Written and maintained by CASRAI Editorial Board
Last updated
Three new cases of the same resistant organism turn up on a step-down unit inside a week. Is that just the background rate of admissions from the community, or is it case one, two and three of a cluster that started before anyone noticed? The answer isn’t a judgment call — it’s the output of a specific, ordered sequence of steps that field epidemiology has used for decades, scaled from state health department investigations down to a single hospital unit. This page walks that sequence as a hospital infection-prevention and patient-safety workflow: what an infection preventionist, patient safety officer, quality director or risk manager actually does at each step, in order, from confirming the diagnosis to communicating the findings.
It picks up after two preliminary steps CDC’s own field epidemiology training places before the numbered sequence — assembling the response and confirming the count actually clears the bar of “more cases than expected” — and it deliberately routes around one step rather than duplicate it: building the epidemic curve itself. That’s a distinct skill with its own decision points (which interval to use, onset date versus specimen date, reading a point-source shape versus a propagated one) and it already has a full, dedicated treatment on this site — see Epidemic Curve: Choosing the Interval, Onset vs Specimen Date, and Bounding the Exposure Window. Here, descriptive epidemiology is one stop in a ten-step sequence, not the destination; follow that link when you actually reach step 4 below.
Before step one: confirm there’s an outbreak, and confirm it’s the right track
CDC’s Principles of Epidemiology in Public Health Practice defines an outbreak as the occurrence of more cases of disease than expected in a given area or among a specific group of people over a particular period of time. In a hospital, “expected” is set by your own endemic baseline for that unit, organism and time window — NHSN’s risk-adjusted device-associated rates (see CLABSI and CAUTI for the specific surveillance criteria those baselines are built from) are usually the reference point, not a national average.
It’s also worth ruling out the wrong track before you start. A single unexpected death or serious harm event is worked as a sentinel event through root cause analysis, not this sequence — the two investigative tracks share some tools (chart review, timeline construction, interviews) but they exist for different triggers and produce different work product. This page is for a cluster: two or more related cases where transmission, a common source, or a process failure is a live hypothesis.
Step 1: Verify the diagnosis
Before spending investigation time on a cluster, confirm the cases are what they appear to be. That means checking the actual laboratory result, not just the ordering clinician’s working diagnosis: was the identification confirmed at the species and resistance-mechanism level, or is it a presumptive result pending confirmatory testing? Is there a plausible pre-analytic explanation — specimen contamination, a shared collection kit, a lab reagent lot issue — that would produce a false cluster rather than a real one? For a healthcare-associated infection cluster, verifying the diagnosis often means re-checking each case against the same NHSN surveillance definition used for reporting (LCBI criteria for CLABSI, SUTI/ABUTI criteria for CAUTI) rather than the bedside clinical impression, since surveillance and clinical diagnosis can diverge.
Step 2: Construct a working case definition
Every case that goes on the line list is a decision, and the case definition is what makes that decision consistent instead of ad hoc. CDC’s field epidemiology course frames a case definition as a standard set of criteria — clinical features, plus restrictions by time, place and person — for deciding whether an individual should be classified as having the condition of interest. Most hospital investigations run tiered definitions (confirmed, probable, suspect) so borderline cases aren’t simply dropped, they’re tracked separately.
One rule from CDC’s course is easy to violate without noticing: the case definition must not include the exposure or risk factor you are actually trying to evaluate. If you’re investigating whether a particular piece of shared equipment caused the cluster, defining a case partly by exposure to that equipment guarantees a spurious association — you’ve built the answer into the question. Keep the case definition to clinical and laboratory criteria; exposure is what step 5 and step 6 test, not what step 2 assumes.
Step 3: Find cases systematically, and build the line list
Passive case finding — waiting for the lab or a clinician to flag the next case — misses cases that were already in the record before anyone was looking for a pattern. Active case finding means going back through the record with the case definition in hand: a retrospective lab query for the organism, a chart review of the affected unit over a defined look-back window, and where relevant, alerting other units or facilities the transmission pathway could plausibly reach (a shared bronchoscope service, a shared agency staffing pool).
Every case found gets one row on a line list: a spreadsheet with one row per case and one column per variable — identifier, unit/room, admission date, symptom onset date, specimen collection date, relevant exposures (procedures, devices, staff assignments, room history), and case-definition tier. The line list is the raw material for every step that follows it, including the epidemic curve itself, which is one column of that line list turned into a histogram.
Step 4: Perform descriptive epidemiology — time, place and person
This is the step that characterizes the outbreak along its three classic axes before you commit to any specific hypothesis:
- Time — the epidemic curve. This is exactly the step the Epidemic Curve guide covers in full: which interval to use, plotting onset versus specimen-collection date, and reading a point-source, continuous common-source, intermittent common-source or propagated pattern. Don’t rebuild that logic here — build the line list in step 3, then follow that guide.
- Place — a spot map. Plot each case by room, bed or workstation on a floor plan; clustering along a corridor, a shared bathroom, or a specific piece of fixed equipment is often visible on a spot map well before it’s provable statistically.
- Person — who got sick and who didn’t, among everyone who could plausibly have been exposed: patient acuity, procedure history, staff assignment pattern, room adjacency, shared equipment or device use.
Descriptive epidemiology generates hypotheses; it doesn’t test them. That’s the next two steps.
Step 5: Develop hypotheses
From the pattern in step 4, generate specific, testable explanations for the source, the vehicle and the mode of transmission — a common environmental source, a colonized or infected staff member, a contaminated shared device, or person-to-person spread with no single point source at all. Open-ended interviews with cases (and, where useful, with unaffected controls on the same unit) at this stage matter more than a structured questionnaire — the goal is to surface an exposure nobody on the investigation team has thought to ask about yet, not to confirm one you’ve already assumed.
Step 6: Evaluate hypotheses epidemiologically
A hypothesis generated from a pattern is not yet a finding. Test it with an analytic study design: a retrospective cohort study if the population is a defined, closed group (everyone on the unit during the exposure window) where you can calculate attack rates directly, or a case-control study if the at-risk population isn’t well defined or is too large to enumerate completely. Cohort study vs case-control study covers how to choose between the two designs and what each one can and can’t tell you about strength of association. If the results don’t hold up — no exposure clears a meaningful relative risk or odds ratio, or the association doesn’t survive stratification — CDC’s course is explicit that this is normal, not a failure: reconsider the case definition, go back to the cases for a broader open-ended interview, and refine the hypothesis rather than forcing a weak association to stand.
Step 7: Compare and reconcile with laboratory and environmental studies
An epidemiologic association is stronger with microbiological confirmation behind it. Where feasible, that means whole-genome sequencing or another molecular typing method to confirm the case isolates are actually related (not just the same species and susceptibility pattern by coincidence), plus environmental or equipment cultures targeting the specific source the hypothesis in step 5 pointed at. When the two lines of evidence agree, the investigation is on solid ground; when they disagree, that disagreement itself is information — it usually means the epidemiologic hypothesis needs another look, not that the lab result should be discounted.
Step 8: Implement control and prevention measures
In practice, control measures don’t wait for step 7 to finish — as soon as a hypothesis is strong enough to act on, most hospital investigations implement interim controls in parallel with the remaining analytic and laboratory work, then adjust as the picture sharpens. Depending on what the investigation points to, that can mean placing or reinforcing transmission-based precautions or enhanced barrier precautions for affected and exposed patients, an enhanced terminal cleaning pass on implicated rooms or equipment, removing or reprocessing a specific piece of shared equipment, cohorting affected patients and staff, or restricting a device or procedure until the source is addressed. Match the control measure to the transmission mode the evidence actually supports — precautions aimed at the wrong route cost effort without closing the exposure.
Step 9: Initiate or maintain surveillance
Confirming an outbreak is over is itself a surveillance decision, not an assumption. The usual practice is to keep active case-finding running for a defined period past the last case — commonly framed as one or two maximum incubation periods for the organism involved, though the right window depends on the specific pathogen and should be set with input from the lab and, where a reportable condition is involved, the local or state health department. A quiet week is not the same thing as a closed outbreak if that window hasn’t elapsed yet.
Step 10: Communicate findings
The investigation isn’t finished when the last control measure is implemented — it’s finished when the findings reach everyone who needs them. In a hospital that typically means a written summary to the infection control committee and hospital leadership, notification to the local or state health department where the organism or condition is reportable (check your jurisdiction’s reportable-conditions list — requirements and timeframes vary by state and by pathogen), and, where relevant, notification to affected patients or families through the channel your risk management program uses for that kind of disclosure.
How that report is framed and where it’s stored matters beyond the immediate response. Work product generated for a patient-safety activity can qualify for protection under the Patient Safety and Quality Improvement Act if it’s routed through a Patient Safety Organization — see Patient Safety Organization Reporting and the Work Product Privilege for what qualifies and what breaks that protection. An outbreak report that mixes protected patient-safety analysis with material that has to be reported externally regardless (like state-reportable disease notifications) needs to keep those two functions clearly separated on paper, not just in intent.
Frequently asked questions
How many cases make something a hospital outbreak?
There’s no fixed number that applies everywhere. An outbreak is defined relative to the expected baseline for that specific organism, unit and time period — two related cases can be a genuine outbreak for an organism with essentially zero endemic baseline on that unit, while the same count for a more common organism might sit inside normal variation. This is why step “before step one” above — confirming the count against your own baseline — comes before the numbered sequence, not after it.
What’s the difference between an outbreak investigation and a root cause analysis?
Root cause analysis is triggered by a single sentinel event — one unexpected death or serious harm — and asks what process failure allowed that one event to happen. An outbreak investigation is triggered by a cluster of related cases and asks what common source or transmission pathway connects them. The two use overlapping tools (timelines, interviews, chart review) but different logic: RCA works backward from one bad outcome, an outbreak investigation works from a pattern across multiple cases toward a shared cause.
What is a line list, and why does it come before the epidemic curve?
A line list is a spreadsheet with one row per case meeting the case definition and one column per variable of interest — onset date, unit, exposures, and so on. It’s the raw dataset the rest of the investigation runs on: the epidemic curve is that dataset’s onset-date column turned into a histogram, the spot map is its location column plotted on a floor plan, and the analytic study in step 6 is built from its exposure columns.
Does the case definition have to include the suspected exposure?
No — deliberately not. CDC’s guidance is explicit that a case definition must not include the exposure or risk factor under investigation, because doing so guarantees a spurious association between the case definition and that exposure. Case definitions are built from clinical and laboratory criteria plus time/place/person restrictions; exposure is what the analytic study in step 6 tests, not what the case definition assumes.
Who typically leads a hospital outbreak investigation?
The infection preventionist usually runs the day-to-day investigation, working with the hospital epidemiologist or medical director for infection prevention, the clinical microbiology lab, and — for reportable organisms or larger clusters — the local or state health department, which may co-lead or take over depending on jurisdiction and scale.








