Morris Hospital Pays $1.36M to Settle Class Action Data Breach Litigation

by | Sep 7, 2025

Morris Hospital & Healthcare Centers decided to resolve a combined class action lawsuit that claimed negligence for not preventing a data breach in April 2023 that impacted 248,943 persons. The terms of the settlement agreement require Morris Hospital to create a $1,361,571.77 settlement fund for payment of attorneys’ fees, legal costs, and class members’ benefits.

In April 2023, Morris Hospital discovered unauthorized access to its system. Threat actors acquired access to the personal data and protected health information (PHI) of present and past patients, employees, as well as their dependents and beneficiaries. The cyberattack conducted by the Royal ransomware group involved the theft of patient data, which was posted on its data leak website. The data breach saw the filing of multiple class action lawsuits, which were combined into one lawsuit – In re: Morris Hospital Data Breach Litigation – filed in the Circuit Court of the Thirteenth Judicial Circuit, Grundy County, Illinois. Aside from negligence, the lawsuit stated claims of breach of fiduciary duty, negligence per se, unjust enrichment, breach of implied contract, and violation of the Illinois Consumer Fraud and Deceptive Business Practices Act.

Morris Hospital rejects all accusations of wrongdoing and liability, although the plaintiffs feel the claims are meritorious. All parties consented to settle the litigation, which was considered the best choice for all parties, taking into account the costs and risks of ongoing litigation. The court has given preliminary approval of the settlement. The schedule of the final fairness hearing is October 24, 2025. Class members’ benefits will be paid after deducting all costs and expenditures from the settlement fund, which includes approximately $453,857.26 in attorneys’ fees, attorneys’ expenses, settlement administration costs, and $2,000 service awards paid to the 13 plaintiffs.

All class members could file a claim for two years of identity theft protection and comprehensive credit monitoring services via CyEx Medical Shield Total. Additionally, class members may opt to file a claim to reimburse documented, out-of-pocket losses up to $5,000. If not filing a claim for losses, class members could alternatively claim a cash payment that is approximately $100, subject to the number of claims submitted. Objection to or exemption from the settlement can be submitted on or before September 29, 2025. The deadline to file a claim is October 28, 2025. For more details about the settlement, visit the website www.morrishospitalsettlement.com/

Cybersecurity awareness should be included in the HIPAA training of employees of covered entities like Morris Hospital

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

COMPREHENSIVE HIPAA TRAINING

Please enable JavaScript in your browser to complete this form.

Ryan Coyne

Ryan Coyne is a results-driven leader in the healthcare compliance industry, specializing in regulatory compliance, compliance training, and assisting healthcare organizations and business associates in achieving and maintaining compliance. With a deep knowledge of healthcare regulations and a keen understanding of the challenges faced by the industry, Ryan has developed a reputation as a trusted advisor and advocate for ethical and compliant practices in healthcare. Ryan has successfully advised and guided numerous healthcare organizations, business associates, and healthcare professionals on achieving and maintaining compliance with regulatory training requirements. Ryan's professional focus is using his in-depth expertise and leading a world class team of subject matter experts at ComplianceJunction in regulatory compliance to help organisations navigate the complex landscape of ensuring staff adhere to healthcare regulations. You can connect with Ryan via LinkedIn and follow on Twitter

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

Comprehensive HIPAA Training

Used in 1000+ Healthcare Organizations and 100+ Universities

    Full Course - Immediate Access

    Privacy Policy