iSedate Logo
Compliance officer reviewing HIPAA penalty documentation with a calculator in a modern office

HIPAA Fine & Settlement Statistics (2026): Penalty Tiers, Yearly Totals & the Biggest Settlements

July 22, 202613 min read

A single HIPAA violation can cost anywhere from USD 145 to over USD 2.19 million, and the largest settlement on record reached USD 16 million. But the dollar figures tell a more useful story than sticker shock: what determines the size of a fine is rarely the size of the breach, and almost always the level of documented compliance, or its absence, that OCR finds.

  • As of January 28, 2026, HIPAA civil penalties range from USD 145 to USD 2,190,294 per violation across four tiers (Federal Register; HHS OCR).
  • Under OCR's 2019 enforcement-discretion notice, annual caps for the first three tiers are lower: USD 36,506 (Tier 1), USD 146,053 (Tier 2), and USD 365,052 (Tier 3).
  • The largest HIPAA settlement ever is Anthem at USD 16 million (2018); Premera Blue Cross is second at USD 6.85 million (HIPAA Journal).
  • 2018 was the record dollar year with about USD 28.7 million collected; 2022 was the record count with 22 penalties (HIPAA Journal).
  • Cignet Health paid USD 4.3 million for denying just 41 patients access to records, proving small incidents can carry large fines (Secureframe; OCR).
  • State attorneys general collected about USD 19.56 million in 2024, and a 49-state Blackbaud settlement reached USD 49.5 million (HIPAA fine statistics).
  • Fines track documented compliance more than breach size, the provable-compliance principle behind iSedate's SedationVault.

What's in This Guide

1 The Four Penalty Tiers & 2026 Amounts

HIPAA penalties are structured in four tiers based on culpability, how much the organization knew, and whether it acted. The dollar amounts are adjusted for inflation annually; the figures below took effect January 28, 2026.

TierCulpabilityPer-Violation Range (2026)
Tier 1No knowledge (and could not have known)$145 – $73,011
Tier 2Reasonable cause, not willful neglect$1,461 – $73,011
Tier 3Willful neglect, corrected within 30 days$14,602 – $73,011
Tier 4Willful neglect, not corrected$73,011 – $2,190,294
$2,190,294
the maximum per-violation penalty and the annual cap for identical violations, as of the January 2026 inflation adjustment.Source: Federal Register, January 28, 2026

 

Stepped bar chart showing four HIPAA penalty tiers from 145 dollars to over 2.19 million per violation
HIPAA penalties climb by culpability: $145 at Tier 1 to $2,190,294 at Tier 4. (Source: Federal Register 2026)

 

Two features of this structure matter in practice. First, penalties are assessed per violation, and a single breach can involve many violations affecting many individuals, so totals climb fast. Second, the tier is set by conduct, not accident: an organization that genuinely could not have known sits in Tier 1, while one that ignored a known problem lands in Tier 4. This is why documentation matters so much, being able to show you took reasonable steps is often what keeps an incident in a lower tier. The amounts adjust each year via an inflation multiplier, so exact figures rise over time; the current multiplier applied was 1.02598.

Source: HIPAA Journal on HIPAA violation fines | Mercer on the 2026 penalty adjustment

See provable sedation compliance

2 The 2019 Enforcement-Discretion Caps

There is a crucial nuance that changes the real-world exposure for most violations, and many summaries get it wrong.

Although the Federal Register lists a USD 2,190,294 annual cap for every tier, OCR has, since an April 2019 Notice of Enforcement Discretion, applied much lower annual caps to the first three tiers. In practice, the caps OCR uses are far more moderate for the less-culpable tiers, reserving the full multi-million-dollar cap for the most serious category.

TierFederal Register Annual CapOCR Enforcement-Discretion Cap (applied)
Tier 1 (no knowledge)$2,190,294$36,506
Tier 2 (reasonable cause)$2,190,294$146,053
Tier 3 (willful neglect, corrected)$2,190,294$365,052
Tier 4 (willful neglect, uncorrected)$2,190,294$2,190,294

The gap between "statutory" and "applied" caps is large, and unresolved. The 2026 inflation adjustment still does not incorporate the 2019 enforcement-discretion caps, which creates genuine confusion about the true maximum for Tiers 1 to 3. Commentators have asked HHS to clarify. For planning purposes, the enforcement-discretion caps above reflect what OCR actually applies, but the higher statutory figures remain formally on the books, so the exposure ceiling for the worst-case Tier 4 conduct is the one number both tables agree on: about USD 2.19 million.

Source: Paubox on the enforcement-discretion caps

See HIPAA-compliant records

3 Year-by-Year Enforcement Totals

OCR's enforcement volume has fluctuated year to year, but the trend line and the record years reveal how the agency's priorities have shifted.

YearEnforcement Actions (settlements + CMPs)Note
2018MultipleRecord dollar year: ~$28.7M collected
202019Right of Access Initiative ramps up
202114
202222Record count; 17 were Right of Access
202313Enforcement dip
202422 closed (16 announced)14 of 22 resolved Security Rule failures
202521Second-highest total ever
$28.7M
collected in 2018, the record year for total HIPAA enforcement dollars, anchored by the Anthem settlement.Source: HIPAA Journal

 

Bar chart showing Anthem 16 million dollars as the largest HIPAA settlement ahead of Premera and Montefiore
Anthem's $16M (2018) remains the largest HIPAA settlement, followed by Premera at $6.85M. (Source: HHS OCR; HIPAA Journal)

 

The composition of enforcement has changed even more than the count. In 2022, 17 of 22 penalties resolved Right of Access violations, reflecting that initiative's peak. By 2024, the balance had shifted to the Security Rule, with 14 of 22 actions resolving security failures, as OCR's risk-analysis initiative took hold. The overall direction is clear: after a dip in 2023, enforcement climbed to its second-highest level ever in 2025, and a large backlog of breaches under investigation, 978 as of early 2026, signals that more penalties from 2023 to 2024 incidents are still coming.

Source: HIPAA Journal State of HIPAA enforcement

See iSedate's SedationVault

4 The Largest Settlements on Record

The headline settlements illustrate what draws OCR's largest penalties, and nearly all trace to the same root failures documented in enforcement history.

OrganizationAmountYearCore Issue
Anthem, Inc.$16,000,00020182015 cyberattack, ~79M records; risk-analysis failures
Premera Blue Cross$6,850,0002020Phishing breach, ~10.5M records; systemic noncompliance
Montefiore Medical Center$4,750,0002024Insider data theft; no audit controls
Cignet Health$4,300,0002011Denied 41 patients access; ignored OCR
NewYork-Presbyterian / Columbia$4,800,0002014ePHI exposed online; inadequate safeguards
Solara Medical Supplies$3,000,0002025Phishing + delayed breach notification
Orthopedics NY$500,0002025Breach affecting 656,086 individuals
Concentra Inc.$112,500202554th Right of Access action

The pattern is consistent across the largest cases: risk-analysis failures, inadequate safeguards, and, notably, insider threats and ignored patient rights. Montefiore's USD 4.75 million penalty is instructive because it stemmed not from an external hacker but from a single employee stealing data over six months, undetected because the organization lacked audit controls on its records. The lesson embedded in the biggest settlements is that OCR penalizes the failure to monitor, document, and control access, the systemic gaps, as heavily as the breach itself.

Source: Secureframe on major HIPAA settlements | HIPAA fine statistics on named cases

See audit-ready records

5 When Small Incidents Cost Big

One of the most important lessons in the fine data is counterintuitive: the size of a penalty often has little to do with the size of the breach.

$4.3M
paid by Cignet Health for denying just 41 patients access to their records and ignoring OCR's investigation.Source: Secureframe; OCR
$170,000
penalty against a single dental practice in 2024 for failing to provide timely record access.Source: Healthcare Law Insights; OCR

Cignet's penalty came from 41 patients, not millions, and was driven by the organization's conduct: it denied a clear legal right and then ignored the regulator. The dental-practice penalty makes the same point at a scale any small office can relate to. Fine size tracks culpability, cooperation, and whether the entity honored patient rights and documented its compliance, not the raw number of records involved. A small practice cannot comfort itself with "we're too small to matter" or "it was only a few patients." The willingness to ignore a rule is what OCR penalizes, and that is available to organizations of any size.

Source: Secureframe on the Cignet case | Healthcare Law Insights on the dental-practice penalty

See SedationVault for dentists

6 The State Attorney General Layer

Finally, a source of exposure many practices overlook entirely: OCR is not the only enforcer. State attorneys general can pursue the same conduct, creating the potential for parallel penalties.

$19.56M
collected by state attorneys general across nine enforcement actions in 2024, separate from OCR.Source: HIPAA fine statistics
$49.5M
the 49-state Blackbaud settlement, the largest state-level penalty tied to a healthcare data breach.Source: HIPAA fine statistics

State attorneys general have authority to enforce HIPAA and parallel state privacy laws, and they increasingly do. The Comstar case in 2026 illustrates the dual exposure vividly: a business associate faced a USD 515,000 state AG fine (Massachusetts and Connecticut) plus a separate USD 75,000 OCR settlement for the same breach. The critical planning insight is that the OCR settlement is often the smallest piece of the total financial exposure. Between OCR penalties, state AG actions, class-action lawsuits, breach-notification costs, and remediation, the full cost of a breach dwarfs the headline federal fine, which is why prevention economics are so favorable.

For the underlying violation types and causes behind these fines, see the companion report on HIPAA violation statistics.

Book a SedationVault demo

7 Summary Table: Every Statistic at a Glance

StatisticFigureSourceYear
Tier 1 penalty range (per violation)$145 – $73,011Federal Register2026
Tier 2 penalty range$1,461 – $73,011Federal Register2026
Tier 3 penalty range$14,602 – $73,011Federal Register2026
Tier 4 penalty range$73,011 – $2,190,294Federal Register2026
Annual cap (identical violations)$2,190,294Federal Register2026
2026 inflation multiplier applied1.02598OMB / HHS2026
Tier 1 enforcement-discretion cap$36,506OCR (2019 notice)2026
Largest HIPAA settlement (Anthem)$16,000,000HIPAA Journal / OCR2018
Second-largest (Premera)$6,850,000OCR2020
Montefiore (insider threat)$4,750,000OCR2024
Cignet (41 patients, access)$4,300,000OCR2011
Record dollar year~$28.7MHIPAA Journal2018
Record count year22 actionsHIPAA Journal2022
2025 enforcement actions21HIPAA Journal2025
State AG collections$19.56M (9 actions)HIPAA fine statistics2024
Blackbaud 49-state settlement$49.5MHIPAA fine statistics2024
Dental-practice access penalty$170,000Healthcare Law Insights2024
See SedationVault for oral surgeons

Frequently Asked Questions

How much is a HIPAA violation fine?

As of January 28, 2026, HIPAA civil monetary penalties range from USD 145 per violation at the lowest tier to USD 2,190,294 per violation at the most serious tier, with an annual cap of USD 2,190,294 for identical violations. The amount depends on the entity's level of culpability across four tiers, and penalties are adjusted for inflation each year.

What are the four HIPAA penalty tiers?

Tier 1 (no knowledge): USD 145 to USD 73,011 per violation. Tier 2 (reasonable cause): USD 1,461 to USD 73,011. Tier 3 (willful neglect, corrected within 30 days): USD 14,602 to USD 73,011. Tier 4 (willful neglect, not corrected): USD 73,011 to USD 2,190,294. Under a 2019 enforcement-discretion notice, OCR applies lower annual caps to the first three tiers.

What is the largest HIPAA fine ever?

The largest single HIPAA settlement is Anthem's USD 16 million payment in 2018, resolving a 2015 cyberattack that exposed the data of nearly 79 million people. The second largest is Premera Blue Cross at USD 6.85 million. 2018 was the record year for total HIPAA enforcement, with about USD 28.7 million collected.

Do state attorneys general also fine for HIPAA violations?

Yes. State attorneys general can enforce HIPAA and parallel state privacy laws, creating dual exposure. In 2024, state AGs collected about USD 19.56 million across nine actions, and a 49-state settlement against Blackbaud reached USD 49.5 million. An organization can face penalties from both OCR and one or more states for the same breach.

Can a small fine come from a small breach?

Not necessarily. Fine size tracks culpability and conduct more than breach size. The Cignet Health case cost USD 4.3 million for denying just 41 patients access to records, and a USD 170,000 penalty hit a single dental practice. Ignoring patient rights or failing to document compliance can produce large penalties even from small incidents.

Methodology & Sources

Primary and institutional sources: the Federal Register (civil monetary penalty amounts effective January 28, 2026), the U.S. Department of Health and Human Services Office for Civil Rights (settlements, enforcement totals, and the 2019 Notice of Enforcement Discretion), and the HITECH Act penalty framework. Enforcement and settlement documentation: HIPAA Journal, Secureframe, Mercer, Paubox, Healthcare Law Insights, and additional HIPAA fine compilations for named settlements and yearly totals.

Note on figures: HIPAA penalty amounts are adjusted for inflation annually, so the specific dollar figures change each year; the amounts shown reflect the adjustment effective January 28, 2026 (multiplier 1.02598) and will be updated when HHS publishes the next adjustment. The gap between the statutory annual caps in the Federal Register and the lower caps OCR applies under its 2019 enforcement-discretion notice is noted where relevant and remains formally unresolved. This article covers HIPAA fines, penalty tiers, and settlements; for the underlying violation types and causes, see the companion report on HIPAA violation statistics. This is general information, not legal advice; consult qualified HIPAA counsel for your practice's specific exposure. Statistics reflect the most recent available data as of 2026.

 

Dr. Taylor Tate, DDS

Dr. Taylor Tate, DDS

Dentist | Software Developer | Sedation Dentistry Instructor

Dr. Tate's is an exceptional dentist, a leader in the sedation dentistry field, a teacher and mentor, an entrepreneur, and humanitarian. He has a passion for technology, safety, and efficiency. He's one of the driving forces behind iSedate's new software development SedationVault, which has proven to protect and streamline his dental practice and others across the nation. Due to it's extraordinary accuracy and efficiency, iSedate was formed to share their digital charting and compliance software with other technology-first dental practices. Accurate sedation charting protects both the practice and patient and has proven to be an extremely valuable asset. Before launch, it was tested on over 6800 successful procedures. Plus, it's new intelligence platform provides audit ready state compliance reports at the click of a button. Dr. Tate also helps advance the entire sedation dentistry industry by holding sedation dentistry classes every month to dentists coming from all over the country and other parts of the world to learn sedation dentistry best practices for safety and compliance. Dr. Tate uses these live training sessions to teach hands-on safety and compliance techniques while also giving back to his local community by offering free dental work to those who can't afford expensive procedures.

Back to Blog