Five Recent Office for Civil Rights HIPAA Ransomware Settlements

Bruce D. Armon, Evan J. Foster
Published

Ransomware ‘attacks’ against health care providers, business associates and third-party administrators are not practice or geography or size specific. They can happen to any entity, not only a health care provider, at any time. The U.S. Department of Health and Human Services (“HHS”) Office for Civil Rights (“OCR”) describes ransomware as, “malicious software that blocks access to data—typically by encrypting it with a key known only to the attacker—until a ransom is paid.” Ransomware also has the ability to exfiltrate data outside of the victim’s environment, allowing the attacker to again extort the victim by threatening to sell the data to the highest bidder or post it publicly unless a ransom is paid. To date, including a settlement announced at the end of July 2026, OCR has been a party to 21 ransomware enforcement actions.

The most recent OCR settlement was with OSF Healthcare System and its related entities. OSF has locations in Illinois and Michigan. As part of its investigation following an OSF breach report filed in October 2021, OCR uncovered evidence suggesting OSF had potentially violated provisions of the HIPAA Privacy, Security and Breach notification rules. This ransomware incident affected the PHI of almost 54,000 individuals. As part of the OCR settlement, OSF agreed to implement a two-year corrective action plan and pay $552,500.

Four other recent ransomware settlements with OCR included: 

  • Axia Women’s Health, a network of women’s health care providers in New Jersey, Pennsylvania, Ohio, Indiana, and Kentucky. The ransomware affected almost 38,000 individuals and the group agreed to a $320,000 OCR settlement. This breach was reported in December 2020.
  • Assured Imaging, a medical imaging and screening service provider with corporate headquarters in Arizona and California. The ransomware affected almost 245,000 individuals and the provider agreed to a $375,000 OCR settlement. This breach was reported in May 2020.
  • Consociate Health, a third-party administrator of employee-sponsored benefit programs that provides health plan administration, plan analytics and consulting services to HIPAA-covered entities as a business associate. More than 136,000 individuals were affected by the ransomware and Consociate agreed to a $225,000 settlement. The Consociate breach was reported to OCR in November and December 2021.
  • Star Group, a self-funded employee benefits plan of a Connecticut-based energy provider. More than 9,000 individuals were affected by this ransomware incident. Star Group agreed to a $245,000 OCR settlement. The ransomware incident was reported in October 2021.

There are several important takeaways from these OCR settlements. HIPAA-covered entities should perform regular and thorough risk analyses of potential risk and vulnerabilities to its electronic protected health information (“ePHI”). Similarly, HIPAA-covered entities should develop and implement risk management plans to address and mitigate security risks. This may include conducting tabletop exercises to practice an organization’s response to a ransomware incident, conducting regular testing of backup and restoration procedures and reviewing and updating cyber insurance coverage. In the past several years, OCR settlements have focused on alleged HIPAA security rule and breach notification violations as opposed to privacy rule considerations.

As part of the ransomware settlement announcement, OCR notes the following.

OCR recommends that health care providers, health plans, health care clearinghouses, and business associates that are covered by the HIPAA Security Rule take the following steps to prevent or mitigate cyber-threats:

  • Identify where ePHI is located in the organization, including how ePHI enters, flows through, and leaves the organization’s information systems.
  • Periodically conduct, and update as needed, a risk analysis and develop and implement a risk management plan to address identified risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
  • Ensure audit controls are in place to record and examine information system activity.
  • Implement regular review of information system activity.
  • Utilize mechanisms to authenticate information to ensure only authorized users are accessing ePHI.
  • Encrypt ePHI in transit and at rest to guard against unauthorized access to ePHI when appropriate.
  • Incorporate lessons learned from incidents into the organization’s overall security management process.
  • Provide workforce members with regular HIPAA training that is specific to the organization and to the workforce members’ respective job duties.

Why do ransomware attacks keep happening? Because bad actors can significantly impact the affected target and in some instances get paid for their deliberate actions. Healthcare organizations are an especially attractive target because of the perceived value and sensitivity of ePHI. The target must address questions and investigation by OCR and await OCR recommendations—which can be a multi-year process—and then determine if a settlement agreement and the adoption of a corrective action plan are in the organization’s best interest. Ransomware victims are also likely to be targeted in class action lawsuits alleging a failure to maintain adequate security measures. Maintaining vigorous HIPAA security rule protections can help a HIPAA-covered entity prevent the success of a bad actor and may mitigate the consequences of an OCR investigation following a breach incident. 

Saul Ewing regularly assists covered entities and business associates with respect to HIPAA compliance issues, breach responses, business associate agreements, and drafting and updating HIPAA policies and procedures. For questions about how ransomware attacks and how OCR settlements may impact your organization, please contact Bruce Armon, Head, Health Care Practice, and Evan Foster, Head, Cybersecurity and Privacy Practice.

Authors
Bruce Armon
Evan Foster Headshot
Related Services