$5.48M HealthEC Settlement Resolves Data Breach Lawsuit Over Cyberattack Affecting Millions of Patients
Lempinen v. HealthEC, LLC
Filed: January 3, 2024 ◆§ 2:24-cv-00026
HealthEC faces a class action over a July 2023 data breach that reportedly exposed personal information belonging to almost 4.5 million of its clients’ patients.
HealthEC and several healthcare providers have agreed to pay a nearly $5.5 million settlement to resolve a consolidated class action lawsuit over a data breach announced in December 2023.
Don’t miss the next class action settlement deadline. Sign up for ClassAction.org’s free weekly newsletter.
Under the terms of the class action settlement, the population health technology company and certain healthcare entities to which it provides data analytics services—namely, Corewell Health, Beaumont ACO, MD Valuecare and Community Health Care Systems—will pay a total of $5,482,500 to resolve the claims of approximately 1.67 million patients of the healthcare providers whose personal information and/or protected health data was compromised in the HealthEC data breach.
To receive benefits from the HealthEC settlement, eligible class members must submit a timely, valid claim form by mail or online through the court-approved website once it is established.
ClassAction.org will update this page when the official HealthEC settlement website is launched.
According to the 13-page preliminary approval order issued by United States Magistrate Judge Stacey D. Adams on June 6, 2025, eligible class members have until November 18, 2025 to file a HealthEC settlement claim form.
As part of the deal, class members will be entitled to receive reimbursement for losses that are “fairly traceable” to the data breach and were incurred between July 14, 2023 and the date a claim form is filed, the settlement agreement says. Per the agreement, these out-of-pocket losses must be unreimbursed and supported by documentation and may include costs incurred as a result of fraud, identity theft or other misuse of personal information; fees related to credit freezes or credit monitoring services; notary, fax, postage, mileage or phone charges; and other miscellaneous expenses.
Class members may also submit a claim form for compensation of $25 per hour for time spent remedying fraud, identity theft or other data misuse that is reasonably traceable to the cyberattack or taking preventive measures to avoid incident-related losses, the settlement agreement relays.
Related Reading: HealthEC Facing Class Action Following July 2023 Data Breach
In lieu of the aforementioned benefits, class members can opt for a $25 cash payment, or $50 for California consumers, the settlement agreement shares.
HealthEC settlement payments may be reduced or increased on a pro rata basis to exhaust the settlement fund, the agreement adds.
In addition, the agreement says that all class members are eligible to enroll in at least three years of medical record and credit monitoring services and $1 million identity theft insurance at no cost. Consumers can access these services after the HealthEC settlement goes into effect even if they do not submit a claim form, the document notes.
The court will decide whether to grant final approval to the terms of the deal at a hearing on January 12, 2026. Settlement benefits, including information about activating credit and identity theft monitoring services, will be issued to eligible class members only if the deal receives ultimate court approval.
Consumers can expect notice of the settlement to be sent out via mail or email by July 21, 2025, court documents relay.
The HealthEC class action lawsuit alleged that negligent cybersecurity on the part of the company resulted in the cyberattack, which reportedly impacted the personal data of more than 4.6 million patients in total across the numerous healthcare entities affiliated with HealthEC.
The data breach lawsuit further contended that the company was aware its systems were vulnerable yet “prioritized its profit motive” over its duty to safeguard patients’ information.
Head to ClassAction.org’s settlements page for a complete list of data breach settlements.
Video Game Addiction Lawsuits
If your child suffers from video game addiction — including Fortnite addiction or Roblox addiction — you may be able to take legal action. Gamers 18 to 22 may also qualify.
Learn more:Video Game Addiction Lawsuit
Depo-Provera Lawsuits
Anyone who received Depo-Provera or Depo-Provera SubQ injections and has been diagnosed with meningioma, a type of brain tumor, may be able to take legal action.
Read more: Depo-Provera Lawsuit
How Do I Join a Class Action Lawsuit?
Did you know there's usually nothing you need to do to join, sign up for, or add your name to new class action lawsuits when they're initially filed?
Read more here: How Do I Join a Class Action Lawsuit?
Stay Current
Sign Up For
Our Newsletter
New cases and investigations, settlement deadlines, and news straight to your inbox.
Before commenting, please review our comment policy.