Class action settlements have closed lawsuits against Palomar Health Medical Group in California and Summit Medical Group in Tennessee, both tied to 2024 intrusions.
Palomar, which serves patients at 20 locations across San Diego and Riverside counties, agreed to a $3.1M fund covering 1,140,221 people. Intruders had network access from April 23 to May 5, 2024. Exposed data included names, dates of birth, Social Security numbers, medical histories and insurance details. Patients consolidated their claims in September 2024 and alleged the group failed to apply reasonable safeguards. Palomar denied wrongdoing.
Summit Medical Group, which runs more than 90 sites in Tennessee, settled over a November 2024 incident affecting 464,000 patients and employees. Plaintiffs argued the group knew on September 19, 2024, that data was exposed yet did not mail notifications until March 2025. The deal offers two years of medical data monitoring, reimbursement of documented losses up to $2,500 and up to $45 for lost time, with cash payments capped at $500,000.
Both cases settled to avoid litigation costs. For healthcare compliance teams, the Summit timeline is the cautionary note: regulators and courts increasingly treat delayed breach notification as its own liability, separate from the intrusion itself. Groups should document detection dates and notification decisions carefully, because the gap between them often becomes the centerpiece of a class action.