Most compliance content leads with the biggest possible fine to grab attention. That number is real, but it's also the least likely outcome for a two- or three-provider practice. What's far more common — and far more likely to actually happen to you — deserves more attention than it usually gets.
The ceiling number, for context
HHS enforces the HIPAA Security Rule through the Office for Civil Rights, with civil penalties tiered by the level of culpability — ranging from "didn't know and couldn't reasonably have known" up to "willful neglect, uncorrected." The current maximum for willful neglect sits at $2,190,294 per violation category, per calendar year, adjusted periodically for inflation.
That's the number you'll see cited everywhere. It's accurate. It's also almost never what happens to a small practice, because it requires proving willful neglect — a knowing, uncorrected failure — not a genuine mistake or a gap the practice wasn't aware of.
What actually happens more often
Corrective Action Plans. The far more typical OCR outcome for a small provider is a CAP — a mandated, monitored plan to fix specific deficiencies, often paired with a smaller settlement, sometimes in the tens of thousands rather than the millions. These come with reporting requirements that can run for years, meaning the practice is under active oversight long after the initial incident.
Breach notification costs. If patient data is compromised, you're required to notify every affected patient, and — depending on scale — potentially the media and HHS directly. For a practice with a few thousand patient records, notification alone (letters, credit monitoring offers, a dedicated call line) can run into tens of thousands of dollars before any penalty is even assessed.
Insurance and lending consequences. A documented breach or enforcement action shows up in cyber-insurance underwriting and can raise premiums substantially at renewal — sometimes for years. It can also complicate practice financing or a future sale, since buyers and lenders increasingly ask for compliance history during due diligence.
Patient trust. Harder to put a number on, but real. Practices that experience a publicized breach commonly see measurable patient attrition in the following year — people don't always leave loudly, they just don't come back.
The pattern behind most enforcement actions
Reviewing OCR's published enforcement history, a consistent theme emerges: it's rarely a single catastrophic failure. It's usually a missing risk assessment, an expired or absent Business Associate Agreement, or an access control gap that existed for a long time before anything went wrong. The incident is often what surfaces the gap — the gap itself had been sitting there, undocumented, for months or years.
That's actually the encouraging part. These are addressable, unglamorous fixes: a documented risk assessment, a complete BAA inventory, defined access controls. None of it requires guessing at what auditors want. The requirements are published; the work is just doing them systematically, before an incident forces the issue.