You can sue someone for looking at your medical records without permission, but almost never under HIPAA itself. Federal courts have held that HIPAA gives enforcement power to the government, not to patients, so a private lawsuit has to rest on state law — usually a tort claim like invasion of privacy or breach of confidentiality — and you generally have to show the snooping caused you real harm.1Justia. Acara v. Banks
Why HIPAA Isn’t the Lawsuit
HIPAA sets national standards for how health plans, certain providers, and their business partners must protect health information, and it gives the Office for Civil Rights authority to investigate complaints and impose civil penalties.2HHS. HIPAA for Professionals3HHS. How OCR Enforces the HIPAA Privacy and Security Rules What HIPAA does not do is let you, the patient, walk into court and sue under the statute. That distinction has sunk cases that were otherwise sympathetic, so if you want money from the person or organization that accessed your file, HIPAA is a reporting channel, not a cause of action.
You can still file a complaint with OCR. That triggers a federal investigation and may result in corrective action or penalties against the organization. It runs on its own track, separate from any lawsuit you bring.
What You Actually Sue Under
Private lawsuits over medical record snooping are built on state law. The common theories are invasion of privacy and breach of confidentiality, and some states have their own medical confidentiality statutes on top of the common-law torts. Which theories are available, and how they’re defined, depends entirely on the state where the breach happened.
To win, you generally have to prove two things: someone accessed your records without authorization, and that access caused you actual harm. Harm the courts recognize typically includes:
- Financial loss from identity theft
- Damage to your professional reputation
- Severe emotional distress
There is also a deadline. Every state has a statute of limitations that caps how long you have to file after the breach, and it varies by state and by the type of claim. If you think your records were viewed improperly, treat the clock as already running and talk to a lawyer before deciding whether to sue.
What the Case Law Shows
Two cases illustrate the difference between a lawsuit that survives and one that doesn’t.
In Doe v. Medlantic Health Care Group, Inc., a patient sued after an employee accessed and shared sensitive medical information without permission. The jury found the provider liable for failing to maintain a confidential relationship and awarded damages for the unauthorized disclosure.4Justia. Doe v. Medlantic Health Care Group, Inc. The claim worked because it was pleaded under state confidentiality law.
In Sheldon v. Kettering Health Network, a woman sued after an employee accessed her records without permission. The court dismissed the case, in part because the plaintiff tried to build her claims on HIPAA requirements.5Justia. Sheldon v. Kettering Health Network The lesson is narrow and important: the facts of an unauthorized access case matter less than whether the legal theory is one the courts will actually hear.
What You Can Recover
If you win, damages fall into two buckets. Compensatory damages pay you back for actual losses tied to the breach — the cost of credit monitoring after identity theft, lost wages, therapy bills, and similar out-of-pocket harm.
Punitive damages are separate. They aren’t meant to compensate you; they’re meant to punish the defendant and deter others. Courts typically reserve them for access that was especially reckless or done with intent to cause harm, so they aren’t available in every case.
What the Other Side Will Argue
Expect two defenses. The first is that no real harm occurred. Even if someone looked at your file, the defendant will argue you can’t point to a specific financial or emotional injury, and without that, the case can be dismissed. This is why documenting the effects of the breach matters as much as proving the access itself.
The second is that the access was accidental. A system error or an inadvertent click, the argument goes, isn’t the kind of deliberate intrusion the law is aimed at. This defense lands harder when the organization can show a track record of following security protocols and moving quickly once the problem was found.
Evidence to Lock Down Now
The single most useful piece of evidence in a snooping case is the audit trail. Federal rules require covered healthcare entities to use audit controls that record activity within their electronic health systems, and those logs can show exactly which user opened your file and when.6GovInfo. 45 C.F.R. § 164.312 Patients don’t always have an automatic right to those logs, but they can typically be requested through discovery once a lawsuit is filed. Move quickly so they aren’t overwritten or lost.
Keep everything else too. Save copies of every written complaint you send the provider and any investigation report they send back. These show the provider knew about the incident and document how they responded. In some cases, expert testimony from a cybersecurity professional can explain how the access happened. And keep your own log of the fallout: costs, missed work, emotional effects, anything a jury would need to see to measure damages.
What to Do Right Now
Report the suspected access to the healthcare provider in writing. Include the dates, why you suspect a breach, and any names you have. A written complaint creates a formal record and forces an internal investigation.
File a complaint with the Office for Civil Rights. That handles the federal side and doesn’t require you to decide anything about a lawsuit yet.
Then talk to a lawyer who works in privacy or healthcare law in your state. They can tell you which state-law theories are available where you live, whether your harm is the kind courts will compensate, and how much time you have left on the statute of limitations. They can also send preservation letters to keep the audit logs and other evidence from disappearing while you decide what to do.