Guide

HIPAA Violations, Fines, and Penalties

The four penalty tiers with current ranges, notable OCR settlements, the violations that actually get cited, and state AG enforcement.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

HIPAA penalties are not priced by the breach — they are priced by culpability, which means the same incident can cost an organisation with a documented programme a corrective action plan, and cost an organisation without one millions.

The four penalty tiers

The HITECH Act established a four-tier civil penalty structure, codified at 45 CFR 160.404, that scales with what the organisation knew and did. The tiers are:

  • Tier 1 — lack of knowledge. The entity did not know of the violation and, exercising reasonable diligence, would not have known.
  • Tier 2 — reasonable cause. The violation had a reasonable cause and was not due to willful neglect.
  • Tier 3 — willful neglect, corrected. Conscious, intentional failure or reckless indifference, but the violation was corrected within 30 days of discovery.
  • Tier 4 — willful neglect, not corrected. The same culpability, left unfixed.

The dollar amounts are adjusted annually for inflation, so any specific figure has a shelf life. As of recent adjustments, the per-violation minimums run from roughly $140 at Tier 1 to roughly $71,000 at Tier 4, with per-violation maximums above $70,000 at every tier for the statutory scheme. Annual caps add a second layer of nuance: the statute contemplates an annual cap per violation type that inflation adjustments have pushed to roughly $2 million, but a 2019 HHS notice of enforcement discretion applies lower annual caps to the lower tiers — on the order of $25,000 for Tier 1, $100,000 for Tier 2, and $250,000 for Tier 3 before inflation adjustment, with only Tier 4 retaining the full cap. Check the current year’s figures before quoting numbers in a board deck; the structure, not the exact dollars, is the durable part.

Two features of the structure matter more than the numbers. First, “per violation” multiplies: each day a required safeguard is absent, or each individual affected, can be counted as a separate violation, which is how continuing failures compound into large totals. Second, the tiers reward documentation. An organisation that identified a gap in its risk analysis, assigned an owner, and was working a dated remediation plan is arguing Tier 1 or 2; the same gap with no paperwork looks like willful neglect. Your documentation is, quite literally, your penalty defence.

Criminal penalties

Civil money penalties come from OCR; criminal cases go to the Department of Justice. Knowingly obtaining or disclosing individually identifiable health information in violation of HIPAA carries up to $50,000 and one year in prison; doing so under false pretences, up to $100,000 and five years; and doing so with intent to sell, transfer, or use PHI for commercial advantage, personal gain, or malicious harm, up to $250,000 and ten years. Prosecutions are uncommon but real, and they name individuals — employees snooping on records and selling patient data are the recurring fact patterns.

Notable OCR enforcement actions

A few well-known cases sketch the landscape. Anthem’s 2018 settlement of $16 million — following a breach affecting nearly 79 million people — remains the benchmark large OCR resolution. Premera Blue Cross settled for $6.85 million in 2020, and Excellus Health Plan for $5.1 million, both after multi-year intrusions. Advocate Health Care ($5.55 million, 2016) and Memorial Healthcare System ($5.5 million, 2017) show that unencrypted devices and unmonitored insider access, respectively, can price similarly to sophisticated attacks. Cignet Health’s $4.3 million civil money penalty in 2011 — the first CMP under HIPAA — arose substantially from refusing patients access to their records and failing to cooperate with the investigation.

One instructive counterpoint: MD Anderson was assessed a $4.3 million penalty over unencrypted devices, and a federal appeals court later vacated it as arbitrary — a reminder that penalties are contestable, and that OCR’s positions are not the last legal word. The reliable pattern across the docket, though, is that resolution agreements almost always include a multi-year corrective action plan with OCR monitoring, and practitioners will tell you the corrective action plan often costs more than the cheque.

At the other end of the scale, OCR’s Right of Access initiative has produced dozens of settlements — many against small practices, frequently in the $10,000–$100,000 range — for the simple failure to give patients timely copies of their own records. Enforcement is not only a large-organisation problem.

The violations that actually get cited

Across resolution agreements, a handful of findings recur:

  • No risk analysis — the number one finding. The absent or inadequate risk analysis under 164.308(a)(1) appears in the large majority of significant OCR actions. It is the first document requested in an investigation, it cannot be created retroactively, and its absence colours everything else toward willful neglect.
  • No risk management follow-through. A risk analysis whose findings were filed and forgotten — identified risks with no remediation plan, owners, or dates.
  • Missing business associate agreements. Vendors handling PHI with no BAA in place, a pure documentation failure that OCR treats as a standalone violation.
  • Right of access failures. Late, incomplete, or overpriced responses to patients requesting their own records.
  • Insufficient access controls and audit review. Shared credentials, unrevoked departed-employee access, and audit logs nobody reads — the mechanism behind most insider incidents.
  • Unencrypted devices and media. Encryption is addressable rather than required, but a stolen unencrypted laptop plus no documented analysis of why encryption was skipped is a settled fact pattern.
  • Late breach notification. Missing the 60-day clock, which converts a bad week into a separate violation.

The common thread: these are programme failures, not sophistication failures. None requires an advanced adversary — only an absent document.

State attorney general enforcement

The HITECH Act gave state attorneys general authority to bring civil actions for HIPAA violations affecting their residents, with statutory damages available, and AGs have used it since Connecticut’s first action in 2010. The modern pattern is the multistate coalition: in 2020, attorneys general from dozens of states collectively settled with Anthem for $39.5 million over the same breach OCR resolved for $16 million — the states recovered more than the federal regulator. AGs also stack state law on top: consumer protection statutes, state breach notification laws, and regimes like New York’s SHIELD Act or California’s CMIA give them causes of action HIPAA alone would not. For planning purposes, treat any significant breach as a three-front event: OCR, state AGs, and private litigation.

What actually determines your outcome

Read enough resolution agreements and the pattern is unmistakable. The breach itself is rarely what is punished — organisations with strong programmes suffer breaches and close investigations without penalty. What is punished is what the investigation finds underneath: no current risk analysis, no BAAs, no training records, warnings ignored for years. The tier system formalises this: the difference between Tier 1 and Tier 4 is not the incident, it is the file. The cheapest penalty defence available is a current, documented, actively worked compliance programme — which is also, not coincidentally, the thing the compliance checklist exists to build.

Where SuperHIPAA fits

The platform maintains the exact artefacts investigators request first — risk analysis, remediation tracking, BAA register, training records, incident log — dated and versioned, so culpability arguments are made with documents rather than assurances. Our team runs the risk analysis itself when you need it done properly.

Start where you are

Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report showing which of the commonly cited gaps above apply to you, and what to fix first. If you are further along than you thought, we will tell you that too.

Questions

What are the four HIPAA penalty tiers?

They track culpability: Tier 1, the entity did not know and could not reasonably have known; Tier 2, reasonable cause, not willful neglect; Tier 3, willful neglect corrected within 30 days; Tier 4, willful neglect not corrected. Per-violation amounts and annual caps rise with each tier and are adjusted for inflation each year.

What is the maximum HIPAA fine?

For the top tier, the per-violation maximum sits above $70,000 as of recent inflation adjustments, with an annual cap per violation type that has historically run to roughly $2 million — though HHS enforcement discretion since 2019 has applied lower annual caps to the lower tiers. Multi-year, multi-provision cases are how settlements reach eight figures.

What is the most common HIPAA violation?

Failure to conduct an accurate, thorough risk analysis under 45 CFR 164.308(a)(1). It appears in the large majority of OCR's significant enforcement actions because it is the first document investigators request and the one organisations most often cannot produce.

Can individuals go to prison for HIPAA violations?

Yes. Criminal enforcement runs through the Department of Justice, with penalties up to $50,000 and one year for knowing violations, up to $100,000 and five years where false pretences are involved, and up to $250,000 and ten years where PHI is obtained or disclosed for commercial advantage, personal gain, or malicious harm.

Do OCR fines apply to small practices?

Yes. OCR's Right of Access initiative alone has produced dozens of settlements against small and solo practices, typically in the tens of thousands of dollars. Size affects the amount, not the exposure.

Can state attorneys general enforce HIPAA?

Yes. The HITECH Act authorised state AGs to bring civil actions for HIPAA violations affecting their residents, and they use it — sometimes in multistate coalitions whose settlements have exceeded what OCR itself obtained for the same breach.

Does a breach automatically mean a fine?

No. Most reported breaches close without penalty. Fines follow when the investigation finds the underlying programme deficient — no risk analysis, no BAAs, ignored warnings. The breach opens the file; the missing documentation writes the cheque.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo