Plain answers
What a HIPAA violation actually costs, and why the published numbers disagree
Almost every page on this subject quotes an alarming maximum without saying where it came from. That matters more than usual here, because three official sources publish HIPAA penalty amounts and they do not agree: the statute Congress wrote, the regulation HHS codified, and the inflation table HHS updates each year. A fourth document, an enforcement notice from 2019, says the agency will follow the statute rather than its own regulation. Untangling that is most of the work, so this page shows the current figures and then explains which authority each one rests on.
The current civil penalty figures
The operative dollar amounts live in HHS's department-wide inflation table at 45 CFR 102.3, not in the HIPAA regulation itself; 102.3 restates every penalty the department administers in current dollars. Its right-most column is headed "2025 Maximum adjusted penalty," published on January 28, 2026 at 91 FR 3665, and it is still the most recent column HHS has issued.
| Culpability tier | Minimum | Maximum | Calendar-year cap |
|---|---|---|---|
| Did not know, and would not have known with reasonable diligence | $145 | $73,011 | $2,190,294 |
| Reasonable cause, and not willful neglect | $1,461 | $73,011 | $2,190,294 |
| Willful neglect, corrected within 30 days | $14,602 | $73,011 | $2,190,294 |
| Willful neglect, not corrected | $73,011 | $2,190,294 | $2,190,294 |
Per violation, except the calendar-year column. Source: 45 CFR 102.3, 2025 column, read August 21, 2026. Violations from before February 18, 2009 sit on a separate line at $198 per violation with a $49,848 annual cap.
Those amounts apply to penalties assessed on or after the date that adjustment published, for violations occurring on or after November 2, 2015. Older violations, and penalties assessed before September 6, 2016, run on the figures in force at the time. (45 CFR 102.2)
What the tiers are measuring
The four tiers come from 45 CFR 160.404, and each one turns on what the organization knew and did. Harm is weighed separately, under 160.408. The regulation labels none of the tiers; each is a full clause describing a state of mind. The bottom tier covers a violation the entity "did not know and, by exercising reasonable diligence, would not have known" about. The top two both involve willful neglect and are separated by a single fact — whether the violation was corrected "during the 30-day period beginning on the first date the covered entity or business associate liable for the penalty knew, or, by exercising reasonable diligence, would have known that the violation occurred." (45 CFR 160.404(b)(2))
That thirty-day window is the one figure here an organization can still move after something has already gone wrong. Correcting inside it puts the floor at $14,602; missing it puts the floor at $73,011 for the same conduct.
How a single incident becomes many violations
The per-violation figures look survivable until you see how violations are counted. The Secretary determines the number "based on the nature of the covered entity's or business associate's obligation to act or not act under the provision that is violated," and the section then adds:
In the case of continuing violation of a provision, a separate violation occurs each day the covered entity or business associate is in violation of the provision. — 45 CFR 160.406
A missing risk analysis or an unencrypted server is not one violation; it is one violation for every day the condition persisted. The number of people affected enters separately, as one of the factors the Secretary weighs in setting the amount within a tier. (45 CFR 160.408(a)) This is why the calendar-year cap is usually the figure that matters in a serious case, and why the dispute over that cap, below, is not academic.
Why the caps you find quoted do not match
Here the sources diverge, which is why a single confident cap figure should make you ask which source it came from. The statute sets four different annual limits, one per tier — $25,000, $100,000, $250,000, and $1,500,000 — in 42 U.S.C. 1320d-5(a)(3), linked below. When HHS codified the tiers at 45 CFR 160.404, it applied the highest of those, $1,500,000, to all four. So the regulation is more punitive at the bottom three tiers than the statute it implements.
In April 2019 HHS said so itself. A Notification of Enforcement Discretion concluded that "the better reading of the HITECH Act" was the statute's four separate limits, announced that "all HIPAA enforcement actions will be governed by" those tiers as adjusted for inflation, and stated that the department expected to fix the regulation through rulemaking. That notice is marked effective indefinitely. (84 FR 18151)
Seven years later the rulemaking has not happened. The eCFR source note for 160.404 records its last amendment as 81 FR 61581 in September 2016. 45 CFR 102.3 still publishes one uniform cap across all four tiers, and a Federal Register search on August 21, 2026 turned up nothing rescinding or superseding the 2019 notice. The result is a gap we can describe but not resolve: HHS has never published inflation-adjusted versions of the three lower caps. The codified cap is $2,190,294; the enforcement posture points at $25,000, $100,000, and $250,000 in un-adjusted dollars, with the notice saying only that they apply "as adjusted for inflation." Anyone quoting a precise current figure for those three is doing arithmetic HHS has not endorsed.
How the numbers move, and why there is no 2026 column
Civil monetary penalties across the federal government are re-indexed under the Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015. Each agency must adjust its penalties "not later than January 15 of every year" and publish the result in the Federal Register. The multiplier is the ratio of the Consumer Price Index for all urban consumers in one October to the previous October, and each figure is rounded to the nearest dollar. For the 2025 adjustment the multiplier was 1.02598, derived from an October 2024 index of 315.664 against October 2023's 307.671. (28 U.S.C. 2461 note, 45 CFR 102.3 n.7)
HHS has rarely met that January 15 date. Reading its annual adjustment rules in the Federal Register on August 21, 2026, the recent ones published at 87 FR 15100 in March 2022, 88 FR 69531 in October 2023, 89 FR 64815 in August 2024, and then 91 FR 3665 in January 2026, with nothing at all during 2025. The department has published nothing yet for 2026, so the 2025 column remains current and a "2026 HIPAA penalty" figure does not exist. Pages advertising one are extrapolating. We will update this page when HHS publishes.
Criminal penalties sit on a different track
A separate statute makes it a federal crime to knowingly obtain or disclose individually identifiable health information in violation of the rules. The exposure is up to $50,000 and one year in prison; committing the offense under false pretenses raises it to $100,000 and five years; doing it with intent to sell, transfer, or use the information for commercial advantage, personal gain, or malicious harm raises it to $250,000 and ten years. (42 U.S.C. 1320d-6(b))
Those figures behave differently from the civil ones in two ways. Congress set them by statute, so they sit outside the annual inflation exercise and do not move each January. They also attach to a person, which is why the curious employee looking up a neighbor's chart is exposed personally where the civil scheme, which runs against covered entities and business associates, is not. Where a criminal penalty has been imposed for an act, no civil money penalty may be imposed for the same act. (42 U.S.C. 1320d-5(b)(1))
What moves the number in practice
The regulation contemplates that many matters resolve without a penalty. Where a complaint or compliance review indicates noncompliance, the Secretary "may attempt to reach a resolution of the matter satisfactory to the Secretary by informal means," which the regulation says may include demonstrated compliance or a completed corrective action plan. (45 CFR 160.312(a)(1)) When an amount is set, 45 CFR 160.408 lists the factors that raise or lower it: the nature and extent of the violation and of the resulting harm, the organization's history of prior compliance including how it responded to earlier complaints and to technical assistance, its financial condition, and any other matter justice requires.
Documented training is one input to that history-of-compliance factor. No course can promise it will change the outcome of an incident. What it gives you is an answer on the day an investigator asks what your staff was taught and when, and that answer is much cheaper to have filed in advance than to reconstruct afterwards.
How our course fits
The eight chapters cover the Privacy and Security Rules in about thirty-five minutes, with the enforcement chapter built on these same sections. Every chapter ends with a quiz and the course closes with a final exam; the pass mark is 80% throughout. Each learner earns a dated certificate, and organization admins can export the roster as a CSV, which is the training record the documentation rules expect you to keep for six years. No certificate from any vendor, ours included, is a government credential or a guarantee of compliance. What the training rules actually require covers that obligation in the regulation's own words.
Dollar figures read from 45 CFR 102.3 on August 21, 2026, reflecting Title 45 as current through August 19, 2026, and re-checked against the Federal Register for any later adjustment. Educational material, not legal advice.
Common questions
What is the maximum fine for a HIPAA violation?
Under the codified table, $73,011 for a single violation in the first three tiers and $2,190,294 for one in the top tier, with a calendar-year cap of $2,190,294 for repeated violations of the same requirement. Those are the 2025 adjusted figures at 45 CFR 102.3. Whether the three lower tiers really carry that cap is unsettled, because HHS said in 2019 it would instead apply the statute's much lower per-tier limits and has never reconciled the two.
Are these the 2026 penalty amounts?
No, and no 2026 amounts exist yet. The most recent adjustment HHS has published is the 2025 one, issued January 28, 2026. The department is required to adjust annually by January 15 but has missed that date in most recent years, so the 2025 column stays operative until a new rule publishes.
Can an individual employee be fined personally?
Civil money penalties under 45 CFR 160.404 run against covered entities and business associates. Individual staff are reached by the criminal statute instead: 42 U.S.C. 1320d-6 applies to a person who knowingly obtains or discloses identifiable health information in violation of the rules, and individuals have been prosecuted under it.
Does a breach automatically mean a penalty?
No. Where an investigation indicates noncompliance, the Secretary may resolve the matter by informal means, which the regulation describes as demonstrated compliance or a completed corrective action plan. A penalty is one of several possible outcomes.
What is the 30-day correction window?
It separates the two willful neglect tiers. If a violation due to willful neglect is corrected within 30 days of the date the organization knew or should have known about it, the minimum penalty is $14,602; if it is not, the minimum becomes $73,011. The clock runs from the date the organization knew or, exercising reasonable diligence, would have known — not from the day someone escalated it internally.
Do the caps reset each year?
45 CFR 160.404(b) applies the cap to violations of an identical requirement or prohibition during a calendar year, running January 1 through December 31. Reading that alongside 160.406, which makes a continuing violation a separate violation each day, a lapse spanning a year boundary falls into both years, and violations of different requirements are counted against separate caps. That is our reading of the two sections rather than language either one states outright.
Training your team, documented
Eight short video chapters, quizzes on each, individual certificates, and an exportable record for the whole team.