HIPAA Fine Calculator
Pick a culpability tier, enter how many violations and how many calendar years, and get the minimum-to-maximum civil penalty range under 45 CFR § 160.404 with the 2026 inflation-adjusted amounts and annual caps applied.
Pre-filled with a realistic example: a misdirected mailing that exposed 250 patient records, found by a staff member (reasonable cause). Change any input and the range updates instantly.
Estimated civil penalty exposure
Tier 2: Reasonable Cause250 violations × 1 calendar year · 2026 amounts · $1,461 – $73,011 per violation
Minimum
$365,250
below cap
Maximum
$2,190,294
uncapped $18.25M → capped
The cap is per identical provision per calendar year. A breach that violates the risk-analysis requirement and the breach-notification rule carries two separate caps. OCR also weighs harm, history, cooperation, and ability to pay under 45 CFR § 160.408, so real settlements land well below these figures.
| Tier (2026) | Per violation | Cap / year |
|---|---|---|
| Tier 1: Lack of Knowledge | $145 – $73,011 | $2,190,294 |
| ▸ Tier 2: Reasonable Cause | $1,461 – $73,011 | $2,190,294 |
| Tier 3: Willful Neglect (Corrected) | $14,602 – $73,011 | $2,190,294 |
| Tier 4: Willful Neglect (Not Corrected) | $73,011 – $2,190,294 | $2,190,294 |
FIG · 01How HIPAA Fines Are Calculated
HIPAA civil money penalties come from 42 U.S.C. § 1320d-5, implemented at 45 CFR § 160.404. There are four culpability tiers, each with a minimum and maximum per violation and a cap of $2,190,294 per identical provision per calendar year. HHS adjusts the dollar figures for inflation every January; this tool uses the 2026 amounts.
The formula is simple: per-violation amount × number of violations, then cut off at the cap for each year involved. What is not simple is how OCR counts violations, which is why most online tables are misleading. The same incident can be one violation or fifty thousand depending on which provision was broken. Our guide to HIPAA violation penalties walks through the tiers in depth; the most common violations show which provisions get cited most.
How OCR Counts Violations
45 CFR § 160.406 lets OCR treat each affected individual, or each day of continued non-compliance, as a separate violation. Three counting rules cover almost every case:
Per record
An impermissible disclosure is one violation per individual whose PHI was exposed. A 4,000-record breach is 4,000 violations of § 164.502.
Per day
An ongoing failure (no risk analysis, no BAA, no policies) is one violation per day it continued. 18 months without a risk analysis is ~548 violations of § 164.308(a)(1).
Per provision
The annual cap is per identical provision. One incident that breaks the Security Rule, the Privacy Rule, and the Breach Notification Rule carries three separate caps.
Worked example: a lost unencrypted laptop with 3,200 patient records, no encryption, and no risk analysis for two years. That is 3,200 disclosure violations (one cap), ~730 days of a missing risk analysis (a second cap, split across two years), and possibly a late-notification violation (a third). Run each one through the calculator separately and add them up.
How to Use This HIPAA Fine Calculator
- 1
Pick the culpability level — Be honest. OCR decides this from your records, not your intent. If you had no policies, no training, and no risk analysis, expect willful neglect.
- 2
Toggle whether it was corrected within 30 days — The clock starts the day you knew, or should have known. For willful neglect this drops you a tier; for anything less it is an affirmative defense that bars the penalty entirely.
- 3
Enter the violation count — Records affected for a disclosure, or days of non-compliance for a missing safeguard. Use the presets for a quick scenario.
- 4
Set the calendar years the violation spanned — Each year gets its own cap. A failure that ran from November to February touches two years.
- 5
Read the range against the cap — The meter shows how far your exposure sits from the maximum. Print or copy the summary for your risk register or board memo.
Pair the output with your risk assessment and incident report so the dollar figure sits next to the likelihood and the facts. That is what a board or an insurer wants to see.
The 2019 Enforcement Discretion Caps
In April 2019 HHS published a Notice of Enforcement Discretion saying it would apply lower annual caps for the first three tiers than the statute allows: $25,000 for Tier 1, $100,000 for Tier 2, and $250,000 for Tier 3 (base figures, adjusted for inflation each year). Only Tier 4, willful neglect left uncorrected, keeps the full statutory cap.
This calculator shows the statutory caps from the regulation because the notice is discretionary, was never codified, and HHS said it may change it without further notice. Treat the lower caps as the likely ceiling for a good-faith mistake and the statutory cap as the number that appears in a demand letter. Either way, the cheapest path is still a documented compliance program and workforce training that keeps you out of willful neglect.
Recent OCR Settlements for Scale
The calculator shows statutory exposure. Real outcomes are negotiated. Notice that the record count barely predicts the amount: a 15-million-record breach settled for $10,000 and a single-patient insider snooping case for $800,000. What moves the number is the failure to do a risk analysis, slow breach notification, and the entity's size.
| Entity | Date | Amount | Records | What went wrong |
|---|---|---|---|---|
| Warby ParkerCMP | 2025-02-20 | $1,500,000 | ~197,000 | No risk analysis, weak security measures, no log review after credential-stuffing attack |
| BayCare Health System | 2025-05-28 | $800,000 | 1 complainant | Insider accessed a patient's records; access controls and risk management failures |
| PIH Health | 2025-01 | $600,000 | 189,763 | Phishing breach; risk analysis and late breach notification |
| OSF Healthcare System | 2026-07-29 | $552,250 | 53,907 | 2021 ransomware; risk analysis failure, late notices to patients and HHS |
| Syracuse ASC | 2025-07-24 | $250,000 | ~24,900 | Ransomware; no risk analysis, notification timing |
| Comstar, LLC (BA) | 2025-05-30 | $75,000 | 585,621 | Ransomware at an ambulance-billing vendor; no risk analysis. MA and CT AGs later added $515,000 (2026) |
| MMG Fusion (BA) | 2026-03-05 | $10,000 | ~15,000,000 | Exposed appointment data; risk analysis and notification failures. Amount reflects ability to pay |
CMP = civil money penalty imposed unilaterally; all others are resolution agreements with a corrective action plan and 2–3 years of OCR monitoring. BA = business associate. Sources: HHS OCR press releases, HIPAA Journal enforcement tracker (checked Aug 2026).
State Attorney General Actions
The HITECH Act (42 U.S.C. § 1320d-5(d)) lets any state attorney general sue on behalf of residents for HIPAA violations. Federal damages in those suits are limited to $100 per violation, capped at $25,000 per identical provision per year, plus attorney fees. That sounds small until you remember states stack their own consumer-protection and data-breach statutes on top, which is where the big numbers come from.
Comstar paid OCR $75,000 in 2025, then $515,000 to the Massachusetts and Connecticut AGs in 2026 for the same breach. Multi-state actions run higher still. Our guide to filing a HIPAA complaint covers both the OCR and the state routes. Add state exposure on top of whatever this calculator shows.
Criminal Penalties (42 U.S.C. § 1320d-6)
Civil penalties are for the organization. Criminal charges, prosecuted by the Department of Justice, are for the individual who knowingly obtained or disclosed PHI. Employees snooping on records, selling patient lists, or using PHI for identity theft are the typical defendants. These are not adjusted for inflation.
| Conduct | Fine | Prison | Cite |
|---|---|---|---|
| Knowingly obtaining or disclosing PHI | Up to $50,000 | Up to 1 year | § 1320d-6(b)(1) |
| Under false pretenses | Up to $100,000 | Up to 5 years | § 1320d-6(b)(2) |
| Intent to sell, transfer, or use for commercial advantage, personal gain, or malicious harm | Up to $250,000 | Up to 10 years | § 1320d-6(b)(3) |
The 2005 DOJ opinion confirms individuals inside a covered entity can be charged directly. Your sanctions policy and training log are what separate an organizational civil case from an employee's criminal one.
HIPAA Fine FAQ
+Is the fine per violation or per breach?
Per violation. One breach usually contains many violations: one per affected person for the disclosure, plus one per day for each safeguard that was missing. The calculator prices one provision at a time.
+Can a small practice really be fined millions?
Statutorily, yes. In practice OCR weighs ability to pay under 45 CFR § 160.408 and most small-practice settlements land between $10,000 and $250,000. The exposure number still matters for cyber insurance and vendor contracts.
+Does self-reporting reduce the fine?
Reporting a breach is required, so it does not earn credit by itself. Cooperating with the investigation, correcting fast, and having a prior risk analysis on file are the factors that move the amount down.
+Are business associates fined the same way?
Yes. Since the 2013 Omnibus Rule business associates are directly liable under the same four tiers. Comstar and MMG Fusion in the table above were both business associates. A signed BAA does not shift that liability.
+How far back can OCR go?
Six years from the date OCR knew or should have known of the violation (45 CFR § 160.414). Retention rules for HIPAA documentation are also six years, which is not a coincidence.
Related Tools & Guides
HIPAA Violation Penalties Explained
The four civil tiers, criminal charges, and what OCR actually fines for, with current amounts.
Most Common HIPAA Violations
The provisions OCR cites most often and how each one gets counted.
HIPAA Breach Notification Rule
60-day deadlines, the 500-record threshold, and the four-factor risk assessment.
HIPAA Risk Assessment Tool
The risk analysis OCR asks for first in nearly every investigation.
HIPAA Incident Report Form
Document an incident and run the breach risk assessment that decides if it is reportable.