25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Community Health Systems HIPAA Breach Lawsuits Mount

The data breach at Community Health Systems which was reported in August was the second largest in history, with 4.5 million records potentially accessed by a suspected group of Chinese hackers. The successful attack and data theft has left millions of patients potentially exposed and at risk of identity theft and financial loss. The data accessed included personal information such as names, addresses, social security numbers and date of births; information the thieves can use to create fake documents and run up huge debts.

The HIPAA breach has understandably resulted in legal action being taken against CHS by some of the victims, with at least two class action lawsuits now filed against the healthcare provider and operator of 206 nationwide hospitals.   A class action lawsuit has been filed by firms Slack & Davis and Branch Law Firm with Briana Brito named as the class representative. A second class action suit has been filed on behalf of 5 Alabama residents (and all others affected). Specific dollar amounts have not been stipulated and are being left to the courts to decide.

The lawsuits contend that CHS failed to implement appropriate security measures to protect the data of its patients and that its negligence in this respect allowed hackers to access its patient database.

With victims of identity theft as well as those who believe themselves to be at risk being encouraged to claim damages it is likely that more class action lawsuits will soon follow. However, recent court cases have made it clear to would be plaintiffs that actual loss or damage must have been suffered in order for damages to be applicable. Plaintiffs who have not been the victim of identity theft or suffered financial losses are not being viewed favorably by the courts.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

One class action lawsuit also alleges diminished value of services as a result of the data security incident, while the slow response to the discovery of the data breach and the delay in notifying victims appears to be a major focus in the lawsuits.

This is the second major financial hit that CHS has taken this year having agreed on a $98 million settlement with the Department of Justice after irregularities were found in its billing practices. The data breach is likely to cost CHS up to $150 million in fines and lawsuits, while the effect that this year – and the data breach in particular – will have on the company’s reputation is impossible to calculate.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist