Enforcement

What OCR actually cited in its newest ransomware settlement

Published August 11, 2026

On July 29, 2026, HHS posted a resolution agreement with a large Illinois health system that closes a ransomware investigation five years in the making. The headline number is $552,250. The more useful detail is the order of what OCR cited — because the first item on the list is a requirement that applies to a one-person practice in exactly the same words.

The facts

Who:
OSF Healthcare System and its affiliated covered entities (Peoria, Illinois)
Posted:
July 29, 2026 (agreement signed by OSF July 1, 2026)
What it is:
A settlement — a resolution agreement with a $552,250 resolution amount, plus a corrective action plan. Not a civil money penalty, and expressly not an admission of liability.
The breach:
The “Nephilim” ransomware variant, found on OSF systems April 23, 2021. OSF determined on August 24, 2021 that attackers had taken the protected health information of 53,907 patients, and notified patients and HHS on October 1, 2021.
Source:
The resolution agreement on hhs.gov (OCR transaction 22-445707)

What OCR cited, in its order

The agreement lists four items of covered conduct. They are worth reading in sequence, because the sequence is the story:

  1. The risk analysis. OSF “failed to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities” to the electronic patient information it held — 45 CFR 164.308(a)(1)(ii)(A).
  2. The disclosure itself. The stolen data was an impermissible disclosure of 53,907 people’s information — 45 CFR 164.502(a).
  3. Late notice to the people affected 45 CFR 164.404(b).
  4. Late notice to HHS, required when a breach reaches 500 or more people — 45 CFR 164.408(b).

The ransomware attack is item two. Item one is a piece of paperwork that was supposed to exist before anything went wrong. That ordering is not an accident — it is the signature of OCR’s Risk Analysis Initiative, which has been citing that same subsection since it launched in late 2024.

Be clear about the size difference

OSF is not a comparable organization to a small practice, and pretending otherwise would be dishonest. It runs 16 hospitals and roughly 27,000 staff across Illinois and Michigan. A settlement figure scaled to that, arising from four findings and a breach affecting nearly 54,000 people, tells you nothing about what a solo practice would face. For scale in the other direction: OCR has settled ransomware investigations in this same period for as little as $10,000.

So do not read this as a number hanging over your office. Read it for the citation. The dollar amount scales with the organization; the regulation does not. Section 164.308(a)(1)(ii)(A) has no size threshold, no employee count, and no carve-out for small practices — it is the same sentence for a 27,000-person system and a therapist working alone.

The five-year tail

The ransomware was found in April 2021. The agreement was signed in July 2026. That gap is the part most worth absorbing: an investigation asks what your safeguards looked like at the time of the incident, and it may ask years afterwards. Documentation is not something that can be produced retroactively when the question arrives — by then, the only honest answer is whatever you actually wrote down at the time.

Two of the four findings here are about timing rather than security: notice to patients and notice to HHS both came later than the rules allow. Those clocks run on the same terms whatever the size of the practice, and they start running during the worst week you will ever have — which is exactly why the plan for them gets written beforehand.

The one takeaway

If you run a small practice, the transferable lesson from this settlement is narrow and specific: the first thing cited was the missing risk analysis, and that requirement already applies to you under the Security Rule in force today — not under any proposed update still working its way through rulemaking. A documented, dated security risk assessment is where a defensible answer starts. It is not a guarantee, it does not settle the question on its own, and no honest product will tell you it does. It is simply the first thing an investigation asks for, and the one thing that cannot be created after the fact.

Start HIPAAPath free

Free — no account needed to start, and your answers never leave your browser. Not legal advice: for questions about your specific obligations, talk to a healthcare attorney.

Can you help us make this better?

How easy is HIPAAPath to use so far?
HardEasy

Please don’t include patient information — this goes to us by email.