Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

  • About HHS
  • Programs & Services
  • Grants & Contracts
  • Laws & Regulations
  • Radical Transparency
  • Big Wins
  • HIPAA for Individuals
  • Filing a Complaint
  • HIPAA for Professionals
  • Newsroom
Breadcrumb
  1. HHS
  2. HIPAA Home
  3. For Professionals
  4. HIPAA Compliance and Enforcement
  5. Reports to Congress on Privacy Rule and Security Rule Compliance
  • HIPAA for Professionals
  • Regulatory Initiatives
  • Privacy
    • Summary of the Privacy Rule
    • Guidance
    • Combined Text of All Rules
    • HIPAA Related Links
  • Security
    • Security Rule NPRM
    • Summary of the Security Rule
    • Security Guidance
    • Cyber Security Guidance
  • Breach Notification
    • Breach Reporting
    • Guidance
    • Reports to Congress
    • Regulation History
  • Compliance & Enforcement
    • Enforcement Rule
    • Enforcement Process
    • Enforcement Data
    • Resolution Agreements
    • Case Examples
    • Audit
    • Reports to Congress
    • State Attorneys General
  • Special Topics
    • HIPAA and Part 2
    • Change Healthcare Cybersecurity Incident FAQs
    • HIPAA and COVID-19
    • HIPAA and Reproductive Health
      • HIPAA and Final Rule Notice
    • HIPAA and Telehealth
    • HIPAA and FERPA
    • Research
    • Public Health
    • Emergency Response
    • Health Information Technology
    • Health Apps
  • Patient Safety
  • Covered Entities & Business Associates
    • Business Associate Contracts
    • Business Associates
  • Training & Resources
  • FAQs for Professionals
  • Other Administrative Simplification Rules

Reports to Congress on Privacy Rule and Security Rule Compliance

Section 13424(a) of the Health Information Technology for Economic and Clinical Health (HITECH) Act requires the Secretary of the Department of Health and Human Services (the Department) to prepare and submit an annual report to Congress regarding compliance with the Privacy and Security Rules promulgated under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) (Pub. L. 104-191). In addition, Section 13424(a)(2) of the HITECH Act requires that each report be made available to the public on the web site of the Department.

The following report was prepared in accordance with these statutory requirements. For the years for which the report is prepared, the report summarizes complaints received by the Department of alleged violations of the provisions of Subtitle D of the HITECH Act, as well as of the HIPAA Privacy, Security and Breach Notification Rules at 45 CFR Parts 160 and 164.

2022 Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance

2021 Report to Congress on HIPAA Privacy, Security, and Breach Notification Compliance

2020 Report to Congress on HIPAA Privacy, Security, and Breach Notification Compliance

2019 Report to Congress on HIPAA Privacy, Security, and Breach Notification Compliance*

2018 Report to Congress on HIPAA Privacy, Security, and Breach Notification Compliance*

2015-2016-2017 Report to Congress on HIPAA Privacy, Security, and Breach Notification Compliance - Submitted to Congress on February 22, 2019.

2013 - 2014 Submission Letter to the Report to Congress on HIPAA Privacy, Security and Breach Notification Compliance

2013 - 2014 Report to Congress on HIPAA privacy, Security and Breach Notification Compliance

2011 – 2012 Submission Letter for the Report to Congress on HIPAA Privacy, Security and Breach Notification Compliance

2011 – 2012 Report to Congress on HIPAA Privacy, Security and Breach Notification Compliance

2009 - 2010 Submission Letter for the Report to Congress on Privacy Rule and Security Rule Compliance

2009 - 2010 Report to Congress on Privacy Rule and Security Rule Compliance

* People using assistive technology may not be able to fully access information in this file. For assistance, contact the HHS Office for Civil Rights at (800) 368-1019, TDD toll-free: (800) 537-7697, or by emailing OCRMail@hhs.gov.

View the Reports to Congress on Breach Notification

Content created by Office for Civil Rights (OCR)
Content last reviewed February 22, 2024
Back to top

Subscribe to Email Updates

Receive the latest updates from the Secretary and Press Releases.

Subscribe
  • Contact HHS
  • Careers
  • HHS FAQs
  • Nondiscrimination Notice
  • Press Room
  • HHS Archive
  • Accessibility Statement
  • Privacy Policy
  • Budget/Performance
  • Inspector General
  • Web Site Disclaimers
  • EEO/No Fear Act
  • FOIA
  • The White House
  • USA.gov
  • Vulnerability Disclosure Policy
HHS Logo

HHS Headquarters

200 Independence Avenue, S.W.
Washington, D.C. 20201
Toll Free Call Center: 1-877-696-6775​

Follow HHS

Follow Secretary Kennedy