Healthcare Services Group pays $3M to settle data breach class action

Nursing home support services provider agrees to $3M payout after September 2024 cyberattack exposed data of 624,496 individuals.

MedRisk Staff
By
2 Min Read

A federal class action over a September 2024 cyberattack at a major nursing home services vendor has been resolved with a $3 million settlement, offering healthcare organizations a case study in downstream liability from third-party access to sensitive systems.

The vendor operates across nearly every state, supplying support staff to hospitals and nursing homes. Investigators found the intrusion started on September 27, 2024, roughly ten days before the activity was flagged. Files removed from its systems included Social Security numbers, driver’s license data, banking details, login credentials, and medical histories for more than 600,000 individuals.

The consolidated lawsuit, filed in the Eastern District of Pennsylvania after notification letters went out in August 2025, alleged negligence and breach of fiduciary duty. The company denied wrongdoing but chose to settle rather than litigate. The payout covers claims that the vendor failed to safeguard protected health information under federal and state law.

The case highlights a recurring risk pattern: service vendors with deep network integration across hundreds of client sites create proportional exposure. For hospitals and nursing facilities, verifying that third-party vendors maintain current risk assessments, documented incident response plans, and breach notification timelines is a practical step toward limiting class action exposure from partner-originated incidents.

Share This Article