NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Vasindas’ Around the Clock Care Settles Data Breach Litigation

Vasindas’ Around the Clock Care, Inc., a California-based provider of home care services, has settled class action litigation over a January 2024 targeted cyberattack. Suspicious activity was identified within its computer systems on or around June 18, 2024. The investigation determined that an unauthorized third party first accessed its network on January 30, 2024, and maintained access for almost five months. During that time, files were copied from its network that contained the personal and protected health information of customers, employees, and patients.

Data compromised in the incident included names, Social Security numbers, driver’s license numbers/state identification numbers, financial account information, medical information, and health insurance information. The breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 3,785 individuals, and the affected individuals were notified on August 16, 2024.

The first class action lawsuit was filed on August 27, 2024, alleging this was a ransomware attack that could have been prevented if appropriate cybersecurity measures had been implemented. The lawsuit alleged that basic cybersecurity measures had not even been implemented and that there was insufficient monitoring of network activity, since the unauthorized access was not detected for almost five months. A second class action lawsuit was filed, and the two actions were consolidated – Nelson et al. v. Vasindas’ Around the Clock Care, Inc. – in the Superior Court for Kern County, California.

All parties explored an early resolution to the litigation, and while mediation was not successful, an agreement was reached, and a settlement has now been finalized and approved by the court, with no admission of wrongdoing or liability by the defendant. The defendant continues to deny all allegations and claims in the lawsuit, and maintains that the plaintiffs did not suffer any damages as a result of the data incident.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Under the terms of the settlement, the defendant will pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. Class members are entitled to claim a two-year membership to a medical data monitoring service and may also claim one of two cash payments. A claim may be submitted for compensation for documented, unreimbursed losses due to the data breach up to a maximum of $2,500, or they may claim an alternative one-time cash payment of $70. The deadline for objection and opting out is October 26, 2026. The deadline for submitting a claim is November 23, 2026, and the final fairness hearing is scheduled for December 3, 2026.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist