ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Community Care Alliance to pay $1.09 million to settle data breach class action

Community Care Alliance, a behavioral health and social services provider based in Woonsocket, Rhode Island, has agreed to a $1.09 million settlement to resolve a class action lawsuit stemming from a July 2024 ransomware attack that compromised sensitive data belonging to nearly 115,000 individuals.


The breach, attributed to the Rhysida ransomware group, occurred between July 1 and July 5, 2024, and was discovered by the organization on July 6. During that period, cybercriminals gained unauthorized access to Community Care Alliance’s network and exfiltrated an estimated 2.5 terabytes of data. The stolen information included names, addresses, dates of birth, Social Security numbers, driver’s license numbers, medical diagnoses, lab results, medication details, health insurance information, and other personally identifiable health data.


Rhysida is known for its double extortion tactics, in which stolen data is not only encrypted but also sold or auctioned if a ransom is not paid. In this case, the group claimed to have put the stolen database up for sale.


The lawsuit, Flacco v. Community Care Alliance, was filed in the Superior Court for the State of Rhode Island, Providence County. It alleged that Community Care Alliance failed to implement adequate cybersecurity safeguards, which plaintiffs argued could have prevented the breach. The suit also included claims of breach of implied contract and unjust enrichment.


While Community Care Alliance denies any wrongdoing or liability, the organization chose to settle the matter to avoid the uncertainty and cost of prolonged litigation. The settlement fund will cover attorneys’ fees of approximately $363,000, administrative expenses, and a $2,500 service award to the named plaintiff. Remaining funds will be distributed to affected class members.


Individuals whose data was exposed may file claims for reimbursement of documented financial losses related to the breach, capped at $5,000 per person. Eligible expenses include fraudulent charges, identity theft-related costs, and other out-of-pocket expenses incurred after July 29, 2024.


Alternatively, or in addition, class members may elect to receive a flat cash payment of $100, although final amounts may vary depending on the number of valid claims submitted. Claimants may also opt for two years of identity protection services, including credit and dark web monitoring and insurance coverage.


The court has granted preliminary approval of the settlement. Class members must submit claims by October 1, 2025. The deadline to object or opt out is September 2, 2025. A final fairness hearing is scheduled for October 8, 2025.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543