With healthcare data breaches on the rise, keeping your compliance posture up to date is more important than ever. HIPAA violations can lead to hefty fines, ranging from $145 to more than $2 million annually, and even criminal charges with up to 10 years in prison.
The Office for Civil Rights (OCR) enforces compliance through audits and investigations, penalizing violations such as unauthorized access to protected health information (PHI), lack of encryption and delayed breach notifications. Here's how to protect your organization from HIPAA penalties, fines and common, costly violations.
Take a look at the following numbers related to HIPAA violations as of October 31, 2024, as reported by the HHS:
HIPAA violation fines and penalties result from noncompliance with HIPAA rules. They can result in civil and criminal penalties, depending on the type and severity of the violation. Fines for HIPAA violations range from minimum to maximum amounts and have a calendar-year cap of $2,190,294 for multiple violations of the same HIPAA provision.
The Department of Health and Human Services (HHS) and OCR enforce HIPAA through regular audits and investigations after a complaint or breach. Since the Enforcement Final Rule of 2006, OCR can issue financial penalties and require corrective action plans and resolution agreements to help the covered entity achieve HIPAA compliance. The state attorneys general can also issue HIPAA violation fines and penalties.
OCR typically prefers to resolve violations through non-punitive measures, such as voluntary compliance and corrective action plans. However, when fines for HIPAA violations are necessary, OCR follows a tiered penalty structure to assess the severity of the violation and impose a proportional penalty.
Any person or entity that handles protected health information (PHI) must comply with HIPAA rules, including:
What are the consequences of violating HIPAA? They depend on the type and severity of the violation: civil and criminal. Each category has graded tiers to determine penalties for HIPAA violations.
OCR assesses a case and the covered entity’s liability based on four tiers of increasing culpability. Each tier has minimum and maximum penalty amounts and an annual cap on penalties for multiple violations of the same provision. The following list of HIPAA fines is based on the most recent numbers released in January 2024 and is adjusted for inflation.
Tier 1: Lack of knowledge
The covered entity or business associate was unaware and, through due diligence, could not have known that the HIPAA rule was violated.
Tier 2: Reasonable cause and not willful neglect
The covered entity knew or should have known through due diligence that its action (or omission) violated HIPAA, but the violation was not caused by willful neglect.
Tier 3: Willful neglect, corrected within 30 days
The violation resulted from willful neglect, but the covered entity took corrective action within 30 days.
Tier 4: Willful neglect, not corrected within 30 days
The violation of HIPAA rules constituted willful neglect, and the entity made no attempt to correct the violation within 30 days.
Employers usually receive civil penalties for violations committed by their employees in health care. But not always. If healthcare professionals knowingly misuse or unlawfully obtain PHI, they are held criminally liable.
The Department of Justice (DOJ), not the OCR, handles criminal penalties for HIPAA violations. Criminal penalties can range from fines to jail time, depending on severity. A judge determines the penalties based on three categories of criminal violations.
Tier 1: Wrongful disclosure of PHI
This tier is the lowest-level violation. It covers cases of reasonable cause, in which the individual should have known better, and lack of knowledge, where the individual didn’t know they violated a rule. The DOJ doesn’t acknowledge ignorance of HIPAA regulations as an excuse for violating HIPAA rules because all covered entities are responsible for compliance.
Maximum penalty: Up to $50,000, up to one year in prison, or both.
Tier 2: Wrongful disclosure of PHI under false pretenses
This tier includes obtaining PHI under false pretenses or disclosing it without permission. For example, a hospital employee cannot access the records of patients who aren’t under their care.
Maximum penalty: Up to $100,000, up to five years of prison time, or both.
Tier 3: Wrongful disclosure of PHI under false pretenses with malicious intent
The most severe violation is when the individual who commits the crime wrongfully obtains PHI with the intent to sell, transfer, or use the data for personal gain, commercial advantage, or malicious harm.
Maximum penalty: Up to $250,000, ten years of prison time, or both.
Financial penalties most commonly result from the following HIPAA violations:
HIPAA compliance is based mostly on properly securing private data, especially with cyberattacks at an all-time high. Health care organizations, in particular, have massive amounts of data, making them a target for many bad actors. While a breach can reveal HIPAA violations, it’s not considered a violation on its own.
As a goal, compliance reduces the risk of a breach to acceptable levels through due diligence. OCR assesses the nature of a breach and investigates possible weaknesses from noncompliance.
HIPAA violations come in an array of types. Let’s take a look at a few of the main ones.
Intentional versus accidental
Not all violations are intentional. Even otherwise-compliant organizations make mistakes, such as accidentally disclosing PHI to the wrong person or persons. In this case, the person or persons who discover the violation must report it to the organization’s privacy officer. The privacy officer then evaluates the situation to determine the scope of the breach and actions needed to reduce risk and prevent future harm.
Depending on the nature of the violation, the organization might be required to report it to OCR. Failure to report a violation can result in penalties.
When assessing the violation, OCR determines the severity based on the tier system. The civil penalty for unknowingly violating HIPAA falls under Tier 1. But accidental disclosures may fall into other tiers depending on the circumstances.
Accidental violations include:
Accidental HIPAA violations can still result in civil penalties, even if there was no malicious intent. The severity of the penalty depends on the level of negligence:
If the violation is corrected within 30 days, penalties may be reduced. Failing to address the issue quickly can escalate the violation to willful neglect, increasing penalties.
Additionally, repeated accidental violations can trigger compliance audits, corrective action plans, reputational damage, and potential lawsuits. To prevent accidental HIPAA violations, organizations must train employees, monitor access to PHI, encrypt sensitive data, and enforce least-privilege access controls.
Knowledge of HIPAA guidelines
Some violations occur with knowledge that HIPAA guidelines are being broken. These violations range in severity, depending on the intent of the individual or entity. Common examples of this type of violation include:
A recent case that was resolved in 2021 involved Jennifer Lynne Bacor, a patient care technician at a Cedar Rapids hospital. She used her login credentials to access her ex-boyfriend’s PHI multiple times, even though he wasn’t one of her patients after he was treated at the hospital on various occasions.
Upon accessing his information, Bacor took a picture of a medical photograph and then shared it with a third party. The third party shared the photo with the ex-boyfriend and others in a Facebook message along with “taunting language and emojis.”
Bacor was sentenced to five years of probation and fined $1,000 as punishment for violating HIPAA and weaponizing her boyfriend’s private medical information. Bacor was also restricted from any employment that would grant her access to private medical information during her probationary period.
Criminal HIPAA violations
Violating HIPAA can result in criminal penalties, depending on the severity and intent of the breach. Criminal violations typically involve accessing patient records for personal gain or commercial advantage or sharing PHI with the intent to do harm. For example, they might involve taking social security numbers and birth dates to commit identity fraud. Criminal penalties are less common than civil monetary damages for HIPAA violations.
For example, in 2019, the DOJ charged a former patient coordinator, Linda Sue Kalina, with wrongfully disclosing another individual's health information. During her employment, Kalina improperly accessed 111 patient records. She “unlawfully disclosed personal gynecological health information related to two such patients, with intent to cause those individuals embarrassment and mental distress.” Kalina was sentenced to one year of imprisonment, followed by three years of supervised release.
Theft of patient information
Lost or stolen patient information can occur when an employee accesses and steals the PHI on file or when records are left unsecured. For example, a medical professional might leave an unencrypted thumb drive loaded with patient information at a coffee shop where it’s stolen by a third party. Another example is when a medical office is burglarized.
Theft can also occur through a cybersecurity breach due to access failures, such as compromised credentials or poor security infrastructure. In 2023, 725 breaches were reported to HHS, affecting 133 million patients. The four largest breaches were against a major healthcare facilities operator, a medical transcription company, and two dental organizations.
Wrongful disclosures
Wrongful disclosures cover civil and criminal liabilities based on severity. HIPAA violation penalties for employees that wrongfully disclose PHI can include HIPAA fines up to $250,000 and 10 years in prison for criminal violations. However, wrongful disclosure can be as simple as neglecting to get a patient’s signature on a HIPAA release form before releasing the information to a third party.
HIPAA settlements
The OCR and HHS may settle cases with covered entities and business associates through resolution agreements. These agreements can include a HIPAA violation lawsuit payout and obligations to perform corrective actions and submit reports to HHS, typically for three years.
For example, in one recent case, the Children’s Hospital & Medical Center (CHMC) agreed to take corrective actions and pay $80,000 to settle a potential violation of the HIPAA right of access standard. If HHS can’t reach a satisfactory resolution agreement with the covered entity, it can impose civil monetary penalties for noncompliance.
Covered entities and business associates that have access to PHI must implement and adhere to the technical, physical, and administrative safeguards outlined in HIPAA. They must also comply with the HIPAA Privacy Rule and HIPAA Security Rule to protect the integrity of PHI.
The HIPAA Privacy Rule addresses the use and disclosure of PHI and establishes safeguards to protect it. It also gives patients the right to access their medical records and obtain copies on request in a reasonable timeframe. The HIPAA Security Rule specifically addresses the use and protection of PHI that was created, received, maintained, or transmitted electronically.
To comply with the HIPAA Security Rule, the CDC requires all covered entities to:
Of course, these requirements are easier said than done. While external cyberattacks continue to increase, with healthcare organizations as a top target, covered entities must manage risks both inside and outside their organizations. In fact, 66% of incidents involved insiders rather than external threats.
For example, a HIPAA violation where someone’s PHI is disclosed is often the result of human error rather than malicious intent. These compliance errors are most commonly the result of:
Besides human error, be on the lookout for the following common violations:
To prevent violations and the consequences that follow, secure PHI at every level by applying the following best practices.
1. Review current data security practices
To achieve compliance, understand your security landscape. Review current security practices and systems to identify vulnerabilities and compliance gaps. Formally conduct any required audits and assessments, and review and document the results. This review sets the foundation for a systematic compliance plan.
2. Conduct routine monitoring of record access
As part of ongoing compliance practices, conduct routine monitoring of all recorded access involving PHI. Regular monitoring helps detect errors or violations early so you can mitigate the impact and correct the incident.
3. Implement access control
For ePHI, access control is the control doing the most work to secure data across your organization’s network. For this level of control, assign unique logins to each user and establish procedures to govern the release or disclosure of ePHI in the event of an emergency. Also, as part of any access control program, implement system-wide audit controls and activity logs to record access and attempted access. After accessing the data, log how the data is used.
4. Enable full disk encryption
Encrypting files is part of achieving HIPAA compliance and protecting private records. Enable full disk encryption (FDE) as an effective, low-cost method of securing sensitive data. FDE encrypts data on a device, protecting the information even if the device is lost or stolen. For end-to-end protection, take time to review your organization-wide encryption policy.
5. Train employees on HIPAA standards and best practices
To reduce human-error violations and prevent negligent practices, train all employees on HIPAA standards and policies. Conduct training annually for all employees and during onboarding for all new employees.
Training helps employees who handle PHI recognize and avoid malware and cyberattacks, such as phishing. It also reinforces proper handling of digital and physical records, such as disposal procedures.
HIPAA violations can be costly. To protect your organization and data, start with control over the privileged accounts that can reach PHI. This is what the Delinea Platform is built to do; it gives your organization the ability to:
Managing permissions across an organization is time-consuming and can be error-prone. With Delinea, you can vault and rotate privileged credentials and automate least-privilege access, so only authorized users handle PHI.
Delinea's audit and compliance solution pulls that activity into one place, which reduces the time it takes to respond to an auditor and leaves you with a record of when and how PHI was accessed.