IntelliHartx Data Breach Lawsuits Added to Fortra Cyberattack MDL
Kelly v. IntelliHartx, LLC
Filed: February 20, 2024 ◆§ 1:24-cv-20638
A lawsuit filed last summer alleges healthcare revenue cycle company IntelliHartx failed to protect sensitive consumer information during a 2023 data breach.
A proposed class action lawsuit filed last summer alleges Ohio healthcare revenue cycle company IntelliHartx failed to protect sensitive consumer information during a 2023 data breach that impacted more than 489,000 people.
Want to stay in the loop on class actions that matter to you? Sign up for ClassAction.org’s free weekly newsletter here.
The 60-page data breach lawsuit and several related cases against IntelliHartx were added this week to the multidistrict litigation (MDL) formed to more efficiently handle roughly 50 lawsuits filed over the January 2023 data breach of the Fortra file-transfer software by Russian ransomware hackers.
According to the suit, the information compromised in the IntelliHartx data breach included full names, addresses, dates of birth, Social Security numbers, and medical and health insurance details, which are protected under Health Insurance Portability and Accountability Act (HIPAA) regulations.
“The Data Breach was a direct result of [IntelliHartx’s] failure to implement adequate and reasonable cyber-security procedures and protocols necessary to protect its patients’ Private Information from a foreseeable and preventable cyber-attack,” the complaint alleges, claiming the company maintained the exfiltrated data in “a reckless manner.”
In its notice to data breach victims, IntelliHartx relayed that it discovered on February 2, 2023 that its secure file transfer protocol provider, Fortra, experienced a “data privacy event,” the case relays. The company said it promptly launched an investigation to determine the nature and scope of the incident and concluded in May that IntelliHartx patients’ information had been accessed without authorization, the filing says.
The case states, however, that the defendant failed to note in its data breach letter the root cause of the incident, the vulnerabilities exploited by those responsible, and the measures taken to ensure such an event does not happen again.
According to the suit, the private information exposed in the IntelliHartx data breach was not encrypted. If it had been, the perpetrators “would have exfiltrated only unintelligible data,” the complaint asserts.
The lawsuit goes on to contend that IntelliHartx’s offer of 24 months of identity theft monitoring services for data breach victims is “wholly inadequate” as consumers impacted by a cyberattack can face years of ongoing identity theft and medical and financial fraud.
The case looks to cover all United States residents whose private information was compromised in the data breach announced by IntelliHartx in June 2023.
Get class action lawsuit news sent to your inbox – sign up for ClassAction.org’s free weekly newsletter here.
Hair Relaxer Lawsuits
Women who developed ovarian or uterine cancer after using hair relaxers such as Dark & Lovely and Motions may now have an opportunity to take legal action.
Read more here: Hair Relaxer Cancer Lawsuits
How Do I Join a Class Action Lawsuit?
Did you know there's usually nothing you need to do to join, sign up for, or add your name to new class action lawsuits when they're initially filed?
Read more here: How Do I Join a Class Action Lawsuit?
Stay Current
Sign Up For
Our Newsletter
New cases and investigations, settlement deadlines, and news straight to your inbox.
Before commenting, please review our comment policy.