A HIPAA violation is not automatically a felony, but the same incident can create federal felony exposure when a person knowingly and wrongfully obtains or discloses protected health information under false pretenses or with intent to sell, transfer, or use the information for commercial advantage, personal gain, or malicious harm, while many HIPAA compliance violations are addressed through civil enforcement rather than criminal prosecution.
HIPAA compliance failures are usually handled through civil enforcement under the HIPAA Privacy Rule, the HIPAA Security Rule, and the HIPAA Breach Notification Rule. Civil enforcement focuses on organizational obligations such as administrative safeguards, technical safeguards, policies and procedures, workforce training, and breach response. Civil cases may result in corrective action obligations, resolution agreements, and civil monetary penalties.
Criminal liability under HIPAA applies when a person knowingly and wrongfully obtains or discloses individually identifiable health information. The offense level depends on the intent and surrounding facts. A knowing wrongful obtainment or disclosure can carry a maximum term of imprisonment of one year. Wrongful obtainment or disclosure under false pretenses can carry a maximum term of imprisonment of five years. Wrongful obtainment or disclosure with intent to sell, transfer, or use the information for commercial advantage, personal gain, or malicious harm can carry a maximum term of imprisonment of ten years.
Felony exposure arises when the maximum term of imprisonment exceeds one year, which aligns with the five year and ten year penalty levels. Conduct that supports felony charging includes accessing records by misrepresenting authority, obtaining information under false pretenses, selling patient information, using patient information for fraud, or disclosing information to cause harm. The facts of the incident, the actor’s intent, and available evidence drive charging decisions.
Organizations reduce criminal risk by preventing unauthorized access and documenting workforce conduct controls. Role-based access, audit logging, sanctions for unauthorized access, and training that distinguishes job-related access from curiosity access support compliance and deter misconduct. Incident response procedures that preserve logs and support internal investigations help ensure that suspected criminal activity is handled through appropriate reporting and escalation channels.
