OSF Healthcare System Pays $552K To Resolve HIPAA Breach Notification; Risk Analysis Violations

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced that another settlement has been agreed to resolve alleged HIPAA violations uncovered during an investigation of a ransomware-related data breach. This is OCR’s 21st HIPAA enforcement action stemming from a ransomware investigation, in this case, an attack involving Nephilim ransomware.

OCR initiated an investigation of OSF Healthcare System and its Affiliated Covered Entities (OSF) after receiving a breach notification on October 1, 2021. In that notification, OCR was informed that the attack was identified on April 23, 2021, when ransomware was used to encrypt files. The attackers also dropped a ransom note demanding payment to prevent the publication of stolen data and for the keys to decrypt data. OSF determined on August 24, 2021, that the ransomware group had exfiltrated patients’ protected health information, and notification letters were sent to the 53,907 affected individuals on October 1, 2021.

OCR’s investigation confirmed that the ransomware group exfiltrated protected health information in the attack, and that there had been an impermissible disclosure of the protected health information of 53,907 patients. The HIPAA Breach Notification Rule requires HIPAA-regulated entities to issue notifications to the HHS Secretary and the affected individuals within 60 days of the discovery of a data breach. OCR determined that OSF failed to issue timely notifications to the affected individuals and the HHS Secretary, who were informed more than five months after the attack was detected.

While it may not be possible to prevent cyberattacks, HIPAA-regulated entities are required to implement safeguards to reduce risks and vulnerabilities to a reasonable and appropriate level. Risks cannot be effectively managed if HIPAA-regulated entities do not first conduct a comprehensive and accurate risk analysis.  OCR determined that OSF failed to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to ePHI held by OSF.

The settlement agreed between OCR and OSF resolves those four HIPAA violations. OSF has agreed to pay a financial penalty of $552,250 and adopt a corrective action plan to address the areas of noncompliance. OCR will monitor OSF for compliance with that plan for a period of two years from the date of the settlement agreement.

This is the 8th settlement to be announced by OCR so far in 2026, and the largest settlement of the year. Across the 8 enforcement actions, OCR has collected $2,280,250 in penalties.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/