Beyond SOC 2
Can a person go to jail for violating HIPAA?
Can you go to jail for violating HIPAA?
Yes. HIPAA has criminal penalties, including prison sentences of up to ten years, for knowingly obtaining or disclosing individually identifiable health information without authorization. They are set out in 42 U.S.C. 1320d-6 and prosecuted by the Department of Justice. Criminal cases are rare, and they require a knowing act. Most HIPAA enforcement is civil, run by the HHS Office for Civil Rights, and ends in fines and corrective action plans rather than prison.
The criminal penalty tiers
| Conduct | Maximum fine | Maximum prison term |
|---|---|---|
| Knowingly obtaining or disclosing health information without authorization | $50,000 | 1 year |
| The same, under false pretenses | $100,000 | 5 years |
| The same, with intent to sell, transfer, or use it for commercial advantage, personal gain, or malicious harm | $250,000 | 10 years |
These tiers apply to individuals as well as organizations. The HITECH Act of 2009 made clear that employees of covered entities, not just the entities themselves, can be prosecuted. The first federal prison sentence for a HIPAA violation came in 2010: a former UCLA Health System researcher received four months after pleading guilty to misdemeanor counts of reading patient records without authorization. He had not sold or used the information.
Civil penalties, where most enforcement happens
Civil penalties do not require intent. They scale with culpability, from violations the organization could not have known about to willful neglect that was never corrected.
| Tier | Culpability | 2026 minimum per violation | Annual cap OCR applies |
|---|---|---|---|
| 1 | Did not know and could not reasonably have known | $145 | $36,506 |
| 2 | Reasonable cause, not willful neglect | $1,461 | $146,053 |
| 3 | Willful neglect, corrected within 30 days | $14,602 | $365,052 |
| 4 | Willful neglect, not corrected | $73,011 | $2,190,294 |
The annual caps apply per identical violation type per calendar year, and the lower caps for tiers 1 to 3 come from OCR's 2019 notice of enforcement discretion. HHS adjusts all amounts for inflation each year; the 2026 figures apply to penalties assessed on or after January 28, 2026. In practice, most OCR investigations close with technical assistance or a resolution agreement: a payment plus a multi-year corrective action plan that OCR monitors.
What actually gets organizations penalized
The pattern in OCR's published resolution agreements is consistent. The most common finding is the absence of an accurate, current risk analysis, followed by missing access controls, no audit logging, and no business associate agreement with a vendor handling PHI. These are documentation and process failures more often than technical breaches.
For a SaaS company handling PHI as a business associate, the practical exposure is civil and contractual: OCR penalties, breach notification costs, and a covered-entity customer terminating the contract. Criminal liability attaches to people who knowingly misuse the data. For which obligations apply to a SaaS vendor, see what HIPAA compliance means for a SaaS company.