Skip to content

HIPAA Compliance and Enforcement

 

Learn about HIPAA enforcement, penalties for violations, common violations, BAA, HIPAA Security Risk Analysis, HIPAA and MIPS, and more, through the Frequently Asked Questions (FAQs) below. Please schedule a free consultation, if you are looking for experienced professionals to help you comply with HIPAA, conduct a HIPAA Security Analysis, and for other customized services.

Table of Contents

Who enforces HIPAA? 

 

HIPAA enforcement is led by the HHS Office for Civil Rights (OCR), which investigates complaints, conducts compliance reviews and audits, and imposes civil monetary penalties for violations. OCR has run two major enforcement initiatives: a Right of Access initiative launched in 2019, producing more than 54 financial penalties through early 2026 against entities ranging from solo dental practices to major university health systems, and a risk analysis enforcement initiative active since 2024, which expanded in 2026 to also cover risk management. The Department of Justice handles criminal HIPAA violations referred by OCR when it identifies knowing or willful conduct. State attorneys general may independently bring civil actions on behalf of residents and seek damages and injunctive relief.

 

What are the penalties for HIPAA violations? 

 

HIPAA violations carry both civil and criminal penalties, scaled to the severity and culpability of the violation. Civil monetary penalties (effective January 28, 2026, per the 2025 inflation adjustment) are organized into four tiers: 

Tier 1, No Knowledge: The organization did not know and could not reasonably have known of the violation. Per-violation range: $145 to $73,011. Discretionary annual cap for identical violations: approximately $36,505. 

Tier 2, Reasonable Cause: The violation resulted from reasonable cause but not willful neglect. Per-violation range: $1,461 to $73,011. Discretionary annual cap: approximately $146,053. 

Tier 3, Willful Neglect, Corrected: The violation resulted from willful neglect but was corrected within the required timeframe (generally 30 days). Per-violation range: $14,602 to $73,011. Discretionary annual cap: approximately $365,052. 

Tier 4, Willful Neglect, Not Corrected: The most serious category. Per-violation range: $73,011 to $2,190,294. Annual cap: $2,190,294. 

OCR’s 2019 Notice of Enforcement Discretion, which establishes the lower annual caps for Tiers 1 through 3, is a policy position, not codified regulation, and OCR retains authority to rescind it. All penalty amounts are adjusted annually for inflation. 

Criminal penalties apply to individuals who knowingly obtain or disclose PHI in violation of HIPAA: basic violations carry fines up to $50,000 and up to one year of imprisonment; violations committed under false pretenses carry up to $100,000 and five years; violations with intent to sell, transfer, or use PHI for commercial advantage, personal gain, or malicious harm carry up to $250,000 and ten years. Criminal cases are prosecuted by the DOJ, not OCR. 

State attorney general enforcement: State attorneys general may bring civil actions on behalf of residents, with damages of $100 per violation, capped at $25,000 per calendar year for identical violations, independent of any OCR civil monetary penalties. 

 

What are the most commonly cited HIPAA violations in OCR investigations? 

 

Five violation types dominate OCR’s complaint data, impermissible disclosures top the list, followed by failures in safeguards, patient access, ePHI administrative controls, and minimum necessary compliance. In order of frequency, the most commonly alleged issues in HIPAA complaints are: (1) impermissible uses and disclosures of PHI; (2) lack of safeguards for PHI; (3) failure to provide patients access to their own PHI; (4) lack of administrative safeguards for ePHI; and (5) use or disclosure of more than the minimum necessary PHI. Since the Privacy Rule took effect, OCR has received more than 371,000 HIPAA complaints and, as of early 2026, has imposed civil monetary penalties or agreed settlements in more than 170 cases. Criminal referrals to the DOJ have exceeded 2,400. OCR’s current enforcement priorities are the Right of Access initiative and the risk analysis initiative, which expanded in 2026 to also require evidence of active risk management. 

 

 

What is a Business Associate Agreement (BAA)? 

 

A Business Associate Agreement (BAA) is a legally required written contract between a HIPAA covered entity and a business associate, executed before any PHI is shared. The BAA must specify the permitted uses and disclosures of PHI by the business associate; require the business associate to implement appropriate safeguards; obligate the business associate to report security incidents and breaches to the covered entity; ensure that any subcontractors who handle PHI are bound by the same restrictions; and allow termination if the business associate violates a material term. A covered entity that fails to confirm a business associate’s HIPAA compliance before sharing PHI, and a breach subsequently occurs, may itself bear liability for the resulting violation. 

 

What is a HIPAA Security Risk Analysis, and is it required? 

 

A security risk analysis is a required, comprehensive evaluation of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI, it is not optional, and it is an explicit required implementation specification under the HIPAA Security Rule (45 CFR § 164.308(a)(1)). A proper analysis identifies where ePHI is stored, received, maintained, and transmitted; assesses threats and vulnerabilities; evaluates the likelihood and impact of those threats; reviews existing security controls; and determines the overall risk level. Organizations must then implement measures sufficient to reduce identified risks to a reasonable level, document all decisions, and revisit the analysis regularly or whenever significant environmental or operational changes occur. 

 

How often must a HIPAA risk analysis be conducted? 

 

HIPAA requires a risk analysis to be performed initially and updated on an ongoing basis, it is not a one-time event. No specific frequency is prescribed, but OCR has made clear through enforcement actions that the analysis must be repeated whenever significant environmental or operational changes affect ePHI security, such as implementing new technology, moving to a new facility, adding workforce members, or experiencing a data breach. OCR launched a dedicated risk analysis enforcement initiative in 2024 and, in 2026, expanded it to require evidence of active risk management, meaning organizations must demonstrate that identified risks were actually reduced to an acceptable level, not merely documented. 

 

What is HIPAA’s relationship to the MIPS Security Risk Analysis requirement? 

 

MIPS independently requires a Security Risk Analysis each performance year, reinforcing but entirely separate from the HIPAA Security Rule obligation, with different consequences for non-compliance. The Merit-based Incentive Payment System (MIPS), administered by CMS, requires eligible clinicians participating in Medicare to complete an SRA as part of the Promoting Interoperability (PI) performance category, and to have implemented certified electronic health record technology (CEHRT). Failing to attest to completing the SRA results in a score of zero for the entire PI category, significantly reducing the clinician’s overall MIPS composite score and affecting Medicare reimbursement rates. Because MIPS participants are also typically HIPAA covered entities, both requirements apply simultaneously, governed by different regulatory frameworks with different consequences for non-compliance. 

 

What is the “Wall of Shame” in HIPAA enforcement? 

 

The “Wall of Shame” is the informal name for HHS OCR’s public-facing Breach Notification Portal, the database where HHS posts information about all reported breaches of unsecured PHI affecting 500 or more individuals. The portal displays the covered entity’s name, state, number of individuals affected, type of entity, type of breach (theft, hacking, or unauthorized access), and location of the breached information (laptop, network server, email system, or paper records). This information is publicly searchable by anyone. Appearing on the portal carries significant reputational consequences and automatically triggers an OCR investigation. Healthcare organizations regularly consult the portal at hhs.gov to review peer breaches, benchmark their own risk profile, and identify emerging threat vectors. 

 

What is the “Recognized Security Practices” provision, and how does it affect enforcement? 

 

Recognized Security Practices (RSPs) give covered entities a concrete legal benefit: when demonstrably implemented enterprise-wide for at least 12 consecutive months before a security incident, OCR is legally required to treat them as a mitigating factor in determining civil monetary penalties, audit scope, and resolution agreement terms. This requirement was introduced by a January 2021 amendment to the HITECH Act (Public Law 116-321) and creates a congressionally mandated incentive for healthcare organizations to adopt rigorous cybersecurity practices. 

The amendment recognizes three categories of RSPs: standards developed under the NIST Act (primarily the NIST Cybersecurity Framework and related NIST special publications); approaches developed under Section 405(d) of the Cybersecurity Act of 2015 (the Health Industry Cybersecurity Practices, or HICP, published by HHS); and other programs addressing cybersecurity developed, recognized, or promulgated under statute or regulation. Implementing RSPs is entirely voluntary, not adopting them is not treated as an aggravating factor that increases penalties. RSPs are not a safe harbor: they do not eliminate liability for Security Rule violations and apply only to Security Rule investigations and audits, not to Privacy Rule or Breach Notification Rule matters. To benefit from RSP consideration, organizations must provide evidence, such as third-party audit reports, vulnerability scan results, policies and procedures, and training documentation, demonstrating enterprise-wide, continuous implementation.

 

How do you file a complaint with OCR for a HIPAA violation, and what happens after? 

 

Any individual who believes their HIPAA rights have been violated may file a complaint directly with HHS’s Office for Civil Rights (OCR) at no cost, through the OCR complaint portal at hhs.gov/ocr/complaints, by mail, by fax, or in person at an OCR regional office. Complaints must be filed within 180 days of when the complainant knew or should have known of the alleged violation, though OCR has discretion to waive this deadline for good cause. Anonymous complaints are not accepted. A valid complaint must name the covered entity or business associate believed to have violated HIPAA, describe the alleged acts or omissions, and be filed by the affected individual or their personal representative. 

Once received, OCR screens the complaint to determine jurisdiction, confirming the named entity is a covered entity or business associate, that the alleged conduct would constitute a violation if true, and that the complaint was timely. Complaints failing the jurisdictional screen are closed without investigation. Those that pass proceed to one of three outcomes: technical assistance and closure for minor correctable issues; a formal investigation requesting documentation from both parties; or a resolution agreement or civil monetary penalty for serious matters. If a violation is found, OCR seeks voluntary compliance through corrective action before imposing financial penalties. Individuals do not currently receive a share of financial penalties collected, though HITECH contemplates a methodology for sharing civil monetary penalties with harmed individuals, a framework HHS has been developing but has not finalized as of March 2026.

 

Explore Blogs, Webinars and other Resources

Trusted by Reputed Companies

pVerify, Inc.
Electronic Data Solutions
Bernard Robinson & Company
Avance Care
iCliniq
Botsplash
Logically
Mr.Internet Systems
Vision Radiology
Tangible Solutions
Tangible Solutions
WorkSmart
Triyam
Med First Primary and Urgent Care
Arizona State Radiology
DataCaliper
Dose Spot Company Logo
DoseSpot
Forsyte I.T. Solutions
Tego Data

Accreditations and Associations

* Disclaimer: This list of accreditations is held by our team of employees and consultants.

What Our Clients Say

We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center

Our Growing List of Credentials

0 +
Assessments
0 +
Clients
0 +
Assessment Libraries
0 +
Years of Experience
0 +
No. of Staff Trained
0 +
HIPAA
0 +
SOC 2 Readiness
0 +
Pen Testing
0 +
ISO 27001 Certifications
0 +
Dollars Saved in Compliance Penalties