# How to switch from legacy incident software

> Switch in five moves. Confirm export rights. Export everything, including attachments and audit history. Map old categories to a shorter list. Run both systems 30 to 60 days, then make the old one read-only. Keep records as long as rules require, such as 5 years for OSHA logs.

Source: https://incidentkit.ai/use-cases/switch-from-legacy-incident-software · Updated Oct 5, 2026

For: Risk or quality leader with an old incident system and a renewal date coming

## Can you switch without losing history?

Yes, if you secure the export before your notice date. OSHA wants the 300 log, annual summary and 301 reports kept 5 years after the year they cover (29 CFR 1904.33).

ASC surveyors ask for 6 months of surgeries and a year of transfers and deaths. QAPI expects adverse events tracked over time. As a rule of thumb, start at least 90 days before the contract ends.

## What to export

Export everything in this table, then check it.

| Data | Why it matters | Ask your vendor for |
| --- | --- | --- |
| Incident records, all fields | Core history | Full export |
| People, roles, locations | Right unit and site | User and location lists |
| Investigations and notes | Proof of analysis | Investigation fields |
| Corrective actions, evidence | Proof of fixes | Action records, files |
| Attachments: photos, statements, PDFs | Evidence | Bulk files by record ID |
| Audit and change history | Who changed what | Audit log export |
| Forms, categories, routing rules | Rebuild your setup | Configuration documents |
| State reports and OSHA logs | Retention duties | Copies of all filed |

Exports usually arrive as spreadsheets plus a folder of files. Check the record ID appears in both. If rules cannot be exported, photograph each screen.

### Check the export before you rely on it

- Compare yearly totals by incident type with the old reports.
- Open ten records with attachments and compare to the screen.
- Check dates and times for time zone shifts.
- Check names and notes for broken characters.
- Confirm the audit history shows who changed what.

## Check the contract before you give notice

Check these points before you give notice.

- Your right to export, the format, any fee.
- The notice period and any automatic renewal.
- Access after the contract ends.
- When the vendor deletes your data, and whether it certifies deletion.
- For healthcare, the business associate agreement and patient information at the end.
- Whether the vendor will run a test export first.

## An example plan for one site

One site can move in about 12 weeks.

*A suggestion, not a promise.*

| When | What happens |
| --- | --- |
| Weeks 1 to 2 | Confirm export rights. Request the export. List forms, rules, users, integrations. |
| Weeks 3 to 4 | Check a sample. Map old categories to incident types. |
| Weeks 5 to 6 | Set up forms, routing, roles. Import history. Train users. |
| Weeks 7 to 12 | Go live. Run both systems. Reconcile weekly. |
| After | Go read-only. Keep a verified archive. |

## Run both systems in parallel

Run both for 30 to 60 days. Reconcile weekly.

1. **Pick a go-live date** Use the first of a month or quarter.
2. **New events go in the new system only** From go-live, nobody files in the old one.
3. **Decide the rule for open cases** Finish them in the old system, or import and close them in the new. Pick one.
4. **Reconcile weekly** Compare counts by type for 30 to 60 days. Check every difference.
5. **Brief staff once** One page: which system, where QR codes point, who to ask.
6. **Retire the old system to read-only** After two clean weeks, make it read-only. Keep a verified archive.

## Import and done-for-you migration

Import brings history into IncidentKit, so trends span the cutover. Mapping starts from a pack, which sets incident types, forms, regulator exports and roles for a site type. See [import and migration](https://incidentkit.ai/product/import-and-migration).

Old categories become fewer incident types. These examples are invented.

| Old categories | Mapped to |
| --- | --- |
| Fall: witnessed, Fall: unwitnessed, Fall: no injury | One fall type with fields for witnessed, injury, location |
| Med error: wrong dose, Med error: omission, Med error: wrong time | One medication error type; error kind is a field |
| Misc, Other, Unknown | Reviewed, not carried forward |

Regulated plans include done-for-you setup. Network plans, for groups of 10 or more sites, include migration. IncidentKit runs alongside your EHR, CMMS and HRIS; deeper integrations are rolling out.

## Mistakes to avoid

These habits cause most migration problems.

- Retyping open cases. Import them or finish them in place.
- Carrying over 200 categories. Map to a short list first.
- Exporting without attachments or audit history.
- Switching off the old system before counts match.
- Letting the contract end date set the schedule.
- Forgetting QR codes and email addresses for intake.
- Skipping integrations such as HR feeds or work order links.

## Before and after

- **Before:** Nobody knows how to get the data out.
  **After:** You ask for a full export in writing, then check it.
- **Before:** Hundreds of categories mean miscoded reports and noisy trends.
  **After:** History imports into cleaner incident types, so trends carry across.
- **Before:** The renewal arrives before anyone checks export rights.
  **After:** Old and new systems run side by side until counts match.
- **Before:** Fear of losing history keeps you on an old tool.
  **After:** Regulated plans get done-for-you setup; Network plans get migration.

## Frequently asked questions

### How long does it take to switch incident reporting software?

Weeks, not days. Do export and mapping first, then a 30 to 60 day parallel run per site. Ask any vendor for a written plan and named owners.

### Do I need to import old incidents at all?

Not always. If you only need an archive, keep a verified read-only export as long as rules require. Import the period you trend and survey against, and archive the rest.

### Can we keep using our EHR, CMMS or HRIS?

Yes. IncidentKit runs alongside them and does not replace them. Deeper EHR, CMMS and HRIS integrations are rolling out; see [integrations and API](https://incidentkit.ai/product/integrations-and-api) for what is live.

### What does done-for-you migration include?

Regulated plans include done-for-you setup. Network plans, for 10 or more sites, include migration. Ask for the scope in writing.

## Sources

- [OSHA: 29 CFR 1904.33, retention and updating](https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.33)
- [CMS: State Operations Manual Appendix L, entrance conference requests for ASCs](https://www.cms.gov/Regulations-and-Guidance/Guidance/Manuals/downloads/som107ap_l_ambulatory.pdf)
- [CMS: State Operations Manual Appendix PP, F867 adverse event tracking (42 CFR 483.75(c)(4), (e)(2))](https://www.cms.gov/medicare/provider-enrollment-and-certification/guidanceforlawsandregulations/downloads/appendix-pp-state-operations-manual.pdf)
- [eCFR: 42 CFR 416.43, ASC QAPI](https://www.ecfr.gov/current/title-42/section-416.43)

## Related

- [Migrate incident data from paper, Excel or legacy software](https://incidentkit.ai/product/import-and-migration)
- [Incident reporting software alternatives](https://incidentkit.ai/alternatives)
- [Compare incident reporting software: the full matrix](https://incidentkit.ai/compare)
- [Incident management software buyer's guide: how to choose](https://incidentkit.ai/guides/incident-management-software-buyers-guide)
- [Multi-site incident reporting software for groups](https://incidentkit.ai/solutions/multi-site-groups)
- [Incident reporting software pricing: free to start](https://incidentkit.ai/pricing)
