OSF HealthCare System and its Affiliated Covered Entities (OSF HealthCare) agreed to pay $552,250 to resolve potential HIPAA violations. OSF is headquartered in Illinois and operates healthcare facilities in Illinois and Michigan. The OCR will monitor the organization under a corrective action plan for two years.
The Office for Civil Rights (OCR) enforces HIPAA Privacy, Security, and Breach Notification Rules. These rules require covered entities and business associates to protect the privacy and security of protected health information (PHI) and electronic protected health information (ePHI).
The enforcement action serves as another reminder that OCR expects organizations to maintain an accurate risk analysis and an effective risk management program.
OCR Director
OCR Director Paula M. Stannard emphasized the importance of conducting a thorough HIPAA risk analysis.
She stated, “An accurate and thorough HIPAA risk analysis is required by law. It also helps protect health information and reduce ransomware risks. Organizations that fail to identify vulnerabilities often discover them only after an attack.”
When did this Start?
OCR opened its investigation after OSF reported a data breach in October 2021.
In April 2021, OSF discovered that attackers had infected their systems with the Nephilim ransomware variant. The attackers exfiltrated the PHI of 53,907 individuals.
The compromised information included driver’s license numbers, diagnoses, treatment records, prescription information, medical record numbers, provider names, service dates, financial account information, and health insurance information.
Potential HIPAA Violations
OCR identified several potential HIPAA violations. OSF allegedly failed to conduct an accurate and thorough risk analysis. The organization impermissibly disclosed the PHI of 53,907 individuals. OSF also failed to notify affected individuals within the required timeframe. In addition, OSF did not provide timely breach notification to the Secretary of Health and Human Services.
The Aftermath
Under the resolution agreement, OSF will implement a corrective action plan for two years. The organization also paid $552,250 to OCR. The corrective action plan requires OSF to strengthen its HIPAA compliance program. OSF must conduct a comprehensive risk analysis. The analysis must identify risks to the confidentiality, integrity, and availability of ePHI. OSF must also develop and implement a risk management plan. The plan must address and reduce identified security risks and vulnerabilities.
Recommendations
OCR recommends several cybersecurity practices for covered entities and business associates.
- Identify where ePHI is stored and how it enters, moves through, and leaves your systems.
- Conduct and update risk analyses regularly.
- Develop and maintain a risk management plan.
- Implement audit controls to record and review system activity.
- Review information system activity on a regular basis.
- Verify user identities before granting access to ePHI.
- Encrypt ePHI during transmission and while stored whenever appropriate.
- Apply lessons learned from security incidents to improve security programs.
- Provide regular HIPAA training that reflects employee responsibilities.
The HIPAA Rules
The HIPAA Privacy Rule establishes national standards for protecting PHI. It also limits how organizations use and disclose PHI. The rule gives individuals important rights, including timely access to their health records.
The HIPAA Security Rule requires administrative, physical, and technical safeguards. These safeguards protect the confidentiality, integrity, and availability of ePHI. The Security Rule also requires organizations to perform accurate and thorough risk analyses.
The HIPAA Breach Notification Rule requires covered entities and business associates to notify affected parties after a breach of unsecured PHI.
OCR continues to enforce the HIPAA Rules to protect patient information.
Protect Your Organization Before It’s Too Late
HIPAA compliance isn’t a one-time project. It’s an ongoing process. At Aris Medical Solutions, our HIPAA Keeper™ system simplifies compliance with a cloud-based platform that walks you through each requirement, step by step. From risk analysis to training and documentation, you’ll have everything you need to stay protected, compliant, and audit ready.

Protect your practice — and your patients.
Schedule your HIPAA compliance review today and protect your organization from the next enforcement headline.









