The fax went to the wrong number

Still one of the most common breaches in small practice. What to do in the first hour, why a paper fax and an efax are legally different animals, and the four factors that decide whether you are notifying families.

Last verified: 2026-07-12

Health care runs on fax machines, and it will keep running on them long after everyone agrees it should not. Which is why one of the most common breaches in American small practice remains the oldest one: a transposed digit, an outdated number in a referral list, a cover sheet that went to a hardware store in a different area code.

It happens to careful people. What separates a contained incident from a reportable breach is almost entirely what you do in the next hour.

The first hour

Call the recipient. Now. Most misdirected faxes land somewhere ordinary: another clinic, an office, a business. Call, explain briefly, and ask them to destroy it.

Get it in writing. An email or a signed note confirming that the fax was destroyed and not copied, forwarded, or read beyond what was needed to identify the sender. Ask for the time it was destroyed. The good-faith recipient who confirms destruction is not a courtesy. That confirmation is the single most valuable piece of evidence you will collect, and it feeds directly into factor four of the assessment below.

Write down what was on it. Which client, which document, which identifiers. A scheduling confirmation with a first name is a different event from an authorization packet with a date of birth, a diagnosis, and an insurance ID.

“That confirmation is the single most valuable piece of evidence you will collect, and it feeds directly into factor four of the assessment below.”

Write down the timeline. When it was sent, when you learned it went astray, when you called, what they said. Discovery is the moment the clock starts, and this record is your evidence of when that was.

Tell your officer, and log it as a security incident even before you know whether it is a breach.

Is it a breach?

It is an impermissible disclosure, so start from the presumption: it is a breach unless you document a risk assessment demonstrating a low probability that the PHI was compromised, weighing the four factors (45 CFR 164.402).

Factor one: what was in it. Name and appointment time is one thing; name, date of birth, diagnosis, insurance ID, and a clinical summary is another. The more identifiable and sensitive, the harder the assessment gets.

Factor two: who received it. This factor does the most work in fax cases, and it is where the outcomes diverge sharply. A fax that reached another HIPAA-covered provider, who is legally obligated to protect it and who confirms destruction, is a materially lower-risk event than one that reached an unknown business, a private residence, or a number that just rings and nobody answers. An unreachable recipient is the bad case: you cannot establish who has it or what they did with it, and an assessment that cannot answer factor two rarely lands honestly at low probability.

Factor three: was it actually acquired or viewed. Someone had to look at the top of the page to know it was misdirected, so “nobody saw it” is almost never true. What you can often establish is that it was not read past that point, and the confirmation of destruction is what establishes it.

Factor four: mitigation. This is the factor you control after the fact, and it is the reason the first hour matters so much. Prompt call, written destruction confirmation, recipient identified and cooperative: that is strong mitigation. No answer at the number, no confirmation, no idea where the pages went: that is none.

Two honest outcomes. Contained: covered recipient, confirmed destruction, limited content, written assessment, low probability of compromise, documented and retained six years. No notification. Not contained: unknown recipient, no confirmation, or sensitive content in unknown hands. Then it is a breach, and the clocks are here: individuals within 60 days, HHS at year-end for events under 500, at the same time as individuals above that.

The temptation in a fax case is to talk yourself into the first outcome because the second is embarrassing. Resist it. The assessment is evidence, and its reader will not be hoping.

The distinction nobody knows about

Faxes are legally two different animals, and which one you sent decides which rules reach it.

A paper-to-paper fax is not electronic media. The definition of electronic media excludes transmissions where the information did not exist in electronic form immediately before the transmission, and it names paper-to-paper faxes and voice telephone calls specifically (45 CFR 160.103). So a page fed into a physical machine and printed on another physical machine is not ePHI, and the Security Rule does not reach that transmission.

Everything else about it still applies. It is PHI, so the Privacy Rule governs the disclosure. It is a breach question, so the Breach Notification Rule governs the response. The safeguards requirement (45 CFR 164.530(c)) and the mitigation duty (45 CFR 164.530(f)) both apply. The paper carve-out is a narrow technical fact about one rule, not a shelter.

An efax, a computer-generated fax, or a fax service is ePHI, full stop. The document was electronic before it moved, so it is electronic media, the Security Rule applies in full, and the fax service that transmits and stores it is a business associate that needs a signed BAA. Most clinics that “still fax” are actually running efax through a vendor, which means most clinics that think they are outside the Security Rule on this are not.

Prevention, which is boring and works

  • Verify the number before every send, out loud, against a maintained list. The transposed digit is the entire failure mode.
  • Maintain the list. Referral numbers rot. A quarterly check of the numbers you fax most is an hour that pays for itself the first time.
  • Program the frequent ones. Speed dial entries do not transpose digits; humans do.
  • Cover sheet with a confidentiality notice and a callback number, so a stranger who receives it knows immediately who to call. It does not prevent the error; it dramatically improves your factor four.
  • Send the minimum. Minimum necessary applies (45 CFR 164.502(b)), and the fax that carried three pages instead of thirty is a smaller incident by construction.
  • Confirm receipt for anything sensitive, and follow up when confirmations do not arrive.
  • Ask whether it needs to be a fax at all. Most faxes exist because a payer or a referral partner asked for one years ago. Some of them will take a secure portal upload today, and the safest misdirected fax is the one nobody sent.

The reason this page exists

Nobody builds a compliance program around faxes, and that is precisely why they keep producing breaches. It is a small, dull, human failure that the entire industry has decided is beneath its attention, and it will quietly outproduce every exotic threat in your risk analysis.

An hour of prevention and one written procedure. That is the whole intervention, and it is worth more to a small clinic than most of what gets sold as compliance.

The short version

  • A misdirected fax is an impermissible disclosure, and it is presumed to be a breach unless a documented four-factor assessment shows a low probability of compromise.
  • Call the recipient immediately and ask for written confirmation that the fax was destroyed; that confirmation is the strongest mitigation evidence you can get.
  • A paper-to-paper fax is not electronic media, so the Security Rule does not reach it, but the Privacy Rule and the breach rule absolutely do.
  • An efax or computer-generated fax is ePHI, and the Security Rule applies in full.
  • Prevention is boring and it works: verified number lists, confirmed numbers before sending, cover sheets, and the habit of asking whether a fax is needed at all.

This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.

Sources

The assessment you can actually defend.

A misdirected fax turns on evidence: who received it, what it held, what you did within the hour. WiseUpHIPAA keeps the incident record, the assessment, and the proof, honestly, so the file holds up six years later.