The penalties for HIPAA non-compliance can range from $100 to $50,000 per person to almost $1.5 million. Not complying with the Security Rule can also result in jail time.
The violations are broken into four tiers:
- Tier 1 – It applies when the entity is in a situation where they did not know about the breach. The penalty is $100 to $50,000 per violation.
- Tier 2 – It applies when the entity knew about the diligence but did not act with willful neglect. The penalty ranges from $1,000 to $50,000.
- Tier 3 – It applies when an entity has acted with willful neglect;however, the problem or issue has been corrected. The penalty ranges from $10,000 to $50,000.
- Tier 4 – It applies when the entity has acted with willful neglect and failed to solve the issue. The penalty ranges from $50,000 to $1.5 million.