Who will enforce the Privacy Rule and what are the penalties?
The Privacy Rule is administered by the DHHS Office of Civil Rights. These penalties include: • Fines of $100 for each accidental violation • Fines up to $250,000 and federal prison sentences of up to 10 years for selling PHI or using it to harm someone. Persons who violate HIPAA are also liable for prosecution under state privacy laws.