A small dental practice in Georgia thought its biggest regulatory worry was the state dental board. Then a former patient filed a complaint about unauthorized access to her medical records. Within weeks, a federal investigator was requesting documentation the practice couldn't produce. The fine? Over $60,000 — and the practice had never even heard of the agency that issued it.
If you're asking what government agency enforces HIPAA, the answer is the Office for Civil Rights (OCR), a division within the U.S. Department of Health and Human Services (HHS). OCR is the primary federal watchdog responsible for investigating HIPAA complaints, conducting compliance audits, and imposing civil monetary penalties on covered entities and business associates that violate the law.
But OCR isn't alone. Other agencies play supporting roles depending on the violation. Understanding who enforces HIPAA — and how — is essential for every healthcare organization, health plan, and clearinghouse operating in 2026.
OCR: The Primary Agency Behind HIPAA Enforcement
The Office for Civil Rights has been the lead enforcement arm for HIPAA's Privacy, Security, and Breach Notification Rules since 2003. That's when the Privacy Rule first took effect and HHS needed an agency to handle complaints and compliance reviews.
Here's what OCR actually does on a day-to-day basis. It receives complaints from patients and workforce members. It investigates potential violations. It issues corrective action plans and, when necessary, levies penalties that can reach into the millions.
I've seen organizations assume OCR is a paper tiger — a bureaucratic office that sends stern letters and moves on. That assumption has cost some of them everything. OCR has the authority to refer criminal cases to the Department of Justice and to publish enforcement results on its public breach and enforcement portal, which serves as a permanent record of failure.
How OCR Investigates a HIPAA Complaint
Most OCR investigations start with a complaint. Anyone can file one — a patient, an employee, even a competing provider. OCR also initiates investigations based on breach reports submitted through the Breach Notification Rule process.
Step 1: Intake and Review
OCR reviews the complaint to determine whether it falls within HIPAA jurisdiction. Complaints about entities that aren't covered entities or business associates get dismissed. Complaints filed more than 180 days after the incident may also be rejected unless there's good cause for the delay.
Step 2: Investigation
If OCR accepts the complaint, the real work begins. Investigators request documentation: policies, training records, risk assessments, access logs, and business associate agreements. I've worked with clients who scrambled to produce records during this phase — and couldn't. That absence of documentation is itself evidence of noncompliance.
Step 3: Resolution
OCR can resolve a case through voluntary compliance, a corrective action plan, or a formal settlement with financial penalties. In the most egregious situations, OCR imposes civil monetary penalties after a hearing.
Your organization's response speed and documentation quality during an investigation directly affect the outcome. This is where structured HIPAA workforce training pays for itself — not in theory, but in the evidence it creates.
The $4.75 Million Wake-Up Call From a University Health System
In 2020, OCR announced a $4.75 million settlement with the University of Rochester Medical Center (URMC) after investigating the loss of an unencrypted flash drive and a stolen laptop. The underlying problem wasn't the theft — it was that URMC had failed to conduct an enterprise-wide risk analysis, failed to implement encryption, and failed to manage its devices properly despite a previous similar incident.
OCR didn't just fine URMC. It required a corrective action plan that included two years of monitoring. The message was clear: repeat failures escalate penalties dramatically.
I bring up this case because it illustrates something most organizations miss. OCR doesn't just punish the breach. It punishes the systemic failures that allowed the breach to happen. Missing risk assessments, absent training records, and ignored prior warnings are the real triggers for large settlements.
What Other Government Agencies Play a Role?
While OCR handles the heavy lifting, it's not the only government agency involved in HIPAA enforcement.
The Department of Justice (DOJ)
Criminal violations of HIPAA — such as knowingly obtaining or disclosing PHI for personal gain, commercial advantage, or malicious intent — fall under DOJ jurisdiction. OCR refers these cases to DOJ for prosecution. Criminal penalties can include fines up to $250,000 and imprisonment up to 10 years, depending on the severity of the offense.
State Attorneys General
The HITECH Act gave state attorneys general the authority to bring civil actions on behalf of state residents for HIPAA violations. Several states have used this power aggressively. This means your organization can face enforcement from both federal and state authorities for the same incident.
The Federal Trade Commission (FTC)
The FTC doesn't enforce HIPAA directly, but it enforces the Health Breach Notification Rule for entities not covered by HIPAA — such as health apps and personal health record vendors. If your organization straddles the line between covered entity and tech vendor, you could fall under both OCR and FTC scrutiny.
What Is the Main Agency That Enforces HIPAA?
The main government agency that enforces HIPAA is the Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services (HHS). OCR enforces the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. It investigates complaints, conducts compliance reviews, and can impose civil monetary penalties ranging from $141 to over $2 million per violation category per year, with an annual maximum that can exceed $2 million per identical provision. Criminal violations are referred to the Department of Justice.
Penalties OCR Can Impose in 2026
OCR's penalty structure operates on a tiered system, adjusted annually for inflation. Here's the current framework:
- Tier 1 — Lack of Knowledge: The covered entity didn't know about the violation and couldn't have reasonably known. Minimum penalty per violation starts at $141.
- Tier 2 — Reasonable Cause: The violation was due to reasonable cause, not willful neglect. Penalties increase significantly.
- Tier 3 — Willful Neglect, Corrected: The entity acted with willful neglect but corrected the issue within 30 days. Penalties start at approximately $12,000 per violation.
- Tier 4 — Willful Neglect, Not Corrected: The most severe category. Minimum penalties start around $60,000 per violation, with annual caps that can reach over $2 million.
These aren't hypothetical numbers. OCR publishes every resolution agreement on the HHS enforcement page. I recommend bookmarking it and reviewing new cases quarterly.
Why Knowing the Enforcer Changes How You Prepare
Here's what I tell every client: understanding what government agency enforces HIPAA isn't just trivia. It shapes your entire compliance strategy.
When you know OCR investigates based on documentation, you prioritize documentation. When you know OCR looks for completed risk assessments, you complete them. When you know OCR checks training records, you make sure every member of your workforce has completed current, role-appropriate training through a program like the HIPAA training catalog at HIPAACertify.
Compliance isn't about avoiding fines alone. It's about building the evidence trail that proves you took HIPAA seriously before something went wrong.
Three Things OCR Looks for First
In my experience, OCR investigators consistently prioritize three areas early in any investigation:
- A current, comprehensive risk analysis. Not a checklist from five years ago — a living document that reflects your current environment, including ePHI stored in cloud systems, mobile devices, and telehealth platforms.
- Workforce training records. OCR wants to see that every employee, contractor, and volunteer who touches PHI has received HIPAA training and that the training is documented with dates and completion evidence.
- Business associate agreements. Every vendor that accesses, stores, or transmits PHI on your behalf must have a signed, current BAA. Missing agreements are one of the most common findings in OCR investigations.
Don't Wait for a Complaint to Learn This Lesson
Most organizations discover who enforces HIPAA only after they're on the receiving end of an investigation. By then, the gaps in training, documentation, and risk management are already exposed.
The smarter path is straightforward: treat HIPAA compliance as an ongoing operational requirement, not a one-time project. Train your workforce consistently. Document everything. Conduct risk assessments annually — at minimum.
OCR is watching. State attorneys general are watching. And patients are more informed about their rights than ever before. The organizations that survive enforcement scrutiny are the ones that prepared before the complaint arrived.