# A structured incident record, from report to claim file

> Insureds capture incidents early, so carriers get cleaner data and claims-ready files.

Source: https://incidentkit.ai/solutions/insurers-and-risk-pools · Updated Oct 5, 2026

**Status: rolling out.** This pack is being released in stages.

**Who:** The insured reports, investigates and signs. The carrier, third-party administrator (TPA), pool or captive receives; this path is early, and the page says where.

## The problems

- **The first report arrives late and thin:** A claim can start with an email weeks later, from someone who was not there. Facts arrive in the order the insured recalls them.
- **Notice timing can decide how a policy responds:** Claims-made policies respond when a claim is reported in force or in an extended reporting period (NAIC). An incident nobody captured may never be reported.
- **Loss control works from lagging data:** IRMI defines loss control as reducing the chance or severity of loss. Without early data, it sees the loss run, not the near misses.
- **Every insured reports in a different shape:** Workers' compensation first reports follow state forms and deadlines, such as Texas's eight days. Liability notices have no common intake.

## Incident types in the pack

- First notice of a possible claim
- Notice of circumstances under a claims-made form
- Workers' compensation first report of injury
- Medication errors and wrong-site events
- Falls with injury in senior living
- Abuse and neglect allegations with a reporting clock
- Employee injuries that are OSHA recordable
- Equipment failures and property damage
- Repeat events at one insured
- Corrective actions after a serious event
- Contractor and visitor injuries
- Incident files requested by an adjuster or counsel

## Regulators and standards

- **IAIABC EDI Claims standard:** IAIABC publishes the standard for first and subsequent reports of injury (FROI, SROI) sent to jurisdictions. Release 3.1 is current. Our integration is rolling out, with no conformance claimed today.
- **State workers' compensation agencies:** Each state sets its own first-report rules. Texas uses DWC Form-001, due within eight days after an employee cannot work for over a day, or immediately for disease or death.
- **OSHA recordkeeping forms, 29 CFR 1904.29:** An insurance form can replace the OSHA 301 if it is as readable, carries the same information and follows the same instructions. Names may be shared to process a claim.
- **NAIC: claims-made forms, risk retention groups, captives:** Risk retention groups are liability insurers owned by their members (Liability Risk Retention Act of 1986). Captives are owned by the insured. Claims-made and occurrence forms respond differently.
- **AHRQ Patient Safety Organization program:** Patient safety work product reported to a listed PSO can carry federal protections when requirements are met. The insured and its counsel decide what goes to a carrier.
- **HIPAA:** A carrier is separate from the insured provider. The insured's privacy officer and counsel decide what patient information flows to it, and on what basis. See [HIPAA](https://incidentkit.ai/hipaa).

## How it works

1. **Live: the insured captures the incident when it happens** Staff text what happened to Lauren, or use QR or email. Lauren drafts the form, marked 'Lauren · draft' until a person approves it. Every change is logged.
2. **Live: the insured investigates and closes the loop** Contributing factors, five whys and disposition, then corrective actions with an owner, due date, evidence and effectiveness check. Nothing closes until verified.
3. **Live: the insured sends a claims-ready packet** When an incident may become a claim, the insured exports the narrative, timeline, investigation, actions and audit trail as a packet. Nothing leaves unless the insured sends it.
4. **Rolling out: a structured feed for carriers and TPAs** A data feed and API for carriers and TPAs to receive incident records in one structure, plus workers' compensation first-report integration. We name no supported carriers or TPAs today.

## Scenario: From an unplanned transfer to a claims-ready file

A surgery center transfers a patient; every step through day 40 works today, and the last is rolling out.

- **Tuesday, 15:10, Circulating nurse texts Lauren.** From recovery, the circulating nurse texts Lauren that the patient's condition changed 20 minutes ago and an ambulance is on the way.
- **Tuesday, 15:12, Lauren drafts the transfer report.** Lauren asks when it started, what was done, who was told and whether the family knows. The draft is marked 'Lauren · draft'.
- **Tuesday, 15:40, Escalation notifies administrator and risk lead.** The charge nurse reviews, edits and signs. Rules notify the administrator and risk lead, because the insured treats transfers as possible claims.
- **Wednesday, 09:00, Administrator opens the investigation.** The administrator lists the causes. The risk lead reads the policy's notice conditions and decides whether to notify the carrier. That decision stays with the insured.
- **Wednesday, 10:30, Packet reaches carrier claims intake.** The insured exports a packet with the narrative, timeline, investigation and audit trail. It goes to claims intake. The adjuster starts from a record, not an email chain.
- **Day 10, Investigation closes with two actions.** Each of the two corrective actions has an owner and a due date.
- **Day 40, Effectiveness check closes the actions.** If the insured shares the file, loss control sees the fix held. Evidence is attached and the effectiveness check is done before the actions close.
- **When the feed ships, Structured feed reaches the carrier.** Rolling out: the same event reaches a participating carrier or TPA as a structured record when the insured sends it, not as a document someone retypes.

## What is in the pack

**Forms:** The insured's incident form for its setting, from any pack; Investigation record with causes, five whys and disposition; Action plan with owner, due date, evidence, effectiveness check; Workers' comp first-report data set (rolling out)

**Routing:** Possible claims alert the risk lead and administrator at once; Severity rules for loss-control events; Reminders for open actions after serious events

**Exports:** Claims-ready file: narrative, investigation, audit trail (live); QAPI summaries and survey packets (live); OSHA 300, 300A and 301 exports (rolling out); Carrier and TPA data feed and API (rolling out); Workers' comp first-report integration (rolling out)

**Roles:** The insured's reporters, reviewers and action owners; The insured's administrators decide what is shared; Carrier and TPA access: packets today, direct feed rolling out

## Outcomes

- **Earlier first notice, by design:** Incidents are recorded when they happen, with a time and an author. Whether to notify a carrier stays the insured's call.
- **Cleaner data at the source:** Same questions per event type, with structured fields behind the narrative. Structure at intake is what makes a later feed possible.
- **Loss-control visibility:** A loss-control team can see repeat events, overdue actions and unchecked fixes, with the insured's agreement.
- **A claims-ready file from day one:** The packet carries the narrative, investigation and audit trail, so an adjuster starts from a record. See [audit trail](https://incidentkit.ai/product/audit-trail) and [compliance packets](https://incidentkit.ai/product/compliance-packets).

## Frequently asked questions

### Can an insurer or TPA use IncidentKit today?

Not as a carrier product. Today the insured is the customer. It reports, investigates and closes incidents in IncidentKit. It can send a claims-ready packet to a carrier, TPA or counsel. The carrier-side data feed and first-report integration are rolling out.

### How does this relate to workers' compensation first reports?

IncidentKit captures the data a first report of injury (FROI) needs. The integration that sends it onward is rolling out. Claims administrators use the IAIABC EDI standard, now Release 3.1, to send FROI and later reports (SROI) to jurisdictions. See [FROI](https://incidentkit.ai/glossary/froi).

### Does sharing incident data with a carrier waive privilege?

That is a question for the insured's counsel, because answers differ by state and program. Federal protections can apply to patient safety work product reported to a listed PSO. IncidentKit does not decide what the insured shares.

### Will a carrier see our incidents automatically?

No. Today nothing leaves the organization unless the insured exports it. Our intent for the feed is that the insured controls what is shared and with whom.

### How can a carrier, TPA or pool take part?

Tell us what a feed would need to contain for your claims or loss-control team. Early input shapes what we build. Use [contact](https://incidentkit.ai/contact) or see the [partners](https://incidentkit.ai/partners) page.

## Sources

- [IAIABC, EDI Claims standards (FROI and SROI)](https://www.iaiabc.org/edi-claims)
- [Texas Department of Insurance, Employer FAQ (DWC Form-001 deadline)](https://www.tdi.texas.gov/wc/employer/employerfaq.html)
- [29 CFR 1904.29, Forms (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.29)
- [NAIC, Risk retention groups](https://content.naic.org/insurance-topics/risk-retention-groups)
- [NAIC, Captive insurance companies](https://content.naic.org/insurance-topics/captive-insurance-companies)
- [NAIC, Medical malpractice insurance (claims-made and occurrence forms)](https://content.naic.org/insurance-topics/medical-malpractice-insurance)
- [IRMI, Loss control definition](https://www.irmi.com/term/insurance-definitions/loss-control)
- [AHRQ, Patient Safety Organization (PSO) Program](https://pso.ahrq.gov/)

## Related

- [QAPI, survey and OSHA compliance packets](https://incidentkit.ai/product/compliance-packets)
- [Incident reporting API, webhooks and integrations](https://incidentkit.ai/product/integrations-and-api)
- [Incident audit trail: every change, who and when](https://incidentkit.ai/product/audit-trail)
- [Incident investigations and root cause analysis](https://incidentkit.ai/product/investigations)
- [FROI (First Report of Injury): definition and meaning](https://incidentkit.ai/glossary/froi)
- [Workers' compensation: definition and meaning](https://incidentkit.ai/glossary/workers-compensation)
- [Patient safety organization: definition and meaning](https://incidentkit.ai/glossary/patient-safety-organization)
- [Multi-site incident reporting software for groups](https://incidentkit.ai/solutions/multi-site-groups)
- [IncidentKit partner program](https://incidentkit.ai/partners)
- [HIPAA and BAA for incident reporting](https://incidentkit.ai/hipaa)
- [OSHA 301 incident report: the 18 fields and deadlines](https://incidentkit.ai/compliance/osha/osha-301-incident-report)
- [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview)
- [OSHA severe injury reporting: 8-hour and 24-hour rules](https://incidentkit.ai/compliance/osha/severe-injury-reporting)
- [State adverse event reporting for hospitals, ASCs and SNFs](https://incidentkit.ai/compliance/reporting-deadlines/state-reporting-overview)
- [Joint Commission sentinel event policy: definition and RCA](https://incidentkit.ai/compliance/reporting-deadlines/sentinel-events)
