
OnePoint Patient Care has agreed to settle a class action lawsuit stemming from a 2024 data security breach that compromised the personal data of more than 1.7 million individuals.
Between August 6 and August 8, 2024, OnePoint Patient Care, a hospice-dedicated pharmacy located in Tempe, Arizona, suffered a significant data breach after threat actors gained unauthorised access to the company’s network and stole sensitive personal and protected health information. The exposed data included names, addresses, dates of birth, Social Security numbers, medical record numbers, health insurance details, diagnoses, prescription information, and other treatment-related data.
In a filing with the Maine state regulator, OnePoint Patient Care disclosed that the incident affected more than 1.74 million individuals, making it one of the largest healthcare data breaches reported in 2024.
Following the cyberattack, a class action lawsuit was filed against OnePoint Patient Care in the U.S. District Court for the Western District of Kentucky. The plaintiffs alleged that the company failed to adequately protect their personal information, resulting in harms such as loss of privacy, reduced value of their compromised data, and time spent dealing with the aftermath of the breach. The lawsuit includes claims of negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, and seeks both monetary damages and court-ordered measures to improve data security.
OnePoint Patient Care denied any wrongdoing, arguing that it was the victim of a criminal cyberattack and that the claims were not appropriate for class action treatment. Despite these objections, both parties agreed to settle the lawsuit, concluding that a settlement was the most practical way to resolve the dispute and provide benefits to affected individuals while avoiding the risks and uncertainty of continued litigation.
As part of the settlement, Lee University will create a $2.115 million settlement fund to pay eligible claims submitted by class members, in addition to covering settlement administration expenses, attorneys’ fees and costs, and any court-approved service awards.
The settlement provides two cash payment options: reimbursement of up to $3,500 for documented out-of-pocket losses related to the data breach, subject to proportional adjustments based on the number of valid claims, or an estimated $100 alternative cash payment for class members without documented losses, which may also be adjusted depending on the number of approved claims.
The proposed settlement has been granted preliminary approval by the court but has not yet become final. A final approval hearing is scheduled for September 23, when the court will decide whether to approve the settlement.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543