HIPAA violations and fines: What healthcare organizations need to know

Written by Inês Pimentel

Published August 24, 2026

PHI and PII

Quick summary

HIPAA violations happen when a covered entity or business associate fails to meet the HIPAA Privacy, Security or Breach Notification Rule. Civil penalties range from a few hundred dollars to more than $2 million per violation, set across four tiers based on how much the organization knew. 

What this guide covers: HIPAA violation types, penalty tiers, real enforcement cases and practical risk reduction

Who it’s for: Healthcare marketers, analytics leads, compliance officers, IT and legal teams

HIPAA compliance in marketing is genuinely complicated. The tools healthcare marketers rely on weren’t designed with healthcare regulations in mind, and the line between what’s permitted and what isn’t isn’t always obvious from reading the law.

This guide covers the practical side: how violations happen, what they cost, how enforcement works, and what healthcare marketing and analytics teams can do to reduce their exposure.

Disclaimer: This page is based on publicly available HHS OCR guidance and enforcement records. It is not legal advice. For guidance specific to your organization, consult qualified healthcare privacy counsel.

What is a HIPAA violation?

What counts as a HIPAA violation?

Quick answer

A HIPAA violation occurs when a covered entity or business associate fails to meet the requirements of the HIPAA Privacy Rule, Security Rule, or Breach Notification Rule.

Violations range from administrative gaps – a missing policy or outdated training record – to serious incidents involving large-scale unauthorized disclosure of patient information.

Not every violation leads to a penalty. HHS OCR considers the nature of the issue, harm caused, compliance history, and corrective actions taken when deciding how to respond.

HIPAA violations stem from three rules. Here’s what each one governs and the violations it commonly produces. 

RuleWhat it governsCommon violation types
Privacy RuleHow protected health information (PHI) can be used and disclosedUnauthorized disclosures, missing patient rights processes, sharing with third parties without authorization
Security RuleTechnical, physical, and administrative safeguards for electronic PHI (ePHI)Insufficient access controls, missing encryption, inadequate risk assessments
Breach Notification RuleObligations when PHI is improperly disclosedLate or missing notification, incomplete breach assessment

What is the difference between a violation and a breach?

A breach is a specific type of HIPAA violation – the unauthorized acquisition, access, use, or disclosure of PHI in a way that compromises its security or privacy. Not every breach triggers notification; HIPAA provides a four-factor risk assessment framework to determine whether notification is required.

A violation is broader: any failure to meet a HIPAA requirement, whether or not PHI was actually disclosed. Running an analytics platform and collecting PHI without a business associate agreement (BAA), for example, is a violation even if no data incident occurred.

Who can be held liable for a HIPAA violation?

Both covered entities and their vendors can be held liable. Here’s who HIPAA applies to and how.

Entity typeLiable under HIPAAExamples
Covered entityYesHospitals, health plans, healthcare clearinghouses, most healthcare providers
Business associateYes (since HITECH 2009)Analytics vendors, martech platforms, cloud hosts, billing services handling PHI
Business associate subcontractorYesA subprocessor used by an analytics vendor that handles PHI
Individual employeeYes, in criminal casesEmployees who knowingly access or disclose PHI improperly

HIPAA penalty tiers: What violations cost

How does HHS OCR calculate HIPAA fines?

OCR uses a four-tier penalty structure based on the level of culpability – how aware the organization was of the issue and what they did about it. The same underlying incident can result in very different penalties depending on which tier applies.

Civil penalty tiers

OCR sets civil penalties across four tiers based on how much the organization knew. Amounts adjust for inflation each January.

TierStandardMin per violationMax per violationAnnual cap (OCR enforcement discretion)
Tier 1Did not know, and could not have known with reasonable diligence$145 [orig. $100]$73,011$25,000
Tier 2Reasonable cause – knew or should have known, but not willful neglect$1,461 [orig. $1,000]$73,011$100,000
Tier 3Willful neglect – corrected within 30 days$14,602 [orig. $10,000]$73,011$250,000
Tier 4Willful neglect – not corrected$73,011 [orig. $50,000]$2,190,294$2,190,294

The figures above reflect the amounts effective from January 28, 2026, following HHS’s latest inflation adjustment. Original HITECH Act statutory minimums are shown in brackets for reference.

A note on annual caps: In 2019, OCR issued a Notice of Enforcement Discretion applying lower annual caps for Tiers 1–3 (as shown above). The official inflation-adjusted cap for all tiers is $2,190,294 per identical provision per year – OCR can rescind the discretionary caps at any time. For risk planning purposes, use the official cap, not the discretionary figures.

A note on “per violation”: OCR can treat each individual patient record affected as a separate violation. An improperly configured analytics tag running on a patient portal for several months can generate a large number of individual violations – which is why the annual cap matters more than the per-violation figure in most real cases.

Criminal penalties

The Department of Justice handles criminal cases separately from HHS civil enforcement, with penalties that can include prison time.

TierStandardPenalty
BasicKnowing violationUp to 1 year imprisonment + $50,000 fine
AggravatedViolation under false pretensesUp to 5 years imprisonment + $100,000 fine
Most severeViolation for personal gain or to cause harmUp to 10 years imprisonment + $250,000 fine

What is the largest HIPAA fine on record?

The largest HIPAA settlement on record is $16 million, paid by Anthem, Inc. in 2018 following a series of cyberattacks that exposed the ePHI of nearly 79 million individuals. OCR’s investigation found that Anthem had failed to conduct an enterprise-wide risk analysis, lacked sufficient procedures to review system activity, and failed to implement minimum access controls. 

Most enforcement actions settle at significantly lower amounts, though multi-million-dollar resolutions have become more common as OCR has focused on digital tracking technology in recent years.

The most common HIPAA violations in healthcare marketing 

What violations do healthcare marketing teams most commonly encounter?

The marketing and analytics violations that surface most often in OCR enforcement actions and compliance audits tend to fall into a handful of consistent categories. Here are the most frequent ones, ranked by enforcement risk. 

The most common ones fall into a few categories: analytics tools used without a BAA, PHI leaking through URL parameters, and session recording in patient portals.

Violation typeHow it typically happensEnforcement risk level
Analytics platforms without BAAsStandard analytics tools used on any page where PHI is present without contractual HIPAA protectionsHigh – OCR guidance explicitly addresses this
PHI in URL parametersPage URLs containing condition names, appointment details, or identifiers transmitted to third-party analyticsHigh – discovered through data audits
Session recording in post-login areasScreen capture tools running in authenticated patient portalsHigh – directly captures PHI
Missing or inadequate risk assessmentNo documented periodic risk assessment, or one that doesn’t cover the full analytics stackMedium – OCR requires this as a baseline
Outdated or incomplete BAAsBAAs in place but not updated to reflect HITECH, or missing some vendors in the data chainMedium – typically surfaces during breach investigation
Unauthorized use of patient data for marketingUsing patient data for marketing purposes without valid authorizationMedium-High – OCR scrutinizes this closely

Note: They usually aren’t the result of anyone doing something they knew was wrong. They’re the result of technology decisions that were made without a compliance review, or tools that were set up before the regulatory picture became as clear as it’s today.

Is using Google Analytics on a healthcare website a HIPAA violation?

Quick answer

In most cases where PHI is present, yes. Google Analytics doesn’t offer a BAA for standard use and its terms of service prohibit the use of PHI.

Using GA4 on a patient portal, appointment scheduler, symptom checker, or any page where PHI is present or could be inferred is generally considered an impermissible disclosure of PHI to a third party without HIPAA protections in place.

HHS and the FTC have both issued guidance confirming that tracking technologies on healthcare websites can violate HIPAA when they transmit PHI-related data to platforms that aren’t covered by a BAA.

What are the most common Security Rule violations?

Security Rule violations usually trace back to a missing safeguard. The most common are missing access controls, no risk analysis, unencrypted ePHI and vendors without BAAs.

Security Rule violationWhat was typically missing
Insufficient access controlsNo role-based permissions; no MFA on systems handling PHI
Missing or inadequate risk analysisNo annual assessment; assessment not updated after system changes
No encryptionePHI transmitted or stored without encryption
Insufficient audit controlsNo access logging; logs not reviewed regularly
Missing workforce trainingStaff accessing PHI without documented HIPAA training
No business associate agreementsVendors handling PHI without BAAs

How analytics and tracking tools factor into HIPAA compliance 

Can an analytics platform cause a HIPAA violation?

Quick answer

Yes – when it processes PHI without a BAA in place, or transmits PHI to a third-party platform that isn’t covered by HIPAA protections.

This is an area where well-intentioned marketing teams often find themselves in a difficult position: the tools they’ve been using for years weren’t designed with healthcare compliance in mind, and the regulatory picture around digital tracking has become significantly clearer only in the last few years.

PHI can leak at every layer of a standard analytics stack. Here’s where each risk sits and which tools are involved.

Stack layerTool examplesHow PHI exposure can occur
Web analyticsGoogle AnalyticsFull URL sent to Google servers, including health-related parameters; no BAA available
Advertising pixelsMeta Pixel, Google Ads tagPage URL and user identifiers sent to ad platforms, including health-inferred data
Session recordingHotjar, FullStory, Microsoft ClarityScreen captures in patient portals may record PHI displayed on screen
Tag managementGoogle Tag ManagerTags configured to fire on post-login pages can transmit session data
Marketing automationHubSpot, MarketoHealth data synced to CRM without a BAA constitutes an impermissible disclosure
A/B testingOptimizely, VWOTests on patient-facing pages may capture or transmit PHI
HeatmappingCrazy EggClick and scroll data on health forms may include PHI

What is the HHS guidance on tracking pixels in healthcare?

Quick answer

HHS OCR published its original bulletin on online tracking technologies on December 1, 2022, clarifying that tracking technologies – pixels, cookies, and similar tools – on the websites or apps of HIPAA-covered entities can constitute an impermissible disclosure of PHI when they transmit information about individuals’ health conditions, treatment, or health-seeking behavior to third parties without a BAA.

OCR updated the bulletin on March 18, 2024, providing additional examples to help organizations distinguish when information collected on unauthenticated pages is or isn’t PHI. The update emphasized that simply visiting a general informational page (such as job postings or visiting hours) doesn’t automatically create PHI – but visiting pages related to specific health conditions or services may.

On June 20, 2024, a US District Court for the Northern District of Texas ruled that HHS had exceeded its statutory authority with respect to the parts of the bulletin addressing unauthenticated pages and IP addresses. That portion of the guidance was vacated. The guidance on authenticated pages – patient portals, appointment schedulers, prescription pages – remains in full effect.

Some page types carry more risk than others. Here’s how each stands after the June 2024 court ruling. 

Page typeRisk levelStatus after June 2024 ruling
Patient portals (authenticated)HighFully in effect
Appointment scheduling (authenticated)HighFully in effect
Prescription refill pages (authenticated)HighFully in effect
Symptom checkers with user inputHighLargely in effect
General unauthenticated pagesLowerVacated portion – reduced ambiguity
General marketing and informational pagesLowerVacated portion – reduced ambiguity

Does server-side tracking solve the pixel compliance problem?

Server-side tagging meaningfully reduces the risk of PHI reaching third-party platforms by filtering and controlling data before it leaves your infrastructure. It’s a strong part of a compliant setup – but it still needs to be paired with a HIPAA-compliant analytics platform that will sign a BAA, and the server-side configuration needs to be audited to confirm PHI is being filtered correctly.

Real HIPAA enforcement examples 

What do real HIPAA enforcement actions look like?

Quick answer

They range from multi-million-dollar settlements for large breaches down to five-figure fines for records-access failures.

These real OCR settlement examples below show the range of issues that lead to formal action, and what they cost, drawn from publicly available OCR records.

Type of organizationViolationSettlement amountKey finding
Large health insurerCyberattacks exposing ePHI of ~79 million individuals$16 million (2018)Failed to conduct enterprise-wide risk analysis; no minimum access controls; inadequate system activity review
General hospitalInviting ABC News film crews onto premises without patient authorization$999,000 combined (2018)Impermissible disclosure of PHI to third parties (film crew); failure to implement appropriate safeguards before media access
Health system providerMultiple breaches; employees improperly accessing records$2.15 million (2019)Failure to restrict workforce access; inadequate audit controls
Diagnostic medical imaging centerBreach exposing 300,000+ patient records$3 million (2019)Failure to implement risk analysis and security measures
Small medical practiceFailure to provide patient timely access to recordsVaries ($10,000–$200,000 range across Right of Access cases)Privacy Rule violations; failure to respond to patient access requests within required timeframes

Settlement amounts are from publicly announced HHS OCR resolutions (hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements). They represent negotiated outcomes, not necessarily the maximum penalty that could have applied.

What enforcement activity has involved digital tracking tools?

Between 2022 and 2024, a number of healthcare organizations faced regulatory scrutiny and class action litigation after third-party tracking pixels were discovered on patient-facing websites. The common thread across those situations:

  • Pixels had been installed by marketing teams as standard practice, without a compliance review
  • The pixels were transmitting URL data – including health-related page names and appointment details – to advertising platforms without BAAs
  • The extent of the data transmission wasn’t known until a security audit or media report brought it to light
  • Responses included pixel removal, patient notification, and in some cases significant legal costs

These situations accelerated OCR’s focus on digital tracking and directly informed the 2022 guidance referenced above.

How HHS OCR investigations work 

How does OCR find out about HIPAA violations?

OCR investigations start from several triggers. Here’s what sets each one in motion. 

TriggerWhat happens
Patient complaintIndividual files a complaint with OCR; OCR opens an investigation
Breach report (500+ individuals)Covered entity submits breach report; OCR may investigate
Media coverageHigh-profile incidents reported publicly can prompt OCR review
OCR compliance auditOCR selects organizations for proactive review under its audit program
Employee or whistleblower complaintStaff reports a potential violation to OCR
Annual breach logBreaches affecting fewer than 500 individuals are reported annually; OCR may follow up

What happens during an OCR investigation?

  1. Notice of investigation – OCR notifies the covered entity that a complaint has been received or an audit is underway
  2. Document request – OCR requests policies, procedures, risk assessments, BAAs, training records, and technical documentation
  3. Technical review – OCR may review system configurations and access logs
  4. Findings – OCR issues its findings and identifies any required corrective actions
  5. Resolution – Cases resolve through voluntary compliance, technical assistance, corrective action plans, or formal settlement agreements
  6. Monitoring period – Significant resolutions typically include a corrective action plan with OCR oversight over 2–3 years

What does a corrective action plan typically require?

A corrective action plan usually covers the same core elements. Here’s what each one involves. 

ElementWhat it involves
Risk analysisComprehensive assessment of the full environment, including analytics and martech
Risk management planDocumented plan addressing identified vulnerabilities with timelines
Policy updatesRevised HIPAA policies and procedures
Workforce trainingUpdated training delivered and documented
BAA auditReview and update of all business associate agreements
Ongoing reportingRegular progress reports to OCR during the monitoring period

Reducing your HIPAA violation risk in marketing and analytics 

Where should healthcare marketing teams focus first?

The highest-priority actions are the ones that address the most active enforcement focus areas and the most common sources of inadvertent exposure.

These are the highest-priority actions for marketing teams, ordered by where enforcement is most active. 

PriorityActionWhy it matters
1Audit third-party pixels and tracking tags on patient-facing pagesPixel-related disclosures are the primary current OCR focus
2Confirm BAA status for every analytics and martech vendorNo BAA with a vendor handling PHI is a compliance gap
3Move patient portal and appointment analytics to a HIPAA-compliant platformAddresses the exposure at the source
4Implement URL scrubbing to prevent PHI transmission through parametersCovers a common inadvertent disclosure vector
5Conduct and document a periodic risk assessment that covers your analytics stackRequired by HIPAA; the absence of one is itself a violation
6Update all BAAs to reflect HITECH requirementsOutdated BAAs may not provide the protections you expect
7Train marketing and analytics staff on the HIPAA-specific risks in the tools they useWorkforce training is a required safeguard
8Add a compliance review step before any new martech tool is deployedPrevents new gaps from being introduced

SUCCESS STORY

How Shepherd Center gained HIPAA compliance and full visibility into patient acquisition

Shepherd Center replaced Google Analytics with Piwik PRO to close compliance gaps and get a complete picture of patient acquisition – resulting in a 40% rise in online patient referrals and a 215% increase in page views.

“I really liked how intuitive, easy, and familiar Piwik PRO felt compared to other platforms.”
Chris Walker, Director of Digital Strategy and Marketing, Shepherd Center

What if you discover a potential violation that has already occurred?

Quick answer

Document the discovery, preserve the evidence, involve legal counsel and contain the issue – then run the four-factor risk assessment to determine if it’s reportable. 

Finding a gap in your setup is actually a good outcome – it means you can address it. If your organization discovers a potential violation, the recommended steps are:

  1. Document the discovery – record the date, what was found, and who identified it
  2. Preserve the evidence – avoid deleting logs or configurations before legal and compliance review
  3. Involve legal counsel – breach assessment is a legal determination; qualified guidance matters here
  4. Contain the issue – disable or reconfigure the tool causing the exposure, after documenting its current state
  5. Complete the four-factor risk assessment – this determines whether the incident is a reportable breach
  6. Assess notification obligations – if reportable, the 60-day clock runs from the date of discovery
  7. Review the broader stack – one gap is often a signal that similar issues may exist elsewhere

Get compliant analytics – without giving up marketing visibility

Most healthcare marketers manage the same pressure: compliance rules that limit what can be tracked, and leadership that expects full visibility anyway. Piwik PRO is built to give you both, so your team isn’t choosing between staying compliant and doing their job.

Piwik PRO gives healthcare organizations full marketing analytics visibility within a HIPAA-compliant setup. We sign the BAA, your data stays in your infrastructure, and your team keeps the campaign data, attribution, and behavioral insights it needs to make good decisions.

See what HIPAA-compliant analytics looks like for your organization

Regulatory resources

Frequently asked questions

What is the most common HIPAA violation?

Failure to conduct an adequate risk analysis is the most frequently cited violation in OCR enforcement actions. It’s a required Security Rule safeguard, and many organizations either skip it or complete it without covering their full technology environment – including analytics and marketing tools.

Can a healthcare organization be fined for a violation they didn’t know about?

Yes. Tier 1 penalties apply specifically to violations where the organization didn’t know and couldn’t reasonably have known.

Does HIPAA apply to business associates as well as covered entities?

Yes. Since HITECH, business associates are directly liable for certain HIPAA violations – they can be investigated and fined by OCR independently of the covered entity. Any analytics vendor, martech platform, or cloud provider handling PHI is a business associate and subject to HIPAA enforcement.

What’s the difference between a HIPAA fine and a HIPAA settlement?

A fine is a penalty imposed by OCR through formal proceedings. Most enforcement actions are resolved through settlements – negotiated agreements where the organization pays a resolution amount and agrees to a corrective action plan, without OCR making a formal liability finding. Settlements typically come with monitoring requirements for 2–3 years.

Can patients sue a healthcare organization for a HIPAA violation?

HIPAA doesn’t provide a private right of action – individuals can’t sue directly under HIPAA. However, violations frequently support state law claims including negligence, breach of confidentiality, and consumer protection violations. Class action litigation following digital tracking disclosures has in some cases resulted in settlements that exceed the HIPAA penalties themselves.

What is the OCR “Wall of Shame”?

The HHS Breach Portal is a public database maintained by OCR listing all reported breaches of unsecured PHI affecting 500 or more individuals. It includes the organization name, state, type of breach, and number of individuals affected. Listings are publicly searchable and remain on the portal indefinitely.

How quickly does a healthcare organization need to report a breach?

Affected individuals and HHS OCR must be notified within 60 days of discovering a breach affecting 500 or more individuals. Breaches affecting fewer than 500 individuals can be included in an annual log submitted to HHS by March 1 of the following year. Some state laws have shorter timelines.

Can a marketing vendor’s actions create a HIPAA violation for a healthcare organization?

Yes. If a marketing vendor handles PHI on your behalf, you’re responsible for ensuring that relationship is covered by a BAA. If no BAA exists, sharing PHI with that vendor is itself a violation – regardless of what the vendor does with the data afterward.