HIPAA Sanction Policy Generator
The required policy almost nobody has written down.
HIPAA requires you to apply appropriate sanctions when a workforce member breaks your privacy or security rules, and to document the sanctions you apply. It does not tell you what those sanctions should be. Answer a few questions and this tool drafts a complete sanction policy: four graduated levels with real conduct examples, the whistleblower exceptions most templates omit, a decision procedure, and the six-year record. Free, private, and no account required.
The generator
Answer a few questions, get a policy you can take to counsel
Section 5 of the draft is not optional and cannot be switched off. HIPAA itself carves whistleblower disclosures, workforce crime-victim disclosures, and complaint or testimony activity out of the sanction standard at 45 CFR 164.530(e)(1), and retaliation for those activities is separately prohibited at 45 CFR 160.316. Your selected entity type is subject to both the Privacy Rule and Security Rule sanction requirements.
A sanction policy only works if the workforce was told what the rules are first. The documentation a reviewer asks for is the pair: the policy that set the expectation, and the training records showing who was taught it and when.
This draft is built from 45 CFR 164.308(a)(1)(ii)(C), 45 CFR 164.530(e), and published HHS guidance on sanction policies. Nothing you enter is sent anywhere and nothing is stored. The draft is educational, is not legal advice, and adopting it does not make an organization HIPAA compliant. Have it reviewed and adapted by qualified counsel and by your HR function before you adopt it.
What it covers
Six things this draft gets right
Required, not addressable
Built on 45 CFR 164.308(a)(1)(ii)(C)
The Security Rule marks the sanction policy as a Required implementation specification. There is no documenting an alternative and no reasonable-and-appropriate escape hatch. You either have one or you do not.
Entity aware
Covered entity and business associate drafts differ
The Privacy Rule sanction standard at 164.530(e) is written for covered entities. Business associates owe the Security Rule version directly. Pick your role and the authority section changes to match.
The part templates skip
Whistleblower exceptions are built in
The sanction standard explicitly does not reach protected disclosures under 164.502(j) or complaint and testimony activity under 164.530(g)(2). That clause is in every draft and cannot be switched off.
Four levels
Coaching through termination, with real examples
OCR asks entities to weigh severity, intent, and whether conduct shows a pattern. The draft turns that into four graduated levels with concrete conduct examples at each one.
Evidence you can produce
The eight-field sanction record and the six-year clock
Section 10 lists what to write down and cites the retention periods at 164.316(b)(2)(i) and 164.530(j)(2). Documenting the sanction is its own separate requirement at 164.530(e)(2).
Private by design
Nothing leaves your browser
The policy is assembled entirely on your device. No account, no email, and none of the organization details you enter are sent anywhere or stored.
The full picture
Why the sanction policy is the requirement that quietly decides everything else
Two separate requirements, and they do not cover the same organizations
Most people encounter the sanction requirement once, in a compliance checklist, as a single line item. It is actually two requirements in two different rules, with two different scopes, and knowing which ones apply to you is the first thing your policy has to get right.
The Security Rule version lives at 45 CFR 164.308(a)(1)(ii)(C). It reads, in full: "Sanction policy (Required). Apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity or business associate." Two words in that sentence carry most of the weight. "Required" is a term of art in the Security Rule. The rule splits implementation specifications into Required and Addressable, and for an Addressable specification an entity may assess whether it is reasonable and appropriate, and if it is not, document why and implement an equivalent alternative measure. A Required specification has no such path. Risk analysis, risk management, sanction policy, and information system activity review are all Required under the Security Management Process standard. The second word is "or business associate": this requirement reaches vendors directly, not just through their contracts.
The Privacy Rule version lives at 45 CFR 164.530(e)(1): "A covered entity must have and apply appropriate sanctions against members of its workforce who fail to comply with the privacy policies and procedures of the covered entity or the requirements of this subpart or subpart D of this part." Note what is missing. This one says covered entity and stops there. Business associates are not subject to the Privacy Rule sanction standard of its own force. In practice almost every business associate agreement imports an equivalent expectation, and a vendor that cannot show a sanction process will struggle in customer security review regardless of what the regulation technically requires of it. But the citation in your policy should be honest about which rule is doing the work.
There is a third piece that is easy to miss. The Privacy Rule adds an implementation specification at 164.530(e)(2) requiring the covered entity to document the sanctions that are applied, if any. That is a distinct obligation from applying them. It is entirely possible to respond to an incident well, discipline the right person proportionately, and still be cited, because nobody wrote it down in time.
What OCR actually says it wants
HHS has published direct guidance on this. The October 2023 OCR Cybersecurity Newsletter is devoted entirely to sanction policies, and it is the closest thing to a specification you will get. Its framing is worth quoting: sanction policies "offer a great opportunity for regulated entities to establish and communicate compliance obligations and expectations to their workforce members." The document is not written as a punishment manual. It is written as a communication instrument, and that reframing changes how you draft one.
OCR is explicit that it does not prescribe penalties. Regulated entities vary in size, resources, and relative risk, so HHS leaves the details of sanction policies to the discretion of the entity. What it does ask for is a shape. Sanctions should be appropriate to the nature of the violation. Their severity should vary with the severity of the violation, with whether the violation was intentional or unintentional, and with whether the violation indicated a pattern or practice. And they should range from a warning to termination. Those three sentences are the entire federal design brief for a sanction policy, and they are why the generator produces graduated levels rather than a flat rule.
OCR also recommends the mechanics: implement the policy through a formal, documented process; require workforce members to acknowledge that a violation may result in sanctions; provide examples of potential violations so people can recognize them; and document the personnel involved, the procedural steps, the timeframes, the reasons sanctions were imposed, and the outcomes, retaining that documentation for at least six years.
And then there is the point OCR makes about execution, which matters more than any drafting choice. It asks entities to consider whether their sanction policies align with their general disciplinary policies, how the individuals and departments involved can work in concert, and how sanctions can be fairly and consistently applied throughout the organization, to all workforce members, including management. That last clause is the one to read twice. A sanction policy applied to schedulers but not to surgeons is not a strict policy with exceptions. It is evidence that the program is decorative.
Enforcement: the two failure modes OCR has actually resolved
The same OCR newsletter describes two resolved cases that illustrate the two distinct ways a sanction program fails. In the first, an entity allegedly disclosed protected health information through press releases issued to fifteen media outlets and through published statements, and then failed to document timely the sanctions imposed on the workforce members responsible. The sanctions apparently happened. The documentation did not happen on time. In the second, after a workforce member allegedly disclosed protected health information to a reporter, the entity allegedly failed to apply appropriate sanctions against that member at all.
Those two shapes, sanctioned but not documented and not sanctioned at all, are the entire risk surface here, and they call for different fixes. The first is a records problem solved by a standing record template and a named owner who closes the file. The second is usually a courage problem or an authority problem: the person who broke the rule outranked the person who noticed. Writing the decision owner and the escalation path into the policy in advance, before anyone specific is involved, is how you keep that decision from being renegotiated in the moment.
The clause most free templates leave out
Search for a HIPAA sanction policy template and you will find plenty. A striking number of them omit the single clause that carries the most legal risk, which is the set of activities you are forbidden to sanction.
The exception is written into the standard itself. Section 164.530(e)(1) ends with: "This standard does not apply to a member of the covered entity's workforce with respect to actions that are covered by and that meet the conditions of 164.502(j) or paragraph (g)(2) of this section." Follow those two pointers and you find the protected conduct.
45 CFR 164.502(j)(1) protects whistleblower disclosures. A workforce member who believes in good faith that the covered entity has engaged in conduct that is unlawful or otherwise violates professional or clinical standards, or that the care, services, or conditions provided potentially endanger one or more patients, workers, or the public, may disclose protected health information to a health oversight agency, a public health authority authorized to investigate the conduct, an appropriate health care accreditation organization, or an attorney retained by or on behalf of the workforce member to determine their legal options. Section 164.502(j)(2) protects a workforce member who is the victim of a criminal act and discloses information about the suspected perpetrator to a law enforcement official, limited to the identifying information listed at 164.512(f)(2)(i).
The second pointer, 164.530(g)(2), routes to 45 CFR 160.316, which prohibits a covered entity or business associate from threatening, intimidating, coercing, harassing, discriminating against, or taking any other retaliatory action against any individual for filing a complaint under 160.306, for testifying, assisting, or participating in an investigation, compliance review, proceeding, or hearing, or for opposing any act or practice made unlawful by the HIPAA Rules where the person has a good-faith belief the practice is unlawful and the manner of opposition is reasonable.
The practical consequence is sharp. An organization that disciplines someone for reporting it to a state health oversight agency has not merely made a bad HR decision. It has taken an action the sanction standard expressly does not authorize and that a separate provision expressly prohibits, in a context where the person it disciplined already has a live channel to the regulator. State whistleblower statutes and ordinary employment law frequently reach further than HIPAA does. This is why the generator keeps section 5 in every draft with no toggle, and why the draft routes any sanction that touches this territory through the policy owner and counsel before it is applied.
Designing levels that a manager can actually apply
The hard part of a sanction policy is not severity. It is repeatability. Two managers in two departments, six months apart, facing the same conduct, should land in the same place. That only happens if the policy gives them a small number of clearly bounded levels and a short, explicit list of factors, and if somebody checks afterward that the levels were applied consistently.
The four levels in the generator move from documented coaching, through a written warning with mandatory retraining, to a final warning with access restriction or suspension, to termination with external referral. What makes them usable is the examples attached to each. "Leaving a workstation unlocked" and "sending a chart to the wrong external fax number" are recognizably different events, and putting them in writing at different levels is what stops a manager from improvising. At the top level, the referral language points to 42 U.S.C. 1320d-6, the criminal provision covering knowing wrongful disclosure of individually identifiable health information, which is enforced by the Department of Justice rather than by OCR and is the reason the most serious cases leave the building.
The factor list matters as much as the levels. Nature and extent of the information, intent, whether it shows a pattern, whether the person had been trained on the specific policy, what they did to contain it, whether they self-reported, and how comparable conduct has been treated before. Writing the factors down converts a gut call into a record with reasoning in it, which is exactly what a reviewer asks to see.
One design choice deserves defending: crediting prompt self-reporting with a lower sanction. It can feel like softness. It is the opposite. An organization that only learns about incidents when an audit or a complaint surfaces them has already lost the window in which containment, mitigation under 45 CFR 164.530(f), and an honest four-factor breach assessment are possible. A policy that punishes an honest, promptly reported mistake exactly as hard as a concealed one teaches your workforce that silence is the rational move, and you will pay for that lesson later at a much worse moment. Self-reporting should reduce the sanction, never erase it, and it should not apply to intentional misuse.
Where the sanction decision sits in the incident timeline
A sanction decision and a breach decision run in parallel from the same facts, and confusing them is a common and expensive error.
The breach question is governed by 45 CFR 164.402: an impermissible use or disclosure of unsecured protected health information is presumed to be a breach unless the entity demonstrates a low probability that the information was compromised, based on a documented risk assessment covering the nature and extent of the information, the unauthorized person involved, whether the information was actually acquired or viewed, and the extent to which the risk has been mitigated. If it is a breach, individual notice runs without unreasonable delay and no later than sixty days after discovery under 164.404. That analysis is about the information and the risk to individuals.
The sanction question is about the workforce member and your policies. The two answers are genuinely independent. A nurse who accesses a celebrity's chart out of curiosity and views nothing further may generate a clear Level 4 sanction and, after a documented four-factor assessment, no reportable breach. A misdirected mailing caused by a vendor's print error may be a reportable breach affecting hundreds of people with no sanctionable workforce conduct anywhere in it. Run both, document both, and do not let one substitute for the other. Mitigation under 164.530(f) is a third, independent duty: you must mitigate known harmful effects to the extent practicable, whether or not anyone is disciplined and whether or not notice is required.
Sequence matters too. Preserve evidence before anything else, because audit logs, message copies, and device state all decay or get overwritten, and both the sanction file and the breach assessment depend on them. Then investigate, give the workforce member an opportunity to respond, decide, apply, and document. Applying the sanction without unreasonable delay is not a formality. Delay is one of the two failure modes OCR has actually cited.
Training and sanctions are the same control seen from two sides
A sanction is only defensible if the person knew the rule. That is not a philosophical point, it is an evidentiary one: the sanction file that cannot show the workforce member was trained on the policy they broke is a much weaker file than one that can.
The underlying training duties are specific. Under 45 CFR 164.530(b), a covered entity must train all workforce members on the privacy policies and procedures as necessary and appropriate for them to carry out their functions, must train each new workforce member within a reasonable period of time after they join, and must train each workforce member whose functions are affected by a material change in policy within a reasonable period after the change takes effect. It must document that the training was provided. Under 45 CFR 164.308(a)(5), covered entities and business associates alike must implement a security awareness and training program for the entire workforce, including management. Some states go further: Texas Health and Safety Code 181.101, for example, requires role-appropriate training for employees of a covered entity within ninety days of hire.
OCR makes the link in the other direction as well, noting that training workforce members on the sanction policy itself promotes compliance by informing them which actions are prohibited and punishable. The deterrent only works if the policy is communicated, which is why the acknowledgment block at the end of the generated draft is not decoration. The pair of records you want in a file is the acknowledgment showing the person received the policy and the training record showing they were taught the rule.
This is also the honest limit of what training buys you. Completing a course demonstrates that named individuals received instruction on a specific date. It does not make an organization compliant, and nobody can certify that it is. The federal government does not accredit or endorse HIPAA training providers. What a course produces is dated, verifiable evidence that the expectation was communicated, which is precisely the evidence a sanction decision leans on.
What the proposed Security Rule update would change
HHS published a Notice of Proposed Rulemaking on January 6, 2025 at 90 FR 898, under RIN 0945-AA22, proposing the first substantial Security Rule overhaul since 2013. Two of its proposals bear directly on sanction policies. It would require regulated entities to develop written documentation of all Security Rule policies, procedures, plans, and analyses, and it would remove the distinction between required and addressable implementation specifications, making nearly all of them required.
Neither proposal is in effect. The comment period closed on March 7, 2025, and HHS states that the current Security Rule remains in effect while the rulemaking proceeds. The final rule has been pushed out repeatedly and now sits on the long-term agenda. Treat it as direction of travel, not obligation.
The direction of travel is useful anyway. Sanction policy is already Required today, so the addressable-to-required change would not affect it. But an organization whose sanction practice lives in a manager's head, or in a paragraph of an employee handbook, is relying on an interpretation that gets harder to defend as the written documentation expectation firms up. Writing it down now costs an afternoon and moves you toward wherever the rule lands.
How to actually adopt it
A generated draft is a starting point, not a finished policy. Four steps turn it into something real.
First, reconcile it with the disciplinary policy you already have. If HR runs a three-step progressive discipline process and your HIPAA policy has four levels, decide now how those map, because the moment you need the answer you will not want to be inventing it. Where a collective bargaining agreement governs discipline, its procedures usually control and your policy has to fit inside them.
Second, name a real person as the decision owner, not a committee. The generator asks for a title rather than a name so the policy survives turnover, but somebody has to hold it. Give that person the authority to apply a sanction to anyone in the organization, including people above them on the org chart, and write the escalation path for that case explicitly.
Third, distribute it and collect acknowledgments. An unacknowledged policy is very hard to enforce and produces exactly the evidentiary gap discussed above. Fold the acknowledgment into onboarding and into your annual training cycle so it renews without anyone remembering to chase it.
Fourth, review it on a schedule and record that you did. Security Rule documentation must be reviewed periodically and updated as needed in response to environmental or operational changes under 45 CFR 164.316(b)(2)(iii). A dated review note showing the policy was examined and either changed or confirmed is a small artifact that disproportionately improves how a program reads to an outside reviewer.
Then have counsel look at it. The draft this tool produces is built from the regulation text and published HHS guidance, and it is written to be edited. It is not legal advice, it does not account for your state law, your accreditation standards, your union agreements, or the specific terms of your business associate agreements, and adopting it does not make your organization compliant. What it does is get you from a blank page to a reviewable document in a few minutes, with the citations already attached.
Keep going
What to build next
Guide
HIPAA employee training policy
The policy that sets the expectation your sanction policy enforces. Who gets trained, when, on what, and what the records have to show.
Read the guideGuide
HIPAA breach risk assessment
The four-factor analysis that runs in parallel with a sanction decision. Different question, different standard, and neither answers the other.
Work the analysisGuide
HIPAA incident response plan
Where the sanction procedure plugs in. Reporting, evidence preservation, investigation, and the handoff into notification analysis.
Build the planFree tool
Free HIPAA BAA generator
Sanctions cover your workforce. Vendors are handled through the agreement instead. Draft the one the relationship requires.
Generate a BAAFree tool
HIPAA violation penalty calculator
What the organization faces when internal sanctions were absent or late, by culpability tier, with the current federal amounts.
Estimate exposureTemplate
Free HIPAA training log template
The companion record. A sanction file that cannot show the person was trained on the policy is a much weaker file.
Get the templateSanction policy FAQ
Common questions about HIPAA sanctions
Is a HIPAA sanction policy actually required?
Yes, twice over for a covered entity. The Security Rule lists the sanction policy at 45 CFR 164.308(a)(1)(ii)(C) as a Required implementation specification of the Security Management Process standard, which means it must be implemented rather than assessed as reasonable and appropriate. The Privacy Rule states separately at 45 CFR 164.530(e)(1) that a covered entity must have and apply appropriate sanctions against workforce members who fail to comply with its privacy policies and procedures or with the rules themselves. Business associates owe the Security Rule version directly and are not subject to the Privacy Rule standard, though almost every business associate agreement effectively imports an equivalent expectation.
Does HIPAA say what the punishment has to be?
No, and that is deliberate. HHS leaves the details of sanction policies to the discretion of the regulated entity so the response can fit the size, resources, and relative risk of the organization. There is no federal penalty schedule matching specific conduct to specific consequences. What OCR does expect is that sanctions vary with the severity of the violation, with whether it was intentional or unintentional, and with whether it indicated a pattern or practice, and that they range from a warning to termination. The generator turns that guidance into four graduated levels you can adjust.
Who counts as a workforce member for sanction purposes?
More people than most policies name. The definition at 45 CFR 160.103 covers employees, volunteers, trainees, and other persons whose conduct in the performance of work for the entity is under its direct control, whether or not the entity pays them. That sweeps in contractors working under your supervision, temporary staff, students on clinical placement, interns, and board members who touch protected health information. It does not cover outside vendors that are business associates. Their conduct runs through the business associate agreement and your vendor management process, not through your sanction policy.
Are there people you are not allowed to sanction?
Yes, and this is the clause most free templates leave out. The sanction standard at 45 CFR 164.530(e)(1) states on its face that it does not apply to a workforce member with respect to actions covered by and meeting the conditions of 45 CFR 164.502(j) or 45 CFR 164.530(g)(2). Section 164.502(j) protects good-faith whistleblower disclosures to health oversight agencies, public health authorities, accreditation organizations, or the workforce member's own attorney, and it protects a workforce member who is the victim of a crime and discloses limited information about the suspected perpetrator to law enforcement. Separately, 45 CFR 160.316 prohibits retaliation for filing a complaint with the Secretary, for testifying or participating in an investigation or proceeding, and for good-faith opposition to unlawful practices. Sanctioning protected activity converts an internal HR matter into a separate federal violation.
Do we have to document sanctions we apply?
Yes, as an independent requirement. 45 CFR 164.530(e)(2) requires a covered entity to document the sanctions that are applied, if any, as part of the documentation standard at 164.530(j). OCR guidance recommends recording the personnel involved, the procedural steps, the timeframes, the reason the sanction was imposed, and the outcome. Retention is six years from the date of creation or the date the record was last in effect, whichever is later, under 45 CFR 164.530(j)(2) for Privacy Rule documentation and 45 CFR 164.316(b)(2)(i) for Security Rule documentation. Note the failure mode here: it is possible to sanction someone appropriately and still be cited, because the documentation was late or missing.
Does a sanction mean we had a reportable breach?
No. They are separate decisions with separate standards and neither one settles the other. Whether an incident is a reportable breach turns on 45 CFR 164.402, where an impermissible use or disclosure of unsecured protected health information is presumed to be a breach unless a documented four-factor risk assessment shows a low probability that the information was compromised. Whether a sanction is appropriate turns on whether a workforce member failed to follow your policies. Plenty of sanctionable conduct produces no reportable breach, and plenty of reportable breaches involve nobody who did anything wrong. Run both analyses and document both.
Should managers and clinicians be sanctioned the same way as front-line staff?
Yes, and OCR says so directly. Its guidance asks regulated entities to consider how sanction policies can be fairly and consistently applied throughout the organization, to all workforce members, including management. This is where sanction programs most often fail in practice: a policy that is enforced against a receptionist but not against a physician or a vice president is evidence that the program is not real. Periodic consistency review, comparing how similar conduct was treated across departments and seniority levels, is the practical control.
Can we sanction someone for not completing HIPAA training?
You can, and many organizations do. Training is a requirement in its own right at 45 CFR 164.530(b) for covered entities and 45 CFR 164.308(a)(5) for the security awareness program, and if your policy states that assigned training must be completed by a deadline, missing that deadline is a policy violation like any other. The generator has an optional clause covering overdue training, overdue retraining assigned as part of a sanction, and having another person complete training on your behalf. What matters more is the reverse direction: a sanction is much harder to defend when the file cannot show the workforce member was trained on the policy they broke.
How does the proposed Security Rule update change this?
It has not changed anything yet. HHS published a Notice of Proposed Rulemaking to strengthen the Security Rule in the Federal Register on January 6, 2025 at 90 FR 898, and the comment period closed on March 7, 2025. Among other things it would require written versions of all Security Rule policies, procedures, plans, and analyses, and would remove the distinction between required and addressable implementation specifications with limited exceptions. As of this writing no final rule has been issued, HHS has moved the rulemaking to its long-term agenda, and the current Security Rule remains in effect. A written, dated, acknowledged sanction policy already satisfies the direction the proposal points in, which is a good reason to write yours now rather than wait.
Does having this policy make our organization HIPAA compliant?
No. A sanction policy satisfies one implementation specification out of many. Organizational compliance is a much larger program that includes a written risk analysis, administrative, physical, and technical safeguards, a notice of privacy practices, individual rights processes, business associate agreements, breach response, and ongoing oversight. No document template and no training provider can certify an organization as HIPAA compliant, and the federal government does not accredit or endorse training providers. What a written policy and dated training records give you is evidence: proof that expectations were set and that named people were taught them on specific dates.
Once the policy is written, the next record a reviewer asks for is training. Start with HIPAA certification or plan a team rollout for everyone who touches PHI.
The other half of the file