Federal regulators have announced more than 20 HIPAA settlements and civil monetary penalties across 2025 and 2026, with the U.S. Department of Health and Human Services Office for Civil Rights (OCR) targeting hospitals, business associates, retailers, accounting firms, dental software vendors, and employer-sponsored health plans. Nearly every case shares the same underlying finding: the organization never conducted a proper risk analysis of its electronic protected health information before a breach hit. Dollar amounts have ranged from $10,000 to $3 million, and every settlement carries years of federal oversight on top of the check.
Recent HIPAA Settlements in 2025
The largest 2025 settlement came early. On January 14, OCR announced a $3 million agreement with Solara Medical Supplies over a phishing attack that compromised more than 114,000 patient records between April and June 2019. Solara then mailed breach notification letters to the wrong addresses, exposing another 1,531 people. OCR cited an inadequate risk analysis, insufficient security measures, and late breach notifications.1HHS.gov. Solara Medical Supplies Resolution Agreement and Corrective Action Plan
On February 20, 2025, OCR imposed a $1.5 million civil monetary penalty on Warby Parker after credential-stuffing attacks between September and November 2018 exposed names, addresses, payment card data, and prescription information for nearly 198,000 customers. OCR found three Security Rule violations, including failure to conduct a risk analysis and failure to review system activity logs. Warby Parker did not contest the penalty and waived its right to a hearing. Because corrective action plans are only part of negotiated settlements rather than imposed penalties, OCR could not require one here.2HHS.gov. Penalty Against Warby Parker3HIPAA Journal. Warby Parker HIPAA Penalty
USR Holdings, a business associate managing mental health and substance abuse treatment facilities, paid $337,750 in a settlement announced January 8, 2025. Between August and December 2018, unauthorized parties accessed and deleted electronic health records affecting 2,903 individuals. The breach went undetected for nearly four months. OCR cited failures in risk analysis, system activity monitoring, and data backup procedures.4HHS.gov. USR Holdings Resolution Agreement and Corrective Action Plan
In March 2025, Health Fitness Corporation settled for $227,816 after a software misconfiguration left patient data exposed to internet search crawlers beginning in 2015. The company did not discover the problem until 2018 and did not complete a compliant risk analysis until January 2024, nearly six years after reporting the breach.5HHS.gov. OCR Settles HIPAA Security Rule Investigation With Health Fitness Corporation
Several settlements followed through the spring and summer.
- BayCare Health System paid $800,000 in May 2025 after a former staff member’s credentials were used to access a patient’s records at a Florida hospital. The patient learned of the breach when an unknown person contacted her with photographs of her medical records. OCR found failures in access authorization, risk management, and audit controls.6HHS.gov. OCR HIPAA Agreement With BayCare
- Comstar, LLC settled for $75,000 in June 2025 over a 2022 ransomware attack affecting roughly 585,000 individuals. OCR found the ambulance billing company had not performed a thorough risk analysis or implemented adequate risk management measures.7Nixon Peabody. 2025 HIPAA Enforcement Tally Rises Following Three New Settlements
- Syracuse ASC agreed to $250,000 in July 2025 after the PYSA ransomware variant hit the ambulatory surgery center in March 2021, compromising names, Social Security numbers, financial data, and clinical information for 24,891 people. OCR also cited delayed breach notifications.8HHS.gov. OCR HIPAA Resolution Agreement With Syracuse ASC
- BST & Co. CPAs, LLP settled for $175,000 in August 2025. The accounting firm, acting as a business associate, was hit by ransomware introduced through a phishing email in December 2019, exposing health information for 170,000 individuals from a New York physician group client.9HHS.gov. OCR Settles HIPAA Security Rule Investigation With BST
2026 Settlements
On February 19, 2026, Top of the World Ranch Treatment Center agreed to pay $103,000 following a March 2023 phishing attack that compromised records of 1,980 patients. The core finding, again, was that the organization had never conducted a compliant risk analysis. The agreement includes a two-year corrective action plan.10HHS.gov. OCR Settles HIPAA Security Rule Investigation With TWRTC
The largest 2026 case by breach size involved MMG Fusion, a dental software vendor whose systems were infiltrated in December 2020. Names, phone numbers, addresses, dates of birth, and appointment details for approximately 15 million individuals were stolen and later posted on the dark web. MMG did not report the breach. OCR only learned of it after receiving a complaint in January 2023. The investigation identified three failures: no risk analysis, no breach notification within the required 60 days, and impermissible disclosure of protected health information. The settlement, announced March 5, 2026, was just $10,000, a figure OCR said reflected the company’s financial condition. HIQOR Dental signed as MMG’s successor. The three-year corrective action plan is unusually extensive, requiring a full risk analysis, rewritten HIPAA policies, workforce training, and retroactive breach notifications to affected dental practices and their patients.11HHS.gov. OCR MMG Fusion HIPAA Agreement12HIPAA Journal. MMG Fusion HIPAA Settlement
In April 2026, OCR announced a $245,000 settlement with Star Group, L.P. Health Benefits Plan, a self-funded employer-sponsored group health plan. A 2021 ransomware attack had compromised records of 9,316 plan participants, including Social Security numbers, claims data, and benefits information. Employer health plans have historically attracted less enforcement attention than hospitals and insurers, and OCR found that the plan had failed to identify where its electronic health data was stored and had no documented risk analysis process at all.13HHS.gov. Resolution Agreements and Civil Money Penalties
The Common Thread Regulators Keep Citing
Every one of the first ten enforcement actions of 2025 cited the organization’s failure to conduct a thorough, enterprise-wide risk analysis as required by the HIPAA Security Rule. OCR has formalized this focus as a “Risk Analysis Initiative” and treats it as the foundation from which other security obligations follow. The agency has pursued penalties regardless of whether the underlying breach involved ransomware, phishing, misconfigured servers, or insider access.13HHS.gov. Resolution Agreements and Civil Money Penalties
Amounts vary widely because OCR weighs the nature of the violation, the number of people affected, the organization’s compliance history, and its financial condition. That is how functionally similar violations produced settlements from $10,000 for the financially distressed MMG Fusion up to $3 million for Solara.14HHS.gov. Enforcement Highlights
State Attorneys General Are Adding Parallel Penalties
OCR is not the only regulator pursuing HIPAA-related violations. State attorneys general have authority under the HITECH Act to bring civil actions, and they have been increasingly willing to do so, often coordinating across state lines.
In 2024, state AGs imposed roughly $19.5 million in fines across nine actions. California hit Blackbaud with a $6.75 million penalty over a ransomware breach affecting 5.5 million records. New York fined Enzo Biochem $4.5 million in a multistate action with New Jersey and Connecticut, and imposed $1 million on Albany ENT & Allergy Services, which was also required to invest $2.24 million in cybersecurity improvements.15HIPAA Journal. HIPAA Enforcement by State Attorneys General
Comstar, which paid OCR $75,000 in 2025, was also hit with a separate $515,000 state-level settlement with the Massachusetts attorney general, assisted by Connecticut, for the same breach. A single data breach can now trigger investigations from OCR, one or more state AGs, and private litigation at the same time.15HIPAA Journal. HIPAA Enforcement by State Attorneys General
The Largest HIPAA Settlements on Record
The current wave fits inside a longer arc of rising penalties. The biggest HIPAA settlements to date include:
- Anthem, Inc. paid $16 million in 2018 after cyberattacks exposed records of nearly 79 million people, then the largest health data breach in U.S. history.16HHS.gov. Anthem Resolution Agreement
- Premera Blue Cross paid $6.85 million in 2020. A May 2014 spear-phishing attack let hackers linger in Premera’s systems for nearly nine months, exposing data for 10.4 million individuals. OCR found “systemic noncompliance.” Premera also paid a separate $10 million settlement to 30 state attorneys general and $74 million to resolve a class action.17HHS.gov. Premera Blue Cross Resolution Agreement18HIPAA Journal. OCR Imposes 2nd Largest Ever HIPAA Penalty on Premera Blue Cross
- Advocate Health Care paid $5.55 million in 2016 over three separate breaches, including the theft of four unencrypted desktop computers containing nearly four million patient records. OCR found that some compliance failures dated to the inception of the Security Rule.19HHS.gov. Advocate Health Care Network Resolution Agreement
- Solara Medical Supplies paid $3 million in 2025, now among the largest, reflecting continuing upward pressure on penalties for phishing-related breaches.1HHS.gov. Solara Medical Supplies Resolution Agreement and Corrective Action Plan
Through October 2024, OCR had resolved 152 cases through civil monetary penalties or settlements, totaling nearly $145 million.14HHS.gov. Enforcement Highlights
Right of Access and Parental Access Cases
OCR’s other long-running enforcement priority, the Right of Access Initiative, targets organizations that fail to give patients timely access to their own health records. HIPAA requires covered entities to fulfill access requests within 30 days, and OCR has completed more than 50 enforcement actions under the initiative.13HHS.gov. Resolution Agreements and Civil Money Penalties
Oregon Health & Science University was assessed a $200,000 penalty in March 2025 for failing to provide timely access. Concentra, the occupational health company, settled for $112,500 in May 2025 after a patient made six access requests beginning in February 2018 and did not receive her records until March 2019. OCR had originally proposed a $250,000 penalty. The reduced amount was agreed to before a scheduled administrative hearing.20HHS.gov. OCR Settles With Concentra
In late 2025, OCR expanded the initiative to include parental access to minor children’s records as a specific enforcement priority. In a December 2025 guidance letter, OCR Director Paula Stannard warned that some health systems and electronic health record vendors have implemented age-based or policy-based restrictions that block parents from accessing their children’s records even when the parents are legally authorized. OCR has launched compliance reviews of large health systems and signaled that more investigations and settlements on parental access should be expected throughout 2026.21HHS.gov. OCR Letter on HIPAA Privacy Rule and Parental Access to Minor Children’s Medical Records
What a HIPAA Settlement Actually Requires
The dollar figure is only part of the obligation. Every recent settlement includes a corrective action plan that imposes years of federal oversight. Standard terms require the organization to conduct a comprehensive, enterprise-wide risk analysis; develop a written risk management plan with timelines and assigned responsibilities; rewrite and distribute HIPAA policies and procedures; train all workforce members who handle protected health information; and submit regular compliance reports to OCR, including documentation of any internal policy failures. Most plans run two years. Some extend to three. Organizations must keep compliance records for six years, and if they fall short on the plan, OCR can add further civil monetary penalties.22HHS.gov. L.A. Care Health Plan Resolution Agreement23HHS.gov. Health Specialists Resolution Agreement and Corrective Action Plan