Nonprofit Healthcare Network Agrees to $1.3M Data Breach Settlement
A $1.3 Million Settlement Closes Out a 2024 Healthcare Breach
A nonprofit community healthcare network based in Southern California has agreed to pay $1.3 million to resolve a class action lawsuit tied to a 2024 cyberattack that exposed the sensitive data of more than 129,000 people. The settlement gives affected patients several ways to recover money and get free credit monitoring, and it offers a useful case study for any medical practice trying to understand what a breach actually costs after the fact.
The money was agreed to after extended negotiations between the parties, and the organization settled without admitting any wrongdoing or liability. That structure is standard for these cases: settling ends the litigation risk and expense without the defendant conceding fault.
What Class Members Can Claim
The $1.3 million settlement fund covers attorneys' fees and expenses, the cost of administering the settlement, and service awards for the two class representatives who brought the case. Whatever remains after those deductions pays for benefits to class members, and there are three main ways to collect.
- Reimbursement for documented losses. Class members can file for up to $5,000 to cover out-of-pocket costs they can document as tied to the breach, such as fraud losses or fees paid to deal with identity theft.
- A pro rata cash payment. Even without submitting a documented-loss claim, class members can request a flat cash payment. That amount is estimated at roughly $25 per person, though the exact figure depends on how many people file.
- A California statutory payment. Anyone who was a California resident on July 22, 2024, can also claim an additional statutory payment of $75.
On top of the cash options, every class member can sign up for two years of complimentary credit monitoring and identity theft protection. Credit monitoring is often the most practical benefit in breaches like this one, because exposed Social Security numbers can be misused long after the initial incident.
How the Breach Happened
Suspicious activity was first spotted inside certain computer systems on or around July 22, 2024. The organization launched an investigation, which confirmed that an unauthorized third party had reached an email server and pulled out emails and files containing personally identifiable information and protected health information.
The exposed data was extensive, and what each person lost varied from one individual to the next. Across the affected population, the compromised information included:
- Names, addresses, phone numbers, and dates of birth
- Social Security numbers, driver's license numbers, passport numbers, and birth certificate numbers
- Financial account information
- Health insurance details, Medicare and Medicaid numbers, medical record numbers, and patient IDs
- Medical information such as diagnoses, treatments and procedures, medical histories, allergies, prescriptions, test results, and vital signs
- User IDs and passwords, plus vehicle license plate and VIN numbers
That combination of financial, government-ID, and medical data is exactly what makes healthcare breaches so damaging. A stolen credit card can be canceled in minutes. A Social Security number paired with a full medical history cannot be reset, which is why these records sell at a premium and why the fallout can stretch for years.
The Legal Timeline
Notification letters went out to affected individuals starting in December 2024, and the incident was reported to the HHS Office for Civil Rights as involving the protected health information of 129,048 people.
The first class action followed in January 2025, with a second suit filed in early February 2025. The plaintiffs agreed to coordinate, and an amended complaint was filed in June 2025 in the Superior Court of California for the County of Riverside.
The lawsuit argued that the breach was preventable and stemmed from a failure to put reasonable and appropriate cybersecurity measures in place. It brought claims for negligence, breach of implied contract, and unjust enrichment, along with violations of the California Confidentiality of Medical Information Act, California's Unfair Competition Law, and the California Consumer Privacy Act. The defendant denies all of the material allegations.
Key Deadlines to Know
If you received a notice about this settlement, the dates below matter:
- September 1, 2026 — deadline to exclude yourself from or object to the settlement
- October 1, 2026 — final fairness hearing
- October 21, 2026 — deadline to submit a claim
The court granted preliminary approval, and benefits will be paid out after final approval assuming the settlement holds.
The Real Lesson for Medical Practices
Strip away the specifics and the pattern here is familiar. An email server was compromised, files with patient data walked out the door, and the organization ended up paying $1.3 million plus the cost of notifications, credit monitoring, and legal defense. The lawsuit didn't allege exotic hacking. It alleged that basic, reasonable safeguards weren't in place.
That's the part practice owners should sit with. Regulators and plaintiffs' attorneys increasingly ask a straightforward question after a breach: did you know where your vulnerabilities were, and did you do anything about them? The HIPAA Security Rule already requires a risk analysis, yet a missing or outdated one is among the most common findings in OCR investigations.
You don't need to become a cybersecurity expert to answer that question well. PolySec runs in-person HIPAA security risk assessments built for healthcare practices, including on-site vulnerability scanning, network scans, and review of your policies and business associate agreements. You get an audit-ready findings report and a prioritized remediation roadmap, so instead of guessing where your email server or network might be exposed, you have a documented plan and the support to fix what matters most, while your team stays focused on patients.
Frequently Asked Questions
How much can I get from this settlement? It depends on what you claim. You can request up to $5,000 for documented out-of-pocket losses, an estimated $25 pro rata cash payment, and, if you were a California resident on July 22, 2024, an additional $75 statutory payment. All class members can also claim two years of free credit monitoring and identity theft protection.
What was the deadline to file a claim? Claims must be submitted by October 21, 2026. The deadline to opt out or object was September 1, 2026, and the final fairness hearing is set for October 1, 2026.
How many people were affected? The breach was reported to the HHS Office for Civil Rights as involving 129,048 individuals.
Does settling mean the organization admitted fault? No. The settlement was reached without any admission of wrongdoing or liability, and the defendant denies the material allegations. Settling ends the cost and uncertainty of litigation for both sides.
How can a practice avoid ending up in a similar lawsuit? Start with a current HIPAA security risk assessment to find and document your vulnerabilities, then remediate them on a defensible timeline. Regular assessments, staff training, and tested safeguards are what regulators and courts look for when judging whether protections were "reasonable and appropriate."
