In 2018, a small five-physician cardiology practice in Arizona received a letter that changed everything. Attached was a $3.5 million settlement demand from a federal agency most of their staff had never heard of. The practice — Banner Health — had suffered a breach affecting nearly 3.7 million individuals, and the federal office that came knocking wasn't the FBI, the FTC, or even CMS. If you've ever asked what office enforces HIPAA, the answer walked right through their door: the Office for Civil Rights.
What Office Enforces HIPAA? It's the OCR Under HHS
The Office for Civil Rights (OCR), a division of the U.S. Department of Health and Human Services (HHS), is the primary federal office that enforces HIPAA. That surprises a lot of people. They assume it's the Department of Justice or some healthcare-specific police force. But OCR handles the vast majority of HIPAA complaint investigations, compliance reviews, and penalty actions.
OCR's enforcement authority covers the HIPAA Privacy Rule, the Security Rule, and the Breach Notification Rule. When a patient files a complaint about a covered entity mishandling their protected health information (PHI), it lands on OCR's desk. When a hospital reports a breach of electronic protected health information (ePHI) affecting 500 or more individuals, OCR opens an investigation.
You can see every resolved enforcement action on the HHS Enforcement Actions page — and there are hundreds.
How OCR Investigates HIPAA Complaints
I've walked organizations through OCR investigations, and the process follows a predictable pattern. Here's how it typically unfolds.
Step 1: The Complaint or Breach Report
Most OCR investigations start one of two ways: a complaint filed by an individual, or a breach report submitted by the covered entity itself. Anyone — patients, employees, even anonymous tipsters — can file a complaint through the HHS HIPAA Complaint Portal. The covered entity has no veto power over this process.
Step 2: Intake and Review
OCR reviews the complaint to determine if it falls within their jurisdiction. They check whether the entity qualifies as a covered entity or business associate, whether the alleged violation involves PHI, and whether the complaint was filed within the 180-day window.
Step 3: Investigation
If OCR accepts the case, they request documentation — your policies, your risk analysis, your workforce training records, your breach response logs. I've seen organizations scramble for weeks to produce documents that should have been a five-minute retrieval. That scramble itself signals a compliance gap.
Step 4: Resolution
OCR can resolve cases through technical assistance, voluntary compliance, a corrective action plan, or a financial settlement. The serious cases — the ones that make headlines — result in resolution agreements with six- and seven-figure penalties.
The $16 Million Wake-Up Call from Anthem
If you want to understand OCR's enforcement muscle, look at the Anthem, Inc. case. In 2018, OCR announced a $16 million settlement — the largest HIPAA penalty in history at that time — after a breach exposed the ePHI of nearly 79 million people. OCR's investigation found that Anthem had failed to conduct an enterprise-wide risk analysis, failed to implement sufficient access controls, and lacked adequate workforce training.
That single case illustrates every enforcement lever OCR pulls: risk analysis failures, insufficient technical safeguards, and gaps in employee training. Your organization may never be Anthem's size, but OCR applies the same rules to a three-person therapy practice as it does to a national insurer.
OCR Isn't the Only Player — But It's the Main One
Here's where it gets slightly more complex. While OCR handles civil enforcement of HIPAA, the Department of Justice (DOJ) can pursue criminal HIPAA violations. If an employee intentionally steals PHI for personal gain or malicious intent, DOJ steps in. Criminal penalties can include fines up to $250,000 and imprisonment up to 10 years.
State attorneys general also have the authority to bring civil actions on behalf of state residents for HIPAA violations, thanks to the HITECH Act. Several states have exercised this power. But day in, day out, OCR is the office that enforces HIPAA for the overwhelming majority of cases.
What OCR Looks for During an Investigation
After advising dozens of organizations through compliance audits and complaint responses, I can tell you the items OCR zeroes in on almost every time:
- Risk Analysis: Have you conducted a thorough, documented risk analysis of all ePHI? Not a checklist — a genuine analysis.
- Workforce Training: Can you prove every member of your workforce completed HIPAA training, and can you produce the records?
- Policies and Procedures: Are they written, current, and accessible? Do they actually reflect what your staff does?
- Access Controls: Who has access to PHI, and why? Is access role-based and reviewed regularly?
- Breach Notification Compliance: Did you notify affected individuals, HHS, and (if applicable) the media within the required timeframes?
If any of those areas have gaps, you're exposed — not hypothetically, but practically. OCR has penalized organizations for each of these failures individually.
The Penalty Tiers Most People Get Wrong
OCR's civil monetary penalties follow a four-tier structure, updated under the HITECH Act. Here's the breakdown:
- Tier 1: The entity didn't know and couldn't have reasonably known — $137 to $68,928 per violation.
- Tier 2: Reasonable cause, not willful neglect — $1,379 to $68,928 per violation.
- Tier 3: Willful neglect, corrected within 30 days — $13,785 to $68,928 per violation.
- Tier 4: Willful neglect, not corrected — $68,928 to $2,067,813 per violation.
The annual cap across all tiers is over $2 million per violation category. And OCR can stack violations. A single breach can involve failures in risk analysis, access controls, training, and breach notification — each counted separately.
How to Stay Off OCR's Radar in 2026
You can't eliminate all risk, but you can make your organization a hard target. Here's what I recommend based on real enforcement patterns:
Invest in Workforce Training That's Current and Documented
OCR looks at training records in nearly every investigation. Outdated training — or no training at all — is one of the fastest ways to escalate a minor complaint into a major settlement. Comprehensive programs like the HIPAA Introduction Training 2026 course give your staff the foundation they need and give you the documentation OCR expects.
Conduct and Document Your Risk Analysis Annually
This is the single most common finding in OCR settlements. If you haven't performed a risk analysis in 2026, stop reading and go schedule one. Then document it thoroughly.
Build a Breach Response Plan Before You Need One
The worst time to figure out breach notification timelines is after a breach. Your plan should name specific responsible individuals, outline notification steps, and reference HHS reporting requirements. Practice it annually.
Review Business Associate Agreements
Your vendors who touch PHI need current, compliant business associate agreements. OCR has pursued covered entities specifically for BAA failures.
What Happens If You Ignore OCR?
OCR isn't an office you can stonewall. Failure to cooperate with an investigation can itself result in penalties. In 2019, OCR settled with Bayfront Health St. Petersburg for $85,000 after the organization failed to provide timely access to medical records — a seemingly small violation that turned into a federal enforcement action.
More recently, OCR has increased its focus on the HIPAA Right of Access Initiative, pursuing entities that deny or delay patient access to their own records. These cases often start with a single patient complaint. One complaint, one investigation, one penalty.
Your Next Step: Build the Foundation
Now you know what office enforces HIPAA — and more importantly, you know what OCR looks for when they come knocking. The organizations that fare best aren't necessarily the largest or the most sophisticated. They're the ones that built compliance into their daily operations: current training, documented risk analyses, enforced policies.
If your team's training records have gaps — or if your last training session predates 2024 — start with the HIPAACertify training catalog to bring your workforce up to current standards. It's the single most impactful step you can take before OCR decides to take a closer look.