Failure to comply with the administrative simplification provisions of HIPAA carries the risk of substantial civil and criminal penalties. There are civil fines of up to $100 per violation and up to a maximum of $25,000 per year possible for identical violations. Because any failure to comply could involve violations of multiple standards, the actual total penalties per incident could far exceed the individual maximums. Criminal penalties range from $50,000 and one year in jail for anyone who obtains protected health information, to $50,000 and 5 years in jail for anyone who obtains protected health information under false pretenses, to $250,000 and 10 years in jail for anyone who obtains protected health information with the intent to use it for commercial advantage, personal gain, or malicious harm.