Illinois Gastroenterology Group (IGG) has settled a class-action lawsuit filed against it for failing to prevent the breach of sensitive personal information of over 227,943 patients.
Illinois Gastroenterology Group said that on October 22, 2021, it identified unauthorised activity in its internal systems and immediately launched an investigation. On November 18, it determined that the systems accessed by the threat actors contained sensitive personal information of its patients.
The compromised information included names, birth dates, Social Security numbers, driver’s license numbers, passport information, financial account information, addresses, payment card information, biometric data, employer-assigned identification numbers, and medical information.
“In response to this incident, IGG augmented its policies and procedures addressing network security. IGG accelerated the implementation of an enhanced managed Security Operations Center including the deployment of an endpoint detection and response platform in response to this event with policies enabled specially for ransomware.
“IGG immediately reset passwords and employees with privileged access to sensitive systems were enrolled into our multifactor authentication platform,” the group said.
The data breach affected more than 227,943 individuals whose sensitive personal information was compromised. IGG started notifying all affected individuals almost six months after the security incident took place.
Following this, a class action lawsuit was filed against the healthcare provider for failing to protect patients’ information, violating the Illinois Consumer Fraud and Deceptive Business Practices Act, and more.
According to the lawsuit filed in the Nineteenth Judicial Circuit Court of Lake County, Illinois, IGG failed to implement measures to protect the privacy and confidentiality of the sensitive data collected and stored. Without admitting any wrongdoing, IGG
decided to settle the lawsuit for an undisclosed amount.
As per the settlement terms, class members whose PHI was compromised but whose Social Security Numbers were safe are entitled to receive $50, those whose Social Security Numbers were compromised in the data breach would receive $150, and members would also receive up to $200 for unreimbursed ordinary losses, including “Out-of-Pocket Expenses and Lost Time reimbursement” and up to up to $5,000 for extraordinary losses, such as identity theft.
Furthermore, affected individuals would also get free of cost credit monitoring services for three years, including a $1 million identity theft insurance policy. IGG also needs to implement additional security measures to protect patients’ personal data.
The court has given a deadline until June 16 to submit all claims and the final hearing will take place on June 22.