Skip Navigation

HIPAA Privacy Rule Enforcement

HHS’ Office for Civil Rights is responsible for enforcing the Privacy Rule. Enforcement of the Privacy Rule began April 14, 2003 for most HIPAA covered entities. Since 2003, OCR's enforcement activities have obtained significant results that have improved the privacy practices of covered entities.  The corrective actions obtained by OCR from covered entities have resulted in systemic change that has improved the privacy protection of health information for all individuals they serve.


Enforcement Process 

Learn how OCR enforces the Privacy Rule and to learn what OCR considers during its initial intake and review of a complaint. A flow diagram shows the Privacy Rule Complaint Process.

Financial data   

Enforcement Highlights

See a summary of OCR’s enforcement activities and up to date monthly results, including the number of cases in which corrective action was obtained, no violation was found, or other resolutions were achieved.


Enforcement Data

  Magnifying glass and financial charts
View our annual numbers of enforcement cases shown nationally and by state.

Stack of books

Case Examples and Resolution Agreements 

View examples of the corrective actions OCR has obtained from covered entities.

Back to Top