What Counts as a Reportable HIPAA Breach When a Fax with PHI Goes to the Wrong Clinic?

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

What Counts as a Reportable HIPAA Breach When a Fax with PHI Goes to the Wrong Clinic?

Kevin Henry

HIPAA

September 03, 2026

7 minutes read
Share this article
What Counts as a Reportable HIPAA Breach When a Fax with PHI Goes to the Wrong Clinic?

Misdirected Fax as HIPAA Breach

A fax containing protected health information (PHI) sent to the wrong clinic is an impermissible disclosure to an unauthorized recipient. Under the HIPAA Breach Notification Rule, that disclosure is presumed to be a breach of unsecured PHI unless you can demonstrate—via a documented analysis—that there is a low probability the PHI was compromised.

Misdirected faxes typically stem from an incorrect number, an outdated speed-dial entry, or similar clinic names. Even if the recipient is another healthcare provider, they are not automatically authorized to receive your patients’ PHI. Whether the incident becomes reportable hinges on a timely, fact-based risk assessment and the effectiveness of your PHI exposure mitigation.

  • If the fax included only de-identified data, it is not PHI and therefore not a breach.
  • If PHI was included (e.g., names, diagnoses, account numbers), treat the event as a potential breach pending assessment.

Conducting a Risk Assessment

The four Risk Assessment Factors

  • Nature and extent of PHI involved: Identify data elements (e.g., name, DOB, diagnosis, SSN, financial or mental health details) and the likelihood of re-identification or harm.
  • Unauthorized recipient: Assess who received it (another clinic, vendor, individual), their role, and whether they are bound by privacy safeguards—even if still an unauthorized recipient.
  • Whether the PHI was actually acquired or viewed: Determine if anyone read, copied, scanned, or forwarded the fax (check e-fax access logs, print queues, and attestations).
  • Extent of mitigation: Document swift actions taken—retrieving pages, obtaining written attestations of destruction, sequestering emails, and confirming purges from e-fax systems.

Evidence to collect and preserve

  • Exact fax number dialed, timestamp, page count, and a copy of the transmission report.
  • Contact logs showing when you reached the recipient and who confirmed actions taken.
  • Attestations from the recipient that the PHI was not used or further disclosed and was securely destroyed or returned.
  • Internal notes explaining how the error occurred and what was done to prevent recurrence.

Illustrative outcomes

  • Likely not reportable: One-page scheduling slip with minimal identifiers faxed to the wrong clinic, retrieved immediately, not viewed or scanned, with prompt written confirmation of secure destruction. Document the low probability of compromise and your mitigation.
  • Likely reportable: Multi-page clinical notes with diagnoses and account numbers faxed to the wrong clinic, scanned into their system, or forwarded internally before discovery. The probability of compromise is not low; notifications are required.

Breach Notification Requirements

Who must notify

The covered entity (CE) is responsible for notifying affected individuals. A business associate (BA) must notify the CE without unreasonable delay, providing the identities of affected individuals and the available facts so the CE can meet its obligations.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

HIPAA Reporting Timeline

  • Individuals: Notify without unreasonable delay and no later than 60 calendar days from discovery of the breach.
  • U.S. Department of Health and Human Services (HHS): For 500 or more affected individuals in a state or jurisdiction, notify HHS without unreasonable delay and no later than 60 days from discovery; for fewer than 500, report to HHS no later than 60 days after the end of the calendar year.
  • Media: If 500 or more residents of a single state or jurisdiction are affected, notify prominent media outlets in that area within the same 60-day outer limit.

Content of individual notice

  • A brief description of what happened, including the date of the breach and the date of discovery.
  • The types of PHI involved (e.g., names, diagnoses, account numbers).
  • Steps individuals should take to protect themselves.
  • What you are doing to investigate, mitigate harm, and prevent a recurrence.
  • Contact information, including a toll-free number, email, or postal address.

Exceptions to Breach Presumption

Good Faith Disclosure Exception

An unintentional acquisition, access, or use of PHI in good faith by a workforce member, within the scope of authority, with no further impermissible use or disclosure, is not a breach. This typically does not apply when PHI is sent outside your organization to a different clinic.

Inadvertent disclosure within the same entity

Disclosure from one person authorized to access PHI to another authorized person within the same covered entity or business associate, without further impermissible use, is not a breach. It does not cover sending PHI to a separate clinic.

Recipient could not reasonably retain the information

If you have a good faith belief the unauthorized recipient could not reasonably have retained the PHI—such as a garbled, blank, or immediately intercepted fax—then no breach occurred. This exception is narrow and rarely fits printed faxes; rely on it only with strong documentation.

Documentation and Reporting Procedures

Immediate PHI exposure mitigation

  • Call the wrong clinic at once; ask for their privacy officer. Instruct them not to use, disclose, copy, or scan the fax.
  • Arrange secure destruction or return; request a signed attestation confirming no use or further disclosure and detailing destruction steps.
  • If e-fax was involved, obtain confirmation the document and any previews were purged and access logs preserved.

End-to-end workflow

  • Contain the incident and gather facts (who, what, when, how many individuals, types of PHI).
  • Apply the four Risk Assessment Factors and decide if the probability of compromise is low.
  • If reportable, follow the HIPAA Reporting Timeline for individual, HHS, and media notices as applicable.
  • Implement corrective actions: fix speed-dials, verify numbers, use cover sheets, consider secure alternatives to fax, retrain staff, and address sanctions as appropriate.
  • Retain all documentation—including your risk assessment, mitigation steps, decisions, and copies of notices—for at least six years.

Documentation fundamentals

  • Incident log with dates/times, numbers dialed, page count, and personnel involved.
  • Risk assessment write-up referencing the Risk Assessment Factors and outcome.
  • Mitigation records (attestations, retrieval/destruction confirmations, system logs).
  • Final determination, rationale, and approvals by the privacy or compliance officer.

Summary

A fax with PHI sent to the wrong clinic is an impermissible disclosure and is presumed a breach. Your decision to report turns on a documented risk assessment, effective PHI exposure mitigation, and whether any narrow exceptions apply. When in doubt—or when risk is not demonstrably low—follow the HIPAA Breach Notification Rule and the HIPAA Reporting Timeline.

FAQs

When is a misdirected fax considered a HIPAA breach?

It is presumed a breach because PHI was disclosed to an unauthorized recipient. If your documented risk assessment shows a low probability that the PHI was compromised—or a specific exception applies—it may be treated as a non-breach; otherwise, you must provide breach notifications.

What factors determine the risk assessment outcome?

The four Risk Assessment Factors: the nature and extent of PHI involved, who the unauthorized recipient was, whether the PHI was actually acquired or viewed, and how effectively you mitigated the exposure (e.g., prompt retrieval, destruction, and attestations).

How soon must affected individuals be notified of a breach?

Without unreasonable delay and no later than 60 calendar days from the date of discovery. For incidents involving 500 or more individuals in a state or jurisdiction, you must also notify HHS and the media within the same outer 60-day limit.

What documentation is required for reporting misdirected faxes?

Maintain an incident log, transmission reports, contact and mitigation records (including recipient attestations), a written risk assessment and decision rationale, copies of all notices, and proof of corrective actions. Keep these materials for at least six years to demonstrate compliance with the Breach Notification Rule.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles