My former employer, who is also the owner of the facility( a substance abuse hospital) called one evening asking about treatment for a patient that was admitted earlier that day. This particular patient happened to be a family a family member of his. After checking the patient's chart, it was discovered that he was not listed on the confidentiality agreement giving us permission to discuss treatment. After I explained this to him, his reply was "You DO know who I am, don't you?". I feel like this was a direct violation of HIPAA policy. Anyone else have any thoughts on this and how/where would I report this?