Yes, violating HIPAA is a crime when someone knowingly obtains or discloses protected health information without authorization. Most HIPAA violations are civil matters resolved with fines and corrective action plans. Criminal prosecution is reserved for intentional conduct, and the penalties climb from one year in prison and a $50,000 fine at the low end to ten years and $250,000 when the motive is personal profit or harm.
What Turns a HIPAA Violation Into a Crime
The pivot word in the statute is “knowingly.” A misdirected fax, a laptop left at a coffee shop, an employee who accidentally opens the wrong chart — none of these are crimes. HHS handles them through civil penalties and corrective action plans. A violation becomes potentially criminal when the person was aware of what they were doing: they knew they were obtaining or sharing someone’s health information and did it anyway.
The Department of Justice has read “knowingly” to mean awareness of the conduct itself, not awareness that the conduct violates HIPAA. A hospital employee who deliberately pulls up a neighbor’s records cannot defend themselves by saying they didn’t realize it was illegal.1Department of Justice. Scope Of Criminal Enforcement Under 42 U.S.C. 1320d-6
The Three Penalty Tiers
Federal law sets three penalty tiers for criminal HIPAA violations, and the tier depends entirely on motive.2Office of the Law Revision Counsel. 42 USC 1320d-6 Wrongful Disclosure of Individually Identifiable Health Information
- Knowing violation. A person who knowingly obtains or discloses protected health information without authorization faces up to $50,000 in fines and up to one year in prison. This is baseline intentional misconduct with no aggravating factors.
- False pretenses. When someone uses deception to get the information — impersonating another employee, forging credentials, or fabricating a reason for access — the ceiling rises to $100,000 and five years in prison.
- Commercial or malicious intent. The harshest penalties apply when someone obtains or discloses health information intending to sell it, use it for personal financial gain, or inflict harm. Selling patient lists to personal injury lawyers or using medical records for identity theft falls here, with penalties reaching $250,000 and ten years in prison.
These figures are maximums. A judge decides the actual sentence based on federal sentencing guidelines, the number of victims, the defendant’s cooperation, and other case-specific factors. Courts can also order restitution to compensate victims for financial losses.
Who Can Be Charged
The statute applies to any “person,” and the DOJ has confirmed that includes directors, officers, and rank-and-file employees of covered entities. Most criminal HIPAA prosecutions target individual employees rather than the organizations they work for.1Department of Justice. Scope Of Criminal Enforcement Under 42 U.S.C. 1320d-6
The HITECH Act of 2009 extended the reach further. Business associates — billing services, IT vendors, claims processors, and other contractors that handle health information on behalf of covered entities — are now subject to the same criminal penalties as the covered entities themselves.3Office of the Law Revision Counsel. 42 U.S. Code 17934 – Application of Privacy Provisions and Penalties to Business Associates of Covered Entities
A 2023 case out of Memphis shows how the tiers play out in practice. The DOJ charged six people connected to Methodist Hospital. Five former employees had accessed patient records for accident victims and passed names and phone numbers to a middleman, Roderick Harvey, who sold the information to personal injury attorneys and chiropractors. The employees each faced the Tier 1 maximum of one year in prison and a $50,000 fine. Harvey, who orchestrated and profited from the scheme, faced up to five years and $250,000 for conspiracy to violate HIPAA.4Department of Justice. Former Methodist Hospital Employees Plead Guilty to HIPAA Violations Prosecutors matched the charge to the motive.
How a HIPAA Case Reaches Criminal Court
Two federal agencies split the work. The Office for Civil Rights at HHS investigates HIPAA complaints and conducts compliance reviews, but OCR handles only the civil side — fines, corrective action plans, settlement agreements. It has no authority to file criminal charges.5HHS.gov. How OCR Enforces the HIPAA Privacy and Security Rules
When an OCR investigation surfaces conduct that looks criminal, OCR may refer the matter to the Department of Justice. The DOJ then runs its own investigation and decides whether to prosecute. A single incident can produce both consequences at once: OCR fining the hospital for its security failures while the DOJ prosecutes the employee who stole the records. The two tracks run in parallel, and penalties from one do not offset the other.
What a Conviction Costs Beyond Prison and Fines
A criminal HIPAA conviction triggers consequences that outlast any sentence. The biggest is exclusion from federal healthcare programs. The HHS Office of Inspector General must exclude anyone convicted of a felony related to healthcare fraud, theft, or other financial misconduct committed in connection with healthcare delivery, and the mandatory minimum exclusion period is five years.6Office of the Law Revision Counsel. 42 U.S. Code 1320a-7 – Exclusion of Certain Individuals and Entities From Participation in Medicare and State Health Care Programs
For misdemeanor HIPAA convictions, OIG has discretion rather than an obligation to exclude, and it regularly uses that discretion for healthcare-related offenses.7U.S. Department of Health and Human Services, Office of Inspector General. Referrals for Exclusion Based on Convictions
Exclusion effectively ends a clinical career. A physician, nurse, or therapist who cannot bill Medicare or Medicaid will struggle to find work in any clinical setting. State licensing boards investigate criminal convictions independently and can suspend or revoke a professional license. And a conviction leaves a permanent criminal record that shows up on background checks for any job involving sensitive data.
Can the Victim Sue?
No, not under HIPAA. Every federal circuit to consider the question has held that HIPAA creates no private right of action. If someone steals your medical records, you cannot file a federal lawsuit under HIPAA to recover damages.
Your options under the statute itself are limited to filing a complaint with OCR, which may investigate and penalize the covered entity. Those penalties go to the government, not to you. If a criminal prosecution follows, the court can order restitution as part of sentencing. Outside HIPAA, state tort claims — breach of confidentiality, negligence, identity theft — may provide a route to compensation depending on the circumstances and the state’s laws.
State Criminal Charges on Top of Federal
Federal charges do not preempt state ones. HIPAA sets a federal floor for privacy protection, and stronger state privacy laws remain in force.8HHS.gov. Does the HIPAA Privacy Rule Preempt State Laws
Someone who steals patient records to sell them could face federal prosecution under 42 U.S.C. § 1320d-6 alongside state charges for identity theft, unauthorized computer access, or violation of a state medical privacy statute. Many states criminalize unauthorized access to personal health data on their own terms, and penalties vary widely. Because federal and state prosecutions are treated as separate sovereign actions, a defendant can be tried and sentenced in both systems for the same underlying conduct.