As cited
Copy frozen at (site build).
ransomware
HHS OCR Settles Ransomware Investigation of OSF Healthcare System and Affiliated Covered Entities
The U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR) has concluded a ransomware investigation into OSF Healthcare System and affiliated entities stemming from a June 2021 attack by the Xing Team ransomware group. The settlement addresses OSF's delayed incident response and notification practices, which fell short of Health Insurance Portability and Accountability Act (HIPAA) requirements.
Why it matters: Healthcare providers and their legal teams must understand that HHS OCR enforces strict timely notification obligations following ransomware incidents; delays in breach reporting can result in formal settlements and potential penalties beyond the ransom itself.
- Source published
- First seen by Cybersecurity Tracker