Skip to main content
U.S. flag

An official website of the United States government

Return to Search

FAQ 2019 Who enforces HIPAA?

This is a FAQ about HIPAA.

Final

Issued by: Office for Civil Rights (OCR)

Who enforces the health information privacy and security standards established under the Health Insurance Portability and Accountability Act (HIPAA)?

Answer:

The HIPAA Privacy and Security Rules are enforced by the Office for Civil Rights (OCR). View more information about complaints related to concerns about protected health information.

The Office of E-Health Standards and Services within the Centers for Medicare & Medicaid Services (CMS) enforces the Transactions and Code Sets and National Identifiers (Employer and Provider identifiers) regulations of the Health Insurance Portability and Accountability Act (HIPAA). Complaints regarding the Transactions and Code Sets and National Identifiers regulations may be submitted electronically or via paper form - PDF.  CMS also enforces the insurance portability requirements under Title I of HIPAA. View more information about portability and how to obtain information or assistance.

HHS is committed to making its websites and documents accessible to the widest possible audience, including individuals with disabilities. We are in the process of retroactively making some documents accessible. If you need assistance accessing an accessible version of this document, please reach out to the guidance@hhs.gov.

DISCLAIMER: The contents of this database lack the force and effect of law, except as authorized by law (including Medicare Advantage Rate Announcements and Advance Notices) or as specifically incorporated into a contract. The Department may not cite, use, or rely on any guidance that is not posted on the guidance repository, except to establish historical facts.