How to Report a Potential HIPAA Breach Internally: Step-by-Step Guide for Employees
If you suspect that protected health information (PHI) was exposed or misused, rapid, accurate internal reporting protects patients and your organization. This step-by-step guide shows you exactly how to recognize an issue, alert the right people, and support a timely, compliant response.
Identifying a Potential HIPAA Breach
Know what counts as PHI
PHI is any individually identifiable health information in any form (paper, verbal, electronic) linked to a person’s past, present, or future health, care, or payment. Examples include names, addresses, medical record numbers, full-face photos, device identifiers, and visit dates when tied to health details.
Common red flags
- Misdirected emails, faxes, or mailings containing PHI.
- Lost or stolen devices that store or can access PHI (laptop, phone, USB), especially if unencrypted.
- Unauthorized chart access (“snooping”), sharing passwords, or viewing records without a need to know.
- Discussing patient details in public areas or on unsecured messaging platforms.
- Ransomware, phishing, or suspicious downloads affecting systems with PHI.
Incident vs. breach
Report any privacy or security incident immediately—do not self-diagnose whether it is a “breach.” The privacy officer or HIPAA compliance officer will perform a risk assessment to determine if breach notification is required.
Immediate Reporting Procedures
Act fast—within minutes
- Stop the exposure: recall misaddressed emails, retrieve paper records, and secure areas or devices.
- Preserve evidence: do not delete emails, alter logs, or wipe devices unless directed by IT/security.
- If a device is lost or stolen, notify IT/security at once to enable remote lock/wipe and change passwords.
- Escalate immediately through your internal reporting system and notify your supervisor as policy requires.
- Do not contact affected patients yourself unless instructed; centralized communication prevents confusion.
Designated Reporting Channels
Use the channels your organization designates for HIPAA issues. Typical options include:
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
- Internal reporting system (secure portal or incident hotline) available 24/7.
- HIPAA compliance officer or privacy officer for privacy matters; security officer/IT for security events.
- Immediate supervisor/manager, if policy directs reporting through the chain of command.
- For vendors/business associates: your organization’s privacy officer and, when required, the covered entity per the business associate agreement.
Methods for Reporting Incidents
Portal submission
- Choose the “privacy” or “security” category and enter a concise, factual description.
- Attach supporting screenshots or documents only if the portal is approved for PHI and limit to the minimum necessary.
- Record the case or ticket number for your records.
Hotline or phone
- State that you are reporting a potential HIPAA incident, then provide who, what, when, where, and how.
- Spell names and give contact details so investigators can reach you quickly.
Email or in-person (if permitted)
- Use a secure, designated mailbox. Do not include full PHI unless the channel is approved and encrypted.
- Sample subject: “Urgent: Potential HIPAA incident – Unit/Clinic – MM/DD/YYYY – Short descriptor.”
- Deliver any physical evidence (e.g., misdirected mailings) to the privacy office per policy.
Essential Information to Include
- What happened: clear, objective facts; how the issue was discovered.
- Dates and times: when it occurred and when you discovered/reported it.
- Location/systems: departments, applications, devices, or accounts involved.
- People involved: workforce members, vendors, or unauthorized recipients (names/titles if known).
- PHI details: types of data (e.g., names, MRNs, diagnoses), approximate number of individuals, and whether the information was encrypted or otherwise secured.
- Containment steps taken: recalls, retrievals, password resets, or device locks.
- Exposure scope: who could have viewed or acquired the information and for how long.
- Attachments or logs: only what policy allows; maintain incident documentation without altering originals.
- Your contact information and best times to reach you.
Maintaining Confidentiality During Reporting
- Share on a need-to-know basis only; avoid hallway conversations, texting, or unapproved chat tools.
- Use approved secure channels and mark submissions as confidential.
- Limit PHI in narratives to the minimum necessary; de-identify whenever feasible.
- Avoid blame—stick to verifiable facts so the investigation remains unbiased.
- Do not retaliate or speculate; most organizations have non-retaliation policies for good-faith reporting.
Follow-up and Investigation Procedures
What the privacy team will do
- Triage and containment: secure systems, recover misdirected PHI, and prevent further exposure.
- Fact-finding: collect logs, interview involved parties, and verify which PHI elements were affected.
- Risk assessment: evaluate the nature/extent of PHI, the unauthorized recipient, whether the data was actually viewed/acquired, and mitigation completed.
- Determination: decide if breach notification is required and document the rationale.
- Breach notification (if required): notify affected individuals without unreasonable delay and no later than 60 days after discovery; notify regulators and, in some cases, the media, as applicable.
- Remediation: implement a corrective action plan—process fixes, technology safeguards, retraining, or disciplinary measures as policy dictates.
- Closure: record outcomes and lessons learned to reduce recurrence.
Your role after reporting
- Be available for questions and provide additional evidence promptly.
- Follow containment instructions (password resets, revised workflows, updated checklists).
- Complete any required refresher training and apply new controls in daily work.
Conclusion
Report suspected HIPAA issues immediately, through designated channels, with clear facts and minimal necessary PHI. Strong incident documentation, swift escalation to the privacy officer or HIPAA compliance officer, and cooperation during follow-up enable timely breach notification decisions and an effective corrective action plan.
FAQs
What constitutes a HIPAA breach?
A HIPAA breach is generally an impermissible use or disclosure of unsecured PHI that compromises its privacy or security. Certain exceptions may apply (for example, good-faith, unintentional access by an authorized workforce member, or disclosures where the recipient could not reasonably retain the information). Your privacy team performs a risk assessment to determine whether breach notification is required.
Who should employees report a potential breach to?
Use your internal reporting system and notify your supervisor if policy requires. Always alert the privacy officer or HIPAA compliance officer; involve the security officer/IT for lost devices, phishing, or system issues. Vendors or business associates should also notify their own privacy officer and the covered entity per their agreement.
How quickly must a potential breach be reported internally?
Report immediately—preferably within the same business day and no later than 24 hours, per most organizational policies. Prompt reporting enables timely containment and supports external breach notification deadlines, which require notification to affected individuals without unreasonable delay and within 60 days of discovery when a breach is confirmed.
What information is required when reporting a HIPAA breach?
Provide who, what, when, where, and how; the PHI elements involved and estimated number of individuals; whether the information was encrypted or otherwise secured; steps you have taken to contain the issue; and your contact details. Attach logs or screenshots only through approved secure channels and keep the narrative factual for accurate incident documentation.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.