{{org_field_logo}}
{{org_field_name}}
Registration Number: {{org_field_registration_no}}
Notification of Other Incidents Policy
1. Purpose
The purpose of this policy is to establish a clear and structured approach for the notification, reporting and management of incidents that may impact service users, staff, visitors and the overall operation of {{org_field_name}}.
Ensuring timely and accurate reporting allows for appropriate investigation, risk mitigation and regulatory compliance with the Care Quality Commission (CQC), Health and Safety Executive (HSE), Information Commissioner’s Office (ICO), local authorities and other relevant statutory bodies.
This policy implements the statutory notification duties contained within the Care Quality Commission (Registration) Regulations 2009, including:
- Regulation 16 – Notification of death of a service user.
- Regulation 17 – Notification of death or unauthorised absence of a service user who is detained or liable to be detained under the Mental Health Act 1983.
- Regulation 18 – Notification of other incidents.
- Regulation 22A – Form of notifications to the Commission.
It also supports compliance with:
- Regulation 20 – Duty of Candour under the Health and Social Care Act 2008 (Regulated Activities) Regulations 2014.
- Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 (RIDDOR).
- UK GDPR personal data breach reporting requirements.
- Adult safeguarding requirements under the Care Act 2014.
- Working Together to Safeguard Children 2026 statutory guidance, where the organisation provides services to children or otherwise has relevant safeguarding responsibilities.
- Appropriate outbreak escalation to the UK Health Security Agency (UKHSA).
By implementing this policy, {{org_field_name}} aims to foster a culture of transparency, accountability, learning and continuous improvement, ensuring that incidents requiring internal or external notification are identified, managed and reported appropriately.
2. Scope
This policy applies to:
- All employees, including care workers, administrative staff, and management.
- Service users and their families, ensuring their rights and safety.
- Visitors, contractors, and third-party service providers.
- Regulatory bodies and local authorities, ensuring compliance and cooperation in investigations.
It covers:
- What constitutes a reportable incident.
- The process of notification and reporting.
- Investigation and follow-up procedures.
- Corrective actions and risk prevention.
- Compliance monitoring and continuous improvement.
3. Legal and Regulatory Framework
This policy aligns with the following legal and regulatory requirements:
- Care Quality Commission (Registration) Regulations 2009 – including:
- Regulation 16 – Notification of death of a service user.
- Regulation 17 – Notification of death or unauthorised absence of a service user who is detained or liable to be detained under the Mental Health Act 1983.
- Regulation 18 – Notification of other incidents.
- Regulation 22A – requiring statutory notifications to be made using the forms provided by the CQC.
- Health and Social Care Act 2008 (Regulated Activities) Regulations 2014 – including Regulation 20 (Duty of Candour).
- Reporting of Injuries, Diseases and Dangerous Occurrences Regulations 2013 (RIDDOR) – employer and responsible-person duties concerning specified work-related deaths, injuries, occupational diseases and dangerous occurrences, including applicable reporting timescales.
- Data Protection Act 2018 and UK General Data Protection Regulation (UK GDPR), as amended – including requirements to assess and record personal data breaches, notify the ICO within 72 hours where the statutory threshold is met, where feasible, and communicate a breach to affected individuals without undue delay where it is likely to result in a high risk to their rights and freedoms.
- Care Act 2014, including Section 42, and the Care and Support Statutory Guidance – adult safeguarding duties and multi-agency working.
- Working Together to Safeguard Children 2026 – statutory multi-agency safeguarding guidance applicable in England where {{org_field_name}} provides services to children or otherwise has relevant responsibilities for safeguarding and promoting the welfare of children.
- Mental Capacity Act 2005 and applicable deprivation of liberty requirements – including statutory CQC notification requirements concerning relevant deprivation of liberty applications and outcomes where applicable.
- CQC’s current assessment framework – including relevant Safe and Well-led quality statements concerning learning culture, safeguarding, incident management, governance and statutory notifications.
- Current UK Health Security Agency guidance – concerning the identification, management and escalation of communicable disease outbreaks and other situations requiring health protection advice.
4. Definition of Reportable Incidents
Incidents that must be reported include but are not limited to:
- Service User Safety Incidents:
- Unexplained injuries, significant changes in condition, or unexpected hospitalisation.
- Medication errors leading to harm or risk.
- Falls, burns, or other accidents occurring during care provision.
- Any safeguarding concerns or suspected abuse.
- Development after starting to use our service of a pressure ulcer of grade 3 or above.
- Use of restraint resulting in, or with potential to cause, injury that meets Regulation 18 thresholds (for example, fractures or prolonged pain/psychological harm).
- Staff-Related Incidents:
- Workplace injuries, assaults, or significant health concerns.
- Allegations of misconduct or breaches of professional conduct.
- Exposure to infectious diseases or hazardous materials.
- Environmental and Operational Incidents:
- Power outages, equipment failures, or disruptions affecting service delivery.
- Breaches of security, including unauthorised access to service users’ homes.
- Fire incidents, flooding, or structural hazards in service locations.
- Personal Data Breaches (UK GDPR):
- Assess and log all personal data breaches; notify the ICO within 72 hours of becoming aware if the breach risks individuals’ rights and freedoms (you may submit details in phases).
- Where there is high risk to individuals, inform affected people without undue delay and record decisions/actions taken.
Incidents requiring CQC notification under Regulation 18
- Serious injury in the reasonable opinion of a healthcare professional, resulting in: permanent or ≥28-day sensory/motor/intellectual impairment; structural changes to the body; prolonged pain or psychological harm (≥28 days); or shortened life expectancy.
- Injury requiring treatment by a healthcare professional to prevent death or any of the harms listed above.
- Any abuse or allegation of abuse linked to our regulated activity.
- Any incident reported to, or investigated by, the police.
- Events that prevent or threaten safe operation of the regulated activity, including:
- insufficient suitably qualified/skilled staff;
- interruption of electricity/gas/water/sewerage >24 hours;
- physical damage to premises affecting care;
- failure/malfunction of fire alarms or other safety devices >24 hours.
Mental Capacity and DoLS (adults)
- Notify CQC of the outcome (or withdrawal) of any DoLS request or Court of Protection application once known. (Do not notify intention to apply.)
Medicines and Medical Devices
Report suspected adverse drug reactions or medical device incidents via the MHRA Yellow Card scheme; also follow local clinical governance routes.
5. Notification and Reporting Procedures
To ensure immediate action and regulatory compliance, all accidents, incidents, safeguarding events and other potentially notifiable events must be:
- Reported as soon as possible to the Registered Manager or designated Incident Lead.
- Recorded in the Incident Report Log, including the date, time, location, individuals involved and a factual account of the event.
- Assessed to determine whether an external statutory notification or referral is required.
- Escalated without delay where immediate risks to a service user, staff member or other person remain.
CQC Statutory Notifications
The Registered Manager or authorised delegate will assess incidents against the Care Quality Commission (Registration) Regulations 2009.
Notifications required under Regulation 18 must be submitted without delay.
Relevant Regulation 18 notifications include, where applicable:
- Serious injury to a person using the service.
- Abuse or allegations of abuse involving a service user.
- Incidents reported to, or investigated by, the police.
- Events that prevent, or appear likely to threaten, the provider’s ability to continue carrying on the regulated activity safely or in accordance with registration requirements.
- Insufficient suitably qualified, skilled and experienced staff where this threatens safe service delivery.
- Relevant interruptions of electricity, gas, water or sewerage lasting more than 24 continuous hours at premises owned or used by the provider for carrying on the regulated activity.
- Relevant physical damage to premises affecting care.
- Failure or malfunction of fire alarms or other safety devices for more than 24 continuous hours where the statutory criteria apply.
- Serious injuries meeting the criteria set out in Regulation 18 and current CQC guidance, including relevant grade 3 or above pressure ulcers that develop after a person has started to use the service.
Notifications will be made using the current CQC Provider Portal or current statutory CQC notification form and submission route, as applicable.
In accordance with Regulation 22A, the organisation will use the notification form or process provided by the CQC for the relevant notification type.
Deprivation of Liberty Notifications
Where applicable, the Registered Manager will ensure that the CQC is notified of the outcome of a relevant request for a standard authorisation or relevant Court of Protection application concerning deprivation of liberty once the outcome is known.
Where such a request or application is withdrawn, notification will be made at the point of withdrawal.
The organisation will not submit a CQC notification merely because there is an intention to make an applicable request or application.
Safeguarding
Where an adult safeguarding concern meets the applicable threshold, it will be referred to the relevant local authority in accordance with the Care Act 2014 and local safeguarding procedures.
Where children or young people are involved, safeguarding concerns will be managed in accordance with Working Together to Safeguard Children 2026, applicable local safeguarding partnership arrangements and other relevant statutory requirements.
Relevant local contacts include:
- Adult safeguarding authority: {{org_field_local_authority_authority_name}}
- Adult safeguarding contact: {{org_field_local_authority_phone_number}}
- Children’s safeguarding authority: {{org_field_children_safeguarding_local_authority_authority_name}}
Where there is reason to believe that a criminal offence has been committed or there is an immediate risk of harm, the police will be contacted as appropriate.
RIDDOR – Health and Safety Executive
Where an event meets the statutory criteria under RIDDOR 2013, the responsible person will ensure that the appropriate report is made to the relevant enforcing authority.
Applicable reporting requirements include:
- Deaths and specified injuries must be notified without delay and the statutory report submitted within the applicable period.
- Most reportable accidents must be reported within 10 days.
- Over-seven-day incapacitation must be reported within 15 days of the accident.
- Reportable injuries to non-workers must meet the applicable statutory criteria, including arising from a work-related accident and resulting in the person being taken directly from the scene to hospital for treatment.
- Relevant dangerous occurrences and occupational diseases will be reported in accordance with RIDDOR requirements.
UKHSA – Infectious Disease and Outbreaks
Where a suspected or confirmed outbreak or other situation requires health protection advice or notification, {{org_field_name}} will promptly contact the appropriate local UKHSA Health Protection Team in accordance with current guidance.
Relevant details will be maintained and kept accessible:
- Telephone: {{org_field_outbreaks_support_local_health_protection_team_phone_number}}
- Email: {{org_field_outbreaks_support_local_health_protection_team_email}}
- Website: {{org_field_outbreaks_support_local_health_protection_team_website}}
Personal Data Breaches – ICO
All personal data breaches must be identified, contained, assessed and recorded.
Where a breach is likely to result in a risk to the rights and freedoms of individuals, {{org_field_name}} will notify the Information Commissioner’s Office without undue delay and, where feasible, within 72 hours of becoming aware of the breach.
Where a personal data breach is likely to result in a high risk to individuals’ rights and freedoms, affected individuals will be informed without undue delay unless an applicable legal exception applies.
All personal data breaches will be documented, including those that do not require notification to the ICO.
MHRA
Suspected adverse drug reactions and applicable medical device incidents will be reported through the MHRA Yellow Card scheme where appropriate, in addition to internal reporting and any other applicable regulatory or clinical reporting requirements.
Internal Regulatory Triage
Potentially notifiable incidents will be reviewed promptly by the Registered Manager or authorised delegate to determine:
- Which external reporting or referral requirements apply.
- The applicable statutory timescale.
- Which notification form or reporting route must be used.
- Whether safeguarding, police, HSE, CQC, ICO, UKHSA, MHRA or commissioner reporting is required.
- Whether Duty of Candour applies.
Where a statutory requirement states that notification must be made without delay, internal review procedures must not delay the statutory submission.
Duty of Candour
Where an incident meets the statutory definition of a notifiable safety incident under Regulation 20, {{org_field_name}} will:
- Notify the relevant person as soon as reasonably practicable.
- Provide a truthful account of the facts known at the time.
- Explain what further enquiries or investigations will be undertaken.
- Offer an apology.
- Provide reasonable support.
- Provide the required written follow-up.
- Maintain appropriate records demonstrating compliance with the Duty of Candour.
The wider duty to act openly and transparently applies regardless of whether an incident meets the specific notifiable safety incident threshold.
6. Investigation and Follow-Up Procedures
Each incident undergoes a structured investigation process to ensure root causes are identified and preventive actions are taken. The investigation follows these steps:
- Step 1: Initial Response and Containment
- Immediate actions taken to ensure the safety of service users and staff.
- Temporary control measures implemented if ongoing risks exist.
- Step 2: Gathering Evidence
- Collection of statements from witnesses and affected individuals.
- Review of CCTV (if applicable), records, and environmental conditions.
- Analysis of related care plans, risk assessments, or medication logs.
- Step 3: Root Cause Analysis
- Identification of the contributing factors leading to the incident.
- Assessment of whether procedural failures, environmental hazards, or human error played a role.
- Step 4: Reporting Findings and Actions
- Compilation of an incident report detailing findings and recommended actions.
- Submission of reports to external regulatory bodies where necessary.
- Communication of outcomes to affected service users, families, and staff.
- Include statutory notifications and candour actions in the report. Record CQC notification reference(s), HSE/ICO/MHRA submissions where relevant, and evidence of Duty of Candour discussions and written correspondence.
7. Corrective Actions and Risk Prevention
To prevent recurrence of incidents, corrective actions may include:
- Policy or procedural amendments to address gaps in care delivery.
- Staff retraining or competency assessments.
- Implementation of additional safety measures such as enhanced risk assessments.
- Equipment maintenance and improvements to eliminate hazards.
- Supervision or disciplinary actions where negligence or misconduct is identified.
Share learning and track it (de-identified) through team meetings and the risk register; cross-reference to the CQC Single Assessment Framework quality statements for Safe and Well-led.
8. Compliance Monitoring and Continuous Improvement
To maintain high safety standards and regulatory compliance, {{org_field_name}}:
- Quarterly audits of all statutory notifications (CQC/HSE/ICO/UKHSA/MHRA): check completeness, timeliness (“without delay”, 72-hour/10-day/15-day rules) and evidence of feedback/learning; report outcomes to the Nominated Individual and governance meetings.
- Implements corrective measures based on investigation findings.
- Engages with staff, service users, and regulatory agencies to gather feedback for continuous improvement.
- Regularly updates this policy in response to regulatory changes and best practices.
- Maintain up-to-date access to the CQC provider portal and current forms/templates (Reg 22A), and keep local outbreak contact details current.
9. Policy Review and Updates
This policy will be reviewed at least annually, or sooner where necessary, to ensure that it remains accurate, effective and consistent with current legislation, CQC requirements and other applicable statutory reporting arrangements.
An earlier review will be undertaken where:
- The Care Quality Commission (Registration) Regulations are amended.
- CQC changes its statutory notification requirements, forms, Provider Portal functionality or submission routes.
- RIDDOR legislation or HSE reporting requirements change.
- Safeguarding legislation or statutory guidance changes.
- UK GDPR, the Data Protection Act 2018 or ICO breach-reporting requirements change.
- UKHSA outbreak reporting or escalation arrangements materially change.
- MHRA reporting requirements relevant to the service change.
- A serious incident identifies weaknesses in the organisation’s notification or escalation arrangements.
- An audit identifies late, incomplete, missed or unnecessary statutory notifications.
- CQC, HSE, the ICO, a local authority or another statutory body identifies concerns about the organisation’s reporting arrangements.
- The policy is found to be unclear, ineffective or no longer reflective of current practice.
The Registered Manager is responsible for ensuring that this policy is reviewed, updated and approved as required.
As part of the review process, {{org_field_name}} will consider:
- CQC statutory notification records.
- Incident and accident reports.
- Safeguarding referrals.
- RIDDOR reports.
- Personal data breach records and ICO notifications.
- Outbreak notifications and UKHSA communications.
- MHRA reports where applicable.
- Duty of Candour records.
- Findings from audits and governance reviews.
- Regulatory feedback and inspection findings.
- Changes in legislation and statutory guidance.
- Trends in missed, delayed or incorrectly submitted notifications.
Any amendments made to this policy will be:
- Recorded with the date of review and, where appropriate, a summary of the changes made.
- Approved by the appropriate responsible person within {{org_field_name}}.
- Communicated to relevant staff.
- Reflected in incident-reporting forms, escalation procedures and regulatory notification processes where necessary.
- Incorporated into staff training, supervision or competency assessment where required.
All staff are responsible for following the current version of this policy and for escalating potentially notifiable events promptly.
{{org_field_name}} will use findings from statutory notification audits, incidents, regulatory feedback and policy reviews to improve the accuracy, timeliness and effectiveness of its reporting arrangements.
Responsible Person: {{org_field_registered_manager_first_name}} {{org_field_registered_manager_last_name}}
Reviewed on: {{last_update_date}}
Next Review Date: {{next_review_date}}
Copyright © {{current_year}} – {{org_field_name}}. All rights reserved.