25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

ZOLL Medical Pays $3.5 Million to Settle Data Breach Lawsuit

A $3,500,000 settlement has received preliminary approval from the court to resolve class action data breach litigation against ZOLL Medical Corporation. The litigation relates to a January 2023 data breach that affected more than 1 million individuals.

Zoll Medical is a Chelmsford, Massachusetts-based global medical device and software company that makes products for resuscitation, cardiac monitoring, and critical cardiopulmonary conditions. Unauthorized network access was identified on January 28, 2023, and the investigation confirmed that personally identifiable information (PII) and protected health information (PHI) were exposed in the incident, mainly relating to individuals who received or were considered for use of the ZOLL LifeVest wearable cardioverter defibrillator. According to the breach notice submitted to the HHS’ Office for Civil Rights, the electronic protected health information (ePHI) of 997,097 individuals was involved, including names, addresses, dates of birth, and Social Security numbers. Those individuals started to be notified about the data breach in March 2023.

The data breach sparked 15 class action lawsuits, which were consolidated on April 24, 2023. The consolidated class action complaint was filed on February 26, 2024 – Smith et al. v. ZOLL Medical Corporation – in the U.S. District Court of Massachusetts on behalf of a nationwide class. The plaintiffs claimed that ZOLL Medical had failed to comply with its responsibilities under HIPAA, including a failure to implement appropriate technical, physical, and administrative safeguards to secure the privacy of ePHI, and violated the HIPAA Breach Notification Rule by not issuing timely breach notices. The lawsuit claimed that the breach notices did not include sufficient information about the nature of the breach to allow the victims to take action to protect themselves against data misuse.

The consolidated complaint brough claims for negligence, negligence per se, breach of fiduciary duty, breach of implied contract, unjust enrichment, and declaratory judgment and injunctive relief, and included allegations of violations of the Florida Deceptive and Unfair Trade Practices Act, Kansas Consumer Protection Act, New York General Business Law, Pennsylvania Unfair Trade Practices and Consumer Protection Law, and Illinois Consumer Fraud and Deceptive Business Practices Act.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

ZOLL Medical disagreed with all claims and contentions in the lawsuit, including claims of wrongdoing, fault, and liability. ZOLL Medical sought to have the complaint dismissed, asserting that the plaintiffs failed to state a claim entitling them to relief. The judge issued an order granting the motion to dismiss in part; however, the negligence claims under Massachusetts, Pennsylvania, Illinois, Florida, Texas, and New York law were permitted, along with the claims for breach of fiduciary duty, unjust enrichment, and breach of implied-in-law contract. While mediation was unsuccessful, subsequent negotiations resulted in a settlement that was agreeable to all parties.

The settlement class includes all living individuals who received a notice that their information was impacted by the data incident, with limited exceptions. From the $3,500,000 settlement fund, attorneys’ fees and expenses, settlement administration costs, taxes and tax-related expenses, and service awards for the class representatives will be deducted. The remaining funds will be used to pay for class member benefits.

Class members may submit a claim for reimbursement of documented, unreimbursed out-of-pocket losses incurred due to the data breach up to a maximum of $5,000 per class member. All class members may submit a claim for a cash payment, which will be paid pro rata from the remainder of the settlement fund. Individuals who had their Social Security numbers exposed will receive two shares per valid claim. The SSN share is estimated to be $100, and the non-SSN share is estimated to be $50. The deadline for objection and opting out has passed. Claims must be submitted by September 2, 2026, and the final fairness hearing has been scheduled for September 10, 2026.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist