Who Enforces HIPAA? OCR, State AGs & CMS Explained
HIPAA Enforcement Overview
HIPAA enforcement is shared among multiple federal and state agencies, creating a complex regulatory landscape. Understanding which agency has jurisdiction is critical when responding to complaints or investigations.
Key Enforcement Agencies
| Agency | Primary Jurisdiction | Complaint Authority |
|---|---|---|
| OCR (Office for Civil Rights) | Covered entities & Business Associates | Investigates HIPAA complaints; issues fines and settlements |
| CMS (Centers for Medicare & Medicaid Services) | Medicare/Medicaid providers | Focuses on provider compliance; can impose penalties |
| State Attorneys General | Any entity in their state | Can enforce HIPAA under state laws; coordinate with federal |
| FBI / Justice Department | Criminal violations only | Prosecutes criminal HIPAA violations (identity theft, fraud) |
The Office for Civil Rights (OCR)
Who They Are
The Office for Civil Rights is a division of the U.S. Department of Health and Human Services (HHS). OCR is the primary HIPAA enforcement agency responsible for investigating complaints and issuing civil penalties.
OCR Authority & Jurisdiction
- Authority over: All HIPAA covered entities and their business associates
- Types of violations: Privacy Rule, Security Rule, Breach Notification Rule
- Complaint source: Patients, competitors, employees, OCR voluntary audits
- Penalties: Civil fines from $100 to $50,000+ per violation
How OCR Investigates
- Complaint Receipt: OCR receives complaint (written, online portal, or mail)
- Initial Review: Determines if complaint is within jurisdiction
- Investigation: Contacts entity, reviews records, may conduct on-site audit
- Resolution: Issues findings, proposes settlement, or closes case
- Enforcement: Negotiates Corrective Action Plan (CAP) or issues civil penalty
- Public Reporting: Publishes settlement details and lessons learned
OCR Investigation Timeline
- Complaint filing to initial contact: 3-6 months
- Investigation period: 6-12 months (can be longer)
- Settlement negotiation: 3-6 months
- Total resolution: 1-2+ years is typical
State Attorneys General (State AGs)
Who They Are
The Attorney General in each state can enforce HIPAA under state law. While OCR has primary federal authority, State AGs have concurrent enforcement power and often investigate large-scale breaches or complaints from state residents.
State AG Authority
- Authority over: Any entity (covered or not) operating in their state
- Types of violations: HIPAA + state privacy/consumer protection laws
- Penalties: Can be higher than OCR penalties in some states
- Civil actions: Can file lawsuits on behalf of consumers
State AG vs. OCR Enforcement
- Coordination: State AGs and OCR often coordinate on large breaches
- Dual enforcement: A single breach may trigger OCR AND State AG investigations
- Combined penalties: An entity could face OCR fines AND State AG penalties
- Settlement: State AGs may negotiate separate settlements from OCR
Notable State AG HIPAA Enforcement Examples
- New York: Aggressive HIPAA enforcement; has settled major cases against healthcare providers
- California: Strong privacy law enforcement under CCPA (privacy act); coordinates with HIPAA
- Massachusetts: 201 CMR 17.00 is stricter than HIPAA; Massachusetts AG enforces both
CMS (Centers for Medicare & Medicaid Services)
Who They Are
CMS administers Medicare and Medicaid programs. CMS has its own enforcement authority over HIPAA for providers and suppliers receiving Medicare/Medicaid funding.
CMS Authority
- Authority over: Medicare/Medicaid providers, suppliers, and eligible professionals
- Penalties: Can suspend/terminate Medicare/Medicaid enrollment
- Enforcement focus: Provider compliance with CMS Conditions of Participation (CoPs)
- Relationship to OCR: CMS and OCR share information but operate independently
CMS vs. OCR Enforcement
- OCR focus: Privacy and Security Rules
- CMS focus: Overall compliance with Medicare/Medicaid program requirements
- Overlap: Both may investigate same violations
- Consequences: CMS can terminate Medicare enrollment (business-ending penalty)
Criminal HIPAA Enforcement
The Department of Justice (DOJ)
While OCR handles civil enforcement, the Department of Justice prosecutes criminal HIPAA violations through federal prosecutors.
Criminal HIPAA Violations
- Unauthorized access: Knowingly obtaining PHI without authorization
- Identity theft: Using PHI to commit fraud or identity theft
- Disclosure for profit: Selling patient information for money
- Intent requirement: Must be willful/intentional (not negligence)
Criminal Penalties
- Fines: Up to $250,000 per criminal violation
- Imprisonment: Up to 10 years imprisonment for serious violations
- Examples: Healthcare employee selling patient lists to unauthorized parties
Criminal prosecution is rare but serious. Recent cases include jail sentences for employees who sold patient information.
OCR Penalty Structure
Civil Monetary Penalties (CMPs)
OCR issues penalties based on violation severity and compliance history:
| Violation Category | Minimum Per Violation | Maximum Per Violation | Annual Cap* |
|---|---|---|---|
| Did not know of violation | $100 | $50,000 | $1.5 million |
| Reasonable cause | $1,000 | $50,000 | $1.5 million |
| Willful neglect (corrected) | $10,000 | $50,000 | $1.5 million |
| Willful neglect (not corrected) | $50,000 | $50,000 | $1.5 million |
*Annual cap applies per violation rule, not per entity.
Settlement vs. Fine
- Settlement: OCR and entity agree on resolution, usually includes fine + Corrective Action Plan
- Corrective Action Plan (CAP): Entity commits to specific compliance improvements
- Example: 2023 settlement: $475,000 fine + CAP requiring new policies and training
Frequently Asked Questions
OCR's goal is enforcement and compliance, not closure. However:
- OCR alone: Will not shut down your practice, but will issue penalties and require compliance improvements
- CMS (Medicare/Medicaid): Can suspend/terminate program enrollment if violations are egregious
- State Medical Board: Can revoke license for serious HIPAA violations (separate from OCR)
- Criminal: Criminal prosecution is separate and rare
Most OCR settlements allow the entity to continue operating while implementing compliance improvements.
OCR becomes aware of violations through multiple sources:
- Patient complaints (60%): Most common source; patients file complaints online or by mail
- Employee whistleblowers: Staff report violations to OCR or media
- News/media: OCR monitors reports of breaches
- Voluntary audits: OCR randomly selects entities for audit
- Other agencies: CMS, State AGs, or other agencies refer complaints
You don't have to be accused of a breach to face OCR investigation. Operational non-compliance (like visible sign-in sheets) can trigger complaints.
Yes, absolutely. In fact, this is common for large breaches:
- OCR handles federal HIPAA enforcement
- State AG handles state law enforcement
- Both may investigate the same breach independently
- They coordinate but negotiate separate settlements
- You could face OCR fine + State AG penalty simultaneously
Example: A 2023 health system breach triggered OCR settlement ($2.75M) AND separate State AG settlements (~$1M+). Total penalties exceeded $3.75M.
Immediate action steps:
- Day 1: Notify your legal counsel or attorney immediately
- Day 2-3: Review the complaint details carefully
- Week 1: Preserve all potentially relevant documentation
- Response deadline: OCR typically gives 30 days to respond
- Your response: Work with attorney to prepare thorough written response
- Cooperation: Cooperate fully but protect your interests through counsel
Don't: Ignore the complaint, respond without legal counsel, or destroy documents.
Yes, OCR publishes all major settlements.
- OCR maintains a public database of settled cases on hhs.gov
- Settlements include entity name, violation details, penalty amount, and CAP requirements
- This transparency helps other entities learn from violations
- Competitors and business partners can see your violations
Settlement amounts and violation details are public information. This creates reputational and business consequences beyond the financial penalty.
Worried About HIPAA Enforcement Risk?
Medcurity helps organizations understand their HIPAA enforcement risk and proactively improve compliance to avoid OCR investigations. Our compliance audits identify vulnerabilities before they become complaints.
Get a Compliance Risk Assessment