Who is liable for privacy violation under HIPAA?
Civil and criminal penalties can be imposed for noncompliance with HIPAA. The imposition of these penalties are against Covered Entities (e.g. healthcare provider) but not directed directly against Business Associates (e.g. medical transcription service organization). Healthcare providers should ask their transcription company about their privacy and security regulations and ensure that they are contractually obligated to comply with these regulations. What is the penalty for not meeting HIPAA compliance? The total amount from civil penalties for multiple violations by a Covered Entity during a calendar year is capped at $25,000. HIPAA also provides from criminal liability for Covered Entities for knowingly obtaining or disclosing individually identifiable health information. The maximum penalty is a fine of $50,000 and imprisonment of one year. If the offense is committed under false pretenses, the maximum penalty is a fine of $100,000 and imprisonment of five years. If the offense is