HITECH 4-tier CIVIL MONETARY PENALTIES (CMP) + enforcement (Section 17939; 45 CFR 160.404; inflation-adjusted annually). HHS OCR ENFORCEMENT AUTHORITY: HHS Office for Civil Rights (OCR) primary federal enforcer; tier-based CMPs per HIPAA Privacy + Security Rule + Breach Notification Rule violations. 4-TIER CMP STRUCTURE: TIER 1 - did not know (and through exercise of reasonable diligence would not have known) USD 100-50K per violation, USD 25K annual maximum per category (2009 amounts; inflation-adjusted to USD ~50K-USD ~134K cap as of 2024). TIER 2 - violation due to reasonable cause + not willful neglect USD 1K-50K per violation, USD 100K annual cap (adjusted to USD ~144K-USD ~287K cap). TIER 3 - violation due to willful neglect that was CORRECTED within 30 days USD 10K-50K per violation, USD 250K annual cap (adjusted to USD ~287K-USD ~430K cap). TIER 4 - violation due to willful neglect that was NOT CORRECTED within 30 days USD 50K per violation, USD 1.5M annual cap per category (adjusted to USD ~1.99M cap). NOTE: per category means per provision (e.g. breach + privacy + security separate categories) + annual cap per category. STATE ATTORNEYS GENERAL ENFORCEMENT (Section 17939(g)): state AGs may bring civil action in federal district court on behalf of state residents to enforce HIPAA Privacy + Security Rule violations; remedies + statutory damages USD 100 per violation + injunctive relief + attorneys' fees + costs; state AGs may not bring action without first consulting HHS OCR. RECENT HHS OCR ENFORCEMENT SETTLEMENTS: Anthem USD 16M (2018, largest HIPAA settlement); Premera Blue Cross USD 6.85M (2020); Excellus Health Plan USD 5.1M; Memorial Healthcare USD 5.5M; Advocate Health Care USD 5.55M; Banner Health USD 1.25M; Touchstone Medical Imaging USD 3M; Memorial Hermann USD 2.4M; Massachusetts General USD 1M; OCR Right of Access Initiative (2019+) multiple penalties USD 30K-USD 240K for failure to provide timely electronic access; ransomware-related settlements + corrective action plans + ongoing audit program. CRIMINAL SANCTIONS (42 USC 1320d-6): knowing violations up to USD 50K + 1 year imprisonment; false pretenses USD 100K + 5 years; intent to sell/transfer/use for commercial advantage USD 250K + 10 years; Department of Justice enforces criminal sanctions. OCR HIPAA AUDIT PROGRAM (Section 17940): periodic compliance audits of covered entity + BA; Phase 1 + Phase 2 audits completed; Phase 3 ongoing including ransomware + breach response + privacy + electronic access readiness.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.