A HIPAA complaint against your NEMT company: how OCR investigates and what to send
Overview
A HIPAA complaint must reach HHS's Office for Civil Rights within 180 days of when the person knew of the problem. If OCR opens an investigation, it describes the allegation in writing and asks your company for records, and you must cooperate. Most cases close with technical assistance or corrective action. Unresolved ones can end in a settlement or a civil money penalty, which you have 90 days to contest.
On this page
How a HIPAA complaint reaches OCR
Anyone can file a HIPAA complaint with HHS’s Office for Civil Rights, in writing, on paper or online. It must name the company and describe what it believes went wrong, and it must be filed within 180 days of when the person knew or should have known about it. OCR can waive that deadline for good cause (45 CFR 160.306). A rider, a relative, or one of your own employees can file.
OCR then screens the complaint against three tests before it can act:
- The alleged conduct happened within the past six years.
- The company named is one the HIPAA rules cover: a covered entity or a business associate. Whether your company is one is the first question in the HIPAA guide for NEMT companies.
- The conduct, if true, would break a HIPAA rule. A complaint about a disclosure the rules allow, such as sharing trip details with the clinic treating the rider, goes nowhere.
Most complaints never become investigations. As of October 31, 2024, OCR had received more than 374,321 HIPAA complaints since 2003. About 255,953 were closed as not eligible for enforcement, and in 67,873 more OCR gave early technical assistance without opening an investigation.
Complaints are not the only way an investigation starts
Your own breach report can start one. OCR investigates every breach report covering 500 or more individuals, and it may investigate smaller ones depending on resources and priorities. After reviewing a breach report, OCR may close it, resolve it with technical assistance, refer it to another agency, or investigate.
OCR also runs compliance reviews on its own. Both for complaints and for reviews, the rule says OCR will investigate when a preliminary look at the facts points to a possible violation due to willful neglect, and may investigate in other cases (160.306(c) and 160.308).
What OCR’s first letter means
An investigation starts with a written notice to your company and to the person who complained. In that first contact OCR describes the acts or omissions behind the complaint (160.306(c)(4)), then asks each side for information about what happened. It may ask for specific documents.
Cooperation is not optional. Covered entities and business associates must cooperate with investigations, and must give OCR access during normal business hours to their facilities, books, records, and other information, including protected health information that bears on compliance. If OCR decides documents might be hidden or destroyed, access must be allowed at any time without notice (160.310).
Two things to do the day the letter arrives:
- Preserve everything connected to the allegation: messages, trip records, access logs, and the policy versions in effect at the time.
- Do not act against the person you think complained. HIPAA bars threatening, intimidating, harassing, or otherwise retaliating against anyone who files a complaint, helps an investigation, or opposes a practice they reasonably believe is unlawful (160.316). The rules that protect drivers who report problems are in whistleblower protections for NEMT drivers.
What to send OCR
Send what the letter asks for, organized and on time, with a short cover letter explaining what happened and what you changed. Many of the documents OCR asks for are records the rules already require you to keep for six years from creation or last use (164.316(b) and 164.530(j)):
- Written policies and procedures for privacy and security, including the version in force when the incident happened.
- Your risk analysis and risk management plan. The Security Rule requires an accurate and thorough assessment of risks to electronic rider data and measures that reduce them to a reasonable level (164.308(a)(1)). The HIPAA risk analysis template walks through building one.
- Training records showing each person was trained and when (164.530(b)).
- Business associate agreements with the vendors that hold rider data, and the broker’s agreement if you run its trips.
- Your complaint log, since you must document every privacy complaint you receive and its outcome (164.530(d)).
- Sanctions records showing what you did when staff broke a policy (164.530(e)).
- The breach file: your risk assessment of the incident, the notices you sent, and your log of smaller breaches. Your company carries the burden of proving notices went out or that an incident was not a breach (164.414(b)).
- Proof of the fix: retraining dates, new settings, revised forms.
If the allegation is narrow, such as a driver who discussed a rider at a pickup, the response can be narrow too. If it involves a hacked laptop or email account, expect questions about the risk analysis first.
How does an OCR investigation end?
Most investigations close without money changing hands. OCR may find no violation. Where it finds noncompliance, it first tries to resolve the case informally through voluntary compliance, corrective action, or a resolution agreement, and HHS says most investigations end that way (160.312). Both sides are told the result in writing.
The numbers as of October 31, 2024 show the spread: 31,191 cases resolved by requiring changes or corrective action, or by technical assistance; 15,561 cases with no violation found; and 152 cases that ended in a settlement or civil money penalty, totaling $144,878,972 since 2003. OCR had also referred 2,419 cases to the Department of Justice for possible criminal investigation.
A resolution agreement is a settlement. HHS describes it as an agreement in which the company performs set obligations and reports to HHS, generally for three years, often with a payment. Some recent agreements, such as Comstar’s in 2025, ran two-year corrective action plans.
When OCR moves toward a penalty
If informal resolution fails, the process becomes formal, with short deadlines:
- OCR tells you the matter is not resolved and gives you 30 days to submit written evidence of mitigating factors or affirmative defenses (160.312(a)(3)).
- A notice of proposed determination follows by certified mail or delivery, with the findings, the proposed amount, the penalty tier it relies on, and how to respond (160.420).
- You have 90 days to request a hearing before an administrative law judge, by certified mail. Receipt is presumed five days after the notice date. The request must admit, deny, or explain each finding, and state your defenses (160.504). Miss the 90 days and the penalty can be imposed with no hearing and no appeal.
Gums Dental Care, a solo dental practice in Maryland, shows how a small case escalates. A patient’s first complaint about unanswered records requests closed with a technical assistance letter. A second complaint led to an investigation, which found the patient asked in April and June 2019 and the practice did not try to provide the records until May 2022. OCR proposed a $70,000 penalty in March 2022. The practice requested a hearing, the judge imposed the full amount on September 29, 2023, and the Departmental Appeals Board affirmed on March 22, 2024.
What moves the amount
The penalty tiers turn on what you knew: from not knowing and not having reason to know, up to willful neglect left uncorrected (160.404). The current dollar ranges, which apply to penalties assessed since January 28, 2026, are in the HIPAA guide’s penalty section. Within a tier, OCR weighs these factors (160.408):
- How many riders were affected and for how long.
- The harm: physical, financial, or to reputation, or whether it kept someone from getting care.
- Your history, including how you responded to earlier technical assistance and complaints.
- Your finances and size, including whether a penalty would threaten your ability to keep serving riders.
Two rules work in your favor. OCR may not impose a penalty for a violation that was not due to willful neglect and was corrected within 30 days of when you knew, or should have known, about it (160.410(c)). And under a 2021 amendment to the HITECH Act, HHS must take into account a full year or more of recognized security practices you can document when it decides fines, audits, or settlement remedies. The cybersecurity guide lists the practices HHS recognizes.
Why the risk analysis decides so many cases
A missing or incomplete risk analysis shows up in settlement after settlement, and OCR’s Risk Analysis Initiative, whose first action came in October 2024, focuses select investigations on that one requirement. The cases closest to transportation companies:
- Bryan County Ambulance Authority (Oklahoma), October 31, 2024. The initiative’s first action. A 2022 ransomware attack affected 14,273 patients, OCR found no compliant risk analysis, and the authority paid $90,000 with three years of monitoring.
- Comstar, LLC (Massachusetts), May 30, 2025. A billing company for ambulance services, and the initiative’s ninth action. Ransomware affected 585,621 individuals; Comstar paid $75,000 with two years of monitoring.
- Spencer Gifts health plan, June 18, 2026. The fourteenth action: $450,000 after a ransomware attack, for failing to complete an accurate and thorough risk analysis before the breach.
Earlier cases show what happens when technical assistance is ignored. West Georgia Ambulance reported a lost unencrypted laptop with 500 patients’ information in 2013. OCR found it had never done a risk analysis, trained staff on security, or adopted Security Rule policies, and that it took no meaningful steps after OCR’s technical assistance. It paid $65,000 in December 2019.
State attorneys general can sue too
A state attorney general can bring a federal lawsuit on behalf of state residents harmed by a HIPAA violation, separately from OCR. The court can stop the practice and award damages of up to $100 per violation, capped at $25,000 per calendar year for all violations of an identical requirement, plus costs and attorney fees. The state must notify HHS before filing when it can, and HHS may join the case (42 U.S.C. 1320d-5(d)).
Answering OCR without making it worse
Treat the investigation like a broker or Medicaid audit: one person in charge, every deadline on the calendar, and nothing sent that you have not read.
- Read what the complaint alleges, then gather only the records that answer it.
- Fix the problem now, before OCR asks. A violation corrected within 30 days that was not willful neglect cannot draw a penalty.
- Send a complete, organized response by the date OCR gives, and ask in writing before that date if you need more time.
- Keep the person who complained out of any discipline connected to the complaint.
- Call a health care lawyer when the letter follows a large breach, mentions willful neglect, or turns into a notice of proposed determination.
Showing your safeguards in HealthRide
HealthRide is HIPAA compliant. In the provider portal, access follows each person’s role, sign-ins can use a passkey or a two-step code, and every change is recorded, so you can show OCR who changed a rider’s trip and when. Drivers work in an app that keeps rider details off the phone’s lock screen.
Frequently asked questions
- Will OCR tell us who filed the complaint?
- Not necessarily. The rule requires OCR's first letter to describe the acts or omissions behind the complaint (45 CFR 160.306(c)(4)), not to name the person who filed it, though the facts often make it clear. Whoever it was, the rule is the same: you may not threaten, intimidate, harass, or otherwise retaliate against anyone for filing a complaint, helping an investigation, or opposing a practice they reasonably believe breaks the rules (160.316).
- Does the rider who complained get money from a HIPAA penalty?
- No. Complainants receive no share of a civil money penalty; HHS deposits penalties in the U.S. Treasury. A state attorney general can sue on behalf of the state's residents, though, for up to $100 per violation, capped at $25,000 a calendar year for violations of an identical requirement, plus costs and attorney fees. Claims under state privacy laws are a separate question for a lawyer.
- How long does OCR have to bring a penalty?
- Six years from the date of the violation. Under 45 CFR 160.414, no penalty action may be brought unless OCR starts it within that period. The same six years is how long HIPAA requires you to keep your policies, risk analysis, training records, and other required documentation, counted from when each was created or last in effect, whichever is later.
- Do we need a lawyer to answer OCR's letter?
- Not always. Many small cases close after the company explains what happened and shows the fix. Bring in a health care lawyer when the letter follows a large breach, mentions willful neglect, or asks for years of records, and always when OCR sends a notice that it intends to impose a penalty.
- What happens if we ignore OCR's first letter about a complaint?
- The case escalates. Covered entities and business associates must cooperate with investigations and give OCR access to records (160.310). A Maryland dental practice that did not act after a technical assistance letter faced a second complaint, a full investigation, and a $70,000 civil money penalty that an administrative law judge and the Departmental Appeals Board both upheld.