You generally cannot sue someone for violating HIPAA directly. The statute contains no private right of action, and every federal circuit to consider the question has refused to create one. Your federal option is a complaint to the Department of Health and Human Services, which can investigate and penalize the violator but will not pay you a dime of what it collects. If you want money damages, the realistic path is a lawsuit under your state’s privacy, negligence, or contract laws, where a HIPAA breach often becomes strong evidence even though HIPAA itself is not the cause of action.
Why HIPAA Itself Blocks Your Lawsuit
Congress built HIPAA as a government-enforced framework. Enforcement authority sits with the HHS Office for Civil Rights on the civil side and the Department of Justice on the criminal side. Nothing in the statute lets an individual patient walk into court and sue a provider, insurer, or vendor for a HIPAA violation, and federal courts have consistently refused to read one in.
The practical consequence matters. Even if a hospital employee pulled your chart without authorization and passed it to someone who had no business seeing it, HIPAA gives you no way to recover money for that act. Civil penalties collected by OCR go to the federal government. That is where most patients’ frustration begins, and it is why the real question is almost never “can I sue under HIPAA” but “what else can I sue under.”
Who HIPAA Even Applies To
Before you spend time on either a complaint or a lawsuit that leans on HIPAA, confirm the person or organization is covered. HIPAA reaches three groups:
- Covered entities: healthcare providers, health plans (including Medicare and Medicaid), and healthcare clearinghouses.
- Business associates: third-party vendors that handle protected health information for a covered entity, such as billing companies, IT contractors, cloud storage providers, and shredding services.
- Employees of those organizations, who can face criminal charges for knowingly accessing or disclosing patient data without authorization.
HIPAA does not cover your employer (unless it also runs a health plan or provides care), fitness apps, social media platforms, schools, or friends and family who share your health information. If your disclosure came from somewhere outside those three groups, an OCR complaint will go nowhere and any lawsuit will have to rely entirely on state privacy law.
State Law Claims That Do Let You Sue
State laws in most jurisdictions fill much of the gap HIPAA leaves. The common theories:
- Negligence. You argue the provider had a duty to safeguard your health information, breached that duty, and caused you measurable harm. HIPAA’s standards frequently serve as evidence of what a reasonable provider should have done, even though HIPAA is not the basis of the suit.
- Invasion of privacy. Most states recognize a tort claim when someone publicly discloses private facts about you, and an unauthorized release of medical records fits squarely within it.
- Breach of contract. If you signed a privacy agreement or received a notice of privacy practices that amounted to a promise about how your data would be handled, a violation of that promise can support a contract claim.
Some courts have gone further and allowed plaintiffs to argue that a HIPAA violation is negligence per se, meaning the violation itself establishes that the provider fell below the standard of care. Others have rejected that theory. Availability varies significantly by jurisdiction, and cases are often won or lost at that threshold.
The advantage over an OCR complaint is compensation. A successful lawsuit can produce damages for out-of-pocket costs such as credit monitoring, lost income, and emotional distress. Emotional distress damages are available in many states, but courts generally require you to show the distress was genuine and significant rather than a vague worry about exposure. Attorneys who take these cases typically work on contingency, ranging from 33% to 40% of the recovery, so upfront cost is usually not the barrier.
Class Actions After a Large Breach
When a healthcare organization loses data on thousands or millions of patients, individual suits are impractical and class actions become the vehicle. The critical hurdle is standing: proving every class member suffered a concrete injury, not just that the breach happened. Courts have split. Some accept the cost of monitoring accounts and an increased risk of identity theft; others require evidence of actual fraud before recognizing standing.
Settlements in healthcare data breach class actions have included cash payments, free credit monitoring, and security improvement commitments from the breached entity. If you receive a class notice, you typically need to do nothing to stay in. Opting out is usually only worth considering if your individual damages are unusually large.
Filing a Complaint With the Office for Civil Rights
OCR investigates HIPAA complaints from anyone, at no cost. You will need:
- Your name and contact information. OCR does not investigate anonymous complaints.
- The full name, address, and phone number of the covered entity or business associate you believe violated your rights.
- A description of the incident with specific dates, explaining why you believe it violated HIPAA.
- Supporting documentation: emails, letters, screenshots, medical records, or notes from conversations.
You must file within 180 days of discovering the violation, though OCR can extend that deadline for good cause. Complaints can be submitted through the OCR Complaint Portal, by email to OCRComplaint@hhs.gov, or by mail to the Centralized Case Management Operations at the U.S. Department of Health and Human Services, 200 Independence Avenue S.W., Room 509F, Washington, D.C. 20201.1Department of Health and Human Services (HHS). How to File a Health Information Privacy or Security Complaint
If OCR accepts the complaint, it notifies you and the entity, then investigates. Complex cases can run months or years. When OCR finds a violation, the entity must come into voluntary compliance, adopt required corrective actions, or settle. Uncooperative entities and serious violations can draw civil money penalties, with hearing rights before an HHS administrative law judge.2HHS.gov. What to Expect
Bear in mind again: any penalty collected goes to the government, not to you. The complaint route holds violators accountable and can create leverage, but it does not compensate victims.
How Much Trouble the Violator Can Actually Face
Civil penalties run in four tiers, from unknowing violations to willful neglect left uncorrected. For 2026, per-violation amounts start at $145 at the low end of Tier 1 and reach $2,190,294 at the top of Tier 4, with an annual cap of $2,190,294 for all violations of an identical provision. In a large breach where each affected record can count as a separate violation, totals climb quickly.3Federal Register. Annual Civil Monetary Penalties Inflation Adjustment
Criminal exposure is separate and falls on individuals as well as organizations. Knowingly obtaining or disclosing protected health information carries up to $50,000 and one year in prison; doing so under false pretenses raises it to $100,000 and five years; acting with intent to sell, transfer, or use the information for personal gain or malicious harm reaches $250,000 and ten years. DOJ reads “knowingly” broadly: the person does not need to know the act violates HIPAA, only that they are obtaining or disclosing patient information without authorization.4Office of the Law Revision Counsel. 42 U.S. Code 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information Prosecutions are not common, but they happen; five former Methodist Hospital employees pleaded guilty to selling accident-victim contact information to a middleman working for personal injury attorneys.5United States Department of Justice. Former Methodist Hospital Employees Plead Guilty to HIPAA Violations
Your State Attorney General Is Another Option
The HITECH Act gave state Attorneys General independent authority to bring civil actions on behalf of their residents for HIPAA violations. Unlike OCR penalties, court-ordered damages in an AG action can go to affected individuals, and the AG can also seek injunctions to stop ongoing violations.6HHS.gov. State Attorneys General If a breach affects many people in your state, contacting the AG’s office alongside OCR opens a second avenue. AG offices tend to prioritize large-scale breaches and repeated noncompliance over isolated incidents, but the option exists regardless of size.
Breach Notification Rights That Help Your Case
If a covered entity or business associate discovers your unsecured health information has been breached, HIPAA requires written notice to you within 60 days of discovery. The letter must describe what happened, what types of information were exposed, what you should do to protect yourself, what the entity is doing about it, and how to reach them, including a toll-free number active for at least 90 days.7HHS.gov. Breach Notification Rule
Breaches affecting more than 500 residents of a single state also require notice to prominent media in that area within the same 60 days, and simultaneous reporting to OCR, which lists them on its public breach portal. If you learn about a breach from the news before your letter arrives, the entity is likely still identifying who was affected, but the clock is already running.7HHS.gov. Breach Notification Rule The notification letter is often the single most useful document in a later state-law lawsuit, because it puts the entity’s own account of the breach on the record.
Don’t Overlook the Vendor Behind the Breach
Many HIPAA breaches originate with a third-party vendor rather than the doctor or hospital you dealt with directly. Under rules strengthened by the HITECH Act, business associates are directly liable for their own HIPAA violations. You can name a business associate in an OCR complaint, and OCR can impose the same civil penalties on them as on a covered entity.8HHS.gov. Direct Liability of Business Associates
Business associates also have to notify the covered entity when they discover a breach, and a failure to do that is itself a separate violation. If a billing company or cloud vendor lost your data and the hospital claims ignorance, that does not excuse the vendor. For a state-law lawsuit, both entities are potential defendants, and both may carry insurance that funds a settlement.