HIPAA Social Media Violation: Response & Prevention
Quick response guide for patient information posted on social media platforms
Immediate Action Required
- Document the post with screenshots immediately
- Request content removal from the social platform
- Contact the employee who posted (if identifiable)
- Assess the extent and nature of the disclosure
- Identify all patients affected by the posting
- Notify compliance and legal teams immediately
- Assess breach severity and notification requirements
Response Timeline
First Hours
- Screenshot the post with date, time, and URL information
- Document the platform, account, and visibility (public/private)
- Note the date/time posted and date/time discovered
- Request immediate content removal from platform
- Contact the poster (if employee) and request removal
- Preserve all evidence and comments on the post
- Notify your IT/security and compliance teams
First 24 Hours
- Confirm content removal from the platform
- Request archival removal from search engines if needed
- Interview the employee about intent and access to patient information
- Identify all patient information that was disclosed
- Determine how many people viewed/shared the content
- Assess whether content identified specific patients
- Begin preliminary breach assessment
- Consult with legal counsel
First 7 Days
- Complete breach assessment and documentation
- Determine if OCR notification is required
- Identify all affected patients
- Prepare breach notification messages
- Monitor for ongoing spread or commentary
- Conduct investigation of how employee accessed information
- Prepare disciplinary recommendation
First 30 Days
- Conduct disciplinary hearing with employee
- Issue disciplinary action or termination
- Send breach notifications to affected patients (within 60 days)
- Provide public notification if 500+ affected
- File OCR notification if breach confirmed
- Implement corrective action plan
- Issue policy updates and training
60+ Days
- Submit OCR notification if required
- Monitor social media accounts for future violations
- Conduct staff retraining on social media policies
- Implement technical controls on social media access
- Audit employee use of social media during work
- Retain documentation for ongoing monitoring
Content Removal Strategy
Take immediate steps to remove the content from circulation:
- Platform removal: Contact the social media platform's abuse team with screenshots and request emergency removal
- Search engine removal: Use Google Search Console and Bing Webmaster Tools to request removal from search results
- Archive removal: Request removal from Internet Archive (archive.org) if indexed
- Original poster: Demand removal from the employee's account if they posted it
- Screenshot documentation: Maintain evidence for compliance and investigation
Investigation Process
A thorough investigation is critical for compliance:
- Who posted: Identify the employee responsible
- Information source: Determine how they accessed the patient information
- Intent assessment: Was this intentional breach or negligent mistake?
- Timing: When was the information accessed vs. posted?
- Pattern review: Check if this employee has prior violations
- Scope assessment: How many patients were affected?
- Extent of disclosure: What specific information was posted?
Patient Notification
Social media disclosure is presumed to be a breach requiring notification:
- Notify affected patients within 60 days of discovery
- Explain what information was posted and when
- Describe the platform and audience size
- Inform patients of the disciplinary action taken
- Offer credit monitoring if applicable
- Provide steps for patients to protect themselves
- Include information about your privacy practices
Policy and Prevention Measures
Social media policies should include:
- Prohibition on discussing patients or patient information on social media
- Clear definition of what constitutes PHI in social media context
- Expectations for personal vs. professional social media use
- Consequences for violations ranging from warning to termination
- Guidance on proper handling of patient stories if authorized
- Training requirements for all staff with patient access
Technical controls:
- Monitor employee social media activity during work hours
- Block access to personal social media from clinical systems
- Log access to patient records and cross-reference with social posts
- Use data loss prevention tools on workstations
- Monitor for suspicious posting patterns
Frequently Asked Questions
Is posting patient information on social media always a breach?
Yes, posting identifiable patient information on social media is a breach under HIPAA. Even if the patient is not named, any information that could identify them (demographics, medical condition, location, etc.) is PHI and protected. There are no exceptions for social media.
What should I do if I find content posted by an employee?
Immediately request removal from the platform by contacting their abuse/support team. Take screenshots to document the post. Contact the employee and request they remove it. Assess the severity and begin investigation. Notify your compliance, legal, and IT teams immediately. Document all actions taken.
What if the content goes viral?
Work with the social media platform to remove content and request archival removal. Notify affected patients immediately. Consider issuing a public statement explaining the breach and steps being taken. Monitor for ongoing spread and screenshot evidence. Report to OCR as a material breach.
Can I discipline an employee for this?
Yes, your sanctions policy should address social media violations. Depending on intent and severity, discipline can range from written warning to termination. Malicious disclosures should result in termination. Negligent disclosures should result in suspension or termination. Document all disciplinary actions.
Strengthen Your Social Media Compliance
Get a comprehensive security assessment to identify gaps in your policies and controls.
Get Your Security Analysis