ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

OnePoint Patient Care agrees to $2.12 million settlement over 2024 data breach

OnePoint Patient Care has agreed to settle a class action lawsuit stemming from a 2024 data security breach that compromised the personal data of more than 1.7 million individuals.

 

Between August 6 and August 8, 2024, OnePoint Patient Care, a hospice-dedicated pharmacy located in Tempe, Arizona, suffered a significant data breach after threat actors gained unauthorised access to the company’s network and stole sensitive personal and protected health information. The exposed data included names, addresses, dates of birth, Social Security numbers, medical record numbers, health insurance details, diagnoses, prescription information, and other treatment-related data. 

 

In a filing with the Maine state regulator, OnePoint Patient Care disclosed that the incident affected more than 1.74 million individuals, making it one of the largest healthcare data breaches reported in 2024.

 

Following the cyberattack, a class action lawsuit was filed against OnePoint Patient Care in the U.S. District Court for the Western District of Kentucky. The plaintiffs alleged that the company failed to adequately protect their personal information, resulting in harms such as loss of privacy, reduced value of their compromised data, and time spent dealing with the aftermath of the breach. The lawsuit includes claims of negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, and seeks both monetary damages and court-ordered measures to improve data security.

 

OnePoint Patient Care denied any wrongdoing, arguing that it was the victim of a criminal cyberattack and that the claims were not appropriate for class action treatment. Despite these objections, both parties agreed to settle the lawsuit, concluding that a settlement was the most practical way to resolve the dispute and provide benefits to affected individuals while avoiding the risks and uncertainty of continued litigation.

 

As part of the settlement, Lee University will create a $2.115 million settlement fund to pay eligible claims submitted by class members, in addition to covering settlement administration expenses, attorneys’ fees and costs, and any court-approved service awards.

 

The settlement provides two cash payment options: reimbursement of up to $3,500 for documented out-of-pocket losses related to the data breach, subject to proportional adjustments based on the number of valid claims, or an estimated $100 alternative cash payment for class members without documented losses, which may also be adjusted depending on the number of approved claims.

 

The proposed settlement has been granted preliminary approval by the court but has not yet become final. A final approval hearing is scheduled for September 23, when the court will decide whether to approve the settlement.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543