The most frequently reported HIPAA violations fall into a handful of recurring categories: hacking and IT incidents that now account for the vast majority of large data breaches, unauthorized access to patient records by insiders, careless sharing of protected health information through texts and emails, lost or stolen devices, and the failure to conduct the risk assessments that would catch these problems early. Healthcare consistently leads all industries in reported data breaches, and the nature of those breaches has shifted dramatically over the past decade, with cyberattacks replacing physical theft as the primary threat.
Hacking and IT Incidents Dominate the Breach Landscape
If you looked at the breakdown of healthcare data breaches a decade ago, hacking barely registered. In 2010, hacking or IT incidents made up just 4 percent of all reported breaches of protected health information (PHI). By 2024, that figure had ballooned to 81 percent. The total number of breaches reported also climbed steeply, from 216 in 2010 to 566 in 2024. That growth is almost entirely driven by cyberattacks rather than the kinds of physical incidents (stolen laptops, misplaced files) that used to dominate the picture.1PubMed Central. Ransomware Attacks and Data Breaches in US Health Care Systems
What makes these breaches so damaging is not just their frequency but their scale. Over the period from 2010 to 2024, roughly 732 million patient records were affected by breaches. Hacking and IT incidents alone accounted for about 88 percent of those records, or around 643 million. When a hacker gets in, they tend to access data on a far larger number of patients than a single stolen laptop ever could.1PubMed Central. Ransomware Attacks and Data Breaches in US Health Care Systems
The lesson for healthcare organizations is blunt: the threat model has changed. Locking file cabinets and encrypting USB drives still matter, but the dominant risk is now a remote attacker exploiting a software vulnerability or tricking an employee with a phishing email. Organizations that pour their compliance resources into physical safeguards while neglecting network security are fighting the last war.
Ransomware as a Specific and Evolving Threat
Ransomware deserves its own discussion because it hits healthcare with a unique ferocity. Unlike a data breach where records are quietly copied, ransomware locks an organization out of its own systems and demands payment. That means patient care can be disrupted in real time: appointments canceled, surgeries delayed, emergency departments diverted to other hospitals. The HIPAA violation arises because the attack typically involves unauthorized access to PHI, regardless of whether the attacker actually reads the data.
Ransomware attacks went from zero reported cases in healthcare in 2010 to a peak of about 31 percent of all breaches in 2021, then decreased to roughly 11 percent of breaches by 2024. But the patient impact tells a different story. Since 2020, ransomware has affected more than half of all patients involved in breaches each year, reaching 69 percent in 2024. In other words, ransomware attacks make up a smaller share of total incidents now, but the ones that do hit tend to compromise enormous volumes of records.1PubMed Central. Ransomware Attacks and Data Breaches in US Health Care Systems
That pattern reflects an evolution in how ransomware operators choose their targets. They have shifted toward larger health systems, hospital networks, and the third-party vendors that serve dozens of hospitals at once. A single successful attack on a health IT vendor can ripple outward to affect millions of patient records across many organizations, all of whom must then report the breach under HIPAA.
Unauthorized Access by Insiders
Not every HIPAA violation comes from an outside attacker. One of the most persistent and underappreciated categories is the insider breach, where someone with legitimate access to patient records uses that access inappropriately. This might be a curious employee looking up a neighbor’s medical history, a worker snooping on a celebrity patient, or a disgruntled staff member downloading files on the way out the door. Healthcare has been identified as the sector with the largest number of reported breaches, and analysis of those cases shows that portable device, insider, and physical breaches are the three major categories.2PubMed. When it comes to securing patient health information from breaches, your best medicine is a dose of prevention: A cybersecurity risk assessment checklist
Insider violations often go undetected for months or years because the access looks normal at first glance. The employee has a login, they work in the facility, and they open patient charts all day. The violation is about which charts they open and why. Audit trails can catch this, but only if someone actually reviews them. Many organizations log electronic health record access but lack the resources or the software to flag suspicious patterns, such as an employee in billing repeatedly accessing the records of patients they have no reason to view.
The consequences for individuals caught snooping can be severe. HIPAA violations by employees may lead to termination, and in cases involving deliberate theft of PHI for identity fraud or other criminal purposes, federal prosecutors can bring criminal charges. The Office for Civil Rights (OCR) at the Department of Health and Human Services has settled enforcement actions against organizations that failed to implement adequate access controls, even when the underlying violation was committed by a single rogue employee. The organization is held responsible for not having the safeguards in place to prevent or detect it.
Texting and Other Insecure Communication
Clinicians are under constant pressure to communicate quickly. A surgeon needs to share a photo of an X-ray for a second opinion. A nurse texts a physician about a patient’s lab results after hours. These exchanges happen every day, and many of them violate HIPAA because they occur over channels that were never designed to protect health information.
A survey of hand surgeons illustrates how widespread the problem is. Although 63 percent of respondents acknowledged that text messaging does not meet HIPAA security standards, only 37 percent reported that they actually refrain from texting PHI. Younger surgeons and those who believed their texting was compliant were significantly more likely to report messaging patient information.3ScienceDirect. Electronic Communication of Protected Health Information: Privacy, Security, and HIPAA Compliance
The gap between knowing the rules and following them is the heart of this violation category. Doctors and nurses are well aware that standard SMS, consumer email, and popular messaging apps do not encrypt data in the way HIPAA requires. But the convenience factor is overwhelming, and secure alternatives are sometimes clunky or slow. The result is a daily stream of low-grade HIPAA violations happening in plain sight, most of which never get reported because no breach occurs. The risk materializes when a phone is lost, when a message reaches the wrong person, or when an organization is audited and the practice comes to light.
HIPAA does not ban electronic communication of PHI. It requires that the communication be conducted through channels with appropriate safeguards: encryption in transit, access controls, audit logging, and a proper business associate agreement with the platform provider. Organizations that adopt secure messaging platforms and make them as easy to use as consumer texting see the problem largely disappear, but the investment in those tools is uneven across the industry.
Lost and Stolen Devices
Before hacking took over, the single biggest source of large HIPAA breaches was the theft or loss of laptops, smartphones, portable hard drives, and backup tapes containing unencrypted patient data. A laptop stolen from an employee’s car, a USB drive left at a coffee shop, a backup tape that vanished during shipping: each of these could expose thousands of patient records at once.
The HIPAA Security Rule requires encryption of electronic PHI at rest, but it classifies encryption as an “addressable” requirement rather than a mandatory one. That means organizations can choose not to encrypt if they document why an alternative safeguard is equivalent. In practice, many organizations treated “addressable” as “optional,” and lax encryption contributed to years of avoidable breaches. The trend has improved as full-disk encryption has become standard on most modern devices, but older equipment and portable media remain a weak point.
These days, device theft accounts for a much smaller share of breaches than it once did. The shift toward hacking has been so dramatic that theft, unauthorized access, and improper disposal or loss have all declined as a proportion of total breaches.1PubMed Central. Ransomware Attacks and Data Breaches in US Health Care Systems But it has not disappeared, and OCR continues to investigate and settle cases involving unencrypted devices. The enforcement message is clear: if a device holds patient data and it is not encrypted, losing it will be treated as a reportable breach.
Failure to Conduct Risk Assessments
If there is one violation that shows up in OCR settlement after settlement, it is the failure to perform an adequate, organization-wide risk assessment. The HIPAA Security Rule explicitly requires covered entities and their business associates to conduct regular assessments of potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic PHI. Despite this, many organizations either skip the assessment entirely, perform a superficial one, or do it once and never revisit it.
A risk assessment is not just a checklist exercise. It is supposed to identify where PHI lives across the organization, what threats exist, how likely each threat is, and what the potential impact would be. The assessment then drives decisions about which safeguards to implement. When an organization skips this step, it has no systematic way of knowing where its vulnerabilities are. Analysis of actual breach cases has pointed to recurring security gaps that call for prescriptive fixes based on best practices, and a thorough risk assessment is the mechanism through which those gaps are supposed to be identified.2PubMed. When it comes to securing patient health information from breaches, your best medicine is a dose of prevention: A cybersecurity risk assessment checklist
OCR has been particularly unforgiving on this point. In many high-profile settlements, the organization’s failure to perform a compliant risk assessment is listed as a standalone violation, separate from whatever breach triggered the investigation. The practical takeaway: even if your organization has never experienced a breach, the absence of a documented, current risk assessment is itself a HIPAA violation waiting to be discovered during an audit or complaint investigation.
Tracking Pixels and Hidden Data Sharing
A newer and less intuitive violation has emerged around web tracking technologies. Hospitals and health systems routinely embed third-party tracking pixels on their websites and patient portals. These tiny pieces of code, originally designed for advertising analytics, can capture data about what pages a visitor views, what search terms they enter, and sometimes even appointment scheduling details. When a patient logs into a portal and browses pages related to a specific condition, that browsing behavior can be transmitted to companies like Meta or Google without the patient’s knowledge.
Research has found that the use of third-party tracking pixels significantly increases the risk of a data breach, representing a cybersecurity vulnerability that had not been well documented before. The study’s authors noted that these technologies operate outside the traditional scope of HIPAA protections, creating a regulatory gap.4PubMed Central. Beyond the click: Pixel tracking technologies and patient data security in hospitals
OCR issued a bulletin in late 2022 warning healthcare organizations that tracking technologies on their websites could result in impermissible disclosures of PHI. Several large health systems subsequently disclosed breaches affecting millions of patients, specifically because of tracking pixels that had been installed on their patient-facing web pages, often by marketing teams who did not fully understand the HIPAA implications. This category of violation is likely to grow as regulators and patients become more aware of how web tracking intersects with health data privacy.
Inadequate Employee Training
HIPAA requires that all workforce members receive training on the organization’s privacy and security policies. “Workforce” here is broad: it includes not just employees but also volunteers, trainees, and contractors who handle PHI. The training must be provided when someone joins the organization and updated whenever policies change. In practice, training programs vary wildly in quality, from thoughtful interactive sessions to perfunctory annual slide decks that employees click through without reading.
Training failures tend to surface as a contributing factor to other violations rather than as standalone enforcement actions. An employee who was never taught the organization’s policies on texting PHI, or who never learned what phishing looks like, is more likely to cause a breach. When OCR investigates, the lack of documentation showing adequate training becomes an additional finding. The training requirement has been described as the “cornerstone of meaningful implementation” of HIPAA, which makes sense: the rules only work if the people handling patient data actually know what the rules are.
The challenge for large organizations is that the training has to reach everyone, including part-time staff, temporary workers, and clinicians who rotate through multiple facilities. A single untrained employee can trigger a breach that exposes the organization to an enforcement action. Organizations that treat training as a compliance checkbox rather than an ongoing educational effort tend to have higher rates of accidental disclosures and insider incidents.
Improper Disposal of Records
HIPAA requires that PHI be rendered unreadable, indecipherable, and unreconstructable before disposal. For paper records, that means shredding or incineration, not tossing them into a dumpster. For electronic media, it means degaussing, wiping, or physically destroying hard drives, CDs, and tapes. Despite how straightforward this sounds, improper disposal continues to generate enforcement actions.
The violations here tend to be spectacularly avoidable. There have been cases of medical records found in public dumpsters, old hard drives sold on the secondhand market with patient data still readable, and filing cabinets full of PHI left behind when a clinic moved locations. These incidents make headlines precisely because they are so easily preventable. A shredding contract and a media destruction policy would eliminate the risk, yet some organizations still lack even these basic controls.
Smaller practices and clinics are particularly vulnerable. A large hospital system usually has a records management department and contracts with certified destruction vendors. A solo practitioner closing up shop may not think about the boxes of old patient files in the back closet. When those files end up somewhere they should not be, the practitioner is just as liable under HIPAA as a major health system.
Business Associate Failures
Much of healthcare’s data now flows through third-party vendors: cloud hosting providers, billing companies, transcription services, IT support firms, and increasingly, software platforms that use artificial intelligence. Under HIPAA, any entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity is a business associate and must sign a business associate agreement (BAA). The BAA spells out each party’s obligations for protecting patient data.
Two common violations arise in this area. First, organizations sometimes fail to have BAAs in place at all, particularly with smaller vendors or newer technology providers. Second, the BAA exists on paper but the business associate does not actually comply with the security requirements it agreed to. When a business associate experiences a breach, the covered entity that hired them can also face enforcement action if OCR determines that oversight was lacking.
This issue is becoming more complex as healthcare organizations adopt AI tools. Developers and vendors of large language models can become business associates or subcontractors of a business associate under HIPAA when they process PHI on behalf of covered entities.5PubMed Central. AI Chatbots and Challenges of HIPAA Compliance for AI Developers and Vendors Many clinicians have experimented with consumer AI chatbots for tasks like drafting clinical notes or summarizing patient histories, often without considering that entering PHI into a chatbot could constitute an unauthorized disclosure to a company that has not signed a BAA. As AI tools become more embedded in clinical workflows, the line between a helpful productivity tool and a HIPAA liability is getting thinner.
Denial of Patient Access to Records
Most discussions of HIPAA violations focus on data getting out when it should not. But HIPAA also guarantees patients the right to access their own medical records, and denying or unreasonably delaying that access is itself a violation. Under the Privacy Rule, covered entities must provide a copy of requested records within 30 days (with a possible 30-day extension), and may charge only a reasonable, cost-based fee.
OCR has made patient right-of-access cases an enforcement priority in recent years, settling a string of cases against providers who failed to respond to records requests in a timely manner. The penalties in these cases are often modest compared to major breach settlements, but the signal is clear: ignoring or slow-walking a patient’s records request is treated as seriously as many other HIPAA violations. For patients, knowing this right exists and how to exercise it can be the difference between getting the information they need for a second opinion or insurance dispute and being stuck waiting indefinitely.
How Enforcement Actually Works
Understanding which violations are most common is useful, but it helps to know what happens when one is discovered. Most HIPAA enforcement begins with either a complaint filed by a patient or another individual, or a breach report submitted by the organization itself. The OCR investigates, and the outcome ranges from technical assistance (essentially guidance to fix the problem) at the low end, to resolution agreements with corrective action plans and financial penalties at the high end, to referral for criminal prosecution in the most egregious cases.
Financial penalties are tiered based on the level of culpability. A violation the organization did not know about and could not have reasonably known about sits at the lowest tier. A violation caused by willful neglect that the organization failed to correct within 30 days sits at the highest, with penalties that can reach into the millions of dollars per violation category per year. Most enforcement actions fall somewhere in the middle, involving situations where the organization should have known about the risk and could have prevented it with reasonable effort.
State attorneys general can also enforce HIPAA, and several have become increasingly active in pursuing cases, particularly those involving large breaches affecting residents of their states. This adds a second layer of enforcement that organizations sometimes overlook when they focus exclusively on federal OCR actions.
What Individuals Can Do
If you are a patient, you have more power than you might think. You can file a complaint with OCR online if you believe your health information has been mishandled. You can request an accounting of disclosures to see who has accessed your records. And you can ask pointed questions of your providers about how your data is stored, who has access, and what happens when you use their patient portal.
If you work in healthcare, the practical steps are straightforward even if the implementation takes effort. Know your organization’s policies on PHI, particularly around electronic communication. Do not open patient records you have no clinical or administrative reason to access. Report suspected breaches promptly, because the penalties for failing to report tend to be far worse than the penalties for the underlying incident. And if your organization has not conducted a risk assessment recently, or if your training program consists of a five-minute video once a year, those are warning signs that the compliance infrastructure is not where it needs to be.