When providing advice to health care clients, we have likely all discussed the importance of complying with HIPAA, the federal law that seeks to protect patients’ health information by establishing a number of privacy and security requirements. But perhaps an oft-overlooked consequence not having effective privacy and security policies and procedures is the data breach class action.
HIPAA does not contain a “private right of action” which would allow individuals to sue providers if their health information is compromised as a result of a data breach. However, providers may find themselves the subject of what appears to be an increasing number of data breach class actions.
For example, in October of this year, a Florida judge gave initial approval to a $10million settlement to resolve a proposed class action against a clinic that was being sued for negligence, breach of implied contact, breach of fiduciary duty and a violation of the Florida Deceptive and Unfair Trade Practices Act that. According to the complaint, the clinic allowed an unauthorized third party to gain access to 280,278 current and former patients’ sensitive and personally identifiable information which included pre- and/or pre- and post-operative digital images that appeared on the dark web. If finalized, each class member will automatically receive cash payments of $100 – $75,000 depending on the sensitivity of the images that appeared on the dark web, as well as certain additional payments.
One day before this settlement was announced, a class action case was filed against a pediatric healthcare provider in Colorado for allegedly failing to implement necessary data security safeguards which failure allowed cybercriminals to access patients’ sensitive and personal information. This, the complaint alleges, breached the provider’s duties under both federal and state law, resulting in claims of negligence, breach of implied contract, breach of fiduciary duty, invasion of privacy and unjust enrichment.
These recent class actions underscore that compliance is no longer just about avoiding HIPPA penalties—it is now a frontline defense against costly litigation. Providers should take this moment to reassess their privacy and security practices, ensure their risk analyses are current, and confirm that incident-response plans can withstand real-world attacks. As plaintiffs’ attorneys continue to test new theories of liability, the organizations best positioned to avoid becoming the next test case will be those that treat data security not as a regulatory requirement, but as an operational imperative.