HHS’ Office for Civil Rights Settles Ransomware Investigation with Healthcare System
Settlement Marks OCR's 21st Ransomware Enforcement Action
The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) today announced a settlement with OSF Healthcare System and its Affiliated Covered Entities (OSF), concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules. OSF is headquartered in Illinois and has providers located in Illinois and Michigan.
“An accurate and thorough HIPAA risk analysis is not only required by law, but it is also necessary to protect health information and prevent or mitigate ransomware attacks,” said OCR Director Paula M. Stannard. “If a HIPAA regulated entity doesn’t know what threats and vulnerabilities exist to its electronic protected health information (ePHI), they will often learn the hard way when their systems are hacked.”
OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules, which set forth the requirements that covered entities (health plans, health care clearinghouses, and most health care providers), and business associates must follow to protect the privacy and security of PHI.
The settlement resolves an investigation that OCR initiated after OSF filed a breach report in October 2021. In April of 2021, OSF discovered that its files had been infected with the “Nephilim” variant of ransomware. The PHI of 53,907 individuals was exfiltrated by the threat actor. Affected PHI included driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and health insurance information. OCR found that OSF had potentially violated provisions of the Privacy, Security and Breach Notification Rules, including:
- Failing to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the ePHI held by OSF;
- Impermissibly disclosing the PHI of 53,907 individuals;
- Failing to provide timely breach notification to affected individuals; and
- Failing to provide timely breach notification to the Secretary of HHS.
Under the terms of the resolution agreement, OSF agreed to implement a corrective action plan that OCR will monitor for two years and paid $552,250 to OCR. Under the corrective action plan, OSF has committed to taking steps to ensure compliance with the HIPAA Rules and protect the security of ePHI, including:
- Conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI; and
- Develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis.
Read the resolution agreement and corrective action plan.
OCR recommends that regulated entities, including health care providers, health plans, health care clearinghouses, and business associates take the following steps to mitigate or prevent cyber-threats:
- Identify where ePHI is located in the organization, including how ePHI enters, flows through, and leaves the organization’s information systems.
- Periodically conduct, and update as needed, a risk analysis and develop and implement a risk management plan to address identified risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
- Ensure audit controls are in place to record and examine information system activity.
- Implement regular review of information system activity.
- Utilize mechanisms to authenticate information to ensure only authorized users are accessing ePHI.
- Encrypt ePHI in transit and at rest to guard against unauthorized access to ePHI when appropriate.
- Incorporate lessons learned from incidents into the organization’s overall security management process.
- Provide workforce members with regular HIPAA training that is specific to the organization and to the workforce members’ respective job duties.
OCR is committed to enforcing the HIPAA Rules that protect the privacy and security of individuals’ health information. The HIPAA Privacy Rule establishes national standards to protect individuals' PHI; sets limits and conditions on the uses and disclosures of PHI; and gives individuals certain rights, including the right to timely access their health records. The HIPAA Security Rule establishes national standards to protect and secure our health care system by requiring administrative, physical, and technical safeguards to ensure the confidentiality, integrity, security, and availability of ePHI. The Risk Analysis provision requires regulated organizations (covered entities and business associates) to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by that organization. The Breach Notification Rule requires HIPAA covered entities and their business associates to provide notification following a breach of unsecured PHI. Guidance about the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule, and the Security Rule's Risk Analysis requirement, can also be found on OCR’s website.
Covered entities must comply with breach notification obligations under the HIPAA Breach Notification Rule. In submitting a notice of a breach of unsecured PHI to the HHS Secretary, covered entities must use the HHS Breach Portal.
If you believe that your or another person’s health information privacy or civil rights have been violated, you can file a complaint with OCR.
Follow HHS OCR on X at @HHSOCR.
Like HHS on Facebook, follow HHS on X @HHSgov, @SecKennedy, and sign up for HHS Email Updates.
Last revised: