Skip to main content
v2026.11,610 entries · CC-BY 4.0
CASRAIRegulatory RadarNever miss a regulatory change that affects your research officeA daily digest of new regulatory and compliance content, plus 150 questions/day to Ask CASRAI. Built for research administrators and compliance officers.See Regulatory Radar CASRAI · Own product
GuidePatient Safety & Infection Prevention

Patient Safety Organization Reporting and the Work Product Privilege

A Patient Safety Organization (PSO) lets providers report events under a federal confidentiality and privilege protection created by PSQIA and 42 CFR Part 3. Here’s what patient safety work product actually protects, what it doesn’t, and how PSO reporting differs from ordinary incident reporting.

Ask about Patient Safety Organization Reporting and the Work Product Privilege

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

A Patient Safety Organization (PSO) is a federally recognized entity, listed by the Agency for Healthcare Research and Quality (AHRQ), that hospitals and other providers can report patient safety events to on a legally privileged and confidential basis. The framework comes from the Patient Safety and Quality Improvement Act of 2005 (PSQIA), implemented through a federal regulation at 42 CFR Part 3. AHRQ maintains the official, searchable list of listed PSOs and program guidance at pso.ahrq.gov.

This page focuses on how the privilege actually operates and where its boundaries are — not on the mechanics of finding or choosing a specific PSO from AHRQ’s federal listing, which AHRQ’s own site already covers directly. Page checked against AHRQ and eCFR source material in August 2026; the case law interpreting the privilege’s scope is still actively developing, so treat the boundary discussion below as a framework for asking the right questions internally, not a substitute for institutional legal counsel on a specific document.

What “Patient Safety Work Product” Actually Means

The privilege does not attach to an event, a case, or a topic — it attaches to a specific, defined category of material called patient safety work product (PSWP): data, reports, records, memoranda, analyses, and statements that are assembled or developed by a provider for the purpose of reporting to a listed PSO, and that are reported to a PSO, or that are developed by a PSO for patient safety activities. The mechanism providers use to generate this material internally is a documented patient safety evaluation system (PSES) — the defined process, described in the provider’s own policy, by which information is collected and prepared specifically for PSO reporting. Whether something qualifies as PSWP turns heavily on why and how it was created, not just on what it says.

What the Privilege Protects

PSQIA creates two related protections for genuine PSWP:

  • Confidentiality — restrictions on who PSWP can be disclosed to and under what circumstances.
  • Evidentiary privilege — PSWP is generally not admissible or subject to discovery in federal, state, or administrative proceedings, including medical malpractice litigation, licensing board proceedings, and most other civil, criminal, and administrative actions.

42 CFR Part 3, Subpart C sets out the confidentiality and privilege protections in detail, along with a specific, limited list of circumstances in which PSWP can be permissibly disclosed — for example: disclosure of PSWP that has been rendered non-identifiable; disclosure for authorized patient-safety research; disclosure to a accrediting body without identifying a specific provider, under defined conditions; disclosure with the authorizing provider’s consent; and disclosure to a law enforcement or oversight authority in narrow circumstances involving knowing or willful conduct that resulted in serious injury or death, subject to Secretary approval. Outside that list, the default is non-disclosure.

What Is Not Protected — the Boundary Matters More Than the Privilege Itself

The most consequential and most frequently misunderstood part of PSQIA is what it does not cover, and overstating the privilege’s reach is genuinely risky advice to give a clinical team. Do not treat the following as settled, blanket protection:

  • Original records keep their original character. A patient’s medical record, an incident report required by hospital policy independent of PSO reporting, billing records, and other information that is collected or maintained for a purpose other than reporting to a PSO does not become privileged simply because a copy is also submitted into the PSES or forwarded to a PSO. PSQIA privileges the analysis and reporting activity built around the information; it generally does not retroactively privilege the underlying source record.
  • Information required by other law generally stays subject to that other law. State-mandated adverse-event or “never event” reporting to a health department, and information a provider must maintain to satisfy CMS Conditions of Participation, are typically not shielded from their own applicable disclosure rules merely because related material also moved through a PSES.
  • The case law testing these boundaries is genuinely live, not settled. Courts in different jurisdictions have reached different conclusions on close “dual purpose” questions — for example, how to treat documents or data that would have been created anyway to satisfy a separate state or institutional reporting obligation, but that a provider also routes through its PSES. Do not assume a favorable outcome in one court’s reasoning applies uniformly elsewhere. This is an area where institutional legal counsel, not a general reference page, needs to make the specific call for a specific document.

The practical takeaway for a patient safety office: structure your PSES policy deliberately, be explicit in writing about what is and is not created for PSO-reporting purposes, and never assume that “we submitted it to our PSO” is, by itself, enough to make a document undiscoverable. It is a real and often meaningful protection — it is not a categorical shield.

How PSO Reporting Differs From Ordinary Incident Reporting

Most hospitals already run an internal incident- or occurrence-reporting system for day-to-day quality assurance and risk management. That ordinary internal reporting is generally not automatically privileged under PSQIA — it only gains the federal privilege if it is specifically created within a documented PSES for the purpose of PSO reporting. Three practical differences typically separate the two:

  • Purpose at creation. Ordinary incident reports are usually created for internal operational and risk-management awareness first. PSWP is, by definition, created for PSO reporting and analysis.
  • Standardization. Data reported to a PSO is frequently structured using AHRQ’s Common Formats, enabling aggregation and comparison across the PSO’s reporting providers — a scale of pattern detection an individual hospital’s internal system cannot achieve alone.
  • Aggregation and feedback loop. A PSO can pool de-identified data across many providers through AHRQ’s Network of Patient Safety Databases, surfacing systemic patterns (a device failure mode, a medication-error pattern) that a single institution would not see in its own data alone, and feed that learning back to reporting providers.

How This Relates to Sentinel Event and Malpractice Case Review

A sentinel event review and PSO reporting are separate tracks that frequently intersect. Analysis material generated for a Joint Commission comprehensive systematic analysis can also be structured to qualify as PSWP if it’s genuinely created within the PSES for PSO reporting — but routing a sentinel-event RCA through a PSO does not substitute for, or change the timeline of, the Joint Commission’s own review requirement. Similarly, discussion of a case at a morbidity and mortality conference does not automatically create either PSQIA privilege or state peer-review privilege — both depend on how the underlying material was actually created and documented, not on the label given to the meeting where it was discussed.

AHRQ’s Role

AHRQ lists and conducts outreach to PSOs, publishes the Common Formats used for standardized event reporting, and operates the Network of Patient Safety Databases that aggregates non-identifiable data across participating PSOs. AHRQ does not itself receive identifiable PSWP or investigate individual events — its role is programmatic (listing, standards, aggregation), not case-level.

Frequently Asked Questions

Does reporting to a PSO make information completely undiscoverable in a lawsuit?

No. It creates a real evidentiary privilege for material that genuinely qualifies as patient safety work product, but original records and information required by other law generally are not protected simply because they were also submitted to a PSO. The boundary is fact-specific and the case law is still developing — treat this as a real but bounded protection, not a categorical shield.

Is choosing or working with a specific PSO covered here?

No — AHRQ’s own federal PSO listing at pso.ahrq.gov is the authoritative, current directory of listed PSOs. This page focuses on how the underlying privilege works, which is the part a directory listing doesn’t explain.

Does PSO reporting replace state-mandated adverse-event reporting?

No. State-mandated reporting obligations to a health department operate independently of PSO reporting and generally are not satisfied or shielded by it.

Who administers the PSQIA framework?

The Agency for Healthcare Research and Quality (AHRQ), under the U.S. Department of Health and Human Services, administers the PSO listing program under the implementing regulation at 42 CFR Part 3.

See the Patient Safety & Infection Prevention hub, and related coverage of sentinel events and National Patient Safety Goals.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →