hipaa.systems
Guide

HIPAA violation

What counts as a HIPAA violation, common examples in small practices and health tech companies, how violations differ from breaches, and what happens next.

HIPAA violation at a glance

A HIPAA violation is a failure by a covered entity or business associate to meet a requirement of the HIPAA Privacy, Security or Breach Notification Rules — for example, sharing protected health information without permission, not giving patients timely access to their records, having no risk analysis, missing a BAA with a vendor, or not reporting a breach. Not every incident is a violation, and not every violation is a breach. Violations can lead to corrective action plans and civil penalties from HHS OCR.

Who can commit oneCovered entities and business associates (and their workforce)
Most common findingsMissing risk analysis, improper disclosures, delayed patient access, missing BAAs
Who investigatesHHS Office for Civil Rights
Possible outcomesTechnical assistance, corrective action plan, settlement, civil money penalty
Criminal casesKnowingly obtaining or disclosing PHI unlawfully — Department of Justice

What counts as a violation

A violation is a failure to meet any requirement of the HIPAA rules. They fall into a few groups:

Type Examples
Improper use or disclosure Sharing PHI without a permitted purpose or authorization; staff snooping in records; a misdirected email or fax may be an impermissible disclosure
Missing safeguards No risk analysis; shared logins (unique user IDs are required); addressable safeguards such as encryption neither implemented nor documented
Vendor gaps Using a vendor that is a business associate — email, cloud or AI tools that handle PHI for you — without a BAA
Patient rights Slow or refused access to records; no Notice of Privacy Practices
Breach handling Not assessing an incident, or notifying late

Violation vs breach

A breach is an impermissible use or disclosure that compromises PHI. A violation is a failure to meet a requirement. A lost encrypted laptop may be neither; a missing risk analysis is a violation even if nothing has leaked yet.

What happens after a complaint

Anyone can file a complaint with the HHS Office for Civil Rights, generally within 180 days of when they knew of the problem (45 CFR 160.306). OCR may close it with technical assistance, require a corrective action plan, reach a settlement, or impose civil money penalties — see HIPAA penalties.

Knowingly obtaining or disclosing health information in violation of HIPAA is also a federal crime, prosecuted by the Department of Justice.

How to avoid the common ones

Most findings against small organizations trace back to a few gaps: no risk analysis, missing BAAs, weak access control and slow responses to breaches.

Next steps

Frequently asked questions

What are examples of HIPAA violations?

Staff looking up records out of curiosity, sharing PHI without a permitted purpose, using a business associate without a BAA, not doing a risk analysis, or taking months to answer a patient's records request.

Is a data breach always a HIPAA violation?

No. A breach can happen even with good safeguards. The violation question is whether the organization met its obligations — safeguards, risk analysis, and timely notification.

How do I report a HIPAA violation?

Patients and others can file a complaint with the HHS Office for Civil Rights, generally within 180 days of learning of the problem.