News
TheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachQilin Ransomware Group Claims Attack on Hillebrand Home Health · Data BreachLake Region Healthcare Discloses May 2025 Network Intrusion Exposing Patient SSNs, Medical Records, and Financial Data · Data BreachFamily Health Centers of Southern Indiana Discloses January 2026 Network Intrusion Exposing Patient PHI Including Social Security Numbers · Data BreachInterlock Ransomware Group Claims 540 GB from Texas Hearing Institute, Nearly 30,000 Pediatric Patients Notified · Data BreachWisconsin Department of Health Services Reports HIPAA Breach Affecting 8,157 Medicaid Recipients After Benefits Letters Mailed to Wrong Addresses · Data BreachAmazon's One Medical Seniors Hit by ShinyHunters Extortion Group: 8.8TB of Legacy Patient Data at Risk · Data BreachTheGentlemen Ransomware Group Claims Attack on Advantage Home Health Care · Data BreachCraneware Healthcare Billing Software Breach: Hackers Steal 'Significant Volume' of Data from Vendor Used by Thousands of U.S. Hospitals and Pharmacies · Data BreachQilin Ransomware Group Claims Attack on Hillebrand Home Health · Data BreachLake Region Healthcare Discloses May 2025 Network Intrusion Exposing Patient SSNs, Medical Records, and Financial Data · Data BreachFamily Health Centers of Southern Indiana Discloses January 2026 Network Intrusion Exposing Patient PHI Including Social Security Numbers · Data BreachInterlock Ransomware Group Claims 540 GB from Texas Hearing Institute, Nearly 30,000 Pediatric Patients Notified · Data BreachWisconsin Department of Health Services Reports HIPAA Breach Affecting 8,157 Medicaid Recipients After Benefits Letters Mailed to Wrong Addresses · Data BreachAmazon's One Medical Seniors Hit by ShinyHunters Extortion Group: 8.8TB of Legacy Patient Data at Risk · Data Breach

I think a staff member at our practice violated HIPAA

Investigate promptly. Document everything. Determine if it is a reportable breach.

  1. 1

    Act immediately

    Do not wait. Interview the staff member, gather facts, and preserve any logs or records showing what was accessed. The 60-day breach reporting clock may be running.

  2. 2

    Document the investigation

    Write down everything: what happened, when, whose information was involved, how many patients, and what action was taken.

  3. 3

    Determine if it is a reportable breach

    Use our Breach Notification Checker tool or consult a HIPAA attorney. Not every violation is a reportable breach, but you must make this determination.

  4. 4

    Take appropriate disciplinary action

    HIPAA requires you to apply sanctions to workforce members who violate policies. Document the disciplinary action taken.

  5. 5

    Retrain and update policies if needed

    Identify why the violation happened and close the gap, whether through additional training, updated policies, or technical controls.

Important

If this involves a significant number of patients or sensitive circumstances, consult a HIPAA attorney before taking action.

Related

Not legal advice. Follow your organization's policies and consult counsel for legal questions.