NOVRASCALE
PlatformPricing
Client LoginBook a Free Call
NOVRASCALE
7 min read•Dec 28, 2025•By Matt Delgado

55% of HIPAA Fines Hit Small Practices. Here's What That Means for Yours.

Small practices aren't too small to be fined. Over half of HIPAA enforcement targets small providers. Here's what triggers investigations and what they actually cost.

There’s a common belief among small practice owners that HIPAA enforcement only targets large hospital systems and insurance companies. The data says otherwise.

A review of OCR’s enforcement history shows that the majority of HIPAA fines and settlement agreements involve organizations far smaller than the headline cases suggest. Small practices, clinics, and individual providers appear in enforcement actions with striking regularity.

Source: HHS.gov, Compliance Enforcement Data

What “Small Practice” Enforcement Looks Like

Enforcement actions against small practices typically don’t make national news. But they happen regularly. Since January 2024, OCR has announced 20 enforcement actions with fines ranging from $25,000 to $3 million.

Source: Shook, Hardy & Bacon, “OCR Enforcement Activity: Trends and Insights From a Limited Sample,” March 2025

Here are real examples from recent enforcement:

  • $90,000 — An Oklahoma emergency medical services provider for Security Rule violations (October 2024)
  • $80,000 — A Massachusetts EHR vendor (January 2025)
  • $1.3 million — LA Care Health Plan for a mailing error that exposed PHI of just 1,400 members (2024)

Source: Shook, Hardy & Bacon; HIPAA Journal, “HIPAA Violation Fines — Updated for 2026”

Note the LA Care case: while LA Care is a large health plan, the case illustrates that even a small number of affected individuals — just 1,400 — can result in a $1.3 million fine. The size of the breach doesn’t determine the size of the penalty.

What Triggers an Investigation

Most small practice investigations start with one of two triggers:

  • A patient complaint. A single patient filing a complaint with HHS can trigger an OCR investigation. The complaint can be about anything — a perceived privacy breach, a data request that wasn’t fulfilled, even frustration with how their information was handled.
  • A breach report. HIPAA requires you to report breaches affecting 500 or more individuals to OCR. But even smaller breaches must be logged and reported annually. Any reported breach can trigger a deeper investigation.

As of February 2025, OCR had 650 breach reports under active investigation.

Source: HIPAA Journal, “Healthcare Data Breach Statistics — Updated for 2026”

The #1 Violation: No Risk Analysis

The most frequently cited violation in enforcement actions is inadequate risk analysis, appearing in 13 of the 20 recent enforcement matters. OCR’s Security Risk Analysis Initiative launched in early 2025 resulted in 7 enforcement actions in just its first six months — all tied to organizations that hadn’t properly assessed their risks.

Source: Feldesman LLP, “OCR’s New Security Risk Analysis Initiative Results in Seven Enforcement Actions in First Six Months”

A risk analysis isn’t just about your EHR. It’s about every system that touches PHI — including your website, your email, your scheduling tools, and your contact forms. If you haven’t assessed whether your website is creating PHI exposure, you have a risk analysis gap.

Wondering if your practice has a risk analysis gap? Get a free compliance check →

The Financial Reality

HIPAA penalty tiers are published by HHS:

TierCulpabilityFine RangeAnnual Cap
1Lack of knowledge$141 – $35,581$35,581
2Reasonable cause$1,424 – $71,162$71,162
3Willful neglect (corrected)$14,232 – $71,162$284,582
4Willful neglect (not corrected)$71,162$2,134,831

Source: HHS.gov, 2024 inflation-adjusted Civil Monetary Penalties for HIPAA Violations

The annual cap ranges from $35,581 (Tier 1) up to $2.13 million (Tier 4, willful neglect not corrected). And the average total cost of a healthcare data breach in 2024 was $4.88 million per incident — which includes fines plus notification costs, legal fees, and remediation.

Source: HIPAA Journal, “Healthcare Data Breach Statistics — Updated for 2026”

3 Things You Can Check in 5 Minutes

Before you request a full audit, here are three quick checks you can do on your own site right now:

  1. Look at your contact form. Does it go through a BAA-covered platform (JotForm HIPAA, IntakeQ, FormDR)? Or is it a standard WordPress plugin or Squarespace form? If it’s the latter, that’s your most immediate exposure.
  2. Check your analytics. Go to your website, right-click, “View Source,” and search for “google-analytics” or “gtag.” If you find it, you have a tracking technology issue.
  3. Ask your hosting provider for a BAA. Email them and ask: “Do you sign Business Associate Agreements?” If the answer is no (or if they don’t know what a BAA is), your hosting isn’t HIPAA-compliant.

Those three checks cover the most common violations. For a comprehensive audit that includes all seven common violations plus conversion analysis, that’s what our free HIPAA Website Report Card covers.

The takeaway for small practices: You’re not too small to be investigated, and you’re not too small to be fined. The majority of enforcement actions target organizations smaller than major hospital systems. The most common trigger is something you may not have done yet: a risk analysis that includes your website.

Think Your Practice Is Too Small to Be a Target?

The data says otherwise. Our free Report Card shows you exactly where your site is creating compliance exposure. Before OCR finds it first.

Get Your Free Report Card

If you run a practice in this space, see how we build for Mental Health Practices.

Related Industries

Mental Health Practices →Dental Practices →

Start here

For the full picture, read the pillar guide: 7 HIPAA Violations Hiding on Your Practice Website Right Now.

NOVRASCALE

AI automation for small business. We build the AI system that catches every lead and books more work, so your schedule fills itself.

Get My Free Report Card

Features

  • Lead Generation
  • Website Design
  • Local SEO
  • AI Receptionist
  • AI Follow-Up
  • AI Review Responder
  • AI Quote Builder
  • Review Generation
  • CRM & Pipeline
All features

Industries

  • HVAC
  • Real Estate
  • Roofing
  • Dental
  • Mental Health
  • Law Firms
All 20 industries

Compare

  • vs. Wix
  • vs. Squarespace
  • vs. WordPress
  • vs. GoDaddy
  • vs. Webflow
All comparisons

Tools & resources

  • Free Website Report Card
  • Money-Leak Calculator
  • The platform
  • Request access
  • Demo walkthrough
  • Portfolio
  • Blog
  • Docs
All resources

Company

  • About
  • Reviews
  • Team
  • Contact
  • Talk to Sales
  • FAQ

© 2026 NovraScale LLC. All rights reserved.

Powered by the NovraScale One Platform
PrivacyTermsCancellationBAASecuritySitemap