Legal News about HIPAA Compliance

Multi-Million Settlement Resolves Managed Care of North America Data Breach Litigation

Managed Care of North America, Inc. (MCNA) has agreed to settle class action litigation stemming from a 2023 cybersecurity incident that affected around 8.9 million individuals. MCNA is a provider of dental insurance in Florida, and a third-party administrator of dental benefits in other states and Puerto Rico. MCNA’s subsidiaries include MCNA Dental, MCNA Insurance Company, and Healthplex.

The cybersecurity incident was identified on March 6, 2023, and the forensic investigation determined that an unauthorized third party accessed its network between February 22, 2023, and March 7, 2023, and potentially viewed or obtained private information. The investigation confirmed that sensitive data was exfiltrated from its network.

The compromised data included names, addresses, telephone numbers, email addresses, birth dates, Social Security numbers, driver’s license numbers, government-issued ID numbers, health insurance information, Medicare/Medicaid ID numbers, group plan names and numbers, and information related to the dental and orthodontic care provided. Notification letters started to be sent to the affected individuals on May 26, 2023.

The defendant was named in 25 putative class action complaints, the first of which was filed on June 5, 2023. The lawsuits were materially and substantively identical and were consolidated into a single complaint. The consolidated lawsuit alleged that MCNA was responsible for the data breach due to the failure to implement appropriate cybersecurity measures. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, violations of state consumer protection act statutes, and declaratory and injunctive relief.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

MCNA denies any wrongdoing and sought to have the complaint dismissed. The motion was granted in part and denied in part, and an amended complaint – Crowe, et al., v. Managed Care of North America, Inc., et al. – was filed in the United States District Court for the Southern District of Florida. The defendant’s motion to deny the amended complaint was denied by the court. The parties attended mediation, and a settlement was negotiated that was acceptable to all parties.

Under the terms of the settlement, MCNA will cover costs associated with the litigation, including attorneys’ fees up to $6,400,000 and litigation costs up to $1,313,000. All class members are entitled to enroll in two years of medical data monitoring services, valued at $179.40 per year per settlement class member. A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to $2,500 per class member. There is no alternative cash payment. Claims for reimbursement of losses have been capped at $2,500 per class member and will be paid pro rata if that cap is exceeded. MCNA has also agreed to make changes to its business practices and has implemented additional security measures to better protect sensitive data. The deadline for objection, opting out, and submitting a claim is October 19, 2026. The final fairness hearing has been scheduled for November 16, 2026.

The post Multi-Million Settlement Resolves Managed Care of North America Data Breach Litigation appeared first on The HIPAA Journal.

Highland Oncology Group Settles Litigation Stemming From 2025 Ransomware Attack

Highlands Oncology Group, an Arkansas-based physician-owned community cancer care and research practice serving Northwest Arkansas, Southwest Missouri, and Southeast Oklahoma, has agreed to settle class action litigation stemming from a 2025 ransomware attack and data breach that affected 113,575 individuals.

The ransomware attack was identified by Highlands Oncology Group on or around June 2, 2025. While the attack was identified in early June, the investigation determined that the ransomware group first gained access to its network as early as January 21, 2025. Data accessed and/or exfiltrated included names, dates of birth, Social Security numbers, driver’s license/state identification numbers, passport numbers, credit/debit card numbers, financial account numbers, medical treatment information, medical record numbers, patient account numbers, and/or health insurance policy information.

The affected individuals were notified on August 1, 2025, and the first class action lawsuit was filed on August 5, 2025. In total, thirteen class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint as they had overlapping claims. The consolidated lawsuit – In re Highlands Oncology Group Data Breach Litigation – was filed in the Circuit Court for Washington County, Arkansas, where it is currently pending.

The consolidated lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, and invasion of privacy-intrusion upon seclusion. Highlands Oncology Group sought to have the consolidated class action complaint dismissed; however, after filing that motion, all parties engaged in settlement discussions, and following mediation, the terms of a settlement were negotiated. The settlement has recently received preliminary approval from the court.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Highlands Oncology Group will pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. Class members may submit a claim for one of two cash payments: A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $4,250 per class member, or a claim may be submitted for a one-time pro rata cash payment, estimated to be around $50 per class member.

Regardless of which cash payment is chosen, class members are eligible to enroll in three years of medical data monitoring services, which include a $1 million identity theft insurance policy. The deadline for opting out and objecting to the settlement is October 7, 2026. Claims must be submitted by October 22, 2026, and the final fairness hearing has been scheduled for November 6, 2026.

The post Highland Oncology Group Settles Litigation Stemming From 2025 Ransomware Attack appeared first on The HIPAA Journal.

DaVita Agrees to Pay $15 Million to Settle Data Breach Litigation

In 2025, the kidney dialysis giant DaVita experienced a ransomware attack that involved the theft of sensitive patient data. Some of the affected individuals took legal action in response to the data breach, which they claim has put them at risk of identity theft and fraud. Following extensive negotiations, a $15 million settlement has been proposed to bring the litigation to an end.

DaVita operates more than 3,000 kidney dialysis centers in the United States and 14 other countries. On April 12, 2025, the Interlock ransomware group accessed its network, exfiltrated data, and encrypted files, causing temporary disruption to operations. The forensic investigation determined that the electronic protected health information of 2,689,826 individuals was compromised in the incident, including names, contact information, Social Security numbers, health insurance information, clinical information, and tax information. Interlock claimed to have exfiltrated more than 20 terabytes of data and proceeded to leak around 1.5 terabytes of that data on its web data leak site when the ransom was not paid.

Multiple class action lawsuits were filed in response to the data breach that alleged that it occurred as a result of the defendant’s failure to implement reasonable and appropriate cybersecurity measures. The lawsuits were consolidated – Julian Jenkins, et al v. DaVita Inc. – in the United States District Court for the District of Colorado as they had overlapping claims.

The lawsuit asserted claims for negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, invasion of privacy, and violations of state consumer protection statutes. The lawsuit alleged that the plaintiffs face a current, imminent, and ongoing risk of fraud and identity theft as a result of the theft of their personal and health information, and the publication of that information on the dark web. The defendant denies the claims and contentions in the lawsuit, including claims of negligence, fault, and liability.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

All parties were able to negotiate a settlement to resolve the litigation, with no admission of liability or wrongdoing by DaVita. The proposed $15,000,000 settlement covers attorneys’ fees and expenses, settlement administration costs, service awards for the five class representatives, and a $10,000,000 non-revisionary settlement fund to pay relief to the class members.

Class members may submit a claim for up to $2,500 as reimbursement for documented, unreimbursed out-of-pocket losses due to the data breach. All class members, including those who submit a claim for reimbursement of losses, may claim a pro rata cash payment. The amount will depend on the number of valid claims received. The class consists of approximately 2.3 million individuals, and if everyone submits a claim, that would amount to around $4.17 per class member; however, based on the expected response rate, the cash payments are anticipated to be around $50 per class member.

The post DaVita Agrees to Pay $15 Million to Settle Data Breach Litigation appeared first on The HIPAA Journal.

Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit

Tift Regional Health System Inc, a non-profit health system serving patients in south central Georgia, has agreed to pay $1.2 million to settle a class action lawsuit stemming from a 2022 cyberattack that exposed patient data.

Tift Regional Health, which operates as Southwell, Inc., which is also a defendant, identified suspicious activity within its computer network on or around August 16, 2022. The forensic investigation confirmed that its network was accessed by an unauthorized third party between August 11, 2022, and August 17, 2022. The compromised parts of the network contained documents that included patient names, birth dates, Social Security numbers, and a range of sensitive medical information. Tift Regional Health said those documents may have been accessed or copied in the attack. A ransomware group  – Hive – claimed responsibility for the attack. Hive claimed to have stolen 1 terabyte of data and proceeded to leak some of that data on its data leak site. The data breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 180,142 individuals.

Multiple class action lawsuits were filed against the defendants in response to the data breach. The lawsuits were consolidated into a single action – In Tift Regional Health System, Inc. Data Breach Litigation – in the Superior Court of Tift County, State of Georgia, as the lawsuits had overlapping claims. The consolidated lawsuit alleged that the cyberattack and data breach were due to the defendants’ failures to properly secure, safeguard, and encrypt patient data, and destroy patient data in a timely manner when it was no longer required.  The lawsuit also took issue with the length of time it took to notify the affected individuals. They were not notified about the data breach until August 11, 2023, almost a year after the incident occurred.

The lawsuit asserted claims for negligence, negligence per se, breach of fiduciary duty, breach of implied contract, breach of contract, breach of the covenant of good faith and fair dealing, unjust enrichment, invasion of privacy, violation of the Georgia Uniform Deceptive Trade Practices Act, and for equitable and injunctive relief. The defendants deny the claims and contentions in the lawsuit and maintain there was no wrongdoing and no liability.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Both sides agreed to a settlement to avoid the costs and risks of a trial. The defendants have agreed to establish a $1,200,000 settlement fund to pay benefits to the class members after attorneys’ fees and expenses, settlement administration costs, and service awards for the four class representatives have been deducted. The defendants have also implemented a range of additional measures to better secure sensitive data in their possession, and those measures will be maintained for at least two years at an estimated cost of $4.5 million.

All class members are entitled to enroll in a two-year credit/medical data monitoring and identity theft protection service, and claim one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses up to a maximum of $5,000 per class member, or a claim may be submitted for an alternative cash payment.

The cash payments will be paid pro rata after all other claims and costs have been deducted, and they will exhaust the settlement fund. The cash payments are expected to be approximately $75 per class member but may be higher or lower. The settlement has received preliminary approval from the court, and the final fairness hearing is scheduled for September 14, 2026. The deadline for opting out and objecting to the settlement is September 15, 2026. Claims must be submitted by October 15, 2026.

The post Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit appeared first on The HIPAA Journal.

DAP Health Settles Data Breach Lawsuit for $1,300,000

DAP Health, a nonprofit community healthcare network based in Southern California, has agreed to settle a class action lawsuit that was filed in response to a cyberattack on its computer systems that exposed sensitive patient data.

Suspicious activity was identified within certain computer systems on or around July 22, 2024. An investigation was launched, which confirmed that an unauthorized third party gained access to an email server and exfiltrated emails and files containing personally identifiable information and protected health information. Data stolen in the incident included names, contact information, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, birth certificate numbers, vehicle license plate and VIN numbers, financial account numbers, Medicare/Medicaid numbers, health insurance information, and a range of medical information.

Notification letters started to be sent to the affected individuals in December 2024, and the breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 129,048 individuals. The first class action lawsuit in response to the data breach was filed in January 2025, and a second lawsuit was filed in early February 2025. The plaintiffs agreed to work together, and an amended complaint – Donald Crosslin and Matthew Paone v. DAP Health, Inc. was filed in the Superior Court for the State of California for the County of Riverside in June 2025.

The lawsuit alleged that the data breach could have been prevented and was a result of a failure to implement reasonable and appropriate cybersecurity measures. The lawsuit asserted claims for negligence, breach of implied contract, unjust enrichment, and violations of the California Confidentiality of Medical Information Act, California’s Unfair Competition Law, and the California Consumer Privacy Act. DAP Health denies all material allegations, including claims of wrongdoing, fault, and liability.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Following extensive arm’s-length negotiations, all parties agreed to settle the litigation, with no admission of wrongdoing or liability by the defendant. Under the terms of the settlement, DAP Health has agreed to establish a $1.3 million settlement fund to cover attorneys’ fees and expenses, settlement administration costs, and service awards for the two class representatives. The remainder of the fund will be used to pay for class member benefits.

Class members may submit a claim for reimbursement of documented losses due to the data breach up to a maximum of $5,000 per class member. Regardless of whether a reimbursement claim is submitted, class members may claim a pro rata cash payment. The cash payments are estimated to be $25 per class member. Class members who were California residents on July 22, 2024, can also claim a statutory cash payment of $75. In addition, all class members can submit a claim for two years of complimentary credit monitoring and identity theft protection services.

The deadline for exclusion and objection is September 1, 2026. The deadline for submitting a claim is October 21, 2026. The settlement has received preliminary approval from the court, and the final fairness hearing has been scheduled for October 1, 2026.

The post DAP Health Settles Data Breach Lawsuit for $1,300,000 appeared first on The HIPAA Journal.

OnePoint Patient Care and Clay-Platte Family Medicine Settle Data Breach Lawsuits

Individuals affected by data breaches at OnePoint Patient Care and Clay-Platte Family Medicine may be entitled to claim benefits after settlements have been agreed to resolve class action lawsuits. The lawsuit against OnePoint Patient Care has been settled for $2,115,000, and the Clay-Platte Family Medicine lawsuit has been settled for $1,000,000.

OnePoint Patient Care Data Breach Settlement

OP Pharmacy, LLC, also known as OnePoint Patient Care, LLC, a Kentucky-based hospice-dedicated pharmacy and pharmacy benefits manager, was sued in response to a 2024 data breach. The lawsuit relates to a security incident detected by OnePoint on August 8, 2024. Hackers gained access to systems containing the protected health information of 1,741,152 individuals and copied files from its network between August 6 and August 8, 2024. At the time the lawsuit was filed, approximately 528,000 patients were living. Notification letters were mailed to the affected individuals in October and November, 2024

The lawsuit alleged that the defendant willfully, recklessly, or negligently maintained patient data, as it failed to implement appropriate cybersecurity measures and did not keep its systems free of vulnerabilities. Two lawsuits were filed in response to the breach, which were consolidated as they had overlapping claims. The consolidated lawsuit – Christopher Russo v. OP Pharmacy, LLC a/k/a OnePoint Patient Care, LLC – was filed in the District Court for the Western District of Kentucky, Louisville Division. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, breach of fiduciary duty, and for declaratory and injunctive relief.

The defendant disagrees with the claims and contentions in the lawsuit; however, a settlement was negotiated to avoid the cost and risks associated with a trial and related appeals. OnePoint will establish a $2,115,000 settlement fund, from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives will be deducted. The remaining funds will pay for class member benefits.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

A claim may be submitted for one of two cash payments: reimbursement of documented, unreimbursed losses due to the data breach up to $3,500 per class member, or an alternative pro rata cash payment, estimated to be $100 per claimant. The cash payments will be subject to a pro rata increase or decrease, depending on the number of valid claims received. In addition, OnePoint has agreed to implement additional security measures to reduce the risk of similar breaches in the future. The deadline for exclusion and opting out is August 24, 2026. The deadline for submitting a claim is October 8, 2026, and the final fairness hearing is scheduled for September 23, 2026.

Clay-Platte Family Medicine Data Breach Settlement

Clay-Platte Family Medicine and Barry Pointe Family Care in Kansas City, Missouri, and Cobblestone Family Medicine Clinic dba Clay Platte Family Medicine Clinic and Nathan D. Granger, dba Summit Family and Sports Medicine in Harrisonville, Missouri, were sued in response to a June 2024 data breach involving the electronic protected health information of patients. Hackers gained access to its network on or around June 26, 2024, and potentially viewed or obtained patient data such as names, contact information, dates of birth, Social Security numbers, and medical information.

Multiple class action lawsuits were filed in response to the data breach, which were consolidated into a single action – Highfill, et al. v. Clay-Platte Family Medicine Clinic, P.C., et al – in the U.S. District Court for the Western District of Missouri. The consolidated lawsuit alleged that the defendants failed to implement reasonable and appropriate safeguards to ensure the privacy of patient data, such as the encryption of data on its network. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, invasion of privacy by public disclosure of private facts, breach of fiduciary duty of confidentiality, negligent training and supervision, invasion of privacy, and violations of the Missouri Merchandising Practices Act.

The defendants deny any wrongdoing and sought to have the lawsuit dismissed. The motion to dismiss was granted in part, although certain claims were allowed to proceed. Following mediation and continued negotiations, a settlement was agreed to by all parties. The settlement class consists of the 53,916 individuals who were notified about the data breach. A $1,000,000 settlement fund will be established to pay for court-approved costs and benefits for the class members.

All class members are entitled to enroll in three years of free medical and credit monitoring services. In addition, a claim may be submitted for reimbursement of documented, unreimbursed losses or an alternative cash payment.  Claims for reimbursement of documented losses have been capped at $15,000 per class member. The remainder of the settlement fund will be paid pro rata to individuals who claim an alternative cash payment. The deadline for exclusion and opting out is September 6, 2026. The deadline for submitting a claim is September 30, 2026, and the final fairness hearing is scheduled for September 29, 2026.

The post OnePoint Patient Care and Clay-Platte Family Medicine Settle Data Breach Lawsuits appeared first on The HIPAA Journal.

Highland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits

Settlements have received preliminary approval to resolve class action data breach complaints against Highland Health Systems and Albany Gastroenterology Consultants that stem from breaches of patient data.

Highland Health Systems Data Breach Settlement

A settlement has been agreed to resolve a class action lawsuit against the nonprofit healthcare organization Highland Health Systems, CEO Mickey Turner, and Director of Finance Allen Stokes, stemming from a July 2023 data breach.

A security incident was identified in early July 2023, in which sensitive patient data was accessed and stolen by hackers. Data compromised in the incident included patient and employee data, including names, contact information, birth dates, Social Security numbers, account numbers, payment card information, medical information, health Insurance Information, tax IDs, and other sensitive data. The affected individuals were notified about the data breach on June 13, 2024, and the data breach was reported to the HHS’ Office for Civil Rights as involving the electronic protected health information of 83,543 individuals.

Two class action lawsuits were filed in response to the data breach, which were combined into a single action –Weyerman, et al. v. Highland Health Systems et al.– which is pending in the Circuit Court for Calhoun County, Alabama. The lawsuit alleges that the data breach was the result of the defendants’ negligence and could have been prevented if appropriate cybersecurity measures had been implemented. The lawsuit asserted claims for negligence/negligence per se, breach of express and/or implied contract, wantonness, breach of fiduciary duty, breach of confidence, and unjust enrichment.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The defendants denied all claims and contentions in the lawsuit and sought to have the lawsuit dismissed; however, the court rejected the motion to dismiss in its entirety. Mediation proved unsuccessful; however, a settlement agreement was subsequently negotiated that was acceptable to all parties. Highland Health Systems has agreed to establish a $650,000 settlement fund to cover the costs of litigation, attorneys’ fees, administration costs, and benefits for the class members.

Those benefits include a two-year membership to a medical identity protection service and one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses up to $5,000 per class member, or a one-time pro rata cash payment may be claimed, which is expected to be $85 per class member, but may be higher or lower depending on the number of valid claims received. The deadline for objection and opting out is September 28, 2026. Claims must be submitted by October 28, 2026, and the final approval hearing has been scheduled for November 30, 2026.

Albany Gastroenterology Consultants Data Breach Settlement

Albany Gastroenterology Consultants, PLLC, a New York gastroenterology practice, has agreed to settle litigation stemming from a November 2024 security incident. The incident occurred on or around November 10, 2024. Hackers gained access to its network, where the personally identifiable information and protected health information of 57,751 individuals was stored. Data potentially compromised in the incident included names, addresses, Social Security numbers, medical information, and health insurance information. The affected individuals started to be notified on January 28, 2025.

Multiple class action lawsuits were filed in response to the data breach in the Supreme Court of the State of New York, County of Albany. The defendant filed a motion to dismiss, and the plaintiffs filed their response. All parties agreed to engage in settlement discussions, and during those discussions, the parties agreed that the Circuit Court for the Eleventh Judicial Circuit in and for Miami-Dade County, Florida, was the proper venue and the New York state actions were voluntarily dismissed. The amended lawsuit was filed in Florida – Clements v. Albany Gastroenterology Consultants, PLLC. The negotiated settlement has received preliminary approval from the court.

The defendant will pay attorneys’ fees and expenses, service awards for the class representatives, and will establish a $200,00 settlement fund to pay benefits to the class members. Class members may submit a claim for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $2,500 per class member. Alternatively, a claim may be submitted for a one-time cash payment, expected to be around $10 per class member. In addition, class members are eligible to enrol in a 2-year membership to a credit monitoring and medical data monitoring service. The $200,000 settlement fund will be divided equally between the two cash payments. If the $100,000 for either is exceeded, claims will be paid pro rata. The deadline for objection and opting out is August 21, 2026. Claims must be submitted by October 5, 2026, and the final approval hearing has been scheduled for September 22, 2026.

The post Highland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits appeared first on The HIPAA Journal.

Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation

The volume and sensitive nature of the data stolen from Change Healthcare in its 2024 ransomware attack have led to strict rules being established for data handling by attorneys involved in a consolidated lawsuit against United Health Group (UHG), Change Healthcare, Optum, and other UHG subsidiaries. The rules will help to ensure that the dataset is protected at all times.

The ransomware attack resulted in the theft of approximately 6 terabytes of data, including files containing the electronic protected health information of an estimated 192,700,000 individuals, including names, contact information, Social Security numbers, driver’s license numbers, insurance information, and medical information. UHG paid the BlackCat ransomware group a $22 million ransom to delete the data; however, the operators pocketed the cash and didn’t pay the affiliate, who had retained a copy. The affiliate joined another ransom group, RansomHub, which attempted to extort UHG a second time.

This was the largest-ever healthcare data breach by some distance, and triggered dozens of lawsuits, including class action lawsuits filed by patients who had their data stolen and healthcare providers seeking compensation for the financial and operational disruptions they experienced. On June 7, 2024, the Judicial Panel on Multidistrict Litigation consolidated an initial 49 lawsuits, including 19 consumer complaints and 30 healthcare provider complaints, although the number of lawsuits included in the action has grown to more than 150. The consolidated lawsuit – In Re: Change Healthcare, Inc. Customer Data Security Breach Litigation – was centralized in the U.S. District Court for the District of Minnesota.

The stolen data files are designated discovery material, and due to the sensitive nature of the data and the volume of records, heightened security practices are required to protect against unauthorized access and data theft. The rules concerning the stolen dataset were approved by the plaintiffs’ attorneys and were verified by a cybersecurity expert as being sufficient to ensure the security of the data before being sent to the judge for approval. The stipulated protective order has recently been approved by Magistrate Judge Dulce Foster.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

UHG will provide a single copy of the data on an encrypted hard drive built to a federal security standard, and must provide the key to decrypt the data separately, to ensure that in the event of loss or theft of the drive, the data cannot be accessed. The plaintiffs’ attorneys are required to encrypt the data again once they have received the hard drive, using industry-standard encryption. No copies may be made of the data, and the data cannot be saved to the shared file library used by all individuals involved in the case. The plaintiffs’ attorneys are prohibited from using the dataset to identify or locate potential class members.

The hard drive must only be used on computers that are air-gapped – disconnected from the Internet and all networks, with no Wi-Fi or Bluetooth connectivity. The computers must be newly provisioned and updated prior to use, and when the computers are used, no cables, phones, or storage devices are permitted nearby.  When data access is required, only small samples may be accessed, and no more than 25 people are permitted access at any one time. All samples must be encrypted with strong encryption and a complex password set of at least 16 characters.

An audit trail must be maintained, including a detailed chain of custody of the drive and data, and the log must be provided to UHG on request. When the case ends, or if the plaintiffs’ claims are thrown out, the data must be securely destroyed within 30 days, using a government-approved data wiping method – NIST SP 800-88 – or the hard drive must be physically destroyed, and a detailed certificate of destruction obtained under penalty of perjury.

In the event of a security incident or unauthorized data access or data sharing, UHG must be notified within 48 hours. Should it turn out to be a genuine security incident, both sides are required to engage an external digital forensic firm, and if the plaintiffs are found to be at fault, they must pay the full investigation costs.

The post Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation appeared first on The HIPAA Journal.

Five Healthcare Providers Settle Pixel Class Action Lawsuits

Over the past 18 months, many healthcare providers have settled class action lawsuits over their use of website tracking and analytics tools. The list continues to grow with a further five settlements recently announced; however, class action lawsuits stemming from the use of tracking and analytics tools do not always result in settlements.

A proposed class action lawsuit against CRH Healthcare, doing business as Peachtree Immediate Care in Georgia, that alleged violations of the federal Electronic Communications Privacy Act and asserted claims for negligence/negligence per se, breach of implied contract, breach of express contract, breach of fiduciary duty, and unjust enrichment, has been dismissed with prejudice.

The judge ruled that the complaint was speculative, as the plaintiff failed to explain what damages had been suffered as a result of the defendant’s actions. The plaintiff has been given 14 days to file an amended complaint, or the lawsuit will be permanently dismissed. The decision shows that while tracking and analytics tools may result in disclosures of sensitive data to third parties, the plaintiff(s) must demonstrate that the disclosures resulted in a compensable injury.

Emanate Health Medical Center Pixel Settlement

Emanate Health Medical Center, a nonprofit healthcare organziation based in Covina, California, Emanate Health Medical Center faced multiple class action lawsuits over the use of tracking tools such as pixels. The lawsuits were consolidated into a single complaint – Ortega, et al., v. Emanate Health Medical Center – in the Superior Court of the State of California, County of Los Angeles.

The consolidated lawsuit asserted claims for violations of the California Invasion of Privacy Act, California Confidentiality of Medical Information Act, invasion of privacy under the California Constitution, and common law invasion of privacy – intrusion upon seclusion. Emanate Health Medical Center denies all allegations of wrongdoing and liability, and all material allegations in the lawsuit; however, it agreed to a settlement to avoid the risks and costs of lengthy litigation and the uncertainty of a trial and appeals.

Emanate Health has agreed to establish a $777,000 settlement fund to cover attorneys’ fees and expenses, settlement administration costs, and service awards for the four class representatives. The net settlement fund after costs and expenses have been deducted is expected to be approximately $433,709, which will be divided pro rata between all individuals who submit a claim. In the unlikely event that every class member submits a claim, that would equate to a payment of $11 per class member.

The class consists of individuals who logged in to the Emanate Health patient portal, and/or submitted an online form and/or scheduled an appointment on the Emanate Health website between August 30, 2019, and April 30, 2024. The deadline for objection and opting out is August 31, 2026. Claims must be submitted by September 29, 2026, and the final fairness hearing has been scheduled for November 19, 2026.

Bayhealth Medical Center Pixel Settlement

Bayhealth Medical Center, a hospital system serving patients in central and southern Delaware, faced multiple class action lawsuits over its use of third-party tracking pixels on its website, resulting in disclosures of website users’ sensitive data to third parties. The lawsuits were consolidated into a single complaint – Doe et al. v. Bayhealth Medical Center Inc., d/b/a Bayhealth – in the Superior Court of the State of Delaware

Bayhealth denies all wrongdoing and liability and sought to have the lawsuit dismissed; however, the motion to dismiss was denied, and the claims for negligence, breach of implied covenant of good faith and fair dealing, unjust enrichment, breach of confidentiality, and violation of the Delaware Consumer Fraud Act were allowed to proceed. After prolonged and extensive arm’s length negotiations and mediation, all parties agreed to a settlement to avoid the cost and time required for continued litigation and the uncertainties associated with a trial and related appeals.

Bayhealth has agreed to cover the cost of attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives, and will pay for two benefits for the class members. Class members are eligible to enroll in one year of medical data monitoring services and may submit a claim for a one-time cash payment of $25 per class member. The class consists of all patient portal users who used Bayhealth websites and patient portal websites between January 1, 2019, and December 31, 2025. The deadline for objection and opting out is September 4, 2026. Claims must be submitted by October 5, 2026, and the final fairness hearing has been scheduled for October 29, 2026.

Mount Sinai Medical Center of Florida Pixel Settlement

Mount Sinai Medical Center of Florida, aka Mount Sinai Medical Center, a Miami, FL-based hospital and the largest private, independent not-for-profit teaching hospital in the state, faced multiple class action lawsuits over its use of tracking, analytics, and advertising technologies on its website and patient portal. The lawsuits were consolidated into a single action – Boggiano, et al. v. Mount Sinai Medical Center of Florida a/k/a Mount Sinai Medical Center – in the Circuit Court for Broward County, Florida.

The lawsuit alleged that these tools resulted in the impermissible disclosure of personal and protected health information to third parties, without the knowledge or consent of patients. The lawsuit asserted claims for invasion of privacy and unjust enrichment. The defendant denies wrongdoing and liability, and disagrees with the claims and contentions in the lawsuit; however, after several months of negotiation and mediation, the terms of a settlement were agreed upon.

Mount Sinai Medical Center of Florida will pay attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives, as well as benefits for the class members. The class consists of individuals who accessed the Mount Sinai Medical Center’s Website or Patient Portal between June 10, 2021, and September 18, 2025.

Class members will receive an activation code for one year of medical data monitoring services without submitting a claim. Claims may be submitted for a one-time cash payment from a $220,000 settlement fund. Based on a typical claim volume, the cash payments are expected to be around $20 per class member but may be higher or lower depending on the number of valid claims received. The deadline for objection and opting out is September 14, 2026. Claims must be submitted by September 28, 2026, and the final fairness hearing has been scheduled for October 13, 2026.

University of Pennsylvania Health System (Penn Medicine) Pixel Settlement

The University of Pennsylvania Health System, doing business as Penn Medicine, was sued over its use of Meta Pixel, Google Analytics code, and other tracking, analytics, and advertising tools, which were alleged to have disclosed sensitive website user data to third parties such as Meta and Google.

Several lawsuits were filed in response to the alleged unlawful disclosures of personal and protected health information. The lawsuits were consolidated into a single complaint – Mohr, et al. v. The Trustees of The University of Pennsylvania as Owner and Operator of The University of Pennsylvania Health System (d/b/a Penn Medicine) – in the Court of Common Pleas of Philadelphia County, Pennsylvania. The lawsuit alleged the disclosures of personal and protected health information via these tools violated the Pennsylvania Wiretapping and Electronic Surveillance Control Act. Penn Medicine denies the claims and contentions in the lawsuit, including those related to negligence, fault, wrongdoing, and liability.

All parties agreed to a settlement to avoid the cost and risk of a trial, and the settlement has received preliminary approval from the court. Penn Medicine will establish a $9,500,000 settlement fund to cover attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. Class members may claim a one-time cash payment of up to $15. The defendant has stopped using Meta Pixel on its website, and will not use analytics and advertising technologies on the website for a period of at least two years.

The settlement class consists of individuals who used the myPennMedicine Patient Portal between January 23, 2021, and January 23, 2023. The deadline for objection and opting out is September 1, 2026. Claims must be submitted by September 16, 2026, and the final fairness hearing has been scheduled for November 12, 2026.

Concord Hospital Pixel Settlement

Concord Hospital Health System, a health system based in Concord, New Hampshire, was sued over its use of website tracking tools. The lawsuit – Branson v. Concord Hospital Inc. et al – names Concord Hospital, Inc., Concord Hospital – Laconia, Concord Hospital – Franklin, and Capital Region Healthcare Corporation as defendants, and was filed in the Hillsborough Superior Court, Manchester, New Hampshire.

The lawsuit alleges that the deployment of these tools resulted in disclosures of personal and protected health information to third parties such as Google and Geonetric, without the knowledge or consent of patients, in violation of the New Hampshire Wiretapping and Electronic Surveillance Act and New Hampshire Patient Privacy Law. The defendants deny all allegations in the lawsuit. The parties agreed to a settlement to avoid the costs and risk of a trial.

The settlement class consists of individuals whose information was allegedly intercepted by the tools between May 9, 2021, and the date of the preliminary settlement agreement. The defendants have agreed to establish an $800,000 settlement fund to pay benefits to the class members, after attorneys’ fees and expenses, settlement administration costs, and service awards have been deducted.  Each individual who submits a valid claim will receive an equal pro rata share of the remaining funds. The deadline for objection, opting out, and submitting a claim is September 11, 2026. The final fairness hearing has been scheduled for November 3, 2026.

The post Five Healthcare Providers Settle Pixel Class Action Lawsuits appeared first on The HIPAA Journal.