RoutineMetric

HIPAA Breach Assessment & Penalty Calculator

Defensible 4-Factor Assessment & 2026 HHS OCR Penalty Risk Modeler

This interactive utility facilitates a rigorous 4-factor risk assessment under 45 CFR § 164.402(2) to determine whether data breach disclosures are required. It calculates precise compliance calendars and models potential Civil Money Penalty (CMP) exposure.

Step 1: Incident Characteristics

Step 2: 4-Factor Risk Assessment (45 CFR § 164.402)

Score: 4.25
Weight: 25%
Demographic / Contact Info Only1 pts

Name, address, phone, email, date of birth. Highly unlikely to lead to immediate identity theft or clinical harm.

Clinical & Treatment Records3 pts

Diagnoses, lab orders, medication lists, mental health summaries. Sensitive personal disclosures.

Financial / Billing Data4 pts

Credit/debit card numbers, bank accounts, healthcare claims data. High threat of immediate financial fraud.

Highly Sensitive Identifiers5 pts

Social Security Number, passport/state ID, biometric files, full medical record sets.

Weight: 25%
Other HIPAA Covered Entity / BA1 pts

Recipient is another provider, clinic, or health plan bound by federal confidentiality and Business Associate Agreements.

Trusted Corporate Workforce Member2 pts

Accidental access within the practice, immediately caught, with minimal exposure risk.

General Public / Unrelated Party3 pts

Disclosed accidentally to an individual citizen (e.g., mail sent to the wrong home address).

Threat Actor / Malicious Attacker5 pts

External hacker, commercial competitor, ransomware operator, or phishing operator.

Weight: 25%
Verified No Viewing (Forensic Proof)1 pts

A lost laptop was encrypted, remote-wiped, and audit records indicate zero access attempts.

High Probability of No Access2.5 pts

A misdirected envelope was returned completely sealed, unopened, and intact.

Probable Access4 pts

An unauthorized login was recorded in an EHR module. Logs suggest files were open, but exfiltration is not verified.

Confirmed Access & Exfiltration5 pts

Forensic logs prove files were downloaded, ransomware demand issued, or records public on dark web.

Weight: 25%
Complete & Immediate Mitigation1 pts

The recipient signed a formal confidentiality/non-disclosure statement, confirmed complete file shredding, and cooperated.

Moderate / Incomplete Mitigation3 pts

The device was remote-wiped after a brief delay, or recipient provided verbal deletion confirmations.

No Mitigation Possible / Achieved5 pts

Ransomware exfiltration occurred, files are in wild, or unauthorized party refuses contact.

Step 3: OCR Culpability Level & Timeline

Compromise Probability

High Risk (4.25/5.00)
High/Mandatory Breach

The probability of compromise is high. Statutorily, a breach is legally presumed to have occurred. You must proceed with statutory notification workflows immediately.

Statutory Reporting Timelines

To Affected IndividualsOctober 12, 2026"Without unreasonable delay" (Max 60 calendar days)
To HHS Secretary (OCR)March 1, 2027Within 60 days after end of the calendar year

OCR Civil Money Penalty Risk (2026)

Tier 1: No Knowledge

The entity did not know and, by exercising reasonable diligence, would not have known that the violation occurred.

Estimated Low
$1k
Estimated High
$689k
Model estimates are computed compound ranges clamped at the 2026 maximum annual cap of **$2,067,813** per identical provision violation. Actual enforcement fines are discretionary.
Advertisement
Bottom Banner Ad (728x90)

Regulatory Guide: Performing a Defensible HIPAA 4-Factor Breach Assessment

Under the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules, any impermissible use, disclosure, acquisition, or access of Protected Health Information (PHI) is statutorily presumed to be a breach. This presumption remains active unless the Covered Entity (CE) or Business Associate (BA) can prove that there is a **low probability that the PHI has been compromised**.

To overcome this legal presumption, organizations must complete a multi-factor risk assessment that covers, at minimum, the four objective criteria set forth in **45 CFR § 164.402(2)**. This tool automates that framework to ensure healthcare organizations, clinics, and IT associates generate defensible documentation, establish a standard audit trail, and plan appropriate incident disclosures without triggering premature reports or risk-heavy omissions.

Deep-Dive: The Four Legal Factors Analyzed

Factor 1: Nature and Extent of PHI Involved

Assessment demands that you analyze the exact nature of the exposed dataset. Simple demographic registries (names, addresses) carry significantly lower risk than electronic health record (EHR) files containing active medical histories, behavioral summaries, or diagnostic results. Combining demographic details with financial data (credit cards, banking information) or high-risk identifiers (Social Security Numbers, state IDs) exponentially raises identity-theft threats, making a "low risk" finding difficult to defend.

Factor 2: The Unauthorized Recipient

Who received the impermissible data? If a medical practice accidentally sends billing summaries to another provider bound by identical HIPAA standards and confidentiality obligations, the downstream risk is exceptionally low. However, if the data is exfiltrated by an external cybercriminal threat group (e.g., in a ransomware extortion event) or exposed to the general commercial public, the probability of exploit rises to its maximum statutory limit.

Factor 3: Actual Acquisition or Viewing

Did the unauthorized party actually view or copy the data? If a practice loses an electronic device, but forensic reports prove the hardware was fully encrypted, remote-wiped, and audit trails show zero database query activity, the data was never acquired. Conversely, if an unauthorized EHR login has occurred, audit records indicating multiple patient files were opened are sufficient to trigger a statutory disclosure duty.

Factor 4: The Extent of Mitigation

What immediate corrective steps did you take? Immediate containment is highly weighted. For example, if a clinic sends PHI to the wrong patient, and that recipient returns the document unopened or signs a legally binding non-disclosure certificate confirming secure shredding, the risk has been effectively mitigated. Ongoing ransomware threats or missing files allow no possible mitigation, locking the incident in a high compromise tier.

Statutory Disclosures: 60-Day Deadlines & the 500+ Threshold

Once a breach is identified, the clock starts ticking from the **Date of Discovery** (which is the date the entity knew, or should have known through reasonable diligence, that a security event took place). Individual and media notices must occur **without unreasonable delay** and under no circumstances later than **60 calendar days**.

For breaches affecting **fewer than 500 individuals**, federal OCR disclosures can be compiled annually, due within 60 days following the end of the calendar year (i.e., March 1st, or February 29th on leap years). For breaches affecting **500 or more individuals**, the regulatory burden increases: OCR must be notified immediately alongside individuals, and prominent regional media outlets must receive a structured press disclosure.

HHS OCR Civil Money Penalties (CMPs) — 2026 Adjustments

Failure to comply with the HIPAA Breach Notification or Privacy rules can lead to significant civil fines administered by the Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Under federal mandate, OCR penalizes practices based on their Culpability Level (Tiers 1 to 4).

In 2026, inflation adjustments have updated these tiers:

  • Tier 1 (No Knowledge): Occurs when the practice did not know and could not have reasonably known about the violation. Individual penalties range from $137 to $68,928 per violation.
  • Tier 2 (Reasonable Cause): Deemed when the practice should have been aware of the issue but acted without willful neglect. Individual penalties range from $1,379 to $68,928.
  • Tier 3 (Willful Neglect - Corrected): Defined as conscious intentional disregard or reckless indifference that was fully corrected within 30 days of discovery. Fines range from $13,785 to $68,928 per violation.
  • Tier 4 (Willful Neglect - Uncorrected): Occurs when conscious disregard remains uncorrected after the 30-day window. Fines begin at $68,928 and can escalate directly to the maximum annual cap of $2,067,813.

Frequently Asked Questions (HIPAA Breach Compliance)

Legal Disclaimer: This calculator and educational guide are designed to help health organizations structure breach risk assessments and estimate regulatory deadlines. They do not constitute formal legal counsel or represent binding determinations by HHS OCR. Because breach response carries high compliance stakes, entities must always engage qualified privacy counsel to review incident determinations before final filings.
Advertisement