IN June 2021, a ransomware attack by the relatively unknown Xing Team affected OSF Healthcare, with reports highlighting OSF's inadequate response. A statement issued in October revealed further delays in their incident response. The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a settlement with OSF for potential violations of HIPAA regulations due to an incident where the PHI of 53,907 individuals was compromised.
OSF was fined $552,250 and agreed to a corrective action plan, which includes conducting a comprehensive risk analysis and implementing measures to protect electronic protected health information (ePHI). Key failings included neglecting proper risk assessments, late notifications to affected parties, and potential violations of privacy and security rules.