The Illinois health system agreed to a two-year corrective action plan after federal regulators found it had never completed a compliance risk analysis before attackers exfiltrated data on 53,907 people.
What happened
OSF Healthcare System and its affiliated covered entities paid $552,250 to resolve an investigation into potential HIPAA violations connected to a 2021 ransomware attack, the HHS Office for Civil Rights announced on July 29, 2026. OSF is headquartered in Illinois with providers across Illinois and Michigan. The organization discovered in April 2021 that its files had been infected with the Nephilim ransomware variant, and attackers exfiltrated the protected health information of 53,907 individuals. Exposed data included driver's license numbers, diagnosis and treatment information, prescription records, medical record numbers, provider names, dates of service, financial account information, and health insurance details. The settlement marks OCR's twenty-first ransomware enforcement action.
Going deeper
OCR cited four potential violations, and only one concerns the attack itself. The agency found OSF had failed to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to its electronic protected health information, impermissibly disclosed the PHI of 53,907 individuals, failed to provide timely breach notification to those individuals, and failed to notify the HHS Secretary within the required window. OSF discovered the infection in April 2021 but did not file its breach report until October, which falls outside the 60-day deadline the Breach Notification Rule sets from the point of discovery. The corrective action plan runs two years under OCR monitoring and requires OSF to complete a compliant risk analysis and build a risk management plan addressing whatever that analysis turns up. Five years passed between the attack and the resolution, which is fairly typical for OCR investigations of this kind.
What was said
"An accurate and thorough HIPAA risk analysis is not only required by law, but it is also necessary to protect health information and prevent or mitigate ransomware attacks," said OCR Director Paula M. Stannard in the agency's announcement on July 29, 2026. She framed the consequence in operational terms rather than legal ones, stating, "If a HIPAA-regulated entity doesn't know what threats and vulnerabilities exist to its electronic protected health information (ePHI), they will often learn the hard way when their systems are hacked."
In the know
Risk analysis has become the through-line in nearly every recent OCR resolution. The agency settled four separate ransomware investigations on a single day in April 2026, bringing its totals at that point to nineteen completed ransomware investigations and thirteen under the Risk Analysis Initiative, according to OCR. All four cited the same failure to conduct a compliant assessment. A health plan settlement in June followed the same pattern. The regulatory theory running through these cases is that the missing analysis, rather than the attacker's success, constitutes the violation, which means an organization can face enforcement over gaps it never identified regardless of how the intrusion occurred.
The big picture
Every element of the OSF corrective action plan already sits in the current Security Rule, which matters given that the proposed overhaul making encryption and multifactor authentication mandatory has been pushed to July 2027. Waiting for the new rule offers no protection from enforcement under the existing one. The notification failures in this case deserve separate attention, since two of the four cited violations concerned timing rather than security, and those are the ones a compliance team controls entirely once a breach is discovered. Paubox's What Healthcare Gets Wrong About HIPAA and Email Security report describes organizations treating a completed risk assessment as a permanent compliance status rather than a recurring obligation, which is the pattern OCR keeps documenting in its resolutions. Organizations reviewing their own posture should confirm when their last analysis was completed, whether it covered every system holding ePHI, and whether anyone acted on what it found.
FAQs
What makes a risk analysis "accurate and thorough" in OCR's view?
It must cover every system, application, and device that creates, receives, maintains, or transmits ePHI, including cloud services and business associate connections, rather than sampling a subset. OCR has repeatedly found that assessments limited to a single facility, an EHR system alone, or a vendor-supplied checklist fall short of the requirement at 45 CFR 164.308(a)(1)(ii)(A).
How does OCR decide on a settlement amount?
Resolution amounts weigh the nature and extent of the violation, the harm resulting from it, the entity's history of compliance, and its financial condition. Settlements are voluntary resolutions rather than civil monetary penalties, so the figures generally fall below what the statutory penalty tiers would permit.
What does two years of OCR monitoring involve?
The entity submits its completed risk analysis and risk management plan for OCR review and approval, reports on implementation progress at set intervals, and notifies OCR of any workforce member failure to comply with the revised policies. OCR can extend the term if deliverables are late or inadequate.
Does filing a breach report late create exposure separate from the breach itself?
Yes. Timely notification to affected individuals and to the HHS Secretary are independent requirements, and OCR cited both as separate potential violations here. An organization that handles an incident well technically can still face enforcement purely on notification timing.
Is an entity required to disclose which ransomware variant hit it?
No. Breach reports must describe the types of information involved and the general nature of the incident, not the specific malware family. OCR named Nephilim in this announcement, though entities are not obligated to identify the variant in their own notifications to individuals.
