Ask ten practice owners what a HIPAA violation looks like and nine will describe a hacker. Someone in a hoodie, a ransom note on a screen, a server room at 2 a.m. That picture is not wrong, exactly. It is just badly incomplete, and the incompleteness is what costs money.
I have spent more than twenty five years in network security, fifteen of them running a managed IT firm that supports medical and dental practices, law firms, and small businesses across Central Florida. When I read through the federal enforcement record, I do not mostly see sophisticated attacks. I see specimen containers in a parking lot dumpster. I see a login nobody switched off after someone quit. I see a front desk answering a one star review with clinical detail. I see a records request sitting in a folder for four months because nobody owned it.
Those are the everyday mistakes. Each one is boring. Each one is also a documented federal enforcement action with a dollar figure attached. What follows is what actually counts as a violation, what the HHS Office for Civil Rights has actually penalized, and the specific fix for each. It applies to covered entities and business associates alike.
A violation and a breach are not the same thing
The two words get used interchangeably and carry different obligations.
A violation is any failure to comply with the HIPAA Privacy, Security, or Breach Notification Rules. Most violations never involve a breach at all. Missing a business associate agreement is a violation. Overcharging a patient for a copy of their own chart is a violation. Never conducting a risk analysis is a violation. No data has to leave the building for any of those.
A breach is narrower. Under 45 CFR 164.402 it is the acquisition, access, use, or disclosure of PHI in a manner the Privacy Rule does not permit, which compromises the security or privacy of that information. The presumption runs against you: any impermissible use or disclosure is presumed to be a breach unless you can demonstrate a low probability of compromise through a documented four factor assessment.
Three narrow exceptions apply, and they are worth memorizing:
- Unintentional acquisition, access, or use by a workforce member acting in good faith and within the scope of their authority, with no further impermissible use.
- Inadvertent disclosure between two people who are each authorized to access PHI at the same organization, with no further impermissible use.
- Disclosure where you hold a good faith belief the unauthorized recipient could not reasonably have retained the information.
Notice what is not on that list. An employee who looks up a neighbor’s chart out of curiosity is neither acting unintentionally nor within the scope of their authority. Snooping is a breach.
What a violation costs in 2026
HHS published the current civil monetary penalty amounts in the Federal Register on January 28, 2026. They apply to penalties assessed on or after that date for violations occurring on or after November 2, 2015.
| Tier | Culpability | Minimum per violation | Maximum per violation | Annual cap, identical provision |
|---|---|---|---|---|
| Tier 1 | Did not know, and could not reasonably have known | $145 | $73,011 | $2,190,294 |
| Tier 2 | Reasonable cause, short of willful neglect | $1,461 | $73,011 | $2,190,294 |
| Tier 3 | Willful neglect, corrected within 30 days | $14,602 | $73,011 | $2,190,294 |
| Tier 4 | Willful neglect, not corrected | $73,011 | $2,190,294 | $2,190,294 |
Two caveats matter more than the table. First, since April 2019 OCR has exercised enforcement discretion and applied lower annual caps to the first three tiers than the published regulation requires. That posture is not codified, so treat the published caps as the ceiling and the discretion as a courtesy.
Second, and more usefully: OCR resolves the large majority of its investigations with no financial penalty at all, through voluntary compliance, technical assistance, or a corrective action plan. The realistic downside for a small practice is rarely a seven figure number. It is two years of federal monitoring, the professional hours to survive it, staff time pulled off patient care, and the notification letters. That is the cost most owners never price.
I am not going to tell you one mistake will end your practice. That is the kind of scare marketing I dislike in my own industry. What I will tell you is that every item below is cheap to prevent and tedious to clean up.
The everyday mistakes, and the fix for each
1. Sitting on a patient’s request for their own records
The right of access gives you 30 days, one 30 day written extension, and a reasonable cost based fee. OCR launched a dedicated enforcement initiative in 2019 and it has produced dozens of actions, most of them against small practices.
In 2025, Oregon Health and Science University drew a $200,000 civil monetary penalty over one patient’s records and Concentra settled a single access complaint for $112,500. Earlier years are full of solo dentists and small specialty groups at $5,000, $25,000, and $70,000. The facts are almost always identical: the patient asked, nobody owned the task, the clock ran out.
The fix: name one person who owns records requests, give them a logged queue with a date stamp on intake, and set an internal deadline of 15 days. If you cannot meet 30, send the written extension. The extension is free. Silence is what gets penalized.
2. Posting a patient success story, or answering a bad review
In September 2025, OCR settled with Cadia Healthcare Facilities, five Delaware providers, for $182,000. They had published patient names, photographs, and details of condition and recovery as success stories on their public websites without valid written authorizations. One complaint turned into 150 patients, a two year corrective action plan, training that explicitly covered marketing staff, and breach notices to every person affected.
Review responses are the same exposure in a smaller package. New Vision Dental settled for $23,000 over PHI in Yelp replies and Elite Dental Associates for $10,000 over a social media post. A practice that answers a one star review by mentioning three visits and an unpaid balance has disclosed treatment and payment information publicly. Confirming that someone is a patient at all is a disclosure.
The fix: nothing patient related gets posted without a signed authorization on file, and every review gets a scripted reply that acknowledges nothing beyond an invitation to call the office directly. Train the marketing vendor on it too, because their hands are on the account and their instinct is to rebut.
3. Putting PHI in the regular trash
New England Dermatology and Laser Center paid $300,640 after empty specimen containers went into a dumpster in the practice parking lot. The labels carried patient names, dates of birth, collection dates, and the provider who took the sample, and the breach report covered 58,106 patients. What made it expensive was the follow up answer: this had been standard procedure since 2011. A single lapse is an incident. A decade of it is a pattern, and OCR prices patterns differently.
The fix: locked shred bins in every room that generates paper, a shredding vendor that issues certificates, and a written procedure covering labels, wristbands, specimen containers, prescription bottles, and imaging film, not just charts. Sanitize or destroy drives before anything leaves the building, including the one inside the leased copier.
4. Leaving a departed employee’s access switched on
BayCare Health System settled for $800,000 in 2025 on the strength of one patient complaint. After a hospital visit she was contacted by a stranger holding photographs of her printed records and a video of someone scrolling her chart. The credentials belonged to a former non clinical staff member at an affiliated physician practice that had access for continuity of care. OCR cited insufficient controls against improper credential use and insufficient review of information system activity. Gulf Coast Pain Consultants drew a $1,190,000 civil monetary penalty in 2024 for a related cluster that included failure to terminate access rights.
The fix: an offboarding checklist that runs the same day, every time, with no exception for part timers, contractors, or people who left on excellent terms. EHR, email, VPN, remote access, practice management, imaging, clearinghouse and payer portals, shared passwords, keys, badges. A second person signs off, and you keep the signed sheet, because that is the evidence you will want two years from now. We went deeper on the mechanics of this in Microsoft 365 and Google Workspace Management: Why the Employee Lifecycle Is Where It Actually Breaks.
5. Giving everyone access to everything
The minimum necessary standard says workforce members should reach only the PHI their job requires. Most small practices break it on go live day, because the fastest way to configure an EHR is to give everyone the same role and move on. It is also the failure that turns one curious employee into a reportable event. If your billing coordinator can pull any chart, an audit log will not prevent the disclosure. It only tells you afterward, assuming somebody reads it.
The fix: role based access, reviewed annually and at every role change, then audit logging that is actually reviewed on a schedule. Failure to review records of information system activity is cited repeatedly in OCR settlements. It is an explicit Security Rule requirement, not a maturity upgrade.
6. Never conducting a real risk analysis
This is the most commonly cited Security Rule failure in OCR investigations and, since 2024, the subject of a dedicated enforcement initiative. Scan the 2025 and 2026 settlement lists and risk analysis failure appears over and over, at $5,000, $10,000, $25,000, $75,000, $90,000, $175,000, $250,000, and $350,000. Several of those were small practices.
One clarification, because this is widely misunderstood. A vendor security questionnaire is not a risk analysis. Neither is a penetration test, a vulnerability scan, or a checklist a software company handed you. It is an accurate, thorough, documented, organization wide assessment of the risks to all the ePHI you create, receive, maintain, or transmit. OCR has signaled the initiative expands in 2026 to cover risk management, meaning it will want evidence that identified risks were actually reduced.
The fix: a documented risk analysis, refreshed annually and after any material change such as a new EHR, a new location, or a shift to remote work, paired with a written remediation plan and dated evidence of what you fixed. The remediation record is the half most practices skip and the half OCR asks for. This is the same argument we made in HIPAA Compliance Is Not a Binder.
7. No business associate agreement, or one nobody ever collected
Providence Medical Institute settled for $240,000 in 2024 over Security Rule failures that included a business associate agreement issue. The Center for Children’s Digestive Health paid $31,000 in 2017 for the absence of a BAA alone, with no breach involved. The gap in a small practice is always the same. The EHR has a BAA because the vendor sent one at signup. The shredding company, billing service, answering service, cloud backup, IT provider, marketing agency with a login to the shared inbox, and the copier leasing company with a drive inside the machine do not.
The fix: a vendor inventory, a flag on every vendor that creates, receives, maintains, or transmits PHI for you, and a signed BAA for each, re-verified at renewal. A BAA allocates obligations, it does not transfer them, so a vendor’s compliance program never becomes yours. More on running that inventory in The Vendor Nobody Owns.
8. Sending PHI to the wrong person
Misdirected email and fax is the most common accidental disclosure in a small office. Autocomplete drops the wrong Jennifer into the To field. A fax reaches a number that used to belong to a referring office. Whether it is reportable depends on the four factor assessment. Sometimes an exception applies, but frequently it does not, particularly when the recipient sits outside the organization.
The fix: disable autocomplete for external recipients or add a confirmation prompt, use a secure portal rather than plain email for anything clinical, verify fax numbers annually, and encrypt. Encryption is an addressable specification rather than a flat requirement, but PHI encrypted to the Secretary’s standard is not unsecured PHI, and the notification obligation does not attach to it. That is the strongest practical argument for encryption there is, and we laid out the mechanics in The Email You Send Is the Risk You Forget.
9. Talking about patients where patients can hear
Waiting room conversations, hallway handoffs, a check in monitor angled toward the line, a printer tray in a public corridor. HIPAA does permit incidental disclosures that occur as a byproduct of an otherwise permitted use, provided you have applied reasonable safeguards and the minimum necessary standard. The catch is how much work the word reasonable is doing in that sentence, and most offices have never evaluated theirs.
The fix: walk your own lobby at 9 a.m. on a Monday and sit where a patient sits. Then move the monitor, add a privacy filter, lower the voices, relocate the printer, and write down what you changed and when. The written record is how you demonstrate the safeguards were reasonable.
10. Treating the breach clock as a suggestion
Once a breach of unsecured PHI is discovered, individual notice is due without unreasonable delay and no later than 60 days. Breaches affecting 500 or more people also require notice to HHS and to prominent media in that window. Smaller breaches are logged and submitted to HHS annually within 60 days of year end. Discovery means the first day you knew, or would have known through reasonable diligence, so the clock can start before anybody tells you. Presence Health paid $475,000 in 2017 in the first OCR settlement built on untimely notification, and recent settlements including OSF Healthcare System at $552,250 and PIH Health at $600,000 cite notification failures stacked on the underlying security problems.
The fix: an incident response plan with named roles and the 60 day date calculated on day one, plus a documented four factor assessment for every incident, including the ones you conclude are not reportable. The documentation requirement applies either way, and the retention period is six years.
What is not a HIPAA violation
Confusion runs the other direction too, and these myths burn staff energy that belongs on the real risks.
- A patient telling their own story is not a violation. HIPAA binds covered entities and business associates, not patients.
- Most employers are not covered entities. An employer asking for a doctor’s note is generally not a HIPAA issue, though the ADA, FMLA, and state law may have plenty to say.
- Sign in sheets and calling a patient by name in the waiting room are permitted, as long as they do not reveal the reason for the visit.
- Sharing PHI with another provider for treatment purposes does not require a signed authorization.
- Appointment reminders by voicemail or mail are permitted, subject to minimum necessary and any confidential communication request the patient has made.
The honest limitations
Everything above reduces risk. None of it eliminates risk, and I would rather say so than sell certainty I cannot deliver.
- Policies do not change behavior. A signed acknowledgment is evidence for an investigator, not a control. The practices that stay clean are the ones where a manager enforces the rule on a Tuesday afternoon when nobody is watching. We argued the same point about what OCR and OSHA inspectors actually ask for.
- Role based access cannot stop misuse by someone with legitimate need to know. It narrows the blast radius and produces a log. That is all it does.
- Encryption protects data at rest and in transit. It does nothing about an authenticated user doing the wrong thing, which describes most of the incidents on this list.
- A risk analysis does not make you secure. It tells you where you stand. Remediation is where the value lives, and it is the part most practices defer to next quarter, repeatedly.
HIPAA compliance is also not security. It is a floor, and a twenty year old floor at that. The proposed Security Rule overhaul published January 6, 2025 would raise it substantially, with mandatory annual risk assessments, encryption, multifactor authentication, and vulnerability scanning. That rulemaking has since moved to the long term actions list with a July 2027 target, and those dates are estimates rather than deadlines. Do not plan around waiting for it, a point we made at length in The HIPAA Security Rule Update Slipped to 2027. The current rule is fully enforceable today.
Where I have a stake in this
I run a managed IT and security firm. We sell to medical and dental practices, and several of the fixes above are things we get paid to implement: access reviews, audit log monitoring, offboarding workflows, encryption, backup and recovery, and technical support for risk analysis. Read the article with that in mind.
My self interested reason for writing it anyway is simple. Practices without these basics generate expensive, chaotic, largely unbillable emergencies, and the worst of them open with a call about a letter from OCR. I would rather do the preventive work than the cleanup. That preference is not noble. It is operational, and it happens to line up with yours.
I will also say what an MSP cannot do. We cannot serve as your privacy officer, draft your authorizations, or decide whether an incident is legally reportable, and you should be suspicious of any vendor who offers to. That work belongs to your compliance officer and your healthcare attorney. Anyone selling HIPAA compliance in a box is selling a technical subset and calling it the whole thing.
A reasonable place to start
Pick three items from this list for the current quarter. The offboarding checklist, the business associate inventory, and a single owner for records requests are cheapest to implement and close the most common gaps. If you do not have a current documented risk analysis, make that next quarter’s project.
If you want a second set of eyes on the technical side, where your ePHI actually lives, who can reach it, and whether anyone is reviewing the logs, that is a conversation I have most weeks with practice owners in Central Florida. Call us at (407) 720-6540 and we can talk through where you stand and what is worth doing first. No pitch required.
Frequently asked questions
What is considered a HIPAA violation?
Any failure to comply with the HIPAA Privacy, Security, or Breach Notification Rules. That includes things with no data loss at all, such as missing a business associate agreement, failing to provide a patient their records within 30 days, or never conducting a documented risk analysis. A breach is a narrower subset that involves an impermissible use or disclosure of protected health information.
Can you get fined for an accidental HIPAA violation?
Yes. The lowest penalty tier exists specifically for violations the organization did not know about and could not reasonably have known about, starting at $145 per violation. That said, OCR resolves most investigations without a financial penalty, using voluntary compliance, technical assistance, or a corrective action plan. Intent affects the tier, not whether a violation occurred.
What are the most common HIPAA violations in a small practice?
In the enforcement record the recurring ones are failure to provide timely records access, missing or incomplete risk analysis, leaving former employees’ system access active, giving all staff access to all charts, improper disposal of paper and media, posting patient information on social media or in review responses, missing business associate agreements, and late breach notification.
Is talking about a patient in the waiting room a HIPAA violation?
Not automatically. HIPAA permits incidental disclosures that happen as a byproduct of a permitted use, provided you have reasonable safeguards in place and follow the minimum necessary standard. The risk is that most offices have never evaluated whether their safeguards are reasonable, and have no written record showing they tried.
Sources
- HHS, Annual Civil Monetary Penalties Inflation Adjustment, 91 FR 3665, January 28, 2026
- 45 CFR Part 164 Subpart D, breach definition and exceptions
- OCR settlement, New England Dermatology and Laser Center, improper disposal of PHI
- OCR settlement, BayCare Health System, resolution agreement and corrective action plan
- OCR guidance, HIPAA and the disposal of protected health information
- HHS, Breach Notification Rule guidance and reporting
- HHS, HIPAA Enforcement Rule and penalty tiers
- HIPAA Security Rule NPRM, 90 FR 898, January 6, 2025
A note on figures: penalty amounts come directly from the January 28, 2026 Federal Register notice and are adjusted annually for inflation. Settlement amounts are as published by the HHS Office for Civil Rights. This article is general information about regulatory requirements and is not legal advice.



