BobKamman
Level 15

Read the statute, don't read what other people are writing about the statute when trying to dumb it down.  The statute (Title 31, Section 5336) is here:

 https://www.govinfo.gov/content/pkg/USCODE-2022-title31/pdf/USCODE-2022-title31-subtitleIV-chap53-su... 

I haven't read it thoroughly, but they seem to make a distinction between nonfilers ($10,000 maximum penalty) and people who don't protect the secrecy of data that is filed ($250,000 or more).  But it's not that clear the civil penalty, not just the criminal penalty, is capped.  See the 9th page:

(3) CRIMINAL AND CIVIL PENALTIES.—
(A) REPORTING VIOLATIONS.—Any person
that violates subparagraph (A) or (B) of
paragraph (1)—
(i) shall be liable to the United States
for a civil penalty of not more than $500
for each day that the violation continues
or has not been remedied; and
(ii) may be fined not more than $10,000,
imprisoned for not more than 2 years, or
both.
(B) UNAUTHORIZED DISCLOSURE OR USE VIOLATIONS.—Any person that violates paragraph (2)—
(i) shall be liable to the United States
for a civil penalty of not more than $500
for each day that the violation continues
or has not been remedied; and
(ii)(I) shall be fined not more than
$250,000, or imprisoned for not more than 5
years, or both; or
(II) while violating another law of the
United States or as part of a pattern of
any illegal activity involving more than
$100,000 in a 12-month period, shall be fined

not more than $500,000, imprisoned for not
more than 10 years, or both.