Ransomware

When Ransomware Encrypts Health Data, HIPAA Presumes a Breach: How the Presumption Works

Key Takeaways

  • OCR's July 11, 2016 fact sheet states that when ePHI is encrypted by ransomware "a breach has occurred" because unauthorized individuals have taken possession or control of it
  • Since the 2013 Omnibus Rule, 45 CFR 164.402 presumes an impermissible acquisition is a breach unless a risk assessment of at least four factors shows a low probability that the information was compromised
  • Encryption the entity applied removes the notification duty only if the data was still unreadable when the ransomware reached it; OCR says full disk encryption on a running, logged-in system often is not
  • Section 164.414(b) puts the burden of proof on the covered entity or business associate, and the fact sheet ties that burden to documentation kept under 164.530(j)
  • OCR's July 29, 2026 OSF Healthcare settlement, which it called its 21st ransomware enforcement action, included findings of untimely notice to individuals and to the Secretary

Encryption by an Attacker Is Treated as an Acquisition

The breach notification rule does not mention ransomware. Its definition, at 45 CFR 164.402, turns on "the acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E of this part which compromises the security or privacy of the protected health information." Whether an extortion attack fits that definition was addressed by the HHS Office for Civil Rights in a fact sheet dated July 11, 2016, and its answer rests on how it reads the word acquisition.

The fact sheet takes two steps. First it classifies the event: "The presence of ransomware (or any malware) on a covered entity's or business associate's computer systems is a security incident under the HIPAA Security Rule," citing the definition of security incident at 45 CFR 164.304 and the incident procedures standard at 164.308(a)(6). Then it addresses the data. "When electronic protected health information (ePHI) is encrypted as the result of a ransomware attack, a breach has occurred because the ePHI encrypted by the ransomware was acquired (i.e., unauthorized individuals have taken possession or control of the information), and thus is a 'disclosure' not permitted under the HIPAA Privacy Rule."

The operative idea is control rather than copying. On OCR's reading, an attacker who locks records with a key only the attacker holds has taken possession of them, whether or not a file leaves the network. The same document also describes the breach question as "a fact-specific determination," and most of its analysis concerns the facts that move an incident one way or the other.

The Presumption Replaced a Harm Standard in 2013

The presumption is newer than the rule. Subpart D was first issued as an interim final rule at 74 FR 42767 on August 24, 2009. As HHS later described that version, it provided that "compromises the security or privacy of the protected health information" meant "poses a significant risk of financial, reputational, or other harm to the individual," so notification turned on the entity's own assessment of likely harm.

The Omnibus Rule published on January 25, 2013 removed that standard. HHS reported that approximately 70 of the roughly 85 comments on the breach definition addressed the harm standard, and approximately 60 supported keeping it. It nonetheless agreed with commenters who said the focus on harm to the individual "was too subjective and would lead to inconsistent interpretations and results across covered entities and business associates." The replacement, codified at 78 FR 5695, is paragraph (2) of the definition:

an acquisition, access, use, or disclosure of protected health information in a manner not permitted under subpart E is presumed to be a breach unless the covered entity or business associate, as applicable, demonstrates that there is a low probability that the protected health information has been compromised based on a risk assessment of at least the following factors

45 CFR 164.402, definition of breach, paragraph (2)

Paragraph (1) excludes three situations from the definition altogether: good-faith, within-scope acquisition or use by a workforce member, inadvertent disclosure between people authorized at the same entity or organized health care arrangement, and disclosure to a recipient who "would not reasonably have been able to retain such information." The fact sheet does not rely on any of them for ransomware. It moves from the acquisition finding directly to the presumption.

The Four Factors, Read Against an Encryption Event

The factors appear at 164.402(2)(i) through (iv): the nature and extent of the PHI, including the types of identifiers and likelihood of re-identification; the unauthorized person who used the PHI or to whom it was disclosed; whether the PHI was actually acquired or viewed; and the extent to which the risk has been mitigated. The 2013 preamble said an entity's analysis "must address each factor," that the factors are weighed in combination, and that HHS expects the assessments "to be thorough, completed in good faith, and for the conclusions reached to be reasonable."

The fact sheet identifies the evidence it considers relevant when the event is ransomware: the exact type and variant of malware, "the algorithmic steps undertaken by the malware," communications between the malware and the attackers' command and control servers including exfiltration attempts, and whether the malware propagated to other systems holding ePHI. Knowing the variant, it explains, can show what data the malware searches for, whether it attempts exfiltration, and whether it leaves hidden software for later access.

Two passages pull in opposite directions. On the fourth factor, the fact sheet notes that ransomware frequently deletes the original data after encrypting it, and that an entity "may be able to show mitigation of the impact of a ransomware attack affecting the integrity of PHI through the implementation of robust contingency plans including disaster recovery and data backup plans." It then limits the point: integrity "is only one aspect," and whether PHI has been exfiltrated is also part of the mitigation question. Separately, it treats the four listed factors as a minimum. Where there is "high risk of unavailability of the data, or high risk to the integrity of the data, such additional factors may indicate compromise."

Encryption the Entity Applied, and When It Stops Counting

The notification duties in subpart D attach only to unsecured protected health information, which 164.402 defines as PHI not rendered "unusable, unreadable, or indecipherable to unauthorized persons" through a technology or methodology the Secretary specifies in guidance. The HHS guidance accepts ePHI encrypted as the Security Rule defines encryption, provided the confidential process or key has not been breached, and names NIST Special Publication 800-111 as the standard for data at rest.

The fact sheet applies that to ransomware. If the entity had encrypted the PHI consistently with the guidance so that it was no longer unsecured, the entity "is not required to conduct a risk assessment" and notification is not required. But OCR separates a powered-down device from a running one. Full disk encryption protects a laptop that is shut down and then lost. Once the system is on and the user authenticated, "many full disk encryption solutions will transparently decrypt and encrypt files accessed by the user." Ransomware launched from that session reaches the files in decrypted form, and in that scenario the fact sheet concludes that "an impermissible disclosure of PHI was made and a breach is presumed."

A footnote adds that consistency with SP 800-111 is not only a question of the algorithm. It also involves the encryption methodology (full disk, virtual disk or volume, folder or file), cryptographic key management and, where applicable, pre-boot authentication.

Who Carries the Burden, and What Is Kept

Section 164.414(b) allocates the burden of proof. In the event of a use or disclosure in violation of subpart E, "the covered entity or business associate, as applicable, shall have the burden of demonstrating that all notifications were made as required by this subpart or that the use or disclosure did not constitute a breach." Section 164.414(a) applies several administrative requirements of 164.530 to subpart D, including the documentation requirement at 164.530(j).

The fact sheet connects the two and lists what supporting documentation covers: the risk assessment "demonstrating the conclusions reached," any exception found applicable under paragraph (1) of the breach definition, and documentation that all notifications were made where the incident was determined to be a reportable breach.

The Clocks Once the Presumption Stands

If the presumption is not rebutted, discovery sets every deadline. Under 164.404(a)(2), a breach is treated as discovered on the first day it is known to the covered entity or, by exercising reasonable diligence, would have been known, and knowledge of any workforce member or agent other than the person committing the breach is attributed to the entity. The fact sheet observes that, unless its defenses catch it earlier, an entity "would typically be alerted to the presence of ransomware only after the ransomware has encrypted the user's data and alerted the user to its presence to demand payment."

  • Individuals: without unreasonable delay and no later than 60 calendar days after discovery, under 164.404(b), with the contents listed in 164.404(c)
  • Media: where a breach involves more than 500 residents of a State or jurisdiction, prominent media outlets serving that area, on the same 60-day limit, under 164.406
  • The Secretary: contemporaneously with individual notice where 500 or more individuals are involved, or within 60 days after the end of the calendar year for smaller breaches, under 164.408
  • Business associates: notice to the covered entity no later than 60 calendar days after the business associate's own discovery, identifying each affected individual to the extent possible, under 164.410

The two headcount tests are worded differently: the media duty applies above 500 residents of a single State or jurisdiction, while the contemporaneous report to the Secretary applies at 500 or more individuals in total. The only delay mechanism is 164.412. A written law enforcement statement that notice would impede a criminal investigation or damage national security delays notice for the period it specifies. An oral statement is documented and delays notice no longer than 30 days unless a written statement follows.

The HHS breach reporting page routes notice to the Secretary through an online portal, tells filers who are uncertain of the number affected to "provide an estimate," and allows an addendum to an earlier report using its transaction number. The Change Healthcare incident shows that mechanism in use. OCR's FAQ on the incident, updated as of March 14, 2025, states that Change Healthcare filed a breach report on July 19, 2024 concerning a ransomware attack and listed 500 individuals, which OCR describes as the minimum number that results in posting on the portal, while it was still determining the total.

The same FAQ confirms that OCR's 2016 ransomware guidance applies to that attack, that under the HITECH Act and 164.404 "the covered entity is ultimately responsible for ensuring that such notifications occur," and that OCR verifies large breach reports with the filer before posting them, a process it says is generally completed within 14 days.

What OCR's Ransomware Settlements Have Found

Each of the six ransomware resolutions described below includes a finding that the entity failed to conduct an accurate and thorough risk analysis under the Security Rule. Several also include findings under the Privacy and Breach Notification Rules.

In an April 23, 2026 announcement of four settlements totaling $1,165,000, which OCR said brought its completed ransomware investigations to 19, it found that Assured Imaging, whose ransomware breach affected 244,813 individuals, had impermissibly disclosed PHI and "failed to timely notify affected individuals of the breach," and it paid $375,000. OCR found that the Star Group, L.P. Health Benefits Plan, where an actor deployed ransomware and exfiltrated the PHI of about 9,316 people, had impermissibly disclosed PHI; the plan paid $245,000. The other two, Regional Women's Health Group and Consociate Health, paid $320,000 and $225,000 on risk analysis findings.

On July 29, 2026, OCR announced a $552,250 settlement with OSF Healthcare System, which it called its 21st ransomware enforcement action. OSF discovered Nephilim ransomware in April 2021 and filed a breach report in October 2021; the PHI of 53,907 individuals was exfiltrated. OCR's findings included impermissible disclosure and failing to provide timely breach notification both to affected individuals and to the Secretary. An earlier May 30, 2025 resolution with Comstar, LLC, a billing company that was a business associate of more than 70 covered entities, followed ransomware encryption of servers holding the ePHI of approximately 585,621 individuals. OCR called that its 13th ransomware enforcement action; Comstar paid $75,000.

The resolution agreements themselves were not reviewed for this article. The findings above are as OCR stated them in its press releases.

Background

For the underlying law rather than this development: Healthcare privacy law.

Frequently Asked Questions

Does ransomware count as a HIPAA breach if the attacker never copied the data?
On OCR's reading it can. The 2016 fact sheet treats encryption by the attacker as an acquisition, because the attacker has taken possession or control of the ePHI, which makes it an impermissible disclosure. A breach is then presumed under 45 CFR 164.402 unless a risk assessment shows a low probability of compromise. OCR also describes the question as fact-specific.
Can restoring from backups show a low probability of compromise after ransomware?
Backups bear on the fourth factor. The fact sheet says robust contingency and backup plans may show mitigation of the attack's impact on the integrity of PHI, but calls integrity only one aspect and treats exfiltration as part of the same question. It adds that a high risk to availability or integrity may itself indicate compromise.
Is health data that was encrypted at rest outside the notification rule after a ransomware attack?
Only if it was still unreadable when the ransomware reached it. PHI encrypted consistently with HHS guidance is not unsecured PHI. The fact sheet explains that full disk encryption often decrypts files transparently for a logged-in user on a running system, so ransomware launched in that session can reach decrypted files, and in that case a breach is presumed.
When does the 60-day HIPAA notification period start in a ransomware incident?
At discovery, which 164.404(a)(2) fixes as the first day the breach is known, or by reasonable diligence would have been known, to any workforce member or agent other than the person committing it. Sixty calendar days is the outer limit; the rule also requires notice without unreasonable delay.
Who has to prove that a ransomware incident was not a breach?
The regulated entity. Section 164.414(b) gives the covered entity or business associate the burden of demonstrating either that all required notifications were made or that the use or disclosure was not a breach. The fact sheet points to documentation maintained under 164.530(j) to meet that burden.

Sources

Everything above is reported from these documents. Follow them to verify.

  1. HHS Office for Civil Rights, Fact Sheet: Ransomware and HIPAA (July 11, 2016) agency guidance
  2. 45 CFR 164.402, Definitions (breach and unsecured protected health information) (September 14, 2026) regulation
  3. 45 CFR 164.404, Notification to individuals (September 14, 2026) regulation
  4. 45 CFR 164.406, Notification to the media (September 14, 2026) regulation
  5. 45 CFR 164.408, Notification to the Secretary (September 14, 2026) regulation
  6. 45 CFR 164.410, Notification by a business associate (September 14, 2026) regulation
  7. 45 CFR 164.412, Law enforcement delay (September 14, 2026) regulation
  8. 45 CFR 164.414, Administrative requirements and burden of proof (September 14, 2026) regulation
  9. HHS, Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules (Omnibus Rule), final rule (January 25, 2013) regulation
  10. HHS, Guidance to Render Unsecured Protected Health Information Unusable, Unreadable, or Indecipherable to Unauthorized Individuals agency guidance
  11. HHS, Submitting Notice of a Breach to the Secretary (February 13, 2026) agency guidance
  12. HHS Office for Civil Rights, Change Healthcare Cybersecurity Incident Frequently Asked Questions (March 14, 2025) agency guidance
  13. HHS, Office for Civil Rights Settles Four HIPAA Security Rule Ransomware Investigations (April 23, 2026) agency release
  14. HHS, Office for Civil Rights Settles Ransomware Investigation with Healthcare System (OSF Healthcare System) (July 29, 2026) agency release
  15. HHS, Office for Civil Rights Settles HIPAA Ransomware Cybersecurity Investigation with Comstar, LLC (May 30, 2025) agency release

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.