HIPAA violation fines range from $145 to $73,011 per violation, depending on the level of culpability, with annual caps adjusted periodically for inflation — reaching over $2.1 million for the most serious violations. A single enforcement action in 2024 resulted in a $4.75 million penalty against Montefiore Medical Center, exceeding the HHS Office for Civil Rights’ (OCR) total collections for all of 2023. Criminal penalties — including imprisonment of up to 10 years — apply for intentional violations. The most important thing healthcare organizations need to understand is that even small, seemingly preventable mistakes can trigger multi-million dollar consequences.


  • HIPAA civil penalties range from $145 to $73,011 per violation — adjusted annually for inflation using the OMB cost-of-living multiplier
  • Annual penalty caps reach over $2.1 million for willful neglect violations
  • Criminal penalties include fines up to $250,000 and imprisonment up to 10 years for intentional violations
  • OCR enforcement is accelerating — a single 2024 penalty exceeded all of 2023’s total collections
  • The most common causes of HIPAA fines are not sophisticated cyberattacks — they are preventable failures: missing encryption, paper policies never implemented, and missing BAAs
  • Social media HIPAA violations are a rapidly growing enforcement area — posting patient information online carries the same penalties as a data breach

Concerned about HIPAA compliance gaps? HIPAA Vault provides fully managed hosting with a signed BAA, U.S.-based private servers, and 24/7 security monitoring.

Schedule a free consultation →


HIPAA Penalty Tiers: The Four Categories

The HHS Office for Civil Rights (OCR) enforces the HIPAA Security Rule through through a four-tier civil penalty structure based on the level of culpability. Penalties are adjusted periodically for inflation — the figures below reflect current 2026 levels.

🔄 Rotate your phone for a better view of the comparison table.
Violation Category Description Per Violation Range Annual Cap
Tier 1: Lack of Knowledge The covered entity was unaware and could not have reasonably known $145–$73,011 $2,190,294
Tier 2: Reasonable Cause The violation was due to reasonable cause — not willful neglect $1,461–$73,011 $2,190,294
Tier 3: Willful Neglect — Corrected Willful neglect, corrected within 30 days of discovery $14,602–$73,011 $2,190,294
Tier 4: Willful Neglect — Not Corrected Willful neglect, not corrected within 30 days $73,011 $2,190,294

Penalty figures are adjusted using the OMB cost-of-living multiplier per the Federal Civil Penalties Inflation Adjustment Act. Figures reflect current 2026 inflation-adjusted levels.

Important: These are per-violation figures. If a single breach exposes thousands of patient records, each record may constitute a separate violation — multiplying penalties significantly.


Criminal HIPAA Penalties

In addition to civil penalties enforced by OCR, the Department of Justice (DOJ) can pursue criminal charges for intentional HIPAA violations:

OffenseMaximum FineMaximum Imprisonment
Unknowing violation$50,0001 year
Under false pretenses$100,0005 years
Malicious intent or personal gain$250,00010 years

Criminal prosecutions are relatively rare but increasing. The Montefiore Medical Center case (discussed below) involved an employee who intentionally copied and sold patient data — precisely the type of conduct that triggers criminal investigation.


Real-World HIPAA Penalty Cases: What Actually Goes Wrong

The most important insight from reviewing OCR enforcement history is that the largest fines don’t come from sophisticated nation-state cyberattacks. They come from preventable, often simple failures. As Gil Vidals, CTO and co-founder of HIPAA Vault, notes:

“The details are different obviously but they’re all kind of grouped together. It’s good to keep these things in mind — like what went wrong, how can we improve, what we’ve done better.”

Case 1: Montefiore Medical Center — $4.75 Million (2024)

The violation: A malicious insider — an employee — copied patient information including names and Social Security numbers and sold it for personal profit. The breach was first reported in 2015. A second incident involving unauthorized employee access to patient records occurred between 2018 and 2020.

The penalty: $4.75 million — the largest OCR financial penalty since 2021, and larger than OCR’s total HIPAA enforcement collections for all of 2023.

As Adam Zeineddine of the HIPAA Insider Show noted: “With this one penalty, the Office for Civil Rights has already exceeded its total collections from its HIPAA enforcement actions in 2023.”

Gil Vidals on the insider threat dimension:

“The most common breaches, of course, are from what we call a bad actor, a cyber attacker coming in from the outside. But this one was from an insider. An employee was collecting patient information, including names, social security numbers, personal identifiable information, and they were selling it. That’s kind of a bummer because these companies spend so much money protecting from an attacker from the outside, but we can’t forget the attack from the inside too.”

The lesson: HIPAA compliance requires not only external security controls but internal access controls, audit logging, and the ability to detect and investigate anomalous employee behavior. Even authorized employees can become threats.


Case 2: Feinstein Institute for Medical Research — $3.9 Million (2016)

The violation: A single unencrypted laptop was stolen from an employee’s car. The laptop contained approximately 13,000 patient records including names, dates of birth, diagnoses, and other sensitive health information.

The cause: The organization had already identified that employee laptops were unencrypted. They had a written policy requiring encryption. They simply had not implemented it.

Gil Vidals on this case:

“The organization had already identified that these laptops that these employees were carrying with them were unencrypted and they had a policy that said ‘hey, you have to encrypt all of that’ — but they hadn’t implemented the policy. This is an important point: the paper that healthcare organizations have — I call it ‘paper policies’ — policies that are not worth much more than just the paper they’re written on if they don’t implement it. In this case they had a policy but it didn’t protect them because they didn’t enforce that policy.”

The lesson: Paper policies without enforcement are not compliance. HIPAA requires not only written policies but documented evidence that they are being followed and tested.

Gil Vidals on how HIPAA Vault would have prevented this:

“If they were working with a cloud provider like HIPAA Vault, then that data would have stayed in the cloud. You wouldn’t need employees taking this data onto a laptop and processing it and leaving it on the laptop.”


Case 3: Anthem Inc. — $16 Million (2018)

The largest HIPAA settlement in history at the time. Anthem’s systems were breached by a sophisticated cyberattack that accessed nearly 79 million records. The investigation found Anthem had failed to conduct an enterprise-wide risk analysis, had insufficient controls to detect the intrusion, and failed to identify and respond to the threat in a timely manner.

The lesson: An Annual Security Risk Assessment is not optional. OCR specifically cited Anthem’s failure to conduct one as a primary violation.


Case 4: Warby Parker — $1.5 Million (2025)

The violation: A credential stuffing attack — where hackers used leaked passwords from other breaches to break into customer accounts — compromised the ePHI of 197,986 individuals. Exposed data included names, mailing addresses, email addresses, partial payment card information, and eyewear prescriptions.

OCR cited three violations:

  1. No adequate risk analysis — failure to identify vulnerabilities to ePHI across their systems
  2. Insufficient security measures — failure to reduce identified risks to a reasonable level
  3. No information system activity review — failure to implement audit log and access tracking procedures

Notable: This was a Civil Money Penalty (CMP), not a settlement. Warby Parker waived their right to a hearing and accepted the $1.5 million flat penalty. Because it was not an informal settlement, OCR could not legally compel a Corrective Action Plan — meaning no government-mandated remediation was required.

The lesson: Retail and direct-to-consumer healthcare brands handling vision prescriptions are covered entities subject to HIPAA enforcement. No organization handling PHI is exempt — regardless of industry sector. And even without a corrective action plan, $1.5 million in penalties demonstrates that enforcement is real.


Case 5: Solara Medical Supplies — $3 Million (2025)

The violation: Hackers gained access to eight employee email accounts through a phishing attack, compromising the ePHI of 114,007 individuals. A secondary incident exposed an additional 1,531 individuals when breach notification letters were mailed to wrong addresses. Exposed data included names, Social Security numbers, dates of birth, driver’s licenses, financial account numbers, billing claims, and medical diagnoses related to diabetes care.

OCR cited three violations:

  1. No compliant risk analysis — failure to conduct an accurate, enterprise-wide assessment of risks to ePHI
  2. Inadequate security measures — specifically lacking email protections, multi-factor authentication, and system monitoring
  3. Delayed breach notifications — failed to notify affected individuals, HHS, and media outlets within the required 60-day window

Unlike Warby Parker, this was an informal settlement requiring a two-year Corrective Action Plan. Solara must build a comprehensive ePHI application inventory, implement a risk management framework, rewrite security policies, and retrain their entire workforce.

The lesson: Phishing attacks succeed when MFA is absent and staff aren’t trained. A single phishing email that compromises eight employee accounts — combined with a botched breach notification — resulted in $3 million in penalties and two years of government oversight. Both failures were preventable.


Case 6: Social Media HIPAA Violations

An emerging and rapidly growing enforcement area. Healthcare employees posting patient information on social media — even without obvious identifiers — can trigger HIPAA violations. Common violations include:

  • Posting photos of patients without explicit written authorization
  • Discussing patient cases in identifiable ways on personal social media
  • Responding to negative patient reviews with clinical information
  • Sharing “funny” patient stories that could identify the individual

Social media violations follow the same penalty structure as any other HIPAA violation. The fact that the disclosure was on social media does not reduce the fine — in some cases, the public nature of the disclosure may increase penalties.


The Most Common Causes of HIPAA Violations

Based on HHS OCR enforcement data — updated through October 2024 — the most frequently cited causes of HIPAA violations are, in order of frequency:

CauseFrequency Rank
Impermissible uses and disclosures of PHI#1 Most Common
Lack of safeguards for PHI#2
Lack of patient access to their own PHI#3
Lack of administrative safeguards of ePHI#4
Use or disclosure of more than the minimum necessary PHI#5

Source: HHS OCR Enforcement Highlights — as of October 2024. HHS lists categories in order of frequency without publishing specific percentages.

The most actionable takeaway: Six of the top seven causes are preventable with proper policies, training, and technology — not sophisticated security expertise.


How OCR Investigates and Enforces HIPAA

OCR learns about potential violations through three channels:

1. Breach reports — covered entities are required to notify OCR of breaches affecting 500 or more individuals within 60 days per the HIPAA Breach Notification Rule. Breaches affecting fewer than 500 individuals must be reported annually.

2. Complaints — patients, employees, and others can file complaints with OCR. Any complaint triggers an investigation.

3. Compliance audits — OCR conducts periodic audits of covered entities and business associates, selected both randomly and based on risk factors.

During an investigation, OCR will request extensive documentation including risk assessments, policies and procedures, BAAs, training records, and incident documentation. Organizations have 10 days to respond to an OCR data request — with no exceptions.


How to Avoid HIPAA Violation Fines

The pattern across OCR enforcement cases is clear — most violations stem from a small set of preventable failures:

1. Conduct and document annual Security Risk Assessments The single most common OCR enforcement trigger. The HHS free SRA tool makes this accessible for organizations of any size.

2. Implement and enforce encryption Every device, server, and transmission pathway that handles ePHI must be encrypted — per NIST SP 800-111 guidance for data at rest and TLS 1.2+ for data in transit. “Paper policies” requiring encryption that aren’t enforced provide zero protection — as the Feinstein Institute case demonstrated.

3. Execute BAAs with every vendor that handles PHI Missing or inadequate BAAs are cited in 6% of enforcement actions — and make the covered entity fully liable for vendor breaches.

4. Implement access controls and audit logging The Montefiore case shows that internal threats require the same controls as external ones — role-based access, least-privilege principles, and tamper-evident audit logging.

5. Train staff — including on social media Employee behavior is the most common source of HIPAA violations. Annual training with documentation is required. Social media policies must be explicit.

6. Work with a HIPAA-compliant hosting provider As Gil Vidals notes, moving data to a HIPAA-compliant cloud environment eliminates entire categories of risk — including the stolen laptop scenario that cost Feinstein $3.9 million.


Don’t wait for an OCR investigation to find your compliance gaps.

Schedule a free risk assessment →


HIPAA Penetration Testing—Go Beyond Automated Scans

Validate your security with an objective, third-party audit. We simulate real cyberattacks to uncover vulnerabilities and provide a comprehensive compliance report.

Learn More

Frequently Asked Questions


This article draws on expert commentary from Gil Vidals, CTO and co-founder of HIPAA Vault, and Adam Zeineddine, host of the HIPAA Insider Show, from Episodes 42 and 94. Case study details are drawn from publicly available HHS OCR enforcement announcements. HIPAA Vault has provided managed HIPAA-compliant hosting for healthcare organizations since 1997 — nearly 30 years of healthcare-focused compliance expertise.


Legal Disclaimer: This article is provided for educational and informational purposes only and does not constitute legal advice. HIPAA regulations are complex and fact-specific — the information presented here should not be relied upon as a substitute for advice from a qualified HIPAA compliance attorney or healthcare regulatory specialist. Always consult a licensed attorney regarding your organization’s specific compliance obligations.