Legal News about HIPAA Compliance

Highland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits

Settlements have received preliminary approval to resolve class action data breach complaints against Highland Health Systems and Albany Gastroenterology Consultants that stem from breaches of patient data.

Highland Health Systems Data Breach Settlement

A settlement has been agreed to resolve a class action lawsuit against the nonprofit healthcare organization Highland Health Systems, CEO Mickey Turner, and Director of Finance Allen Stokes, stemming from a July 2023 data breach.

A security incident was identified in early July 2023, in which sensitive patient data was accessed and stolen by hackers. Data compromised in the incident included patient and employee data, including names, contact information, birth dates, Social Security numbers, account numbers, payment card information, medical information, health Insurance Information, tax IDs, and other sensitive data. The affected individuals were notified about the data breach on June 13, 2024, and the data breach was reported to the HHS’ Office for Civil Rights as involving the electronic protected health information of 83,543 individuals.

Two class action lawsuits were filed in response to the data breach, which were combined into a single action –Weyerman, et al. v. Highland Health Systems et al.– which is pending in the Circuit Court for Calhoun County, Alabama. The lawsuit alleges that the data breach was the result of the defendants’ negligence and could have been prevented if appropriate cybersecurity measures had been implemented. The lawsuit asserted claims for negligence/negligence per se, breach of express and/or implied contract, wantonness, breach of fiduciary duty, breach of confidence, and unjust enrichment.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The defendants denied all claims and contentions in the lawsuit and sought to have the lawsuit dismissed; however, the court rejected the motion to dismiss in its entirety. Mediation proved unsuccessful; however, a settlement agreement was subsequently negotiated that was acceptable to all parties. Highland Health Systems has agreed to establish a $650,000 settlement fund to cover the costs of litigation, attorneys’ fees, administration costs, and benefits for the class members.

Those benefits include a two-year membership to a medical identity protection service and one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses up to $5,000 per class member, or a one-time pro rata cash payment may be claimed, which is expected to be $85 per class member, but may be higher or lower depending on the number of valid claims received. The deadline for objection and opting out is September 28, 2026. Claims must be submitted by October 28, 2026, and the final approval hearing has been scheduled for November 30, 2026.

Albany Gastroenterology Consultants Data Breach Settlement

Albany Gastroenterology Consultants, PLLC, a New York gastroenterology practice, has agreed to settle litigation stemming from a November 2024 security incident. The incident occurred on or around November 10, 2024. Hackers gained access to its network, where the personally identifiable information and protected health information of 57,751 individuals was stored. Data potentially compromised in the incident included names, addresses, Social Security numbers, medical information, and health insurance information. The affected individuals started to be notified on January 28, 2025.

Multiple class action lawsuits were filed in response to the data breach in the Supreme Court of the State of New York, County of Albany. The defendant filed a motion to dismiss, and the plaintiffs filed their response. All parties agreed to engage in settlement discussions, and during those discussions, the parties agreed that the Circuit Court for the Eleventh Judicial Circuit in and for Miami-Dade County, Florida, was the proper venue and the New York state actions were voluntarily dismissed. The amended lawsuit was filed in Florida – Clements v. Albany Gastroenterology Consultants, PLLC. The negotiated settlement has received preliminary approval from the court.

The defendant will pay attorneys’ fees and expenses, service awards for the class representatives, and will establish a $200,00 settlement fund to pay benefits to the class members. Class members may submit a claim for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $2,500 per class member. Alternatively, a claim may be submitted for a one-time cash payment, expected to be around $10 per class member. In addition, class members are eligible to enrol in a 2-year membership to a credit monitoring and medical data monitoring service. The $200,000 settlement fund will be divided equally between the two cash payments. If the $100,000 for either is exceeded, claims will be paid pro rata. The deadline for objection and opting out is August 21, 2026. Claims must be submitted by October 5, 2026, and the final approval hearing has been scheduled for September 22, 2026.

The post Highland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits appeared first on The HIPAA Journal.

Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation

The volume and sensitive nature of the data stolen from Change Healthcare in its 2024 ransomware attack have led to strict rules being established for data handling by attorneys involved in a consolidated lawsuit against United Health Group (UHG), Change Healthcare, Optum, and other UHG subsidiaries. The rules will help to ensure that the dataset is protected at all times.

The ransomware attack resulted in the theft of approximately 6 terabytes of data, including files containing the electronic protected health information of an estimated 192,700,000 individuals, including names, contact information, Social Security numbers, driver’s license numbers, insurance information, and medical information. UHG paid the BlackCat ransomware group a $22 million ransom to delete the data; however, the operators pocketed the cash and didn’t pay the affiliate, who had retained a copy. The affiliate joined another ransom group, RansomHub, which attempted to extort UHG a second time.

This was the largest-ever healthcare data breach by some distance, and triggered dozens of lawsuits, including class action lawsuits filed by patients who had their data stolen and healthcare providers seeking compensation for the financial and operational disruptions they experienced. On June 7, 2024, the Judicial Panel on Multidistrict Litigation consolidated an initial 49 lawsuits, including 19 consumer complaints and 30 healthcare provider complaints, although the number of lawsuits included in the action has grown to more than 150. The consolidated lawsuit – In Re: Change Healthcare, Inc. Customer Data Security Breach Litigation – was centralized in the U.S. District Court for the District of Minnesota.

The stolen data files are designated discovery material, and due to the sensitive nature of the data and the volume of records, heightened security practices are required to protect against unauthorized access and data theft. The rules concerning the stolen dataset were approved by the plaintiffs’ attorneys and were verified by a cybersecurity expert as being sufficient to ensure the security of the data before being sent to the judge for approval. The stipulated protective order has recently been approved by Magistrate Judge Dulce Foster.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

UHG will provide a single copy of the data on an encrypted hard drive built to a federal security standard, and must provide the key to decrypt the data separately, to ensure that in the event of loss or theft of the drive, the data cannot be accessed. The plaintiffs’ attorneys are required to encrypt the data again once they have received the hard drive, using industry-standard encryption. No copies may be made of the data, and the data cannot be saved to the shared file library used by all individuals involved in the case. The plaintiffs’ attorneys are prohibited from using the dataset to identify or locate potential class members.

The hard drive must only be used on computers that are air-gapped – disconnected from the Internet and all networks, with no Wi-Fi or Bluetooth connectivity. The computers must be newly provisioned and updated prior to use, and when the computers are used, no cables, phones, or storage devices are permitted nearby.  When data access is required, only small samples may be accessed, and no more than 25 people are permitted access at any one time. All samples must be encrypted with strong encryption and a complex password set of at least 16 characters.

An audit trail must be maintained, including a detailed chain of custody of the drive and data, and the log must be provided to UHG on request. When the case ends, or if the plaintiffs’ claims are thrown out, the data must be securely destroyed within 30 days, using a government-approved data wiping method – NIST SP 800-88 – or the hard drive must be physically destroyed, and a detailed certificate of destruction obtained under penalty of perjury.

In the event of a security incident or unauthorized data access or data sharing, UHG must be notified within 48 hours. Should it turn out to be a genuine security incident, both sides are required to engage an external digital forensic firm, and if the plaintiffs are found to be at fault, they must pay the full investigation costs.

The post Strict Rules Set for Change Healthcare Dataset in Multidistrict Litigation appeared first on The HIPAA Journal.

Five Healthcare Providers Settle Pixel Class Action Lawsuits

Over the past 18 months, many healthcare providers have settled class action lawsuits over their use of website tracking and analytics tools. The list continues to grow with a further five settlements recently announced; however, class action lawsuits stemming from the use of tracking and analytics tools do not always result in settlements.

A proposed class action lawsuit against CRH Healthcare, doing business as Peachtree Immediate Care in Georgia, that alleged violations of the federal Electronic Communications Privacy Act and asserted claims for negligence/negligence per se, breach of implied contract, breach of express contract, breach of fiduciary duty, and unjust enrichment, has been dismissed with prejudice.

The judge ruled that the complaint was speculative, as the plaintiff failed to explain what damages had been suffered as a result of the defendant’s actions. The plaintiff has been given 14 days to file an amended complaint, or the lawsuit will be permanently dismissed. The decision shows that while tracking and analytics tools may result in disclosures of sensitive data to third parties, the plaintiff(s) must demonstrate that the disclosures resulted in a compensable injury.

Emanate Health Medical Center Pixel Settlement

Emanate Health Medical Center, a nonprofit healthcare organziation based in Covina, California, Emanate Health Medical Center faced multiple class action lawsuits over the use of tracking tools such as pixels. The lawsuits were consolidated into a single complaint – Ortega, et al., v. Emanate Health Medical Center – in the Superior Court of the State of California, County of Los Angeles.

The consolidated lawsuit asserted claims for violations of the California Invasion of Privacy Act, California Confidentiality of Medical Information Act, invasion of privacy under the California Constitution, and common law invasion of privacy – intrusion upon seclusion. Emanate Health Medical Center denies all allegations of wrongdoing and liability, and all material allegations in the lawsuit; however, it agreed to a settlement to avoid the risks and costs of lengthy litigation and the uncertainty of a trial and appeals.

Emanate Health has agreed to establish a $777,000 settlement fund to cover attorneys’ fees and expenses, settlement administration costs, and service awards for the four class representatives. The net settlement fund after costs and expenses have been deducted is expected to be approximately $433,709, which will be divided pro rata between all individuals who submit a claim. In the unlikely event that every class member submits a claim, that would equate to a payment of $11 per class member.

The class consists of individuals who logged in to the Emanate Health patient portal, and/or submitted an online form and/or scheduled an appointment on the Emanate Health website between August 30, 2019, and April 30, 2024. The deadline for objection and opting out is August 31, 2026. Claims must be submitted by September 29, 2026, and the final fairness hearing has been scheduled for November 19, 2026.

Bayhealth Medical Center Pixel Settlement

Bayhealth Medical Center, a hospital system serving patients in central and southern Delaware, faced multiple class action lawsuits over its use of third-party tracking pixels on its website, resulting in disclosures of website users’ sensitive data to third parties. The lawsuits were consolidated into a single complaint – Doe et al. v. Bayhealth Medical Center Inc., d/b/a Bayhealth – in the Superior Court of the State of Delaware

Bayhealth denies all wrongdoing and liability and sought to have the lawsuit dismissed; however, the motion to dismiss was denied, and the claims for negligence, breach of implied covenant of good faith and fair dealing, unjust enrichment, breach of confidentiality, and violation of the Delaware Consumer Fraud Act were allowed to proceed. After prolonged and extensive arm’s length negotiations and mediation, all parties agreed to a settlement to avoid the cost and time required for continued litigation and the uncertainties associated with a trial and related appeals.

Bayhealth has agreed to cover the cost of attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives, and will pay for two benefits for the class members. Class members are eligible to enroll in one year of medical data monitoring services and may submit a claim for a one-time cash payment of $25 per class member. The class consists of all patient portal users who used Bayhealth websites and patient portal websites between January 1, 2019, and December 31, 2025. The deadline for objection and opting out is September 4, 2026. Claims must be submitted by October 5, 2026, and the final fairness hearing has been scheduled for October 29, 2026.

Mount Sinai Medical Center of Florida Pixel Settlement

Mount Sinai Medical Center of Florida, aka Mount Sinai Medical Center, a Miami, FL-based hospital and the largest private, independent not-for-profit teaching hospital in the state, faced multiple class action lawsuits over its use of tracking, analytics, and advertising technologies on its website and patient portal. The lawsuits were consolidated into a single action – Boggiano, et al. v. Mount Sinai Medical Center of Florida a/k/a Mount Sinai Medical Center – in the Circuit Court for Broward County, Florida.

The lawsuit alleged that these tools resulted in the impermissible disclosure of personal and protected health information to third parties, without the knowledge or consent of patients. The lawsuit asserted claims for invasion of privacy and unjust enrichment. The defendant denies wrongdoing and liability, and disagrees with the claims and contentions in the lawsuit; however, after several months of negotiation and mediation, the terms of a settlement were agreed upon.

Mount Sinai Medical Center of Florida will pay attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives, as well as benefits for the class members. The class consists of individuals who accessed the Mount Sinai Medical Center’s Website or Patient Portal between June 10, 2021, and September 18, 2025.

Class members will receive an activation code for one year of medical data monitoring services without submitting a claim. Claims may be submitted for a one-time cash payment from a $220,000 settlement fund. Based on a typical claim volume, the cash payments are expected to be around $20 per class member but may be higher or lower depending on the number of valid claims received. The deadline for objection and opting out is September 14, 2026. Claims must be submitted by September 28, 2026, and the final fairness hearing has been scheduled for October 13, 2026.

University of Pennsylvania Health System (Penn Medicine) Pixel Settlement

The University of Pennsylvania Health System, doing business as Penn Medicine, was sued over its use of Meta Pixel, Google Analytics code, and other tracking, analytics, and advertising tools, which were alleged to have disclosed sensitive website user data to third parties such as Meta and Google.

Several lawsuits were filed in response to the alleged unlawful disclosures of personal and protected health information. The lawsuits were consolidated into a single complaint – Mohr, et al. v. The Trustees of The University of Pennsylvania as Owner and Operator of The University of Pennsylvania Health System (d/b/a Penn Medicine) – in the Court of Common Pleas of Philadelphia County, Pennsylvania. The lawsuit alleged the disclosures of personal and protected health information via these tools violated the Pennsylvania Wiretapping and Electronic Surveillance Control Act. Penn Medicine denies the claims and contentions in the lawsuit, including those related to negligence, fault, wrongdoing, and liability.

All parties agreed to a settlement to avoid the cost and risk of a trial, and the settlement has received preliminary approval from the court. Penn Medicine will establish a $9,500,000 settlement fund to cover attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. Class members may claim a one-time cash payment of up to $15. The defendant has stopped using Meta Pixel on its website, and will not use analytics and advertising technologies on the website for a period of at least two years.

The settlement class consists of individuals who used the myPennMedicine Patient Portal between January 23, 2021, and January 23, 2023. The deadline for objection and opting out is September 1, 2026. Claims must be submitted by September 16, 2026, and the final fairness hearing has been scheduled for November 12, 2026.

Concord Hospital Pixel Settlement

Concord Hospital Health System, a health system based in Concord, New Hampshire, was sued over its use of website tracking tools. The lawsuit – Branson v. Concord Hospital Inc. et al – names Concord Hospital, Inc., Concord Hospital – Laconia, Concord Hospital – Franklin, and Capital Region Healthcare Corporation as defendants, and was filed in the Hillsborough Superior Court, Manchester, New Hampshire.

The lawsuit alleges that the deployment of these tools resulted in disclosures of personal and protected health information to third parties such as Google and Geonetric, without the knowledge or consent of patients, in violation of the New Hampshire Wiretapping and Electronic Surveillance Act and New Hampshire Patient Privacy Law. The defendants deny all allegations in the lawsuit. The parties agreed to a settlement to avoid the costs and risk of a trial.

The settlement class consists of individuals whose information was allegedly intercepted by the tools between May 9, 2021, and the date of the preliminary settlement agreement. The defendants have agreed to establish an $800,000 settlement fund to pay benefits to the class members, after attorneys’ fees and expenses, settlement administration costs, and service awards have been deducted.  Each individual who submits a valid claim will receive an equal pro rata share of the remaining funds. The deadline for objection, opting out, and submitting a claim is September 11, 2026. The final fairness hearing has been scheduled for November 3, 2026.

The post Five Healthcare Providers Settle Pixel Class Action Lawsuits appeared first on The HIPAA Journal.

Ransom Cartel Mastermind Sentenced to 16 Years in Prison

The Belarusian cybercriminal behind the Ransom Cartel ransomware group has been sentenced to 16 years in prison for his role in ransomware attacks on at least 18 companies worldwide.

Maksim Silnikau, 40, was the creator and administrator of the Ransom Cartel ransomware-as-a-service operation and recruited other cybercriminals to conduct ransomware attacks globally. According to court documents, Silnikau began developing the ransomware operation in May 2021, initially under a different name, before rebranding it as Ransom Cartel in 2022. Between 2021 and 2023, along with his co-conspirators, at least 18 companies fell victim to attacks, including companies in California, New York, and Nebraska. The attacks caused more than $6.7 million in losses, and the group attempted to extort at least $5.2 million from victims.

Silnikau did not conduct many of the intrusions himself. He was the administrator of the operation and purchased stolen credentials from initial access brokers, recruited affiliates to conduct attacks, negotiated with victims, used cryptocurrency mixers to hide the proceeds from the attacks, and split the money with the group’s affiliates.

Silnikau has a long history of cybercrime, having reportedly been a core member of the REvil ransomware operation, a member of Russian-speaking cybercrime forums since at least 2005, and a member of the cybercrime website Direct Connection from 2011 until the site was shut down in 2016. Silnikau was involved in the distribution of the Angler exploit kit and various malvertising and malware distribution schemes between October 2013 and March 2022. Along with a Ukrainian national and a Russian national, Silnikau was charged with participation in the distribution of the Angler exploit kit in a separate indictment in New Jersey.

Following an international law enforcement investigation, Silnikau was arrested in Spain on July 18, 2023; however, fled while awaiting extradition to the United States to face the charges. He was recaptured attempting to return to Belarus from Poland and was extradited to the U.S. from Poland in 2024 to face the charges in the Eastern District of Virginia. Prosecutors charged Silnikau with seven counts, although he was only convicted on three: conspiracy to commit offenses against the United States, wire fraud, and aggravated identity theft, and was sentenced to 16 years in jail.

The post Ransom Cartel Mastermind Sentenced to 16 Years in Prison appeared first on The HIPAA Journal.

Settlements Resolve Data Breach Lawsuits Against McKenzie Health System & Aspire Health Alliance

Settlements have been agreed to resolve class action data breach lawsuits against McKenzie Health System in Michigan and Aspire Health Alliance in Massachusetts.

McKenzie Health System Data Breach Settlement

McKenzie Health System, the operator of the McKenzie Memorial Hospital, a critical access hospital in Sanilac County, Michigan, has settled a class action lawsuit that was filed in response to an April 2025 cyberattack and data breach. McKenzie Health identified unauthorized access to its computer network on April 15, 2025. The forensic investigation determined that an unauthorized third party accessed its network between April 14, 2025, and April 15, 2025, and potentially obtained files containing patient information.

Data potentially compromised in the incident included names, addresses, birth dates, Social Security numbers, patient account numbers, medical record numbers, diagnosis and treatment information. The data breach was reported to the HHS’ Office for Civil Rights as affecting 58,839 individuals, who started to be notified on or around July 24, 2025.

Several class action lawsuits were filed in response to the data breach, which were consolidated into a single action – In Re: McKenzie Memorial Hospital d/b/a McKenzie Health System 2025 Data Breach Litigation – in the Circuit Court for Sanilac County, Michigan. The consolidated lawsuit alleges that the cyberattack and data breach should have been prevented and occurred due to the defendant’s negligence.

McKenzie Health denies wrongdoing and liability; however, it agreed to a settlement to avoid the litigation costs and expenses, distractions, burden, expense, and disruption to its business operations associated with further litigation. McKenzie Health has agreed to pay attorneys’ fees and expenses, settlement administration costs, and service awards for the eight class representatives.

Under the terms of the settlement, all class members are eligible to enroll in two years of credit monitoring and identity theft protection services. In addition, they may either submit a claim for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $4,000 per class member or claim a one-time $50.00 cash payment. The deadline for opting out, objecting, and submitting a claim is August 24, 2026. The final fairness hearing has been scheduled for October 6, 2026.

Aspire Health Alliance Data Breach Settlement

South Shore Mental Health Center, Inc., doing business as Aspire Health Alliance, a state-designated community behavioral health center with facilities in Quincy, Braintree, and Marshfield in Massachusetts, has agreed to settle class action litigation stemming from a September 2023 cybersecurity incident that affected 17,490 individuals.

Aspire Health Alliance detected unauthorized network access on September 13, 2023, and confirmed that an unauthorized third party accessed and acquired files containing patient information, including names, dates of birth, dates of service, health insurance information, condition or treatment information, Medicare/Medicaid numbers, and patient account numbers. The affected individuals started to be notified about the data breach on April 26, 2024.

On May 10, 2024, a class action lawsuit was filed in the Superior Court of the Commonwealth of Massachusetts, Norfolk County, which was subsequently moved to the Superior Court of the Commonwealth of Massachusetts, Suffolk County. The lawsuit – Joan Tozzi v. South Shore Mental Health Center, Inc. d/b/a Aspire Health Alliance – alleged that the data breach could have been prevented as it occurred as a result of the failure to implement reasonable and appropriate cybersecurity measures. The lawsuit asserted claims for negligence, breach of implied contract, breach of fiduciary duty, and unjust enrichment. Aspire Health Alliance denies wrongdoing or liability.

All parties agreed to a settlement to avoid further legal costs and the uncertainty of a trial and related appeals. Under the terms of the settlement, Aspire Health Alliance has agreed to establish a $400,000 settlement fund to cover class member benefits, attorneys’ fees and expenses, settlement administration costs, and a service award for the class representative.

Class members are entitled to a one-year membership to the CyEx Medical Shield medical data monitoring service and may also submit a claim for one of two cash payments: reimbursement of documented, unreimbursed losses up to a maximum of $2,500 per class member, or a pro rata cash payment, the value of which will depend on the number of valid claims received. The deadline for objection, opting out, and submitting a claim is September 16, 2026. The final fairness hearing has been scheduled for October 1, 2026.

The post Settlements Resolve Data Breach Lawsuits Against McKenzie Health System & Aspire Health Alliance appeared first on The HIPAA Journal.

Data Breach Lawsuits Settled by Omni Healthcare & Western Montana Clinic

Settlements have been agreed to resolve class action data breach lawsuits against Omni Healthcare Financial Holdings and its subsidiaries, and Western Montana Clinic.

Omni Healthcare Financial Holdings Data Breach Settlement

Omni Healthcare Financial Holdings, along with defendants Omni Healthcare Financial, LLC, and Injury Finance, LLC (Omni Healthcare), have settled class action litigation over a January 2024 cybersecurity incident involving the protected health information of 16,852 individuals.

Omni Healthcare, a provider of financial solutions to healthcare organizations and patients, experienced a cybersecurity incident involving unauthorized network access between January 18 and January 19, 2024. Information exposed in the incident included names, contact information, dates of birth, Social Security numbers, diagnosis & treatment information, medical record numbers, treatment costs, provider names, and other information. The affected individuals were notified in April 2025, 15 months after the breach was first detected. In total, Omni Healthcare mailed around 42,000 notifications.

The first class action lawsuit was filed by plaintiff Latasha Hammond on April 16, 2025, followed by a second lawsuit by plaintiff Dawn Hairston. Both lawsuits were filed in the District Court for the Western District of North Carolina, and were consolidated, adding a further two plaintiffs – Hammond et al. v. Omni Healthcare Financial Holdings et al. The litigation was subsequently moved to the Superior Court of Mecklenburg County, North Carolina, where it is pending.

The consolidated lawsuit alleged that the data breach could have been prevented and occurred as a result of the defendants’ failure to implement appropriate industry-standard cybersecurity measures, and its failure to comply with the standards of the HIPAA Privacy and Security Rules. The lawsuit asserted claims for negligence/negligence per se, breach of implied contract, and unjust enrichment. The defendants deny all claims and contentions in the lawsuit, including claims of wrongdoing, fault, and liability.

The parties determined that a settlement was the best outcome, as it avoids further legal costs and the uncertainties of a trial and related appeals. The defendants will cover the cost of attorneys’ fees and expenses, settlement administration costs, service awards for the class representatives, and benefits for the class members.

Class members are entitled to enroll in three years of medical data monitoring and medical identity theft services and may submit a claim for one of two cash payments:

  • Cash Payment A – Reimbursement of documented, unreimbursed losses due to the data breach up to $5,000 per class member, or
  • Cash Payment B – A one-time cash payment of $40 per class member

The final approval hearing has been scheduled for August 13, 2026, and the claims deadline is September 3, 2026.

Western Montana Clinic Data Breach Settlement

Western Montana Clinic, a medical group practice in Missoula, MT, has settled a class action lawsuit stemming from a breach of its email environment in Spring 2025. Suspicious email activity was detected on April 15, 2025, and the forensic investigation confirmed unauthorized access to certain employee email accounts between March 11, 2025, and April 15, 2025.

The data review determined that the protected health information of 8,255 individuals was compromised, and 9,506 individuals were affected in total. Data exposed in the incident included contact information, Social Security numbers, dates of birth, treating physician names, internal identification numbers, dates of service, medication information, diagnostic information, and treatment information. The affected individuals were notified on August 8, 2025.

Western Montana Clinic was sued over the data breach, and the lawsuit – Murphy v. Western Montana Clinic – is pending in the Fourth Judicial District of Montana. The lawsuit claimed the data breach occurred as a result of the failure of the clinic to implement reasonable and appropriate cybersecurity measures, and asserted claims for negligence, negligence per se, breach of implied contract, and unjust enrichment. Western Montana Clinic denies wrongdoing and liability; however, it agreed to settle the lawsuit to avoid the litigation costs and expenses, distractions, burden, and disruption to its business operations associated with further litigation.

Western Montana Clinic has agreed to pay attorneys’ fees and expenses, settlement administration costs, $2,500 service awards to the two named plaintiffs, and class member benefits. Class members may claim a one-year membership to a medical data monitoring service, up to three hours of lost time at $20 per hour, and reimbursement of documented, unreimbursed out-of-pocket losses up to a maximum of $5,000 per class member. The deadline for exclusion and objection is August 17, 2026. Claims must be submitted by September 15, 2026, and the final fairness hearing has been scheduled for September 9, 2026.

The post Data Breach Lawsuits Settled by Omni Healthcare & Western Montana Clinic appeared first on The HIPAA Journal.

FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices

Him & Hers, a San Francisco, CA-based telehealth company, is being sued by the Federal Trade Commission (FTC) and the states of Utah and California over the company’s business and data sharing practices, which are alleged to violate the Federal Trade Act, Restore Online Shoppers’ Confidence Act, Utah Consumer Sales Practices Act, and California’s False Advertising and Unfair Competition Laws.

Him & Hers is a direct-to-consumer business that provides prescription and over-the-counter medications. According to the complaint, filed last week in the U.S. District Court for the Northern District of California, the company claims to maintain consumers’ privacy yet discloses their sensitive data to third-party advertising platforms, without consumers’ knowledge or consent. In addition, the complaint alleges that the company deceives consumers about its billing and cancellation policies.

Him & Hers used tracking technologies such as Meta Pixel and the Meta Conversions API, which automate the recording of user data based on the Him & Hers website and transmit that information to Meta in response to certain events. Him & Hers also used a variety of advertising tools from companies such as Snap, Microsoft, Google, Criteo, Pinterest, TikTok, Trade Desk, and X, which also collected sensitive consumer information and transferred the information to third-party companies for advertising purposes. Him & Hers is also alleged to have sent lists of certain customers to the Meta and Snap custom audience systems.

Oftentimes, consumers use Him & Hers to obtain medications for sensitive medical conditions such as mental health issues, erectile dysfunction, and premature ejaculation. According to the complaint, until at least mid-2023, Him & Hers claimed that “medical records and sensitive information are only accessed by the medical providers managing your care,” and has claimed in its online advertising that consumers are provided with a “100% online, private, and secure process,” yet sensitive information was being shared with third parties for advertising purposes.

In addition to the unlawful data transfers, the complaint alleges that Him & Hers failed to clearly disclose that consumer prescriptions are charged almost immediately after completing an intake form. Consumers were informed that they could consult with a medical provider to find a suitable treatment and would not be charged unless and until their prescriptions are prescribed. The FTC alleges that Him & Hers rarely provides medical consultations, enrolls customers almost immediately into recurring subscription plans, and makes it difficult for consumers to cancel their subscriptions. For instance, consumers are not informed clearly and conspicuously when their recurring prescriptions will be refilled, which makes it difficult for them to cancel before the next billing cycle. Consumers are also not permitted to cancel subscriptions online, only via the phone, email, or chat, and the complaint alleges that consumers must navigate other hurdles, making it “extremely difficult” to cancel subscriptions.

The lawsuit seeks a permanent injunction preventing the company from engaging in unfair and deceptive business practices, civil penalties, and monetary awards. “The FTC’s complaint lays out a troubling scenario—consumers unknowingly locked into recurring subscriptions and the disclosure to third parties of consumers’ most private health information without their consent,” said Christopher Mufarrige, Director of the FTC’s Bureau of Consumer Protection. “The FTC will not hesitate to act on behalf of consumers deprived of their ability to choose which products they want and whether to keep their most sensitive health information private.”

This is not the first time that the FTC has taken action against telehealth companies over the use of tracking technologies. Enforcement actions have previously been filed against the fertility tracking app Premom, BetterHelp, and GoodRx. In each case, the complaints were resolved with financial penalties.

The post FTC; Utah; California Sue Him & Hers Over Business and Data Sharing Practices appeared first on The HIPAA Journal.

Banner Health; LifeStance Health Group Settle Tracking Technology Lawsuits

Two healthcare providers have agreed to settle lawsuits over their use of pixels and other website tracking technologies. The tools allegedly resulted in the disclosure of patient data to the third-party providers of those tools, without the knowledge or consent of website users.

Banner Health Pixel Settlement

Banner Health is a Phoenix, Arizona-based health system that operates 33 hospitals in six U.S. states. Banner Health faced multiple class action lawsuits over its use of pixels and other tracking and analytics tools on its website between June 1, 2020, and November 22, 2023, which were alleged to have disclosed sensitive information to Meta Platforms (Facebook) and Google LLC. The lawsuits were consolidated into a single action – McCulley, et al. v. Banner Health – as they had overlapping claims. The consolidated lawsuit, which names 8 individuals as class representatives, was filed in the District Court for Weld County in the State of Colorado.

The lawsuit asserted claims for breach of confidence, violation of the Electronic Communications Privacy Act (unauthorized interception, use, and disclosure), invasion of privacy-intrusion upon seclusion, unjust enrichment, violations of the Arizona Consumer Fraud Act, California Invasion of Privacy Act, California Confidentiality of Medical Information Act, California Unfair Competition Law, and Colorado Consumer Protection Act. Banner Health denies any wrongdoing and liability.

All parties agreed to a settlement to bring the litigation to an end, and avoid further legal costs and expenses and the uncertainty of a trial. There are approximately 1,028,000 individuals in the settlement class, which consists of individuals who logged into a Banner Health patient account (MyBanner patient portal) between June 1, 2020, and November 22, 2023.

Banner Health has agreed to pay attorneys’ fees and expenses (up to $3,750,000), settlement administration costs, and service awards of $2,500 to each of the 8 class representatives. All class members are entitled to claim a one-time cash payment of $20 and are eligible to receive a one-year membership for the CyEx Privacy Shield Pro service. The deadline for objection, opting out, and submitting a claim is September 5, 2026. The final fairness hearing has been scheduled for September 10, 2026.

LifeStance Health Group Pixel Settlement

LifeStance Health Group is a Scottsdale, Arizona provider of outpatient behavioral health services. Two class action lawsuits were filed alleging that the defendant disclosed information about individuals’ physical and mental health and other sensitive patient information to third parties via tracking tools on its website. The plaintiffs alleged that the tools were used without their knowledge or consent. The lawsuits were consolidated into a single action – Montana Strong, et al. v. LifeStance Health Group Incorporated – in the United States District Court for the District of Arizona.

The lawsuit asserted claims for violation of the California Invasion of Privacy Act, California Confidentiality of Medical Information Act, Electronic Communications Privacy Act (unauthorized interception, use, and disclosure), California Unfair Competition Law, Arizona Consumer Fraud Act, New York General Business Law, and common law invasion of privacy-intrusion upon seclusion. LifeStance Health Group denies all claims and contentions in the lawsuit, including claims of liability and wrongdoing. All parties agreed to a settlement to avoid the cost and distraction of continuing with the litigation and the uncertainty of a trial.

There are two settlement subclasses. Subclass 1 includes all individuals who booked at least one session through the LifeStance online booking tool, accessed through the lifestance.com website, between March 1, 2020, and April 30, 2023. Settlement subclass 2 consists of other members of the LifeStance patient population between the same dates, who are not members of subclass 1.

LifeStance has agreed to establish a $3,027,874.44 settlement fund, which will be split into a subclass 1 fund of $1,203,405.00 and a subclass 2 fund of $1,824,469.44. Attorneys’ fees and expenses and other costs such as settlement administration expenses and service awards for the class representatives will be deducted from those settlement funds. The remainder will be paid to individuals who submit a valid claim.

LifeStance has agreed to discontinue the use of all third-party tracking tools, other than tools that are fully compliant with the HIPAA Rules, for a period of five years from the settlement date. The deadline for objection and opting out is August 31, 2026. Claims must be submitted by September 29, 2026, and the final approval hearing has been scheduled for October 16, 2026.

The post Banner Health; LifeStance Health Group Settle Tracking Technology Lawsuits appeared first on The HIPAA Journal.

$3 Million Settlement Agreed to Resolve Healthcare Services Group Data Breach Litigation

Healthcare Services Group has agreed to pay $3,000,000 to settle litigation arising from a September 2024 cybersecurity incident that involved unauthorized access to systems containing the personal and protected health information of 624,496 individuals.

Healthcare Services Group is a Bensalem, PA-based provider of environmental, dining, and nutritional support services, and works with more than 3,000 healthcare facilities in 48 U.S. states. Suspicious network activity was identified on or around October 7, 2024, and the forensic investigation determined that its network was first breached by an unauthorized third party on September 27, 2024.

Prompt action was taken to prevent further unauthorized access, but files containing protected health information had already been exfiltrated from its network. Those files contained information such as names, Social Security numbers, driver’s license numbers, state identification numbers, financial account details, full access credentials, and medical and health insurance information.

Notification letters started to be mailed to the affected individuals on August 25, 2025, and on August 27, 2025, the first class action lawsuit was filed. Further lawsuits were filed that made similar claims, and the actions were consolidated into a single complaint – Williamson, et al. v. Healthcare Services Group, Inc. – in the United States District Court for the Eastern District of Pennsylvania.

The consolidated lawsuit asserted claims for negligence, breach of implied contract, breach of contracts to which the plaintiffs and class members were intended third-party beneficiaries, breach of fiduciary duty, unjust enrichment, violations of the New Jersey Consumer Fraud Act and Washington Consumer Protection Act, and declaratory and injunctive relief.

Healthcare Services Group denies any wrongdoing and disagrees with all claims and contentions in the lawsuit. All parties agreed to a settlement as they concluded that further litigation would likely be expensive and protracted, and by settling, all parties avoid the uncertainty and risks of a trial.

Healthcare Services Group has agreed to establish a $3,000,000 settlement from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class members will be deducted. The remaining funds will be used to pay benefits to the class members. Class members are entitled to claim three years of single-bureau credit monitoring services, which include identity theft insurance and identity theft recovery services.

A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member, and a claim may also be submitted for a one-time pro rata cash payment. The cash payments will exhaust the settlement fund, and their value depends on the number of valid claims received. Requests for exclusion and objections must be submitted by September 4, 2026. The deadline for submitting a claim is October 1, 2026, and the final fairness hearing is scheduled for September 24, 2026.

The post $3 Million Settlement Agreed to Resolve Healthcare Services Group Data Breach Litigation appeared first on The HIPAA Journal.