OSF HealthCare Pays $552,250 to Settle HIPAA Investigation

Ransomware with OCR fine paid

OSF HealthCare System and its Affiliated Covered Entities (OSF HealthCare) agreed to pay $552,250 to resolve potential HIPAA violations. OSF is headquartered in Illinois and operates healthcare facilities in Illinois and Michigan. The OCR will monitor the organization under a corrective action plan for two years.

The Office for Civil Rights (OCR) enforces HIPAA Privacy, Security, and Breach Notification Rules. These rules require covered entities and business associates to protect the privacy and security of protected health information (PHI) and electronic protected health information (ePHI).

The enforcement action serves as another reminder that OCR expects organizations to maintain an accurate risk analysis and an effective risk management program.

OCR Director

OCR Director Paula M. Stannard emphasized the importance of conducting a thorough HIPAA risk analysis.

She stated, “An accurate and thorough HIPAA risk analysis is required by law. It also helps protect health information and reduce ransomware risks. Organizations that fail to identify vulnerabilities often discover them only after an attack.”

When did this Start?

OCR opened its investigation after OSF reported a data breach in October 2021.

In April 2021, OSF discovered that attackers had infected their systems with the Nephilim ransomware variant. The attackers exfiltrated the PHI of 53,907 individuals.

The compromised information included driver’s license numbers, diagnoses, treatment records, prescription information, medical record numbers, provider names, service dates, financial account information, and health insurance information.

Potential HIPAA Violations

OCR identified several potential HIPAA violations. OSF allegedly failed to conduct an accurate and thorough risk analysis. The organization impermissibly disclosed the PHI of 53,907 individuals. OSF also failed to notify affected individuals within the required timeframe. In addition, OSF did not provide timely breach notification to the Secretary of Health and Human Services.

The Aftermath

Under the resolution agreement, OSF will implement a corrective action plan for two years. The organization also paid $552,250 to OCR. The corrective action plan requires OSF to strengthen its HIPAA compliance program. OSF must conduct a comprehensive risk analysis. The analysis must identify risks to the confidentiality, integrity, and availability of ePHI. OSF must also develop and implement a risk management plan. The plan must address and reduce identified security risks and vulnerabilities.

Recommendations

OCR recommends several cybersecurity practices for covered entities and business associates.

  • Identify where ePHI is stored and how it enters, moves through, and leaves your systems.
  • Conduct and update risk analyses regularly.
  • Develop and maintain a risk management plan.
  • Implement audit controls to record and review system activity.
  • Review information system activity on a regular basis.
  • Verify user identities before granting access to ePHI.
  • Encrypt ePHI during transmission and while stored whenever appropriate.
  • Apply lessons learned from security incidents to improve security programs.
  • Provide regular HIPAA training that reflects employee responsibilities.

The HIPAA Rules

The HIPAA Privacy Rule establishes national standards for protecting PHI. It also limits how organizations use and disclose PHI. The rule gives individuals important rights, including timely access to their health records.

The HIPAA Security Rule requires administrative, physical, and technical safeguards. These safeguards protect the confidentiality, integrity, and availability of ePHI. The Security Rule also requires organizations to perform accurate and thorough risk analyses.

The HIPAA Breach Notification Rule requires covered entities and business associates to notify affected parties after a breach of unsecured PHI.

OCR continues to enforce the HIPAA Rules to protect patient information.

Protect Your Organization Before It’s Too Late

HIPAA compliance isn’t a one-time project. It’s an ongoing process. At Aris Medical Solutions, our HIPAA Keeper system simplifies compliance with a cloud-based platform that walks you through each requirement, step by step. From risk analysis to training and documentation, you’ll have everything you need to stay protected, compliant, and audit ready.

Protect your practice — and your patients.

Schedule your HIPAA compliance review today and protect your organization from the next enforcement headline.

About Suze Shaffer

Suze Shaffer is the owner and president of Aris Medical Solutions. She specializes in HIPAA compliance, risk management, and cyber security. She believes that by educating her clients in understanding why and what needs to be done to protect their practice they have a better outcome.

Suze has been instrumental in helping clients nationwide with risk management, implementing privacy and security rule policies and procedures, and ultimately protecting patient data. She includes state and federal regulatory requirements to ensure clients are protected in all areas.

She has spoken at numerous conferences and functions. She continues to educate organizations how to minimize the risks of data breaches. HIPAA compliance is not an option, it is mandatory for every organization that comes in contact with protected health information to have reasonable and appropriate security measures in place. Unfortunately, most organizations don’t realize they are not compliant until they suffer a data breach or they are faced with an audit or investigation.

Did you know that the Office for Civil Rights (OCR) is the agency that investigates data breaches? Have you seen the heavy fines that have been imposed for non-compliance?

All 50 states now have their own set of privacy laws and the State's Attorney General may also investigate privacy violations!

Drug & Alcohol Treatment Services Ransomware Settlement

July 22, 2026
©2026 Aris Medical Solutions – HIPAA Keeper | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC