OSF Healthcare settles with HHS OCR over ransomware
OSF Healthcare settled with HHS OCR over a 2021 Nephilim-linked breach. A separate report names a possible INCRANSOM health victim.
HHS OCR announced a settlement with OSF Healthcare System over possible HIPAA violations tied to a breach reported in October 2021, when its files were infected with the Nephilim ransomware variant. In parallel, a Security Arsenal report placed Clinton Health Access Initiative, a US-based health organization, among victims attributed to INCRANSOM within a five-day window, although the mention comes from dark web monitoring and not official confirmation of the incident.
OSF Healthcare reaches a settlement with HHS OCR
HHS OCR announced a settlement with OSF Healthcare System over possible HIPAA violations tied to a breach report filed in October 2021, when its files were infected by the Nephilim ransomware variant. The available reference does not specify the settlement amount or any other terms, but it does place the case within a federal regulatory action that has now been closed.
A sector that keeps appearing in ransomware reports
The episode adds to a long list of examples showing that the US health sector continues to surface frequently as a target. Among the available materials is also a Security Arsenal report on INCRANSOM activity, which identified a US-based health organization, Clinton Health Access Initiative, among its victims within a five-day window.
In that case, the source itself says the finding comes from dark web monitoring and not from official confirmation of the incident, so the mention should be read as a preliminary attribution rather than a verified fact established by the affected organization.
Confirmed background
The available sources also include references to confirmed cases and regulatory follow-up in the US healthcare system, such as HHS ASPR TRACIE material on ransomware attack trends against hospitals, clinics and other healthcare organizations between 2016 and 2021, along with coverage of Change Healthcare and other breaches in the sector. Taken together, the material shows repeated and varied impacts, but it does not add a new recent incident with direct official confirmation beyond the settlement announced by HHS OCR with OSF Healthcare.
Sources
- Trends in Ransomware Attacks on US Hospitals Clinics and Other Health Care Delivery Organizations, 2016-2021asprtracie.hhs.gov· HHS ASPR TRACIE
- 150000 Impacted by Madera Community Hospital Data Breachsecurityweek.com· SecurityWeek
- Federal Regulators Settle HIPAA Enforcement Action with OSF Healthcareleadingage.org· LeadingAge
- DentaQuest datatyveri-hack rammer 15 millioner pasienterhealth-isac.org· Health-ISAC
- INCRANSOM Ransomware Gang: 10 Victims in 5 Days — Cross-Sector Campaign Hits Healthcare, Energy & Quantum Techsecurityarsenal.com· Security Arsenal
- La semana en noticias sobre filtracioneskaseya.com· Kaseya
- State AG Sues Change Healthcare in 2024 Ransomware Attackbankinfosecurity.com· BankInfoSecurity
- The State Of Ransomware 2026blackfog.com· BlackFog



