A Fax Meant for a Cardiologist Ended Up at a Car Dealership

I got the call on a Tuesday. A hospital's intake coordinator had faxed 14 pages of patient records — lab results, Social Security numbers, medication lists — to a number one digit off from the referring cardiologist's office. The car dealership that received it called the hospital, confused and a little alarmed. That single misdial triggered a breach notification to HHS, mandatory letters to every affected patient, and months of remediation work.

The root cause wasn't technology. It was bad communication in healthcare — the kind that looks mundane until it triggers a federal investigation.

I've spent over a decade helping covered entities untangle these messes. What I can tell you is this: the most expensive HIPAA violations I've seen didn't start with hackers or ransomware. They started with a voicemail left on the wrong phone. A discharge summary handed to the wrong family member. A group text thread that included a patient's name and diagnosis.

Why Bad Communication Costs More Than You Think

The Office for Civil Rights doesn't have a line item for "poor communication" in its enforcement categories. But when you read through real settlement agreements, communication breakdowns are woven into nearly every case. Misdirected PHI. Unauthorized disclosures during phone calls. Staff who didn't know what they could and couldn't say to a patient's family.

Consider the 2019 settlement with Medical Informatics Engineering. OCR imposed a $1 million penalty after a breach affecting 3.5 million individuals. Among the findings: the organization failed to conduct a proper risk analysis, which meant staff didn't understand the communication safeguards they should have had in place. You can review the details on HHS.gov's enforcement page.

Or look at the $4.3 million settlement with the University of Texas MD Anderson Cancer Center in 2018. The case revolved around unencrypted devices, but the depositions revealed deeper problems — employees who weren't trained on how to handle ePHI in everyday communications. The technical failure was the headline. The communication failure was the cause.

The Five Patterns of Communication Failure I See Over and Over

After working with dozens of organizations post-breach, I've identified five communication patterns that consistently lead to HIPAA trouble. If any of these sound familiar, your organization is carrying risk right now.

1. The "Reply All" Epidemic

A nurse manager sends a staffing update that includes a patient census with names and room numbers. She hits "Reply All" to a distribution list that includes vendors, volunteers, and contractors who have no business seeing that data. I've seen this happen at three separate health systems in the last two years alone.

2. Verbal Disclosures in Public Spaces

Your staff discusses patient cases at the nurses' station, in the elevator, in the cafeteria. The HIPAA Privacy Rule requires reasonable safeguards to limit incidental disclosures. "Reasonable" means lowering your voice isn't enough when you're reading lab results aloud in a shared hallway.

3. Texting PHI on Personal Devices

Physicians text each other about patients constantly. Many use standard SMS on personal phones — no encryption, no remote wipe capability, no audit trail. One lost phone becomes a reportable breach. HHS has been clear that covered entities must implement technical safeguards for ePHI, regardless of the device. The Security Rule requirements don't have a carve-out for convenience.

4. Unclear Authorization Protocols

A patient's adult daughter calls demanding test results. The front desk hands them over because the daughter "sounded like she knew everything already." Without a valid authorization or a confirmed personal representative designation, that's an unauthorized disclosure. Period.

5. Discharge Communication Gaps

Patient leaves the hospital. Discharge paperwork goes to the wrong address because nobody verified it. Follow-up call goes to an old number, and a voicemail with diagnostic details is left on a stranger's phone. These are the quiet breaches that add up fast.

What Does Bad Communication in Healthcare Actually Violate?

Let's get specific. Bad communication can trigger violations across multiple HIPAA provisions:

  • Privacy Rule (45 CFR §164.502): Unauthorized use or disclosure of PHI. This is the most common violation tied to communication failures.
  • Security Rule (45 CFR §164.312): Failure to implement access controls and transmission security for ePHI sent via email, text, or fax.
  • Breach Notification Rule (45 CFR §164.400-414): Once an unauthorized disclosure occurs, your organization must assess whether breach notification is required — to individuals, to HHS, and potentially to media.
  • Minimum Necessary Standard (45 CFR §164.502(b)): Even authorized communications must be limited to the minimum PHI necessary for the purpose. Sending an entire medical record when only a lab result was requested is a violation of this standard.

Each of these creates independent liability. A single misdirected fax can implicate all four.

The $1.9 Million Lesson Most Clinics Haven't Learned Yet

In 2020, OCR settled with Premera Blue Cross for $6.85 million after a breach affecting over 10 million people. The technical findings were damning, but buried in the corrective action plan was a requirement that jumped out at me: Premera had to completely overhaul its workforce training program. Not just IT training — communication training. How staff handle PHI in conversation, in writing, in electronic messages.

That tells you everything about where OCR's priorities are heading. They're not just looking at firewalls. They're looking at whether your receptionist knows what to say — and what not to say — when a patient's employer calls asking if someone was seen in your clinic.

If your workforce training doesn't cover real-world communication scenarios, you're training for a test, not for compliance. Our HIPAA training catalog includes role-specific modules that address exactly these situations — front desk, clinical, administrative, and IT staff each face different communication risks.

How to Fix Communication Before OCR Fixes It for You

Here's what I recommend to every covered entity and business associate I work with:

Audit Your Communication Channels

Map every way PHI moves through your organization. Fax, email, text, phone, EHR messaging, paper handoffs, verbal orders. If you can't list them all, you can't secure them all. This should feed directly into your HIPAA risk analysis — which, as 45 CFR Part 164 Subpart C requires, must be thorough and ongoing.

Implement Role-Based Communication Policies

Your billing team doesn't need the same communication guidelines as your nursing staff. Write policies that match actual workflows. A generic "don't share PHI" poster in the break room isn't a policy — it's decoration.

Train with Scenarios, Not Slides

The most effective workforce training I've seen uses scenario-based learning. Put your staff in situations they'll actually face: the angry family member on the phone, the physician texting from a personal device, the misdirected email. Our scenario-based HIPAA training courses are built around exactly these moments.

Create a Safe Reporting Culture

Staff won't report communication mistakes if they fear punishment. But unreported incidents become unreported breaches, and unreported breaches become OCR investigations. Build a culture where catching a misdirected fax early is rewarded, not punished.

Verify Before You Send — Every Time

Read back fax numbers. Confirm email addresses. Verify patient identity before leaving voicemails. These three-second checks prevent six-figure penalties. Make them non-negotiable.

The Real Risk Isn't a Hacker — It's a Conversation

I tell every client the same thing: your biggest HIPAA risk probably isn't sitting behind a keyboard in another country. It's sitting at your front desk, your nurses' station, or in your physicians' group text thread.

Bad communication in healthcare isn't just a patient safety issue — though it is absolutely that. It's a compliance liability that OCR takes seriously, penalizes aggressively, and investigates thoroughly.

The organizations that avoid enforcement actions aren't the ones with the biggest IT budgets. They're the ones that trained every member of their workforce — from the CEO to the part-time file clerk — on how PHI moves, who can see it, and what to do when something goes wrong.

You already know communication matters. The question is whether your policies, training, and culture reflect that knowledge — or whether you're one misdial away from finding out the hard way.