OSF Healthcare Agrees to $552,250 HIPAA Settlement After Ransomware Investigation

by | Aug 10, 2026 | Healthcare Industry News

OSF Healthcare System agreed to pay $552,250 to resolve alleged violations of the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule following a ransomware incident that affected the protected health information (PHI) of 53,907 patients.

Ransomware Incident Affected Patient Information

Integrated health system OSF Healthcare, based in Peoria, Illinois, serves patients at 174 locations in Illinois and Michigan, including 16 hospitals. OSF Healthcare discovered a ransomware attack on its network on April 23, 2021 that resulted to files encryption. The attacker used a variant of Nephilim ransomware and demanded payment to prevent a data leak and obtain keys to unlock the encrypted files.

A forensic investigation determined on August 24, 2021, that PHI had been exfiltrated from the network. The affected information included names, diagnosis and treatment details, prescription data, medical record numbers, names of provider, dates of services, financial account details, medical insurance information, and driver’s license numbers.

OSF Healthcare notified OCR about the attack on October 1, 2021, and started sending individual notification letters as well.

OCR Investigates HIPAA Violations

OCR initiated an investigation after being notified of the breach. The investigation assessed OSF Healthcare’s compliance with the HIPAA Rules.

The findings of OCR about the OSF Healthcare incident included the following:
OSF failed to conduct a comprehensive and accurate risk analysis to identify risks and vulnerabilities affecting the integrity, confidentiality, and availability of patients’ PHI. The requirement is established under 45 C.F.R. § 164.308(a)(l)(ii)(A).

The exfiltration of data constituted an impermissible disclosure of the PHI of 53,907 patients, in violation of 45 C.F.R. § 164.502(a).

OSF Healthcare failed to provide timely notifications to affected individuals and failed to provide timely notification to the HHS Secretary, which constitute violations under 45 C.F.R. § 164.404(b) and § 164.408(b).

Settlement Requires Corrective Action Plan

OCR determined that the alleged violations warranted a financial penalty. After OCR advised OSF Healthcare System of the investigation findings and its intention to impose a financial penalty, the parties agreed to a settlement to resolve the alleged violations.

The settlement requires OSF Healthcare to pay $552,250 and implement a corrective action plan. OSF Healthcare will be monitored for compliance with the plan for two years.

The corrective action plan requires OSF Healthcare to conduct an accurate and thorough risk analysis and develop and implement a risk management plan addressing and mitigating security risks and vulnerabilities identified through the risk analysis.

OCR Enforcement Activity

OCR settled eight HIPAA investigations this year and collected $2,280,250 in penalties. The OSF Healthcare settlement is the largest penalty to date this year. Investigation of all eight cases concluded that risk analysis failures were involved. The OSF Healthcare issue was the second case that issued a penalty for breach notification failures.

OCR Director Paula M. Stannard stated that an accurate and thorough HIPAA risk analysis is required by law and is intended to help regulated entities identify threats and vulnerabilities involving electronic protected health information. She also stated that risk analysis can help prevent or mitigate ransomware attacks.

Stay Informed

Subscribe To Our Newsletter To Receive Healthcare Industry News Via Email

View our privacy policy

Categories