Last year, a woman in Ohio told me she'd spent three months trying to figure out how to report her dentist's office for posting before-and-after photos of her jaw surgery on Instagram — without her permission. She Googled "how do I file a HIPAA violation" at least a dozen times. Every result gave her a vague answer or buried the actual steps under pages of legal jargon.

She's not alone. The Office for Civil Rights (OCR) at HHS received over 36,000 complaints in a single year. Many more people never file because they don't know how — or they assume nothing will happen. Here's the truth: OCR investigates every complaint that meets its criteria, and some of those investigations have led to multimillion-dollar settlements.

This post gives you the exact process. Whether you're a patient whose records were exposed or a workforce member who witnessed something wrong, I'll walk you through every step.

Who Can File a HIPAA Complaint — And Against Whom?

Anyone can file a complaint. You don't need to be a lawyer. You don't need to be the person whose PHI was compromised, although most complainants are.

You can file against any HIPAA covered entity — hospitals, clinics, health plans, pharmacies, clearinghouses — or their business associates. If a third-party billing company mishandled your protected health information, they're fair game too.

One thing people miss: you can also file if you believe a covered entity denied you access to your own medical records. Under HIPAA's Privacy Rule, you have a right to obtain copies of your PHI. When an organization refuses or drags its feet beyond the 30-day (or 60-day with extension) deadline, that's a reportable violation.

Step 1: Gather Your Evidence Before You File

Before you touch the complaint form, document everything. I've seen OCR dismiss complaints that were legitimate but lacked specifics. Don't let that happen to you.

What to collect

  • Dates: When did the violation occur? When did you discover it?
  • Names: The covered entity's name, address, and the individuals involved if you know them.
  • Description: What happened, in plain language. "The front desk discussed my HIV status in the waiting room on March 12, 2026" is far better than "They violated my privacy."
  • Supporting documents: Screenshots, letters, emails, breach notification letters, denied access requests — anything tangible.

You have 180 days from the date you discovered the violation to file. Miss that window, and OCR will likely reject your complaint unless you can show good cause for the delay.

Step 2: File Your Complaint With the Office for Civil Rights

This is where most people get stuck. It's actually straightforward. You have three options.

Option A: File online through the OCR Complaint Portal

The fastest method. Go to the HHS OCR Complaint Portal and follow the guided prompts. The system walks you through each field. You can upload documents and submit everything digitally.

Option B: File by mail or email

Download the complaint form (OCR Complaint Form Package) from the HHS HIPAA complaint page. Fill it out, sign it, and mail or email it to the OCR regional office that covers the state where the violation happened.

Option C: File by phone

Call OCR's toll line at 1-800-368-1019. A representative can help you file verbally. This works well for people who aren't comfortable with written forms.

Regardless of the method, your complaint must be filed in writing or electronically and include your signature (electronic signatures count on the portal). Anonymous tips don't qualify as formal complaints, but OCR may still look into them.

What Happens After You File a HIPAA Violation Complaint?

This is the part nobody tells you about. Filing the complaint is just the beginning. Here's the actual process OCR follows.

Intake and review

OCR reviews your complaint to determine if it falls under HIPAA jurisdiction. If you filed against your employer (who isn't a covered entity) because a manager told coworkers about your medical leave, OCR will reject it. HIPAA doesn't cover most employers directly — only health plans, providers who transmit claims electronically, and their business associates.

Investigation

If your complaint passes intake, OCR opens an investigation. They contact the covered entity, request documentation, and may conduct on-site reviews. The entity is required to cooperate.

Resolution

OCR resolves cases in several ways: voluntary compliance (the entity fixes the problem), a corrective action plan, or a financial settlement. In serious or repeated cases, OCR imposes civil monetary penalties.

In my experience, most cases end in corrective action. But the settlements that make headlines are staggering. In 2023, OCR settled with Lafourche Medical Group for $480,000 after a phishing attack exposed ePHI — in part because the organization had no security awareness training program. That's a failure I see constantly.

The $4.75 Million Mistake: Why Organizations Should Take Every Complaint Seriously

If you're reading this as a compliance officer rather than a patient, pay attention. Every complaint filed against your organization triggers an OCR review. And OCR doesn't just investigate the narrow issue in the complaint — they look at your entire compliance program.

In one of the largest enforcement actions, Memorial Healthcare System paid $5.5 million in 2017 after OCR found that employees had been improperly accessing patient records for years. The investigation started with complaints. It ended with a massive settlement and a corrective action plan that lasted three years. You can read the details on the HHS enforcement page for Memorial Healthcare System.

The lesson? If your workforce isn't trained on what constitutes unauthorized access, you're exposed. Our course Accessing Records: If It's Not Your Job, It's a Breach addresses exactly this scenario — and it's one of the most common violations I encounter in the field.

Can You File a HIPAA Violation for Social Media Disclosures?

Yes, and these cases are increasing fast. When a healthcare worker posts a patient's image, name, condition, or any identifiable health information on social media, that's a HIPAA violation. It doesn't matter if the post was meant to be "inspiring" or "educational."

I've worked with organizations that were blindsided when an employee's TikTok video — filmed in a patient care area — led to an OCR complaint. The employee didn't think they showed any PHI. The whiteboard behind them told a different story.

If your organization hasn't specifically trained staff on social media risks, you're running on borrowed time. Our Social Media & PHI training covers the exact scenarios that lead to complaints and enforcement actions.

What HIPAA Complaints Can't Do

Filing a HIPAA complaint is not the same as filing a lawsuit. HIPAA does not give individuals a private right of action. You cannot sue someone directly under HIPAA.

What you can do is file with OCR and let the federal enforcement process work. You can also file a complaint with your state attorney general, since many states have their own health privacy laws with additional enforcement mechanisms.

Also, OCR won't award you monetary damages. If you suffered financial harm from a breach, you'd need to pursue that through state courts or join a class action lawsuit — separate from your OCR complaint.

How Long Does an OCR Investigation Take?

Honestly? It varies wildly. Simple cases might resolve in a few months. Complex investigations with large covered entities can take years. OCR has a significant backlog, and staffing levels affect timelines.

Don't let that discourage you from filing. Even if resolution takes time, OCR tracks complaint patterns. Multiple complaints against the same entity accelerate scrutiny. Your complaint might be the one that triggers a deeper investigation into systemic problems.

What Organizations Should Do Right Now

If you're on the compliance side of this equation, don't wait for a complaint to expose your gaps. Here's what I recommend to every covered entity and business associate I work with.

  • Conduct a current risk analysis. Not the one from 2022. A real, updated risk analysis that reflects your current systems and workflows.
  • Train your workforce — all of it. Not just clinicians. Front desk staff, IT, billing, volunteers. Everyone who touches PHI. Browse our full HIPAA training catalog for role-specific courses.
  • Have an incident response plan. When something goes wrong, the first 60 minutes determine whether you contain a problem or create a catastrophe. Our First 60 Minutes: Incident Response course is built for exactly that moment.
  • Document everything. OCR doesn't accept "we told them verbally" as proof of training or policy communication. If it's not documented, it didn't happen.

The Bottom Line on Filing a HIPAA Violation

If you've been asking "how do I file a HIPAA violation," the process is more accessible than most people realize. Gather your evidence, file through the OCR portal or by mail, and let the federal process work. Your complaint matters — it protects not just you, but every patient who walks through that organization's doors after you.

And if you're the organization on the receiving end? Take every complaint as a wake-up call. The organizations that survive OCR scrutiny are the ones that invested in training, documentation, and a culture of compliance long before the complaint arrived.