Skip to main content
FQHC Talent
Back to the news

OCR Settles 4 HIPAA Ransomware Cases, $1.165M Bundled Penalty, 427K Patients Exposed

Federal

Issue

On April 23, 2026, HHS Office for Civil Rights announced settlements with four healthcare entities (Regional Women's Health Group/Axia Women's Health, Assured Imaging, Consociate Health, and Star Group LP Health Benefits Plan) for HIPAA ransomware breaches affecting 427,000 patients. Total penalty: $1,165,000 + 2-year corrective action plans for each.

Common root cause across all four: failure to conduct accurate Security Rule risk analysis. This is OCR's 19th ransomware investigation completed under its dedicated ransomware enforcement initiative, and the first time it bundled multiple settlements in a single press release — signaling a more aggressive, organized ransomware enforcement posture.

Strategic implication for CA FQHCs: every FQHC running OCHIN Epic, eClinicalWorks, NextGen, or athenahealth is squarely in scope.

Three protective actions are non-negotiable for FY26-27:

  • document a current Security Rule risk analysis (annual minimum)
  • inventory all Business Associate Agreements with PHI vendors
  • confirm tested backup-restore procedures.

Pairs with the May 11 Section 504 deadline as a one-two compliance hit — and arrives during the same week as the AltaMed cybersecurity incident class action investigation extends into May.

Key points

  • $1.165M / 4 entities / 427K patients in single OCR announcement
  • Common root cause: failed Security Rule risk analysis
  • OCR's 19th ransomware case — bundled enforcement signal
  • Document current risk analysis + BAA inventory + tested backups now

Sources for this story

HHS Office for Civil Rights

Sources for your board packet

This story's source plus 4 related stories and their sources, ready to print for your team or board.

Free. Unlocking the packet subscribes you to Intel Brief. You'll be subscribed right away, with no confirmation email. Unsubscribe with one click in any issue. If you unsubscribed before, we won't re-add you. We never sell your email. You can open each source above without an email.

#OCR#HIPAA#ransomware#$1.165M-settlement#Security-Rule#risk-analysis#BAA#enforcement-sweep

Part of

Cite this analysis

FQHC Talent. (2026, April 23). OCR Settles 4 HIPAA Ransomware Cases, $1.165M Bundled Penalty, 427K Patients Exposed. Source: HHS Office for Civil Rights. Retrieved October 6, 2026, from https://www.fqhctalent.com/intel/ocr-ransomware-sweep-1-165m-four-entities-april-23-2026

More in Risk & Compliance

Cookie notice

We use Google Analytics, Vercel Web Analytics, and Vercel Speed Insights to improve the site. Select Decline to turn them off in this browser. We honor GPC and Do Not Track. Read our Privacy Policy.