Preparing Your OSHA ITA Submission Without Getting It Rejected
Last reviewed Aug 24, 2026
Electronic submission to OSHA's Injury Tracking Application is an annual chore with an unusual property: you do not find out whether it worked while you are doing it. The ITA validates on upload and answers by email. A rejection costs a round trip, and the round trips happen in the week before the deadline.
The short answer
Run OSHA's own documented cross-checks against your file before uploading. Most rejections are a handful of predictable problems, and two field codings are counterintuitive enough that they catch people out every year.
Who submits what
For healthcare, the answer is usually more than people expect, because the case-level requirement catches most real hospitals.
- 20 to 249 employees in a listed industry: submit Form 300A summary data.
- 100 or more employees in a listed industry: submit Form 300, Form 301 and Form 300A, which is case-level detail rather than totals.
- 250 or more employees: submit Form 300A.
The healthcare NAICS codes appear in the relevant appendices: 6221 general medical and surgical hospitals, 6222 psychiatric and substance abuse, 6223 specialty hospitals, 6231 skilled nursing, plus 6232, 6233, 6239 and 6243.
Any hospital worth the name has 100 or more employees, so the practical answer is that you are submitting full 300 and 301 case data every year.
Tracking this in a spreadsheet?
carefoundryESC keeps employee health records, exposures and the OSHA 300 log in one place, and generates the forms from the records you already keep. Pricing is published; migration is included.
The deadline
March 2, for the prior calendar year. Submission is by manual entry, CSV upload, or API.
The two codings that catch people
These are not intuitive, and getting either wrong produces a file that is accepted and wrong, or rejected without an obvious reason.
no_injuries_illnessesis 1 when there were injuries. Read the field name and you will assume the opposite. It is easy to invert across an entire file.sizeis a band, not a headcount. Putting your actual employee count in it is a common and immediately fatal error.
The cross-checks worth running first
OSHA publishes the validation rules. Running them yourself before upload turns a multi-day email round trip into a fix you make in the same sitting.
- Totals reconcile. The case counts on the 300A must equal what the case-level rows actually contain. If your 300A was maintained separately from the log, this is where it shows.
- Every case has an outcome. Death, days away, restricted or transfer, or other recordable. A case with none of them will not validate.
- Day counts are consistent. Days away and days restricted have caps and cannot exceed what the dates allow.
- Establishment data is complete. EIN, NAICS, address, and annual average employees, all present.
- Dates fall inside the reporting year, and the date of injury is not after the date of the report.
- Required narrative fields are present on every case-level row.
The privacy point nobody mentions until it is too late
The case-data file carries each employee's date of birth and date of hire. OSHA requires them; the 300A does not contain them.
This surprises people who have assumed their submission looks like the summary they post on the wall. It is worth knowing before the file is generated, because it changes who should be allowed to produce and handle it, and it is a reasonable thing to mention to your privacy officer once rather than discover in an audit.
It is also a reason to treat producing this file as a gated action rather than something any user can download.
Practical sequence
- Close the log for the year and reconcile the 300A against the cases, not the other way round.
- Generate the file and run the cross-checks above.
- Fix what fails, in the records rather than in the file, so next year is not the same exercise.
- Upload well before March 2, so that an unexpected rejection still leaves room.
- Keep the confirmation. "We submitted" is not a record.
carefoundryESC generates the ITA file from the case records and runs the documented cross-checks first, naming what to fix in plain sentences rather than leaving you to interpret a rejection email. The column names and value codings are transcribed from OSHA's published specifications rather than inferred. It is part of the OSHA compliance baseline.
Check the current specification
OSHA publishes the establishment and case-data specifications, and they are revised. Work from the current version for the year you are filing rather than from last year's file or from this article.