OSF Healthcare System and its Affiliated Covered Entities have decided to pay $552,250 to settle alleged HIPAA violations following a ransomware attack that impacted the protected health information (PHI) of 53,907 patients.
Peoria, Illinois-based integrated health system, OSF Healthcare, serves patients at 174 locations (with 16 hospitals) in Illinois and Michigan.
On April 23, 2021, OSF Healthcare found out that files on its network were encrypted by ransomware. The threat group used a Nephilim ransomware variant and demanded payment to stop data exposure and get the files decryption keys.
A forensic investigation established on August 24, 2021, that PHI of 53,907 patients had been extracted from the network. The data included names, driver’s license numbers, medical record numbers, diagnosis and treatment details, prescription details, provider names, dates of services, financial account details, and medical insurance information.
OSF Healthcare advised OCR concerning the attack on October 1, 2021. Individual notification letters were issued on that date.
OCR Investigation Findings
OCR started an investigation to check OSF Healthcare’s compliance with the HIPAA Rules right after the breach.
OCR confirmed that OSF Healthcare failed to conduct a complete and accurate risk analysis to determine risks and vulnerabilities impacting the confidentiality, integrity, and availability of patients’ PHI, in violation of 45 C.F.R. § 164.308(a)(l)(ii)(A).
OCR also confirmed that OSF Healthcare had impermissibly disclosed 53,907 patients’ PHI, in violation of 45 C.F.R. § 164.502(a).
The investigation also found that OSF Healthcare did not issue timely breach notifications to impacted individuals and to the Secretary of the HHS, in violation of 45 C.F.R. § 164.404(b) and § 164.408(b).
Settlement Terms
OCR decided that the claimed HIPAA violations called for a financial penalty. After OCR informed OSF Healthcare System of the investigation findings and its intent to enforce a financial penalty, the parties consented to a settlement of the alleged violations in private.
OSF Healthcare decided to pay a $552,250 settlement. The organization also consented to carry out a corrective action plan under OCR’s monitoring for two years.
The corrective action plan necessitates OSF Healthcare to perform a complete and detailed risk analysis. It also requires the provider to develop and carry out a risk management plan dealing with and mitigating security risks and vulnerabilities discovered through its risk analysis.
OCR Settlement Activity
To date, OCR had collected $2,280,250 from eight HIPAA violation penalties. The settlement with OSF Healthcare is the biggest penalty of the year thus far.
All eight investigations were about risk analysis issues. The case with OSF Healthcare relates to a penalty resolving breach notification failures.
