HIPAA penalties in plain English — tiers, caps, and caution
Do not parrot a single "$2.1 million per violation" figure as gospel. OCR uses tiers, inflation adjustments, and annual caps that change.
Journal · Legal, Plain English · F·04 | Last reviewed: October 1, 2026 | 3 min read | By CyberDental Group LLC, Hialeah, Florida
Short answer: HIPAA civil penalties are tiered by culpability, from 'did not know' to 'willful neglect, not corrected,' with per-violation ranges and annual caps adjusted for inflation. In the January 2026 regulatory table, $2,190,294 is both the maximum per violation in the highest tier and the calendar-year cap for violations of an identical requirement or prohibition. OCR's 2019 enforcement discretion applies lower, inflation-adjusted annual caps to the first three tiers. A single headline figure does not describe a typical outcome.
At a glance
| Tiers | 1 Did not know · 2 Reasonable cause · 3 Willful neglect, corrected · 4 Willful neglect, not corrected |
| 2026 table (effective Jan 28, 2026) | Roughly $145 minimum to $73,011 per violation (tiers 1–3 max); $2,190,294 annual cap per identical provision |
| Enforcement discretion (2019) | Lower annual caps for tiers 1–3, adjusted for inflation |
| Also exposed to | State attorneys general; criminal penalties for knowing violations |
| Always verify | The current table in 45 CFR Part 102 and the Federal Register |
General information, not legal advice. Penalty figures are adjusted annually; verify the current table before citing.
Why is "$2.1 million per violation" misleading?
Because it omits the tier, assessment date and whether it means a per-violation maximum or a calendar-year cap. The January 2026 regulatory table lists $2,190,294 as both the highest-tier per-violation maximum and the cap for violations of an identical requirement or prohibition in a calendar year. It is not an automatic fine for a breach or a typical outcome. OCR's separate enforcement-discretion policy matters for lower-tier annual caps. Many cases resolve through settlements and corrective action plans.
What are the four tiers?
Under the HITECH Act's structure (45 CFR 160.404), the penalty depends on the covered entity's or business associate's culpability:
| Tier | Culpability | 2026 per-violation range (effective Jan 28, 2026) |
|---|---|---|
| 1 | Did not know, and could not have known with reasonable diligence | about $145 – $73,011 |
| 2 | Reasonable cause, not willful neglect | about $1,461 – $73,011 |
| 3 | Willful neglect, corrected within the required period | about $14,602 – $73,011 |
| 4 | Willful neglect, not corrected | about $73,011 – $2,190,294 |
HHS adjusts these figures every year for inflation (45 CFR Part 102), so the numbers above reflect the January 28, 2026 adjustment and will change.
What are the annual caps?
The regulatory table lists a calendar-year cap of $2,190,294 for identical violations. But in April 2019, HHS announced it would exercise enforcement discretion and apply substantially lower annual caps to the first three tiers: originally $25,000 (Tier 1), $100,000 (Tier 2) and $250,000 (Tier 3), with $1.5 million for Tier 4, each adjusted for inflation. OCR has said it will use these until further notice. In practice, caps vary by tier and apply per identical provision, so multiple findings can stack.
What else can happen besides a fine?
- Resolution agreements and corrective action plans: often multi-year, with monitoring, policy rewrites and mandatory risk analysis.
- State attorneys general can bring civil actions under HITECH for HIPAA violations.
- Criminal penalties can apply to knowing violations, such as obtaining or disclosing PHI improperly.
- Reputational, operational and insurance consequences, which often exceed the fine.
- Separate state-law exposure. See Florida data-breach notification for dental practices.
What drives OCR's decisions?
Factors include the nature and extent of the violation, the harm, the entity's history, its financial condition, and above all whether it had a current risk analysis, documented safeguards and acted promptly. Failure to conduct a thorough risk analysis has been among the most commonly cited issues, and OCR announced a risk analysis enforcement initiative in late 2024. See Risk analysis vs risk management.
What does this mean for a dental practice?
The cost of an investigation is driven more by documentation and responsiveness than by the table. A practice with a current risk analysis, a risk management plan, signed BAAs, training records and evidence of action is in a far stronger position than one that cannot show any. See HIPAA for dental offices, in plain English.
How should this topic be cited?
Precisely: name the tier, name the year of the table, and distinguish per-violation ranges from annual caps. Avoid quoting a single dollar figure without context.
Frequently asked questions
What is the maximum HIPAA fine?
In 2026 the highest tier carries per-violation amounts up to $2,190,294, and the calendar-year cap for identical violations is $2,190,294. Figures are adjusted annually and OCR's enforcement discretion applies lower caps to lower tiers.
Is the HIPAA fine $2.1 million per violation?
Not automatically. In the January 2026 regulatory table, the highest tier has a $2,190,294 per-violation maximum and the same annual cap for identical violations. The actual amount depends on culpability, facts, assessment date and OCR's enforcement discretion.
How are HIPAA penalty tiers decided?
By culpability: from did not know, to reasonable cause, to willful neglect corrected, to willful neglect not corrected.
Can state attorneys general enforce HIPAA?
Yes. Under the HITECH Act, state attorneys general can bring civil actions for HIPAA violations affecting residents of their state.
Sources and further reading
- Federal Register: HHS civil monetary penalty inflation adjustment (Jan 28, 2026)
- Federal Register: HHS 2019 enforcement discretion by tier
- eCFR: 45 CFR 160.404
- HHS OCR: Resolution agreements and CMPs
Related in the Journal
- Risk analysis vs risk management for dental IT
- HIPAA for dental offices, in plain English
- Florida data-breach notification for dental practices
- What "HIPAA-compliant MSP" means (and does not)
About CyberDental
CyberDental Group LLC is a dental-exclusive managed IT and cybersecurity provider headquartered in Hialeah, Florida. Founded in 2016 by Mr. Dimitri Lopez, it supports 1,000+ licensed dental practices, has completed 250+ dental office IT build-outs, and operates a dental-only HelpDesk. Plans are priced per location: Remote $350/month, Priority $650/month, Ultimate $1,200/month; Concierge is quoted for multi-location groups and DSOs. CyberDental signs a Business Associate Agreement (BAA) with every practice it serves.
- HelpDesk: (954) 639-7049
- Email: support@cyberdental.co
- Address: 480 W 84th Street, Suite B106, Hialeah, FL 33014
- Website: cyberdentalgroup.com