Back to the register

OSF HealthCare System

ArchivedSubmitted 10/01/2021
State
IL
Covered entity type
Healthcare Provider
Individuals affected
53,907
Business associate present
No
Type of breach
Hacking/IT Incident
Location of breached information
Network Server
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) today announced a settlement with OSF Healthcare System and its Affiliated Covered Entities (OSF), concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules. OSF is headquartered in Illinois and has providers located in Illinois and Michigan. OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules , which set forth the requirements that covered entities (health plans, health care clearinghouses, and most health care providers), and business associates must follow to protect the privacy and security of PHI. The settlement resolves an investigation that OCR initiated after OSF filed a breach report in October 2021. In April of 2021, OSF discovered that its files had been infected with the “Nephilim” variant of ransomware. The PHI of 53,907 individuals was exfiltrated by the threat actor. Affected PHI included driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and health insurance information. OCR found that OSF had potentially violated provisions of the Privacy, Security and Breach Notification Rules, including: · Failing to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the ePHI held by OSF; · Impermissibly disclosing the PHI of 53,907 individuals; · Failing to provide timely breach notification to affected individuals; and · Failing to provide timely breach notification to the Secretary of HHS. Under the terms of the resolution agreement, OSF agreed to implement a corrective action plan that OCR will monitor for two years and paid $552,250 to OCR. Under the corrective action plan, OSF has committed to taking steps to ensure compliance with the HIPAA Rules and protect the security of ePHI, including: · Conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI; and · Develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis. The resolution agreement and corrective action plan may be found here. OCR recommends that regulated entities, including health care providers, health plans, health care clearinghouses, and business associates take the following steps to mitigate or prevent cyber-threats: · Identify where ePHI is located in the organization, including how ePHI enters, flows through, and leaves the organization’s information systems. · Periodically conduct, and update as needed, a risk analysis and develop and implement a risk management plan to address identified risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. · Ensure audit controls are in place to record and examine information system activity. · Implement regular review of information system activity. · Utilize mechanisms to authenticate information to ensure only authorized users are accessing ePHI. · Encrypt ePHI in transit and at rest to guard against unauthorized access to ePHI when appropriate. · Incorporate lessons learned from incidents into the organization’s overall security management process. · Provide workforce members with regular HIPAA training that is specific to the organization and to the workforce members’ respective job duties.

Change history

  • 9/23/2026Added to OCR's archive list

Source: U.S. Department of Health and Human Services, Office for Civil Rights, Breach Portal. Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.