A $4.75 Million Penalty — And the Office That Signed It
In 2022, a single medical center in New York received a $4.75 million penalty from an office most of its staff had never heard of. The organization — Memorial Hermann Health System — had disclosed a patient's PHI in a press release. The penalty didn't come from a court. It didn't come from a police department. It came from a small division inside the U.S. Department of Health and Human Services that most healthcare workers would struggle to name.
That division is the Office for Civil Rights, and it's the primary agency HIPAA is enforced by. But OCR isn't the only player. If you work in healthcare — or handle protected health information in any capacity — you need to know exactly who has the authority to investigate you, fine you, and even refer your case for criminal prosecution.
I've spent years watching organizations get blindsided not by the rules themselves, but by the enforcement structure behind them. Let's break down who enforces HIPAA, how the system actually works, and where your organization is most exposed.
HIPAA Is Enforced By OCR — Here's What That Means for You
The Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services (HHS) is the primary federal agency responsible for HIPAA enforcement. OCR investigates complaints, conducts compliance reviews, and negotiates settlements with covered entities and business associates who violate the HIPAA Privacy, Security, and Breach Notification Rules.
When someone files a complaint on the HHS complaint portal, it lands on OCR's desk. From there, investigators determine whether a violation occurred, whether the entity took corrective action, and whether penalties are warranted.
In my experience, most small practices assume OCR only goes after hospitals. That's dangerously wrong. OCR has settled cases with solo dental practices, individual therapists, and small business associates. Size doesn't protect you.
OCR's Enforcement Tools
OCR has a tiered penalty structure that ranges from $137 per violation for unknowing infractions up to approximately $2.13 million per violation category per year for willful neglect that goes uncorrected. These numbers are adjusted annually for inflation.
Beyond financial penalties, OCR can impose corrective action plans that last two to three years. These plans require ongoing monitoring, staff retraining, policy overhauls, and regular reporting back to HHS. I've seen corrective action plans consume more organizational resources than the fine itself.
You can review real enforcement actions and resolution agreements on the OCR Resolution Agreements page.
The DOJ Steps In When It Turns Criminal
OCR handles civil enforcement. But when a HIPAA violation crosses into criminal territory — think intentional theft of patient data, selling PHI, or obtaining records under false pretenses — the Department of Justice (DOJ) takes over.
Under 42 U.S.C. § 1320d-6, criminal penalties for HIPAA violations can reach $250,000 in fines and up to 10 years in prison. The DOJ has prosecuted individuals — not just organizations — for knowingly accessing and disclosing PHI without authorization.
Here's the detail most people miss: criminal HIPAA charges can apply to any person, not just doctors or administrators. I've seen cases involving front-desk staff, medical records technicians, and even a hospital volunteer. If your workforce doesn't understand these stakes, your HIPAA Introduction Training for 2026 needs to address it head-on.
State Attorneys General: The Enforcement Layer Most People Forget
The HITECH Act of 2009 gave state attorneys general the power to bring civil actions on behalf of state residents for HIPAA violations. This was a game-changer, and most compliance officers still underestimate it.
State AGs can seek damages of up to $25,000 per violation category per year, plus injunctive relief. Several states have been aggressive. Indiana's attorney general secured a $1.4 million settlement with a medical records company. New Jersey, Connecticut, and New York have all pursued independent HIPAA-related enforcement actions.
This means your organization can face federal enforcement from OCR, criminal prosecution from the DOJ, and a state-level civil action — all from the same breach. That's three fronts simultaneously.
State Laws That Go Beyond HIPAA
Many states have enacted health privacy laws that are stricter than HIPAA. California's CMIA, Texas's medical privacy statute, and New York's SHIELD Act all impose additional obligations. When state AGs enforce these laws alongside HIPAA, penalties compound fast.
If your organization operates across state lines — especially home health agencies covering multiple service areas — you face an overlapping patchwork of enforcement authority. Our HIPAA Training for Home Health Care Agencies covers exactly these multi-jurisdictional risks.
Who Exactly Can File a HIPAA Complaint?
Anyone. A patient, a family member, an employee, a competitor — literally any person can file a complaint with OCR. There's no filing fee. There's no requirement to hire an attorney. The process starts with a form on the HHS website, and OCR is required to review every submission.
In 2023, OCR received over 33,000 complaints. Not all result in investigations, but a significant number trigger at least a preliminary review. The most common triggers I see are disgruntled employees, patients who overhear conversations about their records, and breach notification letters that prompt recipients to take action.
This is why workforce training isn't optional — it's your first line of defense against the complaint that starts the entire enforcement chain.
CMS and HIPAA: A Limited But Real Role
The Centers for Medicare & Medicaid Services (CMS) doesn't enforce the HIPAA Privacy or Security Rules directly. That's OCR's territory. But CMS enforces the HIPAA administrative simplification provisions — specifically the transaction and code set standards, and the unique identifier requirements.
If your organization submits electronic claims that don't comply with standard transaction formats, CMS can take enforcement action. For most covered entities, this feels like a back-office issue. But I've watched billing teams trigger CMS scrutiny simply by using outdated code sets or non-standard electronic formats.
CMS and OCR communicate. A CMS audit finding can lead to OCR interest, and vice versa. Don't treat these agencies as isolated silos.
What About the FTC?
The Federal Trade Commission doesn't enforce HIPAA directly. But the FTC does enforce its Health Breach Notification Rule, which applies to entities not covered by HIPAA — think health apps, wearable device companies, and non-covered entity vendors. In 2023, the FTC updated this rule and began aggressive enforcement against digital health companies.
If your organization straddles the line between covered entity and technology company, you might face enforcement from both OCR under HIPAA and the FTC under its own authority. The boundaries are blurring, and enforcement agencies know it.
The $1.5 Million Question: What Triggers an OCR Investigation?
Three things reliably trigger OCR enforcement action:
- Breach reports. Any breach affecting 500 or more individuals gets posted on OCR's public breach portal and triggers automatic review.
- Complaints. Individual complaints — especially those showing patterns or systemic failures — move quickly through OCR's pipeline.
- Compliance reviews. OCR can initiate its own investigations without a complaint. These proactive audits have increased in recent years.
The common thread in almost every penalty I've reviewed? The organization lacked a current, documented training program. OCR doesn't accept "we told people about HIPAA during orientation three years ago" as evidence of compliance. You need annual, role-specific workforce training with documented completion records.
How to Protect Your Organization Right Now
Knowing who HIPAA is enforced by is step one. Acting on that knowledge is what separates compliant organizations from cautionary tales. Here's where to start:
- Document everything. Policies, risk assessments, training records, incident response logs. OCR investigators ask for documentation first.
- Train annually. Every member of your workforce — including volunteers, contractors, and business associates — needs current HIPAA training. Explore the full HIPAACertify training catalog for role-specific options.
- Designate a Privacy Officer and Security Officer. HIPAA requires it. OCR checks for it. Many small practices still haven't done it.
- Monitor your business associates. You're responsible for ensuring your BAAs are current and that your partners comply. OCR has penalized covered entities for their vendors' failures.
The Enforcement Net Is Wider Than You Think
HIPAA is enforced by OCR for civil violations, the DOJ for criminal violations, and state attorneys general for state-level actions. CMS handles administrative simplification standards. The FTC patrols the edges where HIPAA doesn't reach.
That's not one enforcer. That's an entire ecosystem of accountability — and every part of it has gotten more active, more resourced, and more aggressive over the past five years.
Your best defense isn't hoping you stay under the radar. It's building a compliance program so thorough that when an investigator comes knocking, you hand them a binder instead of a blank stare.