Written and maintained by CASRAI Editorial Board
Last updated
A hospital’s patient safety plan is the document that describes the organization’s patient safety program itself: who is accountable for it, how events and near misses get reported and reviewed, what relationship (if any) the hospital has with a federally-listed Patient Safety Organization, and what the hospital is trying to improve this year. It is written for the people who own that program — patient-safety officers, infection preventionists, quality directors and risk managers — not for a general compliance audience, and it is a different document from the QAPI plan, even though the two overlap and are frequently confused.
No single CMS Condition of Participation requires a document titled “patient safety plan.” The federal Condition that governs hospital quality work is the Quality Assessment and Performance Improvement program at 42 CFR 482.21 — covered section by section in CASRAI’s QAPI plan guide — and patient safety sits inside it as one named component (Appendix A routes patient-safety, medical-error and adverse-event content to survey tag A-0286). A stand-alone patient safety plan is not a separate federal mandate; it is what most hospitals produce anyway, because accreditors expect an organized, hospital-wide safety program and because a document scoped to safety specifically — rather than to the full quality-assessment mandate — is easier to govern, easier to hand to a new patient-safety officer, and easier to keep out of (or deliberately inside) a Patient Safety Organization’s protected evaluation system. Where a specific state statute imposes its own patient-safety-plan-type requirement, that is noted below rather than assumed to be universal.
Why hospitals keep this separate from the QAPI plan
The QAPI plan is the umbrella document: it has to cover every department, every contracted service, and the hospital’s entire performance-improvement portfolio, not just harm prevention. Patient safety is one input into that portfolio, not a synonym for it — a QAPI program can (and does) run projects on throughput, documentation completeness, or patient experience that have nothing to do with harm.
A patient safety plan narrows the scope back down to the thing patient-safety officers and risk managers are actually accountable for: preventing and responding to harm. Splitting the two documents lets a hospital hand the safety plan to a new patient-safety officer without also handing them the entire QAPI portfolio, and lets it draw a clean line around what does and doesn’t go into a Patient Safety Organization’s protected patient safety evaluation system — a line that is much harder to draw once safety content is scattered through a general-purpose QAPI plan. Some hospitals fold the safety plan into a chapter of the QAPI plan instead of keeping it separate; both are workable, but the content below has to exist somewhere in the document set either way, and a surveyor or new hire should not have to guess which document it’s in.
What the plan has to contain, section by section
1. Purpose, scope and authority
State plainly what the plan governs (harm prevention, event reporting, and the improvement work that follows from both), which entities it applies to (every inpatient and outpatient site, and explicitly whether contracted and off-campus services are included — the same scoping question CMS’s QAPI surveyor guidance asks about the wider quality program), and which body has final authority over it. That authority is normally the governing board, exercised through a patient safety committee or through the hospital’s existing quality committee acting in a dual role. Name the reporting line explicitly: who the patient-safety officer reports to, and how findings reach the board.
2. Governance structure and the patient-safety officer role
This section should name, not just describe: the designated patient-safety officer (or equivalent leadership role, however titled locally), the committee structure that supports them, and the escalation path from a unit-level safety huddle up to committee and board review. In smaller and critical-access hospitals this role is routinely combined with the quality director or chief nursing officer role rather than staffed separately — the plan should say which model applies rather than describing a structure the hospital doesn’t actually run. Include how the committee is resourced (dedicated time, data support, training budget) and how a vacancy in the patient-safety-officer role is covered in the interim, since an undocumented gap here is one of the more visible things a surveyor or new leader notices.
3. The Patient Safety Organization relationship
If the hospital reports some or all of its safety events into a federally-listed Patient Safety Organization, the plan should state which PSO, what categories of event flow into the protected patient safety evaluation system (PSES) versus what stays in an ordinary, unprotected compliance file, and who decides which record goes where. This matters because the confidentiality and privilege protection created by the Patient Safety and Quality Improvement Act of 2005 (PSQIA), implemented at 42 CFR Part 3, is real but bounded — original records and information a hospital is independently required to keep under other law (state mandatory event reporting, the CMS Conditions of Participation themselves) generally are not protected merely by also being routed through a PSO. A hospital that routes all of its safety-program evidence into the PSES with no parallel non-privileged file can find itself unable to demonstrate compliance to a surveyor who is not permitted to ask for PSWP directly. See patient safety organization reporting and the work-product privilege for the full mechanics of what is and isn’t protected; the plan itself only needs to state the hospital’s actual PSO relationship and its rule for what goes where, not re-derive the statute.
4. Event and near-miss reporting mechanisms
Document the reporting system itself: how staff report an event or near miss (the intake channel), what happens to a report in the first 24-72 hours, how severity is triaged, and which event categories trigger which level of review — a documentation error gets a different response than a serious reportable event. State explicitly how a root cause analysis gets triggered and who owns the resulting corrective-action hierarchy, and how routine findings feed into daily or weekly safety huddles rather than only into a quarterly committee cycle. A reporting system that only surfaces events to committee once a quarter is too slow to catch a developing pattern; the plan should describe both the fast loop (huddle-level) and the slow loop (committee- and board-level review). See designing an incident reporting system people actually use for the design considerations behind the intake channel itself — underreporting is usually a design problem, not a culture problem alone.
5. Annual patient safety goals
State the hospital’s own patient safety priorities for the current cycle, how they were selected (typically a mix of internal event data, benchmark performance, and accreditation-driven priorities), who approved them, and how progress against each is measured. This is distinct from — but should explicitly cross-reference — the Joint Commission’s National Patient Safety Goals, which are external, accreditor-set requirements a hospital must meet regardless of its own internal priorities. A hospital’s annual goals section typically layers its own priorities on top of the NPSGs it’s already required to meet, rather than restating them. Give each goal a real target and a review cadence, not just a name — an unmeasurable goal is the version of this section a surveyor or new board member has the hardest time evaluating.
6. Annual evaluation and revision control
Close the plan the same way a QAPI plan should close (see Part IX of CMS’s own Guide for Developing a QAPI Plan, covered in the QAPI guide above): date it, state how often it will be reviewed (at minimum annually), and record its revision history. A plan with no review date and no revision trail reads, to a surveyor or a new patient-safety officer, as a document that was written once and never looked at again — regardless of how good the content is.
How the sections map onto the QAPI plan
Where a hospital keeps the two documents separate, this rough crosswalk keeps them from silently duplicating or contradicting each other:
| Patient safety plan section | Where it interlocks with the QAPI plan |
|---|---|
| Purpose, scope and authority | Should name the same governing body and reporting line the QAPI plan’s governance section names — a plan that gives the board two different reporting structures for safety and quality is describing an organization chart that doesn’t exist. |
| Governance and the patient-safety-officer role | Feeds the QAPI plan’s own governance and leadership section; many hospitals seat the patient-safety officer on the QAPI committee rather than building a fully separate committee. |
| PSO relationship | Determines which QAPI evidence can and cannot be shown to a surveyor — the same protected/unprotected split described above applies to QAPI documentation, not only to safety-specific records. |
| Event and near-miss reporting | Is the primary data source for the QAPI plan’s adverse-event and medical-error tracking, and for the high-risk, high-volume or problem-prone reasoning that opens a chartered performance improvement project. |
| Annual patient safety goals | Often becomes the source of one or more of the year’s chartered PIPs, but is not itself a substitute for the QAPI plan’s own annual project count and scope decisions. |
| Annual evaluation and revision | Should be reviewed on the same cycle as the QAPI plan, even if the two documents are revised on separate tracks — a safety plan that hasn’t been touched in three years next to a QAPI plan updated every year is itself a governance gap. |
State and accreditor variation
Some states layer their own statutory requirements on top of the federal and accreditation picture, and they are typically narrower than a full patient safety plan rather than a duplicate of one. California is a documented example: Health and Safety Code §1339.63 requires general acute care hospitals, special hospitals and surgical clinics to adopt a formal plan specifically to reduce medication-related errors — covering order-entry technology, monitoring, multidisciplinary review and an annual effectiveness assessment — as a licensing condition, not a general patient-safety-plan mandate. Treat that as one illustration of the pattern, not as a national baseline: check your own state’s hospital licensing regulations directly rather than assuming a requirement written for one state applies elsewhere. Accreditors (Joint Commission, DNV NIAHO, HFAP, CIHQ) also carry their own leadership and safety-program expectations alongside the CMS Conditions; read your accreditor’s current standards directly before assuming this page’s structure alone satisfies them.
Frequently asked questions
Is a hospital patient safety plan required by CMS?
Not as a named, stand-alone document. The federal requirement is the QAPI Condition of Participation at 42 CFR 482.21, which includes patient safety, medical errors and adverse events as a component (survey tag A-0286) rather than requiring a separately-titled patient safety plan. Most hospitals produce one anyway because it’s the practical way to organize safety-specific governance, and some states or accreditors layer their own expectations on top — see the state-variation section above.
How is a patient safety plan different from a QAPI plan?
The QAPI plan is the hospital-wide document covering the entire quality-assessment and performance-improvement program, required under 42 CFR 482.21. The patient safety plan is narrower — scoped specifically to harm prevention, event reporting and the safety program’s own governance — and is not itself a CMS-defined document. See the QAPI plan guide for the full structure of the document CMS actually regulates.
Does the patient safety plan need to name our Patient Safety Organization?
If the hospital has a PSO relationship, yes — state which PSO and what the hospital’s rule is for what goes into the protected patient safety evaluation system versus an ordinary compliance file. If the hospital has no PSO relationship, say so plainly rather than leaving the section silent; a silent section reads as an unanswered question, not as a deliberate choice.
Who has to approve the plan?
There’s no CMS-prescribed approval body for this document specifically. In practice it’s approved the same way most hospital governance documents are: by the patient safety or quality committee, then by the governing board, mirroring the QAPI plan’s own approval path.
How often should it be reviewed?
At least annually, with the review date and any revisions recorded in the document itself — the same discipline CMS’s own QAPI plan guidance applies to the QAPI plan (a plan with no date and no revision history isn’t functioning as what it claims to be, whichever document it is).
Related reading
- QAPI Plan, QAPI Report, and PIP Write-Up — the document CMS’s Condition of Participation actually regulates, section by section.
- Patient safety organization reporting and the work-product privilege — what PSQIA and 42 CFR Part 3 protect, and what they don’t.
- Designing a hospital incident reporting system people actually use — the intake channel behind the reporting-mechanisms section above.
- National Patient Safety Goals — the accreditor-set goals that sit alongside a hospital’s own annual priorities.
- Serious reportable events and never events — the event categories that should trigger the plan’s highest level of review.
- Root cause analysis in healthcare and the RCA2 action hierarchy — what happens after an event is reported.
- Safety huddle structure and cadence — the fast reporting loop that should sit underneath the plan’s committee cycle.
- High reliability organization principles in healthcare — the cultural framework a well-run safety plan is usually built on top of.
- Patient safety and infection prevention — the wider cluster this page sits in.








