Quick answer
On April 23, 2026, OCR announced four simultaneous HIPAA ransomware settlements totaling $1,165,000, affecting more than 427,000 individuals. One of those settlements involved Consociate Health, a business associate (not a covered entity), whose ransomware incident triggered direct federal enforcement. Two other recent actions, against Comstar LLC (a medical billing company) and BST and Co. CPAs (an accounting firm), confirm that your vendors carry their own OCR exposure and that their failures can land at your door. Failure to conduct a written risk analysis was cited in every single 2025-2026 OCR ransomware enforcement action; every settled entity must also complete an OCR-monitored corrective action plan.
If you run a small medical, dental, or behavioral health practice, a ransomware attack on your billing company, accounting firm, or software vendor may not feel like your problem at first. But the pattern emerging from 2025-2026 OCR enforcement tells a different story: the attack does not have to hit your systems directly to put your practice under federal investigation.
This post walks through what the recent settlements actually say, what your legal obligations are once a business associate reports a breach, and what small practices, including those in Texas, should be doing now.
What do the 2026 ransomware settlements actually tell us?
The April 23, 2026 batch is notable for its breadth. Four entities settled with OCR on the same day, ranging from Assured Imaging Affiliated Covered Entities ($375,000, 244,813 individuals affected) to Regional Women’s Health Group d/b/a Axia Women’s Health ($320,000, approximately 37,989 individuals). Even Star Group, L.P. Health Benefits Plan, an employer-sponsored group health plan rather than a clinical practice, paid $245,000 after a ransomware attack exfiltrated the PHI of 9,316 health plan members, including Social Security numbers.
The common thread is not organization size or patient count. It is the absence of a documented risk analysis. OCR cited failure to conduct an accurate and thorough risk analysis under 45 CFR § 164.308(a)(1) in every settlement in this batch. As of April 23, 2026, OCR has completed 13 investigations under its dedicated Risk Analysis Initiative, which targets whether regulated entities have conducted the required written assessment of ePHI risks and vulnerabilities.
The penalty structure makes the stakes concrete. Under 45 CFR § 160.404, HIPAA civil money penalties range from $100 per violation at the lowest tier to a minimum of $50,000 per violation for willful neglect that is not corrected, with annual caps of $1,500,000 per violation category. Those amounts are adjusted annually for inflation; Federal Register document 2026-01688, published January 28, 2026, reflects the most recent adjustment. Every entity in the April 2026 batch must also complete a two-year OCR-monitored corrective action plan.
What happens when your business associate gets hit with ransomware?
Consociate, Inc. (d/b/a Consociate Health), a third-party health plan administrator, settled for $225,000 after a July 2020 phishing attack escalated to ransomware deployment in November-December 2021, exposing the ePHI of approximately 136,539 individuals. The 16-month gap between the initial phishing compromise and the ransomware deployment shows how long an attacker can sit inside a vendor’s network before the damage becomes visible. Consociate was a business associate, not a covered entity, but OCR enforced directly against it. Under 42 U.S.C. § 17934, business associates have been subject to the same civil and criminal HIPAA penalty provisions as covered entities since February 17, 2010.
Comstar LLC, a Massachusetts medical billing company serving more than 70 non-profit and municipal emergency ambulance services, settled for $75,000 on May 30, 2025, after a March 2022 ransomware attack exposed the ePHI of 585,621 individuals. A single business associate’s compliance failure cascaded to more than 70 covered-entity clients. BST and Co. CPAs, a New York public accounting firm, settled for $175,000 on August 18, 2025, after ransomware encrypted the ePHI it held on behalf of a physician-group client. An accounting firm, not a clinical entity, was investigated and penalized under the HIPAA Security Rule. The business associate definition at 45 CFR § 160.103 expressly includes persons providing accounting, financial, administrative, or management services to a covered entity where PHI is disclosed.
For small practices in Texas and elsewhere, this creates an exposure chain worth mapping carefully. Under 45 CFR § 164.314(a)(2)(i), your BAA must require the business associate to report any security incident of which it becomes aware, including breaches of unsecured PHI. Once the business associate notifies you, two clocks start simultaneously. Under 45 CFR § 164.410, the BA must notify you within 60 calendar days of discovery, and you then have 60 calendar days to ensure affected individuals receive notice. Texas practices face a parallel state obligation under Texas Business and Commerce Code § 521.053: if the breach affects 250 or more Texas residents, you must also notify the Texas Attorney General within 30 days of determining the breach occurred, a stricter timeline that runs at the same time as the federal notification clock. Texas Health and Safety Code Chapter 181 extends HIPAA-like obligations to entities not even subject to federal HIPAA, and the Texas Attorney General may seek civil penalties that can reach $1.5 million per year for a pattern or practice of violations.
Are small practices and their vendors actually being investigated?
Yes, and the data is consistent. Comprehensive Neurology, PC, a small New York neurology practice, settled for $25,000 on April 25, 2025, after a December 2020 ransomware attack encrypted all ePHI and may have exposed 6,800 patient records, including Social Security numbers and clinical data. Syracuse ASC, LLC (a single ambulatory surgery center) settled for $250,000 on July 23, 2025, after ransomware deployed in March 2021 affected the ePHI of 24,891 individuals. An employer-sponsored group health plan settled for $450,000 on June 18, 2026, after ransomware exposed the PHI (including Social Security numbers) of 10,023 plan members. Small businesses in Texas that sponsor self-funded group health plans should take note: they are covered entities under HIPAA and face direct OCR exposure.
On the threat side, hacking and IT incidents comprised 81% of reported HIPAA breaches affecting 500 or more individuals in 2024, affecting a combined 241,582,022 individuals, according to OCR’s 2024 Annual Report to Congress on Breaches of Unsecured PHI. According to At-Bay’s InsurSec Report, remote access tools such as VPNs and RDP were the initial entry vector for approximately 80% of ransomware claims, making unpatched or misconfigured remote access infrastructure the single most critical ransomware vulnerability for small healthcare practices.
The financial costs extend well beyond OCR penalties. According to the NetDiligence 2024 Cyber Claims Study, ransomware incidents that included recovery expenses averaged $961,000 in total cost, nearly 400% higher than incidents without recovery costs, and the average total incident cost for small-to-medium enterprises rose to $264,000. The Change Healthcare attack, which affected approximately 192.7 million individuals by the time Change Healthcare notified OCR on July 31, 2025, illustrates what happens when a business associate processing claims for hundreds of thousands of providers goes down: UnitedHealth Group reported $1.7 billion in direct response costs in its SEC 10-Q for the nine months ended September 30, 2024, and provided over $6 billion in advance funding to support care providers cut off from claims processing. Small practices felt that cash-flow disruption immediately.
The proposed HIPAA Security Rule overhaul (NPRM published January 6, 2025, with a final rule now targeted for July 2027) would eliminate the distinction between required and addressable implementation specifications, making all specifications mandatory, and would require regulated entities to restore critical electronic information systems and data within 72 hours of a disruption. The rule is not yet final as of this writing, but OCR’s current enforcement pace makes clear that waiting for a final rule is not a compliance strategy.
What to do next
The recurring finding across every 2025-2026 OCR ransomware settlement is the same: no documented risk analysis. That is the starting point, and it is within your control today.
A written risk analysis under 45 CFR § 164.308(a)(1) maps where your ePHI lives, who can access it, and what the realistic threats are, including threats that arrive through the business associates who handle your data on your behalf. From that foundation, you can audit your BAAs for the required security incident reporting provisions, test your contingency plans and backup procedures under 45 CFR § 164.308(a)(7), and document the security decisions you have already made before OCR asks to see them.
North Privacy Advisors works with small and mid-size healthcare practices to conduct HIPAA risk analyses, review business associate agreements, and build defensible compliance programs. If you want to understand your current exposure before OCR does, start with our HIPAA Risk Analysis service.
Last Updated: July 20, 2026