Patient safety work product
Two different protections get discussed on this site, and conflating them would be the easiest mistake to make. They are separate mechanisms with separate rules.
Patient safety work product — the federal mechanism
Under the Patient Safety and Quality Improvement Act of 2005 and the Patient Safety Rule at 42 C.F.R. Part 3, information developed by a provider within a patient safety evaluation system for reporting to a PSO can qualify as patient safety work product, which carries federal confidentiality and privilege protections. The Rule defines the terms — patient safety evaluation system, patient safety work product, disclosure, provider, workforce — at § 3.20, sets out confidentiality at § 3.206, and nonidentification at § 3.212.
The design intent is straightforward: a facility that can analyze its own failures without building the evidence against itself will analyze more of them. The Rule also contains exceptions to confidentiality — the disclosure permissions at § 3.206(b) — and the protections are not unlimited.
The regulation itself is public: 42 C.F.R. Part 3 in the eCFR.
Attorney work product — the mechanism the reporting channel uses
The CareGuard reporting channel transmits incident reports to the facility’s designated legal counsel, so that they are created for the attorney’s review rather than as routine business records. That is a different body of law with different tests, and it belongs to the facility and its lawyers, not to CareGuard. Legal work product.
Why they are described separately here
Because they protect different things, apply to different documents, and fail in different ways. Saying “your report is federally protected” would be sloppy at best. What is accurate is narrower: the reporting channel is designed to route reports to counsel, CareGuard retains no copy, and CareGuard’s status as a listed PSO is a separate fact about CareGuard.
None of this is legal advice. How either protection applies to a particular document in a particular proceeding is a question for a facility’s own counsel and, ultimately, a court. Anyone relying on either should get their own advice before they rely on it.
What this does not do
Neither mechanism turns a report into a filing with a regulator, and neither discharges a mandatory reporting obligation. Emergencies and official routes.
The statute and the rule, quoted
AHRQ states the statutory basis in one sentence: “On July 29, 2005, the President signed the Patient Safety and Quality Improvement Act of 2005 (Patient Safety Act, 42 U.S.C. sections 299b-21 to 299b-26) into law.” It was enacted as Public Law 109-41.
What it did: “The Patient Safety Act amended Title IX of the Public Health Service Act to provide for the improvement of patient safety and to reduce the incidence of events that adversely affect patient safety by authorizing the creation of patient safety organizations (PSOs). PSOs work with providers to improve quality and safety through the collection and analysis of aggregated, confidential data on patient safety events.”
AHRQ’s own description of what a PSO is: “A Patient Safety Organization (PSO) works with healthcare providers to help them improve patient safety and healthcare quality and encourage a culture of safety. PSOs analyze data voluntarily reported by providers and provide feedback aimed at promoting learning and minimizing patient risk.” Two further facts from the same source are worth stating plainly: PSOs do not receive federal funding, and while AHRQ handles listing, it is the HHS Office for Civil Rights that “administers and enforces the confidentiality protections provided to PSWP.”
Patient safety work product, as the rule defines it
The implementing regulation is the Patient Safety Rule, 42 C.F.R. Part 3, titled “Patient Safety Organizations and Patient Safety Work Product.” Section 3.20 defines patient safety work product as “any data, reports, records, memoranda, analyses (such as root cause analyses), or written or oral statements (or copies of any of this material)” which could improve patient safety, health care quality or health care outcomes and which are “assembled or developed by a provider for reporting to a PSO and are reported to a PSO,” or are “developed by a PSO for the conduct of patient safety activities,” or which “identify or constitute the deliberations or analysis of, or identify the fact of reporting pursuant to, a patient safety evaluation system.”
The exclusion that is most often left out
The same section continues: “Patient safety work product does not include a patient’s medical record, billing and discharge information, or any other original patient or provider information; nor does it include information that is collected, maintained, or developed separately, or exists separately, from a patient safety evaluation system. Such separate information or a copy thereof reported to a PSO shall not by reason of its reporting be considered patient safety work product.”
And section 3.20(2)(iii): nothing in the Part limits information that is not patient safety work product from being discovered or admitted in a criminal, civil or administrative proceeding, reported to a government agency for public health or health oversight purposes, or maintained as part of a provider’s recordkeeping obligation under law.
In plain terms: a facility cannot make a record protected by sending a copy of it to a PSO. Anyone who has been told otherwise has been told something the rule specifically forecloses.
Privilege and confidentiality
Section 3.204(a) provides that patient safety work product “shall be privileged and shall not be” subject to a federal, state, local or tribal civil, criminal or administrative subpoena or order, subject to discovery, subject to disclosure under the Freedom of Information Act, admitted as evidence in a governmental civil, criminal, administrative rulemaking or administrative adjudicatory proceeding, or admitted in a professional disciplinary proceeding of a body established or authorized under state law.
Section 3.206(a) provides that patient safety work product “shall be confidential and shall not be disclosed” — subject to the exceptions in the rest of that section. Those exceptions are real and should be read alongside the protection: disclosure in criminal proceedings after a court determines in camera that the material contains evidence of a criminal act, is material to the proceeding, and is not reasonably available from another source; disclosure to permit equitable relief for reporters; disclosure authorized by identified providers; and disclosure for patient safety activities.
And the continued-listing obligation
Section 3.102(b)(2)(i)(C) requires that a PSO, “within the 24-month period that begins on the date of its initial listing as a PSO, and within each sequential 24-month period thereafter, must have 2 bona fide contracts, each of a reasonable period of time, each with a different provider for the purpose of receiving and reviewing patient safety work product.”
AHRQ attaches its own caution to summaries like this one, and it applies here: frequently asked questions and definitions “are summarized here solely for convenience; always rely on the actual text of the Patient Safety Act or Patient Safety Rule in making any determination.” Nothing on this page is legal advice.
References
- Agency for Healthcare Research and Quality 2005. Patient Safety and Quality Improvement Act of 2005, Public Law 109-41, 42 U.S.C. §§ 299b-21 to 299b-26. US Department of Health and Human Services. [statute] · Source
- US Department of Health and Human Services 2008. Patient Safety and Quality Improvement Final Rule, 42 C.F.R. Part 3: Patient Safety Organizations and Patient Safety Work Product. Code of Federal Regulations. [regulation] · Source
- Agency for Healthcare Research and Quality 2026. Patient Safety Organization Program: frequently asked questions. AHRQ PSO Program. [agency guidance] · Source
- Agency for Healthcare Research and Quality 2024. CareGuard, listed Patient Safety Organization P0268. AHRQ PSO Program directory. [federal listing record] · Source