Skip to main content
Category: OCR Enforcement and Penalties

Per-Violation Penalty

Also known as: Per-Violation Civil Money Penalty, CMP Per Violation
Simply put

A per-violation penalty is a civil monetary penalty assessed for each individual instance in which a rule is broken, rather than as a single lump-sum fine. In the HIPAA context, HHS OCR may impose civil monetary penalties on a per-violation basis, with amounts that fall into tiers based on the level of culpability and that are also subject to an annual cap. The specific dollar amounts are adjusted over time and should be confirmed against current guidance.

Formal definition

A per-violation penalty is a civil monetary penalty (CMP) calculated on the basis of each discrete violation of an applicable law or regulation. Under HIPAA, such penalties are assessed by HHS OCR under the Enforcement Rule according to a tiered structure keyed to the entity's level of knowledge and culpability, with both minimum and maximum per-violation amounts as well as an annual limit for identical violations. The specific per-violation and annual figures are inflation-adjusted periodically and vary by tier; practitioners should verify the exact current amounts against the latest HHS OCR guidance and the applicable regulatory text rather than relying on any single reported range. Note that HIPAA penalty amounts differ from per-violation penalties under other regulatory regimes (for example, FTC penalty offenses or other federal civil penalty statutes), which are governed by separate authorities and figures. This entry addresses civil monetary penalties only and does not cover criminal penalties, which involve separate statutory provisions and enforcement authorities.

Why it matters

Per-violation penalties are significant because they can transform what might seem like a single compliance lapse into substantial cumulative exposure. When HHS OCR counts each affected individual, each unsecured record, or each day a violation persists as a discrete instance, the total penalty can escalate quickly even though the underlying failure may stem from one systemic weakness. This is why compliance officers treat the per-violation structure as a driver of risk that is often more consequential than any single headline figure.

The tiered nature of these penalties reinforces the importance of demonstrable good-faith effort and diligence. Because the tiers are keyed to the entity's level of knowledge and culpability, an organization that can show it did not know and could not reasonably have known of a violation is generally positioned differently than one whose conduct reflects willful neglect. Documentation of reasonable safeguards, risk analysis, and prompt corrective action can therefore materially affect where a violation falls within the tiered structure and, in turn, the potential penalty.

Because the specific dollar amounts are inflation-adjusted over time and vary by tier, practitioners should not rely on any single reported figure or range. Reported ranges in secondary sources can become outdated or reflect only one tier rather than the overall minimum and maximum. Readers should confirm the exact current per-violation and annual amounts against the latest HHS OCR guidance and the applicable regulatory text before assessing exposure.

Who it's relevant to

Compliance and Privacy Officers
These professionals need to understand how per-violation counting can multiply exposure across affected individuals, records, or days. This informs how they prioritize risk analysis, document reasonable safeguards, and pursue prompt corrective action to influence where a violation may fall within the tiered structure.
Legal Counsel and Regulatory Advisors
Counsel advising covered entities and business associates must be precise about which tier a given set of facts implicates and about the distinction between civil monetary penalties and separate criminal provisions. They should confirm current inflation-adjusted amounts against the latest HHS OCR guidance rather than relying on secondary reported ranges.
Executives and Risk Managers
Leadership responsible for organizational risk should recognize that per-violation penalties, combined with annual caps and tiered culpability standards, mean that a single systemic failure can carry cumulative financial consequences. This context supports investment in compliance programs and timely remediation, which may reduce penalties in certain circumstances.
Business Associates and Subcontractors
Entities that handle PHI under a business associate relationship may be subject to HHS OCR enforcement for violations of the obligations that attach to them. Understanding the per-violation penalty structure helps these organizations gauge their own potential exposure independent of the covered entities they serve.

Inside Per-Violation Penalty

Per-Violation Structure
HIPAA civil monetary penalties are generally assessed on a per-violation basis, meaning each distinct instance of noncompliance can be counted separately. A single incident, such as a system misconfiguration affecting many records, may give rise to multiple violations depending on how HHS OCR characterizes the conduct.
Tiered Culpability Framework
The penalty amount per violation generally depends on the entity's level of culpability, which ranges across tiers from no knowledge of the violation, to reasonable cause, to willful neglect that is corrected, to willful neglect that is not corrected. Higher culpability tiers carry higher minimum and maximum per-violation amounts.
Minimum and Maximum Amounts
Each culpability tier has a specified minimum and maximum dollar amount per violation. These figures are inflation-adjusted periodically and differ by tier, so the applicable amount depends on both the tier and the year in which the penalty is determined. Exact current figures should be confirmed against current HHS guidance and the applicable CFR provisions.
Annual Cap
Per-violation penalties for identical violations are subject to an annual maximum (calendar-year cap) that also varies by culpability tier and is inflation-adjusted over time. The cap limits total exposure for repeated instances of the same type of violation within a year.
Enforcing Authority
Civil monetary penalties under HIPAA are imposed by the U.S. Department of Health and Human Services, Office for Civil Rights (HHS OCR), under the Enforcement Rule. Certain knowing violations may also carry separate criminal exposure handled through the Department of Justice, which is distinct from these civil per-violation penalties.

Common questions

Answers to the questions practitioners most commonly ask about Per-Violation Penalty.

Does a single incident or a single mistake count as just one violation?
Not necessarily. A single incident can generate multiple violations, and HHS OCR has historically treated each affected individual or each day a requirement went unmet as a separate violation in certain circumstances. Because the number of violations can multiply quickly, total exposure may be far larger than a single per-violation figure suggests. The specific counting methodology depends on the facts and OCR's discretion, so readers should not assume a one-to-one relationship between an incident and a violation.
Are the per-violation penalty amounts fixed figures I can rely on indefinitely?
No. Per-violation penalty amounts are civil monetary penalties that are adjusted over time for inflation, so any figure cited in a general reference may be outdated. The amounts also vary by culpability tier. Because of this, you should always confirm the current minimum and maximum per-violation amounts and the applicable annual cap against current HHS guidance and the current regulatory text rather than relying on a previously published number.
How do the penalty tiers affect what per-violation amount applies to us?
Per-violation amounts generally increase across culpability tiers, which are based on factors such as whether the entity knew or should have known of the violation and whether it resulted from willful neglect that was or was not corrected. The tier that OCR applies drives both the minimum and maximum per-violation range for your situation. Determining the applicable tier is a fact-specific analysis, so you should document your knowledge, diligence, and corrective actions and verify the current tier amounts against current OCR guidance.
Is there a limit on how much we can be penalized for the same requirement in a year?
Generally there is an annual cap that limits total penalties for identical or related violations of the same requirement within a calendar year, and these caps are tiered and inflation-adjusted like the per-violation amounts. The cap does not eliminate exposure, because violations of different requirements can each carry their own cap. Confirm the current cap figures against current HHS guidance, as they change over time.
What factors can influence the per-violation amount OCR ultimately assesses?
OCR generally considers factors such as the nature and extent of the violation, the resulting harm, the entity's history of prior compliance or violations, its financial condition, and whether it took timely corrective action. These factors can move the assessed amount within the applicable tier's range. Maintaining evidence of good-faith compliance efforts and prompt remediation is therefore practically important, though it does not guarantee a particular outcome.
Does achieving HITRUST certification or another framework reduce our per-violation penalty exposure?
HITRUST certification and similar frameworks are not legal requirements and do not by themselves establish HIPAA compliance or set penalty amounts, which are governed by HIPAA regulation and applied by HHS OCR. That said, documented control implementation and diligence may be relevant evidence when OCR weighs culpability and corrective action. Note also that the HITECH Act and state laws may impose additional or separate penalties beyond HIPAA's per-violation structure, so exposure should be evaluated across all applicable authorities.

Common misconceptions

A single breach or incident results in only one penalty.
Because penalties are generally assessed per violation, one incident can be counted as many violations, often tied to the number of affected records or the duration of noncompliance. Total civil exposure is also bounded by the applicable annual cap for identical violations.
The per-violation dollar amounts are fixed and stay the same each year.
The minimum and maximum per-violation amounts, and the annual caps, are inflation-adjusted periodically and vary by culpability tier. Any specific figure should be verified against current HHS OCR guidance and the applicable regulatory text at the time of assessment.
Achieving HITRUST CSF certification eliminates per-violation penalty exposure.
HITRUST is a private framework and its certification is not a legal requirement and does not by itself establish HIPAA compliance. HHS OCR assesses penalties based on HIPAA obligations and culpability; a certification may support a compliance narrative but does not guarantee avoidance of penalties.

Best practices

Treat each affected record and each instance of noncompliance as potentially distinct violations when estimating exposure, since penalties are generally assessed per violation and can accumulate.
Document good-faith compliance efforts, risk analyses, and remediation, as culpability tier (from no knowledge through uncorrected willful neglect) strongly influences per-violation amounts.
Address identified deficiencies promptly, since correcting violations attributable to willful neglect within the required period can place conduct in a lower penalty tier than uncorrected willful neglect.
Verify current minimum, maximum, and annual cap figures against the latest HHS OCR guidance and applicable CFR provisions rather than relying on prior-year amounts, because these figures are inflation-adjusted over time.
Do not assume state law or HITECH obligations are covered by HIPAA analysis alone; confirm whether additional state privacy requirements or separate penalties may apply beyond federal civil monetary penalties.
Coordinate with legal counsel early when a potential violation involves possible willful neglect or knowing conduct, since criminal exposure handled by the Department of Justice is separate from HHS OCR civil per-violation penalties.