A HIPAA unauthorized disclosure happens when a covered entity or business associate shares your protected health information without your written authorization and without qualifying for one of the law’s specific exceptions. If it happened to you, you have 180 days from when you discovered the violation to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights. Federal civil penalties against the organization start at $145 per violation and can reach more than $2.1 million in a calendar year, depending on how negligent the conduct was.
What Counts as an Unauthorized Disclosure
HIPAA generally requires covered entities to obtain your specific written authorization before using or sharing your protected health information. That authorization has to be voluntary and must clearly describe what will be shared, who will receive it, and why.1eCFR. 45 CFR 164.508 – Uses and Disclosures for Which an Authorization Is Required When an organization shares your health data without that authorization and no exception applies, federal law has been broken.
Unauthorized disclosures are not limited to information leaving the organization. An employee who pulls up your chart without a legitimate work reason has committed one too. HIPAA also imposes a “minimum necessary” standard: even where a disclosure is permitted, the covered entity must share only the smallest amount of information needed for the purpose.2eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information Sending your entire file when a single lab result was requested can itself be a violation. The minimum necessary rule doesn’t apply to disclosures for treatment or to disclosures you personally authorize.
Sharing That Doesn’t Need Your Permission
Before you assume a violation occurred, check whether the sharing fits one of HIPAA’s built-in exceptions. The broadest one covers treatment, payment, and healthcare operations. Your doctor can send your records to a specialist for a referral, and your insurer can pull them to process a claim, without asking you again.3eCFR. 45 CFR 164.506 – Uses and Disclosures to Carry Out Treatment, Payment, or Health Care Operations
Additional exceptions apply where health information serves a broader public purpose:
- Public health activities, such as tracking infectious disease outbreaks or reporting adverse drug reactions.
- Reporting suspected abuse, neglect, or domestic violence to authorities.
- Judicial proceedings, when a court order or subpoena compels disclosure.
- Law enforcement requests, including warrants, suspect identification, and reports of certain wounds or injuries.
- Preventing or lessening a serious and imminent threat to health or safety.
- Complying with workers’ compensation laws.
Each of these categories is narrowly defined, and the minimum necessary rule still applies where relevant.4eCFR. 45 CFR 164.512 – Uses and Disclosures for Which an Authorization or Opportunity to Agree or Object Is Not Required If the sharing you’re worried about doesn’t fit into one of these boxes and you never signed off on it, you likely have a complaint worth filing.
Who HIPAA Covers, and Who It Doesn’t
HIPAA reaches two categories of organizations. Covered entities are health plans, healthcare clearinghouses, and healthcare providers that transmit health information electronically. Business associates are companies or individuals that handle protected health information on behalf of a covered entity, such as billing companies, cloud storage providers, or IT consultants.5U.S. Department of Health & Human Services. Covered Entities and Business Associates Both can be held directly liable.
Anyone outside those definitions is not bound by HIPAA, and this is where many complaints fail before they start. Your employer isn’t a covered entity just because it collects health information for sick leave or workers’ compensation. Employment records held by a covered entity acting as an employer are also excluded from the Privacy Rule.6U.S. Department of Health & Human Services. Employers and Health Information in the Workplace Consumer health apps and fitness trackers usually fall outside HIPAA too, unless the app is operated by or for a covered entity. The same heart rate reading can be protected in a hospital and completely unregulated on your smartwatch.
How to File a Complaint With the Office for Civil Rights
If your health information was shared improperly, the primary federal remedy is a written complaint to the HHS Office for Civil Rights. The complaint must identify the entity you believe violated the rules and describe the specific acts or omissions you’re reporting.7eCFR. 45 CFR 160.306 – Complaints to the Secretary
Pull these details together before you start:
- The name of the covered entity or business associate involved.
- When the disclosure happened, or when you learned about it.
- What type of health information was shared and, if you know, who received it.
- A factual description of what happened.
- Any correspondence you’ve already had with the entity’s privacy officer.
You can submit electronically through the OCR Complaint Portal at ocrportal.hhs.gov, or download and mail the Health Information Privacy Complaint Form to the appropriate OCR regional office.8U.S. Department of Health & Human Services. Health Information Privacy Complaint Form
The 180-Day Deadline
File within 180 days of when you knew or should have known the violation occurred.9U.S. Department of Health & Human Services. If I Believe That My Privacy Rights Have Been Violated, When Can I Submit a Complaint OCR can waive that deadline for “good cause,” which HHS has defined to include circumstances that made timely filing impossible.10U.S. Department of Health & Human Services. What OCR Considers During Intake and Review If the deadline is close, file what you have and supplement later.
Retaliation Protections
Federal law prohibits covered entities and business associates from retaliating against anyone who files a complaint, participates in an investigation, or opposes a practice they reasonably believe violates HIPAA. Retaliation includes threats, intimidation, harassment, and discrimination.11eCFR. 45 CFR 160.316 – Refraining From Intimidation or Retaliation An employee who reports a coworker for snooping in records is protected from being fired or disciplined for making that report.
What Happens After You File
OCR first screens the complaint for jurisdiction. If the entity isn’t covered by HIPAA, or the conduct doesn’t fall under the law, OCR will close the matter and notify you.
Complaints that clear screening can be resolved several ways. Many end informally, with the organization agreeing to change its practices. More serious cases lead to a formal resolution agreement, which usually requires a corrective action plan and compliance reports to HHS for about three years, and can include a monetary payment.12U.S. Department of Health & Human Services. Resolution Agreements When OCR can’t reach a satisfactory resolution, it can impose civil money penalties directly.
Penalties the Organization Can Face
Civil penalties are set by HHS and adjusted for inflation each year. They fall into four tiers based on how aware and willful the violation was:13Federal Register. Annual Civil Monetary Penalties Inflation Adjustment
- Tier 1, did not know: $145 to $73,011 per violation, up to $2,190,294 per calendar year.
- Tier 2, reasonable cause: $1,461 to $73,011 per violation, same annual cap.
- Tier 3, willful neglect corrected within 30 days: $14,602 to $73,011 per violation, same annual cap.
- Tier 4, willful neglect not corrected: $73,011 to $2,190,294 per violation, with the annual cap at $2,190,294.
The gap between Tier 3 and Tier 4 is where the real risk sits. An organization that catches a willful violation and fixes it quickly faces roughly $73,000 per violation at the ceiling. One that lets it sit can be hit with more than $2.1 million for the same conduct in a single year.
Criminal prosecution is a separate track, handled by the Department of Justice against individuals who knowingly obtain or disclose protected health information illegally. Knowing violations carry up to $50,000 in fines and a year in prison; disclosures under false pretenses, up to $100,000 and five years; and disclosures for commercial gain or malicious harm, up to $250,000 and ten years. Individual employees can be prosecuted, not just the organization.14GovInfo. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information
You Cannot Sue Under HIPAA Itself
This surprises most people. HIPAA does not create a private right of action. You cannot file a federal lawsuit for a HIPAA violation. Courts have consistently held that enforcement authority belongs to the Secretary of HHS and, for criminal cases, the Department of Justice.15United States Court of Appeals for the Fifth Circuit. Acara v Banks
That doesn’t leave you without legal options. Many states have their own health privacy laws, and some allow individuals to sue for unauthorized disclosure of medical information under state privacy statutes, negligence, or breach-of-contract theories. Where a state law offers stronger protection, the stricter state law controls. HIPAA sets a federal floor, not a ceiling.16U.S. Department of Health & Human Services. Preemption of State Law If you’ve suffered financial harm or serious emotional distress, talking to an attorney about state-law claims is worth doing even though HIPAA itself won’t carry a lawsuit.
Getting an Accounting of Disclosures
If you suspect improper sharing but can’t prove it, you have a right to request an accounting of disclosures from any covered entity. The entity must give you a written list of every disclosure of your protected health information made in the six years before your request.17eCFR. 45 CFR 164.528 – Accounting of Disclosures of Protected Health Information
The accounting won’t include every use of your data. Disclosures for treatment, payment, and healthcare operations are excluded, along with disclosures you personally authorized and those made directly to you. What’s left is the less common sharing: releases to public health agencies, to law enforcement, and any unauthorized disclosures the entity is aware of. Reviewing that list can surface patterns you wouldn’t otherwise see and give you the dates and recipients you need to file a specific, credible complaint.