How is HIPAA enforced?
A. HIPAA is enforced by an agency of the United States government called “Health and Human Services” or “HHS” for short. HHS has the power to investigate plans to determine if they are complying with HIPAA requirements, and plans are obligated to cooperate with the investigation. HHS can fine plans for HIPAA violations. An individual has no civil cause of action under HIPAA, which means that he or she cannot sue a plan because of a HIPAA violation. However, if the plan document has been amended to add HIPAA provisions, the individual may sue to enforce HIPAA under the Employee Retirement Income Security Act of 1974 (“ERISA”).