HHS Increases Civil Penalties for HIPAA Violations

hippalaw

On Jan. 17, 2020, the Department of Health and Human Services (HHS) published a final rule increasing the civil monetary penalties for violations of laws enforced by HHS, including the HIPAA privacy and security rules. HHS is required to adjust these penalties for inflation each year to improve their effectiveness and maintain their deterrent effect. The new penalty amounts are effective for penalties assessed on or after Jan. 17, 2020.

2020 HIPAA Civil Penalties

HHS may assess civil penalties when it discovers a HIPAA violation. The penalty amount depends on the facts involved.

  • For violations where the covered entity does not know about the violation (and by exercising reasonable diligence, would not have known about the violation) the penalty amount is between $119 and $59,522 for each violation.
  • If the violation is due to reasonable cause, the penalty amount is between $1,191 and $59,522 for each violation.
  • For corrected violations that are caused by willful neglect, the penalty amount is between $11,904 and $59,522 for each violation.
  • For violations caused by willful neglect that are not corrected, the penalty amount is $59,522 per violation, with an annual cap of $1,785,651 for all violations of an identical requirement.

Resolution Agreements

Instead of imposing civil penalties for HIPAA violations, HHS will often pursue a resolution agreement that requires the covered entity to take corrective action and pay a settlement amount (which is usually much less than the applicable penalty amount). However, if an agreement cannot be reached, HHS may pursue civil penalties.

Important Dates

Common HIPAA Violations

According to HHS, the compliance problems most frequently reported under HIPAA are:

  • Impermissible uses or disclosures of protected health information (PHI)
  • Lack of safeguards of PHI
  • Lack of patient access to their PHI
  • Lack of administrative safeguards for electronic PHI
  • Use or disclosure of more than the minimum necessary PHI

BecauseHIPAA’scivil penalties are substantial, employers with group health plans should periodically review their compliance with HIPAA’s rules. Download Newsletter

  • Nip Seasonal Allergies in the Bud
    More than 50 million Americans suffer from allergies every year. In particular, springtime allergies...
    LEARN MORE
  • Balancing working from home and caregiving responsibilities
    For many across the country, working from home is their new reality for the...
    LEARN MORE
  • Understanding Your Kidney Health
    March is National Kidney Month, making it a great time to take charge of...
    LEARN MORE
  • Understanding the Value of a Learning Culture
    As employers evaluate how to combat today’s attraction and retention challenges, learning and development...
    LEARN MORE
  • Benefits Offerings to Avoid the Great Resignation
    Employees are walking away from their employers in record numbers; some are calling it...
    LEARN MORE