In February 2023, Banner Health agreed to pay $1.25 million to the Office for Civil Rights after a hacking incident exposed the electronic protected health information of nearly 3 million people. The breach itself was devastating. But the penalty came because OCR found systemic failures — no organization-wide risk analysis, no monitoring of health information systems. That's the pattern I see over and over. HIPAA fines and penalties rarely punish organizations for getting hacked. They punish organizations for not doing the basics before the hack happened.
If you're a compliance officer, practice manager, or IT lead at a covered entity or business associate, this post breaks down exactly how the penalty structure works in 2026, what triggers the biggest fines, and what you can actually do to stay off OCR's radar.
How HIPAA Fines and Penalties Actually Work
The penalty framework comes from the HITECH Act, later refined by HHS rulemaking. OCR — the enforcement arm of the Department of Health and Human Services — investigates complaints and reported breaches. When they find violations, they apply a four-tier penalty structure based on the level of culpability.
Here's how the tiers break down:
- Tier 1 — Lack of Knowledge: The covered entity didn't know and, by exercising reasonable diligence, wouldn't have known about the violation. Penalties range from $137 to $68,928 per violation.
- Tier 2 — Reasonable Cause: The violation was due to reasonable cause, not willful neglect. Penalties range from $1,379 to $68,928 per violation.
- Tier 3 — Willful Neglect (Corrected): The entity committed willful neglect but corrected the issue within 30 days. Penalties range from $13,785 to $68,928 per violation.
- Tier 4 — Willful Neglect (Not Corrected): Willful neglect with no timely correction. Minimum $68,928 per violation, up to $2,067,813 per violation category per year.
These amounts are adjusted annually for inflation. The numbers above reflect the 2024 adjustments published by HHS. The key takeaway: a single category of violation can stack to over $2 million per year. And OCR doesn't always stop at one category.
The Violations That Trigger the Largest Settlements
I've tracked OCR enforcement actions for years. The same failures show up in nearly every major settlement. If you want to understand where the real exposure is for your organization, study these patterns.
No Risk Analysis — the Universal Finding
If there's one violation that appears in virtually every significant OCR settlement, it's the failure to conduct an accurate and thorough risk analysis. The HIPAA Security Rule at 45 CFR Part 164, Subpart C requires it. Yet most organizations either skip it entirely, treat it as a one-time checkbox, or produce something so superficial it wouldn't survive a five-minute review.
When Premera Blue Cross settled with OCR for $6.85 million in 2020, the investigation found the company had failed to conduct a risk analysis sufficient to identify all vulnerabilities to ePHI. Nearly 10.5 million individuals were affected. The fine was enormous, but the root cause was mundane — nobody did a proper risk analysis.
Unauthorized Access to Patient Records
Snooping happens everywhere. Employees look up records of family members, celebrities, coworkers, ex-partners. Every time they do, that's a HIPAA violation — and if your organization hasn't trained staff and implemented access controls, it's your violation too.
In my experience, this is one of the most common and most preventable breach categories. If your workforce hasn't been trained on the boundaries of their access rights, fix that now. Our course Accessing Records: If It's Not Your Job, It's a Breach addresses this scenario directly and gives your staff the clarity they need to understand what legitimate access looks like.
Lack of Business Associate Agreements
Your cloud vendor, your shredding company, your billing service — if they touch PHI, they're business associates. And if you don't have a signed business associate agreement in place, you're exposed. OCR has pursued this repeatedly. It's a paper trail problem, and it's entirely avoidable.
What's the Difference Between a Fine and a Settlement?
This question comes up constantly, so let me be precise. Most of the large dollar amounts you see in the news are resolution agreements — essentially negotiated settlements between OCR and the entity. They include a monetary payment and a corrective action plan that OCR monitors for one to three years.
Civil monetary penalties (CMPs) are different. OCR imposes CMPs when an entity refuses to cooperate or settle. These can be appealed to an administrative law judge. They're rarer but they happen. In 2019, OCR imposed a $4.3 million CMP against MD Anderson Cancer Center for ePHI stored on unencrypted devices — though that penalty was later vacated on appeal.
Criminal penalties exist too, enforced by the Department of Justice rather than OCR. Individuals who knowingly obtain or disclose PHI can face fines up to $250,000 and imprisonment up to 10 years, depending on the intent.
OCR's Enforcement Priorities in 2026
OCR doesn't investigate randomly. They follow complaints and breach reports. Under the Breach Notification Rule, covered entities must report breaches affecting 500 or more individuals to OCR within 60 days. Every one of those reports can trigger an investigation.
Right now, I'm seeing OCR focus heavily on three areas:
- Hacking and IT incidents — these now represent the majority of large breaches reported to HHS.
- Right of Access failures — OCR has been running a targeted enforcement initiative since 2019, with over 45 enforcement actions to date for organizations that failed to provide patients timely access to their records.
- Lack of workforce training — when a breach happens and OCR asks for training records, silence is deadly. If you can't demonstrate that your staff received HIPAA training, OCR treats that as a systemic compliance failure.
If your training program is outdated or nonexistent, our HIPAA training catalog gives you role-specific courses that map directly to the areas OCR scrutinizes.
How to Reduce Your Organization's Exposure to HIPAA Penalties
I won't pretend compliance is simple. But after working with dozens of organizations through OCR investigations, I can tell you the ones that fare best share a few things in common.
Conduct a Real Risk Analysis — and Update It
Not a questionnaire you found online. A genuine, documented assessment of where your ePHI lives, how it moves, and what threats it faces. Update it annually and whenever your environment changes — new EHR, new office, new vendor. The HHS Security Risk Assessment guidance is a solid starting point.
Train Every Member of Your Workforce
HIPAA's definition of "workforce" is broader than you think. It includes employees, volunteers, trainees, and anyone under your direct control — even if they're not paid. Every one of them needs training. And you need to document it.
The training can't be generic. A front desk receptionist handles different PHI scenarios than a network administrator. Role-specific training is what OCR expects to see.
Implement and Enforce Access Controls
Minimum necessary access isn't optional — it's a core requirement of the Privacy Rule. Your staff should only access the PHI they need for their specific job function. Audit logs should be reviewed regularly. When someone accesses records they shouldn't, you need a process that catches it and responds.
Document Everything
Policies without documentation are just good intentions. OCR investigators ask for written policies, training records, risk analyses, incident response logs, BAAs. If you can't produce them, it doesn't matter how good your verbal explanation is. Paper wins.
Can Small Practices Really Face Large HIPAA Fines?
Yes. Unequivocally. In 2022, OCR settled with a solo dental practice in North Carolina for $50,000 after the practice disclosed PHI on a social media review page. In 2023, a small medical practice paid $80,000 for failing to provide a patient access to their records.
OCR has stated repeatedly that no covered entity is too small for enforcement. The Right of Access initiative alone has targeted solo practitioners, small clinics, and individual providers. The dollar amounts may be smaller than the multi-million-dollar settlements against hospital systems, but for a small practice, $50,000 can be existential.
The Real Cost Goes Beyond the Fine
Here's what the penalty amount doesn't capture: the corrective action plan. When OCR settles with your organization, the payment is just the beginning. You'll be under a monitored corrective action plan — typically two to three years — during which OCR reviews your policies, your training, your risk analyses, and your incident response. That monitoring costs time, attention, and money.
Then there's the reputational damage. Every resolution agreement is published on the HHS breach portal and enforcement page. Your patients, partners, and competitors will see it. The settlement amount becomes a permanent part of your organization's public record.
And if the breach was large enough to trigger state attorney general investigations — which happens more often than you'd expect — you may face additional state-level penalties on top of the federal enforcement.
What You Should Do This Week
If you've read this far, you already take compliance seriously. Here are three things you can do immediately to reduce your risk of HIPAA fines and penalties:
- Pull your most recent risk analysis. If it's older than 12 months or you can't find it, that's your first priority.
- Audit your training records. Can you prove every workforce member received HIPAA training this year? If not, close that gap now.
- Review your business associate agreements. Make a list of every vendor that touches PHI. Verify each one has a current, signed BAA.
The organizations that face the harshest penalties aren't the ones that experience breaches. They're the ones that can't demonstrate they tried to prevent them. The difference between a manageable OCR investigation and a seven-figure settlement almost always comes down to documentation, training, and follow-through.