OCR Settles 4 HIPAA Ransomware Cases, $1.165M Bundled Penalty, 427K Patients Exposed
Issue
On April 23, 2026, HHS Office for Civil Rights announced settlements with four healthcare entities (Regional Women's Health Group/Axia Women's Health, Assured Imaging, Consociate Health, and Star Group LP Health Benefits Plan) for HIPAA ransomware breaches affecting 427,000 patients. Total penalty: $1,165,000 + 2-year corrective action plans for each.
Common root cause across all four: failure to conduct accurate Security Rule risk analysis. This is OCR's 19th ransomware investigation completed under its dedicated ransomware enforcement initiative, and the first time it bundled multiple settlements in a single press release — signaling a more aggressive, organized ransomware enforcement posture.
Strategic implication for CA FQHCs: every FQHC running OCHIN Epic, eClinicalWorks, NextGen, or athenahealth is squarely in scope.
Three protective actions are non-negotiable for FY26-27:
- document a current Security Rule risk analysis (annual minimum)
- inventory all Business Associate Agreements with PHI vendors
- confirm tested backup-restore procedures.
Pairs with the May 11 Section 504 deadline as a one-two compliance hit — and arrives during the same week as the AltaMed cybersecurity incident class action investigation extends into May.
Key points
- $1.165M / 4 entities / 427K patients in single OCR announcement
- Common root cause: failed Security Rule risk analysis
- OCR's 19th ransomware case — bundled enforcement signal
- Document current risk analysis + BAA inventory + tested backups now
Sources for this story
HHS Office for Civil RightsSources for your board packet
This story's source plus 4 related stories and their sources, ready to print for your team or board.
Free. Unlocking the packet subscribes you to Intel Brief. You'll be subscribed right away, with no confirmation email. Unsubscribe with one click in any issue. If you unsubscribed before, we won't re-add you. We never sell your email. You can open each source above without an email.
Part of
- Enforcement: privacy, fraud and audits
Data breaches · HIPAA rules and OCR enforcement
FQHC Talent. (2026, April 23). OCR Settles 4 HIPAA Ransomware Cases, $1.165M Bundled Penalty, 427K Patients Exposed. Source: HHS Office for Civil Rights. Retrieved October 6, 2026, from https://www.fqhctalent.com/intel/ocr-ransomware-sweep-1-165m-four-entities-april-23-2026
More in Risk & Compliance
Sep 29
HHS civil rights office says when states can use substance use records
Sep 25
CMS and 37 states pledge to judge Medicaid by health outcomes
Sep 24
Geiger Gibson review finds health centers expect a heavy work-rule frailty burden
Sep 24
CMS seeks input on Part D pharmacy contract terms, including 340B claims