OCR Reaches $552,250 HIPAA Settlement With OSF Healthcare

by

OSF Healthcare System and its Affiliated Covered Entities have decided to pay $552,250 to settle alleged HIPAA violations following a ransomware attack that impacted the protected health information (PHI) of 53,907 patients.

Peoria, Illinois-based integrated health system, OSF Healthcare, serves patients at 174 locations (with 16 hospitals) in Illinois and Michigan.

On April 23, 2021, OSF Healthcare found out that files on its network were encrypted by ransomware. The threat group used a Nephilim ransomware variant and demanded payment to stop data exposure and get the files decryption keys.

Accredited HIPAA Certification

A forensic investigation established on August 24, 2021, that PHI of 53,907 patients had been extracted from the network. The data included names, driver’s license numbers, medical record numbers, diagnosis and treatment details, prescription details, provider names, dates of services, financial account details, and medical insurance information.

OSF Healthcare advised OCR concerning the attack on October 1, 2021. Individual notification letters were issued on that date.

OCR Investigation Findings

OCR started an investigation to check OSF Healthcare’s compliance with the HIPAA Rules right after the breach.

OCR confirmed that OSF Healthcare failed to conduct a complete and accurate risk analysis to determine risks and vulnerabilities impacting the confidentiality, integrity, and availability of patients’ PHI, in violation of 45 C.F.R. § 164.308(a)(l)(ii)(A).

OCR also confirmed that OSF Healthcare had impermissibly disclosed 53,907 patients’ PHI, in violation of 45 C.F.R. § 164.502(a).

The investigation also found that OSF Healthcare did not issue timely breach notifications to impacted individuals and to the Secretary of the HHS, in violation of 45 C.F.R. § 164.404(b) and § 164.408(b).

Settlement Terms

OCR decided that the claimed HIPAA violations called for a financial penalty. After OCR informed OSF Healthcare System of the investigation findings and its intent to enforce a financial penalty, the parties consented to a settlement of the alleged violations in private.

OSF Healthcare decided to pay a $552,250 settlement. The organization also consented to carry out a corrective action plan under OCR’s monitoring for two years.

The corrective action plan necessitates OSF Healthcare to perform a complete and detailed risk analysis. It also requires the provider to develop and carry out a risk management plan dealing with and mitigating security risks and vulnerabilities discovered through its risk analysis.

OCR Settlement Activity

To date, OCR had collected $2,280,250 from eight HIPAA violation penalties. The settlement with OSF Healthcare is the biggest penalty of the year thus far.

All eight investigations were about risk analysis issues. The case with OSF Healthcare relates to a penalty resolving breach notification failures.

James Keogh

James Keogh has been writing about the healthcare sector in the United States for several years and is currently the editor of HIPAAnswers. He has a particular interest in HIPAA and the intersection of healthcare privacy and information technology. He has developed specialized knowledge in HIPAA-related issues, including compliance, patient privacy, and data breaches. You can follow James on Twitter https://x.com/JamesKeoghHIPAA and contact James on LinkedIn https://www.linkedin.com/in/james-keogh-89023681 or email directly at jameskeogh@hipaanswers.com