A California home care provider has closed the books on a class action whose central fact is a detection gap: an intruder spent roughly five months inside the network that holds its patients’ records before anyone noticed.
Vasindas’ Around the Clock Care, Inc. delivers in-home care to patients, and the provider settled over a January 2024 cyberattack, according to a report in the HIPAA Journal. Court filings pin the start of the unauthorized access to January 30, 2024, and say it persisted until suspicious activity surfaced around June 18, nearly five months in which personal and protected health records were copied off the network.
The data that left the network reads as the full spread of identifiers a home care patient might ever share with a provider, reaching into both clinical and financial territory: financial account information and health insurance information, names, Social Security numbers, driver’s license and state identification numbers, and medical information. HHS’ Office for Civil Rights logged the incident as touching 3,785 people, who were told in August 2024. The filings consolidate the claims under Nelson et al. v. Vasindas’ Around the Clock Care, Inc. The case went before California’s Kern County Superior Court, where the settlement won approval.
Two years of medical data monitoring is on offer, alongside a choice between documented-loss reimbursement capped at $2,500 and a flat $70 payment. The window to object or opt out closes October 26, 2026, and claim forms are due November 23, 2026. The agreement carries no admission of wrongdoing.
The plaintiffs’ central allegation, that basic safeguards and monitoring were missing, is the part healthcare security leaders should read closely. Five months is the kind of dwell time that detection engineering and log review are meant to close.