CIRS and the Anonymity You Can Demonstrate
Reporting systems capture only a fraction of events, and reporting remains a matter of trust. What §135a SGB V actually protects, why assurances carry little — and how to recognize verifiable anonymity.

Dr. Sven Jungmann
CEO

The quarterly report is on the table: four reports from the department's CIRS — the critical incident reporting system German hospitals operate — against roughly 900 treated cases in the quarter. The chief physician does not know how to read the number. Perhaps it was a quiet quarter. Perhaps the experienced staff no longer report because nothing followed their last reports. Perhaps the young ones do not report because they are not sure who reads a report.
The research suggests an uncomfortable reading: a 2023 systematic review compared reporting systems with systematic record screening (Global Trigger Tool) and found that reporting systems captured on average 7.0 percent of the adverse events identified that way — range 0 to 37.4 percent, below 10 percent in twelve of fourteen studies [1]. The authors' conclusion: reporting rates are no measure of a facility's safety. A low number can mean a safe quarter or a silent one — from outside, the two cannot be told apart.
Why people do not report
It is rarely the technology. The recommendations of the German Coalition for Patient Safety (Aktionsbündnis Patientensicherheit) on introducing CIRS name the conditions under which people report: voluntariness, freedom from sanctions, anonymity or confidentiality — and the willingness to report declines where personal disadvantage is expected [2]. A quantified relationship between perceived anonymity and reporting rate is something the research has not delivered so far; there is no study with a robust effect size. Qualitatively, the finding runs through every recommendation.
Add an honest insight from practice: complete anonymity often cannot be produced at all. Whoever knows the incident recognizes the department, sometimes the person — in a team of twelve, "anonymous" is a relative term. The Swiss Patient Safety Foundation therefore increasingly speaks of confidentiality rather than anonymity and in part relies on voluntary identification with protected handling [3]. For Germany, this means: whoever promises anonymity should be able to say precisely what is being promised.
What §135a SGB V protects — read closely
The legal position, too, is often presented more generously in training sessions than it is. §135a(3) sentence 1 SGB V provides: reports and data from facility-internal and cross-facility risk-management and error-reporting systems may not be used in legal proceedings to the disadvantage of the person reporting [4]. The exception is narrow: use is permissible only if it serves the prosecution of a criminal offense punishable by a maximum of more than five years' imprisonment, which weighs particularly heavily in the individual case, and whose investigation would otherwise be impossible or substantially more difficult.
Two clarifications belong in every CIRS training session. First: what is protected is the reporting person — the norm is a prohibition on using reports to that person's disadvantage. Second: it is not a general protection of CIRS data against seizure. An explicit prohibition on seizing CIRS reports under German criminal procedure does not exist; access by investigating authorities is possible in principle and is limited via the principle of proportionality. A more far-reaching protection is discussed and demanded in the legal literature, but it is not, so far, the law in force. Whoever promises staff "absolute safety" promises more than the statute delivers — and it is exactly such overstatements that come back on the reporting culture when the first serious case disproves them.
Anonymity as architecture
If neither the promise nor the statute carries alone, the third level remains: the system itself. The difference is easy to test — an assurance sits in a procedural instruction, an architecture sits in the code and can be demonstrated. Technically verifiable anonymity means:
- There is nothing to de-anonymize: no personal identifier on the record, no stored IP addresses, coarsened timestamps. What was never collected can be exposed by no disclosure request and no data leak.
- Minimum cell sizes at query level: analyses below a minimum number of reports or responses are blocked by the system — in the code, so that administrators cannot bypass them either.
- Complementary cell suppression: neighboring cells are suppressed as well, so that small groups cannot be reconstructed by taking differences — 31 responses today, 30 yesterday, makes one identified person.
- Queries below the threshold are refused and logged.
- And all of it is demonstrable: the works council, staff representatives and employees can have the blocking shown to them on the live system, with real queries.
Whoever builds this way has less to promise.
At aiomics, such a foundation is part of the survey suite, which is in pilot operation at rehab clinics: the minimum cell size of ten is enforced at query level in the code — five would be the industry norm — complementary cell suppression included; these design decisions apply to the pilot operation as to every planned expansion. The CIRS-style incident inbox and the staff package including a works-agreement template are planned and not yet shipped. How the suite is built overall is described in PROMs and PREMs: the survey obligation hardly any facility evaluates (in German).
Five questions for any reporting system
- Where is the minimum cell size implemented — in a policy or in the code? And at which level: in the finished report or at the query itself?
- Can an administrator bypass the threshold? If yes, what you have is a convention with a user interface.
- Which metadata does the system store with a report — IP address, device identifier, exact time, logged-in account?
- How does the system prevent differencing queries over time or across filter combinations?
- Can all of this be demonstrated to the works council and the staff on the live system?
A reporting system is as good as the trust of those who feed it — and trust grows where people are allowed to look. What a department can learn from the reported and the unreported events, if the record cooperates, we discuss in the M&M conference and the question: what did we know when? (in German). If you would like to read regularly about error culture, documentation and AI: our weekly briefing Visite (German; English edition Grand Rounds is in preparation) is where we write about all three.
Sources
- Systematisches Review zum Erfassungsgrad von Incident-Reporting-Systemen im Vergleich zum Global Trigger Tool. International Journal for Quality in Health Care. 2023;35(3):mzad056. doi:10.1093/intqhc/mzad056
- Aktionsbündnis Patientensicherheit e. V. Empfehlungen zur Einführung von Critical Incident Reporting Systemen (CIRS). https://www.aps-ev.de/
- Stiftung Patientensicherheit Schweiz. CIRS-Management: häufige Fragen. https://patientensicherheit.ch/cirrnet/cirs-management/faq/
- § 135a SGB V. https://www.gesetze-im-internet.de/sgb_5/__135a.html
The aiomics survey suite is in pilot operation at rehab clinics; the incident inbox and the staff package described here are planned and not yet shipped.


