Skip to main content
U.S. flag

An official website of the United States government

Return to Search

Section 1104 HIPAA Penalties

Guidance for the specific statutes regarding the penalties for noncompliance of covered entities.

Issued by: Centers for Medicare & Medicaid Services (CMS)

Issue Date: August 02, 2020

A gavel, medical emblem, medical person working at a computer, and a set of scales standing on HIPAA and ACA books

The Administrative Simplification provisions outlined in Section 1104 of HIPAA and subsequent legislation require that all HIPAA-covered entities that conduct electronic health care transactions comply with the standards adopted by the Secretary. The standardization of health care information exchange achieves greater uniformity in data transmission and decreases administrative burden.

Specific statutes regarding the penalties for noncompliance of covered entities can be found in the Code Federal Regulation 45 CFR 160.400 through 45 CFR 160.426 and 42 U.S. Code Part C - Administrative Simplification, §1320d–5.

HHS is committed to making its websites and documents accessible to the widest possible audience, including individuals with disabilities. We are in the process of retroactively making some documents accessible. If you need assistance accessing an accessible version of this document, please reach out to the guidance@hhs.gov.

DISCLAIMER: The contents of this database lack the force and effect of law, except as authorized by law (including Medicare Advantage Rate Announcements and Advance Notices) or as specifically incorporated into a contract. The Department may not cite, use, or rely on any guidance that is not posted on the guidance repository, except to establish historical facts.