Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

HHS Exercises Discretion to Reduce Maximum Annual Civil Money Penalties for Certain HIPAA Violations

By Conor Duffy on April 30, 2019
Email this postTweet this postLike this postShare this post on LinkedIn

On April 26, 2019, the U.S. Department of Health and Human Services (HHS) issued a Notification of Enforcement Discretion (Notice) regarding imposition of Civil Money Penalties (CMPs) under HIPAA. In the Notice, HHS announces that it has revisited its prior interpretation of the standards for assessment of CMPs under the HITECH Act, and is exercising its discretion to reduce the maximum amount of CMPs that may be assessed annually for HIPAA violations based on culpability.

The official version of the Notice is dated April 30, 2019 and is available here.

The HITECH Act established four tiers of culpability for HIPAA violations:
1. the entity/individual did not know (and, by exercising reasonable diligence would not have known) that such entity/individual violated the provision;
2. the violation was due to reasonable cause (and not to willful neglect);
3. the violation was due to willful neglect that is timely corrected; or
4. the violation was due to willful neglect that is not timely corrected.

The HITECH Act also set forth tiers of penalties for violations corresponding to the four levels of culpability. The language of the HITECH Act created ambiguity about the cap on CMPs for all violations of a particular HIPAA requirement within a calendar year, which HHS acknowledged in 2009. As part of its Omnibus Rule finalized in 2013, HHS finalized regulations under which the limit for all violations of an identical provision of the HIPAA regulations in a single year would be $1.5 million.

HHS now states in its Notice that “[u]pon further review” of the HITECH Act, it “has determined that the better reading of the HITECH Act is to apply annual limits” as follows:

The above CMP tier structure will be used by HHS until further notice, provided that the amounts will be adjusted annually for inflation in accordance with the Bipartisan Budget Act of 2015. Per the Notice, HHS expects to engage in further rulemaking to revise its HIPAA regulations accordingly.

The Notice represents a welcome development for HIPAA-regulated organizations and individuals at a time when HHS has been increasingly pursuing high-dollar penalties for HIPAA violations.

Interestingly, the Notice also comes less than a month after MD Anderson Cancer Center petitioned the U.S. Court of Appeals for the Fifth Circuit to review HHS’s imposition of $4.35 million in CMPs for HIPAA violations occurring in 2012 and 2013 (see our discussion of that petition here). In that case, HHS alleged that MD Anderson committed ‘second tier’ HIPAA violations (due to reasonable cause but not willful neglect) and assessed calendar-year maximum penalties of $1.5 million for one violation occurring during two calendar years, and $1.348 million for another violation occurring over the course of almost one calendar year. Under the Notice, the per-year maximum penalties for violations of the second culpability tier would be significantly less than those imposed on MD Anderson. Moreover, HHS expressly acknowledges that its new penalty structure represents a “better reading” of the HITECH Act. It therefore remains to be seen whether the Notice will enable MD Anderson, or others, to reduce HIPAA penalties assessed under HHS’s previous interpretation.

Photo of Conor Duffy Conor Duffy

Conor Duffy is a member of Robinson+Cole’s Health Law Group and the firm’s Data Privacy and Security Team. Conor advises hospitals, physician groups, community providers, and other health care entities on general corporate matters and health care issues. He provides legal counsel on…

Conor Duffy is a member of Robinson+Cole’s Health Law Group and the firm’s Data Privacy and Security Team. Conor advises hospitals, physician groups, community providers, and other health care entities on general corporate matters and health care issues. He provides legal counsel on a full range of transactional and regulatory health law issues, including contracting, licensure, mergers and acquisitions, Medicare and Medicaid fraud and abuse laws and regulations, HIPAA compliance, and other data privacy and security matters. Read his rc.com bio here.

Read more about Conor DuffyEmail
Show more Show less
  • Posted in:
    Health Care and Life Sciences, Privacy and Cybersecurity
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo