25% off all training courses Offer ends June 26, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends June 26, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Onsite Women’s Health $2.5M Data Breach Settlement

A breach of the email account of an employee of Onsite Women’s Health that exposed the protected health information of 357,265 individuals has resulted in a $2,525,000 settlement. Onsite Mammography, LLC, which does business as Onsite Women’s Health, a Westfield, Massachusetts-based provider of medical imaging services to hospitals, identified unauthorized access to an employee’s email account in October 2024.

The email account was compromised as a result of a response to a phishing email, and while the account was only accessible for a short period of time, sensitive data was exfiltrated, including names, dates of birth, Social Security numbers, driver’s license numbers, credit card numbers, and information related to patients’ mental or physical conditions, and any care they received.

Multiple class action lawsuits were filed in response to the data breach, which were consolidated – Clarkson, et al. v. Onsite Mammography, LLC, d/b/a Onsite Women’s Health – in the United States District Court District of Massachusetts.  The consolidated lawsuit alleged that inadequate security measures had been implemented to prevent attacks on employee email accounts, and if those measures had been implemented, the data breach could have been prevented or at least the attack could have been detected more quickly, limiting the harm caused.

While the affected individuals were offered 12 months of complimentary credit monitoring services, the plaintiffs argue that the offer was insufficient considering the level of risk they face. They also claim that the defendant provided no reassurances that the stolen data had been deleted or that security had been sufficiently strengthened to prevent similar incidents in the future.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The lawsuit asserted claims for negligence, breach of implied contract, breach of fiduciary duty, invasion of privacy, unjust enrichment, and declaratory judgment. The defendant maintains there was no wrongdoing and disagrees with the claims and contentions asserted by the plaintiffs. Despite disagreeing with the claims, after considering the likely costs and risks associated with continuing with the litigation, Onsite Women’s Health agreed to settle the lawsuit.

Under the terms of the settlement, Onsite Women’s Health will establish a $2,525,000 settlement fund to cover attorneys’ fees and expenses, settlement administration and notification costs, and service awards for the eight class representatives. The remainder of the settlement fund will be used to cover benefits for the class members.

Class members may submit a claim for reimbursement of documented, unreimbursed losses incurred as a result of the data breach up to a maximum of $5,000 per class member. A claim may also be submitted for three years of credit and medical data monitoring and insurance services. Class members may also claim a pro rata cash payment, which will be paid after all costs and claims have been paid and will exhaust the settlement fund. The deadline for objection and exclusion is July 13, 2026. Claims must be submitted by August 11, 2026, and the final fairness hearing has been scheduled for September 9, 2026.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist