Legal News about HIPAA Compliance

Settlement Resolves Class Action Data Breach Complaint Against Community Dental Care

Community Dental Care, a nonprofit Medicaid dental provider in the state of Minnesota, has agreed to settle class action litigation over a 2024 cyberattack and data breach that exposed patients’ personal and protected health information.

The cyberattack and data breach that sparked the litigation occurred on or around December 20, 2024. A cybercriminal actor accessed its network and potentially exfiltrated the personal and protected health information of more than 130,000 individuals, including their names, health insurance information, dates of birth, medical information, and Social Security numbers. Approximately 7,100 of the affected individuals had their Social Security numbers exposed in the incident. Notification letters started to be mailed to the affected individuals on March 28, 2025.

A few days after mailing notifications, a class action lawsuit was filed in the District Court for Ramsey County in the state of Minnesota. A further four class action complaints were filed in response to the data breach, which were consolidated into a single complaint. The consolidated lawsuit alleged that the data breach was due to negligence, as the defendant failed to implement reasonable and appropriate cybersecurity measures. All claims were denied by the defendant, who sought to have the lawsuit dismissed. The motion to dismiss was granted in part and denied in part by the court, with the claims for negligence, negligence per se, and breach of implied contract allowed to proceed. The consolidated class action complaint, In re Community Dental Care, is pending in the District Court for Ramsey County, Minnesota.

Prior to discovery, all parties engaged in discussions about a potential settlement, and after mediation, the terms of a settlement were agreed to by all parties. Class members may submit a claim for reimbursement of documented, unreimbursed losses fairly traceable to the data breach up to a maximum of $5,000 per class member. Alternatively, a claim may be submitted for a one-time cash payment of $50 per class member.  In addition to one of those cash payments, class members are eligible to claim a two-year membership to a medical data monitoring service. The deadline for objection and opting out is September 24, 2026. Claims must be submitted by October 19, 2026, and the final fairness hearing has been scheduled for November 23, 2026.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The post Settlement Resolves Class Action Data Breach Complaint Against Community Dental Care appeared first on The HIPAA Journal.

Modernizing Medicine Agrees to $3M Data Breach Settlement

Modernizing Medicine, a Boca Raton, Florida-based company that provides cloud-based, AI-powered software and electronic health record systems for healthcare providers, has agreed to pay almost $3 million to settle class action data breach litigation.

The litigation stems from a July 2025 cybersecurity incident in which a criminal hacker gained access to two of its computer servers between July 9, 2025, and July 10, 2025. The servers were used for the conversion of data from retiring EHR platforms to the current Modernizing Medicine EHR platform. Data compromised in the incident included names, addresses, dates of birth, phone numbers, email addresses, limited Social Security numbers, health insurance information, and medical information. The affected individuals were notified on or around October 17, 2025. The HHS Office for Civil Rights was informed that 198,795 individuals had been affected.

A class action lawsuit – Cavallaro-Kearins v. Modernizing Medicine, Inc. – was filed on November 19, 2025, in the U.S. District Court for the Southern District of Florida by plaintiff Patricia Cavallaro-Kearins, individually and on behalf of similarly situated individuals. The lawsuit alleged that the data breach occurred as a result of insufficient cybersecurity measures, and asserted claims for negligence, breach of implied contract, invasion of privacy, unjust enrichment, and breach of fiduciary duty. Modernizing Medicine denies wrongdoing and liability.

All parties opted to explore opportunities for early resolution of the litigation, and after a full day of mediation on April 2, 2026, the material terms of a settlement were agreed upon by all parties. The settlement has now been finalized and has received preliminary approval from the court. Under the terms of the settlement, Modernizing Medicine has agreed to establish a $2,999,750.00 settlement fund to pay benefits to the class members, after attorneys’ fees and expenses, settlement administration costs, and service awards have been deducted.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

All class members are entitled to claim a two-year membership to the CyEx Medical Shield Complete medical data monitoring service, plus one of two cash payments. A claim may be submitted for reimbursement of documented losses fairly traceable to the data breach up to a maximum of $5,000 per class member. Alternatively, class members may claim a one-time pro rata cash payment, which is expected to be approximately $75 per class member, but may be higher or lower depending on the number of valid claims received. Claims must be submitted by November 2, 2026, and the final fairness hearing has been scheduled for November 17, 2026. Individuals wishing to object to the settlement or opt out have until October 19, 2026, to do so.

The post Modernizing Medicine Agrees to $3M Data Breach Settlement appeared first on The HIPAA Journal.

Brevard Skin and Cancer Center Settles Class Action Complaint

The Florida dermatology practice, Brevard Skin and Cancer Center, has agreed to a settlement to resolve class action litigation stemming from a 2025 cyberattack and data breach.

Unauthorized activity was identified within its network on October 14, 2025. The forensic investigation confirmed unauthorized network access starting on September 28, 2025, and the exposure of patient data including names, phone numbers, e-mail addresses, dates of birth, Social Security numbers, diagnoses, clinical information, and billing and claims information. The data breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 54,570 individuals. A threat group called PEAR claimed responsibility for the attack and threatened to publish the data unless a ransom was paid.

The first class action lawsuit was filed on October 20, 2025, and similar class action lawsuits were filed by other individuals affected by the data breach. The lawsuits were consolidated into a single action as they had overlapping claims and classes. The consolidated lawsuit – In Re: Brevard Skin & Cancer Center Data Breach Litigation – was filed on February 5, 2026, in the Circuit Court for Brevard County, Florida, where it is currently pending.

The plaintiffs alleged that Brevard Skin and Cancer Center was at fault for the incident and data breach, as it failed to implement appropriate cybersecurity measures, and that if those measures had been implemented, the data breach could have been prevented. The lawsuit asserted claims for negligence, breach of implied contract, unjust enrichment, invasion of privacy, breach of fiduciary duty, and violation of the Florida Deceptive and Unfair Trade Practices Act. All claims and contentions in the lawsuit were denied by Brevard Skin and Cancer Center, including fault, wrongdoing, and liability.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

All parties agreed to a settlement to avoid the delay, risk, and uncertainty of continued litigation. Under the terms of the settlement, Brevard Skin and Cancer Center has agreed to pay attorneys’ fees and expenses, settlement administration costs, service awards for the class representatives, and multiple benefits for the class members.

All class members may claim a one-year membership to the CyEx Medical Shield Complete medical data monitoring service. Class members may also claim up to $2,500 as reimbursement for documented, unreimbursed losses due to the data breach. If a claim for reimbursement of losses is not submitted, class members may claim an alternative one-time $45 cash payment. Class members have until November 2, 2026, to object or opt out. Claims must be submitted by November 16, 2026, and the final fairness hearing has been scheduled for November 30, 2026.

The post Brevard Skin and Cancer Center Settles Class Action Complaint appeared first on The HIPAA Journal.

Central Maine Medical Center & Susan B. Allen Memorial Hospital Settle Data Breach Lawsuits

Central Maine Medical Center & Susan B. Allen Memorial Hospital have agreed to settle class action lawsuits stemming from data security incidents that exposed patient information.

Central Maine Medical Center Data Breach Settlement

Central Maine Medical Center, a Lewiston, Maine-based nonprofit healthcare provider, has agreed to pay $1,368,025 to settle a consolidated class action lawsuit stemming from a 2025 cyberattack and data breach.

The attack was identified on June 1, 2026, and caused the shutdown of IT systems, network servers, and its phone system. The forensic investigation determined that hackers had access to its network between March 19, 2025, and June 1, 2025, and potentially obtained personal and protected health information. According to the lawsuit, notification letters were mailed to 218,884 individuals.

Six putative class action lawsuits were filed in response to the data breach, alleging that Central Maine Healthcare was at fault as reasonable and appropriate cybersecurity measures had not been implemented. The lawsuits were consolidated into a single complaint – In re Central Maine Data Security Litigation – naming the defendants Central Maine Healthcare Corporation and Central Maine Medical Center. The defendants deny all claims and contentions in the lawsuit, including claims of fault, wrongdoing, and liability. The lawsuit was settled to avoid the time, cost, and uncertainty of continued litigation.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The settlement fund will be used to pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. The remainder of the settlement fund will be used to pay benefits to the class members. Class members may claim one of two cash payments: A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member. Alternatively, a claim may be submitted for a one-time, pro rata cash payment, estimated to be around $60 per class member.  In addition to one of those payments, class members may claim a one-year membership to a medical record monitoring service. The deadline for objection and opting out is September 13, 2026. Claims must be submitted by September 28, 2026, and the final fairness hearing has been scheduled for October 28, 2026.

Susan B. Allen Memorial Hospital Data Breach Settlement

A settlement has been agreed to resolve class action litigation against the Butler, Kansas acute-care medical facility, Susan B. Allen Memorial Hospital, to resolve claims stemming from a July 2025 cyberattack and data breach. Hackers gained access to its network and potentially obtained personal and protected health information. The data breach was initially reported to the HHS’ Office for Civil Rights as affecting up to 12,097 individuals, although the HHS’ Office for Civil Rights breach portal has since been updated to indicate that only 11,866 individuals had protected health information compromised in the incident.

Four putative class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint as they had overlapping claims and classes. The consolidated lawsuit, In Re: Susan B. Allen Data Security Litigation, is pending in the District Court of Butler County, Kansas. The plaintiffs allege that the hospital was at fault for the data breach as it failed to implement appropriate cybersecurity measures, and the defendant maintains there was no wrongdoing. A settlement was agreed to avoid the cost, time, distraction, and uncertainty of continued litigation.

The settlement provides two years of credit monitoring and identity theft protection services for all class members. In addition, a claim may be submitted for reimbursement of out-of-pocket losses due to the data breach up to a maximum of $100 per class member. In addition, a claim may be submitted for reimbursement of up to four hours of lost time at $25 per hour. Claims have been capped at an aggregate of $100 per class member. Claims must be submitted by November 12, 2026. Individuals wishing to object to the settlement or exclude themselves must do so by October 13, 2026. The final fairness hearing has been scheduled for December 7, 2026.

The post Central Maine Medical Center & Susan B. Allen Memorial Hospital Settle Data Breach Lawsuits appeared first on The HIPAA Journal.

Palomar Health Medical Group; Summit Medical Group Settle Data Breach Lawsuits

Settlements have been reached to resolve class action data breach lawsuits against Palomar Health Medical Group in California and Summit Medical Group in Tennessee.

Palomar Health Medical Group Data Breach Settlement

Palomar Health Medical Group, a non-profit healthcare organization serving patients at 20 locations in North San Diego County and South Riverside County in Southern California, has agreed to settle class action litigation stemming from a Spring 2024 cybersecurity incident involving the protected health information of 1,140,221 individuals. The incident was identified on May 5, 2024, and the forensic investigation confirmed that hackers had access to its network from April 23, 2024, to May 5, 2024. Data potentially stolen in the incident included names, contact information, dates of birth, Social Security numbers, driver’s license numbers, state identification numbers, medical histories, health information, health insurance information, and other sensitive data.

Several class action lawsuits were filed in response to the data breach, all of which alleged that the data breach could have been prevented and occurred as a result of the failure of the defendant to implement reasonable and appropriate cybersecurity measures. On September 16, 2024, the lawsuits were consolidated into a single complaint – Castro et al. v. Arch Health Partners, Inc. d/b/a Palomar Health Medical Group – which is pending in the Superior Court for the State of California, County of San Diego. The consolidated lawsuit asserted claims for negligence, negligence per se, invasion of privacy, and violations of the California Consumer Privacy Act, California Confidentiality of Medical Information Act, and California Customer Records Act. All claims and contentions in the lawsuit were denied by Palomar Health Medical Group; however, all parties agreed to settle the litigation to avoid the costs and risks associated with continued litigation.

Under the terms of the settlement, Palomar Health Medical Group has agreed to establish a $3,100,000 settlement fund, from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives will be deducted. The remainder of the settlement fund will be used to pay benefits to the class members.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The settlement provides two years of complimentary single-bureau credit monitoring services to all class members. Class members may also claim one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses up to $5,000 per class member, or a claim may be submitted for an alternative pro rata cash payment, estimated to be $60 per class member. The deadline for opting out and objecting to the settlement is October 7, 2026. Claims must be submitted by October 22, 2026, and the final fairness hearing has been scheduled for November 6, 2026.

Summit Medical Group Data Breach Settlement

Summit Medical Group, a Tennessee-based medical group with more than 90 locations in Tennessee, has settled class action litigation stemming from a November 2024 cybersecurity incident that exposed the personal and protected health information of more than 464,000 patients and employees. Data exposed in the incident included names, contact information, demographic information, medical record numbers, provider names, dates of services, facilities of service, treatment information, and/or health insurance information. The affected individuals were notified about the breach in March 2025.

Three putative class action lawsuits were filed in response to the data breach. The lawsuits had overlapping claims and putative classes, and were consolidated into a single lawsuit – Harris, et al. v. Summit Medical Group, PLLC, which is pending in the Circuit Court for Knox County, Tennessee. The consolidated lawsuit alleged that the data breach occurred as a result of insufficient security measures, and despite determining on September 19, 2024, that patient data was exposed, notifications were not mailed until March 2025. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, breach of fiduciary duty, unjust enrichment, and invasion of privacy, all of which were denied by Summit Medical Group. Summit Medical Group sought to have the lawsuit dismissed; however, after considering the time, cost, and risks associated with continued litigation, all parties agreed to settle the litigation. The terms of the settlement have been finalized, and the proposed settlement has received preliminary approval from the court.

The settlement provides two years of medical data monitoring with the CyEx Medical Shield Complete service. In addition, class members may submit a claim for reimbursement of documented out-of-pocket losses due to the data breach up to a maximum of $2,500 per class member. A claim may also be submitted for reimbursement of up to three hours of lost time at $15 per hour (max $45). The cash payments have been capped at $500,000. Claims will be paid pro rata if claims exceed that total.

Summit Medical Group has also agreed to pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. The deadline for objecting to the settlement and exclusion is October 10, 2026. Claims must be submitted by November 4, 2026, and the final fairness hearing has been scheduled for November 19, 2026.

The post Palomar Health Medical Group; Summit Medical Group Settle Data Breach Lawsuits appeared first on The HIPAA Journal.

Wellstar Health System & Cone Health Settle Pixel Lawsuits

Settlements have been agreed to resolve class action lawsuits against Wellstar Health System and Moses H. Cone Memorial Hospital Operating Corporation (Cone Health). The lawsuits stem from the defendants’ use of pixels and other website tracking tools, which are alleged to have resulted in impermissible disclosures of patient data to third parties such as Meta and Google.

Wellstar Health System Pixel Settlement

Wellstar Health System, a Marietta, Georgia-based health system with more than 400 care locations in the state, was sued over its use of tracking tools on its website that are alleged to have resulted in the disclosure of personally identifiable information and protected health information to third parties such as Alphabet Inc. (Google) and Meta Platforms (Facebook), without website users’ knowledge or consent.

The first lawsuit was filed on April 23, 2024, and an amended complaint was filed on August 2, 2024, adding three additional plaintiffs. The lawsuit – Doe v. Wellstar Health System, Inc. –  is pending in the United States District Court for the Northern District of Georgia. The lawsuit asserted claims for invasion of privacy – intrusion upon seclusion, breach of fiduciary duty, negligence, negligence per se, breach of implied contract, breach of express contract, unjust enrichment, and violations of the Electronic Communications Privacy Act. The defendant denies all claims and contentions in the lawsuit and maintains that there was no wrongdoing. A settlement was agreed to by all parties to avoid the time, expense, and uncertainty of a trial and related appeals.

Wellstar Health System has agreed to establish a $4,500,000 settlement fund, from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives will be deducted. The remainder of the settlement fund will be divided equally among all class members who submit a valid claim. The class consists of individuals whose personally identifiable information and/or protected health information was disclosed to third parties via the tracking tools between February 19, 2020, and July 22, 2026. Any remaining settlement funds, such as from uncashed checks, will be distributed to the Good Samaritan Health Center of Cobb.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The deadline for objection and opting out is October 26, 2026. Claims must be submitted by November 10, 2026, and the final fairness hearing has been scheduled for December 1, 2026.

Moses H. Cone Memorial Hospital Operating Corporation (Cone Health) Pixel Settlement

Greensboro, North Carolina-based defendants The Moses H. Cone Memorial Hospital Operating Corporation, d/b/a Cone Health, and The Moses H. Cone Memorial Hospital, d/b/a Cone Health, were sued over the use of tracking tools such as pixels, which had been added to their public website without the knowledge or consent of website users. The lawsuit alleged that the use of the tracking code resulted in disclosures of users’ confidential health information and protected health information to third parties such as Alphabet Inc (Google) and Meta Platforms (Facebook).

The lawsuit, Singh v. The Moses H. Cone Memorial Hospital Operating Corp., et al., is pending in the United States District Court for the Middle District of North Carolina. The lawsuit asserted claims for violation of the Electronic Communications Privacy Act, breach of express contract, breach of implied duty of good faith and fair dealing, breach of implied contract, negligence, breach of fiduciary duty, and unjust enrichment. The defendants maintain that there was no wrongdoing; however, a settlement was agreed by all parties to avoid the costs, delays, and uncertainties of continued litigation.

Cone Health has agreed to establish a $1,765,000 settlement fund, which will be used to pay reasonable attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. After those costs have been deducted, the net settlement fund will be distributed equally among the class members. The value of each cash payment will depend on the number of valid claims received.

The settlement class consists of all individuals who accessed the MyChart patient portal on the defendants’ website between September 1, 2016, and November 3, 2022, as well as any individual who completed a submission form on the defendants’ website between the same dates. The settlement has received preliminary approval from the court. The deadline for opting out and objecting to the settlement is October 5, 2025. Claims must be submitted by October 5, 2026, and the final fairness hearing has been scheduled for November 5, 2026.

The post Wellstar Health System & Cone Health Settle Pixel Lawsuits appeared first on The HIPAA Journal.

OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement

The Wisconsin mailing and printing vendor OneTouchPoint Corp. has agreed to settle class action litigation over a 2022 ransomware attack and data breach that affected more than 2.65 million individuals. The cyberattack that sparked the litigation was identified on April 28, 2022, when files were encrypted on its network. The forensic investigation determined that a ransomware group first accessed its network the previous day on April 27, 2022.

Data exposed and potentially stolen in the incident included names, subscriber ID numbers, diagnoses, medications, addresses, dates of birth, sex, physician demographic information, family histories, social histories, allergies, vitals, immunizations, and other information. OneTouchPoint reported the data breach to the HHS’ Office for Civil Rights as affecting 2,651,396 individuals and issued notifications to the affected individuals in April 2022.

Multiple class action lawsuits were filed in response to the data breach, all of which asserted similar claims. The lawsuits alleged that the data breach should have been prevented and was due to the failure of the defendant to implement reasonable and appropriate cybersecurity measures. The individual lawsuits were consolidated into a single action – Dusterhoft v. OneTouchPoint, Inc. – which is pending in the Circuit Court of Waukesha County, Wisconsin.

The consolidated lawsuit asserted claims for negligence, negligence per se, breach of contract, breach of implied contract, breach of fiduciary duty, breach of confidence, invasion of privacy, fraud, misrepresentation, unjust enrichment, bailment, wantonness, failure to provide adequate notice pursuant to any breach notification statute or common law duty, and violations of state consumer protection laws. All claims and contentions in the lawsuit were denied by the defendant, including claims of fault, wrongdoing, and liability. To avoid the costs and risks associated with a trial and related appeals, all parties agreed to settle the litigation.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Under the terms of the settlement, OneTouchPoint has agreed pay attorneys’ fees and expenses up to $1,500,000, settlement administration costs, service awards of $1,000 for each of the class representatives, and monetary benefits and credit monitoring. The defendant also agreed to injunctive relief and will implement security enhancements valued at approximately $2,000,000, which will be maintained for at least five years.

The settlement class is divided into two subclasses – a monetary relief class and an injunctive relief class. The monetary relief class consists of individuals who were notified that their information had been impacted by the data breach. Those individuals may submit claims for monetary benefits. The injunctive relief class consists of individuals who were notified about the data breach, but the investigation could not determine that the data breach had an actual impact. Those individuals will benefit from the injunctive relief only.

All members of the monetary relief class may choose to receive a complimentary two-year subscription to a single-bureau credit monitoring service, which includes a $1 million identity theft insurance policy. In addition, claims may be submitted for compensation for documented, unreimbursed ordinary losses up to a maximum of $500 per class member, and up to $5,000 compensation for documented, unreimbursed extraordinary losses. In addition, compensation may be claimed for up to four hours of lost time at $25 per hour. Monetary relief class members who choose not to submit a compensation claim may claim an alternative one-time cash payment of $75.

The deadline for opting out of the settlement and objecting is October 16, 2026. Claims must be submitted by November 16, 2026, and the final approval hearing has been scheduled for November 18, 2026. Further information can be found on the settlement website: https://otpdataincident.com/

The post OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement appeared first on The HIPAA Journal.

Multi-Million Settlement Resolves Managed Care of North America Data Breach Litigation

Managed Care of North America, Inc. (MCNA) has agreed to settle class action litigation stemming from a 2023 cybersecurity incident that affected around 8.9 million individuals. MCNA is a provider of dental insurance in Florida, and a third-party administrator of dental benefits in other states and Puerto Rico. MCNA’s subsidiaries include MCNA Dental, MCNA Insurance Company, and Healthplex.

The cybersecurity incident was identified on March 6, 2023, and the forensic investigation determined that an unauthorized third party accessed its network between February 22, 2023, and March 7, 2023, and potentially viewed or obtained private information. The investigation confirmed that sensitive data was exfiltrated from its network.

The compromised data included names, addresses, telephone numbers, email addresses, birth dates, Social Security numbers, driver’s license numbers, government-issued ID numbers, health insurance information, Medicare/Medicaid ID numbers, group plan names and numbers, and information related to the dental and orthodontic care provided. Notification letters started to be sent to the affected individuals on May 26, 2023.

The defendant was named in 25 putative class action complaints, the first of which was filed on June 5, 2023. The lawsuits were materially and substantively identical and were consolidated into a single complaint. The consolidated lawsuit alleged that MCNA was responsible for the data breach due to the failure to implement appropriate cybersecurity measures. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, violations of state consumer protection act statutes, and declaratory and injunctive relief.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

MCNA denies any wrongdoing and sought to have the complaint dismissed. The motion was granted in part and denied in part, and an amended complaint – Crowe, et al., v. Managed Care of North America, Inc., et al. – was filed in the United States District Court for the Southern District of Florida. The defendant’s motion to deny the amended complaint was denied by the court. The parties attended mediation, and a settlement was negotiated that was acceptable to all parties.

Under the terms of the settlement, MCNA will cover costs associated with the litigation, including attorneys’ fees up to $6,400,000 and litigation costs up to $1,313,000. All class members are entitled to enroll in two years of medical data monitoring services, valued at $179.40 per year per settlement class member. A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to $2,500 per class member. There is no alternative cash payment. Claims for reimbursement of losses have been capped at $2,500 per class member and will be paid pro rata if that cap is exceeded. MCNA has also agreed to make changes to its business practices and has implemented additional security measures to better protect sensitive data. The deadline for objection, opting out, and submitting a claim is October 19, 2026. The final fairness hearing has been scheduled for November 16, 2026.

The post Multi-Million Settlement Resolves Managed Care of North America Data Breach Litigation appeared first on The HIPAA Journal.

Highland Oncology Group Settles Litigation Stemming From 2025 Ransomware Attack

Highlands Oncology Group, an Arkansas-based physician-owned community cancer care and research practice serving Northwest Arkansas, Southwest Missouri, and Southeast Oklahoma, has agreed to settle class action litigation stemming from a 2025 ransomware attack and data breach that affected 113,575 individuals.

The ransomware attack was identified by Highlands Oncology Group on or around June 2, 2025. While the attack was identified in early June, the investigation determined that the ransomware group first gained access to its network as early as January 21, 2025. Data accessed and/or exfiltrated included names, dates of birth, Social Security numbers, driver’s license/state identification numbers, passport numbers, credit/debit card numbers, financial account numbers, medical treatment information, medical record numbers, patient account numbers, and/or health insurance policy information.

The affected individuals were notified on August 1, 2025, and the first class action lawsuit was filed on August 5, 2025. In total, thirteen class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint as they had overlapping claims. The consolidated lawsuit – In re Highlands Oncology Group Data Breach Litigation – was filed in the Circuit Court for Washington County, Arkansas, where it is currently pending.

The consolidated lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, and invasion of privacy-intrusion upon seclusion. Highlands Oncology Group sought to have the consolidated class action complaint dismissed; however, after filing that motion, all parties engaged in settlement discussions, and following mediation, the terms of a settlement were negotiated. The settlement has recently received preliminary approval from the court.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Highlands Oncology Group will pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. Class members may submit a claim for one of two cash payments: A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $4,250 per class member, or a claim may be submitted for a one-time pro rata cash payment, estimated to be around $50 per class member.

Regardless of which cash payment is chosen, class members are eligible to enroll in three years of medical data monitoring services, which include a $1 million identity theft insurance policy. The deadline for opting out and objecting to the settlement is October 7, 2026. Claims must be submitted by October 22, 2026, and the final fairness hearing has been scheduled for November 6, 2026.

The post Highland Oncology Group Settles Litigation Stemming From 2025 Ransomware Attack appeared first on The HIPAA Journal.