Quick summary
HIPAA violations happen when a covered entity or business associate fails to meet the HIPAA Privacy, Security or Breach Notification Rule. Civil penalties range from a few hundred dollars to more than $2 million per violation, set across four tiers based on how much the organization knew.
What this guide covers: HIPAA violation types, penalty tiers, real enforcement cases and practical risk reduction
Who it’s for: Healthcare marketers, analytics leads, compliance officers, IT and legal teams
HIPAA compliance in marketing is genuinely complicated. The tools healthcare marketers rely on weren’t designed with healthcare regulations in mind, and the line between what’s permitted and what isn’t isn’t always obvious from reading the law.
This guide covers the practical side: how violations happen, what they cost, how enforcement works, and what healthcare marketing and analytics teams can do to reduce their exposure.
Disclaimer: This page is based on publicly available HHS OCR guidance and enforcement records. It is not legal advice. For guidance specific to your organization, consult qualified healthcare privacy counsel.
Jump to section:
- What is a HIPAA violation?
- HIPAA penalty tiers: What violations cost
- The most common HIPAA violations in healthcare marketing
- How analytics and tracking tools factor into HIPAA compliance
- Real HIPAA enforcement examples
- How HHS OCR investigations work
- Reducing your HIPAA violation risk in marketing and analytics
- What if you discover a potential violation that has already occurred?
- Get compliant analytics – without giving up marketing visibility
- Regulatory resources
- Frequently asked questions
What is a HIPAA violation?
What counts as a HIPAA violation?
Quick answer
A HIPAA violation occurs when a covered entity or business associate fails to meet the requirements of the HIPAA Privacy Rule, Security Rule, or Breach Notification Rule.
Violations range from administrative gaps – a missing policy or outdated training record – to serious incidents involving large-scale unauthorized disclosure of patient information.
Not every violation leads to a penalty. HHS OCR considers the nature of the issue, harm caused, compliance history, and corrective actions taken when deciding how to respond.
HIPAA violations stem from three rules. Here’s what each one governs and the violations it commonly produces.
| Rule | What it governs | Common violation types |
|---|---|---|
| Privacy Rule | How protected health information (PHI) can be used and disclosed | Unauthorized disclosures, missing patient rights processes, sharing with third parties without authorization |
| Security Rule | Technical, physical, and administrative safeguards for electronic PHI (ePHI) | Insufficient access controls, missing encryption, inadequate risk assessments |
| Breach Notification Rule | Obligations when PHI is improperly disclosed | Late or missing notification, incomplete breach assessment |
What is the difference between a violation and a breach?
A breach is a specific type of HIPAA violation – the unauthorized acquisition, access, use, or disclosure of PHI in a way that compromises its security or privacy. Not every breach triggers notification; HIPAA provides a four-factor risk assessment framework to determine whether notification is required.
A violation is broader: any failure to meet a HIPAA requirement, whether or not PHI was actually disclosed. Running an analytics platform and collecting PHI without a business associate agreement (BAA), for example, is a violation even if no data incident occurred.
Who can be held liable for a HIPAA violation?
Both covered entities and their vendors can be held liable. Here’s who HIPAA applies to and how.
| Entity type | Liable under HIPAA | Examples |
|---|---|---|
| Covered entity | Yes | Hospitals, health plans, healthcare clearinghouses, most healthcare providers |
| Business associate | Yes (since HITECH 2009) | Analytics vendors, martech platforms, cloud hosts, billing services handling PHI |
| Business associate subcontractor | Yes | A subprocessor used by an analytics vendor that handles PHI |
| Individual employee | Yes, in criminal cases | Employees who knowingly access or disclose PHI improperly |
HIPAA penalty tiers: What violations cost
How does HHS OCR calculate HIPAA fines?
OCR uses a four-tier penalty structure based on the level of culpability – how aware the organization was of the issue and what they did about it. The same underlying incident can result in very different penalties depending on which tier applies.
Civil penalty tiers
OCR sets civil penalties across four tiers based on how much the organization knew. Amounts adjust for inflation each January.
| Tier | Standard | Min per violation | Max per violation | Annual cap (OCR enforcement discretion) |
|---|---|---|---|---|
| Tier 1 | Did not know, and could not have known with reasonable diligence | $145 [orig. $100] | $73,011 | $25,000 |
| Tier 2 | Reasonable cause – knew or should have known, but not willful neglect | $1,461 [orig. $1,000] | $73,011 | $100,000 |
| Tier 3 | Willful neglect – corrected within 30 days | $14,602 [orig. $10,000] | $73,011 | $250,000 |
| Tier 4 | Willful neglect – not corrected | $73,011 [orig. $50,000] | $2,190,294 | $2,190,294 |
The figures above reflect the amounts effective from January 28, 2026, following HHS’s latest inflation adjustment. Original HITECH Act statutory minimums are shown in brackets for reference.
A note on annual caps: In 2019, OCR issued a Notice of Enforcement Discretion applying lower annual caps for Tiers 1–3 (as shown above). The official inflation-adjusted cap for all tiers is $2,190,294 per identical provision per year – OCR can rescind the discretionary caps at any time. For risk planning purposes, use the official cap, not the discretionary figures.
A note on “per violation”: OCR can treat each individual patient record affected as a separate violation. An improperly configured analytics tag running on a patient portal for several months can generate a large number of individual violations – which is why the annual cap matters more than the per-violation figure in most real cases.
Criminal penalties
The Department of Justice handles criminal cases separately from HHS civil enforcement, with penalties that can include prison time.
| Tier | Standard | Penalty |
|---|---|---|
| Basic | Knowing violation | Up to 1 year imprisonment + $50,000 fine |
| Aggravated | Violation under false pretenses | Up to 5 years imprisonment + $100,000 fine |
| Most severe | Violation for personal gain or to cause harm | Up to 10 years imprisonment + $250,000 fine |
What is the largest HIPAA fine on record?
The largest HIPAA settlement on record is $16 million, paid by Anthem, Inc. in 2018 following a series of cyberattacks that exposed the ePHI of nearly 79 million individuals. OCR’s investigation found that Anthem had failed to conduct an enterprise-wide risk analysis, lacked sufficient procedures to review system activity, and failed to implement minimum access controls.
Most enforcement actions settle at significantly lower amounts, though multi-million-dollar resolutions have become more common as OCR has focused on digital tracking technology in recent years.
The most common HIPAA violations in healthcare marketing
What violations do healthcare marketing teams most commonly encounter?
The marketing and analytics violations that surface most often in OCR enforcement actions and compliance audits tend to fall into a handful of consistent categories. Here are the most frequent ones, ranked by enforcement risk.
The most common ones fall into a few categories: analytics tools used without a BAA, PHI leaking through URL parameters, and session recording in patient portals.
| Violation type | How it typically happens | Enforcement risk level |
|---|---|---|
| Analytics platforms without BAAs | Standard analytics tools used on any page where PHI is present without contractual HIPAA protections | High – OCR guidance explicitly addresses this |
| PHI in URL parameters | Page URLs containing condition names, appointment details, or identifiers transmitted to third-party analytics | High – discovered through data audits |
| Session recording in post-login areas | Screen capture tools running in authenticated patient portals | High – directly captures PHI |
| Missing or inadequate risk assessment | No documented periodic risk assessment, or one that doesn’t cover the full analytics stack | Medium – OCR requires this as a baseline |
| Outdated or incomplete BAAs | BAAs in place but not updated to reflect HITECH, or missing some vendors in the data chain | Medium – typically surfaces during breach investigation |
| Unauthorized use of patient data for marketing | Using patient data for marketing purposes without valid authorization | Medium-High – OCR scrutinizes this closely |
Note: They usually aren’t the result of anyone doing something they knew was wrong. They’re the result of technology decisions that were made without a compliance review, or tools that were set up before the regulatory picture became as clear as it’s today.
Is using Google Analytics on a healthcare website a HIPAA violation?
Quick answer
In most cases where PHI is present, yes. Google Analytics doesn’t offer a BAA for standard use and its terms of service prohibit the use of PHI.
Using GA4 on a patient portal, appointment scheduler, symptom checker, or any page where PHI is present or could be inferred is generally considered an impermissible disclosure of PHI to a third party without HIPAA protections in place.
HHS and the FTC have both issued guidance confirming that tracking technologies on healthcare websites can violate HIPAA when they transmit PHI-related data to platforms that aren’t covered by a BAA.
What are the most common Security Rule violations?
Security Rule violations usually trace back to a missing safeguard. The most common are missing access controls, no risk analysis, unencrypted ePHI and vendors without BAAs.
| Security Rule violation | What was typically missing |
|---|---|
| Insufficient access controls | No role-based permissions; no MFA on systems handling PHI |
| Missing or inadequate risk analysis | No annual assessment; assessment not updated after system changes |
| No encryption | ePHI transmitted or stored without encryption |
| Insufficient audit controls | No access logging; logs not reviewed regularly |
| Missing workforce training | Staff accessing PHI without documented HIPAA training |
| No business associate agreements | Vendors handling PHI without BAAs |
How analytics and tracking tools factor into HIPAA compliance
Can an analytics platform cause a HIPAA violation?
Quick answer
Yes – when it processes PHI without a BAA in place, or transmits PHI to a third-party platform that isn’t covered by HIPAA protections.
This is an area where well-intentioned marketing teams often find themselves in a difficult position: the tools they’ve been using for years weren’t designed with healthcare compliance in mind, and the regulatory picture around digital tracking has become significantly clearer only in the last few years.
PHI can leak at every layer of a standard analytics stack. Here’s where each risk sits and which tools are involved.
| Stack layer | Tool examples | How PHI exposure can occur |
|---|---|---|
| Web analytics | Google Analytics | Full URL sent to Google servers, including health-related parameters; no BAA available |
| Advertising pixels | Meta Pixel, Google Ads tag | Page URL and user identifiers sent to ad platforms, including health-inferred data |
| Session recording | Hotjar, FullStory, Microsoft Clarity | Screen captures in patient portals may record PHI displayed on screen |
| Tag management | Google Tag Manager | Tags configured to fire on post-login pages can transmit session data |
| Marketing automation | HubSpot, Marketo | Health data synced to CRM without a BAA constitutes an impermissible disclosure |
| A/B testing | Optimizely, VWO | Tests on patient-facing pages may capture or transmit PHI |
| Heatmapping | Crazy Egg | Click and scroll data on health forms may include PHI |
What is the HHS guidance on tracking pixels in healthcare?
Quick answer
HHS OCR published its original bulletin on online tracking technologies on December 1, 2022, clarifying that tracking technologies – pixels, cookies, and similar tools – on the websites or apps of HIPAA-covered entities can constitute an impermissible disclosure of PHI when they transmit information about individuals’ health conditions, treatment, or health-seeking behavior to third parties without a BAA.
OCR updated the bulletin on March 18, 2024, providing additional examples to help organizations distinguish when information collected on unauthenticated pages is or isn’t PHI. The update emphasized that simply visiting a general informational page (such as job postings or visiting hours) doesn’t automatically create PHI – but visiting pages related to specific health conditions or services may.
On June 20, 2024, a US District Court for the Northern District of Texas ruled that HHS had exceeded its statutory authority with respect to the parts of the bulletin addressing unauthenticated pages and IP addresses. That portion of the guidance was vacated. The guidance on authenticated pages – patient portals, appointment schedulers, prescription pages – remains in full effect.
Some page types carry more risk than others. Here’s how each stands after the June 2024 court ruling.
| Page type | Risk level | Status after June 2024 ruling |
|---|---|---|
| Patient portals (authenticated) | High | Fully in effect |
| Appointment scheduling (authenticated) | High | Fully in effect |
| Prescription refill pages (authenticated) | High | Fully in effect |
| Symptom checkers with user input | High | Largely in effect |
| General unauthenticated pages | Lower | Vacated portion – reduced ambiguity |
| General marketing and informational pages | Lower | Vacated portion – reduced ambiguity |
Does server-side tracking solve the pixel compliance problem?
Server-side tagging meaningfully reduces the risk of PHI reaching third-party platforms by filtering and controlling data before it leaves your infrastructure. It’s a strong part of a compliant setup – but it still needs to be paired with a HIPAA-compliant analytics platform that will sign a BAA, and the server-side configuration needs to be audited to confirm PHI is being filtered correctly.
Real HIPAA enforcement examples
What do real HIPAA enforcement actions look like?
Quick answer
They range from multi-million-dollar settlements for large breaches down to five-figure fines for records-access failures.
These real OCR settlement examples below show the range of issues that lead to formal action, and what they cost, drawn from publicly available OCR records.
| Type of organization | Violation | Settlement amount | Key finding |
|---|---|---|---|
| Large health insurer | Cyberattacks exposing ePHI of ~79 million individuals | $16 million (2018) | Failed to conduct enterprise-wide risk analysis; no minimum access controls; inadequate system activity review |
| General hospital | Inviting ABC News film crews onto premises without patient authorization | $999,000 combined (2018) | Impermissible disclosure of PHI to third parties (film crew); failure to implement appropriate safeguards before media access |
| Health system provider | Multiple breaches; employees improperly accessing records | $2.15 million (2019) | Failure to restrict workforce access; inadequate audit controls |
| Diagnostic medical imaging center | Breach exposing 300,000+ patient records | $3 million (2019) | Failure to implement risk analysis and security measures |
| Small medical practice | Failure to provide patient timely access to records | Varies ($10,000–$200,000 range across Right of Access cases) | Privacy Rule violations; failure to respond to patient access requests within required timeframes |
Settlement amounts are from publicly announced HHS OCR resolutions (hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements). They represent negotiated outcomes, not necessarily the maximum penalty that could have applied.
What enforcement activity has involved digital tracking tools?
Between 2022 and 2024, a number of healthcare organizations faced regulatory scrutiny and class action litigation after third-party tracking pixels were discovered on patient-facing websites. The common thread across those situations:
- Pixels had been installed by marketing teams as standard practice, without a compliance review
- The pixels were transmitting URL data – including health-related page names and appointment details – to advertising platforms without BAAs
- The extent of the data transmission wasn’t known until a security audit or media report brought it to light
- Responses included pixel removal, patient notification, and in some cases significant legal costs
These situations accelerated OCR’s focus on digital tracking and directly informed the 2022 guidance referenced above.
How HHS OCR investigations work
How does OCR find out about HIPAA violations?
OCR investigations start from several triggers. Here’s what sets each one in motion.
| Trigger | What happens |
|---|---|
| Patient complaint | Individual files a complaint with OCR; OCR opens an investigation |
| Breach report (500+ individuals) | Covered entity submits breach report; OCR may investigate |
| Media coverage | High-profile incidents reported publicly can prompt OCR review |
| OCR compliance audit | OCR selects organizations for proactive review under its audit program |
| Employee or whistleblower complaint | Staff reports a potential violation to OCR |
| Annual breach log | Breaches affecting fewer than 500 individuals are reported annually; OCR may follow up |
What happens during an OCR investigation?
- Notice of investigation – OCR notifies the covered entity that a complaint has been received or an audit is underway
- Document request – OCR requests policies, procedures, risk assessments, BAAs, training records, and technical documentation
- Technical review – OCR may review system configurations and access logs
- Findings – OCR issues its findings and identifies any required corrective actions
- Resolution – Cases resolve through voluntary compliance, technical assistance, corrective action plans, or formal settlement agreements
- Monitoring period – Significant resolutions typically include a corrective action plan with OCR oversight over 2–3 years
What does a corrective action plan typically require?
A corrective action plan usually covers the same core elements. Here’s what each one involves.
| Element | What it involves |
|---|---|
| Risk analysis | Comprehensive assessment of the full environment, including analytics and martech |
| Risk management plan | Documented plan addressing identified vulnerabilities with timelines |
| Policy updates | Revised HIPAA policies and procedures |
| Workforce training | Updated training delivered and documented |
| BAA audit | Review and update of all business associate agreements |
| Ongoing reporting | Regular progress reports to OCR during the monitoring period |
Reducing your HIPAA violation risk in marketing and analytics
Where should healthcare marketing teams focus first?
The highest-priority actions are the ones that address the most active enforcement focus areas and the most common sources of inadvertent exposure.
These are the highest-priority actions for marketing teams, ordered by where enforcement is most active.
| Priority | Action | Why it matters |
|---|---|---|
| 1 | Audit third-party pixels and tracking tags on patient-facing pages | Pixel-related disclosures are the primary current OCR focus |
| 2 | Confirm BAA status for every analytics and martech vendor | No BAA with a vendor handling PHI is a compliance gap |
| 3 | Move patient portal and appointment analytics to a HIPAA-compliant platform | Addresses the exposure at the source |
| 4 | Implement URL scrubbing to prevent PHI transmission through parameters | Covers a common inadvertent disclosure vector |
| 5 | Conduct and document a periodic risk assessment that covers your analytics stack | Required by HIPAA; the absence of one is itself a violation |
| 6 | Update all BAAs to reflect HITECH requirements | Outdated BAAs may not provide the protections you expect |
| 7 | Train marketing and analytics staff on the HIPAA-specific risks in the tools they use | Workforce training is a required safeguard |
| 8 | Add a compliance review step before any new martech tool is deployed | Prevents new gaps from being introduced |

SUCCESS STORY
How Shepherd Center gained HIPAA compliance and full visibility into patient acquisition
Shepherd Center replaced Google Analytics with Piwik PRO to close compliance gaps and get a complete picture of patient acquisition – resulting in a 40% rise in online patient referrals and a 215% increase in page views.
“I really liked how intuitive, easy, and familiar Piwik PRO felt compared to other platforms.”
Chris Walker, Director of Digital Strategy and Marketing, Shepherd Center
What if you discover a potential violation that has already occurred?
Quick answer
Document the discovery, preserve the evidence, involve legal counsel and contain the issue – then run the four-factor risk assessment to determine if it’s reportable.
Finding a gap in your setup is actually a good outcome – it means you can address it. If your organization discovers a potential violation, the recommended steps are:
- Document the discovery – record the date, what was found, and who identified it
- Preserve the evidence – avoid deleting logs or configurations before legal and compliance review
- Involve legal counsel – breach assessment is a legal determination; qualified guidance matters here
- Contain the issue – disable or reconfigure the tool causing the exposure, after documenting its current state
- Complete the four-factor risk assessment – this determines whether the incident is a reportable breach
- Assess notification obligations – if reportable, the 60-day clock runs from the date of discovery
- Review the broader stack – one gap is often a signal that similar issues may exist elsewhere
Get compliant analytics – without giving up marketing visibility
Most healthcare marketers manage the same pressure: compliance rules that limit what can be tracked, and leadership that expects full visibility anyway. Piwik PRO is built to give you both, so your team isn’t choosing between staying compliant and doing their job.
Piwik PRO gives healthcare organizations full marketing analytics visibility within a HIPAA-compliant setup. We sign the BAA, your data stays in your infrastructure, and your team keeps the campaign data, attribution, and behavioral insights it needs to make good decisions.
Regulatory resources
- FTC Health Breach Notification Rule
- HHS Office for Civil Rights
- HHS Breach Portal
- HHS Tracking Technology Bulletin
- HIPAA Enforcement Rule
Frequently asked questions
Failure to conduct an adequate risk analysis is the most frequently cited violation in OCR enforcement actions. It’s a required Security Rule safeguard, and many organizations either skip it or complete it without covering their full technology environment – including analytics and marketing tools.
Yes. Tier 1 penalties apply specifically to violations where the organization didn’t know and couldn’t reasonably have known.
Yes. Since HITECH, business associates are directly liable for certain HIPAA violations – they can be investigated and fined by OCR independently of the covered entity. Any analytics vendor, martech platform, or cloud provider handling PHI is a business associate and subject to HIPAA enforcement.
A fine is a penalty imposed by OCR through formal proceedings. Most enforcement actions are resolved through settlements – negotiated agreements where the organization pays a resolution amount and agrees to a corrective action plan, without OCR making a formal liability finding. Settlements typically come with monitoring requirements for 2–3 years.
HIPAA doesn’t provide a private right of action – individuals can’t sue directly under HIPAA. However, violations frequently support state law claims including negligence, breach of confidentiality, and consumer protection violations. Class action litigation following digital tracking disclosures has in some cases resulted in settlements that exceed the HIPAA penalties themselves.
The HHS Breach Portal is a public database maintained by OCR listing all reported breaches of unsecured PHI affecting 500 or more individuals. It includes the organization name, state, type of breach, and number of individuals affected. Listings are publicly searchable and remain on the portal indefinitely.
Affected individuals and HHS OCR must be notified within 60 days of discovering a breach affecting 500 or more individuals. Breaches affecting fewer than 500 individuals can be included in an annual log submitted to HHS by March 1 of the following year. Some state laws have shorter timelines.
Yes. If a marketing vendor handles PHI on your behalf, you’re responsible for ensuring that relationship is covered by a BAA. If no BAA exists, sharing PHI with that vendor is itself a violation – regardless of what the vendor does with the data afterward.

