All Courses HIPAA HIPAA for Leaders Training What do I do if I get a HIPAA Complaint?

What do I do if I get a HIPAA Complaint?

Video 24 of 26
1 min 21 sec
English
English

Receiving a HIPAA complaint from a patient or business requires immediate, deliberate action. As an organizational leader, you must follow a structured response process, ensure thorough documentation, and maintain strict anti-retaliation standards to keep your compliance defensible.

Steps for Handling a HIPAA Complaint

When a complaint regarding the handling of Protected Health Information (PHI) is received, follow these operational steps immediately:

  • Log the Incident: Enter the initial complaint details into your organization's incident log immediately upon receipt.
  • Provide an Official Complaint Form: Supply the patient or business with an official complaint form, allowing them to explain the incident in their own words, and document the exact date the form was received.
  • Conduct a Formal Investigation: The Privacy Officer must investigate whether organizational policies or procedures were breached and determine if PHI was potentially compromised.

Investigation Outcomes and Next Steps

Depending on the Privacy Officer's findings during the investigation, proceed with one of two response paths:

  • If No Breach Occurred: Document all investigation findings, record how the complaint was resolved, and officially close out the entry in your compliance records.
  • If PHI Was Breached: Immediately initiate your organization's standard breach response workflow. Determine if the event constitutes a reportable breach, notify affected individuals and HHS within statutory deadlines, and log every action taken.

Pro Tip: Build Your Book of Evidence: Document the original complaint, your investigation steps, and the final resolution regardless of the outcome. Keep all associated files filed safely inside your Book of Evidence.

Strict Non-Retaliation Policy

Leaders must never retaliate against an individual or business for filing a HIPAA complaint in good faith. Retaliation itself is a direct HIPAA violation and subjects your organization to serious regulatory penalties.