The nonprofit community healthcare network has agreed to settle a large lawsuit stemming from a data breach in 2024.
What happened
In June of 2025, DAP Health, a community healthcare network based in southern California, became the defendant in a class action lawsuit regarding a data breach that resulted in protected health information (PHI) being exposed. The lawsuit, Donald Crosslin and Matthew Paone v. DAP Health, Inc., alleged that the data breach could have been prevented. The lawsuit further claimed that DAP Health acted negligently, breached its implied contract, and violated multiple California privacy laws.
DAP Health agreed to a settlement approximately one year later, in June 2026, to resolve a class action suit.The settlement followed negotiations which ultimately allowed DAP Health to deny any wrongdoing or liability. However, DAP agreed to a $1.3 million settlement, which will go towards attorneys’ fees and expenses, settlement administration costs, services awards, and benefits for class action members.
Class members have the option to exclude themselves from the settlement until September 1st and a final approval hearing is scheduled for October 1st.
The backstory
The data breach that led to the lawsuit is dated back to 2024. In July of that year, DAP identified suspicious activity inside their network and soon after confirmed that their systems had been accessed by an unauthorized party. The third party gained access to an email server and files containing PHI and other personally identifiable information. The actor went on to exfiltrate these files, which included personal information like names, contact information, dates of birth, Social Security numbers, driver’s license numbers, passport numbers, birth certificate numbers, vehicle license information, health insurance information, and other medical information.
Notifications were sent out beginning in December of 2024. DAP ultimately reported that the breach impacted 129,048 individuals.
In the know
Nonprofit organizations can be particularly vulnerable to data breaches because they generally run tight margins, which can result in less funds going towards preventative measures, like cybersecurity. Many organizations don’t realize how critical prevention is until it’s too late; paying for tools like email software may not seem important when it appears that there is no imminent threat, but organizations need to remember that these risks are significantly harder to mitigate and respond to than to prevent. According to a 2025 research paper, Cybersecurity in Healthcare: New Threat to Patient Safety, “Healthcare organizations suffering cyberattacks face considerable financial implications following cybersecurity incidents, with remediation efforts, data recovery costs, legal fees, and potential regulatory fines all straining limited resources… Healthcare organizations looking to prevent financial loss should invest in cybersecurity measures focusing on prevention, early detection, and rapid response to minimize any resulting cyber incidents. Furthermore, IBM’s most recent report found that healthcare recorded the highest average data breach cost compared to other industries, with an average cost of $6.6 million around the globe.
The big picture
For a nonprofit like DAP Health, even as this case comes to a close, the effects will likely be felt for years as DAP works to financially recover and improve their cybersecurity systems. The financial impacts don’t only hurt DAP’s bottom line; they can impact the organization’s ability to hire practitioners, improve their technology, and how well they can serve patients overall. Every data breach, big or small, can have ramifications that last for years, ultimately harming communities that need medical care. Considering that this breach was connected to a hacked email server, it’s possible the incident could have been prevented with better email security. DAP likely understands that, in hindsight, it’s critical for every organization to constantly improve and update their security systems as needed and to treat cyberattacks as imminent rather than far-off threats.
FAQs
Does California have more privacy laws than other states in the US?
California tends to lead the way when it comes to enacting privacy laws that are responsive to changing technology and privacy concerns. However, many states actively take steps to protect patient privacy. For instance, California’s Confidentiality of Medical Information Act (CMIA) is stricter than HIPAA, and several other states, including Texas and Minnesota, have their own state-specific version.
Are there any consequences for healthcare organizations if individuals object to the settlement?
If someone objects to the settlement, it means they could possibly file a separate lawsuit over the same incident. However, the lawsuit would have to provide unique and new evidence in order to be considered. Generally, once a class action suit is settled, no more lawsuits rise from the same incident.
Does the type of data stolen matter?
Some pieces of data are considered more highly sensitive than others. For instance, Social Security numbers and medical information is seen as particularly valuable on the dark web. However, even “less” valuable data can still be vulnerable in the wrong hands, as it can help threat actors piece together a more complete victim profile, which may aid them in theft or fraud attempts.
