25% off all training courses Offer ends May 8, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends May 8, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Tandem Diabetes Care Facing Class Action Lawsuit over January 2020 Phishing Attack

The San Diego medical device manufacturer, Tandem Diabetes Care Inc., is facing a class action lawsuit in California over a January 2020 data breach that resulted in the exposure and possible theft of the protected health information of more than 140,000 individuals.

The breach was the result of a phishing attack that gave unauthorized individuals access to the email account of an employee between January 17 and January 20, 2020. The information in the email account varied from patient to patient but included a range of private and confidential information including names, dates of birth, insurance information, billing information, healthcare data, and Social Security numbers.

The incident was reported to the HHS’ Office for Civil Rights on March 17, 2020 as affecting 140,781 individuals. Notification letters started to be sent to those individuals the same day.

The lawsuit was filed in the United States District Court in the Southern District of California and alleges violations of the Confidentiality of Medical Information Act (CMIA). The plaintiff and class members seek damages for the negligent disclosure of their personal and healthcare data and injunctive relief.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

CMIA requires healthcare service providers to implement measures to ensure the confidentiality of individually identifiable medical information and prohibits the disclosure to that data without prior authorization from patients. In contrast to HIPAA, CMIA includes a private cause of action which allows patients to take legal action over the negligent disclosure of their confidential health data.

The lawsuit names the plaintiff as C.H, and the putative class divided into two subclasses: All California citizens whose identities, personal data, and medical information were contained in the email account and all other individuals whose information was exposed.

The lawsuit alleges negligence for failing to protect individually identifiable health information. “By making Defendant’s email account accessible to third parties, Defendant negligently created, maintained, preserved, stored, and then exposed Plaintiff’ and the Class members’ individual identifiable “medical information,” states the lawsuit.

The lawsuit alleges Tandem Diabetes Care failed to maintain adequate technological safeguards, which directly and proximately caused foreseeable risk of patient data loss and harm, including identity theft and other economic losses.

The lawsuit alleges patients have suffered damages as a result of the unauthorized release of their personal and protected health information and seeks nominal damages of $1,000 per class member, reimbursement for actual damages suffered, damages provided by the common law, and legal costs.

The lawsuit was filed by Joshua B. Swigart of the law firm Swigart Law Group, who is seeking class action status and a jury trial

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist