Many healthcare organizations think settling data breach lawsuits is a cost-effective way to avoid expensive litigation. Pay the class members, fund some credit monitoring, and move on. McKenzie Health System and Aspire Health Alliance both chose this route after cyberattacks exposed patient data. The logic seems sound: avoid years of legal battles and get back to patient care.
Here's the problem: you're treating the lawsuit as the risk event instead of the breach itself.
Settling Isn't Solving
Settling a lawsuit doesn't mean you've fixed the control failures that caused the breach. It just means you've transferred money to affected individuals and their attorneys. The negligence claims in these lawsuits allege that reasonable cybersecurity measures weren't in place. Settling without admitting liability means you never have to prove your controls were adequate, but it also means you never fix what broke.
McKenzie Health's breach involved unauthorized network access over two days in April 2025, affecting 58,839 individuals. Aspire Health Alliance detected unauthorized access in September 2023 that exposed files containing patient information for 17,490 individuals. Both settled class actions alleging negligence, denying wrongdoing.
Neither settlement requires specific remediation steps or independent security assessments. The money flows to class members (up to $4,000 per person at McKenzie, up to $2,500 at Aspire), but there's no public commitment to implement multi-factor authentication on privileged accounts, segment networks containing protected health information, or deploy endpoint detection and response tools. The settlement doesn't ensure compliance with the HIPAA Security Rule under 45 CFR § 164.312(a)(1) or address authentication requirements under § 164.312(d).
This creates a perverse incentive. If settling is cheaper than fixing your security program and litigating, you'll settle. Then you'll face the next breach with the same gaps.
The Evidence
Look at what these settlements actually require. McKenzie Health agreed to pay for two years of credit monitoring and identity theft protection. Aspire Health Alliance established a $400,000 settlement fund covering benefits, attorneys' fees, administration, and a service award for the class representative. Both offered cash payments for documented losses or flat payments.
None of this addresses the HIPAA Security Rule's administrative safeguards under 45 CFR § 164.308. You're not required to conduct a risk analysis under § 164.308(a)(1)(ii)(A). You don't have to implement a security incident response plan under § 164.308(a)(6)(ii). There's no mandate to review and modify security measures under § 164.308(a)(8).
Compare this to what happens when the HHS Office for Civil Rights investigates a breach and finds violations. OCR's resolution agreements typically require corrective action plans, third-party assessments, ongoing monitoring, and staff training. The settlement approach bypasses all of that external pressure to remediate.
The HITECH Act's breach notification requirements under 42 U.S.C. § 17932 force you to disclose the breach publicly, but they don't force you to fix the underlying problems. You notify affected individuals within 60 days, report to OCR, and move on. The class action settlement is just the financial cleanup after notification.
What to Do Instead
If you're facing a breach and potential class action, don't just settle and declare victory. Use the incident to get budget and executive support for the controls you've been requesting for years.
Start with a third-party forensic investigation that goes beyond attribution. Document every control failure: Was network segmentation inadequate? Did you lack visibility into lateral movement? Were privileged credentials compromised because you weren't enforcing the Principle of Least Privilege? Get this in writing from the forensic firm.
Then map those failures to specific HIPAA Security Rule requirements and industry standards. If an attacker moved laterally across your network for two days without detection, that's a failure of the security monitoring requirement under 45 CFR § 164.308(a)(1)(ii)(D). If credentials were compromised, you've got issues with unique user identification under § 164.312(a)(2)(i) or password management under § 164.308(a)(5)(ii)(D).
Build your remediation plan around these mapped failures. Don't just implement "better security." Deploy specific controls: enforce multi-factor authentication for all remote access and privileged accounts. Implement network segmentation that isolates systems containing electronic protected health information. Deploy endpoint detection and response tools with 24/7 monitoring. Establish a formal Computer Security Incident Response Team with defined escalation procedures for containment, eradication, and recovery.
Document this remediation plan and share it with your board. Make it clear that settling the lawsuit addresses the legal liability but not the operational risk. You're still vulnerable to the next attack if you don't fix the controls.
Then, whether or not you settle the class action, commit to completing the remediation plan and having it validated by a third party. Get a HITRUST CSF assessment or SOC 2 Type II audit that specifically tests the controls you implemented post-breach. Make that validation part of your settlement narrative when you communicate with patients and regulators.
When Settling Makes Sense
Settling does make sense in specific circumstances. If you've already implemented comprehensive remediation, documented it thoroughly, and can demonstrate that the breach resulted from a sophisticated attack that bypassed reasonable controls, then settling avoids the risk of a jury misunderstanding technical security concepts.
If your organization is small and litigation costs would genuinely threaten your ability to continue operations, settlement preserves your capacity to serve patients. A critical access hospital in a rural county can't afford years of discovery and trial preparation that diverts staff and resources from patient care.
And if the plaintiffs' negligence claims are weak because you can demonstrate compliance with the HIPAA Security Rule's required and addressable implementation specifications, settlement lets you avoid the cost of proving that in court while still providing affected individuals with monitoring services and compensation.
But don't confuse settling the lawsuit with addressing the risk. The settlement is a financial transaction. Risk reduction requires fixing controls, validating the fixes, and maintaining those controls over time. You can do both, but only if you recognize they're separate activities with separate goals.
The plaintiffs' attorneys get paid either way. Your patients deserve better than credit monitoring. They deserve an organization that treats the breach as a control failure, not just a litigation event.



