The U.S. Department of Health and Human Services' Office for Civil Rights settled a HIPAA investigation with OSF Healthcare System on July 1, 2026, over a 2021 ransomware attack that exposed the protected health information of 53,907 patients. OSF, a Peoria, Illinois-based health system with providers in Illinois and Michigan, agreed to pay $552,250 and complete a two-year, OCR-monitored corrective action plan.
The resolution agreement, published on HHS.gov, resolves OCR Transaction Number 22-445707. It is not an admission of liability by OSF, and the agreement says so directly. What it does show, in granular detail because the underlying document is a signed legal agreement rather than a press summary, is exactly which HIPAA obligations OCR treats as non-negotiable after a ransomware incident, and how long a health system stays under federal supervision once it settles one.

Source: HHS.gov, OSF Healthcare System Resolution Agreement and Corrective Action Plan, captured August 4, 2026.
What happened, in the agreement's own timeline
OSF discovered the breach on April 23, 2021, when it found files on its network encrypted by the "Nephilim" variant of ransomware, along with a ransom note. The investigation that followed took several months: OSF determined on August 24, 2021 that the attackers had actually stolen patient data, not just encrypted it in place. OSF notified both the affected patients and HHS on October 1, 2021, more than five months after discovering the breach.
That gap between discovery and notification became one of the four violations OCR cited. Under the agreement, OCR's investigation found that OSF:
- Failed to conduct an accurate and thorough risk analysis of the risks and vulnerabilities to its electronic protected health information, a violation of 45 C.F.R. § 164.308(a)(1)(ii)(A).
- Impermissibly disclosed the PHI of 53,907 individuals as a result of the ransomware attack, a violation of 45 C.F.R. § 164.502(a).
- Failed to provide timely breach notification to the affected individuals, a violation of 45 C.F.R. § 164.404(b).
- Failed to provide timely breach notification to the HHS Secretary, a violation of 45 C.F.R. § 164.408(b).
Figure: The settlement OSF agreed to pay HHS following the 2021 ransomware breach.
The violation that shows up in almost every ransomware settlement
The first item on that list, a missing or inadequate risk analysis, is not unique to OSF. It is the finding OCR reaches for most consistently across ransomware-related HIPAA settlements, because a risk analysis under the Security Rule is the foundational safeguard every other technical control is supposed to be built on. If a covered entity cannot show it identified where its electronic PHI lives and what threatens it, OCR treats that as the root cause that let a specific attack succeed, whatever the attack vector turns out to be.
That is why the corrective action plan spends more space on the risk analysis requirement than on anything else. OSF has to submit its proposed scope and methodology for a new risk analysis within 60 days of the agreement taking effect, then submit the completed risk analysis within 90 days of OCR approving that methodology. OCR reviews it, can require revisions, and the back-and-forth continues until OCR gives final approval. OSF then has to repeat the whole process a second time before the two-year compliance term ends, for two full risk analyses submitted to a federal regulator for sign-off.
What OSF's payment amount and plan terms break down to
| Term | Detail |
|---|---|
| Resolution amount | $552,250, due in one lump sum by July 15, 2026 |
| Corrective action plan length | Two years from the agreement's effective date |
| Risk analyses required | Two, each reviewed and approved by OCR before it counts |
| Risk management plan | Submitted within 90 days of OCR's risk analysis approval |
| Reportable events | Any workforce non-compliance with HIPAA policy must be investigated and reported to OCR |
| Annual reports | One per year of the compliance term, with signed workforce-training attestations |
| Document retention | Six years from the agreement's effective date |
None of these terms are unusual by themselves. What stands out is how procedural the whole plan is. OSF is not just promising to do better; it is handing OCR ongoing approval authority over its risk analysis methodology, its risk management plan, and its incident-reporting process for two straight years, with a civil monetary penalty sitting behind any breach of the plan that OSF cannot cure within 30 days of being notified.
What this means if you run a healthcare-adjacent site
Most small and mid-sized businesses that touch health data are not hospital systems, but plenty of them are HIPAA-covered entities or business associates all the same: telehealth platforms, medical billing services, health and wellness apps that integrate with provider systems, and clinics running their own patient portals. The OSF settlement is a useful reminder that a privacy policy's data breach and security language cannot lean on vague reassurance. A generic line promising "reasonable security measures" does not describe what a risk analysis actually is, and it gives a patient no sense of what happens if a breach occurs anyway.
A privacy policy for a HIPAA-covered or HIPAA-adjacent business needs to say plainly what protected health information is collected, how it is secured, and what the breach notification process looks like if something goes wrong, including realistic timelines. OCR's own findings here show that notification delay, not just the breach itself, becomes a separate violation with its own citation. Our Privacy Policy Generator can build breach notification and security language that reflects an actual incident response process, instead of a boilerplate clause that would not survive the kind of scrutiny OSF's did.
Bottom line
A $552,250 payment is a modest number next to some recent HIPAA settlements, but the two-year corrective action plan is the part worth paying attention to. OCR did not just fine OSF and move on; it took direct, ongoing approval authority over how OSF analyzes and manages its security risk, twice over, for the next two years. That is the shape federal HIPAA enforcement is taking after a ransomware breach in 2026: less about the size of the check, more about proving, on a schedule, that the underlying risk analysis gets fixed.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.