94% of Small HIPAA Breaches Aren't Hacks. They're People.
In OCR's 2024 and 2023 breach reports, 94% of sub-500 breaches were unauthorized access or disclosure. That is a training and monitoring problem, not a firewall problem.

There are two HIPAA breach populations, and they behave nothing alike.
In calendar year 2024, OCR received 663 breach reports involving 500 or more individuals, affecting approximately 242,908,056 people. Hacking and IT incidents accounted for 534 of those reports (81%) and 241,582,022 of the individuals (99%). Network servers were the breach location in 418 cases (63%), email in 164 (25%). That is the population that funds security budgets, and it should. Nothing in this post argues otherwise.
In the same year, OCR also received 74,299 breach reports involving fewer than 500 individuals, affecting approximately 340,618 people. Of those, 69,773 — 94% — were unauthorized access or disclosure.
So: small breaches are roughly 99% of all breach reports OCR received and roughly one tenth of one percent of the individuals affected. That asymmetry is why they are ignored. It is also why the ignoring is a mistake. The 500-plus population describes what happens to a health system on the worst day of its decade. The sub-500 population describes what happens at a home health agency on an ordinary Tuesday.
Two populations, two entirely different causes
Put the cause distributions side by side and the argument makes itself.
| Cause | Large breaches (500+ individuals), CY2024 | Small breaches (<500 individuals), CY2024 |
|---|---|---|
| Hacking / IT incident | 534 reports (81%) | — not separately reported |
| Theft | 16 reports (2%) | — not separately reported |
| Improper disposal | 3 reports (under 1%) | — not separately reported |
| Loss | 2 reports (under 1%) | — not separately reported |
| Unauthorized access or disclosure | 108 reports (16%) | 69,773 reports (94%) |
| All other causes combined | — not separately reported | 4,526 reports (6%) |
| Total reports | 663 | 74,299 |
| Individuals affected | ~242,908,056 | ~340,618 |
All large-breach figures above, including the roughly 1,260,000 individuals (about 1%) affected by the 108 unauthorized access or disclosure reports, come from the OCR Annual Report to Congress for calendar year 2024. The 4,526 figure is simply the 74,299 small breaches minus the 69,773 attributed to unauthorized access or disclosure.
The two columns are almost mirror images. In one, the dominant failure is technical. In the other, the dominant failure is a person saying, sending, or showing something to someone who should not have received it.
This is a structural pattern, not a bad year
One year of data is an anecdote. Two is a pattern worth planning around.
The calendar year 2023 report shows 732 large breaches affecting approximately 113,173,613 individuals, with hacking at 590 reports (81%) and unauthorized access or disclosure at 120 (16%). On the small-breach side: 68,315 reports, of which 64,231 — again 94% — were unauthorized access or disclosure.
Eighty-one percent hacking on top, ninety-four percent human disclosure on the bottom, two years running, across a population of well over 140,000 small-breach reports. The composition of small breaches did not move. It is not a fluke of one reporting cycle, and it is not going to be fixed by the next endpoint agent.
The complaint data points the same direction. In its Enforcement Highlights, stated as of October 31, 2024, OCR reports that the top alleged issue in complaints it investigates is impermissible uses and disclosures of PHI, with disclosure of more than the minimum necessary sitting fifth on the same list. People complain about what they hear and see, not about your firewall configuration.
What OCR actually penalizes post-acute providers for
On September 30, 2025, OCR announced a $182,000 settlement with Cadia Healthcare Facilities. There was no intrusion. Cadia posted patient "success stories" — names, photographs, treatment and recovery details — publicly, without valid HIPAA authorization, affecting 150 patients. The corrective action plan runs two years and includes training for marketing personnel.
Read that as an operational warning rather than a marketing story. A post-acute provider was penalized for what it communicated about patients, by employees doing their jobs, in a channel nobody had classified as a disclosure surface. Swap the marketing team for an intake coordinator and the web page for a phone call, and the shape of the failure is identical.
The two rules that govern this space are not obscure. 45 CFR 164.502(b) states: "When using or disclosing protected health information or when requesting protected health information from another covered entity or business associate, a covered entity or business associate must make reasonable efforts to limit protected health information to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request." Exceptions at (b)(2) include disclosures to, or requests by, a health care provider for treatment — which is exactly why clinicians are trained to a different standard than schedulers, and why schedulers often absorb the clinical habit anyway.
And 45 CFR 164.530(c) requires appropriate administrative, technical, and physical safeguards, requires you to reasonably safeguard PHI from unauthorized use or disclosure, and requires you to limit incidental uses and disclosures. "Administrative and physical" is the regulation telling you, in advance, that this is partly a floor-plan and workflow problem.
Where verbal disclosure actually happens in a home care agency
Small breaches in an agency mostly are not files walking out the door. They are sentences. The scenarios below are hypothetical illustrations, not incidents — but any scheduler or intake lead will recognize the shape of them.
- Confirming a visit with whoever answered the phone. A coordinator calls to confirm tomorrow's aide visit, a neighbor or an adult child picks up, and the coordinator confirms the appointment, the service type, and the nurse's name because the call needs to be closed out.
- Discussing a patient with an unauthorized family member. The daughter who calls most often is not always the daughter on the authorization. Frequency of contact quietly becomes a proxy for permission.
- Detailed voicemails. A message that names the patient, the diagnosis, the medication being delivered, or the reason for the visit, left on a shared household line. For hospice agencies this is sharper still: the agency name alone can disclose the condition.
- Over-disclosing to a referral source. A hospital case manager or physician office asks for status and gets the full narrative — social history, family dynamics, prior admissions — when the intended purpose required a fraction of it. Treatment disclosures have latitude under 164.502(b)(2); a status update to a referral coordinator often is not one.
- Speakerphone in shared space. Coordinators sitting four feet apart, on speaker, with a scheduling screen visible to whoever walks past. That is the incidental-disclosure limitation in 164.530(c) being tested continuously, all day.
- Wrong-number and wrong-patient calls. A digit off in the chart, and a full care update goes to a stranger who never reports it.
Notice what these have in common. None of them are malicious. All of them are invisible to your security stack. And almost none of them get discovered unless somebody on the other end of the line complains. PHI disclosure on outbound calls, and the HITECH notification obligations that follow, are covered in call intelligence for healthcare providers.
What to actually do about it
Treating verbal disclosure as a real control surface is unglamorous work. It is also cheap relative to a perimeter program.
- Name the phone line as a disclosure surface in your risk analysis. If your last risk assessment inventoried servers, laptops, and portals but not outbound calls and voicemails, it did not describe your agency.
- Script the ceiling, not just the floor. Most call scripts tell agents what to say. Minimum necessary requires telling them what to stop saying. Define, for each of your top call types — visit confirmation, referral status, authorization and benefits, care escalation — the maximum PHI permitted for that intended purpose.
- Make authorization visible at the moment of the call. Who may receive information about this patient should be one glance away in the system, not an inference from who called last week.
- Write a voicemail standard and make it boring. Callback number, first name, agency identifier where the identifier itself is not disclosive. Nothing about condition, service, or medication.
- Fix the physical layout. Headsets instead of speakerphone, screens angled away from walkways, private space for clinical calls. This is 164.530(c) work, not office decor.
- Review calls for disclosure events, not just tone. Traditional QA scores empathy, hold time, and script adherence. Almost none of it asks whether the agent verified identity before disclosing, or whether the disclosure exceeded the purpose. Add those questions to the form you already use.
- Log near-misses. The value of finding the wrong-number call that disclosed nothing is that it tells you where the process is thin before the next one discloses something.
- Train the non-clinical staff hardest. Cadia's corrective action plan reached marketing personnel for a reason. Schedulers, intake, billing, and marketing handle PHI constantly and are usually trained least.
Also worth reading alongside this: Why HIPAA-aligned voice AI is no longer optional and The Home Care Call Compliance Checklist: What to Record, Redact, and Retain, which covers the retention and redaction side of the same problem.
The uncomfortable part
It is safe to assume that the organizations behind those 69,773 unauthorized access and disclosure reports had HIPAA policies, annual training modules, and signed attestations on file. The policies were not the missing piece. The behavior at the point of contact was simply never observed.
That is the actual gap. You cannot manage a control you never measure, and for most agencies the single highest-volume PHI disclosure channel — the telephone — is the one channel where nobody looks at what was said unless a complaint forces them to.
SurfacerIQ exists because that channel deserves the same routine scrutiny every other system in your agency already gets. If you want to talk through how verbal disclosure risk shows up in your own call volume, talk to us.
This post is general information, not legal advice.
Keep exploring
Related resources
Compliance monitoring →
Flag policy and regulatory issues on every call, not a sample.
Home care & healthcare →
Purpose-built for regulated call handling in home care and health.
HIPAA at SurfacerIQ →
How SurfacerIQ handles PHI, BAAs, and audit trails.
More from Compliance & HIPAA
- Minimum Necessary Applies to Your QA Team, Not Just Your Firewall8 min
- 42 CFR 484.50(e): You Must Document That a Complaint Existed — and How It Ended7 min
- HIPAA Does Not Require You to Keep Call Recordings for Six Years7 min
See SurfacerIQ in action
Calls in. Tickets out. Automatically. See how it works on a real call.
Keep reading
Minimum Necessary Applies to Your QA Team, Not Just Your Firewall
Your QA team can play any recording from any patient. The Privacy Rule has an opinion about that, and it is not the one your encryption vendor answered.
42 CFR 484.50(e): You Must Document That a Complaint Existed — and How It Ended
The CoP does not just require you to investigate complaints. It requires you to document that they existed and how they ended. Where that quietly breaks.
HIPAA Does Not Require You to Keep Call Recordings for Six Years
The six-year figure lives in HIPAA's administrative documentation rule, not in a call recording mandate. Here is what actually binds a home health agency.