Is Texting HIPAA Compliant? Everything You Need to Know
💡 Standard SMS is not HIPAA compliant on its own. Regular texts are not encrypted, have no access controls, and leave no audit trail. Sending...
11 min read
Alvin Amoroso : Updated on August 10, 2026
In June 2025, an ambulance billing company named Comstar paid $75,000 to federal regulators. A ransomware attack had exposed the health records of nearly 586,000 people. Investigators found the company had never run a proper security risk analysis.
That should have closed the file.
It didn't. Seven months later, Comstar agreed to pay another $515,000. This time the money went to the attorneys general of Massachusetts and Connecticut. Same breach, same records, a second bill almost seven times bigger than the first.
Here is what that case really shows. HIPAA does not have one enforcer at one door. It has several. They work from different angles, and they do not take turns.
Most practices assume that clearing one review means the matter is closed. Then a state office opens its own file. Or the case moves to federal prosecutors.
Nothing about the rules changed. The number of people checking your work just did.
So who enforces HIPAA, and what does each body actually control? This guide walks through the whole map. You will see which agency handles most cases, which ones sit alongside it, what happens after a complaint is filed, what fines cost in 2026, and who inside your own practice carries the weight day to day.
Knowing the map is worth your time. It tells you who might call, what they will ask for, and where your real risk sits.
Ask ten office managers what agency enforces HIPAA and most will name one. That answer is close, but it is not complete.
The work is split by subject. One agency owns privacy and security. Another owns billing standards. State and criminal authorities cover the rest.
Knowing who handles what saves you from preparing for the wrong conversation.
| Enforcement body | What it covers | Type of action |
|---|---|---|
| HHS Office for Civil Rights (OCR) | Privacy Rule, Security Rule, Breach Notification Rule | Civil and administrative |
| Centers for Medicare & Medicaid Services (CMS) | Electronic transactions, code sets, provider identifiers | Civil and administrative |
| State attorneys general | HIPAA violations that harm state residents, plus state privacy laws | Civil lawsuits |
| U.S. Department of Justice (DOJ) | Theft, misuse, or sale of patient data | Criminal charges |
Now look at that last column again. Three of those four routes end in a payment. One can end in prison. That gap is why the question of who is responsible for HIPAA enforcement deserves a real answer.
When asking what agency enforces HIPAA, particularly its core privacy and security components, the primary answer lies within the U.S. Department of Health and Human Services (HHS).
While HIPAA originally focused heavily on health insurance reform (Title I, largely enforced by the Department of Labor and Treasury Department), its Administrative Simplification provisions (Title II) set the stage for crucial privacy and security standards. It's important to know that HHS oversees HIPAA compliance related to these Administrative Simplification provisions.
Within HHS, the Office for Civil Rights (OCR) is the key agency delegated with the authority to enforce the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. These rules govern how CEs (like health plans, healthcare clearinghouses, and most healthcare providers) and their BAs must protect PHI.
For many practical purposes, OCR is the answer when asking what agency enforces HIPAA's privacy aspects. This agency oversees HIPAA implementation across the nation.
OCR does not rely on one method. It works through four:
The Privacy Rule protects patient data in every form. That covers electronic files, paper charts, and spoken conversations. It limits what you can share without patient consent. It also gives patients rights over their own records, including the right to a copy.
The Security Rule is narrower. It applies only to electronic protected health information, or ePHI. It asks for safeguards in three areas: how you manage people, how you secure the space, and how you set up your technology.
Wondering who is responsible for enforcing the HIPAA Security Rule at the federal level? That job belongs to OCR.
The Breach Notification Rule starts a clock. After a breach of unsecured data, you must tell affected patients and HHS. Large breaches also require notice to the media. Vendors must tell the practice they serve.
While OCR handles the Privacy, Security, and Breach Notification Rules, another HHS agency, the Centers for Medicare & Medicaid Services (CMS), enforces HIPAA's Administrative Simplification Rules related to standardized electronic transactions, code sets, and unique identifiers (like the National Provider Identifier - NPI). Complaints regarding these specific transaction standards are often handled through CMS's Administrative Simplification Enforcement Testing Tool (ASETT).
So, while OCR is a major player, CMS also contributes to the picture of who is responsible for enforcing HIPAA.

While OCR is the primary enforcer for privacy and security, they are not the only government body who is responsible for HIPAA enforcement. Two other key players significantly impact the enforcement landscape:
The HITECH Act of 2009 gave state attorneys general the power to sue in federal court. They act on behalf of residents whose HIPAA rights were violated. That power runs alongside OCR's, not beneath it.
A state attorney general can open a case on their own. They only have to give HHS written notice before filing suit. They can seek court orders that force a company to change how it works. They can also seek money for the state or for the residents who were harmed.
The Comstar case from the top of this article is the clearest recent example. Federal regulators closed their file for $75,000 in June 2025. Massachusetts and Connecticut filed a joint judgment in January 2026 for $515,000.
That brings the total to $590,000. About 87% of it came from the state side. For your team, the takeaway is blunt. Settling with one authority does not release you from the others.
Criminal cases go somewhere else. Under federal law, knowingly taking or sharing patient data in violation of HIPAA is a crime. The DOJ handles those cases. They usually arrive after OCR refers evidence of intent.
These are not paperwork problems. They involve stealing patient data for identity theft, selling patient lists, or snooping out of malice. Penalties rise with intent:
| Level of intent | Maximum fine | Maximum prison term |
|---|---|---|
| Knowing violation | $50,000 | 1 year |
| Under false pretenses | $100,000 | 5 years |
| For personal gain or malice | $250,000 | 10 years |
Charges are rare, but they are real. A dental receptionist who stole patient data drew two to six years. A hospital employee drew three years. A Florida clinic worker drew four.
In practice, this is why access controls and offboarding steps matter as much as your written policies.
Enforcement rarely looks like a raid. It looks like a letter. Knowing the sequence trades vague dread for a clear checklist.
Where you land depends on what you can show. Practices with current records and a recent risk analysis usually get guidance. Practices with nothing on file usually do not.
Fines carry real numbers, and those numbers moved recently. HHS applied its inflation update on January 28, 2026.
First, one distinction worth keeping straight. A violation is any failure to follow the rules. A breach is a narrower thing: unsecured patient data was used or shared improperly, and that put its privacy at risk.
Every breach is a violation. Not every violation is a breach.
Civil fines are tiered. The tier depends on how much you knew and how fast you acted. The table below reflects the caps OCR applies under its 2019 enforcement discretion notice.
| Tier | Level of fault | Minimum per violation | Maximum per violation | Annual cap |
|---|---|---|---|---|
| 1 | Lack of knowledge | $145 | $36,506 | $36,506 |
| 2 | Reasonable cause | $1,461 | $73,011 | $146,053 |
| 3 | Willful neglect, fixed within 30 days | $14,602 | $73,011 | $365,052 |
| 4 | Willful neglect, not fixed | $73,011 | $2,190,294 | $2,190,294 |
Here is what the tiers really mean. The gap between Tier 1 and Tier 4 is not about the mistake. It is about what you did after you found it.
Take a practice with 500 records exposed through one open vulnerability. At Tier 1, the yearly cap holds the damage near $36,506. Move the same incident to Tier 4 because nobody fixed the problem, and the ceiling jumps to $2,190,294. That is roughly 60 times more, driven entirely by the response.
Those caps also apply per violation type. A practice found at fault in four areas can face four separate caps in one year.
Money is not the only cost. Corrective action plans often run for years and require outside consultants. Breach notices become public. Staff time shifts from patients to paperwork.
Damage to your name tends to outlast the fine. And state penalties can stack on top of federal ones, as Comstar learned.

|
Look at OCR's actions from 2025 and 2026 and a pattern appears fast. Nearly every settlement names the same root cause: no thorough, current security risk analysis. It appears in the $552,250 OSF Healthcare settlement. It appears in the $375,000 Assured Imaging settlement, the $320,000 Axia Women's Health settlement, and the $5,000 Vision Upright MRI settlement. Different sizes, same finding. Two things follow. First, the risk analysis is the highest-leverage document you own. Second, small practices are not invisible. Even a $5,000 settlement comes with a corrective action plan and a public record. |
Outside agencies decide the fines. Your team decides whether there is anything to fine. So who is responsible for implementing and monitoring the HIPAA rules on a normal Tuesday? Two named roles, backed by everyone else.
The Privacy Rule at §164.530 says you must name one. This person writes and updates privacy policies, runs staff training, handles patient record requests, manages complaints, and takes the call if OCR reaches out.
The Security Rule at §164.308 calls for its own role. Their scope is ePHI:
Inside your walls, this is the person who is responsible for enforcing the HIPAA Security Rule.
In smaller practices, one person often wears both hats. That works, as long as the role is written down and the person has real time and real authority. Bigger groups usually split the two.
Either setup is fine. Fuzzy ownership is not. Gaps form where nobody is clearly in charge.
Compliance does not stop at two job titles. Every staff member who touches patient data shares the load. That also answers a related question: who is responsible for complying with HIPAA?
The short list is covered entities, their vendors, any subcontractors who handle patient data, and the staff inside each of them.
That includes daily communication habits. Reminders, billing messages, and follow-up texts all move through channels that either meet the Security Rule or do not.
Standard SMS is not encrypted. A general reminder is fine. A message that names a condition or a test result is not.
Practices that handle this well use a platform built for the rule. They do not ask staff to judge it message by message. Curogram works alongside your EMR to keep two-way texting, patient forms, telemedicine, and payment requests inside a HIPAA-compliant space. The safe path becomes the easy one.
Rules stay abstract until you watch them land. The scenarios below are composites, drawn from patterns in published enforcement actions.
A multi-provider clinic runs an internal review. It finds that its risk analysis is four years out of date. Rather than wait, the practice hires a consultant, writes a fix-it plan, and reports the findings on its own.
OCR responds with guidance and no fine. The proactive record is what makes the difference.
Ransomware hits a regional hospital through a flaw that went unpatched for over a year. The hospital reports the breach and OCR opens a case.
Staff had flagged the risk internally and nobody acted. That pushes the case into willful neglect. The result is a seven-figure settlement and a corrective action plan that runs for years.
Hospital staff open the records of a high-profile patient they never treated. An audit log review catches it. The hospital fires those employees and files a breach report.
OCR requires a corrective action plan for access monitoring. Separately, affected patients complain to their state attorney general, who files a civil suit. It ends in damages and stricter state rules. One incident, two enforcers, two sets of obligations.
So, who enforces HIPAA? Not one office, and not in one way.
OCR sits at the center. It handles the Privacy, Security, and Breach Notification Rules, and it closes most cases with guidance rather than fines. Around it sit CMS, state attorneys general, and the DOJ.
Any one of them can open a file. More than one can open a file on the same event.
But the more useful question is not who is responsible for enforcing HIPAA in Washington. It is what any of them would find if they looked at your practice tomorrow.
Would your risk analysis be current? Could you produce training records? Would every vendor agreement be signed? Would the messages your front desk sent this week hold up under the Security Rule?
Those questions share one thread. Each is answered before an investigation starts, not during one. The practices that come through enforcement well are rarely the ones with the best lawyers. They are the ones with the best habits.
Communication is where habits show up most. It happens hundreds of times a day and rarely gets a second look. Reminders, forms, billing messages, and follow-ups all carry patient data through channels that either meet the standard or quietly do not.
That is a solvable problem. See how Curogram supports HIPAA-compliant patient communication by booking a demo with our team. Find out what secure texting, forms, and telemedicine look like when they run alongside the EMR you already use.
Frequently Asked Questions
Multiple federal and state entities enforce HIPAA. The primary enforcer for the Privacy, Security, and Breach Notification Rules is the Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services (HHS). State Attorneys General also have authority to enforce HIPAA through civil actions. The Department of Justice (DOJ) handles criminal HIPAA violations. Additionally, the Centers for Medicare & Medicaid Services (CMS) enforces specific HIPAA rules related to transactions and code sets. Understanding what agency enforces HIPAA involves recognizing these different players.
HIPAA compliance is mandatory for two main groups: Covered Entities (which include health plans, healthcare clearinghouses, and healthcare providers who conduct certain electronic transactions) and their Business Associates (individuals or organizations that perform functions or activities on behalf of, or provide services to, a Covered Entity involving the use or disclosure of Protected Health Information - PHI). Subcontractors of Business Associates who handle PHI must also comply. Ultimately, both organizations and their workforce members are responsible for ensuring compliance with HIPAA rules applicable to their roles.
The HIPAA Security Rule is a national standard specifically for the protection of electronic Protected Health Information (ePHI). It requires Covered Entities and Business Associates to implement reasonable and appropriate administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of ePHI they create, receive, maintain, or transmit. This includes measures like access controls, encryption, risk analysis, and workforce training. Knowing the rule helps understand the duties of the person who is responsible for enforcing the HIPAA Security Rule internally.
Yes. Federal and state authorities act on their own. A settlement with one does not close the door on the other. Comstar paid OCR $75,000, then paid two state attorneys general $515,000 for the same 2022 attack.
The clock starts the day you discover it. Affected patients must be told without unreasonable delay, and no later than 60 days from discovery. Breaches touching 500 or more people must also be reported to HHS within that same 60 days, along with notice to prominent local media. Smaller breaches are logged and reported to HHS once a year, within 60 days of the end of the calendar year.
💡 Standard SMS is not HIPAA compliant on its own. Regular texts are not encrypted, have no access controls, and leave no audit trail. Sending...
💡 HIPAA compliance for conversational AI means applying the Security Rule's administrative, physical, and technical safeguards to any chatbot,...
The Health Insurance Portability and Accountability Act was enacted in 1996 to ensure the security of patient health records and other vital...