OCR settles HIPAA ransomware case with OSF Healthcare for $552,250
On July 29, 2026, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a settlement with OSF Healthcare System and its Affiliated Covered Entities (OSF). OCR framed the case as its 21st ransomware-related HIPAA enforcement action.
OSF is headquartered in Illinois and operates providers in Illinois and Michigan. The investigation followed a breach report OSF filed in October 2021 after discovering, in April 2021, that files had been infected with the Nephilim ransomware variant. OCR said protected health information (PHI) for 53,907 individuals was exfiltrated, including driver’s license numbers, diagnosis and treatment details, prescriptions, medical record numbers, dates of service, financial account data, and health insurance information.
What OCR found
OCR said OSF potentially violated the HIPAA Privacy, Security, and Breach Notification Rules by:
- Failing to conduct an accurate and thorough risk analysis of risks and vulnerabilities to electronic PHI (ePHI)
- Impermissibly disclosing the PHI of 53,907 individuals
- Failing to provide timely breach notification to affected individuals
- Failing to provide timely breach notification to the HHS Secretary
Under the resolution agreement, OSF paid $552,250 and agreed to a two-year corrective action plan that OCR will monitor. The plan requires OSF to complete an accurate and thorough risk analysis and to develop and implement a risk management plan that addresses the risks identified.
The current HIPAA Security Rule remains in force. This settlement does not rewrite the rules. It shows OCR continuing to treat incomplete risk analysis and late breach notification as enforcement priorities after ransomware incidents.
What to do now
- Confirm you have a current, enterprise-wide Security Rule risk analysis that covers where ePHI lives, how it moves, and how ransomware and related threats are addressed.
- Turn risk-analysis findings into a living risk management plan with owners, timelines, and evidence, not a one-time document.
- Rehearse breach-notification clocks for individuals and HHS so discovery, investigation, and notice stay inside HIPAA timelines.
- Review audit logging, authentication, encryption in transit and at rest, and workforce training against OCR’s published ransomware mitigation recommendations.
- Follow HIPAA on this site for Security Rule timeline updates and later OCR enforcement signals.