News
Aesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachAesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data Breach

I accidentally sent a fax to the wrong number

This may be a reportable breach. Take these steps in the next 24 hours.

  1. 1

    Tell your supervisor or privacy officer immediately

    Do not wait. Report the mistake to your practice manager or privacy officer right away. Time matters for breach response.

  2. 2

    Call the recipient of the fax

    If you know the number it went to, call and ask them to destroy the fax without reading it. Document whether they agreed. This can affect whether it's a reportable breach.

  3. 3

    Document everything

    Write down: what was faxed, whose information it contained, what number it went to, when it happened, and what steps you took. Your practice will need this.

  4. 4

    Your privacy officer will determine next steps

    They will assess whether this is a reportable breach under HIPAA. If the recipient could not have retained the information, it may not be reportable. Do not make this determination yourself.

Important

Your practice has 60 days from discovery to report a breach to HHS if it is determined to be reportable. The clock starts now.

Related

Not legal advice. Follow your organization's policies and consult counsel for legal questions.