
North Carolina-based Marlboro-Chesterfield Pathology has agreed to settle a class action lawsuit arising from its 2025 data security incident.
In May 2025, MCP said that on January 16, it identified suspicious activity within its internal network and immediately launched an investigation to determine the nature and scope of the incident.
The investigation found that an unauthorised party had accessed the network and acquired files containing sensitive patient information. The review determined that the compromised data may have included patients’ names, addresses, dates of birth, medical treatment details and health insurance information.
The breach was reported to the U.S. Department of Health and Human Services’ Office for Civil Rights, where MCP disclosed that 235,911 individuals were affected by the incident.
A class action lawsuit, Cox v. Marlboro-Chesterfield Pathology, P.C., was filed in the Superior Court of Moore County on behalf of plaintiff Cox and other similarly situated individuals. The complaint alleges that MCP failed to adequately protect and safeguard personally identifiable information (PII), resulting in its unauthorised disclosure. According to the lawsuit, the alleged security failures caused harm to the plaintiff and members of the proposed settlement class.
While MCP denied any wrongdoing or negligence, the plaintiffs maintained that the provider failed to adequately protect sensitive personal information, supported by the opinion of their cybersecurity expert. Rather than proceed to trial, both sides agreed to settle the case, avoiding the uncertainty, expense and time associated with continued litigation while providing compensation to eligible class members.
Under the proposed settlement, eligible class members may receive up to $1,000 for documented losses resulting from fraud or identity theft related to the data breach. Alternatively, individuals whose Social Security numbers were compromised may choose a $10 cash payment instead of seeking reimbursement for documented losses.
The agreement also includes one year of 3B Credit Monitoring with up to $1 million in identity theft protection for eligible claimants. Additionally, MCP has agreed to pay up to $100,000 in attorneys’ fees and litigation costs, subject to court approval. The proposed settlement has been granted preliminary approval by the court but has not yet become final. A final approval hearing is scheduled for October 12, 2026, when the court will decide whether to approve the settlement.
The SafePay ransomware group claimed responsibility for the cyber attack on MCP and listed it as a victim on its data leak site. However, neither the group nor the pathology center revealed any details on whether a ransom was paid.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543