

Provide Community Incident Reporting and Management Policy
Incorporating the NHS Patient Safety Incident Response Framework Incorporating IG/IT provisions of ISO27001:2022 standard
Version: V2
Ratified by:
Date ratified:
Job Title of author:
Policy shared with for review and comment

Group Quality & Safety Committee
31/03/2026
Director Nursing & Allied Health Professions
Provide Chief Officers via SLT meeting
Quality and Safety Team
Head of Health, Safety and Compliance
Head of Information Governance & Group Data Protection Officer
Managing Director Provide Care Solutions Ltd
Director Operations Provide Care Solutions Ltd
Operations Director Provide Wellbeing Ltd
Reviewed by Committee or Expert Group Group Quality & Safety Committee
Equality Impact Assessed by:
Related procedural documents
Review date:


Director Nursing & Allied Health Professions
HRPOL01 Freedom to Speak Up (Whistleblowing) Policy
QSPOL03 Duty of Candour Policy
QSPOL09 Risk Management Policy
QSGUI01 Guidance on Writing a Witness Statement
IGPOL62 Information Governance Policy
31/03/2029
It is the responsibility of users to ensure that you are using the most up to date document template – i.e. obtained via the intranet
In developing/reviewing this policy Provide Community has had regard to the principles of the NHS Constitution.
Version Control Sheet
Version Date
V1 September 2024

Author Status Comment
Director Nursing & Allied Health Professions Ratified This policy replaces the Provide Group All Incident reporting (including Serious Incident Reporting) & Management Policy V9 and QSPOL15 Patient Safety Incident Response Framework
IG/IT provisions align with the requirements of ISO27001:2022 standard
V2 February 2026 Director Quality, Safety and Nursing
Yearly Review in line with the requirements of ISO27001: 2022 Standard


1. Introduction
Provide Community is committed to ensuring care delivery is of the highest quality and that its services are safe and effective, with the safety of all colleagues, patients, service users and visitors being a top priority. Within Provide Community safety is everyone’s business.
A key function of developing and maintaining safe, high quality and effective services is to ensure incidents and near misses are reported and acted on in a timely manner and oversight of incident themes and trends is used to inform quality and safety improvement initiatives.
Provide Community’s approach to incident management encompasses:
• Compassionate engagement and involvement of those affected by incidents.
• Openness and honesty being at the heart of our incident response
• Considered and proportionate responses to incidents and safety issues.
• Proactive as well as reactive review of incidents to promote safety and quality
• A safety culture which encourages colleagues to report and speak up about incidents and near misses
2. Purpose
This policy sets out the Provide Community arrangements for the reporting and management of all incidents including near misses to ensure incidents are reported, reviewed and investigated appropriately and in a timely manner, so that lessons are learnt, and quality and safety is maintained and improved This policy Replaces Provide Community “All Incident reporting (including Serious Incident Reporting) & Management Policy V9 and Provide QSPOL15 Patient Safety Incident Response Policy as this policy is aligned to the NHS Patient Safety Incident Response Framework (PSIRF) and the principles of PSIRF have been used to inform the overall approach to the management of significant events across all Health, Social Care and infrastructure services within Provide Community
3. Safety Culture
3.1. Just Culture
Provide Community promotes a “Just culture” which supports a culture of fairness, openness and learning where colleagues can feel confident to speak up when things go wrong, rather than fearing blame. This enables a healthy learning culture where colleagues feel safe to report incidents and near misses and actively contribute to investigations and embedding learning to improve safety and quality.
In a just culture inadvertent human error, freely admitted, is not normally subject to sanction and investigations principally attempt to understand why failings occurred and how the system led to sub-optimal practice However, a just culture also holds people appropriately to account where there is evidence of harm arising from deliberate acts or gross negligence
3.2.
Freedom To Speak Up (Whistleblowing)
Across the Provide Community colleagues have the Freedom to speak up (whistleblow) if they are concerned about quality or safety in the organisation. Freedom to Speak Up (FTSU) is about encouraging a positive culture where people feel they can

speak up and their voices will be heard, and their suggestions acted upon. Speaking up is about anything that gets in the way of providing good care.
For more information refer to HRPOL01 Freedom to Speak Up (Whistleblowing) Provide Group Policy
4. Duty of Candour
Provide Community is committed to supporting families and colleagues when things go wrong and understands the importance of being transparent in admitting mistakes and learning from them to improve the services being delivered.
The Duty of Candour applies to every health and social care provider that the CQC regulates. The statutory duty of candour is a general duty for providers of Health and Social care services to be open and transparent with people receiving care from them. The Professional Duty of Candour requires Health and Social Care professionals to act in an open and transparent way with people receiving care or treatment from them.
The Duty of Candour must be applied when a notifiable safety incident occurs. A notifiable safety incident is one which must meet all 3 of the following criteria
• It must have been unintended or unexpected.
• It must have occurred during the provision of an activity we regulate.
• In the reasonable opinion of a healthcare professional, already has, or might, result in death, or severe or moderate harm to the person receiving care.
If any of these three criteria are not met, it is not a notifiable safety incident (but remember that the overarching duty of candour, to be open and transparent, always applies).
For more information refer to QSPOL03 Duty of Candour Provide Group Policy
5. Informing, Involving and Engaging
It is important that all those affected by an incident receive appropriate support to manage the impact of the events ensuring any clinical, psychological or safety needs they may have as a result of the incident are addressed promptly
While we cannot change what has happened a caring and compassionate response is in our gift and it is an important first step in responding to any incident it is essential that an early explanation is provided about what has happened along with an initial apology in line with the Duty of Candour requirements It is also a priority to ensure that the people affected are given the opportunity to talk about their experience and to ask questions so that their needs can be met, and their insights and questions can inform the investigation and learning from the incident.
When an incident occurs colleagues on duty and the service manager responsible for the service where the incident happened are best placed to ensure that the person/people affected (or where appropriate, their advocate, carer or family) are informed about the incident that has occurred and are offered an apology as appropriate, along with agreeing a plan to ensure appropriate on-going care and support is provided.
Appropriate support should also be provided to colleagues involved in any incident, ensuring they are treated with respect and compassion, and they are involved in the process of exploring what happened using their lived experience and hearing their perspectives on how systems or practice can be improved as part of the learning process. A hot/cold debrief/Swarm Huddle following the incident to allow colleagues time to speak and reflect about the incident is a useful process that managers should consider as part of their initial response to supporting colleagues following an incident.
Where an incident is designated significant enough to warrant a full investigation to identify the learning, the Director responsible for the service should appoint an appropriate person to engage with the people affected by and involved in the incident
The level of involvement and engagement should be proportionate to the type of incident that has occurred and the level of harm that resulted and should be tailored to the needs of the people involved. The guide below provides an example of the engagement and involvement process to support people involved in a significant event.
Harm/ Low Harm Incidents
Colleagues on duty:
• Inform the service user immediately about the Incident and offer an apology and explanation
• Inform their family /carer according to service user wishes
• Agree with service user and their family/carer as appropriate a plan of care to address any actual/potential harm
• Update the service user and their family /carer as appropriate about what is being done to prevent a recurrence/learn from the incident
Colleagues on duty:
• Inform the service user immediately about the Incident and offer an apology and explanation
• Inform their family /carer according to service user wishes
• Agree with service user and their family/carer as appropriate a plan of care to address any actual/potential harm
Service Manager:
• Contacts service user and their family/carer as appropriate
• Offers a meaningful apology
• Explores support needs and agrees plan to address these
• Answers questions and explores their perspective of care issues that may have contributed to the incident
• Explain how the incident will be reviewed to identify what can be learned so that improvements can be made
• Agrees what further contact (if required) will happen
• Where harm as a result of care or service delivery is identified a written duty of candour letter is completed

Service Director appoints an appropriate senior manager to undertake engagement
Designated senior manager:
• Contacts service user and/or their family/carer as appropriate
• Offers a meaningful apology
• Explores support needs and agrees plan to address these
• Answers questions and explores their perspective of care issues that may have contributed to the incident
• Explains how the incident will be reviewed to identify what can be learned so that improvements can be made
• Service user and/or their family/ carer as appropriate are asked what questions they would like answered as part of the review
• Terms of reference of reference for the review are shared with service/user and /or their family /carer as appropriate
• Point of contact for updates and timescales agreed
• Investigation outcomes and learning shared and questions answered.
• Written Duty of Candour letter sent

5.1 Information Governance Incidents Involving and Informing
For Information Governance incidents where a breach of personal data has been identified the level of involvement and engagement should be proportionate to the incident and the data breach. Where a single person is involved the service manager should offer a swift apology and explanation of what happened and what is being done to put things right. Where multiple people are affected or the breach is significant the service Director should work with the Information Governance Officer and Senior Information Risk Owner (SIRO) to agree how people will be informed and what feedback mechanism will be put in place to allow people to contact the organisation and ask to questions /discuss their concerns.
If a breach is likely to result in a high risk to the rights and freedoms of individuals, the UK GDPR says you must inform those concerned directly and without undue delay. In other words, this should take place as soon as possible.
The incident handler/service lead and the Provide Community Information Governance Lead will need to assess both the severity of the potential or actual impact on individuals as a result of a breach and the likelihood of this occurring. If the impact of the breach is more severe, the risk is higher; if the likelihood of the consequences is greater, then again, the risk is higher. In such cases, the incident handler/service Manager or Director depending on severity will need to promptly inform those affected, particularly if there is a need to mitigate an immediate risk of harm to them.
One of the main reasons for informing individuals is to help them take steps to protect themselves from the effect of a breach. Where a significant or high risk is identified the Safeguarding team should also be made aware to assess any potential safeguarding risks that need to be reported and managed to protect the safety of those involved.
5.2 Patient Safety Partners
Within Provide Patient Safety Partners (PSPs) will be actively involved in the design of safer health care at all levels in the organisation. They are members of the public with lived experience employed to support the organisation consider the impact of quality and safety processes and outcomes from a service user perspective. While their title incorporates the word patient, their expertise will support across all areas of Provide Community
6. Incident Reporting
Colleagues are encouraged to report No Harm and/or Near Miss incidents; from a risk management perspective as they help guide procedures to avoid reoccurrences. Timely reporting of incidents allows provide to:
• Reduce the likelihood of reoccurrence
• Provide feedback and information to those involved
• Improve practice as a result of the findings
• Set priorities for investment in training or other resources
• Assess and prepare for legal action
• Promote shared learning across the organisation
All areas of Provide Community will utilise the Datix Incident Reporting System to record incidents and near misses with the exception of the domiciliary care services that will utilise the Access Care Management System to record incidents in the client record.
All incidents should be reported without delay to the person in charge of the service at the time of discovery and should be recorded in the Datix/Access system as appropriate within 24 hours of the incident occurring or having been discovered It is the responsibility of the most senior member of staff on duty when the incident occurs to ensure the incident reporting process is completed.
The reporter must ensure that when recording details of the incident they must be factual and accurate and should not offer opinion or seek to apportion blame and gives consideration for the language used to describe the incident The information recorded should be sufficient to enable a clear understanding of what happened and what steps were taken to support the people affected and to prevent any further harm or potential harm occurring to anyone else
It is the Line Manager’s responsibility to ensure that colleagues are aware of their responsibility of reporting incidents into Datix or Access. It is every colleague’s member’s responsibility to acquaint themselves with Datix or Access and to report accordingly. The colleague that identifies and reports the incident is known as the ‘Reporter’.
Where an incident results in death or severe harm this should be reported without delay to the Director responsible for the service (in hours) or the Director on call (out of hours.) This is to ensure appropriate action can be taken by the Director to support the safety of colleagues /the service user / the public as appropriate and they will manage the incident ensuring onward informing and reporting as appropriate.
CEOs for the Directorate where the event has occurred to be made aware of any significant event as deemed necessary by the Director of Operations or the Quality and Safety team as the earliest opportunity.
To ensure that Provide Senior leadership Team (SLT) are aware of any significant event that the CEO of the Directorate where the event has occurred deems necessary to escalate this could include an event that may/has affected the reputation of Provide Community or caused major service disruption This will be done by the completion of an Executive Notification that the CEO will present at the next possible SLT meeting once a decision for escalation has been made
What is an Incident?
What is Harm?

An incident is any unintended or unexpected event during care/service delivery that caused, or had the potential to cause, harm to the person affected such as a patient, service user, colleague, or visitor.
Harm is the actual impact on a person from the particular incident being reported. This could be an injury (physical or psychological), disease, suffering, disability, or death.
Harm is related directly to the incident and not related to the natural progression of an illness or underlying condition

7. Incident Types
Colleagues should report anything, which causes them concern regarding the health, safety or wellbeing of themselves, or others involved with, or affected by, the organisation’s activities. Some examples of what should be reported are:
• Incidents that cause no harm but had a potential to cause harm and may recur or cause actual harm if not addressed – these incidents are known as near misses
• Those that cause low harm, moderate harm, severe harm or death as a result of the way care was delivered or due to issues with the systems and processes used by the organisation
• Those that involve property or equipment being faulty, damaged or stolen
• Those that concern loss, theft or inappropriate sharing of personal information
• Those that involve violence or aggression towards colleagues, visitors or service users
• Those that stop a service running effectively due to an issue with facilities, premises, staffing or any other reason
• Those where no people were involved: for example, medicine storage issues, flooding in a building: computer access issues, test result issues
• Those that occur as a result of a system, process, care delivery or communication issue between Provide Group services and another provider that has resulted in a near miss or actual harm (transfer of care issues are an example)
• Incidents that occur where care was provided by another organisation as would be the case when caring for people who have formal care packages in place or where people reside in a care home where their care is provided or where joint care provision is in place
• Those that occurred to a service user while in care of another provider but has been identified when coming into the care of Provide Group (e g a pressure ulcer is identified on admission or wrong medicine dispensed by a pharmacy etc)
8. Recording Harms
When an incident occurs it is important to record the level of harm that has resulted so that appropriate action can be taken to support the people affected and ensure that there is an accurate record of what occurred at thetime. Themes and trendsfrom harms can help inform improvements in safety and quality. It also helps to identify when a notifiable safety incident has occurred which needs to be reported to the Care Quality Commission and identifies where the Duty of Candour applies.
When recording an incident, the actual level of harm apparent should be recorded based on the best information available at the time Potential harm should not be recorded. Potential harm is the harm that could have occurred but hasn’t actually happened or isn’t apparent at the time If more information becomes available harm levels can be reviewed and updated to more accurately reflect the actual level of harm that resulted.
Recording harms can be difficult. Below are some examples to guide accurate harm recording:

• A document containing sensitive patent information is sent to the wrong patient. This is very serious and should be recorded as an incident but although serious as we have a duty to protect people’s information this should not be recorded as a moderate or severe harm if the people concerned have not been physically or psychologically harmed and they may be cross about the sharing but not impacted long term psychologically so the incident should be recorded as a no harm incident.
• If a patient dies or is found deceased, this is a very significant situation, but their death may not have occurred as a result of a care safety issue or organisational safety issue as they died of natural causes Therefore, no harm has occurred
• If a service user died during the delivery of care or treatment as a result of a care safety issue, for example they died as a result of an unexpected or unintended event this would be a fatal harm
• If a service user died of natural causes but experienced a care safety issue that did not cause or contributeto their death but was an unintended or unexpected incident, for example, they were given only one of their pain killer tablets instead of 2 causing unnecessary pain and discomfort, this would be a low harm incident
• A category 3 pressure ulcer or wound is discovered on admission. While the wound may need treatment it did not arise as a result of care delivery by Provide Community therefore no harm has occurred while in our care but the harm level should still be recorded appropriate to the level of care and the impact experienced by the service user but the reporter should state ‘No’ to the question “Did the incident occur whilst the patient was under your organisation’s care. ”
• If a person has multiple pressure ulcers that developed by the same mechanism this only needs to be recorded once with the harm level recorded in line with the pressure ulcer with the highest level of harm
• If a service user has multiple pressure ulcers which developed due to different mechanisms (i.e.one develops due to a monitoring device, and the other is related to profiling bed equipment), two distinct incidents have occurred and should be recorded as such.
• Harm levels for pressure ulcers cannot be standardised to categories. This means category 3 pressure ulcers should not routinely be recorded as a moderate harm and category 4 as severe harm. Instead, the size and location of the pressure ulcer and the impact on the service user as a result should determine the harm that is recorded. A category 3 pressure ulcer could be recorded as low harm if it is small and likely to heal rapidly but may be moderate or severe depending on the size and location and the required treatment and long-term outcome
Where there is uncertainty about the level of harm caused the service the Quality and Safety team can be contacted for guidance

9. Harm Levels
Harm level should be identified using the descriptors below. The harm recorded should be the actual harm that resulted not the potential harm
Near Miss
No harm has occurred as an intervention prevented the incident harming someone
No Physical Harm
An incident actually happened but no harm has occurred
No Psychological harm
Being involved in any patient safety incident is not pleasant, but please “no harm’ should be selected if no specific psychological harm that meets the description of ‘low psychological harm’ or worse is identified. Pain should be recorded under physical harm rather than psychological harm
Low Physical Harm
All of the following must apply:
• minimal harm occurred – person/people required extra observation or minor treatment
• did not or is unlikely to need further healthcare beyond a single GP, community healthcare professional, emergency department or clinic visit
• did not or is unlikely to need further treatment beyond dressing changes or short courses of oral medication
• did not or is unlikely to affect the affected person(s) independence
• did not or is unlikely to affect the success of treatment for existing health conditions
Low Psychological harm
At least one of the following must apply:
• distress that did not or is unlikely to need extra treatment beyond a single GP, community healthcare professional, emergency department or clinic visit
• distress that did not or is unlikely to affect the person(s) normal activities for more than a few days
• distress that did not or is unlikely to result in a new mental health diagnosis or a significant deterioration in an existing mental health condition
Moderate Physical Harm
Harm that requires a moderate increase in treatment and at least one of the following must apply:
• has needed or is likely to need healthcare beyond a single GP, community healthcare professional, emergency department or clinic visit, and beyond dressing changes or short courses of medication, but less than 2 weeks additional inpatient care and/or less than 6 months of further treatment, and did not need immediate life-saving intervention
• has limited or is likely to limit the patient’s independence, but for less than 6 months
• has affected or is likely to affect the success of treatment, but without meeting the criteria for reduced life expectancy or accelerated disability described under severe harm
Moderate Psychological harm
At least one of the following must apply:
• distress that did or is likely to need a course of treatment that extends for less than six months
• distress that did or is likely to affect the patient’s normal activities for more than a few days but is unlikely to affect the patient’s ability to live independently for more than six months
• distress that did or is likely to result in a new mental health diagnosis, or a significant deterioration in an existing mental health condition, but where recovery is expected within six months
Severe Physical Harm
At least one of the following must apply:
• permanent harm/permanent alteration of the physiology
• needed immediate life-saving clinical intervention
• is likely to have reduced the patient’s life expectancy

• needed or is likely to need additional inpatient care of more than 2 weeks and/or more than 6 months of further treatment
• has, or is likely to have, exacerbated or hastened permanent or long term (greater than 6 months) disability of their existing health conditions
• has limited or is likely to limit the patient’s independence for 6 months or more.
The harm recorded should be the harm that has directly resulted from the incident and not related to the natural course of the service user's illness or underlying condition
Severe Psychological harm
At least one of the following must apply:
• distress that did or is likely to need a course of treatment that continues for more than six months
• distress that did or is likely to affect the patient’s normal activities or ability to live independently for more than six months
• distress that did or is likely to result in a new mental health diagnosis, or a significant deterioration in an existing mental health condition, and recovery is not expected within six months
Fatal
You should select this option if, at the time of reporting, the person(s) has died and the incident that you are recording may have contributed to their death
• the death of the person - directly due to the incident, rather than the natural course of the person's illness or underlying condition
When recording psychological harm, you are not required to make a formal diagnosis; your answer should be an assessment based on the information you have at the point of recording and can be changed if further information becomes available
The Datix recording system requires the “overall level of harm” to be recorded once the physical and psychological harm levels have been recorded. To record overall level of harm the highest level of harm be it physical or psychological should be recorded as the overall level of harm. E.g. if physical harm is moderate but psychological harm is low the overall level of harm would be “moderate.”
The Access recording system requires a single level of harm based on physical harm alone to be recorded.
10. Incidents Involving Multiple People
Where an incident occurs that impacts on more than one person the harm level should be recorded for each person up to 10 people. If a safety incident affects more than 10 people only one incident form needs to be completed with the details of the person with the highest level of harm in the category fields and outline the other impacts within the “describe what happened” free text field including the number of patients involved. In these instances, it is likely a Patient Safety /Significant Incident Investigation will be instigated and the harm impact experienced by each person involved should be recorded as part of the investigation.
11. Preservation of Evidence
Where equipment, medical devices or buildings may have been involved in an incident where harm occurred, do not disassemble, clean, decontaminate, alter control settings or alter the building environment. Report the incident to a senior manager and follow their advice on where and how to secure the equipment which can then be examined as part of an incident investigation.

In the case of a possible or actual criminal incident or an enforcement agency no action must be taken to clean up an area until the Police/Health and Safety Executive/Fire and Rescue/Environmental Agency have attended. Any evidence must be preserved until any of these agencies have completed their investigation. However, if the safety of service users or colleagues is at risk reasonable precautions must be taken to remove the danger.
In some significant incidents it is important clinical records and other records are secured to prevent sharing, loss or tampering. Where this is necessary the Director of the service will work with the systems team to secure them.
Scene Preservation Preserving evidence in Health and Safety (H&S) investigations is a legal and procedural necessity, ensuring that the causes of accidents or near-misses can be determined to prevent recurrence and to defend against potential legal actions. The primary goal is to maintain the integrity of the scene and materials by preventing cleaning, tampering, or contamination. Immediately isolate the area to prevent unauthorized access, using tape, barriers, or, in serious cases, locking down the area until authorities (such as the Police or HSE) arrive.
All fleet-related incidents, including road traffic collisions, near misses, vehicle damage, or loss of load events must be immediately reported and investigated. Drivers must secure the scene where safe, gather evidence, notify their manager, and complete required documentation. Vehicles involved in severe incidents should not be moved or repaired until authorised by the Health & Safety team or external investigators.
Load securing failures, including load shifts, unsecured pallets, or load collapse within a trailer or warehouse environment, must be treated as a significant near miss or incident depending on severity. Investigations must examine equipment condition, method of securing, competence, loading plans, and any deviation from Safe Systems of Work.
Any Materials Handling Equipment (MHE) involved in a collision, tip-over, impact, or near miss must be immediately taken out of service pending inspection. Operators must undergo post-incident assessment of competency, and investigations must consider environmental conditions, traffic layout, visibility, pedestrian interaction, and MHE maintenance records.
All traffic-related incidents, including near misses between MHE and pedestrians, require a proportionate investigation. The review must consider site layout, segregation compliance, speed control, visibility, lighting, and behavioural elements. Immediate corrective actions may include temporary barriers, route redesign, or supervisor presence.
For any fleet-related incident, telematics, dashcam footage, and GPS data must be secured immediately. Only authorised personnel may retrieve data. Tampering with or deleting telematics data is considered a disciplinary offence. Data will be retained according to GDPR and company retention schedules and used to support investigations and continuous safety improvement. Following any fire or suspected fire, the site must be evacuated immediately in line with the Fire Emergency Plan. No one may re-enter the building until authorised by the Fire Service. Post-incident investigations must involve Facilities, Health & Safety, and where relevant, Dangerous Goods Advisors, to assess ignition sources, stock types, racking integrity, equipment condition, and evacuation effectiveness.

Reporting of Injuries, Diseases and Dangerous Occurrences Regulations (RIDDOR)MHE’s are considered as lifting equipment and could be reportable under RIDDOR even if no injuries and an investigation carried.
12. Incident Management
Incident investigation is important to identify why an incident may have happened and to identify lessons that should be learned to prevent a recurrence and improve quality. Provide Community’s approach to incident management is that it should be proportionate and appropriate to the incident that has happened. For any incident that involves service users the principles of the NHS Patient Safety Incident Response Framework (PSIRF) and methodologies will inform the response and investigation across all provide Health and Social Care Service as it is recognised the Framework sets out processes that are not NHS centric and can be applied organisation wide.
Where possible, incidents should be managed locally where the people who work in the services are best placed to explore what happened and identify ways to improve safety. Where incidents have resulted in significant harm or have impacted or have the potential to impact more people a more detailed response may be required if the harm resulted from care or service delivery issues.
12.1 Health and Safety Incidents
It is the responsibility of the relevant manager to ensure that any incidents or near misses that occur in their area of responsibility are reported and investigated, and the appropriate remedial action is taken to ensure, as far as possible, there is no recurrence. Investigation of health and safety incidents follow the same processes as for clinical incidents so that they are appropriately investigated and reported and improvements in safety can be made.
The Health and Safety team are available to support managers and others on matters which might reasonably lie outside the competence of those carrying out an incident investigation.
12 2 Local Level Incident Management
Where there has been a near miss, no harm or low harm incident. The incident can be managed at the local service level by the designated incident handler (the handler) in conjunction with the service manager. The incident review should be completed within 2 weeks of the incident being reported.
The handler must ensure the people affected have been provided with appropriate care and support and that they have been informed about what has happened and what is being done to keep them safe. Where the handler identifies an on-going risk, this should be escalated to the manager of the service and onward to Director for the service for review and action. The service manager must ensure all colleagues within the service are aware an incident has happened and ensure the learning to improve quality is embedded.
The handler must record in the Datix / Access system the outcome of their review into what happened and what actions they have taken. They should also review the harm level that is recorded to ensure it is accurate. If a harm level is more severe than initially recorded and is identified as moderate or severe the handler should report this to the service manager and onward to the service Director. The Quality and Safey team must

also be notified so that an assessment can be made as to whether a more detailed investigation is required to identify the learning to improve quality and to ensure any Duty of Candour requirements are met.
12 3 Intermediate Level Incident Management
Where there is an incident reported with a moderate harm level the handler must complete a review of the incident within two working days to identify the accuracy of the harm level The handler will review the circumstances of the incident ensuring all appropriate steps have been taken to assure the safety of the people affected, escalating to the service manager and onward to the service Director where they identify on-going risks In all cases the service manager will ensure an apology if appropriate is completed as part of the incident management process and subsequently complete Duty of Candour if the incident is a notifiable safety incident.
Along with the handler, the Quality and Safety team will review all incidents and where moderate harm is identified on DCIQ or where there are potentially gaps in care that need further review the incident will be presented by the handler at the Incident Review Panel (IRP) or escalated directly to an Incident Review Group (IRG).
Where moderate harm incidents are reported on ACCESS Registered Managers within the service are to escalate these incidents to the Quality and Safety team and Senior Leadership within that service. Further to this ACCESS incident data is to be shared and reviewed monthly at Quality Reference Group by Senior Leadership. Incidents were appropriate can be directly escalated to an IRG.
The Incident Review Panel will consider the facts of the incident and will confirm and agree if the incident can be finalised and closed as local management and learning if appropriate; or they may recommend that the incident is further reviewed to achieve greater insight and learning from the incident. If this is the case an Incident Review Group (IRG) will be convened the Quality and Safety team and will include the service, Director The IRG will review the incident and confirm if the incident should be reviewed in more depth utilising one of the following methodologies appropriate to the type of service where the incident occurred:
• Swarm Huddles in health and social care services
• After Action Reviews (AAR) in health and social care services
• Patient Safety Incident Review (PSIR) process in health care services
• Significant Incident Review (SIR) process in social care services
If a review of the harm level is identified as more severe than moderate, then the investigation will be escalated to a significant incident level management process.
12.4 Significant Incident Level Management
A significant incident is an event where something unexpected or unintended has happened or failed to happen and where the consequences are so significant that a structured approach is required to ensure the safety of the people involved and to ensure a thorough review and investigation is completed to learn from the event and improve quality and safety. The types of events that would require a more structured approach are:
• Those that resulted in or had the potential to result in severe harm or death as a result of service delivery/care delivery (not a natural progression of disease)

• A near miss where the potential for harm is very great if systems or practice are not changed
• Actual or alleged abuse; sexual abuse, physical or psychological ill-treatment, or acts of omission which constitute neglect, exploitation, financial or material abuse, discriminative and organisational abuse, self-neglect, domestic abuse, human trafficking and modern-day slavery where the organisation did not take appropriate action/intervention to safeguard against such abuse occurring
• Never Events. These are defined as significant incidents that are wholly preventable because guidance or safety recommendations that provide strong systemic protective barriers are available at a national level and should have been implemented by all healthcare providers. NHS England publishes a reviewed list of Never Events annually and any organisations Providing NHS care are expected to closely monitor the occurrence of Never Events within the services they provide
• Those where multiple people are affected such as:
• A significant test result issue with the potential that one or more people have been harmed or could be harmed
• A significant Information Governance breach
• A significant outbreak of infection or disease affecting with the potential that one or more people have been or could be harmed
• A significant business continuity issue occurred with the potential to affect the organisation’s ability to deliver safe services or the incident has affected people who have been or could have been harmed
Where a significant incident occurs, colleagues on duty should take immediate steps within their competence and role to keep people safe and escalate without delay to their manager and onward to the Director responsible for the service (in hours) or the Manager on call (out of hours.) The Director /On-call manager will take charge of the situation to ensure the safety of people involved and for informing the Chief Officer responsible for the service in office hours or the Executive on-call out of hours.
The Director responsible for the service will lead the overall response to support the management and recovery of the service following the incident ensuring those involved are appropriately supported. This may be part of a business continuity or major incident response if the incident is very significant or involves multiple people where a more robust command and control process is required. If the incident involves less than 10 people and is unlikely to recur or impact on service continuity the incident could be led to resolution by the Service Director
13. Information Governance Incident Management
All organisations processing Health, Public Health and Adult Social Care Personal Data are required to use the Data Security and Protection (DSP) Toolkit Incident Reporting Tool to report level 2 IG incidents that occur. The DSPT toolkit will further assess the incident and where appropriate, automatically reports it to the Information Commissioners Office, the Department of Health, and other regulators.
For most incidents a local review and learning can be undertaken by the Incident handler with support from the Group IG lead following the level 1 incident management process. The IG Significant Incident Reporting Checklist on Datix or Access should be

completed as part of the review. Any IG Incidents categorised as Level 2 or above must be reported to the Group Chief Finance Officer who is the designated Senior Information Responsible Officer (SIRO) for the Group. The SIRO will confirm if the incident meets the criteria of a significant incident reportable via DSPT toolkit to the ICO and will request the Quality and Safety Team to convene a Significant Incident Review Panel. The incident will be managed following the level 3 incident management process and significant incident investigation process.
All Information Governance Significant Incidents (level 2) should be recorded on the Data Security and protection Toolkit (DSP Toolkit) without undue delay (not later than 72 hours of the breach being notified) with as much information as can be ascertained at the time. This will be completed by the organisation’s Information Governance Lead. To enable them to meet this deadline all IG breaches should be reported onto Datix or Access without delay and be reported to the IG lead. A full record of the incident should be completed within 5 working days from when the incident was initially reported. Once incident management and investigation procedures have been followed the incident must be reported on the DSPToolkit, where required in a timely manner and in any case within 72 hours of discovering the incident/breach. Failure to meet the above requirements exposes Provide Group to an administrative fine.
14. Patient Safety/Significant Incident Investigation
The Chief Officer responsible for the service where the incident occurred or Chief Officer designated by the Group Chief Executive if the incident affects multiple services will be accountable for ensuring service safety and recovery following a significant incident.
To support the investigation of a significant/safety incident or significant event the Quality and Safety team will discuss the incident with the relevant service Director and Chief Officer as well as the Chief Executive for Health and Group Chief Nurse or their deputy to confirm that the incident should be designated as a significant incident.
The Quality and Safety team will notify the Senior Leadership Team of the incident and will convene a Patient Safety/Significant Incident Review Group (PSIRG/SIRG) The purpose of the PSIRG/SIRG will be to:
• Review the known facts of the incident and assess the level of harm that has occurred and consider if others are at risk of harm, working to put mitigations in place where needed. Where multiple people are affected, they will put in place a process to review and confirm harms for each individual involved
• Agree how the incident should be investigated (i.e. following the NHS Patient Safety Incident Response Framework for NHS commissioned services, following the Significant Incident Process for Non- NHS services or commissioning an external investigation if a more independent review is required)
• Agree if the incident can be investigated by a single investigator or whether a panel is required to bring expertise together to manage the scale of the incident
• Agree the way in which the investigation will be captured such as a Patient Safety Incident Report/Significant Incident report, Patient Safety Incident

Investigation/Significant Incident Investigation (PSII/SII) or incident Briefing Pack.
• Consider what other investigations have already been instigated or may be instigated to avoid duplication e.g. LeDeR, Coroner inquest, Police Investigation, HSE investigation, safeguarding investigation or other
• Designate an investigating officer/s or Investigation Panel (Chair and members of the panel to be identified)
• Agree terms of reference for the investigation
• Agree timescales for the investigation and how often PSIRG/SIRG needs to meet to track the progress of the investigation
• Agree how the people affected will be involved and engaged including having their voices heard, questions answered, and feedback given on outcomes and learning
• Ensure Duty of Candour is completed if applicable
• Ensure the investigation progress is tracked to avoid unnecessary delays
• Review the draft report to ensure all the terms of reference have been answered
• Agree the final version of the report and recommendations
• Consider wider organisational learning and how this is shared
• Co-ordinate any complaint response or media enquires as part of the overall incident management
• Ensure notification has been completed as required this may include notification to:
• The Senior Leadership Team
• The Care Quality Commission
• The Health and Safety Executive
• The Information Commissioners Office
• The Commissioner for the service
• UKHSA
• MHRA
• The Police
• The Local Authority if there are Safeguarding concerns
• Other
The PSIRG/SIRG will consist of:
• The Chief Officer responsible for the service or function (in their absence the Chief Executive for Health and Group Chief Nurse)
• The Group SIRO or their designated Deputy if the incident concerns Information Governance
• The Director responsible for the service
• The Service Manager/person with the detail of the incident
• The Director Quality, Safety and Nursing or deputy
• A relevant subject matter expert from the corporate teams as appropriate (or externally commissioned if deemed necessary)
• Others as requested by the chair
The Chief Officer responsible for the service will chair the PSIRG/SIRG unless the incident concerns Information Governance or another corporate function such as Health and Safety where it may be more appropriate for another Chief to chair the panel.
14.1 Investigation Methodologies
In line with the NHS Patient Safety Incident Review Framework (PSIRF) the approach to incident management in NHS commissioned services will follow the principles of the framework as set out in the Provide Group PSIRF Plan. Colleagues involved in undertaking investigations will utilise the recommended, proportionate approach and tools to maximise learning
In non – NHS commissioned services incident investigation approach will utilise the PSIRF tools and methodologies to standardise the Provide Community approach to investigations to maximise learning.
Methodology Descriptors
PSIR (Patient Safety Incident Review)
SIR (Significant Incident Review)
PSII (Patient Safety Incident Investigation)
SII (Significant Incident Investigation)

PSIR /SIR Reviews are led by colleagues trained to conduct reviews to achieve learning, and the review and learning is recorded in a PSIR /SIR template. PSIR /SIR training and templates align to the NHS Patient Safety Incident Response Framework
A PSII/ SIIs are led by colleagues trained to conduct investigations, and the investigations utilise the tools and templates aligned to the NHS Patient Safety Incident Response Framework These investigations explore decisions or actions as they relate to the situation. The method is based on the premise that actions or decisions are consequences, not causes, and is guided by the principle that people are well intentioned and strive to do the best they can. The goal is to understand why an action and/or decision was deemed appropriate by those involved at the time and to establish how changes can be made to improve safety. The National PSII template is utilised to guide standardisation of approach and report and the SII template mirrors this approach but has been adapted to suit social care services
Methodology Descriptors
Multidisciplinary Team (MDT) Review

The MDT review supports health and social care teams to:
• Identify learning from multiple safety/significant incidents (including incidents where multiple people were harmed or where there are similar types of incidents)
• Agree, through open discussion, the key contributory factors and system gaps in patient safety incidents for which it is more difficult to collect colleagues’ recollections of events either because of the passage of time or colleagues’ availability.
• To explore a safety theme, pathway, or process.
• To gain insight into ‘work as done’ in a health and social care system.
After Action Review (AAR) An After-Action Review method of evaluation usually takes the form of a facilitated discussion following an event or incident. It enables understanding of the expectations and perspectives of all those involved, and it captures learning, which can then be shared more widely. AAR generates insight from the various perspectives of the MDT and can be used to discuss both positive outcomes as well as incidents. It is based around four questions:
• What was the expected outcome/expected to happen?
• What was the actual outcome/what actually happened?
• What was the difference between the expected outcome and the event?
• What is the learning?
Post Infection Review (PIR) The principal purpose of the Post Infection Review (PIR) is to support commissioners and providers of care to deliver zero tolerance on bloodstream infections. The purpose of the PIR is to identify how a case of bloodstream infection occurred and to identify actions that will prevent it reoccurring. This review is a cross-system process and enables pathways of care and treatment to be examined to identify improvements and/or change.
Swarm Huddle
Thematic Review
A swarm is designed to start as soon as possible after a patient safety incident occurs. Immediately after an incident, colleagues ‘swarm’ to quickly analyse what happened and how it happened and decide what needs to be done to reduce any risk. Swarms enable insights and reflections to be quickly sought and generate prompt learning. This has the benefit of colleagues being able to readily recall key information that may be forgotten over time, and to support colleagues with the aim to identify learning and improvement, in a Just Culture.
A thematic review can identify patterns in data to help answer questions, show links, or identify issues. Thematic reviews can sometimes use a combination of qualitative data with quantitative data to inform findings. Thematic review can be used to inform a safety/significant incident response plan, analyse a safety/significant incident or theme and inform or assess the impact of a safety /quality improvement plan.
15. Timescales for Incident Management and Investigation
What happens
Incident Reported on Datix or Access system
Handler Review
Service Director review of Severe Harm or Fatal Harm incidents
Quality and Safety team Review of all Datix Incidents
Incident Review Panel

Closure of Incidents
Swarm Huddles
AAR - After Action Reviews
Comprehensive Investigation
• PSII- Patient Safety Investigation
• SII -Significant Incident Investigation
Completion of action plans to embed the learning from incidents
When
As soon as possible after the incident is identified
Who
The person who identified the incident
Within 2 weeks of the incident being reported Incident Handler
Within 3 working day
Within 2 working days
Within 21 working days of the incident occurring
• For local level incidents managementwithin 21 working days of the incident occurring
• For intermediate level incidents within 3 months of the incident occurring
• Incidents reporting a death that are subject to a review within 3-6 months of being reported
• Significant incident investigation event see timescales below for PSII /SII
As soon as possible on the day of the incident
As soon as practicably possible
Commences as soon as practical after Significant Incident Review Group commissions the investigation Completes within 6 months of being commissioned depending on complexity unless external processes dictate timescales
Ideally within 4 months of an investigation being completed and the final report being approved but noting on occasion a longer timeline may be required depending on the action
16. Learning from Incidents
The Service Director /Manager on call
Designated Quality and Safety team Reviewer
Quality and Safety team
Quality and Safety Team for Datix Incidents
Service CQC Registered Manager for incidents recorded on Access
Most Senior person on shift co-ordinates the huddle and records the learning
Lead identified at Incident Review Panel or by Service Director from AAR Conductor list held by Quality and Safety team
Significant Incident Review Group commissions investigations and maintains oversight
Service Directors
It is essential that learning from incidents inform improvement in quality and safety. All incidents provide an opportunity for learning, and all colleagues are responsible for participating in investigations and embedding the learning.
Service managers are responsible for ensuring the learning from incidents are recorded, shared with the team and embedded in practice. The Quality and Safety team will maintain oversight of incidents, identifying themes and trends that can inform learning and improvements in quality and safety
The Quality Reference Group will maintain oversight of recommendations and action plans arising from incident investigations to ensure actions are completed in a timely manner, escalating to the Group Quality and Safety Committee where there are issues.
The Quality and Safety team will support and lead on the sharing of learning from incidents internally and externally when appropriate using the relevant medium.

To Support learning from incidents Patient Safety Specialists will be involved in reviewing incident themes and trends and safety processes.
17. Shared Involvement with Other Organisations
For incidents involving other agencies or organisations, the possibility of jointly commissioning a single review will be considered by the Quality and Safety team or by the Patient Safety/Significant Incident Review Group The aim is to enable local reviews to proceed as soon as possible and for lessons to be learned, whilst ensuring coordination of procedures and avoiding duplication of processes. Robust communication is vital when more than one agency is involved in an incident.
18. Responsibilities
Provide Community Board
The Board will set in place an effective quality assurance structure that includes robust incident management processes and oversight of risks, themes and trends arising from incidents as well as reporting and oversight of all significant incidents.
The Provide Community Quality and Safety Committee (QSC)
QSC is the designated Board Committee that will maintain oversight of quality and safety across Provide Community. All significant incidents will be reported to QSC with the exception of Information Governance Incidents which will also be reported to the Finance and Investment Committee. QSC may request deep dives to explore incident themes and trends and will set in place processes to monitor and assure learning from incidents has been acted on and completed. This includes ensuring action plans to implement recommendations are completed
Group Chief Executive Officer (Group CEO)
Has overall accountability for all matters relating to incident reporting and management across the organisation and Provide Group. The Group CEO is responsible for ensuring that systems are in place to report and monitor incident data, respond appropriately to incidents, and learn with respect to all incidents. The Group CEO is also responsible for ensuring that relevant information is made available to the Provide Community Board with respect to reporting and learning from all incidents.
Group Chief Officers
Group Chief Officers are responsible for:
• The Senior Leadership team collectively maintaining oversight of incidents and risks across Provide Community
• Ensuring appropriate management, investigation and embedding of recommendations and learning from incidents and lead on oversight and management of all risks associated with incidents
• Declaring a significant incident when appropriate and initiating an appropriate management response and investigation

• Ensuring appropriate reporting of incidents and risks to company Boards, Group Quality and Safety and Finance and Investment Committees as appropriate and ultimately to the Group Board
The Chief Executive (Provide Health) and Group Chief Nurse have responsibility across Provide Community for Quality and Safety and maintains oversight of incident management across the organisation via the Quality and Safety team function
The Group Chief Finance officer has responsibility for and maintains oversight of all Information Governance incidents leading on management of all Significant Incidents associated with IG
If an incident requires a decision and in the absence of the Group Chief Officer responsible for the service, the Chief Executive (Provide Health) and Group Chief Nurse will make the decision in their absence. If both are absent the Group Chief Executive will decide.
Directors
Directors are responsible for:
• Ensuring that they and all members of their teams are aware of and act in line with the relevant policies governing incidents and associated reporting and learning
• Ensuring all incidents are appropriately managed within their services
• Ensuring identified learning, themes and trends are used to improve quality and safety
• Leading the management response to significant incidents arising in their services and for collectively working to manage incidents effectively across the Provide Group, so that all recommendations and learning are embedded within the services in a timely manner
Service Leads/ Registered Managers
Service leads /Registered Managers are responsible for:
• Ensuring their teams are aware of what to do if an incident or near miss occurs and how to report them
• Ensuring timely review and handling of reported incidents to ensure service safety and to assess harm levels
• Completing reviews and investigation of incidents to identify learning and taking action to improve safety and quality
• Escalating risks and incidents of concern to service Directors and the Quality and Safety team
The Quality and Safety Team
The Quality and Safety team is responsible for:
• Maintaining oversight of incident themes and trends across Provide Community to identify opportunities for learning and quality improvement

• Providing expertise on incident management to all colleagues across the Provide Community
• Facilitating the appropriate response to incidents as they arise
• Putting systems and processes in place to ensure reporting and oversight to inform quality assurance
• Supporting the training and education of colleagues on incident management
The Health and Safety Team
The Reporting of Injuries, Diseases and Dangerous Occurrence Regulations (RIDDOR) 2013 requires a named responsible person on behalf of the organisation to report to the local office of the health and safety executive (HSE). The health and safety lead has been designated as the responsible person on behalf of Provide Community.
The Health and Safety Lead will:
• be responsible for ensuring the statutory notification ofthose specified incidents to the health and safely executive (HSE)
• receive and manage the process of RIDDOR reportable incidents, checking that the forms are completed correctly and sent to the relevant office of the HSE in the prescribed timescale, normally 15 working days
Investigators / Handlers
Investigators / Handlers are responsible for:
• Undertaking a comprehensive review of incidents ensuring the people involved are engaged to ensure their lived experience informs the learning
• Escalating any risks that may affect quality and safety to the Service Manager
• Identifying the learning from an incident and working with the Service Manager and colleagues to improve quality and safety
All Colleagues (clinical and non-clinical) within Provide Community
All colleagues (clinical and non-clinical) are responsible for:
• Being aware of what to do if an incident occurs to keep people safe and how to report it in hours and out of hours
• Reporting all incidents and near misses using the Datix Incident Reporting System or Access System as appropriate
• Informing their relevant Service Manager when incidents or near misses happen within their area, who in turn must inform the Service Directors
• Contributing to investigations, being open and honest about their actions
• Contribute to the implementation of actions to improve safety and quality
• Speak up (whistle blow) if they are concerned about safety and quality where they work

19. Notifications and Reporting
Some incidents will require reporting to additional external bodies. Service Directors will work with Group Chief Officers and the Quality and Safety team or Health and Safety team where relevant to agree what notifications are required and completed
Commissioners /Lead Provider
Health and Social Care contracted services are required to report all significant incidents to the commissioner without delay and if provide is a sub-contractor the Lead Provider would need to be notified so they in turn can inform the Commissioner
Police
Criminal incidents will be reported to the police. These may include assaults or significant threats of harm, hate crimes, theft, vandalism, suspicious activity, or unexpected deaths. Incidents that are suspected to involve deliberate harm or neglect of a Service User may also need to be reported to the police.
If a matter needs to be reported to the police, this can be done by the victim if they are able and want to report the incident or by Provide Community colleagues on behalf of the victim to ensure their safety or in the case of an unexpected death to ensure appropriate reporting and investigation can take place Police can be informed by calling 101 for non- emergency incidents or by calling 999 in an emergency. All matters reported to the police should be recorded in Datix or Access and the Quality and Safety team should be notified as soon as possible so the incident can be investigated and to ensure any onward reporting such as to the CQC is completed if required.
Care Quality Commission (CQC)
Statutory Notifications are required to be sent without delay for organisations where services are regulated by the CQC in the following circumstances:
• Allegations of abuse (against Provide services)
• Death of a person using the service where the death arises as a result of service delivery and how it was provided
• Significant injury to a person where the injury arises as a result of service delivery and how it was provided
• Events that stop a service running safely and properly
• Police Involvement in an incident where the incident affected someone's health, safety and welfare when using, visiting or working at the service
Up to date guidance can be found on the CQC website.
Safeguarding
Where an incident occurs where there is suspected abuse or neglect should be reported to Social Care as they have a statutory duty to safeguard and promote the welfare of children and adults at risk
• Recognise: Identifying physical, emotional, or behavioural signs of abuse, neglect, or harm.
• Respond: Taking immediate action to ensure the person's safety, such as providing first aid or moving them away from danger.
• Record: Documenting exactly what was seen or heard in a clear, factual, and secure report as soon as possible.
• Report: Informing the safeguarding team

• Refer: Escalating the concern to external statutory bodies, such as the Police or Local Authority Social Care, when necessary
In the event of an incident involving safeguarding concerns, it is necessary to liaise with the safeguarding team. If evidence supports the presence of a safeguarding concern, a referral to social care may be required. Depending on the nature of the concern, referrals to the police, Care Quality Commission (CQC), or other external agencies may also be necessary.
https://provide.metacompliance.com/View/Policy/4787335
https://provide.metacompliance.com/View/Policy/4789057
UK Health Security Agency (UKHSA)
If the case is an urgent notifiable disease, you must report it by telephone to your local UKHSA health protection team within 24 hours. This is to discuss actions to protect public health.
Report all cases on the Report a notifiable disease online service within 3 days.
HM Coroner
Sudden and/or unexpected and/or unnatural deaths are notifiable to HM Coroner. In the event of a sudden death the Coroner is informed as a priority and as soon as practicable through the Medical Examiner process (please see https://provide.metacompliance.com/View/Policy/3183032 ).
Health & Safety Executive (HSE)
The Health and Safety Team will ensure that they notify HSE following incidents notifiable under the Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 1995 (RIDDOR) If someone has died or has been injured because of a work-related accident, this may have to be reported under the RIDDOR.
Not all accidents need to be reported – a RIDDOR report is only required when:
• the accident is work related, and
• it results in a reportable injury
Medicines & Healthcare Products Regulatory Agency (MHRA)
Suspected adverse reactions to drugs are notifiable by doctors, nurses, service users, and pharmacists through the Yellow Cards Scheme. Advice and Yellow Cards are available from the MHRA Website and are included in the British National Formulary (BNF). Adverse incidents relating to medical devices are also reportable to the MHRA. All incidents of Medical Devices will be reviewed by Provide Medical Device Safety Officer (MDSO)
Environmental Health Department
Confirmed reports of food poisoning are notifiable to the relevant Local Authority Environmental Health Department
Information Commissioner Office (ICO)
When a personal data breach has occurred, you need to establish the likelihood of the risk to people's rights and freedoms. If a risk is likely, you must notify the ICO; if a risk is unlikely, you don't have to report it. If a reportable incident is identified this must be reported to the ICO without undue delay and not later than 72 hours of becoming aware of it. If the breach is likely to result in a high risk to the individuals, then we must inform the affected individual without undue delay. The ICO provides guidance on the factors that we should take into account when assessing the risk.

NHS estates
Provide Community is required to report incidents relating to fire, buildings, plant, and non-medical equipment to NHS estates. Managers dealing with such incidents must contact the Health and Safety Team with all the relevant information to enable the health and safety lead to complete the required report form
20. Media
An incident may attract media attention and generate a demand for information from the public or service user(s) affected by the incident. Where potential media interest exists, this will be dealt with by the relevant Group Chief Officer with the support of the Head of Marketing and PR or another Group Chief in their absence.
If necessary, a media response plan will be created. The plan will provide reassurance on any public interest issues and promote any help lines for members of the public or service users who may be adversely affected by the incident.
Colleagues should not respond to any media enquiries directly or comment on an incident in the media or on social media. All media enquiries should be directed to the Marketing and PR team by emailing provide.marketing@nhs.net
Appendix 1: Process to categorise an IG incident
Step 1: Establish the scale of the incident. If this is not known, it will be necessary to estimate the maximum potential scale point.
Scoring
0 Information about less than 11 individuals 1 Information about 11-100 individuals 2 Information about 101-1000 individuals
3 Information about 1,001 – or more individuals
Step 2: Identify which sensitivity characteristics may apply and adjust the baseline scale point accordingly.
Sensitivity Factors (SF) modify baseline scale
Select as many sensitivity factors as are applicable to the incident Scoring
(A) No Sensitive personal data (e.g. Health Information) (as defined by the Data Protection Act 2018) at risk nor data to which a duty of confidence is owed

-1 for each
0 for each
(B) Information readily accessible or already in the public domain (e.g. Information equivalent to that found in a telephone directory) Limited demographic data at risk e.g. address/name not included
(C ) Information unlikely to identify individual(s)
(D) Security controls/difficulty to access data
(E) Basic demographic information at risk e.g. telephone number
(F) Detailed clinical information at risk e.g. clinical/care case notes, social care notes
(G) Failure to implement, enforce or follow up appropriate policy/safeguards to protect information e.g. failure to encrypt mobile technology
(H) Individual(s) affected are likely to suffer substantial damage or distress, including significant embarrassment or detriment
+1 for each
(I) Likely to attract media interest and/or a complaint has been made directly to the Information Commissioner by a member of the public, another organisation or an individual
(J) One or more previous incidents of a similar type in the past 12 months
(K) Particularly sensitive information at risk e.g. HIV, STD, Mental Health, Children/Young
Internal incident score of 2 and above is reportable to SIRO who will establish if the incident should be reported on the DSPT toolkit and ICO.
For Further Information please refer to the HSCIC Guidance: Checklist Guidance for Reporting, Managing and investigating Information Governance and Cyber Security Serious Incidents Requiring investigation
Appendix 2: Definitions /Glossary of Terms
Access System
Datix Incident System
Duty of Candour

Handler
Harm
Incident
Incident Review Panel
Electronic incident reporting and management utilising the Access Care Management System in Provide Group support at home services only
Datix Electronic incident reporting and management system utilising the Datix DCIQ system in all areas of the Provide Group except for support at home services which where the incident module in the Access Care Management system is utilised to record and manage the incident within the client record.
All health and social care organisations have a legal responsibility to be open and honest with people and their families when something goes wrong with their treatment or care and causes, or has the potential to cause, harm or distress. This includes saying sorry and taking action to put things right where possible
The person designated as the Handler of an incident reported on Datix or Access. They are the person who is responsible for managing the incident reported to ensure immediate steps are taken to support the people involved, ensuring appropriate care is provided. They then take action to review the incident to learn lessons and take action to prevent recurrence, escalating and reporting to senior managers where there is a risk of recurrence or where significant harm or death has occurred
Harm is the actual impact on a person from the particular incident being reported. This could be an injury (physical or psychological), disease, suffering, disability, or death. Harm is related directly to the incident and not related to the natural progression of an illness or underlying condition
Any event or circumstance arising that could have, or did, lead to unintended or unexpected harm, loss or damage to a person, property, or the organisation
This is a meeting for the incident handler and members of the Quality and Safety team to come together to review the circumstances of an incident that has a harm level of unknown or moderate recorded, Using their professional judgement they consider if an incident can be handled locally or if escalation to a more formal investigation is required to ensure the learning from the incident is achieved and quality improved
Information Governance Incident
Learning from Patient Safety Events (LFPSE):
An information governance incident is a suspected, attempted, successful, or imminent breach of security leading to the threat of or actual accidental, unlawful or unauthorised access to, use, disclosure, breach/loss, modification, or destruction of information, including personal information as defined by the UK’s data privacy regulations; interference with the operation of information systems; or a breach of information security policy or procedures, including the acceptable use of IT systems
The NHS require mandatory reporting of all NHS patient safety incidents to the national Learning from Patient Safety Events system which allows for national oversight and learning from patient safety incidents and the system can be viewed by NHS organisations to allow benchmarking of incidents as well as by the Care Quality Commission who can monitor themes and trends across services they regulate
Any event or circumstance that did not result in harm, loss, or damage, but had the potential to do so e.g. a person is nearly given someone else’s medicine but the second checker spots the mistake and takes action to prevent the medicine being given. Therefore, the incident did not occur, but had it occurred harm may have resulted.
Never Event
Notifiable safety incident
Never Events are defined as significant incidents that are wholly preventable because guidance or safety recommendations that provide strong systemic protective barriers are available at a national level and should have been implemented by all healthcare providers
This is a specific term defined in the duty of candour regulation. It should not be confused with other types of safety incidents or notifications. A notifiable safety incident must meet all 3 of the following criteria:
1. It must have been unintended or unexpected.
2. It must have occurred during the provision of an activity regulated by the CQC.
Near miss
Patient Safety Incident
Patient Safety Incident Response Framework (PSIRF)
Reporter
Safety Incident

Significant Incident
Significant Incident Review Group
3. In the reasonable opinion of a healthcare professional, already has, or might, result in death, or severe or moderate harm to the person receiving care
Something unexpected or unintended has happened, or failed to happen, that could have or did lead to patient harm
This is the national NHS framework that has replaced the NHS Serious Incident Framework which sets out a more proportionate and considered process to managing patient safety incidents in NHS contracted services. Refer to Provide Group policy QSPOL15 Patient Safety Incident Response Policy for more information
Person who identifies an incident and reports it onto Datix / Access system
Something unexpected or unintended has happened, or failed to happen, that could have or did lead to harm to a service user/ member of staff/ member of the public
An adverse event, where the consequences are so significant that a detailed response is justified. Examples are:
• Significant harm or death has occurred to service users as a result of care delivery or acts or omissions in care
• Significant harm or death has occurred to members of the public while visiting the organisation or to staff while undertaking their duties
• Test result errors affecting multiple people with the potential that one or more people have been harmed
• Multiple people are affected by the loss of, sharing of or inappropriate access to their personal data and the incident requires reporting and investigation in line with Information Commissioner guidelines
This is a meeting of senior managers to co-ordinate and oversee the investigation of significant incidents to ensure a robust investigation is undertaken to achieve learning from the incident
Appendix 3: Template Agenda for Initial SIRG
Agenda
Significant Incident Review Group Date & Time:

Item Agenda
1
• Welcome
• Declarations of Interest
2 Review of Events
• Incident to be investigated as a serious incident? Yes/ No
• Is this a NEVER Event Yes /No
3 Assess the level of harm
• Who has been harmed and to what level – is it confirmed
• Are others at risk of harm /potential risk of harm
• Agree process to track harm for all involved
4 Investigation Process
Agree how the investigation will be undertaken
Single investigator
Investigation Panel
External Investigator to be commissioned
External Agency e g NHS England, UKHSA, Coroner inquest, Police Investigation, HSE investigation or other.
5 Designate IO /Investigation Panel
• Identify an investigating officer or Investigation Panel (Chair and members of the panel to be identified)
6 TOR
• Agree Terms of Reference for the investigation
7 Involvement & Engagement
• Agree how the people involved will be informed, involved and engaged
• Confirm process for completing Duty Of Candour
8 Notifications
Identify who has been notified of the incident so far and consider who else needs to be notified who will complete the notifications
The Senior Leadership Team
The Care Quality Commission
The Health and Safety Executive
The Information Commissioners Office
The Commissioner for the service
UKHSA
MHRA
The Police
The Local Authority if there are Safeguarding concerns
other
9 Media
Consider if there is likely to be any media interest and agree management
10 Date and Time of next meeting:
Lead Papers
Appendix 4: Template Agenda for Patient Safety Incident Review Group
Agenda
Patient

Safety Incident Review Group
Date/Time:

Declarations of Interest 2 Review of Events
• Incident to be investigated as a Patient Safety Incident Investigation (PSII)? Yes/ No
• Is this a NEVER Event Yes /No
3 Assess the level of harm
• Who has been harmed and to what level – is it confirmed
• Are others at risk of harm /potential risk of harm
• Agree process to track harm for all involved
4 Investigation Process
Agree how the investigation will be undertaken:
Single investigator
Investigation Panel
How will the information be recorded:
Minutes
Briefing Pack
Other
External Investigator to be commissioned External Agency e.g. NHS England, UKHSA, Coroner inquest, Police Investigation, HSE investigation or other.
5 Designate IO /Investigation Panel
Identify an investigating officer or Investigation Panel (Chair and members of the panel to be identified)
6 TOR Agree Terms of Reference for the investigation
7 Involvement & Engagement
• Agree how the people involved will be informed, involved and engaged Confirm process for completing Duty of Candour
8 Notifications
Identify who has been notified of the incident so far and consider who else needs to be notified, who will complete the notifications.
The Senior Leadership Team
The Care Quality Commission
The Health and Safety Executive
The Information Commissioners Office
The Commissioner for the service
UKHSA
MHRA
The Police
The Local Authority if there are Safeguarding concerns
Other
9 Media
Consider if there is likely to be any media interest and agree management
EQUALITY IMPACT ASSESSMENT TEMPLATE
Stage 1: ‘Screening’
The Equality Impact Assessment needs to be completed so that any decisions made are compliant with the aims of the Public Sector Equality Duty – and that any adverse impact for any protected characteristics are identified and resolved.
Policy Title
Provide Group Incident Reporting and Management Policy
Provide a brief summary (bullet points) of the aims of the Policy
To set out the process and principles of how incidents will be reported, managed and investigated across the Provide Group
EQIA Assessor Name and Job Title
Bridgette Beal
Director Nursing & Allied Health Professions

Date of Assessment
11 October 2024
This stage establishes whether a proposed initiative will have an impact from an equality perspective on any particular group of people or community or whether it is “equality neutral” (i.e. have no effect either positive or negative)
Q1. Will this policy affect one of the following groups more or Less favourably than another?
Details
Group
Age
Consider impact and detail across age ranges on old and younger people. This can include safeguarding, consent and child welfare
Disability
Consider and detail impact on attitudinal, physical, and social barriers.
Sex
Consider and detail impact on men and women (potential to link to carers)
Gender reassignment (including transgender)
Consider and detail impact on transgender and transsexual people. This can include issues such as privacy of data and harassment.
Pregnancy and maternity
Consider and detail impact on working arrangements, part-time working, infant caring responsibilities.
If more or less, explain impact and any valid legal and/or justifiable exception. Include the source of any evidence
Q1. Will this policy affect one of the following groups more or Less favourably than another?
Details

Group
Race
Consider and detail impact on different ethnic groups, nationalities, Roma gypsies, Irish travellers, language and communication barriers.
Religion or belief
Consider and detail impact on people with different religions, beliefs or no belief.
Sexual orientation
Consider and detail impact on heterosexual people as well as lesbian, gay and bi-sexual people
Carers
Consider and detail impact on part-time working, shift-patterns, general caring responsibilities
Other identified groups
Consider and detail on different socioeconomic groups, area inequality, income, resident status (migrants) and other groups experiencing disadvantage and barriers to access.
Assessed Impact overall
Positive ✓ Neutral
Negative
Guidelines: Things to consider
Is the impact of the initiative – whether positive or negativesignificant enough to warrant a more detailed Stage 2 assessment?
If more or less, explain impact and any valid legal and/or justifiable exception. Include the source of any evidence
Yes ✓ No
• Equality impact assessments at Provide take account of relevant equality legislation and include age, (i.e. young and old,); race and ethnicity, gender, disability, religion and faith, and sexual orientation.
• The initiative may have a positive, negative or neutral impact, i.e. have no particular effect on the group/community.
• Where a negative (i.e. adverse) impact is identified, it may be appropriate to make a more detailed EIA (see Stage 2), or, as important, take early action to redress this – e.g. by abandoning or modifying the initiative. NB: If the initiative contravenes equality legislation, it must be abandoned or modified.
• Where an initiative has a positive impact on groups/community relations, the EIA should make this explicit, to enable the outcomes to be monitored over its lifespan.
• Where there is a positive impact on particular groups does this mean there could be an adverse impact on others, and if so can this be justified? - e.g. are there other existing or planned initiatives which redress this?

• It may not be possible to provide detailed answers to some of these questions at the start of the initiative. The EIA may identify a lack of relevant data, and that data-gathering is a specific action required to inform the initiative as it develops, and also to form part of a continuing evaluation and review process.
• It is envisaged that it will be relatively rare for full impact assessments to be carried out at Provide. Usually, where there are particular problems identified in the screening stage, it is envisaged that the approach will be amended at this stage, and/or setting up a monitoring/evaluation system to review a policy’s impact over time.
Stage 2

QUALITY IMPACT ASSESSMENT TEMPLATE
To be used where the ‘screening phase has identified a substantial problem/concern)
This stage examines the initiative in more detail in order to obtain further information where required about its potential adverse or positive impact from an equality perspective. It will help inform whether any action needs to be taken and may form part of a continuing assessment framework as the initiative develops.
Policy/ Project Title
EIA Assessor Name and Job Title Date of Assessment
EIA Review by Chief Officer name and Job Title Date Of Review
Outcome of Chief Officer Review
Q1. What data/information is there on the target beneficiary groups/communities?
Are any of these groups under- or over-represented? Yes No
Do they have access to the same resources? Yes No
What are your sources of data and are there any gaps?
Q2. Is there a potential for this initiative to have a positive impact, such as tackling discrimination, promoting equality of opportunity and good community relations? Yes No
If yes, how? Which are the main groups it will have an impact on?
Q3. Will the initiative have an adverse impact on any particular group or community/community relations? Yes No
If yes, in what way? Will the impact be different for different groups – e.g. men and women?
Q4. Has there been consultation/is consultation planned with stakeholders/ beneficiaries/ colleagues who will be affected by the initiative? Yes No
Summarise (bullet points) any important issues arising from the consultation
Q5. Given your answers to the previous questions, how will your plans be revised to reduce/eliminate negative impact or enhance positive impact?
Are there specific factors which need to be considered? Yes No

Q6. How will the initiative continue to be monitored and evaluated, including its impact on particular groups/ improving community relations? Where appropriate, identify any additional data that will be required
Guidelines: Things to consider
• An initiative may have a positive impact on some sectors of the community but leave others excluded or feeling they are excluded. Consideration should be given to how this can be tackled or minimised.
• It is important to ensure that relevant groups/communities are identified who should be consulted. This may require taking positive action to engage with those groups who are traditionally less likely to respond to consultations and could form a specific part of the initiative.
• The consultation process should form a meaningful part of the initiative as it develops and help inform any future action.
• If the EIA shows an adverse impact, is this because it contravenes any equality legislation? If so, the initiative must be modified or abandoned. There may be another way to meet the objective(s) of the initiative.