What are the penalties for violating HIPAA?

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) established rules protecting the privacy and security of individually identifiable health information. The HIPAA Privacy Rule and Security Rule set national standards requiring organizations and individuals to implement certain administrative, physical, and technical safeguards to maintain the confidentiality, integrity, and availability of protected health information (PHI).

Failure to comply with HIPAA requirements can result in civil and criminal penalties, as well as progressive disciplinary actions through Indiana University, up to and including termination. These civil and criminal penalties can apply to both covered entities and individuals.

Section 13410(D) of the HITECH Act, which became effective on February 18, 2009, revised section 1176(a) of the Social Security Act by establishing:

  • Four categories of violations that reflect increasing levels of culpability
  • Four corresponding tiers of penalties that significantly increase the minimum penalty amount for each violation
  • A maximum penalty amount of $1.5 million for all violations of an identical provision
Civil monetary penalties
Tier Penalty
1. Covered entity or individual did not know (and by exercising reasonable diligence would not have known) the act was a HIPAA violation.
$100-$50,000 for each violation, up to a maximum of $1.5 million for identical provisions during a calendar year
2. The HIPAA violation had a reasonable cause and was not due to willful neglect.
$1,000-$50,000 for each violation, up to a maximum of $1.5 million for identical provisions during a calendar year
3. The HIPAA violation was due to willful neglect but the violation was corrected within the required time period.
$10,000-$50,000 for each violation, up to a maximum of $1.5 million for identical provisions during a calendar year
4. The HIPAA violation was due to willful neglect and was not corrected.
$50,000 or more for each violation, up to a maximum of $1.5 million for identical provisions during a calendar year
Criminal penalties
Tier Potential jail sentence
Unknowingly or with reasonable cause
Up to one year
Under false pretenses Up to five years
For personal gain or malicious reasons
Up to ten years

To report a HIPAA violation, you can use the Complaint Portal Assistant on the US Department of Health and Human Services Office for Civil Rights (OCR) website. If you have questions, you may contact the OCR toll free at 800-368-1019 (TDD: 800-537-7697). For additional contact information, see the OCR's Contact Us page.

UITS provides consulting and online help for Indiana University researchers, faculty, and staff who need help securely processing, storing, and sharing data containing PHI. If you have questions about managing HIPAA-regulated data at IU, contact UITS HIPAA Consulting. For additional details about HIPAA compliance at IU, see HIPAA Privacy & Security on the University Compliance website.

For more, see:

This is document ayzf in the Knowledge Base.
Last modified on 2017-11-06 11:07:45.

Contact us

For help or to comment, email the UITS Support Center.