HomeBlogCompliance & regulatory
Is ransomware a HIPAA breach? The PT practice playbook
OCR presumes it is, and its April 2026 settlements show what investigators want afterward. Deadlines, the calls to make, and the paperwork that sets the fine.

The short version
- OCR has treated ransomware as a presumed HIPAA breach since 2016: encrypting the chart is an unauthorized acquisition, and the burden is on you to prove a low probability of compromise.
- Affected individuals get written notice within 60 days of discovery. HHS is told at the same time if 500 or more people are affected, otherwise in the annual log due 60 days after year end. State law runs a second clock.
- All four of OCR's April 2026 ransomware settlements, $1,165,000 in total, cited the same failure: no accurate and thorough risk analysis before the attack.
- Offline, tested backups, MFA, and a written incident response plan with named roles are what HHS's own small-practice guide and the FBI recommend.
The ransom note is rarely the first sign. It is the front desk at 7:40 on a Monday, unable to open the schedule, and a server that will not boot. The demand is the last step; the break-in came earlier, sometimes months earlier.
That gap is visible in the cases HHS’s Office for Civil Rights settles. On April 23, 2026, OCR announced four ransomware settlements totaling $1,165,000 for breaches that exposed the records of more than 427,000 people. One of the four, Consociate Health, was compromised through a phishing email about six months before the ransomware was discovered in January 2021. Every one of the four was cited for the same thing: no accurate and thorough risk analysis before the attack.
A 2-15 provider PT practice is not too small for this. The FBI’s 2025 Internet Crime Report logged 460 ransomware complaints from the healthcare and public health sector, more than any other of the 16 critical infrastructure sectors it tracks. HHS’s own cybersecurity guide for small health care organizations says the data “suggests smaller ambulatory practices are also targeted and can suffer greater proportional damages.”
Is ransomware a HIPAA breach?
Yes, presumptively. OCR’s position since July 2016, summarized by Arnall Golden Gregory, is that ransomware encrypting protected health information means an unauthorized party has taken possession of it. That is an “acquisition,” and therefore a “disclosure” the Privacy Rule does not permit.
Under the Breach Notification Rule’s definitions, that acquisition is presumed to be a breach unless you can show a “low probability that the protected health information has been compromised.” Four factors decide it: what information was involved and how identifiable it is, who got it, whether it was actually acquired or viewed, and how far the risk has been mitigated.
The burden of proof is on the practice, and the analysis has to be documented well enough to survive an investigator reading it two years later. And “the backups restored fine” is no defense against notification. CISA’s #StopRansomware Guide calls the current playbook “double extortion”: attackers exfiltrate the data, then encrypt, then threaten to publish. HIPAA Journal’s August 2026 breach roundup has a live example, Texas Hearing Institute, where the Interlock group leaked what it had taken, a sign the ransom went unpaid. Assume exfiltration until forensics proves otherwise.
What do you do in the first 24 hours?
Isolate first, investigate second. CISA’s checklist puts it at the top: “Determine which systems were impacted, and immediately isolate them.” If several machines are hit, take the network offline at the switch, or pull the ethernet cable and Wi-Fi on every affected device. Do not power down or wipe anything unless disconnecting is impossible. The memory on an infected machine is evidence, and the guide warns that “dropper” malware has to be identified before anyone rebuilds from backups.
Then make calls, in roughly this order. Your IT provider. A lawyer who handles breach response, because the forensic work is better managed under privilege. Your cyber insurer, because the policy sets notice terms and can name the forensics firm. CISA, your local FBI field office, or IC3 online, which the CISA checklist recommends. HHS’s small-practice guide assumes you have no security staff and still expects a written incident response plan with named roles. In a 2-15 provider practice the incident commander is the owner; the plan should say so before the morning it is needed.
While that happens, the clinic still has patients at 8:00. Paper downtime forms, a printed schedule from last night, and a way to know who is walking in are the difference between a bad day and a canceled week.
What are the HIPAA notification deadlines?
The clock starts at discovery, and discovery is defined against you. Under the individual notice rule, a breach counts as discovered on the first day it is known to the practice “or, by exercising reasonable diligence would have been known.” From there:
- Every affected individual gets written notice “without unreasonable delay and in no case later than 60 calendar days after discovery.” The letter says what happened, what kinds of information were involved, what the person should do, what you are doing about it, and how to reach you.
- If 500 or more people are affected, HHS is notified at the same time through its breach portal. If more than 500 of them live in one state, prominent media outlets in that state get notice too, on the same 60-day clock.
- If fewer than 500 are affected, you log the breach and report it to HHS within 60 days after the end of the calendar year. For anything discovered in 2026, that is March 1, 2027.
- A business associate that discovers a breach, whether your billing company, your IT vendor, or your EHR, owes you notice on the same 60-day outer limit, naming the individuals involved. Your BAA can require faster, and should.
Sixty days is the ceiling, not the target; Assured Imaging, one of April’s four, was cited for missing it. And HIPAA is one clock of two. The National Conference of State Legislatures counts breach notification laws in all 50 states plus the District of Columbia, Guam, Puerto Rico and the Virgin Islands, each with its own definitions and timing. Do not let the federal deadline lull you past a shorter state one.
What does OCR investigate after you report?
The paperwork you had before the attack. Assured Imaging, 244,813 people, $375,000: OCR found it had never conducted a compliant risk analysis. Regional Women’s Health Group, 37,989 people, $320,000: inadequate risk analysis. Star Group’s health plan, 9,316 people, $245,000: inadequate risk analysis. Consociate, 136,539 people, $225,000: the same. OCR’s own count, repeated in Nixon Peabody’s update, stands at 19 completed ransomware investigations and 13 completed under its Risk Analysis Initiative. All four new settlements carry two years of OCR monitoring. OCR Director Paula M. Stannard’s line in the announcement: “Hacking and ransomware are the most frequent type of large breach reported to OCR.”
The tail is long: Cascade Eye and Skin Centers in Washington settled for $250,000 in September 2024 over a ransomware attack from 2017, again for a missing compliant risk analysis. Being the victim of a crime does not end the inquiry.
For a PT practice, the risk analysis can be a few pages. A written inventory of where PHI actually sits (the EHR, the front-desk PCs, email, the scanned intake forms on the shared drive, the laptop the biller takes home), what could go wrong with each, and what you did about it. It is the same document the pending Security Rule overhaul would spell out in more detail, and investigators are already grading it under the rule in force today.
What should be in place before it happens?
Start with what the FBI and HHS both put first: backups that ransomware cannot reach. The IC3 report’s recommendations open with off-site or offline backups that are encrypted and immutable, and go on to least-privilege accounts, MFA on every service you can, and patching. CISA’s guide adds the part practices skip: “regularly test the availability and integrity of backups in a disaster recovery scenario.” A backup nobody has restored from is a hope.
Then the plan. HHS’s small-practice volume defines an incident response plan as “a set of instructions offering a structured approach to detect, resolve, and restore the damage sustained after a cybersecurity incident.” It lists the roles: an incident commander, legal, a privacy and compliance function doing the breach assessment, someone handling communications. Shrink the table to fit your staff, but put a name and a Sunday phone number in every row.
Then the policy. The same HHS guide notes that “many policies require you have a minimum level of security controls in place” and recommends coverage for extortion specifically. Read the conditions before the incident.
And the software. A cloud EHR moves the chart, the backups, the encryption, and the restore window onto the vendor’s engineering, which is the argument in cloud versus server-based EHR. It does not move your obligations: the BAA should state the vendor’s breach notice timing, access should end the day a tech leaves, and your email needs MFA wherever the chart lives. Orion signs a BAA, encrypts data in transit and at rest, and keeps an audit log of who opened what; the details are in Is Orion HIPAA compliant?. The same HIPAA Journal roundup lists SportsMed Physical Therapy in Glen Rock, New Jersey, whose breach, reported to HHS as affecting 3,400 people, was covered this month and traced to one compromised email account. No ransomware, no server, one inbox. Write the plan for that shape too.
The FBI notes that its ransomware loss figure leaves out lost business, downtime, and third-party remediation. For a practice, those are the bill: the notification letters, the forensics invoice, the two-year corrective action plan, and the week the schedule ran on paper. Every one of them shrinks with a tested backup and a risk analysis on file, and OCR has just said so four times in one day.
Book a live demo
See Orion run your practice.
A PT-specific walkthrough, transparent pricing, and straight answers. Your current EHR stays live the whole time.
