A small clinic in Texas thought nobody was watching. They stored patient records on an unencrypted laptop, never trained their staff, and assumed their size made them invisible. Then, in 2019, the Office for Civil Rights came calling. The result: a $1.6 million settlement with the University of Texas MD Anderson Cancer Center for ePHI breaches involving unencrypted devices. If you've ever wondered who oversees HIPAA, that story is your answer — and the consequences are very real.
Understanding which agencies enforce HIPAA isn't just regulatory trivia. It determines who shows up at your door after a breach, who reviews your complaint, and who decides whether your organization pays a five-figure fine or a seven-figure one. I've spent years helping covered entities and business associates prepare for exactly these scenarios. Here's what you need to know.
Who Oversees HIPAA? The Short Answer
The U.S. Department of Health and Human Services (HHS) is the primary federal agency responsible for HIPAA oversight. Within HHS, the Office for Civil Rights (OCR) is the division that handles enforcement of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.
But OCR isn't alone. Depending on the violation, other agencies step in. The picture is more layered than most people realize.
OCR: The Primary HIPAA Enforcer
OCR is the agency you'll deal with most often. They investigate complaints filed by patients and workforce members. They conduct compliance reviews. And they negotiate the settlements that make headlines.
When someone files a complaint on the HHS complaint portal, OCR is the team that opens the case. In my experience, most covered entities don't realize how straightforward the complaint process is for patients. It takes about ten minutes online. That low barrier means OCR receives tens of thousands of complaints every year.
OCR has the authority to impose civil monetary penalties (CMPs) ranging from $137 per violation (for unknowing violations) up to approximately $2.1 million per violation category per year. These penalty tiers were updated under the HITECH Act and are adjusted for inflation annually.
State Attorneys General: The Second Line of Enforcement
Here's what catches many organizations off guard. Since the HITECH Act of 2009, state attorneys general also have the authority to bring civil actions for HIPAA violations on behalf of state residents. This means a single breach can trigger both a federal OCR investigation and a state-level lawsuit — simultaneously.
I've seen organizations focus entirely on federal compliance while ignoring that their state AG has an active health data privacy unit. That's a blind spot you can't afford.
The Department of Justice: Criminal Enforcement
OCR handles civil penalties. The Department of Justice (DOJ) handles criminal HIPAA violations. If a workforce member knowingly obtains or discloses PHI in violation of the law, DOJ can pursue criminal charges that carry fines up to $250,000 and prison sentences up to 10 years.
Criminal referrals are relatively rare, but they happen. They typically involve identity theft, selling patient data, or snooping through records without authorization. Every year, cases make the news — a hospital employee accessing celebrity records, a billing clerk stealing Social Security numbers.
How OCR Investigations Actually Work
I get asked this constantly. Here's the typical sequence.
Step 1: Complaint or breach report. OCR receives a complaint from a patient, a tip from a workforce member, or a breach notification from your organization (required under the Breach Notification Rule for breaches affecting 500 or more individuals).
Step 2: Intake review. OCR determines whether the complaint falls under HIPAA jurisdiction. Not all do. If the entity isn't a covered entity or business associate, OCR closes the case.
Step 3: Investigation. OCR requests documentation — your risk analysis, policies and procedures, training records, business associate agreements. This is where most organizations stumble. They either can't produce what's asked for, or what they produce reveals deeper compliance gaps.
Step 4: Resolution. OCR may resolve the case through technical assistance, a corrective action plan, a resolution agreement with a financial settlement, or a civil monetary penalty. The most serious cases become public enforcement actions posted on the OCR Resolution Agreements page.
What Triggers the Biggest Penalties?
Based on years of reviewing OCR enforcement actions, three patterns dominate the largest settlements:
- Failure to conduct a thorough risk analysis. This shows up in nearly every major settlement. OCR considers it foundational.
- Lack of workforce training. If your staff hasn't been trained on HIPAA policies, OCR treats it as willful neglect — the highest penalty tier.
- Delayed or missing breach notification. The Breach Notification Rule requires notification within 60 days. Missing that deadline compounds the violation.
In 2018, Anthem Inc. agreed to a $16 million settlement with OCR — the largest HIPAA settlement in history at that time — following a breach that affected nearly 79 million people. Among the findings: insufficient risk analysis and failure to implement adequate security controls for ePHI.
The $1.9 Million Lesson Most Small Practices Haven't Learned
Many smaller covered entities assume OCR only goes after hospitals and health plans. That's dangerously wrong.
In 2019, OCR settled with Touchstone Medical Imaging for $3 million over a breach affecting more than 300,000 individuals. The investigation revealed that Touchstone had failed to conduct an accurate risk analysis, lacked a business associate agreement with a vendor, and didn't have breach notification procedures in place.
Size doesn't grant immunity. OCR has pursued solo practitioners, dental offices, and small specialty clinics. If you handle PHI, you're on the radar.
This is exactly why structured workforce training matters. Your staff can't follow rules they don't understand. If you're running a physician's office, our HIPAA training for physicians and clinical environments covers the specific scenarios your team faces daily — from front-desk disclosures to EHR access controls.
Who Oversees HIPAA for Business Associates?
Since the Omnibus Rule of 2013, business associates are directly liable for HIPAA compliance. OCR investigates and penalizes business associates just as it does covered entities.
If you're a billing company, IT vendor, cloud hosting provider, or any organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity, you fall under OCR's jurisdiction. I've worked with business associates who were stunned to learn they needed their own risk analysis, their own policies, and their own training program — independent of whatever the covered entity requires.
What About CMS?
The Centers for Medicare & Medicaid Services (CMS) enforces the HIPAA Administrative Simplification provisions related to electronic transactions and code sets. This is a different slice of HIPAA from what OCR handles. CMS focuses on whether your organization uses the correct electronic transaction standards when submitting claims, eligibility inquiries, and other administrative data.
Most compliance conversations center on privacy and security — OCR's territory. But if your electronic transactions don't meet the standards set in 42 U.S.C. § 1320d-2, CMS has enforcement authority there.
How to Prepare Before an Enforcer Comes Knocking
In my experience, organizations that survive OCR investigations without major penalties share three traits:
They've completed a current, documented risk analysis. Not a checklist from 2019. A thorough, updated assessment that identifies threats to ePHI and documents how they've been addressed.
They train every workforce member — and they can prove it. Training records with dates, names, and topics covered. OCR asks for these almost immediately. If your organization needs a starting point, our HIPAA Introduction Training for 2026 covers the foundational requirements every covered entity and business associate must meet.
They have an incident response plan that's been tested. Not a document gathering dust in a binder. A plan that staff have rehearsed, with clear roles for breach identification, containment, and notification.
Home Health Agencies: A Growing Target
OCR has increasingly focused on home health care organizations. The mobile nature of home health — laptops in cars, paper records in tote bags, verbal discussions in patients' homes — creates unique risks that traditional office-based training doesn't address.
If you operate a home health agency, your training needs to cover scenarios your workforce actually encounters. Our HIPAA training for home health care agencies is built specifically for those environments.
The Bottom Line on HIPAA Oversight
So who oversees HIPAA? HHS through OCR is the primary enforcer for privacy and security. The DOJ handles criminal violations. State attorneys general can bring independent civil actions. CMS enforces transaction standards. Together, they form a multi-layered enforcement structure that leaves very few gaps.
The organizations that get caught aren't usually the ones committing deliberate fraud. They're the ones that assumed compliance was optional, that nobody was watching, or that a breach would never happen to them. Every enforcement action I've reviewed tells the same story: the violation was preventable, and the penalty was avoidable.
Your organization doesn't have to learn that lesson the expensive way.