25% off all training courses Offer ends July 30, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends July 30, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

$3 Million Settlement Agreed to Resolve Healthcare Services Group Data Breach Litigation

Healthcare Services Group has agreed to pay $3,000,000 to settle litigation arising from a September 2024 cybersecurity incident that involved unauthorized access to systems containing the personal and protected health information of 624,496 individuals.

Healthcare Services Group is a Bensalem, PA-based provider of environmental, dining, and nutritional support services, and works with more than 3,000 healthcare facilities in 48 U.S. states. Suspicious network activity was identified on or around October 7, 2024, and the forensic investigation determined that its network was first breached by an unauthorized third party on September 27, 2024.

Prompt action was taken to prevent further unauthorized access, but files containing protected health information had already been exfiltrated from its network. Those files contained information such as names, Social Security numbers, driver’s license numbers, state identification numbers, financial account details, full access credentials, and medical and health insurance information.

Notification letters started to be mailed to the affected individuals on August 25, 2025, and on August 27, 2025, the first class action lawsuit was filed. Further lawsuits were filed that made similar claims, and the actions were consolidated into a single complaint – Williamson, et al. v. Healthcare Services Group, Inc. – in the United States District Court for the Eastern District of Pennsylvania.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The consolidated lawsuit asserted claims for negligence, breach of implied contract, breach of contracts to which the plaintiffs and class members were intended third-party beneficiaries, breach of fiduciary duty, unjust enrichment, violations of the New Jersey Consumer Fraud Act and Washington Consumer Protection Act, and declaratory and injunctive relief.

Healthcare Services Group denies any wrongdoing and disagrees with all claims and contentions in the lawsuit. All parties agreed to a settlement as they concluded that further litigation would likely be expensive and protracted, and by settling, all parties avoid the uncertainty and risks of a trial.

Healthcare Services Group has agreed to establish a $3,000,000 settlement from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class members will be deducted. The remaining funds will be used to pay benefits to the class members. Class members are entitled to claim three years of single-bureau credit monitoring services, which include identity theft insurance and identity theft recovery services.

A claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to a maximum of $5,000 per class member, and a claim may also be submitted for a one-time pro rata cash payment. The cash payments will exhaust the settlement fund, and their value depends on the number of valid claims received. Requests for exclusion and objections must be submitted by September 4, 2026. The deadline for submitting a claim is October 1, 2026, and the final fairness hearing is scheduled for September 24, 2026.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist