# Near-miss reporting and safety culture: a practical guide

> A near miss could have caused harm but was caught or reached no one. It shows the same system weakness as an injury, without the injury. Staff report more when reports lead to fixes, not blame. Use a just culture, make filing quick, and tell reporters what changed.

Source: https://incidentkit.ai/guides/near-miss-reporting-and-safety-culture · Updated Oct 5, 2026

## Near misses expose weaknesses before anyone is hurt

A near miss is an error or hazard that was caught, or never reached anyone, before it caused harm. The Joint Commission calls these close calls or good catches. OSHA and EPA say near miss.

OSHA's process safety rule covers incidents that "could reasonably have resulted" in a catastrophic release. See [near miss](https://incidentkit.ai/glossary/near-miss).

The cause is the same whether or not someone was hurt. CMS gives a surgery center example. Records for two patients booked for the same foot procedure, on opposite feet, get mixed up. The time-out catches it.

CMS says centers should find such errors, because they can cause adverse events.

Surveyors read near misses as proof of how a system behaves. CMS hospital guidance describes a year with three wrong-site surgeries and five near misses, and no action. CMS says that suggests noncompliance with the QAPI condition.

## Most harm events go unreported

In a 2012 HHS Office of Inspector General study, hospital incident systems captured an estimated 14 percent of the harm events Medicare patients experienced. Administrators said staff did not see about 61 percent of harm events as reportable.

Harm is common. A 2022 OIG study found 25 percent of Medicare patients had harm during hospital stays in one month: 12 percent adverse events and 13 percent temporary harm. Physician reviewers judged 43 percent of those events preventable.

Near misses are harder to see, because nothing visible happens. AHRQ's PSNet notes that reports do not show how many near misses occurred. Physicians generally do not use voluntary systems. No feedback is a commonly cited reason people stop.

## Just culture holds people accountable without blame

A just culture keeps people accountable for choices and treats most errors as symptoms of the system. AHRQ's PSNet describes a culture of safety as one where people report errors and near misses without fear of reprimand. See [just culture](https://incidentkit.ai/glossary/just-culture).

*The three categories as commonly described*

| Category | What it looks like | Where the response belongs |
| --- | --- | --- |
| Human error | A slip, lapse or mistake in a system that allowed it | System review: design, workload, tools, communication |
| At-risk behavior | A shortcut that seems safe or saves time | Find out why it makes sense and fix the conditions |
| Reckless behavior | Knowingly taking a significant risk | Administrative or HR process, outside root cause analysis |

A simple test, following RCA2: if a well-trained person in typical conditions made the error, others could too. Look for the system factor. Discipline would change one person and leave the next exposed.

RCA2 says to define blameworthy events in advance, such as criminal or deliberately unsafe acts, and handle them through HR. That protects the analysis and the reporter.

> **Protection from retaliation is also a legal matter** The Joint Commission expects reporting systems "without the risk of retaliation," but accountability for negligence remains. OSHA's recordkeeping rule bars discharging or discriminating against an employee for reporting a work injury or illness. Pennsylvania's MCARE Act protects health care workers who report. See [employee reporting and retaliation](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation).

## Six barriers to reporting, and what fixes them

| Barrier | What you hear | What helps |
| --- | --- | --- |
| Fear of blame | It will end up in my file. | A written just culture policy. Reports kept out of discipline. Leaders who thank the reporter. |
| No feedback | Nothing ever happens. | Acknowledge within a day. Tell the reporter the outcome. |
| Not seen as reportable | That is just how it is here. | A short list of examples per unit. OIG found staff did not see most harm events as reportable. |
| Too slow | I do not have time. | A phone-friendly form that takes the story in plain words. |
| Unclear route | Where do I send this? | One door: a QR code, a link or an email address. |
| Counts that punish | Reporting hurts our safety numbers. | Make sure no bonus, contest or discipline rule discourages reports. OSHA treats a procedure that would deter a reasonable employee as unreasonable. |

## Eight steps to raise near-miss reporting

1. **Define a near miss in plain words** Give five examples per unit, drawn from your own events.
2. **Make the first report take two minutes** Allow a phone, QR code, link or email, in the person's own words.
3. **Accept reports from everyone** Contractors, volunteers and visitors see what employees miss. Skip the login.
4. **Acknowledge within a day** Even an automatic message shows someone received it.
5. **Triage by risk** Rate severity and likelihood, not who filed. See the [root cause analysis and CAPA guide](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide).
6. **Fix cheap things fast** Quick wins show reports work. Post what changed where staff will see it.
7. **Recognize good catches** Thank the person and explain what the catch taught the team.
8. **Review monthly by unit** Look at trends, repeat near misses and open actions. Keep it short.

> **Three questions that turn a near miss into a lesson** What was the worst plausible outcome? What stopped it, design or luck? Where else could the same thing happen? The third question is the preventive half of CAPA.

See [how to get staff to report near misses](https://incidentkit.ai/blog/how-to-get-staff-to-report-near-misses). The [near-miss report template](https://incidentkit.ai/templates/near-miss-report) is a short form to start with.

## Healthcare examples show the work after the catch

**Surgery center.** The time-out caught the mixed-up records. The useful work comes next. Why were two same-day cases with opposite sides scheduled so they could be confused? Is the catching check reliable on a busy day?

**Nursing home (illustrative scenario).** A nursing assistant finds a bed-exit alarm unplugged during rounds. The resident is fine. The report asks why, and finds a shared charger across rooms. A second outlet and a charging check fix it.

Nobody would have found that after a fall.

## Lessons from industry and aviation

**Process safety.** OSHA's standard requires covered employers to investigate any incident that did, or could reasonably have, caused a catastrophic release. Start within 48 hours. A near miss can create a legal duty.

In OSHA and EPA's example, earlier non-lethal releases were blamed on operator error, when funding cuts had weakened mechanical integrity.

**BP Texas City.** The 2005 refinery explosion killed 15 workers and injured 180. The U.S. Chemical Safety Board found safety deficiencies at all levels. BP had put personal injury measures ahead of process safety indicators.

The board urged reporting of incidents and near misses without fear of retaliation. A low injury rate does not prove a safe process. See [TRIR and DART rates](https://incidentkit.ai/compliance/osha/trir-and-dart-rates).

**Aviation.** NASA's Aviation Safety Reporting System takes voluntary reports through NASA, not the regulator. Reports are de-identified. The FAA will not use them in enforcement except for criminal offenses and accidents.

A reporter who files within 10 days of an inadvertent violation may qualify for a penalty waiver. The lesson: separate reporting from discipline, and publish what you learn.

## Feedback keeps reporting alive

A feedback loop runs from report to acknowledgment, triage, action, verification and a message back to the reporter. Without the last step, reporting decays. PSNet lists missing feedback as a common barrier.

The VA triage rules in RCA2 require timely feedback to every known reporter, whatever the risk score.

*Suggested targets. These are recommendations, not regulatory requirements.*

| Stage | Target |
| --- | --- |
| Acknowledge | Same business day |
| Triage | Serious events same day; others within three days |
| Action decided | Low risk within two weeks; serious on the analysis timeline |
| Verify | On the date set in the measure |
| Tell the reporter and unit | Within a week of the decision; monthly unit summary |

A "you said, we did" board or monthly message closes the loop for everyone, not only the person who filed.

## Measure trust, not report volume

The Joint Commission's hospital standards expect leaders to evaluate safety culture regularly with valid, reliable tools. Its ambulatory survey guide lists culture of safety data among documents surveyors expect. AHRQ's Surveys on Patient Safety Culture cover hospitals, medical offices, nursing homes, pharmacies and surgery centers.

Also watch for signs of trust:

- Near-miss share of reports, as a trend, not a quota.
- Hours from event to report; days from report to feedback.
- Share of reports that led to a verified action.
- Repeat near misses by location.

PSNet cautions that some organizations celebrate more reports and others fewer, and both can be wrong. A count needs a denominator and an outcome.

## How IncidentKit supports near-miss reporting

Staff can report through a [QR quick report](https://incidentkit.ai/product/quick-report), [email-to-incident](https://incidentkit.ai/product/email-to-incident) or a web form, and describe what happened by text. Voice is rolling out. [Lauren](https://incidentkit.ai/product/lauren) asks the follow-up questions, and a person reviews and signs.

IncidentKit has no seats, so adding every employee, contractor and visitor costs nothing extra. Non-patient incidents are free on the Open plan. See [near-miss reporting](https://incidentkit.ai/use-cases/near-miss-reporting) and [pricing](https://incidentkit.ai/pricing).

## Frequently asked questions

### What is a near miss?

A near miss is an error or hazard that did not cause harm, either because it was caught in time or because it reached no one. CMS gives the example of mixed-up surgery records caught at the time-out. Hospitals also call near misses close calls or good catches.

### Should near misses be investigated?

Yes, in proportion to risk. Triage by severity and likelihood. Investigate high-risk ones with a team and review low-risk ones quickly. OSHA and EPA urge root cause analysis after any near miss. OSHA's process safety standard requires investigating incidents that could reasonably have caused a catastrophic release.

### What is just culture?

Just culture balances accountability with a focus on systems. It separates human error, at-risk behavior and reckless conduct, and responds to each differently. Most errors lead to system fixes. Deliberate or reckless acts go through HR, outside root cause analysis.

### How do you encourage staff to report near misses?

Make reporting safe, quick and useful. Write a just culture policy, accept reports by phone, QR code or email, acknowledge each within a day, and tell reporters what changed. PSNet names missing feedback as a common barrier, so closing the loop matters more than incentives.

### Can near-miss reports be anonymous?

Yes, with a trade-off. PSNet says most systems are confidential: the reporter is known but protected. Some, like the ICU Safety Reporting System, are fully anonymous. Anonymous reports cannot get follow-up questions. Offer confidentiality by default, and anonymity where fear is high.

### What is a good ratio of near misses to incidents?

There is no valid universal ratio. PSNet notes that event reports lack a denominator and miss unreported near misses. Track the near-miss share of your own reports over time, with feedback speed and repeat events. A rising share after a culture push is a good sign.

## Sources

- [CMS State Operations Manual, Appendix L: Ambulatory Surgical Centers (QAPI near-miss example)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_l_ambulatory.pdf)
- [CMS State Operations Manual, Appendix A: Hospitals (A-0263)](https://www.cms.gov/regulations-and-guidance/guidance/manuals/downloads/som107ap_a_hospitals.pdf)
- [HHS OIG, Hospital Incident Reporting Systems Do Not Capture Most Patient Harm (OEI-06-09-00091, 2012)](https://oig.hhs.gov/oei/reports/oei-06-09-00091.asp)
- [HHS OIG, Adverse Events in Hospitals: A Quarter of Medicare Patients Experienced Harm in October 2018 (2022)](https://oig.hhs.gov/reports/all/2022/adverse-events-in-hospitals-a-quarter-of-medicare-patients-experienced-harm-in-october-2018/)
- [AHRQ PSNet, Patient Safety Event Reporting primer](https://psnet.ahrq.gov/primer/reporting-patient-safety-events)
- [AHRQ PSNet, Culture of Safety primer](https://psnet.ahrq.gov/primer/culture-safety)
- [Joint Commission, National Performance Goals effective January 2026, Hospital Program (NPG.02.03.01)](https://digitalassets.jointcommission.org/api/public/content/9ca80055182b4274842a5780a94f2c82)
- [Joint Commission, Ambulatory Care Accreditation Organization Survey Activity Guide (2026)](https://digitalassets.jointcommission.org/api/public/content/2f21045af9d84f5fbc9bfef10d620469)
- [IHI, Action Hierarchy Tool (RCA2 and blameworthy events)](https://www.ihi.org/sites/default/files/SafetyToolkit_ActionHierarchy.pdf)
- [IHI and NPSF, RCA2: Improving Root Cause Analyses and Actions to Prevent Harm](https://www.ihi.org/sites/default/files/RCA2_ImprovingRootCauseAnalysesandActionstoPreventHarm.pdf)
- [29 CFR Part 1904, including 1904.35 employee involvement (eCFR)](https://www.ecfr.gov/current/title-29/part-1904)
- [Pennsylvania MCARE Act (Act 13 of 2002), section 308](https://www.legis.state.pa.us/WU01/LI/LI/US/PDF/2002/0/0013..PDF)
- [OSHA and EPA, The Importance of Root Cause Analysis During Incident Investigation (fact sheet)](https://www.osha.gov/sites/default/files/publications/OSHA3895.pdf)
- [29 CFR 1910.119, Process safety management of highly hazardous chemicals (eCFR)](https://www.ecfr.gov/current/title-29/section-1910.119)
- [U.S. Chemical Safety Board, BP America Refinery Explosion](https://www.csb.gov/bp-america-refinery-explosion/)
- [NASA Aviation Safety Reporting System, Immunity Policies (FAA Advisory Circular 00-46F)](https://asrs.arc.nasa.gov/overview/immunity.html)

## Related

- [Near-Miss Reporting: How to Build a Program That Works](https://incidentkit.ai/use-cases/near-miss-reporting)
- [How to get staff to report near misses (and keep doing it)](https://incidentkit.ai/blog/how-to-get-staff-to-report-near-misses)
- [Near miss: definition and meaning](https://incidentkit.ai/glossary/near-miss)
- [Just culture: definition and meaning](https://incidentkit.ai/glossary/just-culture)
- [Near Miss Report Template (Free, Printable Form)](https://incidentkit.ai/templates/near-miss-report)
- [Incident reporting in healthcare: the complete guide](https://incidentkit.ai/guides/incident-reporting-in-healthcare)
- [Root cause analysis and CAPA: methods and strong actions](https://incidentkit.ai/guides/root-cause-analysis-and-capa-guide)
- [Injury reporting and retaliation: 29 CFR 1904.35 and 11(c)](https://incidentkit.ai/compliance/osha/employee-reporting-and-retaliation)
