Skip to main content
v2026.11,772 entries · CC-BY 4.0

What Is Root Cause Analysis? (RCA in Patient Safety)

Root cause analysis (RCA) is the structured process healthcare and research-safety teams use to find the systemic causes behind an adverse event, not just the immediate action that preceded it.

Written and maintained by CASRAI Editorial Board

Last updated

Root cause analysis (RCA) is a structured process for figuring out why an adverse event happened — not just the immediate action or equipment failure that preceded it, but the underlying system conditions that made that failure possible, or likely, in the first place. In a healthcare or research-safety setting, RCA is the standard tool teams reach for after something goes wrong: a medication error, a wrong-site event, a lab exposure, a data-integrity breakdown in a clinical trial. Its job is to move an investigation past “who made the mistake” and toward “what about the process let this mistake happen, and reach someone.”

This page answers the broad question — what RCA is, why it exists, and how it differs from related terms you’ll run into in the same conversation. If you already know the basics and need the operational detail — team composition, timeline reconstruction, writing a defensible causal statement — see our deeper guide, Root Cause Analysis in Healthcare: Team, Timeline, and Causal Factors.

The core idea: root cause vs. proximate cause

Most adverse events have an obvious, immediate cause — a nurse administered the wrong dose, a technician skipped a verification step, a freezer alarm went unanswered overnight. That immediate cause is called the proximate cause, and it’s almost never the whole story. RCA exists because fixing only the proximate cause — retraining the individual involved, adding a warning label — tends to produce a fix that doesn’t hold, because the conditions that made the error possible are still in place for the next person.

The alternative framing, used throughout patient-safety literature, distinguishes active errors (the specific action or omission that immediately preceded the event) from latent conditions — underlying weaknesses in staffing, design, training, communication, or process that made that active error more likely, or more likely to actually reach a patient or research participant once it happened. The commonly used mental model for this is the “Swiss cheese” model: several imperfect layers of defense, each with its own holes, occasionally lining up to let a single error pass all the way through to harm. RCA is the process of tracing back through those layers rather than stopping at the first one.

A root cause, in this sense, is a systemic factor that, if corrected, would prevent recurrence of the same failure pattern — not just this one instance of it.

Who uses RCA, and when

In a hospital or health system, RCA is most closely associated with the response to a sentinel event — a patient-safety event that reaches a patient and results in death, permanent harm, or severe temporary harm. A comprehensive, systematic RCA plus a corrective action plan is the standard, expected response once a sentinel event is identified. (For the definition and reporting mechanics of that trigger event itself, see What Is a Sentinel Event?) But RCA isn’t reserved only for the most severe cases: many organizations also run a full or scaled-down RCA on serious near misses, since a near miss carries the same systemic information as an actual harm event without the harm — and waiting for harm to occur before investigating discards that information for free.

Lower-severity, more routine events are typically better served by a lighter-weight review (often called an apparent cause analysis) or by aggregating several related low-harm events and looking for a shared cause, rather than convening a full multidisciplinary RCA for each one. That triage decision — full RCA vs. a lighter review — is usually made by a patient-safety or risk-management office based on actual or potential severity.

Outside acute clinical care, the same discipline shows up anywhere a system depends on catching failures before they compound: laboratory and research-safety incident review, corrective and preventive action (CAPA) processes in regulated research and quality environments, and research-integrity inquiries into data or protocol breakdowns. The underlying logic is identical — distinguish what happened at the surface from what allowed it to happen underneath.

Common RCA methods, at a general level

RCA is a process, not a single technique, and teams typically use one or more structured methods to actually get from a timeline of events to a defensible causal statement:

  • Five Whys — repeatedly asking “why did that happen?” in response to each answer, until the chain of reasoning arrives at a systemic factor rather than an individual action. Simple to run, but easy to stop too early or follow a single linear chain when the real cause is a combination of factors.
  • Fishbone (Ishikawa) diagram — a visual tool that organizes potential contributing factors into standard categories (commonly people, process, equipment, materials, environment, and management) branching off a central problem statement, so a team can look for contributing causes across several categories at once instead of following one chain.
  • Other structured tools — fault tree analysis, causal factor trees, and failure mode approaches — get used depending on event complexity and organizational preference.

Choosing among these, and using them well, is its own skill; our companion guide, Root Cause Analysis for CAPA: Choosing 5 Whys, Fishbone, or Fault Tree, covers when each is the right tool.

How RCA differs from adjacent terms

A few terms get used alongside “root cause analysis” often enough that it’s worth being precise about how they relate:

  • Sentinel event — the triggering incident itself (a defined category of serious patient-safety event), not the investigation. RCA is the standard response to a sentinel event, not a synonym for it. See What Is a Sentinel Event?
  • Never event — a specific, named category of serious, largely preventable event (such as wrong-site surgery) tracked separately by patient-safety organizations. A never event typically triggers an RCA, but the two terms describe different things: one is a category of event, the other is the investigative method used afterward. See What Is a Never Event?
  • Apparent cause analysis — a shorter, typically single-facilitator review used for lower-severity or more straightforward events, rather than the full multidisciplinary RCA process. See our comparison, Apparent Cause Analysis vs. Root Cause Analysis, for how organizations decide which one a given event warrants.
  • RCA2 — not a different investigation method, but a specific framework (originally published by the National Patient Safety Foundation, now maintained by the Institute for Healthcare Improvement) for turning RCA findings into corrective actions that are actually likely to hold, using a weak/intermediate/strong action hierarchy. See RCA2 Action Hierarchy: Weak, Intermediate, and Strong Actions After a Root Cause Analysis.

Why this matters beyond the clinical floor

Research administrators and research-integrity offices encounter the same underlying discipline outside direct patient care: a data-integrity failure in a clinical trial, a biosafety or chemical-safety incident in a research lab, or a research-misconduct inquiry all call for the same distinction between the immediate, visible failure and the systemic condition that allowed it. Grant-funded human-subjects research is often directly subject to institutional adverse-event and unanticipated-problem reporting requirements that expect exactly this kind of systemic analysis, not just a description of what happened. Understanding RCA as a general discipline — rather than a hospital-specific procedure — makes it easier to recognize when a research-side incident calls for the same rigor.

Frequently asked questions

Is root cause analysis required by law or accreditation standards?

Accrediting bodies that use the sentinel-event framework generally expect a comprehensive RCA and corrective action plan following a sentinel event, on a defined timeline set by the applicable accreditation policy. Requirements and exact timelines vary by accreditor and jurisdiction, and policies are revised periodically, so confirm the current requirement against your organization’s applicable accreditation manual rather than treating any single figure as fixed.

Who conducts a root cause analysis?

RCA is typically conducted by a multidisciplinary team rather than a single investigator — convened and facilitated by a patient-safety, quality, or risk-management office, with participation from the staff and departments closest to the event. Team composition and facilitation are covered in more depth in our guide on Root Cause Analysis in Healthcare.

Does every adverse event get a full RCA?

No. Organizations typically triage by severity: sentinel events and serious near misses generally warrant a full RCA, while lower-severity or more routine events are often handled through a lighter apparent cause analysis or aggregate review across several related events instead.

Is RCA only used in hospitals?

No — the same structured, systems-focused investigation logic is used across manufacturing, aviation, and other high-reliability fields, and within research settings for laboratory-safety incidents, data-integrity failures, and quality/CAPA processes. This page focuses on its use in patient-safety and research-safety contexts specifically.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Ask CASRAI · included with Regulatory Radar

Ask about What Is Root Cause Analysis? (RCA in Patient Safety)

Ask CASRAI answers research-administration questions and cites the passages behind every claim — and says so when the corpus does not cover something, instead of guessing. It comes with a Regulatory Radar subscription at $29 a month, alongside the daily digest of regulatory changes and the dashboard of what changed.

150 questions a day, on this site, over the API, or inside your own tools through the CASRAI MCP server.

Everything CASRAI publishes — this page, the dictionary, the guides and the news — stays free to read, with no account and no card.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 72,264 indexed passages, and every answer cites the ones it drew on.