OSF is a large system, but every requirement OCR cited applies to a 3-person clinic the same way it applies to a hospital network. The lead finding (no accurate and thorough risk analysis of the systems that create, receive, maintain, or transmit ePHI) is the single item OCR has flagged most often across recent ransomware settlements. If your practice cannot produce a current written risk analysis that names every device, cloud service, and app that touches PHI, you are exposed on the same theory OSF was.

The breach-notification findings matter just as much for a small practice, because the clock is short and the rule is unforgiving. OSF discovered the intrusion in April 2021, confirmed data theft in August 2021, and did not notify patients or HHS until October 1, 2021. For breaches affecting 500 or more people, HHS must be notified without unreasonable delay and no later than 60 days from discovery, and affected individuals must be notified in the same 60-day window. A small practice with one ransomware event and a slow incident response can miss those deadlines in the same way.

The corrective action plan is the practical read of the settlement: complete an inventory of every system that touches ePHI, run a documented risk analysis against that inventory, and build a written risk management plan with a timeline for fixing what the analysis surfaces. That is the same evidence trail a small practice should be able to hand an OCR investigator on day one, not day 60 of an investigation.

What to check in your practice