Federal Government Reduces Maximum Annual Penalties for Most Healthcare Privacy Violations
Time 1 Minute Read

On April 26, 2019, the U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights announced reductions in available penalties for three out of four tiers of privacy and security violations set forth in the HITECH Act, based on the severity of the violation. Previously, all four tiers of violation were subject to a maximum annual civil monetary penalty of $1.5 million. The revised regime provides for maximum civil penalties of $25,000 for the lowest tier of violation (i.e., unknowing violations), $100,000 for the second tier of violation (i.e., violations where the company had a reasonable cause for the violation occurring) and $250,000 for the third tier of violation (i.e., where the company is willfully neglectful but corrects the violation within 30 days). The maximum penalty for violations resulting from uncorrected willful neglect will remain $1.5 million. The revised penalty tier was published in a Federal Register Notice, which explained HHS’s determination that a better reading of the HITECH Act is to apply annual penalty limits according to severity of the violation. The new penalty rates are effective immediately.

You May Also Be Interested In

Time 2 Minute Read

The U.S. Department of Health and Human Services’ Office for Civil Rights recently announced a settlement with health care software company MMG Fusion to resolve the company’s alleged noncompliance with the HIPAA Privacy, Security and Breach Notification Rules.

Time 4 Minute Read

Recent changes to 42 CFR Part 2 mean many covered entities must update their HIPAA Notices of Privacy Practices by February 16, 2026.

Time 2 Minute Read

On February 19, 2026, the U.S. Department of Health and Human Services’ Office for Civil Rights announced a $103,000 settlement with Top of the World Ranch Treatment Center, an Illinois substance use disorder treatment provider, to resolve alleged noncompliance with the HIPAA Security Rule’s risk analysis requirement.

Time 2 Minute Read

The New York Office of the Attorney General recently reached a $500,000 settlement with a New York orthopedics practice for allegedly failing to protect patient and employee information in light of a 2023 data breach.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page