Skip to main content
Category: Individual Rights

Right to File a Complaint

Also known as: Complaint Right, Right to Complain to OCR, HIPAA Complaint Right
Simply put

Under HIPAA, individuals generally have the right to file a complaint if they believe a covered entity or business associate has not protected their health information or has otherwise violated their privacy rights. Complaints are typically submitted to the U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR), which enforces the HIPAA rules. This right allows people to raise concerns without needing to file a lawsuit themselves.

Formal definition

The right to file a complaint refers to an individual's ability to report a suspected violation of the HIPAA Privacy, Security, or Breach Notification Rules to HHS OCR, the federal authority responsible for HIPAA enforcement. This right is distinct from an individual's separate ability to file an internal complaint directly with the covered entity, which the Privacy Rule generally requires covered entities to accommodate through a designated process and contact. HIPAA does not, as of the applicable regulatory text, create a private right of action for individuals to sue for damages; enforcement is handled by HHS OCR (and in some matters state attorneys general under HITECH). Covered entities and business associates are generally prohibited from retaliating against individuals who exercise this right. Note that HIPAA complaints are separate from broader civil rights complaints (such as discrimination complaints handled by HHS OCR, EEOC, DOJ, or state civil rights agencies), and that state law may provide additional complaint mechanisms or remedies. Specific filing deadlines, procedures, and forms should be confirmed against current HHS OCR guidance.

Why it matters

The right to file a complaint is a cornerstone of HIPAA's enforcement structure because HIPAA does not, as of the applicable regulatory text, create a private right of action allowing individuals to sue a covered entity or business associate directly for damages. Instead, individuals who believe their health information has not been properly protected can bring their concerns to HHS OCR, the federal authority responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules. This mechanism gives patients a meaningful channel to trigger regulatory scrutiny even when they cannot pursue litigation on their own behalf.

For covered entities and business associates, the complaint right shapes both compliance posture and risk. Complaints filed with HHS OCR can prompt investigations, corrective action, and, in some cases, enforcement resolutions. Beyond the federal channel, the Privacy Rule generally requires covered entities to maintain an internal process and designated contact so individuals can complain directly to the organization. Organizations that handle internal complaints poorly may see those concerns escalate to OCR.

HIPAA also generally prohibits retaliation against individuals who exercise this right, which reinforces its role as a protective safeguard. It is important to distinguish HIPAA complaints from broader civil rights complaints, such as discrimination matters handled by HHS OCR, the EEOC, DOJ, or state civil rights agencies; these follow separate processes and legal authorities. State law may also provide additional complaint mechanisms or remedies beyond what HIPAA offers.

Who it's relevant to

Patients and Individuals
Individuals who believe a covered entity or business associate has mishandled their health information or violated their privacy rights can use this right to raise concerns without filing a lawsuit. They may complain internally to the organization and/or file a complaint with HHS OCR, and are generally protected from retaliation for doing so.
Privacy and Compliance Officers
Compliance and privacy officers must ensure their organization maintains a compliant internal complaint process with a designated contact, as generally required by the Privacy Rule, and must handle complaints without retaliating against the individual. Well-managed internal handling can reduce the likelihood of escalation to HHS OCR.
Covered Entities and Business Associates
Both covered entities and business associates fall within HIPAA's enforcement scope and may be subject to HHS OCR investigation prompted by a complaint. They must understand that retaliation against complainants is generally prohibited and that enforcement is handled by OCR rather than through individual lawsuits under HIPAA.
Legal and Enforcement Professionals
Attorneys and enforcement staff should recognize that HIPAA does not create a private right of action, that HHS OCR is the primary enforcement authority, and that state attorneys general may act in some matters under HITECH. They should also distinguish HIPAA complaints from separate civil rights or discrimination complaints and consider additional remedies that state law may provide.

Inside Right to File a Complaint

Complaint to a Covered Entity or Business Associate
The HIPAA Privacy Rule generally requires covered entities to have a process for individuals to file complaints concerning the entity's policies and procedures, its compliance with those policies, or its compliance with the Privacy Rule. This internal complaint mechanism is typically described in the entity's Notice of Privacy Practices.
Complaint to HHS OCR
Individuals may also file a complaint directly with the U.S. Department of Health and Human Services, Office for Civil Rights (HHS OCR), the authority responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules. Such complaints alleging a violation may prompt OCR to review or investigate the matter.
Prohibition on Retaliation
HIPAA generally prohibits covered entities and business associates from intimidating, threatening, coercing, discriminating against, or taking other retaliatory action against an individual for exercising the right to file a complaint, whether internally or with OCR.
Scope Across HIPAA Rules
The complaint right relates to compliance with the Privacy Rule and, more broadly, to obligations OCR enforces, which include the Security Rule (governing ePHI) and the Breach Notification Rule. Readers should distinguish which rule a given concern implicates, since scopes differ.
Timeliness and Filing Requirements
Complaints to OCR are generally expected to be filed within a defined period after the complainant knew or should have known of the alleged violation, and to identify the entity and describe the acts believed to be in violation. Specific filing procedures and timeframes should be verified against current OCR guidance.

Common questions

Answers to the questions practitioners most commonly ask about Right to File a Complaint.

Does filing a HIPAA complaint require me to hire a lawyer or pay a fee?
No. Individuals may generally file a complaint with HHS OCR directly, and there is typically no fee to do so. Legal representation is not required to submit a complaint, though individuals may choose to consult counsel, particularly where state law or other claims may be involved. This entry addresses only the administrative complaint process with OCR and does not describe private lawsuits, which HIPAA generally does not authorize as a private right of action.
If I file a complaint, does that mean the covered entity will automatically be penalized or found in violation?
No. Filing a complaint initiates a process in which HHS OCR may review the matter, but a complaint does not by itself establish that a violation occurred. OCR determines whether it has jurisdiction and whether to investigate, and outcomes vary. Penalties, where applicable, are determined by OCR and their tiers and amounts are adjusted over time; readers should confirm current figures against current OCR guidance.
Where and how is a complaint typically filed with HHS OCR?
Complaints are generally filed with HHS OCR, which offers processes for submission. As of the applicable guidance, OCR has provided electronic and written filing methods. Because the specific portal, forms, and submission channels can change, readers should verify the current filing methods and any required information directly with OCR.
Is there a time limit for filing a HIPAA complaint?
Complaints filed with HHS OCR are generally subject to a time frame measured from when the complainant knew or should have known of the alleged violation, and OCR may waive this period for good cause in some cases. Because the specific timeframe and waiver criteria are set by regulation and guidance, readers should confirm the current deadline against the applicable regulatory text before relying on it.
Can an employee be retaliated against by a covered entity for filing a complaint?
HIPAA generally includes provisions intended to prohibit covered entities and business associates from intimidating, threatening, coercing, or retaliating against individuals who exercise rights such as filing a complaint. The scope and application of these anti-retaliation provisions are defined by regulation, and additional protections may arise under state law or other frameworks. Individuals concerned about retaliation may wish to document the circumstances and verify current protections.
Can a complaint be filed against a business associate, or only against a covered entity?
Complaints to HHS OCR may concern conduct by covered entities and, in appropriate circumstances, business associates, since business associates have direct obligations under certain HIPAA rules. The precise scope of who may be subject to OCR action depends on the defined relationships and the specific rules at issue. Readers should note that obligations attach through those defined relationships rather than to every vendor that handles data, and should verify how a particular situation is treated under current guidance.

Common misconceptions

Filing a HIPAA complaint gives the individual a private right to sue the covered entity for damages under HIPAA.
HIPAA is enforced by HHS OCR, and the right to file a complaint is an administrative avenue rather than a general private cause of action under the statute. Individuals seeking monetary relief may need to look to state law or other legal theories, which fall outside the scope of HIPAA itself; readers should confirm available remedies with counsel.
An individual must complain to the covered entity first before contacting HHS OCR.
The internal complaint process and the ability to file with OCR are generally separate avenues. An individual is typically not required to exhaust the entity's internal process before filing a complaint with OCR, though procedures should be confirmed against current OCR guidance.
A covered entity may discipline or refuse service to someone who files a complaint.
HIPAA generally prohibits retaliation against individuals for exercising the right to file a complaint. Taking adverse action against a complainant for filing may itself raise compliance concerns.

Best practices

Establish and document a clear internal complaint intake process, and describe how individuals may file complaints in the Notice of Privacy Practices.
Train workforce members to recognize complaints, route them appropriately, and avoid any conduct that could be perceived as retaliation against a complainant.
Maintain records of complaints received and their resolution, and retain related documentation consistent with applicable HIPAA retention requirements, which should be verified against current regulation.
Inform individuals of their ability to file a complaint with HHS OCR in addition to any internal process, without requiring exhaustion of the internal process first.
Review the substance of complaints for patterns that may indicate gaps in Privacy, Security, or Breach Notification Rule compliance, and address root causes rather than only individual incidents.
Confirm current OCR filing procedures, timeframes, and any additional obligations under state law or the HITECH Act, since these may impose requirements beyond the baseline HIPAA complaint provisions.