NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new →
HIPAA Fines and Penalties: What OCR Really Charges
Learn

HIPAA Fines and Penalties: What OCR Really Charges

·Alexander Sverdlov

HIPAA civil money penalties come in four tiers set by how culpable you were, from not knowing about a violation to willful neglect you did not correct within 30 days. Since 28 January 2026 the regulation allows $145 to $73,011 per violation in the lowest tier and $73,011 to $2,190,294 in the highest, with $2,190,294 as the regulatory ceiling for identical violations in a calendar year. In practice HHS applies lower yearly caps of $25,000, $100,000, $250,000 and $1,500,000 per tier, under a 2019 notice of enforcement discretion it still cited in its 2024 penalty against Warby Parker. Criminal penalties are separate: up to $250,000 and ten years in prison.

The number that surprises people is not the maximum. It is how the count works. A missing risk analysis is not one violation. It is one violation for every day it stays missing, and HHS can look back six years. This guide sets out the tiers with the current amounts, explains the caps OCR actually uses, rebuilds the Warby Parker penalty line by line, and ends with a table to work out your own exposure. If you are not yet sure HIPAA reaches you, start with covered entities and business associates.

TierCulpabilityPer violation, since 28 Jan 2026Yearly cap in the regulationYearly cap in the 2019 notice
1Did not know and, with reasonable diligence, would not have known$145 to $73,011$2,190,294$25,000
2Reasonable cause, not willful neglect$1,461 to $73,011$2,190,294$100,000
3Willful neglect, corrected within 30 days$14,602 to $73,011$2,190,294$250,000
4Willful neglect, not corrected within 30 days$73,011 to $2,190,294$2,190,294$1,500,000

Amounts are from the table at 45 CFR 102.3 for violations on or after 18 February 2009. The 2019 caps are the figures printed in the notice; HHS said it would apply them as adjusted for inflation.

What are the HIPAA penalty tiers?

The tiers come from the HITECH Act and sit in 45 CFR 160.404. The tier is decided by culpability, not by the size of the breach. Tier 1 covers a violation the covered entity or business associate did not know about and, by exercising reasonable diligence, would not have known about. Tier 2 is reasonable cause and not willful neglect: you knew, or should have known, but did not act with willful neglect. Tiers 3 and 4 are both willful neglect, split by whether you corrected it within 30 days of when you knew or should have known.

The dollar figures in 160.404 itself are the original ones: $100, $1,000, $10,000 and $50,000 as minimums, $50,000 as the per violation maximum for the first three tiers, and $1,500,000 for identical violations in a calendar year. The same section says the amounts are adjusted for inflation every year and published at 45 CFR part 102. The latest adjustment was published on 28 January 2026, applies to penalties assessed on or after that date, and used a multiplier of 1.02598, the change in the October consumer price index from 2023 to 2024. That is why figures of $141, $71,162 and $2,134,831, still printed on many pages, are out of date: they are the 2024 amounts.

Minimum HIPAA civil penalty per violation from 28 January 2026: $145 in tier 1, $1,461 in tier 2, $14,602 in tier 3 and $73,011 in tier 4

Why are the yearly caps lower than the regulation says?

Because of how HHS reads the HITECH Act. When it implemented the HITECH Act in 2009, HHS treated the statute's penalty provisions as conflicting and adopted $1.5 million as the yearly limit for identical violations in every tier. On 30 April 2019 it published a Notification of Enforcement Discretion that adopted a different cumulative yearly limit for each tier: $25,000, $100,000, $250,000 and $1,500,000. In its words: "HHS will use this penalty tier structure, as adjusted for inflation, until further notice." It also said it expected future rulemaking to revise the tiers in the regulation. As of the January 2026 adjustment, the regulation still carries the single ceiling.

The notice is still in use. OCR's September 2024 notice of proposed determination against Warby Parker lists the four tiers with the 2019 limits and states in a footnote that "The CMPs reflect the penalty tiers described in the Notification of Enforcement Discretion (April 30, 2019)". A notice of discretion is not a rule, and HHS can withdraw it. Budget against the 2019 caps, but know they are a policy choice, not a statutory floor.

Yearly caps for identical violations under the 2019 Notification of Enforcement Discretion: $25,000 in tier 1, $100,000 in tier 2, $250,000 in tier 3 and $1,500,000 in tier 4

How does one missing control become a seven figure penalty?

Two rules in subpart D do the work. Under 45 CFR 160.406, "in the case of continuing violation of a provision, a separate violation occurs each day" the entity is in violation. Under 160.414, HHS has six years from the date of the violation to start an action. A control that never existed is therefore a daily violation, every day, inside a six year window, and the yearly cap is reached quickly.

Warby Parker shows the arithmetic. OCR found three Security Rule violations, all in the reasonable cause tier: no accurate and thorough risk analysis, security measures not sufficient to reduce risks to a reasonable and appropriate level until 29 July 2022, and no procedure to regularly review records of information system activity until 12 May 2020. For each, OCR counted days at $1,424, the tier 2 minimum then in force. Ninety days in late 2018 alone came to $128,160 for the risk analysis, capped at $100,000. Seven capped calendar years made $700,000; risk management added $500,000 for five years; activity review $300,000 for three. Warby Parker waived its right to a hearing, and in December 2024 OCR imposed $1,500,000. The breach behind it was credential stuffing against customer accounts, affecting 197,986 people.

How OCR built the Warby Parker penalty: $700,000 for the risk analysis over seven calendar years, $500,000 for risk management over five, $300,000 for activity review over three, $1,500,000 imposed in December 2024

Note what was not counted: the number of people affected did not multiply anything. The count came from duration. The fastest way to cut exposure is to close a gap, because every day it stays open is another violation. The duty that most often starts the count is the one covered in our guide to the HIPAA risk assessment.

What decides where in the range a penalty lands?

Section 160.408 lists the factors HHS weighs, each of which can mitigate or aggravate: the nature and extent of the violation, including the number of individuals affected and how long it lasted; the harm, physical, financial, reputational or to someone's ability to obtain health care; your history of compliance, including how you responded to earlier complaints and technical assistance; your financial condition and size; and "such other matters as justice may require".

Three more provisions matter. Under 160.410(c), HHS may not impose a penalty if you establish that the violation was not due to willful neglect and was corrected within 30 days of when you knew or should have known, or within a longer period HHS allows. Under 160.412, HHS may waive a penalty in whole or in part where it would be excessive relative to the violation. And since a 2021 amendment, 42 U.S.C. 17941 requires HHS to consider whether you had "recognized security practices" in place for not less than the previous 12 months when deciding fines. It cannot raise a fine for lacking them.

How does OCR get from a breach report to a penalty?

Most investigations start with a breach report or a complaint. The Warby Parker timeline shows the formal route: breach report in December 2018, a letter of opportunity in May 2024 inviting written evidence of affirmative defenses, a notice of proposed determination in September 2024, a waived hearing, and a final determination in December 2024. An entity that contests the proposed determination can request a hearing before an administrative law judge, in writing, within 90 days of receiving it (45 CFR 160.504).

Most cases never get that far. OCR's resolution agreements page lists far more settlements than civil money penalties. A settlement is a resolution agreement, usually with a corrective action plan; a civil money penalty is imposed by OCR. Both appear in the press as fines, and they should not be compared as if they were the same thing.

From breach report to civil money penalty, as in the Warby Parker case: breach report, OCR investigation, letter of opportunity, notice of proposed determination, notice of final determination
EntityTypeAmountAnnouncedWhat it concerned
AnthemSettlement$16,000,000October 2018What HHS called the largest health data breach in history; a record settlement at the time
Solara Medical SuppliesSettlement$3,000,000January 2025Phishing
Warby ParkerCivil money penalty$1,500,000February 2025Credential stuffing; risk analysis, risk management, activity review
Gulf Coast Pain ConsultantsCivil money penalty$1.19 millionDecember 2024Security Rule violations
Children's Hospital ColoradoCivil money penalty$548,265December 2024Privacy and Security Rule violations
Oregon Health & Science UniversityCivil money penalty$200,000March 2025Timely patient access to records
Northeast Surgical GroupSettlement$10,000January 2025Ransomware

All amounts and dates are from HHS announcements listed on its resolution agreements page.

What are the criminal penalties for HIPAA violations?

Criminal liability is in a separate statute, 42 U.S.C. 1320d-6. It applies to a person who knowingly, and in violation of HIPAA, uses a unique health identifier or obtains or discloses individually identifiable health information. A 2009 amendment made clear this includes an employee or other individual who obtains or discloses information held by a covered entity without authorization. There are three levels: a fine of up to $50,000, up to one year in prison, or both; up to $100,000 and five years if committed under false pretenses; and up to $250,000 and ten years if committed with intent to sell, transfer or use the information for commercial advantage, personal gain or malicious harm. These amounts are fixed in the statute, not inflation adjusted. If a criminal penalty has been imposed for an act, HHS may not also impose a civil money penalty for it (160.410(a)(2)).

State attorneys general can sue too. Under 42 U.S.C. 1320d-5(d) a state attorney general may bring a civil action on behalf of residents for an injunction or damages of up to $100 per violation, capped at $25,000 a year for identical violations, plus costs and attorney fees, with notice to HHS.

Criminal HIPAA penalties under 42 U.S.C. 1320d-6, up to one, five or ten years in prison with fines up to $50,000, $100,000 or $250,000, and the $25,000 yearly cap on state attorney general damages

What the other results get wrong

Page one for this query is mostly compliance vendors and training sites. Four errors recur. The first is stale figures: $141 to $71,162 and a $2,134,831 cap are the 2024 amounts, replaced on 28 January 2026. The second is presenting the regulation's single yearly ceiling as what OCR applies, without the 2019 notice that lowers it for three of the four tiers. The third is describing penalties as per incident or per breach. They are per violation, and a continuing violation is a new one every day. The fourth is adding settlements and civil money penalties together as if both were fines OCR imposed.

Work out your own exposure

Answer these before you estimate anything. Each row moves the number more than the headline maximum does.

QuestionYour answerWhy it matters
Are you a covered entity, a business associate, or both?Both can be penalised under 160.404.
Do you have a current, enterprise wide risk analysis?Missing it is a daily violation from the day it should have existed.
Which required safeguards are missing today, and since when?Each gap is counted by days, inside a six year window.
Would a gap read as reasonable cause or willful neglect?Tier 2 caps at $100,000 a year in the 2019 notice; tier 4 at $1,500,000.
Could you correct each gap within 30 days of finding it?Correction within 30 days, without willful neglect, is an affirmative defense.
Can you show recognized security practices for the last 12 months?HHS must consider them when deciding fines.
Venvera HIPAA gap assessment page showing a completed initial assessment at 62 percent, with the number of questions answered and the option to start a new assessment

Venvera's HIPAA module keeps the risk analysis as a living register, records the decision on each addressable specification, and dates every safeguard's evidence, so you can see which gaps are open and since when. Start with the free HIPAA risk assessment template or take the free compliance check. Venvera is not a law firm; for a live investigation, talk to counsel. How another regime builds its fines is in our guide to GDPR fines and penalties.

The bottom line on HIPAA penalties: a missing control is a violation every day it stays missing

Frequently asked questions

What is the maximum HIPAA fine?

Under the regulation, $2,190,294 per violation in tier 4 and the same amount for identical violations in a calendar year, for penalties assessed since 28 January 2026. Separate requirements each carry their own yearly limit, which is how penalties above that figure arise. Criminal fines go up to $250,000 per offense.

Are business associates fined directly?

Yes. Section 160.404 applies to a covered entity or business associate, and the Warby Parker notice uses the same wording.

How far back can OCR go?

Six years from the date of the violation, under 45 CFR 160.414. In Warby Parker, OCR began its calculations six years before the date of its proposed determination.

Primary sources

Penalty amounts are from 45 CFR 102.3 as amended by the January 2026 inflation adjustment. Tiers, counting, factors, defenses, waiver and the six year limit are from 45 CFR part 160, subpart D. The yearly caps are from the 2019 Notification of Enforcement Discretion. The Warby Parker figures are from OCR's notice of proposed determination and announcement; the other cases from HHS's resolution agreements page. Criminal penalties are from 42 U.S.C. 1320d-6, state actions from 42 U.S.C. 1320d-5(d) and recognized security practices from 42 U.S.C. 17941.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander →

CONTINUE READING