What If Every Hospital Learned From Every Other Hospital’s Safety Incidents?
On Thursday, I wrote about the death of Donald Gough at the University Hospital of Wales in Cardiff. He received insulin during liver surgery even though he was not diabetic and had no clinical reason to be given it. That post was about one hospital. This one is about learning from patient safety incidents everywhere else.
The hospital made changes after the inquest. Insulin is no longer kept in the fridges in the anesthetists' room. Handovers from anesthesia to recovery now have to be logged. Those seem like reasonable responses to what they learned.
What I could not get past was what happens outside that hospital.
Does somebody at another hospital ask, “Could this happen here? Where is our insulin stored? How solid are our handovers?” Or does each organization have to learn the same lesson on its own, one patient at a time?
I compared it to what I would expect from a large manufacturer. If a worker died from a hazard at one of 50 plants, a serious company would not wait for plant number two to have the same fatality. Every comparable operation would get some version of a stop-and-check within days.
Then Michael Leigh left a comment on my LinkedIn post that pushed the question further. He described his time in the U.S. Navy nuclear program:
“If there was any ‘incident' (any violation of a standard procedure), the vessel was REQUIRED to determine the root cause and then send out a message to the entire nuclear powered fleet to share what happened.”
He said even small infractions got reviewed on every vessel. Then he asked:
“Imagine if every healthcare system was required to self report every incident they had to every similar hospital in the country, and each hospital reviewed and trained on that incident!”
What got my attention wasn't the reporting. Healthcare has plenty of incident reporting. It was the idea that an incident in one organization creates an obligation to learn in all the others.
So I went looking. Does any country's healthcare system actually work that way?
I am not an expert on national patient safety reporting systems, and this isn't me announcing that I have designed the right one. Michael's comment sent me digging to see what already exists.
The short answer, as far as I can tell, is not quite. Denmark and England each do a real piece of it. And what they have learned from running these systems changed my version of the idea.
Denmark Made Reporting Safe
Denmark is a good place to start because they've been doing this for a long time. Denmark was the first country to pass a patient safety law requiring healthcare professionals to report unintended events without fear of sanction, for the purpose of learning. Patients and family members can report too.
The reporting scheme is described as confidential and non-punitive, focused on learning and improvement. That part matters. If we want people to report mistakes, near misses, and unsafe conditions, we cannot build a system that makes reporting personally or professionally dangerous.
In my upcoming book, The Silence Tax: How Lean Leaders Drive Out Fear and Futility, I draw a line between whether speaking up feels safe and whether it feels worthwhile (hat tip to Stephen Shedletzky). Safe is a prediction about consequences. This is the psychological safety question. What do I think will happen to me if I say this? Will I be blamed, embarrassed, or labeled a troublemaker? Will my report be used to find somebody to punish? A sanction-free national reporting scheme speaks directly to that prediction.
Denmark also collects far more than catastrophic harm. In 2024, Danish healthcare organizations reported 489,361 unintended events. About 127,850 were reported individually and 361,511 came in through a simplified aggregate reporting method used for common event types. That is a large pool of potential learning.
I'll come back to worthwhile, after a brief statistical detour on the reporting.
What That Would Look Like in the U.S.
Denmark has about 6 million people. England has about 58 million. Adjusting for population, Denmark logs around 82 reports per 1,000 residents each year and England logs around 43. Scale that range to the roughly 340 million people in the United States and you get somewhere between 15 and 28 million reports a year.
The gap between those two countries is itself instructive. The difference is less about scope than about where the reports actually come from. NHS England says roughly three-quarters of recording to England's previous national systems came from hospitals, with primary care a known low-participation group. Denmark is nearly inverted. Municipal care, meaning home care, nursing homes, rehabilitation, and social residential facilities, accounts for about 85% of everything reported there. Hospitals contribute about 10%.
We're not as far off as those numbers suggest. Pennsylvania requires hospitals, surgical centers, and birthing centers to report both serious events and incidents, which includes events that harmed nobody. In 2024, the state logged 315,418 reports, and about 96% of them were incidents rather than serious events. At Pennsylvania's per-capita rate, a national system would collect around 8 million reports a year. Where reporting is required and non-punitive, Americans report.
It also helps to look at what people actually report. Danish hospitals individually reported 47,573 events in 2024, sorted into 20 categories.
Medication is the largest by a wide margin at 12,133, roughly a quarter of everything. That covers ordering the wrong drug or the wrong dose, giving the wrong preparation or strength, and giving medication at the wrong time.
Second is handover of information, responsibility, and documentation at 8,550. That category is about what gets passed from one clinician, team, or unit to the next at shift change or transfer. Add those two together and you have 43% of all hospital reports.
I'd rather not lean too hard on that, but it's difficult to ignore given how Donald Gough died. An unexplained dose of insulin, and a handover from anesthesia to recovery that the hospital afterward decided had to be logged.
Then treatment and care at 7,514. Samples, tests, and results at 5,354, which covers a test not ordered, a specimen mislabeled, a result that nobody acted on. Referrals, admission, and discharge at 3,968. Five categories, 79% of everything.
The long tail is small in volume and not small in consequence.
- Patient identification, meaning one person mistaken for another, 1,430.
- Medical devices and equipment, 1,274.
- Surgery and anesthesia including ECT, 945.
- Blood and blood products, 216.
- Medical gases and air, 190.
Small numbers, and the kinds of failures that tend to be catastrophic when they land.

The severity mix in Denmark is worth looking at too. Of the 127,850 individually reported events, about 64% had no or unknown consequence for the patient. Around 31% were mild or moderate. About 4% were serious, and roughly half a percent had a fatal outcome. Three-quarters of the total were classified as low overall patient safety risk.
That is what a healthy reporting system looks like from the outside. Almost nothing in it is a catastrophe.
The number I'd point to is a different one. In 2024, Denmark logged 6,010 events where the consequence was judged as possibly fatal. Nothing happened to the patient. Something very nearly did. That's about nine such reports for every one where the outcome actually was fatal. Scaled to our population, a U.S. system operating at that rate would surface something like 340,000 of those a year.
Paul O'Neill built Alcoa's safety work on the idea that you learn at the bottom of the pyramid, not the top. The version in that literature runs something like one fatality for every 30,000 unsafe conditions. The exact ratios were always shaky and have been challenged for decades. The direction holds. Denmark's system, one of the most protective in the world, captures roughly 740 non-fatal reports for every fatal one, which is a far narrower base than the pyramid predicts.

That gap is either good news about healthcare or a measure of what we never hear about. The HHS Office of Inspector General (OIG) found that U.S. hospitals failed to capture half of the events that actually harmed someone. The events that harmed nobody are the easiest of all to leave unmentioned.
Which raises the obvious objection:
If a country our size generated 20 million reports a year, who could possibly read them?
Nobody does, and no serious system pretends otherwise. Denmark's answer is to make most reports cheap to handle. Three-quarters of its reports come in through aggregate reporting, where staff make a tick mark on a paper form at the unit, and somebody submits a monthly count. No narrative, no case file, no analyst. Those categories were chosen because they're frequent and low-consequence. The events that get written up individually are handled locally, in the hospital or municipality where they happened, on a 90-day clock. Only what survives that filter becomes national material.
Safe Is Not the Same as Worthwhile
A reporting system can be completely non-punitive and still fail.
People can decide that nothing bad will happen to them if they report. And then decide that nothing useful will happen either. That is futility, and it is the other half of what I am writing about here and in the book.
A 2016 study of the Danish system is useful here. Researchers looked at how feedback and learning processes were working at four Danish hospital units and found gaps. External reporters were rarely contacted for a conversation. Front-line staff were sparsely involved in the learning process. Few units evaluated whether the interventions they made were effective. And personal factors were frequently identified as the primary contributing factor to incidents, which tells you something about how the analysis was being done.
The paper opens with a plain observation:
“The perceived usefulness of incident reporting systems is an important motivational factor for reporting.”
That is the worthwhile side, stated in academic form. If I spend ten minutes documenting an unsafe condition, what do I predict happens next? Does anybody investigate it, talk with me about it, change anything, or tell me what came of it?
The same paper cites an earlier Danish estimate that only about 4% of incidents that occurred were actually reported to the database. Denmark built one of the most protective reporting environments in the world and still ran into that. Fear may explain some of that gap. Futility could explain some of it too: people concluding that reporting isn't worth the effort.
We need more than psychological safety. We need effective problem-solving, which means not blaming individuals for systemic problems.
Reporting Is Inventory, Not Improvement
An incident report sitting in a database is a bit like a problem written on a sticky note and put on a board. Something has been made visible.
But visibility isn't improvement. Somebody still has to understand the problem, decide what to do, make the change, and check whether it worked.
The World Health Organization makes a version of this point in its 2020 technical report on patient safety incident reporting and learning systems. The foreword says that using incident reporting for true learning, in order to achieve sustainable risk reduction, is still a work in progress. It can be done and has been done, but “not yet on the scale and with the speed that compares with some other high-risk industries.”
Which brings me back to Michael's example. The reporting is the easy part to build. The hard part is making the learning move.
England Looks for the Signal and Then Requires Action
England's NHS gets closer to that. Its Learn from Patient Safety Events service is the national system for recording and analyzing safety events, and NHS England says it supports learning from more than 2.5 million patient safety events recorded each year.
Nobody can send 2.5 million reports to every hospital and ask everyone to study them. That was the first thing that changed my thinking about Michael's proposal. A nuclear fleet and a national health service differ enormously in scale and variety. Send everything to everybody and you have built a new problem.
So England runs a national clinical review process instead. NHS England's National Patient Safety Team reviews around 32,000 records of patient safety events each year, drawn from events involving death or severe harm and other sources, looking for new or under-recognized risks.
One line in their published guidance is my favorite thing I found in all of this. When they evaluate a risk, they explore whether organizations can do…
“something more constructive than simply raising awareness and warning people to be vigilant against error.”
Yes. That sentence could go on the wall of every patient safety department in the world.
Because “be more careful” is not much of a countermeasure. Neither is automatically retraining everyone involved. If two medication packages look nearly identical, change the packaging. If two connectors can be attached the wrong way, change the connectors. If the software makes a dangerous choice easy, change the software. Training might be part of the response, but if the conditions that produced the error stay the same, we have mostly asked the next person to perform better inside the same trap.
England also has National Patient Safety Alerts, which go beyond circulating an interesting case. An alert can instruct organizations to take specified actions, coordinated by an executive lead, with completion tracked. NHS England states that failure to take the required actions may lead to regulatory action by the Care Quality Commission, England's health and social care regulator.
The alerts get specific. A January 2024 alert instructed all relevant NHS-funded providers to transition to NRFit connectors for intrathecal and epidural procedures, with the transition to be completed by January 31, 2025. A September 2024 alert instructed maternity providers to stop pre-preparing oxytocin infusions at ward level, because pre-prepared infusions were being mis-selected when maintenance fluids were intended.
That is a different and more specific thing than “here is something terrible that happened somewhere, please share with your staff.”
If It's Working, Should the Number Go Down?
Here's where I'd expect a leader to push back. If the learning travels and the countermeasures work, shouldn't there be fewer events, and shouldn't the reports drop?
England has two decades of data on this. Reporting to their previous national system rose almost every year, from roughly 100,000 a month in the mid-2010s to more than 2.2 million in the year ending March 2020. It fell once, by about 6%, in the first COVID year, when elective care stopped. Nobody read that as the NHS getting safer.
NHS England's published commentary says why. The system isn't designed to count how many incidents actually occur. Rising numbers indicate an improving reporting culture, and, in their words,
“a decrease cannot be interpreted as an increase in the safety of the NHS.”
That's the national body that owns the data telling you the number can't be read in either direction.
The reason is that two things move it at once. Prevention should reduce how many events happen. Trust and visible follow-through should increase the share of events that get reported. The count is both of those multiplied together, and the denominator, the number of events that actually occurred, is never known.
So a falling report count is the most dangerous chart in the building. An organization that fixed real problems and an organization that quietly taught people not to bother both produce the same line going down. Whoever presents it picks the story, and people generally pick the flattering one.
Watch how easy it is to fool yourself even with clean data. Denmark added three new aggregate reporting categories in March 2024 and retired another in August. Its total climbed from about 300,000 in 2020 to nearly 490,000 in 2024, while the number of individually written-up events fell. Headline up 63%, narratives down. Two opposite stories in one number.
If I were running this, I wouldn't track the count as a safety measure at all. I'd track the share of reports describing events that harmed nobody, because people only file those when they believe it's worth doing. I'd track what fraction of reporters heard back. I'd track how long it takes from report to a change that got verified.
And I'd measure actual harm some other way entirely, through record review, because that's the only path to the number nobody has.
Can AI Read What People Can't?
This is the part where somebody says AI, and I want to be careful, because “AI will read it all” is the kind of claim that sounds like a plan but isn't.
But the volume problem is a genuinely good fit. Reading millions of free-text narratives, grouping the ones that describe the same failure in different words, and flagging the rare thing that looks like nothing on its own but shows up in eleven organizations over five months is exactly the work humans do badly at scale and machines do reasonably well.
NHS England says as much. It describes LFPSE as built to enable better use of technology like machine learning, and it redesigned the taxonomy to capture more detail about how things went wrong rather than sorting events into fixed lists.
What I find more interesting is where the technology got used first. According to NHS England's own FAQs, one of the first production uses of machine learning in LFPSE is anonymization. A model redacts identifiable details from the free text fields, backed up by rules and then by a team of data officers whose corrections keep training it.
That's not the exciting application. It's the one that makes everything else possible. A national learning system can't circulate narratives that identify a patient or the nurse who filed the report. Redaction at that volume by hand is not realistic. So the first thing the technology bought wasn't insight. It was the ability to share anything at all.
Researchers have gone further with the older NRLS data, using millions of de-identified reports to build classification and clustering approaches. That work is promising and it is still mostly research.
Here's what I keep bumping into, though. A model can only read what somebody wrote down. No amount of processing recovers the report that was never filed because a nurse decided it wasn't worth ten minutes, or because the last person who spoke up got asked what they were thinking.
It also matters what's in the pile. Three-quarters of Denmark's reports are tick marks on a paper form with no narrative attached. There's nothing there for a model to read. Cheap to collect, and cheap in what it can teach you.
And classification isn't judgment.
Grouping a thousand similar reports tells you a pattern exists. Deciding that every hospital in the country now has to change a connector, buy different equipment, or stop a practice that clinicians find convenient is a decision with consequences, and somebody has to own it.
Otherwise, “the algorithm found the pattern” becomes the new “alert sent.”
What We Already Have in the United States
The United States is not starting from zero. AHRQ operates the Network of Patient Safety Databases, which aggregates non-identifiable patient safety data contributed through Patient Safety Organizations, along with Common Formats meant to make reports comparable and dashboards built from the data.
But participation is voluntary, and AHRQ says so directly. Its dashboards carry the disclaimer that the NPSD does not contain a representative sample of patient safety concerns and cannot be used to calculate actual incidence or prevalence.
Then there is the July 2025 OIG report that I wrote about earlier this year. OIG traced harm events it had independently identified among hospitalized Medicare patients and checked whether hospitals had captured those events in their own incident reporting or surveillance systems. Hospitals didn't capture 49% of them. Of the events hospitals did capture, few were investigated, and fewer still led to patient safety improvements. The most common reason staff gave for not capturing an event was that they did not consider it to be harm.
The event happened. The patient was harmed. Half the time, it never entered the hospital's own learning system. For the half that did, investigation wasn't automatic, and improvement was rarer still. Building a better national database does not fix any of that on its own.
What Learning From Patient Safety Incidents Might Look Like Nationally
Michael's Navy example has an appealing simplicity. Something happens, the organization determines the cause, the learning goes out to the fleet, and other units act before it happens to them. Healthcare is much larger and more varied, so copying that literally probably would not work. The underlying principle still seems right to me.
Here is the version I would want after reading about Denmark, England, and what we have here.
Reporting has to be easy and psychologically safe, and it has to include near misses and unsafe conditions. If reporting puts a career or a reputation at risk, we will lose information systematically. That means keeping the learning process separate from the much narrower question of whether somebody acted recklessly or intended harm.
There has to be a shared national taxonomy. Reports from Hospital A need to be comparable to reports from Hospital B or we cannot see patterns. That is essentially OIG's open recommendation to CMS right now.
Reports need de-identification and strong protection for reporters. A system that is understood to be a way of locating someone to blame will be starved of the information it needs.
Analysis has to combine automated clustering with expert review. The work is detecting recurring patterns, rare catastrophic hazards, and genuinely new failure modes.
Dissemination should be targeted rather than universal. An anesthesia hazard goes to anesthesia teams. An infusion pump hazard goes to every organization using that pump. A dangerous default configuration goes to every customer running it.
Where warranted, countermeasures should be required rather than suggested, and they should favor changes to equipment, technology, standard work, or design over another round of retraining.
Somebody has to verify that the countermeasure was implemented and that it worked. “Alert sent” is not an outcome. Neither is “training completed.”
And the original reporter should hear back. Tell people what was learned, what changed, or why nothing changed. A lack of action can breed futility. So can action that's not communicated back to the source.
That last one looks like a courtesy. I think it is closer to a design requirement.
Two Predictions, Two Failure Modes
When I consider reporting an unsafe condition, I am making two predictions. One is about risk to me. The other is about whether it will matter. Again, safe and worthwhile.
Leaders damage the first prediction by blaming, getting defensive, or immediately hunting for who messed up. They damage the second by accepting reports and doing nothing with them. The first produces fear. The second produces futility. Either one, or both together, will produce silence.
A national reporting system has the same two failure modes at a much larger scale. We can build confidentiality protections, non-punitive policies, and anonymous channels, and those things matter. But if people file hundreds of thousands of reports and rarely see anything change, the system is teaching a lesson too. It is teaching people not to bother.
That is one version of the silence tax. An organization pays it when useful information sits in people's heads and never reaches anyone who can act on it. In healthcare, that information is sometimes that two packages are easy to confuse, or that insulin is stored somewhere it shouldn't be, or that a handoff has a hole in it. Sometimes somebody has already seen the exact failure that will injure the next patient.
I still have not found a country that does what Michael described from the nuclear Navy. Denmark has built an unusually broad, legally protected, sanction-free reporting foundation. England has built a strong process for finding selected national risks and turning some of them into required action. The United States has many of the parts and no reliable way to move learning from every relevant event to every organization that needs it.
In the earlier post, I asked what every other hospital learns after one patient is harmed. I would add a second question now. What makes the learning travel?
The patient at Hospital 37 should not have to teach us something Hospitals 1 through 36 already knew.


