# One incident standard across every site you run

> Every site reports and closes the same way, and corporate sees it all.

Source: https://incidentkit.ai/solutions/multi-site-groups · Updated Oct 5, 2026

**Who:** Site staff report, and each site leader signs. A COO, VP of quality or risk, or head of EHS buys and reviews across sites without reading every incident.

## The problems

- **Every site built its own process:** One site uses paper, another a spreadsheet, a third an inherited tool. Corporate retypes a monthly roll-up, so patterns show up a quarter late.
- **Regulators judge each site on its own:** OSHA wants a 300 Log per establishment open a year or longer. CMS expects a QAPI quality program at each nursing home and surgery center.
- **An acquisition arrives with unknown open items:** You inherit the seller's incident history and open actions in a format you did not choose. You cannot set a standard until you see them.
- **Corporate needs visibility, not every report:** Corporate cannot read every incident, and sites should not need permission to run theirs. Set rules for what escalates, to whom, and how fast.

## Incident types in the pack

- Serious events needing same-day corporate notice
- The same incident repeating at two or more sites
- Overdue corrective actions by site and owner
- Reporting clocks running at several sites
- Quarterly QAPI and board quality packets
- OSHA 300A summaries for each establishment
- Survey results with plans of correction in flight
- Incidents at a newly acquired site
- Contractor, visitor and agency-staff incidents
- Carrier questions at renewal
- A new leader inheriting open items
- A policy change that must land everywhere

## Regulators and standards

- **CMS: skilled nursing QAPI, 42 CFR 483.75:** Each long-term care facility, even in a multiunit chain, runs its own QAPI program, and its QAA committee meets at least quarterly. The evidence lives at the facility.
- **CMS: multi-hospital systems, 42 CFR 482.21(g):** A health system's governing body can elect one QAPI program for two or more separately certified hospitals, if each shows its local issues are considered.
- **CMS: surgery centers, 42 CFR 416.41 and 416.43:** Each surgery center's governing body oversees its QAPI program and must provide staff, time, systems and training.
- **OSHA: multiple establishments, 29 CFR 1904.30:** Keep a separate 300 Log for each establishment expected to run a year or longer. Central records are allowed if case data reaches that location within seven calendar days.
- **OSHA: electronic submission, 29 CFR 1904.41:** Covered establishments submit 300A data once a year, by March 2. A corporate office that controls establishments may collect and submit for them.
- **HIPAA: business associates, 45 CFR 160.103:** A vendor that maintains patient information for a covered entity is a business associate. Regulated plans include a business associate agreement (BAA); see [HIPAA](https://incidentkit.ai/hipaa).

## How it works

1. **Set the standard once** Set incident types, severity levels and escalation rules, with a pack for each kind of site. A surgery center, a nursing home and a plant can share one account.
2. **Bring each site live in 48 hours** Our team does the setup: facilities, users, QR codes, role templates, SSO on the Network plan, and import of the site's history. Staff report in their own words by text.
3. **Let each site run its own incidents** Lauren drafts the form from the site's answers. The reviewer edits and signs, and drafted fields are marked 'Lauren · draft' until approved. Severity rules notify corporate.
4. **See every site in one place** Org-level analytics cluster incidents by site, shift, equipment and cause. Overdue actions sort by site and owner. Each facility's QAPI summary or survey packet builds from its own record.

## Scenario: Adding a nursing home to two surgery centers and a plant

A group with two surgery centers and a plant on a rolling-out industry pack buys a nursing home on a Monday.

- **Monday, 09:00, Quality lead adds the nursing home.** The deal closes. The quality lead adds the facility and assigns the nursing home pack. The other sites stay on their own packs.
- **Monday, 14:00, Seller's incident log is imported.** Setup starts. The seller's incident log arrives as a spreadsheet and is imported. Open items keep their original dates and get new owners.
- **Tuesday, Staff get roles through single sign-on.** QR codes go up at the nurse stations, and a nurse texts a test report. Leaders get role templates through single sign-on.
- **Wednesday, 09:00, Facility goes live in 48 hours.** Corporate sees the facility's open actions, some already overdue, next to the other three sites, 48 hours after kickoff.
- **Day 9, 02:40, Night nurse reports an unexplained bruise.** A resident has a bruise of unknown source. The night nurse texts it in. It routes to the administrator at once, with the 42 CFR 483.12(c) reporting windows noted.
- **Day 9, 08:15, Administrator signs the draft report.** The administrator corrects two fields and signs. The regional vice president is alerted under the severity rule. The director of nursing opens the investigation.
- **Day 9, same week, Plant near miss routes separately.** In the same organization, a forklift near miss at the plant routes to the plant manager and EHS lead. Corporate filters both by pack.
- **Day 75, QAA committee reviews the QAPI summary.** The nursing home's QAA committee meets. Its QAPI summary builds from the facility's own incidents and actions, and corporate sees the same data.

## What is in the pack

**Forms:** Group-wide form template with site-level additions; Nursing home report: falls, unknown-source injuries, abuse allegations; Surgery center report: patient events, near misses, equipment; Plant injury and near-miss report; Contractor, visitor and agency-staff incident form

**Routing:** Severity rules notify the site leader first, corporate by threshold; Site-specific recipients and backups for each kind of event; Same-day alerts for events with a reporting clock; Open items reassign when a site leader leaves

**Exports:** QAPI summary per facility; Survey packet per facility; OSHA 300, 300A and 301 per establishment (rolling out); Org-wide analytics by site, shift, equipment and cause; Read API and signed webhooks for your own reporting

**Roles:** Group administrators: sites, packs, SSO and role templates; Corporate reviewers: read and analyze across sites; Site administrators and plant managers: review, sign, assign and close; Investigators and action owners: scoped to their own site

## Outcomes

- **One standard, site-level evidence:** Every site shares incident types, severity levels and action rules, and each keeps its own record for surveyors.
- **Patterns across sites while they are small:** Because every site codes incidents the same way, the same near miss at two plants is one trend, not two anecdotes.
- **New sites on the standard in days:** Done-for-you setup and import put an acquired site on the group's system within 48 hours, with inherited open items visible and owned.
- **Packets for every site without a monthly retype:** QAPI summaries and survey packets build from the record, so corporate reviews them instead of assembling them. See [compliance packets](https://incidentkit.ai/product/compliance-packets).

## Frequently asked questions

### Can one IncidentKit account hold surgery centers, nursing homes and plants together?

Yes. A pack sets incident types, forms, regulator exports and roles for a kind of site, and you can mix packs across sites in one organization. Corporate sees all of them. Industry packs beyond healthcare are rolling out.

### How does pricing work for a group?

No seats, modules or setup fees. Non-patient incidents are free on the Open plan. Healthcare and audit-ready work is a per-site Regulated plan with a BAA, patient information, compliance packets and setup. Groups of 10 or more sites get the custom Network plan, adding SSO, the API, org-wide analytics and migration. See [pricing](https://incidentkit.ai/pricing).

### Can corporate keep OSHA records in one place?

Yes, but each establishment expected to operate a year or longer still needs its own 300 Log. Under 29 CFR 1904.30(b)(2) the central location must receive case information within seven calendar days and send records back within OSHA's access deadlines. IncidentKit keeps each establishment's record separate. OSHA 300, 300A and 301 exports are rolling out.

### How do we bring in a site we just acquired?

We set up the facility, import the seller's incident history, and assign owners to open items. Setup takes 48 hours per site. See [import and migration](https://incidentkit.ai/product/import-and-migration).

### Does IncidentKit replace our EHR, CMMS or HRIS?

No. It runs alongside them. Deeper EHR, CMMS and HRIS integrations are rolling out. Today the platform offers signed webhooks and a read API so your own systems can use incident data. See [integrations and API](https://incidentkit.ai/product/integrations-and-api).

## Sources

- [29 CFR 1904.30, Multiple business establishments (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.30)
- [29 CFR 1904.41, Electronic submission of injury and illness records (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.41)
- [29 CFR 1904.46, Definitions, establishment (eCFR)](https://www.ecfr.gov/current/title-29/part-1904/section-1904.46)
- [42 CFR 483.75, Quality assurance and performance improvement (eCFR)](https://www.ecfr.gov/current/title-42/part-483/section-483.75)
- [42 CFR 482.21, Hospital QAPI program (eCFR)](https://www.ecfr.gov/current/title-42/part-482/section-482.21)
- [42 CFR 416.43, ASC QAPI (eCFR)](https://www.ecfr.gov/current/title-42/part-416/section-416.43)
- [42 CFR 416.41, ASC governing body and management (eCFR)](https://www.ecfr.gov/current/title-42/part-416/section-416.41)
- [45 CFR 160.103, HIPAA definitions, business associate (eCFR)](https://www.ecfr.gov/current/title-45/part-160/section-160.103)
- [CMS State Operations Manual, Appendix PP (F865 and the multiunit chain intent)](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf)

## Related

- [Multi-site incident management with roles and SSO](https://incidentkit.ai/product/multi-site-and-roles)
- [Incident analytics: find the pattern before the next one](https://incidentkit.ai/product/analytics)
- [Migrate incident data from paper, Excel or legacy software](https://incidentkit.ai/product/import-and-migration)
- [Incident reporting API, webhooks and integrations](https://incidentkit.ai/product/integrations-and-api)
- [Incident reporting software pricing: free to start](https://incidentkit.ai/pricing)
- [IncidentKit security overview](https://incidentkit.ai/security)
- [HIPAA and BAA for incident reporting](https://incidentkit.ai/hipaa)
- [QAPI Committee Meetings: Agenda, Data and Minutes](https://incidentkit.ai/use-cases/qapi-committee-meetings)
- [Always Survey-Ready: Stay Prepared for Unannounced Surveys](https://incidentkit.ai/use-cases/always-survey-ready)
- [Nursing home QAPI requirements: 42 CFR 483.75 explained](https://incidentkit.ai/compliance/cms-qapi/skilled-nursing-facilities)
- [ASC QAPI requirements: 42 CFR 416.43 explained](https://incidentkit.ai/compliance/cms-qapi/ambulatory-surgery-centers)
- [Hospital QAPI requirements: 42 CFR 482.21 explained](https://incidentkit.ai/compliance/cms-qapi/hospitals)
- [OSHA recordkeeping requirements: 29 CFR 1904 explained](https://incidentkit.ai/compliance/osha/recordkeeping-overview)
- [OSHA electronic submission: 29 CFR 1904.41 and the ITA](https://incidentkit.ai/compliance/osha/electronic-submission)
- [F865 QAPI program and plan: what surveyors ask for](https://incidentkit.ai/compliance/f-tags/f865)
