
Drug and Alcohol Treatment Services, Inc., a Scranton, Pennsylvania-based addiction treatment provider, has reached a $549,000 class action settlement resolving litigation tied to an October 2024 ransomware attack that compromised sensitive information belonging to more than 22,000 patients and employees.
The company notified the U.S. Department of Health and Human Services’ Office for Civil Rights that 22,215 individuals were affected by the breach. Information stolen or exposed included patient names, dates of birth, Social Security numbers, health insurance details, medical billing and claims records, account numbers, prescription information, and diagnosis and treatment histories.
Drug and Alcohol Treatment Services first detected unauthorized access to its network on October 6, 2024. A subsequent forensic review determined that an unauthorized party had infiltrated the system between October 5 and October 6 of that year, gaining access to patient names, birth dates, medical and treatment histories, insurance and billing records, Social Security numbers, and financial information. The company confirmed the breach internally on December 5, 2024, but affected individuals were not notified until May 2, 2025, nearly five months later.
The notification letters sent to victims did not describe how the breach occurred. The Interlock ransomware group later claimed responsibility for the intrusion, stating it had extracted 150 gigabytes of data. After the company declined to pay a ransom, the group posted the stolen files on its dark web leak site, claiming the material included personal records of both patients and staff.
Eight separate class action lawsuits followed, later consolidated into a single case, Leo Woytach, et al. v. Drug and Alcohol Treatment Services, Inc., filed in the Court of Common Pleas of Lackawanna County, Pennsylvania. Plaintiffs alleged negligence, negligence per se, breach of contract, breach of implied contract, breach of fiduciary duty, breach of confidence, unjust enrichment, and invasion of privacy. The suits argued that the company failed to maintain adequate cybersecurity protections and that the delay in notifying victims prevented them from taking earlier steps to guard against identity theft or fraud. Plaintiffs sought class certification, a jury trial, monetary damages, attorneys’ fees, litigation costs, and a court order requiring the company to strengthen its data security practices.
Drug and Alcohol Treatment Services has denied all allegations and maintains it engaged in no wrongdoing. Following a full day of mediation, both sides reached settlement terms designed to avoid the expense and uncertainty of continued litigation and possible appeals.
Under the agreement, the company will fund a $549,000 settlement pool covering attorneys’ fees, administrative and notification costs, and service awards for the eight class representatives, with the remaining balance distributed to class members. Eligible individuals may file claims for reimbursement of documented, unreimbursed losses tied to the breach, capped at $5,000 per person, or opt instead for a pro rata cash payment, the amount of which will depend on the total number of valid claims submitted. Class members are also entitled to twelve months of complimentary medical data monitoring.
Individuals wishing to exclude themselves from the settlement or file an objection must do so by August 25, 2026. The deadline to submit a claim is September 24, 2026, and a final fairness hearing is scheduled for November 24, 2026.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543