Taxonomy · eight mechanisms · eight measurable proxies · compiled
Administrative Harm
Nobody made a clinical error. The patient was harmed anyway. No reporting system in health care is designed to capture it
Delay, denial, documentation burden, credentialing error, directory error, automated decision, regulatory lag, fragmentation. Each mechanism is defined separately, with the administrative act, the clinical pathway, why it escapes detection, and a measurable proxy that institutions already hold the data for. The page also states the attribution standard the category must meet, and the strongest argument against it.
Policy analysis by Kanwar Partap Singh Gill, MD · compiled · educational analysis, not legal advice.
Harm that arrives through paperwork
Patient safety, as a field, was built around a particular picture of harm: something happens to a patient in a clinical setting, at an identifiable moment, at the hands of an identifiable clinician or a failing piece of equipment. That picture produced incident reporting, root cause analysis, morbidity and mortality review, never-event lists and the whole apparatus of modern quality improvement. It works, and it is incomplete.
The incomplete part is harm that arrives through administration. A treatment that was never refused but never authorised. A referral that existed on paper and never produced an appointment. A medicine that was covered last year and is excluded this year. A physician who cannot see patients for four months because an enrolment file sat in a queue. A rule that arrived three years after the practice it was written to govern had already changed.
Nobody made a clinical error. The patient was harmed anyway. And no reporting system in health care is designed to capture it.
Program item 130, and the third piece of tranche 2. It completes a set: who actually decides maps where authority sits; the regulatory cascade maps where consequence goes; this page asks what the administration of health care does to the people inside it. Like both companions, it is an analytic map rather than a dataset, and it claims no frequencies.
Defining the category
A definition is needed first, because a category this broad becomes useless if it is allowed to mean any bad experience with a health system.
Working definition
Administrative harm is injury to a patient, or to a physician’s capacity to care for patients, produced by the operation of an administrative process rather than by a clinical act or omission — where the process performed as designed, or failed in a way its own controls did not detect.
Four elements do the work in that sentence, and each excludes something.
Element one
Injury, not inconvenience
A delayed appointment that changes nothing is friction. A delayed appointment that allows a treatable condition to progress is harm. The category requires a consequence, not an irritation.
Element two
Produced by process, not by clinical judgement
If a physician chose wrongly, that is clinical error and existing systems address it. This category covers the cases where clinical judgement was sound and never reached the patient.
Element three
The process worked as designed, or failed undetected
This is the element that distinguishes administrative harm from ordinary administrative failure. A queue that produces a four-month wait because it was built to produce a four-month wait is functioning. The harm is designed in.
Element four
Attributable to a process, not to a person
Which is precisely why it is unreported. Every reporting system in health care asks who did it.
That last element is the whole difficulty, and it deserves stating plainly rather than as a complaint: the infrastructure of patient safety is organised around agency, and administrative harm has no agent.
Why it is not measured
Six structural reasons, none of them conspiratorial. Each is an ordinary consequence of how the systems were built.
Reason one
No reporting form has a field for it
Incident reports ask what happened to the patient during care. A harm that consists of care not happening has no event to report and no location to report it from.
Reason two
The harm and the decision sit in different institutions
The denial is made by a payer. The deterioration presents at a clinic. Neither institution holds both halves, and no one is obliged to join them.
Reason three
Latency defeats attribution
Weeks or months separate the administrative act from the clinical consequence, which is long enough for the causal link to become arguable and therefore ignorable.
Reason four
The counterfactual is unobservable
What would have happened with timely authorisation is a clinical judgement about an alternative history. That is hard, and hard is treated as unknowable.
Reason five
The denominator is missing
How many authorisations were delayed, and of those how many mattered? Neither figure is published. Case counts without denominators is the standing analysis.
Reason six
Nobody owns the measurement
A hospital measures its own clinical outcomes. A payer measures its own turnaround. No institution is accountable for the interaction between them, so the interaction is where the harm accumulates unrecorded.
A harm with no form to report it on, no institution that holds both halves, and no denominator does not appear in any dataset. Its absence from the evidence is a fact about the measurement apparatus, not about the world.
1 · Delay
Administrative act
A queue: authorisation, referral, scheduling, enrolment, records transfer
Clinical pathway
Time-dependent conditions progress on their own schedule while the queue runs on its own
Who observes it
The patient, and the treating physician. Neither is asked
Why undetected
The process completed. It simply completed late, and lateness is not an adverse event in any reporting taxonomy
Measurable proxy
Interval from order to service, distributed rather than averaged — the tail is the harm
The purest form of the category, because nothing is refused. Every actor performs their role, the authorisation is granted, the referral is accepted, the appointment is offered. The only variable is elapsed time, and elapsed time is the one thing clinical medicine cannot treat as neutral: a condition that is time-dependent converts administrative duration directly into clinical outcome.
The analytical point is about distributions rather than averages. A median turnaround of two days is compatible with a tail of six weeks, and the tail is where the harm lives. Any measure reported as a mean is structurally incapable of detecting this mechanism, which is a reason to be suspicious of turnaround statistics that appear reassuring.
Related: the prior authorisation dossier.
2 · Denial
Administrative act
A coverage determination against the treating physician’s recommendation
Clinical pathway
Substitution, abandonment or delay of the recommended plan
Who observes it
The patient. Frequently not the payer, which sees a closed file rather than an outcome
Why undetected
A denial upheld on no appeal is recorded as a correct decision. A denial abandoned without appeal is recorded as no decision at all
Measurable proxy
Appeal rate, reversal rate on appeal, and — the missing figure — the abandonment rate
The appeal ladder is real and is the strongest available answer to a wrong denial. Its existence is also what makes the mechanism invisible: because a remedy exists, an unremedied denial is treated as an accepted one. The unexamined quantity is how many denials are simply abandoned, by patients or by practices without the administrative capacity to pursue them.
A reversal rate is a two-edged statistic and should be read carefully in both directions. A high reversal rate on appeal means the initial determinations were unreliable. A low one may mean they were sound — or that only the strongest cases were appealed. Neither reading is available without knowing how many were abandoned, and that figure is not published anywhere.
3 · Documentation burden
Administrative act
Recording, coding, attestation and justification requirements, accumulated from many sources
Clinical pathway
Clinician attention is finite. Time spent on documentation is time not spent on the patient or on thinking
Who observes it
Every clinician. It is the most universally experienced mechanism and among the least documented as harm
Why undetected
No single requirement is unreasonable. The burden is cumulative, and nothing measures cumulative burden
Measurable proxy
Documentation time per encounter; after-hours record time; requirements per encounter by source
The distinctive feature here is that no actor imposed the burden. A payer added a justification field; a regulator added an attestation; an accreditor added a checklist; a health system added a template; a quality programme added a measure. Each was defensible on its own. Nobody was responsible for the total, and the total is what changes clinical practice.
This mechanism also produces a second-order harm the corpus treats separately: documentation designed for billing and compliance rather than for clinical communication degrades the record as a clinical instrument. The note becomes longer and less useful, which is a patient-safety consequence disguised as an efficiency complaint. Related: the healthcare AI dossier, on what happens when generated text is added to this pressure.
4 · Credentialing and enrolment error
Administrative act
A verification, privileging or payer-enrolment process that stalls, errs or is not completed
Clinical pathway
A physician who is licensed, competent and willing cannot see patients, or cannot be paid for seeing them
Who observes it
The physician and the unseen patients, who are by definition never counted
Why undetected
The harm is capacity that never existed. There is no patient record for an appointment that was never available
Measurable proxy
Days from complete application to effective date; error and rework rates; the number of clinical sessions foregone
The clearest case of harm to patients caused by a process that never touches a patient. It is also the mechanism where the counterfactual is unusually solid: a physician credentialed in thirty days rather than one hundred and twenty has ninety days of clinical capacity that otherwise did not exist. The arithmetic does not require a theory of causation.
The recurring aggravating feature is duplication. The same primary source is verified independently by a hospital, several payers, an employer and a carrier, each on its own cycle, each asking the physician to supply the same documents again. Section 805.5 obliges institutions to query the licensing board before granting or renewing privileges, and the federal data bank is queried in parallel — so the verification architecture is duplicative by design rather than by neglect. Related: recredentialing and continuous monitoring.
5 · Network and directory error
Administrative act
A published directory that does not match reality — wrong network status, wrong panel status, wrong location, wrong specialty
Clinical pathway
A patient selects a physician who cannot see them, is not accepting patients, or is not in network. The attempt consumes the patient’s time and may consume their willingness to try again
Who observes it
The patient, at the point of failure
Why undetected
A failed attempt to obtain care generates no clinical record anywhere
Measurable proxy
Directory accuracy audits; appointment availability testing; unmatched referral rates
A small error with a large multiplier, because it operates at the moment of a patient’s decision to seek care. The patient who calls three listed physicians and reaches none of them has not been denied anything. They have simply learned that the system does not work, and that lesson is more durable than any single appointment.
It is worth naming what makes this mechanism structurally different from the others: the harm falls entirely on the patient, and no institution in the chain experiences any consequence from it at all. A directory error costs its publisher nothing.
6 · Automated decision
Administrative act
An algorithmic or rules-based determination applied at volume — coverage, eligibility, risk stratification, prior authorisation triage
Clinical pathway
Whatever the determination governs, applied consistently and at scale
Who observes it
Individually, the patient. In aggregate, potentially nobody
Why undetected
Automated decisions are consistent, and consistency reads as correctness. A systematic error produces no outliers to investigate
Measurable proxy
Override and reversal rates; subgroup analysis of outcomes; the volume of determinations made without individual review
This mechanism inverts the usual relationship between error and detection. Human error is variable, and variability is what quality systems are built to notice. An automated error is uniform: every affected case is affected identically, so nothing stands out, and the very feature that makes automation attractive makes its failures invisible to outlier-based monitoring.
The consequence for oversight is specific. A system that reviews exceptions cannot detect a fault in the rule, because a faulty rule generates no exceptions. Detecting it requires auditing the rule itself, on subgroup outcomes rather than on individual complaints — which is a different kind of oversight from anything currently in place. Related: the reform proposal on algorithmic denial and AI and the practice of medicine.
7 · Regulatory lag
Administrative act
A rule, guideline or coverage policy that arrives after the practice it governs has changed — or does not arrive
Clinical pathway
Either a superseded standard is enforced, or a genuinely novel practice operates with no standard at all
Who observes it
Clinicians, who experience it as a rule that does not fit the medicine
Why undetected
The absence of a rule is not an event, and nothing schedules a review of what has not been written
Measurable proxy
Interval from evidence publication to guideline revision to coverage change to practice change
Lag cuts in both directions, which is why it belongs in this taxonomy rather than in a general complaint about regulators. An outdated rule enforced against current practice is harm. A novel practice operating with no applicable standard is also harm, and the second is increasingly the more common of the two.
The measurable version of this mechanism is one of the more tractable items in the program: the evidence-to-practice interval is composed of dated stages, each of which leaves a dated document. Related: forecasts, which exists to state expectations about that interval before the fact rather than after.
8 · Fragmentation and handoff
Administrative act
Care distributed across institutions with no shared record, no shared accountability and no owner of the interval between them
Clinical pathway
A result, referral or plan is generated by one institution and never actioned by another
Who observes it
Ideally the primary physician, if the information reaches them at all
Why undetected
Every institution completed its own task correctly. The failure lives in the space between tasks, which nobody’s quality system covers
Measurable proxy
Referral loop closure rate; proportion of results acknowledged and actioned; time to closure
The mechanism with the clearest ownership problem. A result is produced correctly, transmitted correctly and received correctly, and nothing happens next, because the duty to act sat with whoever was supposed to be looking and nobody was designated. Each institution passes its own audit.
Loop closure is the single most useful measure in this entire taxonomy, because it is defined at the level of the patient rather than the institution: was the thing that was supposed to happen next actually done? Institutions do not measure it, and the reason they do not is structural rather than negligent — the measure spans the boundary each institution’s audit stops at.
The second patient
The definition at the top of this page includes harm to a physician’s capacity to care for patients, and that inclusion is deliberate rather than sentimental. It rests on a chain that is short and hard to dispute.
Step one
Administrative process consumes clinical attention
Documentation, authorisation, appeals, credentialing, enrolment, compliance training and reporting each take time from a finite budget.
Step two
Attention is the substrate of clinical judgement
Reduced attention degrades diagnostic reasoning, communication and error detection. This is not a moral claim; it is a claim about cognitive capacity under load.
Step three
Degraded judgement reaches patients
At which point the harm becomes clinical, and the existing patient-safety apparatus records it — attributed to the clinician.
Step four
The attribution lands in the wrong place
The event is recorded as a clinical error by an individual. Its administrative origin is not a field on the form, so it is not recorded at all.
An administrative burden becomes a clinical error, and the clinical error becomes the physician’s record. The mechanism converts a system problem into an individual one, and the conversion is invisible in every dataset that matters.
This is where the category connects to the rest of the corpus. A physician facing a peer-review or licensing matter arising from an event with an administrative origin is answering, individually and on the record, for a condition created upstream — and the forum that decides has no mechanism for hearing that. In California hospital peer review the institution at least carries the burden of showing its action is reasonable and warranted under B&P Code §809.3(b)(3), which makes context admissible in a way it is not elsewhere. Related: who actually decides, the regulatory cascade, fitness for duty against discipline, and physician wellness programmes, which examines what happens when a structural condition is offered an individual remedy.
The attribution problem
This category is only as credible as its discipline about causation, and the temptation it invites is obvious: to treat every bad outcome preceded by paperwork as caused by the paperwork. That would be the same error the category exists to criticise, run in the opposite direction.
So the standard applied here is explicit. Four conditions, all of which must hold before a case is described as administrative harm rather than as an outcome that happened to involve administration.
A specific administrative act is identified
Named, dated, and attributable to a process rather than inferred from a bad result.
A clinical pathway is stated
The mechanism by which that act could affect the outcome, articulated in advance rather than reconstructed afterwards.
The counterfactual is examined honestly
What would probably have happened otherwise, with the uncertainty stated. Where the counterfactual cannot be assessed, the case is recorded as unassessable rather than as harm.
Clinical explanations are excluded first
Disease progression, comorbidity, patient decision and clinical error are considered before an administrative cause is asserted. The category is a residual, not a default.
The honest position is that individual attribution is hard and population-level attribution is more tractable. Whether a particular delay harmed a particular patient is often unknowable. Whether a distribution of delays produces harm across a population is an ordinary empirical question, and it is the one worth asking.
The strongest case against this category
A page proposing a new category of harm should state the best argument against it, and this one is serious.
The objection
Administrative processes exist for reasons. Utilisation review restrains genuinely unnecessary and sometimes harmful treatment. Credentialing verification prevents unqualified practice, and the corpus documents in detail why that verification matters. Documentation requirements exist because undocumented care cannot be audited, coordinated or defended. Coverage rules allocate finite resources, and a system with no allocation rules is not a fairer system — it is one that allocates by other means, usually to the advantage of whoever can navigate it best. Calling the friction produced by these processes harm risks reasoning backwards from a preferred policy conclusion.
Three of those propositions are simply correct, and this page accepts them. The response is not that oversight is bad. It is narrower, and it concedes the objection’s premise:
Response one
A process having a purpose does not exempt it from measurement
Utilisation review may be net beneficial and still produce a measurable tail of harm. Both can be true at once, and only one of them is currently counted.
Response two
The burden of the process should be attributed to the process
Where a requirement produces a cost, that cost belongs in the ledger of the requirement rather than in the record of the clinician who absorbed it. This is an accounting objection, not an ideological one.
Response three
Asymmetric measurement is the actual complaint
The benefits of administrative processes are measured, published and cited by the bodies that operate them. The costs are diffuse, fall on people with no reporting channel, and are measured by nobody. A category that makes the second half countable does not presume the answer — it makes the comparison possible for the first time.
The claim is not that oversight causes harm. It is that the cost side of oversight is unmeasured, and that an unmeasured cost is indistinguishable from a cost of zero in every decision that gets made.
How it could be measured
The category is only useful if it can be made empirical. Eight mechanisms, eight measurable proxies, all of them derivable from data that institutions already hold.
| Mechanism | Proxy | Who already holds it |
|---|---|---|
| Delay | Order-to-service interval, full distribution with the tail reported separately | Payers, health systems, scheduling systems |
| Denial | Appeal rate, reversal rate, and abandonment rate | Payers; the third figure is the one not published |
| Documentation burden | Time per encounter, after-hours record time, requirements per encounter by source | Electronic record vendors and health systems |
| Credentialing error | Days from complete application to effective date; rework rate | Hospitals, payers, credentialing organisations |
| Directory error | Accuracy audit results; appointment availability testing | Payers and regulators |
| Automated decision | Override rate, reversal rate, subgroup outcome analysis | Whoever operates the system |
| Regulatory lag | Evidence-to-guideline-to-coverage-to-practice intervals | Public documents throughout — the most publishable row |
| Fragmentation | Referral loop closure rate; results acknowledged and actioned | Health systems and record vendors |
Two of these are already tractable from public material and are therefore where this institute would start: regulatory lag, because every stage leaves a dated public document, and credentialing interval, because the arithmetic of foregone clinical capacity does not require a theory of causation. The remainder need institutional data that exists but is not published, which makes them transparency questions rather than research questions.
One measurement principle governs all eight rows: report distributions, never means. Every mechanism in this taxonomy produces harm in its tail. A system whose average performance is excellent and whose ninety-ninth percentile is catastrophic is, for the patients in that percentile, a catastrophic system — and a mean conceals exactly that.
Remedies that fit
Each mechanism admits a different remedy, and the mismatch between mechanism and remedy is why so much reform effort produces so little change.
Delay
A binding maximum, not a target
Averages are met while tails persist. A ceiling with a consequence attached is the only form that reaches the tail.
Denial
Attribution and burden allocation
Requiring that a denial be attributable to a named reviewer with stated criteria, and that the appeal cost not fall entirely on the patient and the practice.
Documentation burden
A total, and an owner of the total
Nobody is currently accountable for cumulative burden. Any remedy starts with someone being responsible for the sum rather than for their own addition to it.
Credentialing error
Single-source verification with reciprocity
The primary source is the same for every institution asking. The duplication is the defect.
Directory error
Accuracy audits with consequence
A directory error currently costs its publisher nothing, which is a complete explanation of why directories are inaccurate.
Automated decision
Rule-level audit and disclosure
Exception review cannot detect a faulty rule. Auditing the rule against subgroup outcomes can.
Regulatory lag
Scheduled review with a stated trigger
A standing obligation to revisit, tied to evidence publication rather than to a calendar.
Fragmentation
Closure as the measured unit
Measure whether the next thing happened, at the level of the patient rather than the institution.
The pattern across the eight is that the effective remedies are nearly all measurement and attribution rather than prohibition. That is a substantive finding, not a hedge: a diffuse cost borne by people with no reporting channel is corrected first by being counted, and most of these remedies are versions of counting it. Related: the reform agenda and the public accountability checklist.
What this establishes and what it does not
Eight mechanisms defined so they can be measured separately. No frequency, magnitude or rate is claimed anywhere on this page.
No individual harm is asserted, and no institution is named. The attribution standard above is stated precisely so that later work can be held to it.
Utilisation review, credentialing verification and documentation each have real purposes, stated on this page in their strongest form.
Administrative harm is an analytic category for measurement and policy design. It is not a cause of action and this page does not suggest otherwise.
The mechanisms are general. Where California or federal law is cited it is cited for a specific proposition, not to localise the taxonomy.
The category applies only after clinical explanations have been excluded. Used as a default it would be worthless.
Authorities and related analysis
This page is a taxonomy rather than a statutory analysis, so it cites sparingly and only where a specific proposition rests on a specific text. Most of the mechanisms described operate through contract, institutional practice and private policy, where no citable instrument of general application exists.
The duty to request 805 information before granting or renewing privileges — cited for the point that verification duplication is designed rather than accidental. Verified at source 2 September 2026.
The peer review body’s burden of persuasion — cited for the point that context is admissible in this forum in a way it is not elsewhere. Verified 2 September 2026.
The parallel federal query architecture that runs alongside the state inquiry.
Code of Civil Procedure §1094.5
Administrative mandamus, cited for the record-based character of review. Carried from the corpus’s earlier verification.
Related analysis: anonymous allegations · professionalism as a standard · who actually decides · the regulatory cascade · case counts without denominators · why enforcement data need context · fitness for duty against discipline · physician wellness programmes · accountability against punishment · recredentialing and continuous monitoring · economic versus patient-safety credentialing · a public accountability checklist · the prior authorisation dossier · the healthcare AI dossier · the credentialing dossier · the reform agenda · AI and the practice of medicine · prior authorisation duration and algorithmic denial · forecasts · the research program · how medicine works