Taxonomy · eight mechanisms · eight measurable proxies · compiled

Administrative Harm

Nobody made a clinical error. The patient was harmed anyway. No reporting system in health care is designed to capture it

Delay, denial, documentation burden, credentialing error, directory error, automated decision, regulatory lag, fragmentation. Each mechanism is defined separately, with the administrative act, the clinical pathway, why it escapes detection, and a measurable proxy that institutions already hold the data for. The page also states the attribution standard the category must meet, and the strongest argument against it.

Policy analysis by Kanwar Partap Singh Gill, MD · compiled · educational analysis, not legal advice.

Harm that arrives through paperwork

Patient safety, as a field, was built around a particular picture of harm: something happens to a patient in a clinical setting, at an identifiable moment, at the hands of an identifiable clinician or a failing piece of equipment. That picture produced incident reporting, root cause analysis, morbidity and mortality review, never-event lists and the whole apparatus of modern quality improvement. It works, and it is incomplete.

The incomplete part is harm that arrives through administration. A treatment that was never refused but never authorised. A referral that existed on paper and never produced an appointment. A medicine that was covered last year and is excluded this year. A physician who cannot see patients for four months because an enrolment file sat in a queue. A rule that arrived three years after the practice it was written to govern had already changed.

Nobody made a clinical error. The patient was harmed anyway. And no reporting system in health care is designed to capture it.

Program item 130, and the third piece of tranche 2. It completes a set: who actually decides maps where authority sits; the regulatory cascade maps where consequence goes; this page asks what the administration of health care does to the people inside it. Like both companions, it is an analytic map rather than a dataset, and it claims no frequencies.

Defining the category

A definition is needed first, because a category this broad becomes useless if it is allowed to mean any bad experience with a health system.

Working definition

Administrative harm is injury to a patient, or to a physician’s capacity to care for patients, produced by the operation of an administrative process rather than by a clinical act or omission — where the process performed as designed, or failed in a way its own controls did not detect.

Four elements do the work in that sentence, and each excludes something.

Element one

Injury, not inconvenience

A delayed appointment that changes nothing is friction. A delayed appointment that allows a treatable condition to progress is harm. The category requires a consequence, not an irritation.

Element two

Produced by process, not by clinical judgement

If a physician chose wrongly, that is clinical error and existing systems address it. This category covers the cases where clinical judgement was sound and never reached the patient.

Element three

The process worked as designed, or failed undetected

This is the element that distinguishes administrative harm from ordinary administrative failure. A queue that produces a four-month wait because it was built to produce a four-month wait is functioning. The harm is designed in.

Element four

Attributable to a process, not to a person

Which is precisely why it is unreported. Every reporting system in health care asks who did it.

That last element is the whole difficulty, and it deserves stating plainly rather than as a complaint: the infrastructure of patient safety is organised around agency, and administrative harm has no agent.

Why it is not measured

Six structural reasons, none of them conspiratorial. Each is an ordinary consequence of how the systems were built.

Reason one

No reporting form has a field for it

Incident reports ask what happened to the patient during care. A harm that consists of care not happening has no event to report and no location to report it from.

Reason two

The harm and the decision sit in different institutions

The denial is made by a payer. The deterioration presents at a clinic. Neither institution holds both halves, and no one is obliged to join them.

Reason three

Latency defeats attribution

Weeks or months separate the administrative act from the clinical consequence, which is long enough for the causal link to become arguable and therefore ignorable.

Reason four

The counterfactual is unobservable

What would have happened with timely authorisation is a clinical judgement about an alternative history. That is hard, and hard is treated as unknowable.

Reason five

The denominator is missing

How many authorisations were delayed, and of those how many mattered? Neither figure is published. Case counts without denominators is the standing analysis.

Reason six

Nobody owns the measurement

A hospital measures its own clinical outcomes. A payer measures its own turnaround. No institution is accountable for the interaction between them, so the interaction is where the harm accumulates unrecorded.

A harm with no form to report it on, no institution that holds both halves, and no denominator does not appear in any dataset. Its absence from the evidence is a fact about the measurement apparatus, not about the world.

1 · Delay

Mechanism 01Delay

Administrative act

A queue: authorisation, referral, scheduling, enrolment, records transfer

Clinical pathway

Time-dependent conditions progress on their own schedule while the queue runs on its own

Who observes it

The patient, and the treating physician. Neither is asked

Why undetected

The process completed. It simply completed late, and lateness is not an adverse event in any reporting taxonomy

Measurable proxy

Interval from order to service, distributed rather than averaged — the tail is the harm

The purest form of the category, because nothing is refused. Every actor performs their role, the authorisation is granted, the referral is accepted, the appointment is offered. The only variable is elapsed time, and elapsed time is the one thing clinical medicine cannot treat as neutral: a condition that is time-dependent converts administrative duration directly into clinical outcome.

The analytical point is about distributions rather than averages. A median turnaround of two days is compatible with a tail of six weeks, and the tail is where the harm lives. Any measure reported as a mean is structurally incapable of detecting this mechanism, which is a reason to be suspicious of turnaround statistics that appear reassuring.

Related: the prior authorisation dossier.

2 · Denial

Mechanism 02Denial, and the appeal that is theoretically available

Administrative act

A coverage determination against the treating physician’s recommendation

Clinical pathway

Substitution, abandonment or delay of the recommended plan

Who observes it

The patient. Frequently not the payer, which sees a closed file rather than an outcome

Why undetected

A denial upheld on no appeal is recorded as a correct decision. A denial abandoned without appeal is recorded as no decision at all

Measurable proxy

Appeal rate, reversal rate on appeal, and — the missing figure — the abandonment rate

The appeal ladder is real and is the strongest available answer to a wrong denial. Its existence is also what makes the mechanism invisible: because a remedy exists, an unremedied denial is treated as an accepted one. The unexamined quantity is how many denials are simply abandoned, by patients or by practices without the administrative capacity to pursue them.

A reversal rate is a two-edged statistic and should be read carefully in both directions. A high reversal rate on appeal means the initial determinations were unreliable. A low one may mean they were sound — or that only the strongest cases were appealed. Neither reading is available without knowing how many were abandoned, and that figure is not published anywhere.

3 · Documentation burden

Mechanism 03Documentation burden

Administrative act

Recording, coding, attestation and justification requirements, accumulated from many sources

Clinical pathway

Clinician attention is finite. Time spent on documentation is time not spent on the patient or on thinking

Who observes it

Every clinician. It is the most universally experienced mechanism and among the least documented as harm

Why undetected

No single requirement is unreasonable. The burden is cumulative, and nothing measures cumulative burden

Measurable proxy

Documentation time per encounter; after-hours record time; requirements per encounter by source

The distinctive feature here is that no actor imposed the burden. A payer added a justification field; a regulator added an attestation; an accreditor added a checklist; a health system added a template; a quality programme added a measure. Each was defensible on its own. Nobody was responsible for the total, and the total is what changes clinical practice.

This mechanism also produces a second-order harm the corpus treats separately: documentation designed for billing and compliance rather than for clinical communication degrades the record as a clinical instrument. The note becomes longer and less useful, which is a patient-safety consequence disguised as an efficiency complaint. Related: the healthcare AI dossier, on what happens when generated text is added to this pressure.

4 · Credentialing and enrolment error

Mechanism 04Credentialing and enrolment error

Administrative act

A verification, privileging or payer-enrolment process that stalls, errs or is not completed

Clinical pathway

A physician who is licensed, competent and willing cannot see patients, or cannot be paid for seeing them

Who observes it

The physician and the unseen patients, who are by definition never counted

Why undetected

The harm is capacity that never existed. There is no patient record for an appointment that was never available

Measurable proxy

Days from complete application to effective date; error and rework rates; the number of clinical sessions foregone

The clearest case of harm to patients caused by a process that never touches a patient. It is also the mechanism where the counterfactual is unusually solid: a physician credentialed in thirty days rather than one hundred and twenty has ninety days of clinical capacity that otherwise did not exist. The arithmetic does not require a theory of causation.

The recurring aggravating feature is duplication. The same primary source is verified independently by a hospital, several payers, an employer and a carrier, each on its own cycle, each asking the physician to supply the same documents again. Section 805.5 obliges institutions to query the licensing board before granting or renewing privileges, and the federal data bank is queried in parallel — so the verification architecture is duplicative by design rather than by neglect. Related: recredentialing and continuous monitoring.

5 · Network and directory error

Mechanism 05Network and directory error

Administrative act

A published directory that does not match reality — wrong network status, wrong panel status, wrong location, wrong specialty

Clinical pathway

A patient selects a physician who cannot see them, is not accepting patients, or is not in network. The attempt consumes the patient’s time and may consume their willingness to try again

Who observes it

The patient, at the point of failure

Why undetected

A failed attempt to obtain care generates no clinical record anywhere

Measurable proxy

Directory accuracy audits; appointment availability testing; unmatched referral rates

A small error with a large multiplier, because it operates at the moment of a patient’s decision to seek care. The patient who calls three listed physicians and reaches none of them has not been denied anything. They have simply learned that the system does not work, and that lesson is more durable than any single appointment.

It is worth naming what makes this mechanism structurally different from the others: the harm falls entirely on the patient, and no institution in the chain experiences any consequence from it at all. A directory error costs its publisher nothing.

6 · Automated decision

Mechanism 06Automated decision

Administrative act

An algorithmic or rules-based determination applied at volume — coverage, eligibility, risk stratification, prior authorisation triage

Clinical pathway

Whatever the determination governs, applied consistently and at scale

Who observes it

Individually, the patient. In aggregate, potentially nobody

Why undetected

Automated decisions are consistent, and consistency reads as correctness. A systematic error produces no outliers to investigate

Measurable proxy

Override and reversal rates; subgroup analysis of outcomes; the volume of determinations made without individual review

This mechanism inverts the usual relationship between error and detection. Human error is variable, and variability is what quality systems are built to notice. An automated error is uniform: every affected case is affected identically, so nothing stands out, and the very feature that makes automation attractive makes its failures invisible to outlier-based monitoring.

The consequence for oversight is specific. A system that reviews exceptions cannot detect a fault in the rule, because a faulty rule generates no exceptions. Detecting it requires auditing the rule itself, on subgroup outcomes rather than on individual complaints — which is a different kind of oversight from anything currently in place. Related: the reform proposal on algorithmic denial and AI and the practice of medicine.

7 · Regulatory lag

Mechanism 07Regulatory lag

Administrative act

A rule, guideline or coverage policy that arrives after the practice it governs has changed — or does not arrive

Clinical pathway

Either a superseded standard is enforced, or a genuinely novel practice operates with no standard at all

Who observes it

Clinicians, who experience it as a rule that does not fit the medicine

Why undetected

The absence of a rule is not an event, and nothing schedules a review of what has not been written

Measurable proxy

Interval from evidence publication to guideline revision to coverage change to practice change

Lag cuts in both directions, which is why it belongs in this taxonomy rather than in a general complaint about regulators. An outdated rule enforced against current practice is harm. A novel practice operating with no applicable standard is also harm, and the second is increasingly the more common of the two.

The measurable version of this mechanism is one of the more tractable items in the program: the evidence-to-practice interval is composed of dated stages, each of which leaves a dated document. Related: forecasts, which exists to state expectations about that interval before the fact rather than after.

8 · Fragmentation and handoff

Mechanism 08Fragmentation and handoff

Administrative act

Care distributed across institutions with no shared record, no shared accountability and no owner of the interval between them

Clinical pathway

A result, referral or plan is generated by one institution and never actioned by another

Who observes it

Ideally the primary physician, if the information reaches them at all

Why undetected

Every institution completed its own task correctly. The failure lives in the space between tasks, which nobody’s quality system covers

Measurable proxy

Referral loop closure rate; proportion of results acknowledged and actioned; time to closure

The mechanism with the clearest ownership problem. A result is produced correctly, transmitted correctly and received correctly, and nothing happens next, because the duty to act sat with whoever was supposed to be looking and nobody was designated. Each institution passes its own audit.

Loop closure is the single most useful measure in this entire taxonomy, because it is defined at the level of the patient rather than the institution: was the thing that was supposed to happen next actually done? Institutions do not measure it, and the reason they do not is structural rather than negligent — the measure spans the boundary each institution’s audit stops at.

The second patient

The definition at the top of this page includes harm to a physician’s capacity to care for patients, and that inclusion is deliberate rather than sentimental. It rests on a chain that is short and hard to dispute.

Step one

Administrative process consumes clinical attention

Documentation, authorisation, appeals, credentialing, enrolment, compliance training and reporting each take time from a finite budget.

Step two

Attention is the substrate of clinical judgement

Reduced attention degrades diagnostic reasoning, communication and error detection. This is not a moral claim; it is a claim about cognitive capacity under load.

Step three

Degraded judgement reaches patients

At which point the harm becomes clinical, and the existing patient-safety apparatus records it — attributed to the clinician.

Step four

The attribution lands in the wrong place

The event is recorded as a clinical error by an individual. Its administrative origin is not a field on the form, so it is not recorded at all.

An administrative burden becomes a clinical error, and the clinical error becomes the physician’s record. The mechanism converts a system problem into an individual one, and the conversion is invisible in every dataset that matters.

This is where the category connects to the rest of the corpus. A physician facing a peer-review or licensing matter arising from an event with an administrative origin is answering, individually and on the record, for a condition created upstream — and the forum that decides has no mechanism for hearing that. In California hospital peer review the institution at least carries the burden of showing its action is reasonable and warranted under B&P Code §809.3(b)(3), which makes context admissible in a way it is not elsewhere. Related: who actually decides, the regulatory cascade, fitness for duty against discipline, and physician wellness programmes, which examines what happens when a structural condition is offered an individual remedy.

The attribution problem

This category is only as credible as its discipline about causation, and the temptation it invites is obvious: to treat every bad outcome preceded by paperwork as caused by the paperwork. That would be the same error the category exists to criticise, run in the opposite direction.

So the standard applied here is explicit. Four conditions, all of which must hold before a case is described as administrative harm rather than as an outcome that happened to involve administration.

01

A specific administrative act is identified

Named, dated, and attributable to a process rather than inferred from a bad result.

02

A clinical pathway is stated

The mechanism by which that act could affect the outcome, articulated in advance rather than reconstructed afterwards.

03

The counterfactual is examined honestly

What would probably have happened otherwise, with the uncertainty stated. Where the counterfactual cannot be assessed, the case is recorded as unassessable rather than as harm.

04

Clinical explanations are excluded first

Disease progression, comorbidity, patient decision and clinical error are considered before an administrative cause is asserted. The category is a residual, not a default.

The honest position is that individual attribution is hard and population-level attribution is more tractable. Whether a particular delay harmed a particular patient is often unknowable. Whether a distribution of delays produces harm across a population is an ordinary empirical question, and it is the one worth asking.

The strongest case against this category

A page proposing a new category of harm should state the best argument against it, and this one is serious.

The objection

Administrative processes exist for reasons. Utilisation review restrains genuinely unnecessary and sometimes harmful treatment. Credentialing verification prevents unqualified practice, and the corpus documents in detail why that verification matters. Documentation requirements exist because undocumented care cannot be audited, coordinated or defended. Coverage rules allocate finite resources, and a system with no allocation rules is not a fairer system — it is one that allocates by other means, usually to the advantage of whoever can navigate it best. Calling the friction produced by these processes harm risks reasoning backwards from a preferred policy conclusion.

Three of those propositions are simply correct, and this page accepts them. The response is not that oversight is bad. It is narrower, and it concedes the objection’s premise:

Response one

A process having a purpose does not exempt it from measurement

Utilisation review may be net beneficial and still produce a measurable tail of harm. Both can be true at once, and only one of them is currently counted.

Response two

The burden of the process should be attributed to the process

Where a requirement produces a cost, that cost belongs in the ledger of the requirement rather than in the record of the clinician who absorbed it. This is an accounting objection, not an ideological one.

Response three

Asymmetric measurement is the actual complaint

The benefits of administrative processes are measured, published and cited by the bodies that operate them. The costs are diffuse, fall on people with no reporting channel, and are measured by nobody. A category that makes the second half countable does not presume the answer — it makes the comparison possible for the first time.

The claim is not that oversight causes harm. It is that the cost side of oversight is unmeasured, and that an unmeasured cost is indistinguishable from a cost of zero in every decision that gets made.

How it could be measured

The category is only useful if it can be made empirical. Eight mechanisms, eight measurable proxies, all of them derivable from data that institutions already hold.

Measurable proxies for each mechanism, and the institution that already holds the data. No new collection instrument is required for any row — which is why the absence of these measures is a choice rather than a limitation.
MechanismProxyWho already holds it
DelayOrder-to-service interval, full distribution with the tail reported separatelyPayers, health systems, scheduling systems
DenialAppeal rate, reversal rate, and abandonment ratePayers; the third figure is the one not published
Documentation burdenTime per encounter, after-hours record time, requirements per encounter by sourceElectronic record vendors and health systems
Credentialing errorDays from complete application to effective date; rework rateHospitals, payers, credentialing organisations
Directory errorAccuracy audit results; appointment availability testingPayers and regulators
Automated decisionOverride rate, reversal rate, subgroup outcome analysisWhoever operates the system
Regulatory lagEvidence-to-guideline-to-coverage-to-practice intervalsPublic documents throughout — the most publishable row
FragmentationReferral loop closure rate; results acknowledged and actionedHealth systems and record vendors

Two of these are already tractable from public material and are therefore where this institute would start: regulatory lag, because every stage leaves a dated public document, and credentialing interval, because the arithmetic of foregone clinical capacity does not require a theory of causation. The remainder need institutional data that exists but is not published, which makes them transparency questions rather than research questions.

One measurement principle governs all eight rows: report distributions, never means. Every mechanism in this taxonomy produces harm in its tail. A system whose average performance is excellent and whose ninety-ninth percentile is catastrophic is, for the patients in that percentile, a catastrophic system — and a mean conceals exactly that.

Remedies that fit

Each mechanism admits a different remedy, and the mismatch between mechanism and remedy is why so much reform effort produces so little change.

Delay

A binding maximum, not a target

Averages are met while tails persist. A ceiling with a consequence attached is the only form that reaches the tail.

Denial

Attribution and burden allocation

Requiring that a denial be attributable to a named reviewer with stated criteria, and that the appeal cost not fall entirely on the patient and the practice.

Documentation burden

A total, and an owner of the total

Nobody is currently accountable for cumulative burden. Any remedy starts with someone being responsible for the sum rather than for their own addition to it.

Credentialing error

Single-source verification with reciprocity

The primary source is the same for every institution asking. The duplication is the defect.

Directory error

Accuracy audits with consequence

A directory error currently costs its publisher nothing, which is a complete explanation of why directories are inaccurate.

Automated decision

Rule-level audit and disclosure

Exception review cannot detect a faulty rule. Auditing the rule against subgroup outcomes can.

Regulatory lag

Scheduled review with a stated trigger

A standing obligation to revisit, tied to evidence publication rather than to a calendar.

Fragmentation

Closure as the measured unit

Measure whether the next thing happened, at the level of the patient rather than the institution.

The pattern across the eight is that the effective remedies are nearly all measurement and attribution rather than prohibition. That is a substantive finding, not a hedge: a diffuse cost borne by people with no reporting channel is corrected first by being counted, and most of these remedies are versions of counting it. Related: the reform agenda and the public accountability checklist.

What this establishes and what it does not

A taxonomy, not a measurement

Eight mechanisms defined so they can be measured separately. No frequency, magnitude or rate is claimed anywhere on this page.

No case attributed

No individual harm is asserted, and no institution is named. The attribution standard above is stated precisely so that later work can be held to it.

Not a claim that oversight is harmful

Utilisation review, credentialing verification and documentation each have real purposes, stated on this page in their strongest form.

Not a legal theory

Administrative harm is an analytic category for measurement and policy design. It is not a cause of action and this page does not suggest otherwise.

Structural, not jurisdictional

The mechanisms are general. Where California or federal law is cited it is cited for a specific proposition, not to localise the taxonomy.

Deliberately residual

The category applies only after clinical explanations have been excluded. Used as a default it would be worthless.

Authorities and related analysis

This page is a taxonomy rather than a statutory analysis, so it cites sparingly and only where a specific proposition rests on a specific text. Most of the mechanisms described operate through contract, institutional practice and private policy, where no citable instrument of general application exists.

B&P Code §805.5

The duty to request 805 information before granting or renewing privileges — cited for the point that verification duplication is designed rather than accidental. Verified at source 2 September 2026.

B&P Code §809.3

The peer review body’s burden of persuasion — cited for the point that context is admissible in this forum in a way it is not elsewhere. Verified 2 September 2026.

NPDB Guidebook — queries

The parallel federal query architecture that runs alongside the state inquiry.

Code of Civil Procedure §1094.5

Administrative mandamus, cited for the record-based character of review. Carried from the corpus’s earlier verification.

Related analysis: anonymous allegations · professionalism as a standard · who actually decides · the regulatory cascade · case counts without denominators · why enforcement data need context · fitness for duty against discipline · physician wellness programmes · accountability against punishment · recredentialing and continuous monitoring · economic versus patient-safety credentialing · a public accountability checklist · the prior authorisation dossier · the healthcare AI dossier · the credentialing dossier · the reform agenda · AI and the practice of medicine · prior authorisation duration and algorithmic denial · forecasts · the research program · how medicine works