Settlement represents OCR’s 21st ransomware enforcement action

July 29, 2026: The U.S. Department of Health and Human Services Office for Civil Rights announced a settlement with OSF Healthcare System and its Affiliated Covered Entities concerning potential violations of the HIPAA Privacy, Security, and Breach Notification Rules. OSF is headquartered in Illinois and operates healthcare facilities and services in Illinois and Michigan.

The settlement is the 21st enforcement action brought by OCR in connection with ransomware-related incidents.

OCR Director Paula M. Stannard emphasized that conducting an accurate and thorough HIPAA risk analysis is both a legal requirement and an essential part of protecting electronic protected health information, or ePHI. Organizations that fail to identify threats and vulnerabilities may not recognize serious security weaknesses until their systems have already been compromised.

The OSF Ransomware Incident

OCR opened its investigation after OSF submitted a breach notification report on October 1, 2021. OSF had discovered evidence of the “Nephilim” ransomware variant and a ransom note within its systems on April 23, 2021.

OSF later determined that the attackers had stolen the protected health information of 53,907 patients. The compromised information included:

  • Driver’s license numbers
  • Medical record numbers
  • Diagnosis and treatment information
  • Prescription information
  • Healthcare provider names
  • Dates of medical services
  • Financial account information
  • Health insurance information

OCR’s investigation identified several areas of potential noncompliance with the HIPAA Rules.

These included allegations that OSF:

  • Failed to conduct an accurate and thorough risk analysis of potential risks and vulnerabilities affecting its ePHI
  • Impermissibly disclosed the protected health information of 53,907 individuals
  • Failed to provide timely breach notifications to affected individuals
  • Failed to provide timely breach notification to the Secretary of HHS

The resolution agreement does not constitute an admission of liability by OSF or an admission that OSF violated the HIPAA Rules.

Settlement and Corrective Action Requirements

Under the resolution agreement, OSF paid $552,250 to OCR and agreed to implement a corrective action plan. OCR will monitor the organization’s compliance with the plan for two years.

As part of the corrective action plan, OSF must:

  • Conduct an accurate and thorough risk analysis covering the confidentiality, integrity, and availability of its ePHI
  • Identify the systems, equipment, applications, and data locations that create, receive, maintain, or transmit ePHI
  • Develop and implement an enterprise-wide risk management plan
  • Address and reduce the security risks and vulnerabilities identified through the risk analysis
  • Submit required documentation and annual compliance reports to HHS
  • Maintain supporting compliance records for the required retention period

HHS has published the resolution agreement and corrective action plan through its Office for Civil Rights.

Steps Healthcare Organizations Should Take

OCR recommends that covered entities and business associates take proactive measures to prevent ransomware attacks and reduce the effects of cybersecurity incidents.

Healthcare organizations should:

  • Identify where ePHI is stored and document how it enters, moves through, and leaves the organization’s systems
  • Conduct risk analyses periodically and update them when systems, threats, or operations change
  • Develop and maintain a risk management plan that addresses identified vulnerabilities
  • Implement audit controls that record and examine system activity
  • Review system activity regularly for suspicious or unauthorized behavior
  • Use strong authentication controls to ensure that only authorized users can access ePHI
  • Encrypt ePHI while it is stored and transmitted, when appropriate
  • Apply lessons learned from security incidents to the organization’s security management program
  • Provide regular HIPAA training tailored to the organization and each workforce member’s job responsibilities

This enforcement action reinforces the importance of treating HIPAA risk analysis as an ongoing security process rather than a one-time compliance exercise. Healthcare organizations must understand where their ePHI is located, identify the threats that could affect it, and take documented steps to reduce those risks before a breach occurs.

HIPAA Privacy Policy Template

HIPAA Security Policy Template