Examples of HIPAA violations include employees snooping in patient charts, healthcare workers posting identifiable details on social media, lost or stolen unencrypted laptops, dumpsters full of unshredded records, refusing to give patients copies of their own files, missed breach notifications, oversharing with insurers or vendors, working with contractors who never signed a business associate agreement, and skipping the required security risk analysis. Civil penalties run from $145 per violation up to a calendar-year cap of $2,190,294, and criminal cases can reach ten years in federal prison.
Snooping in Patient Records
Curiosity is one of the most common triggers. A nurse pulls up the chart of a celebrity who was just admitted. A registration clerk looks up a neighbor’s diagnosis. Federal rules prohibit covered entities and business associates from using or disclosing protected health information except as specifically permitted, so viewing a record without a treatment, payment, or operations reason is a violation even if nothing gets shared.1eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information: General Rules
Audit controls are what catch it. The Security Rule requires covered entities to log who accessed which records and when.2eCFR. 45 CFR 164.312 – Technical Safeguards When those logs show a scheduler opening oncology records or a billing clerk viewing behavioral health notes, that pattern gets flagged.
Snooping can put the employee personally in criminal jeopardy, not just the employer. Knowingly obtaining individually identifiable health information without authorization carries up to a $50,000 fine and one year in prison. Under false pretenses, the ceiling rises to $100,000 and five years. If the information is obtained to sell, for personal gain, or for malicious purposes, the maximum is $250,000 and ten years.3Office of the Law Revision Counsel. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information
Posting Patient Information on Social Media
Healthcare workers who post about their jobs sometimes cross into a violation without meaning to. A photo of a wound shared in a professional forum. A comment describing a memorable case in enough detail to identify the person. A background shot that catches a whiteboard with names on it. Any disclosure of protected health information beyond treatment, payment, or operations needs valid written authorization from the patient first.4eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required
The trap: you don’t have to use a name to violate the rule. A rare condition, an unusual injury, or the combination of age, location, and treatment date can make someone identifiable. If a reasonable person could figure out who the post is about, the information wasn’t properly de-identified. Well-meaning clinicians often assume leaving out the name is enough. It usually isn’t.
Consequences reach both the employee and the employer. The individual can be fired and, if the disclosure was knowing and willful, prosecuted. The organization faces civil penalties and lasting reputational damage.
Lost or Stolen Unencrypted Devices
A laptop taken from a physician’s car. A USB drive left at a coffee shop. A tablet lifted from an unlocked office. Each becomes a serious violation when the device holds unprotected patient data. The Security Rule treats encryption as an addressable safeguard, meaning the entity must either implement it or document why an equivalent alternative is reasonable.2eCFR. 45 CFR 164.312 – Technical Safeguards In practice there is almost never a good reason to skip encryption on a portable device.
The legal problem isn’t the theft. It’s the decision to store patient data on a device without adequate protection. When information is properly encrypted using validated standards, a theft doesn’t trigger breach notification at all because the data is considered secured.5eCFR. 45 CFR 164.402 – Definitions That safe harbor is the single best insurance policy against a lost device becoming a multi-million-dollar enforcement matter. Some of the largest HIPAA settlements on record involved stolen laptops and drives holding hundreds of thousands of unencrypted records, and the aftermath usually includes years of operating under a corrective action plan.
Improper Disposal of Records and Devices
Protection obligations don’t end when a record is no longer needed. Covered entities have to maintain reasonable safeguards for protected health information through disposal.6U.S. Department of Health and Human Services. Frequently Asked Questions About the Disposal of Protected Health Information That means shredding paper charts rather than tossing them, and wiping hard drives on old computers and photocopiers before selling or recycling them.
This happens more often than people expect. Offices upgrade copiers and forget the machines store scanned images internally. A clinic closes and boxes of patient files end up at the curb. Laptops get donated with years of billing data still on the drive. The organization stays liable for anything an unauthorized person recovers.7eCFR. 45 CFR 164.530 – Administrative Requirements
A workable disposal policy specifies how information will be rendered permanently unreadable. Cross-cut shredding or incineration for paper. Certified data-destruction software or physical destruction for digital media. Treating disposal as an afterthought is how organizations end up with six-figure enforcement actions.
Denying or Delaying a Patient’s Record Request
Patients have a federal right to inspect and copy their own health information. A covered entity has to act on an access request within 30 days, with one possible 30-day extension if it provides a written explanation for the delay.8eCFR. 45 CFR 164.524 – Access of Individuals to Protected Health Information Records must be provided in the form and format the patient asks for, as long as that format is readily producible. If the request is for an electronic copy and the entity keeps records electronically, an electronic copy is what has to be provided.
Refusing to release records because a patient owes money is illegal. An unpaid balance is not a valid reason to withhold records. Other violations in this category include charging fees that exceed the law’s reasonable, cost-based limit, and simply ignoring requests until the patient gives up.
The Office for Civil Rights has made this a priority area. OCR has settled numerous Right of Access cases against small practices and large health systems alike, with penalty amounts reflecting the size of the provider and how egregious the delay was.9U.S. Department of Health and Human Services. Resolution Agreements
One boundary worth knowing: HIPAA does not create a private right of action. You cannot sue a provider in federal court for a HIPAA violation. The enforcement route is filing a complaint with OCR, which then investigates and can impose penalties.10U.S. Department of Health and Human Services. Health Information Privacy Some patients pursue state-law claims for negligence or invasion of privacy on the same facts, but the statute itself doesn’t give individuals standing to sue.
Failing to Report a Breach
Once a breach of unsecured health information happens, staying quiet about it is a separate violation on top of whatever caused the breach. Covered entities have to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. The notice has to describe what happened, what types of information were involved, and what the person should do to protect themselves.11eCFR. 45 CFR 164.404 – Notification to Individuals
Reporting scales with size. If a breach affects 500 or more people in a state or jurisdiction, the entity also has to notify prominent local media outlets within 60 days and report the breach to the HHS Secretary at the same time.12eCFR. 45 CFR 164.406 – Notification to the Media For breaches affecting fewer than 500 people, the individuals still have to be notified within 60 days, but the report to HHS can be filed annually, no later than 60 days after the end of the calendar year in which the breach was discovered.
Organizations sometimes try to sidestep these obligations by reclassifying an incident as something other than a breach or by dragging an internal investigation past the 60-day window. Deliberate non-reporting is treated as willful neglect and lands in the highest penalty tier.
Sharing More Than the Minimum Necessary
The minimum necessary standard is one of the most frequently overlooked HIPAA rules. When using or disclosing protected health information, a covered entity has to make reasonable efforts to limit the data to the smallest amount needed to accomplish the purpose.1eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information: General Rules Being authorized to receive some patient information doesn’t mean being entitled to the entire chart.
Common examples: a hospital sends a full medical record to a life insurance company that requested one specific lab result. A billing department gives a collections agency diagnosis codes along with the balance owed. A specialist receives a referral packet stuffed with years of unrelated treatment history. Each disclosure went further than it needed to.
The minimum necessary standard doesn’t apply to disclosures between providers for treatment, which recognizes that clinicians need flexibility. It applies to nearly everything else: payment, operations, insurer requests, disclosures to business associates, and most routine data sharing.
Business Associate and Vendor Failures
HIPAA reaches beyond doctors and hospitals. Any contractor, vendor, or service provider that handles protected health information for a covered entity is a business associate and is directly liable for compliance. That covers billing companies, cloud storage providers, IT consultants, shredding services, and even lawyers or accountants who receive patient data in the course of their work.13U.S. Department of Health and Human Services. Direct Liability of Business Associates
The most common violation in this area is operating without a business associate agreement. Federal law requires a written contract specifying how the business associate will protect health information, what it can and cannot do with the data, and what happens when the relationship ends. Without that agreement in place, both parties are out of compliance the moment data changes hands.
Responsibility also flows downstream. A business associate that hires subcontractors to process patient data has to execute agreements with those subcontractors too. This chain gets missed regularly because organizations don’t always realize their vendor’s vendor needs to be bound by the same rules. When a subcontractor causes a breach, the business associate is on the hook if it failed to take reasonable steps to address the problem or didn’t have proper agreements in place.
Skipping the Required Risk Analysis
Every covered entity and business associate has to conduct a thorough assessment of the risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic health information it holds.14eCFR. 45 CFR 164.308 – Administrative Safeguards This isn’t optional. It’s a required implementation specification, and failing to do it is probably the single most common finding in OCR enforcement actions.
A proper risk analysis isn’t a one-time checklist. It looks at where patient data lives, how it moves, who can access it, and what could go wrong at each point. It covers physical risks like unlocked server rooms, technical risks like outdated software, and administrative risks like untrained staff. The results drive the rest of the security program.
When OCR investigates a breach, the risk analysis is one of the first documents requested. If it doesn’t exist, or if it clearly wasn’t used to guide actual security decisions, the organization faces penalties for the underlying failure to assess risk on top of penalties for the breach itself.
What the Penalties Look Like
Civil penalties follow a four-tier structure based on the violator’s level of culpability, adjusted annually for inflation:15Regulations.gov. Annual Civil Monetary Penalties Inflation Adjustment
- No knowledge, where the entity didn’t know and couldn’t reasonably have known: $145 to $73,011 per violation, with a calendar-year cap of $2,190,294.
- Reasonable cause, not amounting to willful neglect: $1,461 to $73,011 per violation, same annual cap.
- Willful neglect, corrected within 30 days: $14,602 to $73,011 per violation, same annual cap.
- Willful neglect, not corrected within 30 days: $73,011 to $2,190,294 per violation, with the annual cap also at $2,190,294.
Each improperly accessed record, each missing notification, and each day of noncompliance can count as a separate violation. That’s how enforcement actions routinely reach hundreds of thousands or millions of dollars even inside a single tier.
Criminal penalties fall on individuals rather than organizations and are prosecuted by the Department of Justice. Up to $50,000 and one year for a knowing violation. Up to $100,000 and five years for violations involving false pretenses. Up to $250,000 and ten years when the information is obtained for commercial advantage, personal gain, or malicious purposes.3Office of the Law Revision Counsel. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information Criminal prosecution is less common than civil enforcement, but it does happen, particularly when employees access records to stalk, harass, or commit identity theft.