Patient safety organization · PSO

What a Patient Safety Organization Actually Does

Physician reviewing a patient chart at the bedside in a hospital room

A Patient Safety Organization is a private, federally listed organization where providers can report what actually went wrong, and that patient safety work product becomes privileged and confidential under the Patient Safety and Quality Improvement Act of 2005. It is not a regulator: it cannot cite, fine or license, and it cannot publish findings about a named facility.

People hear “Patient Safety Organization” and picture an inspector. It is closer to the opposite: a PSO is a place where the truth can be told.

The problem the statute solves


Suppose a nursing home nearly loses a resident and investigates properly. Somebody writes down what actually happened, including the parts that reflect badly on the organization, and identifies what has to change.

That document is now evidence. It can be subpoenaed, discovered, introduced in a civil or administrative proceeding, or used in a professional disciplinary action. The more candid the analysis, the more valuable it is to someone suing.

The rational response is not to write it, or to write something careful instead. The information most likely to prevent the next harm is the information most dangerous to record. That is a structural trap, and no amount of exhorting people to be honest gets out of it.

What law created patient safety organizations?


The Patient Safety and Quality Improvement Act of 2005 — Public Law 109–41, enacted July 29, 2005 — created a voluntary system. Providers may report to a listed Patient Safety Organization, and information meeting the statutory definition of patient safety work product gets federal privilege and confidentiality. It is codified at 42 U.S.C. §§ 299b–21 to 299b–26, and implemented by the Patient Safety Rule at 42 C.F.R. Part 3, published as a final rule on November 21, 2008.

The operative language at 42 U.S.C. § 299b–22(b) is short: patient safety work product “shall be confidential and shall not be disclosed,” subject to statutory exceptions.

What is the purpose of a patient safety organization?


It is tempting to read the privilege as legal housekeeping attached to a safety program. It is the reverse. The privilege is the program — it is what changes whether a person is willing to say the true thing — and everything downstream is built on that change.

The statute in more detail.

What can’t a patient safety organization do?


  • Not a regulator. A PSO cannot cite, fine, sanction or license. It does not conduct state surveys.
  • Not a substitute for mandatory reporting. Reporting obligations are unaffected, and information a provider must separately keep or report does not become protected by copying it to a PSO.
  • Not government. A PSO is a private organization listed by the Secretary of HHS through AHRQ. Listed is not endorsed. PSO P0268.
  • Not a publisher. This is the uncomfortable one.

Can a patient safety organization publish what it finds?


The same rule that lets a nurse describe what really happened means the public cannot read it. A PSO cannot publish findings about a named facility. Its parent organization cannot see them either — the protection is federal, not discretionary, and a parent is not an exception.

That is why this foundation’s site can tell you that CareGuard reviews facilities and cannot tell you a single thing it found. It is a real cost, borne on purpose, and any honest description of a PSO has to include it. The boundaries.

Why a scale of harm justifies the trade


The HHS Office of Inspector General’s national study of Medicare skilled nursing facility stays, sampled in August 2011, estimated that 22 percent of beneficiaries experienced adverse events during their stays and a further 11 percent experienced temporary harm — and that physician reviewers judged 59 percent of those events clearly or likely preventable.

The word doing the work there is preventable. It means the information existed somewhere before the harm did. A protection that makes that information sayable is not a technicality.

Frequently asked questions


Is a patient safety organization a regulator?

No. A PSO cannot cite, fine, sanction or license anyone, and it does not conduct state surveys. Reporting to a PSO is voluntary. Its value is different: patient safety work product reported to it becomes privileged and confidential under the Patient Safety and Quality Improvement Act of 2005, so a provider can write down what actually went wrong without creating evidence against itself.

Is a patient safety organization part of the government?

No. A PSO is a private organization listed by the Secretary of Health and Human Services through AHRQ. Listed is not endorsed. The federal role is the listing and the legal protection that attaches to patient safety work product; the PSO itself is not a government agency and does not act like one.

What is an example of a patient safety organization?

CareGuard, a division of Sevadar Foundation, is a listed Patient Safety Organization, number P0268. It reviews care facilities under the federal protections described on this page. That is why this site can say CareGuard reviews facilities but cannot tell you anything it found: the findings are privileged and confidential, even from the foundation that is its parent.

Does reporting to a PSO replace mandatory reporting?

No. Mandatory reporting obligations are unaffected. Information a provider must separately keep or report does not become protected just because a copy goes to a PSO. The privilege covers patient safety work product as the statute defines it, not records the provider already owes to a regulator or anyone else.

Sources


Every figure on this page is traceable. Where a source is a government report, the year the data describe is named alongside it, because it is usually not the year of publication.

  • U.S. Congress. Patient Safety and Quality Improvement Act of 2005, Public Law 109–41, enacted July 29, 2005; 119 Stat. 424. Codified at 42 U.S.C. §§ 299b–21 to 299b–26. govinfo.gov
  • U.S. Department of Health and Human Services. Patient Safety and Quality Improvement; Final Rule, 73 Fed. Reg. 70732 (November 21, 2008). Codified at 42 C.F.R. Part 3, “Patient Safety Organizations and Patient Safety Work Product.” govinfo.gov
  • U.S. Department of Health and Human Services, Office of Inspector General. Adverse Events in Skilled Nursing Facilities: National Incidence Among Medicare Beneficiaries. Report OEI-06-11-00370, February 27, 2014. Data describe a sample of Medicare SNF stays in August 2011. oig.hhs.gov
  • Agency for Healthcare Research and Quality. Listed PSO directory entry for CareGuard, PSO P0268. pso.ahrq.gov/pso/careguard
Contact the Foundation