An Alabama mental health authority has agreed to a $700,000 settlement tied to a 2025 ransomware attack that exposed the records of more than 30,000 patients.
Jefferson-Blount-St. Clair Mental Health Authority identified unauthorized network activity on November 25, 2025. Its investigation found a ransomware group entered the same day and may have obtained employee personal information and protected health information for 30,434 patients. Compromised data included names, Social Security numbers, health insurance details, birth dates, medical information, Medicare and Medicaid data, and billing or claims records.
Several class actions followed and were consolidated as Meyer, et al. v. Jefferson-Blount-St. Clair Mental Health Authority in Alabama’s Jefferson County Circuit Court. The claims spanned negligence, breach of contract, breach of fiduciary duty, invasion of privacy, unjust enrichment, and alleged notification failures under federal and state law.
The authority denies wrongdoing and said it settled to avoid the risk, delay, and cost of continued litigation. The $700,000 fund covers attorneys’ fees, settlement administration and notice costs, and service awards for class representatives.
Why it matters for healthcare security teams — behavioral health providers hold unusually sensitive records, and ransomware crews know it. Backups isolated from the main network, tested restoration, and phishing-resistant multifactor authentication on remote access remain the controls that most often prevent this outcome.