Site Overlay

How to File a HIPAA Complaint

The Centers for Medicare & Medicaid Services (CMS) enforces HIPAA Administrative Simplification Requirements on behalf of Health and Human Services (HHS).

The CMS enforcement activities include investigating complaints about potential noncompliance. Anyone can file a complaint against a HIPAA-covered entity.

Overview of ASETT

The Administrative Simplification Enforcement and Testing Tool (ASETT) is a free online tool operated by the CMS National Standards Group (NSG).

One of the tool’s key capabilities is allowing users to file a complaint alleging that a HIPAA-covered entity, directly or through a business associate acting on its behalf, is noncompliant with Administrative Simplification requirements related to the format and content of electronic, administrative health care transactions.

The NSG can investigate complaints against health plans, healthcare clearinghouses, or healthcare providers that conduct certain transactions electronically.

Should your complaint allege noncompliance with an Administrative Simplification requirement within NSG’s purview, NSG may contact the entity and investigate the issue(s).

NSG works to informally resolve complaints and violations identified during compliance reviews, to the extent practical, by seeking the cooperation of covered entities and providing technical assistance to help covered entities comply voluntarily with applicable Administrative Simplification provisions.

Compliance with Administrative Simplification standards across the healthcare industry will help create significant time and cost savings and allow for more focus on patient care.

Steps to File a Complaint

If you believe an entity is not complying with a transaction, code set, unique identifier, or operating rule requirement, here’s how to file a complaint:

Step 1

Go to ASETT.CMS.GOV

  • If you have a CMS Identity Management System account, you can access additional ASETT features by clicking “Login” at the top right corner of the page.
  • If you create a CMS Identity Management System account, you can save a draft complaint, add info to your complaint, and view complaints you’ve submitted. To create an account, click “Register” at the top-right corner of the ASETT homepage and follow the steps in the ASETT Quick Start Guide or the User Manual.

Step 2

Upon logging in, click the “New Complaint” button on the welcome page.

  • If you aren’t a registered user, click “Get Started” under “File HIPAA Complaint.”

Step 3

Click “Complaint Type” and select the issue you are reporting.

Step 4

Click “Complainant Information” to go to the next page.

  • To keep your complaint conÿdential, select “Yes” for the “Anonymous” option.

Step 5

Fill in the text fields, then click the “Filed Against Entity Information.”

Step 6

Enter information about the HIPAA-covered entity you believe is noncompliant, then click “Complaint Details Information.”

  • Registered users can include supporting files, such as transaction files, correspondence, and copies of benefits explanations to speed up review.

Step 7

Add details about the complaint, then click “Complaint Review.”

Step 8

Review your complaint for accuracy, then click “Submit.”

Enforcement Statistics

The CMS publishes quarterly complaints reports on the HIPAA Enforcement Statistics page of the Administrative Simplification website. The reports provide insights into the types of complaints submitted to NSG and their status (e.g., open, corrective action plan, closed).

Helpful Tips

If you need help registering for or logging into your account, call or email the following:

ASETT Helpdesk
(703) 951-6810
asetthelpdesk@religroupinc.com

Additional Resources

How to File a Complaint Infographic
Complaint Progress Infographic
Quick Start Guide
User Manual
Frequently Asked Questions

Index