HIPAA: Records Sent to Wrong Patient — What to Do
Quick response guide for misdirected medical records and necessary patient notifications
Immediate Action Required
- Identify the recipient of the misdirected records immediately
- Attempt immediate retrieval or destruction
- Contact the wrong recipient by phone first if possible
- Assess what information was inadvertently disclosed
- Document all details of the incident
- Determine if this constitutes a breach
- Notify compliance and legal teams
Response Timeline
First Hours
- Discover and confirm misdirected records incident
- Identify the recipient and contact information
- Attempt immediate phone contact with the recipient
- Request that records be returned or destroyed immediately
- Document the date, time, and method of discovery
- Note what patient information was in the misdirected records
- Identify the intended recipient
- Notify your compliance officer
First 24 Hours
- Follow up in writing with the recipient requesting return
- Send formal written request for destruction/return
- Maintain detailed log of all communication attempts
- Assess whether the recipient accessed or read the records
- Determine if retrieval was successful
- Conduct preliminary breach assessment
- Identify the data involved (names, medical conditions, etc.)
- Notify legal counsel of incident
First 7 Days
- Complete retrieval or document inability to retrieve
- Conduct full breach assessment and documentation
- Determine if OCR notification is required
- Identify all patients affected (both who records were from and who received them)
- Prepare breach notification messages if required
- Review the transmission method and identify system failures
- Plan process improvements
First 30 Days
- Send breach notifications if required (within 60-day deadline)
- Notify media if 500+ patients affected in a jurisdiction
- File OCR notification if breach is confirmed
- Provide supporting documentation to affected parties
- Implement immediate process improvements
- Document all corrective actions
60+ Days
- Submit OCR notification if required
- Complete implementation of preventive measures
- Conduct staff training on record transmission procedures
- Perform audits of record transmission practices
- Monitor for any evidence of unauthorized use
- Retain documentation for potential investigation
Breach Assessment
Determining whether misdirected records constitute a breach depends on several factors:
- Internal misdirection: If records were misdirected to another department within the same covered entity, it may not be a breach if that person has treatment/operations access
- External misdirection: If records went to someone outside your organization, it is typically a breach
- Same patient different unit: Sending one patient's records to another patient in the same organization is a breach
- Successful retrieval: Even with successful retrieval, you must notify both patients if they became aware of the disclosure
- Presumed access: Assume the recipient accessed the information unless evidence shows otherwise
Patient Notification
If a breach is determined, you must notify:
- Patient whose records were misdirected: They were the intended recipient, so they should receive the records anyway
- Patient/recipient who received wrong records: They must be notified they received someone else's PHI
- Timeline: Notification must be sent within 60 days of discovery
- Content: Explain what happened, what information was disclosed, steps to minimize risk, and your corrective actions
Process Improvements
Implement systems to prevent misdirection:
- Automated verification: Use database matching to verify recipient identity before transmission
- Unique identifiers: Use medical record numbers, DOB, and address matching
- Double verification: Require staff to verify recipient information before sending
- Barcode/scanning: Use barcode scanning to match records to recipient
- System improvements: If electronic transmission, implement safeguards in your system
- Staff training: Regular training on proper transmission procedures
- Audit trails: Maintain logs of all record transmissions
- Exception reports: Generate reports of failed verification attempts
Documentation
Maintain comprehensive documentation of the incident:
- Date and time of discovery
- Method of transmission used
- Recipient identification information
- All communication attempts and responses
- Breach assessment findings
- Notification messages sent
- Corrective action plan and implementation
- Follow-up audit results
Frequently Asked Questions
Is misdirected records always a breach?
Not automatically. If the recipient has legitimate access to the records within your organization (same healthcare facility, same department), it may not be a breach. However, if records were sent to a completely unrelated patient or person outside your organization, it is a breach. When in doubt, treat it as a breach.
What if the recipient already received the records?
Immediately contact them requesting return or destruction. You can attempt retrieval even after delivery. If retrieval fails or the recipient refuses, treat as a breach and notify the affected patient. Send a written request documenting your retrieval efforts.
Do I need to notify the patient who received the wrong records?
Yes, the patient who inadvertently received someone else's records must be notified that they received PHI of another person. This notification is required even if you successfully retrieve the documents. They should be notified of what information was exposed and steps to protect themselves.
What process improvements should I implement?
Implement verification procedures before transmission, use unique identifiers, implement double-check systems, and use automated matching to verify recipient information. Consider barcode scanning for paper records and verification workflows for electronic transmissions. Conduct regular audits and staff training.
Prevent Future Incidents
A security risk analysis can identify gaps in your processes and systems.
Get Your Security Analysis