216-RICR-40-10-6
216-RICR-40-10-6. Patient Safety Organizations (version Adoption, 01/27/2009 to 04/30/2018)
RULES AND REGULATIONS PERTAINING TO
CERTIFICATION OF PATIENT SAFETY ORGANIZATIONS
[R23-17.21-PSO]
STATE OF RHODE ISLAND AND PROVIDENCE PLANTATIONS
DEPARTMENT OF HEALTH
January 2009
i
INTRODUCTION
These Rules and Regulations Pertaining to Certification of Patient Safety Organizations
[R23-17.21-PSO] are promulgated pursuant to the authority conferred under §23-17.21 of the
General Laws of Rhode Island, as amended, for the purpose of adopting standards for
certification of patient safety organizations.
Pursuant to the provisions of §42-35-3(c) of the General Laws of Rhode Island, as amended,
the following were given consideration in arriving at these regulations:
(1) Alternative approaches to the regulations; and
(2) Duplication or overlap with other state regulations.
Based on the available information, no known alternative approach, duplication or overlap,
was identified.
ii
TABLE OF CONTENTS
Page
Section 1.0
Definitions
1
Section 2.0
General Provisions
2
2.1
Purpose and Scope
2
2.2
Ineligible Entities
2
Section 3.0
Privilege and Confidentiality Protections
2
3.1
Privilege
2
3.2
Confidentiality of Patient Safety Work Product and Document Log
3
3.3
Exceptions
3
3.4
Continued Protection of Information After Disclosure
4
3.5
Reporter Protection
4
Section 4.0
Reporting Entity Requirements
5
4.1
Effective Date
5
4.2
Document Log
5
4.3
Applicability of Other Reporting Requirements
5
4.4
Nonapplicability of Public Records Law
5
Section 5.0
Patient Safety Organization Requirements
5
5.1
Maintenance of Reports
5
5.2
Dissemination of Information
5
5.3
Safeguards and Security Measures
5
5.4
Required Notifications
7
Section 6.0
Application For Certification
8
6.1
General Requirements
8
6.2
Certification Application
8
6.3
Issuance and Renewal of Certification
10
Section 7.0
Complaints and Enforcement
11
7.1
Complaints and Routine Correspondence.
11
7.2
Penalties
11
Section 8.0
Rules Governing Practices and Procedures
11
Section 9.0
Severability
11
1
SECTION 1.0
DEFINITIONS
Whenever used in these rules and regulations, the following terms shall be construed as follows:
1.1 “Act” means Chapter 23-17.21 of the Rhode Island General Laws, as amended, entitled “The Rhode
Island Patient Safety Act of 2008.”
1.2 “Bona fide contract” means a written contract between a reporting entity and a PSO that is
executed in good faith by officials authorized to execute such contract.
1.3 “Component organization” means an entity that is either:
(a) A unit or division of a corporate organization or of a multi-organizational enterprise; or
(b) A separate organization, whether incorporated or not, that is owned, managed or controlled by
one or more other organization(s), i.e., its parent organization(s).
1.4 “Component PSO” means a patient safety organization certified by the Director that is a component
organization.
1.5 “Department” means the Rhode Island Department of Health.
1.6 “Director" means the Director of the Rhode Island Department of Health.
1.7 “Document log” means an inventory or record, required pursuant to RIGL §23-17.21-6(b), which
itemizes the types of documents submitted to the PSO without indicating the content of such
documents.
1.8 “Entity” means any organization or organizational unit, regardless of whether the organization is
public, private, for-profit or not-for-profit.
1.9 “Health care facility” means any corporation, limited liability company, facility, or institution
licensed by this state to provide health care or professional services, or an officer, employee or
agent thereof acting in the course and scope of his or her employment.
1.10 “Identifiable patient safety work product” means patient safety work product that:
(a) Is presented in a form and manner that allows the identification of any provider or reporting
entity that is a subject of the work product, or any providers or reporting entities that participate
in activities that are a subject of the work product;
(b) Constitutes individually identifiable health information as that term is defined in the Health
Insurance Portability and Accountability Act of 1996 and its implementing regulations (45 CFR
Parts 160-164); or
(c) Is presented in a form and manner that allows the identification of an individual.
1.11 “Near misses” means circumstances in which a patient safety event is narrowly averted.
1.12 “Nonidentifiable patient safety work product” means patient safety work product that is not
identifiable patient safety work product as defined in these regulations.
1.13 “Patient safety activities” means:
(a) Efforts to improve patient safety and the quality of health care delivery;
(b) The collection and analysis of patient safety work product;
(c) The development and dissemination of information with respect to improving patient safety,
such as recommendations, protocols, or information regarding best practices;
(d) The utilization of patient safety work product for the purposes of encouraging a culture of safety
2
and of providing feedback and assistance to effectively minimize patient risk;
(e) The maintenance of procedures to preserve confidentiality with respect to patient safety work
product; and
(f) The provision of appropriate security measures with respect to patient safety work product.
1.14 “Patient safety event” means those events as defined by the national quality forum, institute of
medicine, center for Medicare and Medicaid Services (CMS), and as further defined by the quality
of care advisory committee, as established herein, and shall include near misses.
1.15 “Patient safety organization (PSO)” means any entity certified by the Director whose activity is to
improve patient safety and the quality of health care delivery for patients receiving care through the
collection, aggregation, analysis, investigation, and/or processing of medical or health care related
information submitted to it by reporting entities. A PSO shall not mean any agency or public body
as defined in RIGL §38-2-2(i).
1.16 “Patient safety work product" means all reports, records, memoranda, analyses, statements, root
cause analyses, or written or oral statements, that:
(a) A health care facility or provider prepares for the purpose of disclosing a patient safety event, or
is disclosed, to a patient safety organization;
(b) Is received from a reporting entity, or is created or analyzed by a patient safety organization; or
(c) Directly or indirectly contains deliberations, analytical process, recommendations, conclusions,
or other communications of a patient safety organization or between a patient safety
organization and health care providers or facilities.
1.17 “Quality of Care Advisory Committee” means the committee established by the Director, pursuant
to RIGL §23-17.21-5(b), to advise the Department on PSO-related issues.
1.18 “Regulations” [“these Regulations”] means all sections of the Rules and Regulations Pertaining to
Certification of Patient Safety Organizations [R23-17.21-PSO]. Unless specifically cited otherwise,
all references contained herein shall be interpreted as pertaining to these Regulations.
1.19 “Reporting entity” means any hospital, nursing facility or freestanding ambulatory surgical center
licensed pursuant to RIGL §23-17.
1.20 “RIGL” means the General Laws of Rhode Island, as amended.
SECTION 2.0
GENERAL PROVISIONS
2.1 Purpose and Scope. These Regulations establish standards for certification of a patient safety
organization (PSO), and operational requirements for both a reporting entity and a patient safety
organization.
2.2 Ineligible Entities. Entities that may not seek certification as a PSO include: health insurance
issuers or components of health insurance issuers. Any other entity, public or private, that conducts
regulatory oversight of health care providers, such as accreditation or licensure, may not seek
certification, except that a component of such an entity may seek listing as a component PSO.
SECTION 3.0
PRIVILEGE AND CONFIDENTIALITY PROTECTIONS
3.1 Privilege. Notwithstanding any other provision of federal, state, or local law to the contrary, and
subject to §3.3, patient safety work product and a document log shall be privileged and shall not be:
3
(a) Subject to a federal, state, or local civil, criminal, or administrative subpoena or order, including
in a federal, state, or local civil or administrative disciplinary proceeding against a provider;
(b) Subject to discovery in connection with a federal, state, or local civil, criminal, or administrative
proceeding, including in a federal, state, or local civil or administrative disciplinary proceeding
against a provider;
(c) Subject to disclosure pursuant to 5 USC 5521, RIGL §38-22, or any other similar federal, state, or
local law;
(d) Admitted as evidence in any federal, state, or local governmental civil proceeding, criminal
proceeding, administrative rulemaking proceeding, or administrative adjudicatory proceeding,
including any such proceeding against a provider; or
(e) Admitted in a professional disciplinary proceeding of a professional disciplinary body
established or specifically authorized under state law.
3.2 Confidentiality of Patient Safety Work Product and Document Log. Notwithstanding any other
provision of federal, state or local law to the contrary, and subject to §3.3, the patient safety work
product and document log shall be confidential and shall not be disclosed.
3.3 Exceptions.
(a) Exceptions From Privilege and Confidentiality. §3.1 and §3.2 shall not apply to, and shall not
be construed to prohibit, one or more of the following disclosures:
(1) Disclosure of relevant patient safety work product and document log for use in a criminal
proceeding, but only after a court makes an in camera3 determination that such patient safety
work product and document log contains evidence of a criminal act and that such patient
safety work product and document log is material to the proceeding and not reasonably
available from any other source; or
(2) Disclosure of identifiable patient safety work product and document log if authorized by
each provider or reporting entity identified in such work product.
(b) Exceptions From Confidentiality. §3.2 shall not apply to, and shall not be construed to
prohibit one or more of the following voluntary disclosures:
(1) Disclosure of patient safety work product and document log to a reporting entity to carry out
patient safety activities;
(2) Disclosure of patient safety work product and document log to grantees, contractors, or other
entities carrying out research, evaluation, or demonstration projects authorized, funded,
certified, or otherwise sanctioned by rule or other means by the Director, for the purpose of
conducting research to the extent that disclosure of protected health information would be
allowed for such purpose under the Health Insurance Portability and Accountability Act of
1996, and its implementing regulations (45 C.F.R. Parts 160-164);
(3) Disclosure by a provider to the U.S. Food and Drug Administration with respect to a product
or activity regulated by the Food and Drug Administration;
(4) Voluntary disclosure of patient safety work product and document log by a provider to an
1 Section of the United States Code commonly known as the Freedom of Information Act.
2 Section of the Rhode Island General Laws commonly known as the Access to Public Records Law.
3 In camera refers to a hearing or discussion with a judge in the privacy of his/her chambers or when spectators
and jurors have been excluded from the courtroom.
4
accrediting body that accredits that provider; or
(5) Disclosure of patient safety work product and document log to law enforcement authorities
relating to the commission of a crime, or to an event reasonably believed to be a crime, if the
person making the disclosure believes, reasonably under the circumstances, that the patient
safety work product and document log that is disclosed is necessary for criminal law
enforcement purposes.
3.4 Continued Protection of Information After Disclosure.
(a) General Requirement. Patient safety work product and/or document log that is disclosed under
§3.3 shall continue to be privileged and confidential as provided for in §3.1 and §3.1, and such
disclosure shall not be treated as a waiver of privilege or confidentiality, and the privileged and
confidential nature of such work product and/or document log shall also apply to such work
product and/or document log in the possession or control of a person to whom such work product
and log was disclosed.
(b) Exception. Notwithstanding §3.4(a) and subject to §3.4(c), if patient safety work product and/or
document log is admitted into evidence in a criminal proceeding, the confidentiality protections
provided for in §3.2 shall no longer apply to the work product and/or log so disclosed; and
(c) Construction. §3.4(b) shall not be construed as terminating or limiting the privilege or
confidentiality protections provided for in §3.1 or §3.2 with respect to patient safety work
product and document log other than the specific patient safety work product and document log
disclosed as provided for in §3.3.
(d) Limitations On Actions.
(1) Patient Safety Organizations
(i) General Requirement. A patient safety organization shall not be compelled to disclose
information collected or developed under the Act or these Regulations whether or not
such information is patient safety work product and/or a document log unless such
information is identified, it is not patient safety work product and/or a document log,
and it is not reasonably available from another source.
(ii) Nonapplication. The limitation contained in §3.4(d)(1)(i) shall not apply in an action
against a patient safety organization or with respect to disclosures pursuant to §3.3(a).
(2) Providers. An accrediting body shall not take an accrediting action against a provider based
on the good faith participation of the provider in the collection, development, reporting, or
maintenance of patient safety work product and a document log in accordance with the Act
or these Regulations. An accrediting body may not require a provider or reporting entity to
reveal its communications with any patient safety organization established in accordance
with the Act or these Regulations.
3.5 Reporter Protection.
(a) General Requirement. A provider may not take any adverse employment action, as described
in §3.5(b), against an individual based upon the fact that the individual, in good faith, reported
the information:
(1) To the reporting entity with the intention of having the information reported to a patient
safety organization; or
(2) Directly to a patient safety organization.
(b) Adverse Employment Action. For the purposes of this Section, an adverse employment action
5
includes:
(1) Loss of employment, the failure to promote an individual, or the failure to provide any other
employment related benefit for which the individual would otherwise be eligible; or
(2) An adverse evaluation or decision made in relation to accreditation, certification,
credentialing, or licensing of the individual.
SECTION 4.0
REPORTING ENTITY REQUIREMENTS
4.1 Effective Date: On and after 1 January 2009, a reporting entity may enter into a written contract
with a patient safety organization, certified in accordance with these Regulations, to which it sends
patient safety work product.
4.2 Document Log. Each contract shall require the reporting entity to maintain a document log
itemizing the types of documents submitted to the PSO without indicating the content of such
documents. Such document log shall be accessible to the Department for the sole purpose of
allowing the Department to verify the type of information submitted to PSOs. The Department shall
not have access to patient safety work product. Such document log shall not be subject to a
disclosure to, or use by, any person or entity, other than the PSO and the reporting entity with which
it has contracted, and by the Department for the sole purpose provided in this Section.
4.3 Applicability of Other Reporting Requirements . A reporting entity shall not be exempt from the
requirements of RIGL §23-17-40 or RIGL §5-37-9.
4.4 Nonapplicability of Public Records Law. Patient safety work product (whether identifiable of
nonidentifiable) and any document log submitted to the Director under §4.2 shall not be a public
record for the purposes of RIGL §38-2. A reporting entity shall not be considered a public body or
agency for the purposes of RIGL §38-2.
SECTION 5.0
PATIENT SAFETY ORGANIZATION REQUIREMENTS
5.1 Maintenance of Reports. A PSO shall provide guidance to reporting entities on reporting matters,
and shall maintain all reports and associated documents as confidential and privileged, including any
reports or information with identifiable information.
5.2 Dissemination of Information. A PSO shall, as appropriate, disseminate to health care providers
and facilities, the Department, the Quality of Care Advisory Committee, and the public, information
or recommendations, including suggested policies, procedures or protocols, on best medical practices
or potential system changes designed to improve patient safety and the overall quality of care.
Notwithstanding the foregoing, the PSO shall not disclose identifiable patient safety work product to
the Department, the quality of care advisory committee, or the public.
5.3 Safeguards and Security Measures.
(a) (1) A PSO shall have in place appropriate physical, technical and procedural safeguards and
security measures to ensure the technical integrity, physical safety, and confidentiality of any
patient safety work product. These safeguards and security measures shall be in place at all
times and at any location at which the PSO, its workforce members, or its contractors hold
patient safety work product. Such safeguards and security measures shall comply with state
and federal confidentiality laws including, without limitation, the Health Insurance
Portability and Accountability Act of 1996 and its implementing regulations (45 CFR Parts
6
160-164) and RIGL §5-37.3 [Confidentiality of Health Care Communications and
Information Act].
(2) As provided for in RIGL §23-17.21-8, patient safety work product shall be confidential, and
shall not be subject to any discovery, access or use by any person or entity other than the
PSO and the reporting entity with which the PSO has contracted.
(3) Nothing in the Act or these Regulations shall be construed to prohibit a PSO from choosing
to disclose patient safety work product, or portions of patient safety work product, solely to a
reporting entity, in conformity with the PSO's mission and within its contractual obligations
to the reporting entity who submitted the information. No patient safety organization shall
release protected health information or patient identifying information without meeting the
requirements of state RIGL §5-37.3 [Confidentiality of Health Care Communications and
Information Act] and the federal Health Insurance Portability and Accountability Act of
1996, as amended from time to time, and its implementing regulations (45 CFR Parts 160-
164).
(b) Security Framework. PSOs shall consider the following framework for the security of patient
safety work product. The framework includes four elements: security management, separation
of systems, security monitoring and control, and system assessment. To address the four
elements of this framework, a PSO shall develop appropriate and scalable security standards,
policies, and procedures that are suitable for the size and complexity of its organization.
(1) Security Management. A PSO shall address:
(i) Maintenance and effective implementation of written policies and procedures that
conform to the requirements of this Section to protect the confidentiality, integrity, and
availability of the patient safety work product that is processed, stored, and transmitted;
and to monitor and improve the effectiveness of such policies and procedures, and
(ii) Training of the PSO workforce and PSO contractors who access or hold patient safety
work product regarding the requirements of the Act, these Regulations and the PSO's
policies and procedures regarding the confidentiality and security of patient safety work
product.
(2) Separation of Systems. A PSO shall address:
(i) Maintenance of patient safety work product, whether in electronic or other media,
physically and functionally separate from any other system of records;
(ii) Protection of the media, whether in electronic, paper, or other format, that contain
patient safety work product, limiting access to authorized users and sanitizing and
destroying such media before disposal or release for reuse; and
(iii) Physical and environmental protection, to control and limit physical and virtual access
to places and equipment where patient safety work product is stored or used.
(3) Security Control and Monitoring. A PSO shall address:
(i) Identification of those authorized to have access to patient safety work product and an
audit capacity to detect unlawful, unauthorized or inappropriate access to patient safety
work product, and
(ii) Measures to prevent unauthorized removal, transmission or disclosure of patient safety
work product.
(4) Security Assessment. A PSO shall address:
(i) Periodic assessments of security risks and controls, as determined appropriate by the
7
PSO, to establish if its controls are effective, to correct any deficiency identified, and to
reduce or eliminate any vulnerabilities.
(ii) System and communications protection, to monitor, control, and protect PSO uses,
communications, and transmissions involving patient safety work product to and from
reporting entities and any other responsible persons.
5.4 Required Notifications. A PSO shall meet the following notification requirements:
(a) Notification Regarding PSO Compliance With Minimum Contract Requirement. No later
than forth five (45) calendar days prior to expiration of the PSO’s certification, as specified in
§6.3(a), the PSO shall submit to the Director an attestation as to whether it has met the
requirement of §6.2(b)(1)(iii) regarding two (2) bona fide contracts.
(b) Notification Regarding a PSO's Relationships With Its Contracting Reporting entities. A
PSO shall submit a disclosure statement to the Director regarding its relationships with each
reporting entity with which the PSO has a contract pursuant to the Act and these Regulations if
the circumstances described in either §5.4(b)(1) or §5.4(b)(2) are applicable. The Director shall
receive a disclosure statement within forty five (45) days of the date on which a PSO enters a
contract with a reporting entity if the circumstances are met on the date the contract is entered.
During the contract period, if a PSO subsequently enters one or more relationships with a
contracting reporting entity that create the circumstances described in §5.4(b)(1) or a reporting
entity exerts any control over the PSO of the type described in §5.4(b)(2), the Director shall
receive a disclosure statement from the PSO within forty five (45) days of the date that the PSO
entered each new relationship or of the date on which the reporting entity imposed control of the
type described in §5.4(b)(2).
(1) Taking into account all relationships that the PSO has with the reporting entity, other than
the bona fide contract entered into pursuant to the Act and these Regulations, the PSO shall
fully disclose any other contractual, financial, or reporting relationships described below that
it has with that reporting entity.
(i)
Contractual relationships which are not limited to relationships based on formal
contracts but also encompass relationships based on any oral or written agreement or
any arrangement that imposes responsibilities on the PSO.
(ii)
Financial relationships including any direct or indirect ownership or investment
relationship between the PSO and the contracting reporting entity, shared or common
financial interests or direct or indirect compensation arrangement, whether in cash or
in-kind.
(iii) Reporting relationships including any relationship that gives the reporting entity access
to information or control, directly or indirectly, over the work of the PSO that is not
available to other contracting reporting entities.
(2) Taking into account all relationships that the PSO has with the reporting entity, the PSO
shall fully disclose if it is not independently managed or controlled, or if it does not operate
independently from, the contracting reporting entity. In particular, the PSO shall further
disclose whether the contracting reporting entity has exercised or imposed any type of
management control that could limit the PSO's ability to fairly and accurately perform
patient safety activities and fully describe such control(s).
(3) PSOs may also describe or include in their disclosure statements, as applicable, any
agreements, stipulations, or procedural safeguards that have been created to protect the
ability of the PSO to operate independently or information that indicates the limited impact
or insignificance of its financial, reporting, or contractual relationships with a contracting
8
reporting entity.
SECTION 6.0
APPLICATION FOR CERTIFICATION
6.1 General Requirements:
(a) Certification Required. A patient safety organization (PSO) shall be certified by the Director
pursuant to these Regulations before entering into a contract with a reporting entity.
(b) Submission of Application. Any entity, except as specified in §2.2, may request an initial or
renewal certification as a PSO by submitting a completed application form to the Director on
forms provided by the Department. An individual with authority to make commitments on
behalf of the entity seeking certification will be required to acknowledge each of the certification
requirements, attest that the entity meets each requirement, provide contact information for the
entity, and certify that the PSO will promptly notify the Department during its period of
certification if it can no longer comply with any of the criteria in these Regulations.
(c) Notification of Changes. Any PSO certified pursuant to this Section shall notify the
Department in writing before making any change which would render the information4 contained
in their application for certification no longer accurate.
(d) Federal Certification Required. Any entity requesting certification as a PSO pursuant to these
Regulations shall also obtain and maintain certification/listing as a PSO pursuant to the Patient
Safety and Quality Improvement Act of 2005 (Pub. L. 109-41) and any implementing regulations
promulgated by the U.S. Agency for Healthcare Quality and Research5.
(1) Any PSO certified pursuant to these Regulations prior to the establishment of a federal PSO
certification/listing program shall be required to obtain such certification when it becomes
available. The PSO shall provide copies of all federal PSO certification/listing documents to
the Director pursuant to §6.1(c).
(2) Any entity requesting certification as a PSO pursuant to these Regulations after the
establishment of a federal PSO certification/listing program shall be required to provide
copies of all federal PSO certification/listing documents with their application.
(3) Renewal. A PSO seeking renewal of certification after the establishment of a federal PSO
certification/listing program shall include documentation that the PSO maintains current
certification/listing pursuant to that federal PSO program.
6.2 Certification Application. An application for certification as a PSO shall include, as a minimum,
the following information for review by the Department:
(a) Certification Regarding Patient Safety Activities.
(1) An entity seeking initial certification as a PSO shall attest that it has written policies and
procedures in place to perform each of the following eight (8) patient safety activities:
(i)
Efforts to improve patient safety and the quality of health care delivery;
(ii)
Collection and analysis of patient safety work product;
4 For example, changes involving name of entity, key staff, organizational structure, mailing address or phone
number.
5 Pub. L. 109-41 amended Title IX of the Public Health Service Act (42 U.S.C. 299 et seq.) by adding sections
921 through 926, 42 U.S.C. 299b-21 through 299b-26. Implementing regulations are proposed for
promulgation as 42 CFR Part 3.
9
(iii) Development and dissemination of information with respect to improving patient
safety, such as recommendations, protocols, or information regarding best practices;
(iv) Utilization of patient safety work product for the purposes of encouraging a culture of
safety and of providing feedback and assistance to effectively minimize patient risk;
(v)
Maintenance of procedures to preserve confidentiality with respect to patient safety
work product;
(vi) Provision of appropriate security measures with respect to patient safety work product;
(vii) Utilization of qualified staff; and
(viii) Activities related to the operation of a patient safety evaluation system and to the
provision of feedback to participants in a patient safety evaluation system.
(2) The policies and procedures referenced in §6.2(a)(1) shall provide for compliance with the
privilege and confidentiality provisions of §3.0 and the appropriate safeguards and security
measures required by §5.3.
(3) Renewal. A PSO seeking renewal of certification shall attest that it is performing, and will
continue to perform, each of the eight (8) patient safety activities referenced in §6.2(a)(1),
and is and will continue to comply with the privilege and confidentiality provisions of §3.0
and the appropriate safeguards and security measures required by §5.3.
(b) Certification Regarding PSO Criteria.
(1) An entity seeking initial certification as a PSO shall attest that it will comply with each of
the following seven (7) criteria:
(i)
The mission and primary activity of a PSO shall be to conduct activities that are to
improve patient safety and the quality of health care delivery.
(ii)
The PSO shall have appropriately qualified workforce members, including licensed or
certified medical professionals.
(iii) The PSO, within the initial two (2) year certification period, and within each sequential
two (2) year certification renewal period, shall have entered into at least two (2) bona
fide contracts, each of a reasonable period of time, each with a different reporting
entity for the purpose of receiving and reviewing patient safety work product.
(iv) The PSO is not a health insurance issuer, and is not a component of a health insurance
issuer.
(v)
The PSO shall make disclosures to the Director as required under §5.4.
(vi) To the extent practical and appropriate, the PSO shall collect patient safety work
product from reporting entities in a standardized manner that permits valid
comparisons of similar cases among similar reporting entities.
(vii) The PSO shall utilize patient safety work product for the purpose of providing direct
feedback and assistance to reporting entities to effectively minimize patient risk.
(2) Renewal. A PSO seeking renewal of certification shall also attest that it is complying with,
and will continue to comply with, each of the seven (7) PSO criteria referenced in
§6.2(b)(1).
(c) Additional Certifications Required of Component Organizations. An entity seeking initial
certification as a PSO, that is a component of another organization or enterprise, shall also attest
that it will comply with the following requirements:
10
(1) Separation of Patient Safety Work Product.
(i)
A component PSO shall:
(a) Maintain patient safety work product separately from the rest of the parent
organization(s) of which it is a part; and
(b) Not have a shared information system that could permit access to its patient safety
work product to an individual(s) in, or unit(s) of, the rest of the parent
organization(s) of which it is a part.
(ii)
Notwithstanding the requirements of paragraph §6.2(c)(1)(i), a component PSO may
provide access to identifiable patient safety work product to an individual(s) in, or a
unit(s) of, the rest of the parent organization(s) of which it is a part if the component
PSO enters into a written agreement with such individuals or units that requires that:
(a) The component PSO will only provide access to identifiable patient safety work
product to enable such individuals or units to assist the component PSO in its
conduct of patient safety activities, and
(b) Such individuals or units that receive access to identifiable patient safety work
product pursuant to such written agreement will only use or disclose such
information as specified by the component PSO to assist the component PSO in its
conduct of patient safety activities, will take appropriate security measures to
prevent unauthorized disclosures and will comply with the other certifications the
component has made pursuant to §6.2(c)(2) and §6.2(c)(3) regarding unauthorized
disclosures and conflicts with the mission of the component PSO.
(2) Nondisclosure of Patient Safety Work Product. A component PSO shall require that
members of its workforce and any other contractor staff, or individuals in, or units of, its
parent organization(s) that receive access in accordance with §6.2(c)(1)(ii) to its identifiable
patient safety work product, not be engaged in work for the parent organization(s) of which
it is a part, if the work could be informed or influenced by such individuals' knowledge of
identifiable patient safety work product, except for individuals whose other work for the rest
of the parent organization(s) is solely the provision of clinical care.
(3) Conflict of Interest. The pursuit of the mission of a component PSO shall not create a
conflict of interest with the rest of the parent organization(s) of which it is a part.
(4) Renewal. A component PSO seeking renewal of certification shall also certify that it is
complying with, and will continue to comply with, each of the additional requirements
referenced in §6.2(c)(1)-(c)(3).
6.3 Issuance and Renewal of Certification.
(a) Issuance of Certification. Pursuant to the provisions of §23-17.21-5(a) of the Act, the Director
shall grant certification to a PSO which meets the certification requirements set forth in these
Regulations. The certification shall expire on the last day of the month two (2) years from the
date of issue, unless sooner suspended or revoked.
(b) Renewal of Certification. A PSO may renew a certification every two (2) years upon
submission of an application in accordance with the provisions of §6.2(a)(3), §6.2(b)(3) and
§6.2(c)(4) [if applicable]. In any case in which the responsible individual of a PSO has filed a
renewal application in proper form, including compliance with the notification requirements of
§5.4(a), not less than forty five (45) calendar days prior to expiration of its existing certification,
the existing certification shall not expire until final action on the renewal application has been
taken by the Department.
11
SECTION 7.0
COMPLAINTS AND ENFORCEMENT
7.1 Complaints and Routine Correspondence.
(a) Complaints. Any person who desires to register a complaint citing a violation of the Act or
these Regulations shall submit a written and signed letter of complaint to the Director. All
complaints shall be directed to:
Rhode Island Department of Health
3 Capitol Hill
Providence, RI 02908-5097
Phone: (401) 222-5960
(b) Routine Correspondence. Routine correspondence, including all required notifications and
reports, shall also be directed to the address specified above.
7.2 Penalties.
(a) Civil Monetary Penalty. Subject to §3.4(c), a person who discloses identifiable patient safety
work product and/or document log in a knowing or reckless violation of §3.2 shall be subject to a
civil monetary penalty of not more than ten thousand dollars ($10,000) for each act constituting
such violation.
(b) Relation to Health Insurance Portability and Accountability Act of 1996. Penalties shall not
be imposed both under these Regulations and under the regulations issued pursuant to §264(c)(1)
of the Health Insurance Portability and Accountability Act of 1996 (42 U.S.C. 1320d-2 note) for
a single act or omission.
SECTION 8.0
RULES GOVERNING PRACTICES AND PROCEDURES
8.1 Upon due notice in accordance with RIGL §42-35, all hearings and reviews required under the
provisions of the Act and these Regulations shall be held in accordance with requirements of the
Rules and Regulations of the Rhode Island Department of Health Regarding Practices and
Procedures Before the Department of Health and Access to Public Records of the Department of
Health [R42-35-PP].
SECTION 9.0
SEVERABILITY
9.1 If any section, subsection, sentence, clause, phrase or portion of the Act or these Regulations is for
any reason held invalid or unconstitutional by any court of competent jurisdiction, that portion shall
be deemed a separate, distinct and independent provision and this holding shall not affect the validity
of the remaining portions of the Act or these Regulations.
9.2 Nothing contained in the Act or these Regulations shall be construed to affect any other provisions of
Title 23 of the Rhode Island General Laws, as amended.