CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

HHS OCR Settles Ransomware Investigation of OSF Healthcare System and Affiliated Covered Entities

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3529

As cited

Copy frozen at (site build).

ransomware

HHS OCR Settles Ransomware Investigation of OSF Healthcare System and Affiliated Covered Entities

The U.S. Department of Health and Human Services Office for Civil Rights (HHS OCR) has concluded a ransomware investigation into OSF Healthcare System and affiliated entities stemming from a June 2021 attack by the Xing Team ransomware group. The settlement addresses OSF's delayed incident response and notification practices, which fell short of Health Insurance Portability and Accountability Act (HIPAA) requirements.

Why it matters: Healthcare providers and their legal teams must understand that HHS OCR enforces strict timely notification obligations following ransomware incidents; delays in breach reporting can result in formal settlements and potential penalties beyond the ransom itself.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary