1. Home
  2. |Insights
  3. |DOJ Says HIPAA Criminal Liability Limited to Covered Entities

DOJ Says HIPAA Criminal Liability Limited to Covered Entities

Client Alert | 2 min read | 06.10.05

By Ben Butler

The U.S. Department of Justice (“DOJ”) has indicated criminal prosecution under the privacy-related provisions of the Health Insurance Portability and Accountability Act, P.L. 104-191 (“HIPAA”) will be limited to “covered entities”. In light of this narrowing scope, hospitals, health plans, and other covered entities must be particularly vigilant about maintaining compliance with HIPAA privacy, security, and transactions requirements so that they are not themselves prosecuted under remaining theories of liability, such as agency theory or conspiracy. Also, despite the impression that could be given by DOJ's determination, DOJ still says that senior corporate officials could still be criminally liable for a “covered entity's” misconduct in an egregious case.

In a June 1, 2005 memorandum issued by DOJ's Office of Legal Counsel, DOJ concludes that non-covered entities cannot violate the administrative simplification provisions of HIPAA (specifically, the United States Code, Title 42, Chapter 7, Subchapter XI, Part C) because these provisions “simply do[] not apply to them.” Under HIPAA, “covered entities” include health plans, health care clearinghouses, health care providers who transmit health information in electronic form in connection with a HIPAA-covered transaction, and Medicare prescription drug card sponsors.

The position taken by the DOJ appears to contradict the theory underlying the only criminal conviction to date; of Richard Gibson, a Seattle cancer center employee, who pled guilty to violating HIPAA and was later sentenced to 16 months in prison. As indicated in the summary, at the time of the conviction, the theory of the case appeared questionable given the language of the HIPAA statute. DOJ's Office of Legal Counsel now appears to have reached the same conclusion.

By narrowing the focus of possible criminal prosecution under HIPAA, DOJ has arguably “raised the stakes” for covered entities, who now may be the only remaining targets in some situations. If, as in the Gibson case, an individual employee engages in wrongful conduct involving protected health information, it will be critically important for a covered entity to be able to demonstrate that the employee was not acting in the scope of his or her employment. To this end, covered entities should be sure to take sufficient HIPAA compliance measures, such as an ongoing training and awareness, active enforcement of internal sanctions where appropriate, and maintenance of up-to-date policies and procedures.

Failure to take these measures may open the covered entity up to possible investigation under a theory of agency ( i.e., the employee was acting on behalf of the covered entity or with its knowledge) or conspiracy. Moreover, DOJ states that the criminal liability of a covered entity may even extend, in limited circumstances, “to individuals in managerial roles, including, at times, to individuals with no direct involvement in the offense . . . . [I]t may be that such individuals in particular cases may be prosecuted directly” under HIPAA.

Although federal enforcement of HIPAA to date has been limited, in the event of a high-profile misuse of patient information – as occurred in the Gibson case – prosecutors will want to ensure that someone is held responsible. Health plans, hospitals, and other covered entities must take the necessary measures to minimize exposure.

Insights

Client Alert | 4 min read | 05.01.26

Federal Court Blocks Trump Administration Policies Restricting Wind and Solar Permitting

A coalition of regional clean energy trade associations — including RENEW Northeast, Alliance for Clean Energy New York, Southern Renewable Energy Association, and Interwest Energy Alliance — along with the Green Energy Consumers Alliance (GECA), filed suit in December 2025 against the Department of the Interior (DOI), the Bureau of Land Management, the Bureau of Ocean Energy Management, the U.S. Fish and Wildlife Service (USFWS), and the Army Corps of Engineers. The complaint alleged that five agency actions, issued in response to a series of executive orders and presidential memoranda beginning on January 20, 2025, violated the Administrative Procedure Act (APA) by arbitrarily halting or restricting federal permitting for wind and solar energy projects. Plaintiffs sought a preliminary injunction to halt enforcement of these policies while the litigation proceeds. See Renew Northeast, et al. v. U.S. Dep’t of Interior, et al., No. 25-cv-13961-DJC,  (D. Mass. Apr. 21, 2026) ECF Dkt. 89....