HIPAA penalties are not priced by the breach — they are priced by culpability, which means the same incident can cost an organisation with a documented programme a corrective action plan, and cost an organisation without one millions.
The four penalty tiers
The HITECH Act established a four-tier civil penalty structure, codified at 45 CFR 160.404, that scales with what the organisation knew and did. The tiers are:
- Tier 1 — lack of knowledge. The entity did not know of the violation and, exercising reasonable diligence, would not have known.
- Tier 2 — reasonable cause. The violation had a reasonable cause and was not due to willful neglect.
- Tier 3 — willful neglect, corrected. Conscious, intentional failure or reckless indifference, but the violation was corrected within 30 days of discovery.
- Tier 4 — willful neglect, not corrected. The same culpability, left unfixed.
The dollar amounts are adjusted annually for inflation, so any specific figure has a shelf life. As of recent adjustments, the per-violation minimums run from roughly $140 at Tier 1 to roughly $71,000 at Tier 4, with per-violation maximums above $70,000 at every tier for the statutory scheme. Annual caps add a second layer of nuance: the statute contemplates an annual cap per violation type that inflation adjustments have pushed to roughly $2 million, but a 2019 HHS notice of enforcement discretion applies lower annual caps to the lower tiers — on the order of $25,000 for Tier 1, $100,000 for Tier 2, and $250,000 for Tier 3 before inflation adjustment, with only Tier 4 retaining the full cap. Check the current year’s figures before quoting numbers in a board deck; the structure, not the exact dollars, is the durable part.
Two features of the structure matter more than the numbers. First, “per violation” multiplies: each day a required safeguard is absent, or each individual affected, can be counted as a separate violation, which is how continuing failures compound into large totals. Second, the tiers reward documentation. An organisation that identified a gap in its risk analysis, assigned an owner, and was working a dated remediation plan is arguing Tier 1 or 2; the same gap with no paperwork looks like willful neglect. Your documentation is, quite literally, your penalty defence.
Criminal penalties
Civil money penalties come from OCR; criminal cases go to the Department of Justice. Knowingly obtaining or disclosing individually identifiable health information in violation of HIPAA carries up to $50,000 and one year in prison; doing so under false pretences, up to $100,000 and five years; and doing so with intent to sell, transfer, or use PHI for commercial advantage, personal gain, or malicious harm, up to $250,000 and ten years. Prosecutions are uncommon but real, and they name individuals — employees snooping on records and selling patient data are the recurring fact patterns.
Notable OCR enforcement actions
A few well-known cases sketch the landscape. Anthem’s 2018 settlement of $16 million — following a breach affecting nearly 79 million people — remains the benchmark large OCR resolution. Premera Blue Cross settled for $6.85 million in 2020, and Excellus Health Plan for $5.1 million, both after multi-year intrusions. Advocate Health Care ($5.55 million, 2016) and Memorial Healthcare System ($5.5 million, 2017) show that unencrypted devices and unmonitored insider access, respectively, can price similarly to sophisticated attacks. Cignet Health’s $4.3 million civil money penalty in 2011 — the first CMP under HIPAA — arose substantially from refusing patients access to their records and failing to cooperate with the investigation.
One instructive counterpoint: MD Anderson was assessed a $4.3 million penalty over unencrypted devices, and a federal appeals court later vacated it as arbitrary — a reminder that penalties are contestable, and that OCR’s positions are not the last legal word. The reliable pattern across the docket, though, is that resolution agreements almost always include a multi-year corrective action plan with OCR monitoring, and practitioners will tell you the corrective action plan often costs more than the cheque.
At the other end of the scale, OCR’s Right of Access initiative has produced dozens of settlements — many against small practices, frequently in the $10,000–$100,000 range — for the simple failure to give patients timely copies of their own records. Enforcement is not only a large-organisation problem.
The violations that actually get cited
Across resolution agreements, a handful of findings recur:
- No risk analysis — the number one finding. The absent or inadequate risk analysis under 164.308(a)(1) appears in the large majority of significant OCR actions. It is the first document requested in an investigation, it cannot be created retroactively, and its absence colours everything else toward willful neglect.
- No risk management follow-through. A risk analysis whose findings were filed and forgotten — identified risks with no remediation plan, owners, or dates.
- Missing business associate agreements. Vendors handling PHI with no BAA in place, a pure documentation failure that OCR treats as a standalone violation.
- Right of access failures. Late, incomplete, or overpriced responses to patients requesting their own records.
- Insufficient access controls and audit review. Shared credentials, unrevoked departed-employee access, and audit logs nobody reads — the mechanism behind most insider incidents.
- Unencrypted devices and media. Encryption is addressable rather than required, but a stolen unencrypted laptop plus no documented analysis of why encryption was skipped is a settled fact pattern.
- Late breach notification. Missing the 60-day clock, which converts a bad week into a separate violation.
The common thread: these are programme failures, not sophistication failures. None requires an advanced adversary — only an absent document.
State attorney general enforcement
The HITECH Act gave state attorneys general authority to bring civil actions for HIPAA violations affecting their residents, with statutory damages available, and AGs have used it since Connecticut’s first action in 2010. The modern pattern is the multistate coalition: in 2020, attorneys general from dozens of states collectively settled with Anthem for $39.5 million over the same breach OCR resolved for $16 million — the states recovered more than the federal regulator. AGs also stack state law on top: consumer protection statutes, state breach notification laws, and regimes like New York’s SHIELD Act or California’s CMIA give them causes of action HIPAA alone would not. For planning purposes, treat any significant breach as a three-front event: OCR, state AGs, and private litigation.
What actually determines your outcome
Read enough resolution agreements and the pattern is unmistakable. The breach itself is rarely what is punished — organisations with strong programmes suffer breaches and close investigations without penalty. What is punished is what the investigation finds underneath: no current risk analysis, no BAAs, no training records, warnings ignored for years. The tier system formalises this: the difference between Tier 1 and Tier 4 is not the incident, it is the file. The cheapest penalty defence available is a current, documented, actively worked compliance programme — which is also, not coincidentally, the thing the compliance checklist exists to build.
Where SuperHIPAA fits
The platform maintains the exact artefacts investigators request first — risk analysis, remediation tracking, BAA register, training records, incident log — dated and versioned, so culpability arguments are made with documents rather than assurances. Our team runs the risk analysis itself when you need it done properly.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report showing which of the commonly cited gaps above apply to you, and what to fix first. If you are further along than you thought, we will tell you that too.