The HIPAA Number That Decides Your Penalty Is Not the One in the Headline
Two HIPAA penalty numbers get quoted constantly and both are wrong. Here are the 2026 tiers, and why correcting inside 30 days moves your ceiling from $73,011 to $2,190,294.
Introduction
Ask five people at a medical practice what the maximum HIPAA fine is and you will hear two numbers. One is $1.5 million a year. The other is $2,190,294. Both get quoted in board meetings, both appear in vendor slide decks, and neither is the number that decides what a practice actually pays.
The number that decides it is 30. As in days.
The 2026 penalty tiers, in full
HHS adjusts HIPAA civil money penalties for inflation every January. The current figures took effect 28 January 2026 and were published at 91 FR 3672. They sit in the four HITECH culpability tiers codified at 45 CFR 160.404(b)(2).
| Tier | Culpability | Per violation |
|---|---|---|
| 1 | Did not know, and by exercising reasonable diligence would not have known | $145 to $73,011 |
| 2 | Reasonable cause, not willful neglect | $1,461 to $73,011 |
| 3 | Willful neglect, corrected within 30 days | $14,602 to $73,011 |
| 4 | Willful neglect, not corrected | $73,011 to $2,190,294 |
The calendar-year cap for identical violations, across all four tiers, is $2,190,294. Source: 91 FR 3672, 28 January 2026. Verified 20 August 2026.
Why "$1.5 million" is wrong in both directions
The $1.5 million figure is the original HITECH annual limit before years of inflation adjustment. It is too low: the adjusted calendar-year cap is now $2,190,294.
It is also too high, and this is the part that gets skipped. HHS issued a Notification of Enforcement Discretion in 2019 (84 FR 18151, 30 April 2019) applying substantially lower annual caps to tiers 1 through 3. That notification is still in effect. So a practice budgeting $1.5 million of annual exposure for a good-faith error is overstating the realistic ceiling by a wide margin, while a practice that ignored a known problem is understating it.
The second misquote is worse. $2,190,294 gets repeated as the per-violation maximum. It is not. It is the per-violation ceiling for exactly one tier: willful neglect that was not corrected. Tiers 1, 2, and 3 all stop at $73,011 per violation. If someone quoted you a seven-figure per-violation number for a lost laptop that you encrypted and reported, the arithmetic behind that quote is wrong.
One more thing about all of these numbers. They move every January. A HIPAA penalty figure published without a year attached is stale by default, and a compliance document that hard-codes 2019 dollars is telling you when it was last touched.
Tier 3 and tier 4 are the same conduct
Read those bottom two rows again. Tier 3 is willful neglect. Tier 4 is willful neglect. Same finding, same underlying failure, same bad facts in the investigation file.
The only variable is whether the violation was corrected within 30 days of the date the entity knew, or by exercising reasonable diligence would have known, about it. Correct it, and the ceiling is $73,011. Do not, and the ceiling is $2,190,294. The ceiling moves roughly thirtyfold on the strength of one date.
That reframes what compliance work is worth doing. Policy binders do not move you between those two rows. Three operational capabilities do: you have to find the problem, write down honestly and immediately what you found and when, and be able to finish the fix inside a month.
What a 30-day-executable correction actually requires
Detection you do not depend on a person for. The clock does not start when a staff member finally mentions something. It starts at knew or should have known, which is a diligence standard. Automated log collection and 24/7 monitoring exist largely to establish that date and make it defensible. A practice that discovers an exposed share three months later because a patient complained has already lost the tier 3 argument.
Same-day, honest documentation. The single most damaging habit we see is tidying up the record after the fact: back-dating a ticket, rewriting a note, quietly closing an alert. A messy contemporaneous log that says "14 March, found terminated employee account still active in the EHR, disabled at 10:42" is worth more than a clean reconstruction written in June. The tier 3 argument is a documentary argument.
A remediation path that fits in 30 days. This is where most practices fail on planning rather than intent. Disabling accounts, revoking a vendor credential, encrypting the endpoints you can physically reach, pulling a misconfigured folder off the internet, and issuing corrective training are all 30-day actions. Replacing a practice management system is not. When you write a remediation plan, split it into the part that closes the violation and the part that improves the environment, and make sure the first part has a completion date inside the window. Our approach to cybersecurity for regulated environments is built around that split, and it is the same logic that drives how we scope work for healthcare organizations.
The honest limitation
You do not choose your tier. OCR does. Nothing in your incident response plan lets you self-select tier 3, and any consultant who implies otherwise is selling certainty that does not exist. Investigators weigh the nature of the violation, the harm, your history, and your size, and they are not obligated to accept your characterization of what you knew and when.
What you control is narrow and real: whether the file OCR opens contains a dated record of prompt, documented correction, or a gap. That is it. It is a smaller lever than the marketing suggests, and it is still the highest-value compliance work available to a mid-sized practice.
Texas runs a second clock
Texas practices have obligations that sit on top of HIPAA, and the state versions are frequently tighter.
- Training within 90 days of hire. Tex. Health and Safety Code 181.101 requires PHI training for new employees within 90 days, with a signed statement of attendance retained until the sixth anniversary of the signature.
- Records in 15 business days. Section 181.102 requires electronic health records to be provided within 15 business days of a written request, against HIPAA's general 30-day standard.
- A broader definition of who is covered. Section 181.001 defines covered entity far more expansively than HIPAA does. Businesses that assume they are out of scope federally are often in scope in Texas.
One correction worth making inside your own policy set: the widely repeated Texas rule requiring retraining every two years was repealed by S.B. 1609 in 2013. It still appears in templates circulating today. If your handbook cites it, the handbook has not been reviewed in more than a decade, and that is exactly the kind of detail an investigator notices.
Frequently Asked Questions
What is the maximum HIPAA fine per violation in 2026?
It depends entirely on the tier. Tiers 1, 2, and 3 all cap at $73,011 per violation. Only tier 4, willful neglect that was not corrected, reaches $73,011 to $2,190,294 per violation. The calendar-year cap for identical violations is $2,190,294 across all tiers, though the 2019 enforcement discretion notification applies lower annual caps to tiers 1 through 3.
Is the HIPAA annual penalty cap still $1.5 million?
No. The inflation-adjusted calendar-year cap effective 28 January 2026 is $2,190,294 (91 FR 3672). Separately, the 2019 HHS Notification of Enforcement Discretion (84 FR 18151) remains in effect and applies significantly lower annual caps to the three lower culpability tiers.
How is the 30-day correction period measured?
From the date the covered entity knew, or by exercising reasonable diligence would have known, that the violation occurred. It is not measured from the day someone reported it internally, which is why detection timing and dated records matter more than the response plan itself.
Can we argue our way into tier 3 after the fact?
OCR assigns the tier, not you. What you can influence is the evidence: a contemporaneous, dated record showing the problem was found and corrected promptly. Documentation created after an investigation opens carries far less weight, and inconsistencies in it create their own problems.
Do Texas rules replace HIPAA requirements?
No, they stack. Tex. Health and Safety Code Chapter 181 adds obligations such as training within 90 days of hire and electronic records within 15 business days, and it defines covered entity more broadly than the federal rule. You comply with both.
Why do the penalty numbers keep changing?
HHS is required to adjust civil money penalties for inflation annually, typically published in late January. Any figure you cite should carry its year. If your compliance documents reference amounts from several years ago, they are understating current exposure.
Where to start
If you cannot answer "how would we know, and how fast" for a terminated employee's EHR access, a misconfigured file share, or a lost device, that is the gap worth closing first. A free IT assessment is a reasonable way to find out where your detection and documentation actually stand before a regulator asks.
LayerLogix brings 20+ years of experience and 100% Texas-based support to practices across Greater Houston and Central Texas, with offices in The Woodlands and Round Rock. Call 713-571-2390 to talk through your correction timeline before you need one.
Need Help With Cybersecurity?
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Related Articles
Need Expert IT Support?
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.