The Office for Civil Rights (OCR) is a department within the United States Department of Health and Human Services (HHS). It enforces federal civil rights laws that prohibit discrimination based on race, color, national origin, disability, age and sex in programs and activities that receive federal financial help from HHS.
This includes enforcing the Health Insurance Portability and Accountability Act (HIPAA), which sets standards for protecting certain health information. The OCR also provides technical guidance to help covered entities comply with these laws and regulations.
The OCR enforces HIPAA by investigating complaints and conducting compliance reviews to ensure that covered entities, such as healthcare providers and insurance companies, comply with HIPAA regulations. If the OCR finds that a covered entity has violated HIPAA, it can take a number of enforcement actions, including:
The specific enforcement action that the OCR takes will depend on the severity of the violation and the covered entity's history of compliance with HIPAA.
There are two categories of HIPAA violations: civil and criminal.
Civil HIPAA violations can result in fines ranging from $100 to $50,000 per violation, with a maximum fine of $1.5 million per year for multiple violations of the same requirement.
Criminal HIPAA violations can result in much more severe fines and prison sentences. For example, obtaining or disclosing individually identifiable health information with the intent to sell, transfer or use it for personal gain is a criminal HIPAA violation. It can result in a fine of up to $50,000 and up to one year in prison.
Other criminal HIPAA violations, such as obtaining or disclosing individually identifiable health information under false pretenses, can result in fines of up to $100,000 and up to five years in prison.
It's important to note that these are maximum fines and prison sentences and that the actual penalties imposed by the courts may be lower. The specific penalty will depend on the circumstances of the case.
If you suspect a HIPAA breach, you can report it to the OCR by:
It's important to note that the OCR only has jurisdiction to investigate HIPAA violations by covered entities, such as healthcare providers, health plans and healthcare clearinghouses. If you want to report a HIPAA violation by a business associate of a covered entity, it's best to contact the covered entity directly.