Skip to content

HHS OCR Settles Four HIPAA Security Rule Ransomware Investigations

On April 23, 2026, the US Department of Health and Human Services (HHS), Office for Civil Rights (OCR) announced settlements with four regulated entities following separate ransomware investigations under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. The resolutions bring the total to 19 completed ransomware-related investigations and 13 completed investigations under OCR’s Risk Analysis Initiative.

The settlements involve ransomware breaches that collectively affected over 427,000 individuals and resulted in exposure of unsecured electronic protected health information (ePHI), including demographic data, Social Security numbers (SSNs), financial information, lab results, medications, and diagnoses or conditions. Under the agreements, the entities will implement corrective action plans subject to OCR monitoring for two years and pay a combined total of $1,165,000.

The settlements include the following regulated entities:

  • A network of women’s healthcare providers operating across New Jersey, Pennsylvania, Ohio, Indiana, and Kentucky. The breach affected 37,989 individuals and involved names, addresses, dates of birth, SSNs, driver’s license numbers, diagnoses, lab results, and medications. The provider reported in December 2020 that an unauthorized third party accessed its network and potentially exfiltrated data from its electronic medical records system. OCR found the provider failed to conduct an accurate and thorough risk analysis. The provider paid $320,000.
  • A medical imaging and screening provider with headquarters in Arizona and California. The breach affected 244,813 individuals and involved patient demographic and clinical data, including diagnoses, lab results, medications, and treatment information. The provider reported a ransomware infection in May 2020. OCR determined it impermissibly disclosed protected health information (PHI), failed to conduct a thorough risk analysis, and did not timely notify affected individuals. The provider paid $375,000.
  • A third-party administrator of employee-sponsored benefit programs serving HIPAA-covered entities. The breach affected 136,539 individuals and involved names, addresses, dates of birth, SSNs, financial account information, and health-related data. Following a phishing attack in July 2020, a threat actor gained access to systems later encrypted in a ransomware attack. OCR found the administrator failed to conduct an accurate and thorough risk analysis. The administrator paid $225,000.
  • A self-funded employee benefits plan of a Connecticut-based energy provider. The breach affected 9,316 individuals and involved names, addresses, dates of birth, SSNs, and health plan information including claims and benefit data. OCR determined the plan impermissibly disclosed PHI and failed to conduct a proper risk analysis after a ransomware attack and data exfiltration. The plan paid $245,000.

Compliance Perspective

Issue

Healthcare organizations face ongoing cybersecurity and compliance risks due to the volume and sensitivity of PHI stored and transmitted electronically. Threats such as ransomware, phishing, and unauthorized access continue to expose vulnerabilities in administrative, technical, and physical safeguards, often linked to gaps in risk identification, inconsistent application of policies and procedures, or insufficient ongoing oversight. Under the HIPAA Security Rule, covered entities and business associates are required to implement measures to protect the confidentiality, integrity, and availability of ePHI, including the completion of an accurate and thorough risk analysis and the development of an ongoing risk management process.

Discussion Points

  • Review policies and procedures related to HIPAA compliance, data security, and risk management to ensure they reflect current operational practices and evolving cybersecurity threats. Policies should clearly define responsibilities for safeguarding ePHI, conducting risk analyses, and responding to security incidents. Risk management frameworks should be practical, actionable, and regularly updated. Collaboration with compliance professionals or external consultants can support policy development and refinement, help identify gaps in existing controls, and strengthen overall preparedness.
  • Provide ongoing education and training to staff on HIPAA requirements, data security principles, and safeguards designed to protect ePHI. Training should reinforce responsibilities for identifying and reporting potential security incidents and promote awareness of threats such as phishing, ransomware, and unauthorized access. Education should occur at onboarding and at regular intervals to maintain compliance and awareness. Med-Net Academy offers the course Understanding and Preventing Ransomware Attacks and Other Cyber Assaults, which explains how ransomware operates, outlines consequences of an attack, and highlights the risks posed by advanced persistent threats and zero-day exploits in healthcare. The course also includes case studies and practical steps to reduce risk and prevent infection.
  • Conduct periodic audits and evaluations to assess compliance with HIPAA policies and the effectiveness of security controls. Audits should review risk analysis documentation, system safeguards, and staff adherence to established procedures. Findings should be used to guide corrective actions and strengthen ongoing risk management. Many organizations benefit from independent reviews or structured assessments conducted with external compliance support to validate internal processes and identify improvement opportunities before issues arise. Contact Med-Net Healthcare Consulting or info@mednetconcepts.com for more information.

*This news alert has been prepared by Med-Net Concepts, Inc. for informational purposes only and is not intended to provide legal advice.*