Breach coverage tends to stop after an announcement is made and victims are notified and helped as needed. What follows for the organization runs considerably longer, and the sequence is predictable enough to map, with documented cases attached to every stage.

 

Day zero

An email arrives, someone enters credentials on a page that looks legitimate, and the breach begins. The message sits in a mailbox unremarked, because Paubox's 2025 Healthcare Email Security Report found employees flag 5% of known phishing attempts to their security teams.

 

Days one to twenty-one

Attackers reached Covenant Health's systems on May 18, 2025, and the Massachusetts health system detected them eight days later on May 26. The Record reported that Qilin claimed the attack, stating it had taken 852 gigabytes across roughly 1.35 million files, and the stolen data was later published, which indicates no ransom was paid.

DaVita's intrusion ran longer, with attackers entering on March 24, 2025, and moving undetected until April 12, close to three weeks inside one of the country's largest dialysis providers. Interlock claimed 1.5 terabytes, and the confirmed count reached 2,689,826 individuals.

Those windows are where the leverage gets built, through network mapping, privilege escalation, and staging data for removal, all before anything visible happens.

 

Discovery

Encryption announces itself the moment systems stop working, which is why encryption-based attacks get found quickly. Data theft without encryption produces no equivalent signal, so organizations often learn about it from an attacker's leak site or a law enforcement notification rather than from their own monitoring.

 

The sixty-day clock

HIPAA gives an organization 60 days from discovery to notify affected individuals, but forensics teams sometimes require additional time to complete their investigation.

Covenant Health told the Maine Attorney General's Office in July 2025 that 7,864 individuals had been affected. Its investigation did not finish until December 10, and the revised figure came back at 478,188, including 284,529 Maine residents, with notification letters going out on New Year's Eve. The total number of impacted individuals was greater, and Covenant ultimately updated the information several months later.

A breach is presumed reportable unless the organization can show a low probability that PHI was compromised, assessed against four factors HHS sets out in the Breach Notification Rule. Factors include what data was involved, who accessed it, if it was acquired or only viewed, and what has been done to reduce risk.

Establishing that third factor has become considerably harder, because when an attacker holds valid credentials or a stolen session token, their activity is recorded in the logs as authorized use, leaving the organization to prove a negative against records showing nothing unusual.

While organizations try to answer these questions, they are also actively in the recovery process. The AHA and Joint Commission built their Cyber Resilience Readiness program around a 30-day benchmark, because severe incidents where forensic analysis has to precede restoration routinely run that long.

 

Day sixty

Notice goes to affected patients by first-class mail or email, HHS gets a report, and breaches touching 500 or more individuals in a state also require notice to prominent media outlets there. Smaller breaches go into an annual log instead.

Anything over 500 gets posted to the OCR breach portal, listing the organization, the number affected, and the incident type, where patients, referring providers, and prospective partners can find it years afterward.

 

Months six to eighteen

At this point, the OCR may open an investigation. Reports involving 500 or more individuals get reviewed, and patient complaints, media coverage, or an attacker's leak site can trigger one independently.

What investigators look for has become consistent enough to predict. By June 2026, OCR had completed 20 ransomware enforcement actions and 14 resolutions under its Risk Analysis Initiative, and in nearly all of them the finding was a failure to conduct an accurate and thorough risk analysis before anything happened. OCR Director Paula M. Stannard summarized the agency's position in that announcement, stating that "effective cybersecurity starts with Security Rule compliance."

 

Year one to year two, and beyond

In April 2026 OCR resolved four ransomware investigations for a combined $1,165,000, covering breaches affecting more than 427,000 individuals, with individual amounts between $225,000 and $375,000.

Headcount does not determine the figure. MMG Fusion, a software company acting as a business associate, resolved a breach affecting roughly 15 million individuals for $10,000, while OSF HealthCare settled at $552,250 over a Nephilim attack affecting 53,907, because OCR weighs culpability and cooperation more heavily than the number of people involved.

Solara Medical Supplies shows how far past two years this can run. A phishing attack reached eight employee email accounts between April and June 2019, exposing ePHI for 114,007 individuals, and a second breach report followed in January 2020 after 1,531 notification letters went to wrong addresses. OCR announced the $3 million settlement in January 2025, citing an inadequate risk analysis, insufficient security measures, and late notifications, with a corrective action plan running two years beyond that and a separate $9.76 million class action settlement alongside it. From phishing email to the end of OCR monitoring is close to eight years.

Civil penalties now run from $145 per violation at the lowest tier to a statutory annual cap of $2,190,294 following the inflation adjustment effective January 2026.

 

What runs alongside all of it

A February 2026 study in the American Economic Journal: Economic Policy, covered by HealthTech Magazine, analyzed Medicare claims data and found in-hospital mortality rising 34% to 38% among patients already admitted when a ransomware attack begins. The same researchers attributed between 42 and 67 Medicare patient deaths to ransomware attacks across 2016 to 2021.

IBM's 2025 Cost of a Data Breach Report puts the average healthcare breach at $7.42 million, still the highest of any sector for the fourteenth consecutive year, with healthcare also carrying the longest breach lifecycle at 279 days from intrusion to containment against a global average of 241. DaVita's own SEC filing reported the incident adversely affecting billing and revenue collection cycles as well as patient census, with expected impacts on revenue per treatment and treatment volumes across the full year.

 

Where the clock could have been stopped

Phishing remains the most consistently documented entry point across healthcare ransomware, and removing that message before staff encounters it is the only intervention preventing the entire sequence rather than shortening part of it. Paubox's 2026 Healthcare Email Security Report recorded a 47% increase in attacks getting past the defenses built into Microsoft 365 and Google Workspace during 2025, which is why native filtering is not doing this job alone.

Paubox Inbound Email Security reads sender behavior, message intent, and contextual signals rather than matching against patterns from attacks already catalogued.

Learn more: Paubox Inbound Email Security

 

In the news

HHS published a Notice of Proposed Rulemaking in December 2024 proposing the first major overhaul of the HIPAA Security Rule in more than ten years, and two of its changes would alter this sequence directly.

The proposal removes the distinction between required and addressable implementation specifications, which would make encryption and multi-factor authentication mandatory rather than something an organization can document a reason for skipping. It also expects any software touching ePHI to appear in a maintained technology asset inventory, including AI tools. Both provisions target the same finding OCR keeps making after the fact, that an organization which never inventoried what it had, or never assessed how it could be reached, has no answer when investigators arrive eighteen months later. The rule remains under review.

 

FAQs

When does the 60-day notification clock actually start?

From discovery of the breach, not from when the intrusion began. An organization finding an incident in June relating to access gained in March has 60 days from June, though it still has to reconstruct what happened in the intervening months.

 

What if the affected number changes after notification?

It frequently does. Covenant Health reported 7,864 individuals in July 2025 and revised that to 478,188 in December once its forensic analysis was completed, then issued a second round of notification letters.

 

Does paying a ransom shorten any of this?

It may restore systems faster. It does nothing to the notification obligation, the OCR investigation, or the breach portal entry, because those follow from PHI having been accessed rather than from whether operations recovered.

 

Why do settlement amounts vary so much?

OCR weighs culpability, cooperation, prior compliance history, and whether the organization corrected the problem, alongside the number of individuals affected. A business associate breach touching 15 million people settled at $10,000, while a health system breach affecting 53,907 settled at $552,250.

 

What single thing would have prevented the whole sequence?

Stopping the initial email. Every stage from dwell time to settlement follows from an attacker gaining access, and in most documented healthcare ransomware cases, the way in was a phishing message that reached an inbox.