
Is it a HIPAA violation to say someone is in the hospital?
Key Facts
- Impermissibly disclosed health records jumped from 51.9 million in 2022 to 168 million in 2023, according to HIPAA Journal data.
- The average healthcare data breach grew from 225,000 to nearly 400,000 records in 2024, per recent breach reporting.
- Roughly 80% of breaches leverage identity as a key component, according to Cisco Talos incident response data.
- Proposed 2025 HIPAA Security Rule amendments would give regulated entities just 180 days to comply if passed, per the proposed rule.
- HHS estimates the 2025 proposed HIPAA amendments would cost $9 billion in first-year compliance, per its own analysis.
- The 2013 Omnibus Rule raised maximum annual HIPAA fines from $25,000 to $1.5 million and made business associates directly liable, per regulatory history.
- Proposed amendments would require vulnerability assessments at least every 6 months, including supply chain reviews, under the new requirements.
Frequently Asked Questions
Is it automatically a HIPAA violation to tell someone a person is in the hospital?
Why is healthcare privacy enforcement getting stricter right now?
What are the new 2025 HIPAA changes I keep hearing about?
How much can HIPAA violations actually cost a business?
Does HIPAA apply to my dental or medical practice's phone and lead handling?
What's the simplest way to avoid a HIPAA problem when someone asks about a patient?
The Bottom Line on Patient Privacy
So, is it a HIPAA violation to say someone is in the hospital? The answer depends on who you are, what you say, and whether the patient had a chance to object. For most businesses outside of healthcare — your local plumber, roofer, or law firm — HIPAA simply doesn't apply, because you're not a covered entity handling medical records. But if you run a dental practice, med spa, or other healthcare-adjacent business, the rules matter, and how your team (or your AI) handles callers can make the difference between staying compliant and creating risk. That's why CallMyLeads offers HIPAA-aligned configuration for dental and medical clients: approved scripts only, no diagnosis or treatment advice, and clear disclosure on every call. With healthcare privacy enforcement tightening — impermissibly disclosed records jumped from 51.9 million in 2022 to 168 million in 2023, per HIPAA Journal data cited by Duo — the safest move is to build privacy safeguards into your lead handling from day one. Want to answer every lead in seconds without worrying about what gets said? Book a free 15-minute scoping call and see how it works.