HIPAA Privacy Violations: What They Are, How They Happen, and What Comes Next
HIPAA privacy violations explained: real examples, penalty tiers, OCR investigations, and how to protect your organization. ✅ Updated 2026 July.

HIPAA privacy violations occur when a covered entity or business associate fails to safeguard protected health information (PHI) in the ways required by the Health Insurance Portability and Accountability Act. These violations range from a nurse casually mentioning a patient's diagnosis in a hallway to a hospital failing to encrypt thousands of electronic records stored on an unprotected server. Regardless of size or intent, hipaa privacy violations trigger federal scrutiny and can result in financial penalties, corrective action plans, and lasting reputational harm.
The Privacy Rule, which took effect in April 2003, establishes national standards for how individually identifiable health information must be used, disclosed, and protected. It covers not just large hospital systems but also solo-practice physicians, health insurance plans, pharmacy chains, and the business associates — billing companies, IT vendors, cloud storage providers — that handle PHI on their behalf. Understanding what the rule requires is the first step toward building a compliant organization.
Violations can be accidental or intentional, but the Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services evaluates both categories with equal seriousness. An unintentional disclosure caused by a misconfigured email server may attract lower penalties than deliberate snooping into a celebrity's medical record, but neither is automatically excused. The law imposes an affirmative duty to prevent foreseeable harm, and "we didn't mean to" rarely satisfies regulators when basic safeguards were absent.
The financial exposure can be staggering. OCR can impose civil monetary penalties of up to $2,067,813 per violation category per calendar year under the tiered structure updated in 2023. Criminal penalties under the Department of Justice can add prison time on top of fines. Beyond federal action, many state attorneys general have independent authority to pursue HIPAA violations on behalf of their residents, creating the possibility of parallel enforcement proceedings that compound liability.
Healthcare organizations often underestimate how broad the definition of PHI is. It includes not only obvious items like diagnoses and treatment records but also appointment schedules, billing histories, insurance ID numbers, and even photographs from which a patient could be identified. If any of these data elements are linked — or even linkable — to a specific individual, they qualify as PHI and must be treated with full HIPAA-level protections.
Workforce behavior drives a surprisingly large share of privacy incidents. Employees sending PHI to personal email accounts for convenience, staff texting patient information over unsecured messaging apps, or workers accessing records of friends and family members out of curiosity — all of these constitute violations that covered entities are responsible for preventing through training, technical controls, and disciplinary policies.
This article walks through the most common categories of HIPAA privacy violations, explains how OCR investigates and penalizes them, and provides practical strategies that healthcare professionals and compliance officers can use to reduce risk. Whether you are studying for a certification exam or working in a healthcare setting where PHI flows daily, the concepts here are foundational to understanding how American health privacy law operates in practice.
HIPAA Privacy Violations by the Numbers

Most Common Types of HIPAA Privacy Violations
Sharing PHI with individuals who have no treatment, payment, or healthcare operations need — including disclosures to family members without patient authorization, posting information on social media, or discussing cases in public areas where others can overhear.
Denying or unreasonably delaying a patient's request to access or obtain copies of their own medical records. OCR has made right-of-access enforcement a top priority, issuing dozens of fines exceeding $10,000 for straightforward denials.
Failing to implement technical, administrative, or physical safeguards — such as leaving paper records unsecured, transmitting unencrypted PHI over public Wi-Fi, or neglecting to install software patches on systems storing electronic health records.
Using a patient's PHI for marketing communications without obtaining a valid HIPAA authorization. This includes selling patient lists, targeting patients with third-party ads based on their health conditions, and promotional communications disguised as treatment information.
Employees who have not received adequate HIPAA training regularly cause violations through careless handling of PHI. Covered entities are liable for workforce violations when training programs are absent, outdated, or not documented with completion records.
When a complaint is filed or a breach is reported, the Office for Civil Rights opens a preliminary review to determine whether the allegations fall within its jurisdiction. OCR has authority over covered entities — health plans, healthcare clearinghouses, and most healthcare providers — as well as their business associates. If the respondent does not qualify as a covered entity or business associate, OCR closes the case without further action, but it may refer the matter to another agency with applicable authority.
Once jurisdiction is confirmed, OCR sends a notification letter to the covered entity and requests documentation: policies and procedures, training records, relevant correspondence, system logs, and any breach notification materials already submitted. This document-gathering phase can last several months, and organizations that fail to respond promptly risk additional findings of noncompliance layered on top of the original allegation. Cooperation is not optional — HIPAA explicitly requires covered entities to allow OCR access to records and facilities during an investigation.
OCR investigators then compare the documented practices against the specific Privacy Rule requirements implicated by the complaint. For example, if a patient alleges that their records were shared with an employer, investigators will look at workforce training logs, the minimum necessary standard policies, and any authorizations on file. If the facts support a violation, OCR moves into the resolution phase, which can take the form of an informal resolution, a corrective action plan, or formal civil monetary penalty proceedings.
Informal resolution is by far the most common outcome. Under this approach, the covered entity agrees to implement specific corrective measures — updating policies, retraining staff, adding technical safeguards — and demonstrates compliance within a defined timeframe. OCR closes these cases with a resolution letter rather than a financial penalty. Many organizations view this as the best possible outcome, but it still creates a compliance record and may signal to OCR that deeper scrutiny is warranted if future complaints arise.
When informal resolution is not appropriate — typically because the violation is serious, systemic, or the organization is uncooperative — OCR issues a Notice of Proposed Determination that specifies the penalty amount and the legal basis for it. The covered entity then has thirty days to request a hearing before an administrative law judge. This formal adjudication process can take years, and many organizations negotiate a settlement before it concludes, resulting in a Resolution Agreement and Corrective Action Plan that is publicly posted on OCR's website.
State attorneys general also have independent authority under HIPAA to bring civil actions on behalf of their residents. Several states have exercised this power, adding a second layer of enforcement risk. A hospital that settles with OCR may still face state-level proceedings if the underlying breach affected residents of a state whose attorney general is actively pursuing HIPAA enforcement. Organizations operating across multiple states must therefore monitor enforcement trends at both the federal and state level simultaneously.
The breadth and depth of an OCR investigation can surprise organizations that assumed a single complaint would result in a narrow review. Investigators have discretion to expand scope if they discover evidence of systemic problems during the course of examining a specific allegation. A complaint about one denied record request can open the door to a facility-wide audit of access request procedures, potentially uncovering dozens of additional violations that compound the original exposure significantly.
HIPAA Privacy Violation Penalty Tiers Explained
Tier 1 applies when the covered entity did not know, and by exercising reasonable diligence would not have known, that the act or omission constituted a violation. The minimum penalty is $137 per violation, with an annual cap of $34,464 for identical violations in a calendar year. This tier is reserved for organizations that had reasonable safeguards in place but still experienced an isolated, unforeseeable incident — for example, a misdirected fax sent to a wrong number despite a verified contact list.
Even at Tier 1, organizations cannot simply assume the minimum will apply. OCR evaluates the totality of the compliance program, and an organization with weak overall safeguards may find OCR categorizing the same incident at a higher tier on the grounds that better controls would have prevented it. Documenting a robust, proactive compliance program is therefore essential even before any violation occurs, because that documentation is exactly what OCR will review when assessing culpability tier.

Reporting a HIPAA Privacy Violation: Benefits and Risks
- +Self-reporting may demonstrate good faith and lead to reduced OCR penalties
- +Early disclosure allows the organization to control the narrative before media coverage
- +Breach notification to patients fulfills a legal obligation and preserves trust
- +Reporting triggers internal investigation that often uncovers additional vulnerabilities
- +Cooperation with OCR typically shortens the investigation timeline significantly
- +Documented self-reporting creates a compliance record that can mitigate future enforcement
- −Self-reporting alerts OCR to a violation it might not otherwise have discovered
- −Formal OCR investigations can last years and consume substantial staff resources
- −Resolution Agreements are publicly posted and can attract negative media attention
- −Patients notified of a breach may file individual complaints or pursue state-law claims
- −Corrective Action Plans require ongoing monitoring and periodic progress reports to OCR
- −Financial penalties, even at Tier 1, can strain budgets at smaller covered entities
HIPAA Privacy Compliance Checklist for Covered Entities
- ✓Designate a Privacy Officer responsible for developing and implementing HIPAA policies.
- ✓Conduct an annual risk analysis covering all systems that create, receive, maintain, or transmit PHI.
- ✓Train all workforce members on HIPAA Privacy Rule requirements within 30 days of hire and annually thereafter.
- ✓Establish and document minimum necessary standards for all routine PHI uses and disclosures.
- ✓Obtain signed Business Associate Agreements with every vendor that accesses or processes PHI.
- ✓Post a current Notice of Privacy Practices in the facility and on the organization's public website.
- ✓Implement a written process for patients to request access to their records and respond within 30 days.
- ✓Log all PHI disclosures that are not for treatment, payment, or healthcare operations for the six-year accounting period.
- ✓Maintain a breach response plan and test it at least annually with tabletop exercises.
- ✓Document all sanctions applied to workforce members who violate privacy policies.
Patients Have 30 Days — Not 30 Business Days
OCR's right-of-access initiative has produced more than 50 enforcement actions since 2019, with fines ranging from $3,500 to $240,000. Covered entities must provide patients with a copy of their records within 30 calendar days of the request, with one 30-day extension if the records are not readily available. Charging excessive fees or refusing to send records to a third party designated by the patient are among the most common triggers for right-of-access complaints filed with OCR.
Preventing HIPAA privacy violations requires a layered approach that addresses people, processes, and technology simultaneously. No single safeguard is sufficient on its own. An organization may invest heavily in encryption and access controls but still suffer a violation because a workforce member intentionally bypassed those controls to access a family member's records. Conversely, a culture of strong privacy awareness can compensate for gaps in technical infrastructure, at least temporarily, but will eventually fail without supporting systems.
Workforce training is the most consistently cited corrective action in OCR resolution agreements, which means it is also the most consistently missing element in organizations that experience violations. Effective training goes beyond distributing a policy document and collecting signatures. It should use realistic scenarios drawn from the organization's own work environment, cover the specific types of PHI employees encounter daily, and test comprehension rather than just exposure. Training records must be retained for six years and made available to OCR on request.
Technical safeguards for electronic PHI include access controls that limit system access to authorized users based on their job function, audit controls that log and examine activity in systems containing ePHI, integrity controls that ensure ePHI is not improperly altered or destroyed, and transmission security that guards ePHI moving across networks. While encryption is not explicitly required by the Security Rule, OCR treats failure to encrypt as a significant risk factor, and unencrypted portable devices are responsible for a disproportionate share of large breaches reported on the OCR breach portal.
Physical safeguards are equally important and often overlooked. Workstation use policies should specify that screens displaying PHI must be positioned away from waiting areas and public spaces. Visitors to clinical areas should be escorted or supervised. Paper records must be stored in locked areas when not in use, and document disposal must use cross-cut shredding or locked shred bins serviced by certified destruction vendors. Many violations reported to OCR involve paper records that were improperly discarded — found in dumpsters, recycling bins, or even sold at auction with equipment.
Business associate management is a persistent compliance challenge, particularly as healthcare organizations rely on an expanding ecosystem of cloud services, telehealth platforms, revenue cycle vendors, and health information exchanges. Each of these vendors must sign a Business Associate Agreement before receiving access to PHI, and covered entities must periodically verify that those vendors maintain adequate safeguards. Vendors who subcontract PHI work must in turn obtain Business Associate Agreements from their subcontractors — a chain of accountability that is frequently broken in practice.
Minimum necessary is a foundational Privacy Rule principle that organizations frequently misapply. It requires covered entities to make reasonable efforts to limit PHI use, disclosure, and requests to the minimum amount necessary to accomplish the intended purpose. This does not apply to disclosures for treatment purposes between healthcare providers, but it does apply to disclosures for payment, operations, and most other purposes. Implementing role-based access controls in EHR systems is a practical way to enforce the minimum necessary standard technically rather than relying solely on workforce judgment.
Incident response planning separates organizations that quickly contain breaches from those whose violations expand because of delayed or disorganized reactions. An effective plan identifies who is responsible for detecting, reporting, and assessing potential violations; establishes escalation paths and documentation requirements; and specifies the decision tree for determining whether a breach triggers the 60-day notification obligation to OCR and affected individuals. Organizations that run tabletop exercises at least annually consistently demonstrate faster and more effective responses to real incidents when they occur.

Covered entities must notify affected individuals, OCR, and — for breaches affecting 500 or more residents of a state — prominent local media outlets within 60 calendar days of discovering a breach. The clock starts at discovery, not at the conclusion of the investigation. Organizations that delay notification while conducting forensic reviews frequently find themselves facing an additional violation for untimely notification on top of the underlying breach, compounding both penalty exposure and reputational damage.
For healthcare professionals preparing for HIPAA certification exams or workforce compliance training, understanding the conceptual framework of the Privacy Rule is as important as memorizing specific requirements. Exam questions are frequently scenario-based, requiring test-takers to apply principles to realistic situations rather than simply recall definitions. The most productive study approach pairs careful reading of the actual regulatory text with practice questions that force application of those concepts to concrete fact patterns.
The Privacy Rule's structure revolves around a few core concepts that appear repeatedly in exam questions. PHI is the central object of protection — any individually identifiable health information held by a covered entity or its business associates. The eighteen HIPAA identifiers that must be removed to achieve de-identification under the Safe Harbor method are a frequent exam topic, as are the conditions under which de-identified data loses its de-identified status upon re-linkage with external datasets.
Permitted uses and disclosures form the backbone of Privacy Rule analysis. The rule divides disclosures into those that are required (to the individual upon request or to OCR during compliance reviews), those that are permitted without authorization (for treatment, payment, healthcare operations, and a specified list of public interest purposes), and those that require a valid written authorization. Distinguishing between these three categories — and knowing the specific conditions that apply to each — is essential for both exam success and real-world compliance work.
The minimum necessary standard generates some of the most nuanced exam questions because its application varies by context. It applies to uses within the organization, disclosures to outside parties, and requests for PHI from other entities — but not to disclosures to treating providers, disclosures to the patient, or disclosures authorized by the patient. Understanding these exceptions prevents the common mistake of applying minimum necessary too broadly or too narrowly in scenario questions.
Patient rights under the Privacy Rule are another high-yield exam area. Patients have the right to access and obtain copies of their PHI, to request amendments to records they believe are inaccurate, to receive an accounting of certain disclosures, to request restrictions on certain uses and disclosures, to request confidential communications, and to receive a Notice of Privacy Practices. Each right has specific conditions, timelines, and exceptions that exam questions probe systematically. Knowing not just what the right is but when it applies and when it can be legitimately denied is critical for accurate answers.
Business associate relationships are tested both conceptually and practically. Exam questions may ask you to identify whether a particular vendor qualifies as a business associate, what a compliant Business Associate Agreement must contain, or what happens when a business associate violates HIPAA. The 2013 Omnibus Rule made business associates directly liable for HIPAA compliance rather than merely contractually obligated — a significant shift that frequently appears in exam content covering post-2013 regulatory developments.
One of the most effective study strategies for HIPAA exams is to work through OCR enforcement case summaries, which are publicly available on the HHS website. Each summary describes the facts of a real case, the specific Privacy Rule provisions violated, the corrective actions required, and the penalty imposed. These cases provide rich scenario material that mirrors the structure of exam questions and simultaneously builds the practical pattern recognition that healthcare professionals need in their actual work environments.
Real-world HIPAA compliance looks different across the spectrum of covered entities. A large academic medical center may have a dedicated compliance department, a full-time Privacy Officer, a sophisticated EHR with granular role-based access controls, and a legal team that monitors OCR enforcement trends. A solo-practice dentist operating on thin margins may have one front-desk employee, paper records, and no formal compliance infrastructure whatsoever. Both are covered entities subject to identical Privacy Rule requirements, but the resources available for compliance look nothing alike.
Small practices face a disproportionate compliance burden relative to their resources, yet they also tend to face proportionally lower penalties when violations occur at Tier 1 or Tier 2 because OCR exercises discretion in calibrating penalties to the organization's financial condition. That discretion is not guaranteed, however, and it disappears entirely for willful neglect violations. Small practices that completely ignore HIPAA — maintaining no policies, conducting no training, executing no Business Associate Agreements — are exactly the organizations most likely to trip into the willful neglect category.
Health information technology vendors occupy a complex position in the HIPAA landscape. As business associates, they are directly liable for their own compliance failures under the Omnibus Rule. Software-as-a-service providers, cloud hosting companies, and electronic health record vendors routinely handle enormous volumes of PHI across thousands of covered entity clients. A single security vulnerability in a major EHR platform can simultaneously expose millions of patients' records across hundreds of hospital systems, creating breach notification obligations that cascade across the entire client base simultaneously.
The intersection of HIPAA with emerging technologies creates new compliance questions that the original 1996 statute could not have anticipated. Wearable health devices, remote patient monitoring platforms, AI-powered diagnostic tools, and consumer health applications all potentially create, receive, or transmit PHI in ways that may or may not bring their developers within HIPAA's regulatory scope. The line between a regulated health app and an unregulated wellness app is frequently unclear, and OCR has issued guidance attempting to draw those distinctions — but new technologies continue to outpace regulatory clarity.
Social media presents a particularly acute risk area for healthcare workforce members. Posting a photo from inside a clinical facility can inadvertently capture patients in the background. Venting about a difficult case online — even without using names — can violate HIPAA if details are specific enough to identify an individual. Participating in online communities where healthcare workers share workplace stories can cross privacy lines with a single thoughtless comment. Covered entities should maintain explicit social media policies and include social media scenarios in annual workforce training.
Telehealth expansion following 2020 created a wave of new compliance questions around video platforms, remote prescribing, and interstate patient care. Platforms not covered by a Business Associate Agreement cannot be used for telehealth visits involving PHI, regardless of how popular or convenient they may be. The temporary enforcement discretion OCR exercised during the COVID-19 public health emergency permitted the use of non-HIPAA-compliant video platforms under specific conditions — but that flexibility was time-limited and does not represent the permanent regulatory baseline that covered entities must maintain going forward.
Healthcare organizations that treat HIPAA compliance as a one-time checkbox exercise rather than an ongoing program consistently encounter the same pattern: initial compliance activities at implementation, followed by years of drift as policies become outdated, training lapses, and new risks emerge without corresponding controls. OCR investigators are skilled at identifying this pattern from documentation gaps, and the absence of recent updates to policies and training materials is itself a red flag that elevates scrutiny of the underlying conduct being investigated.
HIPAA Questions and Answers
About the Author

Certified Internal Auditor & Compliance Certification Expert
University of Illinois Gies College of BusinessBrian Henderson is a Certified Internal Auditor, Certified Information Systems Auditor, and Certified Fraud Examiner with an MBA from the University of Illinois. He has 19 years of internal audit and regulatory compliance experience across financial services and healthcare industries, and coaches professionals through CIA, CISA, CFE, and SOX compliance certification programs.
Join the Discussion
Connect with other students preparing for this exam. Share tips, ask questions, and get advice from people who have been there.
View discussion (6 replies)



