Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatbreach-disclosure-notificationmass-credential-exposureenforcement-action

Healthcare Privacy and Data Breach Class-Action Settlements

Updated 3mo agoFirst seen Jan 15, 20263 sources

Several healthcare organizations are resolving class-action litigation tied to alleged exposure of sensitive patient data, with settlements emphasizing cost avoidance rather than admissions of wrongdoing. Kaiser Permanente agreed to a $46 million settlement over claims that patient interactions with certain Kaiser websites and digital tools resulted in personal health information being transmitted to third parties (including Google, Microsoft Bing, Twitter/X, and Adobe) via online tracking/advertising technologies; the allegations focus on web/digital activity rather than Kaiser’s core electronic medical record systems, and the proposed class period spans 2017–2024.

Separately, two healthcare entities reached settlements following network intrusions that allegedly exposed protected health information and other sensitive identifiers. Mystic Valley Elder Services agreed to pay $520,000 to settle claims stemming from an April 2024 incident in which attackers accessed its network and potentially obtained data including SSNs, financial/payment data, credentials, and medical/insurance information affecting ~89,600 people; plaintiffs also alleged delayed detection and notification. Consulting Radiologists Ltd. received approval for a $2.2 million settlement after a 2024 intrusion affecting up to 583,824 individuals, with allegations including inadequate security controls and delayed breach notification; the organization reported that some impacted records included medical/insurance data and SSNs (for a subset of individuals).

Share:
Healthcare Privacy and Data Breach Class-Action Settlements
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jan 15, 20265mo ago

Kaiser agrees to $46 million patient data privacy settlement

Kaiser Permanente agreed to a $46 million settlement to resolve litigation alleging patient-related website data was improperly shared with third parties via tracking technologies. Kaiser denied wrongdoing, said it removed certain technologies out of caution, and settled to avoid prolonged litigation.

Jan 14, 20265mo ago

Mystic Valley Elder Services agrees to $520,000 settlement

Mystic Valley Elder Services agreed to a $520,000 mediated settlement to resolve consolidated class action litigation over its April 2024 breach. The deal includes estimated cash payments of about $75 per class member, reimbursement of documented losses up to $5,000, and two years of credit monitoring and identity theft protection.

Jan 13, 20265mo ago

Consulting Radiologists reaches court-approved $2.2 million settlement

A court-approved $2.2 million settlement resolved consolidated class action litigation over the Consulting Radiologists data breach. The settlement offers reimbursement for documented losses up to $5,000, two years of single-bureau credit monitoring, and cash payments expected to be about $125 for Social Security number-impacted individuals and $50 for others.

Jan 1, 20251y ago

Court allows key claims in Consulting Radiologists case to proceed

After partially dismissing some claims in the Consulting Radiologists litigation, the court allowed core claims to continue, including negligence and claims under the Minnesota Consumer Fraud Act and Health Records Act. This kept the main breach-related allegations alive ahead of settlement.

Mystic Valley class action complaints are consolidated

Five class action complaints arising from the Mystic Valley Elder Services breach were consolidated in Middlesex County Superior Court, Massachusetts, under the case In re Mystic Valley Elder Services Inc. The consolidated suit alleged inadequate cybersecurity, delayed detection, and untimely notification.

Jun 14, 20242y ago

Consulting Radiologists reports breach to HHS OCR

Consulting Radiologists reported its data breach to the HHS Office for Civil Rights, stating that up to 583,824 individuals may have been affected. The filing made the healthcare incident publicly reportable at the federal level.

Apr 5, 20242y ago

Mystic Valley Elder Services suffers network intrusion

Mystic Valley Elder Services experienced a network intrusion and data breach on April 5, 2024. The incident potentially exposed sensitive personal and health information of more than 89,600 individuals.

Feb 12, 20242y ago

Consulting Radiologists detects unauthorized network intrusion

Consulting Radiologists identified an unauthorized intrusion into its network on February 12, 2024. Investigators later determined the intruder may have accessed patient data, including names, addresses, dates of birth, medical and insurance information, and Social Security numbers for 19,346 individuals.

Jan 1, 20179y ago

Kaiser allegedly shared patient website data with third parties

Between 2017 and 2024, Kaiser Permanente allegedly transmitted data from certain patient-facing websites to third parties including Google, Microsoft Bing, Twitter/X, and Adobe through web tracking technologies. The allegations concerned online platform interactions rather than Kaiser’s internal medical record systems.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

6 LINKEDOpen in app
Organizations
6 linked
Kaiser PermanenteXMicrosoft CorporationAdobeGoogleBecker's Hospital Review
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.