Lawsuit against Ascension over data breach affecting 5.6M patients moves forward
A lawsuit against one of the largest nonprofit health systems can move forward, though some claims made by a class action of plaintiffs were dismissed.
The initial complaint was filed in May 2024, shortly after Ascension Health—a Catholic healthcare network with over 90 hospitals in 17 states—was hit by a ransomware attack that exposed records on 5.6 million patients to hackers. The plaintiffs in the case accuse the organization of failing to deploy adequate security that would have stopped the breach from occurring.
Data leaked to hackers included protected health information, along with Social Security numbers, patient contact information and details on patients’ insurance.
In covering the case, Bloomberg Law reports that the U.S. District Court for the Eastern District of Missouri agreed that evidence shown in court was sufficient to demonstrate that Ascension was negligent and that the health system has a duty to protect sensitive patient data.
Per the ruling, allegations that federal law stemming from the Health Insurance Portability and Accountability Act (HIPAA) was violated are allowed to proceed. However, the judge dismissed more specific accusations, namely that Ascension violated a contractual obligation to protect patient privacy.
The court agreed with arguments from the defendant that it was hackers who organized the data theft, not Ascension, which in no way benefited from the attack on its network.
The narrower lawsuit can now move forward, with patients in seven states represented by the class action plaintiffs. The litigants are seeking damages, many of which are a result of incidents of identity theft that stemmed from the breach.
Further, it is alleged that delayed medical care caused substantial injury to some patients. Notably, the cyberattack impacted healthcare services in at least 12 states and forced many Ascension hospitals to operate on pen-and-paper backups.
For more, read Bloomberg Law’s full coverage at the link below.
