Medical Malpractice

Negligent Credentialing and the Hospital's Own Files

Negligent credentialing reaches the hospital's own duty to vet the physicians it privileges, and it opens a file the defense fights to keep sealed.

Hospital medical staff credentialing files and application folders stacked on an administrator's desk

When a surgeon with a documented history of complications is handed operating-room privileges and then injures your client, the negligent act is not only the surgeon's. It is the hospital's decision to grant and renew privileges without meaningful review. Negligent credentialing reaches that decision directly, and it opens a file the hospital fights hard to keep closed.

The corporate-negligence foundation

The theory rests on corporate negligence, the principle that a hospital owes patients an independent duty of reasonable care in selecting and retaining the physicians it allows to practice within its walls. The doctrine traces to Darling v. Charleston Community Memorial Hospital, the 1965 Illinois decision that broke from the old rule treating hospitals as mere hostelries for independent doctors. California recognized the parallel duty in Elam v. College Park Hospital (1982) 132 Cal.App.3d 332, holding that a hospital may be liable for negligently screening the competency of the medical staff it credentials. Most states now accept some version of the duty, though the labels and the proof burdens vary.

The claim is distinct from vicarious liability and from ostensible agency. Those theories borrow the physician's negligence and impute it to the hospital. Negligent credentialing is direct: the hospital breached its own duty by extending privileges it should have withheld or should have pulled. That distinction matters, because a hospital can concede the physician was an independent contractor and still owe the credentialing duty.

The file the hospital does not want to produce

Every credentialing case turns on the physician's privileging file: the initial application, the primary-source verifications, the references, the malpractice-claims history, the query responses from the National Practitioner Data Bank, and the periodic reappointment reviews. Federal law requires hospitals to query the Data Bank when a physician applies and at least every two years on reappointment. A hospital that failed to query, or queried and did nothing with an adverse report, has handed you the breach.

The defense will invoke the peer-review privilege to bury all of it. The fight over that privilege is its own subject, and we have covered the mechanics of getting past it, but the key line for credentialing is the distinction many jurisdictions draw between the peer-review committee's deliberations and the underlying credentialing documents. Applications, verifications, and Data Bank responses often sit outside the privilege even where the committee's internal debate is protected. Frame your requests to that distinction and make the hospital justify each withholding on a document-by-document log rather than a blanket assertion.

Proving the breach

Breach in a credentialing case is measured against the hospital's own bylaws and the standards of the accrediting bodies, chiefly the Joint Commission, plus state licensing regulations. The bylaws almost always require primary-source verification, a review of claims history, and a reappointment process on a fixed cycle. When the file shows the hospital skipped a step its own bylaws demanded, the breach is close to self-proving. A credentialing expert, usually a physician executive or a medical-staff professional, ties the omission to the standard of care for hospital governance.

The stronger cases share a pattern: prior malpractice payments, a restriction or revocation at another facility, a specialty board the physician never actually held, or a string of internal complaints that reappointment ignored. Each is the kind of red flag the credentialing process exists to catch.

The causation problem

Credentialing cases live or die on causation, and it is a two-layer proof. You must show the physician was in fact negligent in the care that injured your client, and you must show that competent credentialing would have prevented that physician from being in the room. The second layer is where defendants push back hardest, arguing that even a diligent review would have cleared the doctor. That is why the red-flag evidence matters so much: a documented history the hospital could have seen closes the gap between the breach and the harm. Without it, the claim collapses into speculation.

Where it fits the settlement picture

Negligent credentialing adds a defendant with its own insurance tower and, often, its own appetite to settle rather than air its governance failures to a jury. It also reshapes the lien analysis, because a hospital that treated the patient and is also a defendant faces obvious problems asserting its own hospital lien against the recovery. Practitioners building medical-malpractice files should plead the credentialing theory early, because the discovery it unlocks takes time to pry loose, and the relevant appellate authority on privilege varies enough by state that the fight has to start at the first request for production.

The takeaway

The credentialing claim converts a hospital from a bystander into a principal with its own duty and its own paper trail. The evidence is documentary, the breach is measured against the hospital's own rules, and the causation proof depends on red flags the process should have caught. Demand the privileging file early, hold the line on the privilege distinction, and make the hospital account for the physician it chose to let operate.

The LawyersTrend Brief · Fridays

One weekly email. Every new article.

Friday mornings — every PI article we publish that week, plus rankings updates and key verdicts. Free. One-click unsubscribe.