CiberLATAMbywhalemate

OSF Healthcare settles with HHS OCR over ransomware

OSF Healthcare settled with HHS OCR over a 2021 Nephilim-linked breach. A separate report names a possible INCRANSOM health victim.

Whalemate Labs · AI-assisted researchPublished:Updated 2 min read

HHS OCR announced a settlement with OSF Healthcare System over possible HIPAA violations tied to a breach reported in October 2021, when its files were infected with the Nephilim ransomware variant. In parallel, a Security Arsenal report placed Clinton Health Access Initiative, a US-based health organization, among victims attributed to INCRANSOM within a five-day window, although the mention comes from dark web monitoring and not official confirmation of the incident.

HHS OCR announced a settlement agreement with OSF Healthcare System over possible HIPAA violations tied to a breach reported in October 2021, when its files were infected by the Nephilim ransomware variant. The case adds to other reports of ransomware activity in the US health sector, including a reported INCRANSOM victim cited by Security Arsenal.

What did HHS OCR settle with OSF Healthcare?

HHS OCR announced a settlement agreement with OSF Healthcare System over possible HIPAA violations tied to a breach reported in October 2021, when its files were infected by the Nephilim ransomware variant. The available reference does not specify the settlement amount or any other terms, but it does place the case within a federal regulatory action that has now been closed.

What other attribution appeared in ransomware reports?

The episode adds to a broader record in which the US health sector continues to appear frequently as a target. Among the available materials is also a Security Arsenal report on INCRANSOM activity that attributed Clinton Health Access Initiative, a US-based health organization, to its list of victims within a five-day window.

In that case, the source itself says the information comes from dark web monitoring and not from official confirmation of the incident, so the mention should be read as a preliminary attribution rather than a fact verified by the affected organization.

What confirmed background is cited in the health sector?

Among the available sources are also references to confirmed cases and regulatory follow-up in the US health system, including HHS ASPR TRACIE material on ransomware attack trends against hospitals, clinics, and other healthcare organizations between 2016 and 2021, as well as coverage of Change Healthcare and other breaches in the sector. Taken together, the material shows repeated and varied impacts, but it does not add a new recent incident with direct official confirmation beyond the settlement announced by HHS OCR with OSF Healthcare.

Sources

View all