Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

  • About HHS
  • Programs & Services
  • Grants & Contracts
  • Laws & Regulations
  • Radical Transparency
  • HIPAA for Individuals
  • Filing a Complaint
  • HIPAA for Professionals
  • Newsroom
Breadcrumb
  1. HHS
  2. HIPAA Home
  3. Filing a HIPAA Complaint
  4. HIPAA What to Expect
  • Filing a Complaint
    • Complaint Process
    • File a Complaint Online
    • What to Expect
    • File a Patient Safety Confidentiality Complaint

What to Expect

You may file a health information privacy and security complaint with the Office for Civil Rights (OCR) if you feel a covered entity or business associate violated your (or someone else’s) health information privacy rights or committed another violation of the Privacy, Security or Breach Notification Rules.

How OCR Investigates a Health Information Privacy and Security Complaint

OCR carefully reviews all health information privacy and security complaints. Under the law, OCR only may take action on complaints if:

  • Your rights were violated by a covered entity or business associate
  • You file your complaint within 180 days of the violation

What Happens After the Investigation

At the end of the investigation, OCR issues a letter describing the resolution of the investigation.

If OCR determines that a covered entity or business associate may not have complied with the HIPAA Rules, that entity or business associate must:

  • Voluntarily comply with the HIPAA Rules
  • Take corrective action
  • Agree to a settlement

If the covered entity or business associate does not take satisfactory action to resolve the matter, OCR may decide to impose civil money penalties (CMPs) on the covered entity. If CMPs are imposed, the covered entity may request a hearing in which an HHS administrative law judge decides if the penalties are supported by the evidence in the case.

Content created by Office for Civil Rights (OCR)
Content last reviewed November 20, 2023
Back to top

Subscribe to Email Updates

Receive the latest updates from the Secretary and Press Releases.

Subscribe
  • Contact HHS
  • Careers
  • HHS FAQs
  • Nondiscrimination Notice
  • Press Room
  • HHS Archive
  • Accessibility Statement
  • Privacy Policy
  • Budget/Performance
  • Inspector General
  • Web Site Disclaimers
  • EEO/No Fear Act
  • FOIA
  • The White House
  • USA.gov
  • Vulnerability Disclosure Policy
HHS Logo

HHS Headquarters

200 Independence Avenue, S.W.
Washington, D.C. 20201
Toll Free Call Center: 1-877-696-6775​

Follow HHS

Follow Secretary Kennedy