The 2023 incident impacted 83,543 individuals and shows how nonprofits can struggle following a breach.

 

What happened

A settlement was recently reached in the case of Weyerman, et al. v. Highland Health Systems et al. that follows a 2023 data breach. The lawsuit, which is the result of two suits that were combined into a single action, is currently pending in Circuit Court for Calhoun County, Alabama. While the suit is still pending, it is expected to pass in the final approval hearing, scheduled for November 30th, 2026.

Overarchingly, the lawsuit claims that Highland Health Systems, a non-profit health practice that specializes in mental health and care for developmental disabilities, failed to prevent the data breach by being negligent. The lawsuit makes several claims, like breach of implied contract and breach of fiduciary duty. As part of the settlement, Highland has agreed to pay a $650,000 settlement, but will not have to admit wrongdoing.

 

The backstory

The incident dates back to July 3rd of 2023, when, according to HIghland’s breach notice, the organization detected unusual activity on their network. Upon discovery, Highland immediately disconnected all access to the network and began an investigation into the incident, which determined that some files had been accessed by an unauthorized actor.

During the investigation, which was completed on May 24th, 2024, Highland determined the following information was impacted: dates of birth, Social Security numbers, account numbers, payment card numbers and pins, email addresses and passwords, medical information and health insurance information, tax ID, and driver’s license or state ID information.

In response, Highland noted several specific steps they would be taking to prevent future breaches, like using security monitoring software, adopting new encryption technologies, deploying additional safeguards, and additional steps to improve overall security.

 

Why it matters

The incident impacted a large non-profit hospital, resulting in approximately 83,545 individuals having their personal information accessed. Most hospitals operate on tight margins, a trend expected to continue as expenses grow. Non-profits tend to struggle even more, relying on funding from outside organizations and the government. In 2025, Mayo Clinic, one of the largest nonprofits, reported a 3% operating margin, the exact number generally necessary to maintain financial health. Smaller practices are even more vulnerable to turbulent economies and researchers believe these organizations are still financially recovering from the COVID-19 pandemic.

 

The big picture

When it comes to a settlement amount, the final cost is determined through negotiations, by adding up financial losses, harms, and other associated costs. The agreement doesn’t consider the financial repercussions for organizations like Highland, or how those repercussions may, in turn, be felt by the community the practice serves. Over the last few years, countless hospitals have closed down clinics, filed for bankruptcy, or closed down their doors altogether for financial reasons. While there are many other factors that contribute to a hospital’s closure (rural hospitals, for instance, face the most challenging funding crises), massive data breaches and the costs associated with them can send organizations over the edge.

Data breaches have also grown more sophisticated, with hackers using advanced tactics that are difficult to detect and harder to thwart, but as hacker technology improves, so does cybersecurity software. Paubox’s email suite can help protect organizations from one of the most common attack vectors, phishing, by eliminating human error. For any organization, a simple solution can be the difference between paying a massive settlement or continuing to operate as normal.

 

FAQs

What is breach of implied contract and breach of fiduciary duty?

A breach of an implied contract means that there was an unspoken agreement, in this case it was to keep data secure, that was broken. A breach of fiduciary duty means that the healthcare center had an obligation to act in the best interest of its patients, in this case, again keeping data secure, and failed to do so.

 

What were some of the additional safeguards Highland committed to?

Specifically, Highland said they would be adopting NIST-compliant technical safeguards. This refers to the National Institute of Standards and Technology, which outlines frameworks for data protection for a variety of subjects, like supply chain risk management.