FirstHR

HIPAA Violation Examples: What Counts and What Does Not

Real examples of HIPAA violations, the current penalty tiers, and the question most guides skip: whether HIPAA applies to your business at all.

Nick Anisimov

Nick Anisimov

FirstHR Founder

Compliance
24 min

HIPAA Violation Examples

The examples every guide lists, plus the two questions almost none of them answer: whether the rule applies to your business at all, and which of the things people routinely call HIPAA violations are governed by an entirely different law. With the current penalty tiers, the annual caps that federal enforcement actually applies rather than the published ones, and real cases with the amounts attached

Almost every article on this subject is a list of twenty violations written for a hospital compliance officer. The lists are accurate. They also skip the two questions the average person searching this actually has, which are whether any of it applies to them and whether the thing that just happened at their workplace was really a HIPAA problem.

Here is the answer to the first one, from the federal health department itself: the Privacy Rule does not protect employment records, even where the information in them is health related, and in most cases it does not apply to the actions of an employer at all. A business that holds sick notes, accommodation paperwork, and workers compensation files is, for the overwhelming majority of employers, outside HIPAA entirely.

That does not mean the information is unprotected. It means a different set of laws governs it, and confusing the two produces both false alarms and real exposure in the places nobody is looking. This guide gives the examples, the penalty tiers with the caps federal enforcement actually applies rather than the published ones, and real cases with amounts. It also gives the part the healthcare-focused pages leave out: a three question coverage test, a list of things that are not HIPAA violations and what law governs them instead, and the specific HR scenarios worth watching. I build employee records tooling at FirstHR, so the access and records half of this is the part I work on daily.

TL;DR
A HIPAA violation is a failure by a covered entity or business associate to comply with the Privacy, Security, or Breach Notification Rules. Most employers are neither, and the federal health department states that the Privacy Rule does not protect employment records. Three situations pull an ordinary business in: a self-insured health plan, an onsite clinic or program that bills electronically, or acting as a business associate. Civil penalties run four tiers from $145 to $2,190,294 per violation, and intent is not required.

What Counts as a Violation

A HIPAA violation is any failure by a covered entity or one of its business associates to comply with the Privacy, Security, or Breach Notification Rules. Intent is not an element, which is why accidental disclosures appear throughout federal enforcement history.

Definition
HIPAA violation
Non-compliance with any requirement of the HIPAA Privacy, Security, or Breach Notification Rules by a covered entity or a business associate. Covered entities are health plans, health care clearinghouses, and health care providers that transmit health information electronically in connection with standard transactions. Business associates are organizations that create, receive, maintain, or transmit protected health information on a covered entity's behalf. Violations range from an unlocked filing cabinet to a systemic failure to conduct a risk analysis, and the level of culpability determines the penalty tier rather than whether a violation occurred.

Federal enforcement data groups the most frequently cited issues into a consistent order. According to the Office for Civil Rights enforcement highlights, the most common compliance issues investigated are impermissible uses and disclosures of protected health information, lack of safeguards for that information, lack of patient access to their own records, lack of administrative safeguards for electronic information, and use or disclosure of more than the minimum necessary.

374,321
Complaints received since 2003
1,193
Compliance reviews initiated
99%
Of cases resolved

Two things follow from that ordering. The largest category is not hacking, it is people telling other people things they should not have. And the third category is a surprise to most readers: refusing or delaying an individual's access to their own records is itself a violation, and it has been the subject of a dedicated enforcement initiative aimed largely at small providers.

Does It Apply to You

Before reading any list of violations, settle whether the rule reaches your business. For most employers it does not, and this is the single most consequential misunderstanding in the entire subject.

The federal health department addresses this directly in guidance on employers and health information in the workplace, stating that the Privacy Rule does not protect employment records even where the information in them is health related, and that in most cases the rule does not apply to the actions of an employer. Your employer can ask for a doctor's note for sick leave, workers compensation, a wellness program, or health insurance without HIPAA being involved at all.

What the rule does control is the other direction: whether a health plan or a covered provider may share information about you with your employer. If your employer asks your provider directly, the provider generally cannot answer without your authorization. The obligation sits on the provider, not on the question.

Three situations bring an ordinary business inside the rules.

You sponsor a self-insured group health planThe plan is covered, the company as employer still is notWhen a business funds employee health claims itself rather than buying fully insured coverage, the plan becomes a covered entity. The obligation attaches to the plan and to whoever administers it, which is why a firewall between plan information and employment decisions is required. A fully insured plan where the insurer handles everything creates far lighter obligations for the employer.
You run an onsite clinic or a program that bills electronicallyThe clinic is a health care providerAn onsite clinic, an occupational health service, or an employee assistance program becomes a covered health care provider if it transmits standard electronic transactions such as claims. The employer side of the business remains outside the rule, but the clinic itself sits inside it, and the separation between the two has to be real rather than notional.
You are a business associate of a covered entityThe contract creates the obligationA vendor that creates, receives, maintains, or transmits protected health information on behalf of a covered entity is a business associate and is directly liable under the rules. This catches software companies, billing services, shredding companies, and consultants, usually via a signed business associate agreement they may not have read closely.
If none of the three describes your business, HIPAA almost certainly does not govern how you handle employee health information. Other laws still do, which is the part most articles on this subject leave out entirely.
Covered Entity Is a Function, Not a Company
A business can be partly covered and mostly not. A company that sponsors a self-insured plan is a covered entity through the plan while remaining outside the rules in everything it does as an employer. That is why the required separation is between functions rather than between organizations, and why plan information must not flow into employment decisions. Drawing that line on paper and then ignoring it in practice is a more realistic risk for a small business than any hacking scenario.
What worked for me
The conversation I have had most often about this starts with someone certain that a HIPAA violation has occurred, and it almost never has. A manager mentioned a colleague's surgery in a team meeting, or an owner told a customer why someone was out. Both are genuinely bad practice and both damage trust immediately. Neither is a HIPAA violation, and saying so is not letting anyone off, because the right answer is that a different obligation applies and it is one nobody has bothered to look up. The energy that goes into arguing about the acronym is the energy that should be going into the confidentiality rule that actually governs the situation.

What Is Not a Violation

This table does not exist on any competing page and it resolves more real disputes than the examples list does. Each row is something routinely called a HIPAA violation that is not one, with the law that actually governs it.

The situationA HIPAA violation?What actually governs it
Your employer asks for a doctor's noteNoEmployment record. State law and company policy apply
A manager tells the team why you were absentNoConfidentiality obligations, and possibly ADA if a disability is implied
HR keeps your accommodation paperworkNoThe Americans with Disabilities Act requires it be kept confidential and separate
Your employer asks about a family medical historyNoThe Genetic Information Nondiscrimination Act, which restricts this sharply
A coworker asks why you were in hospitalNoNothing legal. It is a workplace conduct matter
A business requires proof of vaccination to enterNoThe rule restricts providers and plans, not businesses asking questions
Your employer sees your leave certificationNoFMLA confidentiality rules require separate, restricted storage
A workers compensation insurer receives your recordsUsually noState workers compensation law, which often authorizes the disclosure
Your clinic tells your employer your diagnosis without consentYesThis is the direction HIPAA actually restricts

The last row is the shape of a real one. HIPAA restricts what a plan or a provider may disclose, not what an employer may ask or hold. Once that is clear, most workplace disputes about health information reveal themselves as questions about the Americans with Disabilities Act or about FMLA confidentiality, both of which impose real requirements that get missed precisely because everyone is arguing about the wrong statute.

The same confusion reaches wellness programs and employee assistance programs, both of which sit under different rules than most people assume.

The practical consequence for an employer is a filing rule rather than a legal one. Medical information you hold about employees belongs in a separate, access-restricted file rather than in the general personnel file, and several of those separations are legally required even though none of them come from HIPAA.

Still Using Spreadsheets for Onboarding?
Automate documents, training assignments, task management, and track onboarding progress in real time.
See How It Works

Common Examples

Six categories cover the overwhelming majority of enforcement activity. Read them as failure modes rather than as a list of prohibited acts.

Snooping in records with no work reasonLooking up a neighbor, a relative, a colleague, or a public figure out of curiosity. Access being technically possible is not authorization, and this category is where criminal referrals concentrate because intent is easy to establish from the access logs.
Disclosure to someone with no right to itDiscussing a patient in a corridor, an elevator, or a waiting room; posting anything identifying on social media; telling a family member something the individual did not authorize. Impermissible use and disclosure is the single most frequently cited category in federal enforcement data.
Losing an unencrypted deviceA laptop, phone, or drive containing health information, lost or stolen without encryption. Encryption is what turns a lost device into a non-event, and its absence is what turns the same incident into a reportable breach with a penalty attached.
Sending information to the wrong recipientA misdirected email, a fax to an outdated number, a letter in the wrong envelope, a mail merge that shifted by one row. The most common cause of small breaches and almost always genuinely accidental, which does not remove the notification obligation.
Improper disposalPaper records in a regular bin, devices sold or recycled without wiping, filing cabinets left behind in a move. Disposal is the step nobody assigns to anyone, which is why it produces enforcement actions long after the underlying process was abandoned.
Access that was never removedA departed employee whose credentials still work, a contractor with standing access to a shared drive, an account nobody deprovisioned. This is an offboarding failure that presents as a security incident, and it is one of the cheapest categories to eliminate entirely.
Note how few of these involve hackers. Most enforcement in this area follows from ordinary operational failures inside organizations that meant no harm, which is the useful thing to understand if you are trying to prevent one rather than to read about one.
ExampleCategoryWhy it is a violationUsually preventable by
Looking up a celebrity's chart out of curiositySnoopingNo treatment, payment, or operations purposeAccess logs plus a sanctions policy people believe in
Discussing a patient by name in a liftDisclosureOverheard by people with no right to the informationTraining, and a rule about where clinical conversations happen
Posting a photo with a chart visible in the backgroundDisclosureIdentifying information published to the worldA social media policy that says this specifically
A laptop stolen from a car, not encryptedSafeguardsFailure to implement reasonable protectionFull disk encryption on everything, without exception
An email to the wrong client with an attached listDisclosureImpermissible disclosure regardless of intentExternal send warnings and a pause before attaching
Records dumped in a skip during an office moveDisposalNo reasonable safeguard at end of lifeNaming a person responsible for disposal
A former employee's login still activeAccess controlAccess retained without authorizationOffboarding that removes access the same day
Refusing a patient a copy of their own recordRight of accessA distinct and heavily enforced obligationA written request process with a clock on it
Website analytics transmitting patient data to a third partyDisclosureInformation shared without authorizationAuditing what your site sends and to whom

Unintentional Violations

Intent is not required, which surprises people and explains a large share of enforcement. The question is never whether someone meant it; it is what safeguards existed and whether the incident was handled properly afterward.

Accidental incidentDoes it still count?What determines the outcome
Misdirected email or faxYesHow quickly it was caught, contained, and notified
Lost unencrypted deviceYes, and heavilyEncryption would usually have made it a non-event
Overheard conversationYes, technicallyWhether reasonable safeguards were in place, not whether anyone listened
Wrong record opened and closed immediatelyPossibly notSome inadvertent access within an entity is permitted if it was in good faith and went no further
A colleague seeing a screen in passingUsually notIncidental disclosure is tolerated where reasonable safeguards exist
Sending records to a former employee's addressYesAn address list nobody maintained is a safeguards failure

Two rows in the middle carry the useful nuance. The rules contemplate incidental disclosures that occur despite reasonable safeguards and do not treat them as violations, which is why a conversation partially overheard in a properly designed space is different from one conducted loudly in a public lobby. The distinction is the safeguards, not the outcome.

Encryption Is the Difference Between an Incident and a Breach
A lost encrypted device is generally not a reportable breach, because the information is not usable. The same device unencrypted is a breach with notification obligations and potential penalties. Several of the largest settlements involving small numbers of people trace to exactly this distinction. If you hold health information on any portable device, full disk encryption is the cheapest risk reduction available anywhere in this article.

Violation vs Breach

The two words are used interchangeably in ordinary speech and mean different things in the rules. Every breach is a violation; most violations are not breaches.

ViolationBreach
What it isAny failure to comply with the rulesImpermissible acquisition, access, use, or disclosure that compromises security or privacy
Requires information to be exposedNoYes
Notification requiredNot inherentlyYes, to individuals and to the federal regulator
TimingNo notification clockIndividuals without unreasonable delay and within 60 days; large breaches reported concurrently
PresumptionEstablished by investigationAn impermissible disclosure is presumed a breach unless a risk assessment shows low probability of compromise
ExampleNo risk analysis on fileA stolen unencrypted laptop with records on it

The presumption in the fifth row is the operationally important one. When something impermissible happens, the default assumption is that it is a breach, and the way out is a documented four-factor risk assessment rather than a judgment call nobody wrote down. Organizations that skip the documentation lose the argument later even when the underlying assessment was reasonable.

Large breaches are published on the federal breach reporting portal, which is worth looking at once if only to see how ordinary most entries are. The list is dominated by email incidents and lost devices rather than by sophisticated attacks.

Penalties and Tiers

Civil penalties run in four tiers determined by culpability, and the amounts are adjusted for inflation annually. Here are the figures effective from the most recent adjustment.

TierCulpabilityMinimum per violationMaximum per violationPublished annual cap
1Did not know and could not reasonably have known$145$73,011$2,190,294
2Reasonable cause, not willful neglect$1,461$73,011$2,190,294
3Willful neglect, corrected within 30 days$14,602$73,011$2,190,294
4Willful neglect, not corrected$73,011$2,190,294$2,190,294

Now the part almost every competing page gets wrong. The published annual cap in the Federal Register adjustment is the same for all four tiers, but that is not what enforcement actually applies. Since a notification of enforcement discretion issued in April 2019, the regulator has applied substantially lower annual caps to the first three tiers, on its own reading of the underlying statute. Using the current inflation-adjusted figures, that works out to roughly $36,505 for tier one, $146,053 for tier two, $365,052 for tier three, and the full $2,190,294 only for tier four.

The Cap You Read Is Not the Cap Applied
Penalty tables across this topic show a $2,190,294 annual cap for all four tiers because that is the published figure. In practice the regulator has applied reduced annual caps to tiers one through three since 2019 under an enforcement discretion notice, leaving the full amount exposed only at the top tier. Both facts are true, and citing only the first substantially overstates the realistic exposure for an organization that made an honest mistake.

Criminal penalties sit on a separate track and apply to individuals as well as organizations: up to $50,000 and one year for knowingly obtaining or disclosing information, up to $100,000 and five years where the offense involves false pretenses, and up to $250,000 and ten years where it is committed for personal gain or malicious harm.

Companies Using FirstHR Onboard 3x Faster
Join hundreds of small businesses who transformed their new hire experience.
See It in Action

Real Enforcement Cases

The cases are more instructive than the categories, because they show what actually attracts a penalty and how ordinary the underlying failures usually are.

CaseAmountWhat happenedThe lesson
A large health system$865,500Employees repeatedly viewed celebrity records with no work reasonSnooping is an access control failure, not just a personnel matter
A medical center$4.75 millionAn employee took patient data over several months undetectedThe detection gap mattered more than the theft
A university medical center$3 millionA lost unencrypted flash drive and a stolen unencrypted laptopEncryption would likely have prevented both entirely
A medical supplies company$3 millionA phishing attack exposed data on more than 114,000 peopleEmail compromise is the most common entry point
A health insurer$16 millionA breach affecting 78.8 million recordsThe largest settlement of its kind
A regional health provider$200,000Failure to provide an individual access to their own recordsRight of access enforcement targets organizations of every size

The individual consequence is worth stating too. A former hospital researcher who accessed patient records after his employment ended was sentenced to four months in federal prison and fined $2,000, in what prosecutors described as the first incarceration in the country for a misdemeanor offense under these rules. Access that was never removed is not only an organizational failure; it can be a personal one.

The last row of the table is the one small organizations should read twice. Enforcement is not confined to large hospitals, and a dedicated initiative has pursued small providers for failing to give patients copies of their own records. The assumption that regulators only chase large institutions is not supported by the settlement record.

HR Scenarios to Watch

If your business does sit inside the rules through a plan, a clinic, or a business associate agreement, these are the situations where the line gets crossed without anyone intending to.

ScenarioThe riskWhat to do
Self-insured plan administrationPlan information reaching people who make employment decisionsA documented firewall, and access limited to named plan administrators
Wellness program dataHealth data flowing back to managers in identifiable formAggregate reporting only, and confirm what the vendor sends you
Employee assistance programThe program may itself be a covered providerConfirm status with the provider and check the agreement
Onsite clinic recordsClinic records treated as employment recordsKeep them separate in both storage and access
Vendors handling plan dataBusiness associate obligations nobody has readKnow which agreements you have signed and what they commit you to
DeparturesAccess to plan or clinic systems surviving the last dayDeprovision on the day, from a single checklist

The first row is the one that separates a compliant sponsor from a non-compliant one, and it is a structural problem rather than a technical one. In a company of twenty, the person administering the plan is frequently the same person who makes hiring and firing decisions, and the required separation is genuinely hard to achieve. Where it cannot be achieved internally, moving administration to a third party is a legitimate answer.

The last row is the cheapest to fix and the most commonly missed. Access that outlives employment appears in enforcement actions repeatedly, and it is eliminated entirely by treating deprovisioning as a step on the offboarding checklist rather than as something to remember.

How to Prevent Them

Six actions cover most of the realistic exposure for a small organization. They are unglamorous and they are what the enforcement record actually rewards.

1
Settle whether you are covered, in writing
Answer the three coverage questions and record the answer with a date. Half the organizations worrying about this are not subject to the rules, and half the ones that are have never confirmed it. Either way, an undocumented assumption is the wrong starting point.
2
Encrypt every portable device without exception
Laptops, phones, and drives. This single control is what separates a lost device from a reportable breach, and it appears in the enforcement record more often than any other technical failure.
3
Give people the minimum access their job requires
Not the access that is convenient, and not the access their predecessor had. Most snooping cases are possible only because access was broader than the role needed, and narrowing it costs nothing recurring.
4
Remove access the day someone leaves
From one checklist, covering every system rather than the two obvious ones. Access that survives a departure shows up in enforcement actions and is entirely preventable by process.
5
Separate health information from the general personnel file
Required by several laws regardless of whether HIPAA applies to you, and it is the control that limits damage when a file is shared more widely than intended.
6
Write down what happened when something goes wrong
Date, what was involved, how many people, whether it was encrypted, who was notified, and what changed afterward. A documented assessment is what converts an incident into a handled incident, and the absence of one is what turns a defensible judgment into an indefensible gap.
Coverage Check, Health Data Map, and Incident Log
ABCDE
1QuestionYes or noIf yes, what is coveredWho confirmedDate
2Do we sponsor a self-insured group health planThe plan, not the employer function
3Do we sponsor a fully insured plan onlyLighter obligations, mostly on the insurer
4Do we operate an onsite clinic or occupational health serviceThe clinic if it bills electronically
5Do we run an employee assistance program that bills electronicallyThat program
6Do we handle health information on behalf of another companyUs, as a business associate
7Have we signed any business associate agreementWhatever the agreement covers
8If all answers are noHIPAA likely does not govern our employee health data

The first sheet answers the coverage question and dates the answer. The second maps every category of employee health information you hold against which law governs it and whether it must be stored separately, which is the artifact that resolves nearly every workplace argument on this topic before it starts. The third is the incident log, which matters mainly because the version written afterward from memory is worth much less than the one written on the day.

Access and records discipline is the through-line across all six steps, and it is also ordinary document management practice rather than anything HIPAA specific. If you already keep employee records with role-based access, dated acknowledgments, and a clean offboarding routine, you have most of this whether or not you are covered.

How to Report One

Reporting runs on a defined process with a clock attached, and one feature of the law surprises nearly everyone.

StepWhat happensTiming
Raise it internally with the privacy officerMany issues resolve here, and covered entities are expected to have a processAs soon as practical
File a complaint with the federal regulatorSubmitted through the complaint portal, in writingGenerally within 180 days of when you knew or should have known
Investigation or technical assistanceMost cases end in corrective action rather than a penaltyVaries widely
Retaliation protectionRetaliation against someone who files is prohibitedApplies throughout
No private lawsuit under the statuteAn individual cannot sue under HIPAA itselfOther claims under state law may still exist

The last row is the surprise. HIPAA creates no private right of action, so an individual who believes their information was mishandled cannot sue under it. Claims still arise, but under state privacy law, negligence, or contract rather than the federal statute. This is worth knowing before anyone in a workplace dispute reaches for the word.

For an employer on the receiving end of an internal complaint, the useful sequence is the same regardless of whether HIPAA applies: establish what information was involved, establish who saw it, document both, fix the control that failed, and tell the person what you did. That sequence resolves the legitimate grievance in most cases and creates the record you would want if it ever became formal.

Key Takeaways
A HIPAA violation is any failure by a covered entity or business associate to comply with the Privacy, Security, or Breach Notification Rules. Intent is not required.
The federal health department states that the Privacy Rule does not protect employment records and in most cases does not apply to the actions of an employer.
Three situations bring an ordinary business inside the rules: sponsoring a self-insured group health plan, running an onsite clinic or program that bills electronically, or acting as a business associate.
Most things people call HIPAA violations at work are not. Sick notes, accommodation paperwork, and leave certifications are governed by the ADA, FMLA, GINA, and state law instead.
HIPAA restricts what a plan or provider may disclose, not what an employer may ask or hold. That direction is the whole distinction.
Six failure modes cover most enforcement: snooping, impermissible disclosure, lost unencrypted devices, misdirected messages, improper disposal, and access that was never removed.
Encryption is the difference between an incident and a reportable breach, and it is the cheapest control available.
Every breach is a violation but most violations are not breaches. An impermissible disclosure is presumed to be a breach unless a documented risk assessment shows otherwise.
Civil penalties run four tiers from $145 to $2,190,294 per violation, with criminal exposure reaching $250,000 and ten years for offenses committed for personal gain.
The published annual cap is identical across tiers, but enforcement has applied substantially lower caps to the first three tiers since 2019. Most penalty tables omit this.
Enforcement reaches small organizations. A dedicated initiative has pursued small providers over failures to give individuals copies of their own records.
HIPAA creates no private right of action, so an individual cannot sue under it directly, though state law claims may still exist.

Frequently Asked Questions

What is considered a HIPAA violation?

A HIPAA violation is any failure by a covered entity or its business associate to comply with the Privacy, Security, or Breach Notification Rules. The most frequently cited categories in federal enforcement data are impermissible uses and disclosures of protected health information, lack of safeguards for that information, denying individuals access to their own records, missing administrative safeguards for electronic records, and using or disclosing more than the minimum necessary. Intent is not required; an accidental disclosure is still a violation.

Does HIPAA apply to employers?

Generally not, when the employer is acting as an employer. HIPAA regulates health plans, health care clearinghouses, and health care providers that transmit standard electronic transactions. The federal health department states plainly that the Privacy Rule does not protect employment records, even where the information in them is health related, and that in most cases the rule does not apply to the actions of an employer. Three situations change this: sponsoring a self-insured group health plan, running an onsite clinic or similar program that bills electronically, or acting as a business associate.

Is it a HIPAA violation for my employer to share my medical information?

Usually not a HIPAA violation, though it may violate a different law. Health information your employer holds in your employment record sits outside HIPAA. Sharing it inappropriately can still breach confidentiality obligations under the Americans with Disabilities Act, the Family and Medical Leave Act, the Genetic Information Nondiscrimination Act, state privacy statutes, or your employment contract. The correct question is rarely whether HIPAA was violated. It is which law actually governs the information in question.

What are the most common HIPAA violations?

Six categories account for most of them. Accessing records without a work-related reason, often called snooping. Disclosing information to someone who has no right to it, including in conversation or on social media. Losing an unencrypted laptop, phone, or drive. Sending information to the wrong recipient by email, fax, or post. Improper disposal of paper records or devices. And access that was never removed when someone left. Notably few involve hackers; most are ordinary operational failures.

What is an example of an unintentional HIPAA violation?

A misdirected email containing patient information, a fax sent to an outdated number, a conversation about a patient overheard in a waiting room, or a laptop stolen from a car. Federal enforcement does not require intent, and several substantial penalties have followed from purely accidental incidents, including a three million dollar settlement arising from a lost unencrypted flash drive and a stolen unencrypted laptop. The absence of encryption, rather than the loss itself, is usually what converts the incident into an enforceable failure.

What are the penalties for a HIPAA violation?

Civil penalties run in four tiers based on culpability. For penalties assessed on or after the most recent inflation adjustment, minimums are $145 for lack of knowledge, $1,461 for reasonable cause, $14,602 for willful neglect corrected within thirty days, and $73,011 for willful neglect not corrected. The maximum per violation is $73,011 for the first three tiers and $2,190,294 for the fourth. Criminal penalties reach $250,000 and ten years in prison for offenses committed for personal gain or malicious harm.

What is the difference between a HIPAA violation and a breach?

A violation is any failure to comply with the rules. A breach is a specific kind of violation: an impermissible acquisition, access, use, or disclosure of protected health information that compromises its security or privacy, and it carries mandatory notification obligations. Every breach is a violation, but not every violation is a breach. An impermissible disclosure is presumed to be a breach unless a documented risk assessment shows a low probability that the information was compromised.

Can you be fired for a HIPAA violation?

Yes, and termination is a common outcome even for a single incident, particularly for accessing records without a work reason. Employers subject to the rules are expected to apply sanctions for violations, and access logs make individual accountability straightforward to establish. Individuals can also face criminal liability in serious cases; the first person incarcerated for a misdemeanor HIPAA offense was a former hospital researcher who accessed patient records after his employment ended.

How do you report a HIPAA violation?

Start with the organization's own privacy officer if you are comfortable doing so, since many issues resolve internally. A formal complaint goes to the federal Office for Civil Rights through its complaint portal, generally within 180 days of when you knew or should have known about the act, with extensions available for good cause. Complaints can be filed anonymously as to the public record, and retaliation against someone who files is itself prohibited. Note that HIPAA provides no private right of action, so an individual cannot sue under it directly.

Ready to transform your onboarding?

7-day free trial No credit card required
Start Your Free Trial