25% off all training courses Offer ends May 29, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 29, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Heartland Alliance Agrees to Data Breach Settlement

A Chicago anti-poverty organization and associated companies have agreed to a $300,000 settlement to resolve a class action lawsuit filed in response to a 2022 data breach. On or around December 15, 2022, Heartland Alliance disclosed a data security incident and mailed notification letters on or around December 21, 2022. An unauthorized third party had access to its network, where files containing sensitive data were stored. Those files contained names, dates of birth, Social Security numbers, driver’s license numbers, bank account numbers, and medical/health information. While the data breach was announced in December 2022, the hackers gained access to the network on January 26, 2022. Heartland Alliance reported the data breach to the HHS’ Office for Civil Rights as involving the protected health information of 46,694 individuals.

A lawsuit was filed against the several Heartland entities – Wittmeyer et al. v. Heartland Alliance for Human Needs & Human Rights, Heartland Alliance Health, Heartland Alliance International, LLC, Heartland Housing, Inc., and Heartland Human Care Services, Inc. – in the Circuit Court for Lake County, Illinois, County Department, Chancery Division over the data breach. The plaintiffs alleged that the defendants were negligent due to failing to implement reasonable security measures pursuant to HIPAA, the FTC Act, and the Illinois Consumer Fraud and Deceptive Business Practices Act.

The lawsuit also asserted claims of negligence per se, related to the lack of encryption or equivalent safeguards as required by HIPAA, breach of contract, breach of implied contract, and a violation of the Illinois Consumer Fraud and Deceptive Business Practices Act. The defendants deny all claims and contentions in the litigation and maintain there was no wrongdoing; however, a settlement was agreed after considering the costs, expenses, distraction, and risks associated with continuing with the litigation.

Under the terms of the settlement, class members may claim compensation for documented, unreimbursed losses of up to $6,000. That includes up to $1,000 for ordinary losses and up to $5,000 for extraordinary losses due to identity theft and fraud. Claims may also be submitted for up to three hours of lost time at $22.50 per hour as compensation for time spent resolving issues related to the data breach. The settlement also includes two years of three-bureau credit monitoring services, which include a $1 million identity theft insurance policy.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The settlement has received preliminary approval from the court, and the final approval hearing has been scheduled for November 19, 2025. Individuals wishing to object to or exclude themselves from the settlement must do so by September 30, 2025, and claims for compensation, lost time, and credit monitoring services must be submitted by October 30, 2025. Further information can be found on the settlement website: https://heartlanddatasettlement.com/

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist