ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Integris Health reaches $30 million settlement in data breach lawsuit affecting 2.4 million patients

Integris Health, an Oklahoma-based healthcare system operating 16 hospitals and numerous medical facilities across the state, has agreed to pay $30 million to settle a class action lawsuit stemming from a major data breach that occurred in November 2023. The incident compromised the personal information of nearly 2.4 million individuals, including approximately 224,000 minors.


According to Integris Health’s official notice, the breach took place on November 28, 2023, when an unauthorized party gained access to files containing sensitive patient data. The exposed information varied by individual but included names, contact details, demographic information, and Social Security numbers.


In a subsequent notice issued in February 2024, Integris Health reported that some patients had received direct communications from a group claiming responsibility for the cyberattack. The organization urged recipients not to engage with the messages or click any embedded links. According to the class action complaint, the hackers allegedly demanded ransom payments from patients, threatening to post their information on the dark web if payments were not made.


The breach, one of the largest reported to the U.S. Department of Health and Human Services in 2024, drew national attention due to the unusual tactic of hackers contacting patients directly. Plaintiffs in the lawsuit claimed that Integris Health failed to employ reasonable cybersecurity safeguards, leaving patient data vulnerable to theft and potential misuse.


While Integris Health did not admit to any wrongdoing, the company agreed to the $30 million settlement to resolve the allegations. Under the terms of the agreement, class members who can document out-of-pocket losses directly tied to the breach will be eligible for compensation of up to $25,000. Those without documented losses may receive an estimated $100 pro rata payment after all claims and administrative costs are paid.


In addition to monetary compensation, all affected individuals will receive three years of free credit monitoring and identity protection services from the three major credit bureaus, which include up to $1 million in identity theft insurance coverage.


The deadline to file for exclusion or objection to the settlement is November 21, 2025. A final approval hearing is scheduled for December 16, 2025, when the court will determine whether to approve the settlement agreement.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543