← MedLegal AI

How to Read Hospital Incident Reports as a Plaintiff Attorney

Published 2026-05-27 · John Mahoney · MedLegal AI

Verify it yourself — free, no login

See how AI medical-record review links every fact to the exact Bates page that proves it — click any citation and jump straight to the record.

See the 60-second demo →

Hospital incident reports and root cause analyses are often the single most powerful documents in a medical malpractice case — when you can get them. They contain the hospital's own contemporaneous assessment of what went wrong, often with explicit identification of contributing factors and policy failures. They also sit at the center of one of the most contested areas of malpractice discovery: peer review privilege.

This guide covers what these documents are, where they live, what's discoverable in what jurisdictions, and how to use them when you get them.

The Document Hierarchy

Hospitals generate several related but distinct safety-related documents. Discovery treatment varies by document type:

Incident reports (also called event reports, occurrence reports, variance reports)

The frontline document. A nurse, physician, or other staff member files an incident report when something unexpected happens — a fall, a medication error, an unexpected death, a near-miss. Reports are typically filed in an electronic incident reporting system (Verge, RL6, Quantros, Origami, Datix, etc.).

Discovery treatment: highly variable. Some jurisdictions protect incident reports under peer review privilege. Others permit discovery, particularly when the report describes facts (versus opinions or recommendations).

Root cause analyses (RCAs)

For serious events, hospitals conduct a formal RCA. A multidisciplinary team reviews the event, identifies contributing factors, and recommends corrective actions. The output is a written RCA report.

Discovery treatment: typically protected by peer review privilege in most jurisdictions, particularly when conducted under a hospital's Patient Safety Organization (PSO) framework. But the underlying facts — what happened in the patient's care — are not protected.

Sentinel event reports

Joint Commission defines "sentinel events" as unexpected occurrences involving death, serious physical or psychological injury, or risk thereof. Reporting to the Joint Commission is voluntary but encouraged. The Joint Commission's database of sentinel events is aggregated and de-identified.

Discovery treatment: the hospital's internal sentinel event report is typically protected. The Joint Commission's aggregated database is publicly available but does not identify specific events.

Peer review committee minutes

Medical staff committees (M&M committees, quality committees, credentialing committees) review individual provider performance. Minutes typically include discussion of specific cases.

Discovery treatment: protected by peer review privilege in nearly all jurisdictions. The level of protection varies.

Patient Safety Organization (PSO) work product

The federal Patient Safety and Quality Improvement Act of 2005 (PSQIA) created federal privilege for Patient Safety Work Product (PSWP) shared with PSOs. This is the strongest privilege available for hospital safety analysis — but also the most narrow.

Discovery treatment: protected by federal statute. But the protection applies only to materials created specifically for the PSO. Pre-existing medical records and the underlying patient care information are not PSWP.

State-by-State Peer Review Privilege Survey

Peer review privilege rules vary significantly. A working summary:

Strong privilege jurisdictions

Many states have broad peer review privilege protecting incident reports, RCAs, and committee minutes. Examples include Texas (Tex. Health & Safety Code § 161.032), California (Cal. Evid. Code § 1157), Florida (Fla. Stat. § 766.101), and most other states with comprehensive peer review statutes.

Limited privilege jurisdictions

Some states limit peer review privilege to specific committee proceedings, leaving incident reports and pre-committee materials discoverable. The trend has been toward broadening privilege, but several states maintain narrow rules.

The "facts vs. opinions" distinction

Even in strong-privilege states, the underlying facts in an incident report are typically not privileged. The recipient committee's opinions and recommendations may be protected, but the factual narrative of what happened often is not. This distinction matters for drafting discovery requests.

The 2008 Patient Safety Rule (PSQIA)

The federal PSQIA established a uniform privilege for PSWP. Hospitals that work with PSOs can shield their patient safety analyses under federal law. The PSO infrastructure has grown substantially; many hospitals route their incident analyses through PSOs to leverage federal privilege.

But PSO privilege has limits. The Supreme Court in Tibbs v. Bunnell (Ky. 2014) clarified that pre-existing patient records and information collected for non-safety purposes (e.g., for regulatory compliance) cannot be magically made PSWP by routing through a PSO. Hospitals that try to over-claim PSWP can face sanctions.

Map every event in the chart to discovery requests

MedLegal AI's Timeline Builder identifies every adverse event documented in the medical record — the predicate facts for requesting incident reports and RCAs.

Try Timeline Builder →

How to Find Out an Incident Report Exists

Hospitals don't volunteer that incident reports exist. You have to identify their existence through other means:

Triggering events in the medical record

Most hospital policies require an incident report for: any unexpected death, any significant adverse drug event, any patient fall with injury, any medication error reaching the patient, any wrong-site procedure, any unexpected return to the OR, any patient injury during transport, and any equipment malfunction during patient care. When the medical record documents one of these events, an incident report almost certainly exists.

Risk management notes

Some EMRs flag charts that risk management has reviewed. Look for "risk management notified," "incident report filed," or similar notations. These confirm the existence of an incident report.

30(b)(6) depositions

Notice a Rule 30(b)(6) deposition of the hospital's risk management department. Ask: was an incident report filed regarding this patient? Who filed it? Was an RCA conducted? Who participated?

State reporting requirements

Many states require hospitals to report adverse events to state health departments. The state reports may be discoverable directly from the state agency through public records requests, even if the underlying incident reports are privileged.

How to Compel Production (Strategically)

Even where incident reports are privileged, you can often obtain functional equivalents:

Pre-incident-report materials

The patient care record itself, the nursing notes describing the event, the physician's notes documenting the event — none of these are privileged. They contain the underlying facts.

Statements by staff

Witness statements taken by hospital risk management may be privileged if taken in anticipation of litigation. But statements that staff make as part of routine documentation, or to families, or in informal conversation, are not privileged.

Photographs and physical evidence

Hospital incident-response procedures often involve photographing the scene (for falls), preserving equipment (for device-related events), and sequestering medication packaging. These are not privileged.

Communications outside the privilege scope

Communications between the hospital and outside parties (e.g., the manufacturer of a malfunctioning device, the state health department, the patient's family) are not privileged even if related to the incident.

Policies and procedures

The hospital's incident-reporting policy, RCA policy, and patient safety policies are not privileged. They establish what should have been done in response to the event — and any failure to follow those policies becomes additional evidence of negligence.

How to Use Incident Reports When You Get Them

When you successfully compel production of an incident report or RCA, use it strategically:

Admission of fault

Incident reports often contain candid assessments of what went wrong, sometimes including explicit admissions of policy violation. These statements are powerful at trial.

Contributing factor identification

RCAs typically identify contributing factors: staffing levels, training gaps, communication failures, equipment issues, protocol non-compliance. Each factor supports a separate negligence theory.

Corrective action recommendations

RCAs typically include recommended corrective actions. The fact that the hospital identified actions to prevent recurrence is itself evidence that prevention was possible — refuting any "unavoidable" defense.

Subsequent remedial measures

Federal Rule of Evidence 407 limits use of subsequent remedial measures to prove negligence. But the RCA itself often documents that the cause was preventable, which is admissible for purposes other than proving negligence (e.g., to prove ownership, control, or feasibility of precautionary measures).

Pattern evidence

If prior incident reports show similar events at the same facility, the hospital was on notice. Discovery requests should target prior similar incidents in the same unit or involving the same provider.

The "Apology Statute" Wrinkle

Many states have enacted "apology statutes" that exclude provider expressions of sympathy or apology from evidence. The scope varies: some statutes exclude only general expressions of sympathy ("I'm sorry this happened"); others exclude actual admissions of fault ("I made a mistake").

For plaintiff attorneys, this matters during depositions. A provider's expression of sympathy may have been an effective admission of fault but may be inadmissible. Plan your deposition questions accordingly — focus on facts and actions rather than statements of regret.

Workup Strategy

Identifying which events in a complex hospital admission warranted incident reports is a tedious manual task. AI-assisted records review can flag every event meeting common incident-report triggers — medication errors, falls, unexpected escalations of care, near-misses, equipment issues — with page-level citations. The discovery request then targets specific events with specific dates, which is much harder for the hospital to brush off.

Identify every reportable event in seconds

MedLegal AI flags adverse events, near-misses, and incident-report triggers across complex hospital admissions. Free trial, no credit card.

Start Free Trial →

Bottom Line

Hospital incident reports and RCAs are valuable but contested discovery targets. Most jurisdictions protect them through peer review privilege, but the underlying facts in patient care remain discoverable. The strongest cases use the medical record to prove what happened, then use targeted discovery to compel production of incident-report-equivalent materials (witness statements, policies, contemporaneous communications) that the privilege doesn't cover. When you do successfully compel an incident report or RCA, it often becomes the centerpiece of trial.

Related reading: discovery checklist, EMR audit trail tricks, nursing red flags.

See the AI cite its source — no login
Most legal AI is wrong 17–33% of the time. Watch MedLegal AI pin every finding to the exact record page — click any citation and it jumps to the line that proves it.
Watch the 30-second demo →