OCR fines OSF Healthcare $552,250 after ransomware probe finds compliance gaps

HHS Office for Civil Rights settles HIPAA investigation with OSF Healthcare System for $552,250 over a 2021 ransomware attack affecting 53,907 individuals.

MedRisk Staff
By
2 Min Read

The US Department of Health and Human Services Office for Civil Rights has settled a HIPAA investigation with OSF Healthcare System for $552,250, resolving allegations tied to a 2021 ransomware attack that exposed the protected health information of 53,907 individuals.

OCR determined that OSF Healthcare violated multiple HIPAA rules during the April 2021 incident, in which the Nephilim ransomware variant encrypted files on the health system’s network. The agency found that OSF failed to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to its electronic protected health information, impermissibly disclosed the PHI of nearly 54,000 individuals, and failed to provide timely breach notification to both affected individuals and the HHS secretary.

The attack was carried out by a little-known ransomware group called Xing Team, which exfiltrated data including driver’s license numbers, diagnosis and treatment information, prescription records, medical record numbers, financial account details, and health insurance information. OSF Healthcare, headquartered in Peoria, Illinois, operates providers across Illinois and Michigan.

Under the settlement terms, OSF Healthcare agreed to implement a corrective action plan monitored by OCR for two years. The plan requires the health system to conduct a complete risk analysis and develop a risk management plan to address identified security gaps. OCR Director Paula M. Stannard noted that an accurate and thorough HIPAA risk analysis is necessary to protect health information and prevent or mitigate ransomware attacks. The $552,250 penalty is the largest HIPAA enforcement action of the year to date.

Share This Article