Written and maintained by CASRAI Editorial Board
Last updated
A near miss, a medication that reached a patient without harm, and a wrong-site surgery all get reported into the same intake system — but they cannot get the same downstream response. The decision that sorts them is severity classification: a graded scale, assigned after intake by a trained reviewer, that determines how deep the investigation goes and what the organization is obligated to do next. Written for patient-safety officers, quality directors, risk managers and infection preventionists who own or sit on the event-review process, not for frontline staff filing a single report.
Why classification is a triage step, not a label
Severity classification is easy to mistake for paperwork — a field in the event-review record that gets filled in after the fact. In a working safety programme it is the opposite: it is the decision that routes everything downstream. Two events can look similar on the intake form and diverge completely once a trained reviewer scores them, because the score — not the raw description — is what determines:
- Investigation depth. A short, single-reviewer look at the apparent cause, a full multidisciplinary root cause analysis, or aggregation into a batch of similar low-harm events for a common-cause analysis.
- Reporting obligation. Whether the event stays inside the organization’s internal quality record, gets logged for state mandatory-reporting purposes, or triggers a Joint Commission self-report window for accredited organizations.
- Timeline. A same-day internal review versus a formal process with a defined completion deadline.
Our guide on designing a hospital incident-reporting system makes the case for keeping this scoring step out of the intake form itself — a frontline reporter shouldn’t have to pre-judge severity under time pressure. This guide picks up exactly where that one leaves off: it’s about the scale trained reviewers apply once a report reaches the review stage, and what each tier on that scale actually triggers.
The graded scale: adapting NCC MERP for general event reporting
The best-known graded harm scale in U.S. healthcare is the NCC MERP Index for Categorizing Medication Errors, published by the National Coordinating Council for Medication Error Reporting and Prevention. It was built for medication events specifically, running from Category A (circumstances or events with the capacity to cause error, but no actual error) through Category B and C (an error occurred but didn’t reach the patient, or reached the patient without harm), into increasing degrees of harm, up to Category I (an error contributed to a patient’s death).
Most hospitals don’t build a second scale from scratch for general safety events. They adapt the same underlying no-harm-to-death gradient — the same principle, not necessarily the same nine letters — to score any reported event, medication-related or not. A workable general-purpose version collapses to a small number of tiers a reviewer can apply consistently:
- Near miss / good catch — the unsafe act or condition was caught before it reached the patient at all.
- Unsafe condition — no event has occurred yet, but the setup (equipment, staffing, environment) is one lapse away from causing one.
- Reached the patient, no harm — the event occurred but caused no detectable harm, sometimes with monitoring required to confirm that.
- Temporary harm — harm occurred that required intervention or monitoring but resolved without lasting effect.
- Serious or permanent harm — harm that is severe, prolonged, or permanent.
- Death — the event contributed to the patient’s death.
The bottom two tiers and the top tier do specific work in the system beyond just describing what happened. Serious/permanent harm and death are exactly the outcomes that can meet the Joint Commission’s sentinel-event definition — a patient safety event, not primarily related to the natural course of the patient’s illness, that results in death, permanent harm, or severe temporary harm. Meeting that definition is what triggers the accreditation-driven review requirement described on that page, independent of whether the organization chooses to self-report. Near misses and unsafe conditions, by contrast, are what feed a common-cause analysis when aggregated across many low-harm reports rather than investigated one at a time (more below).
Keep the classification step separate from the intake step
One design point is worth restating because it’s easy to get backwards: the reporter filing the initial report is generally in the worst position to score severity accurately. They may not yet know whether an apparently minor event will turn out to have caused lasting harm, and a form that forces that judgment at the point of filing is a documented reason people abandon reporting altogether. Classification belongs to a trained reviewer, done against a consistent, written scale, after the facts of the case — chart review, clinician follow-up, monitoring outcomes — are actually known. Applying the scale consistently across reviewers matters as much as picking the right scale: a written rubric with example cases for each tier, and periodic calibration sessions where reviewers score the same case independently and compare, catches the drift that happens when severity becomes a matter of individual judgment call.
How severity determines investigation depth
Severity classification is the triage decision that sits upstream of choosing which investigation method to use. The three methods below aren’t interchangeable options a reviewer picks freely — each is scoped to a severity band, and the classification step is what assigns an event to one:
| Severity tier | Typical investigation | Why |
|---|---|---|
| Near miss / unsafe condition (individually) | Logged, not individually investigated | Too low-signal on its own to justify a full review of a single instance |
| Near misses and low-harm events, aggregated | Common-cause analysis | Looks for a shared cause across a batch of similar low-severity reports rather than treating each as an isolated case |
| Reached the patient, no harm to temporary harm, with an evident single cause | Apparent cause analysis (ACA) | A short chain of “why” questions to the first plausible, sufficient cause is proportionate when the cause is uncomplicated and the harm is limited |
| Sentinel events and serious, complex, or likely-to-recur harm | Root cause analysis (RCA), graded by an RCA²-style action hierarchy | The multidisciplinary, systems-level process the severity and stakes justify — see the comparison above for exactly what RCA does that ACA skips |
Two things worth being precise about. First, escalation only ever runs one direction: a case that starts as an apparent cause review can be escalated to a full RCA if it turns out to be more complex than the initial severity score suggested, but a sentinel-level event is never downgraded to a lighter review after the fact. Second, common-cause analysis operates on a different unit of analysis than the other two — it isn’t a lighter version of RCA applied to one event, it’s a method for finding a shared cause across many events that individually didn’t meet the bar for a standalone investigation. A reviewer scoring severity is effectively answering “which of these three lanes does this belong in,” and getting that sorting right the first time is what keeps a safety office’s limited investigation capacity pointed at the events that most need it.
How severity determines reporting obligation
The same classification also determines what the organization owes, and to whom, once the review is done:
- Internal quality record only. Most near misses, unsafe conditions, and no-harm events stay inside the organization’s own quality-improvement process — reviewed, trended, and used to drive changes, with no external reporting requirement attached to the individual case.
- State mandatory event reporting. A number of states require hospitals to report defined categories of serious adverse events — often built around the National Quality Forum’s Serious Reportable Events list — to a state health department. Requirements vary by state; check your jurisdiction’s specific statute and reportable-event list rather than assuming a national standard applies.
- Joint Commission self-report, for accredited organizations. An event that meets the sentinel-event definition triggers the expectation of a full internal review regardless of self-reporting, and organizations that do self-report (or whose event becomes known to the Joint Commission another way) are expected to submit a completed analysis and corrective action plan within a defined window.
- Patient Safety Organization submission. If reports are routed through a PSO relationship, the underlying data can carry federal privilege as patient safety work product under PSQIA — but that privilege has real limits, and records required by other law generally aren’t shielded merely for having also passed through a PSO. See our guide on PSO reporting and the work-product privilege for what it does and doesn’t protect.
Because these obligations stack — a single serious event can be simultaneously subject to internal review, a state reporting requirement, and Joint Commission expectations — getting the severity call right at intake isn’t just an investigation-method decision. Under-classifying a case that actually meets the sentinel-event threshold risks missing a real reporting obligation; over-classifying routine events dilutes reviewer time and, in a PSO-routed system, adds unnecessary reporting volume without adding signal.
Building consistency across reviewers
A severity scale is only as reliable as the reviewers applying it. A few practices keep classification decisions defensible and repeatable:
- Write the scale down with example cases for each tier, not just abstract definitions — “reached the patient, required extra monitoring but no treatment” reads very differently to different reviewers without a concrete anchor case.
- Score after the facts are in, not at first report — outcome, not intent or process deviation, generally drives the tier, and outcome often isn’t known until follow-up.
- Calibrate periodically. Have two or more reviewers independently score the same set of past cases and compare; persistent disagreement on where the near-miss/no-harm line or the moderate/serious-harm line falls is a sign the written rubric needs sharper anchor language, not that classification is inherently subjective.
- Route escalation decisions through a second reviewer for boundary cases — an event that could plausibly sit just above or below the sentinel threshold is exactly where a second opinion earns its cost, given what sits on the other side of that line.
Frequently asked questions
Is severity classification the same as the Just Culture algorithm?
No — they classify two different things. Severity classification scores the outcome: how much harm occurred or nearly occurred, which determines investigation depth and reporting obligation. The Just Culture algorithm is a separate decision tree that classifies an individual’s behavior — human error, an at-risk choice, or reckless conduct — after the facts are known. A single event gets scored on both dimensions independently; a high-severity outcome doesn’t imply reckless behavior, and a near miss can still surface a behavior worth addressing through the Just Culture process.
Who should be doing the classification — the reporter or a reviewer?
A trained reviewer, not the person who filed the initial report. Reporters generally can’t yet know the eventual outcome at the moment they file, and asking them to pre-judge severity is a documented cause of abandoned reports. Keep the intake form’s severity field shallow (near miss / unsafe condition / event with harm, at most) and do the fine-grained tiering as a separate review step.
Does every serious-harm event automatically require a root cause analysis?
Events that meet the sentinel-event definition — death, permanent harm, or severe temporary harm not primarily related to the patient’s underlying condition — are expected to receive a full comprehensive systematic analysis (RCA) regardless of whether the organization self-reports to the Joint Commission. Serious harm that falls short of the sentinel threshold is more often handled with apparent cause analysis, escalated to RCA if the review surfaces something more complex than it first appeared.
How is common-cause analysis different from scoring an individual event’s severity?
Severity classification operates on one event at a time. Common-cause analysis operates on a batch of similar lower-severity events — near misses and no/low-harm reports — aggregated over time to look for a shared underlying cause that wouldn’t be visible from any single case. An event doesn’t get a CCA instead of a severity score; low-severity events are still individually classified, and it’s the aggregate pattern across many of them that a CCA investigates.








