A Receptionist, a Celebrity, and a $4.3 Million Fine

In 2019, the University of Rochester Medical Center paid $3 million to settle with OCR after employees stored ePHI on unencrypted flash drives. No hack. No sophisticated cyberattack. Just thumb drives without passwords. That's how most violations of HIPAA actually happen — not through dramatic data heists, but through routine carelessness that nobody catches until it's too late.

I've spent years reviewing OCR enforcement actions, and the pattern is stunningly consistent. Organizations don't get fined for bad luck. They get fined for ignoring the basics — skipping risk assessments, forgetting to train staff, or failing to encrypt devices that walk out the door every night.

If you're responsible for compliance at a covered entity or business associate, this post is your field guide. I'll walk through the most common violations of HIPAA, the real enforcement actions behind them, and exactly what you can do to stay off OCR's radar.

What Actually Counts as a HIPAA Violation?

A HIPAA violation occurs when a covered entity or business associate fails to comply with any provision of the HIPAA Privacy Rule, Security Rule, Breach Notification Rule, or Enforcement Rule. The Office for Civil Rights (OCR) at HHS investigates complaints and conducts compliance reviews. You can see the full text of the enforcement process on the HHS enforcement page.

Violations range from unknowing infractions (minimum $137 per violation) to willful neglect left uncorrected (up to $2,067,813 per violation). Those numbers add up fast when you're talking about thousands of affected patients.

The Five Violations I See Over and Over Again

1. No Risk Analysis — The Most Expensive Oversight in Healthcare

If I had to pick the single most common thread across OCR settlements, it's this: the organization never conducted a thorough, documented risk analysis. The Security Rule requires it under 45 CFR § 164.308(a)(1). Yet covered entities routinely skip it or treat it as a one-time checkbox.

Premera Blue Cross learned this the hard way. In 2020, OCR announced a $6.85 million settlement after a breach affecting over 10.4 million people. The investigation found that Premera failed to conduct a risk analysis sufficient to identify threats to ePHI. Details are publicly available on the OCR settlement page for Premera.

2. Lack of Workforce Training

Your staff handles PHI every single day. When they don't understand the rules — what they can share, who they can share it with, how to handle a misdirected fax — you're one mistake away from a reportable breach.

I've investigated incidents where a well-meaning nurse texted a patient's lab results to the wrong phone number. Where a billing clerk emailed a spreadsheet of patient names and Social Security numbers to a personal Gmail account "to work from home." These aren't hypotheticals. They're Tuesday.

The HIPAA Privacy and Security Rules both mandate workforce training. If your onboarding program doesn't include HIPAA-specific education, your organization is already in violation. Our HIPAA Introduction Training 2026 covers exactly what your team needs to know — from PHI handling to breach notification obligations.

3. Impermissible Disclosures of PHI

This category covers everything from snooping in medical records to accidentally mailing a patient's explanation of benefits to the wrong address. OCR has made it clear that even unintentional disclosures can result in enforcement action if the underlying policies and safeguards were inadequate.

Memorial Hermann Health System paid $2.4 million in 2017 after disclosing a patient's PHI in a press release. A press release. The organization named the patient publicly in connection with an arrest, linking the individual to a healthcare facility. That single disclosure triggered a full OCR investigation.

4. Failing to Provide Patient Access to Records

Here's one that surprises people: denying or delaying patient access to their own medical records is a HIPAA violation. OCR launched its HIPAA Right of Access Initiative in 2019, and the settlements have been rolling in ever since.

Penalties in these cases typically range from $15,000 to $240,000 — smaller than mega-breaches but devastating for small practices. A single patient complaint is all it takes. If your organization can't fulfill a records request within 30 days (with one 30-day extension), you're exposed.

5. No Business Associate Agreements

Every vendor that touches PHI on your behalf needs a signed Business Associate Agreement (BAA). Cloud storage providers, billing companies, shredding services, IT consultants — if they can access PHI, they need a BAA. Period.

I still walk into organizations that use consumer-grade file sharing tools without BAAs. They assume the vendor "probably" complies. That assumption has cost organizations millions.

The $1.9 Million Lesson Most Dental Offices Haven't Learned Yet

Small practices often believe OCR only targets large hospital systems. That's dangerously wrong. In recent years, OCR has settled with solo practitioners and small clinics for six-figure amounts.

The penalties aren't always about the size of the breach. They're about the size of the compliance gap. A dental office that never conducted a risk analysis, never trained staff, and never encrypted its laptops is carrying the same regulatory obligations as a major health system — just without the legal department.

If you run a small practice, start with a risk analysis and baseline training. The HIPAACertify training catalog has structured courses designed for organizations of every size.

How OCR Decides Who Gets Investigated

OCR receives tens of thousands of complaints each year. Not all lead to investigations, but here's what I've seen trigger escalation:

  • Breach reports affecting 500+ individuals — these are posted publicly on the HHS Breach Portal and almost always trigger a review.
  • Patient complaints — especially repeated complaints about the same organization.
  • Media coverage — if your breach makes the news, OCR pays attention.
  • Patterns of non-compliance — prior corrective action plans that weren't followed through.

OCR also conducts random audits, though less frequently. The point is: you can't predict when the spotlight will land on you. Your only real strategy is to be ready before it does.

What Are the Penalty Tiers for Violations of HIPAA?

OCR uses a four-tier penalty structure, updated annually for inflation:

  • Tier 1: Lack of knowledge — $137 to $68,928 per violation
  • Tier 2: Reasonable cause — $1,379 to $68,928 per violation
  • Tier 3: Willful neglect, corrected within 30 days — $13,785 to $68,928 per violation
  • Tier 4: Willful neglect, not corrected — $68,928 to $2,067,813 per violation

The annual cap across all tiers for identical violations is $2,067,813. These figures come directly from the Code of Federal Regulations, 45 CFR Part 160, Subpart D. Criminal penalties — including imprisonment — can apply when PHI is obtained or disclosed knowingly or for personal gain.

Three Steps You Can Take This Week

You don't need a six-month project plan to start closing gaps. Here's what I tell every client in our first meeting:

Step 1: Run or Update Your Risk Analysis

If you haven't done one in the past 12 months, you're overdue. Document every system that stores, transmits, or processes ePHI. Identify threats. Assess your current safeguards. Write it down. OCR wants paper trails.

Step 2: Train Every Member of Your Workforce

Not just clinicians — everyone. Front desk staff, IT contractors, volunteers, interns. The Privacy Rule defines "workforce" broadly, and OCR holds you accountable for all of them. Enroll your team in HIPAA Introduction Training 2026 to cover the fundamentals quickly and thoroughly.

Step 3: Audit Your Business Associate Agreements

Pull a list of every vendor with potential access to PHI. Check each one for a current, signed BAA. If any are missing, get them executed immediately. If a vendor refuses to sign, find a new vendor.

The Real Cost Isn't the Fine

I always tell clients: the settlement check is the least painful part. The real damage from violations of HIPAA is the corrective action plan that follows. These plans typically last two to three years and require monitored compliance reviews, mandatory reporting to OCR, and third-party audits at your own expense.

Then there's the reputational hit. Your organization's name goes on the HHS Wall of Shame — the public breach portal — for the world to see. Patients leave. Referral partners get nervous. Recruiting gets harder.

The organizations that avoid all of this aren't the ones with the biggest budgets. They're the ones that treat compliance as an ongoing discipline, not a one-time project. They train consistently. They document relentlessly. And they take violations of HIPAA seriously before OCR forces them to.

That's the difference between a proactive compliance program and a very expensive regret.