Quality management without the detour through a survey bureau.
You build the questionnaires. Patients complete them at the bedside or at home; staff answer anonymously through a separate channel. Answers are stored exactly as given, and evaluation happens at group level, with the cohort sizes and completeness figures an auditor asks for. The module runs on its own. Where the rest of the platform is in use, an evaluation can also be broken down by indication group, department or length of stay.
In most facilities it goes like this. A bureau posts out paper questionnaires every quarter, scans what comes back, and delivers an evaluation some weeks later. It gives a satisfaction figure with the average for comparable facilities beside it. What accounts for the gap — which ward, which indication group, which part of the stay — the evaluation does not say. As evidence for the certification body it is enough. As a basis for deciding what to do differently next quarter it gives you nothing to work with.
≈ 1,200inpatient rehabilitation facilities must have their internal quality management certified; the revised federal rehabilitation agreement has applied since 1 July 2025Federal Working Group on Rehabilitation (BAR), 2025
≥ 25evaluable questionnaires a department has to reach before the pension insurer produces an adjusted report for itGerman Pension Insurance, survey FAQ
The rulebooks ask for more than the survey itself: an appraisal of the results, measures derived from them, and a later check on whether those measures worked. The federal rehabilitation agreement lists the derivation of corrective measures and improvement proposals from internal outcome measurement as a quality indicator, and requires a management review at least once a year in which attainment of measurable quality objectives is examined. ISO 9001:2015 asks for the same inputs in clause 9.3. An evaluation that is three months old and knows no sub-groups covers the first step of that.
Four differences from having an outside bureau run the surveys, and one that weighs more than the four together.
The same day
Speed
A completed form is in the evaluation the moment it is submitted. Between the end of a collection wave and the figures there is no printing, posting or scanning left. A change made in January can be checked in February rather than in April.
Ward, indication, measurement point
Resolution
Evaluations break down to ward, indication group, quarter and measurement point, as long as the minimum group size is met. A figure for the whole hospital shows a deviation. Where it comes from shows only in the breakdown.
No unit price per wave
Cost
The bureau route is paid for by the wave: printing, posting, returns, scanning, evaluation. In-house that share falls away, and an additional collection costs essentially the time it takes to set up. Licences for licensed instruments are unaffected and stay with the facility.
No collating by hand
Effort inside the house
Today the quality manager gathers figures from the bureau report, the complaints list and several spreadsheets, and builds the quarterly report out of them. The analytics layer assembles the report from the data it already holds. Reviewing and approving it stays with the quality manager.
From someone else's benchmark to your own improvement process
A bureau report sets your figure beside the average of a comparison database whose composition you do not know. A certification audit asks for something else: the quality objectives you set yourself, the measures you derived from them, and evidence that you measured their effect again. That is the continuous improvement process ISO 9001 and the federal rehabilitation agreement require, and here it accumulates over time as a by-product of the ongoing work. External results, from the pension insurer's survey for instance, can be set alongside as a labelled reference line without taking over as the yardstick.
The weekly report names what stood out this week and which measure falls due, which settles the order of work without anyone deriving it from several lists. Planned on top of that is a natural-language query: you ask how satisfaction on a given ward has developed since a change was made, and get the figures with cohort sizes and source links — or the answer that the group is too small to say. Answers draw exclusively on evaluations that have already passed the minimum group size.
Two components
Collection and analytics are separate parts of the module. The separation has a regulatory reason: nothing is computed and nothing is assessed on the collection side.
Component 1
The form builder
The quality manager builds the form: nine field types, shared answer scales, labels in several languages, branching of the "if yes, please explain" kind. Publishing creates a fixed version. Every incoming response records which version it answered, so a later edit to the form leaves a collection already under way untouched.
Assigned to one person for one measurement point — admission, mid-stay, discharge, follow-up. Several forms travel on a single access link.
Completed without an account, through a single-use link or QR code, on a clinic tablet or on the respondent's own device at home
One question per screen, continuous auto-save, resumable after an interruption. Abandoned forms are marked incomplete and still count in the evaluation.
Read-aloud and voice input run on the device itself. Recordings do not leave the tablet.
A print version as PDF for patients who would rather answer on paper. On request the whole distribution runs by post, with no email and no reminders.
Results table and CSV export with a freely configurable column order — for instance the order in which the discharge letter is dictated
Component 2
The analytics
The analytics layer reads the stored answers and computes at group level only. Behind every figure sits a stored definition: formula, data source, period, target value, accountable person. When someone in an audit asks how a number came about, that definition opens from the figure itself.
Admission compared with discharge as a group statistic, each with the cohort size and a statement of how complete the underlying data is
Broken down by indication group, department, ward, quarter and payer. Where a sub-group falls below the minimum size it is not shown, and the suppression is noted in its place.
A time-series view with control limits, from which you can tell whether a change sits within ordinary variation
Quality objectives with a target value and tolerance band. Every measure carries an accountable person, a due date, and a date on which its figure is measured again.
Complaints and incident reports by count, category and handling time. The free text is not processed and stays in the record.
Figures from the platform's other modules where those are in use. They are already aggregated there and never reach the analytics layer as an individual case.
Four reports from the same data
All four come out of the same evaluations. Every figure opens the evaluation it came from, and every passage of text the figures it rests on.
The weekly report
One page for the leadership meeting: notable movements from the past week, measures due and overdue, deadlines coming up, where response rates stand. In a week with none of that, the report says so in one sentence.
The quarterly report
Laid out along the inputs ISO 9001:2015 requires in clause 9.3 for the management review: status of measures from the previous review, attainment of quality objectives, results from the patient and staff surveys, complaint statistics, improvement proposals derived from them, and an annex on methodology.
The management review pack
Put together once a year from the four quarters: the full examination of quality objectives, an overview of which measures demonstrably worked, and the references to audit results and reporting obligations. The federal rehabilitation agreement requires this review at least annually.
Audit day
A read-only session with a fixed duration, run by the quality manager while the auditors follow along. For every statement about how a requirement is covered, the underlying evidence opens: approved reports, completed collection waves, closed measures.
Passages drafted with AI support are labelled, individually reviewable, and marked as drafts until a named person approves them. The figures and tables are produced without AI. If a facility switches the text support off, the reports remain complete.
How a satisfaction figure turns into somewhere to start
A satisfaction figure for a ward tells you it sits below the rest of the hospital. To answer why, the evaluation needs details of the treatment itself — and the platform is already keeping those.
The paperwork comes in
Bulk upload takes in whole document sets, the connections to fax, laboratory and the hospital system fetch incoming documents, and conversation documentation records what was discussed. The case is described before the first questionnaire is assigned.
The data is checked
The consistency report compares entries across all sources and names the contradictions. Citation references tie every adopted entry to the document it came from. An evaluation is only as defensible as the data underneath it, and an audit asks about both.
The evaluation gains attributes
Coding support structures ICD and OPS codes, department and length of stay. An evaluation can then be broken down by indication group, ward or quarter without anyone merging lists by hand.
The differences become explainable
Where a group does worse than the rest of the clinic, that can be set against what the records hold for those cases: indication group, length of stay, department, how complete the paperwork was at admission, how many follow-up requests were needed. That gives the quality manager a hypothesis to pursue. Such a connection remains a statistical observation and proves no cause; the evaluations say so on the spot.
Without the other modules
The module can be run on its own. With no hospital-system connection, a collection wave starts from the calendar rather than from admission and discharge events, and evaluation runs on the attributes the questionnaire itself captures. The reports are laid out the same way either way. If a connection is added later, further attributes become available to break results down by, and the data already collected is kept.
What the evidence supports — and what it does not
Survey data is often marketed with an effect the studies do not bear out. Where the research actually stands:
Patient experience is connected to safety and to clinical outcome.
A systematic review of 55 studies finds consistent positive associations between patient experience, patient safety and clinical effectiveness across disease areas, care settings and study designs. The authors take from this that patient experience should be carried as a quality dimension in its own right.
Staff exhaustion is connected to patient safety as well.
A systematic review of 46 studies finds, in 21 of the 30 studies measuring occupational exhaustion, an association with patient safety, and in four more for individual sub-scales. That association is one of the reasons the rulebooks carry the staff survey alongside the patient survey. The authors also note that prospective studies are missing, so which is cause and which is effect cannot be determined; the evaluations record that on the spot.
The Cochrane review of 116 randomised trials with 49,785 patients concludes that feeding questionnaire results back to providers improves communication moderately and quality of life slightly, while probably doing little for general health perception, social functioning or pain. Certainty of the evidence ranges from very low to moderate. So we make no claim of better outcomes through surveying. The value is in the work that follows: evaluate, decide on a measure, measure again.
An analysis of 38,664 responses at two hospitals shows what tick-box questions miss: a substantial share of those who give a domain the highest rating leave a comment that is not positive. Around 15 per cent of the topics identified concerned things worth praising, close to 9 per cent concrete room for improvement. Free text therefore stays in the questionnaire, and reading it stays with people for the time being.
On the collection side, no value is computed for an individual, not even a sum across their answers. Answers are stored and displayed back unchanged, the way a paper form would return them. There is no grading by degree, no threshold, no colour highlighting of individual answers, and no ordering by how someone answered.
Sensitive answers are not detected automatically, and nobody is notified automatically. A question about self-harm appears as it does on the paper form; the clinical response rests with the staff running the collection, as it does on paper. Branching in the form shows and hides fields; nothing is routed onward by the content of an answer.
The analytics layer shows groups. No individual appears in it, whether patient or member of staff. No prediction, prognosis or assessment of a single case is produced. Improvement proposals concern the organisation's processes, not the treatment of individual people.
aiomics ships no questionnaire content. Licensed instruments are licensed and entered by the facility itself; the registry records proof of licence and permits activation only once it is there. We transmit nothing to payers, the Medical Service or registries — sending stays with the facility.
A documented qualification under MDCG 2019-11 and Rule 11 of the EU Medical Device Regulation exists for this module: not a medical device, subject to the constraints above. The constraints are held in the quality management system and checked automatically during development. Where a planned function departs from them, it is re-qualified before it is built.
Employee surveys the works council can support
The German quality-management directive requires regular employee surveys that are "as anonymous as possible". The harder part is co-determination: an electronic survey tool counts as a technical facility under § 87 (1) no. 6 of the Works Constitution Act (Betriebsverfassungsgesetz), because it could permit inferences about individual employees. We assume co-determination applies and set the module up accordingly.
Anonymity follows from how the system is built: no identifiers are captured, no IP addresses logged, and only coarse timestamps stored. At no point does a link between an answer and a person come into existence.
The minimum group size is ten, enforced in the database query, for every breakdown, every cross-tabulation and every comparison over time. Five is the industry norm. Complementary cells that would allow a suppressed group to be worked back out are suppressed with it; queries below the threshold are refused and logged.
There is no privileged access to individual staff responses, including for our own support team. Access in the event of a fault is four-eyes and logged.
A works agreement template and a technical description of the anonymity design are part of the delivery. Until works council involvement is on record, the employee pack cannot be switched on.
Under Federal Labour Court case law (1 ABR 47/16, 1 ABR 13/17), a voluntary and consistently anonymous survey is not a personnel questionnaire within the meaning of § 94 of the Works Constitution Act and is not co-determined on that basis. Where a survey serves the psychosocial risk assessment required under occupational safety law, § 87 (1) no. 7 applies in addition; the template covers that case too.
Patient-satisfaction evaluations are not related back to individual staff. The finest attribution a questionnaire may target is the team or the ward.
What runs today, what follows
Where each part currently stands. This overview is kept up to date.
In use
Collection
Builder with nine field types, versioned publishing, assignment through a single-use link, results table and CSV export. Shipped and in operation.
In pilot
Collection waves and accessibility
Instrument registry with proof of licence, waves triggered by calendar or by admission and discharge events, stored standard sets per measurement point, print version as PDF, progress indicator, further language versions, distribution by post. Being trialled at the pilot sites.
Planned
Analytics, reports, measures
Group-level evaluation, admission compared with discharge, breakdowns with a minimum group size, time-series views with control limits, the four reports, measures with re-measurement, an obligations calendar and the audit session. In specification; regulatory qualification and the data protection impact assessment run before development.
Planned
Employee pack and incident reporting
Anonymous collection channel, employee survey with a minimum group size, near-miss reporting, works agreement template. Release requires a completed data protection impact assessment.
Legal framework and data processing
Processing entirely within the European Union (data centre in Frankfurt). No further sub-processors are added inside the professional-confidentiality circle under § 203 of the German Criminal Code.
Information security to ISO/IEC 27001, certified by TÜV Nord. Responses sit in a dedicated append-only table under its own key; a correction is made by a superseding response rather than by overwriting.
Templates for the data processing agreement and the data protection impact assessment are part of the delivery. For the employee pack, a completed impact assessment is a precondition of activation.
Rulebooks accounted for: the Federal Joint Committee's quality-management directive (§§ 4, 6), § 37 Book Nine of the Social Code with the federal rehabilitation agreement, § 137d Book Five of the Social Code with the statutory rehabilitation quality-assurance procedure, ISO 9001:2015 clause 9.3, § 87 of the Works Constitution Act.
Accessibility to WCAG 2.2 AA and the German federal accessibility ordinance: one question per screen, large controls, errors never signalled by colour alone, plain wording.
Preparation for the requirements of the EU AI Act. AI-supported passages are labelled, and AI literacy training for hospital staff is part of the delivery.
Frequent questions
Does this replace the German Pension Insurance's own post-discharge survey?
No. The pension insurer runs that survey itself, 8 to 12 weeks after discharge, reports once a year and covers only the cases it funds. The module collects in addition, in-house, during the stay and at discharge, across all payers. The insurer's results can be placed beside your own as a clearly labelled reference line.
Does the quality-management directive apply to rehabilitation clinics too?
It binds office-based physicians, medical care centres and hospitals licensed under § 108 Book Five of the Social Code. For rehabilitation facilities the duty follows from § 37 Book Nine with the federal rehabilitation agreement, and from § 137d Book Five with the statutory quality-assurance procedure. Both require feedback from rehabilitation patients, an appraisal of it, and measures derived from it.
Which questionnaires do you ship?
None. Licences for instruments are held by the facility. We supply the registry they are kept in, with licence class, rights holder, term and a reminder before expiry. Licensed instruments cannot be activated until proof is recorded; contractually barred instruments cannot be created at all. Freely usable instruments are normally entered by the facility itself.
Why does the questionnaire not compute a sum?
Because a computed value for an individual that serves a medical purpose would bring the software inside the scope of the Medical Device Regulation. The separation is therefore built in: the collection side stores and displays, the analytics side computes, and it computes across groups. An automated check during development refuses any build in which computation logic appears on the collection side.
What happens if someone answers a sensitive question in a worrying way?
The same as on paper: the answer is there and the staff running the collection read it. The system detects nothing, notifies nobody and forwards nothing. The rollout package includes a briefing sheet stating exactly that to the staff handing out the forms — the common assumption is that a digital system will have alerted someone already.
Do we need a hospital-system connection for this?
No. Without one, a collection wave starts from the calendar and evaluation runs on the attributes the form itself captures. With one, admission and discharge trigger the waves, and evaluations can also be broken down by indication group, department and length of stay. The reports are laid out the same way in both cases.
What response rate should we expect compared with paper?
We quote no figure, because we have not yet measured one across several facilities. The benchmark is each facility's own paper response rate when forms are handed out with staff present. For bedside collection we are working towards at least 70 per cent. What decides it is that accompaniment: the flow is built for a handover of under thirty seconds, because unaccompanied collection reliably comes back worse.
How do you make staff believe the anonymity?
By capturing nothing that would allow attribution, and by letting the works council check that. The package includes the technical description of the anonymity design and a works agreement template; the minimum group size of ten is enforced in the database query and stated in the interface. Whether it convinced anyone shows in the second wave: if participation rises, the question is answered.
Who is allowed to see which evaluation?
The roles are separate: collection, results view, analytics, report approval, works council information, audit session. No role has access to individual records; individual staff responses are closed to every role. Every query is logged, the logs cannot be altered, and they are open to the data protection officer.
Can we use the module without introducing the rest of the platform?
Yes. Collection and analytics work on their own. Where further modules are in use, their aggregated figures appear as additional tiles and the case attributes of the verified record as further ways to break results down. Where they are absent, those tiles are absent; the remaining evaluations are unaffected.
How long before a first collection is running?
For a standard form we reckon on under 15 minutes to build and under a minute per assignment; with a standard set stored, assignment usually falls away. What takes longer is agreeing what is to be measured and who owns the measures.
Do you use AI in the analytics?
The statistics are rule-based and versioned; no AI is involved there. What is AI-supported are the draft passages in the report and, planned, a natural-language query that reaches only evaluations already suppressed to the threshold. Both are labelled, individually reviewable and switchable off per facility; the figures and tables stay complete without AI.
We go through your existing surveys: instruments, cadence, response rates, and what happens to the results today. Then we tell you which part of it we would replace and which we would leave alone. If your current arrangement holds up, we say that too.