HIPAA & PRIVACY

HIPAA Violation Penalties and Fines (2026 Tiers)

Civil fines run from $145 to $2,190,294 per violation depending on culpability, with a $2.19M annual cap per provision. Criminal cases can mean prison. Below: the current tiers, how OCR counts violations, what recent practices actually paid, and what happens to the employee involved.

Cyanotype of a desk with a calculator, a closed ledger and a stack of sealed envelopesFIG · 01
A desk with a calculator, a closed ledger and a stack of sealed envelopes.

Civil penalty tiers, 2026

45 CFR 160.404 · inflation-adjusted

Tier 1Did not know

$145 – $73,011

per violation · cap $2,190,294/yr

Tier 2Reasonable cause

$1,461 – $73,011

per violation · cap $2,190,294/yr

Tier 3Willful neglect, fixed in 30 days

$14,602 – $73,011

per violation · cap $2,190,294/yr

Tier 4Willful neglect, not fixed

$73,011 – $2,190,294

per violation · cap $2,190,294/yr

“Annual cap” means per calendar year, per identical provision violated. Amounts apply to penalties assessed on or after January 28, 2026.

Estimate your exposure with the fine calculator
Cyanotype vignette of a calculator with blank tape curling over a closed ledgerFIG · 02
A calculator with blank tape curling over a closed ledger.

The Four Civil Penalty Tiers Explained

HIPAA civil penalties come from 42 USC 1320d-5, implemented at 45 CFR 160.404. The tier is set by culpability, not by how bad the breach was. Two practices can leak the same number of records and be fined very differently, because one had a risk analysis on file and the other did not.

Tier 1 — you did not know, and could not reasonably have known

The practice had reasonable safeguards and the violation still slipped through. Example: a vendor with a signed BAA misconfigures a server you had no way to inspect. If you fix a Tier 1 or Tier 2 problem within 30 days of learning about it, OCR is barred from imposing a civil money penalty at all (45 CFR 160.410).

Tier 2 — reasonable cause

You knew, or should have known with reasonable diligence, but it was not willful neglect. Most breach-driven settlements land here in practice: a phishing email that got through, a lost unencrypted laptop where a policy existed but was not followed.

Tier 3 — willful neglect, corrected within 30 days

Conscious, intentional failure or reckless indifference. The classic fact pattern is never having done a risk analysis. Correcting inside 30 days keeps you in Tier 3; it does not erase the penalty.

Tier 4 — willful neglect, not corrected

Same conduct, left unfixed past 30 days. The minimum per violation equals the Tier 1–3 maximum, and a single provision can reach the full annual cap. This is the tier behind the seven-figure civil money penalties.

Lowest per-violation minimum

$145

Tier 1

Tier 1–3 per-violation maximum

$73,011

also the Tier 4 minimum

Statutory annual cap

$2,190,294

per provision, per year

How “a violation” is counted. OCR can count each affected record, each day a requirement went unmet, or each occurrence. A missing risk analysis is usually counted per day, so a two-year gap is roughly 730 violations of one provision, capped per calendar year. Our HIPAA fine calculator runs that arithmetic with the 2026 amounts.

Annual Caps and the 2019 Enforcement Discretion

The regulation sets one cap for all four tiers: $2,190,294 per calendar year for all violations of an identical provision. That is per provision. A practice that failed the risk analysis standard, the access-control standard, and the breach-notification deadline in the same year faces three separate caps.

How OCR actually caps by tier (2019 Notice of Enforcement Discretion)

In April 2019 HHS announced it would exercise discretion and apply a lower annual cap for the three less-culpable tiers. The 2019 figures were:

TierRegulatory cap (current)Discretionary cap (2019, pre-inflation)
Tier 1$2,190,294$25,000
Tier 2$2,190,294$100,000
Tier 3$2,190,294$250,000
Tier 4$2,190,294$1,500,000

The discretionary caps are adjusted for inflation each year alongside the regulatory amounts. They were never written into 45 CFR 160.404, so HHS can withdraw them without rulemaking.

Why this matters less than it looks. Most OCR money changes hands through negotiated settlements (resolution agreements), not formal civil money penalties. Settlement amounts are not bound by the tier math at all. The caps mainly set OCR's leverage when it drafts a Notice of Proposed Determination. See the recent enforcement table below for what practices actually paid.

Criminal Penalties: Can You Go to Jail for a HIPAA Violation?

Yes. Criminal HIPAA cases are brought by the Department of Justice, not OCR, under 42 USC 1320d-6. The statute has three tiers keyed to intent. These dollar figures are set in the statute and are not inflation-adjusted like the civil amounts.

Knowingly obtaining or disclosing individually identifiable health information

Example: A billing clerk looks up a neighbor's chart out of curiosity.

up to $50,000

up to 1 year

Same offense committed under false pretenses

Example: Calling a clinic pretending to be the patient's physician to get records released.

up to $100,000

up to 5 years

With intent to sell, transfer, or use PHI for commercial advantage, personal gain, or malicious harm

Example: Selling patient lists to an identity-theft ring or a personal-injury marketer.

up to $250,000

up to 10 years

Who can be charged

Individuals, not just organizations. A 2005 DOJ opinion confirmed that employees and directors of a covered entity can be prosecuted directly, and courts have since upheld convictions of front-line staff who snooped or sold records.

“Knowingly” is a low bar

The government must show you knew you were obtaining or disclosing health information, not that you knew HIPAA prohibited it. Ignorance of the rule is not a defense. Prosecutors often pair the charge with wire fraud or aggravated identity theft, which carry their own sentences.

Realistically, prison sentences follow snooping-for-profit and record-selling cases, not honest mistakes. An honest mistake is a civil matter, and usually an internal one. What a practice should worry about is the everyday violations that show a pattern OCR can call willful neglect.

State Attorneys General and Employer Sanctions

State attorney general actions (HITECH)

Since the HITECH Act of 2009, every state AG can sue in federal court on behalf of residents harmed by a HIPAA Privacy or Security Rule violation (42 USC 1320d-5(d)). Statutory damages are $100 per violation, capped at $25,000 per calendar year for violations of an identical requirement, plus attorney fees. Those figures are also inflation-adjusted. In practice AGs stack HIPAA on top of state consumer-protection and data-breach statutes, which is where the large numbers come from.

  • State actions run in parallel with OCR and are not limited by the federal annual caps.
  • New York has been the most active. In 2025 the NY AG fined Orthopedics NY $500,000 over a breach affecting roughly 656,000 people.
  • Multistate coalitions have settled breach cases with vendors for millions; the HIPAA count is one piece of a larger complaint.

There is still no private right of action under HIPAA. Patients cannot sue you for a HIPAA violation directly; they file a complaint with OCR or their AG, or sue under state negligence law using HIPAA as the standard of care.

Can you get fired for a HIPAA violation?

Yes, and it is the most common consequence by far. The Privacy Rule requires covered entities to apply sanctions against workforce members who violate their policies (45 CFR 164.530(e)), and the Security Rule has a matching sanction policy standard. OCR reviews whether sanctions were applied when it investigates. A practice that shrugs off staff snooping looks like willful neglect.

A typical sanction ladder

1

Verbal or written warning

First accidental, low-impact slip: a misdirected fax caught quickly, a screen left unlocked.

2

Retraining and documented corrective action

Repeat carelessness, or a first incident that exposed PHI outside the practice.

3

Suspension or loss of system access

Accessing a record with no treatment, payment, or operations reason.

4

Termination

Intentional snooping, sharing PHI on social media, taking records to a new employer, or any conduct that triggers a breach report.

5

Referral to licensing board or law enforcement

Selling data, identity theft, or disclosures with malicious intent. Nurses and physicians can lose their license independently of any HIPAA fine.

Sanctions must be documented and consistent. Write the ladder into your HIPAA policy, cover it in annual training, and log every incident on a incident report form so you can show OCR the record.

Recent OCR Enforcement Actions (2024–2026)

Nine verified actions, newest first. Notice the pattern: the finding in almost every case is a missing or incomplete risk analysis, and the trigger is a breach report or a patient complaint. Amounts are what the entity paid; every case also carried a corrective action plan with two to three years of OCR monitoring.

DateEntityAmountTypeWhat OCR found
2026-07-29OSF Healthcare System (IL)$552,250SettlementRansomware; no comprehensive risk analysis; 53,907 patients
2026-06-18Spencer Gifts health plan$450,000SettlementRansomware at an employer group health plan; risk analysis and policy failures
2026-04-24Assured Imaging$375,000SettlementRansomware; no evidence a risk analysis was ever done
2026-03-05MMG Fusion (software vendor)$10,000SettlementBusiness associate breach affecting ~15 million; 3-year corrective plan
2025-05-28BayCare Health System (FL)$800,000SettlementInsider gave a non-clinician access; minimum-necessary and activity-review failures
2025-04-23PIH Health (CA)$600,000SettlementPhishing exposed 189,763 records; late breach notifications
2025-02-20Warby Parker$1,500,000CMPCredential stuffing; no risk analysis; did not contest the penalty
2025-01-14Solara Medical Supplies$3,000,000SettlementPhishing exposed 114,007 patients; breach notification failures
2024-02-06Montefiore Medical Center (NY)$4,750,000SettlementEmployee sold 12,517 records; no risk analysis or activity monitoring

Settlement = negotiated resolution agreement with no admission of liability. CMP = civil money penalty imposed by OCR after a Notice of Proposed Determination. Sources: HHS OCR press releases.

Read the $10,000 row carefully. A vendor breach touching roughly 15 million people settled for less than a small dental practice paid for a ransomware incident. OCR weighs financial condition and cooperation heavily (next section). Size of breach is one factor, not the multiplier. Under the Breach Notification Rule you still owe notification within 60 days no matter what the eventual penalty is.

What OCR Weighs When Setting the Amount

Inside a tier the number is not fixed. 45 CFR 160.408 lists the factors OCR must consider, and the settlements above show how they move the needle. The same list is what OCR reviews when it decides whether to investigate a patient complaint at all.

Pushes the penalty up

  • Number of individuals affected and how long the violation ran
  • Physical, financial, or reputational harm to patients (identity theft, denied care)
  • Prior indications of noncompliance: earlier complaints, earlier OCR contact, a previous corrective plan
  • No risk analysis, or one that ignored a system that later got breached
  • Ignoring OCR data requests, missing deadlines, incomplete responses

Pulls the penalty down

  • Fixing the problem within 30 days of discovery (mandatory defense at Tier 1–2, mitigating at Tier 3–4)
  • Documented safeguards that existed and were followed, even if they failed
  • Voluntary breach report, cooperation, and timely notification to patients
  • Financial condition: OCR has openly reduced penalties so a provider can keep operating
  • Sanctioning the responsible employee and retraining the workforce

The three documents that decide your tier

  1. 1. A current risk analysis. Missing in nearly every action above. Run the risk assessment tool and date it.
  2. 2. Training records. Proves staff knew the rule, which is what separates reasonable cause from willful neglect. Keep a training log.
  3. 3. Signed BAAs. Vendor breaches become your Tier 3 problem if there is no BAA on file.

Work through the HIPAA audit checklist once a year and you have the paper trail that turns a Tier 3 finding into a Tier 2 conversation.

Common Questions About HIPAA Fines

Quick Reference: HIPAA Penalties at a Glance

Civil (OCR)

$145 to $2,190,294 per violation across four culpability tiers; $2.19M cap per provision per year. Tier 1–2 fixed within 30 days: no penalty.

Criminal (DOJ)

Knowing disclosure: $50k / 1 yr. False pretenses: $100k / 5 yrs. Sale or malicious use: $250k / 10 yrs. Individuals can be charged.

State AG (HITECH)

$100 per violation, $25k per year per requirement (inflation-adjusted), plus state breach and consumer-protection laws on top.

Employer

Sanctions are required by 45 CFR 164.530(e). Termination for intentional access is standard; licensing boards act separately.

Related Tools & Guides