OSF Healthcare settles with HHS OCR over ransomware
OSF Healthcare settled with HHS OCR over a 2021 Nephilim-linked breach. A separate report names a possible INCRANSOM health victim.
HHS OCR announced a settlement with OSF Healthcare System over possible HIPAA violations tied to a breach reported in October 2021, when its files were infected with the Nephilim ransomware variant. In parallel, a Security Arsenal report placed Clinton Health Access Initiative, a US-based health organization, among victims attributed to INCRANSOM within a five-day window, although the mention comes from dark web monitoring and not official confirmation of the incident.
HHS OCR announced a settlement agreement with OSF Healthcare System over possible HIPAA violations tied to a breach reported in October 2021, when its files were infected by the Nephilim ransomware variant. The case adds to other reports of ransomware activity in the US health sector, including a reported INCRANSOM victim cited by Security Arsenal.
What did HHS OCR settle with OSF Healthcare?
HHS OCR announced a settlement agreement with OSF Healthcare System over possible HIPAA violations tied to a breach reported in October 2021, when its files were infected by the Nephilim ransomware variant. The available reference does not specify the settlement amount or any other terms, but it does place the case within a federal regulatory action that has now been closed.
What other attribution appeared in ransomware reports?
The episode adds to a broader record in which the US health sector continues to appear frequently as a target. Among the available materials is also a Security Arsenal report on INCRANSOM activity that attributed Clinton Health Access Initiative, a US-based health organization, to its list of victims within a five-day window.
In that case, the source itself says the information comes from dark web monitoring and not from official confirmation of the incident, so the mention should be read as a preliminary attribution rather than a fact verified by the affected organization.
What confirmed background is cited in the health sector?
Among the available sources are also references to confirmed cases and regulatory follow-up in the US health system, including HHS ASPR TRACIE material on ransomware attack trends against hospitals, clinics, and other healthcare organizations between 2016 and 2021, as well as coverage of Change Healthcare and other breaches in the sector. Taken together, the material shows repeated and varied impacts, but it does not add a new recent incident with direct official confirmation beyond the settlement announced by HHS OCR with OSF Healthcare.
Sources
- Trends in Ransomware Attacks on US Hospitals Clinics and Other Health Care Delivery Organizations, 2016-2021asprtracie.hhs.gov· HHS ASPR TRACIE
- 150000 Impacted by Madera Community Hospital Data Breachsecurityweek.com· SecurityWeek
- Federal Regulators Settle HIPAA Enforcement Action with OSF Healthcareleadingage.org· LeadingAge
- DentaQuest datatyveri-hack rammer 15 millioner pasienterhealth-isac.org· Health-ISAC
- La semana en noticias sobre filtracioneskaseya.com· Kaseya
- State AG Sues Change Healthcare in 2024 Ransomware Attackbankinfosecurity.com· BankInfoSecurity
- The State Of Ransomware 2026blackfog.com· BlackFog
- INCRANSOM Ransomware Gang: 10 Victims in 5 Days — Cross-Sector Campaign Hits Healthcare, Energy & Quantum Techsecurityarsenal.com· Security Arsenal



