Ransomware Settlement Shows the Cost of Skipping a Risk Analysis

Ransomware Settlement Shows the Cost of Skipping a Risk Analysis

Federal regulators reached a $450,000 settlement in June with an employer-sponsored health plan, closing out an investigation tied to a 2021 ransomware attack that exposed protected health information for more than 10,000 people. 

The real risk? The Department of Health and Human Services (HHS) found the plan had never completed the risk analysis required under HIPAA before the breach occurred.

"Effective cybersecurity starts with Security Rule compliance, ensuring that Security Rule provisions are implemented before a cyberattack occurs." — Paula M. Stannard, Director, HHS Office for Civil Rights

This wasn't a hospital or a nursing home. It was a health plan, and the Office for Civil Rights OCR) held it accountable to the same standard every covered entity is expected to meet. 

As we know, ANY organization handling electronic protected health information is expected to identify its own vulnerabilities before an attacker does. That includes long-term care, skilled nursing, home health, hospice, and other healthcare facilities.  

The settlement also required a two-year corrective action plan, a full risk analysis, revised policies, and documented staff training. None of that is optional after the fact. It's supposed to happen first. Enforcement actions like this one are a preview of what regulators expect industry-wide.

If your facility hasn't looked at its own risk analysis recently, this is a good week to start. CHUG offers members consulting services to help you identify and address any gaps in your own compliance and preparedness. Reach out to get started >


The key to successfully mitigating any emergency is preparedness. CHUG members have access to a comprehensive suite of educational workshops that utilize real-life case studies to teach effective responses to storms and emergency situations. This training can be lifesaving. Not a member? Become a member today. Already a member? Visit the Member Portal for a full calendar of events and member-exclusive content.

Connie Pollke