Key Takeaways
- In fiscal year 2023, the U.S. Department of Health and Human Services' Office for Civil Rights (OCR) received 674,817 HIPAA complaints, marking a 10% increase from the previous year.
- OCR imposed $6.8 million in HIPAA civil monetary penalties in FY2023, with 78% of penalties resulting from data breaches.
- From 2003 to 2023, OCR has collected over $130 million in HIPAA settlements and judgments across 1,200+ cases.
- In 2023, OCR's breach portal recorded 723 large breaches affecting 133 million individuals under HIPAA.
- Hacking/IT incidents accounted for 83% of major HIPAA breaches (500+ affected) in 2023.
- The largest HIPAA breach of 2023 involved 11.7 million records from a California pharmacy benefit manager.
- 89% of covered entities are HIPAA compliant with basic privacy standards per 2023 surveys.
- 62% of healthcare organizations conducted annual HIPAA risk assessments in 2023.
- Only 45% of providers fully implemented HIPAA Security Rule technical safeguards in 2022 audits.
- In FY2023, OCR closed 42,000+ HIPAA cases, with 15% resulting in enforcement actions.
- OCR conducted 112 HIPAA compliance reviews in 2023, focusing on high-risk entities.
- From 2019-2023, OCR issued 250+ corrective action plans to resolve HIPAA violations.
- 92% of healthcare workers received HIPAA training in 2023 per surveys.
- 76% of organizations provide HIPAA training within 30 days of hire.
- Only 43% of small practices offer annual HIPAA refresher training.
HIPAA enforcement grew with rising breaches and heavy fines in 2023.
Compliance Statistics
Compliance Statistics Interpretation
Data Breaches
Data Breaches Interpretation
Education and Training
Education and Training Interpretation
Enforcement Actions
Enforcement Actions Interpretation
Violations and Fines
Violations and Fines Interpretation
Sources & References
- Reference 1HHShhs.govVisit source
- Reference 2HIPAAJOURNALhipaajournal.comVisit source
- Reference 3OCRPORTALocrportal.hhs.govVisit source
- Reference 4HEALTHIThealthit.govVisit source
- Reference 5JUSTICEjustice.govVisit source
- Reference 6PONEMONponemon.orgVisit source
- Reference 7HIMSShimss.orgVisit source
- Reference 8BECKERSHOSPITALREVIEWbeckershospitalreview.comVisit source
- Reference 9HEALTHSECTORCOUNCILhealthsectorcouncil.orgVisit source
- Reference 10GAOgao.govVisit source
- Reference 11AMERICANBARamericanbar.orgVisit source
- Reference 12IBMibm.comVisit source
- Reference 13VERIZONverizon.comVisit source
- Reference 14PHRphr.comVisit source
- Reference 15CDCcdc.govVisit source
- Reference 16MGMAmgma.comVisit source
- Reference 17HFMAhfma.orgVisit source
- Reference 18KLASRESEARCHklasresearch.comVisit source
- Reference 19AAFPaafp.orgVisit source
- Reference 20KFFkff.orgVisit source
- Reference 21AMA-ASSNama-assn.orgVisit source
- Reference 22COMMONWEALTHFUNDcommonwealthfund.orgVisit source
- Reference 23JOINTCOMMISSIONjointcommission.orgVisit source
- Reference 24ADAada.orgVisit source
- Reference 25CMScms.govVisit source
- Reference 26ATAata.orgVisit source
- Reference 27NCPANETncpanet.orgVisit source
- Reference 28ISACAisaca.orgVisit source
- Reference 29NAAGnaag.orgVisit source
- Reference 30NCBIncbi.nlm.nih.govVisit source
- Reference 31ANAana.orgVisit source
- Reference 32SHRMshrm.orgVisit source
- Reference 33AAMCaamc.orgVisit source
- Reference 34ONC-HEALTHITonc-healthit.govVisit source
- Reference 35MILLENIALHEALTHmillenialhealth.orgVisit source
- Reference 36AHAaha.orgVisit source






