Legal News about HIPAA Compliance

$3 Million Settlement Agreed to Resolve Healthcare Services Group Data Breach Litigation

Healthcare Services Group has agreed to pay $3,000,000 to settle litigation arising from a September 2024 cybersecurity incident that involved unauthorized access to systems containing the personal and protected health information of 624,496 individuals.

Healthcare Services Group is a Bensalem, PA-based provider of environmental, dining, and nutritional support services, and works with more than 3,000 healthcare facilities in 48 U.S. states. Suspicious network activity was identified on or around October 7, 2024, and the forensic investigation determined that its network was first breached by an unauthorized third party on September 27, 2024.

Prompt action was taken to prevent further unauthorized access, but files containing protected health information had already been exfiltrated from its network. Those files contained information such as names, Social Security numbers, driver’s license numbers, state identification numbers, financial account details, full access credentials, and medical and health insurance information.

Notification letters started to be mailed to the affected individuals on August 25, 2025, and on August 27, 2025, the first class action lawsuit was filed. Further lawsuits were filed that made similar claims, and the actions were consolidated into a single complaint – Williamson, et al. v. Healthcare Services Group, Inc. – in the United States District Court for the Eastern District of Pennsylvania.

The consolidated lawsuit asserted claims for negligence, breach of implied contract, breach of contracts to which the plaintiffs and class members were intended third-party beneficiaries, breach of fiduciary duty, unjust enrichment, violations of the New Jersey Consumer Fraud Act and Washington Consumer Protection Act, and declaratory and injunctive relief.

Healthcare Services Group denies any wrongdoing and disagrees with all claims and contentions in the lawsuit. All parties agreed to a settlement as they concluded that further litigation would likely be expensive and protracted, and by settling, all parties avoid the uncertainty and risks of a trial.

Healthcare Services Group has agreed to establish a $3,000,000 settlement from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class members will be deducted. The remaining funds will be used to pay benefits to the class members. Class members are entitled to claim three years of single-bureau credit monitoring services, which include identity theft insurance and identity theft recovery services.

A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member, and a claim may also be submitted for a one-time pro rata cash payment. The cash payments will exhaust the settlement fund, and their value depends on the number of valid claims received. Requests for exclusion and objections must be submitted by September 4, 2026. The deadline for submitting a claim is October 1, 2026, and the final fairness hearing is scheduled for September 24, 2026.

The post $3 Million Settlement Agreed to Resolve Healthcare Services Group Data Breach Litigation appeared first on The HIPAA Journal.

ApolloMD Agrees to Pay $4.02M to Settle Data Breach Lawsuit

ApolloMD Business Services, a business associate that provides integrated, multispecialty physician, APC, and practice management services, has agreed to settle a class action lawsuit stemming from a May 2025 ransomware attack.

The attack was identified by ApolloMD on or around May 22, 2025, and the forensic investigation determined that a ransomware actor accessed its network between May 22 and May 23, 2025, potentially exfiltrating files containing the protected health information of patients of its healthcare provider clients. The Qilin ransomware group claimed responsibility for the attack.

The ApolloMD data breach included names, dates of birth, health information, health insurance information, and for some individuals, Social Security numbers, and was reported to the HHS’ Office for Civil Rights as affecting 626,540 individuals. The first batch of notification letters was mailed to the affected individuals starting in September 2025, with a second wave of notifications issued in March 2026.

The first class action lawsuits were filed shortly after the first round of notification letters were issued. In January 2026, the court granted the motion to consolidate the lawsuits into a single complaint – In re ApolloMD Data Breach Litigation – which was filed in the U.S. District Court for the Northern District of Georgia, Atlanta Division.

The consolidated lawsuit alleged that the ransomware attack occurred as a result of the failure of the defendant to implement reasonable and appropriate cybersecurity measures. ApolloMD denies all claims and contentions asserted in the action, including any wrongdoing and liability. Following mediation in January 2026, the parties agreed on the material terms of a settlement, which has now been finalized and has received preliminary approval from the court.

The defendant has agreed to establish a $4,020,000 settlement fund to pay benefits to the class members, after attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives have been deducted. All class members are entitled to a one-year membership to a CyEx medical data monitoring service and may claim one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member. Alternatively, a pro rata cash payment may be claimed, estimated at $75 per claimant. The cash payments will be subject to a pro rata increase or decrease depending on the number of claims received.

The deadline for objection and opting out is August 31, 2026. Claims must be submitted by September 30, 2026, and the final fairness hearing has been scheduled for October 5, 2026.

The post ApolloMD Agrees to Pay $4.02M to Settle Data Breach Lawsuit appeared first on The HIPAA Journal.

23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit

A coalition of 42 state attorneys general has agreed to a $18 million settlement with 23andMe (now Chrome Holding Co.) to resolve alleged cybersecurity failures that led to an October 2023 data breach affecting 6.9 million of its customers. The settlement also includes a commitment to implement new data security measures to better secure consumer data and prevent further data breaches.

The 23andMe data breach occurred as a result of credential stuffing, which is where credentials obtained in a data breach at one or more companies are used to try to gain access to accounts on an unrelated platform. These attacks can only succeed if individuals reuse the same credentials across multiple accounts. When the credential stuffing campaign was discovered, 23andMe maintained that there had not been a breach, and that the compromised accounts were the result of customers’ poor security practices.

While 23andMe customers took risks by reusing their credentials on the 23andMe site, the multistate investigation found that 23andMe was at fault as the company lacked basic cybersecurity measures for preventing credential-based attacks. For instance, 23andMe did not compare users’ passwords against blocklists of known breached passwords, did not require multifactor authentication, and did not have rate limiting or intrusion prevention measures in place. Further, there was insufficient logging and monitoring, which allowed the credential-stuffing campaign to go unnoticed for five months between April 2023 and September 2023, and a failure to investigate and address unusual login patterns, such as a massive spike in login attempts indicative of a credential stuffing campaign. The investigation also identified a failure to fix known vulnerabilities and properly review and test design features of its platform.

23andMe filed for bankruptcy protection in March 2025, and the company’s data was sold to TTAM Research, a company formed by 23andMe founder and former CEO, Anne Wojcicki. The coalition sued 23andMe during the company’s bankruptcy, and the new data security requirements apply to TTAM, which is now registered as 23andMe Research Institute. The $18 million settlement will be paid to the participating states, with New York due to receive more than $705,000.

“Companies have a duty to protect their customers’ personal information from hackers, but 23andMe put millions of its customers at risk with its flimsy security measures,” said Attorney General James. “New Yorkers trusted 23andMe with their sensitive and personal genetic data, only to find that data stolen and put up for sale on the dark corners of the internet. As a result of our coalition’s action, 23andMe will pay for violating the law, and strict rules will be put in place to protect their customers.”

23andMe has previously agreed to pay $46.75 million as compensation to victims of the data breach, and has previously been fined by data protection watchdogs in Spain ($2.75M) and the United Kingdom ($3.1M) over the data breach. California did not participate in the multistate action, having filed its own lawsuit; however, a bankruptcy judge ruled this month that the state cannot seek monetary relief due to its Chapter 11 reorganization plan.

The post 23andMe Pays $18 Million to Settle Multistate Data Breach Lawsuit appeared first on The HIPAA Journal.

Atrium Health Pays Up to $1.8M to Resolve Pixel Lawsuit

Charlotte-Mecklenburg Hospital Authority, doing business as Atrium Health, has agreed to pay up to $1,800,000 to settle a class action lawsuit stemming from its use of pixels and other tracking technologies on its MyAtriumHealth (formerly called MyCarolinas) patient portal.

North Carolina-based Atrium Health operates a dozen hospitals in North and South Carolina, along with more than 900 care facilities in the two states. Like many health systems, Atrium Health used tracking technologies on its patient portal. These tools have important uses for website operators; however, their use on healthcare websites risks impermissible disclosures of sensitive data.

When these tools are added to authenticated web pages such as patient portals, patients’ protected health information may be disclosed to the third-party providers of the tools, such as Meta (Facebook) and Google. Following an investigation, Atrium Health determined that between January 1, 2015, and July 31, 2019, the protected health information of up to 585,959 patients may have been impermissibly disclosed to third parties as a result of the use of these tools. When reporting the data breach, Atrium Health assumed that all patients who used the portal had their ePHI impermissibly disclosed.

The data potentially compromised included IP addresses and third-party identifiers/cookies. If forms were filled out, that disclosed information may also have included full names, email addresses, phone numbers, city/state/zip code, gender, and any other information entered into the forms.

Multiple class action lawsuits were filed in response to the data breach, which were consolidated into a single complaint – Julie Roberts, et al. v. The Charlotte-Mecklenburg Hospital Authority – in the Superior Court of Mecklenburg County, North Carolina, naming Julie Roberts, Judith Sigmon, Darielle Hill, and Chrisanna Brown as representatives of a national class.

The plaintiffs alleged that their privacy had been violated by the defendant’s use of these tools, which they claim were added to the patient portal without their knowledge or consent. The lawsuit asserted claims for breach of express contract, breach of implied duty of good faith and fair dealing, breach of implied contract, negligence, breach of fiduciary duty, and unjust enrichment.

Atrium Health denies all wrongdoing and maintains it has not violated any laws and filed a motion to dismiss, which was partially successful; however, the lawsuit was allowed to proceed. The parties ultimately agreed to a settlement to avoid the costs and risks associated with continuing the litigation.

The settlement covers all individuals residing in the United States who had patient portal accounts – MyAtriumHealth or MyCarolinas – between January 1, 2025, and April 10, 2024, with limited exceptions. Atrium Health has agreed to establish a $1,800,000 settlement fund, from which $1,500,000 will be used to cover attorneys’ fees and expenses, administration costs (for Group 1 claims), and payments to individuals who used their accounts between January 1, 2015, and July 31, 2019.

The settlement also includes up to $300,000 to pay for claims from individuals who had a Patient Portal account between January 1, 2015, and April 10, 2024, but did not access their account between January 1, 2015, and July 31, 2019. (Group 2). The remainder of the funds in the Group 1 settlement will be paid pro rata to individuals who submit a claim, and individuals in Group 2 will receive a payment of up to $10 if they submit a claim. The deadline for opting out and objection is August 31, 2026. Claims must be submitted by September 28, 2026, and the final fairness hearing has been scheduled for September 30, 2026.

The post Atrium Health Pays Up to $1.8M to Resolve Pixel Lawsuit appeared first on The HIPAA Journal.

Vision Care Providers Settle Data Breach Class Actions

Settlements have been agreed to resolve class action lawsuits against two vision care providers: Total Vision in California and Naper Grove Vision Care in Illinois. Both providers fell victim to hacking incidents that exposed patient data.

Total Vision Settlement

A settlement has been agreed to resolve class action litigation against Total Vision LLC, which owns and operates a network of optometry centers throughout California. Total Vision experienced a hacking incident on or around October 30, 2020, in which hackers accessed a database server. The server contained sensitive patient information such as names, addresses, dates of birth, Social Security numbers, and prescription information. The data breach was reported to the HHS’ Office for Civil Rights as affecting 138,402 current and former patients.

Total Vision faced two class action lawsuits over the data breach, which were consolidated into a single complaint – Ramey, et al. v. Total Vision, LLC, et al. – in the Superior Court of California, County of San Diego, naming Anjanette Ramey and Jane Doe as class representatives. In addition to Total Vision, John C. Pack, O.D., and Beverly Bianes, O.D., Inc., and John C. Pack, O.D., and Beverly Bianes, O.D., were named as defendants.

The lawsuit alleged the data breach occurred as a result of the negligence of the defendants, who failed to properly secure the server and protect patient information, then failed to issue adequate breach notices. The plaintiffs allege that they experienced numerous instances of attempted data misuse and identity theft as a result of the security incident. The lawsuit asserted claims for negligence, breach of implied contract, and violations of California’s unfair competition law, the Confidentiality of Medical Information Act, and California security notification laws, all of which were denied by the defendants, along with the allegations of wrongdoing and liability.

During mediation on November 21, 2023, the terms of a settlement were agreed by all parties, and the settlement has now been finalized and has received preliminary approval from the court. The defendants have agreed to establish a $475,000 settlement fund, from which attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives will be deducted. The remaining funds will be used to pay for class member benefits.

Claims may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $1,000 per class member, and/or a claim may be submitted for a pro rata cash payment, the value of which will depend on the number of valid claims received. The defendants have also agreed to implement improved data security measures, valued at $224,000. The exclusion/objection deadline is September 4, 2026. Claims must be submitted by October 5, 2026, and the final fairness hearing has been scheduled for December 18, 2026.

Naper Grove Vision Care Settlement

Naper Grove Vision Care in Naperville, Illinois, has settled class action litigation stemming from a May 2025 security incident that involved unauthorized access to the protected health information of 20,093 individuals. On May 24, 2025, Naper Grove Vision Care identified unauthorized network access. The Interlock ransomware group claimed responsibility for the attack and obtained patient information such as names, addresses, birth dates, driver’s license numbers, patient numbers, health insurance information, explanation of benefits documents, and medical condition and treatment information. Some Social Security numbers were also among the accessed data.

Multiple class action lawsuits were filed in response to the data breach, which were consolidated – In re Naper Grove Data Breach Litigation – in the Circuit Court of the Eighteenth Judicial Circuit, Dupage County, Illinois. The consolidated lawsuit names Ashley Fett and Paul Mifsud as class representatives. The lawsuit alleged that the data breach occurred due to the failure to implement reasonable and appropriate cybersecurity measures, and asserted claims for negligence, negligence per se, breach of implied contract, unjust enrichment, and violations of the Illinois Consumer Fraud and Deceptive Business Practices Act. All claims and contentions continue to be denied by Naper Grove Vision Care.

All parties have agreed to settle the litigation, with no admission of fault, liability, or wrongdoing. The defendant will cover the cost of attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the class representatives.  Claims may be submitted for reimbursement of documented, unreimbursed out-of-pocket losses due to the data breach up to a maximum of $1,000 per class member.

If a claim for reimbursement of losses is not submitted, class members may submit a claim for an alternative cash payment. The cash payments will be paid pro rata from a $50,000 settlement fund. Regardless of which option is chosen, class members qualify for a one-year membership to a credit and medical data monitoring service. The deadline for objection/exclusion is September 18, 2026. Claims must be submitted by September 18, 2026, and the final approval hearing has been scheduled for October 20, 2026.

The post Vision Care Providers Settle Data Breach Class Actions appeared first on The HIPAA Journal.

Physicians Primary Care of Southwest Florida Agrees to Data Breach Settlement

Physicians Primary Care of Southwest Florida was the victim of a targeted cyberattack in September 2024 that exposed patient data. The data breach sparked a class action lawsuit alleging the breach could have been prevented, as Physicians Primary Care of Southwest Florida failed to implement reasonable and appropriate security measures to prevent unauthorized access to patient data in its possession.

Physicians Primary Care of Southwest Florida is a medical facility with offices in Fort Myers, Cape Coral, Estero, and Lehigh Acres, Florida, that specializes in internal medicine, obstetrics, gynecology, family practice, and pediatrics. On or around September 17, 2024, unauthorized access to its network was identified. The hackers behind the attack had access to the network from September 15, 2024, to September 17, 2024, and potentially viewed or obtained patient data such as names, health information, and Social Security numbers. The data breach was reported to the HHS’ Office for Civil Rights as affecting 170,653 individuals.

The first lawsuit over the data breach was filed on December 3, 2024, in the Circuit Court of the Twentieth Judicial Circuit. An amended complaint was filed on March 7, 2025, in the Circuit Court for Lee County, Florida, naming two alternative plaintiffs, as the plaintiff who filed the initial complaint was determined not to be a putative class member.

The lawsuit – Cirillo et al. v. Physicians Primary Care of Southwest Florida, P.L. – asserted claims for negligence, breach of implied contract, breach of fiduciary duty, violation of the Florida Deceptive and Unfair Trade Practices Act, and declaratory judgment. Physicians Primary Care of Southwest Florida denies wrongdoing and liability and disagrees with the claims and contentions asserted by the lawsuit.

Shortly after the amended complaint was filed, the parties began exploring the possibility of an early resolution. A settlement was not agreed upon during mediation, but after several months of negotiations, terms were agreed that were acceptable to all parties. The settlement class consists of all living adults in the United States who received a notification that the data breach involved their information.

Under the terms of the settlement, class members may submit a claim for reimbursement of documented, unreimbursed out-of-pocket losses due to the data breach up to a maximum of $5,000 per class member. There is no alternative cash payment; however, all individuals are eligible to enroll in two years of medical monitoring services, which include a $1 million identity theft insurance policy.

The settlement has received preliminary approval from the court, and the final fairness hearing has been scheduled for September 14, 2026. Individuals wishing to object to the settlement or opt out must do so by August 30, 2026. Claims must be submitted by September 29, 2026

The post Physicians Primary Care of Southwest Florida Agrees to Data Breach Settlement appeared first on The HIPAA Journal.

Lucent Health Solutions to Pay Up to 1.95M to Settle Data Breach Litigation

A settlement has been agreed to resolve a class action lawsuit against the Nashville, TN-based health plan administration service provider, Lucent Health Solutions. The litigation stems from an October 2023 phishing attack that allowed a threat actor to obtain credentials for an email account.

Lucent Health Solutions said the threat actor only had a 90-minute window to access the account, and no evidence was found of data theft; however, the account contained the protected health information of approximately 37,000 individuals, including their names, dates of birth, Social Security numbers, and health, dental, and vision group and/or plan numbers.  The affected individuals were notified about the data breach in  January 2025, 15 months after the breach occurred.

A putative class action lawsuit was filed by plaintiff Royal Corralejo – Royal Corralejo v. Lucent Health Solutions, LLC Litigation – in the Circuit Court for Davidson County, Tennessee, which was removed to the United States District Court for the Middle District of Tennessee. The lawsuit alleged that the defendant had failed to implement reasonable and appropriate cybersecurity measures, resulting in the data breach. The defendant denies all claims and contentions in the lawsuit and maintains that there was no wrongdoing.

After considering the costs and risks associated with a trial and related appeals, all parties agreed to discuss settling the lawsuit. During mediation on August 29, 2025, the material terms of a settlement were agreed by all parties, with no admission of liability or wrongdoing by the defendant. The settlement provides several benefits for the class members. Class members may submit a claim for reimbursement of documented, unreimbursed ordinary losses due to the data breach up to a maximum of $550 per class member, and a claim for up to $5,500 reimbursement for extraordinary losses from fraud or identity theft. A claim may also be submitted for up to 5 hours of lost time at $25 per hour.

Individuals who chose not to claim those benefits may instead claim a one-time cash payment of $80. Regardless of whether a claim is submitted for reimbursement of losses or the cash payment, class members may also claim a three-year membership to the CyEx Medical Shield Complete medical data monitoring service.

The defendant has agreed to pay up to $1,950,000 to resolve the lawsuit, which includes attorneys’ fees and expenses, settlement administration and notification costs, and a service award for the plaintiff. Should claims exceed that total, claims will be subject to a pro rata reduction. The deadline for objection and opting out of the settlement is August 21, 2026. The deadline for submitting a claim is September 5, 2026, and the final fairness hearing has been scheduled for September 9, 2026.

The post Lucent Health Solutions to Pay Up to 1.95M to Settle Data Breach Litigation appeared first on The HIPAA Journal.

Marlboro-Chesterfield Pathology Agrees to Settle Lawsuit Over 2025 Ransomware Attack

A settlement has been agreed to resolve a class action lawsuit against the Pinehurst, North Carolina-based molecular, cytology, and pathology service provider Marlboro-Chesterfield Pathology, P.C. The lawsuit was filed in response to a January 2025 ransomware attack by the SafePay ransomware group.

Unauthorized network access was identified on January 16, 2025, and the forensic investigation confirmed that 235,911 individuals had their data compromised in the attack, including their names, dates of birth, Social Security numbers, and protected health information. The affected individuals were notified about the incident on or around May 7, 2025.

A class action lawsuit – Cox v. Marlboro-Chesterfield Pathology, P.C – was filed in the County of Moor Superior Court by plaintiff Cox, individually and on behalf of similarly affected individuals. Plaintiff Cox alleged that her personal and protected health information was in the hands of cybercriminals as a result of the attack, and that the ransomware attack occurred as a result of the failure of Marlboro-Chesterfield Pathology to implement reasonable and appropriate cybersecurity measures to protect sensitive data on its network.

Marlboro-Chesterfield Pathology maintains there was no wrongdoing and disagrees with the claims and contentions in the lawsuit, including claims of fault and liability, and plaintiff Cox believes her claims are valid. After arms-length negotiations, and after the parties considered the costs and risks associated with continuing with the litigation, they entered into settlement discussions, and the material terms of a settlement were agreed on November 21, 2025.

The settlement has now been finalized and has received preliminary approval from the court. The defendant has agreed to pay attorneys’ fees and expenses, settlement administration and notice costs, and a service award for the class representative. Attorneys’ fees and costs have been capped at $100,000.

Class members may submit a claim for reimbursement of documented, unreimbursed out-of-pocket losses due to the data breach up to a maximum of $1,000 per class member. Individuals who had their Social Security numbers compromised in the incident may submit a claim for an alternative cash payment of $10, should they choose not to submit a claim for reimbursement of losses.

All individuals, regardless of whether they submit a claim for reimbursement of losses or the cash payment, are entitled to a one-year membership to a credit monitoring and identity theft protection service, which includes a $1 million identity theft insurance policy. The deadline for objection, opting out, and submitting a claim is August 21, 2026. The final fairness hearing has been scheduled for October 12, 2026.

The post Marlboro-Chesterfield Pathology Agrees to Settle Lawsuit Over 2025 Ransomware Attack appeared first on The HIPAA Journal.

Memorial Healthcare Services Settles Pixel Litigation

Memorial Healthcare Services, a nonprofit healthcare provider serving patients in Southern California, has agreed to settle a class action lawsuit over its use of pixels and other tracking, web analytics, and advertising technologies on its website.

The tools are alleged to have been added to the website without the knowledge or consent of patients, causing website users’ personally identifiable information (PII) to be collected and transferred to third parties.  The disclosures of PII and health information without consent are alleged to have violated the  California Invasion of Privacy Act. Memorial Healthcare Services maintains that there was no wrongdoing.

The lawsuit – Valladolid v. Memorial Health Services – was filed by plaintiff Michelle Valladolid in the Superior Court of California, County of Los Angeles, individually and on behalf of similarly situated individuals. After considering the likely cost of continuing with the litigation and risks associated with a trial and related appeals, the defendant and plaintiff agreed to settle the litigation.

The parties were not able to agree to the terms of a settlement during a full-day mediation session on April 3, 2025; however, through ongoing negotiations, the material terms of a settlement were agreed upon, and the terms have now been finalized. The proposed settlement has received preliminary approval from the court, and the final fairness hearing has been scheduled for September 17, 2026. The class consists of individuals who accessed the Memorial Health Services patient portal between March 7, 2022, and July 8, 2022.

Under the terms of the settlement, class members may claim a one-time cash payment, which will be paid pro rata from the $750,000 settlement fund. The defendant has agreed to cover the cost of attorneys’ fees and expenses, settlement administration and notification costs, and a service award for the class representative, which will be deducted from the settlement fund before any cash payments are made. The remaining funds will be shared equally between all class members who submit a valid claim.

Individuals wishing to object to the settlement must do so by July 15, 2026. The deadline for opting out is August 21, 2026, and claims must be submitted by August 21, 2026. Further information can be found on the settlement website: https://mhspixelsettlement.com/

The post Memorial Healthcare Services Settles Pixel Litigation appeared first on The HIPAA Journal.