The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has settled with a healthcare system following a ransomware investigation that found potential violations of the HIPAA Security Rule.

 

What happened

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has reached a $552,250 settlement with OSF HealthCare System following an investigation into a 2021 ransomware attack that exposed the protected health information (PHI) of more than 53,000 patients.

The settlement resolves allegations that the Illinois-based healthcare provider failed to comply with multiple requirements of the HIPAA Privacy, Security, and Breach Notification Rules, reinforcing OCR's message that healthcare organizations must proactively manage cyber risks before an attack occurs.

 

The backstory

The investigation stems from an April 2021 ransomware attack in which threat actors gained unauthorized access to OSF HealthCare's network and deployed the Nephilim ransomware variant. During the attack, files were encrypted and sensitive patient information was exfiltrated. A forensic investigation later confirmed that the breach affected 53,907 individuals. The compromised data included patient names, addresses, dates of birth, Social Security numbers, driver's license numbers, medical record numbers, health insurance information, diagnoses, treatment details, and financial account information.

OCR launched its investigation after OSF HealthCare reported the breach and determined the health system had potentially violated several provisions of HIPAA. According to OCR, the investigation identified several areas where OSF HealthCare allegedly failed to meet HIPAA requirements before and after the ransomware incident.

The agency found that the healthcare system did not conduct an accurate and thorough risk analysis to identify potential threats and vulnerabilities to electronic protected health information (ePHI). OCR also alleged that OSF HealthCare failed to implement sufficient security measures to reduce identified risks and did not provide timely breach notifications to all affected individuals, as required under the HIPAA Breach Notification Rule.

 

Going deeper

Under the settlement, OSF HealthCare will pay $552,250 and implement a two-year corrective action plan monitored by OCR. The organization must conduct a comprehensive enterprise-wide risk analysis, develop and implement a risk management plan, revise its HIPAA policies and procedures, train its workforce, and submit regular compliance reports to the agency. The enforcement action is part of OCR's ongoing Risk Analysis Initiative, which targets organizations that fail to perform comprehensive security risk assessments.

 

What was said

“An accurate and thorough HIPAA risk analysis is not only required by law, but it is also necessary to protect health information and prevent or mitigate ransomware attacks,” said OCR Director Paula M. Stannard in the HHS press release. She added that “If a HIPAA regulated entity doesn’t know what threats and vulnerabilities exist to its electronic protected health information (ePHI), they will often learn the hard way when their systems are hacked.”

 

In the know

The HIPAA Security Rule requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). Key requirements include conducting regular security risk analyses, implementing risk management measures, controlling access to sensitive systems, training employees, and continuously monitoring for security threats.

While compliance cannot prevent every cyberattack, it can significantly reduce the likelihood and impact of ransomware incidents. By identifying vulnerabilities, strengthening security controls, and ensuring employees follow cybersecurity best practices, organizations are better equipped to detect, contain, and recover from attacks before they compromise patient data or disrupt healthcare operations. Recent enforcement actions by the HHS Office for Civil Rights (OCR) also demonstrate that regulators expect these safeguards to be in place before an attack occurs, making Security Rule compliance a critical component of healthcare cybersecurity.

 

Why it matters

According to Paubox’s Healthcare Email Security Report, the healthcare industry has seen a “264% increased surge of ransomware attacks” since 2018, placing increasing pressure on organizations to strengthen their cybersecurity defenses. OCR's latest enforcement action reinforces that regulators expect healthcare providers to proactively comply with the HIPAA Security Rule and may pursue enforcement when organizations fail to implement appropriate security measures before an attack occurs.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQS

What is a HIPAA security risk analysis?

A security risk analysis is a comprehensive assessment that identifies potential threats and vulnerabilities to ePHI. It is a requirement of the HIPAA Security Rule and forms the foundation of an organization's cybersecurity program.

 

What is a corrective action plan?

A corrective action plan (CAP) is a legally binding agreement requiring an organization to improve its HIPAA compliance. It may include conducting a risk analysis, implementing new security controls, updating policies and procedures, providing workforce training, and submitting regular reports to OCR.

 

What happens if a healthcare organization violates the HIPAA Security Rule?

Organizations found to have violated the HIPAA Security Rule may face financial penalties, corrective action plans, ongoing federal oversight, and reputational damage. The severity of enforcement depends on the nature of the violations and the organization's efforts to address identified risks.