Immune — Self Heal, an iStudio Technologies product
Compliance31 Jul 2026 · 6 min read

Is a ransomware attack a HIPAA breach?

One of the most consequential questions a hospital faces after a ransomware attack is deceptively simple: do we have to report it? Federal guidance answers more firmly than many organizations expect, and getting the analysis wrong carries its own penalties.

By Immune Threat Research

The presumption of a breach

US federal guidance is direct: when ransomware encrypts electronic protected health information (ePHI), a breach is presumed to have occurred. The reasoning is that the data was 'acquired' — the ransomware took control of it — which counts as an unauthorized disclosure under the HIPAA Breach Notification Rule.

That presumption can be rebutted, but the burden is on the organization. You must demonstrate, through a documented risk assessment, that there is a low probability the PHI was compromised. Absent that, notification obligations apply.

The four-factor risk assessment

Rebutting the presumption means working through the Breach Notification Rule's risk assessment, which weighs factors including the nature and extent of the PHI involved, who accessed or acquired it, whether it was actually viewed or exfiltrated, and the extent to which the risk has been mitigated.

Here is the practical trap: many organizations cannot answer these questions with confidence because they lack the visibility. If you can't prove what an attacker touched, you can't argue low probability of compromise — so the breach presumption stands, and you notify.

  • Was the ePHI encrypted (by you) before the attack? Properly encrypted data may fall under a safe-harbor.
  • Can you show what the attacker accessed and whether data left the environment?
  • Do you have immutable logs that a regulator will accept as evidence?

Notification timelines

If notification is required, the clock matters. Affected individuals and HHS must be notified without unreasonable delay and no later than 60 days from discovery. Breaches affecting 500 or more people in a jurisdiction also trigger media notification and prompt HHS posting on its public breach portal.

Modern double-extortion attacks — where data is stolen before encryption — make the breach determination even clearer, since exfiltration is a disclosure by any reading.

How visibility changes the outcome

The difference between a manageable incident and a compliance crisis often comes down to evidence. An organization that can show, with tamper-proof records, exactly what an attacker reached and whether data left is in a far stronger position — both to rebut the breach presumption where legitimate and to notify accurately where required.

Immune's immutable audit logging and network-level visibility are designed for precisely this. By recording what happened during an incident in a form that can't be altered, and by surfacing exfiltration as it occurs, Immune helps hospitals make the breach determination on facts rather than assumptions — and supports the notification obligations that follow.

Sources

Figures are drawn from the cited sources and were current as of publication. Content was rephrased for compliance with source licensing.

Turn this threat intelligence into resilience

See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems — whatever group is behind the next attack.

Talk to us

See Immune protect your organization

Tell us about your environment and our team will show you exactly how Immune detects, contains, and self-heals through a ransomware attack — including the connected devices your current tools can't reach. We respond within one business day.

  • A working demo on a realistic scenario
  • Agentless coverage for medical and connected devices
  • On-premises and data-sovereignty deployment options
  • A frank look at where Immune fits alongside your stack

Request your demo

Tell us a little about your organization and we'll be in touch.

By submitting, you agree to be contacted about Immune. We respect your privacy and never share your details. See our privacy policy.