Illinois-headquartered healthcare system settles potential HIPAA violations after data breach
Key Highlights
- OSF Healthcare experienced a ransomware attack that compromised the PHI of nearly 54,000 patients, prompting an OCR investigation.
- The investigation revealed potential violations including failure to perform a thorough risk analysis and delayed breach notifications to affected individuals and HHS.
- OSF paid a settlement of $552,250 and committed to a corrective action plan to address HIPAA compliance issues and improve data security measures.

