The most common clinic incident is not a nation-state attacker. It is a referral sent to the wrong practice, an attachment with the previous patient still attached, or a staff member who forwarded a thread to themselves.
First hour
- Stop further sends. Recall if the system supports it; do not assume recall worked.
- Ask the unintended recipient to delete the message and confirm in writing.
- Preserve the original message and headers. Do not "clean up" the inbox.
- Notify the privacy officer, not only the office manager.
Then document the assessment
HIPAA asks whether PHI was compromised. That analysis needs facts: what was in the message, who received it, whether it was opened, and what mitigation you completed. Consumer email rarely gives you those facts. A healthcare inbox with archiving does.
HIPAA Companion keeps message activity in an audit-ready log so the privacy officer is not reconstructing a story from screenshots. Pair that with a written incident procedure and a short staff drill twice a year.
