OSHA Compliance

10 Common OSHA 300 Log Mistakes Healthcare Facilities Make (and How to Avoid Them)

carefoundryESC Team · Occupational Health & Compliance · Oct 8, 2025 · 7 min read

Last reviewed Oct 8, 2025

If you keep the OSHA 300 Log for a hospital or nursing facility, be aware that OSHA 300 Log mistakes now carry higher stakes than they did two years ago — because the rules changed under you and a lot of teams haven't caught up. As of January 1, 2024, establishments with 100 or more employees in designated high-hazard industries have to electronically submit the detailed Form 300 and Form 301 data to OSHA every year, not just the 300A summary they've been uploading (OSHA final rule, July 17, 2023). Hospitals and nursing/residential care are explicitly on that list: NAICS 6221, 6222, 6223 and the 623 codes all appear in Appendix B to Subpart E. So no, healthcare is not partially exempt, and the case-level detail you used to keep in-house now leaves the building.

That raises the stakes on getting the log right. Here are the ten recordkeeping mistakes healthcare teams make most, with the fix for each.

1. Mishandling needlesticks and sharps injuries

Two errors ride together here. First, a needlestick or a cut from a sharp contaminated with blood or OPIM is recordable — people forget these when the employee "feels fine." Second, these are privacy concern cases. You must not write the employee's name on the 300 Log; you enter "privacy case" and keep a separate, confidential list matching case numbers to names (1904.29(b)(6)–(9)). The same privacy rule covers HIV, hepatitis, TB, mental illness, injuries to an intimate body part, and cases from sexual assault. Facilities still routinely leave employee names in the Name column for exactly these entries.

2. Guessing at recordability

A case is recordable if it's work-related and results in any one of: death, days away from work, restricted work or job transfer, medical treatment beyond first aid, loss of consciousness, or a significant injury or illness diagnosed by a physician or other licensed health care professional (1904.7(b)(1)). Two traps: treating "beyond first aid" loosely — the test is whether the treatment used a nonprescription medication at nonprescription strength (first aid) versus a prescription medication or an over-the-counter drug at prescription strength (medical treatment) — and missing that a clinician's diagnosis alone (cancer, a fractured bone, a punctured eardrum) makes a case recordable even with no lost time.

3. Blowing the 7-day entry deadline

You have seven calendar days from receiving information that a recordable case occurred to enter it on both the 300 Log and the 301 (1904.29(b)(3)). Calendar, not business — a Friday report doesn't buy you the weekend. The fix is a standing intake habit: log first, investigate the details after.

4. Miscounting days — and not capping at 180

Day counts drive your rates, so errors here compound. Two things trip people up. You count calendar days, not scheduled workdays. And you may cap days away at 180, with the same 180-day cap on restricted or transfer days (1904.7(b)(3)(vii) and (b)(4)). Once a case hits 180 in either column, you stop counting — you're not required to track beyond that.

5. Correcting the log the wrong way

This one draws citations because it's so visible. When you find an error or reclassify a case, you line out or remove the original entry and enter the corrected information. Do not erase it, do not white it out, do not scribble it into oblivion (1904.33(b)(1)). The old entry should still be legible; the correction sits alongside it. This same section requires you to keep the log current for newly discovered or reclassified cases throughout the retention period.

6. Throwing records out too early

Keep the 300 Log, the privacy case list, the 300A annual summary, and the 301 forms for five years past the end of the calendar year they cover (1904.33(a)). If a compliance officer asks for 2020 during a 2025 inspection, you need it. Purging on a rolling one- or three-year schedule — a common records-retention default — is a recordkeeping violation waiting to happen.

7. Botching the 300A certification

The annual summary isn't self-certifying. A company executive must sign it — specifically an owner, a corporate officer, the highest-ranking company official working at that establishment, or that person's immediate supervisor (1904.32(b)(3)–(4)). The OH nurse or safety coordinator preparing the summary usually does not qualify. Get the signature lined up before February.

8. Missing the posting window (and skipping the year-end review)

Post the 300A from February 1 through April 30 (1904.32(b)(6)). Taking it down May 1 is fine; taking it down in February is not. Before you post, you're required to review the log for completeness and accuracy and fix any gaps (1904.32(a)(1)) — that review is the mistake-catcher for the 300 log errors described above.

9. Skipping the ITA electronic submission

Back to the big one. If your establishment had 100+ employees at any point last year and falls in a covered NAICS code, you must submit your 300 and 301 data through OSHA's Injury Tracking Application by March 2. OSHA does not take these by mail or email. Establishments with peak employment of 19 or fewer, and those in partially exempt industries, don't submit — but most hospitals and nursing facilities are well over the line. Check the ITA Coverage Application if you're unsure whether a given establishment qualifies.

10. Confusing recording with reporting — and chilling reports

Recording (the log) and reporting (calling OSHA) are separate duties. You must report a work-related fatality within 8 hours, and an in-patient hospitalization, amputation, or loss of an eye within 24 hours (1904.39(a)(1)–(2)). Logging it is not reporting it. And watch the culture piece: you must maintain a reasonable procedure for employees to report injuries and cannot retaliate against anyone who does (1904.35(b)(1)). Post-incident policies that discourage reporting are themselves a violation.

What these mistakes cost

Recordkeeping isn't a footnote in the penalty schedule. The federal maximums taking effect January 15, 2026 run up to $16,550 per violation for serious, other-than-serious, and posting/recordkeeping violations, up to $16,550 per day for failure to abate, and up to $165,514 per violation for willful or repeated violations (OSHA Penalties). Miss the posting, skip the certification, and blow the ITA upload in the same year and those stack.

One caveat worth stating plainly: these are federal figures and federal deadlines. If you operate in a State Plan state — California, Washington, Michigan and others — your penalty amounts and some recordkeeping specifics may differ, and you should confirm against your state agency. This article is practitioner guidance, not legal advice.

FAQ

How long do I have to keep the logs? Five years past the end of the calendar year the records cover — the 300 Log, the privacy case list, the 300A summary, and the 301 forms (1904.33(a)).

How do I fix a mistake on the 300 Log? Line out or remove the original entry and write the corrected information next to it. Never erase or white out — the original must remain legible (1904.33(b)(1)).

What recordkeeping errors most often trigger citations? Late or incomplete logs, missing the year-end review, an uncertified or unposted 300A, a failed ITA submission, and improper corrections — each carrying up to $16,550 per violation (OSHA Penalties).

Most of these come down to the same discipline: enter within seven days, review before posting, and treat the log as a living record you keep current for five years. If you're still tracking recordability, privacy cases, and 300A/301 output in a spreadsheet, a purpose-built system like carefoundryESC can generate the OSHA forms and flag privacy cases automatically — but the rules above hold no matter what tool you use. When in doubt on a close call, the primary sources linked here are the ones an inspector will cite too.

See carefoundryESC in action

Generate OSHA 300/300A/301 reports, track immunizations, and manage employee health from one HIPAA-aligned system.

Request a demo →
← Back to the blog