News
Do I Need a BAA With My Vendor? A Plain-English Guide to Which Vendors Require a Business Associate Agreement · Business AssociatesYour 'Success Story' Program Just Cost This Rehab Facility $182,000: The Cadia Healthcare HIPAA Settlement · OCR EnforcementAn Accounting Firm Just Paid a HIPAA Fine: BST and Co. CPAs and What It Means for Professional Services Firms · OCR Enforcement15 Million Records, a $10,000 Fine, and a Company That No Longer Exists: The MMG Fusion Story · OCR EnforcementOCR Creates Religious Discrimination Units: What the Restructuring Means for HIPAA Enforcement · Rule UpdateOCR Director: The Cost of Doing Nothing Is Very High · Rule UpdateHIPAA Victims May Soon Receive a Share of OCR Fines: What the Proposed Compensation Program Means · Rule UpdateOCR Restructured: Three New Divisions and What It Means for HIPAA Enforcement · Rule UpdateRehab Center Pays $103,000 After Phishing Attack: OCR's 11th Risk Analysis Enforcement Action · OCR EnforcementConcentra Pays $112,500 After Patient Made Six Records Requests Over 13 Months · OCR EnforcementHIPAA Security Rule Final Rule: May Deadline Passes With No Announcement · Rule UpdateDo I Need a BAA With My Vendor? A Plain-English Guide to Which Vendors Require a Business Associate Agreement · Business AssociatesYour 'Success Story' Program Just Cost This Rehab Facility $182,000: The Cadia Healthcare HIPAA Settlement · OCR EnforcementAn Accounting Firm Just Paid a HIPAA Fine: BST and Co. CPAs and What It Means for Professional Services Firms · OCR Enforcement15 Million Records, a $10,000 Fine, and a Company That No Longer Exists: The MMG Fusion Story · OCR EnforcementOCR Creates Religious Discrimination Units: What the Restructuring Means for HIPAA Enforcement · Rule UpdateOCR Director: The Cost of Doing Nothing Is Very High · Rule UpdateHIPAA Victims May Soon Receive a Share of OCR Fines: What the Proposed Compensation Program Means · Rule UpdateOCR Restructured: Three New Divisions and What It Means for HIPAA Enforcement · Rule UpdateRehab Center Pays $103,000 After Phishing Attack: OCR's 11th Risk Analysis Enforcement Action · OCR EnforcementConcentra Pays $112,500 After Patient Made Six Records Requests Over 13 Months · OCR EnforcementHIPAA Security Rule Final Rule: May Deadline Passes With No Announcement · Rule Update
Beginnerfront deskpractice managerprovidervendor

What should I do if I think something went wrong?

Wrong fax, strange email, lost phone, or coworker snooping, here's how to respond without making it worse.

TL;DR

Stop, tell your privacy officer or supervisor right away, and document facts. Do not try to cover it up or decide on your own if it is a 'real' breach. That is leadership's job with legal help.

Updated 2026-04-21

Most HIPAA problems are not movie-style hacker attacks. They are human moments: a fax to the wrong clinic, an email auto-filled to the wrong person, a tablet left in a coffee shop, or a curious employee opening a celebrity chart.

Your job is not to be the lawyer. Your job is to report quickly and preserve the story.

Step 1: Pause the harm if you can

If you just sent something to the wrong place, tell your supervisor immediately, sometimes IT or the recipient can contain the message before it spreads.

If a device is missing, report it so remote wipe or password rotation can start.

Step 2: Tell the right person today

Your practice should name a privacy officer or escalation path. Use it even if you feel embarrassed. Early reporting is what turns an "oops" into a managed incident instead of a cover-up.

Step 3: Write down plain facts

Note what happened, when, whose information was involved (best estimate), what systems were used, and what you already did. Screenshots and fax logs help.

Common situations

Wrong fax number. Notify supervisor; your office may call the recipient to request destruction; leadership decides if breach analysis is needed.

Email to the wrong address, IT may recall messages in some systems; if not, document and escalate.

Lost phone or laptop. Report immediately; encryption status matters a lot for next steps.

Coworker browsing charts with no work reason, Do not confront; report to the privacy officer for investigation.

What not to do

  • Don't delete evidence.
  • Don't promise a patient that "nothing will happen" until the facts are reviewed.
  • Don't decide on your own that it was "too small" to mention.

Not legal advice. Educational overview only; consult qualified counsel for your situation.