When people hear a HIPAA penalty figure, they picture a single fine for a single mistake. That is not how the maths works. Penalties are assessed per violation, and a systemic failure — no risk analysis, an unencrypted database, a control that failed for every record it touched — can be counted as one violation per affected individual. That is how a lapse most founders would call "an oversight" turns into a seven-figure resolution. The good news buried in that structure is that the size of the penalty tracks the size of the negligence: the tiers are built around how much you knew and how you responded, which means the outcome is largely within your control.
Who Enforces, and How
Two agencies sit behind HIPAA penalties. Civil enforcement runs through the Department of Health and Human Services' Office for Civil Rights (OCR), which investigates complaints and breaches and can impose civil monetary penalties. Criminal enforcement runs through the Department of Justice, reserved for cases where PHI is knowingly obtained or disclosed in violation of the law.
In practice, most OCR cases don't end in a formal penalty at all — they end in a resolution agreement: a negotiated settlement paired with a corrective action plan that puts the organisation under monitored obligations, often for years. That structure matters, because the headline dollar figure is only part of the cost. The corrective action plan — rewriting policies, running the risk analysis you should already have had, submitting to oversight — is frequently the more expensive and disruptive half.
The Four Civil Penalty Tiers
The civil penalty system is built around a single idea: culpability. The less you knew and the better you responded, the lower the floor; the more you ignored, the higher it climbs. There are four tiers.
| Tier | Culpability | Minimum per violation | Annual cap (per provision) |
|---|---|---|---|
| Tier 1 | Did not know, and could not reasonably have known | ~$100 | ~$25,000 |
| Tier 2 | Reasonable cause, but not willful neglect | ~$1,000 | ~$100,000 |
| Tier 3 | Willful neglect — corrected within 30 days | ~$10,000 | ~$250,000 |
| Tier 4 | Willful neglect — not corrected | ~$50,000 | ~$1,500,000 |
These are the statutory reference amounts, and the maximum per violation reaches roughly $50,000 across the tiers. Two things adjust them in practice: HHS's 2019 enforcement discretion set the tiered annual caps shown above, and every amount is adjusted for inflation each year — so the real numbers today sit higher than the round figures. Treat the tiers as the shape of the system, not a fixed price list.
The lever that matters most in this table is the jump into willful neglect. Tiers 1 and 2 are for organisations that tried and fell short. Tiers 3 and 4 are for those that didn't try — no risk analysis, ignored warnings, known gaps left open. And the single word separating Tier 3 from Tier 4 is corrected: fixing the problem within 30 days of discovery can be the difference between a $250,000 ceiling and a $1.5 million one.
When It Becomes Criminal
Civil penalties are about failures of diligence. Criminal penalties are about intent — knowingly obtaining or disclosing PHI in violation of HIPAA — and they come with prison time. The Department of Justice recognises three escalating levels.
| Conduct | Fine up to | Prison up to |
|---|---|---|
| Knowingly obtaining or disclosing PHI | $50,000 | 1 year |
| Offenses committed under false pretenses | $100,000 | 5 years |
| Intent to sell, transfer, or use PHI for personal gain, commercial advantage, or malicious harm | $250,000 | 10 years |
These cases are rarer than civil settlements, and they typically involve an individual — an employee snooping in records, someone selling patient data — rather than a company's security posture. But they are a reminder that HIPAA is not purely a corporate compliance matter: a person can be prosecuted, and the intent to profit from PHI is what pushes conduct to the top of the scale.
What the Fines Actually Look Like
The tiers are theory. What regulators have actually charged tells you what they care about. A sample of landmark resolutions, from the largest ever down to the settlement that put every vendor on notice:
| Case (year) | Amount | What happened |
|---|---|---|
| Anthem (2018) | $16,000,000 | A 2015 cyberattack exposed the PHI of nearly 79 million people; OCR cited risk-analysis and control failures. The largest HIPAA settlement to date |
| Premera Blue Cross (2020) | $6,850,000 | A breach affecting over 10 million individuals, with longstanding, unaddressed security gaps |
| Advocate Health Care (2016) | $5,550,000 | Multiple breaches and a missing enterprise-wide risk analysis — the largest against a single entity at the time |
| Cignet Health (2011) | $4,300,000 | The first-ever civil monetary penalty — for denying patients access to their records and failing to cooperate with OCR |
| CHCS (2016) | $650,000 | A stolen unencrypted iPhone exposed 412 residents' PHI — the first settlement directly with a business associate |
Read the "what happened" column and a pattern jumps out. These are rarely exotic attacks. They are missing risk analyses, unencrypted devices, denied access requests, and gaps that had been known and left open — the ordinary failures that a basic programme would have caught. The CHCS case is the one every startup should sit with: a vendor, not a hospital, paid because it handled PHI without the controls the law assumes. We tell that story in full in HIPAA explained for startups.
What Drives a Big Fine
Across the enforcement record, the same handful of factors turn a manageable incident into a headline penalty. They are worth knowing precisely because each one is avoidable.
- No risk analysis. The single most cited failing in OCR settlements. Its absence is what pushes a case toward willful neglect, because the law treats the risk analysis as the baseline every regulated party must have.
- Unencrypted PHI. Encryption is a safe harbour under the Breach Notification Rule; skipping it turns a lost laptop into a reportable, penalisable breach.
- Known, unaddressed gaps. A vulnerability you were warned about and left open is the definition of willful neglect — and the jump to the top tier.
- Delay and non-cooperation. Slow notification, or stonewalling an OCR investigation, aggravates the outcome. Cignet's penalty was as much about non-cooperation as the original violation.
- Denying individual rights. OCR has a dedicated Right of Access initiative; refusing patients their own records is an easy, self-inflicted violation.
If you read the OCR resolutions closely, one document is missing again and again: a current, thorough security risk analysis. It is the cheapest control to have and the most expensive to lack, because its absence is what reclassifies an honest mistake as willful neglect and moves the penalty into the top tier. Run it, date it, and act on it before anything else.
The Cost Beyond the Fine
The civil penalty is the most visible cost, but rarely the largest. An enforcement action drags a long tail behind it, and for a startup the tail can be existential in a way the fine alone is not.
✗ The Fine Is Only the Start
- A multi-year corrective action plan under OCR oversight
- Breach notification and credit-monitoring costs
- Legal, forensic, and remediation spend
- Enterprise deals lost during a public breach
- Reputational damage in a trust-driven market
✓ What Prevention Costs Instead
- A documented risk analysis, refreshed on a cadence
- Encryption and access controls you likely need anyway
- Signed BAAs before PHI ever moves
- Workforce training and a tested breach plan
- Evidence that doubles as SOC 2 and ISO 27001 readiness
The asymmetry is the whole argument. The preventive column is a known, modest, mostly one-time-plus-maintenance cost that also advances your other compliance goals. The penalty column is an unbounded, reputationally toxic cost that arrives at the worst possible moment. Much of the prevention work is the same as ISO 27001 for healthcare, so it is rarely spent only on HIPAA.
Map where ePHI lives, assess the threats, and record it. This one artefact does more to keep you out of the top tier than any other single action.
At rest and in transit. Encryption is the safe harbour that can turn a breach into a non-event under the notification rule.
Correcting a discovered problem within 30 days is the documented line between Tier 3 and Tier 4 — literally a six-figure difference in the ceiling.
Give individuals their records, meet the 60-day breach deadlines, and cooperate with OCR. Self-inflicted, avoidable violations are the easiest penalties to never incur.
Final Thought
HIPAA penalties look terrifying as a number and become almost logical as a system. The framework doesn't punish having an incident; it punishes not trying — no risk analysis, no encryption, known gaps ignored, individuals stonewalled. Every one of the landmark fines is, at its core, a story about a control that a modest programme would have had. Which means the fine is less a threat than a mirror: it reflects how seriously the organisation took the data before anything went wrong.
The test: imagine OCR asking for your risk analysis tomorrow. If you can hand over a current, dated document and show you acted on it, you are structurally in the lower tiers no matter what happens. If that document doesn't exist, you are one incident away from willful neglect — and that gap, not the breach itself, is what the biggest fines are really made of.
Frequently Asked Questions
Civil penalties run from around $100 per violation at the lowest tier to $50,000 per violation at the highest, with annual caps reaching roughly $1.5 million per identical provision — and every figure is adjusted for inflation each year, so current amounts are higher. Because a single failing can count as thousands of violations (one per affected record), real settlements routinely land in the hundreds of thousands to millions.
They are set by culpability. Tier 1: you did not know and could not reasonably have known. Tier 2: reasonable cause, but not willful neglect. Tier 3: willful neglect that you corrected within 30 days. Tier 4: willful neglect that you did not correct. Penalties rise sharply from tier to tier — the more you knew or ignored, the higher the floor.
Yes. Criminal penalties, prosecuted by the Department of Justice, apply when PHI is knowingly obtained or disclosed in violation of HIPAA. They range from up to $50,000 and one year in prison for a knowing violation, to $100,000 and five years under false pretenses, to $250,000 and ten years when done to sell PHI or for personal gain or malicious harm.
The largest HIPAA settlement to date is Anthem's $16 million in 2018, following a 2015 cyberattack that exposed the protected health information of nearly 79 million people. OCR found failures in risk analysis and controls that let attackers move through Anthem's systems undetected for months.