NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement

The Wisconsin mailing and printing vendor OneTouchPoint Corp. has agreed to settle class action litigation over a 2022 ransomware attack and data breach that affected more than 2.65 million individuals. The cyberattack that sparked the litigation was identified on April 28, 2022, when files were encrypted on its network. The forensic investigation determined that a ransomware group first accessed its network the previous day on April 27, 2022.

Data exposed and potentially stolen in the incident included names, subscriber ID numbers, diagnoses, medications, addresses, dates of birth, sex, physician demographic information, family histories, social histories, allergies, vitals, immunizations, and other information. OneTouchPoint reported the data breach to the HHS’ Office for Civil Rights as affecting 2,651,396 individuals and issued notifications to the affected individuals in April 2022.

Multiple class action lawsuits were filed in response to the data breach, all of which asserted similar claims. The lawsuits alleged that the data breach should have been prevented and was due to the failure of the defendant to implement reasonable and appropriate cybersecurity measures. The individual lawsuits were consolidated into a single action – Dusterhoft v. OneTouchPoint, Inc. – which is pending in the Circuit Court of Waukesha County, Wisconsin.

The consolidated lawsuit asserted claims for negligence, negligence per se, breach of contract, breach of implied contract, breach of fiduciary duty, breach of confidence, invasion of privacy, fraud, misrepresentation, unjust enrichment, bailment, wantonness, failure to provide adequate notice pursuant to any breach notification statute or common law duty, and violations of state consumer protection laws. All claims and contentions in the lawsuit were denied by the defendant, including claims of fault, wrongdoing, and liability. To avoid the costs and risks associated with a trial and related appeals, all parties agreed to settle the litigation.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Under the terms of the settlement, OneTouchPoint has agreed pay attorneys’ fees and expenses up to $1,500,000, settlement administration costs, service awards of $1,000 for each of the class representatives, and monetary benefits and credit monitoring. The defendant also agreed to injunctive relief and will implement security enhancements valued at approximately $2,000,000, which will be maintained for at least five years.

The settlement class is divided into two subclasses – a monetary relief class and an injunctive relief class. The monetary relief class consists of individuals who were notified that their information had been impacted by the data breach. Those individuals may submit claims for monetary benefits. The injunctive relief class consists of individuals who were notified about the data breach, but the investigation could not determine that the data breach had an actual impact. Those individuals will benefit from the injunctive relief only.

All members of the monetary relief class may choose to receive a complimentary two-year subscription to a single-bureau credit monitoring service, which includes a $1 million identity theft insurance policy. In addition, claims may be submitted for compensation for documented, unreimbursed ordinary losses up to a maximum of $500 per class member, and up to $5,000 compensation for documented, unreimbursed extraordinary losses. In addition, compensation may be claimed for up to four hours of lost time at $25 per hour. Monetary relief class members who choose not to submit a compensation claim may claim an alternative one-time cash payment of $75.

The deadline for opting out of the settlement and objecting is October 16, 2026. Claims must be submitted by November 16, 2026, and the final approval hearing has been scheduled for November 18, 2026. Further information can be found on the settlement website: https://otpdataincident.com/

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist