Can you Afford to Pay a $552,250 Settlement for HIPAA Violations?

by Olivia Wann, JD
Another ransomware enforcement action sends a clear message to health care providers: A HIPAA risk analysis must be accurate, thorough, and capable of identifying the organization’s actual cybersecurity risks.
On July 29, 2026, the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced a settlement with OSF HealthCare System and its affiliated covered entities, marking OCR’s 21st ransomware enforcement action. OSF agreed to pay $552,250 and comply with a corrective action plan that will be monitored by OCR for two years.
The case arose from a 2021 ransomware attack involving the Nephilim ransomware variant. OSF discovered evidence of ransomware on April 23, 2021. During its investigation, OSF determined that threat actors had stolen the protected health information (PHI) of 53,907 individuals.
What Did OCR Find?
OCR’s investigation identified several areas of concern under the HIPAA Privacy, Security, and Breach Notification Rules.
According to the Resolution Agreement, OCR determined that OSF:
- Failed to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to its electronic protected health information (ePHI);
- Impermissibly disclosed the PHI of 53,907 individuals as a result of the stolen data;
- Failed to provide timely notification to affected individuals; and
- Failed to provide timely notification to the HHS Secretary regarding the breach affecting more than 500 individuals.
The settlement itself does not constitute an admission of liability by OSF. The parties entered into the agreement to resolve the OCR investigation.
The Corrective Action Plan Is Particularly Important
For health care organizations, the corrective action plan may be more instructive than the settlement amount.
OSF must conduct an accurate and thorough risk analysis addressing security threats and vulnerabilities involving its ePHI. The analysis must incorporate electronic equipment, data systems, programs, applications, off-site data storage, and other technology that creates, receives, maintains, or transmits ePHI.
OSF must also develop and implement an enterprise-wide risk management plan addressing the risks and vulnerabilities identified through its risk analysis. The plan must include processes and timelines for implementing, evaluating, and revising remediation activities.
The corrective action plan goes beyond simply completing a risk assessment and putting it in a file. OSF is required to conduct annual assessments during the two-year compliance period and report its compliance to OCR.
Workforce Compliance Is Also Under the Microscope
Another significant component of the corrective action plan involves workforce compliance.
If OSF determines that a workforce member failed to comply with its existing Privacy, Security, or Breach Notification policies and procedures, OSF must investigate the matter and, when appropriate, report the event to OCR. The report must describe the event, the policies involved, and the corrective and preventive measures taken—including appropriate sanctions when warranted.
OSF must also submit annual reports to OCR that include an attestation regarding completion of required HIPAA training by its workforce.
What Does This Mean for Dental Practices?
While OSF is a large health care system, the lesson is highly relevant to dental practices of every size.
OCR’s ransomware enforcement actions demonstrate that cybersecurity compliance is not limited to having antivirus software, firewalls, backups, or a written HIPAA policy. A practice must be able to demonstrate that it has identified its actual risks to ePHI and has taken reasonable steps to address those risks.
For a dental practice, that risk analysis should consider the technology and systems actually used by the practice, including:
- Practice management and electronic health record systems;
- Cloud-based software and storage;
- Email systems;
- Patient portals;
- Computers, laptops, and mobile devices;
- Backup systems;
- Dental imaging and radiography systems;
- Remote access;
- Third-party vendors and business associates;
- Cybersecurity protections and vulnerabilities;
- Workforce access to ePHI; and
- Emerging technologies, including artificial intelligence (AI) tools.
A generic HIPAA risk assessment that does not accurately reflect the practice’s current technology, vendors, workflows, and vulnerabilities may not be enough.
The Takeaway
The OSF settlement is another reminder that HIPAA compliance must be an ongoing process—not a binder on a shelf.
A strong HIPAA Security Rule compliance program should include a current and thorough risk analysis, a documented risk management plan, appropriate policies and procedures, workforce training, vendor oversight, incident response procedures, and documentation demonstrating that identified risks are actually being addressed.
OCR’s ransomware enforcement actions continue to reinforce one important point:
If your practice cannot identify its cybersecurity risks, it cannot effectively manage them. And if you cannot demonstrate your compliance efforts, you may have difficulty defending your program when OCR comes knocking.
The complete OSF HealthCare System Resolution Agreement and Corrective Action Plan is available from HHS OCR. Read the OSF Resolution Agreement and Corrective Action Plan
Source: U.S. Department of Health and Human Services, Office for Civil Rights, July 29, 2026.