OSF Healthcare System Agrees to $552,250 HIPAA Settlement Following OCR Investigation

OSF Healthcare System and its affiliated covered entities agreed to pay $552,250 to resolve an investigation by the Office for Civil Rights into alleged violations of the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule.

OSF Healthcare is an integrated health system based in Peoria, Illinois. The organization serves patients at 174 locations across Illinois and Michigan, including 16 hospitals.

On April 23, 2021, OSF Healthcare identified a ransomware attack resulting in the encryption of files on its network. The attacker used a variant of Nephilim ransomware. The attackers demanded payment to prevent a data leak and to obtain the encryption keys needed to unlock the affected files.

A forensic investigation concluded on August 24, 2021, that protected health information (PHI) belonging to 53,907 patients had been exfiltrated from the network. The compromised data included patient names, diagnosis and treatment details, medical record numbers, names of provider, dates of service, prescription information, driver’s license numbers, financial account information, and medical insurance data.

The Office for Civil Rights received notification about the incident on October 1, 2021. Individual notification letters sent to affected patients also began on October 1, 2021.

OCR Investigation Findings

The Office for Civil Rights initiated an investigation because the incident involved the PHI of more than 500 individuals.

The investigation determined that OSF Healthcare had not conducted a comprehensive and accurate risk analysis to identify risks and vulnerabilities affecting the integrity, confidentiality, and availability of PHI. The investigation identified this as a requirement under 45 C.F.R. § 164.308(a)(1)(ii)(A).

The Office for Civil Rights also determined that the PHI of 53,907 patients had been disclosed in a manner that constituted an impermissible disclosure under 45 C.F.R. § 164.502(a).

The investigation also found that OSF Healthcare did not provide timely notification to affected individuals and did not provide timely notification to the Secretary of the U.S. Department of Health and Human Services. The findings identified alleged violations of 45 C.F.R. § 164.404(b) and 45 C.F.R. § 164.408(b).

The Office for Civil Rights determined that the alleged violations warranted a financial penalty. After the agency informed OSF Healthcare of its findings and its intention to impose a penalty, the matter was resolved through a settlement.

Settlement Terms

Under the settlement, OSF Healthcare agreed to pay $552,250. The organization also agreed to implement a corrective action plan. Compliance with that plan will be monitored for two years.

The corrective action plan requires OSF Healthcare to conduct an accurate and thorough risk analysis. The organization must also create and enforce a risk management plan to address the security issues and vulnerabilities found through that analysis.

OCR Director Paula M. Stannard stated that performing a HIPAA risk analysis is a legal requirement and serves a role in protecting health information, reducing the impact of ransomware attacks. She also stated that regulated entities that do not identify threats and vulnerabilities affecting electronic protected health information (ePHI) may discover those weaknesses only after a successful cyberattack.

The Office for Civil Rights has resolved eight HIPAA investigations through settlements during the current year and collected $2,280,250 in penalties. The OSF Healthcare settlement represents the largest financial penalty among those settlements during the year to date.

Image credit: 2100209798 – Reni, AdobeStock / logo©OSFHealthcare

Twitter Facebook LinkedIn Reddit Copy link Link copied to clipboard
Photo of author

Posted by

John Blacksmith

John Blacksmith is a journalist with several years experience in both print and online publications. John has specialised in Information technology in the healthcare sector and in particular in healthcare data security and privacy. His focus on healthcare data means he has specialist knowledge of the HIPAA regulations. John has a degree in journalism and many years experience.
Twitter
LinkedIn