HIPAA Violation Penalty Calculator

Compare a hypothetical HIPAA civil penalty calculation.

Pick a hypothetical culpability tier, enter a hypothetical violation count, and see an illustrative civil penalty range using current federal sources. Then review how training, risk analysis, and other records may inform reasonable diligence and remediation without treating any single control as a guaranteed tier. Free, private, and no account required.

4culpability tiers
$2.19Mhighest annual limit shown
0data leaves your browser

The calculator

Compare a hypothetical range in two steps

Select a hypothetical tier and violation count. The illustration uses 2026 per-violation figures and the identified annual limit, but it does not determine a real tier, count, or outcome.
1. Choose the culpability tier

Choose a tier for a hypothetical comparison. The actual tier depends on the legal standard, the complete facts, and HHS's determination.

This tier applies when HHS finds reasonable cause rather than willful neglect. The calculator cannot determine whether a real set of facts meets that legal standard.

2. Estimate the number of violations

Enter a hypothetical count. How HHS counts violations depends on the provision and the facts, so do not assume that each affected person or record is a separate violation.

hypothetical violations

Per-violation figures are the 2026 inflation-adjusted amounts in 45 CFR 102.3. Annual calculations use OCR's 2019 enforcement-discretion policy limits of $25,000, $100,000, and $250,000 for Tiers 1 through 3, and the 2026 table limit of $2,190,294 for Tier 4. Confirm current law and policy before relying on any amount. This estimator does not account for case-specific counting, settlements, criminal penalties, or state actions and is not legal advice.

What it shows

Six things this penalty calculator makes clear

The tool uses the federal penalty structure to explain how a selected tier, violation count, and annual cap shape the estimate.

Four tiers

Compare the four culpability tiers

Select a hypothetical tier, from no knowledge to uncorrected willful neglect. Only HHS can determine the tier for an actual matter.

Current amounts

2026 inflation-adjusted figures

Per-violation minimums and maximums come from the 2026 federal table at 45 CFR 102.3. Annual limits are identified separately.

Per-violation math

Why one incident can involve multiple violations

Depending on the violated provision and the facts, HHS may count violations by separate instances or days of noncompliance, subject to the applicable annual cap.

Annual cap

Regulatory table and policy caps

The tool applies OCR's lower annual enforcement-discretion limits for Tiers 1 through 3 and the 2026 table cap for Tier 4.

Settlement reality

Statutory range, not a prediction

HHS publishes resolution agreements and civil money penalties, but this tool cannot predict the outcome or amount of an actual matter.

Compliance evidence

Documentation is one part of the facts

Training, risk analysis, and written policies can be evidence of reasonable diligence and remediation. They do not determine a penalty tier by themselves.

The full picture

How HIPAA violation penalties actually work

A plain-English guide to the civil tiers, how violation counts affect the range, and the criminal and state exposure beyond the federal civil estimate.

Civil penalties: the four tiers that decide the number

When the Office for Civil Rights, the part of the Department of Health and Human Services that enforces HIPAA, finds a violation, it sets the civil penalty using a four-tier system based on culpability. Culpability is just a formal word for how much the organization knew or reasonably should have known, whether the conduct was reasonable cause or willful neglect, and, for willful neglect, whether the violation was corrected within the applicable 30-day period. The structure lives in the statute at 42 USC 1320d-5 and the regulation at 45 CFR 160.404. The actual dollar amounts are published in the federal penalty table at 45 CFR 102.3, which HHS adjusts for inflation.

Tier 1 covers a violation the person did not know about and, through reasonable diligence, would not have known about. Tier 2 covers reasonable cause that does not amount to willful neglect. Tier 3 and Tier 4 address willful neglect and distinguish whether correction occurred within 30 days after the first date the person knew, or by exercising reasonable diligence would have known, that the violation occurred. The calculator presents these as hypothetical selections only.

The calculator above uses these tiers directly. When you select a tier, it applies that tier's 2026 per-violation minimum and maximum and multiplies by the number of violations you enter. Choosing a different tier changes the range sharply, but the calculator does not determine which legal standard fits an actual case. That requires the facts and, when needed, legal advice.

Why a single incident can involve multiple violations

One incident does not necessarily equal one civil violation. The penalty amounts apply per violation, and an incident may involve more than one requirement or more than one period of noncompliance. Depending on the provision and the facts, HHS may count separate instances or days. This calculator asks you to enter a hypothetical violation count; it does not assume that every affected record is a separate violation.

This is why the number-of-violations input changes the range so quickly. Use it to compare plausible scenarios, not to predict how HHS would count a real matter. The exercise can still show why data minimization, segmentation, encryption decisions, and least-privilege access matter: those controls can reduce how much information one incident exposes.

Model more than one count when the facts are uncertain, and document why each scenario is plausible. The difference between those runs is calculation uncertainty, not a forecast of the enforcement result. Better access records, narrower data holdings, and segmented systems can help an organization establish what was and was not affected.

How the annual limits work

The 2026 federal table at 45 CFR 102.3 lists inflation-adjusted per-violation amounts and a $2,190,294 general annual maximum for violations of an identical provision. OCR's 2019 notification of enforcement discretion separately states annual limits of $25,000, $100,000, and $250,000 for Tiers 1 through 3 until further notice. The calculator applies those lower policy limits to the first three tiers and the current table limit to Tier 4.

The provision and calendar year matter to the annual calculation, and an investigation can address more than one provision or period. HHS determines the applicable legal basis, count, tier, and penalty factors from the facts. This tool models only one selected tier and one hypothetical count, so it should not be used to calculate total exposure in an actual investigation.

What the calculation is, and what it is not

The output combines 2026 regulatory per-violation amounts with the annual limit identified for the selected tier. It is not a prediction of what an organization would pay. HHS publishes matters resolved through resolution agreements as well as civil money penalties. This calculator cannot predict which path, tier, count, amount, or corrective terms would apply to an actual matter.

Under 45 CFR 160.408, HHS considers factors such as the nature and circumstances of the violation, resulting harm, compliance history, financial condition, and other matters justice may require. A corrective action plan can add policies, assessments, training, reporting, or monitoring obligations. Training and a documented compliance program can reduce operational risk and create evidence of corrective work, but they cannot guarantee that an incident, investigation, or penalty will be avoided.

Criminal penalties are a separate track

The penalties in this calculator are civil, but HIPAA also carries criminal penalties under 42 USC 1320d-6, prosecuted by the Department of Justice rather than the Office for Civil Rights. Criminal liability attaches when someone knowingly obtains or discloses protected health information in violation of the rules. The basic offense can bring a fine up to $50,000 and up to one year in prison. When the offense is committed under false pretenses, the exposure rises to $100,000 and up to five years. And when the information is taken with intent to sell it or to use it for commercial advantage, personal gain, or malicious harm, the penalty can reach $250,000 and up to ten years in prison.

Criminal liability is separate from the civil calculator and depends on the statutory elements and facts. Workforce policies, instruction, access controls, and sanctions procedures can address different operational duties, but they do not determine whether criminal liability exists.

State attorneys general add another layer

Federal penalties are not the whole story either. The HITECH Act gave state attorneys general the power to bring civil actions for HIPAA violations on behalf of the residents of their state. State medical-privacy and breach-notification laws may also impose separate duties and remedies. The calculator includes only the federal HIPAA civil amounts and does not evaluate any state law or action.

Requirements HHS may examine

Published HHS matters address a range of provisions, including risk analysis, risk management, access controls, impermissible uses or disclosures, business-associate arrangements, and individual access rights. Encryption and other addressable specifications require a documented reasonable-and-appropriate analysis under 164.306(d), not a universal checkbox. The relevant findings in any matter depend on the entity's role, systems, decisions, and facts.

These items require a mix of governance, technical safeguards, contracts, and workforce practice. A risk analysis is a process, not a product. Encryption decisions depend on the systems and risks. Access reviews and prompt offboarding require repeatable procedures. Business associate agreements must be in place when the vendor relationship requires one. Training needs role-relevant content and retrievable records. If a required safeguard is missing, that gap may become part of the violation analysis, but OCR's conclusion still depends on the complete facts.

How training and documentation can inform the review

The applicable tier turns on the legal culpability standard and the specific facts, not on a checklist. Risk analyses, training records, written policies, and corrective-action records can help show what the organization knew, what reasonable diligence it used, and how quickly it responded. Missing required safeguards or ignoring known problems may support a finding of neglect, but having a certificate or policy does not automatically qualify an organization for Tier 1 or Tier 2.

Training matters because the Privacy and Security Rules contain workforce training duties, and dated completion records can help show what instruction was provided. Training can also give workers a process for recognizing and escalating risky handling or a possible incident. OCR still evaluates the full facts, including reasonable diligence, policies, risk analysis, corrective action, and the nature and duration of the violation. A certificate alone does not establish compliance, good faith, or a penalty tier.

Turning the estimate into action

Use the calculator as a decision aid, not a verdict. Run your own realistic numbers: select hypothetical tiers and violation counts, then compare how the selected assumptions affect the illustration. Do not enter the number of records you hold as a default violation count. Review applicable safeguards with the risk-assessment tool, investigate any follow-up items, and document corrective decisions. If workforce instruction is applicable, assign relevant training and keep the required records. Training is one control among many and does not determine a penalty tier by itself.

Keep going

Guides and tools for reducing compliance risk

Once you have seen the range, these pages help you understand the rules, review your current controls, and prioritize remediation.

Penalty FAQ

Common questions about HIPAA violation penalties

Is this HIPAA penalty calculator free?

Yes. The calculator is completely free, runs entirely in your browser, and needs no account or email. Choose a culpability tier, enter the number of violations, and you get an instant estimated penalty range using the current federal amounts. Nothing you enter leaves your device.

How accurate are the penalty amounts?

The per-violation minimums and maximums are the 2026 inflation-adjusted figures in 45 CFR 102.3. The annual calculation separately applies OCR's 2019 enforcement-discretion policy limits of $25,000, $100,000, and $250,000 for Tiers 1 through 3, and the 2026 table limit of $2,190,294 for Tier 4. The output is an illustration, not a prediction of an actual penalty.

What is the maximum penalty for a HIPAA violation?

The 2026 table at 45 CFR 102.3 lists $2,190,294 as the maximum for a single Tier 4 violation and as the general calendar-year maximum for violations of an identical provision. OCR's enforcement-discretion policy states lower annual limits for Tiers 1 through 3. The applicable tier, violation count, provision, year, and limit depend on HHS's findings.

How does OCR decide which tier applies?

The tier turns on culpability. Tier 1 is for a violation the person did not know about and, through reasonable diligence, would not have known about. Tier 2 is reasonable cause that is not willful neglect. Tier 3 and Tier 4 distinguish whether willful neglect was corrected within 30 days after the first date the person knew, or by reasonable diligence would have known, that the violation occurred. HHS evaluates the complete facts.

Are there criminal penalties too?

Yes, separately from these civil penalties. Knowingly obtaining or disclosing protected health information in violation of HIPAA can carry criminal fines up to $50,000 and up to one year in prison, rising to $100,000 and five years for offenses committed under false pretenses, and up to $250,000 and ten years when the intent is to sell, transfer, or use the information for commercial advantage, personal gain, or malicious harm. Criminal cases are prosecuted by the Department of Justice, not OCR, and are not included in this calculator.

Can a state also fine us for a HIPAA violation?

The HITECH Act authorizes state attorneys general to bring civil actions for HIPAA violations on behalf of residents. Separate state medical-privacy or breach-notification laws may also apply. This tool illustrates only federal HIPAA civil amounts and does not evaluate state law or a possible state action.

How do we lower our penalty exposure?

Reduce the likelihood, duration, and scale of violations. That includes a current risk analysis, role-relevant workforce training with dated records, required business associate agreements, appropriate safeguards, prompt incident response, and timely corrective action. Those measures may support reasonable-diligence and mitigation arguments, but they do not move an organization into a specific tier automatically.

Use the estimate to prioritize practical controls. Start with HIPAA certification or plan a team rollout for your whole workforce.

Primary sources: 45 CFR 160.404 defines the culpability tiers, 45 CFR 160.410 addresses the correction period, 45 CFR 160.408 lists penalty-amount factors, and 45 CFR 102.3 contains the inflation-adjusted amounts, and the 2019 OCR enforcement-discretion notification states the lower annual policy limits for Tiers 1 through 3.

Document preventive work

Document applicable preventive work.

A risk analysis, risk-management decisions, policies, and applicable training records document different parts of a compliance program. No single control guarantees a penalty tier. If workforce instruction is applicable, USA HIPAA courses provide dated certificates that can be retained with related records.