What a Patient Safety Organization Is

A Patient Safety Organization exists because of a specific problem in law, not a specific problem in medicine.

The problem the statute was written for


If a hospital or a nursing home investigates its own near-miss honestly, writes down what it found, and identifies what has to change, that document becomes evidence. It can be subpoenaed. It can be introduced in a civil proceeding, a disciplinary proceeding, or a licensing action. The more candid the analysis, the more useful it is to a plaintiff.

The predictable result is that nobody writes it down — or the writing is careful rather than honest. The information most likely to prevent the next harm is the information most dangerous to record.

What Congress did about it


The Patient Safety and Quality Improvement Act of 2005, Public Law 109–41, enacted July 29, 2005, created a voluntary framework: providers may report information to a listed Patient Safety Organization, and information that meets the statutory definition of patient safety work product receives federal privilege and confidentiality protection. The statute is codified at 42 U.S.C. §§ 299b–21 to 299b–26; the implementing regulation is the Patient Safety Rule at 42 C.F.R. Part 3, published as a final rule on November 21, 2008.

The privilege — 42 U.S.C. § 299b–22(a): “Notwithstanding any other provision of Federal, State, or local law, and subject to subsection (c), patient safety work product shall be privileged and shall not be… subject to a Federal, State, or local civil, criminal, or administrative subpoena or order…”

The confidentiality — 42 U.S.C. § 299b–22(b): “Notwithstanding any other provision of Federal, State, or local law, and subject to subsection (c), patient safety work product shall be confidential and shall not be disclosed.”

Both are subject to statutory exceptions set out in subsection (c) and in the Patient Safety Rule.

What patient safety work product is


The statute defines it, at 42 U.S.C. § 299b–21(7)(A), as data, reports, records, memoranda, analyses — such as root cause analyses — or written or oral statements assembled or developed by a provider for reporting to a Patient Safety Organization, together with the material a PSO develops in conducting its own patient safety activities.

The definition matters because it is not unlimited. Information a provider is separately required to keep or report — a medical record, a billing record, a mandated state report — does not become protected by routing a copy through a PSO. That boundary is the most commonly misunderstood part of the whole regime.

Why the protection is the mechanism


It is tempting to read the privilege as a legal detail attached to a safety program. It is the other way round. The privilege is the program: it is the thing that changes what a person is willing to say, and everything useful downstream depends on that change.

This has an uncomfortable corollary that a foundation should state rather than hide. The same protection that lets a nurse describe what really happened also means the public cannot read it. A PSO cannot publish its findings about a named facility, and this site cannot tell you what CareGuard found anywhere. Read more: What a Patient Safety Organization actually does.

How an organization becomes a PSO


An entity applies to AHRQ and attests that it meets the statutory and regulatory criteria. If AHRQ accepts the certification, the Secretary of HHS lists the organization, AHRQ assigns a PSO number, and the listing runs for a fixed period. Listing carries continuing obligations — including a requirement to hold two bona fide contracts within each successive 24-month period, disclosure requirements where a PSO has certain relationships with a provider it also contracts with, and a duty to notify AHRQ promptly of changes in listing information or of any inability to comply with its attestations.

CareGuard’s listing →

Questions


Is a PSO a government agency?

No. A PSO is a private organization listed by the Secretary of HHS through AHRQ. Listed is not employed by, deputized by or endorsed by. What we are not. Read more: What a Patient Safety Organization actually does.

Does reporting to a PSO replace reporting to the state?

No. Mandatory reporting obligations are unaffected, and information a provider is separately required to keep or report does not become protected by sending it to a PSO. CareGuard’s own site sets out the official routes: emergencies and official routes. Read more: The things a building does to people.

Can the protection be waived for a good reason?

The exceptions are set by statute and regulation, not by the PSO’s discretion or its parent organization’s. That is precisely why a supporter of this foundation cannot obtain protected information. Independence and boundaries. Read more: What a Patient Safety Organization actually does.

Sources


Every figure on this page is traceable. Where a source is a government report, the year the data describe is named alongside it, because it is usually not the year of publication.

  • U.S. Congress. Patient Safety and Quality Improvement Act of 2005, Public Law 109–41, enacted July 29, 2005; 119 Stat. 424. Codified at 42 U.S.C. §§ 299b–21 to 299b–26. govinfo.gov
  • U.S. Department of Health and Human Services. Patient Safety and Quality Improvement; Final Rule, 73 Fed. Reg. 70732 (November 21, 2008). Codified at 42 C.F.R. Part 3, “Patient Safety Organizations and Patient Safety Work Product.” govinfo.gov

Back to CareGuard