
What are the top 5 HIPAA violations?
Key Facts
- OCR has received over 374,321 HIPAA complaints since 2003 and imposed $144.9 million in penalties across 152 enforcement cases
- Impermissible uses and disclosures of PHI rank as the #1 most frequently alleged HIPAA violation
- One organization paid $387,000 after faxing a patient's complete HIV record to their employer
- Failing to revoke an ex-employee's access to 557 patients' ePHI cost one organization over $111,000
- Most small HIPAA breaches stem from human error like misdirected faxes and emails, not sophisticated cyberattacks
- Standard SMS generally isn't HIPAA compliant for ePHI due to missing encryption, access controls, and audit controls
- A permissible recall message becomes a HIPAA violation when run through an email platform that won't sign a Business Associate Agreement
The Most Common HIPAA Violations: What OCR Data Shows
The OCR enforcement data since 2003 reveals a clear pattern in HIPAA violations, with certain issues recurring far more frequently than others. Understanding these patterns helps organizations focus their compliance efforts where they matter most. Over 374,321 complaints have been received by the OCR since April 2003, with 99% resolved and $144,878,972.00 in civil money penalties imposed or settled across 152 cases.
The top five violations, ranked by frequency in complaints, are impermissible uses and disclosures of PHI, lack of safeguards for PHI, lack of patient access to PHI, lack of administrative safeguards for electronic PHI, and use or disclosure of more than the minimum necessary PHI. These categories represent the most common pitfalls in HIPAA compliance, often stemming from procedural gaps or human error rather than sophisticated cyberattacks.
Real enforcement examples illustrate the tangible impact of these violations. A $387,000 settlement resulted from faxing a patient's complete HIV record to their employer, while a $2.2 million penalty followed the unauthorized filming of "NY Med" without patient authorization. Another case saw a $111,000+ penalty for failing to terminate an ex-employee's access to a scheduling calendar containing ePHI of 557 patients. These incidents highlight how preventable mistakes—like misdirected communications or delayed access revocation—can lead to significant financial and reputational harm.
For businesses handling patient information, CallMyCustomers builds safeguards directly into its outreach process to address these common failure points. Every campaign operates under a Business Associate Agreement (BAA) for HIPAA-covered clients, ensuring that patient data is handled in compliance with privacy and security rules. Owner approval of all scripts and messages prevents impermissible disclosures, while immediate honoring of opt-outs and explicit consent collection in the booking flow support patient rights and minimum necessary principles. By combining human judgment with automated scale, the service reduces reliance on error-prone manual processes while maintaining strict adherence to HIPAA requirements. Turn past customers, old quotes, and inactive members into booked work — approved by you, run by us. Start with a free list review.
Why These Violations Happen: Human Error and Tool Risks in Patient Outreach
A single misdirected fax once cost a healthcare organization $387,000. It wasn't a sophisticated cyberattack — just an employee sending a patient's complete HIV record to the wrong recipient, an employer no less. That's the uncomfortable truth behind most HIPAA violations: they're preventable human errors, not elaborate hacks.
The Office for Civil Rights has received over 374,000 HIPAA complaints since 2003, and the most frequently alleged violations — impermissible disclosures, lack of safeguards, and exceeding the minimum-necessary standard — trace back to everyday procedural gaps. According to HIPAA Journal's breach analysis, the majority of small breaches (under 500 individuals) are unauthorized access and disclosure incidents like accidentally faxing, emailing, or mailing PHI to the wrong person.
Common workforce errors include:
- Leaving devices unsecured or sharing passwords
- Using unsecured communication channels for PHI
- Sending records to the wrong recipient
- Failing to terminate a former employee's system access
That last one is real: one organization paid over $111,000 after failing to revoke an ex-employee's access to a scheduling calendar containing ePHI for 557 patients. As risk management expert Donna Vanderpool puts it, no amount of IT resources can prevent breaches involving blatant violations of patient confidentiality — culture and accountability matter as much as technology.
For clinics running patient reactivation campaigns, the root cause is often the tool, not the message. A perfectly permissible recall reminder becomes a violation when the patient list — names, emails, last-visit dates, procedure interests — sits in an email platform that won't sign a Business Associate Agreement, according to compliance guidance on patient reactivation. Standard SMS compounds the risk: it generally isn't HIPAA compliant for ePHI due to missing encryption, access controls, and audit controls, and should only be used when patients initiate contact or request texts with documented consent, per HIPAA Journal.
This is why compliant outreach structure matters more than good intentions. Treatment-adjacent messages like recall reminders and follow-ups generally fall under healthcare operations and don't require separate authorization — but opt-outs must work immediately, and sensitive details must stay out of subject lines. When clinics work with outreach partners, safeguards like operating under BAA/HIPAA agreements, collecting explicit consent in the booking flow, and having the practice approve every script before anything is sent turn reactivation from a liability into a controlled, defensible process. CallMyCustomers, for example, builds all three into its clinic campaigns — because the goal is reconnecting with dormant patients, not creating the next enforcement case.
How CallMyCustomers Built-In Safeguards Prevent Each Violation
How CallMyCustomers Built-In Safeguards Prevent Each Violation
CallMyCustomers turns compliance risks into secure, permission-based reactivation by embedding safeguards that directly counter the top five HIPAA violations identified in OCR enforcement data. Each control is designed to align with regulatory requirements while supporting effective patient outreach for service businesses.
For impermissible uses and disclosures of PHI—the most frequently alleged violation—CallMyCustomers operates all dental, med spa, and clinic outreach under a signed Business Associate Agreement (BAA), ensuring that protected health information is handled only as permitted under HIPAA for treatment, payment, or healthcare operations. This addresses the core risk of using non-compliant tools, where even permissible recall messages become violations if patient data resides in platforms unwilling to sign a BAA.
To prevent lack of safeguards for PHI, the service enforces owner approval of every script, offer, and message before outreach begins, combining real human judgment with automated scale. This procedural safeguard minimizes human error, such as sharing PHI via unsecured channels or curiosity-driven access, which HIPAA Journal identifies as common workforce violations rooted in procedural gaps rather than sophisticated attacks.
Immediate opt-out honoring eliminates the risk of failing to respect patient access rights, a top-five violation often tied to delayed or ignored requests. CallMyCustomers honors opt-outs instantly across all channels, ensuring that once a patient requests no further contact, their preference is respected everywhere—aligning with guidance that opt-out mechanisms must work "immediately, everywhere" for treatment-adjacent communications.
For lack of administrative safeguards for electronic PHI, the platform integrates regulated texting practices that comply with TCPA and A2P 10DLC standards, avoiding the pitfalls of standard SMS, which lacks encryption and access controls. Texts are only sent when patients have initiated contact or provided documented consent, with explicit consent collected during the booking flow to ensure compliance when ePHI is involved.
Finally, to prevent use or disclosure of more than the minimum necessary PHI, CallMyCustomers limits outreach to essential information—such as appointment reminders or service follow-ups—without including sensitive details in subject lines, preview text, or message bodies. This minimum-necessary approach is reinforced by owner-reviewed content and segmentation based solely on recency, service type, or membership status, ensuring that only relevant, non-sensitive data is used in reactivation efforts.
By mapping each safeguard to a specific violation, CallMyCustomers demonstrates how permission-based reactivation can be both effective and compliant—turning a dormant list into booked work without compromising patient privacy. Turn past customers, old quotes, and inactive members into booked work — approved by you, run by us. Start with a free list review.
Frequently Asked Questions
What are the top 5 HIPAA violations according to OCR enforcement data?
How many HIPAA complaints has the OCR received since 2003, and what percentage were resolved?
Can a recall reminder become a HIPAA violation even if the message itself is permissible?
Why is standard SMS considered risky for sending ePHI under HIPAA?
What real-world example shows the cost of failing to revoke an ex-employee's access to patient data?
How does CallMyCustomers prevent impermissible disclosures of PHI during patient outreach?
From Risk to Reactivation: Turning Compliance into Customer Loyalty
The data is clear: HIPAA violations most often stem from preventable human errors and tool gaps, not sophisticated breaches. Over 374,000 complaints since 2003 reveal recurring patterns—impermissible disclosures, weak safeguards, ignored access requests, administrative oversights, and excessive data sharing—that can derail patient trust and trigger costly penalties. For service businesses looking to reconnect with inactive customers, the solution isn’t just better intentions but built-in safeguards: operating under a BAA, owner-approved messaging, instant opt-out honoring, and explicit consent collection turn outreach into a compliant, defensible process. When done right, reactivating past customers isn’t just low-risk—it’s a proven revenue driver, often costing far less than acquiring new leads. Start with a free list review to see how your dormant list can become booked work—approved by you, run by us. Learn how compliant reactivation pays for itself versus paid acquisition.