Susan B. Allen Memorial Hospital Breach: What Compliance Teams Should Take Away

August 13, 2026

On this page

Ready to be survey-ready?

See how AccrediCulture turns compliance into an operating system across every facility.

The short answer for compliance teams

Compliance officers should read the Susan B. Allen Memorial Hospital matter as a live case study in the three failures OCR keeps citing: an incomplete Security Rule risk analysis under 45 CFR §164.308(a)(1), weak technical safeguards under §164.312, and slow or incomplete breach notification workflows under §164.404. The El Dorado, Kansas hospital disclosed a targeted cyberattack in July 2025, and a class-action settlement was reached that pays affected patients up to $100 plus credit monitoring, with a final approval hearing set for December 7, 2026.

The pattern is familiar. When OCR investigates a breach of this profile, it typically demands a multi-year Corrective Action Plan (CAP) with documented remediation, board-level attestation, and periodic reporting. OCR resolved 785 data breach investigations in 2024, including 12 with resolution agreements, corrective action plans, and monetary settlements or civil monetary penalties, and every single one turned on the same fundamentals. Treat the Susan B. Allen incident as the checklist you use to test your own program this quarter.

The §164 citations OCR keeps writing (and what they mean for your CAP)

Susan B. Allen Memorial Hospital Breach: What Compliance Teams Should Take Away — The §164 citations OCR keeps writing (and what they mean for your CAP)

Look at OCR’s Risk Analysis Initiative, launched in late 2024. In every single case under the initiative, OCR indicated that the regulated entities failed to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all its ePHI. That is not a paperwork ding. That is the finding that unlocks the CAP.

Ransomware sits at the center of this shift. The Risk Analysis Initiative comes as OCR reported a 264% increase in reported large breaches involving ransomware attacks since 2018. The recent Guam Memorial Hospital case shows how OCR handles hospital ransomware: a public hospital in Guam experienced a ransomware attack affecting the ePHI of approximately 5,000 patients, with a settlement amount of $25,000 issued on April 17, 2025.

When we work with compliance directors on CAP-readiness, we map every §164 sub-section to a specific artifact: the NIST SP 800-30 risk assessment methodology output, the §164.308(a)(1)(ii)(B) risk management plan, the §164.312(a)(1) unique user IDs and audit controls, and the §164.404 patient notification log. If a surveyor or OCR investigator asks to see any one of those, you should be able to open a single command center view and hand it over. That is the difference between a 30-day scramble and a same-day response.

What a single-platform command center actually proves to a surveyor

Susan B. Allen Memorial Hospital Breach: What Compliance Teams Should Take Away — What a single-platform command center actually proves to a surveyor

Kansas has its own breach notification statute (K.S.A. 50-7a02), which stacks on top of §164.404. Add The Joint Commission’s Information Management standards and CMS Conditions of Participation, and a hospital compliance director is proving the same remediation to three or four different audiences. That is where fragmentation kills you.

Here is what we help compliance teams consolidate into one system:

  • Risk analysis of record. The current NIST SP 800-30 assessment, the §164.308(a)(1)(ii)(B) risk management plan, and every mitigation dated and owned.
  • Access controls and audit logs. §164.312(a) and (b) evidence, with re-credentialing and PSV tied to the same record.
  • Incident and grievance log. Every event, every 60-day patient notification clock, every state AG notification, every media notice if the breach exceeds 500 individuals.
  • Policy attestations. Workforce training completions tied to the policy version in force at the time of the incident.
  • CAPA tracking. Root cause, corrective action, owner, due date, evidence of closure. Surveyor-ready.

When you can walk a Joint Commission surveyor, a CARF surveyor, an OCR investigator, and your board through the same screen, you are continuously ready. Not scrambling in survey week. That is what audit-ready looks like in practice, and it is common sense once the pieces live in one place.

Frequently asked questions

What HIPAA violations did OCR cite in the Susan B. Allen Memorial Hospital matter?
The publicly available information to date centers on a class-action settlement resolving allegations that Susan B. Allen Memorial Hospital failed to adequately protect patient data during a targeted cyberattack in July 2025. In similar breach investigations, OCR typically cites §164.308(a)(1) risk analysis failures, §164.312 technical safeguards gaps, and §164.404 breach notification timing issues.

What corrective action plan requirements typically follow an OCR HIPAA settlement?
A CAP usually runs two to three years and requires a fresh enterprise-wide risk analysis, a revised risk management plan, updated policies and procedures, workforce training, and periodic reports to OCR. Every deliverable requires documentation the covered entity can produce on demand.

How long do covered entities have to report a breach under the HIPAA Breach Notification Rule?
Under 45 CFR §164.404, individual notification must be made without unreasonable delay and in no case later than 60 calendar days after discovery of the breach. Breaches affecting 500 or more individuals also require notice to HHS and prominent media outlets within that window.

What does an OCR-compliant Security Rule risk analysis under 45 CFR §164.308(a)(1) actually require?
An accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all ePHI held by the covered entity, using a repeatable methodology such as NIST SP 800-30, with documented findings, prioritized mitigations, and evidence of periodic updates.

How should hospitals document breach-response and incident-management activities to withstand OCR scrutiny?
Log every incident with root cause, containment actions, patient and regulator notifications, and CAPA closure evidence in a single source of truth. Tie each entry to the policy version in force at the time and the workforce members trained on it. If you can produce that trail in one export, you are ready.

Scroll to Top