NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Palomar Health Medical Group; Summit Medical Group Settle Data Breach Lawsuits

Settlements have been reached to resolve class action data breach lawsuits against Palomar Health Medical Group in California and Summit Medical Group in Tennessee.

Palomar Health Medical Group Data Breach Settlement

Palomar Health Medical Group, a non-profit healthcare organization serving patients at 20 locations in North San Diego County and South Riverside County in Southern California, has agreed to settle class action litigation stemming from a Spring 2024 cybersecurity incident involving the protected health information of 1,140,221 individuals. The incident was identified on May 5, 2024, and the forensic investigation confirmed that hackers had access to its network from April 23, 2024, to May 5, 2024. Data potentially stolen in the incident included names, contact information, dates of birth, Social Security numbers, driver’s license numbers, state identification numbers, medical histories, health information, health insurance information, and other sensitive data.

Several class action lawsuits were filed in response to the data breach, all of which alleged that the data breach could have been prevented and occurred as a result of the failure of the defendant to implement reasonable and appropriate cybersecurity measures. On September 16, 2024, the lawsuits were consolidated into a single complaint – Castro et al. v. Arch Health Partners, Inc. d/b/a Palomar Health Medical Group – which is pending in the Superior Court for the State of California, County of San Diego. The consolidated lawsuit asserted claims for negligence, negligence per se, invasion of privacy, and violations of the California Consumer Privacy Act, California Confidentiality of Medical Information Act, and California Customer Records Act. All claims and contentions in the lawsuit were denied by Palomar Health Medical Group; however, all parties agreed to settle the litigation to avoid the costs and risks associated with continued litigation.

Under the terms of the settlement, Palomar Health Medical Group has agreed to establish a $3,100,000 settlement fund, from which attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives will be deducted. The remainder of the settlement fund will be used to pay benefits to the class members.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The settlement provides two years of complimentary single-bureau credit monitoring services to all class members. Class members may also claim one of two cash payments. A claim may be submitted for reimbursement of documented, unreimbursed losses up to $5,000 per class member, or a claim may be submitted for an alternative pro rata cash payment, estimated to be $60 per class member. The deadline for opting out and objecting to the settlement is October 7, 2026. Claims must be submitted by October 22, 2026, and the final fairness hearing has been scheduled for November 6, 2026.

Summit Medical Group Data Breach Settlement

Summit Medical Group, a Tennessee-based medical group with more than 90 locations in Tennessee, has settled class action litigation stemming from a November 2024 cybersecurity incident that exposed the personal and protected health information of more than 464,000 patients and employees. Data exposed in the incident included names, contact information, demographic information, medical record numbers, provider names, dates of services, facilities of service, treatment information, and/or health insurance information. The affected individuals were notified about the breach in March 2025.

Three putative class action lawsuits were filed in response to the data breach. The lawsuits had overlapping claims and putative classes, and were consolidated into a single lawsuit – Harris, et al. v. Summit Medical Group, PLLC, which is pending in the Circuit Court for Knox County, Tennessee. The consolidated lawsuit alleged that the data breach occurred as a result of insufficient security measures, and despite determining on September 19, 2024, that patient data was exposed, notifications were not mailed until March 2025. The lawsuit asserted claims for negligence, negligence per se, breach of implied contract, breach of fiduciary duty, unjust enrichment, and invasion of privacy, all of which were denied by Summit Medical Group. Summit Medical Group sought to have the lawsuit dismissed; however, after considering the time, cost, and risks associated with continued litigation, all parties agreed to settle the litigation. The terms of the settlement have been finalized, and the proposed settlement has received preliminary approval from the court.

The settlement provides two years of medical data monitoring with the CyEx Medical Shield Complete service. In addition, class members may submit a claim for reimbursement of documented out-of-pocket losses due to the data breach up to a maximum of $2,500 per class member. A claim may also be submitted for reimbursement of up to three hours of lost time at $15 per hour (max $45). The cash payments have been capped at $500,000. Claims will be paid pro rata if claims exceed that total.

Summit Medical Group has also agreed to pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. The deadline for objecting to the settlement and exclusion is October 10, 2026. Claims must be submitted by November 4, 2026, and the final fairness hearing has been scheduled for November 19, 2026.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist