HIPAA compliance and enforcement dashboard showing audit findings, an overdue risk analysis, and a settlement case-tracking table on dual monitors in a dental office

The fastest way to understand HIPAA is not to read the rule. It is to look at what the government has actually penalized practices for.

These HIPAA violation examples are real enforcement actions from the HHS Office for Civil Rights, and most of them are not the massive insurer breaches that make headlines. They are small practices, including ten dental offices, penalized for ordinary mistakes: answering a Yelp review, being slow to hand over records, or never running a risk analysis. Every dollar figure and every case below is drawn from OCR’s own published enforcement record. Read them as a warning list. A few of these practices dug in and made things worse, and you will see where. But most of them started in the same ordinary places your own office operates in every day: the front desk, the records request, the reply to a bad review.

Every Dental Practice OCR Has Penalized

Most roundups of HIPAA violations are written for hospitals and health systems. Dental practices are usually a footnote, if they appear at all. So we went through OCR’s enforcement record and pulled out every monetary action against a dental provider that OCR publishes on its own pages.

As of September 2026 there are ten. Here they are, largest to smallest, dated by the year OCR announced each one. OCR also resolves cases with corrective action and no payment, so this is the record of actions that carried a dollar figure. Its Right of Access Initiative is still running, so this list grows.

Practice Year What triggered it Instrument Amount
Great Expressions Dental Center of Georgia 2022 Records delay over a year, plus a copying fee not based on cost Settlement $80,000
Gums Dental Care, LLC 2024 Records withheld for nearly three years Civil money penalty $70,000
Northcutt Dental-Fairhope, LLC 2022 Patient list disclosed to a political campaign and marketing vendor Settlement $62,500
Dr. U. Phillip Igbinadolor, D.M.D. & Associates 2022 Patient information posted in a reply to a negative review Civil money penalty $50,000
Family Dental Care, P.C. 2022 Only portions of a record provided, complete set delayed Settlement $30,000
Dr. Donald Brockley, D.D.M. 2022 Failure to provide a patient a copy of their record Settlement after litigation $30,000
B. Steven L. Hardy, D.D.S. (Paradise Family Dental) 2022 Failure to provide timely access to requested records Settlement $25,000
New Vision Dental 2022 Patient information disclosed across multiple review replies Settlement $23,000
Elite Dental Associates 2019 Social media reply disclosing a patient’s information Settlement $10,000
Lawrence Bell, Jr., D.D.S. 2022 Failure to provide timely access to a record Settlement $5,000

Two things stand out immediately. Not one of these ten involves a hacker. And six of the ten are a patient asking for their own records and not getting them fast enough.

That second point scales in a direction worth noticing. These are front-desk process failures, so a group running 40 offices is running the same records clock 40 times over, at 40 different front desks, with 40 different people deciding what counts as urgent. The largest fine in the table is a case in point: Great Expressions Dental Center of Georgia is a multi-location group practice, not a solo office.

There is also a distinction in that fourth column worth understanding before you read the cases, because it changes both the size of the number and how it is arrived at.

Settlement Versus Civil Money Penalty

Eight of the ten are settlements. Two are civil money penalties. Those are not the same thing, and one of the things separating them is whether the matter could be resolved informally once OCR made contact.

A settlement is negotiated. The practice agrees to pay an amount and follow a corrective action plan, and OCR closes the matter with no admission of liability. A civil money penalty is imposed. OCR calculates what the regulation says you owe and issues it, and your options are to pay or to fight it in front of an administrative law judge.

Both dental practices that ended up with penalties rather than settlements got there without the case being resolved informally, though by different routes. One never engaged with the investigation at all. The other disputed the obligation, litigated it, and handed over the records only after a penalty had been proposed.

Decision diagram showing how a HIPAA case ends: after OCR makes contact, a case either resolves informally and becomes a settlement, or goes unresolved and becomes a civil money penalty

Social Media and the Front-Desk Reflex to Respond

Some of the most avoidable violations in dentistry come from responding to online reviews. It feels like customer service. To OCR, it is an impermissible disclosure of protected health information.

1. Elite Dental Associates: $10,000 for a Yelp Reply

A Dallas dental practice responded to a patient’s Yelp review by disclosing her last name and details about her health condition, treatment, and insurance. OCR settled with Elite Dental Associates for 10,000 dollars in 2019. The practice was defending its reputation. It disclosed a patient’s information to the entire internet to do it.

2. New Vision Dental: $23,000 for the Same Mistake, Worse

A California practice did the same thing at greater scale, disclosing patient information across multiple review responses. OCR settled with New Vision Dental for 23,000 dollars in 2022, more than double what Elite paid. Replying once is a mistake. Making it your standard practice for handling criticism is a pattern, and the settlement reflects that.

3. Dr. U. Phillip Igbinadolor: $50,000 for Ignoring the Investigation

This is the most expensive review response among the dental actions, and it is worth understanding why. A North Carolina practice with offices in Charlotte and Monroe disclosed a patient’s information on a webpage in response to a negative online review. The underlying mistake is the same one Elite and New Vision made.

What happened next is not. According to OCR’s enforcement record, the practice did not respond to OCR’s data request, did not respond to or object to an administrative subpoena, and waived its right to a hearing by not contesting the findings. OCR imposed a 50,000 dollar civil money penalty.

Elite paid 10,000 dollars for the same category of disclosure. Penalty amounts turn on several factors, including how long a violation ran and the practice’s financial position, but engaging with the investigation is the variable most visibly in your control. The operational lesson is narrow and worth saying plainly: a letter from OCR is not something to set aside until things quiet down.

4. Northcutt Dental: $62,500 for a Campaign Mailing List

A dental practice in Fairhope, Alabama disclosed its patients’ information to a campaign manager and a third-party marketing company hired to help with a state senate election campaign. Northcutt Dental-Fairhope agreed to corrective action and paid 62,500 dollars.

This one catches practices off guard because it does not feel like a disclosure at all. The patient list is right there, it is your list, and handing it to a vendor feels like an internal decision. It is not. A vendor that handles patient information on your behalf is generally a business associate, which means the relationship needs an agreement before any data moves. A campaign is not a permitted use at all.

Being Slow to Hand Over Records

Patients have a right to their own records, quickly and at a reasonable cost. OCR ran a Right of Access Initiative that penalized dozens of providers for missing that, and six dental practices are among them. On this record it is the most common way a dental office ends up on the enforcement list.

Under the Privacy Rule, a practice has 30 days to act on a request, with the possibility of one 30-day extension, and any fee has to be reasonable and cost-based.

5. Great Expressions Dental Center of Georgia: $80,000

A patient waited over a year for records, and the practice charged a copying fee that was not based on actual cost. OCR settled with Great Expressions Dental Center of Georgia for 80,000 dollars, the largest dental settlement in the record. The lesson is two-part: provide records promptly, and never overcharge for them.

6. Family Dental Care: $30,000

A Chicago practice provided only portions of a patient’s records, and the complete set did not follow in time. That failure alone, settled in a 2022 action alongside Great Expressions and Paradise Family Dental, cost Family Dental Care 30,000 dollars. There was no breach, no hacker, and no lost laptop. Worth noting for anyone who assumes a partial response stops the clock: it does not.

7. Paradise Family Dental: $25,000

A Las Vegas practice failed to provide a mother copies of her own and her minor child’s records, which took roughly eight months to arrive. OCR determined that failure was a potential violation of the right of access provision, and B. Steven L. Hardy, D.D.S., LTD, doing business as Paradise Family Dental, paid 25,000 dollars. Worth remembering when the request comes from a parent for a child’s records: it carries the same clock as any other.

8. Dr. Donald Brockley: $30,000 After Going to Court

A solo practitioner in Butler, Pennsylvania failed to provide a patient a copy of their record. After OCR issued a Notice of Proposed Determination, Dr. Brockley requested a hearing before an administrative law judge. The litigation was resolved by a settlement agreement before the court ruled, at 30,000 dollars plus corrective action.

Worth noting for any owner who assumes fighting it is the cheaper path: this is a solo practice that contested the finding, spent the money to litigate, and settled anyway, on top of whatever the litigation itself cost.

9. Lawrence Bell, Jr., D.D.S.: $5,000

A Baltimore practice failed to provide timely access to a patient’s medical record and paid 5,000 dollars to settle. This is the smallest published figure on the dental record, and it is the one most worth showing your front desk. Five thousand dollars is not a business-ending number. It is the cheapest possible version of this mistake rather than a safe one, and it is entirely avoidable.

10. Gums Dental Care: $70,000, and the Number Behind It

A solo practice in Silver Spring, Maryland did not provide a patient the dental records she requested for her and her three children. She asked on June 26, 2019. The records were finally delivered on May 17, 2022, by Dropbox, after OCR had already proposed a penalty.

OCR found the violation was willful neglect and counted it as running 1,028 days, from August 26, 2019 through the day it issued its proposed penalty on March 29, 2022. The administrative law judge decision shows the arithmetic that ordinarily stays hidden. Because a continuing violation counts as a separate violation each day it persists, the daily figure was 63,973 dollars, the statutory minimum for uncorrected willful neglect in that period.

Multiply that across a violation running nearly three years and the total exposure reaches into the millions. OCR put it at 7,676,692 dollars. Worth knowing that even this number was disputed: the judge calculated the correct maximum as 7,266,279 dollars, roughly 410,000 dollars lower, because the statutory ceiling for each of the earlier years was lower than the single figure OCR had applied to all of them. The appeals board called the difference immaterial and declined to settle it, since the penalty actually imposed was nowhere near either number.

OCR reduced the penalty to 70,000 dollars. The decision explains why, and it is not a technicality. OCR determined that imposing the full amount on a solo practitioner serving an urban and suburban community would likely end that practice’s ability to provide care in its service area, and it factored in the pandemic. The judge upheld both the violation and the reduced penalty, and the Departmental Appeals Board affirmed that decision in 2024.

That is the tier table further down this page, applied to a real dental office. The seven-figure number is what the regulation permitted. The 70,000 dollars is what discretion produced. A practice should not plan around the assumption that discretion will show up.

Three Non-Dental Cases Worth Knowing

The ten cases above are every dental practice OCR had penalized as of September 2026. One more action sits just outside that list and is worth a line. In March 2026 OCR settled with MMG Fusion, which it describes as a Maryland software company whose product communicates directly with patients on behalf of covered entities. OCR cited it for failing to notify the covered entities affected by its breach, and it paid 10,000 dollars. Do not read that figure as a measure of severity: the incident touched millions of records, and the company was effectively defunct by the time the matter resolved. It was a business associate rather than a practice, so it is not in the table above, but it is the case most likely to describe something already installed in your own office. We covered it in our roundup of the biggest dental data breaches.

The three cases below are not dental at all. They are here because they show what happens at the next order of magnitude, where a breach is in play and OCR’s attention turns to whether the organization had ever assessed its own risk.

When you move up to the large penalties, one failure appears again and again. The organization never conducted a thorough security risk analysis, so when an attacker got in, the gaps had never been identified and there was no record of due diligence. This is among the most frequently cited failures in HIPAA enforcement, and it is worth separating from the breach risk assessment that follows an incident. The risk analysis is the ongoing exercise you owe under the Security Rule whether or not anything has gone wrong.

Anthem: $16 Million

The largest HIPAA settlement on record. A cyberattack exposed the data of nearly 79 million people, and OCR found the insurer had failed to conduct an enterprise-wide risk analysis and lacked adequate controls. Anthem settled for 16 million dollars in 2018. The scale is enormous, but the root failure is the same one that catches a solo office.

Doctors’ Management Services: $100,000 for a Vendor’s Ransomware

This one is worth knowing because the target was a practice management company rather than a provider, and because it was widely reported at the time as OCR’s first ransomware settlement. Several more have followed since. It was hit in 2017, affecting more than 206,000 people, and OCR found it had failed to run an accurate risk analysis and review its system activity. The 100,000 dollar settlement in 2023 signaled that suffering a ransomware attack does not close the question. OCR will look at whether your own compliance obligations were met before it happened.

Comstar: $75,000

A vendor suffered a ransomware breach affecting more than 585,000 people, and OCR again cited the failure to conduct a thorough risk analysis in its 2025 settlement of 75,000 dollars. OCR now runs a Risk Analysis Initiative, and the same root cause turns up across its recent cases. That is the pattern once a breach is in play, which is a different failure from the one that has been catching dental offices.

What a HIPAA Violation Actually Costs

Civil penalties are set in four tiers based on how culpable the provider was, from an honest mistake to willful neglect that was never fixed. The amounts are adjusted for inflation every year. These are the figures in effect for 2026.

Tier Culpability Minimum per violation Annual cap OCR applies
1 No knowledge of the violation $145 $36,506
2 Reasonable cause, not willful neglect $1,461 $146,053
3 Willful neglect, corrected $14,602 $365,052
4 Willful neglect, not corrected $73,011 $2,190,294

One nuance worth knowing: the per-violation minimums are set in statute, but the graduated per-tier annual caps above reflect OCR’s own enforcement-discretion practice, first announced in 2019. The current regulation still applies the highest cap, 2,190,294 dollars, across all four tiers. In practice OCR penalizes lower tiers against the lower caps, but the law on the books has not been formally amended to match.

The tier is not about the size of the breach. It is about whether you were making a good-faith effort and whether you fixed the problem once you knew. A practice that documented its risk analysis and acted on it is in a far better position to argue reasonable diligence than one that ignored the requirement for years.

Gums Dental is what tier four looks like in a dental office. The daily figure OCR applied there was the tier four per-violation minimum in force at the time, and every one of those 1,028 days counted as its own violation. The figures in the table above are the 2026 amounts, so they are higher than the ones that applied in that case, but the structure is identical. Note that all of these figures move with inflation, so check the current year’s table rather than quoting one you read a while ago.

How Dental Practices Stay Off This List

So the habits that keep a dental practice off this list are front-desk habits, in roughly the order the record suggests. For a DSO or a group, that means they are policy questions rather than personal ones, because a habit only holds across locations if someone owns it centrally. Answer record requests inside 30 days, and charge only what the copies actually cost. Never disclose anything about a patient in a public reply, no matter how unfair the review feels. Put an agreement in place before any vendor touches your patient list. And if a letter arrives from OCR, answer it. If the thing that arrives is an incident rather than a letter, our data breach response plan for dental practices covers the first hour.

Run and document a security risk analysis too. That one is what the three non-dental cases above turn on, and it is what OCR examines after a ransomware incident, so it matters a great deal. It is just not what has been fining dental offices.

For a fuller run-down, these are the HIPAA violations dental practices commit most often and how to avoid them in your own office. The habits above map to a broader control set in our HIPAA compliance checklist for dental practices. You can also see where breaches land publicly on the government’s HIPAA breach reporting portal, and how the largest incidents in the field actually happened in our roundup of the biggest dental data breaches.

The uncomfortable truth in this list is how ordinary these decisions look from the inside. A review reply, a records request set aside during a busy stretch, a patient list handed to a vendor. None of it feels like a violation in the moment, which is why the fix is process rather than intent.

HIPAA Violation Examples FAQs

What is the most common HIPAA violation for dental practices?

Among the dental practices OCR has actually penalized, it is failing to provide patients their records promptly and at a reasonable cost. Six of the ten dental enforcement actions in OCR’s record are right of access cases, more than every other category combined. The second pattern is disclosing patient information in response to online reviews, which accounts for three more. Neither involves a hacker. They involve everyday front-desk and office decisions that quietly cross a compliance line.

Can a dental practice be fined for responding to a Yelp review?

Yes, and three practices have been. Elite Dental Associates paid 10,000 dollars, New Vision Dental paid 23,000 dollars, and Dr. U. Phillip Igbinadolor was assessed a 50,000 dollar civil money penalty. Even confirming that someone is a patient, or referencing their treatment, is a disclosure of protected health information without authorization. The safe practice is to respond to all reviews with a generic message that never acknowledges any specific patient or visit.

How much can a HIPAA violation cost?

It depends on culpability. Penalties run in four tiers, from a minimum of 145 dollars per violation for an honest mistake up to an annual cap of roughly 2.19 million dollars for willful neglect that is never corrected. Dental enforcement actions have ranged from 5,000 to 80,000 dollars, though the Gums Dental decision put that practice’s maximum exposure at more than 7.2 million dollars before OCR reduced the penalty to 70,000. The amount turns heavily on whether the practice made a documented good-faith effort to comply.

What is the difference between a settlement and a civil money penalty?

A settlement is negotiated and closes the matter with no admission of liability, usually paired with a corrective action plan. A civil money penalty is imposed by OCR under the regulation, and the practice either pays it or challenges it before an administrative law judge. Eight of the ten dental actions were settlements. In both cases that became penalties, the underlying problem went unresolved while OCR was still asking about it.

How long does a dental practice have to provide records?

Thirty days from the request, with the possibility of one 30-day extension, and any fee charged has to be reasonable and cost-based. Both halves matter. Great Expressions was penalized for the delay and for a copying fee that was not based on actual cost.

What single step would have prevented the most of these cases?

Answering records requests inside the 30 day window. It would have prevented six of the ten dental enforcement actions on OCR’s record, more than every other category combined, and it costs nothing to fix.

A documented security risk analysis is the other control worth naming, and it is the one OCR cites in nearly every large settlement including the recent ransomware cases. It answers a different risk. The records clock is what has actually been fining dental practices.

Posted in Dental Cybersecurity

Filter By: