Skip to content
HIPAA

HHS Issues Annual Report on HIPAA Compliance

The Baldwin Group
|
Updated: April 24, 2024
|
1 minute read

As required by the Health Information Technology for Economic and Clinical Health (HITECH) Act, the Office of Civil Rights (OCR) has issued its annual report to Congress on HIPAA Privacy, Security, and Breach Notification Rule compliance for the 2022 calendar year.

Employer Action Items

Plan sponsors of HIPAA-covered entities, especially those of self-insured health plans and business associates, should continually self-assess their compliance with the HIPAA privacy and data security rules, and the requirements under the HITECH Act. This includes ensuring business associate agreements are current, appropriate safeguards are being maintained, and policies and procedures are up-to-date and being followed.

Summary

A summary of OCR’s findings found that during 2022, it received 30,435 new complaints alleging violations of HIPAA and the HITECH Act, and resolved 32,250 complaints. Most of these (87%) were resolved before initiating an investigation. In the 560 investigations that the OCR conducted, the covered entity or business associate took corrective action. 17 were resolved with Resolution Agreements and Corrective Action Plans (RA/CAP) and monetary settlements totaling over $802,500, and two with civil money penalties totaling $100,000.

The OCR also completed 846 compliance reviews and required entities to take corrective action or pay a civil penalty in 674 (80%) of these investigations, two of which resulted in RA/CAPs, along with monetary payments totaling over $2.4 million.

In addition, the OCR engaged in 124 outreach activities to (1) increase education to the public about their HIPAA rights, and to regulated entities about trends in large HIPAA breaches and (2) educate regarding the requirements of the HIPAA rules.

Read the full report here.


Related Insights

Stay in the know

Our experts monitor your industry and global events to provide meaningful insights and help break down what you need to know, potential impacts, and how you should respond.

Baldwin Bulletin
Upcoming Compliance Deadlines August 2025
Employers must comply with numerous reporting and disclosure requirements in connection with their group health plans. Please note the following upcoming...
Baldwin Bulletin
The ACA In Mergers in Acquisitions – Part I
August 2025Jason Sheffield, National Director of Compliance Identifying and Mitigating ACA-related Liabilities Arising in Connection with Corporate Transactional Activities Introduction...
Baldwin Bulletin
IRS Announces 2026 Affordable Care Act Pay-or-Play Penalties 
August 2025  Stephanie Hall, Associate Director, Benefits Compliance  On July 22, 2025, the Internal Revenue Service (“IRS”) announced the updated...
Baldwin Bulletin
Navigating “Mini-COBRA” or “COBRA-like” (state continuation of coverage) Requirements: A New Era for ERISA Compliance 
August 2025  Deanna Sizemore, Associate Director, Benefits Compliance  For employer plan sponsors, understanding and complying with various benefit laws is...
Baldwin Bulletin
Navigating Medicare Part D: 2026 Creditable Coverage Changes & Disclosure Essentials for Employers 
August 2025Deanna Sizemore, Associate Director, Benefits Compliance Summary  As we look forward to 2026, employer-sponsored health plans face new considerations...
Let's make it possible

Partner with us to build solutions that align with your business, individual, or employee needs and open new possibilities for your future.

Connect with us