Ministry of Health Disability Support Reporting in New Zealand

Whaikaha and Ministry of Health-funded disability providers operate under reporting obligations that go beyond delivering services and submitting invoices. Incident reporting, service delivery data, and quality audit responses are all contractual obligations — and getting them wrong has real consequences for your contract, your star rating, and ultimately the people you support.

This article covers the three main reporting streams for NZ disability providers — incident notification, service delivery reporting, and quality certification — explains what triggers each, and shows how to build reporting discipline into daily operations so you're never reconstructing records from memory under audit pressure.

Reporting requirements vary by service type and funder. Always refer to your specific Whaikaha or MoH service specification for authoritative timelines and categories. Last reviewed: Aug 2026.

Three Reporting Streams — Don't Conflate Them

A common confusion for smaller providers is treating all reporting as one undifferentiated task. In practice there are three distinct streams, each with different triggers, frequencies, recipients, and consequences for non-compliance:

  1. Incident and serious event reporting — event-triggered notification to your funder when specified adverse events occur
  2. Service delivery reporting — periodic data submission showing what services were actually delivered against funded allocations
  3. Quality and certification reporting — responses to audit findings under Ngā Paerewa (NZS 8134:2021) and associated corrective action plans

Each stream has different failure modes. Missing an incident notification is a contract breach. Inaccurate service delivery data is a funding compliance issue. Failing to respond to audit findings within required timeframes can result in escalated monitoring or sanction. Understanding which stream each obligation belongs to prevents the common mistake of treating them all the same way.

Incident and Serious Event Reporting

What Must Be Reported

Your service specification lists the categories of events that require funder notification. These typically include:

  • Unexpected death — any death of a service user that was not anticipated given their known clinical condition at the time
  • Serious injury — injury requiring emergency department attendance, hospital admission, or specialist treatment
  • Abuse or neglect — actual or reasonably suspected physical, sexual, psychological, or financial abuse, or neglect causing harm, by any person in the service environment (worker, another service user, visitor, family member)
  • Restraint incidents — any use of physical restraint, seclusion, or restrictive practice that falls outside an approved behaviour support plan, and any near-miss where restraint was considered
  • Missing persons — a service user who cannot be located and is assessed as being at risk due to their circumstances
  • Serious medication errors — errors that caused harm or had the potential to cause serious harm; not every administration error requires notification, but the threshold is lower than many providers assume
  • Significant property damage — damage to the service environment or a service user's property that affects their safety or wellbeing

Reporting Timelines

Timelines vary by category and severity. As a general guide:

  • Immediate (within hours) — unexpected death, serious assault, suspected child abuse. These require a phone call to your contract manager followed promptly by a written report. Don't wait until you have the full picture to make the initial notification.
  • Within 24 hours — serious injury, missing persons, confirmed or strongly suspected abuse
  • Within 5 working days — other notifiable incidents as defined in your specification; full written investigation reports for urgent events initially reported by phone

These are defaults — your specific contract may have tighter timeframes. Check your service specification, not this article, for definitive timelines.

What a Strong Incident Report Looks Like

Funders are assessing not just what happened but how your organisation responds. A report that arrives late, is vague about facts, or shows no evidence of investigation or learning sends a signal about your governance. A strong incident report includes:

  • Date, time, and location — exact, not approximate
  • A factual description of events — what happened, in sequence, without interpretation or blame attribution
  • People involved — use initials or coded identifiers for service users to protect privacy in external reports
  • Immediate actions taken — what did you do in the first hour to ensure safety and contain harm?
  • Other notifications — police (if a crime may have occurred), the Health and Disability Commissioner (if the incident warrants), WorkSafe NZ (if a serious workplace injury or near-miss)
  • Investigation findings — what root cause analysis was done? What did you find?
  • Actions taken to prevent recurrence — specific, with responsible persons and completion dates
  • Outcome for the affected person — what happened to the service user? Are they safe?

Internal Incident Register

Beyond funder-notifiable incidents, maintain an internal register capturing all incidents — including minor ones, near-misses, and events that don't meet notification thresholds. This register is a quality improvement tool. Patterns in minor incidents often precede serious events — if a particular house is generating repeated "minor" falls, that pattern deserves intervention before someone is seriously injured.

Auditors regularly request the internal incident register. If it only contains events that were reported externally, it suggests either you're not recording minor events, or your threshold for funder notification is too high. Either way, it's a finding.

Service Delivery Reporting

What You Submit

Providers typically submit service delivery data to Whaikaha or MoH on a monthly or quarterly basis, depending on your contract. This data includes:

  • Hours delivered by service type and funding category
  • Number of people supported during the reporting period
  • New starts and exits — people who began or ended services
  • Variances from funded allocations — where actual delivery differs from the approved plan
  • Where required, outcome data — goals achieved, progress against support plan objectives

Why Accuracy Matters

Service delivery data drives funding reconciliation. Two types of error create problems:

  • Over-reporting — claiming for hours not delivered is fraud. Even if accidental, if your claim consistently exceeds verified delivery, recovery action follows.
  • Under-reporting — reporting fewer hours than delivered means you're delivering unfunded services from your own resources. Systematic under-reporting also masks unmet need that should be escalated through NASC for increased funding.

Your primary evidence for service delivery is your timesheet and clock-in records. GPS-verified clock-in creates an objective timestamp that is far more defensible in a funding audit than paper timesheets or a coordinator's manual records. Progress notes provide the narrative evidence that support was actually delivered in a meaningful way — not just that a worker was physically present.

Variances Require Explanation

If you consistently deliver significantly fewer hours than funded, your funder will ask why. Acceptable explanations include hospitalisation, person choosing to decline services, or support needs changing. Unacceptable explanations include roster gaps that were never filled or coordination failures. Each variance should be documented with a reason at the time, not reconstructed months later when the funder queries it.

Quality Certification and Audit Responses

Ngā Paerewa (NZS 8134:2021) audits are conducted by accredited Conformity Assessment Bodies. Audit outcomes fall into three grades:

  • Attained — fully meets the criterion
  • Partially attained — meets some but not all elements of the criterion; requires a corrective action plan
  • Unattained — does not meet the criterion; requires a corrective action plan with escalated timelines and possible follow-up audit

Responding to Corrective Action Notices

When your audit generates partial attainment or unattainment findings, you receive a corrective action notice specifying what must be addressed and by when. Your response must:

  • Acknowledge the finding — not dispute it unless you have clear evidence it was incorrectly assessed
  • Describe the specific actions you will take (not vague commitments like "we will improve our processes")
  • Assign responsibility — who is accountable for each action?
  • Set completion dates — realistic but not indefinite
  • Provide evidence of completion — when you've done what you said you'd do, document it and submit evidence

Funders assess not just whether the finding is addressed but whether your organisation is capable of identifying and fixing its own problems. A strong corrective action response demonstrates organisational learning. A perfunctory response that ticks boxes without addressing root cause signals the opposite.

Other Mandatory Notifications

Beyond your funder, several other agencies may require notification depending on the nature of the event:

  • WorkSafe NZ — notifiable workplace events include any death, serious harm, or notifiable disease that arises from work. A support worker injured during a client transfer, or a worker assaulted by a service user, may trigger WorkSafe notification obligations.
  • Police — any event that involves a crime (assault, theft, sexual offending, suspicious death) must be reported to Police. Don't wait for internal investigation to be complete before reporting a possible crime — report first, investigate in parallel.
  • Health and Disability Commissioner (HDC) — anyone can complain to the HDC about a health or disability provider. You're not required to self-refer to the HDC, but if a service user or family member indicates they intend to complain, be cooperative and transparent. Attempts to discourage complaints escalate situations that might otherwise be resolvable.
  • Privacy Commissioner — notifiable privacy breaches require notification under the Privacy Act 2020. See our article on NZ Privacy Act obligations for care providers for detail.

Building Reporting Into Daily Operations

Providers who treat reporting as a separate compliance activity inevitably find themselves reconstructing records under pressure. Providers who build it into daily operations never face that problem.

Progress Notes as the Foundation

Every shift should generate a progress note completed the same day. Progress notes are the primary evidence for service delivery reporting, incident investigations, and audit assessments. Notes written days or weeks after the fact are a red flag for auditors — they suggest documentation is created to justify claims rather than to record what actually happened.

Incident Register as a Live Document

The incident register should be updated the day an incident occurs, not weekly in a batch. Timeliness of internal recording is assessed during audits as an indicator of whether incidents are being taken seriously and investigated promptly.

Funder Reports from Actual Data

Service delivery reports should be generated directly from your timesheet and attendance data, not assembled manually from coordinators' recollections. If your service delivery reports require significant manual reconstruction, they're at high risk of inaccuracy — and inaccuracy in either direction creates compliance exposure.

The providers who get through audits cleanly aren't necessarily doing more work — they're documenting what they do systematically, in real time. See how KareShift helps NZ disability providers capture service delivery evidence, incident records, and timesheet data in one place.

Incident logging, timesheets, and progress notes — in one place

KareShift captures the service delivery evidence NZ disability providers need for funder reporting and audits. 90 days free — no credit card required.

Start Free Trial