Pabau GO app

The new Pabau GO is heredownload on the App Store

Download on the App Store
Book a demo Book a demo
Compliance and security

How to successfully handle a HIPAA violation investigation

Avatar photo Maja Popovska
Last Updated: July 28, 2026
Reviewed by: Avatar photo Lucy Galloway
Key takeaways

Key takeaways

The Office for Civil Rights (OCR), part of the US Department of Health and Human Services, investigates HIPAA violations and enforces the Privacy and Security Rules.

Investigations are typically triggered by a patient complaint, a breach affecting 500 or more people, or a random OCR compliance audit.

Key deadlines to track: a 60-day window to report a breach, 180 days for patients to file a complaint, and 30 days to pay a fine after signing a resolution agreement.

Violations get resolved once your practice signs a Resolution Agreement with the OCR, which sets out any corrective actions and penalties.

In the middle of a HIPAA investigation is the last place you want your practice to be.

As a federal law, HIPAA sets rules that healthcare organizations, including your practice, must follow. Compliance violations, such as data breaches, can still happen because of internal or external factors.

If a violation is severe enough, or you don’t address it, it can trigger a formal investigation at your practice. The outcome can affect your business, your patient trust, and your finances through fines.

Read our guide on how to handle a HIPAA violation investigation and how to minimize its impact on your practice.

Or, get started by downloading our free step-by-step HIPAA compliance checklist.

Who investigates HIPAA violations?

HIPAA violation investigations are conducted by the Office for Civil Rights (OCR). The OCR works directly under the US Department of Health and Human Services (HHS) and mainly focuses on enforcing the HIPAA Privacy and Security Rules.

The OCR also proposes penalties and corrective action plans that your practice should implement if a violation was proven. It’s then your legal obligation to inspect and act upon any detected HIPAA violation and resolve it within a given deadline.

What types of HIPAA violations will the OCR investigate?

Not every HIPAA violation type is subject to an investigation by the OCR. For the OCR to launch a HIPAA investigation against you, there needs to be a larger violation.

A formal investigation by the OCR will only happen in these instances:

1. When a patient files a privacy violation complaint

This is the most common reason the OCR will investigate your practice for a HIPAA violation. The same can happen if a patient’s personal or treatment information is breached, regardless of whether the breach was your fault.

If a patient was denied access to their medical records, for example, they have the right to file a privacy complaint against you. A patient doesn’t have to file a formal complaint if you prove that you resolved the violation. But if a patient is still dissatisfied with the outcome, they can turn to the OCR.

To avoid a patient filing a violation complaint, it’s necessary to understand the rights your patients have under HIPAA.

2. When the breach affects 500+ individuals

Breaches come in all shapes and sizes, and this applies to every practice type, including medical spas and physical therapy practices. A smaller breach, one that affects under 500 people, can usually be handled on your own, without needing an OCR investigation.

However, you must report any breach that affects over 500 people to the OCR, so they can investigate further and help you address the threat.

When reporting a breach, you need to submit supporting documentation on the detected breach, alongside proof that you notified your patients about the issue.

3. When the OCR performs audits

The OCR has a right to perform compliance checks without giving a heads-up. This helps them ensure that healthcare practices comply with all HIPAA requirements at all times.

Sometimes, the OCR decides to perform a completely random audit of your HIPAA compliance as a regular practice, to confirm that you fulfill all HIPAA requirements. Other times, the OCR will have a specific reason to launch the investigation.

A deliberate HIPAA audit by the OCR might be triggered if you:

  • Had a recent breach of PHI
  • Experienced ransomware or malware incidents
  • Misplaced or lost any electronic devices that store PHI
  • Didn’t dispose of paper PHI (by using shredding services or locked trash bins)
  • Had office burglaries that might have threatened the safety of PHI

How does the OCR handle HIPAA violation complaints?

The OCR might accept a patient’s HIPAA violation complaint if it believes there’s enough evidence. If that happens, here’s the timeline you can expect:

  1. An investigation into the patient’s complaint is triggered.
  2. The OCR notifies you and the complainant of this process by letter.
  3. The OCR gives you enough time to submit the required documentation.
  4. The OCR needs up to 180 days to review the documentation and violation grounds.
  5. The OCR makes a final decision and lets you and the complainant know in writing.
  6. You have around a month to correct any violations or pay any imposed fines.

The OCR will mainly look into:

  • The type and volume of PHI affected by the breach
  • The security measures you implemented to protect PHI
  • Any risk analysis you performed to detect PHI threats
  • Whether your privacy policies align with HIPAA requirements
  • Any breach response strategies you have prepared
  • Any employee compliance training you carried out
  • Relevant paperwork that supports your HIPAA compliance
  • Any Business Associate Agreement you signed
  • Your business associates’ adherence to HIPAA compliance

Fines for HIPAA violations

If you fail to meet the changes required by the OCR, or ignore them, they might decide to give you a higher fine or even take legal action. These fines vary in amount, depending on the violation type and severity.

As of 2026 (adjusted annually for inflation), the OCR’s HIPAA penalty tiers are approximately:

  • Tier 1 (no knowledge): $145–$36,505.50 per violation, up to $36,505.50 per year
  • Tier 2 (reasonable cause): $1,461–$73,011 per violation, up to $146,053 per year
  • Tier 3 (willful neglect, corrected): $14,602–$73,011 per violation, up to $365,052 per year
  • Tier 4 (willful neglect, not corrected): $73,011–$2,190,294 per violation, up to $2,190,294 per year

These figures update annually, so check the latest Federal Register notice for the current-year amounts before relying on them.

hipaa violation fines

Important deadlines for HIPAA violation investigations

The OCR sets several different deadlines when investigating a HIPAA violation:

HIPAA violations
  1. 60 days to report a breach as a healthcare organization. Your practice can report a HIPAA violation to the Office for Civil Rights (OCR) within 60 days of discovering the breach. Missed deadlines may result in higher penalties if the OCR discovers the violation first.
  2. 180 days for patients to file a violation complaint. Patients have 180 days from the date of the violation, or from the date they discovered it, to file a complaint. If they miss this deadline, the OCR may not look into their complaint.
  3. 180 days for the OCR to investigate and make a decision. The OCR aims to decide on HIPAA complaints within 180 days of receiving the complaint, though this period can be extended for more complex or larger cases.
  4. 30 days to pay a violation fine. If the OCR fines you, you have 30 days to pay from the day you reach a resolution agreement. Missing this deadline lets the OCR take additional legal action to collect the fine.
  5. 10 business days to respond to an OCR audit. If the OCR runs a random audit of your HIPAA compliance, you’ll be notified and given 10 days to submit the data and documentation it requires.

The OCR doesn’t set a specific deadline for implementing its recommendations and corrective steps, but you should do it as fast as possible, usually within 30 days. The OCR may work with you to establish a reasonable timeline, depending on how serious the violation is.

How to report a detected HIPAA breach to the OCR

You’re legally obliged to report a HIPAA breach threat to the OCR if the breach has affected over 500 people. To report it, you’ll go through the following steps:

  • Enter the basic details of your practice and the person who manages IT security.
  • Summarize how the breach was discovered. This should be written by the person who discovered it.
  • Detail the nature and extent of the PHI involved.
  • Detail the unauthorized person to whom the disclosure was made.
  • Determine whether the PHI was acquired or viewed by the unauthorized person.
  • Safely store all breach documentation, in case you need to present it during another breach.

Handling a HIPAA violation complaint during an investigation

Say a patient files a formal violation complaint with the OCR. If you’ve already appointed a compliance or privacy officer, which is a HIPAA compliance requirement, you turn to them first.

Their foremost responsibility is to investigate the reason behind the violation, and its extent, before the OCR checks in with you. This process is detailed, but it needs to happen fast and error-free. Addressing the damage promptly helps you look prepared in the eyes of the OCR.

While your compliance officer handles the formal steps, you’ll also want a plan for restoring confidence once it’s resolved. Simple outreach, like well-timed thank you notes for clients, can help re-establish goodwill without discussing any protected details.

A note: if a single compliance officer can’t perform a whole internal investigation, you might need to appoint a committee of officers.

Since you need to be swift and efficient, here’s how to best handle a violation complaint so you can present yourself well before the OCR.

1. Register the complaint

First, make sure your compliance officer has processed the formal complaint, and has:

  • Added a date stamp and logged the complaint as an official record
  • Informed the patient in writing that their complaint has been received
  • Identified everyone involved in the violation
  • Inspected whether the breach was internal or external
  • Checked whether any of your policies and procedures were breached
  • Informed the patient of the findings and resolution, in writing

A HIPAA compliant CRM makes it easier to log and time-stamp every step of this process automatically.

If the officer concludes that there is no active violation, they should date-stamp the complaint as closed and inform the patient in writing. You’ll also need to submit a risk assessment to the OCR to prove that PHI wasn’t affected, alongside supporting reports. Clinical documentation software can help keep this paperwork organized and ready to submit.

2. Conduct a comprehensive risk analysis

If a violation has been detected in your electronic devices or privacy and security policies, you’ll need to perform a risk analysis to determine the source.

Some aspects to cover in your risk analysis include:

  • Assess your compliance training and access control policies
  • Review whether your data storage and transfer methods are viable
  • Evaluate physical security measures, like access controls and locked rooms
  • Inspect technical safeguards, like encryption, authentication, and network security
  • Inspect potential threats to your electronic protected health information (ePHI)
  • Review how your employees complied with HIPAA policies and procedures
  • Assess or update your business associate agreements
  • Document any detected threats and resolution recommendations
  • Collaborate with HIPAA experts for a comprehensive assessment

3. Double-check your devices

Devices like computers, laptops, and smartphones can be used to store protected patient information. Such devices can easily end up misplaced, unattended, or stolen, which puts the PHI stored on them at risk of exposure or misuse.

To spot any issues, check all devices you use, like the patient journey iPad, and see how well the data on them is protected. Good EHR security practices, like device encryption and access logging, reduce this risk.

Do you have a strong password policy? Are you using 2FA to sign in to platforms via a device? Are your folders locked? Has anyone accessed a device without authorized access to PHI? You’ll need to answer these questions for the OCR, backed by evidence.

4. Evaluate your HIPAA policies and procedures

Next, your compliance officer(s) will need to review your HIPAA policies and check whether they align with the latest regulations and updates.

HIPAA compliance changes often, so keep an eye on regulatory updates. Double-check your plan for handling emergencies in case of a breach and address any weak points in your procedures.

Every practice needs HIPAA compliance documentation prepared ahead of time, following a checklist like ours. This helps the OCR determine what aspects of your compliance were successfully covered, and what documentation might be incomplete or outdated. Solid medical decision making documentation also strengthens your position if a complaint ever escalates to a formal OCR review.

Necessary HIPAA compliance records to have ready for the OCR include reports on the usage and storage of PHI, an emergency plan for prompt incident response, and worksheets on how you implemented HIPAA’s specific rules.

This can also include signed consent forms, like an anti-wrinkle consent or chemical peel consent form.

Other examples include completed patient forms, such as a doctor’s note for work.

Billing entries such as CPT code 99383 and CPT code 11010 count as PHI too, and both need to be retained under HIPAA.

5. Understand patient rights

Patients have the right to access their health information, like treatment details, photos, and billing records. They should also be able to edit or update their information, and to give you consent before you use or share their PHI.

Patients also have the right to:

  • Know how their health information is used and disclosed
  • Request restrictions on the use and disclosure of their information
  • Receive a notice of privacy practices from healthcare providers
  • Request confidential communication methods, such as a HIPAA compliant telehealth option for appointments
  • Be informed of breaches of their health information
  • Obtain an accounting of disclosures of their health information
  • Designate individuals who can access their health information, typically through a signed HIPAA authorization form
  • File complaints with the Office for Civil Rights

At the same time, patients don’t have the right to:

  • Access medical records of other family members without their consent
  • Access certain medical records, like psychotherapy notes
  • Demand specific security measures for protecting their data
  • Refuse payment for healthcare services
  • File a lawsuit against your practice due to a HIPAA violation

Whenever you handle protected health information, you must inform patients of what they can and can’t do with their data, and let them know how their PHI is secured and handled.

6. Re-examine your compliance workforce training

If you determine that the reported HIPAA violation was the result of internal employee negligence, you need to investigate further:

  1. Check how extensive your HIPAA compliance training is, and test employees on their knowledge.
  2. Create a plan for retraining employees on HIPAA compliance, so they know how to implement HIPAA’s security, privacy, and breach notification guidelines.

If an employee was at fault for the violation

Share this with your HR department or the person who manages your employees or monitors HIPAA compliance, such as your appointed compliance officer.

It’s your practice’s responsibility to investigate which employee caused a violation, whether it was intentional or accidental, and whether they knew they were breaking HIPAA’s policies. To ensure understanding and compliance, you need to (re)train your staff on HIPAA regulations and policies.

If a business associate was responsible for the violation

Forward the complaint to them, and inform the person who filed it. But it’s ultimately your responsibility to investigate whether your business associates are at fault for the HIPAA violation in question.

A word from the experts

The best way to learn about HIPAA investigations is to ask the people who deal with them.

David D. Smith, co-founder of BladGo, maker of the BladGo handheld bladder scanner, has extensive experience in the medical industry and understands that handling a HIPAA investigation can be a complex process. He encourages practices to take action rather than stress:

“HIPAA investigations can be daunting. However, if healthcare organizations and providers adhere to HIPAA guidelines and take appropriate measures to protect patient data privacy, then there is nothing to worry about.”

He shares five steps you can take during the process:

  1. Keep calm and composed. HIPAA investigations can be intimidating and stressful, but it’s essential to cooperate with investigators and not try to hide anything. Following the rules, regulations, and laws should give you the confidence to handle an investigation.
  2. Prepare documentation. During the investigation, officials may ask for documents related to your organization’s HIPAA compliance. Being prepared with these documents beforehand, including policy manuals, security plans, training records, incident response plans, breach notification letters, and risk assessments, demonstrates your readiness.
  3. Conduct a thorough self-assessment. Before HHS investigates, review your security policies, any breaches or complaints filed, staff training records, documented risk assessments, and an evaluation of third-party vendors who handle patient data. This helps you identify and resolve vulnerabilities ahead of any fine or penalty.
  4. Comply with HIPAA and keep up with periodic training. Make sure all employees are appropriately trained on HIPAA guidelines, with sessions updated frequently so staff stay current on what to do if a HIPAA proceeding arises. This periodic refresh helps prevent complaints, breaches, and costly investigations.
  5. Engage professional HIPAA counsel. HIPAA laws can be difficult to understand, but you don’t have to face an investigation alone. A trusted legal team with HIPAA compliance expertise can guide you through the investigation process and help you mitigate possible penalties.

How the OCR will conclude the HIPAA violation investigation

After you’re done investigating internally, your practice will have to present arguments regarding the violation incident before the OCR. The person who filed the complaint does the same. After considering what both sides have to say, the OCR reviews the information and evidence and decides.

When the OCR makes a final decision (in up to 180 days), it shares that decision with your practice and the person who filed the complaint, in writing. It will also propose a deadline by which you need to complete all suggested corrective actions. Sometimes, the OCR will even collaborate with you to resolve the issues faster.

Next, the OCR asks you to sign a Resolution Agreement. This official agreement outlines the corrective actions and penalties the OCR imposes for the violation. It’s signed by both the OCR and yourself, but not by the person who filed the complaint.

If the OCR decides to fine you for the violation, you’ll have to pay it within 30 days of receiving it. When the OCR wants a second opinion or extra review, it sends the complaint to its parent agency, the Department of Health and Human Services (HHS).

The OCR cannot act on a violation complaint if the action took place before the HIPAA Privacy Rule’s compliance date, April 14, 2003.

How Pabau supports HIPAA compliance and investigation readiness

The best way to handle a HIPAA investigation is to avoid one in the first place, by keeping robust compliance policies and processes in place from the start. One way to do this is with practice management software that supports your HIPAA compliance, like Pabau.

Pabau offers several features that support your HIPAA compliance, such as data encryption and automatic audit logs that record who accessed a patient record and when. That audit trail is exactly what the OCR asks for during an investigation, so you can hand over the documentation on request instead of piecing it together after the fact.

Digital consent forms and treatment notes also stay attached to each patient’s file inside Pabau’s practice management software, rather than sitting on a shared drive or a practitioner’s personal device, so PHI isn’t scattered across tools that are harder to secure and audit.

Keep HIPAA audit trails ready for the OCR

Pabau's data encryption and automatic audit logs record who accessed a patient record and when, so you can hand over documentation the moment the OCR asks for it.

Pabau clinic management dashboard

Conclusion

An OCR investigation moves at the OCR’s pace, not yours, so the work that protects your practice happens well before that letter arrives.

A compliance officer who already knows the process, a risk assessment that’s less than a year old, and audit logs that show exactly who touched a patient’s file will do more for your outcome than anything you scramble to produce after a complaint lands.

That’s the trade-off worth remembering: a bit of ongoing discipline now, against thousands of dollars in Tier 3 or Tier 4 penalties later if the paperwork isn’t there when the OCR asks for it.

Book a demo to see how Pabau keeps that documentation ready before an investigation ever starts.

Continue your research

Continue your research

Need to log every compliance step automatically? A HIPAA compliant CRM keeps every step of a compliance review time-stamped and easy to produce for the OCR.

Wondering what makes practice software HIPAA-ready? HIPAA compliance software breaks down the encryption, access controls, and audit logging the Privacy and Security Rules expect.

Storing PHI on shared drives or personal devices? EHR security covers the safeguards that keep patient records out of reach of anyone who shouldn’t see them.

Struggling to keep compliance paperwork organized? Clinical documentation software centralizes the records an OCR investigation will ask you to produce.

Frequently asked questions

Who investigates HIPAA violations at healthcare practices?

HIPAA violation investigations are conducted by the Office for Civil Rights (OCR), which operates under the US Department of Health and Human Services (HHS). The OCR is responsible for enforcing HIPAA Privacy and Security Rules and proposing penalties and corrective action plans for violations.

What can trigger a formal HIPAA violation investigation at my practice?

Severe HIPAA compliance violations, particularly data breaches caused by internal or external factors, can trigger a formal investigation if not properly addressed. The severity of the violation and the lack of immediate corrective action are key factors that may prompt the OCR to initiate an investigation.

What are the potential consequences of a HIPAA violation investigation for my practice?

A HIPAA violation investigation can result in significant financial penalties, damage to patient trust, business impact, and stress on your practice operations. The outcome of the investigation can lead to skyrocketing fines and mandatory corrective action plans that your practice must implement.

Can patients file complaints that lead to a HIPAA violation investigation?

Yes, patients can file complaints about HIPAA violations at your practice, which can trigger a formal investigation by the OCR. Taking patient complaints seriously and addressing them promptly is essential to preventing escalation to a federal investigation level.

×