🏥 HIPAA⚖️ Penalties📘 Plain English

HIPAA Penalties in Plain English — What the Fines Actually Look Like

The number that gets quoted is per violation — and a single failing can be thousands of violations. Here is how HIPAA penalties really work: the civil tiers, the criminal exposure, and the settlements that show what regulators actually charge for.

SS
Soham Sawant
🔐 Cybersecurity Expert & Technical Writer·📖 8 min read
📅 June 2026·🏢 SecComply
HIPAA penalties and fines explained civil tiers criminal penalties OCR settlements

HIPAA fines aren't priced by the incident — they're priced by the violation, and by how much you knew and ignored.

When people hear a HIPAA penalty figure, they picture a single fine for a single mistake. That is not how the maths works. Penalties are assessed per violation, and a systemic failure — no risk analysis, an unencrypted database, a control that failed for every record it touched — can be counted as one violation per affected individual. That is how a lapse most founders would call "an oversight" turns into a seven-figure resolution. The good news buried in that structure is that the size of the penalty tracks the size of the negligence: the tiers are built around how much you knew and how you responded, which means the outcome is largely within your control.

4 tiers
Civil penalties scale by how culpable you were
Per violation
Often counted once per affected record
$250K / 10 yr
The top criminal penalty for selling or misusing PHI
$16M
Anthem's 2018 settlement — the largest to date

Who Enforces, and How

Two agencies sit behind HIPAA penalties. Civil enforcement runs through the Department of Health and Human Services' Office for Civil Rights (OCR), which investigates complaints and breaches and can impose civil monetary penalties. Criminal enforcement runs through the Department of Justice, reserved for cases where PHI is knowingly obtained or disclosed in violation of the law.

In practice, most OCR cases don't end in a formal penalty at all — they end in a resolution agreement: a negotiated settlement paired with a corrective action plan that puts the organisation under monitored obligations, often for years. That structure matters, because the headline dollar figure is only part of the cost. The corrective action plan — rewriting policies, running the risk analysis you should already have had, submitting to oversight — is frequently the more expensive and disruptive half.

The Four Civil Penalty Tiers

The civil penalty system is built around a single idea: culpability. The less you knew and the better you responded, the lower the floor; the more you ignored, the higher it climbs. There are four tiers.

TierCulpabilityMinimum per violationAnnual cap (per provision)
Tier 1Did not know, and could not reasonably have known~$100~$25,000
Tier 2Reasonable cause, but not willful neglect~$1,000~$100,000
Tier 3Willful neglect — corrected within 30 days~$10,000~$250,000
Tier 4Willful neglect — not corrected~$50,000~$1,500,000
💡
THE FIGURES MOVE EVERY YEAR

These are the statutory reference amounts, and the maximum per violation reaches roughly $50,000 across the tiers. Two things adjust them in practice: HHS's 2019 enforcement discretion set the tiered annual caps shown above, and every amount is adjusted for inflation each year — so the real numbers today sit higher than the round figures. Treat the tiers as the shape of the system, not a fixed price list.

The lever that matters most in this table is the jump into willful neglect. Tiers 1 and 2 are for organisations that tried and fell short. Tiers 3 and 4 are for those that didn't try — no risk analysis, ignored warnings, known gaps left open. And the single word separating Tier 3 from Tier 4 is corrected: fixing the problem within 30 days of discovery can be the difference between a $250,000 ceiling and a $1.5 million one.

When It Becomes Criminal

Civil penalties are about failures of diligence. Criminal penalties are about intent — knowingly obtaining or disclosing PHI in violation of HIPAA — and they come with prison time. The Department of Justice recognises three escalating levels.

ConductFine up toPrison up to
Knowingly obtaining or disclosing PHI$50,0001 year
Offenses committed under false pretenses$100,0005 years
Intent to sell, transfer, or use PHI for personal gain, commercial advantage, or malicious harm$250,00010 years

These cases are rarer than civil settlements, and they typically involve an individual — an employee snooping in records, someone selling patient data — rather than a company's security posture. But they are a reminder that HIPAA is not purely a corporate compliance matter: a person can be prosecuted, and the intent to profit from PHI is what pushes conduct to the top of the scale.

What the Fines Actually Look Like

The tiers are theory. What regulators have actually charged tells you what they care about. A sample of landmark resolutions, from the largest ever down to the settlement that put every vendor on notice:

Case (year)AmountWhat happened
Anthem (2018)$16,000,000A 2015 cyberattack exposed the PHI of nearly 79 million people; OCR cited risk-analysis and control failures. The largest HIPAA settlement to date
Premera Blue Cross (2020)$6,850,000A breach affecting over 10 million individuals, with longstanding, unaddressed security gaps
Advocate Health Care (2016)$5,550,000Multiple breaches and a missing enterprise-wide risk analysis — the largest against a single entity at the time
Cignet Health (2011)$4,300,000The first-ever civil monetary penalty — for denying patients access to their records and failing to cooperate with OCR
CHCS (2016)$650,000A stolen unencrypted iPhone exposed 412 residents' PHI — the first settlement directly with a business associate

Read the "what happened" column and a pattern jumps out. These are rarely exotic attacks. They are missing risk analyses, unencrypted devices, denied access requests, and gaps that had been known and left open — the ordinary failures that a basic programme would have caught. The CHCS case is the one every startup should sit with: a vendor, not a hospital, paid because it handled PHI without the controls the law assumes. We tell that story in full in HIPAA explained for startups.

What Drives a Big Fine

Across the enforcement record, the same handful of factors turn a manageable incident into a headline penalty. They are worth knowing precisely because each one is avoidable.

  • No risk analysis. The single most cited failing in OCR settlements. Its absence is what pushes a case toward willful neglect, because the law treats the risk analysis as the baseline every regulated party must have.
  • Unencrypted PHI. Encryption is a safe harbour under the Breach Notification Rule; skipping it turns a lost laptop into a reportable, penalisable breach.
  • Known, unaddressed gaps. A vulnerability you were warned about and left open is the definition of willful neglect — and the jump to the top tier.
  • Delay and non-cooperation. Slow notification, or stonewalling an OCR investigation, aggravates the outcome. Cignet's penalty was as much about non-cooperation as the original violation.
  • Denying individual rights. OCR has a dedicated Right of Access initiative; refusing patients their own records is an easy, self-inflicted violation.
🚨
THE RISK ANALYSIS IS THE HILL THESE CASES DIE ON

If you read the OCR resolutions closely, one document is missing again and again: a current, thorough security risk analysis. It is the cheapest control to have and the most expensive to lack, because its absence is what reclassifies an honest mistake as willful neglect and moves the penalty into the top tier. Run it, date it, and act on it before anything else.

The Cost Beyond the Fine

The civil penalty is the most visible cost, but rarely the largest. An enforcement action drags a long tail behind it, and for a startup the tail can be existential in a way the fine alone is not.

✗ The Fine Is Only the Start

  • A multi-year corrective action plan under OCR oversight
  • Breach notification and credit-monitoring costs
  • Legal, forensic, and remediation spend
  • Enterprise deals lost during a public breach
  • Reputational damage in a trust-driven market

✓ What Prevention Costs Instead

  • A documented risk analysis, refreshed on a cadence
  • Encryption and access controls you likely need anyway
  • Signed BAAs before PHI ever moves
  • Workforce training and a tested breach plan
  • Evidence that doubles as SOC 2 and ISO 27001 readiness

The asymmetry is the whole argument. The preventive column is a known, modest, mostly one-time-plus-maintenance cost that also advances your other compliance goals. The penalty column is an unbounded, reputationally toxic cost that arrives at the worst possible moment. Much of the prevention work is the same as ISO 27001 for healthcare, so it is rarely spent only on HIPAA.

1
Run and document a risk analysis

Map where ePHI lives, assess the threats, and record it. This one artefact does more to keep you out of the top tier than any other single action.

2
Encrypt PHI everywhere

At rest and in transit. Encryption is the safe harbour that can turn a breach into a non-event under the notification rule.

3
Fix known gaps fast

Correcting a discovered problem within 30 days is the documented line between Tier 3 and Tier 4 — literally a six-figure difference in the ceiling.

4
Honour access and notify on time

Give individuals their records, meet the 60-day breach deadlines, and cooperate with OCR. Self-inflicted, avoidable violations are the easiest penalties to never incur.

Final Thought

HIPAA penalties look terrifying as a number and become almost logical as a system. The framework doesn't punish having an incident; it punishes not trying — no risk analysis, no encryption, known gaps ignored, individuals stonewalled. Every one of the landmark fines is, at its core, a story about a control that a modest programme would have had. Which means the fine is less a threat than a mirror: it reflects how seriously the organisation took the data before anything went wrong.

The test: imagine OCR asking for your risk analysis tomorrow. If you can hand over a current, dated document and show you acted on it, you are structurally in the lower tiers no matter what happens. If that document doesn't exist, you are one incident away from willful neglect — and that gap, not the breach itself, is what the biggest fines are really made of.

Stay in the Lower Tiers — Before You Ever Need To

SecComply runs the risk analysis OCR looks for first, closes the encryption and access gaps that drive the biggest fines, and gets your BAAs, training, and breach plan in place — so a bad day stays a bad day, not a seven-figure resolution.

Frequently Asked Questions

How much is a HIPAA fine?

Civil penalties run from around $100 per violation at the lowest tier to $50,000 per violation at the highest, with annual caps reaching roughly $1.5 million per identical provision — and every figure is adjusted for inflation each year, so current amounts are higher. Because a single failing can count as thousands of violations (one per affected record), real settlements routinely land in the hundreds of thousands to millions.

What are the four HIPAA penalty tiers?

They are set by culpability. Tier 1: you did not know and could not reasonably have known. Tier 2: reasonable cause, but not willful neglect. Tier 3: willful neglect that you corrected within 30 days. Tier 4: willful neglect that you did not correct. Penalties rise sharply from tier to tier — the more you knew or ignored, the higher the floor.

Can you go to jail for a HIPAA violation?

Yes. Criminal penalties, prosecuted by the Department of Justice, apply when PHI is knowingly obtained or disclosed in violation of HIPAA. They range from up to $50,000 and one year in prison for a knowing violation, to $100,000 and five years under false pretenses, to $250,000 and ten years when done to sell PHI or for personal gain or malicious harm.

What is the largest HIPAA fine ever?

The largest HIPAA settlement to date is Anthem's $16 million in 2018, following a 2015 cyberattack that exposed the protected health information of nearly 79 million people. OCR found failures in risk analysis and controls that let attackers move through Anthem's systems undetected for months.