Omni Healthcare and its subsidiaries have agreed to a proposed class action settlement arising from a January 2024 cyberattack.

 

What happened

According to Omni Healthcare’s breach notice, the company discovered a network disruption on January 19 and determined that an unauthorized third party accessed or acquired files between January 18 and January 19. The data varied but could include names, contact information, birth dates, Social Security numbers, medical record numbers, diagnoses, treatment information, treatment costs, and provider names.

HHS records the incident as affecting the protected health information of 16,852 individuals, while the executed agreement says Omni mailed notices to approximately 42,000 people, including Social Security numbers may have been involved. Plaintiffs alleged that Omni failed to safeguard the information; Omni denied wrongdoing and liability. The Mecklenburg County Superior Court preliminarily approved the settlement.

 

Going deeper

The breach occurred on Omni Healthcare’s network rather than on the networks of its healthcare clients. Colorado Springs Orthopaedic Group said the incident was a ransomware attack involving Omni Healthcare and information associated with patients who used Injury Finance, an Omni subsidiary, and confirmed that its own computer network was not involved.

It allowed an attack on one business associate to expose information connected to patients from multiple providers. However, neither Omni’s notice nor the public settlement documents identify the initial route into its network. There is therefore no confirmed evidence that the attacker used phishing, stolen credentials, an unpatched vulnerability, or another specific technique. No ransomware group has been publicly identified.

 

What was said

According to the settlement agreement, “On April 16, 2025, Plaintiff Latasha Hammond filed a putative class action against

Defendants in the United States District Court for the Western District of North Carolina, seeking

damages on behalf of herself and a putative class of all similarly situated individuals (the

“Hammond Action). On April 17, 2025, an additional case related to the Data Incident with

similar claims and overlapping classes was filed in the same court as the Hammond Action by

Plaintiff Dawn Hairston (the “Hairston Action”).”

 

Why it matters

Paubox recently covered Staten Island University Hospital agreeing to settle breach related litigation following a breach at business associate The Medibase Group in January 2024 that involved PHI of 35,106 patients. Both this case and Omni reinforce how one vendor’s data incident can cascade into a series of notifications, litigation expenses, monitoring obligations, and increased examination across affiliated healthcare entities.

A 2025 study of 209 healthcare delivery respondents found 60% did not consistently monitor third-party access to sensitive data. Study authors noted, “HDOs recognize the increasing threat of third-party cyber breaches but are struggling to effectively address them.” Vendor cybersecurity should be managed like risk, not a checkbox during contract negotiations.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQs

What is fourth-party cyber risk?

Fourth-party risk comes from a vendor’s subcontractors, cloud providers, or other downstream partners. Subcontractors handling protected health information (PHI) are also business associates and must accept the same applicable HIPAA restrictions through downstream business associate agreements (BAAs).

 

Who must notify affected patients?

The covered entity is ultimately responsible for ensuring patients are notified, although it may delegate delivery of the notices to the vendor. The parties should decide who has the necessary patient information and is best positioned to communicate clearly.

 

How quickly must a vendor report a breach?

A business associate must notify the covered entity without unreasonable delay and no later than 60 days after discovering a breach. The 60-day limit is not a waiting period, and contracts can require much faster notification.