HIPAA Violation at Work: Examples, Penalties, and Reporting

A HIPAA violation at work happens when someone at a healthcare provider, health plan, healthcare clearinghouse, or one of their business associates accesses, uses, or shares a patient’s protected health information without authorization. Depending on what happened and why, the consequences run from a written warning up to civil penalties of $2,190,294 per calendar year and criminal sentences of up to 10 years in prison.1Federal Register. Annual Civil Monetary Penalties Inflation Adjustment2Office of the Law Revision Counsel. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information

Who HIPAA Actually Covers at Work

HIPAA’s rules apply to “covered entities” and their “business associates.” Covered entities are healthcare providers who transmit health information electronically (hospitals, clinics, pharmacies, dentists, psychologists), health insurance companies and employer-sponsored health plans, and healthcare clearinghouses. Business associates are outside vendors that handle patient data for a covered entity, such as billing services, IT contractors, cloud storage providers, and medical transcription companies. Business associates are directly liable for HIPAA compliance under a written agreement with the covered entity.3HHS.gov. Covered Entities and Business Associates

If your employer is not on that list, HIPAA does not govern how it handles your own health information. HHS states that “in most cases, the Privacy Rule does not apply to the actions of an employer,” and employment records are not protected by HIPAA even when they contain health details.4HHS.gov. Employers and Health Information in the Workplace A retail manager who tells coworkers about your medical leave has not committed a HIPAA violation. Other laws may protect you in that situation, including the Americans with Disabilities Act, which requires employers to keep employee medical information confidential.5U.S. Equal Employment Opportunity Commission. Enforcement Guidance on Disability-Related Inquiries and Medical Examinations of Employees under the ADA

One more boundary worth knowing: even at a covered entity, employment records held by the organization in its role as an employer are excluded from HIPAA’s definition of protected health information.6eCFR. 45 CFR 160.103 – Definitions A hospital’s own sick-leave files for its staff are not PHI. That same hospital’s patient records are.

Common Examples of HIPAA Violations at Work

Most workplace violations aren’t dramatic. They come from carelessness, curiosity, or systems that give employees more access than they need. These are the patterns OCR sees most often:

  • Snooping in records. Looking up a coworker, family member, neighbor, or celebrity’s medical file with no work-related reason. This is the violation that gets individual employees fired and reported to licensing boards more than almost any other.
  • Talking in public areas. Discussing patient details in a hallway, elevator, or cafeteria where unauthorized people can overhear. Spoken disclosures count.
  • Improper disposal. Throwing unshredded paper records into a regular trash bin, or failing to wipe electronic devices before disposal.
  • Sharing on social media. Posting patient photos or case details, even without using a name, if the person could still be identified.
  • Unsecured devices. Losing a laptop, USB drive, or smartphone that holds unencrypted PHI. Encryption is the single biggest factor in whether a lost device becomes a reportable breach.
  • Leaving systems unlocked. Walking away from a workstation without logging out, or leaving patient records visible on a screen in a shared area.
  • Unnecessary sharing with coworkers. Passing PHI to colleagues who have no role in that patient’s treatment or billing, even when everyone involved works at the same covered entity.

That last item runs into the “minimum necessary” standard, which requires organizations to limit access to only the PHI needed for a specific task. A billing clerk processing an insurance claim needs the diagnosis and procedure codes, not the patient’s full psychiatric history.7HHS.gov. Minimum Necessary Requirement Overly broad access is one of the most common sources of workplace violations, and it usually reflects poorly designed permissions rather than deliberate misconduct.

OCR has investigated over 31,000 cases and imposed civil penalties or settlements in 152 of them, totaling nearly $145 million.8U.S. Department of Health & Human Services. Enforcement Highlights The rest of the cases were not ignored; most closed with corrective action plans that forced organizations to overhaul policies and retrain staff.

What to Do If You Witness a Violation

Start with your organization’s internal channels. Most covered entities have a privacy officer or compliance officer whose job is to receive these reports, investigate, and start corrective action before regulators get involved. Internal reporting also matters because a breach is legally treated as “discovered” the moment anyone in the workforce knows about it or reasonably should have; the clock on the organization’s own notification duties begins there.9eCFR. 45 CFR 164.404 – Notification to Individuals

If internal reporting doesn’t produce an adequate response, file a complaint with the HHS Office for Civil Rights. OCR takes complaints through its online Complaint Portal and also by mail, fax, or email. Include the name of the entity, what happened, and roughly when. You have 180 days from when you learned of the violation to file, though OCR can extend that for good cause.10HHS.gov. How to File a Health Information Privacy or Security Complaint

OCR does not investigate anonymous complaints. You have to include your name and contact information, but you can ask OCR to keep your identity confidential during the investigation.10HHS.gov. How to File a Health Information Privacy or Security Complaint

Retaliation Is Prohibited

The Privacy Rule bars covered entities from intimidating, threatening, coercing, discriminating against, or taking any retaliatory action against a workforce member for filing a HIPAA complaint or participating in an investigation. An organization also cannot use its own privacy policies as cover for punishing someone who reports a genuine violation to an appropriate authority.11eCFR. 45 CFR 164.530 – Administrative Requirements If retaliation happens, HHS instructs you to report it to OCR through the same channels used for the underlying complaint.10HHS.gov. How to File a Health Information Privacy or Security Complaint

Penalties for the Employee Who Violated HIPAA

An employee who violates HIPAA can face discipline from the employer and, in serious cases, prosecution by the federal government.

Employer discipline varies with the conduct. OCR’s published case examples show written warnings and retraining for lesser incidents, letters of reprimand in a personnel file, probationary periods, and termination for more serious behavior. In snooping cases, covered entities have also reported employees to their professional licensing boards.12U.S. Department of Health & Human Services. All Case Examples A nurse or physician reported to a licensing authority can face suspension or revocation on top of losing the job.

Criminal prosecution is reserved for knowing violations. Federal law sets three tiers:2Office of the Law Revision Counsel. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information

  • Knowing violation: up to $50,000 in fines and one year in prison.
  • Under false pretenses: up to $100,000 in fines and five years in prison.
  • Intent to sell, transfer, or use PHI for commercial advantage, personal gain, or malicious harm: up to $250,000 in fines and 10 years in prison.

Criminal referrals go to the Department of Justice. They’re relatively rare, but they happen, and “I didn’t know it was a violation” is not a defense when the government can show the conduct was knowing.

Penalties for the Organization

OCR imposes civil monetary penalties on covered entities and business associates based on four tiers of culpability, adjusted annually for inflation. As of January 2026:1Federal Register. Annual Civil Monetary Penalties Inflation Adjustment

  • Tier 1, did not know: the entity was unaware and could not reasonably have known. $145 to $73,011 per violation.
  • Tier 2, reasonable cause: the violation resulted from reasonable cause rather than willful neglect. $1,461 to $73,011 per violation.
  • Tier 3, willful neglect, corrected: willful neglect corrected within 30 days of discovery. $14,602 to $73,011 per violation.
  • Tier 4, willful neglect, not corrected: willful neglect not corrected within 30 days. $73,011 to $2,190,294 per violation.

The statutory annual cap for identical violations in a calendar year is $2,190,294 across all tiers.1Federal Register. Annual Civil Monetary Penalties Inflation Adjustment Since 2019, HHS has exercised enforcement discretion to apply lower per-tier annual caps in practice: $25,000 for Tier 1, $100,000 for Tier 2, $250,000 for Tier 3, and $1,500,000 for Tier 4. These lower caps remain a matter of discretion rather than binding regulation.13Federal Register. Notification of Enforcement Discretion Regarding HIPAA Civil Money Penalties

“Per violation” can mean per patient record or per day that a systemic failure continues. A single data breach affecting thousands of patients can generate penalties well beyond the per-violation minimums. Beyond the money, organizations often face mandatory corrective action plans requiring policy overhauls, workforce retraining, and years of compliance monitoring.