Skip to main content
Guide

What Triggers an OCR Marketing Investigation

OCR marketing investigations start from complaints, self-reported breaches, media coverage, and agency referrals. Here is what actually opens a file and how long it takes.

8 min read

An OCR marketing investigation almost always starts with a complaint from one person, usually a patient who saw their own information somewhere it should not have been. The other entry points are a breach report you filed yourself, a media story, a referral from another agency, and OCR's own compliance reviews triggered by patterns in complaints or breach data. OCR does not scan websites looking for violations. It responds to what arrives. Curve is HIPAA-compliant ad tracking with a signed BAA on every plan, and the value of that is mostly upstream: no disclosure, no complaint, no file.

The five entry points

OCR has published how its cases begin, and the distribution is heavily weighted toward one channel.

  • Individual complaints. Since the Privacy Rule compliance date in April 2003, OCR has received more than 374,000 HIPAA complaints. This is the dominant path by a wide margin, and it is the path every published marketing enforcement action took.
  • Self-reported breaches. Covered entities must report breaches of unsecured PHI. Those affecting 500 or more individuals go to OCR within 60 days of discovery, along with notice to individuals and to prominent media outlets in the affected jurisdictions. Breaches under 500 are logged and submitted within 60 days of the end of the calendar year.
  • Compliance reviews initiated by OCR. More than 1,190 to date. OCR opens these on its own based on media reports, referrals from other state and federal agencies, trends in complaints or breach reports, and other indications of noncompliance identified by headquarters or regional staff.
  • Media coverage. Named explicitly by OCR as a compliance review trigger. A local news segment about a clinic posting patient photos is a valid basis for opening a review with no complaint at all.
  • Referrals from other agencies. The FTC, state attorneys general, and state health departments all refer matters. The July 2023 joint FTC and OCR letter to roughly 130 hospital systems and telehealth providers about online tracking technologies is a signal of how closely those two agencies coordinate on this subject.

What actually generates the complaint in marketing cases

Reading the published marketing enforcement actions, the triggering events are strikingly ordinary.

A reply to an online review. Elite Dental Associates, New Vision Dental, Manasa Health Center, and U. Phillip Igbinadolor DMD and Associates all began when a practice answered a negative review with details about the patient. In each case the patient complained. The reply feels like self-defense to the person writing it and reads as a disclosure to everyone else.

A photo posted as a success story. Cadia Healthcare's case began with a complaint received by OCR on September 20, 2021 about a disclosure online. The facilities had posted photographs of roughly 150 residents on social media without HIPAA-compliant authorizations. The settlement was $182,000.

A patient list handed to a marketing vendor. Northcutt Dental-Fairhope gave a campaign manager a spreadsheet of 3,657 patient names and addresses and used a third-party marketing company to email 5,385 individuals. Settlement, $62,500.

A vendor engaged without a BAA. Raleigh Orthopaedic Clinic transferred x-ray films covering 17,300 patients to a vendor on an oral agreement. The disclosure itself was the violation, independent of any downstream harm. Settlement, $750,000.

Notice what is absent from that list: nobody was hacked. Every one of these was a deliberate marketing act performed by someone doing their job.

The tracking scenario is different, and worse

Website tracking does not usually generate a patient complaint, because patients cannot see it. It generates the second trigger instead: your own breach report.

When an organization discovers that a pixel has been transmitting patient data, it runs the four-factor risk assessment required by the Breach Notification Rule. Under that rule a breach is presumed unless the documented analysis shows a low probability of compromise. If the analysis does not clear that bar, the organization notifies individuals, notifies OCR, and, above 500 individuals, notifies media outlets. The scale in tracking cases is enormous. Advocate Aurora notified roughly 3 million people. Cerebral notified more than 3.17 million. Kaiser Permanente's disclosure covered 13.4 million.

Those filings are public and permanently listed on the HHS breach portal. They are also read by plaintiffs' firms, which is the more immediate consequence: the private class actions in this space have produced far larger numbers than OCR's marketing penalties, with cumulative healthcare pixel settlements crossing $100 million.

One qualification. In June 2024, a federal court vacated the portion of OCR's online tracking bulletin that addressed unauthenticated public webpages, holding OCR had exceeded its authority in treating an IP address combined with a visit to a public health-topic page as a PHI disclosure. OCR withdrew its appeal in August 2024. The rest of the bulletin stands, including its treatment of authenticated portals and its core position that tracking technologies transmitting individually identifiable health information to vendors constitute a PHI disclosure.

How long these take

The gap between the triggering event and the public outcome is the number most teams underestimate.

New Vision Dental: complaint received November 2017, settlement announced December 2022. Manasa Health Center: complaint received April 2020, settlement announced June 2023. Cadia Healthcare: complaint received September 2021, settlement announced 2025. Northcutt Dental's conduct dated to 2017 and the settlement came in March 2022.

Three to five years is normal. That has two implications. Fixing the problem after the complaint arrives does not close the matter, though it does affect the penalty tier. And the conduct being investigated may be years behind your current configuration, which means an inventory of what your stack does today is not a defense for what it did in 2022.

What happens once a file is open

Most complaints do not become investigations. OCR resolves the large majority before opening one, and provides technical assistance in lieu of investigation in a further share of cases. When OCR does investigate, the sequence is a data request, a written response with supporting documentation, follow-up questions, and then one of three outcomes: closure, a resolution agreement with a corrective action plan and a payment, or a civil monetary penalty.

The distinction between a settlement and a civil monetary penalty is worth knowing. A settlement is negotiated. A CMP is imposed, generally after an entity declines to settle or fails to respond. Igbinadolor's $50,000 was a CMP. Most of the others were settlements.

Penalty tiers turn on what you knew and how fast you corrected. Tier 1 requires that you did not know and would not have known exercising reasonable diligence. Tier 3 and Tier 4 both involve willful neglect, separated only by whether correction happened within 30 days, and the annual caps differ by more than $1.8 million.

How Curve removes the underlying disclosure

Investigations follow disclosures. The most reliable way to not be investigated over marketing data is for the marketing data to contain nothing that requires authorization.

Curve's tracking script replaces the Meta Pixel and Google tag, so events go to Curve's US-hosted infrastructure rather than directly to platforms that will not sign a BAA. Per-destination field mapping decides what forwards, with nothing sent by default and only explicitly mapped fields moving. Identifiers are SHA-256 hashed to each platform's conversion API requirements. Neutral event aliases mean the ad platform receives a generic conversion name rather than a service line, so no condition appears in an ad interface. PHI-pattern detection flags payloads containing PHI-shaped values, which matters here specifically: it converts a silent, years-long disclosure into an alert you can act on inside the 30-day correction window.

That last point is the one that maps directly to enforcement outcomes. The difference between a tier 3 and tier 4 posture is detection and correction speed, and detection is a technical capability, not a policy. Our guides to why client-side pixels create a HIPAA violation and routing ad clicks to a CRM without PHI cover the two paths where marketing data most often leaves.

The four things worth auditing now

Review replies. Establish that nobody responds to an online review with anything beyond a generic invitation to contact the office. Confirming that someone is a patient is itself a disclosure.

Photos and testimonials. Every image and quote used in marketing needs a signed authorization on file that names the marketing use. A patient's verbal agreement, or their own public post, does not satisfy 45 CFR 164.508.

Lists. Any patient list that has left your systems, to an agency, a mailing house, or an ad platform, is a disclosure that needed either an authorization or a BAA covering the recipient.

Vendors. Every marketing tool touching form submissions, appointments, or contact records needs a signed BAA. That includes your CRM and automation layer, which is where coverage most often runs out. Our assessment of HubSpot's HIPAA posture for clinics works through what that review looks like for one common example.

Frequently asked questions

Does OCR proactively scan websites for tracking pixels?

No. OCR responds to complaints, breach reports, media coverage, and referrals, and it opens compliance reviews based on patterns in that inbound material. Plaintiffs' firms do scan websites, which is why private litigation has moved faster than OCR on tracking.

Can a former employee trigger an investigation?

Yes. OCR accepts complaints from anyone, not only from patients. Employees and former employees are a recurring source, and a complaint does not have to name a specific harmed individual to be reviewed.

If we fix the problem before OCR contacts us, does that end it?

It does not close the matter, but it changes the penalty analysis substantially. Correction within 30 days of discovery is the line between the two willful neglect tiers, and documented remediation is what supports the lower tiers.

Does filing a breach report guarantee an investigation?

Breaches affecting 500 or more individuals receive OCR attention as a matter of course. Smaller breaches are logged and reported annually and are less likely to be investigated individually, though they can feed the trend analysis that prompts a compliance review.

Is a marketing agency investigated separately?

An agency handling PHI on your behalf is a business associate and faces direct liability, so both parties can be investigated over the same conduct. The covered entity's own obligations do not transfer.

What is the single most common marketing trigger?

Responding to an online review with patient-specific information. Four of the published enforcement actions in this area come from exactly that, and it is the one with the shortest path from act to complaint, because the patient sees it immediately.

Where to start

Two audits, both short. First, a policy audit: who is authorized to reply to reviews, who approves marketing images, and who can export a patient list. Second, a technical audit: which scripts run on your site, which vendors receive form and appointment data, and which of them have signed BAAs.

The second one is faster than it sounds. Run our free compliance scanner to see what is currently loading on your site and transmitting data. To see how the ad tracking layer works when it sits behind a signed BAA and flags PHI-shaped values before they travel, visit curvecompliance.com.

Reviewed August 2026. This is general information, not legal advice. Enforcement outcomes depend on facts specific to each matter. Consult qualified counsel about your own situation.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit