Filing a HIPAA Violation

The page below is a sample from the LabCE course HIPAA Privacy and Security Rules. Access the complete course and earn ASCLS P.A.C.E.-approved continuing education credits by subscribing online.

Learn more about HIPAA Privacy and Security Rules (online CE course)
Filing a HIPAA Violation

A person who believes a covered entity or business associate is not complying with HIPAA's administrative simplification provisions may file a complaint with the Secretary of Health and Human Services (HHS).
  1. A complaint must be filed in writing on paper or electronically.
  2. A complaint must name the person who is the subject of the complaint and describe the acts or omissions believed to violate the applicable administrative simplification provision(s).
  3. A complaint must be filed within 180 days of when the complainant knew or should have known that the act or omission complained of occurred (the HHS Secretary may waive this time limit if there is good cause).
Compliance violations are further investigated by the HHS Secretary, who will then decide if a civil penalty is appropriate.