Shieldra
Free HIPAA Violation Checker
Screen a privacy or security incident for the factors that determine whether it is a HIPAA violation — who was involved, whether PHI was exposed, whether the disclosure was permitted, and whether breach notification may be triggered. Runs entirely in your browser.
By the Shieldra Compliance Team · Last updated July 2026
Key takeaways
- Not every privacy problem is a HIPAA violation — HIPAA only applies to covered entities and their business associates.
- A disclosure is only a violation if it was not permitted; treatment, payment, and health care operations are permitted uses.
- Incidental disclosures with reasonable safeguards, and genuinely de-identified data, generally fall outside a violation.
- The checker runs in your browser, requires no account, and submits nothing to OCR.
- It is a triage tool, not legal advice or a breach risk assessment.
What it checks
- Covered entity or business associate status
- PHI and identifiability
- Unauthorized access or disclosure
- Permitted use and incidental disclosure factors
- Breach notification review triggers
Privacy-first design
- Runs in the browser
- No account required
- No OCR submission
- Spam and promotional text blocked locally
How to tell whether something is a HIPAA violation
1. Does HIPAA even apply?
HIPAA covers health care providers, health plans, and clearinghouses, plus the business associates that handle PHI on their behalf. Employers, most consumer health apps, and most wellness products are not covered entities — their obligations usually come from FTC rules or state privacy law instead. If applicability is uncertain, the checker says so rather than guessing.
2. Was protected health information involved?
PHI means health information that can be tied to an individual: diagnosis, treatment, medication, billing, insurance, lab results, or appointment details combined with an identifier such as a name, email, phone number, medical record number, address, image, or claim number. Genuinely de-identified data — with no reasonable way to connect it to a person — is not PHI.
3. Was the disclosure actually unauthorized?
This is the step people skip. Uses for treatment, payment, and health care operations are permitted without patient authorization, as are brief incidental disclosures where reasonable safeguards were in place and the minimum necessary standard was respected. A violation requires an access or disclosure with no permission and no legal basis — a wrong recipient, snooping, a public posting, a shared login, a lost device, or an exposed file.
4. Does breach notification get triggered?
Security incidents such as ransomware, phishing, a stolen laptop, an exposed cloud bucket, a leaked portal, or a misdirected batch file may require notification to individuals, HHS, and sometimes the media. Encryption is the key exception: encrypted PHI exposed in a breach generally does not require notification, which is why it is the single highest-leverage control.
What to do if it looks like a violation
Document what happened while the details are fresh — what was disclosed, to whom, when it was discovered, and what was done about it. That record is what a breach risk assessment is built from, and reconstructing it weeks later is how minor findings become major ones.
Then run the formal analysis. A four-factor breach risk assessment determines whether notification is required, and the clock on notification starts at discovery, not at conclusion. This checker is a triage tool to help you decide whether that analysis is warranted; it is not legal advice and does not replace your Privacy Officer or counsel.
Frequently asked questions
Is every privacy mistake a HIPAA violation?
No. HIPAA only applies to covered entities — health care providers, health plans, and clearinghouses — and their business associates. It also only applies when protected health information is involved and the use or disclosure was not permitted. Treatment, payment, and health care operations are permitted uses.
What is an incidental disclosure?
A brief, unavoidable exposure that occurs alongside a permitted use, where reasonable safeguards were in place and only the minimum necessary information was involved — such as a conversation overheard in a waiting room. Incidental disclosures are generally not violations.
Does a breach always require notification?
No. Notification depends on a four-factor breach risk assessment, and encrypted PHI benefits from the safe harbor under the Breach Notification Rule — encrypted data exposed in a breach typically does not require notification.
Is my incident data sent anywhere?
No. The checker runs entirely in your browser, requires no account, and submits nothing to OCR or to Shieldra.
Can I use this instead of a breach risk assessment?
No. It is a triage tool to help you decide whether formal analysis is warranted. It is not legal advice, and it does not replace the four-factor breach risk assessment or your Privacy Officer’s judgment.