Written and maintained by CASRAI Editorial Board
Last updated
Hospitals routinely conflate three legally distinct protections when they talk about “peer review privilege”: federal immunity from money damages under the Health Care Quality Improvement Act (HCQIA), federal confidentiality for patient safety work product (PSWP) reported to a listed Patient Safety Organization under the Patient Safety and Quality Improvement Act (PSQIA), and state peer-review privilege statutes that shield committee records from discovery in litigation. They solve different problems, attach to different material, and can be lost in different ways. This page is deliberately not about journal peer review — see clinical peer review vs. journal peer review if that is what you are looking for.
What federal HCQIA immunity actually protects — money damages, not confidentiality
The Health Care Quality Improvement Act of 1986 (42 U.S.C. §§11101–11152) does not make peer review records confidential at all. It shields a hospital, its peer review committee, and individual participants from money-damages liability arising out of a professional review action, provided the action meets four conditions set out at 42 U.S.C. §11112(a):
- the action was taken in the reasonable belief it furthered quality health care;
- the entity made a reasonable effort to obtain the facts of the matter;
- the physician was given adequate notice and hearing procedures, or other procedures fair under the circumstances; and
- the action was taken in the reasonable belief it was warranted by the facts known after that fact-finding and hearing process.
The statute presumes a professional review action meets all four standards unless the physician challenging it rebuts that presumption by a preponderance of the evidence — a deliberately physician-unfriendly burden that is the main reason HCQIA immunity is difficult to defeat in practice. Crucially, none of this touches whether a plaintiff’s lawyer can see the committee’s records; it only limits what a hospital can be forced to pay if a review action itself is challenged as wrongful.
What the federal PSWP privilege protects — confidentiality, but only for PSO-bound material
A separate federal law, the Patient Safety and Quality Improvement Act of 2005, implemented at 42 CFR Part 3, creates confidentiality and legal privilege for patient safety work product (PSWP): data, reports, analyses and deliberations assembled specifically within a documented patient safety evaluation system for the purpose of reporting to a federally listed Patient Safety Organization. See PSO reporting and the work product privilege for the full mechanics of what qualifies and what the privilege actually blocks. The PSWP privilege and HCQIA immunity are frequently discussed together because both come from federal patient-safety statutes, but they protect different things: PSWP privilege keeps qualifying material out of discovery and off the record in litigation; HCQIA immunity limits monetary liability for a review decision regardless of whether the underlying records are discoverable.
What state peer-review privilege protects — and why it is not one rule
Peer review privilege in the sense most medical staff offices mean — “can the plaintiff’s attorney subpoena our credentials committee’s minutes and the outside reviewer’s report?” — is overwhelmingly a matter of state evidentiary law, not federal law. Every state has its own peer review privilege statute, and they diverge in real, consequential ways: which entities and committee types are covered (hospital medical staff committees are covered almost everywhere; ambulatory surgery centers, physician practice groups and other non-hospital settings are covered in some states and not others), what categories of claim the privilege can be asserted against, what procedural conditions a committee must satisfy to keep the protection intact, and how broadly courts read exceptions. A document produced by “a root cause analysis conducted by or at the direction of a qualifying committee” may be privileged in a given state; functionally identical work done by an administrator acting alone, outside that committee structure, typically is not. There is no substitute for checking the specific statute in every state where an organization operates — this page describes the shape of the issue, not a specific state’s rule.
How the three protections actually interact
In practice, an organization needs all three working correctly for different reasons:
- State peer-review privilege is what keeps the credentials committee’s internal deliberation, the external reviewer’s report, and related correspondence out of a malpractice plaintiff’s discovery requests.
- Federal PSWP privilege is a separate, narrower federal backstop for whatever material was specifically generated for PSO reporting — it does not automatically cover everything a peer review committee produces, only what flows through the documented patient safety evaluation system.
- HCQIA immunity is what limits the hospital’s and the participating physicians’ exposure to money damages if the physician under review sues over the review action itself, and it applies regardless of whether the underlying records were ever privileged from discovery.
A hospital can satisfy HCQIA’s four conditions perfectly and still lose a discovery fight over its committee minutes if it did not also structure the review to fit its state’s privilege statute — the two protections do not rise and fall together.
When to route a case to external peer review
External peer review — sending a case to a reviewer with no employment, referral, or competitive relationship to the practitioner under review — is not the default path; it is a response to a specific gap internal review cannot close. The recurring triggers:
- No qualified internal reviewer. A small or single-specialty medical staff often has no one credentialed in the relevant subspecialty who is not also a direct competitor or close colleague of the physician under review.
- Conflict of interest. Even where internal expertise exists, a reviewer who competes for referrals with the subject, or who has a documented personal conflict, can taint the process and undermine the “reasonable effort to obtain the facts” standard HCQIA immunity depends on.
- High-severity or high-visibility events. Sentinel events, cases with regulatory or media exposure, or cases likely to end in litigation benefit from a reviewer whose independence is not itself an issue a plaintiff’s attorney can raise.
- A bylaws-defined second-tier requirement. Many medical staff bylaws specify that certain findings (an adverse recommendation, a pattern flagged through OPPE or FPPE) automatically trigger external review before the credentials committee acts on them — see medical staff bylaws requirements for where that provision belongs.
Sharing the external reviewer’s report with the physician under review, specifically to let them respond before a final decision, is itself part of a properly run peer review process in most states and is not, on its own, a typical waiver trigger — but because waiver rules genuinely vary state to state, confirm this against local counsel before treating it as settled, and route any such disclosure through the same committee structure that generated the request rather than an informal side channel.
What breaks the privilege
Peer-review privilege is not self-executing; it depends on the process actually matching what the statute and the bylaws describe. The waiver patterns that recur across states:
- Material generated outside a qualifying committee. A root cause analysis or incident review conducted by an administrator or a single physician, without being conducted by or at the direction of the properly constituted committee, typically falls outside the privilege even if the topic and content look identical to protected work.
- Disclosure to unauthorized recipients. Sharing committee minutes, an external reviewer’s report, or peer review discussion with anyone outside the defined committee membership — including informally, in a hallway conversation or a forwarded email — is one of the most common ways organizations lose the protection they assumed they had.
- A gap between the written policy and actual practice. If the bylaws or peer review policy describe a process the organization does not actually follow — a committee that never really meets as described, documentation that skips steps the policy requires — courts have treated that mismatch as evidence the material was not really produced for peer review purposes.
- Using the peer review label after the fact. Retroactively calling a document “peer review material” because litigation started does not create privilege for something generated for another purpose (routine risk management, a billing audit, ordinary quality reporting) at the time it was created.
The practical implication is the same across all four: privilege protection is earned by the process at the time the material is created, not asserted afterward. An organization that wants the protection to hold needs its bylaws, its actual committee practice, and its confidentiality discipline to match, continuously — not just on paper.
Practical safeguards
- Review the peer review sections of the medical staff bylaws on a regular cycle, not only when a legal problem surfaces — see medical staff bylaws requirements for what the CMS Conditions of Participation and Joint Commission’s MS chapter each expect those sections to contain.
- Log the committee’s actual membership, quorum, and stated purpose for every meeting that touches a specific practitioner’s case — the record of who was in the room and why is often what a court checks first.
- Route any incident-review or root-cause-analysis work through the committee structure from the start, rather than having an administrator investigate informally and hand results to the committee after the fact.
- Put a written confidentiality reminder in front of every participant, including external reviewers, and require external reviewers to sign a confidentiality agreement before receiving case material.
- Keep PSO-bound patient safety evaluation system material and ordinary peer-review committee material in separate, clearly labeled tracks — conflating the two makes it harder to establish which of the two distinct federal protections, if either, actually applies to a given document.
FAQ
Is peer review privilege the same thing as HIPAA?
No. HIPAA governs the privacy and security of individually identifiable health information generally. Peer review privilege is a separate legal doctrine — state evidentiary law, plus the federal PSWP privilege where PSO reporting is involved — that shields the process and product of quality review specifically from discovery in litigation.
Does HCQIA immunity mean our committee’s records can’t be subpoenaed?
No. HCQIA limits money-damages liability for the review action itself; it says nothing about whether the underlying records are discoverable. That question is answered by state peer-review privilege law and, for PSO-bound material, the federal PSWP privilege — not by HCQIA.
Do we need external review for every FPPE-for-cause case?
Not automatically. External review is warranted when no qualified, conflict-free internal reviewer exists, when the case is high-severity or high-visibility, or when the bylaws specifically require it for certain findings — not as a default step for every focused review.
Can we lose the privilege just by telling the physician what the external reviewer found?
Sharing an external review with the physician under review, to let them respond before a final decision, is generally part of a properly run process rather than a waiver — but because state rules on this vary, confirm the specific answer for each state an organization operates in before relying on it.








