How to Read Hospital Incident Reports as a Plaintiff Attorney
Verify it yourself — free, no login
See how AI medical-record review links every fact to the exact Bates page that proves it — click any citation and jump straight to the record.
See the 60-second demo →Hospital incident reports and root cause analyses are often the single most powerful documents in a medical malpractice case — when you can get them. They contain the hospital's own contemporaneous assessment of what went wrong, often with explicit identification of contributing factors and policy failures. They also sit at the center of one of the most contested areas of malpractice discovery: peer review privilege.
This guide covers what these documents are, where they live, what's discoverable in what jurisdictions, and how to use them when you get them.
The Document Hierarchy
Hospitals generate several related but distinct safety-related documents. Discovery treatment varies by document type:
Incident reports (also called event reports, occurrence reports, variance reports)
The frontline document. A nurse, physician, or other staff member files an incident report when something unexpected happens — a fall, a medication error, an unexpected death, a near-miss. Reports are typically filed in an electronic incident reporting system (Verge, RL6, Quantros, Origami, Datix, etc.).
Discovery treatment: highly variable. Some jurisdictions protect incident reports under peer review privilege. Others permit discovery, particularly when the report describes facts (versus opinions or recommendations).
Root cause analyses (RCAs)
For serious events, hospitals conduct a formal RCA. A multidisciplinary team reviews the event, identifies contributing factors, and recommends corrective actions. The output is a written RCA report.
Discovery treatment: typically protected by peer review privilege in most jurisdictions, particularly when conducted under a hospital's Patient Safety Organization (PSO) framework. But the underlying facts — what happened in the patient's care — are not protected.
Sentinel event reports
Joint Commission defines "sentinel events" as unexpected occurrences involving death, serious physical or psychological injury, or risk thereof. Reporting to the Joint Commission is voluntary but encouraged. The Joint Commission's database of sentinel events is aggregated and de-identified.
Discovery treatment: the hospital's internal sentinel event report is typically protected. The Joint Commission's aggregated database is publicly available but does not identify specific events.
Peer review committee minutes
Medical staff committees (M&M committees, quality committees, credentialing committees) review individual provider performance. Minutes typically include discussion of specific cases.
Discovery treatment: protected by peer review privilege in nearly all jurisdictions. The level of protection varies.
Patient Safety Organization (PSO) work product
The federal Patient Safety and Quality Improvement Act of 2005 (PSQIA) created federal privilege for Patient Safety Work Product (PSWP) shared with PSOs. This is the strongest privilege available for hospital safety analysis — but also the most narrow.
Discovery treatment: protected by federal statute. But the protection applies only to materials created specifically for the PSO. Pre-existing medical records and the underlying patient care information are not PSWP.
State-by-State Peer Review Privilege Survey
Peer review privilege rules vary significantly. A working summary:
Strong privilege jurisdictions
Many states have broad peer review privilege protecting incident reports, RCAs, and committee minutes. Examples include Texas (Tex. Health & Safety Code § 161.032), California (Cal. Evid. Code § 1157), Florida (Fla. Stat. § 766.101), and most other states with comprehensive peer review statutes.
Limited privilege jurisdictions
Some states limit peer review privilege to specific committee proceedings, leaving incident reports and pre-committee materials discoverable. The trend has been toward broadening privilege, but several states maintain narrow rules.
The "facts vs. opinions" distinction
Even in strong-privilege states, the underlying facts in an incident report are typically not privileged. The recipient committee's opinions and recommendations may be protected, but the factual narrative of what happened often is not. This distinction matters for drafting discovery requests.
The 2008 Patient Safety Rule (PSQIA)
The federal PSQIA established a uniform privilege for PSWP. Hospitals that work with PSOs can shield their patient safety analyses under federal law. The PSO infrastructure has grown substantially; many hospitals route their incident analyses through PSOs to leverage federal privilege.
But PSO privilege has limits. The Supreme Court in Tibbs v. Bunnell (Ky. 2014) clarified that pre-existing patient records and information collected for non-safety purposes (e.g., for regulatory compliance) cannot be magically made PSWP by routing through a PSO. Hospitals that try to over-claim PSWP can face sanctions.
Map every event in the chart to discovery requests
MedLegal AI's Timeline Builder identifies every adverse event documented in the medical record — the predicate facts for requesting incident reports and RCAs.
Try Timeline Builder →How to Find Out an Incident Report Exists
Hospitals don't volunteer that incident reports exist. You have to identify their existence through other means:
Triggering events in the medical record
Most hospital policies require an incident report for: any unexpected death, any significant adverse drug event, any patient fall with injury, any medication error reaching the patient, any wrong-site procedure, any unexpected return to the OR, any patient injury during transport, and any equipment malfunction during patient care. When the medical record documents one of these events, an incident report almost certainly exists.
Risk management notes
Some EMRs flag charts that risk management has reviewed. Look for "risk management notified," "incident report filed," or similar notations. These confirm the existence of an incident report.
30(b)(6) depositions
Notice a Rule 30(b)(6) deposition of the hospital's risk management department. Ask: was an incident report filed regarding this patient? Who filed it? Was an RCA conducted? Who participated?
State reporting requirements
Many states require hospitals to report adverse events to state health departments. The state reports may be discoverable directly from the state agency through public records requests, even if the underlying incident reports are privileged.
How to Compel Production (Strategically)
Even where incident reports are privileged, you can often obtain functional equivalents:
Pre-incident-report materials
The patient care record itself, the nursing notes describing the event, the physician's notes documenting the event — none of these are privileged. They contain the underlying facts.
Statements by staff
Witness statements taken by hospital risk management may be privileged if taken in anticipation of litigation. But statements that staff make as part of routine documentation, or to families, or in informal conversation, are not privileged.
Photographs and physical evidence
Hospital incident-response procedures often involve photographing the scene (for falls), preserving equipment (for device-related events), and sequestering medication packaging. These are not privileged.
Communications outside the privilege scope
Communications between the hospital and outside parties (e.g., the manufacturer of a malfunctioning device, the state health department, the patient's family) are not privileged even if related to the incident.
Policies and procedures
The hospital's incident-reporting policy, RCA policy, and patient safety policies are not privileged. They establish what should have been done in response to the event — and any failure to follow those policies becomes additional evidence of negligence.
How to Use Incident Reports When You Get Them
When you successfully compel production of an incident report or RCA, use it strategically:
Admission of fault
Incident reports often contain candid assessments of what went wrong, sometimes including explicit admissions of policy violation. These statements are powerful at trial.
Contributing factor identification
RCAs typically identify contributing factors: staffing levels, training gaps, communication failures, equipment issues, protocol non-compliance. Each factor supports a separate negligence theory.
Corrective action recommendations
RCAs typically include recommended corrective actions. The fact that the hospital identified actions to prevent recurrence is itself evidence that prevention was possible — refuting any "unavoidable" defense.
Subsequent remedial measures
Federal Rule of Evidence 407 limits use of subsequent remedial measures to prove negligence. But the RCA itself often documents that the cause was preventable, which is admissible for purposes other than proving negligence (e.g., to prove ownership, control, or feasibility of precautionary measures).
Pattern evidence
If prior incident reports show similar events at the same facility, the hospital was on notice. Discovery requests should target prior similar incidents in the same unit or involving the same provider.
The "Apology Statute" Wrinkle
Many states have enacted "apology statutes" that exclude provider expressions of sympathy or apology from evidence. The scope varies: some statutes exclude only general expressions of sympathy ("I'm sorry this happened"); others exclude actual admissions of fault ("I made a mistake").
For plaintiff attorneys, this matters during depositions. A provider's expression of sympathy may have been an effective admission of fault but may be inadmissible. Plan your deposition questions accordingly — focus on facts and actions rather than statements of regret.
Workup Strategy
Identifying which events in a complex hospital admission warranted incident reports is a tedious manual task. AI-assisted records review can flag every event meeting common incident-report triggers — medication errors, falls, unexpected escalations of care, near-misses, equipment issues — with page-level citations. The discovery request then targets specific events with specific dates, which is much harder for the hospital to brush off.
Identify every reportable event in seconds
MedLegal AI flags adverse events, near-misses, and incident-report triggers across complex hospital admissions. Free trial, no credit card.
Start Free Trial →Bottom Line
Hospital incident reports and RCAs are valuable but contested discovery targets. Most jurisdictions protect them through peer review privilege, but the underlying facts in patient care remain discoverable. The strongest cases use the medical record to prove what happened, then use targeted discovery to compel production of incident-report-equivalent materials (witness statements, policies, contemporaneous communications) that the privilege doesn't cover. When you do successfully compel an incident report or RCA, it often becomes the centerpiece of trial.
Related reading: discovery checklist, EMR audit trail tricks, nursing red flags.