Note: Your progress in watching these videos WILL NOT be tracked. These training videos are the same videos you will experience when you take the full ProHIPAA for Leaders program. You may begin the training for free at any time to start officially tracking your progress toward your certificate of completion.

Show full transcript for HIPAA Violations and Penalties video

In this lesson, we'll cover HIPAA violations and penalties, how penalty amounts are calculated, the role of a Book of Evidence, and a practical example of addressing workstation security risks.

HIPAA Penalties & Financial Impacts

Since HIPAA enforcement began, penalties have become increasingly common. Penalty amounts depend directly on the seriousness of the violation and the organization's level of responsibility, ranging from around ten thousand dollars to millions of dollars.

As of mid-2026, the largest HIPAA settlement on record remains the 2018 Anthem case at $16 million, which followed the largest healthcare data breach in history.

Pro Tip #1: The Book of Evidence: It is critical for covered entities to maintain written policies and procedures, known as a Book of Evidence. Not only is this a legal requirement under HIPAA, but it protects your organization in the event of a breach, violation, or audit.

Workstation Security & Password Protection

As demonstrated in the office scenario, managing passwords properly is an essential part of complying with HIPAA security policies. Displaying passwords on sticky notes attached to computer monitors or placing them under keyboards creates an immediate security risk.

Password Security Standards

You are required by law to use a password to access PHI, and passwords must be secure and complex. Avoid placing password notes around your workstation or under your keyboard, as these are the very first places unauthorized individuals look when attempting to gain system access.

Pro Tip #2: Addressing Compliance Issues: Privacy officers and team leaders should address security violations promptly and constructively, helping staff implement secure alternatives to keep all systems protected.