Skip to content

OSF HealthCare System

Disclosed Oct 19, 20205 years ago94,171 affectedConfirmed

Official notice

The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) today announced a settlement with OSF Healthcare System and its Affiliated Covered Entities (OSF), concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules. OSF is headquartered in Illinois and has providers located in Illinois and Michigan. OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules , which set forth the requirements that covered entities (health plans, health care clearinghouses, and most health care providers), and business associates must follow to protect the privacy and security of PHI. The settlement resolves an investigation that OCR initiated after OSF filed a breach report in October 2021. In April of 2021, OSF discovered that its files had been infected with the “Nephilim” variant of ransomware. The PHI of 53,907 individuals was exfiltrated by the threat actor. Affected PHI included driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and

What is known

People affected94,171 (as reported to HHS)
DisclosedOct 19, 2020
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): OSF HealthCare System (Healthcare Provider, IL)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalOct 19, 202094,171
HHS archivetotalOct 1, 202153,907
History of this record
  • 2026-09-25 · records: 53907 to 94171 · backfill source
  • 2026-09-25 · disclosed: 2021-10-01 to 2020-10-19 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about OSF HealthCare System

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.