Unauthorized Patient Data Sale Is HIPAA Crime

Unauthorized sales of patient health data can trigger criminal charges under HIPAA, according to federal prosecutors and health privacy legal experts. The law requires explicit patient authorization before any protected health information changes hands for purposes beyond treatment, payment, or standard healthcare operations.
The Difference Between Consent and Authorization
The Privacy Rule distinguishes between two concepts that many patients conflate. Consent allows providers to use health information for treatment, payment, and healthcare operations. The rule permits but does not require covered entities to obtain such consent. Authorization, by contrast, is mandatory when providers want to disclose protected health information for other purposes or to outside parties.
An authorization is a detailed document. It grants permission to use health data for specified purposes, generally anything outside standard treatment, payment, or operations. The U.S. Department of Health and Human Services notes that where the Privacy Rule requires authorization, voluntary consent alone is insufficient unless it meets all authorization requirements.
Patients typically sign a Notice of Privacy Practices upon entering care. They also execute a separate HIPAA Authorization Form when appropriate. For substance use disorder treatment records, additional requirements under 42 CFR Part 2 now more closely align with standard HIPAA protections. Starting February 16, 2026, these special protections must be included in the standard Notice of Privacy Practices.
When Third-Party Access Crosses the Line
Problems arise when providers enter remunerative arrangements with pharmaceutical companies, medical device manufacturers, or other third parties seeking access to patient schedules or electronic medical records. A third party might want to identify candidates for clinical trials or procedures involving a specific device.
Related: Patients weigh in on AI scribes
Under 45 CFR §§164.501 and 508(a)(3), any communication meeting the definition of marketing requires patient authorization. If a covered entity receives direct or indirect payment from a third party in exchange for patient information, the authorization must explicitly state that remuneration is involved. Patients must be able to opt out or revoke authorization at any time.
Without proper authorization, this conduct constitutes illegal marketing and sale of protected health information. The practice violates the confidentiality safeguards that patients expect when seeking medical care.
The right to privacy in medical records predates HIPAA by more than a century. The U.S. Supreme Court held in 1891 that no right is more carefully guarded by common law than an individual’s possession and control of their own person. This principle underlies modern health privacy protections.
Federal Prosecution of Patient Data Schemes
Federal authorities have pursued criminal cases against healthcare workers who sold patient information without authorization. A November 2022 indictment charged Roderick Harvey, 40, and five former employees of Methodist Hospital with conspiracy and unauthorized disclosure of patient data.
According to the U.S. Department of Justice, Harvey paid the hospital employees to provide names and phone numbers of patients involved in motor vehicle accidents. The scheme ran from November 2017 through December 2020. Harvey then sold the information to personal injury attorneys and chiropractors.
Related: Quebec faces doctor shortage, Alberta overreaches
The conspiracy charge carries a maximum penalty of five years imprisonment, a $250,000 fine, and three years of supervised release. Harvey faced additional charges of obtaining patient information with intent to sell it for financial gain on various dates between November 2017 and September 2019. Each of those seven counts carries a maximum penalty of 10 years imprisonment, a $250,000 fine, and three years of supervised release.
The five hospital employees each faced separate charges for disclosing the information to Harvey. That violation carries a maximum penalty of one year imprisonment, a $50,000 fine, and one year of supervised release.
DOJ officials emphasized that HIPAA’s provisions make it a federal crime to disclose patient information, or to obtain patient information with the intent to sell, transfer, or use it for personal gain.
Healthcare providers with financial ties to outside companies should review their data-sharing practices carefully. Proper safeguards and fully informed patient authorization remain the primary defenses against both regulatory action and criminal prosecution for unauthorized patient data disclosure.
