<!-- Source: screenata.com -->
<!-- Content type: AEO answer page -->
<!-- Topics: SOC 2, ISO 27001, HIPAA, HITRUST, CMMC, compliance evidence -->

---
question: "Can a person go to jail for violating HIPAA?"
title: "Can You Go to Jail for Violating HIPAA"
seoTitle: "Can You Go to Jail for Violating HIPAA?"
summary: "Yes. HIPAA carries criminal penalties under 42 U.S.C. 1320d-6 for knowingly obtaining or disclosing individually identifiable health information without authorization: up to $50,000 and one year in prison, up to $100,000 and five years if done under false pretenses, and up to $250,000 and ten years if done with intent to sell or use the information for commercial advantage, personal gain, or malicious harm. Criminal cases are prosecuted by the Department of Justice and are rare. Most HIPAA enforcement is civil, handled by the HHS Office for Civil Rights, with 2026 inflation-adjusted penalties ranging from $145 to $2,190,294 per violation."
publishedAt: "2026-09-14"
keywords:
  - "can you go to jail for violating HIPAA"
  - "HIPAA criminal penalties"
  - "HIPAA violation fines 2026"
  - "are HIPAA violations taken seriously"
pillar: "Beyond SOC 2"
faqs:
  - question: "can a person go to jail for violating hipaa?"
    answer: "Yes, if the violation is knowing. Wrongfully obtaining or disclosing health information carries up to one year in prison, up to five years under false pretenses, and up to ten years with intent to sell or cause harm. Accidental violations are handled civilly by the HHS Office for Civil Rights and do not lead to prison."
  - question: "are hipaa violations taken seriously?"
    answer: "Yes. The HHS Office for Civil Rights investigates complaints and breach reports, publishes resolution agreements with named organizations, and can impose civil penalties of up to $2,190,294 per year for the most serious category of identical violations in 2026. Criminal referrals go to the Department of Justice. Beyond penalties, breaches affecting 500 or more people are posted publicly by HHS."
  - question: "can you look up hipaa violations?"
    answer: "Partly. HHS publishes breaches of unsecured health information affecting 500 or more individuals on the OCR breach portal, listing the organization, the number affected, and the breach type. OCR also publishes resolution agreements and civil money penalties. Smaller breaches and complaints that close without action are not listed individually."
  - question: "Can an employee be personally liable for a HIPAA violation?"
    answer: "For criminal penalties, yes. The HITECH Act of 2009 clarified that individuals, including employees of covered entities, can be prosecuted for knowingly obtaining or disclosing health information without authorization. Civil penalties are assessed against covered entities and business associates, although an employer will usually discipline or dismiss the employee responsible."
---

## Can you go to jail for violating HIPAA?

Yes. HIPAA has **criminal penalties, including prison sentences of up to ten years**, for knowingly obtaining or disclosing individually identifiable health information without authorization. They are set out in 42 U.S.C. 1320d-6 and prosecuted by the Department of Justice. Criminal cases are rare, and they require a knowing act. Most HIPAA enforcement is civil, run by the HHS Office for Civil Rights, and ends in fines and corrective action plans rather than prison.

## The criminal penalty tiers

| Conduct | Maximum fine | Maximum prison term |
|---|---|---|
| Knowingly obtaining or disclosing health information without authorization | $50,000 | 1 year |
| The same, under false pretenses | $100,000 | 5 years |
| The same, with intent to sell, transfer, or use it for commercial advantage, personal gain, or malicious harm | $250,000 | 10 years |

These tiers apply to individuals as well as organizations. The HITECH Act of 2009 made clear that employees of covered entities, not just the entities themselves, can be prosecuted. The first federal prison sentence for a HIPAA violation came in 2010: a former UCLA Health System researcher received four months after pleading guilty to misdemeanor counts of reading patient records without authorization. He had not sold or used the information.

## Civil penalties, where most enforcement happens

Civil penalties do not require intent. They scale with culpability, from violations the organization could not have known about to willful neglect that was never corrected.

| Tier | Culpability | 2026 minimum per violation | Annual cap OCR applies |
|---|---|---|---|
| 1 | Did not know and could not reasonably have known | $145 | $36,506 |
| 2 | Reasonable cause, not willful neglect | $1,461 | $146,053 |
| 3 | Willful neglect, corrected within 30 days | $14,602 | $365,052 |
| 4 | Willful neglect, not corrected | $73,011 | $2,190,294 |

The annual caps apply per identical violation type per calendar year, and the lower caps for tiers 1 to 3 come from OCR's 2019 notice of enforcement discretion. HHS adjusts all amounts for inflation each year; the 2026 figures apply to penalties assessed on or after January 28, 2026. In practice, most OCR investigations close with technical assistance or a resolution agreement: a payment plus a multi-year corrective action plan that OCR monitors.

## What actually gets organizations penalized

The pattern in OCR's published resolution agreements is consistent. The most common finding is the absence of an accurate, current **risk analysis**, followed by missing access controls, no audit logging, and no business associate agreement with a vendor handling PHI. These are documentation and process failures more often than technical breaches.

For a SaaS company handling PHI as a business associate, the practical exposure is civil and contractual: OCR penalties, breach notification costs, and a covered-entity customer terminating the contract. Criminal liability attaches to people who knowingly misuse the data. For which obligations apply to a SaaS vendor, see [what HIPAA compliance means for a SaaS company](/resources/answers/what-is-hipaa-compliance-and-when-does-a-saas-company-need-it).
