Table of Contents
The U.S. Department of Health and Human Services’ Office for Civil Rights has announced an OSF HealthCare HIPAA settlement resolving alleged violations tied to a 2021 ransomware attack on the Peoria, Illinois-based health system.
What Triggered This OSF HealthCare HIPAA Settlement
On April 23, 2021, OSF HealthCare discovered that ransomware had been used to encrypt files on its network. The threat group deployed a variant of Nephilim ransomware to encrypt files and demanded payment to prevent a data leak and to obtain the keys to unlock the encrypted files. OSF is headquartered in Illinois and has providers located in Illinois and Michigan, serving patients at 174 locations, including 16 hospitals.
How Many Patients Were Affected
The forensic investigation determined on August 24, 2021, that the protected health information of 53,907 patients was exfiltrated during the attack. According to separate reporting, the attackers, identified as a group called Xing Team, added OSF to its leak site on May 18, 2021, and published the stolen data on June 3, 2021.
What OCR Found Wrong in This OSF HealthCare HIPAA Settlement
OCR determined that OSF Healthcare failed to issue timely notifications to the individuals affected by the data breach and did not provide a timely notification to the Secretary of HHS, in violation of federal breach notification requirements. Affected individuals and HHS were informed more than five months after the attack was detected, well beyond the 60-day window HIPAA’s Breach Notification Rule requires.
A Failure to Conduct Adequate Risk Analysis
OCR also determined that OSF failed to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the electronic protected health information it held. “An accurate and thorough HIPAA risk analysis is not only required by law, but it is also necessary to protect health information and prevent or mitigate ransomware attacks,” said OCR Director Paula M. Stannard.
Terms of the OSF HealthCare HIPAA Settlement
Under the terms of the settlement, OSF Healthcare agreed to pay the $552,250 penalty in one lump sum by July 15, 2026, and will implement a corrective action plan that OCR will monitor for a period of two years.
What the Corrective Action Plan Requires
The corrective action plan includes the requirement to conduct an accurate and thorough risk analysis, and develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in that analysis, directly targeting the specific compliance gaps OCR’s investigation uncovered.
How This Fits a Broader Pattern of Ransomware Enforcement
This settlement marks OCR’s 21st HIPAA enforcement action stemming from a ransomware investigation. It follows a cluster of four separate ransomware-related settlements OCR announced in April 2026, together affecting more than 427,000 individuals and totaling more than $1 million in financial penalties, with all four cases citing similar gaps in risk analysis, risk management, and technical safeguards.
A Recurring Theme in OCR’s Enforcement Focus
OCR’s investigation identified gaps in OSF’s risk analysis, risk management, and technical safeguards, the same cluster of deficiencies regulators have cited repeatedly in ransomware-related enforcement actions over the past several years, suggesting inadequate risk analysis remains one of the most common and consequential compliance failures OCR encounters across the healthcare industry.
What This OSF HealthCare HIPAA Settlement Means for Other Health Systems
Given that risk analysis failures have now appeared repeatedly across OCR’s recent ransomware enforcement actions, health systems nationwide may want to treat this settlement as a signal to prioritize comprehensive, enterprise-wide risk analyses before an incident occurs rather than after. OCR’s recommendation that regulated entities identify where electronic protected health information is located and how it flows through their organization offers a concrete starting point for systems seeking to avoid similar penalties.
What to Watch Going Forward
As OCR continues its pattern of ransomware-related HIPAA enforcement, with 21 such settlements now on record, health systems should expect continued scrutiny of both technical safeguards and breach notification timelines following any future security incident. Given the two-year corrective action plan now governing OSF’s compliance, other health systems facing similar ransomware incidents may look to this OSF HealthCare HIPAA settlement as a benchmark for the kinds of risk analysis and risk management improvements OCR expects to see implemented following a breach.
For more healthcare industry updates, insights and news, visit DistilINFO. Click here to subscribe to stay informed.
