OSF Healthcare Settles with HHS Over HIPAA Violations Following Ransomware Attack
Last month, the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a settlement with Illinois-based OSF Healthcare System and its Affiliated Covered Entities (OSF) regarding potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules.
The settlement resolves an investigation initiated by OCR after OSF filed a breach report in October 2021. In April 2021, OSF discovered that its files had been infected with the “Nephilim” variant of ransomware. The threat actor exfiltrated the PHI (Protected Health Information) of 53,907 individuals. This included driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of service, financial account information, and health insurance information.
OCR found that OSF may have violated provisions of the Privacy, Security, and Breach Notification Rules, including:
- Failing to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the ePHI (electronic Protected Health Information) held by OSF
- Impermissibly disclosing the PHI of 53,907 individuals
- Failing to provide timely breach notification to affected individuals
- Failing to provide timely breach notification to the Secretary of HHS
Under the terms of the resolution agreement, OSF agreed to implement a corrective action plan that OCR will monitor for two years and to pay $552,250 to OCR.
About the Author
Pietje Kobus-McAllisterPietje Kobus-McAllister
Lead Reporter
Pietje Kobus-McAllister has an international background and experience in content management and editing. She studied journalism in the Netherlands and Communications and Creative Nonfiction in the U.S. Pietje joined Healthcare Innovation in January 2024.
