Skip to content
Behavioral Health Resource Solutionby The Vanguard Solution

Search the resource library

Search procedure codes, payer policies, state requirements and more

Compliance & Accreditation

HIPAA Violations: Examples, Fines & Prevention Guide

HIPAA violation examples, penalty tiers, and real enforcement cases — plus how behavioral health and addiction treatment facilities prevent them.

HIPAA Violations in Behavioral Health

Quick Facts

Category
Federal Compliance
Published
Jun 12, 2026
Reading Time
16 min

Need compliance help?

A HIPAA violation can cost a treatment facility six or seven figures, trigger years of federal monitoring, and do referral-network damage that outlasts both. This guide explains what counts as a violation, what enforcement actually looks like in behavioral health, what it costs, and how facilities prevent violations — written for operators and compliance officers, not lawyers. (It is also not legal advice; for decisions about a specific incident, involve qualified counsel.)

What Is a HIPAA Violation?

A HIPAA violation is a failure to comply with any requirement of the HIPAA Privacy Rule, Security Rule, or Breach Notification Rule ↗ by a covered entity or business associate. That is the whole definition — and each word matters:

Searchers often say “ PHI violation,” which is the same idea from the data’s point of view. Protected health information (PHI) is individually identifiable health information held or transmitted by a covered entity or business associate, in any form. The Privacy Rule’s de-identification standard enumerates 18 identifiers — name, address, dates, phone, email, SSN, medical record number, photographs, and so on — that connect health information to a person ( 45 CFR 164.514 ↗ ). In a treatment facility, PHI includes the fact that a person is a client at all — census lists, sign-in sheets, and alumni lists are PHI, not just charts.

Who has to comply? Covered entities (most treatment providers) and their business associates. Whether HIPAA applies to adjacent businesses — sober living homes, recovery coaches, cash-pay practices — is its own analysis: see Who Does HIPAA Apply To for the covered-entity decision tree.

  • A violation is any noncompliance, whether or not information actually got out (an unencrypted laptop policy gap is a violation even before a laptop goes missing).
  • A breach is a specific kind of event: an impermissible acquisition, access, use, or disclosure of protected health information that compromises its security or privacy.
  • A security incident is broader still — attempted or successful unauthorized access to systems — and not every incident is a breach or a violation.

The Three Rules You Can Violate

The Privacy Rule governs uses and disclosures of PHI in any form. At a treatment facility, Privacy Rule compliance looks like: disclosures limited to treatment, payment, and operations (or made with valid authorization); minimum-necessary limits on internal access; a current Notice of Privacy Practices; processes for client access, amendment, and accounting requests; and front-office habits that do not leak who is in care. Most “people problems” — gossip, snooping, social media — are Privacy Rule violations.

The Security Rule governs electronic PHI specifically. Compliance means administrative, physical, and technical safeguards: a documented risk analysis, workforce access management, device and media controls, encryption decisions, audit controls, and contingency planning ( 45 CFR Part 164, Subpart C ↗ ). Most “technology problems” — stolen laptops, ransomware, unmonitored EHR access — become Security Rule violations when the safeguards behind them were missing or undocumented.

The Breach Notification Rule governs what happens after an impermissible disclosure: notifying affected individuals, HHS, and sometimes the media on fixed timelines ( 45 CFR 164.400–414 ↗ ). Facilities violate this rule by discovering a breach and notifying late, incompletely, or not at all — a separate violation stacked on whatever caused the breach.

HIPAA Violation Examples in Behavioral Health Settings

Generic HIPAA example lists are written for hospitals. These fifteen scenarios are the ones that actually happen in behavioral health and addiction treatment settings. Every example is fictional and illustrative.

Impermissible disclosure

Snooping and unauthorized access

Lost and stolen devices

Improper disposal

Vendors and BAAs

Communications and marketing

Physical environment

  • Confirming someone is a client. A staff member tells a caller, “Yes, he’s here, want to leave a message?” In behavioral health, the fact of admission is itself PHI — and if the program is a Part 2 program, confirming SUD treatment status without consent also violates 42 CFR Part 2. Rule: Privacy. Fix: scripted front-desk responses and verification procedures for callers.
  • Responding to an online review. An owner replies to a one-star Google review with details of the reviewer’s treatment. Public confirmation of care plus clinical detail is a textbook impermissible disclosure — and one OCR has settled over (see the enforcement cases below). Rule: Privacy. Fix: never confirm a reviewer was a client; respond generically and take it offline.
  • Faxing or emailing records to the wrong recipient. A discharge summary goes to a misdialed fax number or an autocompleted wrong email address. Rule: Privacy (and Security if unencrypted email). Fix: verified recipient directories, confirmation steps for new destinations, encrypted transmission.
  • Looking up a famous client — or an ex. A technician with EHR access opens the chart of someone they know personally, with no treatment role. Access without a job-based need is a violation even if nothing is shared. Rules: Privacy and Security. Fix: role-based access, audit-log review, and visible enforcement.
  • Browsing census out of curiosity. Staff scroll the full facility census when their role involves one unit. Rules: Privacy (minimum necessary) and Security (access management). Fix: scope access by role; review access patterns.
  • An unencrypted laptop disappears from a car. If the device held ePHI and was not encrypted, the loss is presumptively a reportable breach, and the missing encryption decision becomes the Security Rule violation OCR examines. Rule: Security. Fix: full-disk encryption everywhere, mobile device management, no local PHI storage.
  • A personal phone full of client texts is lost. Staff texting clients from personal, unmanaged devices puts PHI outside every safeguard the facility documented. Rule: Security. Fix: sanctioned secure-messaging channels and a bring-your-own-device policy with teeth.
  • Paper charts in the dumpster. Old intake packets tossed during an office move, found by a journalist or a former client’s family. Rule: Privacy (safeguards). Fix: shredding contracts with a business associate agreement, disposal logs.
  • Retired computers sold with drives intact. Rule: Security (media disposal). Fix: documented sanitization or destruction for every device leaving service.
  • No business associate agreement with the billing company. A facility shares full claim files with an outside biller for years with no BAA in place. The sharing itself is impermissible, regardless of whether anything goes wrong. Rule: Privacy. Fix: a BAA inventory covering billers, EHR vendor, IT, shredding, answering service, and any analytics or marketing vendor touching PHI.
  • Social media posts from inside the facility. A staff celebration photo with a visible whiteboard of client first names and room numbers; an alumni-event photo posted without authorizations. Rule: Privacy. Fix: photo policy, authorization forms, designated review before posting.
  • Texting PHI without safeguards. Appointment reminders that include diagnosis or program names sent by standard SMS to unverified numbers. Rules: Privacy and Security. Fix: minimum-necessary reminder content, client communication preferences, secure messaging.
  • Alumni lists used for marketing. The admissions team emails a promotion to a list of former clients — using PHI for marketing without authorization, and identifying every recipient as a treatment alum to anyone who sees the list. Rule: Privacy (marketing authorization requirements). Fix: marketing-use authorizations or stop.
  • Sign-in sheets and lobby whiteboards. A waiting-room sign-in sheet that lists full names and reasons for visit, visible to everyone who signs after them — a recurring small-facility issue. Rule: Privacy (reasonable safeguards). Fix: minimal sign-in fields, covered sheets, clear screens and boards.
  • Overheard treatment conversations. Case reviews held at the nursing station, audible in the hallway. Incidental disclosures are permitted only when reasonable safeguards are in place. Rule: Privacy. Fix: private spaces for clinical conversations; sound-masking where layouts are tight.

Penalties and Fines: What a Violation Actually Costs

Civil penalties are tiered by culpability under 45 CFR 160.404 ↗, and the dollar amounts are adjusted for inflation every year in the Federal Register — so any table you read (including this one) needs a date check at publish. The structure, as established by the HITECH Act and HHS’s 2019 penalty-cap reinterpretation:

Three operator takeaways: penalties are counted per violation (one lost laptop can equal hundreds of violations — one per affected record); the tier turns on what you knew and what you documented (a current risk analysis is your best evidence against “willful neglect”); and corrected-within-30-days is a real, money-saving distinction.

Culpability tierWhat it meansPer-violation penaltyAnnual cap (same provision)
1. No knowledgeDid not know and could not reasonably have knownLowest minimum per violationLowest cap
2. Reasonable causeKnew or should have known, but not willful neglectHigher minimumHigher cap
3. Willful neglect, correctedConscious disregard, corrected within 30 daysSubstantially higher minimumSubstantially higher cap
4. Willful neglect, uncorrectedConscious disregard, not correctedHighest minimumHighest cap (statutory base $1.5M, adjusted annually)

Criminal HIPAA Penalties

Criminal penalties are separate, prosecuted by the Department of Justice under 42 U.S.C. § 1320d-6 ↗, and apply to individuals as well as organizations:

State attorneys general can also bring HIPAA enforcement actions on behalf of residents, and many states have their own health-privacy statutes with separate penalties.

ConductMaximum fineMaximum imprisonment
Knowingly obtaining/disclosing PHI in violation of HIPAA$50,0001 year
Under false pretenses$100,0005 years
With intent to sell, transfer, or use for commercial advantage, personal gain, or malicious harm$250,00010 years

Real Enforcement Cases

OCR publishes its settlements and civil monetary penalties in an enforcement archive ↗. A few that matter for behavioral health operators:

The pattern across the archive: OCR settlements almost always cite the absence of an accurate, thorough risk analysis — not just the incident itself.

  • Manasa Health Center (2023, $30,000) — a New Jersey psychiatric practice settled with OCR after allegedly disclosing a patient’s PHI while responding to a negative online review. Small practice, small dollar figure, national press: the reputational multiplier is the lesson.
  • Green Ridge Behavioral Health (2024, $40,000) — a Maryland mental health practice settled following a ransomware attack that affected patient records; OCR’s findings centered on risk-analysis and safeguard failures. Among the first OCR ransomware settlements — and it landed on a small behavioral health practice, not a hospital system.
  • Lifespan (2020, $1,040,000) — a health system settled after the theft of an unencrypted laptop; OCR cited the lack of encryption and device controls. The unencrypted-device fact pattern repeats across the archive.
  • Anthem (2018, $16,000,000) — the largest HIPAA settlement to date, following a cyberattack affecting nearly 79 million people. The scale is hospital-world, but the cited failures — risk analysis, access monitoring — are the same ones OCR cites at small facilities.

The Consequences Beyond Fines

The fine is rarely the expensive part. A facility that violates HIPAA at scale typically also faces:

  • A corrective action plan (CAP) with monitoring. Most OCR settlements include a multi-year CAP — mandated policies, training, audits, and reporting to OCR. Budget for years of compliance overhead, not a one-time payment.
  • Breach response costs. Forensics, legal counsel, notification mailing, credit monitoring, call-center support — costs that scale with affected records and arrive whether or not OCR ever fines you.
  • Licensing and accreditation exposure. State licensing agencies can treat privacy failures as licensure issues, and accreditors evaluate information-management practices — privacy failures surface in Joint Commission and CARF surveys.
  • Referral and payer damage. Behavioral health is referral-driven. A public breach makes hospitals, EAPs, courts, and alumni networks hesitate, and payer audits can follow press coverage.
  • Individual consequences for staff. Termination is standard for snooping and disclosure violations, and criminal referral is possible for intentional misuse — a point worth making explicitly in workforce training.
  • Civil litigation. HIPAA itself has no private right of action, but breach victims sue under state negligence and privacy theories, often as class actions.

HIPAA Isn’t the Only Rule: 42 CFR Part 2

For substance use disorder programs, HIPAA is the floor, not the ceiling. 42 CFR Part 2 protects SUD treatment records held by federally assisted programs, with consent requirements stricter than HIPAA’s — historically including restrictions on re-disclosure and on use of records in legal proceedings.

The 2024 Part 2 final rule aligned much of Part 2 with HIPAA: a single patient consent can now cover future uses and disclosures for treatment, payment, and operations; Part 2 breach notification follows the HIPAA Breach Notification Rule; and civil and criminal enforcement now parallels HIPAA’s penalty structure — meaning a Part 2 violation can now cost what a HIPAA violation costs.

The operator’s takeaway: a disclosure that survives HIPAA analysis can still violate Part 2 (and vice versa). SUD programs should run both analyses on every disclosure pathway — referrals, payers, family communication, court requests, and marketing above all.

If a Violation Happens: Breach Notification Requirements

When an impermissible use or disclosure occurs, the Breach Notification Rule ( 45 CFR 164.400–414 ↗ ) sets the clock:

Two traps: “discovery” starts when anyone in your workforce knew or should have known — not when leadership found out; and business associate breaches are your notification obligation, on your timeline, which is why BAA breach-reporting clauses matter.

  • Assess. A breach is presumed reportable unless a documented risk assessment demonstrates a low probability that PHI was compromised (nature of the data, who received it, whether it was actually viewed, mitigation).
  • Notify individuals without unreasonable delay and no later than 60 days from discovery, by written notice, describing what happened, what information was involved, and what they should do.
  • Notify HHS. Breaches affecting 500 or more individuals: report to HHS contemporaneously with individual notice. Breaches affecting fewer than 500: log them and report annually, within 60 days after the calendar year ends.
  • Notify the media for breaches affecting more than 500 residents of a state or jurisdiction: notice to prominent media outlets in that area.
  • Document everything. Burden of proof on timing and content of notifications sits with the facility.

How Treatment Facilities Prevent Violations

Prevention is mostly unglamorous infrastructure. The elements OCR and accreditors keep coming back to:

Software carries a large share of this. An EHR built for behavioral health can enforce role-based permissions, maintain audit trails on every record access, and keep documentation inside a controlled system instead of on personal devices and spreadsheets. For the workflow view, see our post on how software protects behavioral health organizations from HIPAA violations and the broader cybersecurity guide for treatment organizations. HIPAA-ready behavioral health EHR software and connected behavioral health RCM are the infrastructure layers many of the controls above run on.

One spelling note, since search data says it matters: the law is HIPAA — the Health Insurance Portability and Accountability Act — commonly misspelled “HIPPA.” Same statute, same penalties, however it’s spelled.

This page is general information, not legal advice. For incident-specific decisions, involve privacy counsel.

  • A real risk analysis, refreshed on a schedule. The most-cited failure in OCR’s settlement archive is the missing or stale security risk analysis. Inventory where ePHI lives, identify threats, rate them, and document remediation decisions — then redo it when systems change and at least annually.
  • Training with a cadence, not an orientation checkbox. Privacy and security training at hire and at least annually, with role-specific scenarios (front desk, clinical, billing) and documented completion. See staff training requirements.
  • Role-based access control. Staff see the records their role requires — nothing more — and access is reviewed when roles change and terminated on the last day of employment.
  • Audit logging that someone reads. Logs of who opened which record only prevent snooping if access reviews actually happen.
  • BAAs with every vendor that touches PHI. Billers, EHR, IT and hosting, answering services, shredding, analytics. Keep a current inventory.
  • Device and disposal discipline. Encryption on every laptop and phone that can touch PHI, mobile device management, sanitization before disposal, shredding for paper.
  • An incident response plan you have rehearsed. The 60-day clock is unforgiving when the plan is being written during the incident.

Sources

Ready to put the infrastructure layer in place? Request a demo to see how supports HIPAA-compliant operations end to end.

  • HHS HIPAA for Professionals ↗ — Privacy, Security, and Breach Notification Rule summaries
  • HHS OCR Resolution Agreements ↗ — enforcement case archive
  • 45 CFR Part 160, Subpart D ↗ — civil penalty tiers (160.404)
  • 45 CFR 164.400–414 ↗ — Breach Notification Rule
  • 42 U.S.C. § 1320d-6 ↗ — criminal penalties
  • eCFR 42 CFR Part 2 ↗ — SUD record confidentiality

This guide is provided for informational purposes only and does not constitute legal, regulatory, or professional advice. Regulations change frequently — always verify current requirements with the relevant state agency or accrediting body. is not a law firm or consulting firm.

See a Compliance-Ready EHR

helps behavioral health organizations navigate compliance with confidence.

Reference tables

Culpability tierWhat it meansPer-violation penaltyAnnual cap (same provision)
1. No knowledgeDid not know and could not reasonably have knownLowest minimum per violationLowest cap
2. Reasonable causeKnew or should have known, but not willful neglectHigher minimumHigher cap
3. Willful neglect, correctedConscious disregard, corrected within 30 daysSubstantially higher minimumSubstantially higher cap
4. Willful neglect, uncorrectedConscious disregard, not correctedHighest minimumHighest cap (statutory base $1.5M, adjusted annually)
ConductMaximum fineMaximum imprisonment
Knowingly obtaining/disclosing PHI in violation of HIPAA$50,0001 year
Under false pretenses$100,0005 years
With intent to sell, transfer, or use for commercial advantage, personal gain, or malicious harm$250,00010 years

Common questions

Official sources

1,157 words · reviewed 2026-06-12
HIPAA Violations: Examples, Fines & Prevention Guide — The Behavioral Health Resource Solution