In 2025, OCR fined or settled with Solara Medical Supplies ($3 million), Warby Parker ($1.5 million), BayCare, PIH Health and many smaller providers and vendors. One of the smallest was Vision Upright MRI ($5,000). Most had no adequate risk analysis. That is a written check of where patient data lives and what threatens it. HHS lists 24 actions dated 2025.
The Office for Civil Rights had a year. Twenty-four enforcement actions on HHS’s list for 2025. The settlements and penalties in this post range from $5,000 to $3 million. A Risk Analysis Initiative targeting common HIPAA violations that kept producing cases all year. And a continuing Right of Access Initiative that kept adding cases.
Update (October 2026): We first wrote this article using mid-2025 data. HHS keeps a list of its HIPAA settlements and fines. That list shows 24 enforcement actions dated 2025, and some of them are not covered below. We checked the dates and amounts below against that list and fixed them. Two cases below (Heritage Valley and Bryan County) were announced in 2024. We marked them that way.
The organizations that got caught weren’t all large hospital systems.
- A medical billing company.
- An eyewear retailer.
- A public hospital.
- A wellness program vendor.
- A radiology practice.
Several cases involved HIPAA violations by staff. In one, an employee looked at records they had no reason to see. In another, former employees could still get into systems. OCR took action against small organizations as well as large ones. If you think HIPAA enforcement only targets big players, 2025 should change your mind.
For a broader look at the types of HIPAA violations and their penalties, the enforcement patterns from this year reinforce what the penalty structure has always made clear. For a detailed look at real cases, see our HIPAA violation examples and penalties breakdown.
Here’s who paid, what they did wrong, and what your practice can learn from each case.
The Biggest HIPAA Settlements of 2025
1. Solara Medical Supplies: $3,000,000
The year’s largest settlement arrived on January 14, 2025. Solara Medical Supplies, a California-based supplier of insulin pumps and continuous glucose monitors, agreed to pay $3 million for HIPAA Security Rule and Breach Notification Rule violations.
In 2019, a phishing attack compromised multiple employee email accounts. Attackers had access for months before anyone noticed. The breach exposed ePHI for about 114,000 patients: names, Social Security numbers, financial accounts, health insurance information, and clinical details.
OCR’s problem wasn’t that Solara got phished. Phishing happens. The problem was that Solara hadn’t run a thorough risk analysis before the attack, hadn’t done enough to manage its risks, and then took too long to notify patients after discovery.
Three million dollars. For a breach that started with one employee clicking one link. The phishing email was the trigger. The missing risk analysis was the HIPAA breach.
2. Warby Parker: $1,500,000
On February 20, 2025, OCR slapped a $1.5 million civil monetary penalty on Warby Parker, the eyewear company. As a provider of prescription eyewear, Warby Parker handles prescriptions and vision records. That makes them a covered entity under HIPAA, which means HIPAA applies to them directly.
The penalty stemmed from a 2018 credential stuffing attack. Attackers took username/password combinations from other breaches and tried them on Warby Parker’s systems. Because people reuse passwords, roughly 200,000 customer accounts were compromised.
OCR found three problems. Warby Parker hadn’t run an adequate risk analysis. It hadn’t put adequate security measures in place. And it didn’t regularly check its system activity records to spot unauthorized access quickly. The $1.5 million penalty arrived more than six years after the breach. OCR has a long memory.
3. Heritage Valley Health System: $950,000 (2024)
Heritage Valley, a Pennsylvania health system, paid $950,000 to settle alleged HIPAA Security Rule breaches tied to the 2017 NotPetya malware attack. The malware entered Heritage Valley’s network through a connection with its business associate, Nuance Communications, as part of the global NotPetya outbreak. Note the date: OCR announced this settlement on July 1, 2024. That makes it a 2024 case. We included it because it shows the same pattern.
OCR’s investigation found the usual suspects: no adequate risk analysis, and no backup plan for responding to an emergency that damages systems containing ePHI. The case is a reminder that you don’t have to be the direct target of an attack: your vendor’s compromise can become your compliance failure.
4. BayCare Health System: $800,000
BayCare, a large Florida-based health system, settled in May 2025 for $800,000 over a malicious insider incident. An employee accessed patient records without authorization: classic insider threat.
The fine wasn’t for having a bad employee. It was for not catching them. BayCare hadn’t implemented adequate controls to monitor who was accessing patient records and flag unusual access patterns. An authorized user was viewing records they had no business reason to see, and the organization’s systems weren’t catching it.
The settlement included a two-year corrective action plan monitored by OCR. That monitoring is its own burden: regular reporting, audits, and the constant knowledge that OCR is watching everything you do.
5. PIH Health: $600,000
PIH Health, a Southern California health system, settled for $600,000 in April 2025 following a phishing breach. OCR’s investigation found that PIH had not done a thorough security risk analysis. It also lacked adequate safeguards to protect ePHI.
Another phishing case. Another missing risk analysis. The pattern is getting repetitive because the underlying failure is the same.
OCR’s Risk Analysis Initiative: The Cases Keep Coming
In late 2024, OCR formally launched the Risk Analysis Initiative, a targeted enforcement campaign focused on organizations that haven’t done an adequate security risk analysis. A risk analysis is a written check of where your patient data lives, what threatens it, and how likely harm is. Several 2025 cases came from this effort alone. By early 2026, the count hit 11 with the Top of the World Ranch settlement.
OCR made the reasoning explicit: the risk analysis is the foundation of HIPAA Security Rule compliance. Everything else (access controls, staff training, incident response) is supposed to grow out of a written understanding of where your ePHI lives and what threatens it. Skip the risk analysis, and your entire compliance program is built on sand. If you haven’t done one, the risk analysis guide is where to start.
Here are more cases, many of them from this effort:
6. Northeast Radiology: $350,000
On April 4, 2025, OCR announced a $350,000 settlement with Northeast Radiology, a Connecticut-based imaging practice. The case involved a PACS server exposure that left imaging records accessible. OCR’s investigation found the practice hadn’t run an adequate risk analysis. Two-year corrective action plan.
A radiology practice. Not a hospital system. Not a national health plan. A specialty practice that handles imaging data. If they can get hit, so can you.
7. USR Holdings: $337,750
Announced January 8, 2025, this settlement involved a business associate whose database was opened by an outside party without permission. A business associate is a vendor that handles patient data for a covered entity. The attacker not only accessed but deleted ePHI belonging to over 2,900 people. USR agreed to pay $337,750 and submit to two years of OCR monitoring.
8. Syracuse ASC: $250,000
On July 23, 2025, OCR settled with an ambulatory surgery center in Syracuse for $250,000 following a ransomware breach affecting 24,891 people. The investigation found insufficient risk analysis and inadequate protections. Two-year corrective action plan.
An ambulatory surgery center. Not a massive operation. The kind of facility that exists in every mid-sized city in America.
9. Health Fitness Corporation: $227,816
Health Fitness Corporation, an Illinois-based employer wellness program company, settled for $227,816 in March 2025. It was another action under the Risk Analysis Initiative. The case grew out of a breach affecting roughly 4,300 people.
OCR’s investigation found the company had never run a thorough risk analysis. Not an outdated one. Not an incomplete one. Never done it at all. Health Fitness Corporation is a business associate, a mid-size company that probably assumed HIPAA compliance was primarily the covered entity’s problem. OCR disagrees.
10. Behavioral Health Solution of Deer Oaks: $225,000
On July 7, 2025, OCR reached a $225,000 settlement with Deer Oaks, a behavioral health provider, for not doing an adequate risk analysis and for lacking proper safeguards for ePHI. Two-year corrective action plan.
11. Cadia Healthcare Facilities: $182,000
On April 22, 2025, OCR settled with five healthcare providers collectively known as Cadia Healthcare Facilities for $182,000 over HIPAA Privacy Rule and Breach Notification Rule violations. The case involved an impermissible disclosure of patients’ health data on social media. That means the data was shared without permission. Two-year corrective action plan.
12. Bryan County Ambulance Authority: $90,000 (2024)
An Oklahoma EMS provider hit by ransomware. No adequate risk analysis before the attack. OCR announced the settlement in October 2024, so this is a 2024 case.
OCR settled for $90,000 with a three-year corrective action plan. An ambulance authority. A small emergency services operation in rural Oklahoma. OCR doesn’t care about your size.
13. Elgon Information Systems: $80,000
A business associate that provides IT services, hit by ransomware affecting patient data. Settlement: $80,000 plus three years of OCR monitoring. Another example of why business associate agreements need teeth, and why BAs need their own compliance programs.
14. Comstar: $75,000
Comstar, a Massachusetts EMS billing company, paid $75,000 in May 2025. Another business associate. No adequate risk analysis. Then a ransomware attack exposed patient ePHI.
15. Guam Memorial Hospital Authority: $25,000
A public hospital in Guam hit by ransomware, with a secondary incident involving two former employees accessing systems after they left the job. Settlement: $25,000 plus three years of OCR monitoring.
Twenty-five thousand dollars. For a public hospital on a Pacific island territory. OCR’s enforcement reach has no geographic boundaries and no minimum threshold for action.
16. Vision Upright MRI: $5,000
Settled for $5,000 in May 2025 after failing to perform any risk analysis whatsoever and delaying breach notice following a server attack. The smallest fine on the list, but the message is clear: even $5,000 hurts when you’re a small imaging facility, and the corrective action plan duties hurt more.
The Right of Access Cases Keep Coming
On April 30, 2025, OCR reached a $112,500 settlement with Concentra, a Texas-based occupational health company operating urgent care clinics nationwide. The case came from OCR’s Right of Access Initiative.
A patient first requested his health records in February 2018. He made six separate requests over the following months. He didn’t receive his records until March 2019, more than a year after his initial request. HIPAA requires you to act on records requests within 30 days. You can extend that once, by up to 30 more days. To do that, you must tell the patient in writing why you need more time and when you will act (45 CFR 164.524).
This was another enforcement action under the Right of Access Initiative. That is OCR’s push, running since 2019, to make sure patients can get their own records. It’s one of OCR’s most reliable enforcement pipelines because the cases are easy to prove: patient asked for records, didn’t get them in time, complained to OCR. The paper trail writes itself.
If your practice has any ambiguity about your records request process (who receives requests, who fulfills them, what the turnaround time is, what happens when it slips), fix it before a patient files a complaint.
The 3 Patterns Behind the 2025 HIPAA Fines
Look across the cases above and the same failures show up in different combinations.
Pattern 1: No Adequate Risk Analysis
This showed up in most of the cases above. OCR’s corrective action plans are the fix-it plans it watches after a case closes. Almost all of them require the organization to do a new, thorough risk analysis as step one. The Security Rule has required a risk analysis since 2005. Organizations are still getting caught without one in 2025.
A risk analysis that meets the rule isn’t a form you fill out once and file away. It’s a written process that identifies where all your ePHI exists: in your EHR, yes, but also in email, billing systems, backup drives, paper files, cloud storage, mobile devices, and every other place data touches. It assesses threats and vulnerabilities (weak spots). It rates how likely and how harmful each one is. It lists the protections you already have. And it produces a remediation plan, meaning a plan with deadlines to fix the gaps.
Most practices that claim they’ve “done” a risk analysis have done something lighter than this. OCR knows the difference. The ‘addressable’ doesn’t mean ‘optional’ principle applies here: every addressable requirement needs a written decision. Addressable means you decide if it fits your practice and write down why.
Pattern 2: No Monitoring or Access Controls
The BayCare insider case. The Warby Parker credential stuffing attack. Gulf Coast Pain Consultants, hit with a $1.19 million penalty in late 2024 for failing to end a former employee’s access to systems containing ePHI. If you can’t see who’s accessing records and you can’t revoke access when someone leaves, you’re exposed.
You don’t need AI-powered monitoring tools. You need audit logs, someone who reviews them, and a process for terminating access on the same day an employee departs. MFA would be required under a proposed update to the Security Rule. HHS proposed it in January 2025, and it is not final yet. MFA means a second login step, like a code on your phone. You can get ahead of it now.
Pattern 3: Slow or Missing Breach Notification
Solara took too long to notify patients. Vision Upright MRI delayed notice after a server attack. The clock under HIPAA starts when you discover the breach, not when your investigation is complete.
You have 60 days at most. You also can’t put it off without a good reason. Most organizations that miss the deadline aren’t being malicious: they’re scrambling to understand what happened and hoping the timeline hasn’t expired. It usually has.
The March 1 small breach reporting deadline catches many practices off guard too: smaller breaches affecting fewer than 500 people have their own annual reporting rule that’s easy to miss.
It’s Not Just Hospitals Getting HIPAA Fines
Here’s what stands out about the 2025 enforcement list: the diversity of organizations that got caught.
- A medical device supplier (Solara)
- An eyewear retailer (Warby Parker)
- A health system (BayCare, PIH Health)
- An ambulatory surgery center (Syracuse ASC)
- A behavioral health provider (Deer Oaks)
- An EMS billing company (Comstar)
- A wellness program company (Health Fitness)
- An IT services company (Elgon)
- A business associate, meaning a vendor that held patient data (USR Holdings)
- A radiology practice (Northeast Radiology)
- An occupational health company (Concentra)
- A public hospital in Guam
If you handle ePHI in any capacity (as a covered entity or a business associate), OCR can investigate you. The $5,000 settlement for Vision Upright MRI and the $3 million fine for Solara came from the same enforcement program, applied to the same fundamental failures, scaled to the size and severity of the case.
What These HIPAA Fines Signal for 2026
The Risk Analysis Initiative is not winding down. OCR kept announcing Risk Analysis Initiative cases into 2026. Its 12th, with MMG Fusion, came in March 2026. The change in administration did not stop enforcement.
The proposed HIPAA Security Rule updates are still only proposed. HHS published them in January 2025 and now aims for a final rule in July 2027. If finalized, they would raise the baseline a lot: required MFA, required encryption, scans for security weak spots at least every six months, and a written list of all your technology. Organizations that haven’t started on these could face a steep climb. Penalties matter too. The latest inflation adjustment to HIPAA penalty amounts set the yearly cap at $2,190,294 for violations of the same requirement.
The Change Healthcare breach put vendor management in OCR’s crosshairs. Expect enforcement actions related to inadequate business associate oversight to increase.
Here’s how to read OCR’s direction: they will keep finding organizations that haven’t done the foundational work, and they will keep making examples of them.
The foundational work isn’t complicated.
- A risk analysis.
- Documented policies that people actually follow.
- Staff training that’s current and recorded.
- Audit logs that get reviewed.
- Breach notification steps that are tested before you need them.
- Access removal that happens on day one, not day thirty.
In the 2025 cases above, organizations that skipped this work paid between $5,000 and $3 million. The only question is whether your practice has done the work to stay off next year’s list.
2025 to 2026 HIPAA Penalty Tier Reference
HIPAA civil monetary penalties are adjusted for inflation. The amounts below are the latest ones in 45 CFR 102.3 (the 2025 adjustment). The yearly cap covers all violations of the same requirement in one calendar year.
Since April 2019, OCR has also followed a policy with lower yearly caps for Tiers 1 to 3. Those caps are $25,000, $100,000 and $250,000 before inflation. The policy is called a Notice of Enforcement Discretion. It is not binding, so OCR can drop it at any time.
| Tier | Culpability Level | Per-Violation Min | Per-Violation Max | Annual Cap |
|---|---|---|---|---|
| Tier 1 | Did not know | $145 | $73,011 | $2,190,294 |
| Tier 2 | Reasonable cause | $1,461 | $73,011 | $2,190,294 |
| Tier 3 | Willful neglect (corrected) | $14,602 | $73,011 | $2,190,294 |
| Tier 4 | Willful neglect (not corrected) | $73,011 | $2,190,294 | $2,190,294 |
The per-violation framing is important. OCR can count each patient record exposed, each day of non-compliance, or each impermissible disclosure as a separate violation. A single breach affecting 10,000 patients could theoretically result in 10,000 separate violations.
One important protection comes from a 2021 change to the HITECH Act (Public Law 116-321). Under it, HHS must consider whether you had "recognized security practices" in place for at least the previous 12 months. HHS weighs this when it decides a fine or the scope of an audit. Recognized security practices means following a known security framework, such as the NIST Cybersecurity Framework. This does not guarantee a lower fine. But the law also says HHS cannot raise a fine because those practices are missing.
What Happens After OCR Opens an Investigation
Most covered entities focus on avoiding fines. Fewer understand what the investigation process looks like. Knowing the process helps you prepare before OCR ever contacts you.
How investigations start:
- Breach reports: If a breach affects 500 or more people, you must report it to HHS within 60 days of finding it. OCR reviews these reports. If fewer than 500 people are affected, you report it to HHS once a year.
- Complaints: Any person can file a complaint with OCR alleging a HIPAA violation. OCR receives thousands per year and screens them for merit. If your organization is the subject of a complaint, see our guide to responding to a HIPAA complaint for the privacy officer's step-by-step response process.
- Audits: OCR also runs an audit program. It can pick covered entities and business associates even when no one has reported a problem.
The investigation timeline:
- OCR notifies the covered entity in writing
- Entity provides requested documentation (policies, risk analysis, training records, incident logs, BAA inventory)
- OCR reviews the documents and may visit in person
- OCR issues findings: no violation, technical assistance letter, or notice of proposed determination (the precursor to a penalty)
- Entity may request a hearing to contest proposed penalties
- Resolution via settlement agreement plus corrective action plan, or civil monetary penalty
What to have ready before OCR asks:
- Current, signed risk analysis (a proposed Security Rule update would require a review at least every 12 months; HHS published it in January 2025, and it is not final yet)
- Complete Business Associate Agreement inventory with execution dates
- Workforce training records including names, dates, and content covered
- Incident response documentation for any reported or investigated breaches
- Security policies and procedures with review dates
When Non-Healthcare Companies Get HIPAA Fines
One of the more notable 2025 enforcement actions involved Warby Parker, the eyewear company, which received a $1.5 million civil money penalty in February 2025 following a cybersecurity investigation. A civil money penalty is a fine OCR imposes, not a settlement both sides agree to. Because Warby Parker handles vision prescriptions and health information, they qualify as a covered entity under HIPAA.
The lesson: HIPAA follows what a business does, not what industry it says it is in. Some businesses provide health care and send health information electronically, for things like insurance billing. Those are covered entities.
A vendor that handles patient data for a covered entity is a business associate. Both must follow HIPAA. Vision care providers, dental practices and pharmacies usually fall under HIPAA this way. Wellness programs and employer health programs fall under HIPAA only when they are, or work for, a covered entity such as a group health plan.
2025 enforcement snapshot: HHS’s list shows 24 enforcement actions dated 2025. Most of the cases in this post involved a missing or weak risk analysis. The amounts in this post range from $5,000 (Vision Upright MRI) to $3,000,000 (Solara Medical Supplies).
See how real practices have navigated these enforcement challenges in our compliance case studies.
Sources
- HHS OCR Resolution Agreements and Civil Money Penalties
- HHS OCR Enforcement Highlights
- 45 CFR Part 160, Subpart D: Civil Money Penalties
- Federal Register (Aug. 8, 2024): HHS Annual Civil Monetary Penalties Inflation Adjustment (2024 amounts)
- 45 CFR 102.3: current inflation-adjusted HIPAA penalty amounts
- HHS OCR Breach Portal
Related Reading
- How to Run a Risk Analysis That Won’t Get You Fined
- Why ‘Addressable’ Doesn’t Mean ‘Optional’
- The New HIPAA Security Rule Is Coming
- The Small Practice HIPAA Compliance Starter Kit
Need help with your risk analysis or compliance program? One Guy Consulting offers affordable HIPAA compliance packages, including the risk analysis that OCR keeps fining people for not doing. Explore HIPAA compliance services Run your risk assessment now HIPAA compliance consulting
Related: OCR audit program | HIPAA violations and penalties guide
Frequently Asked Questions
What was the largest HIPAA fine in 2025?
The largest financial penalty announced in 2025 was Solara Medical Supplies' $3,000,000 settlement in January 2025. HHS's list shows 24 enforcement actions dated that year. Most of the fines in this post came from three problems: no risk analysis, weak access controls, and late breach notifications.
Can a small practice get fined by OCR?
Yes. OCR does not only target large health systems. Small practices have been fined for the same violations, particularly for failing to perform a security risk assessment, which OCR considers a baseline requirement under the Security Rule.
How can my practice avoid HIPAA fines?
Start with a current security risk assessment, maintain up-to-date policies, train your workforce annually, and document everything. Most fines result from organizations that skipped these fundamentals, not from sophisticated attacks.
What is the maximum HIPAA fine in 2025?
Under the latest inflation adjustment (45 CFR 102.3), the most OCR can fine for a single violation is $2,190,294. That is for Tier 4 (willful neglect, not corrected). Willful neglect means a conscious or reckless failure to follow the rule. The yearly cap for violations of the same requirement is also $2,190,294. For Tiers 1 through 3, the most for one violation is $73,011.
Since 2019, OCR has followed a policy, which it is not bound by, with lower yearly caps for those three tiers. Those caps are $25,000, $100,000 and $250,000 before inflation. These figures are adjusted for inflation annually.
Can HIPAA fines be reduced or waived?
They can be lower. A 2021 change to the HITECH Act (Public Law 116-321) says HHS must consider your security practices when it sets a fine. It looks at whether you had recognized security practices in place for at least the previous 12 months. That means following a known security framework, such as the NIST Cybersecurity Framework. The law also says HHS cannot raise a fine because those practices are missing.
Does HIPAA apply to non-healthcare companies?
Yes, if they handle protected health information. Warby Parker received a $1.5 million civil money penalty in February 2025. It provides prescription eyewear, so it is a covered entity. A business is a covered entity if it provides health care and sends health information electronically, for things like insurance billing. A vendor that handles patient data for a covered entity is a business associate. Both must follow HIPAA, regardless of their primary industry.
What triggers an OCR HIPAA investigation?
Three common triggers: a breach report affecting 500 or more people, a complaint filed with OCR, or selection for OCR’s audit program. The common thread is documentation: organizations that maintain complete compliance records fare significantly better than those that cannot produce documents on demand.