HHS fines OSF HealthCare $552K over ransomware breach

Advertisement

The U.S. Department of Health and Human Services’ Office for Civil Rights (OCR) has settled a HIPAA investigation with Peoria, Ill.-based OSF HealthCare over a 2021 ransomware attack that exposed the protected health information of 53,907 patients.

OSF discovered in April 2021 that its files had been infected with the “Nephilim” ransomware variant and filed a breach report with HHS in October 2021. The exposed data included driver’s license numbers, diagnosis and treatment information, prescription details, medical record numbers, provider names, dates of service, financial account information and health insurance information.

OCR’s investigation found OSF potentially violated the HIPAA Privacy, Security and Breach Notification Rules by failing to conduct an accurate and thorough risk analysis of its electronic protected health information, impermissibly disclosing the PHI of 53,907 individuals, and failing to provide timely breach notification to both affected individuals and the HHS secretary.

Under the resolution agreement, OSF will pay $552,250 to OCR and complete a two-year, OCR-monitored corrective action plan requiring an updated risk analysis and a risk management plan to address identified vulnerabilities, according to a July 29 news release from HHS.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement