
Sending a patient's medical information to the wrong recipient raises immediate questions about confidentiality and your practice's obligations under HIPAA.
An unauthorized disclosure of protected health information (PHI) generally creates a presumed breach. However, determining notification requirements requires an assessment of the information disclosed, who received it, and the circumstances surrounding the incident.
Thus, your practice must respond promptly and document its findings.
In this article, we discuss when a misdirected text constitutes a HIPAA breach, the actions your practice should take, and applicable notification requirements.
We also look at the recipient verification and how you can incorporate iPlum's secure texting into your patient communication procedures.
Table of Contents
1. When does texting the wrong patient constitute a HIPAA breach?
2. What should you do immediately after sending the text?
3. How should your practice assess the disclosure and decide on notification?
4. You can reduce wrong-patient texting errors with recipient checks and iPlum
5. Texting the wrong patient: frequently asked questions (FAQs)
6. Pair recipient checks with iPlum’s secure patient texting
When does texting the wrong patient constitute a HIPAA breach?
Determining when texting the wrong patient amounts to a HIPAA breach starts by answering the following questions:
Did the text disclose identifiable patient health information?
A message must contain PHI for its disclosure to constitute a HIPAA breach. PHI connects an identifiable patient to information about their health, treatment, or payment for care.
Examples include:
- A patient's name attached to laboratory results
- A prescription photograph showing identifying details
- A billing message identifying the patient and treatment received.
That said, a message need not name the patient to disclose PHI. A phone number, attachment, or combination of details can identify them. Conversely, a general office-hours announcement containing no identifiable patient information would not constitute a PHI disclosure.
Did the information reach a recipient who was not authorized to receive it?
Sending PHI to another patient generally constitutes an unauthorized disclosure. Receiving care at the same practice does not entitle the recipient to another patient's medical information.
Similarly, a relative's presence in your contact list does not establish permission to receive the information. Thus, your practice must determine whether HIPAA permitted the disclosure to that recipient under the circumstances.
Does the disclosure remain a presumed breach after assessment?
An unauthorized PHI disclosure is presumed to be a breach unless a defined exception applies or your practice documents a low probability that the information was compromised.
The assessment examines the information disclosed, the recipient, evidence of access or viewing, and measures taken to limit further exposure.
Therefore, if no exception applies and your practice cannot demonstrate a low probability of compromise, it must treat the disclosure as a breach. A recipient's promise to delete the text does not, by itself, establish otherwise.
What should you do immediately after sending the text?
Once you discover that a patient's information reached the wrong recipient, act promptly to limit further disclosure and establish what happened.
Your immediate response should proceed before your practice reaches a final breach determination.
Here's what that involves:
Stop further messages and notify your privacy officer
First, stop sending messages in the incorrect conversation. If you scheduled additional texts for that recipient, pause them until you verify the contact details.
Then notify your privacy officer or the person responsible for investigating privacy incidents. Provide the message content, the number that received it, and the times you sent the text and discovered the mistake.
In addition, report the facts you know. If you cannot determine who owns the number or whether they read the message, state that uncertainty instead of delaying the report.
Ask the unintended recipient to delete the information
Contact the recipient promptly, following your practice's incident response procedure. Explain that your practice sent the message in error and ask them to:
- Delete the text and any attachments.
- Refrain from copying, forwarding, or using the information.
- Confirm whether they opened, saved, or shared it.
During that exchange, avoid repeating the patient's name, diagnosis, or other medical details. In other words, do not disclose additional information.
Also, record the recipient's response, including any confirmation of deletion. If they have already forwarded the text, notify your privacy officer so the investigation can account for the additional disclosure.
Preserve the message and document your response
Preserve your practice's copy of the text and relevant records in an access-restricted incident file. Remember, deleting the conversation from the sender's phone does not erase the disclosure and could remove evidence needed for the assessment.
Be sure to document:
- The text and attachments sent
- The intended and unintended recipients
- Available transmission and read-status information
- Your attempts to contact the recipient
- Their responses and any actions taken
Also, distinguish confirmed facts from assumptions. A missing read receipt, for instance, does not establish that the recipient never viewed the information.
Verify the intended patient's details before continuing communication
Finally, compare the intended patient's number with the current patient record before resending the message. If the details conflict, verify them through an established contact method.
Where the text concerns urgent results or treatment instructions, arrange appropriate clinical follow-up promptly. Your practice should address the patient's care needs alongside the privacy investigation.
However, separate the clinical follow-up from formal breach notification. The privacy officer should coordinate any required notice based on the assessment.
How should your practice assess the disclosure and decide on notification?
Your privacy officer should use the evidence gathered during the initial response to evaluate the disclosure.
The assessment must explain what the facts establish and how they affect the notification decision.
Here's what the officer needs to do:
Evaluate the disclosure against HIPAA's four assessment factors
HIPAA requires consideration of at least four factors. For a text sent to the wrong patient, examine:
- The information disclosed: Identify the clinical details, identifiers, and attachments involved. Consider whether the recipient could identify the patient from the message or the surrounding context.
- The unintended recipient: Establish who received the text and whether they have confidentiality obligations. Another patient does not have the same professional obligations as a healthcare provider.
- Evidence that the information was acquired or viewed: Examine available message records and the recipient's response. A reply that discusses the results establishes more than just the transmission status.
- Measures taken to limit exposure: Evaluate the recipient's deletion confirmation, any evidence of forwarding, and your ability to address further disclosures.
Consider these factors together. After all, a reassuring response from the recipient does not outweigh evidence that they already shared the information.
Record why the notification is or is not required
After evaluating the evidence, document the conclusion and its basis. If your practice determines that notification is unnecessary, explain the applicable exception or the evidence establishing a low probability of compromise.
If the evidence does not justify that conclusion and no exception applies, proceed with the required notifications for a breach of unsecured PHI. Preserve the assessment alongside the incident records and copies of any notices.
Notify the patient whose information was exposed
The affected patient is the individual whose medical information you disclosed, rather than the unintended recipient.
Notify that patient promptly, with no unreasonable delay and no later than 60 calendar days after discovery. The deadline begins with discovery, not completion of your investigation.
Send written notice by first-class mail, or email if the patient has agreed to electronic notice. Explain:
- What happened, including relevant dates
- The types of information involved
- Steps the patient should take to protect themselves
- Your practice's investigation, mitigation, and prevention measures
- How the patient can contact your practice with questions
Report the breach to HHS under the applicable deadline
A reportable breach involving one patient still requires an HHS report.
For breaches affecting fewer than 500 individuals, submit the report within 60 days after the calendar year in which you discovered the breach ends. You can report earlier.
It is worth noting, though, that the annual reporting schedule does not extend the patient notification deadline. Your practice must track the two obligations separately.
You can reduce wrong-patient texting errors with recipient checks and iPlum
After addressing the disclosure, your practice should identify the cause of the error.
An outdated number, an incorrect contact selection, and an attachment copied from another patient's record require different corrections.
Recipient checks allow you to determine who receives the information. Meanwhile, iPlum's business contacts and encrypted texting give your practice features it can incorporate into that process.
Let's unpack that.
Create patient contacts using verified information
Start by comparing the patient's contact details with their current record.
Confirm which number belongs to the patient and which belongs to an authorized caregiver. If the patient reports a change to their number, update the relevant contact before sending further messages.
iPlum's Business Contacts allow you to store patient contacts separately from your phone's personal address book. The service stores business contacts in an encrypted container, and you can access them through the iPlum app or portal.
With Business Contacts, your practice can establish a designated contact entry for patient communication. That way, employees can select patients from a dedicated business contact list instead of searching through personal contacts when preparing a message.
Establish an encrypted conversation with the verified patient
Once you have verified the contact, establish the channel your practice will use for sensitive exchanges.
With iPlum's HIPAA-compliant solution, you can invite patients to secure texting. Patients create a free account through the mobile app or web portal and accept your invitation. The account allows your practice to exchange encrypted messages with your patients through a secure channel separate from SMS or MMS.
Check the recipient and message together before sending
A structured conversation provides context, but employees must still confirm that the information belongs to its recipient.
Before sending clinical information:
- Compare the selected contact with the patient record.
- Review the message for details copied from another patient's correspondence.
- Open attachments and check the patient identifiers.
- Confirm that you selected the intended secure conversation.
Make that check immediately before sending, particularly after moving between patient records.
Use text templates instead of copying another patient's message
Copying a previous message can carry another patient's name, appointment details, or treatment information into a new conversation.
But with iPlum's text templates, your practice can create reusable wording for reminders, instructions, and follow-up messages. You can prepare the wording without patient-specific details, then personalize it for the intended recipient.
Retrieve archived texts when investigating a mistaken disclosure
A breach assessment requires an accurate account of what your practice sent. Access to the original text allows your privacy officer to examine the disclosed information.
iPlum provides text archiving and downloadable logs, allowing your practice to retrieve the message involved, review its contents, and export the relevant text logs for the incident record.
Manage employee lines and permissions through a practice account
When a misdirected text comes from an employee's business line, your practice needs access to the relevant communication records.
An iPlum multi-user account allows administrators to manage employee lines, restrict permissions for certain features, and access centralized text archives. Your practice can use those functions to administer its patient communication accounts and retrieve relevant records during an investigation.
Texting the wrong patient: frequently asked questions (FAQs)
Is texting the wrong patient a HIPAA breach if the message contains no PHI?
No. A text containing no PHI does not constitute a HIPAA breach. However, assess the attachments and conversation context before concluding that no identifiable patient information was disclosed.
Does deleting the text from the sender's phone reverse the disclosure?
No. Deleting your copy does not delete the recipient's copy or reverse the disclosure. Preserve your practice's evidence and follow its incident response procedure.
Does the recipient's promise to delete the message eliminate notification requirements?
No. A deletion promise alone does not eliminate notification requirements. Your practice must document an applicable exception or a low probability that the PHI was compromised.
Must your practice report a breach involving only one patient?
Yes. A reportable breach affecting one patient requires notification to that patient and HHS. The patient notification deadline differs from the annual HHS reporting deadline.
Does encrypted texting prevent a wrong-patient disclosure?
No. Encryption does not correct recipient selection. If an unauthorized recipient can read the information, your practice must assess the disclosure even though the exchange used encryption.
Pair recipient checks with iPlum’s secure patient texting
A misdirected text requires a prompt response, a documented assessment, and notification when required.
Once your practice addresses the incident, it should correct the process that allowed the error.
Verified contacts, careful message review, and an established secure channel all contribute to that work. iPlum provides business contacts, encrypted texting, reusable templates, and text archives that your practice can add to its communication procedures.
To establish a secure channel for patient engagement, click the link below to get started with iPlum and invite your patients to begin using secure texting.

%20(1).avif)
.avif)