Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

HHS.gov
  • About HHS
  • Programs & Services
  • Grants & Contracts
  • Laws & Regulations

Breadcrumb

  1. Home
  2. About
  3. News
  4. HHS Office for Civil Rights Delivers Annual Reports to Congress on HIPAA Compliance and Breaches of Unsecured Protected Health Information
  • News
  • Blog
  • HHS Live
  • Podcasts
  • Media Guidelines for HHS Employees
FOR IMMEDIATE RELEASE
February 17, 2023
Contact: HHS Press Office
202-690-6343
media@hhs.gov

HHS Office for Civil Rights Delivers Annual Reports to Congress on HIPAA Compliance and Breaches of Unsecured Protected Health Information

Reports highlight for regulated entities where to focus HIPAA compliance efforts

To help regulated entities better comply with the requirements of the HIPAA Privacy, Security, and Breach Notification Rules, the HHS Office for Civil Rights (OCR) is sharing two Reports to Congress for 2021, on HIPAA Privacy, Security, and Breach Notification Rule Compliance and Breaches of Unsecured Protected Health Information. These reports, delivered to Congress today, may benefit regulated entities to assist in their HIPAA compliance efforts. The reports also share steps taken by OCR to investigate complaints, breach reports, and compliance reviews regarding potential violations of the HIPAA Rules.  The reports include important data on the numbers of HIPAA cases investigated, areas of noncompliance, and insights into trends such as cybersecurity readiness.  

“The health care industry is one of the most diverse industries in our economy, and OCR is responsible for enforcing the HIPAA Rules to support greater privacy and security of individuals’ protected health information,” said OCR Director Melanie Fontes Rainer. “We will continue to provide guidance and technical assistance on compliance with the HIPAA Rules, as well as a vigorous enforcement program to address potential HIPAA violations.”

The 2021 Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance identifies the number of complaints received, the method by which those complaints were resolved, the number of compliance reviews initiated by OCR, and the outcome of each review. 

The Annual Report to Congress on Breaches of Unsecured Protected Health Information identifies the number and nature of breaches of unsecured protected health information (PHI) that were reported to the Secretary of HHS during calendar year 2021 and the actions taken in response to those breaches.  It also highlights the continued need for regulated entities to improve compliance with the HIPAA Security Rule requirements, including:

  • risk analysis and risk management;
  • information system activity review;
  • audit controls; and
  • access controls.

These compliance concerns were identified as areas needing improvement in 2021 OCR breach investigations. As it was the previous three years, hacking/IT incidents remain the largest category of breaches occurring in 2021 affecting 500 or more individuals, and affected the most individuals, comprising 75% of the reported breaches.  Network servers is the largest category by location for breaches involving 500 or more individuals.

OCR’s 2021 Report to Congress on HIPAA Privacy, Security, and Breach Notification Rule Compliance may be found at: https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/reports-congress/index.html

OCR’s 2021 Report to Congress on Breaches of Unsecured Protected Health Information may be found at:  https://www.hhs.gov/hipaa/for-professionals/breach-notification/reports-congress/index.html

OCR is committed to enforcing the HIPAA Rules and supporting the privacy and security of peoples’ health information. If you believe that your or another person’s health information privacy or civil rights have been violated, you can file a complaint with OCR at: https://www.hhs.gov/ocr/complaints/index.html.

###
Note: All HHS press releases, fact sheets and other news materials are available at https://www.hhs.gov/news.
Like HHS on Facebook, follow HHS on Twitter @HHSgov, and sign up for HHS Email Updates.
Last revised: February 17, 2023

Sign Up for Email Updates

Receive the latest updates from the Secretary, Blogs, and News Releases

Sign Up

Subscribe to RSS

Receive latest updates

Subscribe to our RSS

Related News Releases

  • HHS Office for Civil Rights Settles with L.A. Care Health Plan Over Potential HIPAA Security Rule Violations

  • HHS Issues New Proposed Rule to Strengthen Prohibitions Against Discrimination on the Basis of a Disability in Health Care and Human Services Programs

  • HHS and the U.S. Attorney’s Office Secures Agreement Resolving HIV Discrimination Complaint Involving a New Jersey Home Healthcare Provider

Related Blog Posts

  • HHS Blog thumbnail

    Improving the Cybersecurity Posture of Healthcare in 2022

Media Inquiries

For general media inquiries, please contact media@hhs.gov.

Content created by Office of Civil Rights
Content last reviewed February 17, 2023
Back to top
  • Contact HHS
  • Careers
  • HHS FAQs
  • Nondiscrimination Notice
  • HHS Archive
  • Accessibility
  • Privacy Policy
  • Viewers & Players
  • Budget/Performance
  • Inspector General
  • Web Site Disclaimers
  • EEO/No Fear Act
  • FOIA
  • The White House
  • USA.gov
  • Vulnerability Disclosure Policy

Sign Up for Email Updates

Receive the latest updates from the Secretary, Blogs, and News Releases.

Sign Up
HHS Logo

HHS Headquarters

200 Independence Avenue, S.W.
Washington, D.C. 20201
Toll Free Call Center: 1-877-696-6775​