Skip to main content
Guide

HIPAA Marketing Penalties: A Reference Table

The 2026 HIPAA civil penalty tiers, the criminal tiers, and every marketing-related enforcement action OCR has resolved, with the dollar figure attached to each.

9 min read

HIPAA marketing penalties run from $145 to $2,190,294 per violation category per year under the civil monetary penalty tiers effective January 28, 2026, and the marketing cases OCR has actually resolved have landed between $10,000 and $182,000. Criminal exposure tops out at ten years. Those regulatory numbers are usually the smaller line, because class actions over website tracking have cost individual health systems eight figures. Curve is HIPAA-compliant ad tracking, attribution, and analytics with a signed BAA on every plan, built so marketing data never becomes the disclosure that opens one of these files.

The civil monetary penalty tiers

OCR assesses civil monetary penalties on a four-tier structure set by the HITECH Act and adjusted for inflation each year. The amounts below took effect on January 28, 2026. The annual cap applies per violation category, per calendar year, which means a single incident that breaches several requirements can be assessed several times over.

  • Tier 1, lack of knowledge. The entity did not know and, exercising reasonable diligence, would not have known of the violation. Minimum $145 per violation, maximum $36,505.50 per violation, annual cap $36,505.50.
  • Tier 2, reasonable cause. The violation was due to reasonable cause and not willful neglect. Minimum $1,461 per violation, maximum $73,011 per violation, annual cap $146,053.
  • Tier 3, willful neglect corrected within 30 days. Minimum $14,602 per violation, maximum $73,011 per violation, annual cap $365,052.
  • Tier 4, willful neglect not corrected. Minimum $73,011 per violation, maximum $2,190,294 per violation, annual cap $2,190,294.

Two things about that structure matter more than the headline maximum. First, tier placement turns on what you knew and when you fixed it, not on how many records were involved. Second, "per violation" in a tracking case is not obviously one violation. OCR has discretion in how it counts, and an impermissible disclosure affecting a million patients is not automatically a million violations, but it is also not automatically one.

The criminal tiers

Criminal penalties under 42 U.S.C. 1320d-6 are charged by the Department of Justice, not OCR, and they attach to individuals as well as organizations.

  • Knowing disclosure. Up to $50,000 and up to one year in prison.
  • Under false pretenses. Up to $100,000 and up to five years.
  • For commercial advantage, personal gain, or malicious harm. Up to $250,000 and up to ten years.

Criminal referrals in marketing contexts are rare. They are worth knowing about because the third tier names commercial advantage explicitly, and selling or trading patient lists is squarely inside it.

What HIPAA counts as marketing

The definition sits at 45 CFR 164.501 and the authorization requirement at 45 CFR 164.508(a)(3). Marketing is a communication about a product or service that encourages the recipient to buy or use it. Using or disclosing PHI for marketing requires a written, signed authorization from the individual first, and if the covered entity is being paid by a third party for the communication, the authorization has to say so.

The carve-outs are narrower than most marketing teams assume. Face-to-face communication with the individual does not require authorization. Neither does a promotional gift of nominal value. Communications about the entity's own health-related products and services, about treatment, and about case management fall outside the marketing definition entirely, which is why appointment reminders and refill notices are permitted.

What is not carved out: a testimonial on your website, a before-and-after photo in an ad, a patient list handed to an agency, or a detail about a specific patient posted in reply to a review. Each of those is a use or disclosure of PHI for marketing, and each requires an authorization that names the use.

Marketing-related enforcement actions on record

This is the useful reference, because it shows what OCR has actually charged rather than what the statute permits. Every figure below is from a published OCR resolution agreement or civil monetary penalty notice.

  • Elite Dental Associates, $10,000, October 2019. Settlement. The Texas practice replied to Yelp reviews with patient names, treatment details, and insurance information.
  • U. Phillip Igbinadolor, DMD and Associates, $50,000, March 2022. Civil monetary penalty, not a settlement. The North Carolina practice posted a patient's PHI on a public webpage in response to a negative online review.
  • Northcutt Dental-Fairhope, $62,500, March 2022. Settlement. The owner gave a political campaign manager a spreadsheet with the names and addresses of 3,657 patients, then used a third-party marketing company to email a total of 5,385 individuals. This is the purest marketing-list case OCR has published.
  • New Vision Dental, $23,000, December 2022. Settlement. The California practice disclosed names, treatment, and insurance information in responses to unfavorable Yelp reviews.
  • Manasa Health Center, $30,000, June 2023. Settlement. The New Jersey psychiatric provider disclosed a patient's diagnosis and treatment information in a reply to a negative review.
  • Cadia Healthcare, $182,000, 2025. Settlement. Five Delaware facilities posted resident success stories on social media, including photographs of roughly 150 residents, without HIPAA-compliant authorizations, and then failed to notify the affected individuals.
  • Raleigh Orthopaedic Clinic, $750,000, April 2016. Settlement. Not a marketing case, but the closest analogue on the vendor side: the clinic handed x-ray films covering 17,300 patients to a vendor on an oral agreement, with no BAA in place. The disclosure itself was the violation.

The pattern is consistent. Small practices, small dollar amounts, and almost always a single visible act: a review reply, a photo, a list. OCR does not need a hacker to open a file. It needs a complaint.

The larger numbers sit outside OCR

Treating the OCR tiers as your exposure ceiling understates the picture considerably. Three other channels have produced bigger figures.

Private class actions

Website tracking suits are brought under state wiretap and privacy statutes rather than HIPAA, which has no private right of action. Advocate Aurora Health settled at $12.225 million. Novant Health settled at $6.6 million. Kaiser Permanente agreed to a fund of up to $47.5 million, with $46 million as the base figure. Sutter Health settled at $21.5 million. MarinHealth Medical Center settled at $3 million. Cumulative healthcare pixel settlements have crossed $100 million.

The Federal Trade Commission

For companies outside HIPAA's reach, and for HIPAA-regulated entities making privacy promises, the FTC enforces under Section 5 and the Health Breach Notification Rule. GoodRx paid a $1.5 million civil penalty. BetterHelp paid $7.8 million. Cerebral was ordered to pay more than $7 million. Evoke Wellness paid $1.9 million over deceptive search advertising. Civil penalties under the FTC Act are capped at $53,088 per violation, a figure that carried into 2026 because the annual inflation adjustment was not made.

State attorneys general

State AGs can enforce HIPAA directly under HITECH, and they also have their own privacy statutes. California's largest CCPA settlement to date, $1.55 million against Healthline Media in July 2025, was specifically about health-related tracking and targeted advertising.

How Curve keeps marketing data out of this path

Nearly every case above shares a mechanism: PHI moved to somewhere it was not authorized to go, whether that was a review page, a campaign manager's inbox, or an ad platform's servers. The ad platform version is the one that scales, because it happens automatically, on every page load, without anyone deciding to do it.

Curve replaces the Meta Pixel and Google tag with a tracking script that sends events to Curve's US-hosted infrastructure rather than directly to platforms that will not sign a BAA. From there, four controls decide what leaves. Per-destination field mapping means only fields you explicitly map forward, and the default is that nothing does. Identifiers are SHA-256 hashed to each platform's conversion API requirements. Neutral event aliases mean the ad platform sees a generic conversion name rather than the service line, so no condition is ever displayed in an ad interface. PHI-pattern detection flags payloads containing PHI-shaped values, such as SSNs, MRN-style identifiers, and long numeric sequences, so you find out when an upstream form changes rather than months later.

The result is a conversion signal with no health context, which needs no authorization because it contains no PHI, while the data that does carry health context stays inside a system that has signed a BAA. For the underlying architecture, see our explanation of why client-side pixels create a HIPAA violation and our answer on whether the Meta Pixel or Conversions API is HIPAA safe.

Reading the tiers against your own stack

The tier structure rewards two behaviors: knowing what your systems do, and fixing problems within 30 days of finding them. Both are operational, not legal.

Knowing what your systems do means being able to answer, today, which scripts run on your site, which vendors receive form data, and which of them have signed BAAs. A team that cannot answer that is closer to the willful neglect tiers than to the lack-of-knowledge tier, because reasonable diligence is the standard, not actual awareness.

Fixing within 30 days means having a path from discovery to removal that does not require a quarterly release cycle. The difference between tier 3 and tier 4 is a $1.8 million swing in the annual cap, and it turns on that window. For the tracking layer specifically, our guide to HIPAA-compliant conversion tracking setup covers what a compliant configuration looks like across Google, Meta, and Microsoft.

Frequently asked questions

Can a patient sue us directly for a HIPAA marketing violation?

Not under HIPAA, which has no private right of action. They can complain to OCR, and they can sue under state wiretap, consumer protection, and privacy statutes. That second route is where the large tracking settlements have come from.

Does OCR fine per patient affected?

Not automatically. Penalties are assessed per violation, and OCR has discretion in how violations are counted. The published marketing cases show modest totals even where hundreds or thousands of individuals were involved, because the violations were counted by the requirement breached rather than by the record.

Is a patient testimonial on our website a HIPAA violation?

It is a marketing use of PHI, so it requires a signed authorization that names the use before publication. With that authorization it is permitted. Without one it is not, and a patient's own public review does not supply it.

Do the 2026 penalty amounts apply to conduct that happened earlier?

The inflation-adjusted amounts apply to penalties assessed after the adjustment date, so conduct from a prior year can be penalized at current rates. Waiting does not lock in older figures.

Our agency runs our ad accounts. Who is liable?

Both parties can be. An agency handling PHI on your behalf is a business associate and needs a BAA, and business associates face direct liability. The covered entity retains its own obligations regardless.

What is the fastest way to move from tier 4 toward tier 1?

Document what you know and act on it quickly. Tier placement is about diligence and correction. An organization that scans its own properties, records what it finds, and remediates on a defined timeline has a different posture than one that has never looked.

Where to start

Start with an inventory rather than a policy. List every script on your web properties, every vendor that receives form or appointment data, and which of them have executed BAAs. Then compare that list against what your ad platforms are actually receiving, because the gap between the two is where these cases originate.

Run our free compliance scanner to see which tracking scripts are live on your site right now, or visit curvecompliance.com to see how Curve handles the ad tracking layer with a signed BAA on every plan.

Reviewed August 2026. This is general information, not legal advice. Penalty amounts change with annual inflation adjustments, and enforcement outcomes turn on facts specific to each matter. Consult qualified counsel about your own situation.

Stay Compliant. Scale Confidently.

Join healthcare innovators who trust Curve for HIPAA-compliant ad tracking.Launch in hours, not months. Your growth stack, now HIPAA-safe.

Book a free tracking audit