HIPAA Violation Penalties and Fines: 2026 Enforcement Guide
HIPAA penalties range from $145 per violation for unknowing infractions to over $2.19 million annually for willful neglect, following the inflation adjustment that took effect on 28 January 2026. Understanding the penalty structure helps frame the ROI of compliance investment.
2026 Penalty Tiers (Inflation-Adjusted)
Amounts effective 28 January 2026, after HHS applied the OMB inflation multiplier (1.02598) to the prior figures. Per-violation amounts are the Federal Register statutory ranges, codified at 45 CFR 160.404 and adjusted annually for inflation by HHS notice; the annual caps shown are the lower per-tier limits OCR applies under its April 2019 Notice of Enforcement Discretion (the statutory cap for all tiers is $2,190,294).
| Tier | Culpability Level | Per Violation | Annual Cap |
|---|---|---|---|
| Tier 1 | Did not know (and could not have known) | $145 - $73,011 | $36,505 |
| Tier 2 | Reasonable cause (not willful neglect) | $1,461 - $73,011 | $146,053 |
| Tier 3 | Willful neglect, corrected within 30 days | $14,602 - $73,011 | $365,052 |
| Tier 4 | Willful neglect, not corrected | $73,011+ | $2,190,294 |
Criminal Penalties (DOJ Prosecution)
| Offense | Maximum Fine | Maximum Prison |
|---|---|---|
| Knowingly obtaining or disclosing PHI | $50,000 | 1 year |
| Under false pretenses | $100,000 | 5 years |
| For personal gain or malicious intent | $250,000 | 10 years |
Recent Enforcement Examples (2025-2026)
OCR's Risk Analysis Initiative is the dominant enforcement theme: nearly every 2025-2026 settlement turns on a missing or inadequate security risk analysis, usually surfaced by a ransomware or phishing breach. On 24 April 2026 alone OCR announced four ransomware resolutions totalling $1,165,000, each carrying a corrective action plan under two years of OCR monitoring. Amounts below are as published by OCR in its resolution agreements and civil money penalties record and the accompanying HHS press releases, checked July 2026.
Solara Medical Supplies (2025)
Risk analysis and risk-management failures plus improper breach notification after a phishing attack exposed the ePHI of 114,007 individuals.
$3,000,000
Warby Parker (2025)
Failure to conduct a HIPAA-compliant risk analysis; credential-stuffing attacks affected more than 198,000 individuals.
$1,500,000
Assured Imaging (2026)
Never conducted a risk analysis. Ransomware exposed the ePHI of 244,813 individuals, who were not notified within the required 60 days.
$375,000
Regional Women's Health Group / Axia (2026)
Risk Analysis Initiative settlement. Failure to conduct a comprehensive, accurate risk analysis after a ransomware attack affecting 37,989 individuals.
$320,000
Star Group Health Benefits Plan (2026)
Risk Analysis Initiative settlement. Failure to thoroughly assess risks and vulnerabilities to the ePHI of 9,316 individuals.
$245,000
Consociate Health (2026)
Network compromised via phishing six months before the ransomware was discovered, affecting approximately 136,539 individuals. No accurate, thorough risk analysis on file.
$225,000
MMG Fusion (2026)
A business associate breach affecting 15 million individuals settled for $10,000 in March 2026. The lesson is not that OCR treats scale lightly; it is that a resolution amount reflects what the entity can pay, so the settlement figure is a poor proxy for what the breach cost.
$10,000
Total Cost of a Healthcare Data Breach
The OCR settlement is rarely the largest number on the invoice. IBM's Cost of a Data Breach Report 2026 puts the average healthcare breach at $6.64 million, the highest of any industry it measures for the thirteenth year running and several times the size of a typical OCR resolution amount above. The gap between the two is everything the fine does not cover:
- Forensic investigation to establish what was accessed and when.
- Breach notification and credit monitoring for every affected individual, which is why the number of records drives the bill far more than the severity of the failure does.
- Legal defence and class-action exposure, which in healthcare frequently exceeds the regulatory penalty.
- Remediation: the controls you were supposed to have, bought under time pressure.
- Lost business, which IBM consistently identifies as one of the largest components.
- Cyber-insurance repricing at renewal.
We do not publish a dollar range against each of those lines. They vary by orders of magnitude with record count, attack type and litigation exposure, no primary source publishes them as a schedule, and a tidy table of invented ranges would only give false precision to a number IBM already measures directly. The $6.64 million average is the sourced figure; your own exposure is a function of how many records you hold.
State Attorney General Enforcement
State penalties stack on top of federal OCR penalties. Several states have enacted their own health privacy laws with additional enforcement mechanisms:
California
CCPA/CPRA
Up to $7,500 per violation
New York
SHIELD Act
Up to $5,000 per violation, $250K cap
Texas
HB 300
$5,000 - $250,000 per violation
Massachusetts
201 CMR 17.00
$5,000 per violation, $50K per incident