Valley Oaks Health Data Breach Settlement Gets First Nod from Court

Valley Oaks Health faced class action litigation over a June 2023 data security incident that affected 50,352 individuals. The consolidated lawsuit has recently been settled. Hackers accessed the Valley Oaks Health network between June 8, 2023, and June 13, 2023, and potentially obtained files containing names, Social Security numbers, driver’s license numbers, state ID numbers, credit/debit card numbers, access codes/passwords, biometric data, and other sensitive information.

Multiple class action lawsuits were filed in response to the data breach, which were consolidated into a single action – In re: Valley Oaks Data Incident Litigation – as the lawsuits had overlapping claims and classes. The consolidated lawsuit is pending in the Superior Court for Tippecanoe, Indiana. The consolidated lawsuit asserted claims for negligence, negligence per se, breach of implied contract, breach of fiduciary duty, and unjust enrichment, all of which are denied by Valley Oaks Health, which maintains there was no wrongdoing.

Valley Oaks Health sought to have the lawsuit dismissed; however, the motion to dismiss was rejected by the court. A full day of mediation did not result in a settlement; however, after several months of negotiations, a settlement was agreed to avoid the cost, delay, and risks of protracted litigation.  The settlement has recently received preliminary approval from the court.

Valley Oaks Health has agreed to pay attorneys’ fees and expenses, settlement notification and administration costs, and service awards for the seven class representatives (total of $17,500). Attorneys’ fees are capped at $450,000. Claims may be submitted for reimbursement of up to $500 in documented, unreimbursed ordinary losses due to the data breach, including up to four hours of lost time at $20 per hour. A claim may also be submitted for up to $5,000 as reimbursement for documented, unreimbursed extraordinary losses. If claims are not submitted for reimbursement of losses or lost time, a claim may be submitted for an alternative $40 cash payment. All class members are entitled to enroll in two years of medical data monitoring services.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The deadline for opting out, objecting to the settlement, and submitting a claim is November 9, 2026. The final fairness hearing has been scheduled for December 10, 2026.

The post Valley Oaks Health Data Breach Settlement Gets First Nod from Court appeared first on The HIPAA Journal.

Bacon County Health Services Investigating Cyber Incident

Data breaches have been announced by Bacon County Health Services in Georgia, Comprehensive Orthopaedics & Musculoskeletal Care in Connecticut, Imagine the Possibilities in Iowa, and Health Plans Inc. in Massachusetts.

Bacon County Health Services

Bacon County Health Services, an Alma, Georgia-based nonprofit healthcare organization, is investigating a data security incident involving unauthorized access to systems containing patient information. Bacon County Health Services provides healthcare services to individuals in and around Alma through Bacon County Hospital, Twin Oaks Convalescent Center, and a rural health clinic.

Suspicious network activity was identified on July 27, 2026, and the forensic investigation determined that an unauthorized third party had access to its computer network between July 10, 2026, and July 27, 2026.  The investigation confirmed that files containing patient information were exfiltrated by the threat actor. The data review is ongoing, and the number of affected individuals and the types of data involved have yet to be determined. Notification letters will be mailed to the affected individuals when the data review is concluded. At the time of announcing the incident, no misuse of the affected data had been identified.

While the incident may not have affected all patients, Bacon County Health Services has warned all patients to remain vigilant against identity theft and fraud. To meet breach reporting requirements, the HHS’ Office for Civil Rights has been informed and provided with an estimate of at least 501 affected individuals. The total will be updated when the data review is concluded.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Comprehensive Orthopaedics & Musculoskeletal Care

Comprehensive Orthopaedics & Musculoskeletal Care, a Connecticut-based orthopedic practice, has recently notified the HHS’ Office for Civil Rights about a breach of the protected health information of 21,897 individuals. According to the practice’s substitute data breach notice, suspicious network activity was identified on February 12, 2026. Immediate action was taken to investigate the activity and secure its network, and it was confirmed that an unauthorized third party potentially accessed sensitive data.

The investigation and data review were completed on June 17, 2026, confirming that the impacted data included names, dates of birth, Social Security numbers, financial account numbers, payment card information, government-issued ID numbers, medical information, and health insurance information. While not described as a ransomware attack, a ransomware group called Crypto24 claimed to have exfiltrated sensitive data, including patients’ protected health information. The group has published the stolen data on its dark web data leak site.

Imagine the Possibilities

Imagine the Possibilities, an Iowa-based nonprofit organization that provides community-based support services for individuals with intellectual difficulties, has notified the HHS’ Office for Civil Rights about a breach of the protected health information of 1,693 individuals. The security incident occurred at one of its business associates, the Waterloo, IA-based insurance agency PDCM Insurance. Suspicious activity was identified within the PDCM Insurance network on April 28, 2025, and the forensic investigation confirmed unauthorized access to files and folders between April 27, 2025, and April 28, 2025. The review of the affected data was recently completed.

Data potentially compromised in the incident included names in combination with one or more of the following: date of birth, Social Security number, driver’s license number, state identification number, taxpayer identification number, financial account information, treatment information, diagnosis, treating/referring physician, prescription/medication information, group health insurance/subscriber number, medical policy number, individual health insurance/subscriber number, and/or medical record number. It is currently unclear how many of the company’s clients have been affected. PDCM Insurance said it has reviewed its security policies and procedures and has implemented additional safeguards to prevent similar incidents in the future.

Health Plans Inc.

Health Plans Inc., a Westborough, Massachusetts-based third-party administrator of self-funded employer health and benefit plans, has disclosed a cybersecurity incident involving one of its SaaS vendors. The number of affected individuals has yet to be publicly disclosed.

The incident involved Alegeus, a Waltham, Massachusetts-based provider of a SaaS platform for administering healthcare accounts. The data breach details have yet to be publicly disclosed, other than Social Security numbers being exposed. Alegeus has confirmed that it has taken steps to reduce the risk of similar incidents in the future and is offering the affected individuals two years of complimentary credit monitoring services.

The post Bacon County Health Services Investigating Cyber Incident appeared first on The HIPAA Journal.