Category: Patient safety organizations

  • Why CareGuard keeps no copy of your report

    CareGuard transmits incident reports to a facility’s ownership and counsel and retains nothing. What that protects, what it costs, and what it does not do.

    It is the most counterintuitive part of the design and the one worth explaining rather than burying in a policy page.

    The rule

    Reports submitted through the CareGuard Reporting System are transmitted to the facility’s designated legal counsel and to facility ownership. CareGuard acts as a facilitator of that transmission and does not retain, store or maintain the reports.

    What it protects

    • CareGuard cannot be subpoenaed for something it does not have. An organization holding copies of incident reports about dozens of facilities is a target and a single point of failure. One that holds none is neither.
    • One fewer copy exists. Every additional repository of a sensitive report is another place it can be breached, leaked or mishandled.
    • The chain is short. Reporter, counsel, ownership. Nobody in the middle sitting on a file about a building they have never been in.

    What it costs, stated plainly

    • No status updates. There is nothing here to look up. A person who reports will not hear back, and is told so before they submit.
    • No aggregate view. CareGuard cannot show an owner a trend across their portfolio from reports, because it does not hold them.
    • No recovery. If ownership loses a report, CareGuard cannot resend it.

    What it does not do

    Keeping no copy does not make a report a legal filing, does not make it confidential in any particular proceeding, and does not discharge anyone’s mandatory reporting duty. A report to CareGuard goes to a private party — a facility’s owners and their lawyers — and that is all it does.

    This is why every page on this site that invites a report says so above the link, and names the routes that do have authority: 911 in an emergency, the Missouri Adult Abuse and Neglect Hotline at 800-392-0210 for suspected abuse, neglect or exploitation of an adult, and the Missouri Long-Term Care Ombudsman at 800-309-3282 for an independent advocate. Those routes in full.

    The trade being offered

    An owner will not put a reporting channel in their building if the channel accumulates a discoverable archive about them somewhere else. Retaining nothing is what makes an owner willing to hear bad news in writing at all — and a channel that exists and is used is worth more to a resident than a better one that no owner installs.


    What CareGuard does not keep · Legal work product.

  • What a Patient Safety Organization actually is

    PSOs were created by the Patient Safety and Quality Improvement Act of 2005. What listing means, what it does not mean, and why the confusion matters.

    “Patient Safety Organization” sounds like a regulator. It is precisely the opposite, and the difference is the whole point of the statute.

    The problem the law was written for

    Hospitals and long-term care facilities knew a great deal about their own near misses and did not write it down, because writing it down created a document that could be used against them. The result was an industry that could not learn from itself: the events with the most to teach were the events least likely to be recorded.

    On July 29, 2005 the President signed the Patient Safety and Quality Improvement Act of 2005 — the Patient Safety Act, 42 U.S.C. §§ 299b-21 to 299b-26. AHRQ summarizes it as amending Title IX of the Public Health Service Act “to provide for the improvement of patient safety and to reduce the incidence of events that adversely affect patient safety by authorizing the creation of patient safety organizations.”

    What a PSO does

    AHRQ puts it in one sentence: PSOs “work with providers to improve quality and safety through the collection and analysis of aggregated, confidential data on patient safety events.” The operative word is confidential. Information a provider develops for reporting to a PSO can qualify as patient safety work product and carry federal confidentiality and privilege protections under the Patient Safety Rule, 42 C.F.R. Part 3.

    The trade the statute offers is explicit: analyze your failures honestly, and the analysis is protected. Patient safety work product.

    What listing means

    A PSO is listed by the Secretary of Health and Human Services, through AHRQ, after certifying that it meets the statutory criteria. Listings run three years. A listed PSO must hold two bona fide contracts in each successive 24-month period and must promptly notify the Secretary if it can no longer comply with any of its attestations or if the information it submitted stops being accurate.

    What listing does not mean

    • It confers no authority over any provider.
    • It is not an accreditation or a license, and a PSO is asked on the listing form whether it accredits or licenses providers — CareGuard attested that it does not.
    • It says nothing about the quality of any facility a PSO works with.
    • It is not issued by Medicare or CMS, which have no role in listing PSOs.

    Why this gets confused

    Because everything else with a federal number attached to a health care organization is a permission to operate or a rating. A PSO number is neither. It is closer to a registration that unlocks a confidentiality mechanism than to a credential.

    It is also why a facility cannot advertise itself using a PSO’s name as a quality mark. CareGuard does not certify facilities, and no facility can accurately say it is CareGuard certified. That is worth its own piece.


    CareGuard is a Patient Safety Organization listed by AHRQ, PSO P0268, effective November 22, 2024. The listing · the public record at AHRQ.


    The statute and the rule, quoted

    AHRQ states the statutory basis in one sentence: “On July 29, 2005, the President signed the Patient Safety and Quality Improvement Act of 2005 (Patient Safety Act, 42 U.S.C. sections 299b-21 to 299b-26) into law.” It was enacted as Public Law 109-41.

    What it did: “The Patient Safety Act amended Title IX of the Public Health Service Act to provide for the improvement of patient safety and to reduce the incidence of events that adversely affect patient safety by authorizing the creation of patient safety organizations (PSOs). PSOs work with providers to improve quality and safety through the collection and analysis of aggregated, confidential data on patient safety events.”

    AHRQ’s own description of what a PSO is: “A Patient Safety Organization (PSO) works with healthcare providers to help them improve patient safety and healthcare quality and encourage a culture of safety. PSOs analyze data voluntarily reported by providers and provide feedback aimed at promoting learning and minimizing patient risk.” Two further facts from the same source are worth stating plainly: PSOs do not receive federal funding, and while AHRQ handles listing, it is the HHS Office for Civil Rights that “administers and enforces the confidentiality protections provided to PSWP.”

    Patient safety work product, as the rule defines it

    The implementing regulation is the Patient Safety Rule, 42 C.F.R. Part 3, titled “Patient Safety Organizations and Patient Safety Work Product.” Section 3.20 defines patient safety work product as “any data, reports, records, memoranda, analyses (such as root cause analyses), or written or oral statements (or copies of any of this material)” which could improve patient safety, health care quality or health care outcomes and which are “assembled or developed by a provider for reporting to a PSO and are reported to a PSO,” or are “developed by a PSO for the conduct of patient safety activities,” or which “identify or constitute the deliberations or analysis of, or identify the fact of reporting pursuant to, a patient safety evaluation system.”

    The exclusion that is most often left out

    The same section continues: “Patient safety work product does not include a patient’s medical record, billing and discharge information, or any other original patient or provider information; nor does it include information that is collected, maintained, or developed separately, or exists separately, from a patient safety evaluation system. Such separate information or a copy thereof reported to a PSO shall not by reason of its reporting be considered patient safety work product.”

    And section 3.20(2)(iii): nothing in the Part limits information that is not patient safety work product from being discovered or admitted in a criminal, civil or administrative proceeding, reported to a government agency for public health or health oversight purposes, or maintained as part of a provider’s recordkeeping obligation under law.

    In plain terms: a facility cannot make a record protected by sending a copy of it to a PSO. Anyone who has been told otherwise has been told something the rule specifically forecloses.

    Privilege and confidentiality

    Section 3.204(a) provides that patient safety work product “shall be privileged and shall not be” subject to a federal, state, local or tribal civil, criminal or administrative subpoena or order, subject to discovery, subject to disclosure under the Freedom of Information Act, admitted as evidence in a governmental civil, criminal, administrative rulemaking or administrative adjudicatory proceeding, or admitted in a professional disciplinary proceeding of a body established or authorized under state law.

    Section 3.206(a) provides that patient safety work product “shall be confidential and shall not be disclosed” — subject to the exceptions in the rest of that section. Those exceptions are real and should be read alongside the protection: disclosure in criminal proceedings after a court determines in camera that the material contains evidence of a criminal act, is material to the proceeding, and is not reasonably available from another source; disclosure to permit equitable relief for reporters; disclosure authorized by identified providers; and disclosure for patient safety activities.

    And the continued-listing obligation

    Section 3.102(b)(2)(i)(C) requires that a PSO, “within the 24-month period that begins on the date of its initial listing as a PSO, and within each sequential 24-month period thereafter, must have 2 bona fide contracts, each of a reasonable period of time, each with a different provider for the purpose of receiving and reviewing patient safety work product.”

    AHRQ attaches its own caution to summaries like this one, and it applies here: frequently asked questions and definitions “are summarized here solely for convenience; always rely on the actual text of the Patient Safety Act or Patient Safety Rule in making any determination.” Nothing on this page is legal advice.

    References

    1. Agency for Healthcare Research and Quality 2005. Patient Safety and Quality Improvement Act of 2005, Public Law 109-41, 42 U.S.C. §§ 299b-21 to 299b-26. US Department of Health and Human Services. [statute] · Source
    2. US Department of Health and Human Services 2008. Patient Safety and Quality Improvement Final Rule, 42 C.F.R. Part 3: Patient Safety Organizations and Patient Safety Work Product. Code of Federal Regulations. [regulation] · Source
    3. Agency for Healthcare Research and Quality 2026. Patient Safety Organization Program: frequently asked questions. AHRQ PSO Program. [agency guidance] · Source
    4. Agency for Healthcare Research and Quality 2024. CareGuard, listed Patient Safety Organization P0268. AHRQ PSO Program directory. [federal listing record] · Source
  • Why we stopped saying “certified”

    CareGuard attested to AHRQ that it does not accredit or license providers. The old website said the opposite. Here is the correction and why it matters.

    CareGuard’s previous website was built almost entirely on a word CareGuard is not entitled to use. This is the correction, in public, because a quiet edit would not be one.

    What the old site said

    It offered “Compliance and Medical Safety Certification for Nursing Home Facilities.” It described “Our Comprehensive Certification Process.” It said “When a facility is Care Guard certified, you can be confident that it’s been thoroughly reviewed.” Its final call to action read: “Get your facility CERTIFIED.”

    What CareGuard actually told the federal government

    On the certification form for initial listing as a Patient Safety Organization, CareGuard attested that it is not “an entity that accredits or licenses health care providers” and not “an entity that oversees or enforces statutory or regulatory requirements governing the delivery of health care services.”

    Those attestations are conditions of the listing. A listed PSO has an ongoing obligation to notify AHRQ promptly if it can no longer comply with any of them.

    Why the two cannot both stand

    An organization cannot attest in Washington that it does not accredit providers and advertise in St. Louis that facilities are certified by it. The word “certified” does specific work in health care: it tells a reader that an authority applied a standard and issued a finding a third party can rely on. CareGuard applies a checklist and reports to the owner who commissioned it. Those are not the same act, and dressing one as the other misleads exactly the people least able to check — families choosing a facility.

    The vocabulary now

    • Correct: safety review, facility safety assessment, patient safety review.
    • Correct credential line: a Patient Safety Organization listed by AHRQ, PSO P0268.
    • Never: certified, certification, accredited, CareGuard certified, CareGuard approved.
    • Also never: Medicare certified — Medicare does not list PSOs at all; PEO, which is a different kind of organization entirely; and any description of CareGuard as a nursing home, which it is not and has never been.

    What a facility can accurately say

    That it commissioned a CareGuard safety review, when it was done, and what it found. That is a stronger claim than a seal, because it is checkable.

    The count, while we are here

    The review is 189 items across 54 categories. Any other figure that has circulated is wrong and is not used on this site. All 54 categories.


    What CareGuard is not · Editorial policy.