CorrectCare Data Breach Lawsuit Settles for $6.9 Million

Sept. 25, 2024
Breach exposed sensitive information and left the personal data of 600,000 individuals vulnerable

 

HIPAA Journal’s Steve Alder reported on September 23 that the CorrectCare Integrated Health data breach lawsuit has been settled for $6.49 million. CorrectCare, a Kentucky-based medical claims processor for correctional facilities, experienced a cybersecurity breach between January 22, 2022, and July 7, 2022. The breach, affecting around 600,000 people, was not reported until November 2022.

“In July 2022, CorrectCare identified a misconfiguration on its web server that allowed two file directories to be accessed over the Internet without authentication,” Alder wrote.

Shub & Johns’s attorney, Benjamin F. Johns, filed a class action lawsuit against CorrectCare on December 7, 2022. “On September 17, 2024, Chief Judge Danny C. Reeves issued an order granting final approval to the $6.9 million settlement,” Alder stated.

Over 100,000 claims were filed, representing about 17 percent of the class action suit.

Sponsored Recommendations

Cloud Communications: Connecting Care at the Core

Cloud communications is the present, the recent past, and the future of collaborative healthcare.

The Ultimate HIPAA Security Guide for Cloud Communications

The healthcare industry is leading the charge in innovation, embracing cutting-edge technologies to enhance patient care and optimize operations. Forward-thinking organizations...

Improving Workplace Safety and Patient Care in Behavioral Health

In 2023, Vail Health enhanced safety in their behavioral health clinic, but the impact went beyond their expectations. Read their case study to see how prioritizing workplace ...

Transforming Hospital Capacity Through Smarter Patient Progression Strategies

Helping patients move seamlessly through every stage of their care, from admission to discharge, is critical to ensuring patient safety, improving outcomes, and optimizing capacity...