HIPAA violation
What counts as a HIPAA violation, common examples in small practices and health tech companies, how violations differ from breaches, and what happens next.
HIPAA violation at a glance
A HIPAA violation is a failure by a covered entity or business associate to meet a requirement of the HIPAA Privacy, Security or Breach Notification Rules — for example, sharing protected health information without permission, not giving patients timely access to their records, having no risk analysis, missing a BAA with a vendor, or not reporting a breach. Not every incident is a violation, and not every violation is a breach. Violations can lead to corrective action plans and civil penalties from HHS OCR.
| Who can commit one | Covered entities and business associates (and their workforce) |
|---|---|
| Most common findings | Missing risk analysis, improper disclosures, delayed patient access, missing BAAs |
| Who investigates | HHS Office for Civil Rights |
| Possible outcomes | Technical assistance, corrective action plan, settlement, civil money penalty |
| Criminal cases | Knowingly obtaining or disclosing PHI unlawfully — Department of Justice |
What counts as a violation
A violation is a failure to meet any requirement of the HIPAA rules. They fall into a few groups:
| Type | Examples |
|---|---|
| Improper use or disclosure | Sharing PHI without a permitted purpose or authorization; staff snooping in records; a misdirected email or fax may be an impermissible disclosure |
| Missing safeguards | No risk analysis; shared logins (unique user IDs are required); addressable safeguards such as encryption neither implemented nor documented |
| Vendor gaps | Using a vendor that is a business associate — email, cloud or AI tools that handle PHI for you — without a BAA |
| Patient rights | Slow or refused access to records; no Notice of Privacy Practices |
| Breach handling | Not assessing an incident, or notifying late |
Violation vs breach
A breach is an impermissible use or disclosure that compromises PHI. A violation is a failure to meet a requirement. A lost encrypted laptop may be neither; a missing risk analysis is a violation even if nothing has leaked yet.
What happens after a complaint
Anyone can file a complaint with the HHS Office for Civil Rights, generally within 180 days of when they knew of the problem (45 CFR 160.306). OCR may close it with technical assistance, require a corrective action plan, reach a settlement, or impose civil money penalties — see HIPAA penalties.
Knowingly obtaining or disclosing health information in violation of HIPAA is also a federal crime, prosecuted by the Department of Justice.
How to avoid the common ones
Most findings against small organizations trace back to a few gaps: no risk analysis, missing BAAs, weak access control and slow responses to breaches.
Next steps
- HIPAA for therapists in private practice →Scenario
- Notifying patients of a breach →Requirement
- Security risk analysis →Requirement
- Business associate agreements (BAAs) →Requirement
- PHI and ePHI →Requirement
Frequently asked questions
What are examples of HIPAA violations?
Staff looking up records out of curiosity, sharing PHI without a permitted purpose, using a business associate without a BAA, not doing a risk analysis, or taking months to answer a patient's records request.
Is a data breach always a HIPAA violation?
No. A breach can happen even with good safeguards. The violation question is whether the organization met its obligations — safeguards, risk analysis, and timely notification.
How do I report a HIPAA violation?
Patients and others can file a complaint with the HHS Office for Civil Rights, generally within 180 days of learning of the problem.