Key Takeaways
- Three bodies enforce the fines and penalties for HIPAA violations: OCR (civil penalties), the Department of Justice (criminal charges), and state attorneys general (concurrent civil actions).
- Civil penalties in 2026 range from $145 to $2,190,294 per violation, set by the level of culpability
- Criminal penalties run up to $250,000 and 10 years in prison, and they apply to individuals, not just organizations.
- A single incident can become thousands of violations, which is how a small mistake reaches 6 or 7 figures.
Table of Contents
Introduction
Healthcare practices spend heavily on EHRs, security tools, and staff training, yet the HIPAA violation fines and penalties that follow an investigation usually come down to something far simpler than technology.
Did you identify your risks? Did you limit who can access patient records? Did you document what you did?
Those three questions run through HHS guidance on risk analysis and nearly every recent enforcement action, because regulators want evidence that compliance was treated as an ongoing habit, not a once-a-year checkbox.
It is also why practice size offers so little protection. A solo clinic that cannot answer those questions is more exposed than a large system that can, and OCR has fined practices of every size.
This guide explains how HIPAA violation fines and penalties work in 2026, what regulators evaluate during an investigation, and the everyday steps that keep a practice in the lowest penalty tiers.
What are the HIPAA Violation Fines and Penalties in 2026?
Civil HIPAA violation fines and penalties in 2026 run from $145 to $2,190,294 per violation, sorted into four tiers based on how much you knew and how fast you fixed the problem. OCR sets these, and state attorneys general can pile on their own fines of up to $25,000 per violation category each year.
The current per-violation amounts, effective for penalties assessed on or after January 28, 2026 under the HHS inflation adjustment, are:
| Tier |
Culpability |
Minimum Per Violation |
Maximum Per Violation |
Annual Cap |
| 1 |
Did not know, and could not reasonably have known |
$145 |
$73,011 |
$2,190,294 |
| 2 |
Reasonable cause and not willful neglect |
$1,461 |
$73,011 |
$2,190,294 |
| 3 |
Willful neglect, corrected within 30 days |
$14,602 |
$73,011 |
$2,190,294 |
| 4 |
Willful neglect but not corrected |
$73,011
|
$2,190,294 |
$2,190,294 |
Since a 2019 Notice of Enforcement Discretion, OCR has applied much lower annual caps to Tiers 1 through 3. For 2026, those effective caps work out to roughly $36,505.50 for Tier 1, $146,053 for Tier 2, and $365,052 for Tier 3. Only Tier 4 carries the full $2,190,294. It’s a policy choice rather than a locked-in rule, so OCR could revert, but it is how the agency has operated for years.
Two more factors that decide what you would actually owe. First, that cap applies per category of violation, so if OCR finds problems in 3 separate areas, you could face three separate caps rather than one. Second, OCR rarely reaches for the maximum.
It weighs how many patients were affected, how much harm resulted, whether you had already addressed the issue, your prior history, and whether you cooperated with the investigation. In simple terms, the number is determined far more by what you can show you did than by the ceiling printed on the table.
What are the criminal penalties for HIPAA violations?
Criminal penalties are a separate track from civil fines, prosecuted by the Department of Justice rather than OCR, and they target individuals who knowingly misuse protected health information. Under Section 1320d-6 of the Social Security Act, the penalties escalate across three tiers based on intent.
There are three tiers, based on intent:
| Criminal Tier |
Conduct |
Maximum Fine |
Maximum Prison |
| 1. Basic offense |
Deliberate access to or disclosure of PHI without authorization |
$50,000 |
1 Year |
| 2. False pretenses |
Same, but done under false claims about identity or authority to gain access |
$100,000 |
5 Years |
| 3. Intent to profit or harm |
Done with intent to sell, transfer, or use PHI for commercial advantage, personal gain, or malicious harm |
$250,000 |
10 Years |
- Who is liable: Criminal penalties apply to individuals, not organizations. A hospital employee who accesses records without authorization, not the hospital itself, would face charges. Civil penalties, by contrast, are levied against the covered entity or business associate.
- Real cases: Individuals cannot receive civil monetary penalties from OCR; those go to the organization. But individuals can face criminal penalties from the DOJ, with fines up to $250,000 and up to 10 years in prison for a deliberate violation of HIPAA. Common cases involve staff who look up celebrity records or an ex-partner’s file, or employees who sell patient data for fraud.
- How cases start: OCR looks at the privacy or security incident on the civil side, then refers a matter to the DOJ when evidence points to criminal intent. OCR has no criminal enforcement authority of its own.
- Added exposure: Other statutes, such as identity theft or wire fraud, can add exposure beyond HIPAA’s tiers when the facts support them. Real sentences and fines in a given case can end up higher than the HIPAA-specific caps alone.
What Everyday Actions Trigger HIPAA Fines in a Clinical Setting?
Most penalties trace back to routine, avoidable clinical behavior rather than sophisticated cyberattacks. The actions below are the ones that surface repeatedly in OCR investigations:
- Record snooping: Accessing a patient’s chart without a treatment, payment, or operations reason, including out of curiosity about a coworker, family member, or public figure.
- Unsecured texting or emailing of PHI: Sending patient details over personal messaging apps or unencrypted email where they can be intercepted or misdelivered.
- Lost or stolen devices: An unencrypted laptop, phone, or USB drive holding patient data is one of the most common triggers for a large penalty.
- Verbal disclosures in shared spaces: Discussing identifiable patients in hallways, elevators, waiting rooms, or at the front desk where others can overhear.
- Social media posts: Sharing any patient-identifiable detail or image, even without a name, and even in a closed group.
- Improper disposal: Throwing records, labels, or prescription information into regular trash instead of shredding or securely destroying them.
The single most frequently penalized violation, however, is none of these. Under OCR’s Right of Access Initiative, dozens of practices have been fined for failing to provide patients a copy of their own records within the required window, generally 30 days.
It is common in HIPAA violation fines and penalties, avoidable, and a standing OCR enforcement priority, which makes it one of the easiest penalties for a provider to incur and to prevent.
Your next HIPAA fine could start with a routine task.
Bacancy’s HIPAA compliance services help you identify weak points in everyday workflows and put the right safeguards in place before they become compliance issues.
Can Individuals Be Fined, and How Does One Incident Become Many Violations?
Yes, individuals can be held personally liable, and a single incident can be counted as thousands of separate violations. Organizational civil liability rests with the practice, but criminal exposure attaches to the individual who knowingly misuses PHI, which is how a staff member’s action can become both the practice’s penalty and their own prosecution.
The counting mechanic is what turns a modest mistake into a catastrophic number. OCR can count a violation per affected individual or per day that non-compliance continues. A single lost laptop holding 2,000 patient records is not one violation.
It can be assessed as 2,000 violations, which is precisely how a $145 minimum reaches 6 or 7 figures. The math is rarely about the size of the error. The fines and penalties for HIPAA violations scale with the volume of records and the length of time the problem went unaddressed, not the severity of the initial slip.
What are the HIPAA Breach Notification Requirements and Deadlines?
HIPAA requires an organization to notify affected individuals without unreasonable delay and no later than 60 calendar days after discovering a breach. HHS must also be notified, within 60 days if 500 or more individuals are affected, or annually (within 60 days of the calendar year’s end) if fewer than 500 are affected. Prominent media outlets must be notified, within 60 days, only when a breach affects 500 or more residents of a single state or jurisdiction.
What counts as a breach?
Any impermissible use or disclosure of unsecured PHI is treated as a breach unless the organization can document through a formal risk assessment that there is a low probability the information was actually compromised. However, the default assumptions favour the patients and not the organizations.
Who has to be notified:
There are up to three audiences, depending on the size of the breach.
- 1. Affected individuals. Every person whose PHI was involved must be notified, always, regardless of how many people were affected.
- 2. HHS. Every breach gets reported to HHS eventually. The timing differs by size, covered below.
- 3. The media. Only required if the breach affects 500 or more residents of one state or jurisdiction.
What the notice must contain?
- A plain-language description of what happened, including the date of the breach and the date it was discovered
- What types of information were involved (name, SSN, diagnosis, account numbers, etc.)
- Steps the individual should take to protect themselves
- What the organization is doing to investigate, contain the damage, and prevent it from happening again
- Contact information so the person can ask questions
Individuals get the same 60-day deadline no matter the size of the breach. The only thing that changes with breach size is how fast HHS and the media find out.
The one exception to the 60-day rule:
If law enforcement determines that notifying people right away would interfere with an active criminal investigation or compromise national security, the organization must delay notification for a period tied to that request. Outside of that specific circumstance, the deadline doesn’t bend.
What happens if contact info is outdated?
If the organization can’t reach 10 or more affected people because their contact information is stale, it must post a substitute notice on its website, prominently displayed, for 90 consecutive days.
How Should a Provider Respond to a Breach or Suspected Violation?
The fines and penalties for HIPAA violations are only the visible part of the cost. The real total comes mostly from what happens after the fine, not the fine itself. Corrective action plans, breach response, legal exposure, and lost trust routinely add up to several times the original penalty.
1. Assess and contain
Conduct the four-factor risk assessment to determine whether the incident is a reportable breach, and stop ongoing exposure (revoke access, recover the device, disable the account).
2. Document everything
Record the discovery date, the assessment, who was affected, and every action taken. OCR treats poor documentation as an aggravating factor and thorough records as evidence of diligence.
3. Notify within the deadline
Send individual notices and, where the 500-individual threshold is met, the HHS and media notices, all inside the 60-day window described above. There is no grace period.
4. Remediate the root cause
Fix what allowed the incident (encrypt devices, tighten access controls, retrain staff) and keep proof of the correction.
Can a HIPAA Penalty Be Appealed, and What Training Is Required to Prevent One?
A civil money penalty can be appealed, and documented training is one of the clearest ways to reduce the odds of facing one. When OCR proposes a penalty, the entity has the right to request a hearing before an HHS Administrative Law Judge (ALJ), where it can contest the findings and the amount before the penalty becomes final. Reductions and settlements do happen, though the burden is on the provider to show OCR’s determination was unsupported.
Prevention is far cheaper than appeal, and training is central to it. HIPAA requires workforce training on privacy and security policies, both for new hires and periodically thereafter, with refreshers whenever policies or systems change. Beyond satisfying the rule, documented training is a recognized mitigating factor in how OCR calculates a penalty.
A practice that can show every staff member was trained, with records to prove it, is in a materially stronger position than one that cannot, both in avoiding violations and in arguing down a penalty if one is proposed.
What Does a HIPAA Violation Cost Beyond the Fine?
The fines and penalties for HIPAA violations are only the visible part of the cost. The real total comes mostly from what happens after the fine, not the fine itself. Corrective action plans, breach response, legal exposure, and lost trust routinely add up to several times the original penalty.
1. Corrective Action Plan (CAP)
Nearly every OCR settlement includes a CAP lasting 2 to 3 years, with mandated security upgrades, ongoing risk assessments, workforce retraining, and OCR monitoring throughout. The operational cost of a CAP frequently exceeds the fine itself.
2. Breach notification
Mailing letters, staffing a call center, and running the required notification process costs roughly $3 to $5 per affected individual. A breach affecting 100,000 people can cost $300,000 to $500,000 in notifications alone.
3. Forensic investigation
Bringing in outside experts to determine what happened and containing it typically runs $50,000 to $500,000 or more, depending on the scope of the breach.
4. Legal defense and litigation
Class-action lawsuits often stack on top of the regulatory penalty, and they can move fast. When Yale New Haven Health System’s 2025 breach exposed 5.6 million patient records, a consolidated class action combining 18 lawsuits settled for $18 million in just 7 months.
5. Technology and security remediation
Encryption upgrades, access controls, and monitoring tools mandated after a breach add real, ongoing cost. Refuah Health Center paid a $450,000 HIPAA fine and was separately required to invest $1.2 million in cybersecurity improvements before legal fees, notification costs, and lost revenue were even counted.
6. State-level penalties
State attorneys general can pursue their own fines on top of OCR’s, sometimes for the same incident, resulting in combined penalties that can dwarf the original OCR settlement.
7. Lost patients and referrals
Trust does not return quickly. Patients who fear future misuse of their data are less likely to schedule procedures, authorize information sharing, or use patient portals. Referral partners often tighten relationships or add contractual requirements after a breach becomes public.
8. Public listing
Large breaches land on HHS’s public breach portal, sometimes called the “wall of shame,” where journalists, competitors, and patients can see them indefinitely.
9. Insurance and contract friction
Cyber insurance carriers may raise premiums or reduce coverage after a claim. Payers and large employers can add new audit rights and indemnity clauses to future contracts.
Conclusion
Every HIPAA requirement ultimately serves one purpose: protecting the privacy and trust that patients place in your organization. While HIPAA violation fines and penalties often receive the most attention, it’s the long-term impact on patient care, operational stability, and your organizational reputation that matters most.
That is where the right technology partner helps. Bacancy’s healthcare IT services help you to build secure, scalable, HIPAA-compliant systems. From modernizing legacy applications to strengthening cybersecurity, we make sure compliance is built into how the technology works, rather than added on afterward.
Frequently Asked Questions (FAQs)
Does malpractice insurance cover HIPAA fines?
Usually not. Standard medical malpractice policies cover bodily-injury claims but not regulatory penalties. Coverage for fines and penalties for HIPAA violations, breach response, and defense costs typically requires a separate cyber liability or regulatory policy, and even those often exclude or limit civil money penalties. Providers should confirm exactly what their policy covers before an incident occurs.
Can a patient sue a provider directly for a HIPAA violation?
HIPAA contains no private right of action, so a patient cannot sue under HIPAA itself. However, patients frequently pursue the same conduct through state privacy laws, negligence claims, or breach-of-confidentiality suits, and large breaches often lead to class actions. A HIPAA violation can also serve as evidence of a standard-of-care failure in those state cases.
What happens if a staff member violates HIPAA without the practice knowing?
The practice can still be liable. OCR examines whether the organization had adequate safeguards, training, access controls, and monitoring in place. If those were missing, the staff member’s action can become the practice’s penalty even absent the employer’s knowledge, while the individual may separately face criminal charges if the conduct was knowing and intentional.
What is the maximum fine for a HIPAA violation?
The maximum HIPAA fine depends on the violation tier and the number of violations. Serious or willful neglect violations that remain uncorrected can result in penalties reaching millions of dollars through multiple violations or settlements. The final amount is determined by the severity of the incident and the enforcement action taken by the Office for Civil Rights (OCR).
Who can be fined for violating HIPAA?
Fines and penalties for HIPAA violations may apply to covered entities such as healthcare providers, health plans, and healthcare clearinghouses, as well as business associates that handle PHI on their behalf. Organizations are responsible for ensuring their employees, contractors, and third-party vendors follow HIPAA requirements.