Law / United States

HIPAA Privacy Rule

45 CFR Part 164, Subpart E (Sections 164.500-164.534)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 14 April 2003.

A sensitive categories rule binding public and private bodies.

As of 23 August 2026.

What it requires

  • Do not use or disclose protected health information except as the Privacy Rule permits or requires, and limit use and disclosure to the minimum necessary.
  • Strip biometric identifiers, including voiceprints and full-face photographic images, before treating health data as de-identified.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Knowingly and in violation of HIPAA obtaining or disclosing individually identifiable health information, when done with intent to sell, transfer, or use it for commercial advantage, personal gain, or malicious harm, is a federal crime under 42 U.S.C. 1320d-6(b)(3): a fine of up to $250,000 and imprisonment of up to 10 years, or both.

Penalty structure

45 CFR 160.404 sets four culpability tiers per violation, adjusted for inflation annually and published at 45 CFR 102.3 (2025 figures shown): (i) no knowledge and no reasonable diligence would have revealed the violation, $145 to $73,011 per violation; (ii) reasonable cause, not willful neglect, $1,461 to $73,011; (iii) willful neglect, corrected within 30 days, $14,602 to $73,011; (iv) willful neglect, not corrected within 30 days, $73,011 up to the annual cap. Every tier is subject to a $2,190,294 annual cap for identical violations of the same administrative simplification provision in a calendar year.

Rule
Per violation only
As of
2 September 2026
Minimum
145
Currency
USD
Fixed cap
2,190,294
Per violation unit
Violation
Per violation amount
2,190,294

Who enforces it

Enforcement body

HHS Office for Civil Rights

Enforcement record

Counts resolution agreements and civil money penalties HHS OCR's own published Resolution Agreements list dates to calendar year 2025 (25 actions), the latest complete calendar year the list covers, up from 14 in 2024; 5 more had posted for 2026 by the list's last review date of August 27, 2026. OCR's separate Enforcement Highlights page states a cumulative program total, as of October 31, 2024, of 152 settlements or civil money penalties totaling $144,878,972 since the Privacy Rule's 2003 compliance date; that cumulative total is not used here because it predates the 2025 and 2026 actions counted above and the two pages are not reconciled to a single running total. No per-case fine amounts are aggregated into a fines total here.

As of
2 September 2026
Trend
Rising
Source link
https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html
Actions per year
25

What it reaches

Obligation class

Consent, Disclosure, Data subject rights, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Restricts covered entities (health plans, health care clearinghouses, and most health care providers) and their business associates from using or disclosing protected health information except as the Rule permits or requires, and conditions most non-routine disclosures on individual authorization.

Its de-identification safe harbor is the one place federal law names biometric identifiers, including voice prints and full-face photographic images, as identifiers that must be stripped before health data is treated as de-identified.

When LexLint raises it

  • handles_health_records

Read the law

eCFR, current regulatory text, 45 CFR Part 164 Subpart E

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app