Medcurity Get Compliance Help

Who Enforces HIPAA? OCR, State AGs & CMS Explained

Quick Answer: HIPAA is primarily enforced by the Office for Civil Rights (OCR) within the Department of Health and Human Services. State Attorneys General can also enforce HIPAA, and CMS enforces it for Medicare/Medicaid providers. Each agency has different authority, investigation processes, and penalty structures. A single HIPAA violation may trigger investigations by multiple agencies.

HIPAA Enforcement Overview

HIPAA enforcement is shared among multiple federal and state agencies, creating a complex regulatory landscape. Understanding which agency has jurisdiction is critical when responding to complaints or investigations.

Key Enforcement Agencies

Agency Primary Jurisdiction Complaint Authority
OCR (Office for Civil Rights) Covered entities & Business Associates Investigates HIPAA complaints; issues fines and settlements
CMS (Centers for Medicare & Medicaid Services) Medicare/Medicaid providers Focuses on provider compliance; can impose penalties
State Attorneys General Any entity in their state Can enforce HIPAA under state laws; coordinate with federal
FBI / Justice Department Criminal violations only Prosecutes criminal HIPAA violations (identity theft, fraud)

The Office for Civil Rights (OCR)

Who They Are

The Office for Civil Rights is a division of the U.S. Department of Health and Human Services (HHS). OCR is the primary HIPAA enforcement agency responsible for investigating complaints and issuing civil penalties.

OCR Authority & Jurisdiction

How OCR Investigates

  1. Complaint Receipt: OCR receives complaint (written, online portal, or mail)
  2. Initial Review: Determines if complaint is within jurisdiction
  3. Investigation: Contacts entity, reviews records, may conduct on-site audit
  4. Resolution: Issues findings, proposes settlement, or closes case
  5. Enforcement: Negotiates Corrective Action Plan (CAP) or issues civil penalty
  6. Public Reporting: Publishes settlement details and lessons learned

OCR Investigation Timeline

How to Handle OCR Investigation: If OCR contacts you about a complaint, take it seriously. You have the right to legal representation. Respond within required timeframes (usually 30 days). Cooperate fully but carefully—everything you provide becomes evidence. Consider working with a HIPAA attorney.

State Attorneys General (State AGs)

Who They Are

The Attorney General in each state can enforce HIPAA under state law. While OCR has primary federal authority, State AGs have concurrent enforcement power and often investigate large-scale breaches or complaints from state residents.

State AG Authority

State AG vs. OCR Enforcement

Notable State AG HIPAA Enforcement Examples

Important: If a breach affects residents of multiple states, you may face investigations by multiple State AGs simultaneously. This significantly increases legal complexity and potential penalties.

CMS (Centers for Medicare & Medicaid Services)

Who They Are

CMS administers Medicare and Medicaid programs. CMS has its own enforcement authority over HIPAA for providers and suppliers receiving Medicare/Medicaid funding.

CMS Authority

CMS vs. OCR Enforcement

Critical: For Medicare/Medicaid providers, CMS enforcement can be more devastating than OCR fines. Losing Medicare/Medicaid enrollment can eliminate a major revenue source. HIPAA compliance is essential for maintaining program eligibility.

Criminal HIPAA Enforcement

The Department of Justice (DOJ)

While OCR handles civil enforcement, the Department of Justice prosecutes criminal HIPAA violations through federal prosecutors.

Criminal HIPAA Violations

Criminal Penalties

Criminal prosecution is rare but serious. Recent cases include jail sentences for employees who sold patient information.

OCR Penalty Structure

Civil Monetary Penalties (CMPs)

OCR issues penalties based on violation severity and compliance history:

Violation Category Minimum Per Violation Maximum Per Violation Annual Cap*
Did not know of violation $100 $50,000 $1.5 million
Reasonable cause $1,000 $50,000 $1.5 million
Willful neglect (corrected) $10,000 $50,000 $1.5 million
Willful neglect (not corrected) $50,000 $50,000 $1.5 million

*Annual cap applies per violation rule, not per entity.

Settlement vs. Fine

Frequently Asked Questions

If OCR investigates us, will they shut us down?

OCR's goal is enforcement and compliance, not closure. However:

  • OCR alone: Will not shut down your practice, but will issue penalties and require compliance improvements
  • CMS (Medicare/Medicaid): Can suspend/terminate program enrollment if violations are egregious
  • State Medical Board: Can revoke license for serious HIPAA violations (separate from OCR)
  • Criminal: Criminal prosecution is separate and rare

Most OCR settlements allow the entity to continue operating while implementing compliance improvements.

How does OCR find out about HIPAA violations?

OCR becomes aware of violations through multiple sources:

  • Patient complaints (60%): Most common source; patients file complaints online or by mail
  • Employee whistleblowers: Staff report violations to OCR or media
  • News/media: OCR monitors reports of breaches
  • Voluntary audits: OCR randomly selects entities for audit
  • Other agencies: CMS, State AGs, or other agencies refer complaints

You don't have to be accused of a breach to face OCR investigation. Operational non-compliance (like visible sign-in sheets) can trigger complaints.

Can we be investigated by both OCR and State AG?

Yes, absolutely. In fact, this is common for large breaches:

  • OCR handles federal HIPAA enforcement
  • State AG handles state law enforcement
  • Both may investigate the same breach independently
  • They coordinate but negotiate separate settlements
  • You could face OCR fine + State AG penalty simultaneously

Example: A 2023 health system breach triggered OCR settlement ($2.75M) AND separate State AG settlements (~$1M+). Total penalties exceeded $3.75M.

What should we do if we receive an OCR complaint?

Immediate action steps:

  • Day 1: Notify your legal counsel or attorney immediately
  • Day 2-3: Review the complaint details carefully
  • Week 1: Preserve all potentially relevant documentation
  • Response deadline: OCR typically gives 30 days to respond
  • Your response: Work with attorney to prepare thorough written response
  • Cooperation: Cooperate fully but protect your interests through counsel

Don't: Ignore the complaint, respond without legal counsel, or destroy documents.

Are OCR settlements published publicly?

Yes, OCR publishes all major settlements.

  • OCR maintains a public database of settled cases on hhs.gov
  • Settlements include entity name, violation details, penalty amount, and CAP requirements
  • This transparency helps other entities learn from violations
  • Competitors and business partners can see your violations

Settlement amounts and violation details are public information. This creates reputational and business consequences beyond the financial penalty.

Worried About HIPAA Enforcement Risk?

Medcurity helps organizations understand their HIPAA enforcement risk and proactively improve compliance to avoid OCR investigations. Our compliance audits identify vulnerabilities before they become complaints.

Get a Compliance Risk Assessment