HIPAA Violation Penalties

The page below is a sample from the LabCE course HIPAA Privacy and Security Rules. Access the complete course and earn ASCLS P.A.C.E.-approved continuing education credits by subscribing online.

Learn more about HIPAA Privacy and Security Rules (online CE course)
HIPAA Violation Penalties

There are four tiers of increasing penalty amounts that correspond to the levels of culpability associated with the HIPAA violation:
  1. (lowest category) Situations where the covered entity or business associate did not know and would not have known without exercising reasonable diligence
  2. Violations due to reasonable cause and not to willful neglect
  3. Violations due to willful neglect corrected within a specific period
  4. (highest category) Violations due to willful neglect that are not corrected
The civil penalty is determined by the HHS Secretary, who will investigate the complaint and decide how to handle the HIPAA violation. Within one year, the maximum violation penalty is $1.5 million USD for all violations of the same kind.

Categories of HIPAA violations and the associated financial penalties.