Subscribe To Our Newsletter
OnePoint Patient Care has agreed to pay $2,115,000 to resolve a consolidated class action lawsuit, Russo v. OP Pharmacy, LLC a/k/a OnePoint Patient Care, LLC (Case No. 3:24-cv-00649), following an August 2024 data breach.
If you received a data breach notice from OnePoint Patient Care informing you that your personal and medical details were exposed in an August 2024 cyberattack, you may be eligible to receive cash reimbursement or a direct payment from a new $2.115 million class action settlement. The lawsuit alleged that the hospice pharmacy services provider failed to implement industry-standard cybersecurity measures, leaving highly sensitive patient and medical data vulnerable to unauthorized hackers. Affected individuals have until October 8, 2026, to file a claim.
When patients and families rely on hospice care, they expect their most personal health information to remain completely secure. Experiencing a data breach during or after end-of-life medical care creates unnecessary stress, putting vulnerable families at risk of identity theft and financial fraud. At ClassActionU.org, we believe everyday people deserve peace of mind and strict data security, and we empower consumers to hold healthcare companies accountable when they fail to protect sensitive patient records.
The settlement resolves a consolidated federal class action lawsuit titled Russo v. OP Pharmacy, LLC a/k/a OnePoint Patient Care, LLC (Case No. 3:24-cv-00649), filed in the U.S. District Court for the Western District of Kentucky.
OnePoint Patient Care operates as a specialized hospice pharmacy and pharmacy benefit manager, providing dispensing and medication management services across the nation. According to court records, unauthorized cybercriminals breached the company’s internal computer network between August 6 and August 8, 2024, exfiltrating confidential files stored on its servers.
Plaintiffs in the lawsuit claimed that OnePoint Patient Care failed to deploy adequate cyber defenses to protect the confidential data entrusted to its care. Court filings reveal that the compromised database contained sensitive personal and protected health information belonging to approximately 528,452 individuals nationwide, including:
Full legal names and addresses
Health facility locations
Medical record numbers
Medical diagnoses and treatment details
Prescription information
Social Security numbers (for a subset of impacted patients)
The lawsuit alleged that OnePoint Patient Care was negligent in protecting this private data, exposing hospice patients and their families to an ongoing threat of identity theft and financial exploitation. OnePoint Patient Care denies all legal claims and maintains that its computer security protocols were reasonable, but agreed to the $2.115 million settlement fund to bring an end to the litigation and avoid the expenses and uncertainties of a trial.
You may be eligible to receive money from the settlement if you currently reside in the United States and received a written notice from OnePoint Patient Care or the settlement administrator stating that your personal or medical details were potentially compromised in the August 2024 data breach.
Court documents indicate that the settlement class encompasses an estimated 528,452 living U.S. residents.
If you received a class notice by mail or email, your name is already included on the official settlement list. Your notice contains a unique Login ID and PIN, which will allow you to complete your claim form quickly online. If you are unsure whether you are included, you can reach out to the official settlement administrator to check your status.
Under the court-approved preliminary settlement terms, eligible class members who file a valid and timely claim form can select between two payment choices:
Documented Out-of-Pocket Loss Reimbursement (Up to $3,500): You can file a claim to recover up to $3,500 for actual, documented financial losses resulting directly from the data breach. Covered expenses include fees for credit reports, credit monitoring services, identity theft insurance, bank charges, long-distance phone calls, cell phone data usage, postage, and local transportation costs. To receive this payout, you must submit supporting proof such as receipts, bank statements, or invoices.
Alternative Pro Rata Cash Payment (~$100, No Proof Required): In place of reimbursement for documented losses, class members can select a flat cash payment estimated at $100. No receipts or documentation are required to choose this option. The final cash payout amount may increase or decrease depending on the overall number of valid claims filed.
All class payments will be distributed after the court grants final approval to the deal and any potential legal appeals are fully resolved.
This class action highlights fundamental protections regarding patient privacy and health data security. Healthcare providers and pharmacy benefit managers are subject to strict regulations, including the Health Insurance Portability and Accountability Act (HIPAA) and state consumer protection laws, which require companies to safeguard protected health information.
When medical vendors fail to implement necessary technical and administrative safeguards, cybercriminals can easily target vulnerable systems. Medical data breaches are particularly harmful because stolen health records, Social Security numbers, and prescription histories cannot simply be changed like a compromised credit card number.
Class action lawsuits provide a legal pathway for affected patients and families to unite, demanding financial compensation for their lost time and diminished privacy while compelling healthcare organizations to upgrade their digital security infrastructure.
New cases and investigations, settlement deadlines, and news straight to your inbox.