On Wednesday, July 29, 2026, the HHS Office for Civil Rights announced a $552,250 settlement with OSF Healthcare System and its affiliated covered entities, a health system headquartered in Illinois with providers in Illinois and Michigan. The case is, among other things, a lesson in HIPAA breach notification deadlines. It began in April 2021, when OSF discovered that its files had been infected with the Nephilim variant of ransomware. OCR's investigation concluded that the protected health information of 53,907 individuals had been impermissibly disclosed, that OSF had not conducted an accurate and thorough risk analysis, and that it had failed to notify affected individuals and the HHS Secretary within the time the Breach Notification Rule requires.

We have written before about OCR's ransomware settlements and the risk analysis finding that appears in nearly all of them. It appears here too. What makes this one worth its own article for a small practice is the second finding: the notifications were late. HIPAA breach notification deadlines are fixed, they start running from a date many practices misidentify, and they are the part of a breach response that a two-physician office is most likely to get wrong in the confusion after an attack. The other thing worth noticing is the calendar. The attack was in April 2021. The settlement is July 2026. OCR's investigations take years, and the documentation you create in the first sixty days is what you will be judged on five years later.

This article lays out what happened, the deadlines, what the corrective action plan requires, and what we would check in an independent practice this week. It is operational guidance, not legal advice; a breach is a situation for counsel.

Key takeaways

  • OCR announced the OSF Healthcare settlement on July 29, 2026: $552,250, a two-year corrective action plan under OCR monitoring, and findings of no compliant risk analysis, impermissible disclosure of 53,907 individuals' PHI, and late notification to individuals and to HHS.
  • The Breach Notification Rule requires notice to affected individuals without unreasonable delay and no later than 60 calendar days after discovery, notice to HHS within 60 days for breaches affecting 500 or more people (and to prominent media in the affected state), and an annual log submission for smaller breaches within 60 days after the end of the calendar year.
  • Discovery is the day the breach is known, or by exercising reasonable diligence would have been known, to anyone in the organization other than the person who caused it; the clock does not wait for the forensic report.
  • Every ransomware incident involving unsecured PHI is presumed to be a breach unless the practice documents a low probability of compromise through a four-factor risk assessment.

What happened and when

A glossary line first. OCR, the Office for Civil Rights, is the HHS agency that enforces the HIPAA Privacy, Security and Breach Notification Rules. A resolution agreement is a settlement in which the covered entity pays an amount and agrees to a corrective action plan without admitting liability. The Security Rule requires a risk analysis: a documented, organization-wide assessment of the risks and vulnerabilities to electronic PHI, which is the foundation for every other safeguard.

DateEvent
April 2021OSF discovers files infected with Nephilim ransomware
2021 to 2026OCR investigation, including review of OSF's risk analysis and breach notification records
July 29, 2026OCR announces the resolution agreement: $552,250 and a two-year corrective action plan
2026 to 2028OSF completes an enterprise-wide risk analysis, builds a risk management plan, and reports to OCR under monitoring

OCR's findings, as described in the announcement, were four: OSF failed to conduct an accurate and thorough risk analysis of the risks to its electronic PHI; the ransomware attack resulted in the impermissible disclosure of the PHI of 53,907 individuals; OSF failed to provide timely breach notification to those individuals; and OSF failed to notify the HHS Secretary within the required window. The OCR director's statement emphasized that a thorough risk analysis is both a legal requirement and a practical defense against ransomware.

The corrective action plan follows the pattern of OCR's recent ransomware cases: complete a compliant risk analysis, build and implement a risk management plan addressing the findings, and submit both to OCR for review, with the plan running two years under monitoring. For a health system that is a significant project. For a small practice, the same two documents are the core of a compliance program, and they are what OCR asks for first.

HIPAA breach notification deadlines, precisely

The Breach Notification Rule sets three deadlines, and all of them count from discovery. Individual notice must be sent by first-class mail (or email if the individual agreed) without unreasonable delay and in no case later than 60 calendar days after discovery. If the breach affects 500 or more individuals, notice to the HHS Secretary through the OCR breach portal is due at the same time, within 60 days, and notice to prominent media outlets serving the state or jurisdiction is due within 60 days if 500 or more residents of that state are affected. If the breach affects fewer than 500 individuals, the practice logs it and submits the log to HHS within 60 days after the end of the calendar year in which it was discovered; individual notice is still due within 60 days of discovery.

Sixty days is the outer limit, not the target. OCR has said in guidance and in enforcement that waiting until day 59 without reason is itself an unreasonable delay. The common mistake is treating the forensic investigation as the clock: "we could not notify until we knew who was affected." The rule allows the practice to send notice with the information it has and supplement later, and it allows a law enforcement delay only when a law enforcement official states in writing that notice would impede an investigation.

Discovery is the other trap. A breach is treated as discovered on the first day it is known to the covered entity, or by exercising reasonable diligence would have been known, to any workforce member or agent other than the person who committed it. The day the front desk noticed the files were encrypted is the day the clock started, not the day the IT vendor confirmed data was taken. Business associates have their own duty to notify the covered entity, and the agreement should set that deadline in days.

Ransomware is presumed to be a breach

OCR's ransomware guidance, in place since 2016, states that when ransomware encrypts electronic PHI, a breach is presumed to have occurred because the PHI was acquired by an unauthorized party, unless the covered entity can demonstrate a low probability that the PHI was compromised. That demonstration is the four-factor risk assessment: the nature and extent of the PHI involved, the unauthorized person who used or received it, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated. The assessment has to be documented at the time. A practice that decides "it was just encrypted, nothing was taken" without a written assessment has made the OSF mistake in miniature.

In our experience the decision not to notify is the one that ages worst. If the forensics later show exfiltration, the practice has both a late notification and a documented decision to withhold it. When in doubt, notify, and write down why.

What this means for a small practice

You are smaller than OSF and less likely to be investigated, but the rules are identical and OCR's settlements in the last two years have included small providers as well as systems. Three things follow from this case. First, the risk analysis has to exist, be current, cover every system that holds PHI including the billing system and the clearinghouse connection, and be a document you can hand over. Second, the breach response plan has to name who declares a breach, who does the four-factor assessment, who counts affected individuals, who drafts notices and who files with HHS, with the 60-day clock written on the first page. Third, the vendor agreements have to give you the vendor's incident notice fast enough to meet your own deadlines; a clause that says "promptly" is not a deadline.

We also think practices should run a tabletop exercise once a year: pick a Tuesday, pretend the practice management system is encrypted, and walk through the first 72 hours with the actual people who would do the work. It takes an hour, and it exposes the missing phone numbers, the unknown backup restore time and the "who calls the patients" question before they matter. Practices whose billing runs through us as a medical billing client should include our contact in that exercise, because claims and remits are part of the data at risk, and an RCM audit can be scoped to include the vendor and data-flow inventory the risk analysis depends on.

Questions we hear

Our IT vendor handles security. Doesn't the risk analysis belong to them?

No. The Security Rule places the obligation on the covered entity. Your IT vendor can perform the technical assessment and should, but the practice owns the document, has to understand it, and has to act on the findings. OCR fines practices, not their IT vendors, for missing risk analyses.

If we restore from backup within a day and the attackers never got in to the data, do we have to notify?

You have to do and document the four-factor assessment. If it supports a low probability of compromise, for example because forensic evidence shows encryption without exfiltration and the affected data was itself encrypted at rest with keys the attacker did not obtain, you may conclude there was no breach. Document it thoroughly and have counsel review; five years later, that document is your defense.

Does cyber insurance change any of this?

It pays for some of it and it usually brings a breach coach and forensic firm, both useful. It does not extend any deadline, and some policies require notice to the carrier within days to preserve coverage, which is one more clock to put in the response plan.

What to do this week

  1. Locate your most recent security risk analysis; if it is more than a year old, does not cover the billing system and clearinghouse, or does not exist, schedule it now.
  2. Open your breach response plan and confirm it names an owner for each step, states the 60-day deadlines and the definition of discovery, and includes the four-factor assessment template.
  3. Check your business associate agreements for a vendor incident notice deadline stated in days, and ask the vendors without one to amend.
  4. Schedule a one-hour tabletop exercise for the practice's ransomware scenario before the end of the third quarter.
  5. Confirm who at the practice has the login for the OCR breach portal and where the cyber insurance notice requirements are written down.