Attorney-Client Privilege in Healthcare Risk Management: What Actually Gets Protected

Attorney-client and peer review privilege don't automatically protect hospital risk management documents. Learn what courts actually require, including lessons from a December 2025 Kentucky Supreme Court ruling.

Learnsignal Education Team
6 min read
Updated

A patient safety incident happens, and within hours someone from risk management is writing it up. Six months later, a plaintiff's attorney requests that document in discovery — and whether it gets handed over can turn on details most clinical staff have never been told: who asked for the document to be written, what it was written for, and how it was labelled and routed internally. Attorney-client privilege and its close relatives (work-product protection, peer review privilege, and the federal patient safety work product privilege) are not automatic shields. Get the process wrong and a document meant to be protected becomes Exhibit A.

Three different protections, often confused as one

Healthcare risk management documents can potentially draw on three distinct legal protections, each with its own rules:

  • Attorney-client privilege and work-product doctrine. Protects communications made for the purpose of obtaining legal advice, and materials prepared in anticipation of litigation. This is the general common-law privilege that applies across industries, not something unique to healthcare.
  • State peer review privilege. A separate, state-law protection for records generated by a hospital's formal peer review process (credentialing committees, quality assurance committees) — the theory being that clinicians won't candidly evaluate each other's care if their evaluations can be used against them in court.
  • Federal patient safety work product (PSWP) privilege. Created by the Patient Safety and Quality Improvement Act of 2005 (PSQIA), this protects information collected and created specifically for reporting to a federally listed Patient Safety Organization (PSO). It is a genuinely separate, nationwide protection that exists independently of whatever peer review privilege a given state recognises.

A single incident report or root cause analysis might qualify for one, several, or none of these — and the requirements are not interchangeable.

Why incident reports so often lose privilege protection

Hospitals frequently assume any document routed through "risk management" is automatically privileged. Courts disagree. In Flynn v. University Hospital, an Ohio court confirmed that hospital incident reports can be protected by attorney-client privilege — but only when they are genuinely prepared for that purpose, not simply generated as routine paperwork. The hospital in that case struggled to show the report had actually gone to a peer review committee or been prepared for an attorney, which is exactly the kind of gap that defeats a privilege claim. The party asserting privilege carries the burden of proving it applies, and "we always write these up" is not, by itself, a legal purpose.

A 2025 case shows how fine the line is

The distinction between protected and unprotected documents was drawn sharply in Baptist Healthcare System v. Kitchen, decided by the Kentucky Supreme Court in December 2025. The Court held that the hospital's root cause analysis was fully protected as federal patient safety work product under PSQIA — because it was prepared specifically for reporting to a patient safety organisation, and the Court rejected the plaintiff's argument that the underlying facts inside it could be pulled out and disclosed separately. The entire document stayed privileged.

But the same hospital's incident report, covering the same event, was not protected. Because it was created immediately after the incident to satisfy a routine regulatory requirement — not as part of a deliberate, reflective safety review — it lacked the purpose and timing that both PSQIA and Kentucky's peer review statute require. Same hospital, same underlying event, two different outcomes, because one document was built for legal/safety-review purposes and the other was built to tick a compliance box.

What this means for how documents actually get created

The practical lesson isn't "write less down" — under-documentation creates its own investigation and documentation risk. It's that the same underlying facts often need to live in two different documents with two different purposes, clearly labelled as such:

  • A contemporaneous incident report, completed promptly to meet regulatory and internal reporting obligations. Treat this as likely discoverable and write it as pure fact — what happened, who was involved, what immediate action was taken — without speculation, blame, or legal conclusions.
  • A separate root cause analysis or peer review record, initiated deliberately for safety-improvement or PSO-reporting purposes, ideally at the direction of legal counsel or the designated patient safety officer, and clearly documented as such from the outset rather than relabelled after the fact.

Mixing the two — writing legal conclusions and blame assessments into the same document that also serves as the routine incident log — is one of the most common ways hospitals accidentally waive protection they could otherwise have had.

Building this into risk management training

Frontline staff and risk managers don't need to become lawyers, but they do need to understand three practical rules: never guess at fault or write legal conclusions into a routine incident report; know which internal process (peer review committee, PSO reporting, legal department referral) a given document is being prepared for before writing it; and involve legal counsel or the compliance/risk management lead early when an event is serious enough that litigation is a realistic possibility. This connects directly to the wider culture-of-compliance work healthcare organisations are already doing, and to open disclosure practice, since what gets disclosed to a patient and what gets protected internally are governed by different rules and shouldn't be conflated by staff handling both.

Frequently asked questions

Does labelling a document "privileged and confidential" make it privileged?
No. Courts look at the actual purpose and process behind a document, not its header. A routine report stamped "confidential" that was never prepared for legal advice or a peer review process will still be ordered produced.

Is peer review privilege the same in every state?
No — peer review privilege is created by state law, and its scope, exceptions, and what qualifies as a "peer review committee" vary significantly by state. Federal PSWP privilege under PSQIA is the one nationwide protection that applies consistently, provided the PSO-reporting requirements are met.

Who should decide whether a document is prepared for legal purposes?
Ideally legal counsel or the risk management/compliance lead, involved early and specifically for that purpose — not left to whichever staff member happens to be documenting the incident.

Getting this distinction right protects both patient safety improvement work and the organisation's legal position — and it's a gap most general compliance training doesn't cover. Learnsignal's CPD training library includes risk management and compliance training for healthcare organisations navigating exactly this kind of legal complexity.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Healthcare Compliance & CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans