HIPAA Violations: How to Report One

A HIPAA violation happens when your health information is mishandled. What counts, how to report it to HHS OCR, the deadline, and what remedies you have.

Last updated August 06, 2026 By LawfareClaims.org

A HIPAA violation happens when a covered entity — a hospital, insurer, doctor's office, or their business associate — mishandles your protected health information (PHI). This guide explains what qualifies, how to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR), the deadlines you must meet, and what remedies may be available to you.

What Is a HIPAA Violation?

A HIPAA violation occurs when a covered entity or its business associate fails to comply with any provision of the Health Insurance Portability and Accountability Act of 1996 or its implementing regulations. HIPAA protects your protected health information (PHI) — any data that can identify you and relates to your health condition, treatment, or payment for healthcare. This includes medical records, billing details, lab results, prescription history, and even verbal conversations between your care team.

PHI is protected in three forms: written, electronic (ePHI), and oral. A nurse discussing your diagnosis in a crowded elevator is a potential violation just as much as an unencrypted email sent to the wrong address. Know your legal rights so you can recognize when yours have been violated.

Not every error rises to the level of an actionable violation. HHS distinguishes between willful neglect — the most serious category — and innocent mistakes. But even accidental disclosures must be reported internally and, in many cases, to you and to HHS.

Who Must Follow HIPAA?

HIPAA applies to covered entities and their business associates — not to every company that handles health information. Covered entities include health plans (insurance companies, HMOs, employer-sponsored health plans), healthcare clearinghouses, and most healthcare providers that transmit health information electronically. Business associates are vendors and contractors those entities hire — cloud storage providers, billing companies, IT vendors, and legal firms that handle PHI on their behalf.

Employers, life insurers, workers' compensation carriers, and most school district health records are generally not covered under HIPAA. If a company that is not a covered entity misuses your health data, your remedy may lie in state consumer-protection law rather than HIPAA itself. See our guide to consumer rights for more information.

Can Your Employer Violate HIPAA?

This is one of the most common misunderstandings about HIPAA. In most situations, an ordinary employer cannot "violate HIPAA" the way people assume, because a company acting purely as your employer is not a HIPAA covered entity. When you hand your boss a doctor's note, disclose a diagnosis to request time off, or give medical information for an accommodation, that information usually sits outside HIPAA entirely — the law regulates hospitals, insurers, clearinghouses, and their business associates, not the HR department.

There are two important exceptions where HIPAA does reach your workplace. First, your employer's group health plan is a covered entity, so protected health information held by the plan (claims data, enrollment records, wellness-program data run through the plan) is protected — and a plan that leaks it can be reported to HHS OCR like any other covered entity. Second, if your employer is itself a healthcare provider or a business associate handling patients' PHI, it must follow HIPAA for that patient data.

When your employer mishandles your medical information outside those channels, the law that usually protects you is not HIPAA but the Americans with Disabilities Act. The ADA requires employers to keep employee medical information confidential and stored separately from personnel files, and the Equal Employment Opportunity Commission (EEOC) enforces that duty. The Genetic Information Nondiscrimination Act (GINA) adds protection for family-history and genetic data, and many states impose their own medical-confidentiality rules on employers. So a supervisor who broadcasts your diagnosis to coworkers may well have broken the law — just not HIPAA.

What this means in practice: if the mishandling involves your employer's health plan, file an HHS OCR complaint (see below). If it involves your employer acting as an employer — a manager disclosing your condition, medical files left unsecured, a demand for genetic information — your remedy is typically an EEOC charge under the ADA or a claim under state privacy law, not an OCR complaint. Our guide to workplace rights and the consumer rights page explain those parallel paths.

Common Types of HIPAA Violations

Unauthorized disclosure of PHI is the most frequently reported HIPAA violation category, accounting for roughly 65% of complaints received by HHS OCR in recent years. Below are the violations people most often encounter.

Unauthorized Access or Disclosure

This includes sharing your records with a family member without your authorization, selling PHI to marketers, or posting patient information on social media. A hospital employee peeking at a celebrity patient's chart — even without sharing it — is a violation.

Failure to Provide Access

HIPAA gives you the right to inspect and obtain a copy of your medical records within 30 days of request. Refusing or unreasonably delaying that access violates the Privacy Rule. HHS OCR has levied fines as high as $240,000 for repeated right-of-access failures.

Inadequate Safeguards (Security Rule)

The HIPAA Security Rule requires covered entities to implement administrative, physical, and technical safeguards for ePHI. Storing patient records on an unencrypted laptop, failing to install security patches, or allowing unauthorized staff access are textbook Security Rule violations. Check our page on data breach rights if your PHI was exposed in a cyberattack.

Improper Disposal

Throwing patient files in an open dumpster or failing to wipe a hard drive before disposing of it violates HIPAA's disposal standards. HHS has fined practices tens of thousands of dollars for paper records left in public trash receptacles.

Missing or Deficient Business Associate Agreement

Covered entities must have signed Business Associate Agreements (BAAs) with every vendor that touches PHI. Operating without a BAA — or having one that omits required terms — is itself a violation even if no PHI is actually misused.

HIPAA Breaches: Mass Tort vs. Class Action

Large healthcare data breaches often spawn both regulatory investigations and civil litigation, and understanding the difference matters for choosing your path.

Feature Mass Tort Class Action
Individual claims Yes — each plaintiff retains separate claim No — claims consolidated into one suit
Damages Individualized based on your harm Shared pro-rata among class members
Attorney control Higher — your lawyer works for you alone Lower — class counsel negotiates for the group
Common in healthcare breaches? Less common; used for severe individual harm Very common; typical for large data exposures
Average payout per claimant Varies widely; can be higher for documented harm Often $50–$500 in small breach settlements
Time to resolution 2–5 years typically 1–4 years typically

Browse related class actions to see whether an active suit covers your breach. If you experienced significant documented harm — identity theft, medical fraud, delayed treatment — you may benefit from individual litigation advice rather than joining a class.

How to Report a HIPAA Violation to HHS OCR

Filing a HIPAA complaint with HHS OCR is free, does not require an attorney, and can be done entirely online. The Office for Civil Rights is the primary federal enforcer of HIPAA and has collected more than $150 million in penalties and settlements since the program's inception.

Step 1 — Gather Your Information

Before you start, collect: the name and address of the covered entity or business associate; a description of what happened and when; how you believe the Privacy or Security Rule was violated; and any documents (denial letters, breach notices, screenshots) that support your complaint.

Step 2 — Submit the Complaint Form

Go to the HHS OCR complaint portal at hhs.gov. You can file online using the OCR Complaint Portal, by mail, or by fax. The online portal is fastest and allows you to upload supporting documents immediately. You will need to create an account or log in through Login.gov.

Step 3 — Describe the Violation Clearly

Use plain language. State the date of the incident, who disclosed your information, to whom it was disclosed, and how you found out. If you received a breach notification letter, attach it. OCR investigators are experienced but they rely on the information you provide to open an investigation.

Step 4 — Submit and Keep Your Confirmation

After submission you will receive a case number. Save it. OCR will send an acknowledgment within a few days. Initial screening typically takes 30–60 days, after which OCR decides whether to open a formal investigation.

Can You Report a HIPAA Violation Anonymously?

You can, but there is a trade-off worth understanding before you file. The OCR complaint form asks whether you consent to OCR sharing your identity with the covered entity you are reporting. You are allowed to withhold that consent — but OCR generally needs to disclose who you are in order to investigate, because the covered entity has to know which incident and which patient the complaint concerns. Decline consent and OCR may be unable to open a full investigation, though it can still record the complaint and use it to spot patterns of repeat offenders.

Two protections make filing under your own name less risky than people fear. First, HIPAA's anti-retaliation rule (45 CFR 160.316) makes it illegal for a covered entity to retaliate against, intimidate, or discriminate against anyone who files a complaint or cooperates with an OCR investigation — so a provider that punishes you for reporting has committed a second violation. Second, you can ask OCR to keep your identity confidential to the extent the law allows, and OCR does not publish complainant names.

If you need true anonymity — for example, you are a current employee of the covered entity — practical options include filing through an attorney who submits on your behalf, or reporting internally to the entity's HIPAA Privacy Officer, who is required to accept complaints. Whistleblowers reporting an employer's PHI mishandling may also have separate federal and state protections that a healthcare-privacy attorney can explain.

The 180-Day Filing Deadline

You must file your HHS OCR complaint within 180 days of the date you knew — or should have known — about the violation. Missing this deadline almost always results in dismissal. OCR can grant extensions for "good cause," but that standard is applied narrowly, so file as early as possible.

If the violation was ongoing — for example, a provider repeatedly denying you record access — the 180-day clock may restart with each new refusal. Document every denial with dates and the name of the person who refused.

State law complaints often carry different — sometimes longer — statutes of limitations. A privacy attorney can advise you on whether a parallel state claim buys you more time.

What Happens After You File? The OCR Investigation Process

The OCR investigation process moves through predictable stages. First, OCR conducts an initial intake review to determine whether your complaint meets the jurisdictional requirements — the respondent must be a HIPAA covered entity, and the complaint must be filed within the 180-day window. OCR closes complaints that fail these screens without investigation and sends you a letter explaining why.

If your complaint passes intake, OCR opens an investigation. Investigators may request documents from both you and the covered entity, conduct site visits, and interview staff. Most investigations resolve through voluntary compliance — the covered entity agrees to correct the problem and may implement a corrective action plan.

In more serious cases, OCR may pursue a formal civil money penalty. You will not receive a share of any fine OCR collects; those funds go to the U.S. Treasury. Your benefit is corrective action and, potentially, evidence useful in a private lawsuit under state law.

HIPAA Penalties and Enforcement

HIPAA civil money penalties are tiered based on culpability, ranging from $141 to $71,162 per violation per year, with annual caps per violation category reaching $2.1 million (figures adjusted for inflation as of 2024). Willful neglect that is not corrected carries the steepest penalties — $71,162 to $2,134,831 per violation category per year under current guidance from HHS OCR's enforcement page.

The Department of Justice handles criminal HIPAA violations. Knowingly obtaining or disclosing PHI carries up to one year in prison; offenses committed under false pretenses carry up to five years; violations for personal gain or malicious harm carry up to ten years. The average HIPAA settlement in 2023 was approximately $1.9 million, though smaller covered entities often settle for far less.

Can You Sue for a HIPAA Violation?

HIPAA does not create a private right of action — you cannot sue a hospital directly under HIPAA in federal court. However, this does not leave you without a legal remedy. Many states have enacted health-privacy statutes that do allow private suits, and a HIPAA violation can serve as evidence of negligence in a state-law claim for breach of confidentiality, negligence, or invasion of privacy.

Courts in states including California, Texas, New York, and Illinois have allowed plaintiffs to use HIPAA as the standard of care in negligence claims even when HIPAA itself is not the cause of action. If your PHI exposure led to documented harm — fraudulent medical claims, identity theft, employment discrimination — you may have a stronger state-law case. Use our eligibility check tool to see whether your situation fits an active claim.

State Privacy Laws That May Help You

State laws frequently provide stronger protections than HIPAA and, importantly, give you a direct cause of action. California's Confidentiality of Medical Information Act (CMIA) allows patients to sue providers for negligent disclosure and recover actual damages plus attorney fees. Washington's My Health MY Data Act, effective March 2024, covers health data collected by consumer apps and tech companies that are entirely outside HIPAA's reach.

Illinois's Biometric Information Privacy Act (BIPA) has been used successfully against healthcare employers that collected fingerprints or retinal scans without consent — resulting in settlements exceeding $700 million in aggregate across multiple cases. If you live in a state with robust privacy statutes, a state-law claim may deliver faster, more direct compensation than an OCR complaint alone.

How to Protect Yourself Going Forward

Proactive steps can limit future exposure and help you catch violations early. Request a copy of your Notice of Privacy Practices from every provider and read the section on permitted disclosures. Exercise your HIPAA right to an Accounting of Disclosures — providers must give you a list of every non-routine disclosure of your PHI for the past six years, within 60 days of your request.

Set up fraud alerts with the major credit bureaus if your PHI included Social Security numbers or financial identifiers. Place a freeze on your credit file — it is free under federal law and the single most effective step against medical identity theft. Monitor your Explanation of Benefits (EOB) statements for procedures you did not receive; fraudulent claims are often the first sign that your PHI has been misused.

If you discover an active breach, report it immediately to the provider's HIPAA Privacy Officer (every covered entity must have one), document the conversation in writing, and follow up with an OCR complaint if the provider is unresponsive within a reasonable period.

Frequently Asked Questions

What qualifies as a HIPAA violation?

Any unauthorized use or disclosure of protected health information (PHI) by a covered entity or business associate qualifies. This includes sharing records without patient authorization, failing to safeguard electronic records, denying patients access to their own files, and operating without a Business Associate Agreement.

How do I file a HIPAA complaint?

File online at the HHS OCR Complaint Portal (hhs.gov/hipaa/filing-a-complaint), by mail to your regional OCR office, or by fax. The complaint is free, no attorney is required, and you must file within 180 days of learning about the violation.

What is the deadline to report a HIPAA violation?

You have 180 days from the date you knew or should have known about the violation. Extensions for good cause are rare and narrowly granted. File as soon as you have the facts documented to avoid missing the window.

Can I get money from a HIPAA complaint?

Fines collected by HHS OCR go to the U.S. Treasury — you do not receive a share. However, you may pursue compensation through state-law claims for negligence, breach of confidentiality, or invasion of privacy, where courts have awarded actual damages, emotional distress, and attorney fees.

Does HIPAA apply to my employer's wellness program?

It depends. Employer-sponsored group health plans are covered entities, so PHI held by the health plan is protected. However, data collected directly by the employer — outside the health plan — is generally not covered by HIPAA. State laws may fill this gap.

What should I do if I received a breach notification letter?

Read the letter carefully to understand what data was exposed and what the provider is offering (credit monitoring, fraud alerts). Keep the letter as evidence. File an HHS OCR complaint if the breach appears to involve negligence. Check whether a class action has been filed for your breach at our class actions page, and monitor your financial and medical accounts for suspicious activity.

Can a covered entity share my PHI without my consent?

HIPAA permits certain disclosures without authorization — for treatment, payment, and healthcare operations (TPO); to public health authorities; and in emergencies. However, disclosures beyond these permitted categories require your written authorization. Marketing uses, sale of PHI, and most disclosures to employers require your explicit consent.

Can my employer violate HIPAA?

Usually not directly — a company acting purely as your employer is not a HIPAA covered entity, so medical information you give HR generally falls outside HIPAA. The exceptions are your employer's group health plan (which is covered) and employers that are themselves healthcare providers. When an employer mishandles your medical information otherwise, the law that protects you is typically the Americans with Disabilities Act, enforced by the EEOC, or a state privacy statute — not HIPAA.

Can I report a HIPAA violation anonymously?

You can file without consenting to have your identity shared, but OCR usually needs to disclose who you are to fully investigate, so a fully anonymous complaint may limit what OCR can do. HIPAA's anti-retaliation rule (45 CFR 160.316) makes it illegal for a covered entity to punish you for filing, and OCR does not publish complainant names. For true anonymity, you can file through an attorney or report internally to the entity's HIPAA Privacy Officer.

Ready to Take Action?

If you believe your health information was mishandled, you have options — and a 180-day clock ticking. Start by checking whether your situation qualifies for an existing claim or a direct OCR complaint.

For personalized guidance, consult a licensed healthcare privacy attorney. Many offer free consultations for HIPAA and medical-privacy matters.

Not sure where you stand?

Check your eligibility in under 2 minutes — free, private, and no commitment required.

Latest related briefings