When administrators think about breaches, they picture hackers and ransomware. But a great many privacy incidents in healthcare are mundane and entirely non-technical: an envelope addressed to the wrong person, a chart left on a counter, a fax sent to the wrong number. The HIPAA Breach Notification Rule applies to protected health information in any form, including paper, so these incidents deserve the same attention as a cyber event.
Resident or patient information placed in the wrong envelope, a window envelope that shows more than it should, or a mailing list that mixes up addresses.
A misdialed fax number or an autocompleted email address can send records to someone with no right to see them.
Charts on a nursing station counter, printouts at a shared printer, or a clipboard left in a hallway are visible to visitors and other residents.
Documents placed in regular trash or recycling rather than shredded.
Discussing a resident's condition in a hallway, a dining room or an elevator.
A bag with paperwork left in a car or on a bus, or a missing laptop or phone.
Monitors facing a lobby or open area, and workstations left unlocked.
Handing documents to a visitor or family member who is not authorized to receive them.
Make it a habit to verify the name on the document against the name on the envelope, and have a second person spot-check high-volume mailings. Choose envelopes that do not reveal sensitive information through the window.
Store frequently used fax numbers and confirm new ones by phone before sending. Turn off or review email autocomplete for external addresses, and use a cover sheet that includes a confidentiality notice and a callback number.
Adopt a clean-desk practice at nursing stations and offices. Charts are closed or put away when not in use. Set up printers so that print jobs are released only when the user is present.
Place locked shred bins where paper is generated, and use a documented pickup or on-site shredding service. Keep a record of when pickups occurred.
Remind staff to move conversations to private areas and keep voices low. Use names sparingly in public areas.
Use privacy filters and automatic screen locks, and place workstations so that screens are not visible to the public.
When records must leave the building, use a locked bag, keep it with you and never leave it in a vehicle.
Retrieve or contain the information as quickly as possible. Call the recipient and ask them to return or destroy it, and document that request.
Report it internally immediately to the privacy officer.
Document the facts: what was involved, who received it, when it happened and what was done.
Assess the incident under your breach policy. HIPAA requires a risk assessment to determine whether notification is needed, and specific timelines apply when it is.
Look for the cause and fix the process, not just the single mistake.
Staff who fear punishment hide mistakes. Make it simple to report, thank people who do, and share anonymized lessons in team meetings. A short reminder at huddles, such as a "verify before you send" moment, is more effective than an annual lecture.
UnityCare IT helps healthcare organizations with the technical side of privacy: print controls, screen locks, fax and email safeguards and secure document handling. We are glad to review your workflow with you.
Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172