How to switch from legacy incident software
Short answer
Switch in five moves. Confirm export rights. Export everything, including attachments and audit history. Map old categories to a shorter list. Run both systems 30 to 60 days, then make the old one read-only. Keep records as long as rules require, such as 5 years for OSHA logs.
Can you switch without losing history?
Yes, if you secure the export before your notice date. OSHA wants the 300 log, annual summary and 301 reports kept 5 years after the year they cover (29 CFR 1904.33).
ASC surveyors ask for 6 months of surgeries and a year of transfers and deaths. QAPI expects adverse events tracked over time. As a rule of thumb, start at least 90 days before the contract ends.
What to export
Export everything in this table, then check it.
| Data | Why it matters | Ask your vendor for |
|---|---|---|
| Incident records, all fields | Core history | Full export |
| People, roles, locations | Right unit and site | User and location lists |
| Investigations and notes | Proof of analysis | Investigation fields |
| Corrective actions, evidence | Proof of fixes | Action records, files |
| Attachments: photos, statements, PDFs | Evidence | Bulk files by record ID |
| Audit and change history | Who changed what | Audit log export |
| Forms, categories, routing rules | Rebuild your setup | Configuration documents |
| State reports and OSHA logs | Retention duties | Copies of all filed |
Exports usually arrive as spreadsheets plus a folder of files. Check the record ID appears in both. If rules cannot be exported, photograph each screen.
Check the export before you rely on it
- Compare yearly totals by incident type with the old reports.
- Open ten records with attachments and compare to the screen.
- Check dates and times for time zone shifts.
- Check names and notes for broken characters.
- Confirm the audit history shows who changed what.
Check the contract before you give notice
Check these points before you give notice.
- Your right to export, the format, any fee.
- The notice period and any automatic renewal.
- Access after the contract ends.
- When the vendor deletes your data, and whether it certifies deletion.
- For healthcare, the business associate agreement and patient information at the end.
- Whether the vendor will run a test export first.
An example plan for one site
One site can move in about 12 weeks.
| When | What happens |
|---|---|
| Weeks 1 to 2 | Confirm export rights. Request the export. List forms, rules, users, integrations. |
| Weeks 3 to 4 | Check a sample. Map old categories to incident types. |
| Weeks 5 to 6 | Set up forms, routing, roles. Import history. Train users. |
| Weeks 7 to 12 | Go live. Run both systems. Reconcile weekly. |
| After | Go read-only. Keep a verified archive. |
Run both systems in parallel
Run both for 30 to 60 days. Reconcile weekly.
- Pick a go-live dateUse the first of a month or quarter.
- New events go in the new system onlyFrom go-live, nobody files in the old one.
- Decide the rule for open casesFinish them in the old system, or import and close them in the new. Pick one.
- Reconcile weeklyCompare counts by type for 30 to 60 days. Check every difference.
- Brief staff onceOne page: which system, where QR codes point, who to ask.
- Retire the old system to read-onlyAfter two clean weeks, make it read-only. Keep a verified archive.
Import and done-for-you migration
Import brings history into IncidentKit, so trends span the cutover. Mapping starts from a pack, which sets incident types, forms, regulator exports and roles for a site type. See import and migration.
Old categories become fewer incident types. These examples are invented.
| Old categories | Mapped to |
|---|---|
| Fall: witnessed, Fall: unwitnessed, Fall: no injury | One fall type with fields for witnessed, injury, location |
| Med error: wrong dose, Med error: omission, Med error: wrong time | One medication error type; error kind is a field |
| Misc, Other, Unknown | Reviewed, not carried forward |
Regulated plans include done-for-you setup. Network plans, for groups of 10 or more sites, include migration. IncidentKit runs alongside your EHR, CMMS and HRIS; deeper integrations are rolling out.
Mistakes to avoid
These habits cause most migration problems.
- Retyping open cases. Import them or finish them in place.
- Carrying over 200 categories. Map to a short list first.
- Exporting without attachments or audit history.
- Switching off the old system before counts match.
- Letting the contract end date set the schedule.
- Forgetting QR codes and email addresses for intake.
- Skipping integrations such as HR feeds or work order links.
The parts of IncidentKit behind this
- Import and migration: Import past incidents from a spreadsheet, or we move them from your old system.
- Incident reporting: The full record holds who, what, where, harm, evidence and what happens next.
- Audit trail: Every edit is logged, so you can show who changed what, and when.
- Multi-site and roles: Run one program across many sites, with six roles and single sign-on.
- Integrations and API: Read API, webhooks and SSO now. Deeper EHR, CMMS and HRIS links come later.
- Compliance packets: Records laid out the way surveyors and inspectors want them.
Frequently asked questions
How long does it take to switch incident reporting software?
Weeks, not days. Do export and mapping first, then a 30 to 60 day parallel run per site. Ask any vendor for a written plan and named owners.
Do I need to import old incidents at all?
Not always. If you only need an archive, keep a verified read-only export as long as rules require. Import the period you trend and survey against, and archive the rest.
Can we keep using our EHR, CMMS or HRIS?
Yes. IncidentKit runs alongside them and does not replace them. Deeper EHR, CMMS and HRIS integrations are rolling out; see integrations and API for what is live.
What does done-for-you migration include?
Regulated plans include done-for-you setup. Network plans, for 10 or more sites, include migration. Ask for the scope in writing.
Sources
- OSHA: 29 CFR 1904.33, retention and updating
- CMS: State Operations Manual Appendix L, entrance conference requests for ASCs
- CMS: State Operations Manual Appendix PP, F867 adverse event tracking (42 CFR 483.75(c)(4), (e)(2))
- eCFR: 42 CFR 416.43, ASC QAPI
Reviewed against the sources above on Oct 5, 2026. Rules change: confirm current requirements with the issuing body or your counsel before relying on any summary.
Start with one incident.
Create your kit in about ten minutes and report the first incident the same day. Free to start, no card.