OnePoint Patient Care and Clay-Platte Family Medicine Settle Data Breach Lawsuits

Individuals affected by data breaches at OnePoint Patient Care and Clay-Platte Family Medicine may be entitled to claim benefits after settlements have been agreed to resolve class action lawsuits. The lawsuit against OnePoint Patient Care has been settled for $2,115,000, and the Clay-Platte Family Medicine lawsuit has been settled for $1,000,000.

OnePoint Patient Care Data Breach Settlement

OP Pharmacy, LLC, also known as OnePoint Patient Care, LLC, a Kentucky-based hospice-dedicated pharmacy and pharmacy benefits manager, was sued in response to a 2024 data breach. The lawsuit relates to a security incident detected by OnePoint on August 8, 2024. Hackers gained access to systems containing the protected health information of 1,741,152 individuals and copied files from its network between August 6 and August 8, 2024. At the time the lawsuit was filed, approximately 528,000 patients were living. Notification letters were mailed to the affected individuals in October and November, 2024

The lawsuit alleged that the defendant willfully, recklessly, or negligently maintained patient data, as it failed to implement appropriate cybersecurity measures and did not keep its systems free of vulnerabilities. Two lawsuits were filed in response to the breach, which were consolidated as they had overlapping claims. The consolidated lawsuit – Christopher Russo v. OP Pharmacy, LLC a/k/a OnePoint Patient Care, LLC – was filed in the District Court for the Western District of Kentucky, Louisville Division. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, breach of fiduciary duty, and for declaratory and injunctive relief.

The defendant disagrees with the claims and contentions in the lawsuit; however, a settlement was negotiated to avoid the cost and risks associated with a trial and related appeals. OnePoint will establish a $2,115,000 settlement fund, from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives will be deducted. The remaining funds will pay for class member benefits.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

A claim may be submitted for one of two cash payments: reimbursement of documented, unreimbursed losses due to the data breach up to $3,500 per class member, or an alternative pro rata cash payment, estimated to be $100 per claimant. The cash payments will be subject to a pro rata increase or decrease, depending on the number of valid claims received. In addition, OnePoint has agreed to implement additional security measures to reduce the risk of similar breaches in the future. The deadline for exclusion and opting out is August 24, 2026. The deadline for submitting a claim is October 8, 2026, and the final fairness hearing is scheduled for September 23, 2026.

Clay-Platte Family Medicine Data Breach Settlement

Clay-Platte Family Medicine and Barry Pointe Family Care in Kansas City, Missouri, and Cobblestone Family Medicine Clinic dba Clay Platte Family Medicine Clinic and Nathan D. Granger, dba Summit Family and Sports Medicine in Harrisonville, Missouri, were sued in response to a June 2024 data breach involving the electronic protected health information of patients. Hackers gained access to its network on or around June 26, 2024, and potentially viewed or obtained patient data such as names, contact information, dates of birth, Social Security numbers, and medical information.

Multiple class action lawsuits were filed in response to the data breach, which were consolidated into a single action – Highfill, et al. v. Clay-Platte Family Medicine Clinic, P.C., et al – in the U.S. District Court for the Western District of Missouri. The consolidated lawsuit alleged that the defendants failed to implement reasonable and appropriate safeguards to ensure the privacy of patient data, such as the encryption of data on its network. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, invasion of privacy by public disclosure of private facts, breach of fiduciary duty of confidentiality, negligent training and supervision, invasion of privacy, and violations of the Missouri Merchandising Practices Act.

The defendants deny any wrongdoing and sought to have the lawsuit dismissed. The motion to dismiss was granted in part, although certain claims were allowed to proceed. Following mediation and continued negotiations, a settlement was agreed to by all parties. The settlement class consists of the 53,916 individuals who were notified about the data breach. A $1,000,000 settlement fund will be established to pay for court-approved costs and benefits for the class members.

All class members are entitled to enroll in three years of free medical and credit monitoring services. In addition, a claim may be submitted for reimbursement of documented, unreimbursed losses or an alternative cash payment.  Claims for reimbursement of documented losses have been capped at $15,000 per class member. The remainder of the settlement fund will be paid pro rata to individuals who claim an alternative cash payment. The deadline for exclusion and opting out is September 6, 2026. The deadline for submitting a claim is September 30, 2026, and the final fairness hearing is scheduled for September 29, 2026.

The post OnePoint Patient Care and Clay-Platte Family Medicine Settle Data Breach Lawsuits appeared first on The HIPAA Journal.

Highland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits

Settlements have received preliminary approval to resolve class action data breach complaints against Highland Health Systems and Albany Gastroenterology Consultants that stem from breaches of patient data.

Highland Health Systems Data Breach Settlement

A settlement has been agreed to resolve a class action lawsuit against the nonprofit healthcare organization Highland Health Systems, CEO Mickey Turner, and Director of Finance Allen Stokes, stemming from a July 2023 data breach.

A security incident was identified in early July 2023, in which sensitive patient data was accessed and stolen by hackers. Data compromised in the incident included patient and employee data, including names, contact information, birth dates, Social Security numbers, account numbers, payment card information, medical information, health Insurance Information, tax IDs, and other sensitive data. The affected individuals were notified about the data breach on June 13, 2024, and the data breach was reported to the HHS’ Office for Civil Rights as involving the electronic protected health information of 83,543 individuals.

Two class action lawsuits were filed in response to the data breach, which were combined into a single action –Weyerman, et al. v. Highland Health Systems et al.– which is pending in the Circuit Court for Calhoun County, Alabama. The lawsuit alleges that the data breach was the result of the defendants’ negligence and could have been prevented if appropriate cybersecurity measures had been implemented. The lawsuit asserted claims for negligence/negligence per se, breach of express and/or implied contract, wantonness, breach of fiduciary duty, breach of confidence, and unjust enrichment.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The defendants denied all claims and contentions in the lawsuit and sought to have the lawsuit dismissed; however, the court rejected the motion to dismiss in its entirety. Mediation proved unsuccessful; however, a settlement agreement was subsequently negotiated that was acceptable to all parties. Highland Health Systems has agreed to establish a $650,000 settlement fund to cover the costs of litigation, attorneys’ fees, administration costs, and benefits for the class members.

Those benefits include a two-year membership to a medical identity protection service and one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses up to $5,000 per class member, or a one-time pro rata cash payment may be claimed, which is expected to be $85 per class member, but may be higher or lower depending on the number of valid claims received. The deadline for objection and opting out is September 28, 2026. Claims must be submitted by October 28, 2026, and the final approval hearing has been scheduled for November 30, 2026.

Albany Gastroenterology Consultants Data Breach Settlement

Albany Gastroenterology Consultants, PLLC, a New York gastroenterology practice, has agreed to settle litigation stemming from a November 2024 security incident. The incident occurred on or around November 10, 2024. Hackers gained access to its network, where the personally identifiable information and protected health information of 57,751 individuals was stored. Data potentially compromised in the incident included names, addresses, Social Security numbers, medical information, and health insurance information. The affected individuals started to be notified on January 28, 2025.

Multiple class action lawsuits were filed in response to the data breach in the Supreme Court of the State of New York, County of Albany. The defendant filed a motion to dismiss, and the plaintiffs filed their response. All parties agreed to engage in settlement discussions, and during those discussions, the parties agreed that the Circuit Court for the Eleventh Judicial Circuit in and for Miami-Dade County, Florida, was the proper venue and the New York state actions were voluntarily dismissed. The amended lawsuit was filed in Florida – Clements v. Albany Gastroenterology Consultants, PLLC. The negotiated settlement has received preliminary approval from the court.

The defendant will pay attorneys’ fees and expenses, service awards for the class representatives, and will establish a $200,00 settlement fund to pay benefits to the class members. Class members may submit a claim for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $2,500 per class member. Alternatively, a claim may be submitted for a one-time cash payment, expected to be around $10 per class member. In addition, class members are eligible to enrol in a 2-year membership to a credit monitoring and medical data monitoring service. The $200,000 settlement fund will be divided equally between the two cash payments. If the $100,000 for either is exceeded, claims will be paid pro rata. The deadline for objection and opting out is August 21, 2026. Claims must be submitted by October 5, 2026, and the final approval hearing has been scheduled for September 22, 2026.

The post Highland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits appeared first on The HIPAA Journal.

Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation

The volume and sensitive nature of the data stolen from Change Healthcare in its 2024 ransomware attack have led to strict rules being established for data handling by attorneys involved in a consolidated lawsuit against United Health Group (UHG), Change Healthcare, Optum, and other UHG subsidiaries. The rules will help to ensure that the dataset is protected at all times.

The ransomware attack resulted in the theft of approximately 6 terabytes of data, including files containing the electronic protected health information of an estimated 192,700,000 individuals, including names, contact information, Social Security numbers, driver’s license numbers, insurance information, and medical information. UHG paid the BlackCat ransomware group a $22 million ransom to delete the data; however, the operators pocketed the cash and didn’t pay the affiliate, who had retained a copy. The affiliate joined another ransom group, RansomHub, which attempted to extort UHG a second time.

This was the largest-ever healthcare data breach by some distance, and triggered dozens of lawsuits, including class action lawsuits filed by patients who had their data stolen and healthcare providers seeking compensation for the financial and operational disruptions they experienced. On June 7, 2024, the Judicial Panel on Multidistrict Litigation consolidated an initial 49 lawsuits, including 19 consumer complaints and 30 healthcare provider complaints, although the number of lawsuits included in the action has grown to more than 150. The consolidated lawsuit – In Re: Change Healthcare, Inc. Customer Data Security Breach Litigation – was centralized in the U.S. District Court for the District of Minnesota.

The stolen data files are designated discovery material, and due to the sensitive nature of the data and the volume of records, heightened security practices are required to protect against unauthorized access and data theft. The rules concerning the stolen dataset were approved by the plaintiffs’ attorneys and were verified by a cybersecurity expert as being sufficient to ensure the security of the data before being sent to the judge for approval. The stipulated protective order has recently been approved by Magistrate Judge Dulce Foster.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

UHG will provide a single copy of the data on an encrypted hard drive built to a federal security standard, and must provide the key to decrypt the data separately, to ensure that in the event of loss or theft of the drive, the data cannot be accessed. The plaintiffs’ attorneys are required to encrypt the data again once they have received the hard drive, using industry-standard encryption. No copies may be made of the data, and the data cannot be saved to the shared file library used by all individuals involved in the case. The plaintiffs’ attorneys are prohibited from using the dataset to identify or locate potential class members.

The hard drive must only be used on computers that are air-gapped – disconnected from the Internet and all networks, with no Wi-Fi or Bluetooth connectivity. The computers must be newly provisioned and updated prior to use, and when the computers are used, no cables, phones, or storage devices are permitted nearby.  When data access is required, only small samples may be accessed, and no more than 25 people are permitted access at any one time. All samples must be encrypted with strong encryption and a complex password set of at least 16 characters.

An audit trail must be maintained, including a detailed chain of custody of the drive and data, and the log must be provided to UHG on request. When the case ends, or if the plaintiffs’ claims are thrown out, the data must be securely destroyed within 30 days, using a government-approved data wiping method – NIST SP 800-88 – or the hard drive must be physically destroyed, and a detailed certificate of destruction obtained under penalty of perjury.

In the event of a security incident or unauthorized data access or data sharing, UHG must be notified within 48 hours. Should it turn out to be a genuine security incident, both sides are required to engage an external digital forensic firm, and if the plaintiffs are found to be at fault, they must pay the full investigation costs.

The post Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation appeared first on The HIPAA Journal.

Critical Vulnerabilities Identified in Popular Consumer Fertility Device

Vulnerabilities have been identified in two consumer health and wellness devices – The Mira Hormone Monitor, a popular fertility tracking device, and the Pulsetto Vagus Nerve Stimulator. Vulnerabilities in the former could result in sensitive data exposure and data manipulation. The latter has a vulnerability that poses a safety risk to users.

Mira Hormone Monitor & Mira Android App

Multiple vulnerabilities have been identified in the Mira Hormone Monitor and its associated Android app that could expose sensitive health data, cause a denial-of-service condition, and allow an unauthorized individual to take control of user accounts and manipulate data, potentially resulting in failed fertility treatments, missed fertility windows, or unwanted pregnancies.

The vulnerabilities were identified by a team of researchers at Northeastern University SPQR Lab. The research was partly funded by the Department of Health and Human Services’ Advanced Research Projects Agency for Health (ARPA-H) through a grant issued under the Universal Patching and Remediation for Autonomous Defense program. The vulnerabilities were reported to the device manufacturer, Quanovate Tech, which has taken steps to address the vulnerabilities.

The researchers conducted a full-chain security assessment of the Mira Ultra 5 fertility hormone analyzer and associated Android app and cloud infrastructure. The researchers identified 20 vulnerabilities in the device, app, and cloud infrastructure, including two critical vulnerabilities. The most serious vulnerabilities could be exploited by an attacker to gain read and write access to reproductive health profiles, resulting in forgery, deletion, or destruction of health information, and to gain control of cloud accounts and access hormone record information and account settings.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Key Vulnerabilities

The vulnerabilities include weak or missing authentication, transmission of user data to third parties through analytics code and SDKs, hard-coded API keys, a lack of rate-limiting/IP-throttling, and publicly accessible firmware. The vulnerabilities affect Mira Monitor Firmware 1.7.1.47 and Mira Android App 4.5.15.4.

Vulnerability CVSS v3.1 Base Score CVSS v4.0 Base Score Outcome of Successful Exploitation
CVE-2026-68067 9.8 (Critical) 9.8 (Critical) Gain control of cloud accounts and access hormone record information and account settings.
CVE-2026-67568 9.1 (Critical) 9.3 (Critical) Gain read and write access to reproductive health profiles, resulting in forgery, deletion, or destruction of health information.
CVE-2026-66875 8.8 (High) 8.7 (High) Extract stored hormone measurements; denial-of-service; passively track the user.
CVE-2026-67558 7.4 (High) 8.2 (High) Capture live session token information; inject forged hormone measurements into the victim’s cloud record and clinical trend view.
CVE-2026-66098 6.5 (Medium) 7.1 (High) Denial-of-service; disrupt ovulation tracking and fertility monitoring workflow.
CVE-2026-66832 6.5 (Medium) 6.9 (Medium) Obtain live session token.
CVE-2026-66340 5.3 (Medium) 6.9 (Medium) Brute force access to user account
CVE-2026-64934 4.3 (Medium) 5.3 (Medium) Submission of arbitrary firmware version strings for their own device; evade vendor-side vulnerable-fleet analytics; suppress security update prompts to the user; misrepresent patch-adoption metrics.

The researchers coordinated with the device manufacturer and CISA and previewed the findings after Quanovate had completed two rounds of remediation. Quanovate has released updates to fix these vulnerabilities, and users should upgrade to the latest firmware/app versions: iOS v3.5.18 / Android v4.5.18. Firmware v01.07.01.53 is updated via the app when the device is connected. No evidence has been found of any actual or attempted exploitation of the vulnerabilities.

Pulsetto Vagus Nerve Stimulator

A high-severity vulnerability has been identified in the firmware of the Pulsetto Vagus Nerve Stimulator. Successful exploitation could allow an attacker to disable electrical safety mechanisms or modify other stimulation output settings.

The issue is due to the firmware accepting hidden commands over its Bluetooth Low Energy (BLE) interface. The commands are sent without authorization or encryption and are never issued by the companion mobile application; however, they are fully processed when the device is powered on.

The vulnerability is tracked as CVE-2026-18844 and affects all current versions. The vulnerability has been assigned a CVSS v3.1 base score of 8.1, and a v4.0 base score of 7.2.  The vulnerability was identified by researcher and security author A.C. Buglione, who reported the vulnerability to CISA.  CISA reached out to Pulsetto regarding the vulnerability but did not receive a response. CISA has therefore advised users to contact Pulsetto directly for information on how the issue can be remediated.

The post Critical Vulnerabilities Identified in Popular Consumer Fertility Device appeared first on The HIPAA Journal.