HIPAA Sanction Policy: What OCR Expects You to Document
A medical assistant at your practice opens the chart of a patient she is not treating — her sister-in-law. Your EHR audit log flags the access three weeks later during a routine review. She has been with you six years, she is well liked, and her supervisor wants to handle it with a conversation. What you do in the next ten business days is governed by your HIPAA sanction policy, and if you do not have one, you are already out of compliance with two separate provisions of the regulation.
This article is for the person who has to run that process: the practice owner, privacy officer, or compliance lead who signs the write-up and keeps the file. It covers what the rule actually requires, how to build a tier structure that holds up, who does what, and what the documented evidence looks like when the Office for Civil Rights asks for it.
The Two Rules That Make a Sanction Policy Mandatory
People treat this as an HR nicety. It is not. Two independent HIPAA provisions require it.
Privacy Rule, 45 CFR 164.530(e)(1): a covered entity must have and apply appropriate sanctions against workforce members who fail to comply with its privacy policies and procedures or with the requirements of the Privacy Rule or Breach Notification Rule. Paragraph (e)(2) adds the documentation obligation — you must document the sanctions that are applied, if any.
Security Rule, 45 CFR 164.308(a)(1)(ii)(C): apply appropriate sanctions against workforce members who fail to comply with your security policies and procedures. This is a required implementation specification, not an addressable one. There is no risk-based off-ramp. You do it, or you are non-compliant.
Business associates are directly bound by the Security Rule provision. If you are a billing company, an IT managed service provider, or a transcription vendor, this obligation is yours too — not something you inherit from your client's policy manual.
Retention runs six years. Under 164.530(j)(2) and 164.316(b)(2)(i), you keep the policy and the records of its application for six years from creation or from the date it was last in effect, whichever is later. That means a sanction file from a 2020 incident is still discoverable in 2026.
What Is a HIPAA Sanction Policy?
A HIPAA sanction policy is a written, board-or-owner-approved document that states how your organization disciplines workforce members who violate HIPAA privacy or security requirements. A compliant policy contains six elements:
- Scope — who counts as workforce, including volunteers, students, scribes, per-diem staff, and contractors under your direct control
- A graduated tier structure tying categories of violation to categories of consequence
- The investigation process — who investigates, what evidence is gathered, and the timeline
- Decision authority — who approves each level of sanction
- Documentation and retention — what goes in the file and for how long
- The statutory exceptions where sanctions are prohibited
A policy that exists in a binder but has never been applied is worse than no policy. It becomes evidence that you knew the standard and chose not to meet it.
The Tier Structure That Survives an Investigation
OCR does not prescribe specific penalties. It expects the sanction to be proportionate, consistently applied, and documented. A four-tier model is the format most practices can actually operate.
Tier 1 — Unintentional, low harm
A nurse leaves a printed schedule on the break room table. A staffer faxes a records release to the wrong number in the directory. Response: documented verbal counseling, retraining on the specific policy, entry in the sanction log. No PHI exposure beyond a contained recipient.
Tier 2 — Negligent, or a repeat Tier 1
Shared login credentials. Screen left unlocked in a public corridor after prior warning. PHI discussed in the waiting area loudly enough to be overheard. Response: written warning, mandatory retraining within 14 days, 90-day supervisory check-in.
Tier 3 — Intentional access without a treatment, payment, or operations purpose
Curiosity browsing. Looking up a coworker, a neighbor, a family member, or a local public figure. Response: suspension pending investigation, final written warning or termination, breach risk assessment under 164.402, and mandatory reporting through your incident process.
Tier 4 — Malicious or commercial
Selling records. Photographing charts. Removing PHI to use at a competing practice. Downloading a patient list before resignation. Response: immediate termination, notification to counsel, referral to law enforcement where warranted, and licensure board reporting where applicable.
Write the examples into the policy. Vague tiers produce inconsistent decisions, and inconsistency is what makes a sanction indefensible — both to OCR and to an employment lawyer representing the terminated employee.
Who Owns Each Step: A Role Map
Assign these by name and title in the policy itself, not by department.
- Privacy Officer — receives the report, opens the incident file, conducts or oversees the investigation, performs the four-factor breach risk assessment, recommends the tier.
- Security Officer — pulls audit logs, access records, and system evidence; confirms the technical facts; disables credentials on suspension or termination.
- Direct supervisor — provides context on prior counseling, delivers the sanction with HR present, does not unilaterally set the tier.
- HR or practice administrator — ensures the sanction aligns with the employee handbook and any collective bargaining or employment agreement, maintains the personnel record.
- Owner or governing body — approves Tier 4 outcomes and any deviation from the published tier.
Set a clock. A defensible standard: incident reported within one business day of discovery, investigation opened within two, technical evidence collected within five, sanction decision within ten business days. Write those numbers down and hold to them.
The Five Documents in a Defensible Sanction File
When an investigator requests your sanction records, this is what should be in the folder for each incident:
- The incident report — date discovered, date of the underlying conduct, reporter, description of facts
- The evidence — audit log excerpt, access report, screenshot, witness statement, email trail
- The risk assessment — the 164.402 four-factor analysis showing whether the incident was a reportable breach, and the reasoning either way
- The sanction determination — tier applied, rationale, signature of the deciding official, employee acknowledgment or a note that acknowledgment was refused
- The corrective action — retraining completion record, policy revision, technical control added, and the date each was completed
Maintain a summary sanction log alongside the individual files: date, incident type, tier applied, outcome. That log is the single fastest way to demonstrate consistent application across years and across staff. It is also how you catch your own drift — if front-desk staff receive written warnings for conduct that gets providers a verbal reminder, the log will show it before OCR does.
Three Situations Where You Must Not Sanction
Section 164.530(e)(1)(ii) carves out conduct you are barred from punishing. Your policy must name these explicitly.
- Whistleblower disclosures under 164.502(j) — a workforce member who reports in good faith to a health oversight agency, an accreditation body, or an attorney
- Crime-victim disclosures under 164.502(j)(2) — a workforce member who is the victim of a criminal act and discloses limited information to law enforcement
- Protected participation — filing a complaint with HHS, testifying in or assisting an investigation, compliance review, or proceeding
Separately, 164.530(g) prohibits intimidating or retaliatory acts against individuals who exercise these rights. A sanction that looks like retaliation converts a manageable personnel matter into an enforcement problem. Reference these protections in your annual workforce training so staff know reporting is safe.
Business Associates, Contractors, and Where Your Sanction Authority Ends
The rule reaches your workforce, defined at 45 CFR 164.103 to include employees, volunteers, trainees, and other persons whose conduct is under your direct control — paid or not. A scribe placed by a staffing agency who works under your supervision is typically workforce. Your sanction policy applies to her.
A billing company that processes your claims is not workforce. You cannot discipline its employees. Your leverage is contractual, which is why the business associate agreement matters here: it must obligate the vendor to maintain its own sanction process, report incidents to you, and cooperate with your investigation. If your agreements are stale, generic, or missing entirely for vendors you onboarded this year, generate a signature-ready business associate agreement through a guided six-step wizard with PDF and DOCX export — one-time purchase, no subscription — and close the gap before the next incident forces the question.
Run a reconciliation once a year: every vendor with PHI access appears on your BAA list, and every BAA on the list names a current vendor. Document the date you performed it.
A Worked Example: The Snooping Incident, Day by Day
Return to the medical assistant and her sister-in-law's chart.
Day 0: Security officer's monthly audit log review flags eleven chart accesses with no corresponding encounter. He notifies the privacy officer the same day and preserves the log export.
Day 1: Privacy officer opens the incident file. Confirms with scheduling that the employee was never assigned to those encounters. Confirms with billing that no claim exists.
Day 3: Interview with the employee, supervisor present. She admits curiosity, denies disclosing anything. Statement written and signed.
Day 4: Four-factor risk assessment completed. Nature of PHI: full chart including behavioral health notes. Unauthorized person: an internal workforce member. Whether acquired or viewed: yes, viewed. Mitigation: none available. Conclusion — reportable breach affecting one individual. Notification letter drafted for the 60-day deadline under 164.404.
Day 7: Tier 3 sanction determined. Final written warning, five-day unpaid suspension, retraining, six-month access monitoring. Owner countersigns.
Day 9: Sanction delivered and acknowledged. Retraining scheduled. Sanction log updated.
Day 20: Patient notification mailed. Incident logged for the annual small-breach report to HHS due within 60 days after year-end.
Every one of those steps produced a dated artifact. That is what "documented evidence" means.
Where Practices Actually Fail
The pattern in OCR's public resolutions is rarely a missing policy document. It is a policy that was never operationalized: no audit log review to detect violations, no record that the sanction was applied, or discipline that varied by seniority. Browse the HHS breach portal and you will see how often internal unauthorized access sits behind a reported incident.
Two more common failures. First, no detection mechanism — a sanction policy with no audit log review is unenforceable by design. Second, no annual review. Your policy should carry a review date, an approver signature, and a version number. HHS maintains its Security Rule guidance library, and NIST's SP 800-66 Revision 2 maps each administrative safeguard, including sanctions, to practical implementation steps.
Your 30-Day Implementation Plan
Days 1–7: Locate your current policy. Confirm it cites both 164.530(e) and 164.308(a)(1)(ii)(C). Confirm it defines workforce and names the statutory exceptions.
Days 8–14: Write the four tiers with real examples drawn from your own environment. Assign decision authority by title. Set your investigation clock.
Days 15–21: Build the sanction log and the incident file template. Establish a monthly audit log review with a named owner and a documented output.
Days 22–30: Obtain owner approval and signature. Train all workforce members, including providers, and retain the training roster. Add the policy to your annual review calendar.
If your broader document set is thin — risk analysis, policies, workforce training records — you can generate the full compliance document set rather than assembling it from templates of unknown provenance. And when the vendor side of the file needs work, build a compliant BAA in about ten minutes so your contractual controls match the internal ones you just tightened. A sanction policy is only as strong as the ecosystem it sits in.