Skip to main content
Category: OCR Enforcement and Penalties

Willful Neglect Uncorrected (Tier 4)

Also known as: Tier 4 Violation, Willful Neglect Not Corrected, Willful Neglect (Uncorrected)
Simply put

Willful Neglect Uncorrected, often called Tier 4, is the most serious category of HIPAA violation under the penalty structure applied by HHS OCR. It generally applies when a violation results from conscious, intentional disregard of HIPAA obligations and the entity fails to fix the problem within the required correction period. Because both the intent and the failure to correct are present, this tier typically carries the highest per-violation penalties.

Formal definition

Willful Neglect Uncorrected (Tier 4) is the highest culpability tier in HIPAA's civil monetary penalty framework as administered by HHS OCR. It applies when a violation is attributable to willful neglect, generally understood as conscious, intentional failure or reckless indifference to a HIPAA requirement, and the violation is not corrected within the applicable statutory correction window. This tier is distinguished from Tier 3 (willful neglect that is timely corrected) precisely by the failure to remediate; note that HHS is generally prohibited from imposing penalties for violations corrected within a defined period (commonly cited as 30 days) except in willful neglect cases. Per-violation and annual penalty amounts for this and other tiers are set by statute and regulation, are adjusted over time for inflation, and should be confirmed against current HHS guidance rather than treated as fixed. This entry addresses HIPAA civil monetary penalties only; it does not cover potential criminal liability, and state law or the HITECH Act may impose additional or differing requirements.

Why it matters

Willful Neglect Uncorrected sits at the top of HIPAA's four-tier civil penalty structure, and it represents the scenario HHS OCR treats most seriously: an entity that consciously disregarded or was recklessly indifferent to a HIPAA requirement and then failed to fix the problem within the applicable correction window. Because both the culpable intent and the failure to remediate are present, this tier generally carries the highest per-violation penalties of any category. For compliance leaders, it is the outcome that a well-run compliance program is designed to avoid entirely.

What often distinguishes Tier 4 from lesser tiers is not the initial mistake but the response to it. HHS is generally prohibited from imposing penalties for violations corrected within a defined period, commonly cited as 30 days, except in cases of willful neglect. In practice, this means that identifying a deficiency and letting it persist unaddressed can move an organization from a posture where penalties may be avoided into the most severe penalty category. Documentation of prompt, good-faith remediation is therefore a meaningful protective factor.

Specific per-violation and annual penalty figures for this tier are set by statute and regulation and are adjusted over time for inflation, so any dollar amounts cited in secondary sources should be confirmed against current HHS guidance rather than treated as fixed. This entry addresses civil monetary penalties only; it does not cover potential criminal liability, and the HITECH Act or state law may impose additional or differing requirements.

Who it's relevant to

Compliance and Privacy Officers
Those responsible for HIPAA compliance programs should treat Tier 4 as the outcome their processes are designed to prevent. Timely identification and documented remediation of known deficiencies is central, since the failure to correct within the applicable window is what elevates a violation into this most severe category.
Security Officers and IT Leadership
Security personnel who become aware of gaps, whether in administrative, physical, or technical safeguards, should ensure those gaps are tracked and addressed within the applicable correction period. Persistent, unaddressed deficiencies can support a finding of willful neglect that is not corrected.
Covered Entities and Business Associates
Both covered entities and business associates are subject to HIPAA's civil penalty framework as enforced by HHS OCR. Understanding that prompt correction can, in many cases, avoid penalties entirely, while a failure to correct in willful neglect cases can trigger the highest tier, helps prioritize remediation resources.
Legal Counsel and Executives
Legal and executive leadership should recognize that Tier 4 carries the highest per-violation civil penalties, that specific amounts are adjusted over time and must be confirmed against current HHS guidance, and that this civil framework is separate from potential criminal liability and from additional requirements that the HITECH Act or state law may impose.

Inside Willful Neglect Uncorrected (Tier 4)

Willful Neglect (Statutory Concept)
A HIPAA culpability category defined generally as conscious, intentional failure or reckless indifference to the obligation to comply with a HIPAA requirement. It represents a higher degree of fault than reasonable cause or lack of knowledge, and is assessed by HHS OCR during enforcement.
Uncorrected Component
The distinguishing feature of Tier 4: the violation attributed to willful neglect was not corrected within the applicable time period following discovery. Failure to remediate elevates the matter beyond the willful neglect that is timely corrected tier.
Highest Penalty Tier
Tier 4 generally corresponds to the most severe civil monetary penalty tier under the HIPAA Enforcement Rule. Specific per-violation and annual cap figures are adjusted over time and should be confirmed against current HHS OCR guidance rather than treated as fixed amounts.
Enforcement Authority
Civil monetary penalties for this tier are imposed by HHS OCR under the HIPAA Enforcement Rule. This tier addresses civil enforcement and is distinct from any criminal penalties, which may involve other authorities.
Applicability to Covered Entities and Business Associates
The tiered penalty structure generally applies to both covered entities and business associates that are directly liable for applicable HIPAA violations. Liability attaches based on the entity's defined role and obligations, not merely because it handles data.

Common questions

Answers to the questions practitioners most commonly ask about Willful Neglect Uncorrected (Tier 4).

Does willful neglect uncorrected apply only to intentional violations of HIPAA?
No. Willful neglect is generally defined as conscious, intentional failure or reckless indifference to the obligation to comply with a HIPAA requirement, but it does not require an intent to cause harm or an intent to violate the rule itself. The distinguishing feature of the uncorrected tier is that the violation was not corrected within the applicable time period after the entity knew or should have known of it. This is separate from the question of whether the underlying conduct was deliberate. Readers should confirm the specific culpability standards and correction timeframes against the current HIPAA Enforcement Rule text.
Is the penalty amount for a Tier 4 violation a fixed figure I can rely on?
No. Civil monetary penalty tiers, minimum and maximum per-violation amounts, and annual caps under the HIPAA Enforcement Rule are subject to periodic inflation adjustments and other updates by HHS. Any specific dollar figure should be treated as time-sensitive and confirmed against the current regulation and OCR guidance rather than relied upon from a static reference. This entry describes Tier 4 as the highest culpability category but does not fix a permanent penalty amount.
How does the correction period affect whether a violation is classified as Tier 3 versus Tier 4?
The distinction generally turns on whether a violation attributable to willful neglect was corrected within the applicable time period following discovery. A willful neglect violation that is timely corrected is typically treated under the corrected (Tier 3) category, while one that is not corrected within that window falls into the uncorrected (Tier 4) category. Because the specific correction timeframe is set by regulation, entities should verify the current period and what counts as adequate correction against the applicable Enforcement Rule provisions.
What should a covered entity or business associate do immediately upon discovering a potential willful neglect situation?
As a general practical matter, an organization that identifies a compliance failure should document the discovery date, promptly assess and remediate the underlying deficiency, and preserve evidence of the corrective actions taken and their timing. Because the uncorrected tier hinges on failure to correct within the applicable period, timely and documented remediation is central to avoiding escalation to the highest tier. Specific obligations and timelines should be confirmed against the current Enforcement Rule and any applicable OCR guidance, and legal counsel is typically advisable when Tier 4 exposure is a concern.
Does maintaining a HITRUST CSF certification prevent a finding of willful neglect?
No. HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance or shield an entity from an OCR enforcement finding. A robust control program may support an organization's demonstration of reasonable diligence, but the culpability determination is made by HHS OCR under the HIPAA Enforcement Rule based on the facts, not on any private certification status. Entities should not treat certification as a guarantee against a willful neglect finding.
How does documentation help demonstrate that a violation does not rise to willful neglect uncorrected?
Because the uncorrected tier depends on both the culpability standard and the failure to correct within the applicable period, contemporaneous documentation is generally important. Records showing when a deficiency was discovered, the reasonable diligence exercised beforehand, and the corrective steps taken and their dates can help an organization show that any violation was addressed rather than left uncorrected. What is ultimately persuasive is determined by OCR under the current Enforcement Rule, so organizations should align their documentation practices with current regulatory expectations and verify requirements against the applicable text.

Common misconceptions

The penalty amounts for Tier 4 are fixed and can be quoted precisely from a single figure.
Civil monetary penalty amounts and annual caps are periodically adjusted for inflation and revised through HHS guidance. Practitioners should verify current per-violation ranges and caps against the current regulatory text and OCR guidance rather than relying on a memorized figure.
Any serious or costly HIPAA violation automatically falls into the willful neglect uncorrected tier.
Tier placement depends on the entity's culpability (such as lack of knowledge, reasonable cause, or willful neglect) and, for willful neglect, whether the violation was corrected. A violation involving no willful neglect, or one corrected within the applicable period, would generally fall into a lower tier.
Holding a HITRUST CSF certification prevents an organization from being placed in this tier.
HITRUST is a private organization and the HITRUST CSF is a certifiable control framework; certification is not a legal requirement and does not by itself establish HIPAA compliance or immunity from enforcement. OCR determines tier placement based on its own findings regarding compliance and correction.

Best practices

Establish and document a formal process to promptly investigate, remediate, and record correction of identified HIPAA violations, since timely correction is what generally distinguishes this tier from the willful-neglect-corrected tier.
Maintain evidence of good-faith compliance efforts, including risk analyses and safeguard implementation, to reduce the likelihood of an OCR determination of willful neglect.
Track discovery dates and internal correction timelines for potential violations so that remediation occurs within the applicable period rather than lingering uncorrected.
Confirm current civil monetary penalty ranges and annual caps against the latest HHS OCR guidance and regulatory text before relying on any specific figure in planning or reporting.
Clarify direct HIPAA liability for both covered entities and business associates in agreements and internal policies so remediation responsibilities are assigned and not overlooked.
Do not treat control-framework certifications such as HITRUST as a substitute for demonstrable HIPAA compliance and correction, and account for potential additional obligations under HITECH and applicable state law.