Who Enforces HIPAA? Understanding Key Enforcement Agencies
HIPAA compliance forms the bedrock of patient trust in the healthcare system, establishing essential rules for safeguarding sensitive health...
A medical assistant forwards a chart to her personal Gmail so she can finish a prior auth after her kid's soccer game. Nobody meant any harm. That forward is an impermissible disclosure, and exactly the kind of thing an OCR investigator finds sitting in an email log two years later.
Most investigations begin with a patient complaint or a breach report your own compliance officer had to file. Any breach touching 500 or more people goes to HHS within 60 days, then onto a public federal list anyone can search. Reporters and plaintiff attorneys read that list.
HIPAA violation consequences stack. A federal fine, a corrective action plan you pay to run, state attorneys general who can charge you separately for the same incident, and patients who move their records down the street.
We published The Definitive Guide to HIPAA Violation Consequences in 2025. Every dollar figure in it changed on January 28, 2026, when HHS applied its inflation adjustment. This version carries the current numbers and the enforcement pattern sitting underneath them.
None of this is limited to hospitals. A four-provider family practice and a billing company that never sees a patient carry the same exposure. Business associates have been directly liable since 2009, and OCR keeps fining them.
One thing we'd tell any practice manager: risk analysis failure appears in almost every settlement OCR announced over the past two years. It's the first document investigators ask to see, and plenty of clinics can't produce a current one.
The law people worry about today is not really the law Congress passed in 1996. Two of its three letters stand for portability, which nobody thinks about anymore.
HIPAA started as a way to let workers keep health coverage between jobs. Privacy and security were secondary. Then records moved off paper and onto servers, and the secondary part swallowed the rest.
Congress passed the HITECH Act in 2009 to push clinics toward electronic health records. It also built the four-tier penalty structure OCR still uses, tightened breach notification deadlines, and raised the ceiling on fines. Regulators have been steadily raising that ceiling every year since.
Two groups carry the obligation. Covered entities are health plans, clearinghouses, and providers: your clinic, your dentist, the imaging center, the pharmacy on the corner.
Business associates are everyone you hire who touches protected health information. Billing companies, IT vendors, cloud storage, answering services, shredding companies, your malpractice attorney, the software running your appointment reminders.
HITECH made business associates directly answerable for their own failures. Your billing company can be fined without you being fined, and the reverse is also true.
MMG Fusion, a dental software vendor, settled with OCR in 2026 over a risk analysis failure, a breach notification failure, and an exposure touching the PHI of 15 million patients. Comstar, an ambulance billing company, paid $75,000 to OCR and then $515,000 to Massachusetts and Connecticut for the same underlying incident. One breach, three separate bills.
Most penalties for HIPAA violations are civil money penalties, which is the usual answer to what happens if you violate HIPAA. They run on a four-tier scale built around how much you knew and what you did about it.
HHS published its inflation adjustment in the Federal Register on January 28, 2026, applying the 1.02598 multiplier set by the Office of Management and Budget. These amounts apply to any penalty assessed on or after that date, even for older violations, as long as the conduct happened after November 2, 2015.
OCR civil penalty amounts, effective January 28, 2026
|
Tier |
What it means |
Minimum |
Maximum |
Annual limit |
|---|---|---|---|---|
|
Tier 1 |
Didn't know, couldn't reasonably have known |
$145 |
$73,011 |
$2,190,294 |
|
Tier 2 |
Reasonable cause, not willful neglect |
$1,461 |
$73,011 |
$2,190,294 |
|
Tier 3 |
Willful neglect, fixed within 30 days |
$14,602 |
$73,011 |
$2,190,294 |
|
Tier 4 |
Willful neglect, never fixed |
$73,011 |
$2,190,294 |
$2,190,294 |
One wrinkle matters if you're modeling worst-case exposure. Since April 2019, OCR has applied lower annual caps to the first three tiers under a notice of enforcement discretion. Adjusted for inflation, those working caps land near $36,506, $146,053, and $365,052. OCR can withdraw that notice whenever it likes, since it's policy rather than law.
Annual limits also apply per requirement, not per organization. Fail four separate Security Rule provisions, and you can collect four caps.
Picture a rural clinic that hires a local IT shop with no healthcare clients. Nobody there wipes an old server before decommissioning it, and the drive lands at a scrapyard with ePHI still on it. Staff at the clinic had no idea. That's Tier 1 territory, and it still costs money.
Tier 2 usually looks like a document nobody acted on. Your risk analysis flags aging software on networked devices, and IT marks it low priority because the budget is tight. Eight months later somebody walks in through that exact hole. OCR reads the analysis you wrote and asks why you ignored yourself.
Willful neglect means conscious or reckless disregard for the rules. One fact separates Tier 3 from Tier 4: whether you made a real correction within 30 days of finding the problem.
That window is worth memorizing, because it's the difference between a $73,011 ceiling and a $2,190,294 one on the same conduct. Warby Parker learned the expensive version in 2025, drawing a $1.5 million civil money penalty over risk analysis, risk management, and a failure to monitor systems holding ePHI.
Tiers set the range. Investigators pick the figure, and cooperation moves it more than most people expect.
Some conduct leaves OCR's hands entirely. Criminal cases go to the Department of Justice, and they land on individuals far more often than on organizations.
Criminal exposure scales with why the person did it. Curiosity sits at the bottom. Profit sits at the top.
Criminal penalties under HIPAA, by conduct
|
Conduct |
Maximum fine |
Maximum prison term |
|---|---|---|
|
Knowingly obtaining or disclosing PHI |
$50,000 |
1 year |
|
Obtaining PHI under false pretenses |
$100,000 |
5 years |
|
Taking PHI to sell, transfer, or cause harm |
$250,000 |
10 years |
Prison time isn't hypothetical. A former receptionist at a New York dental practice received 2 to 6 years for stealing PHI. A patient care coordinator at UPMC got a year. A Florida clinic worker drew 48 months over theft of patient data tied to wire fraud.
None of those people ran an IT department. They had legitimate logins and used them for something else.
OCR refers cases to DOJ when the facts suggest someone knowingly misused access. Snooping on an ex-partner's chart qualifies. So does calling a records department while impersonating a physician to pull files you have no right to.
Most organizations survive these cases with a settlement. For the employee, a conviction usually ends the career, and the practice still absorbs the breach notification, the investigation, and the civil exposure that follows.
Ask anyone who's been through an OCR investigation what it cost, and the settlement figure is rarely the number they quote you.
OCR settlements almost always come bundled with a corrective action plan. A CAP is enforceable, and it puts a federal agency inside your operations for years.
Practices routinely spend more on the plan than on the penalty itself, mostly in consultant hours and staff time nobody had spare.
A federal settlement doesn't close the matter. State AGs hold their own authority under HITECH, and they often prefer state consumer protection and data security laws because those cases are easier to win.
Blackbaud paid $49.5 million across 49 states and DC after one breach. Comstar's incident produced an OCR settlement and a $515,000 multistate action. Budget for the possibility of both.
Manasa Health Center paid $30,000 after responding to negative Google reviews with details about the patients who wrote them. That is a front desk decision made in about ninety seconds, on a Tuesday, by someone trying to defend the practice.
Cadia Healthcare paid $182,000 over a social media disclosure and a breach notification failure. Yakima Valley Memorial paid $240,000 after 23 hospital security guards browsed the records of 419 patients. No hacker was involved in any of them.
Reputation damage follows the same path. Patients read the news coverage, the one-star reviews stay indexed, and referral partners start treating you as a liability.
HIPAA gives patients no private right to sue, which stops nothing. Class actions arrive under state law instead, built on negligence and breach of implied contract, and the defense costs land whether you win or lose.
State licensing boards run their own track. A nurse or therapist named in a breach of confidentiality can face suspension separate from anything OCR does.
The quietest cost is turnover. New restrictions land on the same staff who were already short-handed, blame circulates, and your best front desk person takes a job at the practice down the road.
Understanding the penalties for non-compliance with HIPAA is the easy part. Preventing them comes down to four things, and one of them does most of the work.
Read OCR's settlement announcements from the past two years, and the same phrase keeps appearing. Risk analysis failure was cited in every enforcement action OCR announced in 2026 and in most of the 2025 actions.
OCR settlements announced in 2026
|
Organization |
Amount |
Cited failure |
|---|---|---|
|
Spencer Gifts benefit plans |
$450,000 |
Risk analysis; missing HIPAA policies |
|
Assured Imaging |
$375,000 |
Risk analysis; ePHI of 244,813 people |
|
Axia Women's Health |
$320,000 |
Risk analysis |
|
Star Group health plan |
$245,000 |
Risk analysis; ePHI of 9,316 people |
|
Top of the World Ranch |
$103,000 |
Risk analysis |
A security risk analysis is not a form you file once. It's a running inventory of where PHI lives, what could reach it, and what you did about each gap. Undated or missing, it becomes the first thing an investigator writes down.
Those 23 security guards at Yakima Valley had working credentials. Access control failures rarely involve broken systems; they involve permissions nobody revisited after somebody changed roles.
Audit who can see what, twice a year. Kill logins the day someone leaves, not the following month. And check that your EHR is actually writing access logs somewhere a person reviews.
Staff will text patients. They'll do it from personal phones if you don't give them something better, and those threads sit outside every safeguard you've built.
A compliant channel needs three things: encryption, a signed BAA with the vendor, and an audit trail tying each message to a user. Curogram provides all three for two-way patient texting, and messages stay attached to the chart in your EHR rather than living on a staff member's iPhone. That also gives you something to hand an investigator.
Missing business associate agreements show up in OCR findings year after year. Signing one takes an afternoon and a signature from each side.
Keep a current list of every vendor with PHI access, the date each BAA was signed, and who owns the relationship internally. Then ask what those vendors do for security, because their breach becomes your breach notification.

Consequences of non-compliance with HIPAA scale with what you knew and how fast you moved after you knew it.
Most practices reading this won't face a criminal charge or a seven-figure penalty. They'll face a complaint, an investigation, and a set of questions about a risk analysis that either exists or doesn't. OCR resolves the majority of its cases with technical assistance rather than a fine.
Your own records answer most of those questions before you do. Meeting minutes showing a flagged risk you deferred can move a case from Tier 1 to Tier 2. Attach a remediation log to a dated risk analysis, and you've handed the investigator your cheapest defense.
That 30-day correction window changes your exposure more than anything else on this list. Finding a problem and fixing it inside a month keeps a willful neglect finding capped at $73,011 rather than $2,190,294. The clock starts on discovery, not on the day you finish deciding who to tell.
Get the analysis current, tighten access, and move patient texting onto a channel with a BAA behind it. Those three moves address most of what OCR actually charges people for.
If you do one thing this quarter, pull up your risk analysis and check the date on it. Every OCR settlement announced in 2026 cited that document.
Curogram connects with your EHR and keeps patient messaging encrypted, logged, and covered by a signed BAA. Book a demo and we'll walk through your current workflow.
It depends entirely on culpability. A Tier 1 violation starts at $145, while Tier 4 willful neglect that goes uncorrected runs from $73,011 to $2,190,294. Annual limits apply per requirement violated, so a finding across four Security Rule provisions can produce four separate caps. Most real cases resolve as settlements well below the ceilings.
The Security Rule requires an accurate, current assessment of risks to electronic PHI, and it's the first document OCR asks for. When investigators find one that's missing, years old, or limited to a single system, everything else in the file looks weaker.
OCR has also run a formal risk analysis enforcement initiative and confirmed it will extend that focus to risk management in 2026. It's the cheapest failure to fix and the most commonly cited.
Accidental disclosures still count, though intent shapes the outcome heavily. Genuine mistakes usually land in Tier 1 or Tier 2, where penalties are lower, and OCR often resolves matters through technical assistance instead of a fine.
What turns a small incident into a large one is failing to notify, failing to document, or ignoring a problem you already identified. Correcting the issue within 30 days matters more than almost anything else you do afterward.
Investigators look at what the organization knew and when it knew it. No knowledge with reasonable diligence puts you in Tier 1, while awareness without adequate action puts you in Tier 2.
Conscious or reckless disregard moves the case into willful neglect, and the 30-day correction window separates Tier 3 from Tier 4. Your own documentation, including risk analyses and meeting minutes, is often what establishes the tier.
HITECH gave state attorneys general independent authority to pursue HIPAA violations, and most states also have data security and consumer protection laws that apply to the same breach. Those state cases are frequently easier to win and can carry their own penalties.
Comstar settled with OCR and then paid $515,000 to Massachusetts and Connecticut over one incident. Multistate actions can reach much further, as Blackbaud's $49.5 million settlement across 49 states showed.
HIPAA compliance forms the bedrock of patient trust in the healthcare system, establishing essential rules for safeguarding sensitive health...
💡 HIPAA compliance for conversational AI means applying the Security Rule's administrative, physical, and technical safeguards to any chatbot,...
💡EMR integration is a compliance lifesaver because it eliminates double entry, centralizes communication, and ensures every patient interaction is...