Four settlements in one announcement is a busy day for the HHS Office for Civil Rights. On April 23, 2026 OCR announced resolution agreements with Regional Women's Health Group, doing business as Axia Women's Health ($320,000), Assured Imaging Affiliated Covered Entities ($375,000), Consociate, Inc., doing business as Consociate Health ($225,000) and the Star Group, L.P. Health Benefits Plan ($245,000). All four followed ransomware attacks. Together the incidents affected more than 427,000 people. All four cite the same core failure: the organization had not conducted an accurate and thorough risk analysis of the risks to electronic protected health information, as the Security Rule has required since 2005.
This is not new. OCR announced a Risk Analysis Initiative in late 2024 and has been settling ransomware cases under it steadily since; with these four, it has now closed 19 ransomware investigations and 13 under the initiative. What is worth noticing is the size of the organizations. These are not national health systems. A women's health group, an imaging company, a benefits administrator and a self-funded employer plan. OCR is reaching the middle of the market, and independent practices are the next tier down.
Key takeaways
- Four settlements, $1,165,000, four ransomware attacks, one shared finding: no accurate and thorough risk analysis.
- Each settlement carries a two-year corrective action plan with OCR monitoring, which costs more in staff time than the payment.
- April's breach reports were fewer (47) but led by physician groups, a dermatology practice and an eye clinic, not health systems.
- A practice-sized risk analysis takes about two days a year and is the difference between technical assistance and a resolution agreement.
- MFA on email and remote access, tested backups, and a BAA with every vendor are the controls named in almost every settlement.
The four cases
| Entity | What it is | Individuals affected | Settlement |
|---|---|---|---|
| Regional Women's Health Group (Axia Women's Health) | Multi-site women's health group | About 38,000 | $320,000 |
| Assured Imaging Affiliated Covered Entities | Mobile and outpatient imaging | 244,813 | $375,000 |
| Consociate, Inc. (Consociate Health) | Third-party benefits administrator | More than 135,000 | $225,000 |
| Star Group, L.P. Health Benefits Plan | Self-funded employer health plan | 9,316 | $245,000 |
Two details are worth reading in the agreements themselves. The Assured Imaging case also cites late breach notification, a reminder that the 60-day clock starts at discovery, not at the end of the forensic investigation. And the Star Group plan, with about 9,300 members, paid nearly as much as organizations with twenty times the exposure. OCR does not size the settlement to the head count. It sizes it to the failures it finds, and a missing risk analysis is a failure regardless of how small the entity is.
April 2026 by the numbers
The HIPAA Journal's report on April, compiled from the OCR breach portal, counts 47 breaches of 500 or more records reported during the month, affecting 1,336,264 people. That is a 33.8 percent drop in breach count from March, which had 71, and well below the twelve-month average of about 62 a month. Hacking and IT incidents accounted for 36 of the 47 reports (76.6 percent) and for 92.8 percent of the people affected. Thirty-six reports came from providers, eight from health plans and three from business associates. Through April 30, 252 large breaches had been reported in 2026, compared with 276 for the same period in 2025 and 299 in 2024.
The five largest were Florida Physician Specialists (276,498 individuals, hacking with confirmed data theft), Southern Illinois Dermatology (160,312), Laurel Eye Clinic (145,221), Innovative Scientific Solutions (143,842) and Hospital Caribbean Medical Center in Puerto Rico (92,000, a ransomware attack with data theft).
Look at that list again. A physician group, a dermatology practice, an eye clinic. Practices with a few dozen providers, not health systems. The pattern of 2026 so far is that attackers have moved down-market because the large targets have hardened and the small ones have not.
What "risk analysis" actually means
The Security Rule requires a covered entity to identify where ePHI is created, received, maintained and transmitted, identify threats and vulnerabilities to it, assess current controls, rate the likelihood and impact of each risk, and document the whole thing. Then it requires a risk management plan that addresses the findings. OCR's settlements repeatedly find one of three things: no risk analysis at all, a risk analysis from years ago that was never updated, or a document that lists policies without ever inventorying systems.
A risk analysis is not a checklist saying you have a firewall. It is a document that says: here are the 14 systems that hold our ePHI (EHR, practice management, clearinghouse portal, email, the imaging server, the fax server, the scanner's hard drive, three laptops, the phone system's voicemail, the billing vendor's portal, the patient portal, the backup drive), here is who can reach each one and how, here is what could go wrong, and here is what we are doing about it, in order of priority.
The word "enterprise-wide" appears in these agreements for a reason. A risk analysis that covers the EHR and stops is the most common partial effort we see. The scanner with a hard drive, the old laptop the locum used, the text messages between the on-call physician and the front desk: those are in scope, and the settlements say so.
A practice-sized approach
| Step | Output | Time for a 5-provider practice |
|---|---|---|
| Inventory every system and device that touches ePHI | A spreadsheet with owner, location, access method, vendor | Half a day |
| Map data flows in and out (referrals, claims, remittances, lab interfaces, patient messages) | A one-page diagram | Two hours |
| Rate each system for likelihood and impact of compromise | A high, medium, low rating with a sentence of reasoning | Half a day |
| List controls in place and gaps (MFA, backups tested, patching, access reviews, encryption at rest) | The gap list, prioritized | Half a day |
| Write the risk management plan with owners and dates | A dated plan, reviewed by the practice owner | Two hours |
Two days of work, once a year, with an update whenever you add a system. It will not make you unbreachable. It will make the difference between a breach that OCR closes with technical assistance and one that ends in a resolution agreement and a two-year corrective action plan. The plan is the expensive part: two years of policy revisions, training records, annual risk analyses submitted to OCR for review, and a compliance officer's time that a five-provider practice does not have.
The controls that show up in every settlement
Read the resolution agreements from the past 18 months and the same items recur. Multi-factor authentication on email and remote access. Backups that are offline or immutable and have actually been restored in a test. Patching on a schedule with a record. Termination of access the day a staff member leaves. Encryption of laptops. Logging that someone reviews. A business associate agreement with every vendor that touches ePHI, including the billing company, the transcription or AI scribe vendor, the IT provider and the shredding service.
None of these are expensive for a practice. MFA on Microsoft 365 or Google Workspace is a setting. Immutable backups are a subscription. The expensive part is the ransomware event that happens because none of them were turned on.
Where the billing office fits
Billing staff have broad access: the practice management system, the clearinghouse, payer portals with thousands of member records, the bank's lockbox. Phishing aimed at billing staff is common because the credentials are valuable. Two habits help. First, payer portal credentials should be individual, never shared, and should be removed when someone leaves. Second, any request to change a bank account for deposits or a vendor's payment details gets a phone call to a known number before anyone acts on it. We have seen practices lose remittances to a spoofed email that said the clearinghouse had changed its EFT details.
If your billing vendor holds your data, ask them two questions: when was your last risk analysis, and can we see your SOC 2 report? Revelrex is HIPAA compliant and SOC 2 compliant and will answer both questions for any practice we work with, including through our medical billing engagements.
Questions we hear
We have a security questionnaire from our EHR vendor. Does that count as a risk analysis?
No. A vendor's questionnaire covers the vendor's product. Your risk analysis covers your practice: every system, every device, every person with access. The vendor's SOC 2 report and BAA are inputs to your analysis, not substitutes for it.
We are a two-physician practice. Would OCR really investigate us?
OCR opens an investigation for every breach of 500 or more records and reviews smaller ones too. The Star Group plan in this batch had about 9,300 members. Size does not exempt you; it just means the corrective action plan hurts more.
Should we hire someone to do the risk analysis?
You can, and for a practice with no IT staff it is often sensible. But the inventory and the data flow map should be built by the people who work in the practice, because they know where the ePHI actually goes. An outside assessor who never asks about the scanner or the personal phones produces the kind of document these settlements describe as inadequate.
What to do this month
- Find your risk analysis. If it does not exist or is older than a year, schedule the two days above before the end of June.
- Turn on MFA for every email account and every remote access path. Today.
- Restore one file from backup and record that you did it and how long it took.
- List every vendor with access to ePHI and confirm a signed BAA exists for each.
- Remove portal and system access for anyone who left in the past year and was missed.
- Read one of the April resolution agreements on the OCR website with your practice manager. Twenty minutes, and it lands differently than any training slide.
This is operational guidance, not legal advice. If you have had an incident, involve counsel and your cyber insurer before you do anything else.
