HHS Office for Civil Rights Reaches Agreement with Pennsylvania Hospital Over Care of Deaf Patient in Emergency Department – HHS.gov
OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement – The HIPAA Journal
OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement
The Wisconsin mailing and printing vendor OneTouchPoint Corp. has agreed to settle class action litigation over a 2022 ransomware attack and data breach that affected more than 2.65 million individuals. The cyberattack that sparked the litigation was identified on April 28, 2022, when files were encrypted on its network. The forensic investigation determined that a ransomware group first accessed its network the previous day on April 27, 2022.
Data exposed and potentially stolen in the incident included names, subscriber ID numbers, diagnoses, medications, addresses, dates of birth, sex, physician demographic information, family histories, social histories, allergies, vitals, immunizations, and other information. OneTouchPoint reported the data breach to the HHS’ Office for Civil Rights as affecting 2,651,396 individuals and issued notifications to the affected individuals in April 2022.
Multiple class action lawsuits were filed in response to the data breach, all of which asserted similar claims. The lawsuits alleged that the data breach should have been prevented and was due to the failure of the defendant to implement reasonable and appropriate cybersecurity measures. The individual lawsuits were consolidated into a single action – Dusterhoft v. OneTouchPoint, Inc. – which is pending in the Circuit Court of Waukesha County, Wisconsin.
The consolidated lawsuit asserted claims for negligence, negligence per se, breach of contract, breach of implied contract, breach of fiduciary duty, breach of confidence, invasion of privacy, fraud, misrepresentation, unjust enrichment, bailment, wantonness, failure to provide adequate notice pursuant to any breach notification statute or common law duty, and violations of state consumer protection laws. All claims and contentions in the lawsuit were denied by the defendant, including claims of fault, wrongdoing, and liability. To avoid the costs and risks associated with a trial and related appeals, all parties agreed to settle the litigation.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Under the terms of the settlement, OneTouchPoint has agreed pay attorneys’ fees and expenses up to $1,500,000, settlement administration costs, service awards of $1,000 for each of the class representatives, and monetary benefits and credit monitoring. The defendant also agreed to injunctive relief and will implement security enhancements valued at approximately $2,000,000, which will be maintained for at least five years.
The settlement class is divided into two subclasses – a monetary relief class and an injunctive relief class. The monetary relief class consists of individuals who were notified that their information had been impacted by the data breach. Those individuals may submit claims for monetary benefits. The injunctive relief class consists of individuals who were notified about the data breach, but the investigation could not determine that the data breach had an actual impact. Those individuals will benefit from the injunctive relief only.
All members of the monetary relief class may choose to receive a complimentary two-year subscription to a single-bureau credit monitoring service, which includes a $1 million identity theft insurance policy. In addition, claims may be submitted for compensation for documented, unreimbursed ordinary losses up to a maximum of $500 per class member, and up to $5,000 compensation for documented, unreimbursed extraordinary losses. In addition, compensation may be claimed for up to four hours of lost time at $25 per hour. Monetary relief class members who choose not to submit a compensation claim may claim an alternative one-time cash payment of $75.
The deadline for opting out of the settlement and objecting is October 16, 2026. Claims must be submitted by November 16, 2026, and the final approval hearing has been scheduled for November 18, 2026. Further information can be found on the settlement website: https://otpdataincident.com/
The post OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement appeared first on The HIPAA Journal.
NFI North Data Breach Affects Almost 50,000 Individuals – The HIPAA Journal
NFI North Data Breach Affects Almost 50,000 Individuals
Data breaches have been announced by NFI North in New Hampshire, Nephrology Associates in Kansas, PAMCAH-UA Local 675 Health and Welfare Fund in Hawaii, and Indico Data Solutions in Massachusetts.
NFI North, Inc.
NFI North, Inc., a Contoocook, New Hampshire-based nonprofit human services organization that provides mental health, behavioral, and educational support services in New Hampshire and Maine, has notified the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) about a breach of the protected health information of 49,540 individuals.
According to the NFI North substitute breach notice, suspicious activity was identified within its network on or around September 6, 2025. The investigation and data review concluded on July 6, 2026, when it was confirmed that data compromised in the incident included names, addresses, birth dates, Social Security numbers, driver’s license numbers, financial account information, medical information, and health insurance information. NFI North engaged cybersecurity professionals to assist with the investigation, and additional technical safeguards have been implemented to prevent similar incidents in the future.
Nephrology Associates
Nephrology Associates, M.D., P.A., a network of clinics in Kansas and Missouri that provide care to patients with chronic kidney disease and other kidney disorders, has announced a data security incident that has affected 24,088 individuals. Suspicious network activity was identified on or around April 9, 2026. Assisted by third-party cybersecurity experts, the practice determined that its network had been accessed by an unauthorized third party between January 17, 2026, and April 9, 2026. The affected systems were reviewed and, on July 1, 2026, the practice confirmed that data exposed in the incident included names, birth dates, Social Security numbers, driver’s license numbers/state identification numbers, other government identifiers, diagnosis and treatment information, and health insurance information.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
On or around July 30, 2026, notification letters started to be mailed to the affected individuals. At the time of issuing the notifications, Nephrology Associates was unaware of any actual or attempted misuse of the exposed data. As a precaution against identity theft and fraud, individuals whose Social Security numbers were involved have been offered complimentary credit monitoring services. While not mentioned in the data breach notice, this appears to have been an attack by the cybercriminal group called The Gentlemen. No data appears to have been leaked; however, the group has offered the data for sale.
PAMCAH-UA Local 675 Health and Welfare Fund
PAMCAH-UA Local 675 Health and Welfare Fund, a multiemployer trust fund in Honolulu, Hawaii, that provides medical, dental, vision, and welfare benefits to union plumbers and fitters and their families, has identified unauthorized access to the email accounts of some of its employees.
The forensic investigation determined that certain employee email accounts were accessed by an unauthorized third party between September 23, 2025, and October 9, 2025. During that time, emails and files in the account may have been viewed or acquired. The accounts were reviewed and found to contain the personal and protected health information of 8,319 individuals, including names, dates of birth, medical information, health insurance information, driver’s license numbers, and Social Security numbers. Notification letters have now been mailed to the affected individuals with information on how they can protect themselves against data misuse.
Indico Data Solutions
Indico Data Solutions, Inc., a Massachusetts-based AI-powered software company whose products include an intake and orchestration platform, has announced a data security incident involving the protected health information of 4,840 individuals. It is unclear from the data breach notice when the incident was detected or for how long unauthorized individuals had access to its systems, only that a cybersecurity incident was confirmed by Indico Data Solutions on May 7, 2026. Data potentially compromised in the incident includes names, addresses, and Social Security numbers.
Indico Data Solutions has taken several steps in response to the incident, including rotating access credentials, tightening access controls, and implementing additional monitoring tools. The affected corporate customers have been notified, and Indico Data Solutions has mailed notification letters to the affected individuals and has offered complimentary credit monitoring and identity restoration services.
The post NFI North Data Breach Affects Almost 50,000 Individuals appeared first on The HIPAA Journal.
Luminis Health Working to Restore Systems After Cyberattack – The HIPAA Journal
Luminis Health Working to Restore Systems After Cyberattack
Luminis Health in Maryland is investigating a cyberattack that has taken certain systems offline. Data breaches have been announced by Texas Orthopedic surgeon Jeffrey David Reuben, M.D, Well Child in Tennessee, and Horizon Eye Care Laser & Eye Surgery Center in New Jersey.
Luminis Health, Maryland
Luminis Health, a nonprofit health system that includes Anne Arundel Medical Center in Annapolis and Doctors Community Medical Center in Lanham, announced on September 4, 2026, that it has fallen victim to a cyberattack. The incident has affected both hospitals, which continue to serve patients, although certain appointments have had to be rescheduled. Currently, the phone system and MyChart patient portal remain offline.
Luminis Health said the priority continues to be providing safe, high-quality care to patients; meanwhile, third-party cybersecurity and legal experts have been engaged to investigate and rectify the incident and safely and securely restore access to the affected systems. The health system is currently unable to provide a timeline for how long those processes will take, and it is too soon to tell what extent, if any, that patient data was involved. Should it be determined that patient data was exposed or stolen, patients will be notified in due course. At present, no ransomware or data extortion group appears to have claimed responsibility for the attack.
Jeffrey David Reuben, M.D.
Jeffrey David Reuben, M.D., a Texas-based orthopedic surgeon serving patients at NW Surgery in Houston and medical centers in Bellaire, has recently reported a data security incident that has affected 17,017 current and former patients. The incident was identified on or around April 27, 2026, and assisted by third party cybersecurity professionals, it was confirmed that an unauthorized third party accessed systems containing patient information between April 18 and April 19, 2026.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The investigation and data review were completed on or around July 15, 2026, when it was confirmed that the exposed data included names, Social Security numbers, driver’s license numbers, government-issued ID numbers, and financial information. While no actual or attempted misuse of the affected data has been identified, the affected individuals have been offered complimentary credit monitoring and identity theft protection services for 12 months.
Well Child
Well Child, a provider of school-based healthcare services through partnerships with school districts in Tennessee and Mississippi, has announced a cybersecurity incident that was first identified on June 1, 2026. All servers were immediately taken offline when the incident was identified to prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the unauthorized activity. On June 5, 2026, the investigation confirmed that files containing sensitive personal information had been exfiltrated from a temporary storage server.
The investigation and data review are ongoing; however, it has been determined that the exfiltrated data included Vision Screening Reports, Vision Screening Data Files, Available Students Lists, and PEDS (Parents’ Evaluation of Developmental Status) assessment documents. In addition to student names, the files contained protected health information such as birth dates, medical record numbers, provider names, diagnoses, assessment/test results, treatment dates, and billing and/or procedure codes. For a limited number of individuals, Social Security numbers were also involved. The incident has been reported to the HHS’ Office for Civil Rights using a placeholder figure of at least 500 individuals. The total will be updated when the data review is concluded.
Horizon Eye Care Laser & Eye Surgery Center
Horizon Eye Care Laser & Eye Surgery Center, an ophthalmology practice and eye surgery center with six locations in New Jersey, is investigating a network server hacking incident. Suspicious network activity was identified on or around June 8, 2026. Immediate action was taken to isolate the affected systems, and third-party cybersecurity experts were engaged to investigate the incident.
The investigation and data review are ongoing; however, it has now been confirmed that patient data was compromised in the incident, including names, demographic information, treatment information, and health insurance information. The breach has been reported to the HHS’ Office for Civil Rights using a placeholder figure of at least 501 affected individuals, as the number of affected individuals has yet to be determined.
The post Luminis Health Working to Restore Systems After Cyberattack appeared first on The HIPAA Journal.
