Vasindas’ Around the Clock Care Settles Data Breach Litigation
Vasindas’ Around the Clock Care, Inc., a California-based provider of home care services, has settled class action litigation over a January 2024 targeted cyberattack. Suspicious activity was identified within its computer systems on or around June 18, 2024. The investigation determined that an unauthorized third party first accessed its network on January 30, 2024, and maintained access for almost five months. During that time, files were copied from its network that contained the personal and protected health information of customers, employees, and patients.
Data compromised in the incident included names, Social Security numbers, driver’s license numbers/state identification numbers, financial account information, medical information, and health insurance information. The breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 3,785 individuals, and the affected individuals were notified on August 16, 2024.
The first class action lawsuit was filed on August 27, 2024, alleging this was a ransomware attack that could have been prevented if appropriate cybersecurity measures had been implemented. The lawsuit alleged that basic cybersecurity measures had not even been implemented and that there was insufficient monitoring of network activity, since the unauthorized access was not detected for almost five months. A second class action lawsuit was filed, and the two actions were consolidated – Nelson et al. v. Vasindas’ Around the Clock Care, Inc. – in the Superior Court for Kern County, California.
All parties explored an early resolution to the litigation, and while mediation was not successful, an agreement was reached, and a settlement has now been finalized and approved by the court, with no admission of wrongdoing or liability by the defendant. The defendant continues to deny all allegations and claims in the lawsuit, and maintains that the plaintiffs did not suffer any damages as a result of the data incident.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Under the terms of the settlement, the defendant will pay attorneys’ fees and expenses, settlement administration costs, and service awards for the class representatives. Class members are entitled to claim a two-year membership to a medical data monitoring service and may also claim one of two cash payments. A claim may be submitted for compensation for documented, unreimbursed losses due to the data breach up to a maximum of $2,500, or they may claim an alternative one-time cash payment of $70. The deadline for objection and opting out is October 26, 2026. The deadline for submitting a claim is November 23, 2026, and the final fairness hearing is scheduled for December 3, 2026.


