ArticleCompliance & HIPAA

HIPAA's $1.5M Cap Is Not the Real Number. Neither Is $2.19M.

Two HIPAA annual penalty caps are operative at once: $2,190,294 in regulation and $1.5 million in enforcement policy. Most summaries quote one and get it wrong.

SurfacerIQ TeamAugust 7, 20268 min read
HIPAA's $1.5M Cap Is Not the Real Number. Neither Is $2.19M.

Search for the HIPAA annual penalty cap and you will find two different numbers presented with equal confidence. One set of sources says $1.5 million. Another says $2,190,294. A third quotes $1.5 million and then, a paragraph later, cites the inflation-adjusted per-violation maximums that belong to the other framework entirely.

Both numbers are real. They come from different instruments, they do different work, and they are operative at the same time in different senses. If you are the person who will be asked about this in a board meeting or a due diligence call, the distinction is worth getting exactly right — and most published summaries do not.

Two caps, two instruments

The first number comes from regulation. 45 CFR § 160.404, which implements 42 U.S.C. § 1320d-5, sets the civil money penalty ranges. Those amounts are adjusted for inflation every year. Per the HHS Annual Civil Monetary Penalties Inflation Adjustment published January 28, 2026, the calendar-year cap sits at $2,190,294.

The second number comes from enforcement policy. In the Notification of Enforcement Discretion Regarding HIPAA Civil Money Penalties, 84 Fed. Reg. 18151 (April 30, 2019), HHS said it would apply a lower, tier-specific set of annual limits — topping out at $1,500,000 for the most culpable tier and dropping to $25,000 for the least.

Here is the part that gets dropped: HHS was explicit that the 2019 notice is an exercise of enforcement discretion, not a change to the regulation, and that it expects to address the question through future rulemaking. The regulation was not amended. The lower caps describe how the agency has said it intends to exercise its authority, pending that rulemaking. That is a meaningful thing to rely on and a different thing from a binding ceiling.

So: quoting $2,190,294 without the 2019 notice overstates what OCR has said it will do. Quoting $1.5 million without the regulation understates what the rule on the books permits, and quotes a figure in its original, unadjusted dollars. You need both.

What the regulation says

These are the amounts published in the January 28, 2026 inflation adjustment for the penalty tiers at 45 CFR § 160.404.

Culpability tierMinimum per violationMaximum per violationCalendar-year cap
Reasonable cause$145$73,011$2,190,294
Willful neglect, corrected$14,602$73,011$2,190,294
Willful neglect, not corrected$73,011$2,190,294$2,190,294
Violations occurring before Feb. 18, 2009$198$49,848

Two things to notice. First, in the top tier the per-violation maximum and the annual cap are the same figure, which means a single violation at the ceiling exhausts the annual limit for that provision by itself. Second, the pre-2009 line is a legacy row for conduct predating the HITECH tier structure; it is not a fourth modern tier.

The lowest culpability tier — the covered entity did not know and, exercising reasonable diligence, would not have known — exists in the statute and appears in the 2019 notice below. We have not reproduced an adjusted figure for it here, because we are only publishing amounts we can point at directly.

What OCR has said it will actually apply

These are the original, unadjusted figures as published in the 2019 Notification of Enforcement Discretion. Inflation adjustment applies to the amounts codified in the regulation, so do not treat the numbers below as today's dollars.

Culpability tierMinimum per violationMaximum per violationAnnual cap
No knowledge$100$50,000$25,000
Reasonable cause$1,000$50,000$100,000
Willful neglect, corrected$10,000$50,000$250,000
Willful neglect, not corrected$50,000$50,000$1,500,000

The structural point in this table is the spread. Under the 2019 framework, the difference between the top and bottom annual caps is sixtyfold, and the difference between willful neglect corrected and willful neglect not corrected is a factor of six. Whether you found the problem and fixed it is not a mitigating detail. It is a tier boundary.

Why "per violation" is the number that actually drives exposure

Compliance officers anchor on the cap because it is the largest number on the page. It is also the least useful one, for three reasons.

The cap is not a total. Under 45 CFR § 160.404, the annual limit applies to violations of an identical requirement or prohibition within a calendar year. Failing to conduct a risk analysis and failing to obtain a valid authorization are violations of different provisions. Each carries its own annual limit. An organization with deficiencies across several requirements does not have one ceiling; it has several.

The cap is annual. A control gap that persisted across three calendar years is not measured against one cap. Duration is not a narrative detail that shows up in the corrective action plan. It is a multiplier on the structure itself.

"Per violation" often means per person, per disclosure, or per call. The unit of counting is where scale enters. OCR's own case descriptions are built around scope: 197,986 individuals in one matter, 150 patients in another, approximately 15 million individuals in a third.

What OCR does not publish is a formula. Which is why the actual outcomes look nothing like a multiplication table.

What enforcement actually looks like

Four recent matters, in the agency's own words.

  • Warby Parker — a $1,500,000 civil money penalty imposed in December 2024 and announced February 20, 2025. Not a settlement: a CMP. OCR cited the failure to conduct an accurate and thorough risk analysis, insufficient security measures, and the failure to regularly review information system activity records. 197,986 individuals. The amount happens to match the pre-inflation top-tier annual cap in the 2019 notice; read that as an illustration of scale, not as a formula.
  • Cadia Healthcare Facilities — $182,000, September 30, 2025. Patient "success stories," including names, photographs, and treatment and recovery details, posted to public websites without valid HIPAA authorization. 150 patients. Two-year corrective action plan, including training for marketing personnel.
  • MMG Fusion, LLC — $10,000, March 5, 2026. A business associate, not a covered entity. Approximately 15 million individuals; the breached data included names, phone numbers, addresses, email, date of birth, and appointment details. Three-year corrective action plan.
  • Solara Medical Supplies — $3,000,000, January 14, 2025, arising from phishing and cybersecurity failures. And Oregon Health & Science University — $200,000, March 6, 2025, on Right of Access.

Put those side by side. Fifteen million individuals produced $10,000. One hundred fifty patients produced $182,000. Affected headcount sets the theoretical ceiling; it does not predict the outcome. Conduct, culpability tier, correction, and the entity's circumstances do the work.

For context on the enforcement base rate: as of October 31, 2024, OCR reported 374,321+ complaints received since April 2003, 152 cases resolved with settlements or civil money penalties totaling $144,878,972, and 2,419 criminal referrals to the Department of Justice. The top alleged issue is impermissible uses and disclosures of PHI.

One hundred fifty-two monetary resolutions against 374,321 complaints is a low conversion rate. It is not zero, and the Cadia matter — a marketing team publishing patient stories — is the kind of conduct that occurs in home health, home care, and hospice organizations without anyone experiencing it as a security incident.

What to actually do with this

Know which framework a number is quoting. When a vendor, broker, or consultant hands you a cap figure, ask whether it comes from 45 CFR § 160.404 as adjusted, or from the 2019 enforcement discretion notice. If they cannot say, discount everything else in the deck.

Stop budgeting against the cap. The useful exercise is an inventory of the distinct requirements you could plausibly be found to have violated, because each one carries its own annual limit. One number on a risk register is not a model of your exposure.

Fix what OCR keeps naming. Across these matters the recurring findings are unremarkable: no accurate and thorough risk analysis, no regular review of information system activity records, and disclosure without valid authorization. None of those require a novel threat to trigger.

Treat duration as the variable you control. You do not choose whether a gap exists. You choose how long it exists before you find it, and the corrected/not-corrected boundary is worth a factor of six in the 2019 structure and roughly five times the per-violation minimum in the current regulation.

Include business associates in scope. MMG Fusion was a business associate and was resolved directly. If your vendor diligence stops at a signed BAA, see The Security Questions You Should Ask Any Healthcare SaaS Vendor Before Signing.

Look at your interaction channels. For agencies where most PHI moves by phone, the counting unit and the recording rules are the practical issues; we covered the latter in HIPAA Call Recording Compliance: A 2026 Guide for Healthcare Operators.

The counting problem is an evidence problem

If "per violation" can mean per call or per disclosure, then the difference between one incident and a pattern is whether you know what was actually said across your interactions — and most organizations cannot answer that about last quarter, let alone about a period an investigator defines for them. That gap is the problem SurfacerIQ exists to close.

This is general information, not legal advice; penalty exposure is fact-specific and depends on conduct, culpability, and circumstances your counsel is better positioned to assess.

If you want to talk through how your organization would evidence what happened on its calls during a defined period, talk to us.

See SurfacerIQ in action

Calls in. Tickets out. Automatically. See how it works on a real call.