Note: Your progress in watching these videos WILL NOT be tracked. These training videos are the same videos you will experience when you take the full ProHIPAA for Leaders program. You may begin the training for free at any time to start officially tracking your progress toward your certificate of completion.

Receiving a HIPAA complaint from a patient or business requires immediate, deliberate action. As an organizational leader, you must follow a structured response process, ensure thorough documentation, and maintain strict anti-retaliation standards to keep your compliance defensible.

Steps for Handling a HIPAA Complaint

When a complaint regarding the handling of Protected Health Information (PHI) is received, follow these operational steps immediately:

  • Log the Incident: Enter the initial complaint details into your organization's incident log immediately upon receipt.
  • Provide an Official Complaint Form: Supply the patient or business with an official complaint form, allowing them to explain the incident in their own words, and document the exact date the form was received.
  • Conduct a Formal Investigation: The Privacy Officer must investigate whether organizational policies or procedures were breached and determine if PHI was potentially compromised.

Investigation Outcomes and Next Steps

Depending on the Privacy Officer's findings during the investigation, proceed with one of two response paths:

  • If No Breach Occurred: Document all investigation findings, record how the complaint was resolved, and officially close out the entry in your compliance records.
  • If PHI Was Breached: Immediately initiate your organization's standard breach response workflow. Determine if the event constitutes a reportable breach, notify affected individuals and HHS within statutory deadlines, and log every action taken.

Pro Tip: Build Your Book of Evidence: Document the original complaint, your investigation steps, and the final resolution regardless of the outcome. Keep all associated files filed safely inside your Book of Evidence.

Strict Non-Retaliation Policy

Leaders must never retaliate against an individual or business for filing a HIPAA complaint in good faith. Retaliation itself is a direct HIPAA violation and subjects your organization to serious regulatory penalties.