NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Albany College of Pharmacy and Health Sciences Data Breach Settlement

Albany College of Pharmacy and Health Sciences in New York State has agreed to settle a class action lawsuit stemming from a 2024 cybersecurity incident involving unauthorized access to systems containing the personal and protected health information of employees, patients, applicants, and students.

Suspicious activity was identified within its network on September 14, 2024. The forensic investigation determined that a hacker had access to its network between August 31, 2024, and September 14, 2024, and potentially obtained names, Social Security numbers, financial information, birth and marriage certificates, passport numbers, driver’s license numbers, health insurance information, medical information, and student information. Notification letters were mailed to the 26,411 affected individuals on June 16, 2025, and September 8, 2025.

The first class action lawsuit was filed in June 2025, followed by a further three putative class action lawsuits. The four lawsuits were consolidated into a single action – Levin, et al. v. Albany College of Pharmacy and Health Sciences – which is pending in the Supreme Court of Albany County, New York. Another plaintiff was later added to the consolidated complaint.

The lawsuit asserted claims for negligence, invasion of privacy-intrusion upon seclusion, breach of implied contract, unjust enrichment, and violation of New York’s Information Security Breach and Notification Act. All claims and contentions in the lawsuit were denied by the defendant. Mediation was unsuccessful; however, in the following weeks, the material terms of a settlement were agreed upon, and the terms have now been finalized and received preliminary approval from the court.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The defendant has agreed to pay attorneys’ fees and expenses, settlement administration costs, and service awards of $2,500 for each of the five class representatives. Class members are entitled to claim a two-year membership to a credit, fraud, and identity theft monitoring service. In addition, a claim may be submitted for reimbursement of documented, unreimbursed losses due to the data breach up to $5,000 per class member, and/or compensation for up to four hours of lost time at $20 per hour.

An alternative cash payment of $25 is available for class members who choose not to submit a claim for reimbursement of losses or lost time. The deadline for objection and opting out is October 16, 2026. The deadline for submitting a claim is November 16, 2026, and the final fairness hearing is scheduled for December 10, 2026.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist