Knowing offense
A person knowingly acquires or releases individually identifiable health information in a way the statute does not permit.
HIPAA Readiness
Translate HIPAA criminal penalties into clear scope, owned controls, current evidence, practical remediation, and a readiness position the organization can support.
CISO-led guidance from Ali Hassani, backed by 25+ years of IT, cybersecurity, compliance, and infrastructure experience.
The Department of Justice is responsible for criminal prosecutions. The statute applies to a person who knowingly acts in violation of the HIPAA administrative simplification provisions described in the law.
A person knowingly acquires or releases individually identifiable health information in a way the statute does not permit.
Using deception or another false representation in the offense increases the available maximums.
The highest level addresses sale, transfer, or use for commercial advantage, personal benefit, or malicious harm.
Primary source: 42 U.S.C. § 1320d-6 - Wrongful disclosure of individually identifiable health information. This summary is educational and does not replace legal advice.
Use unique accounts, role-based authorization, access reviews, audit logging, workforce training, sanctions, prompt offboarding, secure support access, and investigation procedures that preserve evidence.
Use the action plan to connect workforce controls with risk analysis, incident response, and recurring evaluation.
This website uses essential cookies for security and operation. Optional analytics and advertising cookies help measure site use and outreach. Choose Allow or Deny. You can change your choice at any time.