Skip to main content
Category: OCR Enforcement and Penalties

Civil Monetary Penalty (CMP)

Also known as: CMP, Civil Money Penalty, Civil Monetary Penalties
Simply put

A civil monetary penalty (CMP) is a financial penalty that a federal government agency can impose on an individual or organization for failing to follow certain legal or regulatory requirements. Different agencies have authority to seek these penalties in different contexts, such as for noncompliance with program rules or for fraud. The specific amounts and the situations in which they apply vary by agency and program, and penalty figures are adjusted over time.

Formal definition

A civil monetary penalty (CMP) is a monetary sanction imposed through civil administrative authority rather than criminal prosecution, assessed by federal agencies against individuals or entities for defined violations. Within the U.S. Department of Health and Human Services, the Office of Inspector General (OIG) holds authority to seek CMPs, assessments, and exclusion against an individual or entity, while the Centers for Medicare & Medicaid Services (CMS) may impose CMPs on facilities such as nursing homes for each day or instance of noncompliance with Medicare and Medicaid requirements. CMP amounts are subject to periodic inflationary adjustment under federal rulemaking. Note that the evidence provided addresses CMPs in the Medicare/Medicaid and OIG enforcement contexts and does not specifically address CMPs imposed under the HIPAA Enforcement Rule; HIPAA-specific penalty tiers and amounts (administered by HHS OCR) are outside the scope of this evidence and should be confirmed against current HHS guidance and the applicable regulatory text.

Why it matters

Civil monetary penalties represent one of the primary ways federal agencies enforce compliance without resorting to criminal prosecution. For healthcare organizations, the prospect of a CMP creates a direct financial incentive to maintain compliance with program requirements, since penalties can be assessed on a per-day or per-instance basis. In the nursing home context, for example, CMS may impose CMPs on facilities for each day or each instance of noncompliance with Medicare and Medicaid requirements, meaning that prolonged or repeated violations can accumulate significant exposure over time.

Beyond CMS, the HHS Office of Inspector General (OIG) holds separate authority to seek CMPs, assessments, and exclusion against individuals or entities, which broadens the range of conduct that can trigger financial sanctions across federal healthcare programs. Because CMP amounts are subject to periodic inflationary adjustment under federal rulemaking, the figures in effect at any given time may differ from prior years, and compliance teams should confirm current amounts against the applicable regulatory text rather than relying on older references.

It is important to note that CMPs discussed here arise in the Medicare/Medicaid and OIG enforcement contexts. HIPAA-specific civil monetary penalties, which are administered by HHS OCR under the HIPAA Enforcement Rule and organized into penalty tiers, are governed by a separate authority and framework. Organizations should not assume that CMP amounts or procedures in one program carry over to HIPAA enforcement, and HIPAA-specific penalty figures should always be confirmed against current HHS OCR guidance.

Who it's relevant to

Nursing home and long-term care compliance staff
Facilities participating in Medicare and Medicaid face CMPs that CMS may assess for each day or instance of noncompliance. Compliance staff at these facilities should understand how penalties accumulate and how collected funds flow into the federal Civil Monetary Penalties fund tied to noncompliant certified facilities.
Healthcare providers and entities subject to OIG oversight
The OIG has authority to seek CMPs, assessments, and exclusion against individuals or entities. Providers and organizations operating in federal healthcare programs should recognize that OIG enforcement can combine financial penalties with exclusion, which carries consequences beyond the monetary amount alone.
HIPAA privacy and security officers
Officers focused on HIPAA compliance should be aware that HIPAA civil monetary penalties are administered by HHS OCR under the HIPAA Enforcement Rule and follow a separate tiered structure. The CMP figures and procedures described in the Medicare/Medicaid and OIG contexts do not directly govern HIPAA enforcement, and HIPAA-specific amounts should be confirmed against current HHS OCR guidance.
Compliance and legal teams tracking penalty amounts
Because CMP amounts are adjusted periodically for inflation through federal rulemaking, teams responsible for risk assessment and budgeting should verify current penalty figures against the applicable regulatory text rather than relying on prior-year values.

Inside CMP

Statutory Authority
A civil monetary penalty is a financial sanction that HHS OCR may impose against a covered entity or business associate for violations of the HIPAA Rules. It is a civil, not criminal, enforcement mechanism; criminal penalties are pursued separately through the Department of Justice.
Tiered Penalty Structure
CMPs are generally organized into tiers based on the entity's level of culpability, ranging from violations where the entity did not know (and could not reasonably have known) of the violation, to violations due to reasonable cause, to willful neglect that is corrected, and willful neglect that is not corrected. Specific per-violation and annual cap figures are adjusted over time and should be confirmed against current OCR guidance.
Culpability and Knowledge
The applicable tier depends largely on the entity's state of knowledge and whether the violation was addressed promptly. Willful neglect that goes uncorrected generally falls into the most severe tier.
Per-Violation Assessment
Penalties are typically calculated on a per-violation basis, with annual limits that apply to multiple violations of an identical provision within a calendar year. The specific dollar amounts and caps are periodically adjusted for inflation and should be verified against current regulatory figures.
Enforcing Authority
For HIPAA, CMPs are imposed by HHS OCR. This is distinct from HITRUST, a private organization whose CSF certification is not a legal requirement and does not by itself shield an entity from CMPs or establish HIPAA compliance.
Mitigating and Aggravating Factors
In determining a penalty amount, OCR generally considers factors such as the nature and extent of the violation and resulting harm, the entity's history of prior compliance, and its financial condition, among others described in the Enforcement Rule.

Common questions

Answers to the questions practitioners most commonly ask about CMP.

Does a HIPAA violation always result in a civil monetary penalty?
No. A HIPAA violation does not automatically trigger a civil monetary penalty. HHS OCR generally has discretion in how it resolves violations, and many matters are resolved through voluntary compliance, corrective action, or technical assistance rather than a formal CMP. The imposition of a penalty typically depends on factors such as the nature and extent of the violation, the level of culpability, and whether the entity took timely corrective steps. Readers should verify current enforcement practices and figures against current OCR guidance.
Is a CMP the same thing as a settlement amount OCR announces in a resolution agreement?
Not exactly. A civil monetary penalty is a penalty formally imposed under the HIPAA Enforcement Rule, whereas a resolution agreement typically involves a negotiated settlement amount that a covered entity or business associate agrees to pay, often accompanied by a corrective action plan, without a formal CMP determination. The two are distinct enforcement outcomes, though both are administered by HHS OCR. The specific figures and structures vary by case and over time, so confirm details against current OCR resources.
Can both a covered entity and its business associate face civil monetary penalties for the same incident?
In general, both covered entities and business associates can be directly subject to CMPs under HIPAA for violations of provisions that apply to them, and obligations for business associates often flow through a business associate agreement. Whether penalties attach to one or both parties in a given incident typically depends on which requirements were violated and each party's role and culpability. This is a fact-specific determination, and readers should consult current OCR guidance and legal counsel for their situation.
How are CMP penalty tiers generally structured under HIPAA?
CMPs under the HIPAA Enforcement Rule are generally organized into tiers that correspond to the level of culpability, such as whether the entity did not know of the violation, whether it resulted from reasonable cause, or whether it involved willful neglect. Penalty amounts and annual caps associated with these tiers are adjusted over time. Because specific figures change, they should be confirmed against current OCR guidance and the applicable regulatory text rather than relied upon from memory.
What factors does OCR typically consider when determining a CMP amount?
OCR generally weighs a range of factors when determining a penalty, which may include the nature and extent of the violation, the nature and extent of resulting harm, the entity's history of prior compliance or violations, the entity's financial condition, and the level of culpability involved. Timely corrective action can also be relevant. Because the analysis is case-specific and guidance evolves, entities should review current OCR materials and consult counsel to understand how these factors may apply.
Does obtaining HITRUST certification protect an organization from a CMP?
No. HITRUST certification is issued by a private organization against the HITRUST CSF and is not a legal requirement, nor does it by itself establish HIPAA compliance or provide immunity from a civil monetary penalty. OCR enforces HIPAA independently of any private framework. Certification may support an organization's compliance efforts and demonstrate diligence, but it does not guarantee that a CMP will not be imposed. Organizations should treat HIPAA compliance and HITRUST certification as related but distinct.

Common misconceptions

A CMP is the same as a criminal penalty under HIPAA.
A CMP is a civil sanction imposed by HHS OCR. Criminal penalties for HIPAA violations are a separate matter pursued by the Department of Justice and are distinct from civil monetary penalties.
Achieving HITRUST CSF certification prevents HIPAA civil monetary penalties.
HITRUST is a private organization and its CSF certification is not a legal requirement. Certification may support an entity's compliance efforts but does not by itself establish HIPAA compliance or exempt an entity from CMPs imposed by HHS OCR.
The penalty tiers and dollar amounts are fixed and permanent.
Penalty tiers are based on culpability, and the associated dollar figures and annual caps are periodically adjusted over time. Practitioners should confirm current amounts against the latest OCR guidance rather than relying on previously published figures.

Best practices

Address suspected violations promptly, since correcting a violation (particularly one involving willful neglect) generally affects which penalty tier applies.
Maintain thorough documentation of your compliance program, remediation efforts, and prior compliance history, as these may serve as mitigating factors OCR considers when determining a penalty.
Verify current per-violation amounts and annual caps against the latest HHS OCR guidance, recognizing that these figures are adjusted over time.
Do not treat HITRUST CSF certification or any single measure as a guarantee against CMPs; use it, where applicable, as one component of a broader HIPAA compliance effort.
Confirm which obligations apply to your organization based on whether it is a covered entity, business associate, or subcontractor, since CMP exposure attaches through these defined relationships.
Consider that state law and the HITECH Act may impose additional requirements or enforcement mechanisms beyond HIPAA CMPs, and account for these in your risk assessment.