Penalties for HIPAA Violations Increase

Insight by
Michael LoVasco

The U.S. Department of Health and Human Services (HHS) has released its inflation-adjusted civil monetary penalties for violations of the HIPAA Privacy and Security Rules. The new amounts apply to penalties assessed on or after Oct. 6, 2023.

HIPAA’s penalties are substantial. Employers with group health plans should periodically review their compliance with the Privacy and Security Rules.

Increased Penalties

Potential penalties for HIPAA violations depend on the type of violation involved. Penalties are broken down into “tiers” that reflect increasing levels of culpability. Each tier carries a minimum and maximum penalty, all of which have increased as follows:

  • For violations where the covered entity or business associate did not know about the violation (and by exercising reasonable diligence, would not have known about the violation), the penalty amount is between $137 and $68,928 for each violation.
  • If the violation is due to reasonable cause, the penalty amount is between $1,379 and $68,928 for each violation.  
  • For corrected violations that are caused by willful neglect, the penalty amount is between $13,785 and $68,928 for each violation.
  • For violations caused by willful neglect that are not corrected, the penalty amount is $68,928 for each violation, with an annual cap of $2,067,813.

HIPAA Enforcement

HHS’ Office for Civil Rights (OCR) is responsible for enforcing the HIPAA Privacy and Security Rules. When OCR determines that a HIPAA violation has occurred, it will often pursue a resolution agreement rather than imposing civil penalties. A resolution agreement typically requires a covered entity or business associate to take corrective action and pay a settlement amount, which is usually much less than the applicable penalty amount. However, if the covered entity or business associate does not take action to resolve the matter in a way that is satisfactory, OCR may decide to impose civil penalties.

Common HIPAA Violations

According to HHS, the compliance problems most frequently reported under HIPAA are:

  • Impermissible uses or disclosures of protected health information (PHI)
  • Lack of safeguards on PHI
  • Lack of patient access to their PHI
  • Lack of Administrative safeguards for electronic PHI
  • Use or disclosure of more than the minimum necessary PHI

Concerned you’re not HIPAA compliant? Ask LoVasco to conduct a complimentary compliance audit. Contact us to learn more.  

Michael LoVasco
Vice President
Share this post

TAKE A FREE ASSESSMENT:

16 Questions to Score Your Organization's Retirement Program

See what you're missing.

Confirm where you shine.

Track progress over time.

Click below to download our free assessment:
Download Free Assessment
Oops! Something went wrong while submitting the form.
Background image of people sitting at an office table in front of a laptop, looking at it and discussing

Not sure where to start?

15 Questions to Score Your Organization's Benefit Program

See what you are missing.

Confirm where you shine.

Track progress over time.

We’ll send your assessment ASAP!
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Background image of people sitting at an office table in front of a laptop, looking at it and discussing

Not sure where to start?

20 Questions to Score Your Organization's Employee Communications Strategy

See what you are missing.

Confirm where you shine.

Track progress over time.

We’ll send over your assessment ASAP!
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Background image of people sitting at an office table in front of a laptop, looking at it and discussing

Subscribe to Our Insights Blog

Receive the latest articles from LoVasco's team of experienced experts on employee benefits and retirement plan best practices.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
©2022 LoVasco. All rights reserved.
Securities and Investment Advisory Services Offered Through M Holdings Securities, Inc. A Registered Broker/Dealer and Investment Advisor, Member FINRA/SIPC. LoVasco Consulting Group is independently owned and operated. LoVasco Consulting Group is a member of M Financial Group. Please go to mfin.com/DisclosureStatement.htm for further details regarding this relationship.

Check the background of this firm and/or investment professional on FINRA's BrokerCheck

For important information related to M Securities, refer to the M Securities' Client Relationship Summary (Form CRS) by navigating to
mfin.com/m-securities.

Registered Representatives are registered to conduct securities business and licensed to conduct insurance businessin limited states. Response to, or contact with, residents of other states will only be made upon compliance withapplicable licensing and registration requirements. The information in this website is for U.S. residents only and doesnot constitute an offer to sell, or a solicitation of an offer to purchase brokerage services to persons outside of the United States.  CA Insurance License #0I92441

This site is for information purposes and should not be construed as legal or tax advice and is not intended to replace the advice of a qualified attorney, financial or tax advisor or plan provider.

#5669272.1

Not sure where to start?

15 Questions to Score Your Organization's Benefit Program

See what you are missing.

Confirm where you shine.

Track progress over time.

We’ll send your assessment ASAP!
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Background image of people sitting at an office table in front of a laptop, looking at it and discussing