
HIPAA Fine & Settlement Statistics (2026): Penalty Tiers, Yearly Totals & the Biggest Settlements
A single HIPAA violation can cost anywhere from USD 145 to over USD 2.19 million, and the largest settlement on record reached USD 16 million. But the dollar figures tell a more useful story than sticker shock: what determines the size of a fine is rarely the size of the breach, and almost always the level of documented compliance, or its absence, that OCR finds.
- As of January 28, 2026, HIPAA civil penalties range from USD 145 to USD 2,190,294 per violation across four tiers (Federal Register; HHS OCR).
- Under OCR's 2019 enforcement-discretion notice, annual caps for the first three tiers are lower: USD 36,506 (Tier 1), USD 146,053 (Tier 2), and USD 365,052 (Tier 3).
- The largest HIPAA settlement ever is Anthem at USD 16 million (2018); Premera Blue Cross is second at USD 6.85 million (HIPAA Journal).
- 2018 was the record dollar year with about USD 28.7 million collected; 2022 was the record count with 22 penalties (HIPAA Journal).
- Cignet Health paid USD 4.3 million for denying just 41 patients access to records, proving small incidents can carry large fines (Secureframe; OCR).
- State attorneys general collected about USD 19.56 million in 2024, and a 49-state Blackbaud settlement reached USD 49.5 million (HIPAA fine statistics).
- Fines track documented compliance more than breach size, the provable-compliance principle behind iSedate's SedationVault.
What's in This Guide
1 The Four Penalty Tiers & 2026 Amounts
HIPAA penalties are structured in four tiers based on culpability, how much the organization knew, and whether it acted. The dollar amounts are adjusted for inflation annually; the figures below took effect January 28, 2026.
| Tier | Culpability | Per-Violation Range (2026) |
|---|---|---|
| Tier 1 | No knowledge (and could not have known) | $145 – $73,011 |
| Tier 2 | Reasonable cause, not willful neglect | $1,461 – $73,011 |
| Tier 3 | Willful neglect, corrected within 30 days | $14,602 – $73,011 |
| Tier 4 | Willful neglect, not corrected | $73,011 – $2,190,294 |

Two features of this structure matter in practice. First, penalties are assessed per violation, and a single breach can involve many violations affecting many individuals, so totals climb fast. Second, the tier is set by conduct, not accident: an organization that genuinely could not have known sits in Tier 1, while one that ignored a known problem lands in Tier 4. This is why documentation matters so much, being able to show you took reasonable steps is often what keeps an incident in a lower tier. The amounts adjust each year via an inflation multiplier, so exact figures rise over time; the current multiplier applied was 1.02598.
Source: HIPAA Journal on HIPAA violation fines | Mercer on the 2026 penalty adjustment
See provable sedation compliance2 The 2019 Enforcement-Discretion Caps
There is a crucial nuance that changes the real-world exposure for most violations, and many summaries get it wrong.
Although the Federal Register lists a USD 2,190,294 annual cap for every tier, OCR has, since an April 2019 Notice of Enforcement Discretion, applied much lower annual caps to the first three tiers. In practice, the caps OCR uses are far more moderate for the less-culpable tiers, reserving the full multi-million-dollar cap for the most serious category.
| Tier | Federal Register Annual Cap | OCR Enforcement-Discretion Cap (applied) |
|---|---|---|
| Tier 1 (no knowledge) | $2,190,294 | $36,506 |
| Tier 2 (reasonable cause) | $2,190,294 | $146,053 |
| Tier 3 (willful neglect, corrected) | $2,190,294 | $365,052 |
| Tier 4 (willful neglect, uncorrected) | $2,190,294 | $2,190,294 |
The gap between "statutory" and "applied" caps is large, and unresolved. The 2026 inflation adjustment still does not incorporate the 2019 enforcement-discretion caps, which creates genuine confusion about the true maximum for Tiers 1 to 3. Commentators have asked HHS to clarify. For planning purposes, the enforcement-discretion caps above reflect what OCR actually applies, but the higher statutory figures remain formally on the books, so the exposure ceiling for the worst-case Tier 4 conduct is the one number both tables agree on: about USD 2.19 million.
Source: Paubox on the enforcement-discretion caps
See HIPAA-compliant records3 Year-by-Year Enforcement Totals
OCR's enforcement volume has fluctuated year to year, but the trend line and the record years reveal how the agency's priorities have shifted.
| Year | Enforcement Actions (settlements + CMPs) | Note |
|---|---|---|
| 2018 | Multiple | Record dollar year: ~$28.7M collected |
| 2020 | 19 | Right of Access Initiative ramps up |
| 2021 | 14 | — |
| 2022 | 22 | Record count; 17 were Right of Access |
| 2023 | 13 | Enforcement dip |
| 2024 | 22 closed (16 announced) | 14 of 22 resolved Security Rule failures |
| 2025 | 21 | Second-highest total ever |

The composition of enforcement has changed even more than the count. In 2022, 17 of 22 penalties resolved Right of Access violations, reflecting that initiative's peak. By 2024, the balance had shifted to the Security Rule, with 14 of 22 actions resolving security failures, as OCR's risk-analysis initiative took hold. The overall direction is clear: after a dip in 2023, enforcement climbed to its second-highest level ever in 2025, and a large backlog of breaches under investigation, 978 as of early 2026, signals that more penalties from 2023 to 2024 incidents are still coming.
Source: HIPAA Journal State of HIPAA enforcement
See iSedate's SedationVault4 The Largest Settlements on Record
The headline settlements illustrate what draws OCR's largest penalties, and nearly all trace to the same root failures documented in enforcement history.
| Organization | Amount | Year | Core Issue |
|---|---|---|---|
| Anthem, Inc. | $16,000,000 | 2018 | 2015 cyberattack, ~79M records; risk-analysis failures |
| Premera Blue Cross | $6,850,000 | 2020 | Phishing breach, ~10.5M records; systemic noncompliance |
| Montefiore Medical Center | $4,750,000 | 2024 | Insider data theft; no audit controls |
| Cignet Health | $4,300,000 | 2011 | Denied 41 patients access; ignored OCR |
| NewYork-Presbyterian / Columbia | $4,800,000 | 2014 | ePHI exposed online; inadequate safeguards |
| Solara Medical Supplies | $3,000,000 | 2025 | Phishing + delayed breach notification |
| Orthopedics NY | $500,000 | 2025 | Breach affecting 656,086 individuals |
| Concentra Inc. | $112,500 | 2025 | 54th Right of Access action |
The pattern is consistent across the largest cases: risk-analysis failures, inadequate safeguards, and, notably, insider threats and ignored patient rights. Montefiore's USD 4.75 million penalty is instructive because it stemmed not from an external hacker but from a single employee stealing data over six months, undetected because the organization lacked audit controls on its records. The lesson embedded in the biggest settlements is that OCR penalizes the failure to monitor, document, and control access, the systemic gaps, as heavily as the breach itself.
iSedate Analysis: Audit controls are what Montefiore was missing
The Montefiore case is worth every practice's attention because the failure, no audit controls on who accessed records, is exactly the kind of gap a small practice assumes it can skip. An insider viewing or exfiltrating records over months, undetected, is only possible when no system logs and monitors access. This is a core reason record systems built with access logging and audit trails matter: they turn "we had no idea" into "we can show exactly who touched this record and when." For sedation records specifically, that audit trail is both a compliance control and a clinical-defensibility asset, the same documentation serves both purposes.
Calculation and interpretation original to iSedate.
Source: Secureframe on major HIPAA settlements | HIPAA fine statistics on named cases
See audit-ready records5 When Small Incidents Cost Big
One of the most important lessons in the fine data is counterintuitive: the size of a penalty often has little to do with the size of the breach.
Cignet's penalty came from 41 patients, not millions, and was driven by the organization's conduct: it denied a clear legal right and then ignored the regulator. The dental-practice penalty makes the same point at a scale any small office can relate to. Fine size tracks culpability, cooperation, and whether the entity honored patient rights and documented its compliance, not the raw number of records involved. A small practice cannot comfort itself with "we're too small to matter" or "it was only a few patients." The willingness to ignore a rule is what OCR penalizes, and that is available to organizations of any size.
Source: Secureframe on the Cignet case | Healthcare Law Insights on the dental-practice penalty
See SedationVault for dentists6 The State Attorney General Layer
Finally, a source of exposure many practices overlook entirely: OCR is not the only enforcer. State attorneys general can pursue the same conduct, creating the potential for parallel penalties.
State attorneys general have authority to enforce HIPAA and parallel state privacy laws, and they increasingly do. The Comstar case in 2026 illustrates the dual exposure vividly: a business associate faced a USD 515,000 state AG fine (Massachusetts and Connecticut) plus a separate USD 75,000 OCR settlement for the same breach. The critical planning insight is that the OCR settlement is often the smallest piece of the total financial exposure. Between OCR penalties, state AG actions, class-action lawsuits, breach-notification costs, and remediation, the full cost of a breach dwarfs the headline federal fine, which is why prevention economics are so favorable.
iSedate Analysis: The total-exposure math favors prevention decisively
Stacking the layers, an OCR penalty, potential state AG fines (sometimes from multiple states), class-action settlements, breach-notification and credit-monitoring costs, remediation, and a corrective action plan, the true cost of a serious HIPAA failure runs far beyond the federal number that makes headlines. Against that, the cost of doing compliance properly, documented risk analysis, secure systems, access controls, and audit-ready records, is small. iSedate's SedationVault contributes to the prevention side for the sedation record specifically: it keeps that high-sensitivity record in HIPAA-compliant cloud storage with access controls and audit trails, captures vitals from compatible monitors such as Edan, MindRay, and Criticare, and exports a clean PDF into whatever chart the practice already keeps, whether Dentrix, Eaglesoft, or Open Dental. It is one part of a compliance program, not the whole of it, but it addresses the sedation record the way the fine data says records should be handled. Reference figures for the founders' own practice reflect thousands of documented sedation procedures, a practice-level dataset, not a nationwide claim.
Calculation and interpretation original to iSedate.
For the underlying violation types and causes behind these fines, see the companion report on HIPAA violation statistics.
Book a SedationVault demo7 Summary Table: Every Statistic at a Glance
| Statistic | Figure | Source | Year |
|---|---|---|---|
| Tier 1 penalty range (per violation) | $145 – $73,011 | Federal Register | 2026 |
| Tier 2 penalty range | $1,461 – $73,011 | Federal Register | 2026 |
| Tier 3 penalty range | $14,602 – $73,011 | Federal Register | 2026 |
| Tier 4 penalty range | $73,011 – $2,190,294 | Federal Register | 2026 |
| Annual cap (identical violations) | $2,190,294 | Federal Register | 2026 |
| 2026 inflation multiplier applied | 1.02598 | OMB / HHS | 2026 |
| Tier 1 enforcement-discretion cap | $36,506 | OCR (2019 notice) | 2026 |
| Largest HIPAA settlement (Anthem) | $16,000,000 | HIPAA Journal / OCR | 2018 |
| Second-largest (Premera) | $6,850,000 | OCR | 2020 |
| Montefiore (insider threat) | $4,750,000 | OCR | 2024 |
| Cignet (41 patients, access) | $4,300,000 | OCR | 2011 |
| Record dollar year | ~$28.7M | HIPAA Journal | 2018 |
| Record count year | 22 actions | HIPAA Journal | 2022 |
| 2025 enforcement actions | 21 | HIPAA Journal | 2025 |
| State AG collections | $19.56M (9 actions) | HIPAA fine statistics | 2024 |
| Blackbaud 49-state settlement | $49.5M | HIPAA fine statistics | 2024 |
| Dental-practice access penalty | $170,000 | Healthcare Law Insights | 2024 |
Frequently Asked Questions
How much is a HIPAA violation fine?
What are the four HIPAA penalty tiers?
What is the largest HIPAA fine ever?
Do state attorneys general also fine for HIPAA violations?
Can a small fine come from a small breach?
Methodology & Sources
Primary and institutional sources: the Federal Register (civil monetary penalty amounts effective January 28, 2026), the U.S. Department of Health and Human Services Office for Civil Rights (settlements, enforcement totals, and the 2019 Notice of Enforcement Discretion), and the HITECH Act penalty framework. Enforcement and settlement documentation: HIPAA Journal, Secureframe, Mercer, Paubox, Healthcare Law Insights, and additional HIPAA fine compilations for named settlements and yearly totals.
Note on figures: HIPAA penalty amounts are adjusted for inflation annually, so the specific dollar figures change each year; the amounts shown reflect the adjustment effective January 28, 2026 (multiplier 1.02598) and will be updated when HHS publishes the next adjustment. The gap between the statutory annual caps in the Federal Register and the lower caps OCR applies under its 2019 enforcement-discretion notice is noted where relevant and remains formally unresolved. This article covers HIPAA fines, penalty tiers, and settlements; for the underlying violation types and causes, see the companion report on HIPAA violation statistics. This is general information, not legal advice; consult qualified HIPAA counsel for your practice's specific exposure. Statistics reflect the most recent available data as of 2026.
Media & press usage: Journalists and researchers are welcome to cite these statistics with attribution to iSedate and a link to this page. The iSedate Analysis boxes contain original interpretation unique to this article.
























