On April 23, 2026, the HHS Office for Civil Rights announced four HIPAA Security Rule settlements on a single day. The four resolutions total $1,165,000 and cover more than 427,000 individuals. The underlying breaches occurred between May 2020 and December 2021, which means OCR closed these matters four to six years after the intrusions that triggered them.
The four settlements share one finding. In each case OCR concluded the regulated entity had failed to conduct an accurate and thorough risk analysis. That is not an incidental commonality. It is the organising principle of OCR's Risk Analysis Initiative, and these four actions bring that initiative to 13 enforcement outcomes and OCR's completed ransomware investigations to 19.
KEY FACTS
- WhatFour simultaneous HIPAA Security Rule settlements announced by HHS OCR, each resting on a failure to conduct an accurate and thorough risk analysis
- WhoAssured Imaging Affiliated Covered Entities, Regional Women's Health Group LLC dba Axia Women's Health, Star Group L.P. Health Benefits Plan, and Consociate Inc. dba Consociate Health
- HowRansomware and phishing intrusions between May 2020 and December 2021, investigated by OCR under its Risk Analysis Initiative
- DataElectronic protected health information. Social Security numbers in three of the four breaches, driver's license numbers in two, credit card or bank account numbers in one, alongside diagnoses, lab results, medications and treatment information
- ActorNot attributed by OCR. TechTarget alone names PYSA ransomware in the Assured Imaging matter
- Impact$1,165,000 in settlements, 427,000+ individuals affected, two-year corrective action plan monitoring for all four entities
WHAT HAPPENED
OCR announced the four resolutions together on April 23, 2026. Each was a negotiated settlement with a corrective action plan rather than a civil money penalty, and each carries a two-year OCR monitoring period.
Assured Imaging Affiliated Covered Entities settled for $375,000 over a breach discovered in May 2020 affecting 244,813 individuals, the largest of the four. HIPAA Journal reports the discovery date as May 19, 2020. OCR's findings in this matter went beyond risk analysis: per Nixon Peabody and Paubox, OCR also found an impermissible disclosure of ePHI and a failure to timely notify affected individuals. TechTarget is the only retrieved source to name a ransomware variant in any of the four matters, identifying PYSA in the Assured Imaging intrusion.
Regional Women's Health Group LLC, doing business as Axia Women's Health, settled for $320,000 over a December 2020 breach. Source figures for the affected population vary: HIPAA Journal, Paubox and HIPAA Training all report 37,989, TechTarget reports 37,000, and Nixon Peabody reports 38,000. OCR's finding was a failure to conduct a comprehensive risk analysis.
Star Group L.P. Health Benefits Plan settled for $245,000 over a breach reported in October 2021 affecting 9,316 individuals. This is the smallest population of the four and the only employer-sponsored health benefits plan in the group. Nixon Peabody reports OCR found both a risk assessment failure and an impermissible disclosure of ePHI.
Consociate Inc., doing business as Consociate Health, settled for $225,000. Three sources report 136,539 individuals affected. The timeline for this matter is inconsistent across sources. Nixon Peabody and Paubox both describe an initial phishing compromise in July 2020 followed by ransomware deployment in November or December 2021, an intrusion-to-encryption interval of roughly 16 months. HIPAA Journal instead reports the breach was discovered on January 14, 2021, with the network compromised approximately six months earlier.
Those accounts cannot both be correct and no retrieved source reconciles them.
OCR Director Paula M. Stannard framed the announcement in prevention terms, stating that "Hacking and ransomware are the most frequent type of large breach reported to OCR." HIPAA Journal further reports that implementation of Security Rule requirements represents "a regulated entity's best opportunity to prevent or mitigate harmful cyberattack effects."
THE ARITHMETIC
The dollar figures reconcile cleanly. $375,000 plus $320,000 plus $245,000 plus $225,000 is exactly $1,165,000, and that total is stated directly by HIPAA Journal, Paubox and HIPAA Training.
The individual counts do not reconcile as cleanly, and the discrepancy is worth stating plainly rather than rounding away. Taking the precise per-entity figures on which three independent outlets agree - 244,813, 37,989, 9,316 and 136,539 - the sum is 428,657. Every retrieved source characterises the aggregate only as "more than 427,000" or "427,000+". None publishes a precise total.
A commonly circulated figure of 427,613 does not appear in any source retrieved for this analysis. It is reproduced exactly by summing TechTarget's rounded per-entity figures (244,813 plus 37,000 plus 9,300 plus 136,500), which indicates it is an artifact of rounded inputs rather than a total OCR published. ZERO|TOLERANCE reports the aggregate as "more than 427,000" and the precise sum as 428,657, and treats 427,613 as unsupported.
HIPAA Journal additionally reports that these four actions bring OCR's 2026 enforcement total to six investigations and $1,278,000, implying roughly $113,000 across the two 2026 matters outside this announcement. That figure is single-source.
THREAT ACTOR
OCR did not attribute any of the four intrusions to a named threat actor, and no formal technical attribution has been issued for any of them. TechTarget names PYSA ransomware in connection with the Assured Imaging breach. PYSA, also tracked as Mespinoza, was active in the 2019 to 2021 period and repeatedly targeted healthcare and education, which is consistent with a May 2020 breach date. No other retrieved source corroborates the PYSA identification, and no variant is named for the Axia, Star Group or Consociate matters.
The Consociate intrusion is described as beginning with phishing rather than direct exploitation.
Attribution is not the point of these enforcement actions. OCR's findings address the defensive posture of the regulated entities, not the identity of the intruders, and the settlements would read identically regardless of which crew deployed the payload.
WHAT WAS EXPOSED
The OCR release could not be retrieved directly, but three independent outlets - HIPAA Journal, Paubox and HIPAA Training - publish field-level data inventories for these matters, and their wording agrees closely. Social Security numbers were exposed in three of the four breaches.
- Assured Imaging Affiliated Covered Entities, 244,813 individuals: names, contact information and addresses, dates of birth, diagnoses and conditions, lab results, medications, and treatment information. No Social Security numbers are reported for this entity. HIPAA Journal renders the second field as "contact information" where Paubox and HIPAA Training render it as "addresses"
- Regional Women's Health Group LLC dba Axia Women's Health, 37,989 individuals: names, addresses, dates of birth, Social Security numbers, driver's license numbers, diagnoses or conditions, lab results, and medications
- Star Group L.P. Health Benefits Plan, 9,316 individuals: names, addresses, dates of birth, Social Security numbers, and health insurance information, including member identification numbers, claims data and benefit selection information
- Consociate Inc. dba Consociate Health, 136,539 individuals: names, addresses, dates of birth, driver's license numbers, Social Security numbers, credit card or bank account numbers, and diagnoses or conditions. Paubox gives no field-level detail for this entity; HIPAA Journal and HIPAA Training agree on the list above
The exposure profile matters more than the record count. Social Security numbers and dates of birth cannot be reissued on request and stay usable for identity fraud indefinitely, which is why SSN exposure independently triggers breach notification duties in every US state. Driver's license numbers, exposed in the Axia and Consociate breaches, are reissuable but slowly and rarely proactively.
Consociate is the most severe of the four on data type despite ranking second by volume. It combines Social Security numbers, driver's license numbers and credit card or bank account numbers in a single record set, which is a complete identity-theft package rather than a partial one. Axia's combination of reproductive health diagnoses with Social Security numbers and driver's license numbers carries a distinct harm profile, because the clinical detail is not merely sensitive but potentially coercive in the wrong hands.
Star Group's claims data and benefit selection information expose the medical and financial relationship between employee and employer.
TECHNICAL FAILURE CHAIN
This is the finding common to all four settlements. 45 CFR 164.308(a)(1)(ii)(A) requires a covered entity or business associate to "conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate." The provision is marked Required, not Addressable. There is no reasonableness escape hatch and no documented alternative measure available.
45 CFR 164.308(a)(1)(ii)(B), also Required, obliges an entity to "implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with 164.306(a)." An entity that never enumerated its risks has no defensible basis for selecting controls. The (A) failure structurally guarantees the (B) failure.
On the Nixon Peabody and Paubox timeline, the Consociate intrusion began with phishing in July 2020 and ransomware was not deployed until November or December 2021. An adversary held access for roughly 16 months to an environment holding Social Security numbers and bank account numbers. No retrieved source states what detection capability existed or when the intrusion was first identified.
In the Assured Imaging matter OCR found the entity failed to timely notify affected individuals, a violation separate from the Security Rule findings. Nixon Peabody records the finding as untimely notification and states no interval. The applicable statutory standard is 45 CFR 164.404(b), which requires notification "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach". The 60-day figure is the deadline the conduct is measured against, not a number OCR published in this matter. Late notification compounds harm by delaying the point at which affected individuals can act.
OCR made this finding in the Assured Imaging and Star Group matters, indicating the failures were not confined to documentation but resulted in ePHI reaching parties not authorised to receive it.
Breaches from 2020 and 2021 were resolved in 2026. The interval means the deterrent signal reaches the market long after the conduct, and any entity whose current risk analysis posture matches these four is already exposed for conduct that will not be adjudicated until the 2030s.
INDICATORS OF COMPROMISE
- Malware familyPYSA ransomware, named in the Assured Imaging matter by TechTarget only, uncorroborated
- Initial access vectorphishing, in the Consociate matter
- Regulatory identifiers45 CFR 164.308(a)(1)(ii)(A) (Risk analysis, Required), 45 CFR 164.308(a)(1)(ii)(B) (Risk management, Required), 45 CFR 164.404(b) (60-day individual notification deadline)
- Exposure windowMay 2020 to December 2021 across the four matters
No hashes, domains, IP addresses or C2 infrastructure were released.
REGULATORY EXPOSURE
- HIPAA Security Rule, 45 CFR 164.308(a)(1)(ii)(A)Risk analysis, Required implementation specification - cited in all four settlements. This is the single most enforceable provision in the Security Rule because compliance is binary and documentary: either a current, accurate, enterprise-wide risk analysis exists or it does not
- HIPAA Security Rule, 45 CFR 164.308(a)(1)(ii)(B)Risk management, Required - the dependent obligation that cannot be satisfied without (A)
- HIPAA Security Rule, 45 CFR 164.306(a)general security standards referenced by the risk management specification
- HIPAA Breach Notification Rule, 45 CFR 164.404(b)notification to individuals "without unreasonable delay and in no case later than 60 calendar days after discovery of a breach" - the standard against which OCR's untimely notification finding in the Assured Imaging matter is measured. Retrieved coverage records the finding without stating an interval; the paragraph text quoted here was retrieved from Cornell Legal Information Institute
- Impermissible disclosure of ePHI - found in the Assured Imaging and Star Group matters
- Settlement structure - negotiated resolution agreements with corrective action plans and two-year OCR monitoring for all four entities, rather than civil money penalties
- State breach notification statutes - Social Security numbers were exposed in the Axia, Star Group and Consociate breaches, which triggers notification duties in every US state independently of HIPAA. Consociate's exposure of credit card or bank account numbers and driver's license numbers engages additional state provisions covering financial account and government identifier data. No state-level enforcement is reported in the retrieved coverage
- Comparative note for multinational providers - the EU analogue is structured differently rather than absent, and neither regime discharges the other. GDPR Article 32(2) requires that in assessing the appropriate level of security "account shall be taken in particular of the risks that are presented by processing", and Article 32(1) requires a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures. Where Article 35(3) is triggered, including for large-scale processing of special categories of data, Article 35(7) separately requires a documented assessment containing "an assessment of the risks to the rights and freedoms of data subjects". The structural difference is that the HIPAA obligation is a single named specification that is always Required, whereas the GDPR obligation is split across Articles 32 and 35 and its impact-assessment limb is triggered by a risk threshold. Whether a given US provider's EU processing crosses that threshold is entity-specific and is not assessed here
INTELLIGENCE GAPS
hhs.gov returned HTTP 403 to automated requests throughout this analysis, as did databreaches.net and hipaaguide.net. Every figure in this article derives from secondary reporting. No primary OCR artifact, resolution agreement or corrective action plan document was obtained. Source confidence is corroborated, not primary.
Precise per-entity figures sum to 428,657. All sources state only "more than 427,000". The widely repeated 427,613 appears in no retrieved source and is reproducible only by summing rounded inputs. The true OCR-stated total is unknown.
This analysis uses 37,989 as the best-corroborated figure.
Nixon Peabody and Paubox place ransomware deployment in November or December 2021 following a July 2020 phishing compromise. HIPAA Journal reports discovery on January 14, 2021 with compromise roughly six months prior. No source reconciles the two accounts.
PYSA is named only by TechTarget and only for Assured Imaging. No variant is identified for the other three matters.
The 45 CFR texts quoted here, being 164.308(a)(1)(ii)(A), 164.308(a)(1)(ii)(B) and 164.404(b), were retrieved from Cornell Legal Information Institute; the GDPR text in the comparative note was retrieved from gdpr-info.eu rather than from EUR-Lex. Whether OCR's resolution agreements cite these paragraphs by number is unconfirmed. No fine or penalty figure is asserted for any non-HIPAA framework in this article.
Per-entity data classes come from HIPAA Journal, Paubox and HIPAA Training, which agree closely and appear to reproduce OCR's release, but the release itself could not be retrieved. Paubox gives no field detail for Consociate. HIPAA Journal renders one Assured Imaging field as "contact information" where the other two render it as "addresses". No source states whether any of the four data sets appeared on a leak site or were subsequently sold.
Dwell time and detection method are undisclosed for three of the four entities, and no source states whether any entity paid a ransom.
ZERO|TOLERANCE Advisory
All four settlements turned on 164.308(a)(1)(ii)(A). Produce an enterprise-wide risk analysis covering every system that creates, receives, maintains or transmits ePHI, date it, version it, and refresh it on a fixed annual cadence and on any material change to the environment. OCR's first document request in any investigation is this artifact, and its absence is dispositive.
A risk analysis that omits systems is not accurate or thorough, and OCR has repeatedly found scope gaps sufficient to sustain a finding. Build and maintain an ePHI asset inventory covering cloud tenants, imaging modalities, backup repositories, third-party administrators and vendor-hosted portals, and reconcile it against the risk analysis scope each cycle.
164.308(a)(1)(ii)(B) is a separate Required specification. Every risk identified must map to a documented remediation decision with an owner, a date and an outcome. Accepted risks require written justification. An analysis with no traceable risk management record satisfies neither provision.
Three of these four breaches exposed Social Security numbers and one exposed bank and card numbers alongside them. Where Social Security numbers, driver's license numbers and financial account numbers are retained for eligibility or billing, tokenise them, encrypt them at rest under separately managed keys, and restrict decryption to named service accounts. Clinical data and identity data compromised together produce materially worse outcomes than either alone.
If the Consociate timeline reported by Nixon Peabody and Paubox is accurate, an adversary held access for roughly 16 months before deploying ransomware. Deploy EDR with retained telemetry across all ePHI-adjacent systems, and specifically alert on the pre-encryption sequence: credential dumping, privilege escalation, volume shadow copy deletion and backup service tampering.
Consociate's intrusion began with phishing. Deploy FIDO2 hardware security keys or platform passkeys for all administrative and remote-access accounts, and eliminate SMS and push-approval MFA for any account with access to ePHI systems.
Assured Imaging drew a separate finding for untimely notification. Maintain a written breach response runbook with the 164.404(b) clock started at discovery, a pre-approved notification template, a standing forensic retainer, and a documented decision record for the four-factor risk assessment. Late notification is independently sanctionable regardless of how the intrusion occurred.
These breaches predate their settlements by four to six years. Retain risk analyses, risk management records, training logs and breach response documentation for the full six-year HIPAA retention period, because the record you will be judged on is the one that existed at the time of the incident, not the one you build after it.
SOURCES
- HHS Office for Civil Rights press release, "HHS' Office for Civil Rights Settles Four HIPAA Security Rule Ransomware Investigations" - https://www.hhs.gov/press-room/ocr-settles-four-ransomware-investigations.html (not retrievable, HTTP 403)
- TechTarget Healthtech Security, "OCR settles four HIPAA investigations, prioritizes risk analysis" - https://www.techtarget.com/healthtechsecurity/news/366642176/OCR-settles-four-HIPAA-investigations-prioritizes-risk-analysis
- Nixon Peabody, "Ransomware enforcement update: 19 investigations completed by OCR, four settlements added" - https://www.nixonpeabody.com/insights/articles/2026/04/30/ransomware-enforcement-update-19-investigations-completed-by-ocr-four-settlements-added
- HIPAA Journal, "OCR Fines Four Regulated Entities for HIPAA Violations That Led to Ransomware Attacks" - https://www.hipaajournal.com/ocr-fines-four-regulated-entities-hipaa-violations-ansomware-attacks/
- Paubox, "OCR settles four HIPAA ransomware cases affecting 427k" - https://www.paubox.com/blog/ocr-settles-four-hipaa-ransomware-cases-affecting-427k
- HIPAA Training, "HHS OCR Settles Four HIPAA Ransomware Investigations Affecting More Than 427,000 Individuals" - https://hipaatraining.net/hhs-ocr-settles-four-hipaa-ransomware-investigations-affecting-more-than-427000-individuals
- Cornell Legal Information Institute, 45 CFR 164.308 - https://www.law.cornell.edu/cfr/text/45/164.308
- Cornell Legal Information Institute, 45 CFR 164.404 - https://www.law.cornell.edu/cfr/text/45/164.404
- GDPR Article 32, Security of processing - https://gdpr-info.eu/art-32-gdpr/
- GDPR Article 35, Data protection impact assessment - https://gdpr-info.eu/art-35-gdpr/