ComplianceOnline

HIPAA Violations - Civil Money Penalties


Office for Civil Rights (OCR) may impose a penalty on a covered entity for a failure to comply with a requirement of the Privacy Rule.

Penalties will vary significantly depending on factors such as:

  • the date of the violation,
  • whether the covered entity knew or should have known of the failure to comply, or
  • whether the covered entity’s failure to comply was due to willful neglect.

Penalties may not exceed a calendar year cap for multiple violations of the same requirement.