A $4.3 Million Settlement Started with a Single Complaint
In 2016, the University of Texas MD Anderson Cancer Center lost an unencrypted USB drive containing ePHI for over 33,000 patients. The breach didn't surface through an internal audit. Someone filed a complaint. That single act triggered an OCR investigation that ultimately led to a $4.3 million civil monetary penalty.
If you've ever wondered whether it actually matters when someone decides to report HIPAA violations, that number should settle it. Every year, thousands of complaints land on OCR's desk. Many of them come from patients. But a surprising number come from employees — people who saw something wrong and decided to speak up.
This post walks you through exactly how to report HIPAA violations, who you should report them to, what protections exist for whistleblowers, and what happens after you file. Whether you're a patient whose records were mishandled or a workforce member who witnessed a coworker snooping through charts, here's your complete guide.
Who Can Report HIPAA Violations — And Who Should
Anyone can file a HIPAA complaint with the U.S. Department of Health and Human Services (HHS). You don't need to be a lawyer. You don't need to be a patient. You don't even need to be the person whose PHI was compromised.
In my experience, reports typically come from three groups:
- Patients who discover their protected health information was disclosed without authorization
- Employees who witness a coworker or supervisor violating HIPAA policies
- Business associates or vendors who notice a covered entity cutting corners on safeguards
Here's what I tell every organization I work with: if your staff doesn't know how to report HIPAA violations internally, they'll report them externally. And external complaints invite federal investigators into your operations. Build a culture where internal reporting is simple, protected, and taken seriously.
How to Report HIPAA Violations to OCR: Step by Step
The Office for Civil Rights (OCR) is the federal agency responsible for enforcing HIPAA. Filing a complaint with them is straightforward.
Step 1: Gather the Details
Before you file, document what happened. Include dates, names (if known), the type of PHI involved, and how the violation occurred. Screenshots, emails, or photos of improperly disposed records can strengthen your complaint.
Step 2: File Your Complaint
You have three options:
- Online: Use the OCR Complaint Portal on HHS.gov
- Mail: Download and complete the complaint form, then mail it to your regional OCR office
- Email or fax: Contact your regional OCR office directly
Step 3: Meet the Deadline
You must file within 180 days of when you discovered the violation. OCR can extend this deadline in limited circumstances, but don't count on it. File early.
Step 4: Wait for OCR's Review
OCR will acknowledge your complaint and determine whether it falls under HIPAA jurisdiction. Not every complaint triggers a full investigation, but every complaint is reviewed. OCR resolved over 300,000 cases between 2003 and 2023 — and many of the largest enforcement actions in history started with a single filed complaint.
What Happens After You Report HIPAA Violations
Once OCR accepts your complaint, they typically follow one of these paths:
- Technical assistance: OCR contacts the covered entity, explains the issue, and the entity voluntarily corrects it
- Resolution agreement: The entity agrees to corrective actions and sometimes pays a settlement
- Civil monetary penalty: In serious cases, OCR imposes fines that can reach millions of dollars
Take the Premera Blue Cross case. A breach affecting over 10.4 million people led to a $6.85 million settlement in 2020. OCR's investigation revealed that Premera had failed to conduct an adequate risk analysis — a violation that shows up in nearly every major enforcement action.
The point? When you report HIPAA violations, you're not just filling out a form. You're potentially triggering an investigation that forces systemic change.
Reporting Internally: Your First and Best Option
I've seen too many organizations treat internal reporting as an afterthought. They'll spend months perfecting their Notice of Privacy Practices and completely neglect their internal complaint process.
Every covered entity is required under the HIPAA Privacy Rule to have a process for individuals to file complaints. Your workforce members need to know:
- Who serves as the Privacy Officer
- How to report suspected violations (phone, email, anonymous hotline)
- That retaliation is prohibited under HIPAA
When internal reporting works, it gives your organization the chance to investigate, contain the incident, and take corrective action before OCR gets involved. Our course on First 60 Minutes: Incident Response walks your team through exactly what to do when a potential violation surfaces — because those first decisions determine whether a minor incident becomes a reportable breach.
The Snooping Problem Nobody Wants to Talk About
One of the most common reasons employees report HIPAA violations internally? Unauthorized access to medical records. A coworker looks up an ex-spouse's chart. A front-desk employee peeks at a celebrity patient's records. A nurse checks a neighbor's lab results out of curiosity.
This isn't hypothetical. In 2017, Memorial Healthcare System paid $5.5 million to settle with OCR after employees impermissibly accessed PHI for over 115,000 patients. The access went undetected for years.
If your organization doesn't train staff on what constitutes authorized access versus snooping, you're leaving yourself exposed. Our Accessing Records: If It's Not Your Job, It's a Breach training module addresses this exact scenario in clear, practical terms your entire workforce will understand.
Whistleblower Protections: What HIPAA Actually Guarantees
Can You Be Fired for Reporting a HIPAA Violation?
HIPAA's Privacy Rule includes an explicit anti-retaliation provision. Under 45 CFR § 164.530(g), a covered entity cannot intimidate, threaten, coerce, discriminate against, or take retaliatory action against any individual who files a HIPAA complaint, participates in an investigation, or opposes any act they believe violates HIPAA.
That means your employer cannot fire you, demote you, cut your hours, or reassign you as punishment for filing a complaint. If they do, that retaliation itself becomes a separate HIPAA violation.
In practice, I always recommend that workforce members document everything before and after they report. Save emails. Note conversations. Keep a timeline. Protections exist on paper, but documentation is what makes them enforceable.
State-Level Reporting: A Path Most People Overlook
HIPAA is federal law, but many states have their own health information privacy statutes with separate enforcement mechanisms. Some states — California, Texas, New York — have attorneys general who aggressively pursue healthcare privacy violations.
If OCR doesn't act on your complaint, your state attorney general's office might. In some cases, state penalties are stiffer than federal ones. It's worth checking your state's health privacy laws and filing a parallel complaint when appropriate.
Social Media Violations: The Growing Frontier
Here's a scenario I encounter more and more: a healthcare worker posts a photo from the office. In the background, a patient chart is visible on a screen. Or a staff member vents about a difficult patient on a private Facebook group, including enough details to identify them.
These are reportable HIPAA violations. And they're happening constantly. If you see this kind of activity in your organization, it needs to be reported — internally first, and to OCR if the organization fails to act. Our Social Media & PHI training was built specifically for this problem, because most workforce members genuinely don't realize they've crossed a line until it's too late.
When Reporting Becomes a Legal Obligation
There's a critical distinction between voluntary complaints and mandatory breach notification. If your organization discovers a breach of unsecured PHI affecting 500 or more individuals, you must notify OCR within 60 days. That's not optional — it's required under the Breach Notification Rule.
Smaller breaches (under 500 individuals) must still be logged and reported to OCR annually. Failure to report breaches is itself a violation that can result in penalties.
I've worked with organizations that delayed breach notification because they were "still investigating." OCR doesn't care about your internal timeline. The 60-day clock starts when you discover the breach — not when you finish your investigation.
Make Reporting Easy, or Pay the Price
Every enforcement action I've studied shares a common thread: the organization made it harder to do the right thing than to ignore the problem. Complicated reporting processes. No designated Privacy Officer. Workforce members afraid of retaliation.
If you want to stay ahead of OCR, make it absurdly simple for your staff and patients to report HIPAA violations. Post the process in breakrooms. Include it in onboarding. Train on it annually. And when someone does report, respond quickly and visibly.
Because the alternative — an OCR investigation triggered by an external complaint — is always more expensive, more disruptive, and more damaging than handling it internally. Browse our full HIPAA training catalog to build a workforce that catches problems before they become penalties.