluntary wellness activity, your own food, off-shift tasks, colds and flu. 3. **Is it a new case?** It is new if the worker had no earlier recorded case of the same type and body part, or had fully recovered. 4. **Does it meet the general criteria?** Death, days away, restricted work or transfer, treatment beyond first aid, or loss of consciousness. Cancer, chronic irreversible disease, a cracked bone and a punctured eardrum count at diagnosis. 5. **Do special criteria apply?** Needlestick and sharps injuries, hearing loss, tuberculosis and medical removal have their own rules. Mental illness counts only if a licensed professional says it is work-related. A commuting crash on the company lot is also an exception. ## OSHA's first aid list is complete Treatment not on the list is medical treatment, whatever the provider's license. Visits only for observation or counseling, and diagnostic tests such as x-rays and blood tests, are not medical treatment. See [first aid](https://incidentkit.ai/glossary/first-aid) and [first aid vs medical treatment](https://incidentkit.ai/blog/first-aid-vs-medical-treatment-osha). | First aid (not recordable on its own) | Medical treatment (recordable) | | --- | --- | | Non-prescription medication at non-prescription strength | Prescription medication, including advice to use a non-prescription drug at prescription strength | | Tetanus immunization | Other vaccines, such as hepatitis B or rabies | | Cleaning, flushing or soaking surface wounds; bandages, gauze, butterfly bandages | Sutures, staples and other wound-closing devices | | Hot or cold therapy; non-rigid wraps and supports | Rigid supports or devices that immobilize a body part | | Temporary splints, slings or collars while transporting someone; eye patches; finger guards | Physical therapy or chiropractic treatment | | Removing splinters or eye foreign bodies by irrigation or swab; draining a blister; massage; fluids for heat stress | Any treatment not on the first aid list | **Example.** A nurse hurts a wrist moving a patient. The clinic gives a cold pack and an elastic wrap. That is first aid, so the case is not recordable. If the clinic instead applies a rigid splint to immobilize the wrist, that is medical treatment, and the case is recordable. A case that meets a criterion is recordable even if the worker declines the recommended treatment. See [recordable vs first aid](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid). ## Count days away and restricted days this way - Start the day after the injury. Count calendar days, weekends included. - You may stop at 180 days, or if the worker leaves for another reason. - Record a case that spans two years once, in the year it began. - Count days a physician recommends, even if the worker comes in. - Restricted work: a routine function (done weekly) or a full shift is off limits. - Producing less while doing every routine function is not a restriction. - For a vague "light duty" note, ask if all routine functions are possible. ## Key deadlines at a glance | What | Deadline | Rule | | --- | --- | --- | | Enter case on 300 Log and 301 | 7 calendar days after learning of it | 1904.29(b)(3) | | Report an employee death to OSHA | 8 hours; only if death is within 30 days of the incident | 1904.39 | | Report inpatient hospitalization, amputation or loss of an eye | 24 hours; only if it occurs within 24 hours of the incident | 1904.39 | | Post the annual summary | By February 1; keep through April 30 | 1904.32 | | Keep records | 5 years after the end of the covered year | 1904.33 | | Give an employee or representative the 300 Log, or an employee their own 301 | By the end of the next business day | 1904.35 | | Give a union representative 301 forms | Within 7 calendar days, case description only | 1904.35 | | Give records to OSHA or other inspectors | Within 4 business hours | 1904.40 | | Retest hearing loss | Within 30 days; if confirmed, record within 7 days of the retest | 1904.10 | | Electronic submission, if covered | March 2 of the following year | 1904.41 | The reporting clock runs from when you or any agent learns of the event and that it was work-related (1904.39(b)(7), (b)(8)). Report by phone to the nearest area office, at 1-800-321-OSHA, or online. If the area office is closed, use the toll-free line or website, not voicemail or email. Highway crashes outside construction work zones and incidents on commercial transportation need not be reported, though they may be recordable. See [severe injury reporting](https://incidentkit.ai/compliance/osha/severe-injury-reporting). ## Some employers submit data to OSHA each year Three groups submit through OSHA's Injury Tracking Application (ITA). Part-time, seasonal and temporary workers count toward headcounts. - 20 to 249 employees, Appendix A to Subpart E industries: Form 300A data. - 250 or more employees that must keep records: Form 300A data. - 100 or more employees, Appendix B industries: 300A, plus 300 and 301 data. Hospitals, nursing care facilities and many residential care facilities are on both appendices. Partially exempt sites do not submit unless OSHA notifies them in writing. The window is January 2 to March 2. The ITA takes a web form, CSV upload or API. Data for 2025 was due March 2, 2026. Data for 2026 is due March 2, 2027. The rule was amended in 2016, 2017, 2019 and 2023, so check OSHA's [injury tracking page](https://incidentkit.ai/compliance/osha/electronic-submission) each January. ## Employees may report freely, without retaliation Give employees a reasonable way to report injuries and illnesses. Tell them how, tell them they have the right to report, and tell them they may not be fired or punished for it. A procedure is not reasonable if it would deter a reasonable employee from reporting accurately. Section 11(c) of the OSH Act separately protects people who report or ask for records. Privacy concern cases get "privacy case" in the name column, with a separate confidential list of names. The rule's list is complete: intimate body parts or the reproductive system, sexual assault, mental illness, HIV, hepatitis, tuberculosis, contaminated needlesticks and sharps injuries, and illnesses where the employee asks for privacy. See [employee reporting and retaliation](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation). ## Healthcare and other special cases have their own rules - **Needlesticks and sharps.** Record every work-related cut from a blood-contaminated sharp, as an injury. - **Sharps injury log.** Part 1904 employers also keep one under the bloodborne pathogens standard. - **Splashes.** Record as an illness only if it leads to a bloodborne diagnosis. - **Patient injuries.** Presumed work-related. See [workplace violence reporting](https://incidentkit.ai/use-cases/workplace-violence-reporting). - **Hearing loss.** Record a 10 dB average shift at 2000, 3000 and 4000 Hz, at 25 dB total. - **Temporary workers.** Whoever supervises them daily records the case, once. - **Several sites.** Record it where it happened, or at the home site. ## How IncidentKit supports OSHA recordkeeping OSHA 300, 300A and 301 exports are rolling out. They are not live yet. Today the incident record can hold the facts a recordability decision needs, such as treatment, days away and restricted days. The [audit trail](https://incidentkit.ai/product/audit-trail) shows who decided what and when. As exports arrive, [compliance packets](https://incidentkit.ai/product/compliance-packets) will draw the forms from the same record. See [OSHA 300 log automation](https://incidentkit.ai/use-cases/osha-300-log-automation) and [workplace injury reporting](https://incidentkit.ai/use-cases/workplace-injury-reporting). OSHA rules change, so check each requirement against the cited section. ## Frequently asked questions ### Does my company need to keep an OSHA 300 log? Probably, if you had more than 10 employees at any time last year and your establishment is not in a partially exempt industry. The size test counts the whole company. The industry test applies by establishment, using NAICS code. Exempt employers must still report deaths, hospitalizations, amputations and eye losses. ### What is the difference between OSHA Forms 300, 300A and 301? Form 300 is the log, one line per recordable case. Form 301 is the incident report with details of each case. Form 300A is the annual summary, certified by a company executive and posted February 1 to April 30. Keep all three for five years. ### When must I report a hospitalization or fatality to OSHA? Report an employee death within 8 hours, and an inpatient hospitalization, amputation or loss of an eye within 24 hours, from when you learn it was work-related. A death counts only if it occurs within 30 days of the incident. The others count only if they occur within 24 hours. ### Is a case recordable if the worker only received first aid? No. A case needing only first aid, with no other criterion such as days away, restricted work or loss of consciousness, is not recordable. OSHA's first aid list is complete. Any treatment not on it, such as prescription medication or sutures, is medical treatment and makes the case recordable. ### How long must OSHA records be kept? Five years after the end of the calendar year they cover. That applies to the 300 Log, the privacy case list, the 300A summary and the 301 forms. Update the log for new cases and changed outcomes. You do not need to update the summary or 301 forms. ### When is the OSHA electronic submission deadline? March 2 of the year after the data year. Data for 2025 was due March 2, 2026, and data for 2026 is due March 2, 2027. Covered employers submit through OSHA's Injury Tracking Application, which opens January 2. Check OSHA's notice each January, because the rules have changed several times. ## Sources - [29 CFR Part 1904, Recording and Reporting Occupational Injuries and Illnesses (eCFR)](https://www.ecfr.gov/current/title-29/part-1904) - [29 CFR 1910.1030, Bloodborne pathogens, including the sharps injury log (eCFR)](https://www.ecfr.gov/current/title-29/section-1910.1030) - [OSHA, Injury and Illness Recordkeeping and Reporting Requirements](https://www.osha.gov/recordkeeping) - [OSHA, Injury Tracking Application (ITA) Information](https://www.osha.gov/injuryreporting) - [U.S. Bureau of Labor Statistics, Compute nonfatal incidence rates](https://www.bls.gov/iif/overview/compute-nonfatal-incidence-rates.htm) ## Related - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [OSHA 301 incident report: the 18 fields and deadlines](https://incidentkit.ai/compliance/osha/osha-301-incident-report) - [OSHA 300A summary: who signs, when to post, how long](https://incidentkit.ai/compliance/osha/osha-300a-summary) - [Recordable vs first aid: OSHA's medical treatment test](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [OSHA electronic submission: 29 CFR 1904.41 and the ITA](https://incidentkit.ai/compliance/osha/electronic-submission) - [OSHA 300 Log Automation: Keep It Accurate Year-Round](https://incidentkit.ai/use-cases/osha-300-log-automation) --- # Incident management software buyer's guide > Choose incident software by testing the job: a two-minute phone report, routing to the right owner, investigations, corrective actions that need proof to close, and exports for surveyors. Ask for a BAA, read the security report, price all three years and plan adoption. Unused software records nothing. Source: https://incidentkit.ai/guides/incident-management-software-buyers-guide · Updated Oct 5, 2026 ## Incident software is your record of what went wrong Incident management software captures incidents, routes them to owners, supports investigation, tracks corrective actions, produces compliance outputs and keeps an audit trail. It is the system of record for what went wrong and what you did. Products fall into four groups: healthcare risk platforms, EHS platforms built around OSHA logs, point solutions for one job, and paper or spreadsheets. See the [comparison pages](https://incidentkit.ai/compare), [alternatives](https://incidentkit.ai/alternatives) and [paper and spreadsheets](https://incidentkit.ai/compare/paper-and-spreadsheets). It should run alongside your EHR, CMMS and HRIS, not replace them. > **Who wrote this** IncidentKit makes incident software, so this guide has a stake. Use the checklist on us too. Where we are the wrong fit, we say so. ## Define the job before you shop 1. **List incident types by site** Falls, medication events, injuries, security events, equipment failures, abuse allegations. 2. **Say who reports, on what device** Clinicians at shared workstations, aides on phones, contractors with no account, visitors with a QR code. 3. **Name who triages, investigates and signs** Software cannot fix an unowned process. 4. **List what you must send outside** State agencies, CMS, OSHA, a patient safety organization, your accreditor, your insurer. 5. **List what you must show on request** Surveyors ask for lists, trends and proof of fixes. See [survey and accreditation readiness](https://incidentkit.ai/guides/survey-and-accreditation-readiness). 6. **List the systems it must connect to** EHR, CMMS, HRIS, single sign-on. Split must-have from nice-to-have. 7. **Count the sites** One surgery center and a 40-site group need different roles, reports and pricing. ## Score what works in a demo, not on slides Reporting is the usual weak point. An HHS OIG study found hospital incident systems captured an estimated 14 percent of patient harm events. Intake design matters more than any dashboard. | Area | What to ask | | --- | --- | | Intake | Can a nurse file from a phone in under two minutes? QR, email, web form, offline entry? No login? Which languages? | | Routing and escalation | Rules by type, severity and location; time-based escalation; acknowledgment tracking. Some outside clocks are as short as 2 hours. | | Investigation | Contributing factors, timeline, interviews, templates. Protected analysis kept apart from compliance records. | | Corrective actions | Owner, due date, evidence, effectiveness check. Can an action close unverified? If so, it proves nothing. | | Standard definitions | AHRQ Common Formats for patient safety organizations, the NQF serious reportable events list, state forms. | | Compliance outputs | QAPI summaries, survey packets, state reports, OSHA 300, 300A, 301. Live or planned? Ask for a live example. | | Analytics | Trends by location, shift, equipment and cause, with denominators. Counts alone mislead. | | Audit trail | Who, when, what changed. Can history be edited or exported? HIPAA requires audit controls. | | Roles and access | Role-based and site-level access, restricted views, single sign-on. Abuse and HR matters need limits. | | Integrations and API | EHR, CMMS, HRIS; read API; signed webhooks. Avoid re-keying. | | Export and exit | Full export of records, attachments and audit trail in open formats. Retention runs years: OSHA records five, process safety reports five, HIPAA policy documents six. | ## Ask for a BAA and read the security report If the system holds patient information, the vendor is a business associate under HIPAA and must sign a business associate agreement. The federal definition names patient safety activities (42 CFR 3.20) among covered functions. See [business associate agreement](https://incidentkit.ai/glossary/business-associate-agreement) and [PHI](https://incidentkit.ai/glossary/phi). | Question | What a good answer includes | | --- | --- | | Will you sign a BAA before we load patient information? | Yes, in writing. The rule requires terms on permitted uses, safeguards, breach reporting, subcontractors, patient rights requests, return or destruction at the end, and your right to end for breach. | | How fast will you tell us about a breach? | HIPAA allows up to 60 calendar days after discovery. Ask for a much shorter window. | | Which subcontractors touch our data? | A named list, bound by the same limits. | | Can we read your security report? | A SOC 2 Type 2 report covering this product, with auditor, period and exceptions visible. The AICPA's 2026 SOC page warns about credibility and quick-turn engagements. | | What do you encrypt, and who has access? | Encryption in transit and at rest, though HIPAA lists it as addressable. Unique IDs, automatic logoff, audit logging, single sign-on, multi-factor authentication. | | Do you use our data to train models? | A clear written answer, covering any AI vendor. | | Where is data stored, and what happens at exit? | Named regions, retention rules, deletion with certification. | | How do you handle security incidents? | Contacts, response process, recovery targets, test history. | Workplace injury records are not automatically protected health information, but they are sensitive. Ask the same questions for non-patient incidents, and ask counsel where the line falls. ## Ask vendors to run your real incidents Give each vendor three of your worst past incidents. Watch them go from report to closed action. Time a night nurse filing a medication event from a phone. ### Reporting - Show a report filed from a phone with no signal. - Show a visitor filing without an account. - How many required fields does the shortest report have? ### Investigation and action - Show an investigation whose cause is a system condition, not a person. - Show an action that cannot close without evidence and an effectiveness check. - Show how a stronger action differs from training alone. ### Compliance and survey - Produce the 12-month list of hospital transfers and deaths in one minute. - Produce a quarterly QAPI committee packet. - Show OSHA 300, 300A and 301 outputs, and which parts are live. ### Data and exit - Export all records, attachments and the audit trail for a site. - Show who can see an abuse allegation, and prove who has. See the [root cause analysis and CAPA guide](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) and the [QAPI program guide](https://incidentkit.ai/guides/qapi-program-guide). ## Price three years, not the first invoice Pricing shapes behavior. If every reporter is a paid seat, you will be tempted to limit who can report. See [incident reporting software pricing models](https://incidentkit.ai/blog/incident-reporting-software-pricing-models). | Model | Watch for | | --- | --- | | Per user or seat | Whether reporters count as seats. | | Per module | Needing three modules for one job. | | Per site | What counts as a site; tiered features. | | Per record or volume | Fees that rise when culture improves. | | Enterprise license | Renewal increases; unbundled extras. | Get these in writing: license cost for the full term with the renewal uplift; setup, migration and training; integration and API fees; AI usage charges; and export or exit fees. Add your own staff time to administer it. IncidentKit's model is plain. Open is free for non-patient incidents. Regulated is a per-site plan for healthcare and audit-ready work, with a BAA, patient information, compliance packets and done-for-you setup. Network is custom for 10 or more sites, with SSO, API, organization-wide analytics and migration. No seats, modules or setup fee. See [pricing](https://incidentkit.ai/pricing). ## Adoption is where projects fail | Failure | Sign | Prevention | | --- | --- | --- | | Reporting stays low | Flat counts; reports only from managers | Short forms, mobile access, feedback to every reporter | | Managers triage late | Reports wait days | A triage owner, targets, escalation | | Actions drift | Overdue list grows; items close with no evidence | Owner and date on every action; no closing without proof | | Legacy habits persist | Staff still use paper or email | Retire the old route on a date; import history | | Nobody reviews data | Dashboards unused | Monthly unit review; quarterly committee review | Start with one unit or site. Train reporters in a short session and managers separately on triage. Review after 30 days before you expand. CMS advises piloting any change in one area first, because some changes have unintended effects. See [import and migration](https://incidentkit.ai/product/import-and-migration). ## Seven buying pitfalls to avoid - **Buying for the survey, not the staff.** If reporters avoid it, dashboards stay empty. - **Judging a demo on perfect data.** Use your own cases. - **Confusing configurable with usable.** A hundred settings do not help a night nurse. - **Ignoring export.** You will want your data back at renewal. - **Accepting AI claims blind.** Ask what a person must approve. - **Letting IT choose alone.** Quality, nursing, EHS and compliance must test it. - **Forgetting the protected record.** Ask how it keeps protected analysis apart. For AI questions, see [AI for incident reporting](https://incidentkit.ai/guides/ai-for-incident-reporting). ## When IncidentKit fits, and when to choose another IncidentKit is incident reporting and corrective-action software for regulated and high-risk work. It has intake by [Lauren](https://incidentkit.ai/product/lauren), QR quick report, email-to-incident and a web form. It adds routing, investigations, verified corrective actions, compliance packets, an audit trail, analytics, and platform features: organizations, facilities, six roles, SSO, signed webhooks and a read API. SSO and the API are part of Network. A person always reviews, edits and signs what Lauren drafts. See IncidentKit's [security](https://incidentkit.ai/security) and [HIPAA](https://incidentkit.ai/hipaa) pages for its own answers to the questions above. Rolling out: voice reporting, OSHA 300, 300A and 301 exports, Spanish and other languages, human-authored RCA templates, deeper EHR, CMMS and HRIS integrations, industry packs beyond healthcare, and an insurer or TPA data feed. If you need one today, ask for a date or choose another product. A broader enterprise risk platform may suit you better if you want claims, contracts and policies in one system and have staff to configure it. IncidentKit is narrower: report it, investigate it, close it, prove it. See the [comparison pages](https://incidentkit.ai/compare). ## A simple weighted scorecard *Example weights. Change them to fit your priorities.* | Criterion | Example weight | Score from | | --- | --- | --- | | Reporting experience | 25 | Timed phone demo | | Corrective action integrity | 20 | Try to close an action without evidence | | Security and BAA | 20 | BAA terms, SOC 2 Type 2 report, subcontractor list | | Compliance outputs | 15 | Live packet or log from your own data | | Three-year cost | 10 | Written quote with renewal terms | | Integrations and exit | 5 | API documentation, test export | | Support and references | 5 | Calls with similar customers | ## Frequently asked questions ### How much does incident reporting software cost? It depends on the model: per user, module, site, record or a custom contract. Get a written quote and compare the full three-year cost, including setup, integrations and renewal increases. IncidentKit publishes its structure: free for non-patient incidents, per site for healthcare, custom for 10 or more sites. ### Do we need a BAA with an incident reporting vendor? Yes, if the system will hold patient information. A vendor that creates, receives, maintains or transmits protected health information for you, including for patient safety activities, is a business associate under HIPAA. Sign before loading patient data, and confirm subcontractors are bound too. ### Should we choose an enterprise risk platform or a focused tool? Choose an enterprise platform if you want claims, contracts and policies in one configurable system and have staff to run it. Choose a focused tool for fast reporting, closed actions and survey evidence with little setup. Test either with your own incidents. ### How long does implementation take? It depends on sites, integrations and imported history, so ask each vendor for a dated plan in writing. A single-unit pilot can start sooner. IncidentKit's Regulated plan includes done-for-you setup, and Network adds migration for groups of 10 or more sites. ### How do we compare incident software vendors fairly? Run one scripted demo for every vendor: three of your real incidents, the same security questions and the same timed phone report. Score with fixed weights, ask for live examples of every compliance output, and request references from organizations like yours. ### Is AI in incident software safe? It can be, if a person approves everything AI drafts, the system marks drafts, and every change is logged. Ask where patient data goes, whether it trains models, and whether the AI vendor signs a BAA. See the AI for incident reporting guide. ## Sources - [45 CFR 160.103, Definitions, including business associate (eCFR)](https://www.ecfr.gov/current/title-45/section-160.103) - [45 CFR 164.504, Business associate contracts (eCFR)](https://www.ecfr.gov/current/title-45/section-164.504) - [45 CFR 164.410, Notification by a business associate (eCFR)](https://www.ecfr.gov/current/title-45/section-164.410) - [45 CFR 164.312, Technical safeguards (eCFR)](https://www.ecfr.gov/current/title-45/section-164.312) - [45 CFR 164.316, Policies, procedures and documentation requirements (eCFR)](https://www.ecfr.gov/current/title-45/section-164.316) - [AICPA and CIMA, System and Organization Controls: SOC Suite of Services](https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services) - [HHS OIG, Hospital Incident Reporting Systems Do Not Capture Most Patient Harm (OEI-06-09-00091, 2012)](https://oig.hhs.gov/oei/reports/oei-06-09-00091.asp) - [AHRQ PSNet, Patient Safety Event Reporting primer](https://psnet.ahrq.gov/primer/reporting-patient-safety-events) - [CMS State Operations Manual, Appendix PP: Long-Term Care Facilities (patient safety evaluation systems and QAPI evidence)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [IHI and NPSF, RCA2: Improving Root Cause Analyses and Actions to Prevent Harm](https://www.ihi.org/sites/default/files/RCA2_ImprovingRootCauseAnalysesandActionstoPreventHarm.pdf) - [29 CFR Part 1904, record retention at 1904.33 (eCFR)](https://www.ecfr.gov/current/title-29/part-1904) - [29 CFR 1910.119, Process safety management, incident investigation retention (eCFR)](https://www.ecfr.gov/current/title-29/section-1910.119) ## Related - [AI for incident reporting: what it can and cannot do](https://incidentkit.ai/guides/ai-for-incident-reporting) - [Survey and accreditation readiness: a continuous approach](https://incidentkit.ai/guides/survey-and-accreditation-readiness) - [Incident reporting software pricing models, explained](https://incidentkit.ai/blog/incident-reporting-software-pricing-models) - [Compare incident reporting software: the full matrix](https://incidentkit.ai/compare) - [Incident reporting software alternatives](https://incidentkit.ai/alternatives) - [Incident reporting software pricing: free to start](https://incidentkit.ai/pricing) - [IncidentKit security overview](https://incidentkit.ai/security) - [Business associate agreement: definition and meaning](https://incidentkit.ai/glossary/business-associate-agreement) --- # AI for incident reporting: what it can and cannot safely do > AI can safely draft incident reports: ask follow-up questions, structure the story, suggest categories and summarize records. It should not decide severity, causes, blame or reporting duties. Keep a person in charge, label AI-drafted fields until approved, log every change, and sign a BAA when patient information is involved. Source: https://incidentkit.ai/guides/ai-for-incident-reporting · Updated Oct 5, 2026 ## The short answer: AI drafts, people decide AI is useful where the task is language: turning a messy account into a structured record, spotting what is missing, and summarizing long text. It is unsafe where the task is judgment or accountability: severity, cause, fault, deadlines and closing an action. The rule is simple. The AI drafts. A named person reviews, edits and signs. The record shows both steps. AAAHC's AI governance guide for ambulatory care (August 2026) calls this meaningful human oversight. See [how AI intake changes incident reporting](https://incidentkit.ai/blog/how-ai-intake-changes-incident-reporting). ## AI can ask, fill and flag at intake | Task | AI role | Person's role | | --- | --- | --- | | Ask follow-up questions | Asks what a risk manager would: time, place, who was told, equipment, outcome | Answers and approves the narrative | | Fill form fields | Proposes values, marked as drafts | Confirms each one | | Suggest type and routing | Suggests a type. Routing rules, not the model, decide who is notified | Corrects the type | | Flag gaps and contradictions | Highlights missing times or conflicting details | Resolves them | | Transcribe or translate | Drafts text from speech or another language | Checks names, doses and times | | Link related reports | Suggests duplicates or related events | Confirms the link | Keep the reporter's own words as the source of truth. Everything the AI adds sits beside them, never replaces them. ### A worked example (illustrative) 1. **The reporter writes** "Found a resident on the floor beside the bed around 2 a.m. He said he was going to the bathroom. I didn't see an injury." 2. **The assistant asks** What time exactly? Was the bed alarm on? Who found the resident and checked for injury? Who was told, and when? 3. **The draft fills in** Fields take only what was said, such as "about 2 a.m." and "no injury seen," each marked draft. Unanswered fields stay blank, not guessed. 4. **The reviewer edits** After the nurse's assessment, the reviewer changes the injury field to a skin tear on the left forearm and records the notifications. 5. **The draft stops short of a cause** If nobody said the alarm failed, the draft does not say so. Causes come later, from the investigation. ## AI can draft and sort in investigations | Task | AI role | Person's role | | --- | --- | --- | | Draft a timeline | Builds it from reports and notes, with a source for each entry | Checks it against records and interviews | | Suggest questions and evidence | Lists interview questions and records to pull | Decides what to ask | | Find clusters | Groups events by location, shift, equipment and cause | Judges if the pattern is real | | Draft contributing factors | Writes first drafts in cause, effect, event form | Team rewrites to the rules. See the [root cause analysis and CAPA guide](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) | | Summarize long records | Produces a short draft | Checks what it left out | | Propose actions | Lists options ranked by strength | Owner and leaders choose. RCA2 asks top leaders to approve each action | ## AI should not decide, close or contact - **Set final severity or harm class.** It drives escalation and outside reporting. - **Decide if a deadline applies.** A model can remind. A person decides. - **State a root cause or assign fault.** Causes are findings, not predictions. - **Recommend discipline.** That belongs in HR, outside root cause analysis. - **Close or verify a corrective action.** Verification needs real-world evidence. - **Contact patients, families or regulators.** A named person must do it. - **Change the record silently.** Every AI edit must be visible and reversible. See [incident reporting in healthcare](https://incidentkit.ai/guides/incident-reporting-in-healthcare) for deadlines. ## Hallucination is a real risk NIST's Generative AI Profile calls false output confabulation: confidently stated but erroneous content. It follows from how models work: they predict likely text. NIST adds that people tend to over-trust automated output, which it calls automation bias. A 2025 npj Digital Medicine study tested clinical note generation across 18 configurations and 12,999 clinician-annotated sentences. It found a 1.47 percent hallucination rate and a 3.45 percent omission rate. Refining prompts and workflows brought major errors below previously reported human note-taking rates. That study covers clinical notes, not incident intake, so it is not a benchmark for any product. Three lessons carry over. Error rates are not zero. Omissions can outnumber inventions. Design and testing change the result. A missing fact, such as a witnessed fall, can matter as much as an invented one. | Failure | Example | Control | | --- | --- | --- | | Fabrication | A draft gives a time the reporter never stated | Fill only from the reporter's words; ask when something is missing | | Omission | A summary drops that a bed alarm was off | Show the original beside the draft; reviewer opens the source | | Misattribution | An action goes to the wrong person or shift | Confirm names and roles | | Overconfident cause | Draft says the cause was failure to follow policy | Treat causes as drafts; require team approval | | Transcription error | A wrong dose in a voice transcript | Reporter confirms names, doses and times | ## Test AI on your own incidents Do not rely on a vendor demo or figures from other tasks. Test on your own text, and set the pass mark before you see results. 1. **Collect real cases** Pull 50 to 100 past narratives, including a few hard ones. Use a BAA or proper de-identification. 2. **Set the pass mark first** Decide what rate of inventions, omissions and wrong categories you accept, and which errors are never acceptable. 3. **Compare drafts with signed records** Have clinicians mark each difference: invention, omission, misattribution or harmless rewording. 4. **Test the review step too** Do reviewers catch planted errors? A rubber-stamp review makes any draft unsafe. 5. **Repeat after every change** Re-run when the vendor changes the model, prompts or form. ## Human-in-the-loop design that holds up 1. **Preserve the reporter's account** Store what was written or dictated, unchanged. 2. **Label AI output as draft** AI-filled fields stay marked and unapproved until a person acts. 3. **Review each field** A named reviewer approves, edits or rejects each one. 4. **Sign by a named person** A person signs the report or investigation. 5. **Log the whole chain** The audit trail records the AI suggestion, the human edit, who approved it and when. 6. **Audit samples** Compare drafts with final records on a schedule to measure edit rates and error types. The last step counters automation bias. Put the most friction where a wrong draft hurts most: severity, cause and reportability. IncidentKit follows this design. [Lauren](https://incidentkit.ai/product/lauren) asks follow-up questions, fills the form and drafts the investigation. Every AI-drafted field shows "Lauren · draft" until approved, and a person always reviews, edits and signs. Staff report by text now. Voice and human-authored RCA templates are rolling out. ## HIPAA and BAA: the model provider counts too If narratives contain patient information, the vendor is a business associate. HIPAA names patient safety activities (42 CFR 3.20) as covered functions. The agreement must include the terms in 45 CFR 164.504(e). See [business associate agreement](https://incidentkit.ai/glossary/business-associate-agreement) and [HIPAA](https://incidentkit.ai/hipaa). The AI model provider is the next link. A subcontractor that handles protected health information for the vendor is itself a business associate, and the vendor's contract must bind it to the same limits. Ask which provider processes your data, whether a BAA covers that exact service, and whether your data trains models. Return-or-destroy terms cover logs and backups. - Add the AI feature to your HIPAA risk analysis. - Send the model only what the task needs. - Ask for a breach notice window far shorter than 60 days. - With a patient safety organization, ask counsel about your evaluation system. ## Log enough to rebuild who decided what HIPAA requires mechanisms that record and examine activity in systems holding electronic protected health information, and controls against improper alteration. For AI features, keep enough to reconstruct who decided what. | Event | Record | | --- | --- | | AI draft generated | Source text, model and version, output as shown, time | | Field edited | Who, when, old and new value | | Field approved | Who, when, which draft | | Record or investigation signed | Signer, time, full state at signing | | AI feature changed or disabled | Who, when, setting before and after | Store each draft as it was shown, because models change. Retention runs for years: OSHA records five years, process safety reports five years, HIPAA policy documents six years. See the [audit trail](https://incidentkit.ai/product/audit-trail). ## Accreditors now write AI expectations In September 2025 the Joint Commission and the Coalition for Health AI released guidance with seven elements: AI policies and governance, patient privacy and transparency, data security, ongoing quality monitoring, voluntary blinded reporting of AI safety events, risk and bias assessment, and training. The fifth element points back to your incident system. AI errors are reportable events. Make sure staff can file one, and review them like any other. AAAHC's v45 standards (August 2026) add an AI governance framework: leadership accountability, risk assessment, cybersecurity, human oversight and transparency. They apply to surveys on or after December 15, 2026. AAAHC's guide includes an AI inventory and vendor checklist. Add your incident software's AI to the inventory. See [AAAHC](https://incidentkit.ai/compliance/accreditation/aaahc) and [Joint Commission](https://incidentkit.ai/compliance/accreditation/joint-commission). ## Questions to ask vendors ### Design - Which fields can the AI draft, and which can it never change? - Is every AI-drafted field marked until a person approves it? - Can a reviewer see the original text beside each draft? - Can we turn each AI feature off? ### Data - Which model providers process our data, and where? - Does a BAA cover that exact service? - Is our data used to train models, by you or your provider? - What do you retain, and how is data deleted at exit? ### Evidence - What do you log for each AI action? - How do you measure fabrication and omission on incident text? - What happens to drafts and tests when the model changes? Pair these with the questions in the [buyer's guide](https://incidentkit.ai/guides/incident-management-software-buyers-guide). ## Frequently asked questions ### Can AI write an incident report? AI can draft one from the reporter's account: ask follow-up questions, fill fields and structure the narrative. A person must review, edit and sign it. Keep the reporter's words unchanged, mark AI-filled fields as drafts until approved, and record who approved what. ### Is it safe to put patient information into an AI tool? Only if the vendor has signed a business associate agreement and the AI model provider that processes the data is also bound by one. Ask whether your data trains models, what is kept, and where it is processed. Without a BAA covering the exact service, do not enter protected health information. ### What is AI hallucination, and how is it controlled? Hallucination, which NIST calls confabulation, is confidently stated but false output. Controls: fill fields only from the reporter's words, ask instead of guessing, link each field to its source, show the original beside drafts, require human approval, and sample drafts against final records. ### Will AI replace risk managers or investigators? No. Judging severity, finding causes, disclosing to families, deciding what to report and verifying fixes all need accountable people. Joint Commission and AAAHC guidance stresses governance and human oversight. AI changes the first draft, not who is responsible. ### Should AI decide severity or whether something is reportable? No. It can suggest, and it can remind a reviewer that a deadline may apply. A named person should set severity and decide on reporting. Rules vary by setting and state, and a wrong call can mean a missed clock or an unneeded report. ### How do we audit AI-assisted incident reports? Log every draft, edit and approval with who and when. Sample records regularly. Compare AI drafts with the final signed record, and track edit rates and error types such as omissions and invented details. Feed findings back into settings, training and vendor review. ## Sources - [NIST, Artificial Intelligence Risk Management Framework: Generative AI Profile (NIST AI 600-1)](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf) - [npj Digital Medicine, A framework to assess clinical safety and hallucination rates of LLMs for medical text summarisation (2025)](https://www.nature.com/articles/s41746-025-01670-7) - [Joint Commission Perspectives, November 2025 (Joint Commission and CHAI responsible AI guidance)](https://digitalassets.jointcommission.org/api/public/content/ac1009e032dc4632a317c35e5ddc86fe) - [AAAHC, v45 Standards press release (August 18, 2026)](https://www.aaahc.org/uploads/2026/08/260817_MBD_DOC_AAAHC-v45-Standards-Press-Release_FINAL.pdf) - [AAAHC, 1095 Advance AI Governance Guide press release (August 17, 2026)](https://www.aaahc.org/uploads/2026/08/2608014_MBD_DOC_1095-Advance-AI-Governance-Guide_Press-Release_FINAL.pdf) - [45 CFR 160.103, Definitions, including business associate (eCFR)](https://www.ecfr.gov/current/title-45/section-160.103) - [45 CFR 164.504, Business associate contracts (eCFR)](https://www.ecfr.gov/current/title-45/section-164.504) - [45 CFR 164.410, Notification by a business associate (eCFR)](https://www.ecfr.gov/current/title-45/section-164.410) - [45 CFR 164.308, Administrative safeguards, including risk analysis (eCFR)](https://www.ecfr.gov/current/title-45/section-164.308) - [45 CFR 164.312, Technical safeguards (eCFR)](https://www.ecfr.gov/current/title-45/section-164.312) - [45 CFR 164.316, Policies, procedures and documentation requirements (eCFR)](https://www.ecfr.gov/current/title-45/section-164.316) - [42 CFR 3.20, Patient safety work product definitions (eCFR)](https://www.ecfr.gov/current/title-42/part-3) - [IHI and NPSF, RCA2: Improving Root Cause Analyses and Actions to Prevent Harm](https://www.ihi.org/sites/default/files/RCA2_ImprovingRootCauseAnalysesandActionstoPreventHarm.pdf) ## Related - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [How AI intake changes incident reporting: forms vs chat](https://incidentkit.ai/blog/how-ai-intake-changes-incident-reporting) - [Incident audit trail: every change, who and when](https://incidentkit.ai/product/audit-trail) - [IncidentKit security overview](https://incidentkit.ai/security) - [HIPAA and BAA for incident reporting](https://incidentkit.ai/hipaa) - [Business associate agreement: definition and meaning](https://incidentkit.ai/glossary/business-associate-agreement) - [Incident management software buyer's guide: how to choose](https://incidentkit.ai/guides/incident-management-software-buyers-guide) - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) --- # Adverse event > An adverse event is patient harm caused by care, not by the illness. Groups define it a bit differently, so say which one you use. Source: https://incidentkit.ai/glossary/adverse-event · Updated Oct 5, 2026 Also known as: AE, adverse patient event ## How groups define it | Group | Its definition | | --- | --- | | CMS, nursing homes (42 CFR 483.5) | A bad, usually unexpected event that causes death or serious injury, or the risk of it. | | HHS Office of Inspector General | Harm to a patient from medical care. Its 2010 hospital study counted short-term harm apart. | | Harvard Medical Practice Study (cited by AHRQ PSNet) | An injury from medical care that lengthened the stay or caused disability at discharge. | | Joint Commission | Sentinel events are the most serious kind. | ## In the rules CMS wants adverse events tracked inside [QAPI](https://incidentkit.ai/glossary/qapi), its quality program. Hospitals, surgery centers, hospices and home health agencies must track them (42 CFR 482.21, 416.43, 418.58 and 484.65). Nursing homes must find, report, track, investigate and study them (42 CFR 483.75(c)(4)). Example: a resident gets a double dose of a blood thinner and goes to the hospital. The facility logs it, finds causes, assigns fixes and tells its quality committee. Mix-up: an adverse event is not always a mistake. A known drug reaction is one. A mistake caught in time is a [near miss](https://incidentkit.ai/glossary/near-miss). ## Frequently asked questions ### Is an adverse event the same as a medical error? No. An error is a mistake. An adverse event is harm. Some adverse events involve no mistake, and many mistakes cause no harm. ### Which adverse events must be reported outside the organization? It depends on the event, setting and state. CMS requires tracking inside QAPI. State laws and device rules may require outside reports. ### What is the difference between an adverse event and a sentinel event? A sentinel event is the most serious kind. It reaches the patient and causes death, severe harm or permanent harm. It needs a full analysis. ## Sources - [AHRQ PSNet: Adverse events, near misses, and errors (primer)](https://psnet.ahrq.gov/primer/adverse-events-near-misses-and-errors) - [42 CFR 483.5: Definitions (long-term care facilities)](https://www.ecfr.gov/current/title-42/section-483.5) - [HHS OIG: Adverse Events in Hospitals: National Incidence Among Medicare Beneficiaries (OEI-06-09-00090, November 2010)](https://oig.hhs.gov/oei/reports/oei-06-09-00090.pdf) - [Joint Commission: Sentinel Event Policy (SE chapter), Comprehensive Accreditation Manual, Update 1, July 2026](https://www.jointcommission.org/-/media/tjc/documents/resources/patient-safety-topics/sentinel-event/camncc_20_se_all_current.pdf) - [42 CFR 482.21: Hospital QAPI condition of participation](https://www.ecfr.gov/current/title-42/section-482.21) - [42 CFR 416.43: ASC QAPI condition for coverage](https://www.ecfr.gov/current/title-42/section-416.43) - [42 CFR 483.75: Nursing home QAPI](https://www.ecfr.gov/current/title-42/section-483.75) ## Related terms - [Near miss](https://incidentkit.ai/glossary/near-miss) - [Sentinel event](https://incidentkit.ai/glossary/sentinel-event) - [Never event](https://incidentkit.ai/glossary/never-event) - [Harm scale](https://incidentkit.ai/glossary/harm-scale) - [QAPI](https://incidentkit.ai/glossary/qapi) - [Medication error](https://incidentkit.ai/glossary/medication-error) ## Related - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Incident reporting software: forms, drafts, workflow](https://incidentkit.ai/product/incident-reporting) --- # Near miss > A near miss is an event that could have hurt someone but did not. Someone caught it in time, or it missed by chance. OSHA calls it a close call. Source: https://incidentkit.ai/glossary/near-miss · Updated Oct 5, 2026 Also known as: close call, potential adverse event ## Near miss and related terms A near miss injured no one. Groups sort the nearby terms in different ways, so the labels matter. | Term | Meaning | Source | | --- | --- | --- | | Near miss or close call | A safety event that did not reach the patient | AHRQ Common Formats | | Near miss (by chance) | No injury, but only by chance | AHRQ PSNet | | Incident | A safety event that reached the patient, harmed or not | AHRQ Common Formats | | Unsafe condition | A situation that makes a safety event more likely | AHRQ Common Formats | ## Where it shows up OSHA tells employers to investigate close calls to find hidden hazards. Under process safety management, you must investigate any incident that could reasonably have caused a catastrophic release. Start within 48 hours (29 CFR 1910.119(m)). Example: a pharmacist spots a look-alike vial before it leaves the pharmacy. A forklift stops short of a person crossing an aisle. No one is hurt, and each shows a problem to fix. Mix-up: an error that reaches the patient with no harm is not a near miss in the AHRQ sense. On the NCC MERP index, an error that never reached the patient is category B. Errors that reached the patient without harm are C and D. ## Frequently asked questions ### What is the difference between a near miss and a no-harm event? A near miss does not reach the patient (AHRQ Common Formats). A no-harm event reaches the patient but causes no injury. ### Do near misses have to be reported to OSHA? Not under the recordkeeping rules. OSHA wants reports of deaths, in-patient hospital stays, amputations and loss of an eye (29 CFR 1904.39). Process safety rules still require an internal investigation. ### Why do near misses matter? Close calls show where hazards are, says OSHA. Looking into them finds hazards before anyone is hurt. ## Sources - [AHRQ PSNet: Adverse events, near misses, and errors (primer)](https://psnet.ahrq.gov/primer/adverse-events-near-misses-and-errors) - [Federal Register, April 8, 2016 (81 FR 20642): AHRQ Common Formats for reporting on health care quality and patient safety](https://www.govinfo.gov/content/pkg/FR-2016-04-08/pdf/2016-08021.pdf) - [OSHA: Recommended practices, hazard identification and assessment (incident investigation)](https://www.osha.gov/safety-management/hazard-identification) - [OSHA 29 CFR 1910.119: Process safety management of highly hazardous chemicals](https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.119) - [OSHA 29 CFR 1904.39: Reporting fatalities, hospitalizations, amputations, and losses of an eye](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.39) - [HHS OIG: Adverse Events in Hospitals: National Incidence Among Medicare Beneficiaries (OEI-06-09-00090, November 2010)](https://oig.hhs.gov/oei/reports/oei-06-09-00090.pdf) ## Related terms - [Adverse event](https://incidentkit.ai/glossary/adverse-event) - [Incident report](https://incidentkit.ai/glossary/incident-report) - [Just culture](https://incidentkit.ai/glossary/just-culture) - [Harm scale](https://incidentkit.ai/glossary/harm-scale) - [Medication error](https://incidentkit.ai/glossary/medication-error) ## Related - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Near Miss Report Template (Free, Printable Form)](https://incidentkit.ai/templates/near-miss-report) - [Near-miss reporting and safety culture: a practical guide](https://incidentkit.ai/guides/near-miss-reporting-and-safety-culture) - [How to get staff to report near misses (and keep doing it)](https://incidentkit.ai/blog/how-to-get-staff-to-report-near-misses) - [QR code quick report for incidents and near misses](https://incidentkit.ai/product/quick-report) --- # Sentinel event > A sentinel event is a patient safety event that reaches a patient and causes death, severe harm or permanent harm. That is the Joint Commission's meaning. Source: https://incidentkit.ai/glossary/sentinel-event · Updated Oct 5, 2026 Also known as: Joint Commission sentinel event ## The official definition The event is not mainly due to the patient's illness. Severe harm counts no matter how long it lasts. Permanent harm counts no matter how mild. Some events count by type. Surgery on the wrong site, patient or procedure counts whatever the outcome. So does a fall, in a setting staffed around the clock, that causes any fracture, or needs surgery, casting or traction, among other results. > These words come from the Update 1 (July 2026) Joint Commission policy. It changes over time, so check the manual you follow. ## What you must do Every sentinel event needs a full, systematic analysis, most often a [root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis). Then carry out a corrective action plan and track it. The policy sets 45 business days from the event, or from when you learn of it. Reporting to the Joint Commission is encouraged, not required. Surveyors do not hunt for sentinel events. They do check how you respond. Mix-up: other groups use their own terms. NQF's [never events](https://incidentkit.ai/glossary/never-event), CMS wording and state laws each have their own lists and clocks. One event can be a sentinel event, a state-reportable event, or both. ## Frequently asked questions ### Do we have to report a sentinel event to the Joint Commission? No. Reporting is strongly encouraged, not required. You must still have a sentinel event policy and fully analyze every sentinel event. ### How long do we have to complete the root cause analysis? The policy expects a thorough analysis and action plan within 45 business days of the event or of learning about it. ### Is every fall a sentinel event? No. A fall counts only with a set result, like a fracture, surgery, casting or traction, a brain, nerve or internal injury needing care, or death or permanent harm. ## Sources - [Joint Commission: Sentinel Event Policy (SE chapter), Comprehensive Accreditation Manual, Update 1, July 2026](https://www.jointcommission.org/-/media/tjc/documents/resources/patient-safety-topics/sentinel-event/camncc_20_se_all_current.pdf) - [AHRQ PSNet: Never events (primer)](https://psnet.ahrq.gov/primer/never-events) - [AHRQ PSNet: Root cause analysis (primer)](https://psnet.ahrq.gov/primer/root-cause-analysis) ## Related terms - [Adverse event](https://incidentkit.ai/glossary/adverse-event) - [Never event](https://incidentkit.ai/glossary/never-event) - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) - [Joint Commission](https://incidentkit.ai/glossary/joint-commission) - [Harm scale](https://incidentkit.ai/glossary/harm-scale) - [Elopement](https://incidentkit.ai/glossary/elopement) ## Related - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) - [What is a sentinel event? Definition, examples, response](https://incidentkit.ai/blog/what-is-a-sentinel-event) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Fall Reporting: What to Record and Review After a Fall](https://incidentkit.ai/use-cases/fall-reporting) --- # Never event > Never events are serious patient safety events that should never happen, like surgery on the wrong body part. The NQF list has 29 of them. Source: https://incidentkit.ai/glossary/never-event · Updated Oct 5, 2026 Also known as: serious reportable event, SRE ## What it means AHRQ PSNet says never events are clear (easy to spot and count), serious (death or major disability) and mostly preventable. Dr. Ken Kizer, then CEO of the National Quality Forum (NQF), coined the term in 2001. The NQF list has 29 serious reportable events in seven groups: - Surgical or invasive procedure - Product or device - Patient protection - Care management - Environmental - Radiologic - Potential criminal ## Payment and reporting In August 2007, CMS said it would stop paying extra costs from many preventable errors, including never events. PSNet says CMS has not paid for wrong-site surgery costs since February 2009. Many states and insurers did the same. For surgery centers, wrong site, side, patient, procedure or implant is also a CMS quality measure (ASC-3) in the [ASC Quality Reporting Program](https://incidentkit.ai/glossary/ascqr). Mix-up: never events, [sentinel events](https://incidentkit.ai/glossary/sentinel-event) and adverse events overlap, but they are different lists. Never events come from NQF, sentinel events from the Joint Commission. An adverse event is any harm from care. ## Frequently asked questions ### Does 'never' mean these events never happen? No. The name states a goal. These events are serious and mostly preventable. When they happen, they are reported and investigated. ### How many events are on the NQF list? AHRQ PSNet says the current list has 29 events in seven groups, from surgery and device events to criminal events. ### Are never events reportable to a regulator? It depends on your state and payers. CMS acts through payment rules, and many states copy them. Check your state and contracts. ## Sources - [AHRQ PSNet: Never events (primer)](https://psnet.ahrq.gov/primer/never-events) - [CMS QualityNet: Ambulatory Surgical Center Quality Reporting Program](https://qualitynet.cms.gov/asc) - [Joint Commission: Sentinel Event Policy (SE chapter), Comprehensive Accreditation Manual, Update 1, July 2026](https://www.jointcommission.org/-/media/tjc/documents/resources/patient-safety-topics/sentinel-event/camncc_20_se_all_current.pdf) ## Related terms - [Sentinel event](https://incidentkit.ai/glossary/sentinel-event) - [Adverse event](https://incidentkit.ai/glossary/adverse-event) - [ASCQR (ASC Quality Reporting Program)](https://incidentkit.ai/glossary/ascqr) - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) ## Related - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) - [ASCQR Program: measures, deadlines, 2.0-point penalty](https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting) - [What is a sentinel event? Definition, examples, response](https://incidentkit.ai/blog/what-is-a-sentinel-event) - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) - [Incident reporting software for surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers) --- # Variance report > A variance report is a hospital's record of care that went off plan, like a wrong dose. Many places treat it as an incident report. Source: https://incidentkit.ai/glossary/variance-report · Updated Oct 5, 2026 Also known as: variance, occurrence report, event report ## What it is It records something that went off the plan of care or the usual process. Hospitals also say incident report, occurrence report or patient safety event report, and use differs by facility. See the [comparison of incident, variance and occurrence reports](https://incidentkit.ai/blog/incident-report-vs-variance-report-vs-occurrence-report). AHRQ PSNet calls these voluntary reporting systems. They rely on the people involved, usually front-line staff, for the details. ## Rules and limits CMS does not require a variance report by name. It requires hospitals to track medical errors and adverse patient events, study the causes and act (42 CFR 482.21(c)(2)). Surgery centers must do the same (42 CFR 416.43(c)(2)). Example: bedside scanning catches a wrong-strength dose. The nurse files a variance report and pharmacy reviews it. Three like reports in a month point to a labeling problem. Limits: PSNet says reports catch only some events. They give a count without a total, so they cannot show true rates. Record facts and system conditions, not blame (see [just culture](https://incidentkit.ai/glossary/just-culture)). ## Frequently asked questions ### Is a variance report the same as an incident report? Often, yes. Some places use one name for process problems and the other for harm events. Check your policy before you compare data. ### Is a variance report legally protected? Not automatically. Federal privilege (42 CFR 3.204) covers patient safety work product sent to a patient safety organization or made in a patient safety evaluation system. State rules differ, so ask counsel. ### What does CMS require instead of a variance report? An ongoing program that tracks adverse events and errors, studies causes and prevents repeats: 42 CFR 482.21(c) for hospitals, 416.43(c) for surgery centers. You choose how to capture events. ## Sources - [AHRQ PSNet: Patient safety event reporting (primer)](https://psnet.ahrq.gov/primer/reporting-patient-safety-events) - [42 CFR 482.21: Hospital QAPI condition of participation](https://www.ecfr.gov/current/title-42/section-482.21) - [42 CFR 416.43: ASC QAPI condition for coverage](https://www.ecfr.gov/current/title-42/section-416.43) - [42 CFR 3.20: Patient safety organization definitions](https://www.ecfr.gov/current/title-42/section-3.20) - [42 CFR 3.204: Privilege of patient safety work product](https://www.ecfr.gov/current/title-42/section-3.204) ## Related terms - [Incident report](https://incidentkit.ai/glossary/incident-report) - [Adverse event](https://incidentkit.ai/glossary/adverse-event) - [Near miss](https://incidentkit.ai/glossary/near-miss) - [Patient safety organization](https://incidentkit.ai/glossary/patient-safety-organization) - [Just culture](https://incidentkit.ai/glossary/just-culture) ## Related - [Incident report vs variance report vs occurrence report](https://incidentkit.ai/blog/incident-report-vs-variance-report-vs-occurrence-report) - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) - [Patient safety event reporting software for hospitals](https://incidentkit.ai/solutions/hospitals) - [Incident reporting software: forms, drafts, workflow](https://incidentkit.ai/product/incident-reporting) - [Replace Paper Incident Forms: A Practical Switch Plan](https://incidentkit.ai/use-cases/replace-paper-incident-forms) --- # Incident report > An incident report is a written record of an unplanned event that hurt, or could have hurt, a person or property. It starts the review. Source: https://incidentkit.ai/glossary/incident-report · Updated Oct 5, 2026 Also known as: event report, occurrence report, accident report ## What it is It records what happened, when and where, who was involved, what was done right away and who knows more. It is the first record, not the last. The investigation adds causes and fixes. Healthcare often says variance, occurrence or patient safety event report. CMS requires adverse events to be tracked and acted on, but no federal rule sets one healthcare form. ## Records the law defines | Record | Who needs it | Key rule | | --- | --- | --- | | OSHA Form 301, Injury and Illness Incident Report | Employers who keep OSHA records, for each recordable case | Finish within 7 calendar days of learning of the case. An equal form, like an insurance form, is allowed (29 CFR 1904.29) | | Process safety incident investigation report | Employers covered by 29 CFR 1910.119 | Start within 48 hours. List dates, a description, contributing factors and advice. Keep five years | | Healthcare event report | Hospitals, surgery centers, nursing homes | No single federal form. It feeds the adverse event tracking QAPI requires | Mix-up: an incident report is not an investigation. Keep what you saw apart from opinions about cause or blame. ## Frequently asked questions ### What should an incident report include? Date, time and place; what happened; who was involved; what was done; who was told. Causes come later. Write what you saw, not who was at fault. ### How soon must an incident report be completed? There is no single clock. OSHA Form 301 is due within 7 calendar days of learning of a recordable case. A process safety investigation must start within 48 hours. States may add deadlines. ### Who should fill out the incident report? The person who saw or found the event, soon, while details are fresh. A supervisor or risk manager then reviews it and picks the investigation level. ## Sources - [AHRQ PSNet: Patient safety event reporting (primer)](https://psnet.ahrq.gov/primer/reporting-patient-safety-events) - [29 CFR 1904.29: Forms (OSHA 300, 300-A and 301)](https://www.ecfr.gov/current/title-29/section-1904.29) - [OSHA 29 CFR 1910.119: Process safety management of highly hazardous chemicals](https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.119) - [42 CFR 482.21: Hospital QAPI condition of participation](https://www.ecfr.gov/current/title-42/section-482.21) - [42 CFR 416.43: ASC QAPI condition for coverage](https://www.ecfr.gov/current/title-42/section-416.43) - [42 CFR 483.75: Nursing home QAPI](https://www.ecfr.gov/current/title-42/section-483.75) ## Related terms - [Variance report](https://incidentkit.ai/glossary/variance-report) - [Near miss](https://incidentkit.ai/glossary/near-miss) - [OSHA recordable injury](https://incidentkit.ai/glossary/osha-recordable) - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) - [Adverse event](https://incidentkit.ai/glossary/adverse-event) ## Related - [How to write an incident report: facts, not opinions](https://incidentkit.ai/blog/how-to-write-an-incident-report) - [Incident report vs variance report vs occurrence report](https://incidentkit.ai/blog/incident-report-vs-variance-report-vs-occurrence-report) - [ASC Incident Report Template for Surgery Centers](https://incidentkit.ai/templates/asc-incident-report) - [Nursing Home Incident Report Template (Printable)](https://incidentkit.ai/templates/nursing-home-incident-report) - [OSHA 301 incident report: the 18 fields and deadlines](https://incidentkit.ai/compliance/osha/osha-301-incident-report) - [Incident reporting software: forms, drafts, workflow](https://incidentkit.ai/product/incident-reporting) --- # QAPI > QAPI (quality assurance and performance improvement) is the quality program CMS requires. Providers use data to track harm and fix root causes. Source: https://incidentkit.ai/glossary/qapi · Updated Oct 5, 2026 Also known as: quality assurance and performance improvement, QAPI program, QAPI/QAA ## What QAPI is QAPI is an ongoing program that runs on data. It is not one committee or one report. CMS's nursing home guide lists five parts: 1. Design and scope 2. Governance and leadership 3. Feedback, data systems and monitoring, including adverse events 4. Performance improvement projects 5. Systematic analysis and systemic action, including root cause analysis ## Where it is required | Setting | Rule | Key point | | --- | --- | --- | | Hospitals | 42 CFR 482.21 | Track adverse patient events. Run improvement projects | | Surgery centers | 42 CFR 416.43 (condition for coverage) | Write down each project's reason and results | | Nursing homes | 42 CFR 483.75 | The QAA committee meets at least each quarter. One project a year on a high-risk area | | Hospices | 42 CFR 418.58 | Track adverse patient events. Record projects and progress | | Home health agencies | 42 CFR 484.65 | Run improvement projects | Mix-up: QAPI is the program. The [QAA committee](https://incidentkit.ai/glossary/qaa-committee) is the nursing home group that oversees it. Hospitals and surgery centers give oversight to the governing body. ## Frequently asked questions ### Is QAPI required for ambulatory surgery centers? Yes. 42 CFR 416.43 is a condition for coverage. It requires a data-driven quality program, tracked adverse events, written improvement projects and governing body oversight. ### What are the five elements of QAPI? Design and scope, leadership, data and feedback, improvement projects, and system-wide analysis and action. CMS's QAPI at a Glance guide describes each. ### What data should a QAPI program use? Quality indicator data and adverse event data, including patient care data. Use it to watch safety, find improvements and check they last. ## Sources - [CMS: QAPI at a Glance, a step-by-step guide for nursing homes](https://www.cms.gov/Medicare/Provider-Enrollment-and-Certification/QAPI/downloads/QAPIAtaGlance.pdf) - [42 CFR 482.21: Hospital QAPI condition of participation](https://www.ecfr.gov/current/title-42/section-482.21) - [42 CFR 416.43: ASC QAPI condition for coverage](https://www.ecfr.gov/current/title-42/section-416.43) - [42 CFR 483.75: Nursing home QAPI](https://www.ecfr.gov/current/title-42/section-483.75) - [42 CFR 418.58: Hospice QAPI condition of participation](https://www.ecfr.gov/current/title-42/section-418.58) - [42 CFR 484.65: Home health agency QAPI condition of participation](https://www.ecfr.gov/current/title-42/section-484.65) ## Related terms - [QAA committee](https://incidentkit.ai/glossary/qaa-committee) - [Performance improvement project](https://incidentkit.ai/glossary/performance-improvement-project) - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) - [Adverse event](https://incidentkit.ai/glossary/adverse-event) - [Effectiveness review](https://incidentkit.ai/glossary/effectiveness-review) ## Related - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [Hospital QAPI requirements: 42 CFR 482.21 explained](https://incidentkit.ai/compliance/cms-qapi/hospitals) - [Hospice QAPI requirements: 42 CFR 418.58 explained](https://incidentkit.ai/compliance/cms-qapi/hospice) - [Home health QAPI requirements: 42 CFR 484.65 guide](https://incidentkit.ai/compliance/cms-qapi/home-health) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) --- # QAA committee > The QAA (quality assessment and assurance) committee runs a nursing home's QAPI quality program. It meets at least every quarter, as CMS requires. Source: https://incidentkit.ai/glossary/qaa-committee · Updated Oct 5, 2026 Also known as: quality assessment and assurance committee, QAA ## Who is on it 42 CFR 483.75(g) says the committee must include the director of nursing, the medical director or a designee, and the infection preventionist. It also needs at least three other staff. One must be the administrator, an owner, a board member or another leader. It reports to the governing body. It meets at least quarterly and as needed. It writes and carries out plans to fix quality problems and reviews data, including drug regimen review data. ## Rules and an example Surveyors cite this rule at F868. The rule also limits sharing. A State or the Secretary may not require the committee's records except to check its own compliance. Good-faith efforts to find and fix quality problems are not a basis for penalties. Example: the committee reviews three months of resident falls and sees a cluster on night shift. It starts a [performance improvement project](https://incidentkit.ai/glossary/performance-improvement-project) on toileting rounds. Mix-up: the committee is not the whole [QAPI](https://incidentkit.ai/glossary/qapi) program. Hospital and surgery center rules do not use the term. They give oversight to the governing body. ## Frequently asked questions ### How often must the QAA committee meet? At least quarterly and as needed (42 CFR 483.75(g)(2)(i)). It meets to coordinate and judge QAPI work, such as picking issues for improvement projects. ### Who must be on the QAA committee? The director of nursing, the medical director or designee, the infection preventionist and at least three other staff, one a leader (administrator, owner or board member). ### Can surveyors read the committee's records? A State or the Secretary may not require them except to check compliance with 42 CFR 483.75. Surveyors can still ask for proof that QAPI works. ## Sources - [42 CFR 483.75: Nursing home QAPI](https://www.ecfr.gov/current/title-42/section-483.75) - [CMS State Operations Manual, Appendix PP: Guidance to Surveyors for Long Term Care Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [CMS: QAPI at a Glance, a step-by-step guide for nursing homes](https://www.cms.gov/Medicare/Provider-Enrollment-and-Certification/QAPI/downloads/QAPIAtaGlance.pdf) ## Related terms - [QAPI](https://incidentkit.ai/glossary/qapi) - [Performance improvement project](https://incidentkit.ai/glossary/performance-improvement-project) - [F-tag](https://incidentkit.ai/glossary/f-tag) - [Corrective and preventive action](https://incidentkit.ai/glossary/corrective-and-preventive-action) ## Related - [F868 QAA committee: members, meetings and evidence](https://incidentkit.ai/compliance/f-tags/f868) - [F865 QAPI program and plan: what surveyors ask for](https://incidentkit.ai/compliance/f-tags/f865) - [F867 QAPI improvement activities: adverse event tracking](https://incidentkit.ai/compliance/f-tags/f867) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [QAPI Meeting Agenda and Minutes Template (Printable)](https://incidentkit.ai/templates/qapi-meeting-agenda-and-minutes) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) --- # Performance improvement project > A performance improvement project (PIP) is a focused effort to fix one specific problem. It uses data to find causes, test changes and measure results. Source: https://incidentkit.ai/glossary/performance-improvement-project · Updated Oct 5, 2026 Also known as: PIP, QAPI project ## What a PIP is CMS calls a PIP a focused effort on one problem, in one area or the whole facility. The team gathers facts to understand the problem, then acts to improve it. It is narrower than QAPI, and it has an end point. CMS's QAPI guide shows a nursing home PIP on unexplained weight loss. The team looked for causes, tried changes in one part of the building with Plan-Do-Study-Act, and measured results before it spread the change. ## What each rule says | Setting | PIP rule | | --- | --- | | Hospitals (42 CFR 482.21(d)) | The number and scope fit the services. Record projects, reasons and measurable progress | | Surgery centers (42 CFR 416.43(d)) | Record each project's reason and a description of its results | | Nursing homes (42 CFR 483.75(e)(3)) | At least one project a year on a high-risk or problem-prone area | | Hospices (42 CFR 418.58(d)) | Build, run and judge projects. Record progress | | Home health (42 CFR 484.65(d)) | Run projects. Required since July 13, 2018 | Mix-up: a PIP is for a pattern or a system problem. One [corrective action](https://incidentkit.ai/glossary/corrective-and-preventive-action) closes one finding. Several findings with a shared cause may call for one PIP. ## Frequently asked questions ### How many performance improvement projects do we need? CMS sets no single number for most settings. The number and scope must fit your services. Nursing homes need at least one a year on a high-risk or problem-prone area. ### Does a PIP have to show measurable improvement? Projects should show measurable progress, and hospitals must record it. Exception: a hospital IT project built to improve patient safety need not show it at the start. ### What documentation do surveyors expect for a PIP? At least the reason for the project and its results. Hospitals and hospices must also record projects underway and progress made. ## Sources - [CMS: QAPI at a Glance, a step-by-step guide for nursing homes](https://www.cms.gov/Medicare/Provider-Enrollment-and-Certification/QAPI/downloads/QAPIAtaGlance.pdf) - [42 CFR 482.21: Hospital QAPI condition of participation](https://www.ecfr.gov/current/title-42/section-482.21) - [42 CFR 416.43: ASC QAPI condition for coverage](https://www.ecfr.gov/current/title-42/section-416.43) - [42 CFR 483.75: Nursing home QAPI](https://www.ecfr.gov/current/title-42/section-483.75) - [42 CFR 418.58: Hospice QAPI condition of participation](https://www.ecfr.gov/current/title-42/section-418.58) - [42 CFR 484.65: Home health agency QAPI condition of participation](https://www.ecfr.gov/current/title-42/section-484.65) ## Related terms - [QAPI](https://incidentkit.ai/glossary/qapi) - [QAA committee](https://incidentkit.ai/glossary/qaa-committee) - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) - [Effectiveness review](https://incidentkit.ai/glossary/effectiveness-review) ## Related - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [QAPI Meeting Agenda and Minutes Template (Printable)](https://incidentkit.ai/templates/qapi-meeting-agenda-and-minutes) - [Hospital QAPI requirements: 42 CFR 482.21 explained](https://incidentkit.ai/compliance/cms-qapi/hospitals) - [Incident analytics: find the pattern before the next one](https://incidentkit.ai/product/analytics) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) --- # Root cause analysis > Root cause analysis (RCA) finds why a serious event happened, so fixes hit causes, not symptoms. It looks at the system, not at blame. Source: https://incidentkit.ai/glossary/root-cause-analysis · Updated Oct 5, 2026 Also known as: RCA, RCA2, comprehensive systematic analysis ## How an RCA works The team rebuilds the event from records and interviews. Then it asks how it happened (the active errors) and why (the hidden conditions in the system). AHRQ PSNet says it seeks system problems, not individual mistakes. A team from different roles does the work, with leaders involved. The VA patient safety center adds that the team keeps asking why, and focuses on how and why, not who. The weak spot is the fix. PSNet says RCAs often fail to produce lasting fixes because they lean on weak steps like training. RCA2 (root cause analysis and action) stresses stronger actions and measured results. ## Where it is expected - Joint Commission: every sentinel event needs a full analysis, most often an RCA. - CMS, nursing homes: look for deeper causes of system-wide problems (42 CFR 483.75(d)(2)(i)). - OSHA: find the root causes of an incident. There is often more than one. Example: a resident falls on the way to the bathroom after a sedative. The RCA finds sedative timing, uneven bed-alarm checks and unclear night-shift ownership. It assigns system fixes with owners and due dates. Mix-up: a root cause is not one cause or one person. A good RCA names several contributing factors and a fix for each. ## Frequently asked questions ### How long should a root cause analysis take? The Joint Commission expects the analysis and action plan within 45 business days of the event or of learning about it. A long gap loses detail. ### Is five whys enough for a serious event? Usually not alone. It follows one chain of cause. IHI notes a problem may have several root causes and points to RCA2 for more rigor. ### Who should be on the RCA team? People who know the process and front-line work, plus leaders, says the VA. Stay fair, and do not stop at the person closest to the event. ## Sources - [AHRQ PSNet: Root cause analysis (primer)](https://psnet.ahrq.gov/primer/root-cause-analysis) - [VHA National Center for Patient Safety: Root cause analysis (page and Guide to Performing a Root Cause Analysis, rev. 02/05/2021)](https://www.patientsafety.va.gov/professionals/onthejob/rca.asp) - [Joint Commission: Sentinel Event Policy (SE chapter), Comprehensive Accreditation Manual, Update 1, July 2026](https://www.jointcommission.org/-/media/tjc/documents/resources/patient-safety-topics/sentinel-event/camncc_20_se_all_current.pdf) - [42 CFR 483.75: Nursing home QAPI](https://www.ecfr.gov/current/title-42/section-483.75) - [OSHA: Recommended practices, hazard identification and assessment (incident investigation)](https://www.osha.gov/safety-management/hazard-identification) - [CMS: QAPI at a Glance, a step-by-step guide for nursing homes](https://www.cms.gov/Medicare/Provider-Enrollment-and-Certification/QAPI/downloads/QAPIAtaGlance.pdf) - [IHI: 5 Whys, finding the root cause](https://www.ihi.org/library/tools/5-whys-finding-root-cause) ## Related terms - [Five whys](https://incidentkit.ai/glossary/five-whys) - [Fishbone diagram](https://incidentkit.ai/glossary/fishbone-diagram) - [Corrective and preventive action](https://incidentkit.ai/glossary/corrective-and-preventive-action) - [Sentinel event](https://incidentkit.ai/glossary/sentinel-event) - [Just culture](https://incidentkit.ai/glossary/just-culture) - [Effectiveness review](https://incidentkit.ai/glossary/effectiveness-review) ## Related - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Root Cause Analysis Worksheet (5 Whys Template)](https://incidentkit.ai/templates/root-cause-analysis-worksheet) - [Five whys vs fishbone vs fault tree: how to choose](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) --- # Corrective and preventive action > CAPA (corrective and preventive action) fixes the cause of a problem, then checks that the fix worked. Healthcare rules often say corrective action. Source: https://incidentkit.ai/glossary/corrective-and-preventive-action · Updated Oct 5, 2026 Also known as: CAPA, corrective action, corrective action plan ## What CAPA covers Corrective action removes the cause of a problem that has happened. Preventive action removes the cause of one that has not happened yet, such as one found in a near miss or an audit. Each needs an owner, a due date, proof it was done and a check that it worked. In IncidentKit, each action has an owner, due date, evidence and an effectiveness check. Nothing closes until it is verified. ## Where it is in the rules - CMS, nursing homes: fixes that change systems and are tracked for results (42 CFR 483.75(d)(2) and (f)(5)). - CMS, surgery centers: judge every improvement for effect (42 CFR 416.43(e)(2)). - Joint Commission: strong actions that remove or control hazards and last, with a timeline and measures. - OSHA process safety management: resolve incident findings fast and record the fixes (29 CFR 1910.119(m)(5)). - FDA: device makers follow the Quality Management System Regulation (effective February 2, 2026). It adds ISO 13485 to 21 CFR Part 820. Mix-up: CAPA is internal. A [plan of correction](https://incidentkit.ai/glossary/plan-of-correction) answers a survey finding. Training and new policies are the weakest tier in VA's ranking of actions. Use them with, not instead of, changes to equipment or process. ## Frequently asked questions ### What is the difference between corrective and preventive action? Corrective action fixes a problem that already happened, like repeat wrong-dose events. Preventive action fixes one that could happen, like a hazard found on a walk-through. ### Is CAPA the same as a plan of correction? No. A plan of correction is the facility's written answer to survey findings. CAPA is internal. A CAPA record can supply the proof a plan of correction describes. ### When can a corrective action be closed? When it is done and a check against a measure set in advance shows it worked. Finishing a task shows work was done, not that the problem stopped. ## Sources - [42 CFR 483.75: Nursing home QAPI](https://www.ecfr.gov/current/title-42/section-483.75) - [42 CFR 416.43: ASC QAPI condition for coverage](https://www.ecfr.gov/current/title-42/section-416.43) - [Joint Commission: Sentinel Event Policy (SE chapter), Comprehensive Accreditation Manual, Update 1, July 2026](https://www.jointcommission.org/-/media/tjc/documents/resources/patient-safety-topics/sentinel-event/camncc_20_se_all_current.pdf) - [OSHA 29 CFR 1910.119: Process safety management of highly hazardous chemicals](https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.119) - [FDA: Quality Management System Regulation (QMSR)](https://www.fda.gov/medical-devices/postmarket-requirements-devices/quality-management-system-regulation-qmsr) - [21 CFR 820.10: Requirements for a quality management system](https://www.ecfr.gov/current/title-21/section-820.10) - [VHA National Center for Patient Safety: Root cause analysis (page and Guide to Performing a Root Cause Analysis, rev. 02/05/2021)](https://www.patientsafety.va.gov/professionals/onthejob/rca.asp) ## Related terms - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) - [Effectiveness review](https://incidentkit.ai/glossary/effectiveness-review) - [Plan of correction](https://incidentkit.ai/glossary/plan-of-correction) - [Hierarchy of controls](https://incidentkit.ai/glossary/hierarchy-of-controls) - [Performance improvement project](https://incidentkit.ai/glossary/performance-improvement-project) ## Related - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Corrective Action Plan Template (CAPA, Printable)](https://incidentkit.ai/templates/corrective-action-plan) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) --- # Effectiveness review > An effectiveness review checks that a fix worked and the problem did not return. A measure and a date set in advance let the action close. Source: https://incidentkit.ai/glossary/effectiveness-review · Updated Oct 5, 2026 Also known as: effectiveness check, effectiveness verification ## What it checks CMS expects providers to measure success after they act and to track results so gains last (42 CFR 483.75(d)(1), 482.21(c)(3)). Nursing home governing bodies must make sure fixes are judged for effect (483.75(f)(5)). So must surgery center governing bodies (416.43(e)(2)). The Joint Commission asks for system-wide improvement with measurable results. The VA gives each action a measure. A process measure shows the action was done. An outcome measure shows whether it worked. ## How to do it 1. Set the measure with the action, like falls with injury per 1,000 resident days. 2. Set a review date far enough out to see a trend. 3. Collect data and compare it to the baseline, the starting numbers. 4. Decide: effective, partly effective or not effective. Reopen the action if it failed. 5. File the proof so a surveyor can see it. CMS also expects an acceptable [plan of correction](https://incidentkit.ai/glossary/plan-of-correction) to say how the facility will monitor results so fixes last. Mix-up: finishing the task is not the review. Installing alarms shows it was done. Fewer falls shows it worked. ## Frequently asked questions ### How long after implementation should the review happen? CMS sets no number of days. Pick a window long enough to show a trend, and record the baseline. ### What counts as evidence of effectiveness? Data tied to your measure: event rates before and after, audit results, or watching the new process in use. Keep both process and outcome measures. ### What if the action did not work? Reopen it. Go back to the causes, choose a stronger action and set a new review date. Recording the failed try shows the system learns. ## Sources - [42 CFR 483.75: Nursing home QAPI](https://www.ecfr.gov/current/title-42/section-483.75) - [42 CFR 482.21: Hospital QAPI condition of participation](https://www.ecfr.gov/current/title-42/section-482.21) - [42 CFR 416.43: ASC QAPI condition for coverage](https://www.ecfr.gov/current/title-42/section-416.43) - [Joint Commission: Sentinel Event Policy (SE chapter), Comprehensive Accreditation Manual, Update 1, July 2026](https://www.jointcommission.org/-/media/tjc/documents/resources/patient-safety-topics/sentinel-event/camncc_20_se_all_current.pdf) - [VHA National Center for Patient Safety: Root cause analysis (page and Guide to Performing a Root Cause Analysis, rev. 02/05/2021)](https://www.patientsafety.va.gov/professionals/onthejob/rca.asp) - [CMS State Operations Manual, Chapter 7: Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c07pdf.pdf) ## Related terms - [Corrective and preventive action](https://incidentkit.ai/glossary/corrective-and-preventive-action) - [Plan of correction](https://incidentkit.ai/glossary/plan-of-correction) - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) - [Performance improvement project](https://incidentkit.ai/glossary/performance-improvement-project) - [QAPI](https://incidentkit.ai/glossary/qapi) ## Related - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Corrective Action Plan Template (CAPA, Printable)](https://incidentkit.ai/templates/corrective-action-plan) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) --- # Just culture > Just culture is a safety approach that treats honest error, risky shortcuts and reckless acts differently. Staff can report mistakes without fear. Source: https://incidentkit.ai/glossary/just-culture · Updated Oct 5, 2026 Also known as: fair and just culture ## What it separates AHRQ PSNet says just culture looks at the system issues that lead people to unsafe acts, and still holds people accountable. It has zero tolerance for reckless behavior. It rejects a pure no-blame stance. | Behavior | Example | Typical response | | --- | --- | --- | | Human error | A slip | Ask why the system allowed it. Support the person | | At-risk behavior | Taking a shortcut | Find out why it seemed fine. Fix the conditions | | Reckless behavior | Ignoring a required safety step | Accountability, up to discipline | PSNet's example: refusing to do a surgical time-out is reckless and merits punishment even if no patient was harmed. ## Why it matters Incident and [near miss](https://incidentkit.ai/glossary/near-miss) reporting works only when staff trust it. PSNet lists a blame-free place, where people report errors without fear of reprimand, as a sign of a safety culture. The VA says its RCA process looks at the how and why, not the who. Mix-up: just culture is not no blame. It sets responsibility by the type of behavior, whatever the result. Two staff who made the same choice are treated alike, even if only one patient was hurt. ## Frequently asked questions ### Is just culture the same as a blame-free culture? No. PSNet says no blame suits many errors, but some acts deserve blame. Just culture looks for system causes and still holds people accountable for reckless acts. ### Does the severity of harm change the response? Not under just culture. The response follows the type of behavior, not how bad the result was. A reckless act with no harm can call for action. ### How does just culture affect incident reporting? It makes reporting safe. If staff expect punishment for honest mistakes, they stop reporting. Then QAPI and root cause analysis lose the data they need. ## Sources - [AHRQ PSNet: Safety culture (primer, includes just culture)](https://psnet.ahrq.gov/primer/culture-safety) - [VHA National Center for Patient Safety: Root cause analysis (page and Guide to Performing a Root Cause Analysis, rev. 02/05/2021)](https://www.patientsafety.va.gov/professionals/onthejob/rca.asp) ## Related terms - [Near miss](https://incidentkit.ai/glossary/near-miss) - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) - [Incident report](https://incidentkit.ai/glossary/incident-report) - [Adverse event](https://incidentkit.ai/glossary/adverse-event) ## Related - [Near-miss reporting and safety culture: a practical guide](https://incidentkit.ai/guides/near-miss-reporting-and-safety-culture) - [How to get staff to report near misses (and keep doing it)](https://incidentkit.ai/blog/how-to-get-staff-to-report-near-misses) - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Incident reporting software for risk and quality leaders](https://incidentkit.ai/solutions/risk-and-quality-leaders) - [Incident reporting software for directors of nursing](https://incidentkit.ai/solutions/directors-of-nursing) --- # Harm scale > A harm scale ranks how much harm an event caused, from none up to death. No scale is universal. Common ones are the NCC MERP index and the CMS grid. Source: https://incidentkit.ai/glossary/harm-scale · Updated Oct 5, 2026 Also known as: harm classification, severity scale, harm index ## Common harm scales A harm scale lets staff rate every event the same way. Pick one scale per event type and define each level in your policy. | Scale | Levels | Used for | | --- | --- | --- | | NCC MERP index | A to I (2001 wording): could cause error; error did not reach the patient; reached with no harm; needed monitoring; short-term harm; hospital stay; permanent harm; life-saving help; death | Medication errors. HHS OIG adapted it for hospital adverse events. | | CMS scope and severity grid | Four severity levels crossed with isolated, pattern or widespread scope, giving A to L | Nursing home survey findings | | Joint Commission harm terms | Severe harm: a life-threatening injury needing constant monitoring, surgery or treatment. Permanent harm: harm that permanently changes the patient's usual health. | The sentinel event definition | ## Using a scale The harm level usually sets how far an event escalates. Death, severe harm or permanent harm brings a full analysis under Joint Commission policy. CMS uses immediate jeopardy (a serious, urgent danger) only when serious harm or death has happened or is likely. Mix-up: a harm level describes the result, not fault. The same error can land at other levels in other patients. Rate the result, then study the cause on its own. ## Frequently asked questions ### Which harm scale should we use? Use the one your regulator or accreditor uses for that event type, mapped to your own levels. IHI uses a modified NCC MERP index (HHS OIG). ### What is the NCC MERP index? A nine-category index, A to I, that sorts medication errors by result, from no harm to death. NCC MERP revised it in November 2022. ### Does the harm level decide how deep the investigation goes? Often. Higher levels bring a formal root cause analysis and leader review. The Joint Commission requires a full analysis for death, severe harm or permanent harm. ## Sources - [HHS OIG: Adverse Events in Hospitals: National Incidence Among Medicare Beneficiaries (OEI-06-09-00090, November 2010)](https://oig.hhs.gov/oei/reports/oei-06-09-00090.pdf) - [NCC MERP: Index for categorizing medication errors](https://www.nccmerp.org/types-medication-errors) - [CMS State Operations Manual, Chapter 7: Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c07pdf.pdf) - [Joint Commission: Sentinel Event Policy (SE chapter), Comprehensive Accreditation Manual, Update 1, July 2026](https://www.jointcommission.org/-/media/tjc/documents/resources/patient-safety-topics/sentinel-event/camncc_20_se_all_current.pdf) - [CMS State Operations Manual, Appendix Q: Core Guidelines for Determining Immediate Jeopardy](https://www.cms.gov/Regulations-and-guidance/Guidance/Manuals/downloads/som107ap_q_immedjeopardy.pdf) ## Related terms - [Adverse event](https://incidentkit.ai/glossary/adverse-event) - [Sentinel event](https://incidentkit.ai/glossary/sentinel-event) - [Medication error](https://incidentkit.ai/glossary/medication-error) - [Immediate jeopardy](https://incidentkit.ai/glossary/immediate-jeopardy) - [Near miss](https://incidentkit.ai/glossary/near-miss) ## Related - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) - [Medication Error Reporting: Steps, Severity and Follow-Up](https://incidentkit.ai/use-cases/medication-error-reporting) - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) - [Incident routing and escalation by severity](https://incidentkit.ai/product/routing-and-escalation) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) --- # Patient safety organization > A patient safety organization (PSO) is a group HHS lists to collect and study safety data. Data sent to it can be legally protected. Source: https://incidentkit.ai/glossary/patient-safety-organization · Updated Oct 5, 2026 Also known as: PSO ## What a PSO is 42 CFR 3.20 defines a PSO as a private or public group, or part of one, that the HHS Secretary lists as a PSO. A health insurance issuer cannot be a PSO. Patient safety work product means data, reports, notes and analyses, such as root cause analyses, that could improve patient safety. They must be made to send to a PSO and then sent, or made by a PSO for safety work. ## What is protected Under 42 CFR 3.204, patient safety work product is privileged, which means legally protected. It is not open to subpoena, discovery, Freedom of Information Act requests, or use as evidence in the listed cases. The exceptions are: - Some criminal cases - Equitable relief - Provider consent - Data that cannot identify anyone Limits: it leaves out the patient's medical record, billing and discharge data and other original records. Copying data to a PSO does not protect it. Duties to report to authorities still apply. Mix-up: sending an event report to a PSO does not replace required reports to the state or CMS. ## Frequently asked questions ### Does reporting to a PSO satisfy state reporting requirements? No. Required reports still go where the law sends them, because data that is not patient safety work product can still go to government agencies. ### Is a root cause analysis privileged if we send it to a PSO? It can be, if it was made for the PSO and sent, or sits in your patient safety evaluation system. The rule lists RCAs as an example. ### Is a PSO a business associate? Generally, yes, if it handles protected health information for a provider. HIPAA's business associate definition includes patient safety work (42 CFR 3.20). ## Sources - [42 CFR 3.20: Patient safety organization definitions](https://www.ecfr.gov/current/title-42/section-3.20) - [42 CFR 3.204: Privilege of patient safety work product](https://www.ecfr.gov/current/title-42/section-3.204) - [45 CFR 160.103: HIPAA definitions (protected health information, business associate)](https://www.ecfr.gov/current/title-45/section-160.103) - [AHRQ PSNet: Patient safety event reporting (primer)](https://psnet.ahrq.gov/primer/reporting-patient-safety-events) ## Related terms - [Incident report](https://incidentkit.ai/glossary/incident-report) - [Variance report](https://incidentkit.ai/glossary/variance-report) - [Business associate agreement](https://incidentkit.ai/glossary/business-associate-agreement) - [Protected health information (PHI)](https://incidentkit.ai/glossary/phi) - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) ## Related - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) - [HIPAA and BAA for incident reporting](https://incidentkit.ai/hipaa) - [IncidentKit security overview](https://incidentkit.ai/security) - [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview) - [Incident audit trail: every change, who and when](https://incidentkit.ai/product/audit-trail) --- # F-tag > An F-tag is a code CMS uses to cite nursing home survey findings, like F689 for accidents. Each tag links to a rule in 42 CFR Part 483. Source: https://incidentkit.ai/glossary/f-tag · Updated Oct 5, 2026 Also known as: F tag, data tag, federal tag ## What an F-tag is Each rule cited on a survey report has a letter and a number. For long-term care the letter is F. Appendix PP gives each tag its rule text, intent, definitions and survey guidance. Life Safety Code findings use K-tags. | Tag | Topic | | --- | --- | | F600 | Freedom from abuse, neglect and exploitation | | F609 and F610 | Reporting alleged violations and responding to them | | F686 | Pressure ulcers (pressure injuries) | | F689 | Accidents: a hazard-free setting, enough supervision and devices | | F759 and F760 | Medication error rates of 5 percent or more; significant medication errors | | F865, F867, F868 | QAPI program, QAPI improvement work, QAA committee | | F880 | Infection prevention and control | ## How tags are used Surveyors cite tags on [Form CMS-2567](https://incidentkit.ai/glossary/cms-2567) and score each for scope and severity. The facility answers each tag in its [plan of correction](https://incidentkit.ai/glossary/plan-of-correction). One event can touch several tags. A fall with injury may involve F689. A pressure injury may involve F686. Mix-up: tag numbers belong to the long-term care survey. Other provider types are cited under their own rules. A surgery center is cited under 42 CFR Part 416. ## Frequently asked questions ### What does the F in F-tag stand for? CMS's letter for long-term care rules in the survey tag series. The letter and number name the exact rule, like F689 for 42 CFR 483.25(d), accidents. ### Do hospitals and surgery centers have F-tags? No. F-tags belong to the nursing home survey. Other provider types are cited under their own rules, such as 42 CFR Part 416 for surgery centers. ### Where can I read the guidance behind an F-tag? In State Operations Manual Appendix PP: the rule, intent, definitions and survey steps for each tag. CMS revises it, so check dates. ## Sources - [CMS State Operations Manual, Appendix PP: Guidance to Surveyors for Long Term Care Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [CMS State Operations Manual, Chapter 2: The Certification Process](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c02.pdf) - [CMS State Operations Manual, Chapter 7: Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c07pdf.pdf) - [42 CFR 483.75: Nursing home QAPI](https://www.ecfr.gov/current/title-42/section-483.75) ## Related terms - [Deficiency](https://incidentkit.ai/glossary/deficiency) - [CMS-2567](https://incidentkit.ai/glossary/cms-2567) - [Plan of correction](https://incidentkit.ai/glossary/plan-of-correction) - [Immediate jeopardy](https://incidentkit.ai/glossary/immediate-jeopardy) - [QAA committee](https://incidentkit.ai/glossary/qaa-committee) ## Related - [F689 accidents and supervision: falls, hazards, devices](https://incidentkit.ai/compliance/f-tags/f689) - [F600 free from abuse and neglect: what surveyors cite](https://incidentkit.ai/compliance/f-tags/f600) - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) - [F610 investigate, prevent and correct alleged violations](https://incidentkit.ai/compliance/f-tags/f610) - [F684 quality of care: what it covers and how it is cited](https://incidentkit.ai/compliance/f-tags/f684) - [F760 significant medication errors: how surveyors cite it](https://incidentkit.ai/compliance/f-tags/f760) - [F880 infection prevention and control: survey guide](https://incidentkit.ai/compliance/f-tags/f880) - [Nursing home recertification survey: process and prep](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) --- # Deficiency > A deficiency is a failure to meet a Medicare or Medicaid rule. A surveyor, or inspector, lists it on Form CMS-2567 and nursing homes get a score. Source: https://incidentkit.ai/glossary/deficiency · Updated Oct 5, 2026 Also known as: survey deficiency, citation, survey finding ## What counts Under 42 CFR 488.301, a nursing home deficiency is a failure to meet a rule in the Act or in 42 CFR Part 483, Subpart B. Noncompliance is a failure big enough that the home is not in substantial compliance. Substantial compliance means any gaps pose no more than a potential for minimal harm. Other providers have standard-level and condition-level gaps. A condition is a broad rule. Standards are the details under it. A gap reaches condition level based on how well the provider meets the standards (42 CFR 488.26). ## How it is scored | Severity | Isolated | Pattern | Widespread | | --- | --- | --- | --- | | Immediate jeopardy (level 4) | J | K | L | | Actual harm, not immediate jeopardy (level 3) | G | H | I | | No actual harm, potential for more than minimal harm (level 2) | D | E | F | | No actual harm, potential for minimal harm (level 1) | A | B | C | Level A is not listed on Form CMS-2567 and needs no [plan of correction](https://incidentkit.ai/glossary/plan-of-correction). All other levels need one. Example: a resident falls and breaks a bone because a care-plan step was missed. In one resident, that scores G. Mix-up: a deficiency is not automatically a fine. The remedy depends on the score and history. ## Frequently asked questions ### What is the difference between a deficiency and noncompliance? Noncompliance (42 CFR 488.301) is a deficiency that keeps a nursing home from substantial compliance. A level A deficiency can leave a home in substantial compliance. ### What is a standard-level versus a condition-level deficiency? Conditions are broad rules. Standards are the details beneath. With only standard-level gaps, a provider may keep taking part if it files an acceptable plan of correction. ### Does every deficiency require a plan of correction? Almost. Nursing homes with findings above scope and severity level A must file one. Other providers with standard-level findings must file one to keep taking part. ## Sources - [42 CFR 488.301: Definitions (nursing home survey and enforcement)](https://www.ecfr.gov/current/title-42/section-488.301) - [42 CFR 488.26: Determining compliance](https://www.ecfr.gov/current/title-42/section-488.26) - [42 CFR 488.28: Providers or suppliers, other than SNFs, NFs, HHAs and hospices, with deficiencies](https://www.ecfr.gov/current/title-42/section-488.28) - [CMS State Operations Manual, Chapter 7: Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c07pdf.pdf) - [CMS State Operations Manual, Chapter 2: The Certification Process](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c02.pdf) ## Related terms - [Immediate jeopardy](https://incidentkit.ai/glossary/immediate-jeopardy) - [CMS-2567](https://incidentkit.ai/glossary/cms-2567) - [Plan of correction](https://incidentkit.ai/glossary/plan-of-correction) - [F-tag](https://incidentkit.ai/glossary/f-tag) - [Conditions for coverage](https://incidentkit.ai/glossary/conditions-for-coverage) ## Related - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) - [Nursing home recertification survey: process and prep](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) - [What to put in a plan of correction (CMS-2567)](https://incidentkit.ai/blog/what-to-put-in-a-plan-of-correction) - [QAPI, survey and OSHA compliance packets](https://incidentkit.ai/product/compliance-packets) --- # Immediate jeopardy > Immediate jeopardy (IJ) means a provider's failure has caused, or will likely cause, serious harm or death. It is the most serious kind of deficiency. Source: https://incidentkit.ai/glossary/immediate-jeopardy · Updated Oct 5, 2026 Also known as: IJ, immediate jeopardy to resident health or safety ## The three parts CMS Appendix Q says the wording varies a little by provider type but has three parts. All three must be present. 1. Noncompliance with one or more federal health, safety or quality rules. 2. A serious bad outcome, or a likely one, for one or more people at risk. 3. A need for immediate action to stop serious harm from happening or happening again. Serious outcomes include death, a major drop in function not due only to disease or age, loss of a limb or disfigurement, and avoidable pain that is excruciating and lasts more than a short time. ## After IJ is called The survey team confirms the finding with the State Agency, tells the administrator right away, and asks for a written removal plan. Removal is checked on site. In nursing homes, IJ is scored J, K or L. CMS applies penalties without first letting the facility fix it. Mix-up: a removal plan is not a [plan of correction](https://incidentkit.ai/glossary/plan-of-correction). The removal plan stops serious harm now and need not fix everything. The plan of correction comes next and shows how the facility gets back to substantial compliance. Example: a resident known to be at risk of leaving is not supervised as the care plan says, and walks out in cold weather. CMS lists heat or cold exposure as a risk of [elopement](https://incidentkit.ai/glossary/elopement). ## Frequently asked questions ### What is an IJ removal plan? Steps taken right away so no one suffers serious harm. It names affected residents and the system change, with the date harm is no longer likely. ### How is immediate jeopardy different from actual harm? Actual harm (level 3, G to I) means a resident was harmed, but not to the IJ standard. IJ (level 4, J to L) means serious injury, harm, impairment or death has happened or is likely. ### Does immediate jeopardy apply to hospitals and surgery centers? Yes. Appendix Q is core guidance for certified providers, suppliers and labs. Other providers use the 42 CFR 489.3 definition. CMS may require a shorter time to fix an IJ. ## Sources - [CMS State Operations Manual, Appendix Q: Core Guidelines for Determining Immediate Jeopardy](https://www.cms.gov/Regulations-and-guidance/Guidance/Manuals/downloads/som107ap_q_immedjeopardy.pdf) - [42 CFR 488.301: Definitions (nursing home survey and enforcement)](https://www.ecfr.gov/current/title-42/section-488.301) - [CMS State Operations Manual, Chapter 7: Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c07pdf.pdf) - [42 CFR 488.28: Providers or suppliers, other than SNFs, NFs, HHAs and hospices, with deficiencies](https://www.ecfr.gov/current/title-42/section-488.28) - [CMS State Operations Manual, Appendix PP: Guidance to Surveyors for Long Term Care Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) ## Related terms - [Deficiency](https://incidentkit.ai/glossary/deficiency) - [Plan of correction](https://incidentkit.ai/glossary/plan-of-correction) - [CMS-2567](https://incidentkit.ai/glossary/cms-2567) - [Elopement](https://incidentkit.ai/glossary/elopement) - [Harm scale](https://incidentkit.ai/glossary/harm-scale) ## Related - [Nursing home recertification survey: process and prep](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) - [F689 accidents and supervision: falls, hazards, devices](https://incidentkit.ai/compliance/f-tags/f689) - [F600 free from abuse and neglect: what surveyors cite](https://incidentkit.ai/compliance/f-tags/f600) - [What to put in a plan of correction (CMS-2567)](https://incidentkit.ai/blog/what-to-put-in-a-plan-of-correction) --- # CMS-2567 > Form CMS-2567 lists each Medicare or Medicaid rule a provider missed. The provider replies on it with a plan to fix them. The public can see it. Source: https://incidentkit.ai/glossary/cms-2567 · Updated Oct 5, 2026 Also known as: Form CMS-2567, Statement of Deficiencies and Plan of Correction, 2567 ## What the form does The State Operations Manual gives the form four jobs: - It is the public record of the deficiencies and the fixes. - It documents each deficiency. - It records the provider's promised fixes and dates. - It lets the provider dispute findings with proof. Each citation shows the tag number, the rule not met, a plain statement that it is not met, and the evidence. For immediate jeopardy (serious, urgent danger), it also records when IJ began, when the entity was told and how it ended. ## Timing For providers other than nursing homes, the State agency mails the form within 10 working days after the survey. The provider has 10 calendar days to return its plan of correction. Nursing homes also have 10 calendar days from receipt (SOM Chapter 7, section 7317). Without an acceptable [plan of correction](https://incidentkit.ai/glossary/plan-of-correction), the State says it will recommend remedies. 42 CFR 488.456(b) requires ending the provider agreement of a facility that does not file an acceptable plan. Example: a nursing home's 2567 cites [F689](https://incidentkit.ai/glossary/f-tag) with proof from record review, interviews and observation. The facility answers line by line. Mix-up: the 2567 is the survey agency's statement. The plan of correction is the facility's written reply on it. ## Frequently asked questions ### Is the CMS-2567 public? Yes. The State Operations Manual calls it the basic document shared with the public about a provider's deficiencies and fixes. ### How long do we have to respond to a CMS-2567? Ten calendar days from receipt, for nursing homes and other providers. Nursing homes have the same time to ask for informal dispute resolution. ### Who signs the plan of correction? For nursing homes, someone with management authority, who should be the administrator. The director of nursing or a corporate representative may also sign. ## Sources - [CMS State Operations Manual, Chapter 2: The Certification Process](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c02.pdf) - [CMS State Operations Manual, Chapter 7: Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c07pdf.pdf) - [CMS State Operations Manual, Appendix Q: Core Guidelines for Determining Immediate Jeopardy](https://www.cms.gov/Regulations-and-guidance/Guidance/Manuals/downloads/som107ap_q_immedjeopardy.pdf) ## Related terms - [Plan of correction](https://incidentkit.ai/glossary/plan-of-correction) - [Deficiency](https://incidentkit.ai/glossary/deficiency) - [F-tag](https://incidentkit.ai/glossary/f-tag) - [Immediate jeopardy](https://incidentkit.ai/glossary/immediate-jeopardy) - [Deemed status](https://incidentkit.ai/glossary/deemed-status) ## Related - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) - [What to put in a plan of correction (CMS-2567)](https://incidentkit.ai/blog/what-to-put-in-a-plan-of-correction) - [Nursing home recertification survey: process and prep](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) - [QAPI, survey and OSHA compliance packets](https://incidentkit.ai/product/compliance-packets) --- # Plan of correction > A plan of correction (PoC) is a provider's written answer to survey findings. It says how and by when the facility will fix each problem and keep it fixed. Source: https://incidentkit.ai/glossary/plan-of-correction · Updated Oct 5, 2026 Also known as: PoC, POC, allegation of compliance ## What it must contain 42 CFR 488.401 defines it as a plan the facility writes and CMS or the survey agency approves. It describes the actions the facility will take and the date it will finish. CMS's manual says an acceptable plan must: - Say how the fix will reach the people affected. - Say how the facility will find others who could be affected. - Name the changes that will stop it from happening again. - Say how the facility will monitor results so the fix lasts. - Give dates when the fixes will be done. The plan serves as the facility's allegation of compliance. That is its own statement that it now meets the rules. ## Timing and who signs Nursing homes must file a plan within 10 calendar days of getting the [CMS-2567](https://incidentkit.ai/glossary/cms-2567). Other providers with standard-level deficiencies may keep taking part only with an acceptable plan. They are usually expected to comply within 60 days of notice, though the survey agency may allow more time (42 CFR 488.28). Example from CMS's QAPI guide: after a weight-loss finding, a nursing home re-weighed all residents, held a staff class and promised three monthly audits. The State accepted it, yet CMS calls that kind of plan a band-aid next to a root cause approach. Mix-up: a plan of correction is not an [immediate jeopardy](https://incidentkit.ai/glossary/immediate-jeopardy) removal plan, and it is not internal CAPA. It is the formal reply to a survey. ## Frequently asked questions ### How long do we have to submit a plan of correction? Nursing homes must file an acceptable plan within 10 calendar days of getting the CMS-2567. Other providers follow the survey agency's request, usually within 60 days of notice. ### What happens if the plan of correction is not acceptable? The State tells the facility in writing. Without an acceptable plan, remedies can be recommended, and 42 CFR 488.456(b) requires ending a nursing home's provider agreement. ### Is a plan of correction an admission of fault? The manual calls it the facility's allegation of compliance: what it will do and by when. Ask counsel how to word it. It must be specific enough to check. ## Sources - [42 CFR 488.401: Definitions (plan of correction)](https://www.ecfr.gov/current/title-42/section-488.401) - [CMS State Operations Manual, Chapter 7: Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c07pdf.pdf) - [42 CFR 488.28: Providers or suppliers, other than SNFs, NFs, HHAs and hospices, with deficiencies](https://www.ecfr.gov/current/title-42/section-488.28) - [CMS State Operations Manual, Chapter 2: The Certification Process](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c02.pdf) ## Related terms - [CMS-2567](https://incidentkit.ai/glossary/cms-2567) - [Deficiency](https://incidentkit.ai/glossary/deficiency) - [Immediate jeopardy](https://incidentkit.ai/glossary/immediate-jeopardy) - [Corrective and preventive action](https://incidentkit.ai/glossary/corrective-and-preventive-action) - [Effectiveness review](https://incidentkit.ai/glossary/effectiveness-review) ## Related - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction) - [What to put in a plan of correction (CMS-2567)](https://incidentkit.ai/blog/what-to-put-in-a-plan-of-correction) - [Nursing home recertification survey: process and prep](https://incidentkit.ai/compliance/survey-readiness/snf-recertification-survey) - [Always Survey-Ready: Stay Prepared for Unannounced Surveys](https://incidentkit.ai/use-cases/always-survey-ready) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [QAPI, survey and OSHA compliance packets](https://incidentkit.ai/product/compliance-packets) --- # Deemed status > Deemed status means CMS lets a provider pass an outside group's survey in place of a state survey. The group must be one CMS has approved. Source: https://incidentkit.ai/glossary/deemed-status · Updated Oct 5, 2026 Also known as: deeming, Medicare deemed status, accreditation in lieu of survey ## What it means CMS can approve outside groups that accredit (formally approve) providers. A provider that passes such a group's survey is treated as meeting Medicare rules (Social Security Act, section 1865). The group, not the State survey agency, then oversees it (State Operations Manual Chapter 2). 42 CFR 488.5 and 488.6 allow deemed status for these provider types: - Surgery centers - Hospitals - Critical access hospitals - Psychiatric hospitals - Home health agencies - Hospices - Nursing homes - Rural health clinics - Most transplant centers A few more types qualify too. Accreditation is voluntary, and only some groups have approved programs for some types. ## What CMS still checks State agencies run validation surveys of deemed providers, on a sample or after a serious complaint. If a survey finds a broad rule (a condition) not met, CMS may pull deemed status for a time. The provider then answers to the State agency until it shows substantial compliance. Accrediting groups must tell CMS within two business days of an immediate jeopardy, a serious and urgent danger (42 CFR 488.5). Example: a surgery center in AAAHC's Medicare Deemed Status program is surveyed by AAAHC, without warning, not by the State agency. It must still meet the [conditions for coverage](https://incidentkit.ai/glossary/conditions-for-coverage) in 42 CFR Part 416. Mix-up: accredited and deemed are not the same. Deemed status is CMS accepting an approved program's accreditation as proof of Medicare compliance. ## Frequently asked questions ### Does deemed status mean the state will never survey us? No. The State agency can run validation surveys and complaint checks. If accreditation ends for failed standards, a State survey is due within 45 calendar days of CMS's notice. ### Is accreditation required to participate in Medicare? No. The State Operations Manual says it is voluntary. A provider can use State agency surveys instead. Some states and payers have their own rules. ### Which accrediting organizations offer deemed status? Only groups with CMS-approved programs for a provider type. The list changes, so check CMS. Examples: the Joint Commission and AAAHC for surgery centers. ## Sources - [CMS State Operations Manual, Chapter 2: The Certification Process](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c02.pdf) - [42 CFR 488.1: Definitions (survey, certification and enforcement)](https://www.ecfr.gov/current/title-42/section-488.1) - [42 CFR 488.5: Application and re-application procedures for accrediting organizations](https://www.ecfr.gov/current/title-42/section-488.5) - [AAAHC: Medicare Deemed Status accreditation](https://www.aaahc.org/accelerated-readiness/program-overview/medicare-deemed/) - [CMS: Conditions for Coverage (CfCs) and Conditions of Participation (CoPs)](https://www.cms.gov/medicare/health-safety-standards/conditions-coverage-participation) ## Related terms - [AAAHC](https://incidentkit.ai/glossary/aaahc) - [Joint Commission](https://incidentkit.ai/glossary/joint-commission) - [Conditions for coverage](https://incidentkit.ai/glossary/conditions-for-coverage) - [Deficiency](https://incidentkit.ai/glossary/deficiency) - [CMS-2567](https://incidentkit.ai/glossary/cms-2567) ## Related - [AAAHC accreditation: surveys, deemed status and QI studies](https://incidentkit.ai/compliance/accreditation/aaahc) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [DNV hospital and ASC accreditation: CMS status and surveys](https://incidentkit.ai/compliance/accreditation/dnv) - [ACHC accreditation: deemed status, surveys and standards](https://incidentkit.ai/compliance/accreditation/achc) - [AAAHC vs Joint Commission for ASCs: how they compare](https://incidentkit.ai/blog/aaahc-vs-joint-commission-for-ascs) - [Survey and accreditation readiness: a continuous approach](https://incidentkit.ai/guides/survey-and-accreditation-readiness) --- # Conditions for coverage > Conditions for coverage (CfCs) are health and safety rules for some Medicare suppliers, like surgery centers. Hospitals have CoPs, the same idea. Source: https://incidentkit.ai/glossary/conditions-for-coverage · Updated Oct 5, 2026 Also known as: CfC, CfCs, conditions for coverage and participation ## What they are CMS says its conditions of participation (CoPs) and conditions for coverage (CfCs) are standards health care groups must meet to take part in Medicare and Medicaid. CMS calls them the base for better quality and safer care. Surgery centers have CfCs in 42 CFR Part 416. Hospitals have CoPs in Part 482. The idea is the same, and CMS lists both on one page, with hospices, home health agencies and others. Each condition holds standards beneath it. The surgery center condition on quality assessment and performance improvement (42 CFR 416.43) has standards for scope, data, activities, improvement projects and governing body duties. ## Condition and standard How well a provider meets the standards decides if a gap is at condition level (42 CFR 488.26). A provider with weak standards may keep taking part if it files an acceptable [plan of correction](https://incidentkit.ai/glossary/plan-of-correction) (42 CFR 488.28). It usually has 60 days to comply. Example: a surgery center tracks adverse events but records no improvement projects. That is a standard-level gap under 416.43(d). It reaches condition level only if the QAPI program falls far short. Mix-up: the names differ by provider type, but the survey logic is shared. ## Frequently asked questions ### What is the difference between conditions of participation and conditions for coverage? Mostly the name. Hospitals have CoPs (42 CFR Part 482). Surgery centers have CfCs (Part 416). Both are standards for taking part in Medicare and Medicaid. ### What does condition-level noncompliance mean? The provider falls so short on the standards that the condition itself is not met. This is more serious than one standard-level gap. A deemed provider can lose deemed status. ### Can a surgery center be certified with deficiencies? Yes, with standard-level deficiencies, if the center files an acceptable plan of correction. They must not endanger patient health and safety or seriously limit care. ## Sources - [CMS: Conditions for Coverage (CfCs) and Conditions of Participation (CoPs)](https://www.cms.gov/medicare/health-safety-standards/conditions-coverage-participation) - [42 CFR 416.43: ASC QAPI condition for coverage](https://www.ecfr.gov/current/title-42/section-416.43) - [42 CFR 488.26: Determining compliance](https://www.ecfr.gov/current/title-42/section-488.26) - [42 CFR 488.28: Providers or suppliers, other than SNFs, NFs, HHAs and hospices, with deficiencies](https://www.ecfr.gov/current/title-42/section-488.28) - [CMS State Operations Manual, Chapter 2: The Certification Process](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c02.pdf) ## Related terms - [Deemed status](https://incidentkit.ai/glossary/deemed-status) - [Deficiency](https://incidentkit.ai/glossary/deficiency) - [QAPI](https://incidentkit.ai/glossary/qapi) - [Plan of correction](https://incidentkit.ai/glossary/plan-of-correction) - [AAAHC](https://incidentkit.ai/glossary/aaahc) ## Related - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) - [AAAHC accreditation: surveys, deemed status and QI studies](https://incidentkit.ai/compliance/accreditation/aaahc) - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [Survey and accreditation readiness: a continuous approach](https://incidentkit.ai/guides/survey-and-accreditation-readiness) --- # OSHA recordable injury > A recordable injury is a new, work-related injury or illness that OSHA says you must log. Care beyond first aid, or lost work time, usually makes it one. Source: https://incidentkit.ai/glossary/osha-recordable · Updated Oct 5, 2026 Also known as: recordable case, recordable incident, OSHA recordable ## The three tests Under 29 CFR 1904.4, you must record an injury or illness if it is work-related, is a new case and meets the general criteria in 1904.7 (or the special cases in 1904.8 through 1904.12). The criteria are: - Death - Days away from work - Restricted work or transfer to another job - [Medical treatment beyond first aid](https://incidentkit.ai/glossary/first-aid) - Loss of consciousness - A significant injury or illness diagnosed by a doctor or other licensed professional Cancer, chronic irreversible disease, a broken or cracked bone and a punctured eardrum must always be recorded at diagnosis. ## Recording and reporting Enter each recordable case on the OSHA 300 Log. Finish a 301 incident report, or an equal form, within seven calendar days of learning of it (29 CFR 1904.29). The 300A yearly summary comes next. Some sites must also send data to OSHA online. Example: a warehouse worker strains a shoulder, and a doctor prescribes pain medicine. That is medical treatment beyond first aid, so the case is recordable. Mix-up: recordable is not reportable. You must also call OSHA about a death (within 8 hours) or an in-patient hospital stay, amputation or loss of an eye (within 24 hours), under 1904.39. Recording a case does not mean fault, a broken rule or [workers' compensation](https://incidentkit.ai/glossary/workers-compensation) eligibility (1904.0). IncidentKit's OSHA 300, 300A and 301 exports are rolling out. ## Frequently asked questions ### Is every workplace injury recordable? No. It must be work-related, a new case and meet a recording criterion. First aid alone is not recordable. Some work-setting cases are excluded under 1904.5(b)(2). ### What is the difference between recordable and reportable? Recordable means it goes on your OSHA 300 Log. Reportable means you must call OSHA within 8 hours of a work-related death, or 24 hours of an in-patient stay, amputation or loss of an eye. ### How soon must a recordable case be entered on the log? Within seven calendar days of learning that it happened, on the OSHA 300 Log and the 301 report or an equal form. ## Sources - [OSHA 29 CFR 1904.4: Recording criteria](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.4) - [OSHA 29 CFR 1904.7: General recording criteria](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.7) - [29 CFR 1904.29: Forms (OSHA 300, 300-A and 301)](https://www.ecfr.gov/current/title-29/section-1904.29) - [OSHA 29 CFR 1904.39: Reporting fatalities, hospitalizations, amputations, and losses of an eye](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.39) - [29 CFR 1904.0: Purpose (recordkeeping rule)](https://www.ecfr.gov/current/title-29/section-1904.0) - [29 CFR 1904.5: Determination of work-relatedness](https://www.ecfr.gov/current/title-29/section-1904.5) - [OSHA: Injury and illness recordkeeping and reporting requirements](https://www.osha.gov/recordkeeping) ## Related terms - [First aid (OSHA recordkeeping)](https://incidentkit.ai/glossary/first-aid) - [DART rate](https://incidentkit.ai/glossary/dart-rate) - [TRIR (total recordable incident rate)](https://incidentkit.ai/glossary/trir) - [Lost-time injury](https://incidentkit.ai/glossary/lost-time-injury) - [Workers' compensation](https://incidentkit.ai/glossary/workers-compensation) - [FROI (First Report of Injury)](https://incidentkit.ai/glossary/froi) ## Related - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [Recordable vs first aid: OSHA's medical treatment test](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [First aid vs medical treatment: the OSHA recordability line](https://incidentkit.ai/blog/first-aid-vs-medical-treatment-osha) - [OSHA recordkeeping guide: Part 1904 for employers](https://incidentkit.ai/guides/osha-recordkeeping-guide) --- # First aid (OSHA recordkeeping) > For OSHA recordkeeping, first aid is only the care on its closed list, like bandages or cleaning a wound. First aid alone is not recordable. Source: https://incidentkit.ai/glossary/first-aid · Updated Oct 5, 2026 Also known as: first aid treatment, first aid only ## First aid or treatment OSHA says its list is complete (29 CFR 1904.7(b)(5)(ii)). No other care counts as first aid. Anything beyond the list is medical treatment, and a case with medical treatment is recordable. | First aid (not recordable on its own) | Medical treatment (recordable) | | --- | --- | | Non-prescription medication at non-prescription strength | Prescription medication, or non-prescription medication at prescription strength | | Tetanus shot | Other shots, such as hepatitis B or rabies | | Cleaning, flushing or soaking wounds; bandages, gauze, butterfly bandages or Steri-Strips | Stitches, staples or other wound-closing devices | | Non-rigid supports such as elastic bandages and wraps | Devices with rigid stays or other ways to hold parts of the body still | | Massage | Physical therapy or chiropractic care | The list also has hot or cold therapy, temporary support for transport, eye patches, removing splinters or eye foreign bodies by simple means, finger guards, draining a blister and drinking fluids for heat stress. ## Rules that surprise people Who gives the care does not matter. A doctor who applies a bandage is still giving first aid. Care beyond the list is medical treatment even from a non-professional. Visits for observation or counseling, and tests like x-rays and blood tests, are not medical treatment. Example: a cashier cuts a finger. The clinic cleans it and applies a bandage. That is first aid. If the clinic closes the cut with stitches, it is medical treatment and recordable. Mix-up: a case can still be [recordable](https://incidentkit.ai/glossary/osha-recordable) after first aid if it involves days away, restriction or loss of consciousness. ## Frequently asked questions ### Are stitches first aid? No. Stitches, staples and other wound-closing devices are medical treatment. Butterfly bandages and Steri-Strips are first aid. ### Is taking ibuprofen first aid? Yes, if it is non-prescription at non-prescription strength. At prescription strength, recommended by a licensed professional, it is medical treatment. ### Is an x-ray medical treatment? No. OSHA excludes tests like x-rays. But a broken bone found on the x-ray is a significant diagnosis, so the case is recordable. ## Sources - [OSHA 29 CFR 1904.7: General recording criteria](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.7) ## Related terms - [OSHA recordable injury](https://incidentkit.ai/glossary/osha-recordable) - [DART rate](https://incidentkit.ai/glossary/dart-rate) - [TRIR (total recordable incident rate)](https://incidentkit.ai/glossary/trir) - [Lost-time injury](https://incidentkit.ai/glossary/lost-time-injury) ## Related - [Recordable vs first aid: OSHA's medical treatment test](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) - [First aid vs medical treatment: the OSHA recordability line](https://incidentkit.ai/blog/first-aid-vs-medical-treatment-osha) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [OSHA recordkeeping guide: Part 1904 for employers](https://incidentkit.ai/guides/osha-recordkeeping-guide) - [Workplace Injury Report Template (OSHA 301 Aligned)](https://incidentkit.ai/templates/workplace-injury-report) --- # DART rate > The DART rate counts OSHA cases with days away, restricted work or job transfer per 100 full-time workers. The formula is cases × 200,000 ÷ hours worked. Source: https://incidentkit.ai/glossary/dart-rate · Updated Oct 5, 2026 Also known as: days away, restricted or transferred rate, DART incident rate ## The formula OSHA's formula for an incidence rate is (number of injuries and illnesses × 200,000) ÷ employee hours worked. For DART, use the cases in the days-away and job-transfer-or-restriction columns of the Form 300 or 300A. The total case rate adds the other-recordable column. BLS explains the 200,000: 40 hours a week for 50 weeks, the hours 100 full-time employees commonly work in a year. Example: 4 DART cases and 500,000 hours worked. 4 × 200,000 = 800,000. Divide by 500,000 to get 1.6 cases per 100 full-time workers. ## How to read it DART counts cases, not days. It leaves out cases that were recordable only for medical treatment beyond first aid. So DART is never higher than the [total recordable rate](https://incidentkit.ai/glossary/trir). Compare with the BLS rate for your industry, not one national number. Mix-up: restricted work is not [lost time](https://incidentkit.ai/glossary/lost-time-injury). DART counts restricted and transferred cases. A lost-time rate usually counts only cases with days away. Count days under 29 CFR 1904.7(b)(3), starting the day after the injury. Use the [TRIR and DART calculator](https://incidentkit.ai/tools/trir-dart-calculator) to run your own numbers. ## Frequently asked questions ### What does DART stand for? Days Away, Restricted or Transferred. It covers recordable cases with missed work, restricted duty or a job move. OSHA computes it from two columns of the Form 300 or 300A. ### Why is 200,000 hours used? It equals 40 hours a week for 50 weeks, the hours 100 full-time employees work in a year. It gives cases per 100 workers at any company size. ### What is the difference between DART and TRIR? TRIR counts every recordable case. DART counts only cases with days away, restriction or transfer. Both use the same 200,000-hour formula. ## Sources - [OSHA: Establishment-specific injury and illness data (rate definitions)](https://www.osha.gov/Establishment-Specific-Injury-and-Illness-Data) - [BLS Handbook of Methods: Survey of Occupational Injuries and Illnesses, calculation](https://www.bls.gov/opub/hom/soii/calculation.htm) - [OSHA 29 CFR 1904.7: General recording criteria](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.7) ## Related terms - [TRIR (total recordable incident rate)](https://incidentkit.ai/glossary/trir) - [LTIR (lost-time injury rate)](https://incidentkit.ai/glossary/ltir) - [Lost-time injury](https://incidentkit.ai/glossary/lost-time-injury) - [OSHA recordable injury](https://incidentkit.ai/glossary/osha-recordable) - [First aid (OSHA recordkeeping)](https://incidentkit.ai/glossary/first-aid) ## Related - [TRIR and DART rates: formula, example and BLS 2024 rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates) - [TRIR and DART rate calculator (OSHA formula)](https://incidentkit.ai/tools/trir-dart-calculator) - [OSHA 300A summary: who signs, when to post, how long](https://incidentkit.ai/compliance/osha/osha-300a-summary) - [OSHA electronic submission: 29 CFR 1904.41 and the ITA](https://incidentkit.ai/compliance/osha/electronic-submission) - [OSHA recordkeeping guide: Part 1904 for employers](https://incidentkit.ai/guides/osha-recordkeeping-guide) --- # TRIR (total recordable incident rate) > TRIR (total recordable incident rate) counts recordable injuries and illnesses per 100 full-time workers a year. OSHA calls it the total case rate. Source: https://incidentkit.ai/glossary/trir · Updated Oct 5, 2026 Also known as: TRIR, total case rate, TCR, recordable incident rate ## The formula OSHA's formula is (number of injuries and illnesses × 200,000) ÷ employee hours worked. Its Total Case Rate counts all cases on the Form 300 or 300A: the days-away, job-transfer-or-restriction and other-recordable columns. The log marks deaths separately, so say how your report counts them. Example: 9 recordable cases and 600,000 hours worked. 9 × 200,000 = 1,800,000. Divide by 600,000 to get 3.0 cases per 100 full-time workers. BLS says the 200,000 is 40 hours a week for 50 weeks, for 100 full-time employees. ## Uses and limits TRIR lets you compare your site with the BLS rate for your industry and track change over time. It counts only recordable cases, so [first aid](https://incidentkit.ai/glossary/first-aid) cases and near misses are outside it. Limits: a rate counts a sprain and an amputation as one case each. With few hours worked, one case swings the number. Pair TRIR with the [DART rate](https://incidentkit.ai/glossary/dart-rate) and with measures of severity and near misses, such as [PSIF](https://incidentkit.ai/glossary/psif) events. Mix-up: TRIR is a rate per 100 full-time workers, not a count. Always show the hours behind it. ## Frequently asked questions ### How do you calculate TRIR? Multiply recordable cases by 200,000. Divide by total hours worked by all employees. The result is cases per 100 full-time workers. Example: 9 cases over 600,000 hours is 3.0. ### Does TRIR include first aid cases? No. Only cases that meet OSHA's recording criteria count. A first-aid-only case stays out unless another criterion applies, like days away. ### Is TRIR the same as OSHA's total case rate? In practice, yes. OSHA's Total Case Rate uses the same formula and the same three columns. Calculators may treat deaths differently, so write down your method. ## Sources - [OSHA: Establishment-specific injury and illness data (rate definitions)](https://www.osha.gov/Establishment-Specific-Injury-and-Illness-Data) - [BLS Handbook of Methods: Survey of Occupational Injuries and Illnesses, calculation](https://www.bls.gov/opub/hom/soii/calculation.htm) - [OSHA 29 CFR 1904.7: General recording criteria](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.7) ## Related terms - [DART rate](https://incidentkit.ai/glossary/dart-rate) - [OSHA recordable injury](https://incidentkit.ai/glossary/osha-recordable) - [LTIR (lost-time injury rate)](https://incidentkit.ai/glossary/ltir) - [First aid (OSHA recordkeeping)](https://incidentkit.ai/glossary/first-aid) - [PSIF (potential serious injury or fatality)](https://incidentkit.ai/glossary/psif) ## Related - [TRIR and DART rates: formula, example and BLS 2024 rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates) - [TRIR and DART rate calculator (OSHA formula)](https://incidentkit.ai/tools/trir-dart-calculator) - [OSHA 300A summary: who signs, when to post, how long](https://incidentkit.ai/compliance/osha/osha-300a-summary) - [OSHA recordkeeping guide: Part 1904 for employers](https://incidentkit.ai/guides/osha-recordkeeping-guide) - [Incident reporting software for EHS managers and leads](https://incidentkit.ai/solutions/ehs-managers) --- # LTIR (lost-time injury rate) > LTIR (lost-time injury rate) counts injuries that cost workdays per set block of hours. OSHA does not use the term, so confirm the formula before you compare. Source: https://incidentkit.ai/glossary/ltir · Updated Oct 5, 2026 Also known as: LTIR, lost time injury rate, lost-time case rate ## The formula and its limits OSHA publishes no rate named LTIR. Its rule counts cases with days away from work. OSHA and BLS figure rates as cases × 200,000 ÷ hours worked. So a U.S.-style LTIR is days-away cases × 200,000 ÷ hours. That base is a habit, not a law. Customers, insurers, parent companies and other countries may define lost time and the hours base differently. Label every figure, for example 'LTIR per 200,000 hours'. Example: 2 lost-time cases and 400,000 hours. 2 × 200,000 = 400,000. Divide by 400,000 to get 1.0. ## What changes the number - Days: OSHA counts calendar days (weekends too) from the day after the injury. Cap: 180. - Restricted duty: [DART](https://incidentkit.ai/glossary/dart-rate) includes it. Lost-time rates usually do not. - Hours base: to restate a rate on B hours as per 200,000, multiply by 200,000 ÷ B. - A rate per 1,000,000 hours becomes per 200,000 when you multiply by 0.2. Mix-up: LTIR, [TRIR](https://incidentkit.ai/glossary/trir) and DART answer different questions. TRIR counts all recordable cases. DART counts days away plus restricted and transferred cases. LTIR is narrower: only cases where the employee was away from work. ## Frequently asked questions ### Is LTIR an OSHA metric? No. OSHA's rates are the total case rate and the DART rate, both on 200,000 hours. LTIR is an industry label, so check how each customer or contract defines it. ### How do I convert an LTIR to a per-200,000-hour rate? Multiply it by 200,000 divided by the hours base it used. For a rate per 1,000,000 hours, multiply by 0.2. Only convert if both count the same cases. ### Does LTIR include restricted duty cases? Usually not. Lost time means the employee was away from work. Restricted work and job transfer count in OSHA's DART rate instead. Say which cases your LTIR includes. ## Sources - [OSHA 29 CFR 1904.7: General recording criteria](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.7) - [OSHA: Establishment-specific injury and illness data (rate definitions)](https://www.osha.gov/Establishment-Specific-Injury-and-Illness-Data) - [BLS Handbook of Methods: Survey of Occupational Injuries and Illnesses, calculation](https://www.bls.gov/opub/hom/soii/calculation.htm) ## Related terms - [Lost-time injury](https://incidentkit.ai/glossary/lost-time-injury) - [DART rate](https://incidentkit.ai/glossary/dart-rate) - [TRIR (total recordable incident rate)](https://incidentkit.ai/glossary/trir) - [OSHA recordable injury](https://incidentkit.ai/glossary/osha-recordable) ## Related - [TRIR and DART rates: formula, example and BLS 2024 rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates) - [TRIR and DART rate calculator (OSHA formula)](https://incidentkit.ai/tools/trir-dart-calculator) - [Recordable vs first aid: OSHA's medical treatment test](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) - [OSHA recordkeeping guide: Part 1904 for employers](https://incidentkit.ai/guides/osha-recordkeeping-guide) --- # Lost-time injury > A lost-time injury is a work injury or illness that keeps a worker home past the day it happened. OSHA's term for it is a days-away case. Source: https://incidentkit.ai/glossary/lost-time-injury · Updated Oct 5, 2026 Also known as: LTI, lost time incident, days away from work case ## The OSHA match Under 29 CFR 1904.7(b)(3), a case with days away gets a check mark in the days-away column and the number of calendar days away. Counting starts the day after the injury or the start of the illness. - Count calendar days the employee could not work, including weekends and holidays. - If a licensed professional advises days away, record them even if the worker returns early. - You may cap the count at 180 days. Estimate long absences until known. - Record the case once, in the year of the injury. Example: a worker hurt on Tuesday returns on Thursday. Wednesday is the only day away, so the case has one day away. ## What is not lost time Restricted work and job transfer are separate OSHA categories. They count toward the [DART rate](https://incidentkit.ai/glossary/dart-rate) but not as days away. A case with medical treatment beyond first aid and no missed or restricted days is recordable, but it is not lost time. Mix-up: company policies often define lost time as a missed shift or scheduled workday. OSHA counts calendar days, so internal numbers and OSHA 300 Log numbers can differ. Say which definition each report uses. See [LTIR](https://incidentkit.ai/glossary/ltir) for the rate. ## Frequently asked questions ### Is the day of the injury counted as a day away? No. OSHA starts counting the day after the injury or the start of the illness. ### Do weekends count toward days away? Yes, if the worker could not have worked them because of the injury. A Friday injury with a Monday return counts only if a clinician says the worker should not have worked. ### What if the employee comes back before the doctor says to? Days away are still recorded as the licensed professional advised, whether or not the worker follows it. If the worker stays home after being cleared, the count ends on the cleared date. ## Sources - [OSHA 29 CFR 1904.7: General recording criteria](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.7) - [OSHA: Establishment-specific injury and illness data (rate definitions)](https://www.osha.gov/Establishment-Specific-Injury-and-Illness-Data) ## Related terms - [LTIR (lost-time injury rate)](https://incidentkit.ai/glossary/ltir) - [DART rate](https://incidentkit.ai/glossary/dart-rate) - [OSHA recordable injury](https://incidentkit.ai/glossary/osha-recordable) - [First aid (OSHA recordkeeping)](https://incidentkit.ai/glossary/first-aid) - [TRIR (total recordable incident rate)](https://incidentkit.ai/glossary/trir) ## Related - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [Recordable vs first aid: OSHA's medical treatment test](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) - [TRIR and DART rates: formula, example and BLS 2024 rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates) - [OSHA recordkeeping guide: Part 1904 for employers](https://incidentkit.ai/guides/osha-recordkeeping-guide) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) --- # PSIF (potential serious injury or fatality) > PSIF means potential serious injury or fatality: an event that could have caused death or life-changing harm. It is a safety term, not an OSHA category. Source: https://incidentkit.ai/glossary/psif · Updated Oct 5, 2026 Also known as: PSIF, potential SIF, SIF precursor ## Rating by what could happen A PSIF rating asks what the event could have caused, not what it did. A load that falls near a worker is a PSIF though no one was hurt. A minor sprain from a routine task is not. The goal is to investigate by possible harm, because outcomes are partly luck. OSHA does not define PSIF. The term is not in its recordkeeping definitions (29 CFR 1904.46). OSHA's own severe categories differ: a work-related death within 8 hours, and an in-patient hospital stay, amputation or loss of an eye within 24 hours (29 CFR 1904.39). Groups also define serious in different ways. ## Using the rating OSHA tells employers to investigate close calls to find hidden hazards and root causes. A PSIF flag sends the highest-risk events to a deeper investigation. The fix should aim high on the [hierarchy of controls](https://incidentkit.ai/glossary/hierarchy-of-controls), such as removing the hazard or changing the equipment. Example: during repairs, a machine starts while a technician is inside the guard. No one is hurt. That is a PSIF and a [lockout/tagout](https://incidentkit.ai/glossary/lockout-tagout) failure. It needs investigation even though it never reaches the OSHA 300 Log. Mix-up: SIF is a serious injury or fatality that happened. PSIF is one that could have. Track PSIF events apart from [TRIR](https://incidentkit.ai/glossary/trir), because a rate that counts all cases equally hides them. ## Frequently asked questions ### Is PSIF an OSHA term? No. OSHA's recordkeeping definitions do not include it. PSIF is a practice term, so write your own criteria and apply them the same way each time. ### How is a PSIF different from a near miss? A PSIF is a smaller group of events: the possible result was death or life-changing harm. Many are near misses. Some are minor injuries. ### Who decides whether an event is a PSIF? Someone trained in your criteria, usually the EHS lead with the supervisor, asking the same questions each time. Write down the rating and the reason. ## Sources - [29 CFR 1904.46: Definitions (recordkeeping rule)](https://www.ecfr.gov/current/title-29/section-1904.46) - [OSHA 29 CFR 1904.39: Reporting fatalities, hospitalizations, amputations, and losses of an eye](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.39) - [OSHA: Recommended practices, hazard identification and assessment (incident investigation)](https://www.osha.gov/safety-management/hazard-identification) - [CDC NIOSH: Hierarchy of controls](https://www.cdc.gov/niosh/hierarchy-of-controls/about/index.html) - [OSHA 29 CFR 1910.147: The control of hazardous energy (lockout/tagout)](https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.147) ## Related terms - [Near miss](https://incidentkit.ai/glossary/near-miss) - [Hierarchy of controls](https://incidentkit.ai/glossary/hierarchy-of-controls) - [Lockout/tagout](https://incidentkit.ai/glossary/lockout-tagout) - [TRIR (total recordable incident rate)](https://incidentkit.ai/glossary/trir) - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) ## Related - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [Near-miss reporting and safety culture: a practical guide](https://incidentkit.ai/guides/near-miss-reporting-and-safety-culture) - [Incident reporting software for EHS managers and leads](https://incidentkit.ai/solutions/ehs-managers) - [Manufacturing incident reporting and OSHA 300 software](https://incidentkit.ai/solutions/manufacturing) --- # Hierarchy of controls > The hierarchy of controls ranks ways to reduce a hazard, from strongest to weakest. NIOSH puts removing the hazard first and protective gear last. Source: https://incidentkit.ai/glossary/hierarchy-of-controls · Updated Oct 5, 2026 Also known as: control hierarchy, hierarchy of hazard controls ## The five levels | Level | What it does (NIOSH) | Example | | --- | --- | --- | | 1. Elimination | Removes the hazard at the source | Stop using the hazardous task or chemical | | 2. Substitution | Uses a safer alternative to the source of the hazard | Replace a solvent with a water-based product | | 3. Engineering controls | Reduce or prevent hazards from contacting workers | Machine guards, interlocks, ventilation | | 4. Administrative controls | Set work practices that cut the time, frequency or strength of exposure | Rotation, procedures, signs | | 5. PPE (personal protective equipment) | Equipment worn to reduce exposure to hazards | Gloves, respirators, hearing protection | NIOSH says the top three work better because they control exposure without much human effort. The lower levels need workers to comply every time. ## Choosing actions Work from the top. Ask if you can remove the hazard, then swap it out. Record why a higher level is not possible before you settle for a lower one. The VA's action ranking for root cause analysis follows the same idea, with stronger, middle and weaker actions. Training and new policies are weaker. Example: after a pinch-point injury, a warning label and retraining are administrative. A fixed guard is engineering. A [corrective action](https://incidentkit.ai/glossary/corrective-and-preventive-action) plan of only training and signs sits at the bottom. Mix-up: PPE is not wrong, just the weakest alone. You often need it on top of higher controls. Also, the hierarchy is NIOSH's framework. Specific OSHA standards set their own rules. ## Frequently asked questions ### Which level of the hierarchy of controls is most effective? Elimination, which removes the hazard at its source. Then substitution, engineering, administrative controls and PPE. NIOSH says the top three work without much human effort. ### Is PPE a bad control? No. It is the last line of defense and weakest alone, since it needs right choice, fit and use every time. It works best with higher controls. ### Is the hierarchy of controls an OSHA requirement? It is a NIOSH framework used across industries. Some OSHA standards set their own control rules, so check yours. It is still a sound way to rank corrective actions. ## Sources - [CDC NIOSH: Hierarchy of controls](https://www.cdc.gov/niosh/hierarchy-of-controls/about/index.html) - [VHA National Center for Patient Safety: Root cause analysis (page and Guide to Performing a Root Cause Analysis, rev. 02/05/2021)](https://www.patientsafety.va.gov/professionals/onthejob/rca.asp) - [VHA National Center for Patient Safety: Proactive risk assessment (HFMEA, fault tree analysis, hierarchy of actions)](https://www.patientsafety.va.gov/professionals/onthejob/hfmea.asp) ## Related terms - [Corrective and preventive action](https://incidentkit.ai/glossary/corrective-and-preventive-action) - [Lockout/tagout](https://incidentkit.ai/glossary/lockout-tagout) - [PSIF (potential serious injury or fatality)](https://incidentkit.ai/glossary/psif) - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) - [Effectiveness review](https://incidentkit.ai/glossary/effectiveness-review) ## Related - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Lockout/tagout 29 CFR 1910.147: program and event data](https://incidentkit.ai/compliance/osha/lockout-tagout) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Incident reporting software for EHS managers and leads](https://incidentkit.ai/solutions/ehs-managers) --- # Lockout/tagout > Lockout/tagout (LOTO) means cutting a machine's power and locking or tagging the switch before repairs. OSHA's standard is 29 CFR 1910.147. Source: https://incidentkit.ai/glossary/lockout-tagout · Updated Oct 5, 2026 Also known as: LOTO, control of hazardous energy, 29 CFR 1910.147 ## What the standard requires 29 CFR 1910.147 covers service and repair of machines where a sudden start-up, or release of stored energy, could hurt workers. The employer must run an energy control program with three parts: procedures, training and inspections. - Use lockout if the energy device can be locked, unless tagout gives full protection. - Use tagout where the device cannot be locked. A tag is a warning, not a block. - Inspect each procedure at least yearly. - The inspector must be an authorized employee (one trained to lock out machines) who does not use it. - Train authorized employees on energy sources and shutoff steps. Tell other employees about the procedures. ## Scope and an example The standard does not cover construction, agriculture, some maritime work, power utilities, electrical hazards under subpart S, or oil and gas well work. Normal production is covered only when, for example, a guard is removed or bypassed. Example: a technician clearing a jam on a packaging line shuts the line down, locks the breaker, adds a personal tag and checks that the line cannot start before reaching in. A LOTO failure with no injury is a [PSIF](https://incidentkit.ai/glossary/psif)-type event that needs investigation. Mix-up: LOTO applies to service and repair, not every machine stop, and a tag alone does not stop energy. It is one control among many on the [hierarchy of controls](https://incidentkit.ai/glossary/hierarchy-of-controls). ## Frequently asked questions ### How often must lockout/tagout procedures be inspected? At least yearly, by an authorized employee who does not use the procedure. The inspection must fix any gaps. For lockout, the inspector also reviews duties with each authorized employee. ### Does 29 CFR 1910.147 apply to construction? No. It excludes construction and agriculture, plus some maritime work, utility installations and a few other types. Check the construction standards instead. ### Is tagout alone acceptable? Only where the device cannot be locked out, or where the employer shows tagout gives full protection. Lockout is the default when the device can be locked. ## Sources - [OSHA 29 CFR 1910.147: The control of hazardous energy (lockout/tagout)](https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.147) ## Related terms - [Hierarchy of controls](https://incidentkit.ai/glossary/hierarchy-of-controls) - [PSIF (potential serious injury or fatality)](https://incidentkit.ai/glossary/psif) - [Near miss](https://incidentkit.ai/glossary/near-miss) - [OSHA recordable injury](https://incidentkit.ai/glossary/osha-recordable) ## Related - [Lockout/tagout 29 CFR 1910.147: program and event data](https://incidentkit.ai/compliance/osha/lockout-tagout) - [Manufacturing incident reporting and OSHA 300 software](https://incidentkit.ai/solutions/manufacturing) - [Incident reporting software for plant managers](https://incidentkit.ai/solutions/plant-managers) - [Warehouse and logistics incident reporting software](https://incidentkit.ai/solutions/warehousing-and-logistics) - [Near Miss Report Template (Free, Printable Form)](https://incidentkit.ai/templates/near-miss-report) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) --- # ASCQR (ASC Quality Reporting Program) > ASCQR is the CMS quality reporting program for surgery centers. Centers that do not report take a 2.0 point cut in their Medicare payment update. Source: https://incidentkit.ai/glossary/ascqr · Updated Oct 5, 2026 Also known as: ASCQR, ASC Quality Reporting Program, ASC QR ## What it requires 42 CFR 416.300 sets the penalty: a 2.0 percentage point cut in a center's yearly payment update for not reporting as CMS requires. There are three kinds of measures: - Claims-based: at least 50 percent of eligible Medicare claims must carry quality data codes (42 CFR 416.310(a)). - Web-based: submit online from January 1 to May 15 of the year before the payment year (416.310(c)). - Patient survey, such as OAS CAHPS: reported on a quarterly schedule CMS posts each year. Web data covers services from two calendar years before the payment year. You need a CMS system account and a security official. ## The event measures CMS's schedule for the CY 2026 reporting period lists these web-based event measures: - ASC-1: patient burn - ASC-2: patient fall - ASC-3: wrong site, side, patient, procedure or implant - ASC-4: hospital transfer or admission for any cause The submission period is January 1 to May 17, 2027. Check QualityNet each year for exact dates. Example: a center that logs each burn and fall as an incident, with date and procedure, can answer ASC-1 and ASC-2 at year end without rebuilding events from memory. Mix-up: ASCQR is a payment-reporting program. It is not accreditation, and it is not the QAPI condition in 42 CFR 416.43, though event data feeds both. The penalty is a lower payment update, not a fine. ## Frequently asked questions ### What is the penalty for not reporting under ASCQR? A 2.0 percentage point cut in the center's yearly payment update (42 CFR 416.300), for the payment year tied to the data period. ### When is the web-based data due? 42 CFR 416.310 sets January 1 to May 15 of the year before the payment year. CMS's CY 2026 schedule lists January 1 to May 17, 2027. Confirm dates on QualityNet. ### Which events does the ASCQR Program track? For CY 2026: patient burn (ASC-1), patient fall (ASC-2), wrong site, side, patient, procedure or implant (ASC-3) and hospital transfer or admission (ASC-4), plus other measures. ## Sources - [42 CFR 416.300: ASCQR Program basis and scope](https://www.ecfr.gov/current/title-42/section-416.300) - [42 CFR 416.310: ASCQR data collection and submission requirements](https://www.ecfr.gov/current/title-42/section-416.310) - [CMS QualityNet: Ambulatory Surgical Center Quality Reporting Program](https://qualitynet.cms.gov/asc) ## Related terms - [Never event](https://incidentkit.ai/glossary/never-event) - [QAPI](https://incidentkit.ai/glossary/qapi) - [Conditions for coverage](https://incidentkit.ai/glossary/conditions-for-coverage) - [Adverse event](https://incidentkit.ai/glossary/adverse-event) - [AAAHC](https://incidentkit.ai/glossary/aaahc) ## Related - [ASCQR Program: measures, deadlines, 2.0-point penalty](https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting) - [ASC Quality Reporting payment update impact calculator](https://incidentkit.ai/tools/ascqr-penalty-calculator) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [Incident reporting software for surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) --- # AAAHC > AAAHC is a group that accredits, or formally approves, outpatient care sites like surgery centers and endoscopy centers. It began in 1979. Source: https://incidentkit.ai/glossary/aaahc · Updated Oct 5, 2026 Also known as: Accreditation Association for Ambulatory Health Care ## What AAAHC is AAAHC says it began in 1979 and focuses only on outpatient (ambulatory) care. It accredits these kinds of sites: - Surgery centers - Office-based surgery centers - Endoscopy centers - Student health centers - Medical and dental group practices - Community health centers - Other outpatient settings Reviews are on site, by peers, and meant to teach. Its accreditation term is a 1,095-day cycle. It offers several survey types, including Medicare Deemed Status surveys, which it says are unannounced. ## Link to CMS rules A surgery center that picks AAAHC's Medicare Deemed Status program is surveyed by AAAHC, not the State agency (see [deemed status](https://incidentkit.ai/glossary/deemed-status)). It must still meet the [conditions for coverage](https://incidentkit.ai/glossary/conditions-for-coverage) in 42 CFR Part 416, including QAPI under 416.43. Example: a surgery center in the program gets a State validation survey after a complaint. Being AAAHC-accredited does not stop CMS from checking the same rules. Mix-up: accreditation is not a license, and Medicare does not require it. Some states and payers may, so check your state and contracts. See also the [comparison of AAAHC and the Joint Commission](https://incidentkit.ai/blog/aaahc-vs-joint-commission-for-ascs). ## Frequently asked questions ### Is AAAHC accreditation required for Medicare? No. The State Operations Manual says it is voluntary. A surgery center can choose State agency surveys instead. Some states or payers have their own rules. ### How long does AAAHC accreditation last? A 1,095-day cycle, or three years. AAAHC calls it '1095 strong': be survey-ready every day, not only on survey day. ### Are AAAHC deemed status surveys announced? No. AAAHC says Medicare Deemed Status surveys are unannounced, with no dates or surveyor names in advance. Centers in the program must stay survey-ready year-round. ## Sources - [AAAHC: About us](https://www.aaahc.org/about/) - [AAAHC: Medicare Deemed Status accreditation](https://www.aaahc.org/accelerated-readiness/program-overview/medicare-deemed/) - [CMS State Operations Manual, Chapter 2: The Certification Process](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c02.pdf) - [42 CFR 416.43: ASC QAPI condition for coverage](https://www.ecfr.gov/current/title-42/section-416.43) ## Related terms - [Deemed status](https://incidentkit.ai/glossary/deemed-status) - [Joint Commission](https://incidentkit.ai/glossary/joint-commission) - [Conditions for coverage](https://incidentkit.ai/glossary/conditions-for-coverage) - [ASCQR (ASC Quality Reporting Program)](https://incidentkit.ai/glossary/ascqr) - [QAPI](https://incidentkit.ai/glossary/qapi) ## Related - [AAAHC accreditation: surveys, deemed status and QI studies](https://incidentkit.ai/compliance/accreditation/aaahc) - [AAAHC vs Joint Commission for ASCs: how they compare](https://incidentkit.ai/blog/aaahc-vs-joint-commission-for-ascs) - [Incident reporting software for surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers) - [ASC survey readiness: what surveyors ask for and check](https://incidentkit.ai/compliance/survey-readiness/asc-survey-readiness) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) --- # Joint Commission > The Joint Commission is a US group that accredits hospitals, outpatient, nursing care and home care sites. It also sets the Sentinel Event Policy. Source: https://incidentkit.ai/glossary/joint-commission · Updated Oct 5, 2026 Also known as: TJC, The Joint Commission ## What it is It publishes a Comprehensive Accreditation Manual for each type of site, such as hospitals, nursing care centers, home care and assisted living. Each manual has a chapter on the Sentinel Event Policy, first adopted in 1996. Its Office of Quality and Patient Safety (OQPS) reviews reported sentinel events, plus the analysis and action plan a site sends in. ## After a serious event Sites it accredits need a sentinel event policy. They must study each such event in full, most often with a root cause analysis. Then they carry out the action plan and check that it works. Reporting to the Joint Commission is encouraged, not required. Surveyors check how a site responds to safety events, adverse events, unsafe conditions and close calls, and to sentinel events. They do not hunt for them. Mix-up: its standards are not CMS rules. Its accreditation can support [deemed status](https://incidentkit.ai/glossary/deemed-status) where CMS has approved its program, but the site still follows CMS rules. Its terms, like [sentinel event](https://incidentkit.ai/glossary/sentinel-event), also differ from CMS usage. ## Frequently asked questions ### Is Joint Commission accreditation mandatory? Not for Medicare. It is voluntary, and providers can use State agency surveys instead. Some states, payers or contracts may require it. ### Does the Joint Commission require reporting of sentinel events? No. Self-reporting is strongly encouraged, not required. You must still have a policy and study every such event in full. ### Does a sentinel event affect our accreditation decision? Not by itself, says the policy. Willful failure to respond well could, such as missing the extra 45 days after the analysis is due. ## Sources - [Joint Commission: Sentinel Event Policy (SE chapter), Comprehensive Accreditation Manual, Update 1, July 2026](https://www.jointcommission.org/-/media/tjc/documents/resources/patient-safety-topics/sentinel-event/camncc_20_se_all_current.pdf) - [CMS State Operations Manual, Chapter 2: The Certification Process](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c02.pdf) - [42 CFR 488.5: Application and re-application procedures for accrediting organizations](https://www.ecfr.gov/current/title-42/section-488.5) ## Related terms - [Sentinel event](https://incidentkit.ai/glossary/sentinel-event) - [Deemed status](https://incidentkit.ai/glossary/deemed-status) - [AAAHC](https://incidentkit.ai/glossary/aaahc) - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) - [Harm scale](https://incidentkit.ai/glossary/harm-scale) ## Related - [Joint Commission accreditation: surveys and sentinel events](https://incidentkit.ai/compliance/accreditation/joint-commission) - [Joint Commission survey readiness: tracers, unannounced](https://incidentkit.ai/compliance/survey-readiness/joint-commission-survey-readiness) - [AAAHC vs Joint Commission for ASCs: how they compare](https://incidentkit.ai/blog/aaahc-vs-joint-commission-for-ascs) - [What is a sentinel event? Definition, examples, response](https://incidentkit.ai/blog/what-is-a-sentinel-event) - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) --- # Five whys > Five whys is a way to find a root cause. Ask why a problem happened, then why again for each answer, until you reach a cause you can fix. Source: https://incidentkit.ai/glossary/five-whys · Updated Oct 5, 2026 Also known as: 5 whys, five whys analysis ## How it works IHI puts it simply: when a problem shows up, ask why five times until you reach the root cause. IHI warns that what we think is the cause may be only another symptom, that there may be more than one root cause, and that different people give different answers. Example: an infusion pump alarm went unanswered. 1. **Why 1** The alarm volume was set too low. 2. **Why 2** Pumps return to low volume after each reset. 3. **Why 3** No one changed the default after the last software update. 4. **Why 4** No one owns pump setup after updates. 5. **Why 5** The biomedical update checklist has no step for alarm settings. Fix the checklist, set a standard default and assign an owner. ## Limits OSHA makes the same point about investigations: do not stop when you decide a worker made an error. Ask whether the worker had the right tools, time, training and supervision. A chain that ends at a person has stopped too early. Five is a guide, not a rule. Stop when you reach a cause that a system change can fix. For serious events, IHI points to its RCA2 tool for more rigor. See [five whys, fishbone and fault tree compared](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree). In IncidentKit, investigations record contributing factors, five whys and the final disposition, and a person reviews and signs. ## Frequently asked questions ### Do you always need exactly five whys? No. Five is a rule of thumb. Keep asking until you reach a cause you can fix with a change in process, equipment or design. That may take three questions or seven. ### Is five whys enough for a sentinel event? Usually not alone. It follows one chain of cause, and serious events often have several. The Joint Commission expects a full analysis. IHI recommends RCA2 for more rigor. ### What is the difference between five whys and a fishbone diagram? Five whys drills down one chain of cause. A fishbone spreads out many possible causes at once. Teams often use both. ## Sources - [IHI: 5 Whys, finding the root cause](https://www.ihi.org/library/tools/5-whys-finding-root-cause) - [VHA National Center for Patient Safety: Root cause analysis (page and Guide to Performing a Root Cause Analysis, rev. 02/05/2021)](https://www.patientsafety.va.gov/professionals/onthejob/rca.asp) - [OSHA: Recommended practices, hazard identification and assessment (incident investigation)](https://www.osha.gov/safety-management/hazard-identification) - [Joint Commission: Sentinel Event Policy (SE chapter), Comprehensive Accreditation Manual, Update 1, July 2026](https://www.jointcommission.org/-/media/tjc/documents/resources/patient-safety-topics/sentinel-event/camncc_20_se_all_current.pdf) ## Related terms - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) - [Fishbone diagram](https://incidentkit.ai/glossary/fishbone-diagram) - [Fault tree analysis](https://incidentkit.ai/glossary/fault-tree-analysis) - [Corrective and preventive action](https://incidentkit.ai/glossary/corrective-and-preventive-action) ## Related - [Five whys vs fishbone vs fault tree: how to choose](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Root Cause Analysis Worksheet (5 Whys Template)](https://incidentkit.ai/templates/root-cause-analysis-worksheet) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) --- # Fishbone diagram > A fishbone diagram maps the possible causes of one problem on branches, like fish bones. Teams also call it a cause-and-effect or Ishikawa diagram. Source: https://incidentkit.ai/glossary/fishbone-diagram · Updated Oct 5, 2026 Also known as: Ishikawa diagram, cause and effect diagram, cause-and-effect diagram ## What it is IHI defines a cause and effect diagram as a graphic tool to explore and show the possible causes of an effect. Use the classic fishbone when causes fit groups like materials, methods, equipment, environment and people. Or use a process-type diagram to show causes at each step. IHI lists three benefits. It shows a team that many causes add up to an effect. It shows how causes relate to the effect and to each other. And it helps find areas to improve. ## How to use it 1. Write the problem at the head, specific and measurable. 2. Draw branches for the groups that fit. 3. Brainstorm causes with the people who do the work. 4. Mark the likeliest causes. Check each against data before you accept it. Example: late first-case starts at a surgery center. Branches might hold people (arrival times), methods (room turnover steps), equipment (instrument trays not ready) and materials (supply stock-outs). Mix-up: a fishbone lists possible causes and does not prove them. Combine it with [five whys](https://incidentkit.ai/glossary/five-whys) and check records. The VA's version works backward with 'caused by' and asks for at least two causes: an action and a condition. In IncidentKit, investigations record contributing factors. ## Frequently asked questions ### Why is it called a fishbone diagram? The problem sits at the head of a long spine, and cause groups branch off like ribs, like a fish skeleton. It is also called an Ishikawa or cause and effect diagram. ### Which categories should a fishbone use? IHI's classic version uses materials, methods, equipment, environment and people. Switch to a process-type diagram or change the groups when causes do not fit. ### Does a fishbone find the root cause? No. It lays out possible causes. Check each one against records, observation and interviews. Confirmed causes lead to corrective actions. ## Sources - [IHI: Cause and effect diagram (QI Essentials toolkit)](https://www.ihi.org/library/tools/cause-and-effect-diagram) - [VHA National Center for Patient Safety: Root cause analysis (page and Guide to Performing a Root Cause Analysis, rev. 02/05/2021)](https://www.patientsafety.va.gov/professionals/onthejob/rca.asp) ## Related terms - [Five whys](https://incidentkit.ai/glossary/five-whys) - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) - [Fault tree analysis](https://incidentkit.ai/glossary/fault-tree-analysis) - [Corrective and preventive action](https://incidentkit.ai/glossary/corrective-and-preventive-action) ## Related - [Five whys vs fishbone vs fault tree: how to choose](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Root Cause Analysis Worksheet (5 Whys Template)](https://incidentkit.ai/templates/root-cause-analysis-worksheet) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) --- # Fault tree analysis > Fault tree analysis (FTA) starts from a bad outcome and maps the combinations of failures that could cause it. OSHA lists it for process hazard analysis. Source: https://incidentkit.ai/glossary/fault-tree-analysis · Updated Oct 5, 2026 Also known as: FTA, fault tree ## How it works Start with the top event, such as a wrong-strength dose reaching a patient. Ask what conditions could cause it, and join them with logic gates. An AND gate means all must happen together. An OR gate means any one is enough. Keep branching until you reach basic events, like a failed device, a missed check or a missing barrier. The tree then shows single points of failure, where one event alone causes the top event, and the barriers that must all fail. You can add probabilities, but a tree without numbers is still useful. Example: a surgical fire needs fuel, an oxidizer and an ignition source together, an AND gate. Remove any one and the fire cannot start, so each input becomes a control to review. ## Where it is used OSHA's process safety management standard lists Fault Tree Analysis among the methods an employer may use for a process hazard analysis, next to what-if, checklist, HAZOP and failure mode and effects analysis (29 CFR 1910.119(e)(2)). The VA's National Center for Patient Safety lists it among its proactive risk assessment methods. Mix-up: a fault tree does not tell the story of what happened. It models how an outcome could happen, so it helps before an event and after one. [Five whys](https://incidentkit.ai/glossary/five-whys) and the [fishbone diagram](https://incidentkit.ai/glossary/fishbone-diagram) trace causes of one event. A fault tree handles combinations and barriers. ## Frequently asked questions ### When should I use a fault tree instead of five whys? Use a fault tree for high-stakes outcomes where several things must fail together. Five whys fits a simpler event with one chain of cause. ### Do I need probabilities to do fault tree analysis? No. A tree with only logic gates and basic events already shows single points of failure. Probabilities help rank risks when you have good data. ### Does OSHA require fault tree analysis? No single method is required. The process safety management standard says an employer must use one or more listed methods that fit the process. Fault Tree Analysis is one. ## Sources - [OSHA 29 CFR 1910.119: Process safety management of highly hazardous chemicals](https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.119) - [VHA National Center for Patient Safety: Proactive risk assessment (HFMEA, fault tree analysis, hierarchy of actions)](https://www.patientsafety.va.gov/professionals/onthejob/hfmea.asp) ## Related terms - [Five whys](https://incidentkit.ai/glossary/five-whys) - [Fishbone diagram](https://incidentkit.ai/glossary/fishbone-diagram) - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) - [Risk matrix](https://incidentkit.ai/glossary/risk-matrix) - [Hierarchy of controls](https://incidentkit.ai/glossary/hierarchy-of-controls) ## Related - [Five whys vs fishbone vs fault tree: how to choose](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Process safety incident reporting and investigation](https://incidentkit.ai/solutions/chemical-and-process-industries) - [PSM incident investigation: 29 CFR 1910.119(m) explained](https://incidentkit.ai/compliance/osha/process-safety-incident-investigation) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) --- # Risk matrix > A risk matrix scores a hazard by crossing how bad the outcome could be with how likely it is. The score sets which problems to fix first. Source: https://incidentkit.ai/glossary/risk-matrix · Updated Oct 5, 2026 Also known as: risk assessment matrix, severity and probability matrix, Safety Assessment Code matrix ## How it works The VA National Center for Patient Safety built a Safety Assessment Code (SAC) matrix to rank adverse events and close calls. Staff pick a severity and a probability and read the score from the grid. | Severity | Probability | | --- | --- | | Minor | Remote: sometime in 5 to 30 years | | Moderate | Uncommon: sometime in 2 to 5 years | | Major | Occasional: several times in 2 years | | Catastrophic | Frequent: several times in 1 year | For RCA, SAC scores run from 1 to 3. The VA requires an RCA for a sentinel event or a high-probability near miss scored Actual 3 or Potential 3. The related HFMEA hazard matrix scores from 1 to 16. A hazard score of 8 or higher goes on to a decision tree. ## Limits The matrix gives priority, not truth. Scores are judgments, so write a clear definition for each severity and probability level, as the VA did, and use it the same way each time. Matrices also leave out how easy a problem is to detect and what controls exist. HFMEA adds those with its decision tree. Mix-up: there is no standard grid size, 4 by 4 or 5 by 5. And a risk matrix looks ahead at what could happen. The CMS scope and severity grid and [harm scales](https://incidentkit.ai/glossary/harm-scale) rate what already happened. ## Frequently asked questions ### Should we use a 4 by 4 or a 5 by 5 matrix? Either can work. What matters is a written definition for every level, used the same way. The VA's SAC matrix has four severity and four probability levels. ### Is a risk matrix the same as the CMS scope and severity grid? No. The CMS grid rates deficiencies already found on a nursing home survey. A risk matrix estimates the priority of a hazard or event from severity and likelihood. ### What is a risk matrix used for in incident management? To decide which events get a full investigation, which are reviewed together and which go to leaders. The VA requires an individual RCA for sentinel events and events scored Actual 3 or Potential 3. ## Sources - [DeRosier J, et al. Using Health Care Failure Mode and Effect Analysis: the VA National Center for Patient Safety's prospective risk analysis system. Jt Comm J Qual Improv, 2002](http://www.patientsafety.va.gov/docs/hfmea/HFMEA_JQI.pdf) - [VHA National Center for Patient Safety: Root cause analysis (page and Guide to Performing a Root Cause Analysis, rev. 02/05/2021)](https://www.patientsafety.va.gov/professionals/onthejob/rca.asp) - [VHA National Center for Patient Safety: Proactive risk assessment (HFMEA, fault tree analysis, hierarchy of actions)](https://www.patientsafety.va.gov/professionals/onthejob/hfmea.asp) - [CMS State Operations Manual, Chapter 7: Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c07pdf.pdf) ## Related terms - [Harm scale](https://incidentkit.ai/glossary/harm-scale) - [Fault tree analysis](https://incidentkit.ai/glossary/fault-tree-analysis) - [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis) - [Near miss](https://incidentkit.ai/glossary/near-miss) - [PSIF (potential serious injury or fatality)](https://incidentkit.ai/glossary/psif) ## Related - [Incident routing and escalation by severity](https://incidentkit.ai/product/routing-and-escalation) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) - [Incident analytics: find the pattern before the next one](https://incidentkit.ai/product/analytics) - [PSM incident investigation: 29 CFR 1910.119(m) explained](https://incidentkit.ai/compliance/osha/process-safety-incident-investigation) --- # Safety data sheet > A safety data sheet (SDS) is a 16-section document on a chemical's hazards and safe handling. Employers must keep one for each hazardous chemical they use. Source: https://incidentkit.ai/glossary/safety-data-sheet · Updated Oct 5, 2026 Also known as: SDS, chemical safety data sheet, hazard communication SDS ## The 16 sections OSHA's Hazard Communication Standard (29 CFR 1910.1200(g)) requires the SDS to be in English and to have these sections in this order: 1. Identification 2. Hazard(s) identification 3. Composition and ingredients 4. First-aid measures 5. Fire-fighting measures 6. Accidental release measures 7. Handling and storage 8. Exposure controls and personal protection 9. Physical and chemical properties 10. Stability and reactivity 11. Toxicological information 12. Ecological information 13. Disposal considerations 14. Transport information 15. Regulatory information 16. Other information, including date of preparation or last revision OSHA does not enforce sections 12 through 15, because those topics are outside its authority. ## Employer duties Employers must have an SDS in the workplace for each hazardous chemical they use, easy to reach on every shift. Manufacturers must add significant new hazard data to the SDS within three months, and send the updated SDS with the next shipment. Example: a lab technician splashes a solvent. The incident record should name the product so responders can use Section 4 (first aid) and Section 8 (exposure controls) from its SDS. Mix-up: the SDS is not the container label. The label gives short hazard warnings. The SDS gives full detail. ## Frequently asked questions ### How many sections does a safety data sheet have? Sixteen, in a set order. OSHA does not enforce sections 12 to 15 (ecological, disposal, transport, regulatory). Section 16 holds other information, including the revision date. ### Where must safety data sheets be kept? In the workplace, for each hazardous chemical the employer uses, and easy to reach on every shift. Not only in an office employees cannot reach. ### Who is responsible for writing the SDS? The chemical maker or importer must get or write one for each hazardous chemical it makes or imports. Employers must get and keep the ones for products they buy. ## Sources - [29 CFR 1910.1200: Hazard Communication](https://www.ecfr.gov/current/title-29/section-1910.1200) ## Related terms - [Hierarchy of controls](https://incidentkit.ai/glossary/hierarchy-of-controls) - [OSHA recordable injury](https://incidentkit.ai/glossary/osha-recordable) - [First aid (OSHA recordkeeping)](https://incidentkit.ai/glossary/first-aid) - [Lockout/tagout](https://incidentkit.ai/glossary/lockout-tagout) ## Related - [Hazard communication 29 CFR 1910.1200: SDS, labels, training](https://incidentkit.ai/compliance/osha/hazard-communication) - [Laboratory and pharma production incident reporting](https://incidentkit.ai/solutions/laboratories-and-pharma-production) - [Process safety incident reporting and investigation](https://incidentkit.ai/solutions/chemical-and-process-industries) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) - [Near Miss Report Template (Free, Printable Form)](https://incidentkit.ai/templates/near-miss-report) --- # Workers' compensation > Workers' compensation is insurance that pays medical care and lost wages for employees hurt or made ill by work. Each state runs it for private employers. Source: https://incidentkit.ai/glossary/workers-compensation · Updated Oct 5, 2026 Also known as: workers comp, workers' comp, WC ## What it is The U.S. Department of Labor (DOL) says its Office of Workers' Compensation Programs runs four federal programs. They cover: - Federal employees - Longshore and harbor workers - Coal miners with black lung - Certain energy employees Hurt private-sector and state and local government workers go to their state workers' compensation board. DOL lists these benefits: wage replacement, medical treatment, vocational rehabilitation (job retraining) and others. State programs differ in forms, deadlines and benefits, so check your state's rules. ## Versus OSHA recordkeeping OSHA says recording an injury does not mean anyone was at fault. It does not mean an OSHA rule was broken, or that the employee can get workers' compensation (29 CFR 1904.0). The two systems use different tests and can reach different answers for the same injury. Example: an employee's cut is cleaned and bandaged on site. That is first aid, so it is not OSHA-recordable. The employee may still file a claim. The state system, not OSHA's first aid list, decides if it is payable. Mix-up: the claim filing, called the [first report of injury](https://incidentkit.ai/glossary/froi), goes to the insurer. The [OSHA 301](https://incidentkit.ai/glossary/osha-recordable) is a separate record, though an insurance form may serve as an equal. ## Frequently asked questions ### Does a workers' compensation claim mean the injury is OSHA recordable? Not automatically. OSHA decides recordability by work-relatedness, new-case status and the recording criteria (29 CFR 1904). A claim paid for first-aid-level care may not be recordable. ### Who regulates workers' compensation for private employers? Each state, through its workers' compensation board or agency. Federal programs cover only specific groups, like federal employees and longshore workers. ### What form starts a workers' compensation claim? The employer's first report of injury, filed with its insurer or claims administrator. Each state and carrier sets the form, content and deadline. ## Sources - [U.S. Department of Labor: Workers' compensation](https://www.dol.gov/general/topic/workcomp) - [29 CFR 1904.0: Purpose (recordkeeping rule)](https://www.ecfr.gov/current/title-29/section-1904.0) - [29 CFR 1904.5: Determination of work-relatedness](https://www.ecfr.gov/current/title-29/section-1904.5) - [29 CFR 1904.29: Forms (OSHA 300, 300-A and 301)](https://www.ecfr.gov/current/title-29/section-1904.29) - [IAIABC: EDI claims standards (first report of injury)](https://www.iaiabc.org/edi-claims) ## Related terms - [FROI (First Report of Injury)](https://incidentkit.ai/glossary/froi) - [OSHA recordable injury](https://incidentkit.ai/glossary/osha-recordable) - [First aid (OSHA recordkeeping)](https://incidentkit.ai/glossary/first-aid) - [Lost-time injury](https://incidentkit.ai/glossary/lost-time-injury) ## Related - [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview) - [OSHA 301 incident report: the 18 fields and deadlines](https://incidentkit.ai/compliance/osha/osha-301-incident-report) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) - [Workplace Injury Report Template (OSHA 301 Aligned)](https://incidentkit.ai/templates/workplace-injury-report) - [Incident reporting for insurers, TPAs and risk pools](https://incidentkit.ai/solutions/insurers-and-risk-pools) --- # FROI (First Report of Injury) > FROI, the First Report of Injury, is the first report of a work injury sent to the workers' compensation insurer. It opens the claim. Source: https://incidentkit.ai/glossary/froi · Updated Oct 5, 2026 Also known as: FROI, first report of injury, employer's first report of injury ## What a FROI is The first report of injury opens the workers' compensation claim. IAIABC says claims administrators use its EDI (electronic) claims standards to send first report of injury and later report (SROI) data to U.S. states. Each state runs workers' compensation for private employers. So the form, the content and the filing deadline depend on the state and the insurer. A FROI is not a federal form. Check your state's rules and your policy. ## FROI and OSHA forms A FROI and the OSHA 301 have different goals, but OSHA allows an equal form. 29 CFR 1904.29 notes that many employers use an insurance form in place of the 301, or add OSHA's required details to an insurance form. Example: an employee burns a hand. The supervisor writes the incident report, HR files the FROI with the carrier, and the EHS lead decides if it is OSHA-recordable. Three records, three owners, one event. Mix-up: filing a FROI does not make a case recordable. Recording a case does not decide [workers' compensation](https://incidentkit.ai/glossary/workers-compensation) eligibility. IncidentKit's insurer and TPA (third-party administrator) data feed is rolling out. ## Frequently asked questions ### Who files the first report of injury? The employer reports the injury to its workers' compensation insurer or claims administrator. That party sends claim data to the state where the state asks. Duties differ by state. ### How is a FROI different from the OSHA 301? The FROI starts an insurance claim. The OSHA 301 is an incident report for each recordable case. An insurance form may serve as the 301 if it holds the same information. ### Does every injury need a FROI? That depends on your state's rules and your policy. OSHA recordability is decided separately. Ask your carrier or broker. ## Sources - [IAIABC: EDI claims standards (first report of injury)](https://www.iaiabc.org/edi-claims) - [U.S. Department of Labor: Workers' compensation](https://www.dol.gov/general/topic/workcomp) - [29 CFR 1904.29: Forms (OSHA 300, 300-A and 301)](https://www.ecfr.gov/current/title-29/section-1904.29) - [29 CFR 1904.0: Purpose (recordkeeping rule)](https://www.ecfr.gov/current/title-29/section-1904.0) ## Related terms - [Workers' compensation](https://incidentkit.ai/glossary/workers-compensation) - [OSHA recordable injury](https://incidentkit.ai/glossary/osha-recordable) - [Incident report](https://incidentkit.ai/glossary/incident-report) - [Lost-time injury](https://incidentkit.ai/glossary/lost-time-injury) ## Related - [OSHA 301 incident report: the 18 fields and deadlines](https://incidentkit.ai/compliance/osha/osha-301-incident-report) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) - [Workplace Injury Report Template (OSHA 301 Aligned)](https://incidentkit.ai/templates/workplace-injury-report) - [Incident reporting for insurers, TPAs and risk pools](https://incidentkit.ai/solutions/insurers-and-risk-pools) - [Incident reporting API, webhooks and integrations](https://incidentkit.ai/product/integrations-and-api) --- # Business associate agreement > A business associate agreement (BAA) is the contract HIPAA requires when a vendor handles patient health data for a provider. It sets the vendor's duties. Source: https://incidentkit.ai/glossary/business-associate-agreement · Updated Oct 5, 2026 Also known as: BAA, HIPAA business associate contract ## What it must say Under 45 CFR 164.504(e), the contract must set how the vendor may use and share protected health information. The vendor, called the business associate, must agree to: - Use or share the data only as the contract allows or the law requires. - Use proper safeguards and follow the Security Rule for electronic data. - Report any misuse, including breaches of unsecured data. - Make sure subcontractors accept the same limits. - Support patient access, amendments and the list of disclosures, and open its records to HHS. - Return or destroy the data at the end, if feasible. The covered entity, meaning the provider or health plan, must be able to end the contract for a material breach. ## When you need one A business associate creates, receives, keeps or sends [protected health information](https://incidentkit.ai/glossary/phi) for a covered entity. Examples are data analysis, quality assurance, patient safety work, billing and consulting. Subcontractors count too. Example: a hospital adopts cloud software that stores patient names and details inside event reports. The vendor is a business associate, so a BAA must be in place before patient data flows. IncidentKit's Regulated plan includes a BAA. Mix-up: a workplace injury report about an employee at a non-healthcare site holds no PHI, so it needs no BAA. A provider that receives treatment disclosures is not a business associate. ## Frequently asked questions ### Do we need a BAA for incident reporting software? Yes, if the vendor handles protected health information for you, as it does when event reports hold patient names or details. With no patient data, a BAA is not the issue. ### Does a business associate's subcontractor need an agreement? Yes. The vendor must make sure any subcontractor that handles protected health information for it agrees to the same limits. ### What happens to our data when the BAA ends? If feasible, the vendor must return or destroy all protected health information it holds and keep no copies. If not, the contract's protections continue. ## Sources - [45 CFR 164.504(e): Business associate contracts](https://www.ecfr.gov/current/title-45/section-164.504) - [45 CFR 160.103: HIPAA definitions (protected health information, business associate)](https://www.ecfr.gov/current/title-45/section-160.103) ## Related terms - [Protected health information (PHI)](https://incidentkit.ai/glossary/phi) - [Patient safety organization](https://incidentkit.ai/glossary/patient-safety-organization) - [Incident report](https://incidentkit.ai/glossary/incident-report) - [Variance report](https://incidentkit.ai/glossary/variance-report) ## Related - [HIPAA and BAA for incident reporting](https://incidentkit.ai/hipaa) - [IncidentKit security overview](https://incidentkit.ai/security) - [Incident reporting software pricing: free to start](https://incidentkit.ai/pricing) - [Incident reporting software: forms, drafts, workflow](https://incidentkit.ai/product/incident-reporting) - [Patient safety event reporting software for hospitals](https://incidentkit.ai/solutions/hospitals) --- # Protected health information (PHI) > Protected health information (PHI) is health data that identifies a person. HIPAA covers it when a provider, plan or their vendor holds it. Source: https://incidentkit.ai/glossary/phi · Updated Oct 5, 2026 Also known as: PHI, protected health information, ePHI ## The HIPAA definition 45 CFR 160.103 defines PHI as health information, in any form, that identifies a person or could reasonably be used to. A provider, health plan, employer or clearinghouse creates or receives it. It relates to a person's health, care or payment for care. PHI does not include: - Education records covered by FERPA - Employment records a covered entity holds as an employer - Data about a person who died more than 50 years ago ## Incident reports A fall report that names the resident, room and injuries is PHI. So is a medication error report with the patient's name, record number and diagnosis. Remove identifiers you do not need. Treat the rest under HIPAA, including a [business associate agreement](https://incidentkit.ai/glossary/business-associate-agreement) with any vendor that holds it. Example: a hospital's file on an employee hurt at work is an employment record, not PHI. The same person's treatment record, made because the hospital treated them as a patient, is PHI. Mix-up: PHI is not every personal detail. It is health information tied to a covered entity or business associate. A worker's injury report at a plant is not PHI. ## Frequently asked questions ### Is an incident report PHI? Yes, if it identifies a patient or resident and relates to health, care or payment. A report on only a worker injury at a non-healthcare employer holds no PHI. ### Are employee injury records PHI? Records a covered entity holds as an employer, like an injury report, are not PHI. Its treatment records of the same person are PHI. ### What makes health information identifiable? It identifies the person, or can reasonably be used to. A name is the clear case, but a mix of details can also identify someone. ## Sources - [45 CFR 160.103: HIPAA definitions (protected health information, business associate)](https://www.ecfr.gov/current/title-45/section-160.103) ## Related terms - [Business associate agreement](https://incidentkit.ai/glossary/business-associate-agreement) - [Patient safety organization](https://incidentkit.ai/glossary/patient-safety-organization) - [Incident report](https://incidentkit.ai/glossary/incident-report) - [Variance report](https://incidentkit.ai/glossary/variance-report) ## Related - [HIPAA and BAA for incident reporting](https://incidentkit.ai/hipaa) - [IncidentKit security overview](https://incidentkit.ai/security) - [Incident audit trail: every change, who and when](https://incidentkit.ai/product/audit-trail) - [Incident reporting software: forms, drafts, workflow](https://incidentkit.ai/product/incident-reporting) - [Patient safety event reporting software for hospitals](https://incidentkit.ai/solutions/hospitals) --- # Medication error > A medication error is a preventable event that may lead to wrong medication use or harm (NCC MERP). CMS adds its own wording for nursing homes. Source: https://incidentkit.ai/glossary/medication-error · Updated Oct 5, 2026 Also known as: med error, drug error ## How groups define it | Group | Definition | | --- | --- | | NCC MERP | A preventable event that may lead to wrong medication use or patient harm while the drug is under the control of a clinician, patient or consumer | | CMS (Appendix PP, F760) | Preparing or giving medication in a way that does not follow the prescriber's order, the maker's specifications (not suggestions), or accepted professional standards | | AHRQ PSNet | A mistake of doing or not doing, at any step from prescribing until the patient gets the drug | CMS adds 'significant': an error that causes discomfort or puts health and safety at risk. F760 requires that residents be free of significant errors. F759 covers the error rate: errors seen, divided by chances for error (doses given plus doses ordered but not given), times 100. A rate of 5 percent or more is cited, with no rounding up from 4.6. ## Error and drug event An adverse drug event is harm from taking a medication. It does not by itself mean an error. A preventable one comes from an error that reaches the patient and causes harm. A potential one is an error that causes no harm, caught or by chance. The NCC MERP index sorts errors by result, from category A to I. Example from CMS: a laxative left out for one day may cause little discomfort. If constipation lasts over three days, the error may be significant. A wrong-strength dose caught by a scan never reached the patient, so it is a [near miss](https://incidentkit.ai/glossary/near-miss). Mix-up: a medication error is not always harmful, and a harmful reaction is not always an error. Rate the result with a [harm scale](https://incidentkit.ai/glossary/harm-scale). ## Frequently asked questions ### What is a significant medication error? In CMS nursing home guidance, an error that causes discomfort or puts health and safety at risk. It depends on the resident, drug type and dose. It is cited at F760. ### How does CMS calculate a medication error rate? Errors seen divided by chances for error (doses given plus doses ordered but not given), times 100. A rate of 5 percent or more is cited at F759, with no rounding up. ### Is a missed dose a medication error? It can be. CMS's own example is a laxative left out for a day. Whether it is significant depends on the resident and the drug. ## Sources - [NCC MERP: About medication errors](https://www.nccmerp.org/about-medication-errors) - [CMS State Operations Manual, Appendix PP: Guidance to Surveyors for Long Term Care Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [AHRQ PSNet: Medication errors and adverse drug events (primer)](https://psnet.ahrq.gov/primer/medication-errors-and-adverse-drug-events) - [NCC MERP: Index for categorizing medication errors](https://www.nccmerp.org/types-medication-errors) - [HHS OIG: Adverse Events in Hospitals: National Incidence Among Medicare Beneficiaries (OEI-06-09-00090, November 2010)](https://oig.hhs.gov/oei/reports/oei-06-09-00090.pdf) ## Related terms - [Adverse event](https://incidentkit.ai/glossary/adverse-event) - [Near miss](https://incidentkit.ai/glossary/near-miss) - [Harm scale](https://incidentkit.ai/glossary/harm-scale) - [F-tag](https://incidentkit.ai/glossary/f-tag) - [Incident report](https://incidentkit.ai/glossary/incident-report) ## Related - [Medication Error Reporting: Steps, Severity and Follow-Up](https://incidentkit.ai/use-cases/medication-error-reporting) - [Medication Error Report Template (Printable Form)](https://incidentkit.ai/templates/medication-error-report) - [F760 significant medication errors: how surveyors cite it](https://incidentkit.ai/compliance/f-tags/f760) - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) - [Incident reporting software: forms, drafts, workflow](https://incidentkit.ai/product/incident-reporting) --- # Elopement > Elopement is when a patient or resident slips out of a facility without staff knowing, when supervision is needed. CMS cites it at F689. Source: https://incidentkit.ai/glossary/elopement · Updated Oct 5, 2026 Also known as: unauthorized departure, patient elopement, resident elopement ## How the term is used CMS guidance says a resident has eloped when they leave the building or a safe area without staff knowing, and supervision is needed. A resident who can make their own choices and leaves on purpose has generally not, unless staff do not know about it or where they are. If staff know, and the risks were explained, it is leaving against medical advice. Wandering is random or repeated movement that can come before elopement. The Joint Commission counts an elopement (unauthorized departure) as a [sentinel event](https://incidentkit.ai/glossary/sentinel-event) if it leads to death, permanent harm or severe harm. This covers settings staffed around the clock, including the emergency department. ## What CMS expects Facilities must find and assess residents at risk, watch them and put steps in the care plan. Alarms help but do not replace supervision, and they need scheduled upkeep and testing. The emergency plan should say how to find a missing resident. CMS names the risks: heat or cold exposure, dehydration, other medical problems, drowning and being hit by a vehicle. Poor supervision is cited at F689. Example: a resident with dementia and a record of exit-seeking leaves through a service door whose alarm was broken. Staff find the resident in the parking lot. That is an elopement and a likely [F689](https://incidentkit.ai/glossary/f-tag) finding. ## Frequently asked questions ### Is leaving against medical advice an elopement? No, under CMS guidance. If a resident leaves with the facility's knowledge, after the risks were explained, it is leaving against medical advice. Record the options offered, risks explained and when staff learned. ### Is every elopement a sentinel event? No. The Joint Commission counts it only when it leads to death, permanent harm or severe harm. Others are still safety events needing review. ### Do door alarms satisfy the requirement? No. CMS says alarms help but do not replace supervision. Staff must respond fast, and alarms need scheduled upkeep and testing. ## Sources - [CMS State Operations Manual, Appendix PP: Guidance to Surveyors for Long Term Care Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [Joint Commission: Sentinel Event Policy (SE chapter), Comprehensive Accreditation Manual, Update 1, July 2026](https://www.jointcommission.org/-/media/tjc/documents/resources/patient-safety-topics/sentinel-event/camncc_20_se_all_current.pdf) ## Related terms - [Sentinel event](https://incidentkit.ai/glossary/sentinel-event) - [F-tag](https://incidentkit.ai/glossary/f-tag) - [Immediate jeopardy](https://incidentkit.ai/glossary/immediate-jeopardy) - [Adverse event](https://incidentkit.ai/glossary/adverse-event) - [Harm scale](https://incidentkit.ai/glossary/harm-scale) ## Related - [F689 accidents and supervision: falls, hazards, devices](https://incidentkit.ai/compliance/f-tags/f689) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) - [Incident reporting software for assisted living](https://incidentkit.ai/solutions/assisted-living) - [Incident reporting software for behavioral health](https://incidentkit.ai/solutions/behavioral-health) - [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events) - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) --- # Pressure injury > A pressure injury is skin and tissue damage from steady pressure, often over a bone. CMS treats it as the same as a pressure ulcer and cites F686. Source: https://incidentkit.ai/glossary/pressure-injury · Updated Oct 5, 2026 Also known as: pressure ulcer, bedsore, decubitus ulcer, PU/PI ## Definition and stages CMS Appendix PP says clinicians may use pressure ulcer, pressure injury, pressure sore, decubitus ulcer or bed sore, as long as pressure is the main cause. It usually forms over a bony area or under a medical device, often with shear (skin dragged against a surface). An injury can show as intact skin, and an ulcer as an open wound. | Stage | CMS description (summarized) | | --- | --- | | Stage 1 | Redness of intact skin that does not fade when pressed | | Stage 2 | Partial loss of skin thickness, with the dermis (inner skin layer) showing | | Stage 3 | Full loss of skin thickness; fat may show | | Stage 4 | Full loss of thickness, with fascia, muscle, tendon, ligament, cartilage or bone showing | | Unstageable | Depth cannot be seen because dead tissue (slough or eschar) covers the wound | | Deep tissue | Deep red, maroon or purple color in intact skin that does not go away | ## The rule F686 (42 CFR 483.25(b)(1)) requires care that meets professional standards to prevent pressure ulcers. A resident must not develop one unless the clinical condition shows it was unavoidable. Residents who have one must get treatment to help it heal and to prevent infection and new ulcers. Mix-up: avoidable versus unavoidable. CMS calls an ulcer unavoidable only if the facility checked the risk, set steps that fit the resident's needs, goals and standards, monitored them and changed them as needed. Stage 2 should not describe moisture-related skin damage or skin tears. Example: a Stage 3 pressure injury is found two weeks after admission. The facility logs it as an incident, reviews the risk assessment and repositioning records, and brings it to its [QAPI](https://incidentkit.ai/glossary/qapi) review. ## Frequently asked questions ### Are pressure ulcer and pressure injury the same thing? CMS treats them as the same when pressure is the main cause. An injury can show as intact skin, and an ulcer as an open wound. Some clinicians use them for different looks. ### What makes a pressure injury unavoidable? Only if it developed even though the facility checked the resident's condition and risks, set fitting steps, monitored them and revised them as needed. ### Which F-tag covers pressure injuries? F686 (42 CFR 483.25(b)(1)), which requires prevention care and treatment. F689 (accidents) and F684 (quality of care) may be cited with it. ## Sources - [CMS State Operations Manual, Appendix PP: Guidance to Surveyors for Long Term Care Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_pp_guidelines_ltcf.pdf) - [CMS State Operations Manual, Chapter 7: Survey and Enforcement Process for Skilled Nursing Facilities and Nursing Facilities](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107c07pdf.pdf) ## Related terms - [F-tag](https://incidentkit.ai/glossary/f-tag) - [Adverse event](https://incidentkit.ai/glossary/adverse-event) - [Harm scale](https://incidentkit.ai/glossary/harm-scale) - [QAPI](https://incidentkit.ai/glossary/qapi) - [Deficiency](https://incidentkit.ai/glossary/deficiency) ## Related - [F684 quality of care: what it covers and how it is cited](https://incidentkit.ai/compliance/f-tags/f684) - [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) - [Hospice incident reporting software for field teams](https://incidentkit.ai/solutions/hospice) - [Home health incident reporting software for field staff](https://incidentkit.ai/solutions/home-health) - [Always Survey-Ready: Stay Prepared for Unannounced Surveys](https://incidentkit.ai/use-cases/always-survey-ready) --- # ASC incident report template > A one-to-two page incident report for surgery centers. It records the patient, procedure, phase of care and harm level. It also logs who was told and when, plus a first review that feeds QAPI. Staff fill in the facts during the shift. The manager decides how deep to investigate. Source: https://incidentkit.ai/templates/asc-incident-report · Updated Oct 5, 2026 ## When to use it - A patient is hurt, or nearly hurt, before, during or after a procedure: a fall, burn or drug event. - A surgical safety event: wrong site, side, patient, procedure or implant, a retained item, or a count that does not match. - A patient is sent to a hospital, or admitted, unexpectedly after the procedure. - Equipment fails while in use on a patient, including events that may need an FDA report. - A near miss: an error caught at the time-out, count or scan, before it reached the patient. ## The template ### 1. Event details - Facility and location (Room or area, such as OR 2, PACU bay 4 or pre-op.) - Date of event - Time of event (Your best guess is fine. Say so in the story.) - Time the event was found (Leave blank if the same. A count error found in recovery is later.) - Event type (Pick the closest fit. Add detail in the story.): Fall / Burn or fire / Medication event / Wrong site, side, patient, procedure or implant / Retained item or count mismatch / Positioning or pressure injury / Equipment or device event / Unplanned transfer or admission / Infection concern / Anesthesia or airway event / Specimen event / Behavior or security / Other - Reported by (name and role) ### 2. Patient and procedure - Patient name or medical record number (Use only what policy allows. Treat this page like a chart.) - Patient date of birth - Scheduled procedure - Procedure done, if different - Proceduralist and anesthesia provider (Names or roles, per policy. The review looks at the system.) - Anesthesia type: None or local only / Moderate sedation or MAC / Regional or neuraxial / General / Not applicable - ASA physical status: I / II / III / IV / Not recorded ### 3. Where in the case it happened - Phase of care: Scheduling or pre-arrival / Registration and pre-op / Time-out and prep / Procedure / Emergence from anesthesia / PACU or phase II recovery / Discharge / After discharge (call-back or return) / Non-patient area - Time-out done before the procedure?: Yes / No / Not applicable - Counts (sponge, sharps, instruments) matched at close? (If off, record who was told, how it was settled, and any imaging.): Yes / No: see story / Not applicable - Equipment or device involved (Name, model, serial or lot number. Tag it and pull it from use.) - Medication, implant or specimen involved - Did the event reach the patient? (Report near misses too. They show a safeguard that worked.): Yes / No: caught before it reached the patient (near miss) ### 4. What happened - Description of the event (What you saw and did, in order. Facts only, no blame.) - Immediate actions taken (Care given, equipment secured, procedure stopped or finished, who was called.) - Patient condition after the event (Vital signs, symptoms, exam findings and any change from before.) - Witnesses and others present (Name and role. Collect written statements apart from this form.) ### 5. Outcome and harm - Harm level (Use your harm scale, such as AHRQ Common Formats. Re-rate if the patient changes.): No harm / Mild harm / Moderate harm / Severe harm / Death - Additional care needed: None / Extra monitoring only / Treatment in the ASC / Delayed discharge / Unplanned transfer to a hospital / Unplanned hospital admission after discharge / Repeat or corrective procedure - Receiving hospital and transfer time (Record call time, handoff and who accepted. CMS expects ASCs to track every transfer.) - Possible sentinel or serious reportable event (If yes, tell the administrator and risk lead now. Start a root cause analysis. Check state rules.) - Possible device-related death or serious injury (ASCs are device user facilities. Report deaths to the FDA and maker, and serious injuries to the maker, in 10 work days (21 CFR 803.30).) ### 6. Notifications - Administrator or medical director told (name, date, time) - Surgeon or attending physician told (name, time) - Patient or representative informed (who, by whom, date, time) (Write what was said and how the patient responded. Follow your disclosure policy.) - Risk manager or quality lead told (name, date, time) - External reports made (state, accreditor, insurer, FDA) (Write 'none' if none. Deadlines differ by state: check yours.) ### 7. Initial review (manager) - Conditions seen that may have helped cause it (List conditions, not people: staffing, schedule pressure, equipment, labeling, handoff, layout.) - Preventable?: Likely yes / Maybe / No / Not sure: needs investigation - Investigation level: Manager review / Focused investigation / Full root cause analysis - Investigation owner and due date - Added to the QAPI event log ### 8. Sign-off - Completed by (name and title) - Signature of person completing the report - Manager or administrator review - Date reviewed ## How to fill it out well 1. Finish sections 1 to 4 before the shift ends. The manager completes sections 5 to 7. 2. Write what you saw: times, what was said, what equipment was in use. Skip guesses about why. 3. Record time-out and count status even when normal. They show which safeguards ran. 4. Secure the equipment, implants, vials and packaging. Tag any device and keep it out of use. 5. Chart clinical facts in the medical record. Keep this report separate. Ask counsel how your state treats incident reports. 6. Send it to the risk or quality lead within your policy window. Set the investigation level that day. ## Tips - Report near misses too. CMS expects ASCs to find errors caught before harm, since they signal future events. - Track every hospital transfer. CMS calls a single transfer a serious, unplanned outcome worth review. - Count events by phase of care each quarter. A cluster shows a weak safeguard. - Write conditions, not people. 'Count not matched before closing' says more than a name. ## Frequently asked questions ### What is an incident report in a surgery center? A same-day, factual record of an event that harmed or could have harmed a patient, visitor or staff member. It starts a review and feeds QAPI. Clinical facts stay in the medical record. ### Does CMS require ambulatory surgery centers to track incidents? In effect, yes. 42 CFR 416.43 requires an ASC to track adverse patient events, study causes and make improvements last. CMS says to at least track hospital transfers. Accreditors like AAAHC review these programs too. ### Which events does CMS give as examples of ASC safety indicators? CMS Appendix L lists patient burn, hospital transfer or admission, patient fall, wrong site, side, patient, procedure or implant, and timely prophylactic antibiotics. Centers may add other measures, and should add infection control. ### Do surgery centers report device problems to the FDA? Yes. Surgery centers are 'device user facilities' (21 CFR 803.3). Report device-related deaths to the FDA and the maker, and serious injuries to the maker (or the FDA if unknown), within 10 work days. ### How does this template work in IncidentKit? Staff describe the event by text. Lauren asks follow-up questions and drafts the fields, marked 'Lauren · draft' until a person reviews, edits and signs. The [surgery center pack](https://incidentkit.ai/solutions/ambulatory-surgery-centers) sets forms, routing and QAPI summaries. ## Sources - [eCFR: 42 CFR 416.43, Quality assessment and performance improvement (ASC)](https://www.ecfr.gov/current/title-42/section-416.43) - [CMS State Operations Manual, Appendix L: Guidance for Surveyors, Ambulatory Surgical Centers](https://cms.hhs.gov/Regulations-and-Guidance/Guidance/Manuals/Downloads/som107ap_l_ambulatory.pdf) - [eCFR: 21 CFR 803.30, Individual adverse event reports: user facilities](https://www.ecfr.gov/current/title-21/section-803.30) - [AHRQ PSNet: Reliability of AHRQ Common Format Harm Scales in rating patient safety events](https://psnet.ahrq.gov/issue/reliability-ahrq-common-format-harm-scales-rating-patient-safety-events) - [AAAHC: Accreditation](https://www.aaahc.org/accreditation/) ## Related - [Incident reporting software for surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [AAAHC accreditation: surveys, deemed status and QI studies](https://incidentkit.ai/compliance/accreditation/aaahc) - [Medical device reporting for user facilities: 21 CFR 803](https://incidentkit.ai/compliance/reporting-deadlines/device-adverse-event-reporting) - [Replace Paper Incident Forms: A Practical Switch Plan](https://incidentkit.ai/use-cases/replace-paper-incident-forms) - [Root Cause Analysis Worksheet (5 Whys Template)](https://incidentkit.ai/templates/root-cause-analysis-worksheet) --- # Nursing home incident report template > A nursing home incident report built around what surveyors check. It covers resident and family notice, physician contact, protective steps and the five-working-day result. An abuse and unexplained-injury screen ties to the two-hour and 24-hour clocks. Use it for falls, elopements, skin injuries, fights between residents and other events. Source: https://incidentkit.ai/templates/nursing-home-incident-report · Updated Oct 5, 2026 ## When to use it - A resident has an accident, fall, injury, elopement, choking episode or other surprise event. - An injury is found and no one knows how. It may be an injury of unknown source. - A resident, family member or staff member alleges, or you suspect, abuse, neglect, exploitation, mistreatment or missing property. - A fight between residents, or a behavior event, puts a resident at risk. - A change in condition after an event needs physician and family notice, with times. ## The template ### 1. Resident and event - Resident name, room and unit - Resident ID or medical record number - Date of event - Time of event - Time found, if different (Key for unwitnessed events.) - Where it happened: Resident room / Bathroom / Hallway / Dining room / Therapy area / Outdoors or courtyard / Transport vehicle / Other - Event type: Fall or near-fall / Injury of unknown source / Skin tear or other injury / Elopement or missing resident / Choking or aspiration / Medication event / Resident-to-resident incident / Alleged abuse, neglect or mistreatment / Missing property / Equipment or environmental hazard / Behavior or self-harm / Other ### 2. Abuse and reporting screen - Is there an allegation or suspicion of abuse, neglect, exploitation, mistreatment or theft of property? (If yes, call the administrator now. Finish this form later. Federal rules (42 CFR 483.12(c)(1)) give 2 hours from the allegation for abuse or serious bodily injury, and 24 hours otherwise.): Yes / No / Unsure: ask the administrator before continuing - Is this an injury of unknown source? (All three: no one saw it, the resident cannot explain it, and it looks suspicious (size, place or number).): Yes: all three criteria apply / No / Not an injury - Serious bodily injury? (CMS: extreme pain, major risk of death, long loss of function, or injury needing surgery, hospital care or rehab.): Yes / No / Unknown - Date and time the allegation was made or the suspicion formed (This starts the reporting clock. Limits run on real clock time, not business hours.) - Reported to administrator (name, date, time) - Reported to State Survey Agency, adult protective services or law enforcement (agency, date, time, confirmation number) (A suspected crime has 2-hour and 24-hour limits too. State rules may be shorter.) - Resident protected from further harm while the investigation is open (Separate the people involved, change assignments or add supervision (42 CFR 483.12(c)(3)).) ### 3. What happened - Description of the event (What you saw, heard and did, in order. Quote the resident. No opinions.) - Witnessed?: Witnessed / Unwitnessed: resident found / Unknown - Last time the resident was seen before the event, and by whom (Needed for any unwitnessed event.) - Staff and others present or nearby - Resident's explanation, if any (Use their words. If they cannot explain, say why.) ### 4. Resident condition and injury - Injuries found (location, size, color, description) (Measure in cm. Note bruises, skin tears, swelling, deformity and pain on movement.) - Injury level: None / Minor: first aid only / Moderate: needs a doctor's exam or treatment / Major: fracture, head injury or hospital transfer / Death - Vital signs and pain score after the event - Mental status compared with usual (A change may need immediate notice.): Same as usual / Changed: describe in the story - Treatment given - Transferred to hospital?: No / Yes: emergency / Yes: scheduled evaluation ### 5. Notifications - Physician or nurse practitioner notified (name, date, time, orders received) (You must consult the physician right away for an accident with injury that may need physician care (42 CFR 483.10(g)(14)).) - Resident representative or family notified (name, relationship, date, time, by whom) (The same rule covers the representative. Record every try if you cannot reach them.) - Resident informed in terms they can understand - Director of nursing notified (date, time) - Medical director notified, if indicated (date, time) - Other state or local reports (state incident reporting, ombudsman) (States set their own rules and deadlines. Check yours.) ### 6. Immediate actions and care plan - Immediate actions taken - Interim safety measures started today (Say what changed now: supervision, device, room, toileting schedule, bed height.) - Care plan updated - Risk assessment updated (fall, elopement, skin or behavior) - Staff briefed (shift, date) ### 7. Investigation - Investigation lead and start date - Findings: contributing conditions (List system conditions, not blame. Keep fact apart from opinion.) - Conclusion: Violation confirmed / Violation not confirmed / Accident: avoidable / Accident: unavoidable / Still under review - Date results reported to administrator and State Survey Agency (Due within 5 working days of the incident (42 CFR 483.12(c)(4)). If a violation is verified, corrective action is required.) - Corrective action taken or planned (owner and due date) - Entered in the QAA/QAPI event log ### 8. Sign-off - Completed by (name and title) - Signature of person completing the report - Director of nursing or administrator review - Date reviewed ## How to fill it out well 1. If abuse or an unexplained injury is possible, start at section 2. Call the administrator first. 2. Record clock times, not just dates. The 2-hour and 24-hour limits run from the moment of the allegation. 3. Quote the resident's own words and note who was there. Report abuse allegations before judging if they are credible. 4. Document every notice try, including unanswered calls, with the time. 5. Write interim safety steps the same day. The care plan update should match what staff do. 6. Keep witness statements, findings and corrective action together so the five-working-day report is easy to send. 7. Give the completed report to the director of nursing or administrator by the end of the shift. ## Tips - Report an allegation first, then investigate. CMS says do not judge if it is credible before reporting. - A fall without injury is still a fall. CMS counts a resident found on the floor as a fall unless evidence shows otherwise. - Review events by shift, location and time of day. The QAA committee needs to see patterns. - Use the [fall incident report](https://incidentkit.ai/templates/fall-incident-report) for extra fall detail: footwear, device, activity and the post-fall huddle. ## Frequently asked questions ### How fast must a nursing home report suspected abuse? Under 42 CFR 483.12(c)(1), report abuse, or an allegation with serious bodily injury, within 2 hours. Report neglect, exploitation or theft without serious bodily injury within 24 hours. Tell the administrator and State Survey Agency, plus others under state law. Results are due in 5 working days. ### What is an injury of unknown source? CMS uses the term when three things are true. No one saw how it happened. The resident could not explain it. And it looks suspicious by size, place (an area not usually hurt) or number. It is treated as an alleged violation, on the same clocks. ### Who must be notified when a resident has an accident? If an accident causes injury that may need a physician, act right away (42 CFR 483.10(g)(14)). Tell the resident, consult the physician and notify the resident representative. The same goes for a significant change in condition, a major treatment change, or a transfer or discharge decision. ### Who has to report a suspected crime against a resident? Covered individuals must report a reasonable suspicion of a crime against a resident to the State Agency and local police. They are the owner, operator, employee, manager, agent or contractor of a federally funded long-term care facility. The limit is 2 hours with serious bodily injury, 24 hours without. Facilities must tell them of this duty yearly. ## Sources - [eCFR: 42 CFR 483.12, Freedom from abuse, neglect, and exploitation](https://www.ecfr.gov/current/title-42/section-483.12) - [eCFR: 42 CFR 483.10, Resident rights (notification of changes, paragraph (g)(14))](https://www.ecfr.gov/current/title-42/section-483.10) - [CMS State Operations Manual, Appendix PP: Guidance to Surveyors for Long Term Care Facilities (F580, F609, F610, F689)](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [eCFR: 42 CFR 483.25, Quality of care (accidents, paragraph (d))](https://www.ecfr.gov/current/title-42/section-483.25) ## Related - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) - [Nursing home abuse reporting: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/reporting-deadlines/abuse-and-neglect-reporting) - [F609 reporting alleged violations: 2-hour and 24-hour rules](https://incidentkit.ai/compliance/f-tags/f609) - [F689 accidents and supervision: falls, hazards, devices](https://incidentkit.ai/compliance/f-tags/f689) - [Abuse Reporting Deadlines for Nursing Homes: 2 and 24 Hours](https://incidentkit.ai/use-cases/abuse-reporting-deadlines) - [Fall Incident Report Template for Healthcare (Printable)](https://incidentkit.ai/templates/fall-incident-report) --- # Fall incident report template > A fall incident report that records what surveyors and post-fall reviews ask for. It covers witnessed or not, what the person was doing, footwear and device, injury and head strike, and notifications with times. It ends with a short post-fall huddle that feeds the care plan. Use it for falls, near-falls and found-on-floor events. Source: https://incidentkit.ai/templates/fall-incident-report · Updated Oct 5, 2026 ## When to use it - A patient or resident comes to rest on the floor or a lower surface by accident, with or without injury. - A near-fall: the person lost balance and was caught, by staff or by themselves, before falling. - A person is found on the floor and no one saw what happened. - You need a record for the post-fall huddle and the care plan update. - The QAPI committee wants falls tracked by location, shift, time of day and activity. ## The template ### 1. Person and event - Patient or resident name and ID - Date of fall - Time of fall - Time found (May be all you know for an unwitnessed fall.) - Exact location (Be specific: 'beside bed, window side' says more than 'room 14'.) - Shift: Day / Evening / Night - Witnessed or unwitnessed: Witnessed by staff / Witnessed by visitor or another patient / Unwitnessed: found on floor / Near-fall: prevented by staff or the person ### 2. Before the fall - Pre-fall activity (Ask what they were trying to do. Reaching and toileting are common.): Walking / Transferring (bed, chair or commode) / Toileting / Getting out of bed / Standing from a chair / Reaching for an object / Being assisted by staff / Showering or bathing / Sitting or lying in bed or chair / Unknown / Other - Footwear: Non-skid shoes or socks / Regular shoes / Slippers / Socks without grips / Barefoot / Other - Assistive device (Say if a device was ordered but out of reach.): None needed / Walker / Cane / Wheelchair / Gait belt with staff / Mechanical lift / Ordered but not in use or not within reach / Other - Most recent fall risk score, tool and date (Use your site's tool, such as the Morse Fall Scale or Hendrich II.) - Call light was within reach and working - Bed, chair or other position-change alarm was in use (Alarms do not replace enough supervision.) - Medications in the last 24 hours that may raise fall risk (Note sedatives, opioids, blood pressure drugs, diuretics, blood thinners and dose changes.) - Environment at the time (Lighting, floor, spills, clutter, bed height, brakes, cords. Look before tidying.) ### 3. What happened - Narrative (What you saw and did. Facts only.) - The person's own account of the fall (Use their words. If they cannot say, write why: confusion, sedation, aphasia.) - Mechanism (Choose what the person or a witness described. 'Unknown' is a valid answer.): Slip / Trip / Loss of balance / Legs gave way / Dizzy or fainted / Slid from bed or chair / Assisted to the floor by staff / Unknown - Witnesses (name and role) ### 4. Injury and assessment - Injury level: None / Minor: scrape, bruise or skin tear / Moderate: needs sutures, splint or treatment / Major: fracture, dislocation, head injury or bleed / Death - Injuries found (body location, size, description) - Head strike or possible head strike (Many policies assume a head strike if the fall was unwitnessed.) - Neuro checks started per policy (Record the start time. Frequency follows your protocol.) - Takes a blood thinner (anticoagulant or antiplatelet) (Tell the physician. It raises the stakes after a head strike.) - Vital signs and pain score, with lying and standing blood pressure if safe (Orthostatic hypotension (low blood pressure on standing) is a common, fixable cause. CDC STEADI checks for it.) - Was the person moved before assessment? (Check for injury before moving. Use a lift if a fracture is suspected.): No: assessed where found / Yes: helped up after assessment / Yes: moved before assessment ### 5. Notifications - Physician or provider notified (name, time, orders received) - Family or representative notified (name, time) (If you cannot reach someone, record each try and its time.) - Supervisor or charge nurse notified (name, time) - Risk manager or administrator notified (name, time) (Tell leaders at once for a major injury, a death or an unexplained injury.) - Hospital or emergency transfer (facility, time, mode) - Possible sentinel event: fracture, surgery or casting, brain, nerve or internal injury needing care, or death or permanent harm (The Joint Commission counts these falls as sentinel events if the injuries come from the fall itself. Start a full analysis.) ### 6. Immediate actions - Care and treatment given - Equipment checked (bed brakes, wheelchair locks, call light, alarms) - Care plan updated - Fall risk reassessed - Interim safety measures put in place today (Examples: toileting schedule, bed in lowest position, non-skid footwear, closer watch, medication review.) ### 7. Post-fall huddle - Huddle date - Participants (roles) - Why did the person fall? Ask why until you reach something you can change. (Example: 'reaching for the call light', then 'light out of reach', then 'no bed set-up check'.) - Contributing factors (patient, task, environment, equipment, staffing, medication) (Write 'not a factor' where none applies.) - Was the fall avoidable?: Likely yes / Maybe / No: it happened despite safeguards / Not sure - Follow-up actions (what, owner, due date) - Date to check the actions are working ### 8. Sign-off - Completed by (name and title) - Signature of person completing the report - Nurse manager or director of nursing review - Date reviewed ## How to fill it out well 1. Check for injury before anyone moves the person. Fill in the form once the person is safe. 2. Record witnessed or unwitnessed honestly. If no one saw it, say what was found and when the person was last seen. 3. Note footwear, device, call light and the room as they were, before it is tidied. 4. Record every notice with a time, and every failed try to reach family. 5. Complete a report even with no injury. A fall without injury is still a fall. 6. Hold a short huddle with the people there. Agree one or two changes you can make and give each an owner. ## Tips - Use one fall definition on all units. CMS counts coming to rest on the ground, floor or a lower level by accident, plus a stopped lost-balance episode. - Ask why twice. 'Reaching for the call light' is where the question starts, not ends. - Review falls by time of day and location. CMS surveyor guidance names both. - Prefer fixes that change the setup, like bed height, lighting or layout, over reminders. The [root cause analysis worksheet](https://incidentkit.ai/templates/root-cause-analysis-worksheet) ranks actions by strength. - Position-change alarms can help, but CMS says they do not remove the need for enough supervision. ## Frequently asked questions ### What counts as a fall? CMS: unintentionally coming to rest on the ground, floor or other lower level, not from an overwhelming outside force. A lost-balance episode that someone or something stopped counts. A resident found on the floor is treated as having fallen unless evidence shows otherwise. ### Does a fall without injury need an incident report? Yes. Falls without injury are the best early warning. They show where and when falls happen before anyone is hurt, and they feed the risk assessment and care plan. QAPI committees track all falls. ### What should a fall incident report include? Date, time and place. Witnessed or not. Activity, footwear and device. Call light and alarms. Risk medications. Injury and head strike. Vital signs. Notifications with times. Immediate actions. Care plan changes. This form covers each. ### When is a fall a sentinel event? For Joint Commission sites staffed around the clock, a fall counts when it causes a fracture. It also counts if it needs surgery, casting or traction, care for a brain, nerve or internal injury, or blood products for a clotting disorder, or if it causes death or permanent harm. Every sentinel event needs a full analysis, reported or not. ### What is the difference between an avoidable and an unavoidable accident? CMS calls an accident avoidable when the facility failed to find hazards or assess risk. It is also avoidable if the facility did not act on them, carry out steps like supervision and devices, or check that the steps worked. It is unavoidable when it happened despite all four. The huddle section records this call. ## Sources - [CMS State Operations Manual, Appendix PP: F689, Accidents (definitions and guidance)](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [eCFR: 42 CFR 483.25, Quality of care (paragraph (d), accidents)](https://www.ecfr.gov/current/title-42/section-483.25) - [CDC: STEADI clinical resources for fall prevention](https://www.cdc.gov/steadi/hcp/clinical-resources/index.html) - [The Joint Commission: Sentinel Event Policy (Comprehensive Accreditation Manual, SE chapter)](https://www.jointcommission.org/-/media/tjc/documents/resources/patient-safety-topics/sentinel-event/camncc_20_se_all_current.pdf) - [AHRQ PSNet: Preventing Falls in Hospitals toolkit](https://psnet.ahrq.gov/issue/preventing-falls-hospitals-toolkit-improving-quality-care) ## Related - [Fall Reporting: What to Record and Review After a Fall](https://incidentkit.ai/use-cases/fall-reporting) - [F689 accidents and supervision: falls, hazards, devices](https://incidentkit.ai/compliance/f-tags/f689) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) - [Patient safety event reporting software for hospitals](https://incidentkit.ai/solutions/hospitals) - [Root Cause Analysis Worksheet (5 Whys Template)](https://incidentkit.ai/templates/root-cause-analysis-worksheet) - [Root cause analysis: definition and meaning](https://incidentkit.ai/glossary/root-cause-analysis) --- # Medication error report template > A medication error report that records the drug, dose and route as ordered and as given. It shows which rights were missed, the step where it went wrong, the NCC MERP harm category, contributing factors and who was told. It supports a no-blame review: the goal is the system weakness, not the person. Source: https://incidentkit.ai/templates/medication-error-report · Updated Oct 5, 2026 ## When to use it - A wrong drug, dose, route, time, patient or form reached a patient or resident. - A dose was missed, late, doubled or given with no valid order, or a pump was set to the wrong rate or strength. - An error was caught before it reached the patient, such as by a pharmacist or a barcode alert. - A nursing home resident has an error that may be a significant medication error under CMS guidance (F760). - An adverse drug event happened and an error may have played a part. ## The template ### 1. Report and patient - Date of error - Time of error - Time found - Unit or setting - Patient or resident name and ID - Weight (kg) (Needed to spot weight-based and children's dosing errors.) - Allergies and relevant lab values (Include kidney function, INR, potassium or drug levels if they matter.) - Where in the medication-use process did it begin? (Pick where it began, not where it was found.): Ordering or prescribing / Transcribing or order entry / Dispensing or preparation / Administration / Monitoring / Not sure ### 2. The medication - Medication ordered (name and strength) (Copy from the order, not memory. Use generic names.) - Dose, route and frequency ordered - Medication given or dispensed (name and strength) - Dose, route and rate actually given - High-alert medication? (Use your group's list. ISMP publishes a model list.): Yes / No / Not sure - Look-alike or sound-alike names or packaging involved? (If yes, name the pair in the story.): Yes / No / Unknown - Lot number and expiration, if product-related (Keep the vial, bag or package.) ### 3. Which rights were missed - Right patient (Check every right that applies. Most errors miss more than one.) - Right drug - Right dose - Right route - Right time (late, early or omitted dose) - Right documentation - Other: wrong rate, strength or form, expired product, or missing monitoring (Describe it in the story.) ### 4. What happened - Description of the error (What you saw and did, in order. Facts only, no blame.) - How it was found: Nurse or pharmacist check / Barcode scan alert / Pump alert or drug library / Patient or family noticed / Chart review or reconciliation / Patient's condition changed / Other - Immediate actions taken (Patient assessed, prescriber and pharmacist called, antidote or monitoring ordered, product secured.) - Others involved or present (roles) - Pump history, scan log or order audit trail saved (These show what the systems recorded at the time.) ### 5. Outcome and harm - Did the error reach the patient?: No: caught before reaching the patient / Yes - NCC MERP category (Choose by result. Re-rate if it changes. B to D: no harm. E to H: harm. I: death.): A: circumstances that could cause an error / B: error occurred but did not reach the patient / C: reached the patient, no harm / D: reached the patient, needed monitoring or intervention to preclude harm / E: temporary harm, required intervention / F: temporary harm, required initial or prolonged hospitalization / G: permanent harm / H: required intervention to sustain life / I: may have contributed to or resulted in death - Effects on the patient and monitoring ordered - Antidote or rescue treatment given - Possible significant medication error (nursing homes) (CMS: an error that causes discomfort or puts health and safety at risk. Weigh the resident's condition, the drug type (narrow therapeutic index drugs like warfarin, digoxin, lithium, phenytoin) and repeats.) - Has this happened before?: First time I know of / Repeat: same drug or process / Unknown ### 6. Contributing factors - Look-alike or sound-alike drug names, labels or packaging (Check what applies. These are system conditions, not blame.) - Interruption or distraction during preparation or giving - Workload, staffing or time pressure - Order unclear, incomplete or entered wrong, or a handoff or transcription gap - Barcode scan skipped or down, or a pump or drug library issue - Unfamiliar drug, new process or training gap - Other factors and what the review found ### 7. Notifications and follow-up - Prescriber notified (name, time, orders received) - Pharmacist notified (name, time) - Patient or family told (who, by whom, time) (Say what happened, what is being done and who to call. Follow your disclosure policy.) - Nurse manager, director of nursing or risk manager notified (name, time) - External report, if made (ISMP, FDA MedWatch, PSO, state) (Voluntary programs exist for medication errors. Follow your policy. Write 'none' if none.) - Prevention action proposed (what, owner, due date) (Prefer a system change, like standard strengths, storage changes or barcode checks.) - Review level: Manager review / Medication safety or pharmacy and therapeutics committee / Full root cause analysis ### 8. Sign-off - Completed by (name and title) - Signature of person completing the report - Manager or pharmacist review - Date reviewed ## How to fill it out well 1. Care for the patient first: assess, call the prescriber and act on orders. Fill in the report once the patient is safe. 2. Copy the order and what was given from source records: the MAR, label, pump history or scan log. Not from memory. Keep the packaging. 3. Check every right that was missed, then the contributing factors. Describe conditions in the system. 4. Pick the NCC MERP category from the result. Re-rate it if the patient's condition changes. 5. Report errors that were caught and errors that caused no harm. They are the cheapest lessons you will get. 6. Send the report to the pharmacist and manager. Send errors with harm for formal review as your policy says. ## Tips - Many groups set review depth by NCC MERP category: a quick look for B to D, a formal review for E and above. Write the rule down. - Look for repeats by drug, unit, shift and step. One error is an event. Three in one place is a pattern. - Prefer system fixes. IHI ranks forcing functions, simpler processes and standard equipment above double checks, warnings and training. - Nursing home surveyors figure an error rate from medication pass observation (5% or more is cited). They cite any significant error on its own. ## Frequently asked questions ### What is a medication error? NCC MERP says it is any preventable event that may cause or lead to wrong medication use or patient harm. This is while the drug is under the control of a health care professional, patient or consumer. It can happen at any step from prescribing to monitoring. ### What is the NCC MERP index? A nine-category index, A to I, that rates an error by result. A could cause an error. B did not reach the patient. C and D reached the patient without harm. E to H involve rising harm. I may have contributed to death. Revised in 2022. ### What is the difference between a medication error and an adverse drug event? An adverse drug event is harm from taking a medication. A medication error is a mistake from ordering to giving. AHRQ PSNet notes an adverse drug event does not always mean an error, and about half are preventable. A good report captures both. ### What is a significant medication error in a nursing home? CMS guidance: it causes the resident discomfort or puts health and safety at risk. It depends on the resident's condition, the drug type and how often it happens. Surveyors cite any significant error at F760, and F759 when the medication pass error rate is 5% or higher. ### Should I name the staff member involved? Record roles as your policy requires, but write about conditions: the order, label, workload, device. IHI's RCA2 guidance says reviews should not focus on individual performance. Conduct your group calls blameworthy belongs in a separate HR process. ## Sources - [NCC MERP: About medication errors (definition)](https://www.nccmerp.org/about-medication-errors) - [NCC MERP: Index for Categorizing Medication Errors (2022)](https://www.nccmerp.org/sites/default/files/index-bw-2022.pdf) - [AHRQ PSNet: Medication errors and adverse drug events (primer)](https://psnet.ahrq.gov/primer/medication-errors-and-adverse-drug-events) - [CMS State Operations Manual, Appendix PP: F760, Residents are free of significant medication errors](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) - [ISMP: List of High-Alert Medications in Acute Care Settings](https://home.ecri.org/blogs/ismp-resources/high-alert-medications-in-acute-care-settings) - [IHI: RCA2, Improving Root Cause Analyses and Actions to Prevent Harm](https://www.ihi.org/library/tools/rca2-improving-root-cause-analyses-and-actions-prevent-harm) - [IHI Patient Safety Essentials Toolkit: Action Hierarchy (part of RCA2), as hosted by the Minnesota Department of Health](https://www.health.mn.gov/facilities/patientsafety/adverseevents/toolkit/docs/safetytoolkit_actionhierarchy.pdf) ## Related - [Medication Error Reporting: Steps, Severity and Follow-Up](https://incidentkit.ai/use-cases/medication-error-reporting) - [Medication error: definition and meaning](https://incidentkit.ai/glossary/medication-error) - [F760 significant medication errors: how surveyors cite it](https://incidentkit.ai/compliance/f-tags/f760) - [Incident reporting software for skilled nursing facilities](https://incidentkit.ai/solutions/skilled-nursing-facilities) - [Patient safety event reporting software for hospitals](https://incidentkit.ai/solutions/hospitals) - [Root Cause Analysis Worksheet (5 Whys Template)](https://incidentkit.ai/templates/root-cause-analysis-worksheet) --- # Workplace injury report template > A workplace injury and illness report that collects what OSHA Form 301 asks for. That is the employee, the treating provider, what the employee was doing, what happened, the injury, and the object or substance involved. It adds cause, treatment, a recordability screen and corrective action. It is an internal form, not the OSHA form. Source: https://incidentkit.ai/templates/workplace-injury-report · Updated Oct 5, 2026 ## When to use it - An employee reports a work injury or illness, even a first-aid case, so you can decide if it is recordable. - You need the supporting record for an entry on the OSHA 300 Log. - A needlestick, sharps injury, patient-handling strain, slip, trip, fall, chemical exposure or workplace violence event occurs. - You want one internal form that can stand in for OSHA Form 301 and feed workers' compensation reporting. - A death, in-patient hospital stay, amputation or loss of an eye means a call to OSHA within 8 or 24 hours. ## The template ### 1. Employee - Employee full name (Form 301 collects name, address, birth date, hire date and sex. This section covers all five.) - Home address (street, city, state, ZIP) - Date of birth - Date hired - Sex (OSHA Form 301 offers male or female.): Male / Female - Job title, department and supervisor - Employment status (Whoever supervises a temporary or leased worker day to day records the case (29 CFR 1904.31). Agree with the staffing firm.): Employee on payroll / Temporary or leased worker you supervise day to day / Temporary or leased worker supervised by the staffing firm / Contractor or visitor (not an employee) ### 2. Treating provider - Physician or other health care professional who treated the employee - If treated away from the worksite: facility name and address - Treated in an emergency room?: Yes / No - Hospitalized overnight as an in-patient? (An in-patient stay also starts the 24-hour clock for calling OSHA (29 CFR 1904.39).): Yes / No - Date of first treatment ### 3. Case information - Case number from the OSHA 300 Log (Enter it after the case is on the Log.) - Date of injury or illness - Time the employee began work (Hours into the shift show fatigue and handover patterns over time.) - Time of the event - Time of the event cannot be determined - Exact location (area, department or off-site address) ### 4. What happened - What was the employee doing just before the incident? (Describe the task and tools. Be specific: 'repositioning a resident in bed with one helper', not 'patient care'. Leave out names, phone numbers and Social Security numbers, as OSHA asks.) - What happened? (Tell how it happened, in order: what slipped, moved or failed, and what the employee did.) - What was the injury or illness? (Body part and how: 'strained lower back', 'cut, left index finger', 'chemical burn, hand'.) - What object or substance directly harmed the employee? (A concrete floor, a scalpel, a chlorine solution, a resident's arm. Leave blank if none.) - Body part: Head or face / Eye / Neck / Shoulder / Upper back / Lower back / Arm or elbow / Wrist or hand / Finger / Hip or groin / Leg or knee / Ankle or foot / Multiple body parts / Body systems (illness or exposure) - Nature of injury or illness: Strain or sprain / Cut or laceration / Puncture or needlestick / Bruise or contusion / Fracture / Burn (heat or fire) / Chemical burn or exposure / Amputation / Hearing loss / Respiratory condition / Skin condition / Infection or bloodborne exposure / Psychological / Other - If the employee died, date of death (A work-related death must be reported to OSHA within 8 hours.) ### 5. Cause and context - Event type: Slip, trip or fall / Overexertion or lifting / Patient or resident handling / Struck by or against an object / Caught in or between / Cut, puncture or needlestick / Contact with a chemical / Workplace violence / Vehicle or powered equipment / Heat, burn or fire / Electrical / Repetitive motion or ergonomic / Illness or exposure / Other - Equipment, machine, tool or substance (asset ID or SDS name) (Add the asset tag or serial number. For a machine, record its lockout/tagout status.) - Personal protective equipment: Not required / Required and worn / Required, not worn / Required, worn incorrectly / Required, not available - Task training documented?: Yes / No / Unknown - A guard, interlock or other safety device was bypassed or missing - Conditions at the scene (Wet floor, lighting, noise, clutter, staffing level, time pressure. List conditions, not blame.) - Witnesses (name and contact) ### 6. Treatment and work status - Highest level of care (First aid is a closed list (29 CFR 1904.7): non-prescription medicine at non-prescription strength, tetanus shots, wound cleaning, bandages (not stitches or staples), hot or cold therapy, and a few more. Anything else is medical treatment.): None / First aid only / Medical treatment beyond first aid / Emergency care / Hospital admission - Treatment, medication or procedures ordered - Loss of consciousness?: Yes / No - Diagnosed as a fracture, cracked bone, punctured eardrum, cancer or chronic irreversible disease (A diagnosis by a doctor or licensed professional makes the case recordable.) - Work status: Returned to full duty the same day / Restricted work or job transfer / Days away from work / Not yet known - First day away from work or on restricted duty - Days away from work so far (Count calendar days from the day after the injury, weekends too. OSHA stops counting at 180.) - Days of restricted work or job transfer so far ### 7. Recordability and reporting - Is the case work-related? (OSHA presumes an event at work is work-related unless an exception in 29 CFR 1904.5(b)(2) applies, such as a voluntary wellness activity or eating your own food.): Yes: an event or exposure at work caused or contributed / No: an exception applies / Needs review - Recordable on the OSHA 300 Log? (Recordable if work-related and it causes death, days away, restricted work or transfer, medical treatment beyond first aid, loss of consciousness, or a significant diagnosis (29 CFR 1904.7). Write the answer even if no.): Yes / No / Review with the safety lead - Privacy concern case? (Includes an injury to an intimate body part, sexual assault, mental illness, HIV, hepatitis or tuberculosis, and a needlestick from a contaminated sharp. Keep a private list linking case numbers to names.): No / Yes: leave the name off the 300 Log - Death, in-patient hospitalization, amputation or loss of an eye: OSHA notified (A work-related death must be reported within 8 hours. An in-patient stay, amputation or loss of an eye must be reported within 24 hours (29 CFR 1904.39).) - OSHA report: date, time, method and confirmation - Sharps or bloodborne exposure: post-exposure evaluation offered and sharps injury log updated (The log records the device type and brand, the department and how the exposure happened (29 CFR 1910.1030(h)(5)).) - Workers' compensation first report filed (date and claim number) ### 8. Corrective action and sign-off - Immediate corrective action taken - Root cause or contributing factors, once known - Corrective action, owner and due date - Employee told they can report injuries and illnesses without retaliation (29 CFR 1904.35 requires a reasonable way to report that does not discourage reporting, and bans retaliation.) - Completed by (name, title and phone) - Date completed (Finish within 7 calendar days of learning that a recordable case occurred.) - Signature of person completing the report - Safety, HR or administrator review ## How to fill it out well 1. Complete sections 1 to 4 within a day or two, from the employee's account, the supervisor's view and the provider's papers. Sections 5 to 8 can follow. 2. Write plain facts for the task, the sequence, the injury and the object. Leave names, phone numbers and Social Security numbers out of those fields, as OSHA asks on its form. 3. Screen for recordability that week and write the answer down, even when it is no. 4. Finish within 7 calendar days after you learn a recordable case occurred. Keep the record for 5 years after the year it covers. 5. Call OSHA first for a work-related death (8 hours) or an in-patient stay, amputation or loss of an eye (24 hours). The form can wait. The clock cannot. 6. Give the employee a copy on request, by the end of the next business day. This also goes to former employees and their personal representatives. An authorized employee representative gets only the case section, within 7 calendar days. 7. Use this as your Form 301 equivalent only if it holds everything the OSHA form asks for. It must be filled in the same way. In an OSHA State Plan state, check its rules too. ## Tips - Interview the employee and photograph the scene the same day, before equipment is moved or cleaned up. - Keep the corrective action in the same record so each injury links to the fix and the date it was verified. - Ask about the task, tool and conditions, not the person. Use the [root cause analysis worksheet](https://incidentkit.ai/templates/root-cause-analysis-worksheet) for anything serious or repeated. - Make reporting easy. OSHA requires a reasonable way to report injuries promptly, and bans retaliation for reporting. ## Frequently asked questions ### What does OSHA Form 301 ask for? Form 301 has 18 items in three groups. Employee: name, address, date of birth, date hired, sex. Treating provider: name, where treated, emergency room visit, overnight stay. Case: Log case number, date, time work began, time of event, what the employee was doing, what happened, injury or illness, object or substance, date of death if any. ### Can I use this template instead of OSHA Form 301? OSHA allows an equivalent form: same information, as easy to read, filled in the same way. Many workers' compensation and insurance forms qualify. This template matches Form 301 content but is not an OSHA form, so make sure yours has every item. ### How long do I have to complete the 301, and how long do I keep it? Within 7 calendar days of learning that a recordable work-related injury or illness occurred (29 CFR 1904.29). OSHA's form says to keep it 5 years following the year it covers. ### When must I report an injury directly to OSHA? Report a work-related death within 8 hours. Report an in-patient hospital stay, amputation or loss of an eye within 24 hours. Use your OSHA area office, 1-800-321-OSHA (1-800-321-6742) or OSHA's online form. Voicemail, faxes and emails do not count. ### Can IncidentKit produce OSHA 300, 300A and 301 records? OSHA 300, 300A and 301 exports are rolling out and not yet available. Intake, investigation and corrective actions for [workplace injury reporting](https://incidentkit.ai/use-cases/workplace-injury-reporting) are in the product. Lauren drafts fields and a person reviews and signs. Until the exports ship, use this template as your record. ## Sources - [OSHA: Recordkeeping forms (Forms 300, 300A and 301 package)](https://www.osha.gov/recordkeeping/forms) - [OSHA: Forms 300, 300A and 301 and instructions (PDF package, 06/2019)](https://www.osha.gov/sites/default/files/OSHA-RK-Forms-Package.pdf) - [eCFR: 29 CFR 1904.29, Forms (seven-day completion, equivalent forms, privacy cases)](https://www.ecfr.gov/current/title-29/section-1904.29) - [eCFR: 29 CFR 1904.7, General recording criteria (first aid list, medical treatment, days away)](https://www.ecfr.gov/current/title-29/section-1904.7) - [eCFR: 29 CFR 1904.5, Determination of work-relatedness](https://www.ecfr.gov/current/title-29/section-1904.5) - [eCFR: 29 CFR 1904.39, Reporting fatalities, hospitalizations, amputations and loss of an eye](https://www.ecfr.gov/current/title-29/section-1904.39) - [eCFR: 29 CFR 1904.35, Employee involvement (reporting procedure, retaliation, access to the 301)](https://www.ecfr.gov/current/title-29/section-1904.35) - [eCFR: 29 CFR 1910.1030, Bloodborne pathogens (sharps injury log)](https://www.ecfr.gov/current/title-29/section-1910.1030) ## Related - [OSHA 301 incident report: the 18 fields and deadlines](https://incidentkit.ai/compliance/osha/osha-301-incident-report) - [Recordable vs first aid: OSHA's medical treatment test](https://incidentkit.ai/compliance/osha/recordable-vs-first-aid) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting) - [Workplace Injury Reporting: Steps, Deadlines, Records](https://incidentkit.ai/use-cases/workplace-injury-reporting) - [OSHA 300 Log Automation: Keep It Accurate Year-Round](https://incidentkit.ai/use-cases/osha-300-log-automation) --- # Near miss report template > A short near miss report for events that almost caused harm. It asks what was about to happen, what stopped it, how serious it could have been, and what would prevent a repeat. It works for patient safety, workplace safety and equipment close calls, and takes minutes to finish. Near misses show hazards before someone is hurt. Source: https://incidentkit.ai/templates/near-miss-report · Updated Oct 5, 2026 ## When to use it - Something went wrong but was caught in time, like a wrong-patient label stopped at the scan or a forklift that braked short of a walker. - A safeguard worked and you want to note which: a time-out, barcode, guard, alarm or second person. - You found an unsafe condition before anyone was exposed: a spill, blocked exit, frayed cord or mislabeled bin. - An error reached a stage of the process but did not reach the patient or the worker. - You want a light reporting channel that staff will actually use. ## The template ### 1. What and where - Date - Approximate time - Location or department - Type: Patient safety: medication / Patient safety: procedure or surgical / Patient safety: fall / Patient safety: identification or labeling / Patient safety: equipment or device / Workplace safety: slip, trip or fall / Workplace safety: struck by or caught in / Workplace safety: chemical or electrical / Workplace safety: vehicle or forklift / Security or behavior / Unsafe condition (no event) / Other - Reported by (optional) (Leave your name off if anonymous reports are allowed. Add a contact to hear back.) - I would like feedback on this report (Not hearing back is a common barrier to reporting (AHRQ PSNet).) ### 2. What almost happened - What happened or nearly happened? (Describe it in order. Facts only. No opinions about who was at fault.) - What would have happened if it had not been caught? (Describe the worst realistic outcome. It sets the priority.) - Who or what was exposed (patient, worker, visitor, equipment) - Equipment, product or drug involved - How far did it get? (If it reached the person with no harm, it is a no-harm event. Report it too.): Hazard noticed, no event / Event started and was stopped before anyone was exposed / Reached the person, but no harm followed ### 3. What stopped it - What caught it? ('Luck' is a real answer and the most important one: it means no safeguard worked.): A person noticed / Barcode or scanner / Time-out, checklist or double check / Alarm or alert / Guard, interlock or other physical barrier / Pharmacist or supervisor review / Luck: nothing in place stopped it / Other - Who caught it (role) - What made it possible to catch? (Name it so others can copy it: a label, a habit, a second person, an alert.) - A safeguard that should have caught it was missing or did not work ### 4. How serious could it have been - Worst credible outcome (Pick the worst realistic outcome, not the worst imaginable. This is the severity half of a risk matrix.): No harm / Minor injury or first aid / Moderate injury or treatment / Severe injury, permanent harm or death - How likely is it to happen again? (Think about how often the conditions line up: shift, staffing, equipment, product.): Rare / Possible / Likely / Almost certain - Has this happened before?: First time I know of / Seen before / Happens often - Priority (reviewer) (Use your site's risk matrix to combine severity and likelihood.): Low / Medium / High ### 5. Contributing conditions - Staffing, workload or time pressure (Check what applies. These describe conditions, not people.) - Interruption or distraction - Labels, layout or look-alike items - Equipment, tool or maintenance condition - Procedure unclear, or hard to follow as written - Communication or handoff - Environment: lighting, noise, clutter or a spill - Anything else ### 6. Suggested fix - What would prevent this from happening again? (Ask the people who do the work. Fixes that change the setup beat reminders.) - Type of fix suggested: Remove the hazard or the step / Replace with something safer / Add a physical barrier, guard or forcing function / Change the layout, label or default / Add a checklist, double check or alert / Change a procedure or add training / Not sure - Immediate action already taken - Equipment removed from service, or the area made safe ### 7. Review (manager) - Date received - Reviewed by - Decision: Fixed on the spot / Corrective action assigned / Needs formal investigation / Monitor and trend / No action: reason recorded - Owner and due date - Feedback given to the reporter - Added to the QAPI or safety committee log - Reviewer signature ## How to fill it out well 1. Report as soon as you can, even if you are not sure it counts. If you wonder whether to report it, report it. 2. Sections 1 to 3 are enough for a quick report. A reviewer completes the rest. 3. Say what happened, not who did it. Name the step, item or equipment involved. 4. Say what stopped it. If nothing did and it was luck, say that. It is the most important answer on the form. 5. Reviewers: reply fast, tell the reporter what was decided, and record any fix with an owner and a date. 6. Check later that the fix held. Add the near miss to your trend data by location, shift and cause. ## Tips - Thank people for reporting. AHRQ PSNet says lack of feedback is a commonly cited barrier to reporting, and a short reply beats a poster. - Record the catch as well as the miss. Knowing which safeguard worked tells you what to protect. - Track by location, shift and equipment. Several near misses in one place are a forecast. OSHA encourages investigating close calls as well as injuries. - Keep it blame-free. A [just culture](https://incidentkit.ai/glossary/just-culture) separates honest mistakes from reckless acts so people keep reporting. ## Frequently asked questions ### What is a near miss? An event or condition that could have caused harm but did not, because it was caught in time or by chance. OSHA calls close calls incidents where a worker might have been hurt had things been slightly different. NCC MERP category B did not reach the patient. ### Is a near miss recordable or reportable? A close call with no injury is not recordable under OSHA's rule, which covers work-related injuries and illnesses. OSHA encourages investigating close calls. CMS survey guidance for ASCs expects centers to find near-miss errors. Some states require certain reports, so check yours. ### Why do near miss reports matter? They show hazards and weak safeguards while the cost is still zero. OSHA says investigations should cover close calls as well as injuries, and look for root causes, not blame. AHRQ PSNet adds that reporting works best with feedback to reporters. ### How do I get staff to report near misses? Make reporting short, safe and answered. A form with few fields, an anonymous option, a visible reply and a no-blame review removes the usual reasons people stay quiet. See [how to get staff to report near misses](https://incidentkit.ai/blog/how-to-get-staff-to-report-near-misses). ### What is the difference between a near miss and a no-harm event? A near miss is caught before it reaches the patient or worker. A no-harm event reaches them and no harm follows. Both deserve a report, and the second shows a safeguard that failed. This form asks how far the event got. ## Sources - [OSHA: Incident investigation](https://www.osha.gov/incident-investigation) - [AHRQ PSNet: Reporting patient safety events (primer)](https://psnet.ahrq.gov/primer/reporting-patient-safety-events) - [CMS State Operations Manual, Appendix L: Guidance for Surveyors, Ambulatory Surgical Centers](https://cms.hhs.gov/Regulations-and-Guidance/Guidance/Manuals/Downloads/som107ap_l_ambulatory.pdf) - [NCC MERP: Index for Categorizing Medication Errors (2022)](https://www.nccmerp.org/sites/default/files/index-bw-2022.pdf) ## Related - [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting) - [Near-miss reporting and safety culture: a practical guide](https://incidentkit.ai/guides/near-miss-reporting-and-safety-culture) - [How to get staff to report near misses (and keep doing it)](https://incidentkit.ai/blog/how-to-get-staff-to-report-near-misses) - [Near miss: definition and meaning](https://incidentkit.ai/glossary/near-miss) - [Just culture: definition and meaning](https://incidentkit.ai/glossary/just-culture) - [Root Cause Analysis Worksheet (5 Whys Template)](https://incidentkit.ai/templates/root-cause-analysis-worksheet) --- # Root cause analysis worksheet > A root cause analysis worksheet for incidents and near misses. It walks a small team through the event timeline, five whys, contributing-factor categories, causal statements and a ranked set of actions. Fixes lean on design changes instead of reminders. Each action leaves with a measure and a review date. Source: https://incidentkit.ai/templates/root-cause-analysis-worksheet · Updated Oct 5, 2026 ## When to use it - A serious event, like severe harm, death, permanent harm or a sentinel event, where an accrediting body expects a full analysis. - A cluster or repeat of lower-severity events that points to a shared cause, found in your trend data. - A near miss with high potential for harm, where the safeguards held by chance. - The QAPI committee has chosen a performance improvement project and needs the cause before it picks an action. - A recordable injury or a survey finding needs a documented cause and a lasting corrective action. ## The template ### 1. Event summary - Incident reference number - Date of event - Event in one sentence (Say what happened, not who did it: 'Resident fell while toileting alone at night and fractured a hip.') - Harm level: No harm or near miss / Mild harm / Moderate harm / Severe or permanent harm / Death - Meets your sentinel or serious reportable event definition (The Joint Commission expects the analysis and action plan within 45 business days of the event or of learning about it.) - Analysis team (names and roles) (Include someone who does this work daily, someone who does not, and a leader who can approve changes.) - Date analysis started ### 2. Facts and timeline - Sequence of events with clock times (List what happened in order. Mark the last normal step and where it went wrong. Use records, not memory alone.) - What should have happened (the intended process) (Write the standard, then compare. The gap is where to look.) - Sources reviewed (Records, logs, device data, policies, photos, schedules, staffing sheets. Note who was interviewed.) - What people say made it difficult (Ask 'what made this a sensible thing to do at that moment?' not 'why did you do that?') - Similar earlier events (Search your incident log for the same place, equipment, drug, step or shift.) ### 3. Five whys - Problem statement (One sentence on what went wrong, not who: 'A heparin infusion ran at the wrong concentration.') - Why 1: why did the problem happen? - Why 2: why did that happen? - Why 3: why did that happen? - Why 4: why did that happen? - Why 5: or where the chain stops at something you can change (Stop at a process, design or management choice you can change. 'Be more careful' is not a root cause. If the chain splits, copy this section.) ### 4. Contributing factors by category - Task and process design (Was the process clear and easy to follow? Any workarounds or easy-to-skip steps? Write 'not a factor' if none.) - Communication and handoffs (Were orders and handoffs complete? Was anything spoken that should be written, or lost at shift change?) - Staffing, workload and scheduling (What were staffing and workload? Were staff new, floating, on a long shift or covering several tasks?) - Equipment, technology and software (Did equipment, alarms, software or defaults help or get in the way? Was it the right tool, and maintained?) - Environment and layout (Lighting, noise, clutter, space, storage, signs, distance to supplies.) - Training, competence and supervision (Was training and competency current for this task? Was supervision easy to reach?) - Policies, procedures and leadership oversight (Did a policy exist, match real work and get audited? Did leaders know of earlier warning signs?) - Patient, worker and external factors (Condition, behavior, language, or outside factors like a supplier change.) ### 5. Root causes - Root cause 1, as a causal statement (Use cause and effect: '[Condition] made [event] more likely because [mechanism].' Name conditions, not people or 'failure to'.) - Root cause 2, as a causal statement - Root cause 3, as a causal statement - Evidence for each cause (Point to the record, log or interview that supports it. No evidence means a guess.) - Just culture screen: no reckless or intentional conduct found (If an act looks deliberately unsafe, send it to HR or peer review. IHI says RCA2 is not advised for blameworthy acts.) ### 6. Action plan using the action hierarchy - Stronger actions chosen (Need the least memory from people: redesign, add a forcing function, simplify, standardize equipment, involve leaders. Industrial sites: remove, swap or engineer out the hazard before administrative controls or PPE.) - Intermediate actions chosen (Two independent checks, more staff or less workload, software changes, fewer distractions, checklists, separating look-alikes, read-back.) - Weaker actions chosen (Double checks, warnings, new procedures, training. Alone they rarely hold.) - Every root cause has at least one stronger or intermediate action (IHI recommends at least one stronger or intermediate action for each cause.) - An interim safety measure is in place while the permanent fix is built - Leadership reviewed and approved the actions (If an action is not approved, record why and choose a replacement.) ### 7. Measures and follow-up - Process measure: is the fix being done? (For example, percent of scans completed, rounds done or audits passed.) - Outcome measure: is the harm falling? (For example, falls per 1,000 resident-days, or events by location.) - Target, and how long it must hold - Date to review results (Set it now, before the action ships.) - Lessons to share (units, sites, committees) ### 8. Approval - Date analysis completed - Facilitator - Quality, risk or EHS leader - Senior leader approving the actions - Date reported to the QAPI committee or governing body ## How to fill it out well 1. Match depth to risk. Use the whole worksheet for serious harm, repeat events and high-potential near misses. For lower-risk events, sections 1 to 3 and 6 are enough. 2. Build the timeline first, from records, logs and interviews. Mark the last normal step and where it went wrong. 3. Run the five whys from the problem statement until the answer is something you can change. If the chain splits, copy section 3 and follow each branch. 4. Use the factor categories to catch what the whys missed. Write 'not a factor' where none applies, so readers know you looked. 5. Write each root cause as a cause-and-effect statement about a condition, not a person, and link it to evidence. 6. Pick actions from the stronger and intermediate levels, and use weaker actions to support them. Get a senior leader to approve. 7. Move each approved action into the [corrective action plan](https://incidentkit.ai/templates/corrective-action-plan) with an owner, a due date, evidence and an effectiveness check. ## Tips - Five whys follows one path. The factor categories check that you did not stop at the first plausible chain. - 'Human error' is where the analysis starts. Ask what made the error easy to make and hard to catch. - Retraining and a new policy rarely hold alone. IHI calls them weaker actions. - For a sentinel event reported to the Joint Commission, the analysis and action plan are expected within 45 business days. Every sentinel event needs the analysis, reported or not. - Set the effectiveness review date while the team is still in the room. ## Frequently asked questions ### What is the five whys technique? Five whys moves from a problem to a cause you can change by asking 'why did that happen?' about five times. It suits simple, single-path problems. For complex events, add a timeline and contributing-factor categories, because causes often combine. See [five whys vs fishbone vs fault tree](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree). ### What is the action hierarchy? It ranks fixes by how much they rely on people remembering. Stronger: design changes, forcing functions, simpler processes, standard equipment. Intermediate: redundancy, checklists, software changes. Weaker: double checks, warnings, new policies, training. IHI's version, part of RCA2, builds on VA National Center for Patient Safety tools. ### How long does the Joint Commission allow for a root cause analysis? The Joint Commission expects a thorough analysis and action plan within 45 business days of the event or of learning about it. Reporting is encouraged, not required. The analysis is required for every sentinel event. ### Why do root cause analyses so often fail to prevent repeats? AHRQ PSNet says RCAs often fail to produce lasting fixes because they rely on weak steps like education and policy enforcement. Leadership involvement, stronger actions and measured results help. This worksheet ranks actions and requires a measure and review date. ### Does OSHA expect a root cause analysis? OSHA's guidance asks employers to investigate injuries and close calls to find root causes, not to assign blame, using a team of managers and employees. It requires no single method. A timeline, five whys and the hierarchy of controls are common choices. ## Sources - [IHI Patient Safety Essentials Toolkit: Action Hierarchy (part of RCA2), as hosted by the Minnesota Department of Health](https://www.health.mn.gov/facilities/patientsafety/adverseevents/toolkit/docs/safetytoolkit_actionhierarchy.pdf) - [IHI: RCA2, Improving Root Cause Analyses and Actions to Prevent Harm](https://www.ihi.org/library/tools/rca2-improving-root-cause-analyses-and-actions-prevent-harm) - [AHRQ PSNet: Root cause analysis (primer)](https://psnet.ahrq.gov/primer/root-cause-analysis) - [The Joint Commission: Sentinel Event Policy (Comprehensive Accreditation Manual, SE chapter)](https://www.jointcommission.org/-/media/tjc/documents/resources/patient-safety-topics/sentinel-event/camncc_20_se_all_current.pdf) - [OSHA: Incident investigation](https://www.osha.gov/incident-investigation) - [CDC NIOSH: Hierarchy of controls](https://www.cdc.gov/niosh/hierarchy-of-controls/about/index.html) ## Related - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Root Cause Analysis: How to Run One That Leads to Action](https://incidentkit.ai/use-cases/root-cause-analysis) - [Five whys vs fishbone vs fault tree: how to choose](https://incidentkit.ai/blog/five-whys-vs-fishbone-vs-fault-tree) - [Five whys: definition and meaning](https://incidentkit.ai/glossary/five-whys) - [Corrective Action Plan Template (CAPA, Printable)](https://incidentkit.ai/templates/corrective-action-plan) - [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations) --- # Corrective action plan template > A corrective action plan (CAPA) template that tracks each action from decision to proof. It records the problem and cause, the action strength, an owner, a due date, evidence of completion and a later effectiveness check. The rule it enforces: an action is done when someone has verified the problem stopped, not when the task is checked off. Source: https://incidentkit.ai/templates/corrective-action-plan · Updated Oct 5, 2026 ## When to use it - An investigation or root cause analysis has named causes and you need a plan with owners and dates. - An audit finding, survey deficiency or inspection citation needs an internal action plan behind the formal reply. - A recordable injury or a high-potential near miss calls for a documented fix and follow-up. - A QAPI performance improvement project needs its actions tracked until the measure moves. - An insurer, accreditor or governing body asks to see that corrective actions were done and worked. ## The template ### 1. Plan header - Plan ID - Source: Incident investigation / Root cause analysis / Near-miss trend / Survey or inspection finding / Audit finding / Complaint or grievance / QAPI data review / Other - Related incident, finding or analysis reference - Date opened - Facility or department - Plan owner (one name and role) - Executive sponsor (The leader who can remove barriers and approve resources.) ### 2. Problem and cause - Problem statement (What went wrong, where and how often. No names.) - Root cause or causes this plan addresses (Copy the causal statements from your analysis. If the cause is unknown, the first action is to find it.) - Risk if nothing changes - Priority: Low / Medium / High / Critical: act now - Containment: what was done right away (Interim steps that protect people today, like removing equipment. Containment is not the fix.) ### 3. Action (copy this section for each action) - Action (Start with a verb: 'Install motion-sensor night lights in every resident bathroom', not 'Improve lighting'.) - Action type: Corrective: fixes this event / Preventive: stops the same cause elsewhere / Containment: interim measure / Both corrective and preventive - Action strength (Pair a weaker action with a stronger one. Training alone rarely holds.): Stronger: design change, forcing function, simplify or standardize / Intermediate: checklist, redundancy, software or staffing change / Weaker: training, policy or reminder - Owner (one name and role) (One accountable person, not a team. Work can be handed off, accountability cannot.) - Start date - Due date (Set a real date, sooner for higher risk. If it slips, record the new date and why.) - Resources or approval needed - Status: Not started / In progress / Complete: awaiting verification / Verified effective / Overdue / Cancelled: reason recorded ### 4. Evidence of completion - What proves the action was done? (Name the evidence before you start: a closed work order, a photo, a signed training roster with test results, a policy with its version, a settings screenshot.) - Evidence location (file, link or binder) - Date completed - Verified by (Someone other than the owner should confirm the evidence.) - Date verified ### 5. Effectiveness check - What measure shows the problem is gone? (Pick a measure tied to the cause: audit pass rate, repeat events, observed compliance.) - Target and how long it must hold (For example: no repeat events and every audit passing for three months.) - Baseline before the action (number and period) - Effectiveness check date (Set it when you plan, not when the action closes. Allow enough time for several cycles.) - Result at the check (number and period) - Outcome: Effective: problem resolved and sustained / Partly effective: adjust the action / Not effective: reopen the analysis - Next monitoring date, if sustained ### 6. Review and escalation - Reviewed by the QAPI or safety committee - Committee review date - Barriers or delays - Escalated to (leader) and reason - Lessons shared with other units or sites ### 7. Closure - Every action is verified - The effectiveness check passed - Closure summary - Plan owner - Quality, risk or EHS leader - Closure date ## How to fill it out well 1. Start from causes, not symptoms. Each action should trace back to a root cause in your analysis. 2. Write each action as a specific change with a verb. If someone could do it and no one would notice, it is too vague. 3. Rank each action's strength. Aim for at least one stronger or intermediate action per cause, and use weaker actions to support them. 4. Give each action one owner, a due date and the evidence that will prove it. Decide all three when you plan. 5. Have someone other than the owner verify completion against the evidence, and attach it. 6. Set the effectiveness measure and check date before work starts. Close the plan only when the check passes. 7. Review open and overdue actions at every QAPI or safety committee meeting. Copy the Action section for each added action. ## Tips - Three strong actions beat ten vague ones. Fewer, specific actions get finished and checked. - Do not extend due dates silently. A slipped date is a leadership decision, and the reason belongs in the record. - Keep containment apart from the fix. Containment protects people this week. The fix changes the system. - Ask the people who do the work if the action will hold at 3 a.m. on a short-staffed night. - AHRQ PSNet lists measuring results among the keys to effective root cause analysis. The effectiveness check is that step. A survey reply is separate: see [what to put in a plan of correction](https://incidentkit.ai/blog/what-to-put-in-a-plan-of-correction). ## Frequently asked questions ### What is a corrective action plan? A written list of the specific changes that will fix a problem and keep it from coming back. Each action has an owner, due date, proof it was done and a check that it worked. Often called CAPA, for [corrective and preventive action](https://incidentkit.ai/glossary/corrective-and-preventive-action). ### What is the difference between corrective and preventive action? Corrective action fixes the cause of a problem that already happened. Preventive action stops the same cause from causing a problem elsewhere, like another unit, shift or site. A good plan does both. ### What is an effectiveness check? A planned, later look at data to confirm the problem stopped. Nursing home QAPI requires measuring success after acting and tracking results so gains last (42 CFR 483.75(d)(1)). ASC rules require making sure improvements last (42 CFR 416.43(c)(2)). See [effectiveness review](https://incidentkit.ai/glossary/effectiveness-review). ### How strong should corrective actions be? IHI recommends at least one stronger or intermediate action for each cause. Stronger actions change the design or process. Training and policy changes are often needed but rarely last alone. Leaders should approve, and one person should own and measure each by a set date. ### Who should own a corrective action? One named person, not a team. The owner is accountable for finishing it and for status reports, and can hand off the work. IHI says to assign one person, who may be outside the analysis team, and a completion date. Someone else should verify it. ## Sources - [IHI Patient Safety Essentials Toolkit: Action Hierarchy (part of RCA2), as hosted by the Minnesota Department of Health](https://www.health.mn.gov/facilities/patientsafety/adverseevents/toolkit/docs/safetytoolkit_actionhierarchy.pdf) - [eCFR: 42 CFR 483.75, Quality assurance and performance improvement (nursing homes)](https://www.ecfr.gov/current/title-42/section-483.75) - [eCFR: 42 CFR 416.43, Quality assessment and performance improvement (ASC)](https://www.ecfr.gov/current/title-42/section-416.43) - [AHRQ PSNet: Root cause analysis (primer)](https://psnet.ahrq.gov/primer/root-cause-analysis) ## Related - [Corrective Actions: How to Close Them With Proof](https://incidentkit.ai/use-cases/close-corrective-actions) - [Corrective and preventive actions (CAPA) tracking](https://incidentkit.ai/product/corrective-actions) - [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide) - [Corrective and preventive action: definition and meaning](https://incidentkit.ai/glossary/corrective-and-preventive-action) - [Effectiveness review: definition and meaning](https://incidentkit.ai/glossary/effectiveness-review) - [Root Cause Analysis Worksheet (5 Whys Template)](https://incidentkit.ai/templates/root-cause-analysis-worksheet) --- # QAPI meeting agenda and minutes template > A combined agenda and minutes template for QAPI and QAA committee meetings. It records attendance, data reviewed, adverse events, performance improvement projects and corrective action status. It also records decisions with owners and due dates, and the report to the governing body. The minutes show the program runs on its data and acts on it. Source: https://incidentkit.ai/templates/qapi-meeting-agenda-and-minutes · Updated Oct 5, 2026 ## When to use it - Nursing home QAA committee meetings, which must happen at least quarterly and as needed. - Regular QAPI meetings at surgery centers, hospitals, hospice and home health agencies. - Getting ready for a survey: minutes are proof the program meets, reviews data and acts on it. - A special meeting after a serious event, an abuse allegation or a corrective action that did not work. - Preparing the QAPI report to the governing body. ## The template ### 1. Meeting details - Meeting date - Start time - End time - Meeting type: Regular / Special: called after an event / Annual program review - Format: In person / Video / Hybrid - Chair - Recorder ### 2. Attendance - Setting: Nursing home / Surgery center (ASC) / Hospital / Hospice / Home health / Behavioral health / Other - Members present (name and role) - Members absent (name and role) and who covered - Director of nursing services, medical director or designee, and infection preventionist present (nursing homes) (A nursing home QAA committee must include the director of nursing services, the medical director or designee, the infection preventionist and at least three other staff (42 CFR 483.75(g)(1)).) - Administrator, owner, board member or other leader present (At least one of the other three staff must be a leader.) - Quorum met under the committee charter (Check your charter. Record who covers when a required member is out.) - Guests and presenters ### 3. Previous minutes and open actions - Previous minutes reviewed and approved - Corrections to previous minutes - Open actions reviewed (action, owner, status) (Read every open and overdue item. Ask for evidence, not updates.) - Actions open - Actions overdue - Actions completed since last meeting, with evidence and any effectiveness result (An action is complete when the evidence is attached and the effectiveness check has passed.) ### 4. Data reviewed - Data period covered and sources - Incidents and adverse events (counts by type and harm level) (Include falls, medication errors, infections, skin injuries, transfers, wrong-site events and near misses. Compare with last period.) - Trends by location, shift and cause (Look for clusters: one wing, one shift, one piece of equipment, one drug.) - Quality indicators and performance measures (value, target, trend) (Name each measure, its target and which way it moved since the last meeting.) - Feedback, grievances and complaints from residents, patients, families and staff (Nursing homes must have ways to get and use feedback from staff, residents and representatives (42 CFR 483.75(c)(1)).) - Drug regimen review and pharmacy findings (nursing homes) (The QAA committee must regularly review data, including drug regimen review data (42 CFR 483.75(g)(2)(iii)).) - Audit results (hand hygiene, medication pass, environmental rounds, other) ### 5. Adverse events and serious incidents - Serious events since last meeting (summary, harm and status of investigation) - Sentinel or reportable events this period - Root cause findings presented (Summarize causes and attach the analysis. Name conditions, not people.) - Abuse and neglect allegations reviewed: each reported on time and each investigation completed (Nursing homes: 2 or 24 hours to report, and results to the State Survey Agency in 5 working days.) - Reports made to regulators or accreditors (agency and date) - Near misses reviewed and what they showed ### 6. Performance improvement projects - Active project title or titles - Why this project: the data that selected it (Tie each project to a high-risk, high-volume or problem-prone area your data found (42 CFR 483.75(e)(1); 42 CFR 416.43(c)(1)).) - Aim and measure (target and date) - Progress since last meeting (baseline, current, change) - Status: On track / Behind: plan adjusted / Complete: sustained / Complete: not effective / Stopped: reason recorded / New: approved today - A project on a high-risk or problem-prone area is in place for the year (nursing homes) (Nursing homes must include, at least yearly, a project on high-risk or problem-prone areas found through data (42 CFR 483.75(e)(3)).) ### 7. Decisions and new actions - Decisions made (Write what was decided, not what was discussed.) - New action 1 (what, owner, due date, evidence, effectiveness check date) - New action 2 (what, owner, due date, evidence, effectiveness check date) - Additional actions - Policy or process changes approved, and resources requested ### 8. Governing body report and sign-off - Items to report to the governing body (The nursing home QAA committee reports to the governing body on its work, including QAPI (42 CFR 483.75(g)(2)).) - Date reported to the governing body - Next meeting date - Minutes recorded by - Chair - Recorder - Date minutes approved ## How to fill it out well 1. Send the agenda and data a few days ahead so the meeting is for decisions, not reading. 2. Take attendance by name and role. Record who is absent and who covered. 3. Open with the open and overdue actions. Ask for evidence, not updates. 4. Show data as trends against a target, with the period named, not raw counts. 5. Record decisions, owners and due dates. Leave out the discussion unless it explains a decision. 6. Approve the minutes at the next meeting. Keep them with the data and attachments under your retention policy. 7. Record the date you reported to the governing body, and what you reported. ## Tips - Pick one or two topics for a deeper look each meeting. Rotate them, and always cover adverse events and open actions. - Make the minutes show the loop: data, decision, action, owner, check. A reader should follow one problem from meeting to meeting. - Invite front-line staff to present. Their feedback is part of what the rule asks you to collect and use. - Keep minutes factual and free of blame. Ask counsel how state peer review or quality improvement protections apply before you decide what to attach. ## Frequently asked questions ### How often must a QAPI committee meet? A nursing home QAA committee must meet at least quarterly and as needed (42 CFR 483.75(g)(2)(i)). Surgery centers, hospitals, hospice and home health need an ongoing, data-driven program overseen by the governing body. Check your accreditor and state, and set the schedule in your QAPI plan. ### Who must be on a nursing home QAA committee? The director of nursing services, the medical director or designee, and the infection preventionist. Also at least three other staff, one of them the administrator, owner, board member or another leader (42 CFR 483.75(g)(1)). ### What should QAPI meeting minutes include? Date, attendees and absences. Approval of the last minutes. Open actions. Data reviewed, with trends. Adverse events and lessons. Project progress. Decisions with owners and due dates. The governing body report. Show a loop of data, decision, action and check. ### What does a performance improvement project have to document? ASCs: the reasons for each project and its results (42 CFR 416.43(d)). Hospitals: projects, reasons and measurable progress (42 CFR 482.21). Nursing homes: distinct projects, with at least one a year on a high-risk or problem-prone area found through data (42 CFR 483.75(e)(3)). ### Do surveyors get to see QAPI committee records? In nursing homes, 42 CFR 483.75(h) says a State or the Secretary may not require QAA committee records except as related to compliance with that section. CMS adds that a facility must disclose what shows compliance. Refusal brings an F865 citation. Ask counsel how state law applies. ## Sources - [eCFR: 42 CFR 483.75, Quality assurance and performance improvement (nursing homes)](https://www.ecfr.gov/current/title-42/section-483.75) - [eCFR: 42 CFR 416.43, Quality assessment and performance improvement (ASC)](https://www.ecfr.gov/current/title-42/section-416.43) - [eCFR: 42 CFR 482.21, Quality assessment and performance improvement program (hospitals)](https://www.ecfr.gov/current/title-42/section-482.21) - [eCFR: 42 CFR 418.58, Quality assessment and performance improvement (hospice)](https://www.ecfr.gov/current/title-42/section-418.58) - [eCFR: 42 CFR 484.65, Quality assessment and performance improvement (home health)](https://www.ecfr.gov/current/title-42/section-484.65) - [CMS State Operations Manual, Appendix PP: F865 to F868, Quality assurance and performance improvement](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf) ## Related - [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings) - [QAPI program guide for ASCs, nursing homes and hospitals](https://incidentkit.ai/guides/qapi-program-guide) - [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [QAA committee: definition and meaning](https://incidentkit.ai/glossary/qaa-committee) - [Performance improvement project: definition and meaning](https://incidentkit.ai/glossary/performance-improvement-project) --- # TRIR and DART rate calculator > Get your TRIR and DART rates: OSHA-recordable cases times 200,000, divided by hours worked. Source: https://incidentkit.ai/tools/trir-dart-calculator · Updated Oct 5, 2026 Free, runs in your browser: https://incidentkit.ai/tools/trir-dart-calculator ## How to use it 1. Count the OSHA-recordable cases on your 300 log for the year. 2. Add up the hours your employees actually worked, not paid hours or vacation. 3. For DART, count cases with days away, restricted work or job transfer. 4. Compare with your own past years first. Benchmarks vary by industry (NAICS code). ## Frequently asked questions ### Why 200,000 hours? It is the hours 100 full-time employees work in a year: 100 people × 40 hours × 50 weeks. That gives a rate per 100 full-time workers a year, so sites of different sizes can be compared. ### What counts as hours worked? Hours actually worked by all employees, including temporary and seasonal staff you supervise. Leave out vacation, sick leave and holidays. If you lack exact figures, OSHA's Form 300A instructions explain how to estimate. ### Is a lower TRIR always better? No. A low rate can mean a safe workplace or under-reporting. Pair it with near-miss volume and how fast corrective actions close. A healthy reporting culture often shows more near misses, not fewer. ## Sources - [OSHA: Recordkeeping handbook and Form 300A instructions](https://www.osha.gov/recordkeeping) - [BLS: Survey of Occupational Injuries and Illnesses](https://www.bls.gov/iif/) ## Related - [TRIR and DART rates: formula, example and BLS 2024 rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates) - [TRIR (total recordable incident rate): definition and meaning](https://incidentkit.ai/glossary/trir) - [DART rate: definition and meaning](https://incidentkit.ai/glossary/dart-rate) - [OSHA 300 Log: how to fill it out, column by column](https://incidentkit.ai/compliance/osha/osha-300-log) - [Manufacturing incident reporting and OSHA 300 software](https://incidentkit.ai/solutions/manufacturing) --- # ASCQR payment update impact calculator > See what the 2 percentage point payment update cut for missed ASC quality reporting would cost you. Source: https://incidentkit.ai/tools/ascqr-penalty-calculator · Updated Oct 5, 2026 Free, runs in your browser: https://incidentkit.ai/tools/ascqr-penalty-calculator ## How to use it 1. Enter your annual Medicare ASC payments, from your cost or remittance data. 2. Enter the expected annual payment update percentage. 3. See the dollar gap between the full and the reduced update. 4. Treat it as an estimate. Your actual payment depends on case mix and the final rule. ## Frequently asked questions ### What is the ASC Quality Reporting Program? ASCQR is a CMS pay-for-reporting program for ambulatory surgery centers (ASCs). Centers that do not send required quality data on time get a lower annual payment update. See the [ASCQR guide](https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting) for measures and deadlines. ### Is the reduction cumulative? It applies to the payment update for the affected year. Check the current rule and any exceptions for your center on cms.gov. ### Does this replace my own financial analysis? No. It is a simple estimate for planning talks, not financial or legal advice. ## Sources - [CMS: ASC Quality Reporting Program](https://www.cms.gov/medicare/quality/ambulatory-surgical-center-quality-reporting) ## Related - [ASCQR Program: measures, deadlines, 2.0-point penalty](https://incidentkit.ai/compliance/reporting-deadlines/asc-quality-reporting) - [ASCQR (ASC Quality Reporting Program): definition and meaning](https://incidentkit.ai/glossary/ascqr) - [Incident reporting software for surgery centers](https://incidentkit.ai/solutions/ambulatory-surgery-centers) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [Incident reporting software pricing: free to start](https://incidentkit.ai/pricing) --- # Incident reporting time and cost calculator > Enter your incident volume, minutes per step and hourly cost to see your yearly time and cost. Source: https://incidentkit.ai/tools/incident-cost-calculator · Updated Oct 5, 2026 Free, runs in your browser: https://incidentkit.ai/tools/incident-cost-calculator ## How to use it 1. Enter incidents per year across your sites. 2. Enter the average minutes your team spends on each step today. 3. Enter a blended hourly cost for the people involved. 4. Change the intake time to see what faster reporting does. ## Frequently asked questions ### Where do these numbers come from? Only from what you enter. The calculator uses no benchmarks, so the result reflects your own process. ### What is not included? Costs that are hard to count: harm to patients or workers, penalties, insurance premiums, lawsuits and turnover. They are usually larger than staff time, so this number is a floor. ### How do I get a good estimate of minutes per step? Time five recent incidents from start to finish, or ask the people who file, route and review them. Averages from a few real cases beat guesses. ## Related - [Incident reporting software pricing: free to start](https://incidentkit.ai/pricing) - [Replace Paper Incident Forms: A Practical Switch Plan](https://incidentkit.ai/use-cases/replace-paper-incident-forms) - [Incident management software buyer's guide: how to choose](https://incidentkit.ai/guides/incident-management-software-buyers-guide) - [Lauren: AI incident intake that a person signs](https://incidentkit.ai/product/lauren) - [IncidentKit vs paper and spreadsheets: honest comparison](https://incidentkit.ai/compare/paper-and-spreadsheets) --- # Survey readiness self-check > Surveyors want proof that you find, investigate, fix and verify problems; 20 questions show which gaps to close first. Source: https://incidentkit.ai/tools/survey-readiness-check · Updated Oct 5, 2026 Free, runs in your browser: https://incidentkit.ai/tools/survey-readiness-check ## How to use it 1. Answer yes, partly or no to 20 questions about evidence you can show today. 2. Get a score and a ranked list of gaps. 3. Use the linked guides to close the biggest ones. 4. Repeat each quarter. Readiness is a habit, not an event. ## Frequently asked questions ### Is this a mock survey? No. It is a quick self-check of your evidence. It does not replace a mock survey or your accreditor's standards, but it is a good first pass. ### Who should complete it? Your risk, quality or compliance lead, ideally with the administrator or director of nursing. People often answer differently, which is itself useful. ### Is my data saved? Answers stay in your browser. Nothing is sent unless you choose to email yourself the result. ## Related - [Survey readiness: be ready every day](https://incidentkit.ai/compliance/survey-readiness) - [Survey and accreditation readiness: a continuous approach](https://incidentkit.ai/guides/survey-and-accreditation-readiness) - [Always Survey-Ready: Stay Prepared for Unannounced Surveys](https://incidentkit.ai/use-cases/always-survey-ready) - [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers) - [Plan of correction (CMS-2567): elements and 10-day deadline](https://incidentkit.ai/compliance/survey-readiness/plan-of-correction)