Free Consultation
#hipaa
#phi
#ephi

HIPAA Violation Examples: What Actually Triggers an OCR Enforcement Action

August 7, 2026

The Office for Civil Rights (OCR) closed 2025 with 21 settlements and civil monetary penalties, the second highest annual total on record. That volume did not come from random audits. It came from a small, predictable set of failure categories that repeat across nearly every case: unauthorized disclosure of protected health information, missing business associate agreements, incomplete risk analyses, and breach notifications sent too late.

This article breaks down those categories using OCR's own enforcement record and the requirements written into the Health Insurance Portability and Accountability Act (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act. The core point is straightforward: enforcement follows documented gaps in specific, well-known rules, not bad luck. Organizations that understand which failures OCR investigates most often can close those gaps before a complaint or breach report reaches a federal investigator.

What Does PHI Stand For, and Why Does It Drive Every Violation Category?

Protected health information (PHI) is any individually identifiable health information created, received, maintained, or transmitted by a covered entity or its business associates. This includes medical records, billing details, appointment data, and any identifier tied to a patient's health status or treatment. Nearly every HIPAA violation category traces back to a failure to protect, disclose, or account for PHI correctly, whether the failure involves an email sent to the wrong recipient, a server left unencrypted, or a vendor handling patient data without a signed agreement.

Common HIPAA Violation Categories OCR Investigates

HIPAA violation examples generally fall into five recurring categories, and OCR's recent settlements confirm the pattern. These settlements point to consistent enforcement priorities: 

Impermissible Disclosure of PHI

Impermissible disclosure covers any sharing of PHI outside what the Privacy Rule permits, including posts on social media, embedded tracking tools on patient portals, or records handed to the wrong party. OCR treats these disclosures as a top enforcement priority alongside access delays and security failures.

Security Rule Risk Analysis Failures

A risk analysis failure occurs when a covered entity or business associate never conducts, or never updates, a documented assessment of threats to electronic protected health information (ePHI). Recent resolution agreements consistently address defects in basic Security Rule compliance, with a common finding that the organization failed to conduct a thorough risk analysis consistent with the HIPAA Security Rule. Risk analysis failures are the most commonly identified HIPAA Security Rule violation in OCR's investigations of data breaches and audits, and this single gap now drives more enforcement actions than any other issue.

Right of Access Violations

Patients have a right to obtain a copy of their own records within a defined window, and OCR pursues complaints when that window is missed by a wide margin. In one settlement, OCR resolved alleged Right of Access violations after determining a covered entity failed to provide an individual's PHI within 30 days despite multiple requests, with access ultimately provided more than a year after the initial request. Organizations are expected to track the 30-day deadline, with one possible 30-day extension, to avoid these complaints.

Missing Notice of Privacy Practices

The Notice of Privacy Practices (NPP) is the written statement every patient receives explaining how a provider may use and disclose PHI, along with the patient's rights and the provider's legal duties. Under 45 CFR 164.520, a healthcare provider with a direct treatment relationship must provide the Notice of Privacy Practices no later than the date of first service delivery, including service delivered electronically. A missing, outdated, or improperly distributed notice is a documentation gap that surfaces quickly during any OCR review.

Missing or Noncompliant Business Associate Agreements

A business associate agreement (BAA) is the contract required between a covered entity and any vendor that creates, receives, maintains, or transmits PHI on its behalf. In practical terms, a BAA is the legal document that extends HIPAA's privacy and security obligations to that vendor. A covered entity is required to enter into a contract or other written arrangement with a business associate that meets the requirements at 45 CFR 164.504(e), which spells out exactly what the agreement must contain. A BAA must establish the permitted and required uses and disclosures of PHI, prohibit the business associate from using or disclosing the information beyond what the contract or law permits, and require appropriate safeguards, including Security Rule requirements for electronic PHI. Working with a billing company, cloud host, IT vendor, or answering service without this agreement in place is one of the most common and most avoidable violations OCR identifies.

How Does the HITECH Act Shape Breach Notification Requirements?

HITECH is the 2009 law that added a mandatory breach notification framework to HIPAA and extended direct liability to business associates and their subcontractors. HITECH strengthened HIPAA by creating the federal breach notification rule, extending direct liability to business associates and their subcontractors, increasing enforcement and penalty tiers, and promoting adoption of security controls such as encryption. Before HITECH, business associates faced far less direct exposure for mishandling PHI. That changed permanently once the law took effect.

The notification timeline is fixed and applies regardless of organization size. Breach notification letters must be sent within 60 days of the discovery of a breach, unless a shorter timeframe exists under state law or a delay has been requested by law enforcement. For larger incidents, additional reporting applies. For breaches affecting 500 or more individuals, HHS must be notified within the same 60-day window. Breaches affecting fewer than 500 individuals are reported in an annual summary submitted within 60 days after the end of the calendar year. Media notice is also required within 60 days if 500 or more residents of a state or jurisdiction are affected. Missing any of these windows converts a security incident into a separate, documented compliance failure.

What Do the Penalties Actually Look Like?

Civil monetary penalties scale with culpability, from simple lack of knowledge to willful neglect that goes uncorrected. Penalties for HIPAA violations include civil monetary penalties ranging from $145 to $2,190,294 per violation, depending on the level of culpability. Most resolutions, however, pair a financial settlement with a multi-year corrective action plan (CAP) that mandates new policies, updated risk analyses, and ongoing monitoring. The financial number rarely tells the full story. CAP obligations often carry a heavier operational burden than the settlement itself.

Why Enforcement Trends Point Toward Prevention, Not Reaction

OCR's current enforcement posture centers on a narrow set of repeat failures rather than sweeping new rules. Risk analysis gaps, delayed access responses, missing BAAs, and late breach notices account for the large majority of recent resolution agreements. Closing those specific gaps, rather than waiting for a complaint or breach to force the issue, remains the more defensible position for any organization handling PHI.

Getting Ahead of HIPAA Enforcement Risk

Planet 9 is a Bay Area cybersecurity consulting firm specializing in HIPAA readiness for small and midsize businesses in healthcare, SaaS, and technology. Our vCISOs and compliance managers help organizations choose the right approach, configure GRC tools if needed, and get audit-ready without wasted time.

Book a Free Consultation

Schedule a free consultation today to explore how Planet 9 can help you achieve your security and compliance goals.
Book Free Consultation

FAQs

How does a vCISO service differ from hiring a full-time CISO?
A part-time CISO offers the same strategic oversight and expertise as a full-time CISO but on a flexible, cost-effective basis. It’s ideal for small to mid-sized businesses that need executive-level guidance without the overhead.
Is a virtual CISO service suitable for regulated industries like healthcare or finance?
Yes, virtual CISOs (or fractional CISOs) are especially valuable for industries with strict compliance requirements such as HIPAA, PCI DSS, or GLBA. They help ensure your organization meets regulatory standards and is prepared for audits.
What can I expect during a vCISO engagement?
Our vCISO service typically includes cybersecurity assessments, program development, compliance planning, incident response strategy, vendor risk management, and ongoing executive reporting tailored to your business.
How do I know if my business needs a CISO-as-a-Service?
If you lack in-house security leadership, struggle with compliance, or face growing cyber risks, a vCISO can fill that gap, providing strategic direction, improving resilience, and helping you make smarter security investments.

FAQs

What does PHI stand for in HIPAA compliance?
PHI stands for protected health information, which includes any individually identifiable health data created, received, maintained, or transmitted by a covered entity or business associate. This covers medical records, billing information, and any identifier connected to a patient's health status, care, or payment history.
What is a BAA, and who needs one?
A BAA, or business associate agreement, is a contract required between a covered entity and any vendor that handles PHI on its behalf, such as a billing service, cloud host, or IT provider. The agreement is mandatory under federal regulation before that vendor may access, store, or transmit PHI.
How does HITECH affect breach notification timelines?
The HITECH Act created the federal breach notification framework that requires notifying affected individuals within 60 days of discovering a breach. It also extended direct liability for HIPAA violations to business associates and their subcontractors, not just covered entities.
What triggers most OCR HIPAA enforcement actions?
Most recent OCR enforcement actions trace back to incomplete or missing Security Rule risk analyses, delayed responses to patient access requests, impermissible PHI disclosures, and late breach notifications. These categories account for the majority of settlements and civil monetary penalties issued in recent years.
Is a Notice of Privacy Practices required for every healthcare provider?
Any covered entity with a direct treatment relationship with patients must provide a Notice of Privacy Practices no later than the first date of service, including services delivered electronically. The notice must explain how PHI may be used, patient rights over that information, and the provider's legal duties.

Related blog posts