Call Us Today! 877-659-2467

What are the Consequences of Non-Compliance?

How HIPAA Penalties are Calculated

HIPAA penalties (enforced by the HHS Office for Civil Rights) follow this structure:

  • Per violation: Each instance of noncompliance with a specific HIPAA requirement (Privacy, Security, or Breach Notification Rule) counts as a separate violation.
  • Per day: If a violation persists (e.g., failure to have required security safeguards, ongoing improper disclosure practices, or uncorrected risks), each day of continued noncompliance can be counted as a separate violation. This allows penalties to accumulate quickly for prolonged issues.
  • Per affected individual: For violations like impermissible uses or disclosures of protected health information (PHI), OCR can treat each individual whose PHI is involved as a separate violation.
  • Annual cap per identical provision: There is a calendar-year limit on the total penalty for all violations of the same requirement or prohibition. This cap applies separately to each distinct HIPAA provision violated.

When an investigation is opened, the OCR reviews ALL compliance documentation, not just the complaint or cause.

A $145 fine can easily become over a million dollar penalty

CompliantHIPAA ViolationFine#DaysStatutory Max/YrTotal Amt of Fine Levied
Complaint filedPatient denied access
to Designated Record Set
$145300$43,500$43,500
Found by OCRNo HIPAA risk analysis within 4
years
$1454 Years$52,925$211,700
Found by OCRHIPAA training documentation
was not available
$1454 Years$52,925$211,700
Found by OCRIncomplete Administrative, Physical, and
Technical Safeguard policies and procedures
$1456 Years$52,925$317,550
Found by OCRInadequate employee training on policies and procedures$1456 Years$52,925$317,550
Found by OCRInadequate technical safeguards to protect ePHI.$1456 Years$52,925$317,550
Total Penalty$1,419,450

Aris protects their clients through Partnership, Education, and Support.

©2026 Aris Medical Solutions – HIPAA Risk Management | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC