Susan B. Allen Memorial Hospital Breach: What Compliance Teams Should Take Away
August 13, 2026
On this page
Ready to be survey-ready?
The short answer for compliance teams
Compliance officers should read the Susan B. Allen Memorial Hospital matter as a live case study in the three failures OCR keeps citing: an incomplete Security Rule risk analysis under 45 CFR §164.308(a)(1), weak technical safeguards under §164.312, and slow or incomplete breach notification workflows under §164.404. The El Dorado, Kansas hospital disclosed a targeted cyberattack in July 2025, and a class-action settlement was reached that pays affected patients up to $100 plus credit monitoring, with a final approval hearing set for December 7, 2026.
The pattern is familiar. When OCR investigates a breach of this profile, it typically demands a multi-year Corrective Action Plan (CAP) with documented remediation, board-level attestation, and periodic reporting. OCR resolved 785 data breach investigations in 2024, including 12 with resolution agreements, corrective action plans, and monetary settlements or civil monetary penalties, and every single one turned on the same fundamentals. Treat the Susan B. Allen incident as the checklist you use to test your own program this quarter.
The §164 citations OCR keeps writing (and what they mean for your CAP)
Look at OCR’s Risk Analysis Initiative, launched in late 2024. In every single case under the initiative, OCR indicated that the regulated entities failed to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all its ePHI. That is not a paperwork ding. That is the finding that unlocks the CAP.
Ransomware sits at the center of this shift. The Risk Analysis Initiative comes as OCR reported a 264% increase in reported large breaches involving ransomware attacks since 2018. The recent Guam Memorial Hospital case shows how OCR handles hospital ransomware: a public hospital in Guam experienced a ransomware attack affecting the ePHI of approximately 5,000 patients, with a settlement amount of $25,000 issued on April 17, 2025.
When we work with compliance directors on CAP-readiness, we map every §164 sub-section to a specific artifact: the NIST SP 800-30 risk assessment methodology output, the §164.308(a)(1)(ii)(B) risk management plan, the §164.312(a)(1) unique user IDs and audit controls, and the §164.404 patient notification log. If a surveyor or OCR investigator asks to see any one of those, you should be able to open a single command center view and hand it over. That is the difference between a 30-day scramble and a same-day response.
The real cost, and the real timeline, of a healthcare breach
Boards ask two questions after any breach: how much and how long. Give them real numbers. According to IBM’s 2025 Cost of a Data Breach Report, U.S. Data breaches set a new record at $10.22 million, increasing by 9.2% from an average of $9.36 million in 2024, largely due to higher regulatory fines and detection and escalation costs. Healthcare specifically? Healthcare data breaches took the longest to identify and contain, at an average of 279 days.
The regulatory context matters too. OCR issued 22 financial penalties during 2024, and total collected settlements and penalties reached $9,944,612, with penalties issued to entities across healthcare for risk analysis deficiencies, insufficient security measures, access control failures, and weaknesses in breach notification processes. As OCR Director Melanie Fontes Rainer said in the Memorial Healthcare System right of access settlement, “Health care entities must be responsive to their patients’ requests for their medical records.” The same standard of responsiveness applies to breach notification.
What a single-platform command center actually proves to a surveyor
Kansas has its own breach notification statute (K.S.A. 50-7a02), which stacks on top of §164.404. Add The Joint Commission’s Information Management standards and CMS Conditions of Participation, and a hospital compliance director is proving the same remediation to three or four different audiences. That is where fragmentation kills you.
Here is what we help compliance teams consolidate into one system:
- Risk analysis of record. The current NIST SP 800-30 assessment, the §164.308(a)(1)(ii)(B) risk management plan, and every mitigation dated and owned.
- Access controls and audit logs. §164.312(a) and (b) evidence, with re-credentialing and PSV tied to the same record.
- Incident and grievance log. Every event, every 60-day patient notification clock, every state AG notification, every media notice if the breach exceeds 500 individuals.
- Policy attestations. Workforce training completions tied to the policy version in force at the time of the incident.
- CAPA tracking. Root cause, corrective action, owner, due date, evidence of closure. Surveyor-ready.
When you can walk a Joint Commission surveyor, a CARF surveyor, an OCR investigator, and your board through the same screen, you are continuously ready. Not scrambling in survey week. That is what audit-ready looks like in practice, and it is common sense once the pieces live in one place.
Frequently asked questions
What HIPAA violations did OCR cite in the Susan B. Allen Memorial Hospital matter?
The publicly available information to date centers on a class-action settlement resolving allegations that Susan B. Allen Memorial Hospital failed to adequately protect patient data during a targeted cyberattack in July 2025. In similar breach investigations, OCR typically cites §164.308(a)(1) risk analysis failures, §164.312 technical safeguards gaps, and §164.404 breach notification timing issues.
What corrective action plan requirements typically follow an OCR HIPAA settlement?
A CAP usually runs two to three years and requires a fresh enterprise-wide risk analysis, a revised risk management plan, updated policies and procedures, workforce training, and periodic reports to OCR. Every deliverable requires documentation the covered entity can produce on demand.
How long do covered entities have to report a breach under the HIPAA Breach Notification Rule?
Under 45 CFR §164.404, individual notification must be made without unreasonable delay and in no case later than 60 calendar days after discovery of the breach. Breaches affecting 500 or more individuals also require notice to HHS and prominent media outlets within that window.
What does an OCR-compliant Security Rule risk analysis under 45 CFR §164.308(a)(1) actually require?
An accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI held by the covered entity, using a repeatable methodology such as NIST SP 800-30, with documented findings, prioritized mitigations, and evidence of periodic updates.
How should hospitals document breach-response and incident-management activities to withstand OCR scrutiny?
Log every incident with root cause, containment actions, patient and regulator notifications, and CAPA closure evidence in a single source of truth. Tie each entry to the policy version in force at the time and the workforce members trained on it. If you can produce that trail in one export, you are ready.
References
- Susan B. Allen Memorial Hospital Data Breach Settlement summary
- HIPAA Journal: OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2024
- calHIPAA: 2024 OCR Annual Reports Detail HIPAA Compliance Activity and Data Breaches
- Feldesman LLP: OCR’s Risk Analysis Initiative Yields Seven HIPAA Enforcement Actions
- HIPAA Journal: Average Cost of a Healthcare Data Breach (IBM 2025 Report)
- HHS OCR Resolution Agreements and Civil Money Penalties
- HIT Leaders and News: OCR Settlement with Memorial Healthcare System