A patient voices a concern of privacy violation because the provider mistakenly emailed her medical treatment information to unrecognized email addresses. Your Notice of Privacy Practices correctly informs the patient of her rights under HIPAA to file a privacy complaint with your organization’s Privacy Officer and the Office of
Civil Rights (OCR). As the provider, how should you respond? What is your protocol for handling this patient complaint? Follow these seven steps outlined below to ensure you cover all your bases.