Back to News
Security NewsHighIncidentransomware

HIPAA Enforcement Action Against Employer-Sponsored Health Plan for Ransomware Attack

UnknownMay 7, 2026(about 1 hour ago)

A self-funded employer-sponsored group health plan settled with OCR after a ransomware attack resulted in a breach of electronic protected health information.

On April 23, 2026, the HHS’s Office for Civil Rights (“OCR”) announced a settlement with a self-funded employer-sponsored group health plan (the “Plan”) following a ransomware attack that resulted in a breach of electronic protected health information (“PHI”). Under the settlement, the Plan agreed to pay $245,000 to OCR and to implement a two-year corrective action plan.... By: Haynes Boone

Related News

Get Personalized Alerts

Track vendors and receive alerts when security incidents affect your supply chain.

What We Monitor

Security Incidents

Data breaches, ransomware, and unauthorized access

Vulnerabilities

CVEs and vendor security advisories

Compliance Updates

Regulatory changes and certification news

Legal News

Privacy laws and enforcement actions

Vendor Directory

Browse our directory of SaaS vendors with security documentation and compliance information.