HIPAA specifies stiff penalties for organizations that fail to comply with the law, with fines up to $250,000 and/or 10 years imprisonment for knowingly misusing client information. Organizations were required to comply with the act by April 14, 2003.