HIPAA Social Media Violation: Response & Prevention

Quick response guide for patient information posted on social media platforms

Immediate Action Required

Response Timeline

First Hours

  • Screenshot the post with date, time, and URL information
  • Document the platform, account, and visibility (public/private)
  • Note the date/time posted and date/time discovered
  • Request immediate content removal from platform
  • Contact the poster (if employee) and request removal
  • Preserve all evidence and comments on the post
  • Notify your IT/security and compliance teams

First 24 Hours

  • Confirm content removal from the platform
  • Request archival removal from search engines if needed
  • Interview the employee about intent and access to patient information
  • Identify all patient information that was disclosed
  • Determine how many people viewed/shared the content
  • Assess whether content identified specific patients
  • Begin preliminary breach assessment
  • Consult with legal counsel

First 7 Days

  • Complete breach assessment and documentation
  • Determine if OCR notification is required
  • Identify all affected patients
  • Prepare breach notification messages
  • Monitor for ongoing spread or commentary
  • Conduct investigation of how employee accessed information
  • Prepare disciplinary recommendation

First 30 Days

  • Conduct disciplinary hearing with employee
  • Issue disciplinary action or termination
  • Send breach notifications to affected patients (within 60 days)
  • Provide public notification if 500+ affected
  • File OCR notification if breach confirmed
  • Implement corrective action plan
  • Issue policy updates and training

60+ Days

  • Submit OCR notification if required
  • Monitor social media accounts for future violations
  • Conduct staff retraining on social media policies
  • Implement technical controls on social media access
  • Audit employee use of social media during work
  • Retain documentation for ongoing monitoring

Content Removal Strategy

Take immediate steps to remove the content from circulation:

Investigation Process

A thorough investigation is critical for compliance:

Patient Notification

Social media disclosure is presumed to be a breach requiring notification:

Policy and Prevention Measures

Social media policies should include:

Technical controls:

Frequently Asked Questions

Is posting patient information on social media always a breach?
Yes, posting identifiable patient information on social media is a breach under HIPAA. Even if the patient is not named, any information that could identify them (demographics, medical condition, location, etc.) is PHI and protected. There are no exceptions for social media.
What should I do if I find content posted by an employee?
Immediately request removal from the platform by contacting their abuse/support team. Take screenshots to document the post. Contact the employee and request they remove it. Assess the severity and begin investigation. Notify your compliance, legal, and IT teams immediately. Document all actions taken.
What if the content goes viral?
Work with the social media platform to remove content and request archival removal. Notify affected patients immediately. Consider issuing a public statement explaining the breach and steps being taken. Monitor for ongoing spread and screenshot evidence. Report to OCR as a material breach.
Can I discipline an employee for this?
Yes, your sanctions policy should address social media violations. Depending on intent and severity, discipline can range from written warning to termination. Malicious disclosures should result in termination. Negligent disclosures should result in suspension or termination. Document all disciplinary actions.

Strengthen Your Social Media Compliance

Get a comprehensive security assessment to identify gaps in your policies and controls.

Get Your Security Analysis