A class settlement is closing four years of litigation over a ransomware attack that froze a Wisconsin healthcare mailing vendor and exposed records tied to 2.65 million people. OneTouchPoint, which produces and mails benefit communications for health plans, reached the agreement in the consolidated Dusterhoft case pending in Waukesha County court and continues to deny the claims against it.
Encryption hit company systems on April 28, 2022, and investigators later found the intruders had entered the day before. OneTouchPoint’s report to the HHS Office for Civil Rights counted 2,651,396 affected individuals, with the exposed material spanning names, subscriber identifiers, diagnoses, medications, birth dates, addresses, family and social histories, allergies, vitals and immunization records.
Under the terms, OneTouchPoint pays attorneys’ fees and expenses of up to $1.5M and funds security improvements valued near $2M that must stay in place for five years. Eligible class members receive two years of credit monitoring with $1M in identity theft coverage and can claim up to $500 in documented ordinary losses, $5,000 in extraordinary losses and four hours of lost time at $25 per hour, or take $75 in cash. Exclusion papers are due October 16, claims by November 16, and a final hearing is scheduled for November 18, with details on the settlement site, otpdataincident.com. For provider organizations, the case argues for vetting every partner that touches patient-adjacent mailings, since fulfillment vendors accumulate clinical detail that fuels class suits years after an incident.