The health center is settling a lawsuit stemming from a breach that took place nearly three years ago.
What happened
Lucent Health Solutions, a Nashville-based health plan administration service provider, recently agreed to a settlement over a lawsuit that stemmed from a 2023 data breach. The lawsuit, Royal Corralejo v. Lucent Health Solutions, LLC Litigation, alleged that the services administrator failed to implement reasonable and appropriate cybersecurity measures, which resulted in a data breach. As is common in settlements like these, the service provider denied the claims and wrongdoing but stated that they opted to settle the lawsuit to avoid the costs associated with litigation and the uncertain outcome.
A final approval hearing is scheduled for September 9th, 2026, according to the settlement website.
The backstory
Lucent originally filed the data breach notice with the California Attorney General on January 1st, 2025. It’s unclear if they began notifying victims prior to this date, but their web notice also remains available online. According to the notice, the breach took place on October 2nd, 2023, and was the result of a phishing email. The company stated that a health manager in California opened a single phishing email from an individual they thought they could trust.
The notice added that the IT Team nearly immediately identified suspicious activity on the employee’s email account, and eliminated the unauthorized access within 90 minutes. Through an investigation, a cybersecurity firm “confirmed no information was downloaded or electronically transferred from the email account, and did not identify evidence that an unauthorized individual actually viewed any information.” The notices were provided out of an abundance of caution. However, the settlement agreement shows it’s possible some protected information, like Social Security numbers and dates of birth, may have been accessed. The breach impacted approximately 37,000 individuals.
Why it matters
There are several unique aspects to this case, including how brief the breach was. The incident lasted only 90 minutes, a testament to Lucent’s incident response team and auditing practices. It’s clear the team was closely monitoring their network, even if the breach could have been prevented. In a case like this, where a phishing email is inadvertently opened by an employee, a stronger quarantine process could have avoided the entire incident. Software like the Paubox email suite immediately flags suspicious emails, catching things (like slightly misspelled email addresses, malicious links or attachments, and more) that may slip past the human eye. As AI tools advance, it’s become easier than ever for hackers to craft compelling and realistic narratives, leading to more successful phishing attempts. Without the right software, it’s more likely for even the most astute employees to be taken advantage of.
The big picture
Healthcare organizations should pay particular attention to this case, because even though very little data was stolen and the window of access was so small, victims can still expect to receive a relatively large payout. Despite Lucent’s efficient response to the incident, it unfortunately came too late to prevent this large suit. It’s clear that even small breaches can have hefty costs associated, and Paubox has found that the average cost of a breach is $9.8 million, putting Lucent on the lower side.
FAQs
Why do so many data breach class action lawsuits result in a settlement?
Most healthcare organizations prefer a settlement because the costs associated with trial can be significant, especially when there is a fair amount of evidence against the provider. Providers usually work with their legal team to determine if they may be unlikely to win the case, and will choose to settle if they are likely to lose in trial. For victims, this can also be advantageous, as trials for them are also time-consuming, can span multiple years, and involve out-of-pocket costs. While there aren’t statistics on the number of suits that go to trial versus settle, it’s fairly rare to see a lawsuit like these go to trial.
Why do notices claim different amounts of information were accessed?
There is some discrepancy in the information available online. Lucent’s web notice states no information was accessed, while court documents say otherwise. It’s possible that further investigation revealed that data had been accessed, and that this information came out in mediation or discovery, but is not reflected on Lucent’s website.
