Skip to content
OSHA Review toll free phone number 800-555-6248

HHS OCR Settles Ransomware HIPAA Investigation: Lessons for Dental Practices

The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a $450,000 settlement with a health plan in June 2026 following an investigation into a ransomware attack. The case marks OCR’s 20th ransomware enforcement action and the 14th resolution under its Risk Analysis Initiative — a pattern of enforcement that sends a clear message to all HIPAA-covered entities, including dental practices: having a current, documented HIPAA Security Risk Analysis is not optional.

This post is part of our Dental Bytes eNewsletter 2026 hub, where you can access each monthly issue.

What Happened

In November 2021, the Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans health plan experienced a ransomware attack that resulted in a breach of protected health information (PHI) affecting 10,023 individuals. OCR’s investigation, announced on June 18, 2026, found that the health plan had failed to comply with multiple provisions of the HIPAA Security Rule:

  • Failure to conduct a required Security Risk Analysis. OCR found that the plan had not performed an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic PHI (ePHI).
  • Failure to implement sufficient policies and procedures to reduce identified risks and vulnerabilities to a reasonable and appropriate level.

As part of the settlement, the health plan agreed to pay $450,000 and implement a two-year corrective action plan (CAP) covering risk analysis, policy revision, and workforce training. The plan did not admit wrongdoing.

Why This Matters for Dental Practices

Dental practices are HIPAA-covered entities and face the same enforcement landscape as health plans and hospitals. OCR’s Risk Analysis Initiative has made the Security Risk Analysis the centerpiece of its enforcement priorities — and this is the 14th case in a row where failure to conduct a risk analysis was a primary violation cited.

The pattern is clear: when a ransomware attack triggers an OCR investigation, the first thing investigators look for is whether the covered entity had a current, documented risk analysis. Practices without one are exposed not just to the costs of the breach itself, but to significant civil money penalties on top of it.

Ransomware is also a growing threat in the dental sector. Attackers know that dental practices store valuable patient data and often operate with smaller IT teams and fewer security resources than large hospital systems. That makes dental offices attractive targets.

What Your Dental Practice Must Have in Place

This settlement is a checklist for every dental practice to run through:

  • Conduct a HIPAA Security Risk Analysis. This is the foundational requirement under the HIPAA Security Rule. The risk analysis must be accurate, thorough, and documented. It must cover all ePHI your practice creates, receives, maintains, or transmits — including data in your practice management software, email, and any cloud storage.
  • Update the risk analysis regularly. A one-time analysis is not sufficient. The risk analysis must be reviewed and updated when there are changes to operations, technology, or the threat environment.
  • Implement a risk management plan. Once risks are identified, practices must implement reasonable and appropriate security measures to reduce those risks. Documenting this plan and your actions is critical.
  • Develop and maintain HIPAA security policies and procedures. Written policies that address workforce training, access controls, incident response, and sanctions must be in place and kept current.
  • Train all workforce members. HIPAA requires regular workforce training on security policies and procedures. Document who was trained, when, and on what topics.
  • Have an incident response plan. Know how your practice will respond to a ransomware attack or other security incident before it happens. The plan should cover containment, breach assessment, notification obligations, and recovery steps.

Quick Summary

  • HHS OCR settled its 20th ransomware enforcement action for $450,000 after a 2021 breach of 10,023 individuals’ PHI.
  • The primary violations: failure to conduct a Security Risk Analysis and failure to implement adequate policies.
  • This is the 14th case under OCR’s Risk Analysis Initiative — a clear enforcement signal to all covered entities.
  • Dental practices must have a current, documented HIPAA Security Risk Analysis and a written risk management plan.
  • Regular workforce training and a documented incident response plan are also required and will be scrutinized in any OCR investigation.

Related OSHA Review Resources


About OSHA Review, Inc.
Since 1992, OSHA Review, Inc. has supported dental professionals with regulatory compliance resources, infection control guidance, continuing education, sterilizer monitoring, surface disinfectant products, and dosimetry monitoring services. For more information, visit oshareview.com or call 800-555-6248.

This post is part of the Dental Bytes eNewsletter 2026 series. Visit the hub to access all monthly updates.

Morgan Lawson is the Chief Operations Officer and Managing Editor at OSHA Review, Inc., where he has led dental compliance education and operations since 1999. With over 25 years of experience in OSHA regulations, infection control standards, and dental practice compliance, Morgan oversees the development of content, training programs, and compliance resources trusted by dental practices nationwide.

Back To Top
Search