Federal regulators have announced a $552,250 settlement with OSF Healthcare System resolving an investigation into a 2021 ransomware attack that exposed the protected health information of 53,907 patients.
The Department of Health and Human Services Office for Civil Rights announced the resolution at the end of July. Alongside the payment, OSF agreed to a corrective action plan that the agency will monitor for two years.
OSF is a Peoria, Illinois-based system that operates 16 hospitals and serves patients at 174 locations across Illinois and Michigan. For patients treated there five years ago, the practical relevance is not the dollar figure. It is that the categories of information taken in the attack are the kind that remain useful to criminals long after credit monitoring offers expire.
What the Attackers Took
The intrusion was discovered on April 23, 2021, when ransomware was found encrypting files on the OSF network. Investigators attributed the attack to a variant known as Nephilim, and the attackers left a ransom note demanding payment both to unlock the files and to prevent publication of stolen data.
The forensic investigation concluded in August that data had been exfiltrated. According to HIPAA Journal, the information taken from 53,907 patients included names, driver’s license numbers, diagnosis and treatment details, prescription information, medical record numbers, provider names, dates of service, financial account information and health insurance information.
That combination matters more than a typical retail breach. A stolen payment card can be canceled. A driver’s license number, a medical record number and a treatment history cannot, and together they support medical identity theft, in which someone obtains care or prescriptions under another person’s identity and leaves incorrect information in that person’s medical record.
OSF filed its breach report and began notifying patients on October 1, 2021, roughly five months after the attack was discovered and more than a month after the forensic review established that data had left the network. Under the Breach Notification Rule, covered entities generally must notify affected individuals and the HHS Secretary without unreasonable delay and no later than 60 days after discovering a breach.
What Regulators Found
OCR’s investigation identified what the agency characterizes as potential violations of the HIPAA Privacy, Security and Breach Notification Rules.
The findings centered on three issues. The agency concluded that OSF had not conducted an accurate and thorough risk analysis of the potential risks and vulnerabilities to its electronic protected health information, that the information of 53,907 individuals was impermissibly disclosed, and that the organization failed to provide timely breach notification to both affected individuals and the HHS Secretary.
OCR Director Paula M. Stannard said an accurate and thorough risk analysis is not only required by law but is necessary to protect health information, adding that “if a HIPAA regulated entity doesn’t know what threats and vulnerabilities exist to its electronic protected health information, they will often learn the hard way when their systems are hacked.”
Under the resolution agreement and corrective action plan, OSF committed to conducting an accurate and thorough risk analysis and to developing and implementing a risk management plan addressing the vulnerabilities that analysis identifies. Agreements of this type resolve the investigation without a formal adjudication, and OCR describes the underlying conduct as potential violations rather than established findings.
The Pattern Behind a Single Settlement
This is not an isolated action. According to industry tracking, the OSF agreement is the eighth OCR settlement announced this year and the largest, with $2,280,250 collected across those eight actions. It is also the agency’s 21st enforcement action arising from a ransomware investigation.
The consistency of the findings is the story. All eight of this year’s settlements identified risk analysis failures. In case after case, OCR has centered its enforcement on the same gap: a health care organization that did not complete a rigorous, enterprise-wide analysis of where its patient data lived and what could go wrong. Regulators have made clear they do not treat a successful ransomware attack as bad luck alone.
For patients, the accountability question is narrow but legitimate. Health systems collect sensitive information as a condition of receiving care, and patients have no ability to shop for a provider based on the quality of its risk analysis. Enforcement is one of the few mechanisms through which that obligation is tested.
What Affected Patients Should Do Now
Anyone who received care at an OSF facility before the spring of 2021 and was notified of this breach should assume the exposure is permanent rather than expired.
Freezing credit files with all three major bureaus is free, can be done online, and blocks new accounts from being opened. It is more protective than monitoring, which only reports activity after it happens. Reviewing the explanation of benefits statements from an insurer is the medical equivalent, since charges for care a patient never received are often the first visible sign of medical identity theft.
Patients can also request an accounting of disclosures from a provider, which lists certain releases of their health information, and can ask to review their medical record for entries that do not match their own history. Incorrect clinical information introduced by someone else can affect future treatment decisions, which makes this more than an administrative concern.
Anyone who suspects medical identity theft can report it through the Federal Trade Commission’s identity theft site and should notify both their insurer and their provider directly. Correcting a contaminated record usually requires a written amendment request to the provider, so starting that process early is worthwhile.
No further action is required of patients as a result of this settlement itself. OCR will monitor OSF’s compliance with the corrective action plan for two years, and the agency publishes resolution agreements as they are announced.
Frequently Asked Questions
What happened? Ransomware was discovered encrypting files on the OSF Healthcare network in April 2021, and a forensic investigation later determined that patient information had been stolen from the network.
How many patients were affected? 53,907.
What information was taken? Names, driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of service, financial account information and health insurance information.
What did OSF agree to? A payment of $552,250 and a corrective action plan that OCR will monitor for two years, requiring an accurate and thorough risk analysis and a risk management plan.
Is this an admission of wrongdoing? No. OCR describes the conduct as potential violations, and the agreement resolves the investigation without a formal adjudication of liability.
Do affected patients need to do anything? Nothing is required because of the settlement. Freezing credit files, reviewing insurance explanation of benefits statements, and checking medical records for unfamiliar entries remain sensible steps.
What is medical identity theft? When someone uses another person’s identity to obtain care, prescriptions, or insurance benefits, it can introduce incorrect information into the victim’s medical record.
