HIPAA Violation Examples: What Counts and What Does Not
Real examples of HIPAA violations, the current penalty tiers, and the question most guides skip: whether HIPAA applies to your business at all.
HIPAA Violation Examples
The examples every guide lists, plus the two questions almost none of them answer: whether the rule applies to your business at all, and which of the things people routinely call HIPAA violations are governed by an entirely different law. With the current penalty tiers, the annual caps that federal enforcement actually applies rather than the published ones, and real cases with the amounts attached
Almost every article on this subject is a list of twenty violations written for a hospital compliance officer. The lists are accurate. They also skip the two questions the average person searching this actually has, which are whether any of it applies to them and whether the thing that just happened at their workplace was really a HIPAA problem.
Here is the answer to the first one, from the federal health department itself: the Privacy Rule does not protect employment records, even where the information in them is health related, and in most cases it does not apply to the actions of an employer at all. A business that holds sick notes, accommodation paperwork, and workers compensation files is, for the overwhelming majority of employers, outside HIPAA entirely.
That does not mean the information is unprotected. It means a different set of laws governs it, and confusing the two produces both false alarms and real exposure in the places nobody is looking. This guide gives the examples, the penalty tiers with the caps federal enforcement actually applies rather than the published ones, and real cases with amounts. It also gives the part the healthcare-focused pages leave out: a three question coverage test, a list of things that are not HIPAA violations and what law governs them instead, and the specific HR scenarios worth watching. I build employee records tooling at FirstHR, so the access and records half of this is the part I work on daily.
What Counts as a Violation
A HIPAA violation is any failure by a covered entity or one of its business associates to comply with the Privacy, Security, or Breach Notification Rules. Intent is not an element, which is why accidental disclosures appear throughout federal enforcement history.
Federal enforcement data groups the most frequently cited issues into a consistent order. According to the Office for Civil Rights enforcement highlights, the most common compliance issues investigated are impermissible uses and disclosures of protected health information, lack of safeguards for that information, lack of patient access to their own records, lack of administrative safeguards for electronic information, and use or disclosure of more than the minimum necessary.
Two things follow from that ordering. The largest category is not hacking, it is people telling other people things they should not have. And the third category is a surprise to most readers: refusing or delaying an individual's access to their own records is itself a violation, and it has been the subject of a dedicated enforcement initiative aimed largely at small providers.
Does It Apply to You
Before reading any list of violations, settle whether the rule reaches your business. For most employers it does not, and this is the single most consequential misunderstanding in the entire subject.
The federal health department addresses this directly in guidance on employers and health information in the workplace, stating that the Privacy Rule does not protect employment records even where the information in them is health related, and that in most cases the rule does not apply to the actions of an employer. Your employer can ask for a doctor's note for sick leave, workers compensation, a wellness program, or health insurance without HIPAA being involved at all.
What the rule does control is the other direction: whether a health plan or a covered provider may share information about you with your employer. If your employer asks your provider directly, the provider generally cannot answer without your authorization. The obligation sits on the provider, not on the question.
Three situations bring an ordinary business inside the rules.
What Is Not a Violation
This table does not exist on any competing page and it resolves more real disputes than the examples list does. Each row is something routinely called a HIPAA violation that is not one, with the law that actually governs it.
| The situation | A HIPAA violation? | What actually governs it |
|---|---|---|
| Your employer asks for a doctor's note | No | Employment record. State law and company policy apply |
| A manager tells the team why you were absent | No | Confidentiality obligations, and possibly ADA if a disability is implied |
| HR keeps your accommodation paperwork | No | The Americans with Disabilities Act requires it be kept confidential and separate |
| Your employer asks about a family medical history | No | The Genetic Information Nondiscrimination Act, which restricts this sharply |
| A coworker asks why you were in hospital | No | Nothing legal. It is a workplace conduct matter |
| A business requires proof of vaccination to enter | No | The rule restricts providers and plans, not businesses asking questions |
| Your employer sees your leave certification | No | FMLA confidentiality rules require separate, restricted storage |
| A workers compensation insurer receives your records | Usually no | State workers compensation law, which often authorizes the disclosure |
| Your clinic tells your employer your diagnosis without consent | Yes | This is the direction HIPAA actually restricts |
The last row is the shape of a real one. HIPAA restricts what a plan or a provider may disclose, not what an employer may ask or hold. Once that is clear, most workplace disputes about health information reveal themselves as questions about the Americans with Disabilities Act or about FMLA confidentiality, both of which impose real requirements that get missed precisely because everyone is arguing about the wrong statute.
The same confusion reaches wellness programs and employee assistance programs, both of which sit under different rules than most people assume.
The practical consequence for an employer is a filing rule rather than a legal one. Medical information you hold about employees belongs in a separate, access-restricted file rather than in the general personnel file, and several of those separations are legally required even though none of them come from HIPAA.
Common Examples
Six categories cover the overwhelming majority of enforcement activity. Read them as failure modes rather than as a list of prohibited acts.
| Example | Category | Why it is a violation | Usually preventable by |
|---|---|---|---|
| Looking up a celebrity's chart out of curiosity | Snooping | No treatment, payment, or operations purpose | Access logs plus a sanctions policy people believe in |
| Discussing a patient by name in a lift | Disclosure | Overheard by people with no right to the information | Training, and a rule about where clinical conversations happen |
| Posting a photo with a chart visible in the background | Disclosure | Identifying information published to the world | A social media policy that says this specifically |
| A laptop stolen from a car, not encrypted | Safeguards | Failure to implement reasonable protection | Full disk encryption on everything, without exception |
| An email to the wrong client with an attached list | Disclosure | Impermissible disclosure regardless of intent | External send warnings and a pause before attaching |
| Records dumped in a skip during an office move | Disposal | No reasonable safeguard at end of life | Naming a person responsible for disposal |
| A former employee's login still active | Access control | Access retained without authorization | Offboarding that removes access the same day |
| Refusing a patient a copy of their own record | Right of access | A distinct and heavily enforced obligation | A written request process with a clock on it |
| Website analytics transmitting patient data to a third party | Disclosure | Information shared without authorization | Auditing what your site sends and to whom |
Unintentional Violations
Intent is not required, which surprises people and explains a large share of enforcement. The question is never whether someone meant it; it is what safeguards existed and whether the incident was handled properly afterward.
| Accidental incident | Does it still count? | What determines the outcome |
|---|---|---|
| Misdirected email or fax | Yes | How quickly it was caught, contained, and notified |
| Lost unencrypted device | Yes, and heavily | Encryption would usually have made it a non-event |
| Overheard conversation | Yes, technically | Whether reasonable safeguards were in place, not whether anyone listened |
| Wrong record opened and closed immediately | Possibly not | Some inadvertent access within an entity is permitted if it was in good faith and went no further |
| A colleague seeing a screen in passing | Usually not | Incidental disclosure is tolerated where reasonable safeguards exist |
| Sending records to a former employee's address | Yes | An address list nobody maintained is a safeguards failure |
Two rows in the middle carry the useful nuance. The rules contemplate incidental disclosures that occur despite reasonable safeguards and do not treat them as violations, which is why a conversation partially overheard in a properly designed space is different from one conducted loudly in a public lobby. The distinction is the safeguards, not the outcome.
Violation vs Breach
The two words are used interchangeably in ordinary speech and mean different things in the rules. Every breach is a violation; most violations are not breaches.
| Violation | Breach | |
|---|---|---|
| What it is | Any failure to comply with the rules | Impermissible acquisition, access, use, or disclosure that compromises security or privacy |
| Requires information to be exposed | No | Yes |
| Notification required | Not inherently | Yes, to individuals and to the federal regulator |
| Timing | No notification clock | Individuals without unreasonable delay and within 60 days; large breaches reported concurrently |
| Presumption | Established by investigation | An impermissible disclosure is presumed a breach unless a risk assessment shows low probability of compromise |
| Example | No risk analysis on file | A stolen unencrypted laptop with records on it |
The presumption in the fifth row is the operationally important one. When something impermissible happens, the default assumption is that it is a breach, and the way out is a documented four-factor risk assessment rather than a judgment call nobody wrote down. Organizations that skip the documentation lose the argument later even when the underlying assessment was reasonable.
Large breaches are published on the federal breach reporting portal, which is worth looking at once if only to see how ordinary most entries are. The list is dominated by email incidents and lost devices rather than by sophisticated attacks.
Penalties and Tiers
Civil penalties run in four tiers determined by culpability, and the amounts are adjusted for inflation annually. Here are the figures effective from the most recent adjustment.
| Tier | Culpability | Minimum per violation | Maximum per violation | Published annual cap |
|---|---|---|---|---|
| 1 | Did not know and could not reasonably have known | $145 | $73,011 | $2,190,294 |
| 2 | Reasonable cause, not willful neglect | $1,461 | $73,011 | $2,190,294 |
| 3 | Willful neglect, corrected within 30 days | $14,602 | $73,011 | $2,190,294 |
| 4 | Willful neglect, not corrected | $73,011 | $2,190,294 | $2,190,294 |
Now the part almost every competing page gets wrong. The published annual cap in the Federal Register adjustment is the same for all four tiers, but that is not what enforcement actually applies. Since a notification of enforcement discretion issued in April 2019, the regulator has applied substantially lower annual caps to the first three tiers, on its own reading of the underlying statute. Using the current inflation-adjusted figures, that works out to roughly $36,505 for tier one, $146,053 for tier two, $365,052 for tier three, and the full $2,190,294 only for tier four.
Criminal penalties sit on a separate track and apply to individuals as well as organizations: up to $50,000 and one year for knowingly obtaining or disclosing information, up to $100,000 and five years where the offense involves false pretenses, and up to $250,000 and ten years where it is committed for personal gain or malicious harm.
Real Enforcement Cases
The cases are more instructive than the categories, because they show what actually attracts a penalty and how ordinary the underlying failures usually are.
| Case | Amount | What happened | The lesson |
|---|---|---|---|
| A large health system | $865,500 | Employees repeatedly viewed celebrity records with no work reason | Snooping is an access control failure, not just a personnel matter |
| A medical center | $4.75 million | An employee took patient data over several months undetected | The detection gap mattered more than the theft |
| A university medical center | $3 million | A lost unencrypted flash drive and a stolen unencrypted laptop | Encryption would likely have prevented both entirely |
| A medical supplies company | $3 million | A phishing attack exposed data on more than 114,000 people | Email compromise is the most common entry point |
| A health insurer | $16 million | A breach affecting 78.8 million records | The largest settlement of its kind |
| A regional health provider | $200,000 | Failure to provide an individual access to their own records | Right of access enforcement targets organizations of every size |
The individual consequence is worth stating too. A former hospital researcher who accessed patient records after his employment ended was sentenced to four months in federal prison and fined $2,000, in what prosecutors described as the first incarceration in the country for a misdemeanor offense under these rules. Access that was never removed is not only an organizational failure; it can be a personal one.
The last row of the table is the one small organizations should read twice. Enforcement is not confined to large hospitals, and a dedicated initiative has pursued small providers for failing to give patients copies of their own records. The assumption that regulators only chase large institutions is not supported by the settlement record.
HR Scenarios to Watch
If your business does sit inside the rules through a plan, a clinic, or a business associate agreement, these are the situations where the line gets crossed without anyone intending to.
| Scenario | The risk | What to do |
|---|---|---|
| Self-insured plan administration | Plan information reaching people who make employment decisions | A documented firewall, and access limited to named plan administrators |
| Wellness program data | Health data flowing back to managers in identifiable form | Aggregate reporting only, and confirm what the vendor sends you |
| Employee assistance program | The program may itself be a covered provider | Confirm status with the provider and check the agreement |
| Onsite clinic records | Clinic records treated as employment records | Keep them separate in both storage and access |
| Vendors handling plan data | Business associate obligations nobody has read | Know which agreements you have signed and what they commit you to |
| Departures | Access to plan or clinic systems surviving the last day | Deprovision on the day, from a single checklist |
The first row is the one that separates a compliant sponsor from a non-compliant one, and it is a structural problem rather than a technical one. In a company of twenty, the person administering the plan is frequently the same person who makes hiring and firing decisions, and the required separation is genuinely hard to achieve. Where it cannot be achieved internally, moving administration to a third party is a legitimate answer.
The last row is the cheapest to fix and the most commonly missed. Access that outlives employment appears in enforcement actions repeatedly, and it is eliminated entirely by treating deprovisioning as a step on the offboarding checklist rather than as something to remember.
How to Prevent Them
Six actions cover most of the realistic exposure for a small organization. They are unglamorous and they are what the enforcement record actually rewards.
| A | B | C | D | E | |
|---|---|---|---|---|---|
| 1 | Question | Yes or no | If yes, what is covered | Who confirmed | Date |
| 2 | Do we sponsor a self-insured group health plan | The plan, not the employer function | |||
| 3 | Do we sponsor a fully insured plan only | Lighter obligations, mostly on the insurer | |||
| 4 | Do we operate an onsite clinic or occupational health service | The clinic if it bills electronically | |||
| 5 | Do we run an employee assistance program that bills electronically | That program | |||
| 6 | Do we handle health information on behalf of another company | Us, as a business associate | |||
| 7 | Have we signed any business associate agreement | Whatever the agreement covers | |||
| 8 | If all answers are no | HIPAA likely does not govern our employee health data |
The first sheet answers the coverage question and dates the answer. The second maps every category of employee health information you hold against which law governs it and whether it must be stored separately, which is the artifact that resolves nearly every workplace argument on this topic before it starts. The third is the incident log, which matters mainly because the version written afterward from memory is worth much less than the one written on the day.
Access and records discipline is the through-line across all six steps, and it is also ordinary document management practice rather than anything HIPAA specific. If you already keep employee records with role-based access, dated acknowledgments, and a clean offboarding routine, you have most of this whether or not you are covered.
How to Report One
Reporting runs on a defined process with a clock attached, and one feature of the law surprises nearly everyone.
| Step | What happens | Timing |
|---|---|---|
| Raise it internally with the privacy officer | Many issues resolve here, and covered entities are expected to have a process | As soon as practical |
| File a complaint with the federal regulator | Submitted through the complaint portal, in writing | Generally within 180 days of when you knew or should have known |
| Investigation or technical assistance | Most cases end in corrective action rather than a penalty | Varies widely |
| Retaliation protection | Retaliation against someone who files is prohibited | Applies throughout |
| No private lawsuit under the statute | An individual cannot sue under HIPAA itself | Other claims under state law may still exist |
The last row is the surprise. HIPAA creates no private right of action, so an individual who believes their information was mishandled cannot sue under it. Claims still arise, but under state privacy law, negligence, or contract rather than the federal statute. This is worth knowing before anyone in a workplace dispute reaches for the word.
For an employer on the receiving end of an internal complaint, the useful sequence is the same regardless of whether HIPAA applies: establish what information was involved, establish who saw it, document both, fix the control that failed, and tell the person what you did. That sequence resolves the legitimate grievance in most cases and creates the record you would want if it ever became formal.
Frequently Asked Questions
What is considered a HIPAA violation?
A HIPAA violation is any failure by a covered entity or its business associate to comply with the Privacy, Security, or Breach Notification Rules. The most frequently cited categories in federal enforcement data are impermissible uses and disclosures of protected health information, lack of safeguards for that information, denying individuals access to their own records, missing administrative safeguards for electronic records, and using or disclosing more than the minimum necessary. Intent is not required; an accidental disclosure is still a violation.
Does HIPAA apply to employers?
Generally not, when the employer is acting as an employer. HIPAA regulates health plans, health care clearinghouses, and health care providers that transmit standard electronic transactions. The federal health department states plainly that the Privacy Rule does not protect employment records, even where the information in them is health related, and that in most cases the rule does not apply to the actions of an employer. Three situations change this: sponsoring a self-insured group health plan, running an onsite clinic or similar program that bills electronically, or acting as a business associate.
Is it a HIPAA violation for my employer to share my medical information?
Usually not a HIPAA violation, though it may violate a different law. Health information your employer holds in your employment record sits outside HIPAA. Sharing it inappropriately can still breach confidentiality obligations under the Americans with Disabilities Act, the Family and Medical Leave Act, the Genetic Information Nondiscrimination Act, state privacy statutes, or your employment contract. The correct question is rarely whether HIPAA was violated. It is which law actually governs the information in question.
What are the most common HIPAA violations?
Six categories account for most of them. Accessing records without a work-related reason, often called snooping. Disclosing information to someone who has no right to it, including in conversation or on social media. Losing an unencrypted laptop, phone, or drive. Sending information to the wrong recipient by email, fax, or post. Improper disposal of paper records or devices. And access that was never removed when someone left. Notably few involve hackers; most are ordinary operational failures.
What is an example of an unintentional HIPAA violation?
A misdirected email containing patient information, a fax sent to an outdated number, a conversation about a patient overheard in a waiting room, or a laptop stolen from a car. Federal enforcement does not require intent, and several substantial penalties have followed from purely accidental incidents, including a three million dollar settlement arising from a lost unencrypted flash drive and a stolen unencrypted laptop. The absence of encryption, rather than the loss itself, is usually what converts the incident into an enforceable failure.
What are the penalties for a HIPAA violation?
Civil penalties run in four tiers based on culpability. For penalties assessed on or after the most recent inflation adjustment, minimums are $145 for lack of knowledge, $1,461 for reasonable cause, $14,602 for willful neglect corrected within thirty days, and $73,011 for willful neglect not corrected. The maximum per violation is $73,011 for the first three tiers and $2,190,294 for the fourth. Criminal penalties reach $250,000 and ten years in prison for offenses committed for personal gain or malicious harm.
What is the difference between a HIPAA violation and a breach?
A violation is any failure to comply with the rules. A breach is a specific kind of violation: an impermissible acquisition, access, use, or disclosure of protected health information that compromises its security or privacy, and it carries mandatory notification obligations. Every breach is a violation, but not every violation is a breach. An impermissible disclosure is presumed to be a breach unless a documented risk assessment shows a low probability that the information was compromised.
Can you be fired for a HIPAA violation?
Yes, and termination is a common outcome even for a single incident, particularly for accessing records without a work reason. Employers subject to the rules are expected to apply sanctions for violations, and access logs make individual accountability straightforward to establish. Individuals can also face criminal liability in serious cases; the first person incarcerated for a misdemeanor HIPAA offense was a former hospital researcher who accessed patient records after his employment ended.
How do you report a HIPAA violation?
Start with the organization's own privacy officer if you are comfortable doing so, since many issues resolve internally. A formal complaint goes to the federal Office for Civil Rights through its complaint portal, generally within 180 days of when you knew or should have known about the act, with extensions available for good cause. Complaints can be filed anonymously as to the public record, and retaliation against someone who files is itself prohibited. Note that HIPAA provides no private right of action, so an individual cannot sue under it directly.