Legal News about HIPAA Compliance

Wellstar Health System & Cone Health Settle Pixel Lawsuits

Settlements have been agreed to resolve class action lawsuits against Wellstar Health System and Moses H. Cone Memorial Hospital Operating Corporation (Cone Health). The lawsuits stem from the defendants’ use of pixels and other website tracking tools, which are alleged to have resulted in impermissible disclosures of patient data to third parties such as Meta and Google.

Wellstar Health System Pixel Settlement

Wellstar Health System, a Marietta, Georgia-based health system with more than 400 care locations in the state, was sued over its use of tracking tools on its website that are alleged to have resulted in the disclosure of personally identifiable information and protected health information to third parties such as Alphabet Inc. (Google) and Meta Platforms (Facebook), without website users’ knowledge or consent.

The first lawsuit was filed on April 23, 2024, and an amended complaint was filed on August 2, 2024, adding three additional plaintiffs. The lawsuit – Doe v. Wellstar Health System, Inc. –  is pending in the United States District Court for the Northern District of Georgia. The lawsuit asserted claims for invasion of privacy – intrusion upon seclusion, breach of fiduciary duty, negligence, negligence per se, breach of implied contract, breach of express contract, unjust enrichment, and violations of the Electronic Communications Privacy Act. The defendant denies all claims and contentions in the lawsuit and maintains that there was no wrongdoing. A settlement was agreed to by all parties to avoid the time, expense, and uncertainty of a trial and related appeals.

Wellstar Health System has agreed to establish a $4,500,000 settlement fund, from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives will be deducted. The remainder of the settlement fund will be divided equally among all class members who submit a valid claim. The class consists of individuals whose personally identifiable information and/or protected health information was disclosed to third parties via the tracking tools between February 19, 2020, and July 22, 2026. Any remaining settlement funds, such as from uncashed checks, will be distributed to the Good Samaritan Health Center of Cobb.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The deadline for objection and opting out is October 26, 2026. Claims must be submitted by November 10, 2026, and the final fairness hearing has been scheduled for December 1, 2026.

Moses H. Cone Memorial Hospital Operating Corporation (Cone Health) Pixel Settlement

Greensboro, North Carolina-based defendants The Moses H. Cone Memorial Hospital Operating Corporation, d/b/a Cone Health, and The Moses H. Cone Memorial Hospital, d/b/a Cone Health, were sued over the use of tracking tools such as pixels, which had been added to their public website without the knowledge or consent of website users. The lawsuit alleged that the use of the tracking code resulted in disclosures of users’ confidential health information and protected health information to third parties such as Alphabet Inc (Google) and Meta Platforms (Facebook).

The lawsuit, Singh v. The Moses H. Cone Memorial Hospital Operating Corp., et al., is pending in the United States District Court for the Middle District of North Carolina. The lawsuit asserted claims for violation of the Electronic Communications Privacy Act, breach of express contract, breach of implied duty of good faith and fair dealing, breach of implied contract, negligence, breach of fiduciary duty, and unjust enrichment. The defendants maintain that there was no wrongdoing; however, a settlement was agreed by all parties to avoid the costs, delays, and uncertainties of continued litigation.

Cone Health has agreed to establish a $1,765,000 settlement fund, which will be used to pay reasonable attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. After those costs have been deducted, the net settlement fund will be distributed equally among the class members. The value of each cash payment will depend on the number of valid claims received.

The settlement class consists of all individuals who accessed the MyChart patient portal on the defendants’ website between September 1, 2016, and November 3, 2022, as well as any individual who completed a submission form on the defendants’ website between the same dates. The settlement has received preliminary approval from the court. The deadline for opting out and objecting to the settlement is October 5, 2025. Claims must be submitted by October 5, 2026, and the final fairness hearing has been scheduled for November 5, 2026.

The post Wellstar Health System & Cone Health Settle Pixel Lawsuits appeared first on The HIPAA Journal.

OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement

The Wisconsin mailing and printing vendor OneTouchPoint Corp. has agreed to settle class action litigation over a 2022 ransomware attack and data breach that affected more than 2.65 million individuals. The cyberattack that sparked the litigation was identified on April 28, 2022, when files were encrypted on its network. The forensic investigation determined that a ransomware group first accessed its network the previous day on April 27, 2022.

Data exposed and potentially stolen in the incident included names, subscriber ID numbers, diagnoses, medications, addresses, dates of birth, sex, physician demographic information, family histories, social histories, allergies, vitals, immunizations, and other information. OneTouchPoint reported the data breach to the HHS’ Office for Civil Rights as affecting 2,651,396 individuals and issued notifications to the affected individuals in April 2022.

Multiple class action lawsuits were filed in response to the data breach, all of which asserted similar claims. The lawsuits alleged that the data breach should have been prevented and was due to the failure of the defendant to implement reasonable and appropriate cybersecurity measures. The individual lawsuits were consolidated into a single action – Dusterhoft v. OneTouchPoint, Inc. – which is pending in the Circuit Court of Waukesha County, Wisconsin.

The consolidated lawsuit asserted claims for negligence, negligence per se, breach of contract, breach of implied contract, breach of fiduciary duty, breach of confidence, invasion of privacy, fraud, misrepresentation, unjust enrichment, bailment, wantonness, failure to provide adequate notice pursuant to any breach notification statute or common law duty, and violations of state consumer protection laws. All claims and contentions in the lawsuit were denied by the defendant, including claims of fault, wrongdoing, and liability. To avoid the costs and risks associated with a trial and related appeals, all parties agreed to settle the litigation.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Under the terms of the settlement, OneTouchPoint has agreed pay attorneys’ fees and expenses up to $1,500,000, settlement administration costs, service awards of $1,000 for each of the class representatives, and monetary benefits and credit monitoring. The defendant also agreed to injunctive relief and will implement security enhancements valued at approximately $2,000,000, which will be maintained for at least five years.

The settlement class is divided into two subclasses – a monetary relief class and an injunctive relief class. The monetary relief class consists of individuals who were notified that their information had been impacted by the data breach. Those individuals may submit claims for monetary benefits. The injunctive relief class consists of individuals who were notified about the data breach, but the investigation could not determine that the data breach had an actual impact. Those individuals will benefit from the injunctive relief only.

All members of the monetary relief class may choose to receive a complimentary two-year subscription to a single-bureau credit monitoring service, which includes a $1 million identity theft insurance policy. In addition, claims may be submitted for compensation for documented, unreimbursed ordinary losses up to a maximum of $500 per class member, and up to $5,000 compensation for documented, unreimbursed extraordinary losses. In addition, compensation may be claimed for up to four hours of lost time at $25 per hour. Monetary relief class members who choose not to submit a compensation claim may claim an alternative one-time cash payment of $75.

The deadline for opting out of the settlement and objecting is October 16, 2026. Claims must be submitted by November 16, 2026, and the final approval hearing has been scheduled for November 18, 2026. Further information can be found on the settlement website: https://otpdataincident.com/

The post OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement appeared first on The HIPAA Journal.

Multi-Million Settlement Resolves Managed Care of North America Data Breach Litigation

Managed Care of North America, Inc. (MCNA) has agreed to settle class action litigation stemming from a 2023 cybersecurity incident that affected around 8.9 million individuals. MCNA is a provider of dental insurance in Florida, and a third-party administrator of dental benefits in other states and Puerto Rico. MCNA’s subsidiaries include MCNA Dental, MCNA Insurance Company, and Healthplex.

The cybersecurity incident was identified on March 6, 2023, and the forensic investigation determined that an unauthorized third party accessed its network between February 22, 2023, and March 7, 2023, and potentially viewed or obtained private information. The investigation confirmed that sensitive data was exfiltrated from its network.

The compromised data included names, addresses, telephone numbers, email addresses, birth dates, Social Security numbers, driver’s license numbers, government-issued ID numbers, health insurance information, Medicare/Medicaid ID numbers, group plan names and numbers, and information related to the dental and orthodontic care provided. Notification letters started to be sent to the affected individuals on May 26, 2023.

The defendant was named in 25 putative class action complaints, the first of which was filed on June 5, 2023. The lawsuits were materially and substantively identical and were consolidated into a single complaint. The consolidated lawsuit alleged that MCNA was responsible for the data breach due to the failure to implement appropriate cybersecurity measures. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, violations of state consumer protection act statutes, and declaratory and injunctive relief.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

MCNA denies any wrongdoing and sought to have the complaint dismissed. The motion was granted in part and denied in part, and an amended complaint – Crowe, et al., v. Managed Care of North America, Inc., et al. – was filed in the United States District Court for the Southern District of Florida. The defendant’s motion to deny the amended complaint was denied by the court. The parties attended mediation, and a settlement was negotiated that was acceptable to all parties.

Under the terms of the settlement, MCNA will cover costs associated with the litigation, including attorneys’ fees up to $6,400,000 and litigation costs up to $1,313,000. All class members are entitled to enroll in two years of medical data monitoring services, valued at $179.40 per year per settlement class member. A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to $2,500 per class member. There is no alternative cash payment. Claims for reimbursement of losses have been capped at $2,500 per class member and will be paid pro rata if that cap is exceeded. MCNA has also agreed to make changes to its business practices and has implemented additional security measures to better protect sensitive data. The deadline for objection, opting out, and submitting a claim is October 19, 2026. The final fairness hearing has been scheduled for November 16, 2026.

The post Multi-Million Settlement Resolves Managed Care of North America Data Breach Litigation appeared first on The HIPAA Journal.

Highland Oncology Group Settles Litigation Stemming From 2025 Ransomware Attack

Highlands Oncology Group, an Arkansas-based physician-owned community cancer care and research practice serving Northwest Arkansas, Southwest Missouri, and Southeast Oklahoma, has agreed to settle class action litigation stemming from a 2025 ransomware attack and data breach that affected 113,575 individuals.

The ransomware attack was identified by Highlands Oncology Group on or around June 2, 2025. While the attack was identified in early June, the investigation determined that the ransomware group first gained access to its network as early as January 21, 2025. Data accessed and/or exfiltrated included names, dates of birth, Social Security numbers, driver’s license/state identification numbers, passport numbers, credit/debit card numbers, financial account numbers, medical treatment information, medical record numbers, patient account numbers, and/or health insurance policy information.

The affected individuals were notified on August 1, 2025, and the first class action lawsuit was filed on August 5, 2025. In total, thirteen class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint as they had overlapping claims. The consolidated lawsuit – In re Highlands Oncology Group Data Breach Litigation – was filed in the Circuit Court for Washington County, Arkansas, where it is currently pending.

The consolidated lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, and invasion of privacy-intrusion upon seclusion. Highlands Oncology Group sought to have the consolidated class action complaint dismissed; however, after filing that motion, all parties engaged in settlement discussions, and following mediation, the terms of a settlement were negotiated. The settlement has recently received preliminary approval from the court.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Highlands Oncology Group will pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. Class members may submit a claim for one of two cash payments: A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $4,250 per class member, or a claim may be submitted for a one-time pro rata cash payment, estimated to be around $50 per class member.

Regardless of which cash payment is chosen, class members are eligible to enroll in three years of medical data monitoring services, which include a $1 million identity theft insurance policy. The deadline for opting out and objecting to the settlement is October 7, 2026. Claims must be submitted by October 22, 2026, and the final fairness hearing has been scheduled for November 6, 2026.

The post Highland Oncology Group Settles Litigation Stemming From 2025 Ransomware Attack appeared first on The HIPAA Journal.

DaVita Agrees to Pay $15 Million to Settle Data Breach Litigation

In 2025, the kidney dialysis giant DaVita experienced a ransomware attack that involved the theft of sensitive patient data. Some of the affected individuals took legal action in response to the data breach, which they claim has put them at risk of identity theft and fraud. Following extensive negotiations, a $15 million settlement has been proposed to bring the litigation to an end.

DaVita operates more than 3,000 kidney dialysis centers in the United States and 14 other countries. On April 12, 2025, the Interlock ransomware group accessed its network, exfiltrated data, and encrypted files, causing temporary disruption to operations. The forensic investigation determined that the electronic protected health information of 2,689,826 individuals was compromised in the incident, including names, contact information, Social Security numbers, health insurance information, clinical information, and tax information. Interlock claimed to have exfiltrated more than 20 terabytes of data and proceeded to leak around 1.5 terabytes of that data on its web data leak site when the ransom was not paid.

Multiple class action lawsuits were filed in response to the data breach that alleged that it occurred as a result of the defendant’s failure to implement reasonable and appropriate cybersecurity measures. The lawsuits were consolidated – Julian Jenkins, et al v. DaVita Inc. – in the United States District Court for the District of Colorado as they had overlapping claims.

The lawsuit asserted claims for negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, invasion of privacy, and violations of state consumer protection statutes. The lawsuit alleged that the plaintiffs face a current, imminent, and ongoing risk of fraud and identity theft as a result of the theft of their personal and health information, and the publication of that information on the dark web. The defendant denies the claims and contentions in the lawsuit, including claims of negligence, fault, and liability.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

All parties were able to negotiate a settlement to resolve the litigation, with no admission of liability or wrongdoing by DaVita. The proposed $15,000,000 settlement covers attorneys’ fees and expenses, settlement administration costs, service awards for the five class representatives, and a $10,000,000 non-revisionary settlement fund to pay relief to the class members.

Class members may submit a claim for up to $2,500 as reimbursement for documented, unreimbursed out-of-pocket losses due to the data breach. All class members, including those who submit a claim for reimbursement of losses, may claim a pro rata cash payment. The amount will depend on the number of valid claims received. The class consists of approximately 2.3 million individuals, and if everyone submits a claim, that would amount to around $4.17 per class member; however, based on the expected response rate, the cash payments are anticipated to be around $50 per class member.

The post DaVita Agrees to Pay $15 Million to Settle Data Breach Litigation appeared first on The HIPAA Journal.

Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit

Tift Regional Health System Inc, a non-profit health system serving patients in south central Georgia, has agreed to pay $1.2 million to settle a class action lawsuit stemming from a 2022 cyberattack that exposed patient data.

Tift Regional Health, which operates as Southwell, Inc., which is also a defendant, identified suspicious activity within its computer network on or around August 16, 2022. The forensic investigation confirmed that its network was accessed by an unauthorized third party between August 11, 2022, and August 17, 2022. The compromised parts of the network contained documents that included patient names, birth dates, Social Security numbers, and a range of sensitive medical information. Tift Regional Health said those documents may have been accessed or copied in the attack. A ransomware group  – Hive – claimed responsibility for the attack. Hive claimed to have stolen 1 terabyte of data and proceeded to leak some of that data on its data leak site. The data breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 180,142 individuals.

Multiple class action lawsuits were filed against the defendants in response to the data breach. The lawsuits were consolidated into a single action – In Tift Regional Health System, Inc. Data Breach Litigation – in the Superior Court of Tift County, State of Georgia, as the lawsuits had overlapping claims. The consolidated lawsuit alleged that the cyberattack and data breach were due to the defendants’ failures to properly secure, safeguard, and encrypt patient data, and destroy patient data in a timely manner when it was no longer required.  The lawsuit also took issue with the length of time it took to notify the affected individuals. They were not notified about the data breach until August 11, 2023, almost a year after the incident occurred.

The lawsuit asserted claims for negligence, negligence per se, breach of fiduciary duty, breach of implied contract, breach of contract, breach of the covenant of good faith and fair dealing, unjust enrichment, invasion of privacy, violation of the Georgia Uniform Deceptive Trade Practices Act, and for equitable and injunctive relief. The defendants deny the claims and contentions in the lawsuit and maintain there was no wrongdoing and no liability.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Both sides agreed to a settlement to avoid the costs and risks of a trial. The defendants have agreed to establish a $1,200,000 settlement fund to pay benefits to the class members after attorneys’ fees and expenses, settlement administration costs, and service awards for the four class representatives have been deducted. The defendants have also implemented a range of additional measures to better secure sensitive data in their possession, and those measures will be maintained for at least two years at an estimated cost of $4.5 million.

All class members are entitled to enroll in a two-year credit/medical data monitoring and identity theft protection service, and claim one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses up to a maximum of $5,000 per class member, or a claim may be submitted for an alternative cash payment.

The cash payments will be paid pro rata after all other claims and costs have been deducted, and they will exhaust the settlement fund. The cash payments are expected to be approximately $75 per class member but may be higher or lower. The settlement has received preliminary approval from the court, and the final fairness hearing is scheduled for September 14, 2026. The deadline for opting out and objecting to the settlement is September 15, 2026. Claims must be submitted by October 15, 2026.

The post Tift Regional Health System Pays $1.2 Million to Settle Data Breach Lawsuit appeared first on The HIPAA Journal.

DAP Health Settles Data Breach Lawsuit for $1,300,000

DAP Health, a nonprofit community healthcare network based in Southern California, has agreed to settle a class action lawsuit that was filed in response to a cyberattack on its computer systems that exposed sensitive patient data.

Suspicious activity was identified within certain computer systems on or around July 22, 2024. An investigation was launched, which confirmed that an unauthorized third party gained access to an email server and exfiltrated emails and files containing personally identifiable information and protected health information. Data stolen in the incident included names, contact information, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, birth certificate numbers, vehicle license plate and VIN numbers, financial account numbers, Medicare/Medicaid numbers, health insurance information, and a range of medical information.

Notification letters started to be sent to the affected individuals in December 2024, and the breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 129,048 individuals. The first class action lawsuit in response to the data breach was filed in January 2025, and a second lawsuit was filed in early February 2025. The plaintiffs agreed to work together, and an amended complaint – Donald Crosslin and Matthew Paone v. DAP Health, Inc. was filed in the Superior Court for the State of California for the County of Riverside in June 2025.

The lawsuit alleged that the data breach could have been prevented and was a result of a failure to implement reasonable and appropriate cybersecurity measures. The lawsuit asserted claims for negligence, breach of implied contract, unjust enrichment, and violations of the California Confidentiality of Medical Information Act, California’s Unfair Competition Law, and the California Consumer Privacy Act. DAP Health denies all material allegations, including claims of wrongdoing, fault, and liability.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Following extensive arm’s-length negotiations, all parties agreed to settle the litigation, with no admission of wrongdoing or liability by the defendant. Under the terms of the settlement, DAP Health has agreed to establish a $1.3 million settlement fund to cover attorneys’ fees and expenses, settlement administration costs, and service awards for the two class representatives. The remainder of the fund will be used to pay for class member benefits.

Class members may submit a claim for reimbursement of documented losses due to the data breach up to a maximum of $5,000 per class member. Regardless of whether a reimbursement claim is submitted, class members may claim a pro rata cash payment. The cash payments are estimated to be $25 per class member. Class members who were California residents on July 22, 2024, can also claim a statutory cash payment of $75. In addition, all class members can submit a claim for two years of complimentary credit monitoring and identity theft protection services.

The deadline for exclusion and objection is September 1, 2026. The deadline for submitting a claim is October 21, 2026. The settlement has received preliminary approval from the court, and the final fairness hearing has been scheduled for October 1, 2026.

The post DAP Health Settles Data Breach Lawsuit for $1,300,000 appeared first on The HIPAA Journal.

OnePoint Patient Care and Clay-Platte Family Medicine Settle Data Breach Lawsuits

Individuals affected by data breaches at OnePoint Patient Care and Clay-Platte Family Medicine may be entitled to claim benefits after settlements have been agreed to resolve class action lawsuits. The lawsuit against OnePoint Patient Care has been settled for $2,115,000, and the Clay-Platte Family Medicine lawsuit has been settled for $1,000,000.

OnePoint Patient Care Data Breach Settlement

OP Pharmacy, LLC, also known as OnePoint Patient Care, LLC, a Kentucky-based hospice-dedicated pharmacy and pharmacy benefits manager, was sued in response to a 2024 data breach. The lawsuit relates to a security incident detected by OnePoint on August 8, 2024. Hackers gained access to systems containing the protected health information of 1,741,152 individuals and copied files from its network between August 6 and August 8, 2024. At the time the lawsuit was filed, approximately 528,000 patients were living. Notification letters were mailed to the affected individuals in October and November, 2024

The lawsuit alleged that the defendant willfully, recklessly, or negligently maintained patient data, as it failed to implement appropriate cybersecurity measures and did not keep its systems free of vulnerabilities. Two lawsuits were filed in response to the breach, which were consolidated as they had overlapping claims. The consolidated lawsuit – Christopher Russo v. OP Pharmacy, LLC a/k/a OnePoint Patient Care, LLC – was filed in the District Court for the Western District of Kentucky, Louisville Division. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, breach of fiduciary duty, and for declaratory and injunctive relief.

The defendant disagrees with the claims and contentions in the lawsuit; however, a settlement was negotiated to avoid the cost and risks associated with a trial and related appeals. OnePoint will establish a $2,115,000 settlement fund, from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives will be deducted. The remaining funds will pay for class member benefits.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

A claim may be submitted for one of two cash payments: reimbursement of documented, unreimbursed losses due to the data breach up to $3,500 per class member, or an alternative pro rata cash payment, estimated to be $100 per claimant. The cash payments will be subject to a pro rata increase or decrease, depending on the number of valid claims received. In addition, OnePoint has agreed to implement additional security measures to reduce the risk of similar breaches in the future. The deadline for exclusion and opting out is August 24, 2026. The deadline for submitting a claim is October 8, 2026, and the final fairness hearing is scheduled for September 23, 2026.

Clay-Platte Family Medicine Data Breach Settlement

Clay-Platte Family Medicine and Barry Pointe Family Care in Kansas City, Missouri, and Cobblestone Family Medicine Clinic dba Clay Platte Family Medicine Clinic and Nathan D. Granger, dba Summit Family and Sports Medicine in Harrisonville, Missouri, were sued in response to a June 2024 data breach involving the electronic protected health information of patients. Hackers gained access to its network on or around June 26, 2024, and potentially viewed or obtained patient data such as names, contact information, dates of birth, Social Security numbers, and medical information.

Multiple class action lawsuits were filed in response to the data breach, which were consolidated into a single action – Highfill, et al. v. Clay-Platte Family Medicine Clinic, P.C., et al – in the U.S. District Court for the Western District of Missouri. The consolidated lawsuit alleged that the defendants failed to implement reasonable and appropriate safeguards to ensure the privacy of patient data, such as the encryption of data on its network. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, invasion of privacy by public disclosure of private facts, breach of fiduciary duty of confidentiality, negligent training and supervision, invasion of privacy, and violations of the Missouri Merchandising Practices Act.

The defendants deny any wrongdoing and sought to have the lawsuit dismissed. The motion to dismiss was granted in part, although certain claims were allowed to proceed. Following mediation and continued negotiations, a settlement was agreed to by all parties. The settlement class consists of the 53,916 individuals who were notified about the data breach. A $1,000,000 settlement fund will be established to pay for court-approved costs and benefits for the class members.

All class members are entitled to enroll in three years of free medical and credit monitoring services. In addition, a claim may be submitted for reimbursement of documented, unreimbursed losses or an alternative cash payment.  Claims for reimbursement of documented losses have been capped at $15,000 per class member. The remainder of the settlement fund will be paid pro rata to individuals who claim an alternative cash payment. The deadline for exclusion and opting out is September 6, 2026. The deadline for submitting a claim is September 30, 2026, and the final fairness hearing is scheduled for September 29, 2026.

The post OnePoint Patient Care and Clay-Platte Family Medicine Settle Data Breach Lawsuits appeared first on The HIPAA Journal.

Highland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits

Settlements have received preliminary approval to resolve class action data breach complaints against Highland Health Systems and Albany Gastroenterology Consultants that stem from breaches of patient data.

Highland Health Systems Data Breach Settlement

A settlement has been agreed to resolve a class action lawsuit against the nonprofit healthcare organization Highland Health Systems, CEO Mickey Turner, and Director of Finance Allen Stokes, stemming from a July 2023 data breach.

A security incident was identified in early July 2023, in which sensitive patient data was accessed and stolen by hackers. Data compromised in the incident included patient and employee data, including names, contact information, birth dates, Social Security numbers, account numbers, payment card information, medical information, health Insurance Information, tax IDs, and other sensitive data. The affected individuals were notified about the data breach on June 13, 2024, and the data breach was reported to the HHS’ Office for Civil Rights as involving the electronic protected health information of 83,543 individuals.

Two class action lawsuits were filed in response to the data breach, which were combined into a single action –Weyerman, et al. v. Highland Health Systems et al.– which is pending in the Circuit Court for Calhoun County, Alabama. The lawsuit alleges that the data breach was the result of the defendants’ negligence and could have been prevented if appropriate cybersecurity measures had been implemented. The lawsuit asserted claims for negligence/negligence per se, breach of express and/or implied contract, wantonness, breach of fiduciary duty, breach of confidence, and unjust enrichment.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The defendants denied all claims and contentions in the lawsuit and sought to have the lawsuit dismissed; however, the court rejected the motion to dismiss in its entirety. Mediation proved unsuccessful; however, a settlement agreement was subsequently negotiated that was acceptable to all parties. Highland Health Systems has agreed to establish a $650,000 settlement fund to cover the costs of litigation, attorneys’ fees, administration costs, and benefits for the class members.

Those benefits include a two-year membership to a medical identity protection service and one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses up to $5,000 per class member, or a one-time pro rata cash payment may be claimed, which is expected to be $85 per class member, but may be higher or lower depending on the number of valid claims received. The deadline for objection and opting out is September 28, 2026. Claims must be submitted by October 28, 2026, and the final approval hearing has been scheduled for November 30, 2026.

Albany Gastroenterology Consultants Data Breach Settlement

Albany Gastroenterology Consultants, PLLC, a New York gastroenterology practice, has agreed to settle litigation stemming from a November 2024 security incident. The incident occurred on or around November 10, 2024. Hackers gained access to its network, where the personally identifiable information and protected health information of 57,751 individuals was stored. Data potentially compromised in the incident included names, addresses, Social Security numbers, medical information, and health insurance information. The affected individuals started to be notified on January 28, 2025.

Multiple class action lawsuits were filed in response to the data breach in the Supreme Court of the State of New York, County of Albany. The defendant filed a motion to dismiss, and the plaintiffs filed their response. All parties agreed to engage in settlement discussions, and during those discussions, the parties agreed that the Circuit Court for the Eleventh Judicial Circuit in and for Miami-Dade County, Florida, was the proper venue and the New York state actions were voluntarily dismissed. The amended lawsuit was filed in Florida – Clements v. Albany Gastroenterology Consultants, PLLC. The negotiated settlement has received preliminary approval from the court.

The defendant will pay attorneys’ fees and expenses, service awards for the class representatives, and will establish a $200,00 settlement fund to pay benefits to the class members. Class members may submit a claim for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $2,500 per class member. Alternatively, a claim may be submitted for a one-time cash payment, expected to be around $10 per class member. In addition, class members are eligible to enrol in a 2-year membership to a credit monitoring and medical data monitoring service. The $200,000 settlement fund will be divided equally between the two cash payments. If the $100,000 for either is exceeded, claims will be paid pro rata. The deadline for objection and opting out is August 21, 2026. Claims must be submitted by October 5, 2026, and the final approval hearing has been scheduled for September 22, 2026.

The post Highland Health Systems; Albany Gastroenterology Consultants Settle Data Breach Lawsuits appeared first on The HIPAA Journal.