The data breach impacted approximately 624,496 individuals in 2024.
What happened
In October of 2024, Healthcare Services Group (HCSG), a Bensalem, Pennsylvania-based provider of environmental, dining, and nutritional support for healthcare facilities, became aware of a data breach that impacted 624,496 individuals, including employees and patients. Data that was accessed in the breach included names, Social Security numbers, driver’s license numbers, state identification numbers, financial account information, full access credentials, and medical and health insurance information.
Multiple class action suits were filed, but they were ultimately consolidated into Williamson, et al. v. Healthcare Services Group, Inc. As part of the settlement, HCSG denies any wrongdoing but determined that a settlement was the best course of action to prevent the uncertainty and costs of a trial. Both parties agreed to a $3 million settlement, which will go towards court and attorney fees, service awards, awards to class members, and taxes. A final fairness hearing is scheduled for September 24th, 2026.
The backstory
The breach was discovered on October 7th, 2024, while the breach itself took place between September 27th, 2024, and October 3rd, 2024. According to Security Affairs, the breach notice was initially provided to the Maine Attorney General’s Office, but has since become unavailable due to the office removing their breach database from public viewing following abuse. The breach notice stated that following the discovery, HCSG investigated the incident, notified law enforcement, and soon after began implementing new safeguards and staff training. The investigation was completed on June 3rd, 2025.
At the time, HCSG said they had no evidence of fraud, but still provided free credit monitoring and additional guidance.
HCSG is a large organization, servicing over 3,000 healthcare facilities in 48 states. The company also disclosed the incident to the US Securities and Exchange Commission (SEC), where they again stated they had taken steps to improve their cybersecurity but noted, “The safeguards we use are subject to human implementation and maintenance, technology evolutions and other uncertainties.”
The big picture
Data breaches against healthcare organizations often start at either a healthcare practice itself, or, as in this case, a partner for many practices. HCSG provides numerous critical services to healthcare organizations across the country, but many people may not realize all of the partners a practice may have to operate smoothly. Paubox has noted that vendors can include anything from third-party administrators to medical transcriptionists, data analytics companies, and even accountants. All of these vendors have a role in keeping data safe, but without the right audits and controls, it’s just a matter of time before these vendors are hit with a cyberattack. In their SEC annual filing, HCSG even noted, “Although we have taken steps intended to mitigate the risks presented by potential cyber incidents, it is not possible to protect against every potential power loss, telecommunications failure, cybersecurity attack, data breach, or similar event that may arise.” Although in the world of cybersecurity there is always the element of the unknown, proper security tools can greatly decrease the risk of an attack. In a 2025 article, Paubox emphasized that communication is frequently a cornerstone of stability, especially since so many attacks are carried out through communication systems. Keeping these systems running smoothly and safely can help practices not only protect themselves, but also protect other practices who rely on shared vendors.
FAQs
Why are so many breaches discovered after they have ended?
Often, hackers are stealthy when entering into an organization’s network, working quickly, quietly, and efficiently to access and/or copy data. Once they’ve exited the network, they may notify the victimized company so it is aware, but often, the breach is discovered once individuals experience fraudulent chargers or the company notices that suspicious activity had taken place.
What determines the settlement amount from a class action suit?
Lawsuit settlement amounts vary greatly, but some factors that can influence the amount include the size of the class and the potential for damages, which can be determined by what and how much information was accessed. Other factors, like if notifications were delayed or operations were disrupted, can also contribute to a larger settlement.
