HIPAA Violation Lawsuit Examples: Settlements and Prosecutions

Examples of HIPAA violation lawsuits fall into four buckets: federal resolution agreements between the Office for Civil Rights and a covered entity or vendor, civil actions by state attorneys general, criminal prosecutions by the Department of Justice against individuals, and private class actions brought under state law after data breaches. HIPAA itself contains no private right of action, so patients cannot sue under the statute directly; they sue on negligence, contract, or privacy theories and use HIPAA as evidence of the standard of care. Penalties in the cases below run from a few thousand dollars for a small vendor to $49.5 million for a multistate settlement, and jail time for individuals who stole records.

Who Brings HIPAA Cases

Three sets of enforcers matter. The Office for Civil Rights within the U.S. Department of Health and Human Services investigates complaints and breach reports, resolves most matters through resolution agreements with a monetary payment and a multi-year corrective action plan, and can impose civil monetary penalties if an entity refuses to cooperate. When theft or intentional misuse is involved, OCR can refer the case to the Department of Justice for criminal prosecution.1HHS.gov. How OCR Enforces the HIPAA Privacy and Security Rules Since the HITECH Act of 2009, state attorneys general have had authority to bring their own civil actions, and they often pool resources across dozens of states.2HIPAA Journal. HIPAA Enforcement by State Attorneys General

Criminal penalties run up to one year in prison for knowingly obtaining health information and up to ten years for offenses committed for personal gain or malicious harm.3American Medical Association. HIPAA Violations Enforcement

The Largest Federal Settlements

Anthem: $16 Million (2018)

The biggest OCR settlement on record grew out of cyberattacks disclosed by health insurer Anthem, Inc. in February 2015. Electronic protected health information for nearly 79 million people was exposed. In October 2018, Anthem agreed to pay $16 million and to implement multi-factor authentication, network segmentation, encryption, and three years of third-party security audits.4HHS.gov. Anthem Inc Resolution Agreement Anthem paid another $48.2 million to resolve state attorney general investigations and $115 million to settle a consolidated class action.5HIPAA Journal. Anthem Inc Settles State Attorneys General Data Breach Investigations

Premera Blue Cross: $6.85 Million (2020)

A data breach at Premera Blue Cross exposed the electronic health information of more than 10.4 million individuals. OCR found that Premera had failed to conduct a comprehensive risk analysis, failed to reduce known vulnerabilities, and lacked adequate system monitoring before the breach. The September 2020 settlement of $6.85 million was the second-largest HIPAA penalty at the time.6HHS.gov. Premera Blue Cross Resolution Agreement Premera separately paid a 30-state attorney general coalition $10 million.2HIPAA Journal. HIPAA Enforcement by State Attorneys General

New York-Presbyterian and Columbia University: $4.8 Million (2014)

A misconfigured server made the electronic records of 6,800 patients — patient status, vital signs, medications, and lab results — accessible to internet search engines. New York-Presbyterian Hospital paid $3.3 million and Columbia University paid $1.5 million. OCR found neither institution had conducted a thorough risk analysis or implemented adequate technical safeguards, and both signed three-year corrective action plans.7HHS.gov. New York and Presbyterian Hospital Settlement

Recent OCR Cases

OCR has stepped up enforcement in the last two years around one specific failure: the enterprise-wide risk analysis required by the Security Rule. Every one of the ten resolution agreements OCR signed in the first five months of 2025 involved that deficiency.8HHS.gov. HIPAA Enforcement Resolution Agreements Recent examples:

  • Solara Medical Supplies paid $3 million in January 2025 after a phishing incident led to the impermissible disclosure of over 114,000 patients’ records.9HIPAA Journal. HIPAA Violation Cases
  • Warby Parker was hit with a $1.5 million civil monetary penalty in February 2025 following an investigation into multiple credential-stuffing cyberattacks.8HHS.gov. HIPAA Enforcement Resolution Agreements
  • PIH Health Care Network settled for $600,000 in April 2025 over a phishing attack that exposed records of nearly 200,000 individuals.8HHS.gov. HIPAA Enforcement Resolution Agreements
  • MMG Fusion, a dental-software business associate, settled for $10,000 in March 2026 over a 2020 breach affecting roughly 15 million individuals. OCR cited the company’s limited financial resources in accepting the reduced payment.10HHS.gov. OCR MMG Fusion HIPAA Agreement

Business Associate Cases

Vendors, billing companies, and IT providers that handle health data on behalf of hospitals and health plans became directly liable under HIPAA when the HITECH Act took effect, and OCR has used that authority in cases like these:

  • MedEvolve, Inc., a healthcare software company, paid $350,000 in 2023 after leaving a server with patient names, billing addresses, and phone numbers openly accessible on the internet, exposing data of more than 200,000 people. OCR also found MedEvolve had not entered into a required business associate agreement with a subcontractor.11Dorsey Health Law. HHS OCR Settles HIPAA Investigation With Business Associate for $350,000
  • Health Fitness Corporation, a wellness-plan provider, paid $227,816 in 2025 after a misconfigured server incident and a failure to complete a HIPAA-compliant risk analysis until 2024.9HIPAA Journal. HIPAA Violation Cases
  • Comstar LLC, a billing and collections vendor for ambulance services, paid OCR $75,000 in 2025 after a 2022 ransomware attack affected over 585,000 individuals. The Massachusetts attorney general separately fined Comstar $515,000 for the same breach.9HIPAA Journal. HIPAA Violation Cases

State Attorney General Actions

The first state AG action under HIPAA came in 2010, when Connecticut secured a $250,000 settlement from Health Net, Inc. over a lost unencrypted hard drive containing records of 1.5 million people.2HIPAA Journal. HIPAA Enforcement by State Attorneys General Multistate coalitions have since produced far larger numbers.

Blackbaud: $49.5 Million (2023)

A 49-state coalition led by attorneys general from North Carolina, Alabama, Arizona, Florida, Illinois, and New York settled with Blackbaud, a cloud software company serving nonprofits, for $49.5 million. A 2020 ransomware attack compromised data held by more than 13,000 of Blackbaud’s nonprofit customers, exposing Social Security numbers, financial records, donation histories, and protected health information belonging to millions of individuals. The states alleged Blackbaud had failed to fix known security gaps, then downplayed the breach and led its customers to believe no notification was required.12New York Attorney General. Attorney General James and Multistate Coalition Secure $49.5 Million From Cloud Company Blackbaud Blackbaud also agreed to seven years of third-party compliance assessments.13North Carolina DOJ. Attorney General Josh Stein Announces $49.5 Million Multistate Settlement With Blackbaud

Allure Esthetic: $5 Million (2024)

The Washington attorney general obtained a consent decree against plastic surgeon Dr. Javad Sajan and his practice, Allure Esthetic. The state alleged Sajan forced patients to sign nondisclosure agreements that barred negative reviews, fabricated positive reviews, rigged “best doctor” contests, and manipulated before-and-after photos. The HIPAA piece of the case: the state said the NDAs forced patients to waive privacy rights so the clinic could share health information in response to negative reviews. About 21,000 patients were affected.14Washington Attorney General. AG Ferguson: Plastic Surgeon Must Pay $5 Million for Illegally Manipulating Consumer Reviews15Seattle Times. Seattle Plastic Surgeon Must Pay $5M After Allegedly Faking Reviews

Other Notable AG Settlements

Criminal Prosecutions

Criminal HIPAA cases usually target individual employees who stole or snooped on records for money, curiosity, or spite.

UCLA Medical Center Celebrity Records

Lawanda Jackson, an administrative specialist who had worked at UCLA Medical Center for 32 years, pleaded guilty in December 2008 to a felony charge of obtaining protected health information for commercial purposes. Using her supervisor’s password, Jackson accessed the medical records of celebrities including Britney Spears and Farrah Fawcett and sold the information to the National Enquirer, taking at least $4,600 in payments deposited into her husband’s bank account. She faced up to 10 years in prison and a $250,000 fine, though her plea agreement was expected to result in probation. Jackson died of cancer in March 2009 before sentencing, and the indictment was dismissed.17Los Angeles Times. Former UCLA Hospital Worker Admits Selling Records18U.S. Department of Justice. Former UCLA Medical Center Employee Indicted for Illegally Obtaining Patient Health Information A broader investigation found more than 1,000 patients had had their records improperly accessed at UCLA facilities since 2003, and 165 employees were disciplined.19EMS1. Former UCLA Hospital Worker Admits Selling Records

Methodist Hospital Employees Selling Accident Leads

Five former employees of Methodist Le Bonheur Healthcare in Memphis pleaded guilty to stealing patient information and selling it. Between 2017 and 2020, they accessed records of about 90 car-accident victims and sold the names and phone numbers to Roderick Harvey, who resold the leads to personal injury attorneys and chiropractors for between $200 and $1,000 per batch. Each employee faced up to a year in prison and a $50,000 fine; Harvey, who pleaded guilty to conspiracy, faced up to five years and a $250,000 fine.20Fierce Healthcare. Former Hospital Employees Plea Guilty to Conspiracy to Sell Car Crash Patients Info

Iowa Doctor Sentenced for Snooping

In January 2025, Dr. Gabriel Alejandro Hernandez-Roman was sentenced to one month in jail, a $1,000 fine, and three years of supervised release after pleading guilty to obtaining health information under false pretenses. While working as a resident doctor in Cedar Rapids and Iowa City between 2020 and 2022, he accessed medical records of multiple women who were not his patients and photographed a patient in a hospital setting, sending the image via Snapchat.21U.S. Department of Justice. Doctor Jailed for HIPAA Violations

Class Actions and State-Law Lawsuits

Because HIPAA has no private right of action, patients cannot sue under it, and courts have consistently rejected attempts to do so. They can sue on state-law theories such as negligence, breach of implied contract, and invasion of privacy, and use HIPAA as evidence of the level of care a provider owed.22HIPAA Journal. Can You Sue for a HIPAA Violation

The most prominent example is the Anthem class action. A consolidated lawsuit in federal court in California, overseen by Judge Lucy H. Koh, produced a $115 million settlement that received final approval on August 16, 2018. The class included 19.1 million members whose personal information was stored in the specific data center that was attacked. Class members received two years of credit monitoring or a cash alternative of up to $50, and a separate $15 million fund reimbursed out-of-pocket expenses up to $10,000 per person. Anthem agreed to add data-at-rest encryption and other security upgrades.23HIPAA Journal. Court Approves Anthem $115 Million Data Breach Settlement24Cohen Milstein. Anthem Data Breach Litigation

Smaller class actions arrive steadily. In 2026, courts granted preliminary approval to a $525,000 fund for patients of Blackstone Valley Community Health Care in Rhode Island after a 2023 incident, and a $150,000 fund for patients of Dove Healthcare in Wisconsin after a 2024 cyberattack.25HIPAA Journal. Settlements Agreed to Resolve Two Class Action Healthcare Data Breach Lawsuits These suits are typically settled without an admission of liability and are not, strictly speaking, HIPAA lawsuits, since the claims run through state law.

HIPAA as the Standard of Care

Two cases show how HIPAA gets into state courtrooms even without a private right of action. In Byrne v. Avery Center for Obstetrics and Gynecology (2014), the Connecticut Supreme Court held that a plaintiff could cite HIPAA regulations to establish the standard of care in a negligence claim, and that HIPAA did not preempt state negligence actions involving breaches of protected health information.22HIPAA Journal. Can You Sue for a HIPAA Violation

In Walgreen Co. v. Hinchy, a Walgreens pharmacist in Indianapolis accessed the prescription records of a woman who had previously dated the pharmacist’s husband and shared the information with him; he told others and threatened to use the medical details in a paternity case. A jury awarded $1.8 million, reduced to about $1.44 million after fault was apportioned. The Indiana Court of Appeals upheld the verdict in 2014, finding Walgreens liable under respondeat superior. The court relied on Indiana administrative rules requiring pharmacists to hold prescription information in strict confidence.26HIPAA Journal. Indiana Court Upholds $1.44M HIPAA Privacy Breach Award

Everyday Violations OCR Resolves Quietly

Not every HIPAA case makes headlines. OCR publishes summaries of investigations resolved through voluntary corrective action rather than large fines, and these describe the routine scenarios that draw enforcement:27HHS.gov. All Cases – Enforcement Highlights

  • A nurse practitioner at a multi-hospital system accessed the medical records of her ex-husband. The employer terminated her system access, reported her to the licensing authority, and provided remedial training.
  • A hospital released a patient’s skull x-ray and medical condition to local media without authorization and was required to develop new disclosure policies and retrain staff.
  • A pharmacy chain left pseudoephedrine logbooks with patient information visible at the counter and was required to implement national policies to safeguard the logs.
  • A private practice refused to release medical records because of an outstanding balance. The practice had to provide the records; the Privacy Rule requires access regardless of whether a bill has been paid.
  • A practice charged $100 as a “records review fee” and was ordered to refund it, because the Privacy Rule allows only reasonable cost-based fees for copying and postage.