LeadingAge Texas

08/04/2026 | Press release | Distributed by Public on 08/04/2026 10:11

Federal Regulators Settle HIPAA Enforcement Action with OSF Healthcare

August 04, 2026

Federal Regulators Settle HIPAA Enforcement Action with OSF Healthcare

Home » Federal Regulators Settle HIPAA Enforcement Action with OSF Healthcare

BY Clarette
Share

Recommend

The Department of Health and Human Services (HHS), Office of Civil Rights (OCR) announced on July 29, 2026, that it entered into a settlement agreement with OSF Healthcare System (OSF), concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules.

OCR initiated an investigation of OSF after OSF filed a breach report in October 2021 that its files had been infected with the "Nephilim" variant of ransomware. OCR found that OSF had potentially violated provisions of the Privacy, Security and Breach Notification Rules, including by: failing to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the electronic protected health information (ePHI) held by OSF; impermissibly disclosing the protected health information of 53,907 individuals; failing to provide timely breach notification to affected individuals; and failing to provide timely breach notification to the Secretary of HHS. Under the terms of the resolution agreement, OSF agreed to implement a corrective action plan that OCR will monitor for two years, which includes conducting a risk analysis and developing and implementing a risk management plan. OSF also agreed to pay $552,250 to OCR.

In its announcement, OCR recommended a number of steps for health care providers to mitigate or prevent cyber-threats, including: identifying where ePHI is located in the organization, including how ePHI enters, flows through, and leaves the organization's information systems; periodically conduct, and update as needed, a risk analysis and develop and implement a risk management plan to address identified risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI; and utilizing mechanisms to authenticate information to ensure only authorized users are accessing ePHI.

As these types of ransomware attacks continue to be a concern among aging services providers, LeadingAge's Center for Aging Services Technologies has extensive cybersecurity resources available, including a Cybersecurity White Paper to help providers understand cybersecurity threats, how to mitigate them, and how to respond if attacked.

LeadingAge Texas published this content on August 04, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 04, 2026 at 16:11 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]