In 2018, a small Texas health system called MD Anderson Cancer Center lost three unencrypted devices containing patient records. The result? A $4.3 million penalty from the Office for Civil Rights. One stolen laptop. One lost thumb drive. Millions in fines. If you've ever wondered what is the penalty for a HIPAA violation, the answer isn't a single number — it's a tiered system that can range from a corrective action plan all the way to criminal prosecution and prison time.
I've spent years helping covered entities and business associates navigate this landscape. The penalty structure is more nuanced than most people realize, and the consequences extend far beyond the dollar amount on an OCR settlement letter. Let me walk you through exactly how it works.
The Four Penalty Tiers: What Is the Penalty for a HIPAA Violation?
HHS designed the HIPAA penalty structure with four tiers based on the level of culpability. Congress codified these tiers in the HITECH Act, and OCR applies them in every enforcement action. Here's exactly how they break down:
Tier 1: Did Not Know
The covered entity didn't know about the violation and couldn't have reasonably known. Penalties range from $137 to $68,928 per violation, with an annual maximum of approximately $2 million for identical violations. These amounts are adjusted annually for inflation by HHS.
Tier 2: Reasonable Cause
The organization should have known about the violation but didn't act with willful neglect. Fines range from $1,379 to $68,928 per violation, with a similar annual cap.
Tier 3: Willful Neglect, Corrected
The violation resulted from willful neglect, but the organization corrected it within 30 days of discovery. Penalties range from $13,785 to $68,928 per violation.
Tier 4: Willful Neglect, Not Corrected
This is where OCR drops the hammer. Willful neglect with no timely correction carries a minimum penalty of $68,928 per violation, with an annual maximum exceeding $2 million. And in practice, the total penalties can stack across multiple violation categories, pushing settlements well past that figure.
You can find the current penalty amounts on the HHS enforcement actions page.
Criminal Penalties: When Fines Aren't Enough
Most people focus on civil monetary penalties. But HIPAA also carries criminal penalties enforced by the Department of Justice, not OCR. These apply to individuals — not just organizations.
- Knowingly obtaining or disclosing PHI: Up to $50,000 and one year in prison.
- Offenses committed under false pretenses: Up to $100,000 and five years in prison.
- Offenses with intent to sell, transfer, or use PHI for personal gain or malicious harm: Up to $250,000 and ten years in prison.
These aren't theoretical. In 2020, a former hospital employee in Tennessee pled guilty to criminal HIPAA charges for accessing patient records without authorization. I've seen cases where staff members looked up celebrity medical records out of curiosity. That curiosity led to termination and federal prosecution.
Real Enforcement Actions That Should Keep You Up at Night
Abstract penalty tiers don't tell the full story. Real cases do. Here are enforcement actions pulled directly from OCR's public record:
Anthem Inc. — $16 Million (2018)
The largest HIPAA settlement in history. A cyberattack exposed the ePHI of nearly 79 million individuals. OCR found that Anthem failed to conduct an enterprise-wide risk analysis, failed to implement sufficient access controls, and lacked adequate monitoring. Sixteen million dollars and a corrective action plan that reshaped their entire security program.
Premera Blue Cross — $6.85 Million (2020)
A breach affecting over 10.4 million people. OCR's investigation revealed that Premera failed to conduct a risk analysis sufficient to identify vulnerabilities in its IT systems. The settlement included a two-year corrective action plan with extensive monitoring.
Banner Health — $1.25 Million (2023)
A hacking incident that compromised 2.81 million individuals' records. OCR cited failures including insufficient security monitoring and inadequate risk analysis. This case reminded the industry that even large, well-resourced health systems can fall short.
Every one of these cases shares a common thread: the organization either skipped or poorly executed a risk analysis. That's not coincidence. That's pattern.
State Attorneys General: The Penalty Multiplier Nobody Expects
Here's what catches many organizations off guard. The HITECH Act gave state attorneys general independent authority to bring HIPAA enforcement actions on behalf of their residents. This means you can face an OCR investigation and a state AG lawsuit simultaneously.
Indiana's attorney general secured a $1.4 million settlement with Medical Informatics Engineering in 2019 — on top of a separate $900,000 OCR settlement. Two enforcement actions for the same breach. Your organization could face the same double hit.
Several states have also enacted their own health privacy laws with penalties that stack on top of HIPAA fines. If you operate in multiple states, your exposure multiplies accordingly.
Beyond Fines: The Penalties Nobody Talks About
I've seen organizations fixate on the dollar amounts and completely miss the penalties that actually hurt the most.
Corrective Action Plans
Almost every major OCR settlement includes a multi-year corrective action plan (CAP). These are operationally brutal. They require you to overhaul policies, retrain your entire workforce, submit to external monitoring, and report regularly to OCR. A CAP can consume thousands of staff hours and cost as much as the fine itself.
Reputational Damage
OCR publishes every settlement on its public breach portal — sometimes called the "Wall of Shame." Your patients see it. Your competitors see it. Prospective business partners see it. The HHS Breach Portal is searchable by anyone, and breaches affecting 500 or more individuals stay on it permanently.
Litigation Costs
Class action lawsuits following a HIPAA breach routinely cost more than the OCR settlement. Anthem's $16 million OCR penalty was dwarfed by its $115 million class action settlement. The regulatory fine is often just the opening act.
What Triggers the Harshest Penalties?
After reviewing hundreds of OCR resolution agreements, I can tell you the factors that consistently push penalties to the top of the scale:
- No documented risk analysis. This is the single most cited deficiency in OCR investigations.
- Lack of workforce training. If your staff hasn't been trained on HIPAA requirements — and you can't prove it — OCR treats it as willful neglect.
- Slow or absent breach notification. The Breach Notification Rule requires notification to affected individuals within 60 days. Miss that window and you've added another violation category.
- No incident response plan. When a breach happens and your team doesn't know what to do in the first hour, the damage spirals. Our First 60 Minutes: Incident Response training exists precisely because I've seen this gap destroy organizations.
- Social media disclosures. Staff posting about patients online — even without names — can constitute a HIPAA violation. It happens more than you'd think, and our Social Media & PHI course addresses the exact scenarios that lead to enforcement actions.
How to Reduce Your Penalty Exposure Right Now
OCR has stated publicly that it considers an organization's compliance efforts when determining penalty amounts. Here's what moves the needle:
- Conduct and document a thorough risk analysis annually. Not a checkbox exercise — a real evaluation of where your ePHI lives, how it moves, and what threatens it.
- Train every member of your workforce. Not just clinicians. Front desk staff, IT contractors, billing teams — everyone who touches PHI. Document every session with dates and attendees.
- Build and test your incident response plan. Don't wait for a breach to find out your plan has gaps.
- Encrypt everything. Encryption is an addressable standard under the Security Rule, but failing to implement it without a documented reason is a red flag OCR loves to cite.
- Review your Business Associate Agreements. If a vendor handles PHI and you don't have a current BAA, you're already in violation.
Explore our full HIPAA training catalog to find courses tailored to the specific risks your workforce faces.
The Question That Matters More Than the Fine Amount
Everyone asks what is the penalty for a HIPAA violation. The smarter question is: what would it cost your organization to survive one?
Add up the OCR fine, the corrective action plan expenses, the legal fees, the class action exposure, the lost patients, and the reputational hit. For a small practice, a single Tier 3 or Tier 4 violation can mean closure. For a large health system, it means years of remediation under federal oversight.
The penalty structure exists to make non-compliance more expensive than compliance. In my experience, the organizations that treat HIPAA as a living, daily practice — not an annual checkbox — are the ones that never end up on OCR's Wall of Shame.
Your move.