How is the government enforcing the Privacy Rules?
At least for now, the Office for Civil Rights (“OCR,” the agency responsible for enforcing the Privacy Rules) has indicated that enforcement will be complaint-based. Accordingly, OCR will respond to complaints that are filed but will not proactively investigate. If a patient has a complaint that a physician violated the patient’s privacy rights, the patient may choose to complain to the physician, to OCR, or to both. If the patient complains to OCR, OCR or the Department of Justice (“DOJ”) will likely follow up with the physician to request an explanation and response. OCR/DOJ may ask the physician to implement a voluntary corrective action plan. It is unlikely that OCR or DOJ would make an on-site investigation unless the physician was uncooperative or the government determined that an on-site investigation was necessary. So far, it appears that OCR has not issued any fines. A violation of HIPAA can result in civil fines and/or criminal penalties, however, so it is important that phys