Employee Benefit News for School, City and County Employers

New Civil Penalty Thresholds for SBC, MSP, and HIPAA Violations

Written by Steve Smith | Feb 3, 2026 3:26:33 PM

On January28, 2026, the U.S. Department of Health and Human Services (HHS) issued a final rule increasing several key penalties for group health plans. Because these inflation‑adjusted penalties are substantial, health insurers and employers should periodically review their plan administration practices to help ensure ongoing compliance.

 

Summary of Benefits and Coverage

The Affordable Care Act requires group health plans and health insurance issuers to provide participants and beneficiaries with a Summary of Benefits and Coverage (SBC). Failure by a health insurer or non-federal governmental health plan to provide the SBC may now result in penalties of up to $1,443 per participant or beneficiary, matching the current penalty for ERISA-covered group health plans.

 

Medicare Secondary Payer (MSP)

When Medicare is the secondary payer, employers may not discourage employees from enrolling in their group health plan or offer any financial or other incentive to avoid or terminate enrollment in a plan that would otherwise be primary. Violations can result in penalties of up to $11,823. In addition, insurers, third-party administrators, or plan fiduciaries that fail to report when a group health plan is or was primary may face penalties of up to $1,512.

 

HIPAA Privacy and Security Rules

Penalties for covered entities and business associates that violate HIPAA privacy and security rules vary by the type and severity of the violation. Civil penalties are divided into four tiers based on the organization’s level of knowledge:

  • Tier One: There was no knowledge of the violation, even with reasonable diligence, the penalty amount is between $145-$73,011 per violation with an annual cap of $2,190,294.
  • Tier Two: If the violation was due to reasonable cause, the penalty amount is between $1,461-$73,011 per violation with an annual cap of $2,190,294.
  • Tier Three: For corrected violations caused by willful neglect, the penalty amount is between $14,602-$73,011 per violation with an annual cap of $2,190,294.
  • Tier Four: For violations caused by willful neglect that are not corrected, the penalty amount is between$73,011-$2,190,294 per violation with an annual cap of $2,190,294.

Download the bulletin for more details.