The data breach hit the practice in 2024, then spread to the practices Clay Platte shared patients with.
What happened
A class action suit against Clay Platte Family Medicine Clinic, and co-defendants Summit Family and Sports Medicine, and Barry Pointe Family Care, recently received preliminary approval from the US District Court for the Western District of Missouri.
Under the terms of the settlement, the defendants have agreed to a $1 million fund, which will go towards reimbursement for victim’s documented losses and cash funds for victims. Victims can additionally claim free monitoring services and Clay Platte, along with the other practices, have agreed to commit to certain business practices, which were not stated, for at least five years following the settlement.
The backstory
The lawsuit dates back to June 26th, 2024, when Clay Platte and the providers they share patients with detected suspicious activity in their network environment. Following the discovery, all of the clinics immediately began securing their network and working with a cybersecurity firm. An investigation determined that the incident impacted 53,916 individuals. For those individuals, their names, addresses, Social Security numbers, dates of birth, and health insurance information were impacted. Their review of the data was completed on September 10th, 2024, and soon after, notices began to be mailed.
Why it matters
The case is unique in that there are multiple co-defendants. Generally, one organization or group is found to be primarily responsible for the breach, or at times, a practice and a vendor are found to be jointly responsible. In this case, Clay Platte shared responsibility with two other practices, which creates some questions about how their networks are interconnected. Since Clay Platte initiated providing the notices and is listed first in the defendants section, they may be taking on slightly more responsibility. Nevertheless, the case is a reminder that many organizations are interconnected. Even if one patient is going to a specific podiatrist, it’s entirely possible that a family doctor or another practice could have protected health information.
The big picture
For family practices, like the ones impacted here, it can be particularly challenging to overcome a data breach. According to a study in the Small Business Institute Journal, breaches often result in a myriad of financial challenges, like paying for updated software, audits, and technology. Those reasons are also why smaller practices can be targets for opportunistic attackers, who focus on breaching the easiest targets. Once a breach takes place, these smaller practices struggle with significant reputational harm, legal fees, and costs associated with changing their business practices. According to Paubox, the average data breach costs $7.42 million, a cost that can be crippling for small and even mid-size businesses. While the price of preparing for a breach can be high, it’s still necessary to prevent higher costs in the long run. Plus, highly effective tools like Paubox charge based on the size of your company, rather than a flat rate for every business, making it easy and affordable to keep email safe.
FAQs
Why do data breach legal cases take so long to be resolved?
A lot goes on behind the scenes from when a breach is first discovered until checks land in the hands of class members. Before notification can even begin, organizations have to conduct an in-depth investigation. After notices are provided and a lawsuit begins, a new process of discovery is initiated.
What group is responsible for the breach?
For this incident, like many, we don’t know what malicious organization may have initiated the attack. While it’s common for ransomware groups to provide notes and publicize the hack, many other groups never do so. Instead, they simply sell data or post it on the black market
