The count more than doubled from an initial estimate of 1.1 million, and the exposed data included immunization records and family histories.

 

What happened

OneTouchPoint Corp., a Wisconsin printing and mailing services vendor, has agreed to settle consolidated class action litigation over a 2022 ransomware attack that affected more than 2.65 million people, according to the court-authorized settlement notice. The company found encrypted files on its network on April 28, 2022, and a forensic investigation placed the intruder's first access one day earlier. Its initial disclosure put the affected population at roughly 1.1 million. The consolidated case, captioned Dusterhoft v. OneTouchPoint, Inc., is pending in the Circuit Court of Waukesha County, Wisconsin, and OneTouchPoint denies all claims of fault, wrongdoing, and liability. A final approval hearing is scheduled for November 18, 2026.

 

Going deeper

Data exposed in the incident covered names, addresses, dates of birth, sex, and subscriber identification numbers, alongside diagnoses, medications, allergies, vitals, immunizations, family histories, social histories, and physician demographic information. That range is unusual for a company whose business is printing and posting mail. Vendors in this position produce member communications on behalf of health plans, including explanation of benefits statements, care gap reminders, wellness outreach, and immunization notices, and generating those documents requires the underlying clinical detail rather than a name and address alone. Around 38 health plans and provider organizations were affected. The complaint asserted negligence, negligence per se, breach of contract and implied contract, breach of fiduciary duty, invasion of privacy, unjust enrichment, and failure to provide adequate notice under breach notification law, among other claims.

 

What was said

OneTouchPoint "denies all of the claims and contentions" in the litigation, including allegations of fault, wrongdoing, and liability, according to the settlement notice, which records that the parties resolved the matter to avoid the cost and uncertainty of continued litigation and that the court has made no determination on the merits. Class members have until October 16, 2026, to opt out or object.

 

In the know

The minimum necessary standard governs how much information moves to a vendor in the first place, and HHS states that a covered entity may not use, disclose, or request an entire medical record for a particular purpose unless it can specifically justify the whole record as the amount reasonably needed, in its summary of the Privacy Rule. Business associate agreements must limit the vendor's uses and disclosures consistently with the covered entity's own minimum necessary policies. HHS guidance also permits reasonable reliance on a business associate's judgment about what it needs, under specified conditions, where the professional making the request states that the information is the minimum necessary for the stated purpose. That reliance is where a data feed set up years earlier can quietly widen, since nobody revisits whether a mailing vendor still needs every field it was originally given.

 

The big picture

Vendor-involved incidents behave differently from breaches at a single organization. Analysis of 831 provider-reported ransomware incidents between 2016 and 2024 found that cases involving a business associate were smaller than provider-only breaches on average, while running substantially larger once they crossed 100,000 affected individuals, in research published in Health and Technology. The author describes the shape as hub-and-spoke, with severe risk concentrating in vendors that aggregate data from many clients at once, which is what 2.65 million records drawn from 38 organizations looks like in practice. The recommendation that follows is to tier vendors by the disruption their failure would cause rather than treating every business associate agreement as equivalent. Health plans and providers using outsourced mailing services should establish which data elements each vendor currently receives, whether that set has been reviewed since the contract began, and whether the mailing purpose genuinely requires clinical fields or only the identifiers needed to address and personalize a letter. Reducing what leaves the building is the one control that works regardless of the vendor's own security posture.

 

FAQs

Why do affected counts rise so sharply after an initial disclosure?

Early figures reflect what an organization can establish quickly, often from system inventories rather than from reviewing the data itself. Determining who was actually affected requires examining file contents and matching records to individuals, work that regularly takes months and produces a larger number than the first estimate.

 

Does a print vendor need to be a business associate?

Yes, where it creates, receives, maintains, or transmits protected health information on behalf of a covered entity. Producing patient or member mailings from clinical data meets that definition, and a business associate agreement is required before any information changes hands.

 

What does reasonable reliance mean in practice?

A covered entity may accept a business associate's statement that a requested data set is the minimum necessary for its purpose, provided that reliance is reasonable in the circumstances. It shifts judgment to the requester without removing the covered entity's obligation to have policies governing routine disclosures.