OSF HealthCare Pays $552,250 to Settle HIPAA Investigation

OSF HealthCare System and its Affiliated Covered Entities (OSF HealthCare) agreed to pay $552,250 to resolve potential HIPAA violations. OSF is headquartered in Illinois and operates healthcare facilities in Illinois and Michigan. The OCR will monitor the organization under a corrective action plan for two years.

The Office for Civil Rights (OCR) enforces HIPAA Privacy, Security, and Breach Notification Rules. These rules require covered entities and business associates to protect the privacy and security of protected health information (PHI) and electronic protected health information (ePHI).

The enforcement action serves as another reminder that OCR expects organizations to maintain an accurate risk analysis and an effective risk management program.

OCR Director

OCR Director Paula M. Stannard emphasized the importance of conducting a thorough HIPAA risk analysis.

She stated, “An accurate and thorough HIPAA risk analysis is required by law. It also helps protect health information and reduce ransomware risks. Organizations that fail to identify vulnerabilities often discover them only after an attack.”

When did this Start?

OCR opened its investigation after OSF reported a data breach in October 2021.

In April 2021, OSF discovered that attackers had infected their systems with the Nephilim ransomware variant. The attackers exfiltrated the PHI of 53,907 individuals.

The compromised information included driver’s license numbers, diagnoses, treatment records, prescription information, medical record numbers, provider names, service dates, financial account information, and health insurance information.

Potential HIPAA Violations

OCR identified several potential HIPAA violations. OSF allegedly failed to conduct an accurate and thorough risk analysis. The organization impermissibly disclosed the PHI of 53,907 individuals. OSF also failed to notify affected individuals within the required timeframe. In addition, OSF did not provide timely breach notification to the Secretary of Health and Human Services.

The Aftermath

Under the resolution agreement, OSF will implement a corrective action plan for two years. The organization also paid $552,250 to OCR. The corrective action plan requires OSF to strengthen its HIPAA compliance program. OSF must conduct a comprehensive risk analysis. The analysis must identify risks to the confidentiality, integrity, and availability of ePHI. OSF must also develop and implement a risk management plan. The plan must address and reduce identified security risks and vulnerabilities.

Recommendations

OCR recommends several cybersecurity practices for covered entities and business associates.

  • Identify where ePHI is stored and how it enters, moves through, and leaves your systems.
  • Conduct and update risk analyses regularly.
  • Develop and maintain a risk management plan.
  • Implement audit controls to record and review system activity.
  • Review information system activity on a regular basis.
  • Verify user identities before granting access to ePHI.
  • Encrypt ePHI during transmission and while stored whenever appropriate.
  • Apply lessons learned from security incidents to improve security programs.
  • Provide regular HIPAA training that reflects employee responsibilities.

The HIPAA Rules

The HIPAA Privacy Rule establishes national standards for protecting PHI. It also limits how organizations use and disclose PHI. The rule gives individuals important rights, including timely access to their health records.

The HIPAA Security Rule requires administrative, physical, and technical safeguards. These safeguards protect the confidentiality, integrity, and availability of ePHI. The Security Rule also requires organizations to perform accurate and thorough risk analyses.

The HIPAA Breach Notification Rule requires covered entities and business associates to notify affected parties after a breach of unsecured PHI.

OCR continues to enforce the HIPAA Rules to protect patient information.

Protect Your Organization Before It’s Too Late

HIPAA compliance isn’t a one-time project. It’s an ongoing process. At Aris Medical Solutions, our HIPAA Keeper system simplifies compliance with a cloud-based platform that walks you through each requirement, step by step. From risk analysis to training and documentation, you’ll have everything you need to stay protected, compliant, and audit ready.

Protect your practice — and your patients.

Schedule your HIPAA compliance review today and protect your organization from the next enforcement headline.

Drug & Alcohol Treatment Services Ransomware Settlement

HIPAA Compliance Lessons for Healthcare Providers

Healthcare organizations continue to face an unprecedented wave of ransomware attacks, and the financial consequences extend well beyond regulatory penalties.

The latest example involves Drug and Alcohol Treatment Services, Inc. (DATS), an addiction treatment provider based in Scranton, Pennsylvania. The organization has agreed to settle multiple class action lawsuits arising from an October 2024 ransomware attack that compromised sensitive patient information.

While every healthcare breach has unique circumstances, this case reinforces a lesson every covered entity and business associate should understand:

HIPAA compliance is no longer just about policies and employee training—it must include a comprehensive cybersecurity program.

What Happened?

According to public reports, cybercriminals gained unauthorized access to DATS’ network between October 5 and October 6, 2024. Following its investigation, the organization determined that both protected health information (PHI) and personally identifiable information (PII) had been compromised. The breach affected approximately 22,215 individuals.

The Cost of a Breach is just the beginning

The ransomware attack resulted in far more than the technical challenges of restoring systems and investigating the incident.

According to public reports, multiple lawsuits were consolidated into a single class action, culminating in a proposed $549,000 settlement. As part of the settlement, DATS also agreed to maintain and strengthen its information security program for a period of five years, reinforcing the long-term operational and financial impact that a data breach can have on a healthcare organization.

Often, the long-term business impact exceeds the initial ransomware event.

Why OCR Looks Beyond the Attack

One of the biggest misconceptions in healthcare is that organizations are fined simply because they were hacked.

That is not how HIPAA enforcement typically works.

The HHS Office for Civil Rights (OCR) generally evaluates whether the organization had implemented the reasonable and appropriate safeguards required by the HIPAA Security Rule before the attack occurred.

OCR commonly reviews whether an organization had:

  • Conducted an enterprise-wide security risk analysis
  • Implemented a documented risk management plan
  • Maintained current HIPAA policies and procedures
  • Provided workforce HIPAA training
  • Managed vendor and Business Associate Agreements
  • Maintained incident response procedures
  • Reviewed audit logs and system activity
  • Implemented strong access controls
  • Used multi-factor authentication where appropriate
  • Protected systems with encryption and backups

Organizations that cannot demonstrate these safeguards often face much greater regulatory scrutiny following a breach.

Behavioral Health Organizations Face Higher Privacy Risks

For an addiction treatment provider, the exposure of this type of information is especially concerning because it includes records related to behavioral health and substance use disorder (SUD) treatment. In addition to HIPAA, many SUD treatment records are subject to the heightened confidentiality requirements of 42 CFR Part 2, which imposes stricter protections on the use and disclosure of patient information. A breach involving these records can have significant legal, financial, and reputational consequences, making robust cybersecurity and privacy safeguards essential.

Organizations providing behavioral health, psychiatric, addiction treatment, and substance use services often maintain some of the most sensitive healthcare records.

A ransomware attack affecting these organizations may expose information that patients consider deeply personal, increasing both legal exposure and reputational harm.

Because of the sensitive nature of behavioral health records, providers should regularly review both their HIPAA compliance program and applicable federal and state privacy requirements.

Lessons Every Healthcare Organization Should Learn

Every ransomware incident should prompt healthcare organizations to ask:

  • When was our last Security Risk Analysis?
  • Have we documented how risks are being addressed?
  • Are employees receiving annual HIPAA and cybersecurity training?
  • Are our Business Associate Agreements current?
  • Do we test our incident response and contingency plans?
  • Could we demonstrate compliance during an OCR investigation?

If the answer to any of these questions is “I’m not sure,” now is the time to act, not after a cyberattack.

Summary

The DATS settlement is another reminder that ransomware is no longer a question of if, but when.

Healthcare organizations that invest in both cybersecurity and documented HIPAA compliance place themselves in a much stronger position to protect patients, respond effectively to incidents, and demonstrate compliance if regulators come calling. Thus, protecting them from potential class action lawsuits.

As OCR frequently reminds covered entities, documentation matters.

If it’s not documented, it may be difficult to prove it was ever done.

How the HIPAA Keeper™ Helps

The HIPAA Keeper™ was designed to help healthcare organizations build and maintain a documented compliance program that supports the requirements of the HIPAA Privacy Rule and Security Rule.

The platform helps organizations:

  • Complete annual Security Risk Analyses
  • Develop Risk Management Plans
  • Maintain required HIPAA documentation
  • Train employees
  • Track Business Associate Agreements
  • Document compliance activities
  • Prepare for OCR audits
  • Stay organized throughout the year

Cybersecurity tools help prevent attacks. HIPAA compliance helps demonstrate that your organization took reasonable steps to protect patient information before an attack occurred.

Both are essential.

Don’t leave patient data exposed.

At Aris Medical Solutions, our online HIPAA Keeper™ system helps healthcare providers and business associates maintain full compliance.


Schedule your HIPAA Risk Analysis and Access Control Review with Aris Medical Solutions today.

Class Action Lawsuits against Medical Practices

Patients assume medical practices automatically protect their information

Many patients assume their medical information is automatically protected simply because they are visiting a healthcare provider. However, when a medical practice is not fully compliant with HIPAA requirements, sensitive personal and health information may be at greater risk of unauthorized access, disclosure, theft, or misuse. This can include Social Security numbers, insurance information, medical histories, diagnoses, prescriptions, and financial information.

What does Non-Compliance Mean

Non-HIPAA compliant practices may fail to properly secure computer systems, train employees, monitor access to records, or implement safeguards against cyberattacks and ransomware. As a result, patient information may be exposed through hacking incidents, lost devices, employee mistakes, improper conversations, or unsecured email and texting systems. Once information is compromised, patients may face identity theft, medical fraud, insurance fraud, embarrassment, or loss of privacy.

HIPAA is not a once and done process

HIPAA compliance is not just about avoiding government fines. It is about protecting patient trust, confidentiality, and safety. Patients should feel comfortable asking their healthcare provider how their information is protected, whether staff receive HIPAA training, and what safeguards are in place to help prevent data breaches and unauthorized disclosures.

Private Right of Action

HIPAA itself does not provide individuals with a “private right of action,” meaning patients generally cannot sue a Covered Entity or Business Associate directly under HIPAA for a violation. Enforcement authority belongs to the U.S. Department of Health and Human Services Office for Civil Rights (OCR), which investigates complaints and may impose corrective actions, settlements, or civil monetary penalties.

Class Action Lawsuits

However, while patients may not sue “under HIPAA,” class action lawsuits are becoming more prevalent following healthcare data breaches or privacy incidents. Plaintiffs’ attorneys often use alleged HIPAA failures as evidence of negligence, inadequate security practices, breach of fiduciary duty, or violations of state consumer protection and privacy laws. In many cases, lawsuits focus on claims such as emotional distress, identity theft risk, financial harm, or failure to properly safeguard sensitive information. As healthcare breaches continue to increase and state privacy laws expand, organizations are facing growing litigation exposure even when OCR does not issue a HIPAA fine.

Protect Your Organization Before It’s Too Late

HIPAA compliance isn’t a one-time project. It’s an ongoing process. At Aris Medical Solutions, our HIPAA Keeper system simplifies compliance with a cloud-based platform that walks you through each requirement, step by step. From risk analysis to training and documentation, you’ll have everything you need to stay protected, compliant, and audit ready.

Protect your practice — and your patients.

Schedule your HIPAA compliance review today and protect your organization from the next enforcement headline.

BST & Co. CPAs, LLP fined $175K for Ransomware Breach

OCR Issues 15th Ransomware Enforcement Action and 10th Enforcement Action in Risk Analysis Initiative

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with BST & Co. CPAs, LLP (“BST”), a New York-based public accounting, business advisory, and management consulting firm, for potential violations of the HIPAA Security Rule. As a business associate, BST received financial data containing protected health information (PHI) from a HIPAA covered entity.

OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules

This require covered entities (health plans, health care clearinghouses, and most providers) and business associates like BST to safeguard PHI. The HIPAA Security Rule establishes national standards that protect ePHI through administrative, physical, and technical safeguards. Its Risk Analysis provision requires regulated entities to conduct accurate and thorough assessments of risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.

OCR considers a HIPAA risk analysis essential for locating ePHI and determining what security measures are needed to protect it,”

As quoted by OCR Director Paula M. Stannard. “Conducting a thorough risk analysis that drives a risk management plan serves as a foundation for preventing or mitigating cyberattacks and breaches.”

OCR launched its investigation after BST filed a breach report on February 16, 2020. BST reported that on December 7, 2019, it discovered ransomware on part of its network that affected PHI belonging to a covered entity client. Investigators determined that BST had failed to conduct an accurate and thorough risk analysis of its ePHI environment.

Under the resolution agreement

BST agreed to pay $175,000, implement a corrective action plan monitored by OCR for two years, and strengthen its HIPAA Security Rule compliance. BST must:

  • Conduct a thorough risk analysis of its ePHI environment;
  • Develop and implement a risk management plan to address identified risks;
  • Maintain and revise written HIPAA Privacy and Security Rule policies and procedures; and
  • Expand HIPAA and security training, including annual training for workforce members with PHI access.

OCR urged all covered entities and business associates to reduce cyber threats by:

  • Identifying where ePHI resides and how it flows across systems;
  • Performing and updating risk analyses, and implementing risk management measures;
  • Maintaining audit controls and reviewing system activity;
  • Authenticating user access and encrypting ePHI in transit and at rest;
  • Incorporating lessons learned from incidents into security management; and
  • Delivering workforce training tailored to organizational roles and responsibilities.

This case is a clear warning: even trusted professional firms can face HIPAA penalties if they overlook basic security requirements. A thorough risk analysis and an active risk management plan are not just regulatory obligations, they’re essential safeguards for protecting patient data and maintaining client trust.

At Aris Medical Solutions, our HIPAA Keeper platform helps healthcare organizations perform a complete risk analysis, implement risk management strategies, and maintain ongoing compliance with the HIPAA Privacy and Security Rules – all within one secure, cloud-based system.

Don’t wait for an OCR complaint to expose your weaknesses, schedule your annual HIPAA Risk Analysis today.

Syracuse ASC fined $250K for Ransomware

A Costly Reminder of HIPAA’s Ransomware Readiness Requirements. The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR), announced a settlement with Syracuse ASC, LLC, doing business as Specialty Surgery Center of Central New York, for potential violations of the HIPAA Security and Breach Notification Rules. This case marks OCR’s 14th ransomware enforcement action, reinforcing the growing federal focus on cybersecurity preparedness across the healthcare sector.

History

Syracuse ASC is a single-facility ambulatory surgery center in Liverpool, New York, specializing in ophthalmic, ENT, and pain management procedures. In March 2021, the center experienced a ransomware attack involving the PYSA variant—a sophisticated cross-platform malware known for targeting healthcare organizations.

The incident compromised electronic protected health information (ePHI) for 24,891 individuals. OCR initiated an investigation in October 2021 after Syracuse ASC reported the breach to HHS. The investigation revealed that the center had never conducted an accurate and thorough HIPAA risk analysis, as required by the Security Rule. OCR also found that Syracuse ASC failed to provide timely breach notifications to both affected individuals and HHS.

Settlement Terms

Under the Resolution Agreement, Syracuse ASC agreed to:

  • Pay $250,000 to HHS OCR.
  • Implement a Corrective Action Plan (CAP) monitored for two years.

The CAP requires Syracuse ASC to:

  • Conduct a complete and thorough risk analysis of ePHI systems.
  • Develop and implement a risk management plan to address identified vulnerabilities.
  • Review and revise policies and procedures to ensure compliance with HIPAA.
  • Provide annual HIPAA training for all workforce members handling PHI.

OCR’s Message: Ransomware Risks Are Real

OCR Director Paula M. Stannard stressed the critical importance of proactive cybersecurity, stating:

“Conducting a thorough HIPAA-compliant risk analysis—and developing and implementing risk management measures to address identified risks and vulnerabilities—is even more necessary as sophisticated cyberattacks increase. HIPAA covered entities and business associates make themselves soft targets for cyberattacks if they fail to implement the HIPAA Security Rule requirements.”

This case underscores that failing to complete and document a proper risk analysis not only weakens an organization’s defenses but also constitutes a direct violation of the HIPAA Security Rule.

The Role of the Breach Notification Rule

In addition to security failures, OCR determined that Syracuse ASC violated the HIPAA Breach Notification Rule, which requires covered entities and their business associates to:

  • Notify affected individuals without unreasonable delay (no later than 60 days after discovery).
  • Report the breach to HHS within the same timeframe.
  • Document the scope, cause, and mitigation actions taken.

Delayed notification denies patients their right to act quickly to protect their personal and financial information and signals poor incident response readiness.

OCR’s Recommendations for Preventing Cyber Threats

To help prevent or mitigate ransomware and other cyber threats, OCR recommends that all healthcare entities and business associates:

  • Identify where ePHI is stored, transmitted, and processed across all systems.
  • Conduct and regularly update risk analyses.
  • Implement and maintain a risk management plan addressing identified threats.
  • Establish audit controls to monitor system activity.
  • Authenticate all users accessing ePHI.
  • Encrypt ePHI both at rest and in transit.
  • Incorporate lessons learned from past incidents into the security program.
  • Provide ongoing, role-specific HIPAA training for all staff.

Summary

Ransomware attacks are no longer rare events – they’re a daily threat to healthcare organizations of all sizes. OCR’s 14th ransomware enforcement action makes one thing clear: a missing or incomplete risk analysis is a direct pathway to vulnerability and liability.

Every covered entity and business associate must have a documented risk analysis and risk management plan. This is not just for compliance, but to protect patients, data, and the integrity of their operations.

At Aris Medical Solutions, our online HIPAA Keeper™ is an all in one secure, cloud-based system that helps healthcare providers and business associates simplify compliance by maintaining up-to-date policies, procedures, HIPAA training and documentation to meet every aspect of the HIPAA Privacy and Security Rules.

Protect your practice before an attack happens. Schedule your HIPAA compliance review today and protect your organization from the next enforcement headline.

Comstar, a Business Associate fined $75K for Ransomware Attack

The Office for Civil Rights (OCR) has the authority to conduct compliance reviews and investigations of complaints alleging violations of the Privacy, Security, and Breach Notification Rules (the “HIPAA Rules”) by covered entities and business associates. Comstar, LLC (“Comstar”) meets the definition of “business associate” under 45 C.F.R. § 160.103 because it provides billing, collection, consulting, Electronic Patient Care Reporting (ePCR) hosting, and client/patient services for non-profit and municipal ambulance services.

History

On March 19, 2022, an unknown actor gained access to the electronic protected health information (“ePHI”) maintained on Comstar’s network servers. Comstar did not detect the intrusion until March 26, 2022, when its IT service vendor began receiving support tickets. It was determined ransomware was used to encrypt Comstar’s network servers and that the protected health information (“PHI”) of 585,621 individuals was affected.

HHS’ investigation indicated that the following conduct occurred:

  • Comstar failed to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information that it holds.

Resolution Agreement

  • Comstar has agreed to pay HHS $75,000 on the Effective Date of the Agreement.
  • Comstar agrees to comply with the Corrective Action Plan (“CAP”) and if they fail to cure the breach, then Comstar will be in breach of the Agreement and HHS will not be subject to the Release of the Agreement.
  • HHS does not release Comstar from, nor waive any rights, obligations, or causes of action other than those arising out of or related to the Covered Conduct. This release does not extend to actions that may be brought under section 1177 of the Social Security Act, 42 U.S.C. § 1320d-6.
  • The Agreement is binding on Comstar and its successors, heirs, transferees, and assigns.

Summary

This clearly demonstrates the authority HHS has in assessing fines for business associates. Ransomware affects all types of businesses, and an annual risk analysis helps to uncover vulnerabilities to prevent data breaches.

Every medical practice and business associate must have a documented risk analysis and risk management plan. This is not just for compliance, but to protect patients’ information, and the integrity of their operations.

At Aris Medical Solutions, our online HIPAA Keeper™ is an all in one secure, cloud-based system that helps healthcare providers and business associates simplify compliance by maintaining up-to-date policies, procedures, HIPAA training and documentation to meet every aspect of the HIPAA Privacy and Security Rules.

Protect your practice before an attack happens. Schedule your HIPAA compliance review today and protect your organization from the next enforcement headline.

Green Ridge Behavioral Health is Second Ransomware Settlement

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with Green Ridge Behavioral Health, LLC, a Maryland psychiatric practice. The case involved a ransomware attack that compromised the protected health information of more than 14,000 patients.

Ransomware locks users out of their data until a hacker receives payment. OCR enforces HIPAA’s Privacy, Security, and Breach Notification Rules to protect patient information. This marks OCR’s second ransomware-related settlement.

OCR Director Melanie Fontes Rainer said:
“Ransomware is now one of the most common cyber-attacks. Patients suffer when they cannot access their medical records. Providers must take steps to prevent these attacks and protect patient data.”

The Breach

In February 2019, Green Ridge reported to OCR that ransomware encrypted its servers, company files, and all patient electronic health records. OCR’s investigation found multiple HIPAA Security Rule failures, including:

  • No complete risk analysis of electronic PHI.
  • No effective security measures to reduce risks.
  • No sufficient monitoring of system activity.

Settlement Terms

Green Ridge agreed to pay $40,000 and implement a Corrective Action Plan (CAP) monitored by OCR for three years. The CAP requires Green Ridge to:

  • Conduct a full risk analysis.
  • Create a risk management plan.
  • Update policies and procedures.
  • Train its workforce on HIPAA.
  • Audit third-party vendors and ensure business associate agreements.
  • Report workforce HIPAA violations to OCR.

Recommendations

Ransomware and hacking are now the top cyber threats in healthcare. Large breaches have increased 256% in the last five years. Ransomware rose 264% during the same period. In 2023, hacking caused 79% of large breaches, affecting over 134 million people—a 141% increase from 2022.

OCR recommends medical providers and business associates:

  • Regularly perform risk analysis and risk management.
  • Monitor and audit system activity.
  • Use multi-factor authentication and encryption.
  • Ensure strong vendor agreements.
  • Provide frequent, role-specific workforce training.
  • Apply lessons from past incidents.

At Aris Medical Solutions, our HIPAA Keeper™ platform helps healthcare providers simplify compliance by maintaining up-to-date policies, procedures, and workforce training to meet every aspect of the HIPAA Privacy and Security Rules.

Don’t risk costly penalties. Schedule your HIPAA compliance review today and protect your organization from the next enforcement headline.

©2026 Aris Medical Solutions – HIPAA Keeper | HIPAA Compliance Consultants | All Rights Reserved | Terms and Conditions | Privacy Policy
The content and images on this website is owned by Aris Medical Solutions and their owners. Do not copy any content or images without our consent.
Powered by Bandwise LLC