The HIPAA Enforcement Curve: Why HHS Settlement Amounts Are Climbing for Small Clinics, and What a CFO Should Plan For

The HIPAA Enforcement Curve: Why HHS Settlement Amounts Are Climbing for Small Clinics, and What a CFO Should Plan For
TL;DR
  • HHS Office for Civil Rights is settling more HIPAA cases against small clinics than at any prior point in the rule's history, and the average settlement amount has trended upward each year since 2022.

  • The cited findings are not exotic. They are the same four basics (missing or inadequate Risk Analysis, missing encryption on devices and backups, unreviewed access logs, and missing written policies) that small clinics consistently underinvest in because they assume these problems belong to hospital systems, not to fifteen-provider practices.

  • The CFO question is no longer whether to budget for HIPAA compliance. It is what line item the budget should sit in, what the program costs over a five-year horizon, and how to weigh that cost against the loss exposure your firm is currently carrying without a budgeted program.

The Six-Figure Settlement Over One Unencrypted Laptop

A small specialty clinic in a Midwestern state, a practice with fewer than fifteen providers, no hospital affiliation, and no large IT department, settled with HHS Office for Civil Rights in 2024 for an amount that closed at six figures, with a corrective action plan running multiple years and biennial monitoring. The cited issue was not a sophisticated attack. It was a single laptop, lost in transit, that was not encrypted. The Resolution Agreement noted that the clinic had no documented Risk Analysis covering the device's role in handling protected health information, and no written policy requiring encryption at the device level.

The settlement amounts are not fines on the clinic's worst day. They are the cost the clinic is paying because no one had budgeted for the work that would have prevented the day from happening. And the CFOs who are paying those costs almost universally describe the experience the same way: they did not see HIPAA enforcement as a budget line item until it became one.

That is the conversation worth having before the audit forces it.

 

What the OCR Enforcement Record Actually Shows About Small Clinics

HHS publishes its Resolution Agreements and the underlying enforcement data, and the trend visible in that data is consistent across three dimensions. First, the volume of enforcement actions against small covered entities, meaning practices under fifty providers, has increased each year since 2022. Second, the average settlement amount paid by those small entities has trended upward. Third, the most-cited findings have remained essentially the same for a decade: failure to conduct or update a HIPAA Risk Analysis, failure to encrypt ePHI on portable devices and backup media, failure to review audit logs, and failure to document written policies and procedures.

The story that data tells is not that enforcement has become more aggressive in scope. It is that OCR has shifted its enforcement attention. The largest settlements are still hospital-system-scale events. The most numerous settlements are increasingly small-clinic events with the same four findings cited again and again. From the perspective of a clinic CFO, the line that matters is the second one. Your peers are paying meaningful money for failures that were entirely budgetable in advance.

 

The Four Findings Behind Most Small-Clinic HIPAA Settlements

The HIPAA Security Rule has dozens of standards, and the regulatory framework is not simple. From an enforcement-and-budgeting perspective, four findings have driven the great majority of small-clinic settlements over the past several years. Every CFO planning a healthcare IT and security budget should be able to name them and account for them.

The first finding is failure to conduct a HIPAA Risk Analysis covering ePHI in all its locations. The Security Rule requires the analysis. OCR consistently asks for it during enforcement. Small clinics routinely have either no written analysis, an analysis that is years out of date, or an analysis that does not cover newer systems such as cloud storage, telehealth platforms, mobile devices, and EHR interfaces. The analysis is not a one-time document. It is a continuously-updated program artifact, and it is the document OCR asks for first.

The second finding is failure to encrypt ePHI on devices and backup media. The Security Rule frames encryption as "addressable" rather than "required," but in enforcement practice, OCR has treated unencrypted devices that contain ePHI as nearly-automatic findings unless the clinic has documented why an alternative measure was chosen. The correct CFO posture is to budget for full encryption and not rely on the addressable framing.

The third finding is failure to review audit logs. The Security Rule requires the clinic to monitor activity in systems containing ePHI. Most clinics' systems generate the logs by default. The gap is that no one is reading them, and no one is documented as responsible for reading them. OCR considers this an internal-control failure regardless of whether a breach occurred.

The fourth finding is failure to document written policies and procedures. Many small clinics operate on informal practices that everyone in the building understands but no one has put in writing. The Security Rule requires the documentation. The Privacy Rule requires the documentation. The CFO's budget needs to fund someone, internal or external, to produce and maintain the documentation as a routine deliverable.

 

What a Baseline HIPAA Compliance Program Actually Costs

The CFO question is not whether to budget for compliance. The CFO question is what the program should cost. There is a recognizable cost structure that healthcare partners across the region operate within, and the math is worth seeing in concrete terms.

A baseline compliance program at a clinic of fifteen to fifty providers, including Risk Analysis maintained annually, encryption on all devices and backups, audit-log review as a defined function, written policies maintained and updated, training delivered annually, and vendor management in place, typically runs in a recognizable annual range. The components include a fractional security executive retainer or equivalent leadership time, an annual third-party Risk Analysis or in-program update, encryption tooling on devices and backups, audit-log review as either an internal function or an external partner deliverable, training program licensing and delivery, and a documentation maintenance discipline. The total annual investment is meaningfully less than the median small-clinic HHS settlement reported in OCR data over the past three years.

The implication is straightforward. The annual cost of the program is a budgeted, defensible operating expense. The cost of a settlement is a multi-year corrective-action plan, a payment to OCR, a corrective monitoring obligation, increased cyber insurance premiums for several renewal cycles, the operational disruption of executing the CAP, and reputational drag with patients and referring providers. The first cost is forecastable. The second is not. CFOs who have lived through both describe the difference as not even close.

 

Why Cyber Insurance Requires the Program — It Doesn't Replace It

Every healthcare CFO eventually hears some version of this argument from somewhere in the organization: cyber insurance covers HIPAA exposure, so investing in the program is double-paying for the same risk.

That is a false choice, and reading any modern cyber insurance policy renewal makes it clear why. Cyber carriers in 2026 require, at the application stage, evidence of a documented HIPAA Risk Analysis, evidence of encryption on devices and backups, evidence of MFA on systems containing ePHI, evidence of audit-log review, and evidence of vendor risk management. A clinic that does not have those things is increasingly being declined coverage entirely, or quoted at premium levels that exceed the cost of the program itself. Insurance underwriters have reframed their assessment specifically to require what the Security Rule requires. The two are not substitutes. They are sequential. The program qualifies the clinic for the insurance, and the insurance covers the residual risk after the program is in place.

The right framing is not insurance versus program. It is program first, insurance as a layer on top. Without the first, the second is either unavailable or unaffordable.

 

The Four-Step Sequence for Sizing the HIPAA Program Budget

A defensible sequence for a healthcare CFO sizing the HIPAA program for the first time runs through four steps. First, a current-state assessment that benchmarks the clinic against the four most-cited OCR findings, with a plain-language summary of where the clinic sits on each. Second, a multi-year remediation budget, scoped to address the findings that would most likely surface in an enforcement action. Third, the program's recurring annual cost is separated from one-time remediation investments, so the CFO can present both to the board with a clear distinction. Fourth, the cadence (Risk Analysis updates, audit-log review, training, policy maintenance) is operated as a calendar discipline rather than a quarterly fire drill.

The clinics that finish the sequence describe the program as boring, in the best possible sense. It produces evidence on a schedule. It survives scrutiny. It does not surprise the CFO at budget time, because it is the budget by then.

 

Build the Program on Your Terms Before a Settlement Builds It for You

A CFO who has lived through a small-clinic HIPAA settlement describes the experience as paying for the program twice. First in the settlement amount, then in the corrective-action plan that builds the program the clinic could have built on its own terms. The CFO who has not yet lived through one usually has the choice of which path to take.

If your clinic has not seen a written, current HIPAA Risk Analysis in the last twelve months, that is the conversation to have with your Tech-Operations partner now.

Five Nines Technology Group is the Tech-Operations partner serving clinics, hospitals, and healthcare practices across the region. We focus on helping CFOs translate the HIPAA enforcement curve into a budgeted operating discipline, so the program your team runs is the one you chose, not the one a Resolution Agreement imposes.

Frequently asked questions

What is the median HIPAA settlement amount for a small clinic in recent years?

HHS does not publish a single median figure, but the published Resolution Agreements over the past three years show small-clinic settlements clustering in the low six figures, with a long tail extending higher. Larger clinic systems and hospitals see meaningfully larger settlements; smaller practices have seen six-figure outcomes for findings as basic as a single unencrypted laptop or a missing Risk Analysis.

How does OCR find a small clinic to investigate?

Most small-clinic enforcement actions originate from one of three sources: a breach report the clinic itself filed, a complaint filed by a patient or former employee, or a referral from another regulator. OCR is not actively scanning. It responds to triggers, and the triggers exist whether the clinic is large or small.

Is there a meaningful difference in penalty risk between intentional and accidental HIPAA violations?

The penalty structure is tiered by culpability, ranging from "did not know" through "willful neglect, not corrected." Most small-clinic findings are categorized somewhere in the middle tiers, where the penalties per violation are still substantial. The "did not know" defense rarely applies because the rule has been in effect for over twenty years and is widely covered in industry training.

What if our clinic has cyber insurance? Does that change the budget conversation?

It changes it by changing the insurance underwriting. As of recent renewal cycles, carriers are increasingly requiring evidence of the HIPAA program's components as a precondition to coverage or favorable pricing. The cost of insurance has effectively become contingent on the cost of the program. Treat them as paired line items, not alternatives.

What does an annual Risk Analysis actually cost?

A documented, defensible Risk Analysis for a clinic of fifteen to fifty providers, performed by qualified internal staff or an external partner, typically runs in a low-five-figure range as a one-time engagement, with maintenance updates costing less in subsequent years. The cost is small relative to the consequences of not having one.

Should our clinic disclose its HIPAA program to patients?

Notice of Privacy Practices is required disclosure under the Privacy Rule. Beyond that, your patient-facing communications are a strategic decision. Some clinics make their security program a trust signal in marketing, particularly for behavioral health, pediatric, and specialty practices where trust is part of the patient relationship.

How does HITECH Act enforcement differ from HIPAA Security Rule enforcement?

HITECH expanded HIPAA penalties, extended liability to Business Associates, and introduced the breach notification rule. In practice, OCR enforcement combines all of these. Most small-clinic settlements cite multiple HIPAA and HITECH provisions in a single Resolution Agreement.

Related Blog Posts