HIPAA Requires Notification — But Gives You No Right to Sue
If you received a breach notice from a hospital, clinic, insurer, or other HIPAA-covered entity, the notification itself is required by federal law: the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414) requires covered entities and their business associates to notify affected individuals "without unreasonable delay" and no later than 60 days after discovering a breach of unsecured protected health information. For breaches affecting 500 or more people in a state or jurisdiction, the entity must also notify prominent media outlets and the HHS Secretary immediately; smaller breaches are reported to HHS annually.
What the notice does not give you is a lawsuit under HIPAA itself. Courts have consistently held — and HHS confirms — that HIPAA creates no private right of action; you cannot sue a hospital or insurer directly for "violating HIPAA." What you can do is file a complaint with the HHS Office for Civil Rights (OCR) within 180 days of when you knew about the act or omission (OCR can extend this for good cause). OCR investigates, and for serious or widespread violations can extract corrective action plans and civil monetary penalties — but those penalties go to the U.S. Treasury, not to you.
This gap between "notified" and "compensated" is the central thing to understand: your realistic path to money after a healthcare data breach almost never runs through HIPAA directly. It runs through state law, class action litigation, or — for EU/UK residents — data protection law that does create a direct right to compensation.
What You Can Realistically Recover
The mechanism depends entirely on which law actually applies to your situation
HHS OCR complaint (HIPAA)
No direct payment to you — OCR can impose penalties on the organization and order corrective action, but the money does not come to you.
State private right of action (e.g., CA CMIA)
Statutory damages per violation without proving harm, plus actual damages and possibly attorneys' fees, where your state provides this right. [verify state-specific availability and amounts]
GDPR Article 82 (EU/UK)
Compensation for material and non-material damage, including justified fear of future misuse — assessed on your actual circumstances, not a fixed schedule.
Where the Real Money Rights Live: State Law and GDPR
Several states fill the gap HIPAA leaves open with their own medical-privacy statutes that do create a private right of action. California's Confidentiality of Medical Information Act (CMIA), Civil Code § 56.36, is the best-known: it lets a patient sue a healthcare provider or plan directly, and allows nominal statutory damages (commonly cited around $1,000 per negligent violation, without needing to prove actual harm) plus actual damages, and up to a higher amount for willful violations, plus attorneys' fees. verify current dollar figures and the exact willful-violation cap against the current statute text before relying on a specific number. A May 2026 California Supreme Court decision clarified the standard for what counts as a compensable CMIA breach in the data-breach context — check current case law if you are relying on this route. Other states have their own, narrower medical-privacy statutes; whether your state gives you an equivalent private right of action is state-specific and needs individual confirmation. verify state-by-state
Separately, many health apps, wearables, and direct-to-consumer services (period trackers, fitness apps, at-home test kits) are not HIPAA-covered entities at all, because they don't sit inside the traditional provider/insurer/clearinghouse relationship HIPAA regulates. The FTC's Health Breach Notification Rule — substantially amended in 2024, with the amendments effective July 29, 2024 — fills part of that gap: it requires vendors of "personal health records" and connected health apps/devices that are not HIPAA-covered to notify affected consumers, the FTC, and (for large breaches) the media, on a similar "without unreasonable delay, no later than 60 days" timeline. Like HIPAA, this FTC rule is enforced by the government, not by an individual lawsuit — the FTC can pursue penalties and injunctive relief, but again does not put money directly in your pocket through the rule itself.
If you are in the EU or UK, GDPR gives you something HIPAA does not: Article 82 creates a direct right to compensation from the controller (the healthcare provider, insurer, or app) for material or non-material damage caused by a breach of the GDPR, including a data breach. The Court of Justice of the EU has clarified there is no minimum-severity threshold — well-founded fear of future misuse of your data can itself count as compensable non-material damage — but you still need to show an actual breach, actual damage, and a causal link; compensation is meant to make you whole, not to punish the controller. You can also complain to your national data protection authority (the ICO in the UK) at no cost, in parallel with or instead of a civil claim.
When the Usual Rules Don't Apply
Not every breach triggers a notification duty. If the exposed data was properly encrypted or otherwise rendered "unsecured" only in a way that meets the HHS/NIST safe-harbor standard, it may not count as a reportable breach under HIPAA at all — you may never receive a notice even though a security incident occurred, because the law treats properly-secured data differently from readable data.
Many entities that feel like "healthcare" companies are not HIPAA-covered entities or business associates — a wellness app that never bills insurance or works with a provider, for instance — so a breach there falls to the FTC rule (if it applies) or general state consumer-protection and data-breach-notification law instead, not HIPAA. Don't assume HIPAA applies just because health information was involved.
Class action settlements arising from a large breach are common but are a different track from an individual OCR complaint or state private-right-of-action claim — check any settlement notice carefully for claim deadlines and whether accepting a settlement payment requires you to release other claims.
What to Do After a Healthcare Data Breach Notice
Different tracks for different goals — regulatory pressure, individual compensation, or class settlement
Read the notice carefully and save it
Note exactly what categories of information were exposed (e.g., name and address only, versus diagnosis codes, Social Security numbers, or financial account details) — this materially affects both your practical risk and which legal routes are worth pursuing.
Enroll in any free credit monitoring offered
Breach notices for larger incidents often include free credit monitoring or identity-theft protection for a limited enrollment window — sign up promptly if offered, and keep the confirmation.
File a HIPAA complaint with HHS OCR if a covered entity is involved
Complaints must generally be filed within 180 days of when you knew about the issue (extendable for good cause). This won't pay you directly, but can trigger investigation, corrective action, and penalties against the organization.
Check whether your state gives you a direct claim
California residents should look at the CMIA; other states may have their own medical-privacy or data-breach statutes with a private right of action. This is genuinely state-specific — what works in one state may not exist in another. verify your state's specific statute before assuming a right exists
Watch for class action notices
Large breaches frequently trigger multidistrict litigation or class settlements; if you receive a claims-administrator notice, read the deadline and the proof-of-loss requirements (some settlements pay a flat sum, others require documented out-of-pocket losses for a higher payout).
EU/UK residents: contact the ICO or your national DPA, or pursue an Article 82 claim
A regulator complaint is free and doesn't require a lawyer; a direct Article 82 damages claim is a separate civil route if you have suffered — or reasonably fear — concrete harm from the breach.
Documents to gather
- The original breach notification letter or email
- Any free credit-monitoring or identity-protection enrollment confirmation
- Evidence of actual harm — fraudulent charges, new accounts opened in your name, collection notices for debts you don't recognize
- Correspondence with the healthcare provider, insurer, or app about the breach
- Any class action settlement claim notice you receive
Timelines and Deadlines
The notification deadline the organization owes you is different from the deadline for your own complaint or claim
Track two separate clocks: how quickly the breached organization had to notify you, and how long you have to act once you know.
| Jurisdiction | Limitation Period |
|---|---|
| US — HIPAA breach notification to you | Without unreasonable delay, no later than 60 days after the covered entity discovers the breach |
| US — HHS OCR complaint window | 180 days from when you knew of the act or omission (extendable for good cause) |
| US — FTC Health Breach Notification Rule | Without unreasonable delay, no later than 60 days after discovery (non-HIPAA health apps/devices) |
| California — CMIA civil claim | Subject to California's general statute of limitations for statutory claims verify exact limitation period for your specific CMIA claim |
| EU/UK — GDPR Article 82 claim | Set by each member state's national limitation rules, not by the GDPR itself verify the limitation period in your specific country |
Realistic Outcomes and Caveats
An HHS OCR complaint can lead to a meaningful corrective-action plan or penalty against a healthcare organization with a documented pattern of failures, but it is not a mechanism for individual compensation — treat it as a regulatory-pressure tool, not a payout.
State private-right-of-action claims (where they exist, like California's CMIA) can produce real statutory damages without needing to prove financial loss, but availability, dollar amounts, and procedural requirements vary sharply by state and by the specific facts of the breach — this is not a one-size-fits-all right.
Class action settlements from large breaches often pay a modest flat amount (commonly well under a few hundred dollars) unless you can document actual, provable losses like fraud-related costs, in which case some settlements offer a higher documented-loss tier.
GDPR Article 82 claims are genuinely individualized: courts weigh the seriousness of the breach and the reality of your fear or harm, and outcomes vary considerably by country and by the specific facts.
Common Pitfalls
Assuming HIPAA lets you sue the hospital or insurer directly
It does not — HIPAA has no private right of action. Your realistic path runs through OCR complaints (no payout), state law (where available), or class litigation.
Missing the 180-day OCR complaint window
This clock starts when you knew about the issue, not when you get around to filing — file promptly if you want the complaint considered on time.
Assuming a health app or wearable is HIPAA-covered
Many consumer health apps aren't HIPAA-covered entities at all; the FTC Health Breach Notification Rule, not HIPAA, is usually the relevant framework there.
Not checking your specific state's law
A right that exists in California under the CMIA may simply not exist in your state — don't assume a nationwide private right of action.
Missing a class action settlement claim deadline
These notices can look like spam. Read anything referencing a data breach settlement carefully before discarding it.
Organize Your Healthcare Data Breach Records
Use the calculator to identify which legal route may apply to your situation and organize the notice, dates, and evidence you'll need.
Organize Your Healthcare Data Breach Records
Use the calculator to identify which legal route may apply to your situation and organize the notice, dates, and evidence you'll need.
This stays in your private workspace until you choose a next step. It does not submit a claim on your behalf on its own.
Official and Legal References
US (Federal + State) vs. EU/UK Rights After a Healthcare Breach
Federal HIPAA in the US mandates notification but gives no private right of action — your OCR complaint pressures the organization, but doesn't pay you. Individual states may fill that gap (California's CMIA is the clearest example); non-HIPAA health apps fall under the FTC's Health Breach Notification Rule instead. The EU and UK take a different approach: GDPR Article 82 gives you a direct, individualized right to compensation for material or non-material harm from a breach, enforced through national courts and backed by your national data protection authority. Check which regime actually governs your situation before assuming a right you don't have — or missing one you do.
Frequently Asked Questions
The questions people ask right after opening a breach notice
Can I sue my hospital or insurer directly under HIPAA?
My period-tracking or fitness app got breached — does HIPAA cover that?
I live in California — is the CMIA automatically going to pay me?
Organize Your Healthcare Data Breach Records
Use the calculator to identify which legal route may apply to your situation and organize the notice, dates, and evidence you'll need.