A woman in California walked into her pharmacy and discovered that an employee had accessed her prescription records — not to fill a prescription, but out of personal curiosity. She filed a complaint. Within months, the Office for Civil Rights (OCR) launched an investigation that ended with a corrective action plan and mandatory workforce retraining. That single complaint changed the way an entire organization handled protected health information (PHI).
If you believe a covered entity has violated your HIPAA rights, you have the legal power to do something about it. Here's exactly how to file a HIPAA complaint — and what to expect after you hit submit.
First, Let's Clear Up the Most Common Misspelling
Before we go further: if you searched "file a HIPPA complaint," you're not alone. Thousands of people misspell it every month. The correct acronym is HIPAA — the Health Insurance Portability and Accountability Act. Two A's, one P. Now that we've got that settled, let's get into the process.
Who Can File a HIPAA Complaint — and Against Whom?
Anyone can file a complaint. You don't need to be a patient. You don't need a lawyer. You can be a family member, an employee, or even a concerned bystander who witnessed a violation.
Your complaint must be directed at a covered entity or a business associate. Covered entities include health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically. Business associates are vendors and contractors who handle PHI on their behalf.
You cannot file a HIPAA complaint against your employer for sharing your general employment health records, or against your neighbor for gossiping about your surgery. HIPAA has a specific scope, and understanding that scope before you file saves everyone time.
The Step-by-Step Process to File a HIPAA Complaint with OCR
Step 1: Confirm It's Actually a HIPAA Violation
Not every privacy annoyance is a HIPAA violation. HIPAA covers specific situations involving PHI handled by covered entities and business associates. Ask yourself: Did a healthcare provider, health plan, or their contractor improperly use or disclose my health information? Did they deny me access to my own records? Did they fail to provide a Notice of Privacy Practices?
If the answer is yes to any of those, you likely have grounds to file a HIPAA complaint.
Step 2: Gather Your Information
Before you contact OCR, collect the basics:
- The name and address of the entity you're filing against
- A description of the acts or omissions you believe violated HIPAA
- The date(s) the violation occurred
- Your name, contact information, and relationship to the situation
You don't need ironclad proof. OCR investigators will handle that part. But the more specific you are, the faster your complaint moves through the system.
Step 3: Submit Your Complaint
You have three options for filing:
- Online: Use the OCR Complaint Portal at ocrportal.hhs.gov. This is the fastest method.
- Mail or Fax: Download the complaint form from the HHS HIPAA complaint page and send it to the regional OCR office that covers your state.
- Email: Send your written complaint directly to OCR via the contact info listed on the HHS website.
One critical deadline: you must file within 180 days of when you knew (or should have known) about the violation. OCR can extend this in certain circumstances, but don't count on it.
Step 4: Wait for OCR's Review
After you file a HIPAA complaint, OCR screens it for jurisdictional validity. If it meets the criteria, they'll open an investigation. If not, they may refer you to another agency or close the complaint with an explanation.
OCR will notify you that your complaint was received and keep you updated on the status. Investigations can take months — sometimes years for complex cases.
What Happens After You File a HIPAA Complaint?
This is where things get real. OCR doesn't just send a sternly worded letter. They have enforcement teeth.
In I've seen outcomes ranging from voluntary compliance and corrective action plans to six- and seven-figure civil monetary penalties. Take the 2023 settlement with Yakima Valley Memorial Hospital: OCR imposed a $240,000 penalty after 23 security guards were found to have snooped on patient medical records without authorization. That investigation began with a breach report — but similar cases start with individual complaints.
OCR's enforcement actions over the past decade have resulted in over $142 million in settlements and civil monetary penalties. Those numbers come directly from HHS's enforcement outcomes page.
Possible outcomes of your complaint include:
- The entity voluntarily changes its practices
- OCR negotiates a Resolution Agreement with corrective action
- OCR imposes civil monetary penalties
- OCR refers the case to the Department of Justice for criminal prosecution
Can You File a HIPAA Complaint Anonymously?
Technically, no. OCR requires your contact information to process the complaint. However, HIPAA's anti-retaliation provisions protect you. A covered entity cannot retaliate against you for filing a complaint. If they do, that's a separate violation — and OCR takes it seriously.
I've worked with healthcare employees who feared losing their jobs for reporting a coworker's PHI snooping. In every case I've seen, the whistleblower protections held. The organizations that retaliated ended up in far worse shape than if they'd simply addressed the original issue.
The Training Gap That Creates Most Complaints
Here's what I see over and over in my consulting work: the violations that trigger complaints are almost always preventable. An untrained front-desk employee discusses a patient's diagnosis in a waiting room. A remote worker leaves ePHI visible on a shared home computer. A nurse texts patient information on a personal phone.
These aren't malicious acts. They're training failures.
HIPAA requires every covered entity to train its workforce on policies and procedures related to PHI. Not once. Not during onboarding and then never again. Ongoing, documented training. If your organization hasn't invested in proper HIPAA education, you're not just risking a complaint — you're practically inviting one.
If you manage a healthcare team, our HIPAA Introduction Training for 2026 covers the fundamentals every workforce member needs. For teams with staff working outside the office, the HIPAA Training for Remote Healthcare Workers addresses the unique risks of handling PHI from home — risks that most general training programs miss entirely.
Remote Work Has Made PHI Complaints More Common
Since the shift to hybrid and remote healthcare operations, I've seen a noticeable uptick in complaints related to unsecured ePHI in home environments. Shared Wi-Fi networks. Family members overhearing telehealth calls. Laptops without encryption sitting on kitchen tables.
OCR hasn't relaxed its enforcement posture just because your staff works from home. If anything, they've sharpened it. The same safeguards required in a clinical setting apply to your remote worker's spare bedroom.
Our Working from Home & PHI course was built specifically for this reality. It walks staff through practical, everyday scenarios they'll actually encounter.
What If You're the Covered Entity Receiving a Complaint?
If OCR contacts your organization about a complaint, don't panic — but don't ignore it either. Respond promptly, cooperate fully, and document everything. The organizations that fare best in OCR investigations are the ones that demonstrate good faith: they have written policies, they can prove training occurred, and they take immediate corrective steps.
The organizations that get hit with the biggest penalties are the ones who had no policies, no training records, and no risk analysis. In other words, the ones who treated HIPAA compliance as optional until it wasn't.
Your Right to File a HIPAA Complaint Is Non-Negotiable
HIPAA exists to protect individuals. The complaint process is the mechanism that gives the law its power. Without people willing to file complaints, OCR would have far less visibility into how covered entities actually handle PHI day-to-day.
If you've witnessed a violation — whether you're a patient, an employee, or a family member — you have every right to file a HIPAA complaint. The process is straightforward, the protections are real, and the outcomes matter.
And if you're running a healthcare organization, the best way to avoid being on the receiving end of a complaint is to build a culture where PHI protection is second nature. That starts with training your people — every single one of them — and documenting that you did it.