Grays Harbor Community Hospital Ransomware Lawsuit May be Settled for $185,000

by | Jul 6, 2020

Following mediation talks, there has been an agreement to a proposed settlement between Grays Harbor Community Hospital and Harbor Medical Group and the representative plaintiff in a proposed class action lawsuit connected to a June 2019 ransomware attack that lead to the encryption of patient data.

In order to avoid the uncertainty of a trial and the costs of further litigation, the settlement was negotiated by the plaintiff and Grays Harbor. The settlement was not decided in favor of either party by the Court.

The ransomware attack that resulted in the legal action was discovered during June 2019. The Washington healthcare supplier disabled its systems to contain the virus that had stopped servers from being accessed, but not in time to stop its computer systems from being encrypted. Grays Harbor had backed up its data in preparation for such an attack, but the backup files were also encrypted in the attack. The attack took its electronic health record system offline for almost two months.

A ransom demand of $1 million was issued by the hackers for the keys to decrypt the data. Gray’s Harbor had an insurance policy that supplied cover of up to $1 million, although it is unclear whether that insurance policy paid out and if the ransom was paid. Regardless, it was not possible to retrieve all data encrypted in the attack and some patients’ protected health information was not retrieved.

The lawsuit alleged that breaches took place in relation to the Washington State Consumer Privacy Act, the Washington State Uniform Healthcare Information Act, the Washington State Consumer Privacy Act, the state Constitution’s Right to Privacy, that Grays Harbor Community Hospital and Harbor Medical Group were negligent for failing to protect the privacy of patients, breach of express contract, breach of implied contract, and an intrusion upon seclusion/ invasion of privacy.

There was no admission of liability in the settlement with Grays Harbor Community Hospital and Harbor Medical Group. All claims stated in the lawsuit have been dismissed.

Grays Harbor Community Hospital and Harbor Medical Group proposed a settlement of $185,000 to meet the claims of the 88,000 patients affected by the ransomware attack. Impacted patients can file claims up to a maximum of $210 per person to cover out-of-pocket monetary losses incurred due tothe breach and up to three hours of documented lost time dealing with the fallout from the breach at a rate of $15 per hour.

Claims up to $2,500 will also be accepted to take into account provable other losses incurred that were more likely than not due to the ransomware attack. All available credit monitoring insurance and identity theft insurance must be drained before Grays Harbor is responsible for any larger payouts. If the claims are higher than $185,000 they will be paid pro rata to reduce costs.

Class members have a deadline of July 27, 2020 to exclude themselves from the settlement or submit an objection. A fairness hearing has been set for August 31, 2020. To receive a share of the settlement fund, a claim must be submitted before the end of December 23, 2020.

After the ransomware attack, measures were introduced to enhance security and more than $300,000 has been invested in information security. A further $60,000 will be spent on security enhancements over the next three years.

This is the second data breach settlement to be revealed this week.

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

COMPREHENSIVE HIPAA TRAINING

Ryan Coyne

Ryan Coyne is a results-driven leader in the healthcare compliance industry, specializing in regulatory compliance, compliance training, and assisting healthcare organizations and business associates in achieving and maintaining compliance. With a deep knowledge of healthcare regulations and a keen understanding of the challenges faced by the industry, Ryan has developed a reputation as a trusted advisor and advocate for ethical and compliant practices in healthcare. Ryan has successfully advised and guided numerous healthcare organizations, business associates, and healthcare professionals on achieving and maintaining compliance with regulatory training requirements. Ryan's professional focus is using his in-depth expertise and leading a world class team of subject matter experts at ComplianceJunction in regulatory compliance to help organisations navigate the complex landscape of ensuring staff adhere to healthcare regulations. You can connect with Ryan via LinkedIn and follow on Twitter

Raise the level of HIPAA Awareness in your organization with Learner-Friendly, Comprehensive and Affordable HIPAA Training.

Comprehensive HIPAA Training

Used in 1000+ Healthcare Organizations and 100+ Universities

    Full Course - Immediate Access

    Privacy Policy