HIPAA Penalty Calculator

Estimate HIPAA civil monetary penalties across four tiers using the 2026 HHS inflation-adjusted amounts, from $145 to $73,011 per violation.

Minimum Penalty
$292,200.00
Capped at $2,190,294.00 annually
Maximum Penalty
$2,190,294.00
Pre-cap: $14,602,200.00
Likely Penalty
$1,241,247.00
Midpoint estimate (factor: 1.00x)
Multi-Year Exposure
$1,241,247.00
1 year of potential penalties
Per-Record Cost
$29.22 - $219.03
Based on 10,000 affected records
Total Breach Cost
$1,736,247.00
Penalty + notification + legal + remediation

Penalty Severity

$1,241,247.00
$0Annual Cap: $2,190,294.00

HIPAA Penalty Tier Reference

TierKnowledge LevelMin per ViolationMax per ViolationAnnual CapCriminal?
Tier ADid Not Know$145.00$73,011.00$2,190,294.00No
Tier BReasonable Cause$1,461.00$73,011.00$2,190,294.00No
Tier CWillful Neglect (Corrected)$14,602.00$73,011.00$2,190,294.00Possible
Tier DWillful Neglect (Not Corrected)$73,011.00$73,011.00$2,190,294.00Possible

Total Breach Cost Breakdown

Cost CategoryEstimated CostShare
HIPAA Penalty (likely)$1,241,247.00
71.49%
Breach Notification$20,000.00
1.15%
Credit Monitoring (1 year)$100,000.00
5.76%
Legal & Consulting$75,000.00
4.32%
Reputation / Business Loss$200,000.00
11.52%
Remediation & Security Upgrades$100,000.00
5.76%
Total Exposure$1,736,247.00100%

Disclaimer

This calculator provides estimates based on the January 2026 HHS inflation-adjusted HIPAA civil monetary penalty table. Actual penalties are determined by HHS Office for Civil Rights (OCR) based on many factors, and OCR may also exercise enforcement discretion when applying annual caps in less-culpable tiers. This tool is for educational purposes only and should not be considered legal advice. Consult a healthcare compliance attorney for specific guidance.

Planning notes, formulas, and examples

About the HIPAA Penalty Calculator

HIPAA (Health Insurance Portability and Accountability Act) violations can result in significant civil monetary penalties, structured across four tiers based on the violator's level of culpability. In the January 2026 HHS inflation-adjustment table used on this page, HIPAA penalties range from $145 per violation in the lowest tier to $73,011 per violation in the highest tier, with a calendar-year cap of up to $2,190,294 in the federal penalty table.

This calculator estimates HIPAA penalties based on the violation tier, number of violations, and the federal annual cap used in the HHS penalty table. It helps covered entities and business associates understand their financial exposure and prioritize compliance investments in protecting Protected Health Information (PHI).

When This Page Helps

HIPAA violations carry both civil and potentially criminal penalties. Understanding the penalty structure helps healthcare organizations, business associates, and technology vendors serving healthcare prioritize security investments and quantify the cost of non-compliance.

How to Use the Inputs

  1. Select the violation tier (1โ€“4) based on culpability level.
  2. Enter the number of violations.
  3. Review the per-violation penalty and total before cap.
  4. See the annual cap applied per violation category.
  5. Note that criminal penalties may apply separately.
Formula used
Tier 1 (Did Not Know): $145โ€“$73,011/violation. Tier 2 (Reasonable Cause): $1,461โ€“$73,011/violation. Tier 3 (Willful Neglect, Corrected): $14,602โ€“$73,011/violation. Tier 4 (Willful Neglect, Not Corrected): $73,011/violation. Federal annual cap used on this page: $2,190,294.

Example Calculation

Result: $2,190,294 after annual cap (pre-cap: $2,920,400)

Tier 3 (willful neglect, corrected within 30 days): 200 violations at the $14,602 minimum equals $2,920,400 before the annual cap. The federal penalty table used on this page applies a $2,190,294 calendar-year cap to identical violations, so the capped civil monetary penalty is lower than the raw total.

Tips & Best Practices

  • The federal annual cap in the HHS penalty table is adjusted over time and should be checked each year.
  • Criminal penalties (up to $250K and imprisonment) apply separately from civil penalties.
  • Breach notification failures are separate violations from the underlying breach.
  • Business associates can face direct HIPAA liability under the modern Omnibus/HITECH enforcement structure.
  • Voluntary self-disclosure and prompt correction reduce effective penalties.
  • State attorneys general can also bring HIPAA enforcement actions.

HIPAA Penalty Structure

The four-tier penalty system was established by HITECH and later updated through OCR rulemaking and annual inflation adjustments. The tiered approach makes penalties proportional to culpability, while the annual HHS penalty table updates the dollar amounts over time. OCR also weighs case-specific factors such as violation severity, organizational size, compliance history, cooperation, and corrective action.

Criminal vs. Civil Penalties

Criminal penalties are separate: up to $50,000 and 1 year for basic knowing violations, up to $100,000 and 5 years for false pretenses, and up to $250,000 and 10 years for personal gain or malicious harm. Criminal penalties are comparatively rare and apply to individuals, not just organizations.

Resolution Agreements vs. Civil Money Penalties

Many HIPAA enforcement matters end in resolution agreements rather than the maximum civil money penalty. Those resolutions often combine a monetary settlement with a corrective action plan monitored for multiple years. That means this calculator is best used as an exposure worksheet, not as a prediction of what OCR will assess in any specific case.

Compliance Program Impact

Organizations with mature HIPAA programs, including risk analysis, documented safeguards, training, incident response, and prompt remediation, are generally in a stronger position when OCR evaluates a case. The calculator is most useful when paired with a real compliance review, not as a substitute for one.

Sources & Methodology

Last updated:

Frequently Asked Questions

  • Tier 1: Did not know ($145โ€“$73,011). Tier 2: Reasonable cause, not willful neglect ($1,461โ€“$73,011). Tier 3: Willful neglect, corrected within 30 days ($14,602โ€“$73,011). Tier 4: Willful neglect, not corrected ($73,011 minimum). Each tier reflects escalating levels of culpability.