On June 18, 2026, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) announced a $450,000 settlement and a two-year corrective action plan (CAP) against Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans (the Plan), arising from potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), Privacy, Security, and Breach Notification Rules (HIPAA Rules).
Employee complaints lead to discovery of ransomware attack
The Plan is an employer-sponsored group health plan of Spencer Gifts LLC, a national retail company. The matter stemmed from a breach self-reported by the Plan to OCR in June 2024. Employee complaints initiated an investigation, which revealed that, in November 2021, the Spencer Gifts’ network was accessed by an unauthorized actor deploying ransomware, encrypting data on the company’s systems, including servers that store the Plan’s protected health information (PHI), and demanding ransom. OCR reported that potentially 10,023 individuals were impacted by the breach, which included health plan members’ names, addresses, ZIP codes, phone numbers, and Social Security numbers.
Risk analysis and reasonable policies and procedures remain essential
As a result of its investigation, OCR determined that the potential noncompliance centered on the Plan’s failure to conduct an accurate risk analysis and implement reasonable and appropriate policies and procedures prior to the breach to ensure compliance with HIPAA Rules. This marks OCR’s 14th Risk Analysis Initiative enforcement action and emphasizes the importance of risk analysis to prevent or mitigate a cyberattack. Risk analysis remains one of the most closely examined areas of HIPAA Rule compliance.
As a part of the resolution, the Plan agreed to a two-year CAP, requiring it to conduct a comprehensive risk analysis to identify vulnerabilities affecting the confidentiality and integrity of electronic PHI (ePHI). Furthermore, the Plan must review and revise its HIPAA Rule compliance and related policies and procedures and conduct training for its workforce members on the updated HIPAA policies and procedures.
Takeaways
This settlement serves as a reminder from the OCR director, Paula M. Stannard, that “effective cybersecurity starts with Security Rule compliance” and highlights the importance of taking a proactive approach to cybersecurity before a cyberattack takes place. With the drastic rise in ransomware attacks over the past few years, HIPAA-regulated entities must develop and implement adequate policies and procedures to safeguard their systems from potential cyberattacks and data breaches. This includes determining where the ePHI exists in the organizations’ pathways, ensuring audit controls are in place, implementing regular monitoring procedures to prevent a breach of PHI, and creating safeguards to ensure only authorized users access ePHI.
OCR’s continued push under its Risk Analysis Initiative reminds covered entities and business associates alike of the importance of periodically conducting enterprise-wide risk analyses, including after significant events such as ransomware attacks, and updating the corresponding risk management plan with identified vulnerabilities and remediation timelines.


