What to Do If Patient Information Is Emailed to the Wrong Person: Immediate HIPAA Response Steps
Contact Unintended Recipient
When patient information is sent to the wrong person, treat it as a potential unauthorized disclosure of protected health information (PHI). Act immediately and launch your data breach response to contain the exposure and preserve evidence.
- Reach the unintended recipient at once (phone or secure message). Instruct them not to read, copy, save, or forward the message or attachments.
- Request prompt deletion from inbox, trash, cloud backups, and devices; ask for written confirmation (an email attestation is acceptable).
- If the message contained a secure portal link, revoke access or expire the link. If devices are managed, use remote wipe or recall tools where feasible.
- Notify your privacy officer or incident response lead immediately. If a business associate (BA) is involved, alert the BA contact named in the agreement.
- Preserve evidence: the original email, headers, recipient list, timestamps, bounce/recall notices, and any read receipts or server logs.
Do not conceal or delete records. Early, transparent action strengthens mitigation and supports compliance requirements.
Conduct Risk Assessment
Next, perform the Breach Notification Rule’s four‑factor analysis to determine the probability of compromise and whether HIPAA breach notification is required. Apply your organization’s risk assessment protocol and document each step.
- Nature and extent of PHI involved: Identify data elements (e.g., names, MRNs, diagnoses, medications, SSNs, financial details) and the likelihood of re‑identification.
- Unauthorized person: Consider who received the PHI (another provider bound by privacy rules versus a layperson) and their relationship to the patient.
- Whether PHI was actually acquired or viewed: Check access logs, read receipts, bounce messages, and the recipient’s attestation.
- Mitigation: Evaluate how quickly and completely you limited exposure (confirmed deletion, link revocation, remote wipe, confidentiality assurances).
Special considerations
- If the PHI was properly encrypted (and the key was not compromised), it may not constitute “unsecured PHI,” reducing breach likelihood.
- Inadvertent disclosures within a covered entity or BA between authorized persons may fall under HIPAA exceptions; sending PHI to an outside party generally does not.
- A strong, prompt mitigation record (e.g., written deletion confirmation with no evidence of viewing) can lower risk—but still requires thorough documentation.
- Assess applicable state privacy laws, which can impose shorter timelines or broader definitions than federal rules.
Notify Affected Individuals
If your analysis finds more than a low probability of compromise, provide HIPAA breach notification to each affected individual without unreasonable delay and no later than 60 calendar days from discovery. Coordinate content and delivery with your privacy officer or counsel.
What to include
- What happened, including the breach and discovery dates.
- Types of PHI involved (e.g., identifiers, clinical or financial data), not the full details.
- Steps individuals should take to protect themselves (e.g., monitor accounts, place fraud alerts if SSNs were involved).
- What you are doing to investigate, mitigate harm, and prevent recurrence.
- How to reach you (toll‑free number, email, or postal address).
Use first‑class mail or electronic notice if the individual has consented to email. If contact information is insufficient for 10 or more people, provide substitute notice (for example, a website posting and a toll‑free number available for a set period). Business associates must alert the covered entity so individual notifications can be made on time.
Report Large Breaches
For breaches affecting 500 or more residents of a state or jurisdiction, report to the U.S. Department of Health and Human Services Office for Civil Rights (HHS/OCR) and notify prominent media outlets serving that area without unreasonable delay and no later than 60 days from discovery.
For breaches affecting fewer than 500 individuals, maintain a breach log and submit it to HHS/OCR no later than 60 days after the end of the calendar year in which the breach was discovered.
Business associates must notify the covered entity without unreasonable delay and within 60 days of discovery (so the covered entity can meet its timelines). If law enforcement determines notice would impede an investigation, you may delay notifications as permitted; document any such request.
Ready to assess your HIPAA security risks?
Join thousands of organizations that use Accountable to identify and fix their security gaps.
Take the Free Risk AssessmentDocument Incident
Create complete, contemporaneous incident documentation. Strong records demonstrate due diligence and support audits, investigations, or patient inquiries.
- Discovery timeline: dates and times of the misdirected email, detection, containment, and escalation.
- People and systems: sender, recipients, approvers, mail servers, security tools involved.
- Scope: number of affected individuals and a description of PHI elements exposed.
- Mitigation artifacts: deletion attestations, link revocations, remote wipes, and log excerpts.
- Risk analysis: the four‑factor assessment, rationale, and final determination.
- Notifications: copies, mailing/email dates, and any OCR submissions or media notices.
- Corrective actions: policy changes, technical safeguards, sanctions, and assigned follow‑ups.
Retain incident documentation, risk assessments, and related policies for at least six years, as required by HIPAA record‑keeping rules.
Review Policies
Once the incident is stabilized, tighten policies and controls to prevent recurrence and to meet ongoing compliance requirements across the Privacy, Security, and Breach Notification Rules.
- Reinforce the minimum necessary standard and access controls for email and messaging.
- Reduce addressing errors: limit auto‑complete, require external‑address prompts, or enable “confirm recipient” checks.
- Implement or tune data loss prevention (DLP) for PHI patterns and auto‑encryption on outbound mail.
- Use secure messaging or portal delivery for PHI whenever possible; encrypt email containing PHI by default.
- Harden endpoints: multifactor authentication, MDM for remote wipe, and safe address‑book management.
- Review BA agreements for notification duties and security expectations.
- Update your incident response and data breach response runbooks; schedule regular tabletop exercises.
Provide Staff Training
Deliver targeted training to the sender and team so errors are less likely and are escalated quickly when they occur.
- Microlearning on handling PHI, recognizing risky workflows, and choosing secure channels.
- “Pause before send” habits: double‑check recipients, remove unnecessary PHI, and avoid relying on disclaimers.
- Simulation drills: misaddressed‑email exercises with immediate coaching and feedback.
- Clear escalation paths: who to contact, what details to capture, and how to preserve evidence.
- Measure understanding with short quizzes and track completion for audit readiness.
Conclusion
If patient information is emailed to the wrong person, move fast: contact the recipient, run a documented four‑factor assessment, notify individuals as required, report large breaches, and keep meticulous records. Then strengthen policies and train staff. These steps contain risk, meet HIPAA obligations, and restore trust.
FAQs
What immediate actions should be taken after misdirected patient information is discovered?
Act at once: contact the unintended recipient, instruct them not to read or share the message, and request confirmed deletion. Revoke links or remotely wipe managed devices if possible. Escalate to your privacy officer, preserve evidence (email, headers, logs), and begin your risk assessment protocol.
How is the risk assessment for a HIPAA breach conducted?
Use HIPAA’s four‑factor analysis: evaluate the PHI’s nature and identifiers; who received it; whether it was actually viewed or acquired; and how fully you mitigated the exposure. Document your reasoning and decision. If there is more than a low probability of compromise, proceed with HIPAA breach notification steps.
When must affected individuals be notified?
Provide notice without unreasonable delay and no later than 60 calendar days from discovery of the breach. Send first‑class mail (or email if the person agreed) with required details about what happened, what PHI was involved, protective steps, your mitigation efforts, and contact information. State laws may require even faster notification, so verify local timelines.
Ready to assess your HIPAA security risks?
Join thousands of organizations that use Accountable to identify and fix their security gaps.
Take the Free Risk Assessment