< Back to all clusters
[HEALTH] · United States · 2 sources

started · updated

HIPAA enforcement highlights rising healthcare data breach costs and notification rules

Healthcare organizations faced record-breaking financial consequences for data security failures in 2025, paying approximately $148 million in HIPAA fines. This total was driven significantly by a $126 million settlement involving Change Healthcare. During the same period, data breaches exposed 168 million patient records, with the average cost of a healthcare breach reaching $93 million.

Regulatory enforcement highlights critical compliance requirements regarding breach notifications. A recent settlement involving OSF Healthcare underscores that the 60-day HIPAA breach notification deadline begins on the day a breach is discovered, rather than when a forensic investigation is completed. OSF Healthcare faced investigation after a 110-day delay in notifying the U.S. Department of Health and Human Services (HHS) following a ransomware attack.

Authorities have clarified that ransomware incidents are presumed to constitute HIPAA breaches, requiring organizations to initiate response processes and record discovery dates immediately upon identification.

Entities

HIPAA · OSF HealthCare · Office for Civil Rights · U.S. Department of Health and Human Services