HIPAA: Records Sent to Wrong Patient — What to Do

Quick response guide for misdirected medical records and necessary patient notifications

Immediate Action Required

Response Timeline

First Hours

  • Discover and confirm misdirected records incident
  • Identify the recipient and contact information
  • Attempt immediate phone contact with the recipient
  • Request that records be returned or destroyed immediately
  • Document the date, time, and method of discovery
  • Note what patient information was in the misdirected records
  • Identify the intended recipient
  • Notify your compliance officer

First 24 Hours

  • Follow up in writing with the recipient requesting return
  • Send formal written request for destruction/return
  • Maintain detailed log of all communication attempts
  • Assess whether the recipient accessed or read the records
  • Determine if retrieval was successful
  • Conduct preliminary breach assessment
  • Identify the data involved (names, medical conditions, etc.)
  • Notify legal counsel of incident

First 7 Days

  • Complete retrieval or document inability to retrieve
  • Conduct full breach assessment and documentation
  • Determine if OCR notification is required
  • Identify all patients affected (both who records were from and who received them)
  • Prepare breach notification messages if required
  • Review the transmission method and identify system failures
  • Plan process improvements

First 30 Days

  • Send breach notifications if required (within 60-day deadline)
  • Notify media if 500+ patients affected in a jurisdiction
  • File OCR notification if breach is confirmed
  • Provide supporting documentation to affected parties
  • Implement immediate process improvements
  • Document all corrective actions

60+ Days

  • Submit OCR notification if required
  • Complete implementation of preventive measures
  • Conduct staff training on record transmission procedures
  • Perform audits of record transmission practices
  • Monitor for any evidence of unauthorized use
  • Retain documentation for potential investigation

Breach Assessment

Determining whether misdirected records constitute a breach depends on several factors:

Patient Notification

If a breach is determined, you must notify:

Process Improvements

Implement systems to prevent misdirection:

Documentation

Maintain comprehensive documentation of the incident:

Frequently Asked Questions

Is misdirected records always a breach?
Not automatically. If the recipient has legitimate access to the records within your organization (same healthcare facility, same department), it may not be a breach. However, if records were sent to a completely unrelated patient or person outside your organization, it is a breach. When in doubt, treat it as a breach.
What if the recipient already received the records?
Immediately contact them requesting return or destruction. You can attempt retrieval even after delivery. If retrieval fails or the recipient refuses, treat as a breach and notify the affected patient. Send a written request documenting your retrieval efforts.
Do I need to notify the patient who received the wrong records?
Yes, the patient who inadvertently received someone else's records must be notified that they received PHI of another person. This notification is required even if you successfully retrieve the documents. They should be notified of what information was exposed and steps to protect themselves.
What process improvements should I implement?
Implement verification procedures before transmission, use unique identifiers, implement double-check systems, and use automated matching to verify recipient information. Consider barcode scanning for paper records and verification workflows for electronic transmissions. Conduct regular audits and staff training.

Prevent Future Incidents

A security risk analysis can identify gaps in your processes and systems.

Get Your Security Analysis