Blog · HIPAA email

How to handle a HIPAA incident that started in an inbox

A misdirected referral is an incident first. Whether it becomes a reportable breach depends on what you do in the next hours.

The most common clinic incident is not a nation-state attacker. It is a referral sent to the wrong practice, an attachment with the previous patient still attached, or a staff member who forwarded a thread to themselves.

First hour

  • Stop further sends. Recall if the system supports it; do not assume recall worked.
  • Ask the unintended recipient to delete the message and confirm in writing.
  • Preserve the original message and headers. Do not "clean up" the inbox.
  • Notify the privacy officer, not only the office manager.

Then document the assessment

HIPAA asks whether PHI was compromised. That analysis needs facts: what was in the message, who received it, whether it was opened, and what mitigation you completed. Consumer email rarely gives you those facts. A healthcare inbox with archiving does.

HIPAA Companion keeps message activity in an audit-ready log so the privacy officer is not reconstructing a story from screenshots. Pair that with a written incident procedure and a short staff drill twice a year.