Cyber Incident Victim: OSF HealthCare
Timeline
Summary
OSF Healthcare discovered a ransomware attack on its systems, initiated a forensic investigation, and after the investigation concluded determined that protected health information of over fifty thousand individuals had been exfiltrated. The organization delayed notifying the Department of Health and Human Services and affected individuals until after the investigation finished, resulting in a notification delay that exceeded the sixty‑day requirement under the HIPAA Breach Notification Rule, prompting an Office for Civil Rights investigation and a settlement payment of five hundred fifty‑two thousand two hundred fifty dollars along with a corrective action plan.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On April 23, 2021, OSF Healthcare System discovered that the Nephilim ransomware variant had infiltrated its networks, prompting an immediate internal forensic investigation. The investigation continued for four months, concluding on August 24, 2021, when investigators determined that the protected health information of 53,907 individuals had been exfiltrated. Despite having discovered the breach on April 23, OSF Healthcare did not notify the U.S. Department of Health and Human Services or the affected individuals until October 1, 2021, resulting in a 110‑day delay from the initial discovery. This delay exceeded the 60‑calendar‑day notification deadline mandated by the HIPAA Breach Notification Rule.

The Office for Civil Rights determined that OSF Healthcare violated two core provisions of the HIPAA Breach Notification Rule by failing to notify affected individuals and HHS within 60 days of discovering the breach. The settlement reached with OCR required OSF Healthcare to pay a civil monetary penalty of $552,250. As part of the resolution agreement, the health system agreed to implement a corrective action plan that includes revising its breach notification policies and providing workforce training on HIPAA requirements. OCR will monitor OSF Healthcare’s compliance with the corrective action plan for a period of two years.
The OSF Healthcare case represents OCR’s 21st enforcement action related to ransomware incidents, underscoring the agency’s focus on timely breach notifications. On July 29, OCR announced the resolution agreement and corrective action plan with OSF Healthcare, emphasizing that the 60‑day notification clock starts on the day a breach is discovered, not after forensic investigations conclude. OCR’s statement reinforced that delayed notification, even during an active investigation, constitutes a compliance failure under HIPAA.
