Compliance

    Patient Safety Event Reporting: Federal and State Requirements

    Patient safety event (PSE) reporting is governed by overlapping federal and state requirements. The Patient Safety and Quality Improvement Act of 2005 (PSQIA) created a voluntary federal framework through Patient Safety Organizations (PSOs), while most states mandate reporting of specific adverse events to health departments. Surgical practices must navigate both systems. This guide breaks down what must be reported, to whom, and the legal protections that apply.

    Federal Framework: PSQIA and Patient Safety Organizations

    • The Patient Safety and Quality Improvement Act of 2005 (42 USC 299b-21 through 299b-26) established Patient Safety Organizations (PSOs) as entities that collect, aggregate, and analyze patient safety data submitted voluntarily by providers.
    • Patient Safety Work Product (PSWP) reported to a listed PSO receives federal legal privilege and confidentiality protections under 42 CFR Part 3. This means PSWP cannot be used in civil, criminal, or administrative proceedings and is not subject to discovery or subpoena.
    • To qualify for PSWP protections, the information must be assembled or developed for reporting to a PSO. Incident reports created solely for internal use or state reporting obligations do not automatically qualify. Providers must establish a Patient Safety Evaluation System (PSES) that clearly defines how information flows to the PSO.
    • The Agency for Healthcare Research and Quality (AHRQ) maintains the list of federally certified PSOs. As of 2025, AHRQ lists approximately 80 active PSOs. Providers can find listed PSOs by specialty and state at the AHRQ PSO website.

    State Mandatory Reporting: What Must Be Reported

    • Twenty-seven states and the District of Columbia have mandatory adverse event reporting laws, according to the National Academy for State Health Policy (NASHP). Requirements vary significantly by state in terms of which events are reportable, the reporting timeframe, and the receiving agency.
    • The National Quality Forum (NQF) Serious Reportable Events list (updated 2023) identifies 29 events across six categories: surgical (wrong site, wrong patient, wrong procedure, retained foreign object), product/device, patient protection, care management, environmental, and radiologic. Many states base their mandatory reporting lists on the NQF events.
    • Reporting timeframes range from immediate (within hours for certain sentinel events in states like New York and Pennsylvania) to within 5 to 30 business days for less acute events. California (CDPH) requires reporting of adverse events within 5 business days of detection under Health and Safety Code Section 1279.1.
    • Failure to report a mandatory event carries penalties that vary by state: California imposes fines of $50,000 to $100,000 per violation. New York can impose civil penalties and licensure actions through the Department of Health. Pennsylvania applies the Medical Care Availability and Reduction of Error Act (MCARE Act) penalties.

    Sentinel Events and The Joint Commission

    • The Joint Commission (TJC) defines a sentinel event as a patient safety event that reaches a patient and results in death, permanent harm, or severe temporary harm requiring intervention to sustain life. TJC-accredited facilities are expected (not legally required) to report sentinel events and complete a root cause analysis (RCA) within 45 business days.
    • TJC distinguishes between sentinel events and reviewable sentinel events. TJC reviews cases involving wrong-patient, wrong-site, or wrong-procedure surgery; unintended retention of a foreign object; and several other categories. Self-reporting is voluntary, but TJC may become aware of events through complaints, media reports, or CMS notifications.
    • For non-TJC-accredited facilities (many ASCs and dental surgical offices), sentinel event reporting to TJC does not apply. However, state reporting requirements still apply based on the event type and the facility's state licensing category.
    • CMS requires Medicare-certified facilities to report certain events through the Quality Incident Management System (QIMS) as part of Conditions of Participation. CMS surveys may also review incident reports during periodic inspections.

    Building an Effective Reporting System

    • Establish a dual-track system: one track for state mandatory reporting (which has no confidentiality protections) and a separate track for voluntary PSO reporting (which has PSQIA privilege). Label documents clearly to preserve the legal distinction.
    • Implement a near-miss reporting culture. The AHRQ Patient Safety Network estimates that near-misses outnumber actual adverse events by a ratio of 300 to 1 (based on Heinrich's Triangle). Capturing near-misses identifies system vulnerabilities before patients are harmed.
    • Use standardized event classification (such as the AHRQ Common Formats version 2.0) for consistent data collection. Common Formats provide structured templates for surgical events, medication events, device events, and falls.
    • Train all clinical staff on the difference between incident reports (state-reportable, not privileged) and PSES submissions (PSO-reportable, privileged). Mislabeling can inadvertently waive PSQIA protections.
    Related
    Frequently asked

    Questions patients ask.

    Does reporting a patient safety event to a PSO protect me from a malpractice lawsuit?

    PSQIA protects Patient Safety Work Product (PSWP) from discovery, subpoena, and use in legal proceedings. It does not prevent a lawsuit from being filed. The patient's medical record, which is not PSWP, remains discoverable. PSQIA protects the analysis, root cause investigation, and improvement recommendations submitted to the PSO. To maintain this protection, the information must be clearly developed within your Patient Safety Evaluation System and reported to a listed PSO.

    What is the difference between an adverse event and a sentinel event?

    An adverse event is any harm to a patient caused by medical management (rather than the underlying disease). A sentinel event is a subset: an adverse event that results in death, permanent harm, or severe temporary harm requiring life-sustaining intervention. Not all adverse events are sentinel events. For example, a surgical site infection is an adverse event. A wrong-site surgery resulting in permanent disability is a sentinel event. The distinction matters because sentinel events trigger different reporting obligations and response requirements.

    My state does not have mandatory reporting. Do I still need to report events?

    Even without a state mandate, Medicare Conditions of Participation require reporting and investigation of certain events for certified facilities. If you are TJC-accredited, sentinel event reporting is expected under accreditation standards. Voluntary PSO reporting is available in all states and provides legal protections for the reported data. Additionally, professional liability insurers typically require notification of adverse events as a policy condition. The absence of a state mandate does not eliminate all reporting obligations.

    How do I find a PSO for my surgical practice?

    AHRQ maintains a searchable directory of listed PSOs at pso.ahrq.gov. Filter by state and specialty to find PSOs that serve surgical practices. Many PSOs offer specialty-specific programs for orthopedic, dental, and ambulatory surgery practices. Evaluate PSOs based on their reporting platform, data analysis capabilities, benchmark reports, and cost structure. Some professional societies (such as the American College of Surgeons) operate their own PSOs for member practices.

    For practices

    Bring this to your own practice.

    QR Rx turns every procedure into a branded recovery plan that keeps patients engaged and brings them back. Start free in minutes, or see it live in a 20-minute demo.

    Start free trial

    This blog provides general information about healthcare compliance and aftercare best practices. It does not constitute legal, medical, or regulatory advice. Consult qualified professionals for guidance specific to your practice.