Pabau GO app

The new Pabau GO is heredownload on the App Store

Download on the App Store
Book a demo Book a demo
Compliance and security

HIPAA violation penalties: Tiers, fines, and how to avoid them

Avatar photo Katy Piper
Last Updated: August 28, 2026
Reviewed by: Avatar photo Lucy Galloway
Key takeaways

Key takeaways

HIPAA violation penalties range from $145 to $2,190,294 per violation depending on the level of culpability, structured across four tiers.

Criminal penalties for knowingly misusing PHI can reach $250,000 and 10 years imprisonment under 42 U.S.C. § 1320d-6.

OCR applies lower, tier-specific annual caps under its 2019 enforcement discretion policy, so a single breach touching multiple tiers can trigger several caps at once.

Pabau’s compliance management tools include built-in access controls, audit logs, and digital consent workflows that reduce PHI exposure risk.

Most practices that face HIPAA violation penalties did not plan to violate the law. According to HHS OCR enforcement data, the majority of complaints resolved through corrective action involve failures in safeguards and impermissible disclosures, not deliberate misconduct. The financial consequences, however, do not distinguish between intent and negligence at the fine level. HIPAA violation penalties have reached into the millions for single events, and the annual cap structure means multiple violations compound quickly.

This guide breaks down every penalty tier and explains how OCR calculates fines. It covers employee liability and gives practice managers a prevention framework to stay ahead of enforcement.

Found our content helpful?

What are HIPAA violation penalties and who do they apply to?

HIPAA violation penalties are financial and criminal sanctions under the Health Insurance Portability and Accountability Act. They apply to covered entities and business associates that fail to protect protected health information, known as PHI. The Office for Civil Rights (OCR) at the Department of Health and Human Services (HHS) administers civil enforcement. The Department of Justice (DOJ) handles criminal prosecutions.

Covered entities subject to penalties include healthcare providers, health plans, and healthcare clearinghouses. Business associates, meaning vendors and contractors that access PHI on behalf of a covered entity, are also directly liable under the HITECH Act amendments.

  • Healthcare providers: hospitals, physician practices, dental offices, mental health clinics, med spas providing clinical services
  • Health plans: insurers, employer-sponsored health plans, Medicare and Medicaid programs
  • Healthcare clearinghouses: entities that process non-standard health data into standard formats
  • Business associates: EHR vendors, billing companies, practice management software providers (including those who sign a BAA)

The four civil HIPAA violation penalty tiers

Civil monetary penalties (CMPs) for HIPAA violations are structured across four tiers based on culpability. The Federal Civil Penalties Inflation Adjustment Act requires HHS to update these figures annually. The table below reflects the statutory penalty structure under 45 CFR § 160.404, from HHS’s final rule published January 28, 2026.

Tier Culpability Level Per-Violation Range (Statutory) Statutory Annual Cap
Tier 1 Did not know $145 to $73,011 $2,190,294
Tier 2 Reasonable cause $1,461 to $73,011 $2,190,294
Tier 3 Willful neglect, corrected $14,602 to $73,011 $2,190,294
Tier 4 Willful neglect, not corrected $73,011 to $2,190,294 $2,190,294

Those are the full statutory ranges. In practice, OCR applies lower caps under its 2019 Notice of Enforcement Discretion. That guidance is not legally binding, but OCR has followed it in every enforcement action since 2019.

Under the 2019 policy, the annual caps OCR enforces are $36,505.50 for Tier 1, $146,053 for Tier 2, and $365,052 for Tier 3. Tier 4 stays at $2,190,294. The per-violation minimums and maximums stay the same as the statutory table above.

Critical distinction: OCR’s enforcement-discretion caps apply per violation category, not per organization total. An incident involving both impermissible disclosure and failure to conduct a risk assessment can trigger two separate annual caps simultaneously. OCR’s civil penalty authority is defined under 42 U.S.C. § 1320d-5.

Tier 1: Unknowing violations

Tier 1 applies when a covered entity could not have known, even with reasonable diligence, that a violation occurred. An example: a front-desk staff member sends a patient summary to the wrong fax number without any indication they had the incorrect contact. The $145 statutory minimum reflects OCR’s recognition that good-faith compliance mistakes happen.

Tier 2: Reasonable cause

Tier 2 covers situations where the entity should have known a violation would occur but did not act with willful neglect. Missing a required business associate agreement (BAA) with a vendor who handles PHI is a classic Tier 2 scenario. The entity had no malicious intent but failed to follow a known HIPAA requirement.

Tier 3 and Tier 4: Willful neglect

Willful neglect means conscious, intentional failure to comply with HIPAA requirements. Tier 3 applies when the entity corrects the violation within 30 days of discovery. Tier 4, carrying the highest penalties, applies when willful neglect goes uncorrected. Tier 4 is where OCR’s largest enforcement settlements typically land.

Criminal HIPAA penalties

Criminal penalties for HIPAA violations apply when individuals knowingly obtain or disclose PHI in violation of the law. The DOJ prosecutes these cases under 42 U.S.C. § 1320d-6, and individual employees, not just organizations, face personal criminal exposure.

Criminal Tier Offense Fine Imprisonment
Tier 1 Knowing HIPAA violation Up to $50,000 Up to 1 year
Tier 2 Violation under false pretenses Up to $100,000 Up to 5 years
Tier 3 Intent to sell, transfer, or use PHI for commercial gain or harm Up to $250,000 Up to 10 years

A nurse accessing a celebrity patient’s records out of curiosity, then sharing information with a tabloid, would face Tier 3 criminal prosecution. OCR refers cases to the DOJ when criminal activity is suspected. HIPAA Security Rule violations involving ePHI are particularly scrutinized in these referrals.

How HIPAA penalties apply to employees

Individual employees are not immune from these penalties. OCR typically fines covered entities and business associates as organizations. Employees who deliberately violate HIPAA still face personal criminal exposure under the DOJ prosecution framework above.

Employers bear vicarious liability for employee violations. That creates dual exposure: the organization pays civil fines, and the employee may face termination or criminal charges. HIPAA does not mandate that employers fire employees for violations, but most employment policies treat serious violations as terminable offenses.

  • Accidental violations (Tier 1 events): typically result in retraining, workflow corrections, no termination for first offense
  • Negligent violations (Tier 2 events): may result in formal disciplinary action, performance improvement plans
  • Willful misconduct (Tiers 3-4 and criminal): typically result in immediate termination and DOJ criminal referral

Reviewing your workforce training program is the first step. The intersection of HIPAA and social media is a growing source of employee-level violations. Clinical staff often share images or patient comments online without realizing PHI is embedded.

How OCR calculates HIPAA violation penalties

The tier table shows the range for each culpability level. OCR then picks a specific number within that range using six factors set out in its published enforcement methodology.

  • Nature and extent of the violation: how many individuals were affected, whether PHI was viewed or used
  • Duration: how long the non-compliant condition existed before detection
  • Prior compliance history: previous OCR investigations or unresolved corrective action plans substantially increase penalties
  • Financial condition: OCR can reduce penalties for small practices with limited resources, but this requires documentation
  • Good-faith remediation: entities that self-report violations and immediately begin corrective action consistently receive lower penalties than those that wait for OCR to initiate contact
  • Harm caused: identity theft, financial fraud, or physical harm resulting from a breach drives penalties toward the tier maximum

Self-reporting to OCR before a complaint is filed is the single most effective penalty-reduction strategy available to practices. The data protection best practices that make self-reporting possible start with knowing what data you hold and who can access it.

Pro Tip

Document every compliance issue you find internally, even when self-correcting. OCR treats a practice’s documented compliance history as evidence of good faith. A log showing you identified a missing BAA, escalated it, and fixed it within 72 hours is worth more than a verbal explanation during an investigation.

Common HIPAA violation examples that trigger penalties

Understanding HIPAA violation examples by category helps practices identify where their specific exposure lies. OCR’s enforcement data consistently shows the same violation types appearing across settlement after settlement.

  • Unauthorized PHI access or disclosure: staff accessing records of patients not under their care, emailing PHI to personal accounts, discussing patient information in public areas
  • Missing or incomplete BAAs: working with a billing service, IT vendor, or cloud storage provider that handles PHI without a signed business associate agreement
  • Unencrypted devices: laptops, tablets, or mobile phones containing ePHI without encryption, particularly when lost or stolen
  • Failure to conduct a security risk assessment: the HIPAA Security Rule requires covered entities to perform and document a regular risk analysis. Skipping it is itself a violation
  • Improper PHI disposal: paper records in unsecured recycling bins, hard drives disposed of without wiping, USB drives discarded without destruction
  • Missing workforce training: employees who have not completed documented HIPAA training show up repeatedly in OCR’s enforcement findings
  • Patient access failures: denying or delaying a patient’s right to access their own records within the 30-day HIPAA deadline

Going paperless is one of the most direct ways to reduce disposal and access violations. A paperless, HIPAA-compliant practice eliminates several of the most common physical PHI exposure points simultaneously.

HIPAA enforcement cases and what they cost

Abstract penalty figures become concrete when you look at what OCR has collected. The following cases are drawn from OCR resolution agreements and represent the range of enforcement outcomes across entity types and violation categories.

  • $2.175 million (Sentara Hospitals, November 2019): OCR found the health system under-reported the scope of a breach. It also lacked a business associate agreement with a vendor handling PHI.
  • $6.85 million (Premera Blue Cross, 2020): a cyberattack exposed PHI belonging to 10.4 million individuals. OCR found the insurer failed to run an enterprise-wide risk analysis or put adequate security measures in place.
  • $2.3 million (CHSPSC LLC, September 2020): a cyber intrusion affected over 6 million individuals. OCR cited insufficient hardware and software controls to prevent the breach.
  • $25,000 (Metropolitan Community Health Services, 2020): a federally qualified health center in North Carolina settled with OCR. The relatively small fine showed OCR holds small entities to the same enforcement framework as large health systems.

The pattern across these cases is consistent: the violation itself is usually secondary to the lack of documented risk management. Entities that can show OCR a functioning compliance program, even an imperfect one, tend to reach significantly lower settlement figures.

Who enforces HIPAA violations: OCR, DOJ, and state attorneys general

Most practice managers know OCR enforces HIPAA. Fewer know that state attorneys general have held independent enforcement authority since 2009 under the HITECH Act. They can bring civil actions in addition to OCR penalties.

The enforcement structure works across three channels:

  • OCR (civil enforcement): investigates complaints, conducts audits, imposes civil monetary penalties, negotiates resolution agreements and corrective action plans
  • DOJ (criminal prosecution): prosecutes individuals who knowingly obtain, use, or disclose PHI unlawfully. Handles referrals from OCR
  • State attorneys general: can bring civil actions on behalf of state residents. They may also apply state privacy laws, such as California’s CCPA or New York’s SHIELD Act, which carry additional penalties independent of HIPAA

State-level enforcement adds another layer of exposure for multi-location practices. A practice in California facing a breach involving California residents could receive an OCR CMP and a concurrent California AG action. Reviewing state-specific requirements matters most for practices with more than one location. Requirements for HIPAA compliance software vary by jurisdiction and should be validated at the state level.

How corrective action plans affect HIPAA violation penalties

A corrective action plan (CAP) is OCR’s primary remediation tool. When OCR resolves a case through a resolution agreement rather than a direct civil monetary penalty, the covered entity signs a multi-year agreement. That agreement commits the entity to specific compliance improvements under OCR monitoring.

Completing a CAP can reduce or eliminate financial penalties. The key requirements OCR typically includes in a CAP are:

  • Enterprise-wide risk analysis within 60-90 days
  • Updated HIPAA policies and procedures
  • Workforce training completion documentation
  • Annual compliance reports submitted to OCR
  • OCR audit rights for the duration of the agreement (typically 2-3 years)

Practices already running these processes because of a documented compliance program enter CAP negotiations from a much stronger position. The steps to take after a potential HIPAA violation should be documented in your incident response policy before you need them.

How to prevent HIPAA violations in your practice

Prevention is cheaper than any tier of HIPAA violation penalties. The following checklist reflects OCR’s most common enforcement areas and maps directly to the violation categories above.

  • Conduct an annual security risk assessment and document your findings. This is the single most-cited failure in OCR enforcement actions.
  • Maintain a complete BAA inventory. Every vendor with PHI access needs a signed agreement. Audit your vendor list quarterly.
  • Implement role-based access controls. Staff should access only the patient records relevant to their clinical role. System-generated access logs make this auditable.
  • Train all staff at onboarding and annually thereafter. Training records must be retained for six years.
  • Encrypt all devices containing ePHI. Encryption is a standard OCR expects to see in place. A lost encrypted device does not trigger breach notification requirements.
  • Establish a breach response protocol. HIPAA’s Breach Notification Rule requires notification to affected individuals within 60 days of discovery and to HHS if more than 500 individuals are affected.
  • Document your compliance work. OCR cannot assess good faith without paperwork. A compliance program that exists only in practice, not on paper, provides no protection during an investigation.

For med spas and aesthetic clinics, the compliance picture has specific nuances around consent documentation and before-and-after photo handling. Understanding whether your med spa is HIPAA-covered and to what extent is the starting point for building a proportionate compliance program.

How practice management software reduces HIPAA violation risk

Software infrastructure addresses many of the most common OCR enforcement triggers directly, starting with access control and audit logging. Pabau’s compliance management features are built around exactly these requirements.

Role-based access prevents unauthorized PHI access, the most common violation category. Automatically generated audit logs create the documentation OCR requires to demonstrate good-faith compliance during a CAP negotiation.

The digital consent form system eliminates improper paper disposal risks entirely. Consent records are stored in encrypted, access-controlled patient records rather than in physical files that can be lost, stolen, or improperly discarded. For the patient data security tools that matter most during an OCR audit, encryption and access logging are the two non-negotiables.

Customizable consent and intake forms
Digital consent and intake forms in Pabau replace paper files, so consent records can’t end up lost, stolen, or improperly discarded.

A compliant practice management platform also supports BAA management at the vendor level. Pabau signs BAAs with covered entities as a business associate, ensuring the contractual layer OCR requires is in place from day one of implementation.

Reduce HIPAA exposure before OCR comes knocking

Pabau gives healthcare practices built-in access controls, audit logs, encrypted patient records, and digital consent forms that create a documented compliance trail. See how it works for your practice.

Pabau HIPAA-compliant practice management software

Conclusion

HIPAA violation penalties range from $145 for an unknowing error to $2.19 million per violation for uncorrected willful neglect. The difference between those extremes is largely a compliance program question, not a luck question. Practices with documented risk assessments, trained workforces, signed BAAs, and access-controlled systems consistently land at the lower end of OCR’s penalty range. That still applies even when violations occur.

Pabau gives practices the access controls, audit logs, encrypted records, and digital consent workflows that turn manual compliance work into a built-in operational standard. See how Pabau approaches HIPAA compliance or book a demo to walk through the specific features with your workflow in mind.

Continue your research

Continue your research

Need a HIPAA compliance checklist tailored to medical offices? HIPAA compliance for medical offices covers documentation, training, and breach response requirements for physician practices.

Wondering about the HIPAA Security Rule requirements specifically? HIPAA Security Rule requirements explains the administrative, physical, and technical safeguards OCR audits first.

Running a med spa and unsure of your HIPAA obligations? Do med spas have to be HIPAA compliant answers the coverage question and outlines where aesthetic practices need to focus.

Want to understand the social media risk for clinical staff? HIPAA and social media covers the common employee mistakes that lead to OCR complaints and how to train against them.

Frequently asked questions

What are HIPAA violation penalties in 2026?

HIPAA violation penalties in 2026 range from $145 to $2,190,294 per violation depending on culpability, structured across four tiers. The statutory per-violation ranges run from $145 to $73,011 for an unknowing violation, and from $1,461 to $73,011 for reasonable cause. Willful neglect ranges from $14,602 to $73,011 if corrected, and from $73,011 to $2,190,294 if not. OCR applies lower annual caps in practice under its 2019 enforcement discretion policy.

What are the four tiers of HIPAA violation penalties?

The four tiers are Tier 1, an unknowing violation, and Tier 2, reasonable cause. Tier 3 is willful neglect corrected within 30 days. Tier 4 is willful neglect left uncorrected, carrying the highest penalties, up to $2,190,294 per violation. Each tier has its own per-violation range, but the statutory annual cap is $2,190,294 across all four tiers. OCR applies lower, tier-specific caps in practice under its 2019 enforcement discretion policy.

Can an employee be fired for an accidental HIPAA violation?

Yes, an employer can legally terminate an employee for an accidental HIPAA violation, though it is not required by law. Most employment policies treat the severity of the violation as the determining factor. First-offense accidental disclosures typically result in retraining, while deliberate or repeated violations typically lead to termination. Employees who knowingly misuse PHI also face personal criminal prosecution by the DOJ.

What is the maximum penalty for a HIPAA violation?

The maximum civil penalty for a HIPAA violation is $2,190,294 per violation, for Tier 4 willful neglect that goes uncorrected. That figure is also the statutory annual cap under 45 CFR § 160.404, which applies to every tier. On the criminal side, the maximum is a $250,000 fine and 10 years imprisonment. That applies to violations committed with intent to sell, transfer, or use PHI for commercial advantage or personal gain.

Can I sue someone for a HIPAA violation?

No. HIPAA does not provide a private right of action, meaning individuals cannot file a personal lawsuit to recover damages for a HIPAA violation. Enforcement is exclusively through OCR (civil penalties) and the DOJ (criminal prosecution). Some state privacy laws, such as California’s CMIA, do provide private rights of action for health information violations independent of HIPAA.

Who enforces HIPAA violations?

HIPAA violations are enforced by three authorities: the Office for Civil Rights, the Department of Justice, and state attorneys general. OCR handles civil penalties and corrective action plans. The DOJ prosecutes criminal cases. State attorneys general have held independent enforcement authority since 2009 under the HITECH Act, and can bring civil actions alongside OCR penalties.

Found our content helpful?
×