HIPAA Violation vs. Data Breach: The Key Differences

A HIPAA violation and a data breach overlap but aren't the same — one decides whether you can personally sue. See the differences and which law applies.

Last updated August 25, 2026 By LawfareClaims.org

A HIPAA violation vs data breach question comes up the moment you learn your medical records were exposed. The two overlap but are not the same thing, and the difference decides whether you can personally sue anyone. This guide breaks down what each term covers, who enforces them, and how to find the claim that can actually pay you.

What Is a HIPAA Violation?

A HIPAA violation happens when a healthcare provider, health plan, or their business partner mishandles your protected health information. HIPAA stands for the Health Insurance Portability and Accountability Act, a federal law passed in 1996. It sets privacy and security rules for medical records and other health data.

The law only applies to specific players. It covers "covered entities" (hospitals, doctors, health insurers, and clearinghouses) plus their "business associates," like billing companies or cloud vendors that handle health data on their behalf. A violation can be small, like a nurse looking up a neighbor's chart out of curiosity, or large, like a hospital losing an unencrypted laptop full of patient files.

The HHS Office for Civil Rights (OCR) enforces HIPAA. You can file a complaint with OCR, and it can investigate and fine the entity. But that enforcement path was not built to put money in your pocket, which is the single most important thing to understand before you decide how to respond.

Our HIPAA violation guide covers how to spot one and what to document.

What Is a Data Breach?

A data breach is any unauthorized access, use, or disclosure of your personal information, and it covers far more than medical records. A retailer's customer database, a bank's account records, a school's student files, and a hospital's patient charts can all suffer a data breach. Health data is just one category among many.

State law does most of the work here. All 50 states and Washington, D.C. have data breach notification laws that require companies to tell you when your information is exposed, usually "without unreasonable delay" after they discover it. The Federal Trade Commission also polices data security more broadly, using its authority under the FTC Act to go after companies with careless security practices.

Some states go further and give you a direct right to sue. California is the clearest example: its data breach statutes, along with parts of the CCPA and CPRA, let consumers bring a claim and recover statutory damages without proving a specific dollar loss. Our data breach guide explains how notification works and what evidence to save.

Side by Side: The Full Comparison

A HIPAA violation vs data breach comparison comes down to who is covered, who enforces the rule, and, most importantly, whether you personally can sue. The table below lays out the six differences that matter most.

CriteriaHIPAA violationData breach
What it coversProtected health information onlyAny personal information: financial, retail, education, health, and more
Who is regulatedCovered entities and their business associatesVirtually any company or organization holding personal data
Primary enforcerHHS Office for Civil RightsState attorneys general, the FTC, and sometimes private plaintiffs
Can you personally sue?No. HIPAA has no private right of actionSometimes, depending on the state and the specific statute
Notification deadlineWithin 60 days of discovery, under the HIPAA Breach Notification RuleVaries by state, commonly 30 to 60 days after discovery
Where a fine goesTo the U.S. Treasury, not to youDepends on the claim; a state statutory damages award can go directly to you
Typical individual remedyAn OCR complaint, plus a separate state-law claim if you want compensationA notification, and in some states, a direct lawsuit for damages
VerdictSets the privacy standard, but rarely pays you directlyBroader umbrella, more likely to offer a path to personal compensation

Why You Can't Sue Under HIPAA Directly

You cannot personally sue a hospital or insurer under HIPAA, because the law gives that enforcement power only to the government. This is the single fact that most articles online get wrong or leave out entirely, and it changes how you should respond to a HIPAA incident.

Congress built HIPAA as a regulatory framework, not a lawsuit framework. When a covered entity violates the rules, your recourse is to file a complaint with the HHS Office for Civil Rights.

OCR can investigate, order corrective action, and impose civil monetary penalties. Those penalties are paid to the federal government, not to the patient whose privacy was violated.

This does not mean you have no options. It means the HIPAA violation itself is not your lawsuit. It is evidence inside a different lawsuit.

Courts in many states let you use a provider's HIPAA violation to show it breached a duty of care under state-law negligence, breach of contract, or breach of fiduciary duty. Some states also have their own medical privacy statutes with a direct right to sue. The HIPAA violation proves the healthcare provider fell short of the accepted standard, and the state-law claim is what actually gets you paid.

Practically, this means two separate steps: file the OCR complaint to trigger a regulatory investigation, and separately consult an attorney about a state-law claim if you want compensation. Skipping the second step because you assumed HIPAA itself covered it is the most common mistake people make after a healthcare privacy incident.

Notification Deadlines: HIPAA vs. State Law

HIPAA and state data breach laws run on separate notification clocks, and both can apply to the same incident. Under the HIPAA Breach Notification Rule, a covered entity must notify affected individuals within 60 days of discovering a breach of unsecured protected health information, and it must also notify HHS.

State data breach laws set their own deadline, and it is not always the same number. Many states require notice within 30 to 60 days of discovery, but the exact wording and trigger date vary by state. When health data is involved, a hospital or insurer typically has to satisfy both clocks at once.

Here is a non-obvious detail worth knowing: the notification deadline is not the same as the discovery deadline. An organization can sit on a breach for months before it even counts as "discovered" under the rules, especially if it claims it did not immediately recognize the scope of unauthorized access. If your notification letter arrived a year or more after the actual intrusion, ask specifically when the entity says it discovered the breach; that date, not the intrusion date, usually controls whether notification was timely.

Which Law Applies to Your Situation

The type of information exposed decides which law applies to your case. Ask two questions to sort it out.

  • Was the exposed information medical or health-related, and held by a provider or insurer? If yes, HIPAA privacy rules apply. You likely also have a state-law data breach claim running alongside it.
  • Was the exposed information something else entirely: a retailer's customer list, a bank's account data, a school's records? HIPAA does not apply at all. Your options run through state data breach law and possibly the FTC Act.

If your case is medical, plan for two tracks: an OCR complaint against the provider, and a state-law consultation about compensation. If your case is not medical, skip HIPAA entirely and focus your attorney search on state data breach and consumer-protection statutes.

Can One Incident Be Both?

Yes, a single incident is often both a HIPAA violation and a data breach at the same time. When a hospital, clinic, or health insurer exposes patient records, the incident triggers HIPAA's rules because health data was involved, and it also counts as a data breach under state law because personal information was exposed without authorization.

That overlap is actually good news for you. It means you may have two separate paths running in parallel: an OCR complaint that can pressure the entity into fixing its practices, and a state-law negligence or data breach claim that can pursue compensation for your actual harm, things like the cost of credit monitoring, time spent resolving fraud, or documented emotional distress. Settlements in these cases have ranged from modest amounts per affected individual to nine figures for very large breaches, depending on how many people were affected and how much harm they can show.

Neither path replaces the other. Filing an OCR complaint does not preserve your right to sue, and filing a lawsuit does not stop OCR from investigating. If your medical information was exposed, treat these as two separate to-do items, not one.

Frequently Asked Questions

What is the difference between a HIPAA violation and a data breach?

A HIPAA violation is a mishandling of medical records by a healthcare provider, insurer, or their business associate, enforced by HHS OCR. A data breach is the broader concept of any unauthorized exposure of personal data, covering health, financial, retail, and other information, governed mainly by state law. Medical data breaches can be both at once.

Can I sue a hospital directly under HIPAA?

No, HIPAA has no private right of action, so you cannot personally sue a hospital or insurer under the statute itself. You can file a complaint with HHS OCR, which can investigate and fine the entity, but that fine goes to the government, not to you. Compensation typically requires a separate state-law claim.

If HIPAA doesn't let me sue, how do I get compensated for a medical data breach?

You get compensated through a separate legal theory, not HIPAA itself. Common routes include state-law negligence, breach of contract, breach of fiduciary duty, or a state medical privacy or data breach statute. An attorney typically uses the HIPAA violation as evidence that the provider breached its duty of care.

Does a data breach at a non-medical company involve HIPAA at all?

No. HIPAA only applies to protected health information held by covered entities and their business associates. A breach at a retailer, bank, school, or tech platform is governed by state data breach law and the FTC Act, not HIPAA, unless health records were somehow involved.

How long does a healthcare provider have to notify me after a HIPAA breach?

Under the HIPAA Breach Notification Rule, a covered entity must notify affected individuals within 60 days of discovering a breach of unsecured protected health information. It must also separately notify HHS. State data breach laws set their own deadlines, commonly 30 to 60 days, which can run alongside HIPAA's clock for the same incident.

What should I do first if I get a data breach notice from my doctor's office?

Read the letter carefully to see exactly what information was exposed and when the entity says it discovered the breach. File a complaint with HHS OCR if you believe HIPAA rules were broken, and separately talk to an attorney about whether state law gives you a claim for compensation. Save the notice, since it is your key piece of evidence.

Is a HIPAA violation always a data breach too?

Not always, but often. Some HIPAA violations, like a provider failing to give you your own records on request, do not involve exposed data at all. But when the violation involves unauthorized access, loss, or disclosure of your health information, it also qualifies as a data breach under state law.

Ready to Take the Next Step?

If your medical or personal information was exposed, figure out which law actually gives you a path to compensation before you spend time on the wrong one. Start by checking your situation, then read the guide that matches what happened to you.

Notification and filing deadlines are strict and vary by state, so the sooner you act after receiving a breach notice, the more options you keep open.

Not sure where you stand?

Check your eligibility in under 2 minutes — free, private, and no commitment required.

Latest related briefings