Curogram Blog

Who Enforces HIPAA? Learn the Key Agencies Now

Written by Alvin Amoroso | 4/25/25, 4:00 PM
 💡 HIPAA is not enforced by one agency. The Office for Civil Rights (OCR), part of the U.S. Department of Health and Human Services, handles the Privacy Rule, the Security Rule, and the Breach Notification Rule. CMS covers billing transaction standards.

State attorneys general can also sue on behalf of residents. The Department of Justice steps in when a violation is a crime, such as stealing or selling patient records. One breach can pull in more than one of them at the same time.

Inside a practice, a Privacy Officer and a Security Officer carry the daily work. In 2026, civil fines start at $145 per violation. The yearly cap tops out at $2,190,294.

In June 2025, an ambulance billing company named Comstar paid $75,000 to federal regulators. A ransomware attack had exposed the health records of nearly 586,000 people. Investigators found the company had never run a proper security risk analysis.

That should have closed the file.

It didn't. Seven months later, Comstar agreed to pay another $515,000. This time the money went to the attorneys general of Massachusetts and Connecticut. Same breach, same records, a second bill almost seven times bigger than the first.

Here is what that case really shows. HIPAA does not have one enforcer at one door. It has several. They work from different angles, and they do not take turns.

Most practices assume that clearing one review means the matter is closed. Then a state office opens its own file. Or the case moves to federal prosecutors.

Nothing about the rules changed. The number of people checking your work just did.

So who enforces HIPAA, and what does each body actually control? This guide walks through the whole map. You will see which agency handles most cases, which ones sit alongside it, what happens after a complaint is filed, what fines cost in 2026, and who inside your own practice carries the weight day to day.

Knowing the map is worth your time. It tells you who might call, what they will ask for, and where your real risk sits.

Four Bodies Share the Job

Ask ten office managers what agency enforces HIPAA and most will name one. That answer is close, but it is not complete.

The work is split by subject. One agency owns privacy and security. Another owns billing standards. State and criminal authorities cover the rest.

Knowing who handles what saves you from preparing for the wrong conversation.

Enforcement body What it covers Type of action
HHS Office for Civil Rights (OCR) Privacy Rule, Security Rule, Breach Notification Rule Civil and administrative
Centers for Medicare & Medicaid Services (CMS) Electronic transactions, code sets, provider identifiers Civil and administrative
State attorneys general HIPAA violations that harm state residents, plus state privacy laws Civil lawsuits
U.S. Department of Justice (DOJ) Theft, misuse, or sale of patient data Criminal charges

Now look at that last column again. Three of those four routes end in a payment. One can end in prison. That gap is why the question of who is responsible for HIPAA enforcement deserves a real answer.

The Primary Federal Authority: HHS and the Office for Civil Rights (OCR)

When asking what agency enforces HIPAA, particularly its core privacy and security components, the primary answer lies within the U.S. Department of Health and Human Services (HHS).

While HIPAA originally focused heavily on health insurance reform (Title I, largely enforced by the Department of Labor and Treasury Department), its Administrative Simplification provisions (Title II) set the stage for crucial privacy and security standards. It's important to know that HHS oversees HIPAA compliance related to these Administrative Simplification provisions.

Within HHS, the Office for Civil Rights (OCR) is the key agency delegated with the authority to enforce the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. These rules govern how CEs (like health plans, healthcare clearinghouses, and most healthcare providers) and their BAs must protect PHI.

For many practical purposes, OCR is the answer when asking what agency enforces HIPAA's privacy aspects. This agency oversees HIPAA implementation across the nation.

How OCR Enforces the Rules

OCR does not rely on one method. It works through four:

  1. Complaint investigations. Patients can file directly with OCR through its online portal. The office receives thousands of complaints a year. Staff screen each one, then open a formal case where the facts warrant it.
  2. Compliance reviews and audits. OCR can examine a practice with no complaint at all. It ran a pilot audit program in 2011 and 2012, then a wider round in 2016 and 2017. No large program has run since, but the authority never went away. Audit-ready is a standing state, not a seasonal one.
  3. Guidance and technical help. Many cases come from confusion, not neglect. When OCR finds an honest gap, it often explains the rule and helps the practice fix it. No fine follows. This is the most common outcome by a wide margin.
  4. Formal action. Serious cases end differently. OCR may offer a resolution agreement, which pairs a payment with a corrective action plan. If no deal is reached, it can issue a fine directly.

The Three Rules Behind Most Investigations

The Privacy Rule protects patient data in every form. That covers electronic files, paper charts, and spoken conversations. It limits what you can share without patient consent. It also gives patients rights over their own records, including the right to a copy.

The Security Rule is narrower. It applies only to electronic protected health information, or ePHI. It asks for safeguards in three areas: how you manage people, how you secure the space, and how you set up your technology.

Wondering who is responsible for enforcing the HIPAA Security Rule at the federal level? That job belongs to OCR.

The Breach Notification Rule starts a clock. After a breach of unsecured data, you must tell affected patients and HHS. Large breaches also require notice to the media. Vendors must tell the practice they serve.

A Note on CMS

While OCR handles the Privacy, Security, and Breach Notification Rules, another HHS agency, the Centers for Medicare & Medicaid Services (CMS), enforces HIPAA's Administrative Simplification Rules related to standardized electronic transactions, code sets, and unique identifiers (like the National Provider Identifier - NPI). Complaints regarding these specific transaction standards are often handled through CMS's Administrative Simplification Enforcement Testing Tool (ASETT).

So, while OCR is a major player, CMS also contributes to the picture of who is responsible for enforcing HIPAA.

Expanding the Enforcement Net: State Attorneys General and the Department of Justice

While OCR is the primary enforcer for privacy and security, they are not the only government body who is responsible for HIPAA enforcement. Two other key players significantly impact the enforcement landscape:

State Attorneys General

The HITECH Act of 2009 gave state attorneys general the power to sue in federal court. They act on behalf of residents whose HIPAA rights were violated. That power runs alongside OCR's, not beneath it.

A state attorney general can open a case on their own. They only have to give HHS written notice before filing suit. They can seek court orders that force a company to change how it works. They can also seek money for the state or for the residents who were harmed.

The Comstar case from the top of this article is the clearest recent example. Federal regulators closed their file for $75,000 in June 2025. Massachusetts and Connecticut filed a joint judgment in January 2026 for $515,000.

That brings the total to $590,000. About 87% of it came from the state side. For your team, the takeaway is blunt. Settling with one authority does not release you from the others.

The Department of Justice

Criminal cases go somewhere else. Under federal law, knowingly taking or sharing patient data in violation of HIPAA is a crime. The DOJ handles those cases. They usually arrive after OCR refers evidence of intent.

These are not paperwork problems. They involve stealing patient data for identity theft, selling patient lists, or snooping out of malice. Penalties rise with intent:

Level of intent Maximum fine Maximum prison term
Knowing violation $50,000 1 year
Under false pretenses $100,000 5 years
For personal gain or malice $250,000 10 years

Charges are rare, but they are real. A dental receptionist who stole patient data drew two to six years. A hospital employee drew three years. A Florida clinic worker drew four.

In practice, this is why access controls and offboarding steps matter as much as your written policies.

What Happens After a Complaint Lands

Enforcement rarely looks like a raid. It looks like a letter. Knowing the sequence trades vague dread for a clear checklist.

  1. Something starts a review. A patient complaint, your own breach report, an audit, or a news story can all trigger one.
  2. OCR screens it. Staff confirm that HIPAA applies, that the timing works, and that the claim describes a real violation. Many complaints close right here.
  3. The case opens. OCR asks for records. It reviews your policies and training logs, interviews staff, and sometimes visits the site. Your risk analysis is almost always requested first.
  4. A resolution follows. Cases end in one of five ways: no violation found, informal guidance, a corrective action plan, a settlement with a payment, or a direct fine.

Where you land depends on what you can show. Practices with current records and a recent risk analysis usually get guidance. Practices with nothing on file usually do not.

What HIPAA Violations Cost in 2026

Fines carry real numbers, and those numbers moved recently. HHS applied its inflation update on January 28, 2026.

First, one distinction worth keeping straight. A violation is any failure to follow the rules. A breach is a narrower thing: unsecured patient data was used or shared improperly, and that put its privacy at risk.

Every breach is a violation. Not every violation is a breach.

Civil fines are tiered. The tier depends on how much you knew and how fast you acted. The table below reflects the caps OCR applies under its 2019 enforcement discretion notice.

Tier Level of fault Minimum per violation Maximum per violation Annual cap
1 Lack of knowledge $145 $36,506 $36,506
2 Reasonable cause $1,461 $73,011 $146,053
3 Willful neglect, fixed within 30 days $14,602 $73,011 $365,052
4 Willful neglect, not fixed $73,011 $2,190,294 $2,190,294

Here is what the tiers really mean. The gap between Tier 1 and Tier 4 is not about the mistake. It is about what you did after you found it.

Take a practice with 500 records exposed through one open vulnerability. At Tier 1, the yearly cap holds the damage near $36,506. Move the same incident to Tier 4 because nobody fixed the problem, and the ceiling jumps to $2,190,294. That is roughly 60 times more, driven entirely by the response.

Those caps also apply per violation type. A practice found at fault in four areas can face four separate caps in one year.

Money is not the only cost. Corrective action plans often run for years and require outside consultants. Breach notices become public. Staff time shifts from patients to paperwork.

Damage to your name tends to outlast the fine. And state penalties can stack on top of federal ones, as Comstar learned.

Quick Takeaway: One Failure Shows Up in Almost Every Case

Look at OCR's actions from 2025 and 2026 and a pattern appears fast. Nearly every settlement names the same root cause: no thorough, current security risk analysis.

It appears in the $552,250 OSF Healthcare settlement. It appears in the $375,000 Assured Imaging settlement, the $320,000 Axia Women's Health settlement, and the $5,000 Vision Upright MRI settlement. Different sizes, same finding.

Two things follow. First, the risk analysis is the highest-leverage document you own. Second, small practices are not invisible. Even a $5,000 settlement comes with a corrective action plan and a public record.

Who Owns HIPAA Compliance Inside Your Practice

Outside agencies decide the fines. Your team decides whether there is anything to fine. So who is responsible for implementing and monitoring the HIPAA rules on a normal Tuesday? Two named roles, backed by everyone else.

The Privacy Officer

The Privacy Rule at §164.530 says you must name one. This person writes and updates privacy policies, runs staff training, handles patient record requests, manages complaints, and takes the call if OCR reaches out.

The Security Officer

The Security Rule at §164.308 calls for its own role. Their scope is ePHI:

  • Running and updating the security risk analysis
  • Managing access controls and user permissions
  • Responding to security incidents
  • Overseeing encryption and other technical safeguards
  • Making sure vendor agreements are signed and current

Inside your walls, this is the person who is responsible for enforcing the HIPAA Security Rule.

How the Roles Fit Together

In smaller practices, one person often wears both hats. That works, as long as the role is written down and the person has real time and real authority. Bigger groups usually split the two.

Either setup is fine. Fuzzy ownership is not. Gaps form where nobody is clearly in charge.


Everyone Else

Compliance does not stop at two job titles. Every staff member who touches patient data shares the load. That also answers a related question: who is responsible for complying with HIPAA?

The short list is covered entities, their vendors, any subcontractors who handle patient data, and the staff inside each of them.

That includes daily communication habits. Reminders, billing messages, and follow-up texts all move through channels that either meet the Security Rule or do not.

Standard SMS is not encrypted. A general reminder is fine. A message that names a condition or a test result is not.

Practices that handle this well use a platform built for the rule. They do not ask staff to judge it message by message. Curogram works alongside your EMR to keep two-way texting, patient forms, telemedicine, and payment requests inside a HIPAA-compliant space. The safe path becomes the easy one.

Three Scenarios That Show Enforcement in Action

Rules stay abstract until you watch them land. The scenarios below are composites, drawn from patterns in published enforcement actions.

A Clinic That Found Its Own Gaps

A multi-provider clinic runs an internal review. It finds that its risk analysis is four years out of date. Rather than wait, the practice hires a consultant, writes a fix-it plan, and reports the findings on its own.

OCR responds with guidance and no fine. The proactive record is what makes the difference.

A Hospital That Waited

Ransomware hits a regional hospital through a flaw that went unpatched for over a year. The hospital reports the breach and OCR opens a case.

Staff had flagged the risk internally and nobody acted. That pushes the case into willful neglect. The result is a seven-figure settlement and a corrective action plan that runs for years.

Employees Who Looked Too Closely

Hospital staff open the records of a high-profile patient they never treated. An audit log review catches it. The hospital fires those employees and files a breach report.

OCR requires a corrective action plan for access monitoring. Separately, affected patients complain to their state attorney general, who files a civil suit. It ends in damages and stricter state rules. One incident, two enforcers, two sets of obligations.


Compliance Is Shared, and So Is the Risk

So, who enforces HIPAA? Not one office, and not in one way.

OCR sits at the center. It handles the Privacy, Security, and Breach Notification Rules, and it closes most cases with guidance rather than fines. Around it sit CMS, state attorneys general, and the DOJ.

Any one of them can open a file. More than one can open a file on the same event.

But the more useful question is not who is responsible for enforcing HIPAA in Washington. It is what any of them would find if they looked at your practice tomorrow.

Would your risk analysis be current? Could you produce training records? Would every vendor agreement be signed? Would the messages your front desk sent this week hold up under the Security Rule?

Those questions share one thread. Each is answered before an investigation starts, not during one. The practices that come through enforcement well are rarely the ones with the best lawyers. They are the ones with the best habits.

Communication is where habits show up most. It happens hundreds of times a day and rarely gets a second look. Reminders, forms, billing messages, and follow-ups all carry patient data through channels that either meet the standard or quietly do not.

That is a solvable problem. See how Curogram supports HIPAA-compliant patient communication by booking a demo with our team. Find out what secure texting, forms, and telemedicine look like when they run alongside the EMR you already use.

 

Frequently Asked Questions