How to File a HIPAA Complaint

File with the HHS Office for Civil Rights within 180 days, in writing, naming the entity and describing what happened. It is free, no lawyer is needed, and the practice cannot retaliate. Here is the portal walkthrough, what OCR does with it, and, for practices, how to handle a complaint before it becomes one.

Cyanotype of a sealed envelope with a security tint in its window, propped against a mug on a home deskFIG · 01
A home desk with a blank sheet, a pen, an envelope and a closed laptop.

The complaint path at a glance

45 CFR 160.306
  1. 01

    Internal complaint

    Privacy Officer named in the NPP

  2. 02

    File with OCR

    Portal, mail, fax, or email

  3. 03

    Intake review

    Timely? Covered entity? HIPAA issue?

  4. 04

    Investigation

    Data request, interviews, records

  5. 05

    Resolution

    Technical assistance, corrective action, or penalty

180 days
to file, from when you knew or should have known
374,322
HIPAA complaints received by OCR since April 2003
31,191
cases closed with corrective action
$0
cost to file — no lawyer required

Complaint counts from HHS OCR Enforcement Highlights, as of January 31, 2026.

Cyanotype vignette of a mailbox slot with an envelope halfway inFIG · 02
A mailbox slot with an envelope halfway in.

Step 0: Complain to the Practice First (Usually)

You do not have to complain to the provider before going to OCR. But it is often the fastest fix, and OCR itself resolves tens of thousands of cases by simply pointing the entity at the rule. Every covered entity must have a complaint process and a named contact — it is written into the Notice of Privacy Practices you signed at intake.

45 CFR 164.520(b)(1)(vi)

A statement that you may complain to the practice and to the HHS Secretary, plus a brief description of how to complain to the practice.

45 CFR 164.520(b)(1)(vii)

The name or title and phone number of the person or office that takes complaints and questions.

45 CFR 164.520(b)(1)(vi)

A statement that you will not be retaliated against for filing a complaint.

How to do it

  1. Find the complaint contact in the NPP (ask the front desk for a copy, or check the practice website). It is usually the Privacy Officer.
  2. Put it in writing. Email or a dated letter. State what happened, when, who was involved, and what you want (a correction, an accounting of disclosures, staff retraining, a copy of your records).
  3. Keep a copy and note the date you sent it. Your 180-day OCR clock is still running while you wait, so give the practice a couple of weeks, not months.

Skip straight to OCR when

The complaint is about the Privacy Officer or the owner, the practice has already brushed you off, you were denied access to your records past the 30-day limit, or you are near the 180-day deadline. Your patient rights under HIPAA do not depend on exhausting the internal route.

The 180-Day Window

Under 45 CFR 160.306(b)(3), a complaint must reach OCR within 180 days of when you knew or should have known the act or omission happened. The Secretary can waive the limit “for good cause shown,” but waivers are discretionary. Treat 180 days as hard.

180-day deadline calculator

OCR filing deadline

Enter a date

Counts 180 calendar days. Not legal advice; OCR decides what “should have known” means on your facts.

When the clock starts

  • Wrong-patient letter arrives: the day you opened it.
  • Records request ignored: day 31 after the request (the access deadline).
  • Breach notification letter: the date on the letter, not the breach date.
  • Staff snooping you learned about from a friend: the day you were told.

Good-cause arguments that get made

  • You were hospitalized or incapacitated for part of the window
  • The entity hid the disclosure and you only found out later (the clock usually starts at discovery anyway)
  • You filed with the wrong agency in good faith and were redirected
  • You were waiting on the practice's written response to an internal complaint

If you are late, file anyway and explain the delay in the narrative. OCR can still open a compliance review on its own initiative under 160.308 even if your complaint is untimely.

Filing Through the OCR Complaint Portal, Step by Step

The portal takes 15 to 25 minutes if you have your dates and documents ready. The regulation (160.306(b)) only requires that the complaint be in writing, name the entity, and describe the acts or omissions. The portal collects a lot more than that so intake can move fast.

  1. 1

    Open the OCR Complaint Portal

    ocrportal.hhs.gov/ocr/smartscreen/main.jsf

    Reachable from hhs.gov/ocr/complaints. No account needed. The same portal handles civil rights, conscience, and HIPAA complaints, so the first screens sort you.

  2. 2

    Pick the complaint type

    Health Information Privacy

    Choose the HIPAA (health information privacy or security) track, not "civil rights." Complaints about substance-use treatment records (42 CFR Part 2) also go through OCR.

  3. 3

    Answer the screening questions

    Smart screen

    Was the entity a health plan, provider that bills electronically, clearinghouse, or their business associate? Did it happen within 180 days? "No" answers redirect you rather than block you.

  4. 4

    Enter your contact details

    Complainant information

    Name, mailing address, phone, email. Required. Anonymous complaints are not investigated. If you are filing for someone else (a child, a parent under POA) say so here.

  5. 5

    Identify the entity

    Entity information

    Legal name, street address, phone. Get this from a bill, the NPP, or the state license lookup. Naming the wrong corporate entity is the most common reason intake stalls.

  6. 6

    Describe what happened

    Complaint narrative

    Date(s), who did what, how you found out, what harm followed, what you already asked the practice to do. Facts, in order, no adjectives. Attach copies, not originals.

  7. 7

    Consent and submit

    Consent form and e-signature

    Choose whether OCR may share your name with the entity. Declining can prevent an investigation. Submit, then save the confirmation and transaction number.

Other ways to file

Download the Health Information Privacy Complaint form (PDF) from hhs.gov and send it by any of these. Confirm the current address on hhs.gov before mailing; the portal is the only method with instant confirmation.

Mail

Centralized Case Management Operations, U.S. Dept. of Health and Human Services, 200 Independence Ave SW, Room 509F HHH Bldg, Washington, DC 20201

Email

OCRComplaint@hhs.gov (attach the PDF complaint form and consent)

Fax

(202) 619-3818

Not sure the organization is even covered? Check who HIPAA applies to first. Employers, schools, life insurers, and most fitness apps are not covered entities, and OCR will close those complaints as ineligible.

What to Put in the Complaint

Intake staff read hundreds of these. A complaint that lets them tick “timely, covered entity, alleges a specific rule violation” in two minutes gets opened. One that reads like a review does not.

  • Exact legal name and address of the practice, plan, or vendor
  • Date of each incident and the date you found out
  • Names or roles of the people involved ("front-desk staff on the morning shift" is fine)
  • What information was disclosed, to whom, and how (verbal, paper, portal, text)
  • What you asked the practice to do, and their response, with dates
  • Copies: letters, portal screenshots, texts, the NPP, your records request, the breach notice
  • What you want OCR to make them do

Weak narrative

“This clinic has zero respect for privacy. Everyone in the waiting room heard about my condition and the staff were incredibly rude about it. They should be shut down.”

Strong narrative

“On March 4, 2026 at about 9:10 a.m., a receptionist at Riverside Family Medicine, 120 Main St, called out my name and said ‘you’re here for the HIV follow-up’ in a waiting room with six other patients. I complained in writing to the Privacy Officer on March 6 (copy attached). No response as of April 20.”

Name the rule if you can (“right of access, 164.524”; “minimum necessary”), but do not guess. The most common HIPAA violations guide maps everyday incidents to the rule they break.

What Happens After You File

OCR does not represent you and will not get you money. It decides whether the entity broke the rules and, if so, makes it fix them. Here is how the 370,578 complaints resolved so far actually ended.

  • Not eligible for enforcement

    255,953 · 69%

    Untimely, not a covered entity, withdrawn, or no HIPAA issue alleged.

  • Early technical assistance

    67,873 · 18%

    OCR explained the rule; the entity fixed it without an investigation.

  • Investigated, corrective action

    31,191 · 8%

    Changes to practices required, sometimes with a resolution agreement.

  • Investigated, no violation

    15,561 · 4%

    Entity was found compliant on the facts.

Source: HHS OCR Enforcement Highlights, as of January 31, 2026. Shares rounded.

StageTimingWhat happens
ConfirmationImmediately (portal)Transaction number on screen and by email. Keep it; every later letter references it.
Intake reviewWeeks to a few monthsOCR checks timeliness, jurisdiction, and whether the facts describe a rule violation. It may ask you for more detail.
Notice to both sidesWhen a case opensYou and the entity get a letter. The entity gets a data request: policies, risk analysis, training records, logs. Typical response time is around 30 days.
InvestigationMonths to yearsDocument review, interviews, possibly an on-site visit. Willful-neglect indications must be investigated (160.306(c)).
Closure letterEndStates the finding: no violation, technical assistance, voluntary corrective action, resolution agreement with payment, or a civil money penalty.

Civil money penalties are the rare end of the spectrum, capped at $2.19M per violation category per year in 2026. The entity can contest a proposed penalty before an administrative law judge. Full tiers are in HIPAA violation penalties. Knowing criminal misuse gets referred to the Department of Justice.

Can You Sue Under HIPAA? No. But There Are Other Routes.

HIPAA has no private right of action. Every federal circuit that has considered it agrees: individuals cannot sue a provider for violating HIPAA, and courts dismiss those claims. Enforcement belongs to HHS and, since 2009, state attorneys general. That is why the OCR complaint matters: it is the only federal lever a patient has.

An OCR finding does not pay you a dollar. But it creates a documented violation that a state claim, an AG office, or a settlement negotiation can lean on.

State attorney general

42 U.S.C. 1320d-5(d)

Since HITECH (2009), state AGs can sue in federal court on behalf of residents for HIPAA violations: injunctions plus statutory damages of up to $100 per violation, capped at $25,000 per identical requirement per calendar year, plus attorney fees. AGs must notify HHS first and cannot act while OCR has an action pending on the same violation. Many AG offices now run their own health-privacy complaint intake, and multistate settlements over ransomware breaches have reached seven figures.

State privacy and consumer laws

Varies by state

Most states have medical-confidentiality statutes, and some (California CMIA, Texas, Washington MHMDA) give individuals a direct right to sue. Others reach it through consumer-protection or data-breach statutes.

Common-law tort claims

Negligence, breach of confidence

Courts in several states let plaintiffs use the HIPAA standard as the duty of care in a negligence or breach-of-confidentiality claim (Connecticut's Byrne v. Avery is the usual cite). You sue under state law; HIPAA sets the bar.

Practical order: internal complaint, OCR complaint, and a state AG complaint can all be filed in parallel. Talk to a lawyer about state claims early, because state statutes of limitation (often one to two years) run independently of OCR’s timeline. For what a breach must already have triggered on the practice side, see HIPAA breach notification rules.

You Cannot Be Punished for Filing

Two rules cover this. 45 CFR 160.316 says a covered entity or business associate may not “threaten, intimidate, coerce, harass, discriminate against, or take any other retaliatory action” against anyone for filing a complaint or taking part in an investigation. 45 CFR 164.530(g) repeats it for anyone exercising Privacy Rule rights, and 164.530(h) bars making patients waive those rights to get care.

Protected activity

  • Filing a complaint with OCR or with the practice
  • Testifying, assisting, or participating in an investigation, compliance review, or hearing
  • Opposing a practice you believe in good faith is unlawful, as long as you do not disclose PHI to do it
  • Exercising any HIPAA right: access, amendment, restriction, accounting of disclosures

Prohibited response

  • Dropping you as a patient because you complained
  • Refusing treatment or enrollment unless you waive your right to complain (164.530(h))
  • Threatening, harassing, or discriminating against you or a staff whistleblower
  • Firing or disciplining an employee who reported a violation in good faith

Retaliation is itself a violation you can add to your complaint. File a supplement through the portal using your original transaction number, with dates and any written evidence. Retaliation after an OCR filing tends to move a case from technical assistance toward willful neglect.

For Practices: Handling a Complaint You Receive

A patient complaint handled well is the cheapest compliance win you will get. Handled badly, it becomes the OCR complaint above, and the first thing OCR’s data request asks for is your complaint log and how you responded. Add this workflow to your privacy policy set and train on it.

01Log it the day it arrives

Day 0

Every complaint, verbal or written, goes in the complaint log with a number, date received, complainant, subject, and the staff member who took it. 164.530(d)(2) requires documenting all complaints received and their disposition.

02Acknowledge in writing

Within 2-3 business days

Thank them, restate the issue in one sentence, name the Privacy Officer handling it, give a date you will respond by, and repeat the no-retaliation statement from your NPP.

03Investigate

Within 30 days

Pull audit logs, interview staff, review the policy in force at the time, and decide whether it was an impermissible use or disclosure. If it was, run the four-factor breach risk assessment. That analysis can trigger the 60-day notification clock.

04Respond and remediate

By your promised date

Tell the complainant what you found and what you changed, without disclosing another patient's PHI or personnel details. Apply sanctions per 164.530(e) and record the retraining.

05Document and retain

6 years

The complaint, the investigation notes, the response, sanctions, and the risk assessment are all Privacy Rule documentation under 164.530(j): keep them six years from creation or last effective date, whichever is later.

Complaint log: minimum columns

IDReceivedSubjectFinding / actionClosed
C-2026-0142026-06-03Statement mailed to former addressImpermissible disclosure; low probability of compromise2026-06-19
C-2026-0152026-06-11Records request not fulfilled in 30 daysRight-of-access failure; records sent, workflow fixed2026-06-13
C-2026-0162026-07-02Diagnosis said aloud at check-inIncidental disclosure; front-desk script retrained2026-07-15

Sample entries. Add columns for complainant contact, investigator, sanction applied, and breach-assessment outcome.

If OCR writes to you

Calendar the response deadline in the letter, assign one owner, and answer every item in the data request even if the answer is “we did not have this.” Most cases end in technical assistance when the fundamentals exist: a current risk assessment, signed BAAs, training records, and an incident report for the event. Resolution agreements go to entities that are missing those or stop cooperating.

Quick Reference: Filing a HIPAA Complaint

Try the practice first

Privacy Officer contact is in the NPP (164.520(b)(1)(vi)-(vii)). Write, date it, keep a copy.

180 days

From when you knew or should have known. Extensions only for good cause (160.306(b)(3)).

ocrportal.hhs.gov

Health Information Privacy track. Name, contact, entity, dated narrative, consent. Save the transaction number.

No HIPAA lawsuit

No private right of action. State AG (up to $100/violation, $25k cap per year per requirement), state privacy laws, and negligence claims remain.

No retaliation

160.316 and 164.530(g)-(h). Report retaliation as a supplement to your complaint.

Related Tools & Guides