What should a family do when ABA information is sent to the wrong person? Contact the provider through a verified privacy channel, identify the message or record, recipient, time, delivery route, information involved, and any known access or forwarding. Avoid resending sensitive material. Ask the provider to preserve evidence, contain access, assess applicable breach and notification duties, correct the intended workflow, and explain protective steps to the client in an accessible form.

Treat ABA information sent to the wrong person as a privacy event that needs prompt containment and source-controlled review, even when the eventual legal classification remains open.

Contain the disclosure through a verified route

Call or message the provider's official privacy or security contact. Identify the communication without repeating unnecessary health details. If the family received another person's information, do not forward, copy, post, or investigate it. Follow the provider's authorized return, secure deletion, or preservation direction.

If a portal, shared link, or account remains exposed, tell the provider immediately. An authorized security owner decides revocation, account action, and evidence preservation; the family should not attempt to enter another account.

Name the information flow exactly

A report of ABA information sent to the wrong person should identify the sender, intended recipient, actual recipient, date and time, channel, address or number used, subject, attachment, portal or link, information categories, client identifiers, access evidence, download or forwarding evidence, and how the event was discovered. Preserve the original message and headers when available.

Separate confirmed facts from possibility. A sent message, delivered message, opened link, downloaded file, forwarded record, and public disclosure are different states with different evidence.

Ask for the applicable privacy analysis

For a HIPAA covered entity or business associate, the HHS breach guidance says an impermissible use or disclosure is presumed to be a breach unless an exception applies or a documented assessment of at least four factors supports low probability of compromise, unless the entity elects notice without assessment. The factors concern the PHI, recipient, acquisition or viewing, and mitigation.

That analysis belongs to the regulated entity and qualified privacy or legal roles. State privacy, consumer-health, education, payer, contract, licensing, and professional rules may also apply.

Track notification, mitigation, and workflow repair

Ask what access was revoked, whether the unintended recipient confirmed disposition, what evidence remains, which notifications are required, when the client will be updated, and how the correct recipient will receive the needed information. Keep privacy analysis, client notice, record delivery, service continuity, and corrective action as separate work. When the person uses AAC, preserve access consistent with ASHA's communication guidance.

The HHS OCR process describes the federal complaint route for subjects within its scope. Do not assume an internal investigation pauses any external deadline.

Questions for immediate and follow-up review

Use the wrong-recipient disclosure register to route each question to the person who has authority and evidence to answer it. That may be the client, family, sender, records owner, privacy or security officer, unintended recipient, responsible clinician, provider leader, HHS OCR or another regulator within scope, investigator, legal adviser, or another responsible role.

  • What exact information was sent?
  • Who was intended and who received it?
  • What access or forwarding is confirmed?
  • Which containment action is authorized?
  • Who performs each privacy analysis?
  • Which notifications or complaint routes apply?
  • What test proves correct delivery next time?

Mark each answer as confirmed, open, disputed, inapplicable with a source, or decided by the named authority. Record the evidence, version, date, decision-maker, next action, deadline, and client view. Keep delivery evidence, containment, HIPAA breach analysis, other-law analysis, notification, correct record delivery, service continuity, and workflow correction distinct.

When sources conflict, preserve both versions in the wrong-recipient disclosure register. Ask the authority responsible for the disputed step for written clarification. Complete immediate emergency, medical, protective, or legally required action while that clarification is pending.

Maintain a current wrong-recipient disclosure register

Client, sender, intended and actual recipients, date and time, channel and address, message, attachments, link or portal, information categories, identifiers, delivery, viewing, download and forwarding evidence, discovery, containment, recipient contact, disposition, breach analysis, notifications, correct delivery, workflow correction, owners, and dates belong in one role-limited wrong-recipient disclosure register. Add each event as a new dated entry and preserve original records. Label firsthand observation, client communication, family report, staff report, clinical record, device or system evidence, medical direction, authority response, and interpretation separately.

Give the client an accessible summary of the wrong-recipient disclosure register and invite corrections. Collect only information needed for the safety, care, reporting, investigation, claim, or corrective purpose. Store health, identity, financial, and third-party information through the approved secure route. Record who received each disclosure and why.

For each open row in the wrong-recipient disclosure register, show the responsible owner, due date, consequence of delay, interim protection, escalation contact, and acceptance evidence. A closed status needs a disposition and proof. Silence, a meeting, an apology, a submitted form, or an assigned task does not establish that the underlying risk is resolved.

Prepare for a second failure

Plan a response to an active shared link, repeated forwarding, unknown recipient, public posting, mixed records for several clients, urgent correct delivery, conflicting access logs, failed recipient contact, missed notification clock, or a second misdirected message. The wrong-recipient disclosure register should identify who revokes access, preserves system evidence, communicates with the client, completes the privacy analysis, protects time-sensitive care, redelivers the correct record, and contacts the responsible privacy, security, clinical, regulatory or legal role.

Keep AAC, interpreters and any time-sensitive medication or prescribed-care communication available while resolving the disclosure. Record the actual containment, temporary safeguard, missed control, new evidence, notification and safe continuation condition. Do not ask the client or family to reopen an exposed link, enter another person's account or recreate the disclosure.

If the first containment or contact route fails, use the provider's next approved privacy, security or records channel and document the actual handoff. A provider process cannot replace emergency services, medical judgment, a required external notice or authority outside its scope.

A fictional wrong-recipient review

Zoe's family and provider lock 18 containment and follow-up conditions after a report reaches the wrong email address. Fourteen are verified. Recipient disposition, attachment access evidence, the written breach decision, and the corrected recipient test remain open. Completion is 14 of 18, or 77.8%.

The ratio does not establish a HIPAA breach, complete containment, deletion, identity harm, legal compliance, or safe future delivery.

Measure completion and lived impact

Lock the wrong-recipient disclosure register cohort and checkpoint before counting. Report verified conditions divided by every condition due at that checkpoint. Keep missing, failed, late, and disputed conditions in the denominator with age and owner. Mark an item inapplicable only when the governing source and event facts support that decision.

Focus on Zoe's privacy, exact data flow, recipient identity, access evidence, containment, client notice, correct delivery, workflow repair, and family burden. Pair process counts with the client's direct report, current health and safety, communication access, service continuity, privacy, financial impact, missed time, and household workload. If the client cannot report directly, state whose observation is being reported and preserve the person's accessible opportunities to participate.

A percentage from the wrong-recipient disclosure register describes only its named cohort and time window. It does not prove causation, compliance, fault, clinical safety, investigation quality, client agreement, recurrence prevention, or a future outcome. Report raw counts beside each percentage and explain every exclusion.

Set the next review before closing

Review the wrong-recipient disclosure register at discovery, after link or account containment, after recipient contact, when the breach analysis is documented, before correct redelivery, at each notice deadline, and after the repaired workflow is tested. At each review, confirm current health and safety, the client's priorities, new symptoms or events, open evidence, responsible authorities, deadlines, interim safeguards, and whether the care or access plan still fits.

Close each wrong-recipient disclosure register row with a specific disposition such as medically evaluated, reported, preserved, contained, repaired, replaced, corrected, notified, transferred, declined by the authority, appealed, or completed and tested. Retain the source, decision-maker, rationale, date, and acceptance evidence. Keep an unresolved consequence visible after the task that created it closes.

One named owner remains accountable for every open item in the wrong-recipient disclosure register, including work assigned to another organization. The family should receive a plain-language final summary stating what happened, what was decided, what changed, what remains uncertain, whom to contact, and when the next review will occur.

Related resources

Sources

Finni resources

Ready for the next step?

Find ABA care near you