HIPAA Violations: Real Examples, Fines, and What Happens to Businesses That Get Caught

When business owners look for HIPAA violation examples, they usually want to know exactly what mistakes trigger a federal audit and how much those errors will cost their practice. Massive cyberattacks are not the only way companies get in trouble. Everyday operational gaps cause many compliance failures. A lost laptop, an unsigned vendor contract, or an employee snooping through patient files can all lead to severe financial penalties.
The OCR enforces these regulations, and they look at what you did before the incident. The HHS Office for Civil Rights (OCR) investigates whether you took reasonable steps to protect protected health information (PHI). If you run a healthcare clinic or a vendor business in Chicagoland, understanding where these liabilities hide in your daily operations is the first step toward closing them.
This guide covers what actually counts as an infraction, the most frequent ways businesses fail, and the specific penalty tiers you face if you get caught.

What Qualifies as a HIPAA Violation?
A HIPAA violation is any failure by a covered entity or its business associate to comply with the rules set by the Health Insurance Portability and Accountability Act. This 1996 US federal law uses administrative simplification rules to protect the privacy and security of patient data. A violation occurs when a business compromises this data or fails to implement the required safeguards.
Three core rules define the compliance obligations. A failure under any one of them is a direct violation:
| Rule | What it Governs | Example of a Violation Under it |
|---|---|---|
| Privacy Rule | Uses and disclosures of PHI, plus patient rights over their records | Employee snooping through a family member’s medical file without a valid clinical need |
| Security Rule | Administrative, physical, and technical safeguards for electronic PHI (ePHI) | Unencrypted laptop holding patient data goes missing offsite |
| Breach Notification Rule | What must happen when unsecured PHI is exposed | Failing to notify affected patients within 60 days of discovering a breach |
Covered entities include healthcare providers, health plans, and healthcare clearinghouses. Business associates carry the same burden. If you are an IT provider managing backups or a billing company processing claims, you are directly liable under the Security and Breach Notification Rules — the obligation is identical to the doctor who collected the data.
A data leak does not have to happen for a business to be in violation. A missing policy, an incomplete audit log, or lacking a formally designated Privacy Officer and Security Officer are all punishable offenses. Compliance is an ongoing state you maintain and can evidence, not a certificate you buy.
The FTC has flagged “HIPAA Certified” claims as misleading because no government agency issues that status. You are either actively maintaining your safeguards, or you are operating in violation of the law.
Common HIPAA Violations Practices Actually Commit
The most common HIPAA violations do not look like sophisticated hacker syndicates breaking into a mainframe. They look like simple human errors and neglected it maintenance. These are the specific, everyday failures that lead to government investigations, public breach notifications, and heavy fines.
| Violation | What it Looks Like |
|---|---|
| No risk assessment | No documented, current analysis identifying and mitigating risks to patient data, the single most requested document in an OCR investigation |
| Unencrypted laptops and lost devices | An unencrypted device holding ePHI goes missing offsite, turning a lost laptop or phone into a reportable breach |
| Unauthorized access to patient records | Staff look at the medical files of family, neighbors, celebrities, or ex spouses without a valid clinical or business need |
| Missing Business Associate Agreements | A vendor creates, receives, maintains, or transmits PHI without a signed BAA in place |
| Misdirected emails and faxes | A staff member sends a patient record to the wrong recipient through autocomplete or a misdialed fax |
| Improper disposal of medical records | Paper charts go into a regular recycling bin, or old drives are retired without secure wiping or destruction |
| Social media exposures | A staff post reveals patient information, even without a visible face, through one of HHS’s 18 identifiers |
Before the detailed breakdown, run through this fast self-check:
- [ ] Do you have a documented, current risk analysis on file?
- [ ] Are all offsite laptops, phones, and USB drives encrypted?
- [ ] Can you track who accessed which patient record, and when?
- [ ] Do you have a signed Business Associate Agreement with every vendor that touches PHI?
- [ ] Do outgoing emails and faxes containing PHI use encryption and address verification?
- [ ] Are old hard drives and paper charts destroyed or wiped, not just thrown out?
- [ ] Do staff know what counts as PHI before they post on social media?
Any “no” is a gap worth fixing before it becomes an OCR finding. Here is the detail on each.
1. HIPAA Risk Assessment Failure
A documented, current risk analysis is the absolute foundation of your compliance program. It is also one of the first documents OCR asks for in an investigation. A HIPAA risk assessment failure occurs when a practice or vendor cannot prove they have systematically identified and mitigated the risks to their patient data.
OCR’s recent enforcement actions keep circling back to the same root cause: missing or incomplete risk analyses. If you do not know how to do a HIPAA risk assessment, you are already operating at a severe disadvantage. The Security Rule requires administrative safeguards, including policies, workforce training, access management, and this initial risk analysis. Skipping it is viewed as a fundamental breakdown of your security responsibilities.
2. Unencrypted Laptops, Lost Devices, and Unsecured Network Equipment
A lost or stolen device HIPAA incident is one of the most frequent triggers for a breach investigation. Doctors, nurses, and billing staff frequently take laptops, phones, or USB drives offsite. If a device holding ePHI goes missing and it is unencrypted, you have a reportable breach on your hands.
Properly encrypted data whose key was not compromised is generally not considered unsecured PHI. Because of this safe harbor, losing an encrypted laptop is usually not a reportable breach. Failing to encrypt devices is a massive HIPAA security rule violation that turns a simple lost phone into a public relations nightmare. When you consult the plain-English HIPAA overview, encryption is always at the top of the list.
Network equipment falls under the same Security Rule. Routers, firewalls, and switches that handle ePHI traffic must be hardened to the same standard as laptops and servers. A router shipped with default admin credentials or a firewall running unpatched firmware leaves patient data exposed just as effectively as an unencrypted hard drive.
OCR investigators treat these infrastructure failures identically to a missing device encryption policy. If your IT provider cannot show that every network device touching patient data has been hardened and is under active patch management, that gap is a Security Rule violation waiting to happen.
3. Unauthorized Access to Patient Records
Snooping by employees is a widespread HIPAA violation in the workplace. Staff members looking at the medical files of family members, neighbors, celebrities, or ex-spouses without a valid clinical or business need is a direct violation of the Privacy Rule.
This unauthorized access to patient records often goes unnoticed if the practice lacks proper technical safeguards. The Security Rule requires access controls with unique IDs and comprehensive audit logging. Without these controls, an employer cannot track who viewed a specific file, making this employer HIPAA violation incredibly difficult to investigate and contain.
4. Missing Business Associate Agreements
A business associate is any vendor that creates, receives, maintains, or transmits PHI on a covered entity’s behalf. This includes IT providers, billing companies, EHR vendors, shredding services, and cloud services. A Business Associate Agreement (BAA) is a contract required before a business associate may access PHI. It makes the vendor legally responsible for protecting the data.
A missing or unsigned BAA is itself a violation and one of the most common enforcement findings. Subcontractors of business associates also need BAAs to ensure the legal obligations flow down the entire supply chain.
5. Misdirected Emails and Faxes
Sending sensitive health information to the wrong recipient is a highly common unintentional HIPAA violation. A misdirected email PHI incident happens when a staff member relies on autocomplete in their email client and sends a patient record to the wrong address. It also happens when faxes are dialed incorrectly.
The Security Rule requires transmission security. If you are sending ePHI outside your network without proper email encryption and verification steps, you are violating the technical safeguards. These simple human errors require a formal PHI breach notification if the data is unsecured and falls into the wrong hands.
6. Improper Disposal of Medical Records
Tossing paper charts into a standard office recycling bin is a clear violation of the physical safeguards required by the law. Improper disposal of medical records also applies to digital media. Retiring old computers, servers, or hard drives without securely wiping or physically destroying the storage drives leaves ePHI highly vulnerable.
Facility and device controls, workstation security, and strict media disposal policies are mandatory. If an old clinic hard drive ends up on an online auction site with patient data still intact, the practice is entirely liable for the resulting breach.
7. Social Media Exposures
A social media HIPAA violation occurs when staff members post photos or updates online that inadvertently reveal patient information. Even if a patient’s face is not visible in the background of a clinic selfie, the post can still be a violation.
HHS recognizes 18 identifiers that can make health information identifiable. These include names, addresses, dates, phone numbers, email addresses, Social Security numbers, medical record numbers, and biometric identifiers. Removing all 18 identifiers creates a safe harbor that de-identifies the data. Failing to do so means that a seemingly innocent workplace photo can trigger a formal complaint and a subsequent investigation.
The Penalty Tiers in Plain English
When OCR investigates HIPAA violation cases, they do not just hand out a flat ticket. They assess fines based on a tiered system of culpability. The government looks closely at how much you knew about the problem and what steps you took to correct it. Understanding the HIPAA violation penalty structure helps business owners see exactly how proactive IT management and documentation directly reduce your penalty tier.
The federal civil penalties break down into four tiers based on the level of negligence involved.
| Tier | Culpability | Penalty Range (per violation) |
|---|---|---|
| Tier 1: Did Not Know | The business did not know, and could not reasonably have known, about the violation, even with a strong compliance program in place | $145 to $73,011 per violation, the lowest floor of the four tiers |
| Tier 2: Reasonable Cause | The business knew or should have known about the violation, but the failure was not willful neglect, often because policies existed but were not enforced consistently | $1,461 to $73,011 per violation, a floor ten times higher than Tier 1 |
| Tier 3: Willful Neglect (Corrected) | The business consciously ignored the rules but corrected the problem promptly after discovering it | $14,602 to $73,011 per violation, reserved for neglect fixed within 30 days |
| Tier 4: Willful Neglect (Uncorrected) | The business ignored the rules and made no effort to fix the problem even after it was discovered | $73,011 to $2,190,294 per violation, the maximum tier under HHS’s current penalty schedule |
These figures are set by federal regulation and adjusted for inflation, so treat them as the order of magnitude, not a fixed quote. There is an annual cap that reaches about $2.19 million per violation category, the same ceiling regardless of tier.
A single mistake rarely equals a single violation. Here is how one failure multiplies:
- Violation event — An unencrypted drive holding patient records goes missing
- Per-record multiplication — 500 patient records on one drive = up to 500 individual violations at the assessed tier
- Annual cap — Civil penalties cap at approximately $2.19 million per violation category per year
- Separate criminal track — Knowing misuse or intentional theft of PHI is prosecuted by the Department of Justice (DOJ), with its own fines and prison terms
These are just the civil penalties. Regulators can view 500 exposed patient records on one lost drive as 500 individual violations, which is how fines rapidly escalate to the annual cap.
To understand the scale of enforcement, consider what happens when a massive failure occurs. The 2024 Change Healthcare hack exposed the health data of 192.7 million people — the largest healthcare data breach in US history, per the final figure reported to HHS OCR on July 31, 2025. The exact same rules and penalty structures apply to your operation, regardless of your size.
The Scale of Enforcement
When discussing enforcement, business owners often assume regulators only care about massive hospital systems. The HHS Office for Civil Rights investigates organizations of all sizes, and the documentation standards remain identical. The scale ranges from catastrophic national cyberattacks to quiet, routine audits of local dental clinics.
At the top end of the spectrum, massive failures draw historic scrutiny. As noted earlier, the 2024 Change Healthcare hack remains the largest healthcare data breach in US history, with 192.7 million people affected according to the final figure reported to HHS OCR on July 31, 2025. While a local Chicagoland practice will not generate that volume of exposed records, the exact same regulatory framework applies.
Chicagoland practices face the same audit standards as national hospital systems. A dentist in Burr Ridge or a clinic in Elk Grove Village must produce a current risk analysis, written policies, and signed BAAs — the same documents OCR demands from a Chicago hospital network. The geographic distance from Washington DC offers no buffer: an audit letter lands at a suburban practice the same way it lands at a Cleveland Clinic campus.
LeadingIT serves these towns directly, helping 200 organizations across Illinois meet those standards. If you are a vendor unsure whether these audit standards apply to your operations, reviewing exactly who must comply with HIPAA is the right first step.
When regulators look at smaller practices, they focus heavily on administrative safeguards. A documented, current risk analysis is the foundation of your defense. The government takes this requirement incredibly seriously.
Every HIPAA settlement the government announced in the first 8 months of 2025 (16 of 16) traced back to one failure: no proper risk analysis (source: HHS Office for Civil Rights, 2025).
If you cannot produce this document when asked, you are virtually guaranteed to face fines.
How Violations Get Discovered
Investigations begin through one of three specific triggers. Here is what starts the process and what happens next:
| Discovery Trigger | Who Initiates it | What Happens Next |
|---|---|---|
| Formal Complaint | Patient, employee, or competitor files with HHS OCR | OCR opens an investigation and requests documentation |
| Breach Report | Covered entity self-reports a breach of 500 or more records | OCR investigates whether a compliance failure caused the breach |
| OCR Audit | HHS selects the practice semi-randomly for a review | Strict documentation request: risk analysis, policies, training logs, BAAs |
Complaints drive a large share of investigations. A complaint can come from a patient who noticed a discarded medical chart in a public dumpster. It can come from an employee who witnessed unauthorized snooping. It can even come from a competitor. Because anyone can file, internal security gaps rarely stay hidden forever.
Reported breaches automatically draw regulatory eyes. Once a breach is discovered, HIPAA’s own notification clock starts running:
| When | What Happens |
|---|---|
| Day 0 | A breach of unsecured PHI is discovered |
| Within 60 days | Affected individuals must be notified, without unreasonable delay and no later than 60 days after discovery |
| Same 60-day window, if 500 or more people are affected | HHS and prominent media outlets in the affected area must also be notified |
| Annually, if fewer than 500 people are affected | The breach is rolled into HHS’s annual report instead |
Once you file that report, OCR will likely open an investigation to determine if a compliance failure allowed the breach to happen.
OCR audits are the third trigger. OCR does not publish a fixed annual calendar. Audits run in rounds — Phase 2 has been active since 2016 — and practices are selected semi-randomly from the covered entity pool.
When selected, investigators will ask to see your risk analysis, your written policies, your staff training records, your system access logs, and your incident records. They also demand signed Business Associate Agreements for every vendor that handles your protected health information. Because selection timing is not predictable, the best defense is keeping documentation current year-round rather than scrambling after a letter arrives.
How to Report a Violation
If a patient, employee, or business partner witnesses a compliance failure, the reporting process is straightforward. Complaints are filed directly with the HHS Office for Civil Rights through their online portal. The portal allows individuals to detail the suspected infraction — whether it is a missing safeguard, a denied records request, or a suspected data leak.
Whistleblowers are protected by law, meaning covered entities cannot retaliate against staff members who report legitimate security concerns to the government.
See Where You Stand
Free 2-minute HIPAA Risk-Check: 8 plain-English questions, your audit-readiness level and the gaps to fix. No sign-up to see your result. free 2-minute HIPAA risk assessment
Related Guides
- What Is HIPAA? A Plain-English Guide for Business Owners
- How to Do a HIPAA Risk Assessment: Step-by-Step Guide
- What Is a HIPAA Business Associate Agreement (BAA)?
- The HIPAA Privacy Rule Explained for Businesses
Frequently Asked Questions
What are the four most common HIPAA violations?
The most frequent infractions involve failing to conduct an organization-wide risk analysis, leaving devices unencrypted, unauthorized employee snooping into patient files, and missing Business Associate Agreements. These everyday operational gaps trigger the majority of federal audits and fines. Proactive IT management and strict access controls prevent most of these errors.
What are considered HIPAA violations?
A violation is any failure to implement the required administrative, physical, or technical safeguards to protect protected health information. This includes both unauthorized data disclosures and administrative failures like missing policies or unsigned vendor contracts. You do not need to suffer a data breach to be found in violation of the law.
What is a real life example of a HIPAA violation?
A common real-world example is a nurse losing an unencrypted clinic laptop that contains patient records. Because the electronic protected health information was not encrypted, the loss constitutes a reportable breach. Another frequent example is a staff member posting a workplace photo on social media that accidentally reveals a patient name or medical chart in the background.
What qualifies as a HIPAA violation?
Any breach of the Privacy, Security, or Breach Notification rules qualifies as a violation. This applies equally to covered entities like doctors and their business associates like IT providers and billing companies. Failing to properly dispose of medical records or failing to notify affected individuals within 60 days of a breach are direct violations.
What are the 5 main rules of HIPAA?
For compliance work, businesses focus primarily on the three core rules. The Privacy Rule governs how data is used and disclosed, the Security Rule mandates specific safeguards for electronic data, and the Breach Notification Rule dictates how to report exposed data. The original law also set standards for electronic healthcare transactions and standard identifiers used across the industry.
Protect Your Practice with LeadingIT
LeadingIT is a Chicagoland managed it and cybersecurity provider that has helped Illinois practices meet HIPAA since 2010. We serve roughly 200 organizations and 2,500+ users from our offices in Woodstock and Manteno.
We operate the technical half of compliance: access controls, MFA, encryption, logging, tested backups, and monitoring. We also sign BAAs with our practice clients as a standard procedure and help produce the exact documentation an auditor asks for.
Explore LeadingIT’s HIPAA compliance services to see how we help you become and stay compliant. If you are ready to secure your operations, book a call to discuss your practice with our team, or contact us directly at 815-788-6041.
