Important. If you think client information may have been exposed, tell the practice manager and Zack the same day. Within the hour if you can. You don’t need to be sure. You don’t need to know how bad it is. You just need to say something.
What counts as an incident
Anything where client information may have gone somewhere it shouldn’t. Examples:- An email or text sent to the wrong person
- A lost or stolen phone, laptop, or paper
- A client name or detail pasted into an AI tool, a personal app, or the wrong chat
- Someone accessing a record without a work reason
- A phishing email you clicked, or a login prompt you entered a password into
- A screen visible to someone who shouldn’t see it
- A vendor or system problem that exposed data
- A client telling you they received someone else’s information
- Anything that makes you think “that might be a problem”
How to report
- Tell the practice manager and Zack directly: call, text the practice channel, or email your practice account. Don’t put client details in the message; say “I need to report a possible privacy incident” and they’ll call you.
- Preserve what you can. Don’t delete the email, wipe the device, or clean up. The practice needs to see what happened.
- Write down what you know: what information, about whom (initials), who might have seen it, when, and how. Give it to the practice manager.