Multi-Million Settlement Resolves Managed Care of North America Data Breach Litigation

Managed Care of North America, Inc. (MCNA) has agreed to settle class action litigation stemming from a 2023 cybersecurity incident that affected around 8.9 million individuals. MCNA is a provider of dental insurance in Florida, and a third-party administrator of dental benefits in other states and Puerto Rico. MCNA’s subsidiaries include MCNA Dental, MCNA Insurance Company, and Healthplex.

The cybersecurity incident was identified on March 6, 2023, and the forensic investigation determined that an unauthorized third party accessed its network between February 22, 2023, and March 7, 2023, and potentially viewed or obtained private information. The investigation confirmed that sensitive data was exfiltrated from its network.

The compromised data included names, addresses, telephone numbers, email addresses, birth dates, Social Security numbers, driver’s license numbers, government-issued ID numbers, health insurance information, Medicare/Medicaid ID numbers, group plan names and numbers, and information related to the dental and orthodontic care provided. Notification letters started to be sent to the affected individuals on May 26, 2023.

The defendant was named in 25 putative class action complaints, the first of which was filed on June 5, 2023. The lawsuits were materially and substantively identical and were consolidated into a single complaint. The consolidated lawsuit alleged that MCNA was responsible for the data breach due to the failure to implement appropriate cybersecurity measures. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, violations of state consumer protection act statutes, and declaratory and injunctive relief.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

MCNA denies any wrongdoing and sought to have the complaint dismissed. The motion was granted in part and denied in part, and an amended complaint – Crowe, et al., v. Managed Care of North America, Inc., et al. – was filed in the United States District Court for the Southern District of Florida. The defendant’s motion to deny the amended complaint was denied by the court. The parties attended mediation, and a settlement was negotiated that was acceptable to all parties.

Under the terms of the settlement, MCNA will cover costs associated with the litigation, including attorneys’ fees up to $6,400,000 and litigation costs up to $1,313,000. All class members are entitled to enroll in two years of medical data monitoring services, valued at $179.40 per year per settlement class member. A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to $2,500 per class member. There is no alternative cash payment. Claims for reimbursement of losses have been capped at $2,500 per class member and will be paid pro rata if that cap is exceeded. MCNA has also agreed to make changes to its business practices and has implemented additional security measures to better protect sensitive data. The deadline for objection, opting out, and submitting a claim is October 19, 2026. The final fairness hearing has been scheduled for November 16, 2026.

The post Multi-Million Settlement Resolves Managed Care of North America Data Breach Litigation appeared first on The HIPAA Journal.

Nutex Health Confirms Sensitive Data Stolen in August Cyberattack

Nutex Health, a Houston, Texas-based healthcare management and operations company that delivers care through 27 micro-hospitals, specialty hospitals, and outpatient departments in 12 U.S. states, has disclosed a cyberattack involving the exfiltration of data from some of its servers. Nutex is currently investigating the incident to determine the extent of data theft, including whether provider, employee, or patient data were exposed or stolen.

The incident was disclosed in an August 24, 2026, Item 8.01 Form 8-K filing with the U.S. Securities and Exchange Commission (SEC). Nutex explained that it recently learned of unauthorized activity related to data stored on its computer network. The company activated its incident response plan, implemented containment measures, and engaged an independent third-party cybersecurity response team and forensics experts to assist with the investigation and determine the extent to which data was exposed or stolen.

Per that filing, Nutex said the incident is still being assessed, and it has yet to determine whether private and confidential data was compromised in the incident. At the time, Nutex said it did not believe that the unauthorized access has, had, or is reasonably likely to have a material impact on the company’s business strategy, operations, financial condition or results of operations. Nutex did not disclose the name of the threat group behind the attack or whether it received a ransom demand, but it was aware that private and/or confidential information may be disclosed by the threat actor. At the time, no cybercriminal group had claimed responsibility for the attack.

Then, on August 31, 2026, Nutex filed an Item 1.05 Form 8-K filing with the SEC confirming that this is a material cybersecurity incident. The August 31, 2026, filing states that, “Based on the current status of the Company’s ongoing investigation, the Company believes that certain information maintained on the Company’s servers was accessed and exfiltrated by an unauthorized third party, including patient and employee, credentialed provider, business, and financial information that is private and/or confidential.”

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Nutex also confirmed that the threat actor has threatened to publish the stolen data; however, the company has not yet identified any material impact on its business operations or financial reporting systems. Nutex is continuing to assess the impacted data and the extent to which patient, employee, credentialed provider, confidential business and financial information, intellectual property, or other information may have been accessed, acquired, or exfiltrated.

The threat group behind the attack on Nutex appears to be The Gentlemen, a ransomware-as-a-service (RaaS) operation that first appeared in mid-2025 and significantly ramped up attacks in 2026. While the group’s attacks appear to be opportunistic, the healthcare sector accounts for around 9% of its attacks. The Gentlemen engages in double extortion tactics, exfiltrating sensitive data and demanding a ransom to decrypt files and prevent the release of stolen data.

The post Nutex Health Confirms Sensitive Data Stolen in August Cyberattack appeared first on The HIPAA Journal.

Oncology Firm Novocure Announces Cyberattack and Data Breach

The medical technology and oncology company Novocure has recently confirmed that patient and employee data were exposed in a recent cyberattack. Novocure is a publicly traded company with approximately 1,300 employees worldwide. Its global HQ is in Baar, Switzerland, and its U.S. headquarters is in Portsmouth, New Hampshire. The company has developed a novel non-invasive cancer treatment called Tumor Treating Fields (TTFields), which uses low-intensity, alternating electrical fields to disrupt the division of cancer cells.

Novocure explained in a September 1, 2026, Form-8K filing with the U.S. Securities and Exchange Commission (SEC), that it became aware of unauthorized access to some of its information systems via a subsidiary in mid-August 2026. Its incident response plan was activated, along with containment measures, and an investigation was launched, with assistance provided by third-party cybersecurity forensics experts.

While employee and patient data were stored on the compromised systems, the impact of the data breach was limited. Based on the investigation to date, approximately 1,400 U.S. patients had data exposed in the incident. The breach was limited to internal company ID numbers – no patient names or other identifying data were exposed. Fewer than 50 other patients in the Western United States had additional identifying information exposed, along with general contact information for all U.S. healthcare providers that the company works with, and general contact information for Novocure employees, including job titles and phone numbers. Novocure did not disclose how many employees had their contact information exposed in the incident.

Novocure said there was no unauthorized access to any of its medical treatment devices, no impact to operations, and all systems are fully functional. At the time of issuing the filing, Novocure said it does not believe that the incident will have any material impact or reasonably likely impact on its financial condition or results of operations, although the investigation into the incident is ongoing.  The threat group behind the attack and the nature of the incident were not disclosed.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Several medical technology companies have experienced cyberattacks this year, including Unlimited Technology Systems, CareCloud, Boston Scientific, Medtronic, Stryker, Abbot Laboratories, and iRhythm, although in this case, the impact appears to be limited. Other medtech companies have not been so fortunate. The cyberattacks on Unlimited Technology Systems and CareCloud involved unauthorized access to systems containing 3.8 million and 3.7 million patient records respectively, and the cyberattack on Boston Scientific disrupted operations globally.

The post Oncology Firm Novocure Announces Cyberattack and Data Breach appeared first on The HIPAA Journal.

Highland Oncology Group Settles Litigation Stemming From 2025 Ransomware Attack

Highlands Oncology Group, an Arkansas-based physician-owned community cancer care and research practice serving Northwest Arkansas, Southwest Missouri, and Southeast Oklahoma, has agreed to settle class action litigation stemming from a 2025 ransomware attack and data breach that affected 113,575 individuals.

The ransomware attack was identified by Highlands Oncology Group on or around June 2, 2025. While the attack was identified in early June, the investigation determined that the ransomware group first gained access to its network as early as January 21, 2025. Data accessed and/or exfiltrated included names, dates of birth, Social Security numbers, driver’s license/state identification numbers, passport numbers, credit/debit card numbers, financial account numbers, medical treatment information, medical record numbers, patient account numbers, and/or health insurance policy information.

The affected individuals were notified on August 1, 2025, and the first class action lawsuit was filed on August 5, 2025. In total, thirteen class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint as they had overlapping claims. The consolidated lawsuit – In re Highlands Oncology Group Data Breach Litigation – was filed in the Circuit Court for Washington County, Arkansas, where it is currently pending.

The consolidated lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, and invasion of privacy-intrusion upon seclusion. Highlands Oncology Group sought to have the consolidated class action complaint dismissed; however, after filing that motion, all parties engaged in settlement discussions, and following mediation, the terms of a settlement were negotiated. The settlement has recently received preliminary approval from the court.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Highlands Oncology Group will pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. Class members may submit a claim for one of two cash payments: A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $4,250 per class member, or a claim may be submitted for a one-time pro rata cash payment, estimated to be around $50 per class member.

Regardless of which cash payment is chosen, class members are eligible to enroll in three years of medical data monitoring services, which include a $1 million identity theft insurance policy. The deadline for opting out and objecting to the settlement is October 7, 2026. Claims must be submitted by October 22, 2026, and the final fairness hearing has been scheduled for November 6, 2026.

The post Highland Oncology Group Settles Litigation Stemming From 2025 Ransomware Attack appeared first on The HIPAA Journal.