Entities that violate HIPAA rules are subject to civil fines, as well as criminal penalties with possible jail time, which makes them extremely cautious about sharing medical information with anyone but the patient, even close family members such as spouses and children.