No matter how someone mishandles or discloses PHI, OCR is responsible for enforcing consequences so that the situation won’t happen again. Although depending on the severity, there are different levels of penalties. There are four different categories concerning civil HIPAA violations, and three tiers of criminal violations.