HIPAA Breach Risk Assessment for Prescriptions Faxed to the Wrong Pharmacy

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Breach Risk Assessment for Prescriptions Faxed to the Wrong Pharmacy

Kevin Henry

HIPAA

August 26, 2026

8 minutes read
Share this article
HIPAA Breach Risk Assessment for Prescriptions Faxed to the Wrong Pharmacy

Definition of HIPAA Breach

A HIPAA breach is an impermissible disclosure or use of Protected Health Information (PHI) that compromises its security or privacy under the Breach Notification Rule. Faxing a prescription to the wrong pharmacy is typically an impermissible disclosure because the recipient is not the intended provider for that patient at that moment.

By default, such an incident is presumed to be a breach unless you complete a documented risk assessment showing a low probability that PHI was compromised. That assessment must consider specific Risk Assessment Factors and the totality of circumstances, not assumptions or verbal assurances alone.

In the fax context, “compromise” hinges on what was sent (identifiers, medication details), who received it (another covered entity vs. a non-covered party), whether it was actually viewed or retained, and how effectively you mitigated the exposure.

Key Risk Assessment Factors

Use the following four-factor framework to evaluate PHI exposure from a misdirected prescription fax, focusing on PHI re-identification risk and real-world likelihood of misuse:

1) Nature and extent of PHI involved

  • Identify all data elements: patient name, DOB, address, diagnosis, medication, prescriber, insurance details, and any sensitive indicators (e.g., HIV therapy or mental health medications).
  • Assess PHI Re-identification Risk: even limited data can re-identify a person when combined (name + rare medication + city). Limit harm by ensuring prescription templates avoid unnecessary identifiers.

2) The unauthorized person who received the PHI

  • If the wrong recipient is another pharmacy (a covered entity), the risk can be lower than if a non-covered party received it. However, “covered entity” status alone does not eliminate breach risk.
  • Evaluate their role-based access controls and willingness to attest that the fax was not further used or disclosed.

3) Whether the PHI was actually acquired or viewed

  • Determine if the fax auto-printed, was opened, or remained unread in a secure electronic fax queue. A transmission failure report (no delivery) differs materially from a confirmed printout in a public area.
  • Request details from the recipient: who saw it, for how long, and whether any copies, scans, or images were made.

4) The extent to which the risk has been mitigated

  • Obtain prompt, written confirmation that the recipient securely destroyed or returned all pages and did not further disclose the PHI.
  • Document containment steps, corrective actions, and training delivered to prevent recurrence.

Documentation essentials

  • Maintain a time-stamped record of discovery, investigation, all communications, the four-factor analysis, mitigation, and final determination. Retain evidence (e.g., attestation emails, fax confirmations).
  • Ensure the decision logic clearly supports either “breach—notify” or “low probability of compromise—no notification,” with rationale tied to the Risk Assessment Factors.

Faxing PHI Safeguards

Administrative Safeguards

  • Adopt a written fax policy defining permitted use, verification steps, error handling, and escalation to your Privacy or Security Officer.
  • Train staff on PHI handling, impermissible disclosure scenarios, and how to complete incident documentation within strict timeframes.
  • Maintain an approved directory of pharmacy numbers; require dual verification before adding or changing entries.
  • Use standardized cover sheets with a confidentiality notice that instructs unintended recipients to destroy or return the fax and immediately contact you.

Technical and physical controls

  • Locate fax printers in restricted areas; prohibit routing to public counters. For eFax solutions, ensure secure portals, access controls, and audit logs under a Business Associate Agreement.
  • Disable device memory retention on multifunction printers or enable secure overwrite. Configure automatic deletion of received faxes from electronic queues after processing.
  • Pre-program commonly used pharmacies to reduce misdials; restrict manual dialing when possible.

Process controls and safer alternatives

  • Use read-back verification: confirm the pharmacy name and digits of the number before pressing send.
  • For medications with heightened sensitivity, prefer secure electronic prescribing, including Electronic Prescriptions for Controlled Substances, where allowed by law and payer rules.
  • Require positive delivery confirmation and, for new pharmacies, a quick call-back validation.

Handling Misdirected Faxes

When you discover a misdirected prescription fax, act immediately to contain, investigate, and document the incident.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Immediate containment (same day)

  • Stop any further transmissions to the wrong number. Verify the correct destination and resend only after validation.
  • Call the recipient pharmacy, explain the error, and request secure destruction or immediate return via a secure method.
  • Ask whether anyone viewed, copied, scanned, or used the information; document names, times, and locations.

Verification and mitigation

  • Obtain written attestation from the recipient confirming no further use or disclosure and complete destruction/return of all pages (including cover sheets).
  • If the content could affect patient safety (e.g., controlled substances or therapy start dates), coordinate promptly with the prescriber and the correct pharmacy to prevent delays or duplicate dispensing.

Internal escalation and documentation

  • Notify your Privacy Officer immediately. Open an incident file with the fax image (if available), transmission logs, and all communications.
  • Perform and record the four-factor analysis; decide whether there is a low probability of compromise or a reportable breach.
  • Implement corrective actions: update directories, retrain staff, revise templates, or adjust device settings that contributed to the error.

Breach Notification Requirements

If you cannot demonstrate a low probability of compromise, you must provide notifications in accordance with the Breach Notification Rule.

Individual notice

  • Timeline: Without unreasonable delay and no later than 60 calendar days from discovery.
  • Content: A plain-language description of what happened, the types of PHI involved, steps individuals should take, what you are doing to mitigate and prevent recurrence, and contact methods for questions.
  • Method: First-class mail (or email if the individual has opted in). Use substitute notice when addresses are insufficient.

Regulatory reporting and media

  • To HHS: If 500 or more individuals are affected in a state or jurisdiction, report to HHS contemporaneously with individual notice and notify prominent media. For fewer than 500, log the breach and report to HHS within 60 days after the end of the calendar year.
  • Business Associates: If a fax service or vendor is involved, they must notify the covered entity without unreasonable delay, including the identities of affected individuals and what PHI was involved.

Recordkeeping

  • Retain your risk assessment, notifications, and mitigation evidence per retention policies. Ensure your breach log is complete and auditable.

Exceptions to Breach Definition

Three narrow exceptions may exclude an incident from being a breach; apply them carefully to misdirected faxes.

  • Unintentional acquisition, access, or use by a workforce member acting in good faith within scope of authority, with no further impermissible disclosure. This typically applies inside your organization, not a fax to an external pharmacy.
  • Inadvertent disclosure between authorized persons within the same covered entity (or organized health care arrangement), with no further use or disclosure. A wrong external pharmacy generally falls outside this exception.
  • Good-faith belief that the unauthorized person could not reasonably have retained the information. Examples: a failed transmission or illegible single line on a cover sheet, with evidence showing no retention. A fully printed fax at another pharmacy is usually retainable and thus unlikely to meet this exception.

Minimum Necessary Standard

The Minimum Necessary Standard requires limiting PHI to what is reasonably necessary for the purpose. Although disclosures for treatment are generally not subject to minimum-necessary limits, you should still design fax workflows and templates to avoid extraneous data so that, if a misdirected fax occurs, potential harm is minimized.

Applying minimum necessary to fax workflows

  • Use prescription templates that include only required identifiers and data elements; avoid diagnoses or notes unless necessary for dispensing.
  • Remove nonessential fields on cover sheets; never include Social Security numbers or unrelated clinical details.
  • Adopt role-based access, standardized data entry, and pre-approved pharmacy directories to reduce manual entry errors.
  • When feasible, replace fax with secure e-prescribing and Electronic Prescriptions for Controlled Substances to minimize exposure and create auditable trails.

Conclusion

A misdirected prescription fax is presumptively a breach unless your documented assessment shows a low probability of compromise. Apply the four Risk Assessment Factors rigorously, strengthen Administrative Safeguards and technical controls, and act quickly to contain and mitigate any exposure. Where possible, move to secure electronic prescribing to reduce fax-related risk altogether.

FAQs

What constitutes a HIPAA breach when faxing prescriptions?

A breach occurs when PHI is impermissibly disclosed—such as faxed to a pharmacy that is not the intended recipient—and the security or privacy of that PHI is compromised. Unless you can document a low probability of compromise after a four-factor analysis, you must treat the incident as a reportable breach.

How should a risk assessment be conducted for misdirected faxed PHI?

Evaluate the nature and extent of PHI (and PHI re-identification risk), who received it, whether it was actually acquired or viewed, and how fully you mitigated the exposure. Gather evidence—attestations, logs, timestamps—and document a clear rationale for your determination.

What are the notification requirements if a breach is confirmed?

Notify affected individuals without unreasonable delay and no later than 60 days from discovery, include required content, and use approved delivery methods. Report to HHS based on the number affected and notify the media if 500 or more individuals are impacted in a state or jurisdiction.

How can fax safeguards reduce breach risks?

Implement Administrative Safeguards, secure fax locations and eFax portals, verification and read-back steps, standardized cover sheets, and approved number directories. When feasible, replace faxing with secure e-prescribing and Electronic Prescriptions for Controlled Substances to reduce exposure and create robust audit trails.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles