A nurse in Texas logs into an EHR system, pulls up her ex-husband's new girlfriend's medical records, screenshots the results, and texts them to a friend. Within three months, she's facing federal criminal charges. Not a fine. Not a slap on the wrist. An indictment.

So is a HIPAA violation a felony? The answer is yes — it absolutely can be. And most healthcare workers I talk to have no idea how fast a moment of curiosity can become a federal case.

When a HIPAA Violation Crosses Into Criminal Territory

Most HIPAA violations land in the civil penalty bucket. OCR investigates, the covered entity gets a corrective action plan or a settlement, and life moves on. But there's a second track that most compliance officers barely discuss with their staff: the criminal track.

Under 42 U.S.C. § 1320d-6, anyone who knowingly obtains or discloses individually identifiable health information in violation of HIPAA faces criminal penalties. The Department of Justice — not OCR, not HHS — handles these prosecutions.

Here's how the tiers break down:

  • Knowingly obtaining or disclosing PHI: Up to 1 year in prison and a $50,000 fine (misdemeanor)
  • Obtaining PHI under false pretenses: Up to 5 years in prison and a $100,000 fine (felony)
  • Obtaining PHI with intent to sell, transfer, or use for commercial advantage, personal gain, or malicious harm: Up to 10 years in prison and a $250,000 fine (felony)

That top tier — 10 years and $250,000 — is unambiguously a felony. And the middle tier is too. The bar for "false pretenses" is lower than most people think.

The $250,000 Question: Who Actually Gets Prosecuted?

I've seen a persistent myth in healthcare: "Only organizations get in trouble for HIPAA." That's dangerously wrong. Criminal HIPAA charges target individuals. The DOJ doesn't indict a hospital system. It indicts the person who accessed, stole, or sold the data.

And they do prosecute. Regularly.

In 2023, a former employee of a New York medical practice pled guilty to conspiracy to disclose PHI after selling patient records that were used for fraudulent billing. The DOJ secured the conviction under the felony tier of HIPAA's criminal provisions.

In another case, a former hospital employee in Arkansas was sentenced after accessing patient records without authorization and sharing them publicly. The charges? Criminal HIPAA violation — felony level.

These aren't hypotheticals. The HHS criminal enforcement page documents referred cases, and DOJ press releases confirm the outcomes.

What "Knowingly" Really Means

One word trips people up: "knowingly." Some employees think they're safe because they didn't mean to violate HIPAA. But courts have interpreted "knowingly" to mean the person knew their actions were unauthorized — not that they knew the specific law they were breaking.

If you accessed records you had no treatment, payment, or operations reason to view, and you knew you weren't supposed to, that's enough. You don't need to have read the Federal Register to be prosecuted.

Is a HIPAA Violation a Felony or a Misdemeanor? It Depends on Intent

Let me make this concrete. The same underlying action — accessing PHI without authorization — can be a misdemeanor or a felony depending entirely on what the person did with the information and why.

Scenario 1 — Misdemeanor: A front-desk employee looks up a neighbor's appointment history out of curiosity. No sharing, no financial motive. This is a "knowing" violation — up to 1 year and $50,000.

Scenario 2 — Felony: A billing clerk accesses patient records and provides them to an identity theft ring. Intent to sell or use for personal gain. This is the top criminal tier — up to 10 years and $250,000.

Scenario 3 — Felony: A medical assistant creates a fake login to access ePHI she's been locked out of. False pretenses. Five years and $100,000.

The dividing line is intent. And prosecutors get to argue what your intent was based on your actions, your texts, your browsing history, and your pattern of access.

Why Most Workforce Training Barely Mentions Criminal Penalties

Here's what frustrates me. I review dozens of HIPAA training programs every year. Most of them spend 45 minutes on the Privacy Rule, 10 minutes on breach notification, and approximately 90 seconds on criminal penalties. They'll show a scary number on a slide and move on.

That's a failure. Your workforce needs to understand — viscerally — that snooping in medical records isn't just a "policy violation" that gets you written up. It's a federal offense that can end with a conviction on their permanent record.

Our course Accessing Records: If It's Not Your Job, It's a Breach was built specifically to close this gap. It walks through real scenarios where curiosity turned into criminal liability. Your staff needs this before they make a mistake they can't undo.

The Role of OCR vs. DOJ: Two Tracks, One Violation

A single HIPAA violation can trigger both civil and criminal consequences simultaneously. Here's how the process typically works:

OCR investigates complaints and breach reports. If they find evidence of criminal conduct, they refer the case to the Department of Justice. The DOJ then decides whether to prosecute under the criminal provisions of HIPAA.

Meanwhile, OCR can still pursue civil penalties against the covered entity. So the organization pays a settlement, implements a corrective action plan — and the individual employee faces a separate criminal proceeding.

This dual-track enforcement is exactly why your incident response plan matters. When a breach occurs, the first 60 minutes determine everything — what gets documented, who gets notified, and whether your organization's response helps or hurts the people involved. Our First 60 Minutes: Incident Response training covers this critical window step by step.

Social Media: The Fastest Path to a Criminal HIPAA Charge

I've tracked a disturbing trend over the past few years. More criminal HIPAA referrals now involve social media than any other disclosure channel. An employee posts a photo from the ER that includes a patient's face. A nurse tweets about a celebrity patient. A medical assistant shares a patient's diagnosis in a private Facebook group.

Every one of those actions can meet the "knowingly discloses" standard. Add a motive — clout, revenge, gossip — and you're in felony territory.

This is why Social Media & PHI is one of the most critical training modules we offer. Your staff carries a broadcasting device in their pocket every shift. They need clear guardrails.

What Happens After a Criminal HIPAA Conviction

The prison time and fines are just the beginning. A criminal HIPAA conviction — whether misdemeanor or felony — creates cascading consequences:

  • Professional license revocation: State licensing boards routinely act on criminal convictions related to patient data.
  • Employment consequences: A felony conviction makes future employment in healthcare nearly impossible.
  • Exclusion from federal programs: Convicted individuals can be excluded from participating in Medicare and Medicaid — effectively ending their healthcare career.
  • Civil lawsuits: Patients whose PHI was compromised can pursue civil claims on top of the criminal case.

I spoke with a compliance officer last year whose former employee received a 2-year sentence. "She thought she was just looking," the officer told me. "She didn't understand that looking was the crime."

How to Protect Your Workforce From Criminal Liability

You can't control every employee's behavior. But you can make the stakes unmistakably clear. Here's what I recommend to every covered entity and business associate I work with:

  • Make criminal penalties a standalone training topic. Don't bury it in a slide deck. Dedicate time to it. Use real cases.
  • Implement access auditing. Audit trail reviews are your best early-warning system. If someone is accessing records outside their job function, you need to know before the DOJ does.
  • Create a zero-tolerance snooping policy. Put it in writing. Make every employee sign it. Enforce it consistently.
  • Train on social media specifically. Generic "don't share PHI" guidance isn't enough. Staff need to understand how a single post creates a prosecutable offense.
  • Build a real incident response plan. When unauthorized access happens, your response either contains the damage or amplifies it.

Browse our full HIPAA training catalog to find role-specific courses that address these exact risks.

The Bottom Line: Yes, HIPAA Violations Can Be Felonies

Is a HIPAA violation a felony? It can be — and the threshold is lower than most healthcare workers realize. Accessing ePHI under false pretenses or with intent to profit triggers felony charges carrying up to 10 years in federal prison.

Your employees need more than a vague warning. They need specific, scenario-based training that makes the criminal stakes real. Because by the time the DOJ gets involved, it's too late for a corrective action plan. It's too late for "I didn't know." And it's far too late for an apology.