A nurse in Texas pulls up her ex-husband's medical record out of curiosity. A front desk employee at a dermatology clinic posts a photo of the waiting room sign-in sheet to Instagram. A hospital leaves 71 boxes of patient records in an unlocked storage unit after closing a wing. Three different scenarios. Three different organizations. One thing in common: every single one is a HIPAA violation — and every single one triggered an investigation.
If you've ever searched what is a HIPAA violation (or even "HIPPA violation" — the most common misspelling in healthcare compliance), you're asking the right question. But the textbook definition only gets you halfway. What really matters is understanding how violations happen in the real world, what they cost, and how to keep your organization off the Office for Civil Rights' radar.
What Is a HIPAA Violation, Exactly?
A HIPAA violation occurs when a covered entity or business associate fails to comply with any provision of the HIPAA Privacy Rule, Security Rule, or Breach Notification Rule. That's the legal answer. Here's the practical one: it's any action — or failure to act — that exposes, compromises, or mishandles protected health information (PHI).
That includes electronic PHI (ePHI) stored in your EHR, paper records sitting on a printer tray, and verbal disclosures made in a hallway where other patients can hear. The Department of Health and Human Services (HHS) doesn't care which format the PHI was in. If it was mishandled, it counts.
The Two Buckets: Privacy vs. Security
Most violations fall into one of two categories. Privacy Rule violations involve impermissible uses or disclosures of PHI — sharing information with someone who has no right to see it. Security Rule violations involve failures to protect ePHI through administrative, physical, or technical safeguards — like not encrypting a laptop that later gets stolen from a car.
In my experience, the majority of organizations I've worked with understand the Privacy Rule at a surface level. The Security Rule is where things fall apart. Policies exist on paper but not in practice.
The $4.75 Million Mistake That Started With a Lost Laptop
In 2014, New York-Presbyterian Hospital and Columbia University Medical Center paid a combined $4.8 million to settle HIPAA charges after a physician attempted to deactivate a personally owned computer server and accidentally made 6,800 patients' ePHI accessible on internet search engines. OCR's investigation found that neither entity had conducted a thorough risk analysis or implemented appropriate safeguards. You can review the full resolution agreement on the HHS enforcement page.
This wasn't a malicious hack. It was a physician doing routine IT work without proper oversight. That's how most HIPAA violations happen — not through criminal intent, but through gaps in training, process, and accountability.
The 5 Most Common Ways Organizations Violate HIPAA
After fifteen years consulting on HIPAA compliance, I've seen the same patterns repeat. Here are the five triggers that account for the vast majority of violations I encounter.
1. Snooping in Medical Records
Workforce members accessing patient records without a legitimate treatment, payment, or operations reason is the single most predictable violation in healthcare. It happens every week in hospitals across the country. Curiosity about a coworker's diagnosis, a celebrity patient, or a family member's visit — none of it is permissible.
Our course on Accessing Records: If It's Not Your Job, It's a Breach walks through exactly how organizations should detect, prevent, and respond to this kind of insider access violation.
2. Social Media Disclosures
A selfie in the break room with a patient chart visible in the background. A TikTok about a "crazy case" with just enough detail to identify the patient. I've seen staff genuinely shocked when they're told their post violated federal law. They thought they were being vague enough. They weren't.
If your workforce training doesn't specifically address social media scenarios, you have a gap. Our Social Media & PHI training module covers the exact gray areas that trip staff up.
3. Failure to Perform a Risk Analysis
OCR has stated repeatedly that failure to conduct a comprehensive, organization-wide risk analysis is the most common finding in HIPAA investigations. Not having one isn't just a technical oversight — it tells OCR that your entire security program may be built on guesswork. The HHS risk analysis guidance outlines exactly what's expected.
4. Delayed or Missing Breach Notification
Under the Breach Notification Rule, covered entities must notify affected individuals within 60 days of discovering a breach. If the breach affects 500 or more individuals, you must also notify OCR and prominent media outlets in the affected jurisdiction. I've seen organizations discover a breach and freeze — unsure who to call, what to document, or what triggers the clock. That delay alone becomes a separate violation.
This is exactly why having a documented, rehearsed incident response plan matters. Our First 60 Minutes: Incident Response course gives your team a step-by-step playbook for the critical window right after discovery.
5. Lack of Business Associate Agreements
If your organization shares PHI with a vendor — a cloud storage provider, a billing company, an IT consultant — and you don't have a signed Business Associate Agreement (BAA) in place, you're already in violation. OCR doesn't accept "we assumed they were compliant" as a defense.
What Are the Penalties for a HIPAA Violation?
HHS structures civil monetary penalties into four tiers based on the level of culpability. Here's the current penalty structure:
- Tier 1 — Did Not Know: $137 to $68,928 per violation
- Tier 2 — Reasonable Cause: $1,379 to $68,928 per violation
- Tier 3 — Willful Neglect (Corrected): $13,785 to $68,928 per violation
- Tier 4 — Willful Neglect (Not Corrected): $68,928 to $2,067,813 per violation
Annual caps apply per violation category, but a single incident can involve thousands of individual violations. That math adds up fast. And these figures are adjusted annually for inflation — you can verify the latest amounts on the HHS compliance and enforcement page.
Criminal penalties exist too. The Department of Justice can pursue individuals who knowingly obtain or disclose PHI, with penalties up to $250,000 and ten years in prison for offenses committed with intent to sell or use PHI for personal gain.
Can Employees — Not Just Organizations — Be Held Liable?
Yes. While OCR's civil enforcement actions target covered entities and business associates, individual employees can face criminal prosecution under HIPAA. In practice, this most often happens when a workforce member accesses PHI for personal reasons or sells patient data.
Your staff needs to understand this. A HIPAA violation isn't just the organization's problem. It can follow an individual through their career — and into a courtroom.
How OCR Decides to Investigate
OCR opens investigations based on complaints filed by individuals, reports of breaches affecting 500 or more people, and periodic compliance audits. Here's what I tell every client: assume your next breach will trigger a complaint. Because in 2026, patients are more aware of their rights than ever, and filing a complaint with OCR takes about five minutes on the HHS website.
Once OCR investigates, they don't just look at the incident that triggered the complaint. They look at your entire compliance program — your risk analysis, your training records, your policies, your BAAs, your breach logs. One complaint can unravel years of neglect.
What Should You Do Right Now?
If you're reading this because you're worried about your organization's exposure, here's where to start.
Audit Your Risk Analysis
When was the last time you completed a comprehensive, documented risk analysis? If the answer is "I'm not sure" or "two years ago," that's your first priority. It's the foundation OCR looks for in every single investigation.
Train Your Workforce — With Specificity
Generic annual training slides don't cut it anymore. Your people need scenario-based training that reflects how HIPAA violations actually happen — through social media posts, through record snooping, through mishandled incident responses. Browse our full training catalog to find modules built around real-world situations your staff will recognize.
Document Everything
Policies only protect you if they're written down, distributed, acknowledged, and enforced. OCR wants to see evidence — training completion logs, signed acknowledgments, incident response documentation, corrective action plans. If it isn't documented, it didn't happen.
A HIPAA Violation Is Preventable — That's the Point
Every enforcement action I've studied shares a common thread: the violation was preventable. Not with expensive technology. Not with an army of lawyers. With basic, consistent compliance hygiene — risk analysis, workforce training, access controls, and incident response planning.
Understanding what a HIPAA violation is matters. But understanding how they happen in practice — and building systems to stop them before they start — is what separates organizations that thrive from those writing seven-figure settlement checks.
Your patients trust you with their most sensitive information. The question isn't whether a violation could happen at your organization. It's whether you've done enough to make sure it doesn't.