Skip to main content
v2026.11,610 entries · CC-BY 4.0

Two Patient Identifiers: The Approved List, and Where the Requirement Applies

What the Joint Commission’s two-patient-identifier requirement actually covers: the approved identifier list, why room number is explicitly excluded, and the specific verification points — specimen collection, medication and blood product administration, and procedures — where it applies.

Ask about Two Patient Identifiers: The Approved List, and Where the Requirement Applies

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

A specimen drawn from the wrong patient, or a medication given based on a room number rather than a confirmed identity, is exactly what the two-identifier rule exists to catch before it happens. This page covers the current Joint Commission requirement in the form a hospital patient safety officer, quality director, infection preventionist, or risk manager actually needs it: which identifiers count, which ones don’t — room number chief among the disqualified — and the specific points in care where verification is required, not optional.

The Rule in One Sentence

Before providing care, treatment, or a service, staff must use at least two person-specific patient identifiers — neither of which may be the patient’s room number or physical location — to confirm the right patient is about to receive the right specimen collection, medication, blood product, treatment, or procedure. This is the substance of what has long been cited as NPSG.01.01.01, and it is one of the oldest, most stable requirements in the National Patient Safety Goals program: the core two-identifier expectation has not materially changed in over a decade, even as its chapter home and numbering have.

Approved Identifiers — What Counts

An acceptable identifier is anything that reliably distinguishes one specific patient from every other patient in the facility and does not change based on where that patient happens to be. In practice, hospitals typically draw from:

  • Patient’s full legal name — as documented in the medical record, not a nickname or preferred-but-unregistered name used in isolation.
  • Date of birth — spoken back by the patient (or a family member/caregiver when the patient cannot respond) rather than read aloud by staff and simply confirmed with a “yes.”
  • Medical record number (MRN) — the facility-assigned unique identifier, typically confirmed against the wristband or the chart, not asked of the patient verbally since most patients don’t know their own MRN.
  • Assigned identification number — an account or visit number distinct from the permanent MRN, where a facility’s registration system generates one per encounter.
  • Telephone number, or another person-specific identifier a facility has validated as reliably unique in its own patient population.

The two identifiers used together must be genuinely independent of each other — two data points that could both be wrong in the same way (for example, both pulled from the same mislabeled wristband without any spoken confirmation) don’t provide the redundancy the requirement is built around. Best practice, and what surveyors look for on a tracer, is an active process: asking the patient to state their name and date of birth, then matching what’s stated against the wristband and the order, rather than a passive process of simply reading the wristband and asking the patient to confirm.

What Does Not Count — Room Number and Location

The Joint Commission’s standard explicitly excludes the patient’s room number or physical location as an acceptable identifier, and this is the single most common finding cited on tracer activity for this requirement. The reasoning is direct: patients are moved, rooms are reassigned, beds are shared or renumbered, and two patients can occupy adjacent locations at the same time. A process that relies on location as one of its two identifiers — “the patient in bed 4,” a chart left at a bedside without independent name/DOB confirmation, a specimen labeled by which room it was drawn in rather than confirmed against the patient — is exactly the failure mode the two-identifier rule exists to close off. This applies whether the location reference is spoken (“give this to the patient in 214”) or embedded in a workflow shortcut, such as pre-printing labels by room assignment before specimens are actually collected.

The Verification Points — Where It Applies

The requirement is not a single check performed once at admission. It applies at each of the following points, independently, every time:

  • Before any specimen collection. Both the patient and the specimen container must be confirmed — labeling happens at the bedside, in the presence of the patient, immediately after collection, not in a batch afterward. A specimen labeled before or after the two-identifier check, rather than at the moment of collection, defeats the purpose of the check.
  • Before administering any medication or blood product. This sits alongside, and is distinct from, the separate blood/blood product verification and matching process required for transfusions specifically — the two-identifier check confirms the right patient; transfusion-specific protocols additionally confirm blood type and product compatibility. See the site’s massive transfusion protocol guide for how that additional layer works during an active transfusion event.
  • Before any treatment or procedure. For surgical and invasive procedures specifically, this identification step is one component of the broader Universal Protocol time-out, which also verifies correct site, correct procedure, and correct patient through a distinct, more comprehensive checklist — the two-identifier check is necessary but not sufficient for that context.

Each of these is a discrete verification event. A patient correctly identified at admission, or correctly identified an hour earlier for a medication pass, has not been verified for a specimen collection that happens afterward — the check has to repeat at each point of care, not carry forward from the last time someone checked.

What Changed for Hospitals in 2026, and What Didn’t

Effective January 1, 2026, The Joint Commission replaced the National Patient Safety Goals chapter with a new National Performance Goals (NPG) chapter for the Hospital and Critical Access Hospital accreditation programs specifically — a restructuring covered in full in our NPSG/NPG guide. Accurate patient identification before care, treatment, or a procedure remains one of the recurring safety priorities carried into that renamed chapter; the substance of the two-identifier requirement described on this page has not been removed or weakened by the rename. What has changed is the citation: internal policies, training materials, and audit tools that still reference “NPSG.01.01.01” by that exact number need to be cross-walked to whatever the current NPG numbering assigns this requirement, rather than assuming the old citation still resolves correctly in your accreditation manual. Ambulatory, Behavioral Health Care and Human Services, Home Care, Laboratory, Nursing Care Center, and Office-Based Surgery programs continue to operate under the traditional NPSG chapter and numbering for 2026 — a hospital that also runs an accredited ambulatory clinic or laboratory under the same organization needs to track both structures. Confirm the exact current goal number against your program’s live accreditation manual before citing it in a policy document; treat any specific number stated here or elsewhere as provisional until checked against that source.

Common Implementation Failures

The requirement itself is simple; the gaps that survey findings and root-cause analyses repeatedly surface are process gaps around it, not confusion about the two-identifier concept itself:

  • Passive confirmation instead of active confirmation. Reading the wristband aloud and asking “is this you?” produces a “yes” regardless of accuracy, especially from a sedated, confused, or simply agreeable patient. Asking the patient to independently state their name and date of birth, unprompted, is the more reliable pattern.
  • Batch labeling. Pre-labeling specimen containers or medication doses for multiple patients before individually confirming each one reintroduces exactly the mix-up risk the point-of-care check is meant to prevent.
  • Wristband as the sole source. A wristband that’s wrong, missing, or on the wrong patient defeats a process built entirely around scanning or reading it, with no independent spoken confirmation as a second, genuinely separate check.
  • Identification skipped for patients who “are known.” A returning patient, a staff member’s own relative, or a patient the care team has worked with for days is not exempt — familiarity is a documented contributor to identification errors precisely because it invites a skipped step.
  • Non-verbal or language-discordant patients handled inconsistently. When a patient cannot state their own name and date of birth, the process needs a defined fallback (a second staff member, a family member/caregiver, or a documented alternative verification method) rather than an ad hoc one improvised at the bedside.

These are the patterns a tracer is specifically designed to surface, since a tracer follows a real patient’s actual care sequence rather than reviewing a policy document in isolation. A written policy that states the two-identifier rule correctly is not evidence that the rule is followed at the bedside; the gap between policy and practice is where most identification-related findings originate.

Where This Fits Alongside Other Patient-Identification Safeguards

The two-identifier check is a manual, procedural safeguard — it doesn’t require barcode scanning, RFID, or any specific technology, though many facilities layer barcode-based positive patient identification on top of it as an additional control rather than a replacement for it. A barcode scan that matches a wristband to an order confirms the same two data points (typically MRN and an encoded check value) that the manual process confirms verbally; it does not, by itself, satisfy the requirement if the underlying wristband was applied to the wrong patient in the first place. When a misidentification event does occur and results in harm, it’s evaluated through the separate Sentinel Event review process rather than through the NPSG/NPG framework itself — the identification goal is the preventive requirement; sentinel event review is what happens after prevention has already failed. Work product generated during that review, including root-cause analysis, may carry PSQIA privilege protections if routed through a Patient Safety Organization — see Patient Safety Organization Reporting and the Work Product Privilege for how that protection does and doesn’t apply.

Frequently Asked Questions

Can a patient’s wristband serve as both of the two required identifiers?

Not on its own in most implementations. A single wristband typically encodes name and MRN together as one artifact; if it’s on the wrong patient, checking it twice doesn’t produce two independent confirmations. The stronger, surveyor-preferred pattern pairs a spoken, patient-stated identifier (name, date of birth) with an independent check against the record or wristband, so a single point of failure can’t defeat both checks at once.

Is the patient’s room number ever acceptable as one of the two identifiers?

No. Room number and bed location are explicitly excluded because they aren’t stable to the patient — rooms get reassigned, patients get moved, and two people can occupy nearby locations simultaneously. Any process that uses location, even informally, as a stand-in for identity confirmation does not meet the requirement.

Does this requirement still apply to hospitals in 2026 now that NPSGs were renamed?

Yes. The Hospital and Critical Access Hospital programs moved to a renamed National Performance Goals chapter effective January 1, 2026, but accurate patient identification before care, treatment, or a procedure remains one of the safety priorities carried into that chapter. What changed is the citation number and chapter name, not the underlying obligation to use two identifiers at each verification point.

How does the two-identifier check differ from the Universal Protocol time-out?

The two-identifier check confirms which patient is in front of you; the Universal Protocol time-out, used immediately before surgical and other invasive procedures, additionally confirms correct site, correct procedure, and correct patient positioning through a separate, more comprehensive team verification. Patient identification is one input into the time-out, not a substitute for it.

What’s the difference between this and blood product verification for a transfusion?

The two-identifier check confirms patient identity generally, at any point of care. Transfusion-specific protocols layer additional verification on top — confirming blood type and product compatibility against the specific unit being administered — because a transfusion carries risks (ABO incompatibility) that correct patient identification alone does not fully address.

See the Patient Safety & Infection Prevention hub for related coverage, including the full NPSG/NPG 2026 rename, sentinel event review, and Patient Safety Organization reporting and privilege.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.