Last year, a nurse in Texas called me after her employer — a large hospital system — shared her psychiatric treatment records with her supervisor during a performance review. She was furious. Her first question: "Can I sue my employer for HIPAA violation?"

I hear some version of this question at least twice a month. The answer is more nuanced than you'd expect, and getting it wrong can cost you time, money, and leverage. Here's what actually happens when an employer mishandles your protected health information — and what your real options are.

HIPAA Doesn't Give You the Right to Sue — Here's Why

This is the part nobody wants to hear. HIPAA itself does not create a private right of action. That's legal shorthand for: you cannot file a lawsuit directly under HIPAA. The statute is enforced exclusively by the U.S. Department of Health and Human Services (HHS) through its Office for Civil Rights (OCR).

Congress designed HIPAA as a regulatory framework, not a tort statute. When OCR investigates a complaint and finds a violation, the penalties go to the federal government — not to you. The HHS consumer guidance page spells this out plainly.

So if you Google "can I sue my employer for HIPAA violation" and expect a direct lawsuit under 45 CFR, you'll hit a wall. But that doesn't mean you have no recourse. Far from it.

The OCR Complaint: Your Most Powerful Move

What you can do is file a complaint with OCR. And these complaints have real teeth.

OCR has collected over $142 million in HIPAA enforcement actions since the Privacy Rule took effect. They investigate covered entities and their business associates. If your employer is a healthcare provider, health plan, or healthcare clearinghouse — or acts as one — OCR can investigate them.

Here's the process:

  • File your complaint within 180 days of the violation (extensions are sometimes granted).
  • OCR reviews the complaint and may open a formal investigation.
  • Outcomes range from voluntary compliance agreements to civil monetary penalties in the millions.

You can file online through the OCR complaint portal at HHS.gov. It's straightforward, and I've seen complaints from individual employees trigger full-scale investigations.

A Real Example: The $4.3 Million Penalty Against MD Anderson

The University of Texas MD Anderson Cancer Center lost an unencrypted laptop and USB drives containing ePHI of over 33,500 individuals. OCR imposed a $4.3 million civil monetary penalty. No private lawsuit was needed — OCR did the heavy lifting. While this case involved patient data rather than employee data, it shows the scale of enforcement when PHI is mishandled.

Here's where it gets interesting. While you can't sue under HIPAA directly, you can often sue under state privacy laws, common law theories, or employment statutes — and use the HIPAA violation as evidence.

I've seen attorneys build successful cases using these approaches:

State Privacy Statutes

Many states — including California, Texas, Illinois, and New York — have their own health information privacy laws that do allow private lawsuits. California's Confidentiality of Medical Information Act (CMIA), for example, lets individuals sue for damages when medical information is improperly disclosed.

Negligence and Breach of Confidentiality

If your employer owed you a duty of confidentiality and breached it, you may have a common law negligence claim. Courts in multiple states have accepted HIPAA standards as the benchmark for the "standard of care" — meaning a HIPAA violation can prove your employer fell below acceptable standards.

Wrongful Termination and Retaliation

Were you fired after reporting a HIPAA violation internally? Many states have whistleblower protections. Some federal protections may apply too. The HIPAA violation itself becomes the foundation for a retaliation or wrongful termination claim.

Intentional Infliction of Emotional Distress

In egregious cases — like the nurse whose psychiatric records were disclosed to her supervisor — attorneys sometimes pursue emotional distress claims. These require proof that the conduct was outrageous and caused severe distress, but the unauthorized disclosure of sensitive PHI often meets that bar.

Is Your Employer Even a Covered Entity?

This is a critical threshold question that most people skip. HIPAA only applies to covered entities and their business associates. A covered entity is a health plan, healthcare clearinghouse, or healthcare provider that transmits health information electronically.

If you work at an accounting firm and your manager gossips about your medical condition, that's offensive — but it's probably not a HIPAA violation. Your employer would need to be a covered entity, or the PHI would need to have been obtained through the employer's role as a covered entity (like a self-insured health plan).

Here's the distinction that trips everyone up: your employer can be a covered entity in one role (administering its health plan) and not in another (managing HR records). The Privacy Rule only protects PHI held or transmitted by the covered entity in its covered functions.

What Counts as PHI in the Workplace?

Protected health information is individually identifiable health information held or transmitted by a covered entity. In the workplace, this typically includes:

  • Health plan enrollment records and claims data
  • Medical records obtained as part of FMLA or ADA accommodations
  • Drug test results handled by a covered healthcare provider
  • Workers' compensation medical records (in some circumstances)

General knowledge that an employee called in sick? Not PHI. Your supervisor seeing you leave a doctor's office? Not PHI. The line matters, and understanding it determines whether you have a viable claim.

What You Should Do Right Now If Your Employer Violated Your Privacy

If you believe your employer improperly accessed or disclosed your PHI, take these steps immediately:

  • Document everything. Dates, names, what was disclosed, to whom, and how you learned about it. Screenshots if applicable — especially if the disclosure happened on social media or internal platforms.
  • File an OCR complaint. Don't wait. The 180-day clock is real.
  • Consult an attorney. Look for one who specializes in health privacy or employment law in your state. Bring your documentation.
  • Report internally. If your employer has a privacy officer or compliance hotline, use it. This creates a paper trail and may trigger breach notification obligations under the Breach Notification Rule (45 CFR Part 164, Subpart D).

I've written extensively about how the first hour after discovering a breach shapes everything that follows. If you're on the organizational side and need to prepare your team, the First 60 Minutes: Incident Response training walks through exactly what to do step by step.

The Social Media Angle Most People Miss

One pattern I've seen surge in recent years: employees discovering their PHI was shared informally — in a group chat, on a department's social media page, or through a screenshot passed between coworkers. These disclosures are just as actionable as a formal records breach.

If your employer is a covered entity and a workforce member disclosed your PHI on any platform — internal or external — that's a potential HIPAA violation and grounds for an OCR complaint. Organizations should be training every staff member on these risks. Our Social Media & PHI course covers the exact scenarios that lead to complaints and penalties.

The Bottom Line: You Can't Sue Under HIPAA, But You're Not Powerless

Can you sue your employer for a HIPAA violation? Not under HIPAA itself. But you can file an OCR complaint that triggers a federal investigation. You can sue under state privacy laws. You can bring negligence, retaliation, or emotional distress claims where the HIPAA violation serves as your strongest piece of evidence.

The employees who get results are the ones who act fast, document thoroughly, and understand which legal theory actually applies to their situation. Don't assume you have no options just because HIPAA doesn't hand you a lawsuit on a silver platter.

And if you're an employer reading this — your best defense is a workforce that understands what PHI is, how to handle it, and what happens when they don't. Browse the full HIPAA training catalog to find targeted courses for your team before a complaint lands on OCR's desk with your name on it.