# Patient safety organization

> A patient safety organization (PSO) is a group HHS lists to collect and study safety data. Data sent to it can be legally protected.

Source: https://incidentkit.ai/glossary/patient-safety-organization · Updated Oct 5, 2026

Also known as: PSO

## What a PSO is

42 CFR 3.20 defines a PSO as a private or public group, or part of one, that the HHS Secretary lists as a PSO. A health insurance issuer cannot be a PSO.

Patient safety work product means data, reports, notes and analyses, such as root cause analyses, that could improve patient safety. They must be made to send to a PSO and then sent, or made by a PSO for safety work.

## What is protected

Under 42 CFR 3.204, patient safety work product is privileged, which means legally protected. It is not open to subpoena, discovery, Freedom of Information Act requests, or use as evidence in the listed cases. The exceptions are:

- Some criminal cases
- Equitable relief
- Provider consent
- Data that cannot identify anyone

Limits: it leaves out the patient's medical record, billing and discharge data and other original records. Copying data to a PSO does not protect it. Duties to report to authorities still apply.

Mix-up: sending an event report to a PSO does not replace required reports to the state or CMS.

## Frequently asked questions

### Does reporting to a PSO satisfy state reporting requirements?

No. Required reports still go where the law sends them, because data that is not patient safety work product can still go to government agencies.

### Is a root cause analysis privileged if we send it to a PSO?

It can be, if it was made for the PSO and sent, or sits in your patient safety evaluation system. The rule lists RCAs as an example.

### Is a PSO a business associate?

Generally, yes, if it handles protected health information for a provider. HIPAA's business associate definition includes patient safety work (42 CFR 3.20).

## Sources

- [42 CFR 3.20: Patient safety organization definitions](https://www.ecfr.gov/current/title-42/section-3.20)
- [42 CFR 3.204: Privilege of patient safety work product](https://www.ecfr.gov/current/title-42/section-3.204)
- [45 CFR 160.103: HIPAA definitions (protected health information, business associate)](https://www.ecfr.gov/current/title-45/section-160.103)
- [AHRQ PSNet: Patient safety event reporting (primer)](https://psnet.ahrq.gov/primer/reporting-patient-safety-events)

## Related terms

- [Incident report](https://incidentkit.ai/glossary/incident-report)
- [Variance report](https://incidentkit.ai/glossary/variance-report)
- [Business associate agreement](https://incidentkit.ai/glossary/business-associate-agreement)
- [Protected health information (PHI)](https://incidentkit.ai/glossary/phi)
- [Root cause analysis](https://incidentkit.ai/glossary/root-cause-analysis)

## Related

- [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare)
- [HIPAA and BAA for incident reporting](https://incidentkit.ai/hipaa)
- [IncidentKit security overview](https://incidentkit.ai/security)
- [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview)
- [Incident audit trail: every change, who and when](https://incidentkit.ai/product/audit-trail)
