A Nurse Called Me From Her Car — Here's What She Asked
Last spring, a home health nurse called me from a parking lot. She'd just watched a coworker photograph a patient's wound care chart and text it to a friend — not a colleague, a friend — as a "can you believe this" moment. The nurse was shaking. Her first question wasn't about policy or law. It was simple: who do I report a HIPAA violation to?
She's not alone. I get some version of that question at least twice a week. Patients who find their records were accessed without authorization. Employees who see PHI tossed in open dumpsters. Family members who overhear a receptionist discussing diagnoses in a crowded lobby.
The answer isn't complicated, but the path has real consequences — for you, for the violator, and for the organization. Here's exactly what you need to know in 2026.
The Short Answer: File a Complaint With the HHS Office for Civil Rights
If you're asking who do I report a HIPAA violation to, the primary answer is the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). OCR is the federal agency responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules.
You can file a complaint directly through the HHS OCR complaint portal. It's the same office that has levied more than $142 million in HIPAA enforcement actions since the program began.
But OCR isn't your only option. Depending on the situation, you may also want to report internally first — or simultaneously.
Your Three Reporting Channels — And When to Use Each
1. Internal Reporting: Your Organization's Privacy Officer
Every covered entity and business associate is required to designate a Privacy Officer under 45 CFR § 164.530. If you're an employee, your first step is often reporting the violation internally. This gives the organization a chance to investigate, mitigate harm, and self-report if a breach has occurred.
I've seen organizations catch and contain incidents within hours when employees spoke up early. I've also seen organizations retaliate against the reporter — which is why the next channel exists.
2. Federal Reporting: HHS Office for Civil Rights
Anyone can file a complaint with OCR — patients, employees, family members, even anonymous tipsters. You don't need to be the person whose PHI was exposed. You have 180 days from the date you knew (or should have known) about the violation to file.
You can submit your complaint online, by mail, or by fax. OCR reviews every complaint. Some trigger full investigations. Others result in technical assistance to the covered entity. A small percentage lead to the settlement agreements that make headlines.
For example, in 2023, OCR settled with Yakima Valley Memorial Hospital for $240,000 after 23 security guards were found to have accessed patient medical records without a job-related purpose. That investigation started with a complaint.
3. State Attorneys General
Under the HITECH Act, state attorneys general also have authority to enforce HIPAA. Several states — including Indiana, New Jersey, and New York — have pursued their own HIPAA-related actions. If you believe a violation affects residents of your state, you can file a complaint with your state attorney general's office.
In my experience, state AG offices are most active when a breach affects a large number of state residents or when the covered entity has a pattern of negligence.
What Information Does OCR Need From You?
Your complaint doesn't need to be a legal brief. But the stronger your details, the more likely OCR will investigate. Here's what to include:
- Your name and contact information (or you can request confidentiality)
- The name and address of the entity you believe violated HIPAA
- A description of the acts or omissions — be specific about what happened, when, and what PHI was involved
- The date the violation occurred or when you became aware of it
- Any documentation you have — screenshots, emails, policies, written communications
OCR will acknowledge receipt and may contact you for additional information. They won't tell you the outcome of the investigation in most cases, but if the case leads to a resolution agreement or civil monetary penalty, those are published on the HHS breach enforcement page.
The Retaliation Question Every Employee Asks
Here's what that nurse in the parking lot really wanted to know: "Will I lose my job?"
HIPAA's Privacy Rule includes an explicit anti-retaliation provision under 45 CFR § 164.530(g). A covered entity cannot intimidate, threaten, coerce, discriminate against, or take retaliatory action against any individual who files a HIPAA complaint, testifies in a HIPAA proceeding, or opposes any act that the individual believes violates HIPAA.
That protection is real on paper. In practice, I've seen it tested. Document everything. Save emails. Keep a personal log of conversations with dates and times. If retaliation occurs, that's a separate violation you can report to OCR.
What Happens After You Report a HIPAA Violation
OCR's process generally follows these steps:
- Intake and review: OCR determines whether the complaint describes a potential HIPAA violation and whether it has jurisdiction.
- Investigation: If accepted, OCR may request documentation from the covered entity, conduct interviews, and review policies.
- Resolution: Most cases end in voluntary corrective action or technical assistance. A smaller number result in resolution agreements with monetary penalties and mandatory corrective action plans.
- Civil monetary penalties: In cases of willful neglect or refusal to cooperate, OCR can impose penalties ranging from $137 to over $2 million per violation category per year (adjusted for inflation).
The entire process can take months or even years. OCR is handling thousands of complaints simultaneously. But the investigation itself often forces meaningful change at the organization — I've watched it happen.
When a Violation Is Also a Crime
Some HIPAA violations cross into criminal territory. If someone knowingly obtains or discloses PHI in violation of the law, the Department of Justice (DOJ) can prosecute under 42 U.S.C. § 1320d-6. Criminal penalties can include fines up to $250,000 and imprisonment up to 10 years for offenses committed with intent to sell PHI or use it for personal gain.
You can't file a criminal complaint directly with DOJ for HIPAA. But OCR can — and does — refer cases to DOJ when criminal conduct is suspected. If you believe the violation involves theft, fraud, or intentional misuse of health information, make that clear in your OCR complaint.
Patients vs. Employees: Different Starting Points, Same Destination
If You're a Patient
You have every right to file directly with OCR. You don't need to report internally first, and the covered entity cannot require you to use their grievance process before going to OCR. That said, contacting the organization's Privacy Officer first sometimes resolves the issue faster — and gives them the chance to trigger their own incident response procedures before OCR gets involved.
If You're an Employee or Workforce Member
Start with your internal compliance team if you trust them. Many organizations have anonymous hotlines or reporting tools. If you don't trust the internal process — or if the Privacy Officer is the problem — go straight to OCR. The anti-retaliation protections apply regardless of which path you choose.
If you work in home health care, the reporting dynamics can be especially tricky. You're often working in a patient's home, far from supervisors and compliance teams. Our HIPAA training for home health care agencies covers exactly these field-based scenarios.
The Social Media Scenario That's Exploding in 2026
One category of violations I'm seeing surge right now: social media. Staff posting photos from clinical settings, sharing patient stories in "anonymous" ways that aren't actually anonymous, or using private social media groups to discuss cases.
If you witness a coworker posting PHI on social media, that's absolutely reportable — internally and to OCR. These cases are straightforward because the evidence is usually a screenshot away. Our Social Media & PHI training walks through the exact boundaries every workforce member needs to understand.
Don't Wait for Certainty — Report What You Know
Here's a mistake I see constantly: people wait to report because they're not sure it's "really" a violation. They second-guess themselves. They assume someone else will handle it.
You don't need to be a HIPAA lawyer to file a complaint. You don't need to prove the violation. You just need to describe what you observed. OCR's job is to investigate. Your job is to speak up.
That nurse in the parking lot? She filed internally and with OCR the same day. The organization investigated, terminated the employee who texted the photo, and implemented new mobile device policies within 30 days. No OCR penalty was imposed because they acted quickly and cooperated fully.
That's how the system is supposed to work. But it only works when someone picks up the phone — or fills out the form.
If your organization hasn't trained its workforce on how to recognize and report violations, now is the time. Browse our full HIPAA training catalog to find the right course for your team.