Hospital Management Software: Cost and HIPAA Facts 2026
By Ashiqur Rahman
Somewhere on the vendor website you are evaluating, there is probably a badge that says HIPAA compliant. The agency that enforces HIPAA has published, in writing, that it does not issue such a thing.
That gap between what the rules say and what the market claims runs through this entire category, and it is where this guide spends most of its time. It also covers the aspects of the decision that come before compliance, such as what a hospital management system must do, how much the software costs when anyone will tell you, how the clinic tier differs from the hospital tier, and when it makes more sense to build something custom rather than the more costly option.
The short version. Of seven major enterprise hospital software vendors, one publishes a price. None of the fifteen vendors checked publish an implementation timeline, and only three state clearly that a Business Associate Agreement is included at no extra cost. On penalties, HHS publishes two different sets of annual caps and has never reconciled them, which is why the figure you have seen could be $25,000, $1.5 million or $2,190,294 and still be defensible. HIPAA requires no specific encryption standard, mandates no country for your data, and sets no retention period for medical records. And the correction that should change how you buy: in HHS’s 2024 entity-type data, clinics and hospitals reported 76% of large breaches but 14% of the people harmed, while their software vendors accounted for 85%.
How Omega Solution checked this. Omega Solution opened the published pricing page of every vendor named here on 16 September 2026 and quoted the currency each page actually served rather than the currency its web address implied. Where a vendor publishes no price, this guide says so instead of substituting a review site’s estimate, and five of them publish nothing. Each regulatory claim links to the page of the organisation that published it, which in the case of US regulations, implies the Federal Register and HHS.gov rather than a summary provided by a legal firm. When HHS publishes two opposing perspectives, as it did on penalty caps, both positions, rather than the one that creates a more coherent sentence, appear here with their sources.
What Is a Hospital Management System?
A hospital management system is the software of record for everything a hospital does that is not clinical treatment itself: registering patients, scheduling clinicians, recording what was done, billing for it, and managing beds and inventory. It is an operations system with a clinical record attached, and the clinical record is the part that carries legal weight.
How it differs from an EHR, which is the distinction that confuses buyers
The patient’s clinical chart, including diagnoses, prescriptions, allergies, notes, and outcomes, is an electronic health record. The broader administrative framework that envelops a hospital is called a hospital management system.
In practice, the two have merged. Epic, Oracle Health and MEDITECH sell one product that does both, which is why searching for hospital management software returns EHR vendors. Smaller practices often buy them separately, running a clinical record from one vendor and scheduling and billing from another.
The distinction matters for one reason: the clinical record is the regulated artefact. Your scheduling data is commercially sensitive. Your clinical notes are protected health information with a federal statute attached.
The modules, and which ones decide the purchase
- Master index and patient registration: The most frequent cause of downstream data issues is one record per person, which is more difficult than it might seem.
- Scheduling: Clinicians, rooms, equipment and patients, all constrained against each other.
- The clinical record: Notes, orders, results, medications, allergies.
- Billing and revenue cycle: Coding, claim submission, denial management, patient statements. For most providers, this module decides whether the system pays for itself.
- Pharmacy and inventory: Stock, expiry, controlled substance tracking.
- Reporting: Regulatory submissions, payer reporting, internal operations.
Buyers evaluate on the clinical record because it is what clinicians touch. The revenue cycle module is what determines the return, and it is the one most often under-specified in a demand document.
The question to ask before any demo
Ask the vendor to show you one patient’s complete audit trail: every person who opened the record, when, from where, and what they changed, going back a year, exported to a file you can hand to an auditor. Most demos are built around the clinical workflow rather than the reconstruction of who saw what. The reconstruction is what you will need on the worst day you have.
What Hospital Management Software Costs
Hospital management software splits into two markets that price completely differently. In the enterprise tier, six of seven major vendors publish no price at all, and the one that does charges $499 per provider per month. In the clinic tier, six of eight publish full prices from $19 to $199 per provider. The gap is not scale. It is disclosure.
The enterprise tier, and who will not name a number
Omega Solution checked the published pages of seven major hospital software vendors on 16 September 2026.
| Vendor | Publishes a software price? | What appears instead |
|---|---|---|
| Epic Systems | No | No pricing page exists and no request-a-quote CTA either. The subject is absent |
| Oracle Health | No | “Contact us”, “Request a demo”. Its published pay-as-you-go price list covers payment processing only, at 2.8% and a $0.15 transaction fee |
| MEDITECH | No | Discusses cost only in the abstract, warning against systems exceeding “5% of total operating costs” |
| Altera Digital Health | No | No pricing, no tiers, no pricing CTA |
| athenahealth | No | “Our pricing is simple and transparent” and “our pricing model corresponds to your organization’s collections”. The percentage is never stated |
| NextGen Healthcare | No | “Chat with Sales”, “Book a Meeting”, “Request a Demo” |
| eClinicalWorks | Yes | See below |
eClinicalWorks is the only enterprise vendor in the group publishing real figures:
| Plan | Published price | Basis |
|---|---|---|
| EHR only | $499 per month | Per provider |
| EHR with practice management | $599 per month | Per provider |
| Revenue cycle management | 2.9% | Of practice collections |
All three carry “no start-up costs”, and eClinicalWorks includes initial training for practices with one to nine providers, with additional implementation fees above that.
What this implies for you. The amount you are ultimately offered is not a list price when six out of seven merchants refuse to publish anything. It is an assessment of the amount your company will pay. Arrive at that discussion with eClinicalWorks, the market’s only disclosed benchmark, which is $499 per provider each month, and ask the other company to clarify the differences.
The clinic tier, where prices exist
| Vendor | Standard price | Basis | Free tier or trial |
|---|---|---|---|
| Zanda | US$19, US$49 | Per practitioner | 14-day trial, no card |
| Carepatron | $0, $31, $39 | Per user | Free tier, 14-day trial |
| SimplePractice | $49, $79, $99 | Per clinician | 30-day trial |
| Jane App | $54, $79, $99 | Per practitioner, plus $49 per additional | Demo account only, no trial |
| TherapyNotes | $69 solo, $79 plus $50 per additional clinician | Per clinician | 30-day trial |
| Practice Fusion | $199 | Per provider, annual commitment required | Two-week trial |
Two vendors publish pages titled Pricing that contain no plan prices at all: Tebra and DrChrono. Both publish ancillary fees instead, which produces the odd situation of knowing that DrChrono charges $0.05 per text message and $0.07 per faxed page without knowing what the software costs.
Read the headline prices carefully. Every clinic-tier price above except Jane App’s and Practice Fusion’s is currently discounted on the vendor’s own page. SimplePractice runs 50% off for three months, Carepatron 50% off for six, Zanda 50% off for six. The figures in the table are the standard prices you will pay from month four or seven onward, which is the number to budget against.
The three things none of them publishes
Across all fifteen vendors, enterprise and clinic:
- Zero publish an implementation timeline. Not one. The closest anything comes is eClinicalWorks scoping training by practice size, which is not a duration.
- Only three state unambiguously that a Business Associate Agreement is included at no extra cost, and they are SimplePractice, Carepatron and Zanda. Two more incorporate one without addressing cost. Jane App states that it can work with you to develop a BAA Agreement, which is a negotiation rather than an inclusion. Nine say nothing at all, including every one of the seven enterprise vendors.
- Three of the four that publish a data migration cost do so because the migration is free.
A Business Associate Agreement is not a nice-to-have. Under HHS’s rules, it is the contract that makes it lawful for the vendor to hold your patients’ data at all, which the compliance section covers. Ask for it in writing before you sign, and ask whether it costs extra.
One trap worth knowing
Healthcare software vendors price by the visitor’s location rather than by the web address. Jane App is a Canadian company, and its Canadian pricing path served prices labelled USD when Omega Solution fetched it on 16 September 2026. Zanda, by contrast, does serve genuinely different currencies and genuinely different price points by country, at US$19 on its main path and AU$29 on its Australian one, which are not conversions of each other. Check the currency your own browser is set to before you build a budget on a figure from a comparison article.
Clinic Management Software
Clinic management software is the same category scaled down and priced per practitioner rather than per organisation, running from free to $199 a month. The functional difference is not fewer features. It is that a clinic buys a product and a hospital buys a project, which is why clinic vendors publish prices and hospital vendors do not.
What the smaller tier gives up, and what it does not
Clinic products handle scheduling, the clinical record, billing and patient communication competently. What they generally do not do is multi-site inventory, bed management, operating theatre scheduling, or the regulatory reporting a hospital is obliged to file.
Compliance is something they never give up. A thousand-bed hospital and a two-clinician practice are subject to the same federal regulations. A small practice is expected to establish sufficient and necessary safeguards, not fewer requirements, according to HHS’s Security Rule, which is specifically “scalable, and technology neutral to all different sizes of regulated enterprises”.
The features that separate them in practice
- Insurance and claims handling: The largest functional gap between clinic products. Jane App charges $20 a month plus per-practitioner fees for insurance billing as an add-on rather than including it.
- Group practice structure: Whether additional practitioners cost a full seat or a reduced one. TherapyNotes charges $79 for the first clinician and $50 for each additional. SimplePractice charges $99 and $74.
- Patient-facing booking and reminders: Usually included, occasionally an add-on.
- Documentation assistance: Increasingly sold separately. Jane App charges $15 a month per opted-in practitioner for its AI scribe.
- Telehealth: Included in most, an add-on in some, and worth confirming rather than assuming.
How to size the cost honestly
Multiply the standard price by the number of practitioners who will log in, add the per-practitioner add-ons, and then add the ones sold per-transaction. A four-clinician practice on SimplePractice Plus is $99 for the first and $74 for each of the other three, which is $321 a month standard, not the $49.50 the pricing page leads with.
Custom Hospital Software vs Off-the-Shelf
For most clinics and most hospitals, buying is correct. Packaged products in this category are mature, regulated workflows are genuinely standardised, and the clinic tier starts at $19 a month against a custom build that will not. Omega Solution will say so on a call. Custom becomes rational at three specific points, and organisation size is not one of them.
When buying is obviously right
If your workflows resemble other practices in your speciality, if you have no integration requirement beyond a lab and a clearinghouse, and if nobody in your organisation is currently maintaining a spreadsheet to work around your system, buy. The published clinic-tier products above will beat anything custom on cost and on time to value, and it is not close.
The three points where custom becomes rational
One. The workflow is the differentiator. If how you deliver care is why patients or referrers choose you, and a packaged product forces you to deliver it differently, you are paying a license fee to become more like your competitors.
Two. The integration is the actual problem. This is the most common real reason organisations call Omega Solution about healthcare software. The packaged EHR is fine, the billing system is fine, the lab interface is fine, and the work of moving data between them is consuming a full-time role. That problem lives between two vendors’ products, and neither vendor owns it.
Three. You have outgrown the multi-site model. Packaged products handle multiple locations up to a point. Past it, consolidation becomes somebody’s permanent job, and the reporting stops being trustworthy.
What the comparison articles will not tell you
Omega Solution read the page-one results for this comparison. Of twelve pages, zero mention whether a Business Associate Agreement is included, and zero acknowledge that six of seven enterprise vendors publish no price, which is the single most useful fact a buyer researching cost could be given.
Two of them do release pricing ranges for Oracle Health and Epic, which are displayed as those suppliers’ prices. A price is not disclosed by either seller. These are approximations dressed like quotes.
Patient Data Compliance for Clinics
The most common compliance claim in healthcare software is that a product is HIPAA compliant. The agency that enforces HIPAA has published the opposite. In the Office for Civil Rights’ own words, HHS and OCR “do not certify any persons or products as ‘HIPAA compliant.'” Of 56 competitor pages Omega Solution audited, zero say so. Seven claim otherwise.
What HHS says about compliance badges
The full sentence, from OCR’s page on misleading marketing claims:
“HHS and OCR do not endorse any private consultants’ or education providers’ seminars, materials or systems, and do not certify any persons or products as ‘HIPAA compliant.'”
OCR has said the same thing in two other places. Its FAQ on certification states that HHS “does not endorse or otherwise recognise private organisations’ ‘certifications’ regarding the Security Rule, and such certifications do not absolve covered entities of their legal obligations. Its cloud computing guidance adds that “OCR does not endorse, certify, or recommend specific technology or products.
This is not a technicality. Compliance is a property of how your organisation operates, not a property of software you bought. A vendor can build a product that makes compliance achievable. It cannot sell you compliance, and a badge saying otherwise is marketing.
What the Security Rule requires
Three categories, in HHS’s own words: administrative, physical, and technical safeguards for protecting ePHI. Regulated entities must ensure the confidentiality, integrity and availability of all electronic protected health information they handle, protect against reasonably anticipated threats and impermissible disclosures, and ensure their workforce complies.
Note what is absent: any specific technology. HHS states directly that the Security Rule does not dictate the specific security measures that a regulated entity must use.
Four things HIPAA does not require, and vendors say it does
It does not require a specific encryption standard. Encryption is an addressable implementation specification under 45 CFR 164.312(a)(2)(iv), not a required one, and that text is unchanged. HHS: The Security standards were designed to be ‘technology neutral’. If a risk assessment concludes encryption is reasonable and appropriate, you must implement it, and if it concludes otherwise, you must document that and implement an equivalent alternative. Of the pages Omega Solution audited, two present specific algorithms as HIPAA requirements, one asserting flatly that “Encryption Is Now Mandatory.”
It does not require your data to be stored in any particular country. From HHS’s cloud guidance: “The HIPAA Rules do not include requirements specific to protection of electronic protected health information processed or stored by a CSP or any other business associate outside of the United States.” OCR notes the risks may vary by location, which is a risk-assessment point rather than a residency rule.
It does not specify how long medical records must be kept. HHS: Medical record retention obligations are not covered by the HIPAA Privacy Rule. Instead, the length of time that medical records must be kept is typically governed by state regulations. Your compliance documentation is subject to retention requirements under HIPAA, which is distinct from the charts.
It does not certify software. See above.
The penalty figures, and why HHS has two answers
This is the messiest corner of HIPAA, and the mess belongs to the regulator rather than to the people quoting it. HHS publishes two different sets of annual caps and has never reconciled them.
What the regulation says. 45 CFR 160.404 sets four culpability tiers and applies the same annual cap for identical violations to all four. Those amounts are adjusted for inflation each year under 45 CFR part 102. The figures are current as of 28 January 2026, published at 91 FR 3665:
| Culpability tier | Minimum per violation | Maximum per violation | Annual cap |
|---|---|---|---|
| Did not know | $145 | $73,011 | $2,190,294 |
| Reasonable cause | $1,461 | $73,011 | $2,190,294 |
| Willful neglect, corrected | $14,602 | $73,011 | $2,190,294 |
| Willful neglect, not corrected | $73,011 | $2,190,294 | $2,190,294 |
Note the shape of that last row, because it is the part most often reproduced wrongly: $73,011 is the maximum for the first three tiers and the minimum for the fourth. At the top tier, a single violation can reach the annual cap on its own.
What HHS says it will actually do. In April 2019, HHS published a Notification of Enforcement Discretion at 84 FR 18151, concluding that the better reading of the HITECH Act is four different annual limits, and stating that as a matter of enforcement discretion, all HIPAA enforcement actions will be governed by the following interim penalty tiers:
| Culpability tier | Per violation, unadjusted | Annual limit |
|---|---|---|
| Did not know | $100 to $50,000 | $25,000 |
| Reasonable cause | $1,000 to $50,000 | $100,000 |
| Willful neglect, corrected | $10,000 to $50,000 | $250,000 |
| Willful neglect, not corrected | $50,000 | $1,500,000 |
Not just the annual column, but both columns are affected by the gap. A single infraction in all four tiers is limited to $50,000 under the 2019 notice. The top-tier cap is 43 times greater at $2,190,294 under the inflation-adjusted legislation.
And then nothing happened. HHS wrote in 2019 that it expects to engage in future rulemaking to revise the penalty tiers in the current regulation. As of September 2026, that rulemaking has not occurred. The regulation still carries one cap for all four tiers. The enforcement notice still governs enforcement.
Two things follow, and both matter more than the headline number.
It is impractical to expose a lower-tier infraction to $2.19 million. According to OCR, a violation you were unaware of will be subject to an annual cap of $25,000. That exposure is overstated by a factor of almost eighty when reading the inflation-adjusted regulation alone.
And $1.5 million is not a stale number. It is the enforcement-discretion annual cap for willful neglect left uncorrected, which is the tier most likely to apply in an enforcement action anyone writes about. A page quoting $1.5 million may be citing OCR’s stated position rather than failing to update.
Are the 2019 caps themselves inflation-adjusted? HHS has never published an adjusted version of them. The annual adjustment operates on the amounts in the regulation, and the 2019 notice has stood untouched since publication. An adjusted set does circulate, at roughly $36,505, $146,022, $365,055 and $2,190,294, and it is worth knowing where those came from: they are HIPAA Journal’s own arithmetic, applying the OMB multipliers to the 2019 figures, and that publication says so openly. They are a reasonable estimate. They are not an HHS number, and no HHS document contains them.
So the four figures OCR has actually committed to in writing are the unadjusted ones above. What that means for your own exposure in a specific enforcement action is a question for counsel, not for a software vendor.

Why does this matter when you read anything else on HIPAA penalties? The problem in the category is not that publishers use an old number. It is that nobody says which of HHS’s two positions their number comes from, and that distinction is the only thing that makes any of the figures interpretable. Of the six competitor pages Omega Solution audited that quote penalties, none distinguishes the regulation from the enforcement discretion. One prints a $1.9 million annual cap and a “$5,000 to $75,000 per violation” range that matches neither.
The breach data, and the correction inside it
HHS publishes every breach affecting 500 or more people. Read any figure in this area with its year attached, because the two most recent years are not comparable and quoting either alone will mislead you.
| Calendar year | Breaches of 500+ | Individuals or records affected |
|---|---|---|
| 2024 | 663 | 242,908,056 |
| 2025 | 710 | 61,556,256 |
More breaches, a quarter of the people. A single very large incident can move the individual’s column by an order of magnitude while the breach count barely shifts, which is why the count and the total belong together or not at all.
Hacking dominates in both years, and mundane causes barely register. In 2025, hacking and IT incidents were 68.7% of breaches and 85.3% of records, with unauthorised access or disclosure at 20.7% of breaches and 2.4% of records. In 2024, the split was starker still, at 81% of breaches and 99% of individuals. Theft, loss and improper disposal together accounted for 21 breaches out of 663 that year. The lost laptop is not the threat model any more.
And the correction that should change how you buy. On the entity-type breakdown in OCR’s 2024 Report to Congress, health care providers reported 505 of the large breaches, 76% of the count, but only 14% of the people affected. Business associates reported 106 breaches, 16% of the count, and 85% of the people affected.
Providers also commit several minor violations. Their merchants have few major ones. The best rationale for reading the Business Associate Agreement, which nine out of fifteen suppliers will not discuss, is that the vendors you select will have the biggest impact on whether your patients’ data is exposed.

Two notes on dating. The entity-type split above is calendar year 2024, because HHS has not published a 2025 breakdown by entity type. And by location in 2024, network servers accounted for 63% of breaches and 98% of affected individuals, email for 25% and 2%, and the electronic medical record itself for 20 breaches out of 663.
Your reporting deadlines
For a breach affecting 500 or more individuals, notify HHS “without unreasonable delay” and no later than 60 calendar days from discovery. For breaches affecting fewer than 500, you may report annually, within 60 days after the end of the calendar year in which the breach was discovered. Individuals must be notified within 60 days either way, and breaches affecting more than 500 residents of a state also require media notice.
The rule change that has not happened
In January 2025, HHS proposed a substantial Security Rule update at 90 FR 898, which would, among other things, make much of what is currently addressable into a requirement. It received 4,747 comments.
It has not been finalised, and the date has already slipped once. A final rule was previously expected in May 2026. The 2026 Unified Agenda now lists the rulemaking under Long-Term Actions with a projected final action of July 2027. Anyone telling you new HIPAA security requirements take effect this year is ahead of the regulator. The current Security Rule remains in effect, which is what HHS itself says, and 45 CFR 164.312(a)(2)(iv) still reads as it did.
Outside the United States, briefly
European Union. Health data is special category data under GDPR Article 9(1), and processing it is prohibited unless a specific condition applies. Separately, the European Health Data Space Regulation (EU) 2025/327 entered into force in March 2025, with general application from 26 March 2027 and its major obligations phased to 2029 and 2031.
Canada. Under PIPEDA, breaches are reportable where there is a real risk of significant harm, and the deadline is as soon as feasible rather than a fixed day count. Organisations must keep records of all breaches for two years, not only reportable ones.
What a Clinic Management Rollout Involves
Omega Solution has not published a healthcare client story with measured outcomes, so this section is not one. It is an account of the work and where it slips. Of seven page-one results for healthcare software case studies, six are listing pages rather than case studies, and the best-evidenced example is a 2011 National Academies chapter.
The four phases
Phase one, the patient index. Before any software is chosen, decide what a patient record is and who owns it. Practices arrive with the same human being entered three times under two spellings and a maiden name. This phase produces nothing visible and determines whether every later number is trustworthy.
One site, one speciality, and phase two. For a complete cycle that includes a billing run, a rejection, a referral, and a records request, choose the most common workflow, not the simplest. Issues discovered here cost one site to resolve.
Phase three, the interfaces. Lab, imaging, pharmacy, clearinghouse, and whatever your referrers use. This is the phase that is invisible from the front desk and the one that overruns.
Phase four, the remaining sites. One at a time. A simultaneous cutover across locations is the most expensive mistake available in this category, and it is entirely avoidable.
What a real case study would have to contain
A healthcare software case study is worth reading only if it carries the client name or an agreed anonymisation, the patient or encounter volume, a before-and-after number with a stated baseline, a named person with their job title, and the rollout duration per site. Of the seven results Omega Solution audited, two give a before-and-after number with a stated baseline and two quote a named person with a title. Omega Solution holds itself to all five, which is the reason no client is named here.
Why Omega Solution Builds Healthcare Systems
Omega Solution builds custom software from Dhaka for clients in the United States, Canada and Europe, and holds no reseller license on either side of the buy-or-build question. That is why this guide spends more words telling you when to buy a $19-a-month product than selling a build.
Where Omega Solution is useful in healthcare
The work that genuinely needs building in this sector is rarely another patient record. It is the layer between systems: moving data between an EHR, a billing platform, a lab interface and a reporting obligation, without a person retyping it and without the audit trail breaking in the middle.
Omega Solution’s healthcare product, Healthcare OS, covers staff and doctor management, patient records, appointments, medicines and billing with role-based access, and is the starting point when a practice wants something configured rather than written from scratch. Where the requirement is integration or consolidation, the work is custom by nature.
What Omega Solution will tell you on the call?
That most practices should be bought. That a Business Associate Agreement is a contract question before it is a technical one. That nobody can sell you HIPAA compliance, including Omega Solution. And that if the honest answer is a packaged product at $49 a month, that is the answer you will get.
Longer-term work is judged over years and over audits, which is why maintenance and support is a named part of the engagement rather than an afterthought.
Frequently Asked Questions
The ten answers below cover what hospital management software costs, why most enterprise vendors will not quote one, and the four things HIPAA is widely said to require and does not. Every regulatory answer links to the body that issued the rule, and the penalty figures are the inflation-adjusted amounts current as of 28 January 2026.
How much does hospital management software cost?
Six of seven major enterprise vendors publish no price at all. The exception is eClinicalWorks at $499 per provider per month for its EHR, $599 with practice management, or 2.9% of collections for revenue cycle management. Clinic-tier products publish standard prices from $19 to $199 per provider per month.
Why will Epic and Oracle Health not publish a price?
Neither publishes pricing of any kind on its own site, and Epic has no pricing page or quote request at all. Any Epic or Cerner figure you see in a comparison article is that publisher’s estimate, not a vendor price, even when it is presented in a pricing table.
Is there such a thing as HIPAA-certified software?
No. HHS’s Office for Civil Rights states that it does not certify any persons or products as ‘HIPAA compliant’, and that private certifications do not absolve covered entities of their legal obligations. Compliance is a property of how your organisation operates, not something a product can carry.
Does HIPAA require encryption?
Not specifically. Encryption is an addressable implementation specification rather than a required one, and HHS describes the Security Rule as technology neutral. If your risk assessment finds encryption reasonable and appropriate, you must implement it. If not, you must document that and implement an equivalent alternative.
Does HIPAA require patient data to stay in the United States?
No. HHS states the HIPAA Rules include no requirements specific to protecting electronic protected health information stored outside the United States, provided a Business Associate Agreement is in place, and the other rules are met. OCR notes that risks may vary by location, which is a risk-assessment consideration rather than a residency requirement.
What is the maximum HIPAA fine?
It depends on which HHS document you read, and both are current. The inflation-adjusted regulation sets one annual cap of $2,190,294 across all four culpability tiers as of 28 January 2026. A 2019 HHS enforcement discretion notice applies four different annual limits, from $25,000 for a violation you did not know about up to $1,500,000 for willful neglect left uncorrected, and states that all enforcement actions will be governed by those tiers. HHS said it would reconcile the two by rulemaking and has not.
How long do I have to report a breach?
For breaches affecting 500 or more individuals, notify HHS without unreasonable delay and within 60 calendar days of discovery. For breaches affecting fewer than 500, you may report annually within 60 days after the end of the calendar year in which the breach was discovered. Individuals must be notified within 60 days in both cases.
Are most healthcare breaches caused by clinics or by their vendors?
By count, providers report 76% of large breaches. By people affected, business associates account for 85%. Providers have many small breaches and their vendors have few enormous ones, which makes vendor selection the larger determinant of exposure.
Do the new HIPAA security rules take effect soon?
No. The Security Rule update proposed in January 2025 has not been finalised. The 2026 Unified Agenda lists it as a long-term action with a projected final action of July 2027, and HHS states the current Security Rule remains in effect.
Is a Business Associate Agreement included in the price?
Usually unstated. Of fifteen vendors checked, only SimplePractice, Carepatron and Zanda state clearly that a Business Associate Agreement is included at no extra cost. Nine say nothing at all, including every enterprise vendor. Ask before you sign.





Sep 19, 2026
