Found Paper EOBs in a Dumpster Behind an Outpatient Clinic? Here’s What to Do Next

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Found Paper EOBs in a Dumpster Behind an Outpatient Clinic? Here’s What to Do Next

Kevin Henry

Data Breaches

August 28, 2026

6 minutes read
Share this article
Found Paper EOBs in a Dumpster Behind an Outpatient Clinic? Here’s What to Do Next

Discovering Paper EOBs in a Dumpster

If you stumble on Explanation of Benefits (EOB) documents in a dumpster, treat the situation as urgent. EOBs often list patient names, account numbers, services, and plan details—information that qualifies as Protected Health Information and must be safeguarded.

Because these documents likely originate from a healthcare provider or health plan, mishandling them can trigger obligations under the Health Insurance Portability and Accountability Act. Your goal is to minimize further exposure, alert responsible parties quickly, and help ensure the records are secured without creating additional risk.

Taking Immediate Precautions

If you are a passerby or neighbor

  • Do not read, sort, photograph, or share the pages. Avoid spreading Protected Health Information.
  • Do not climb into containers or remove items; respect private property and your personal safety.
  • Note the date, time, and precise location. Capture only high-level details (for example, the clinic name on a bin) without photographing readable patient data.
  • If safe and lawful, reduce scatter risk—such as gently closing a lid—then step away.
  • Notify the clinic immediately and ask for the Compliance Officer or manager on duty. If you cannot reach anyone and the papers are at risk of public exposure, consider contacting property management or the non-emergency police line.
  • Avoid posting about the discovery on social media; that can amplify the Privacy Breach Notification scope.

If you work for the clinic

  • Secure the area and pause routine trash pickup. Retrieve documents using gloves and place them into locked containers designated for Secure Document Disposal.
  • Log who secured the records, when, and from where. Keep a simple chain-of-custody record without creating new copies of PHI.
  • Preserve minimal, non-identifying photos of the scene (for internal compliance only) and immediately notify your Compliance Officer and privacy team.

Understanding Privacy and Security Risks

Paper EOBs can expose patients to Identity Theft Risk and medical identity fraud. Details like policy numbers, service dates, and provider information can be misused to obtain care, submit false claims, or open accounts.

Beyond financial harm, improper disclosure undermines patient trust and can result in regulatory scrutiny and penalties. Even a small stack of EOBs can affect dozens of people, so act quickly to contain and document the incident.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Reporting to Authorities

If you are a member of the public

  • Contact the clinic and ask to speak with the Compliance Officer or practice manager. Provide the location and what you observed without sharing patient details.
  • If the clinic cannot be reached or does not respond, you may notify the health plan named on the EOBs or submit a complaint to the federal agency that enforces HIPAA.
  • Call law enforcement if you suspect criminal dumping, tampering, or imminent misuse of the records.

If you work for the clinic

  • Notify leadership, legal counsel, and the Compliance Officer immediately. Begin a documented risk assessment to determine whether a reportable breach occurred.
  • Follow your incident response plan, including escalation steps, containment, and verification of how the materials entered the waste stream.
  • Begin preparations for Privacy Breach Notification and other Regulatory Reporting Requirements, as applicable.

Implementing Corrective Measures

Once the records are secured, focus on root cause and remediation. Determine whether the documents came from patient correspondence, billing, or a third party. Interview staff, review workflows, and examine camera or access logs if available.

  • Immediate fixes: replace open bins with locked consoles, schedule an urgent pickup by your Secure Document Disposal vendor, and suspend standard trash service until controls are restored.
  • Process changes: update written procedures, post signage near printers and mailrooms, and require double-checks before discarding any paper related to billing.
  • People actions: provide rapid refresher training, reinforce “no PHI in regular trash,” and apply sanctions per policy if warranted.
  • Patient support: prepare call center scripts and consider credit monitoring if data elements raise Identity Theft Risk.
  • Verification: conduct a post-incident audit to confirm corrective actions are working and documented.

Under the Health Insurance Portability and Accountability Act, EOBs typically contain Protected Health Information. An impermissible disclosure may trigger the HIPAA Breach Notification Rule, requiring notices to affected individuals without unreasonable delay and, in many cases, notifications to federal regulators and other parties.

State privacy and data breach laws may impose additional duties, timelines, or thresholds, including notifications to state attorneys general or consumer reporting agencies. If a disposal vendor handles PHI, ensure there is a current business associate agreement and that the vendor’s practices meet your Regulatory Reporting Requirements and security standards.

Penalties can include corrective action plans and civil monetary penalties. Thorough documentation, prompt mitigation, and demonstrated improvements are essential in regulatory reviews.

Preventing Future Disclosures

  • Deploy locked shred consoles in all work areas and require cross-cut shredding or certified destruction through a vetted Secure Document Disposal vendor.
  • Adopt “scan-and-destroy” workflows with retention schedules, so paper is kept only as long as necessary and disposed of securely.
  • Train staff on handling EOBs and other PHI at onboarding and through periodic refreshers; reinforce with quick-reference posters near discard points.
  • Audit routinely: spot-check bins, review vendor chain-of-custody records, and run simulated “dumpster” tests.
  • Tighten physical controls: keep loading docks, mailrooms, and copy areas restricted; place clear labels on trash vs. secure bins.
  • Monitor incidents centrally so your Compliance Officer can spot patterns and drive continuous improvement.

FAQs.

What should I do immediately after finding paper EOBs in a dumpster?

Avoid handling or photographing the pages, note the location and time, and alert the clinic’s Compliance Officer or manager right away. If the papers are scattering and you cannot reach anyone, reduce the spread only if safe and lawful, then step back and consider notifying property management or non-emergency law enforcement.

Who should be notified about the discovery?

Start with the clinic’s Compliance Officer or practice manager. If they are unreachable or unresponsive, you can notify the health plan named on the EOBs or contact the federal agency that enforces HIPAA. If criminal dumping or theft is suspected, involve local law enforcement.

What laws protect patient information in this situation?

The Health Insurance Portability and Accountability Act protects medical privacy and governs how covered entities and their business associates handle PHI. Many states also have breach notification and medical privacy statutes that can add duties and timelines beyond HIPAA’s Privacy Breach Notification framework.

How can clinics prevent future disposal breaches?

Use locked consoles and certified Secure Document Disposal, train staff regularly, audit discard points, and maintain strong vendor oversight. Pair these controls with documented procedures, retention schedules, and active monitoring by your Compliance Officer to reduce risk and meet Regulatory Reporting Requirements.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles