HIPAA Violation Examples: 15 Common Scenarios and How to Avoid Them
Quick answer: Most HIPAA violations are not sophisticated cyberattacks — they are everyday process failures: snooping in records, lost unencrypted devices, improper disposal, oversharing on social media, missing agreements, and ignored patient requests. The scenarios below are common, real-world violation patterns that mirror the conduct OCR repeatedly penalizes. Each is paired with the control that prevents it, because the point is not to memorize cautionary tales but to close the gaps before they become your story.
15 common HIPAA violation scenarios
- Snooping on records. A workforce member views a celebrity’s, coworker’s, or ex-partner’s chart with no treatment reason. Prevented by role-based access and routine audit-log review.
- Lost or stolen unencrypted laptop. A device holding PHI disappears from a car or home. Encryption is a safe harbor that turns a reportable breach into a non-event.
- Improper disposal. Paper charts in an open dumpster or hard drives discarded without wiping. Prevented by documented disposal and media-sanitization procedures.
- Social media oversharing. Staff post a patient photo, a “funny” case, or respond to an online review with identifying detail. See our HIPAA social media policy guidance.
- Misdirected email or fax. The right record sent to the wrong recipient — a leading cause of reportable breaches. Prevented by verification steps and minimum-necessary habits.
- No Business Associate Agreement. Sharing PHI with a vendor before a BAA is signed. Every vendor that touches PHI needs one.
- No risk analysis. Operating without an accurate, enterprise-wide Security Risk Analysis — the single most cited finding in OCR settlements.
- Ignoring patient access requests. Failing to provide records within the deadline or overcharging — the focus of OCR’s Right of Access Initiative.
- Texting PHI over consumer SMS. Unencrypted texts with no provider agreement. Use a secure messaging platform instead.
- Shared or weak logins. A single “frontdesk” login with no multi-factor authentication, making audit trails meaningless.
- Unattended workstations. Screens left open in patient-visible areas. Prevented by automatic logoff and physical safeguards.
- Talking about patients in public. Hallway, elevator, or check-in conversations overheard by others — an oral-PHI disclosure.
- Terminated employee keeps access. Accounts not deactivated on the last day. Prevented by same-day deprovisioning.
- Unpatched or end-of-life systems. Software no longer receiving security updates, left exposed because it was never inventoried.
- Releasing more than necessary. Sending an entire record when a single result was requested, violating the minimum necessary standard.
The pattern behind the examples
Read together, these scenarios share a root: a gap that nobody had inventoried or assigned an owner. Snooping persists where no one reviews logs; lost-device breaches happen where encryption was “addressable” and skipped; missing BAAs survive because no one tracks the vendor list. That is exactly what a structured assessment is designed to catch, and why a simple HIPAA compliance checklist paired with a real risk analysis prevents far more violations than any single policy.
How the risk analysis prevents these
Almost every scenario above maps to a control the Security Risk Analysis is supposed to evaluate. That analysis is required under 45 CFR § 164.308(a)(1)(ii)(A) — an accurate and thorough assessment of risks to all electronic PHI — and it forces you to ask who has access, which devices and vendors touch PHI, whether encryption and logging are on, and how access is removed when someone leaves. The reason OCR’s first request is always the risk analysis is that it is where these everyday failures are supposed to be found and fixed first.
The proposed 2026 Security Rule update
In December 2024, the HHS Office for Civil Rights published a Notice of Proposed Rulemaking (NPRM) to modernize the Security Rule. It is a proposal, not final law, and nothing in it is enforceable today. If finalized as written, it would make measures that are currently “addressable” — such as encryption and multi-factor authentication, two controls that would have prevented several scenarios above — effectively mandatory, with roughly a 240-day compliance window after publication. Closing these gaps now is the same work the proposal would later require.
How Medcurity helps
Medcurity turns this list of failure modes into a structured, guided Security Risk Analysis: it walks you through access, devices, vendors, and workflows, flags the gaps that cause real violations, and tracks remediation with audit-ready documentation. Pricing is $499/year (about $42/month) for a single organization; larger or multi-location organizations can request a quote. The fastest way to stay off the violation list is to find your gaps before someone else does.
Frequently Asked Questions
What is the most common HIPAA violation?
In OCR enforcement, the most frequently cited issue is the lack of an accurate, enterprise-wide risk analysis. Among day-to-day incidents, lost or stolen unencrypted devices, misdirected email or fax, and unauthorized record access (snooping) are among the most common.
Is snooping in records really a HIPAA violation?
Yes. Accessing a patient’s record without a legitimate treatment, payment, or operations reason is an impermissible use of PHI, even by an authorized employee and even if nothing is shared. It is prevented by role-based access and detected through audit-log review.
Can a single employee cause a HIPAA violation for the whole organization?
Yes. The covered entity is responsible for its workforce’s conduct, so one person’s snooping, mis-sent email, or social media post can create organizational liability. That is why training, access controls, and monitoring are organizational obligations, not individual ones.
How do we avoid HIPAA violations?
Maintain a current Security Risk Analysis, enforce role-based access and multi-factor authentication, encrypt devices and email, sign Business Associate Agreements with every vendor that touches PHI, deprovision access promptly, train staff, and review audit logs. Most violations trace back to one of these being missing.