started · updated
HIPAA enforcement highlights rising healthcare data breach costs and notification rules
Healthcare organizations faced record-breaking financial consequences for data security failures in 2025, paying approximately $148 million in HIPAA fines. This total was driven significantly by a $126 million settlement involving Change Healthcare. During the same period, data breaches exposed 168 million patient records, with the average cost of a healthcare breach reaching $93 million.
Regulatory enforcement highlights critical compliance requirements regarding breach notifications. A recent settlement involving OSF Healthcare underscores that the 60-day HIPAA breach notification deadline begins on the day a breach is discovered, rather than when a forensic investigation is completed. OSF Healthcare faced investigation after a 110-day delay in notifying the U.S. Department of Health and Human Services (HHS) following a ransomware attack.
Authorities have clarified that ransomware incidents are presumed to constitute HIPAA breaches, requiring organizations to initiate response processes and record discovery dates immediately upon identification.
Entities
HIPAA · OSF HealthCare · Office for Civil Rights · U.S. Department of Health and Human Services