Understanding the Impact of Breach Settlements
When MCNA settled its class action lawsuit for a 2023 data breach affecting 8.9 million individuals, compliance officers were eager to understand the implications for their programs. The settlement included up to $6.4 million in legal fees, $1.3 million in litigation costs, and two years of medical data monitoring services valued at $179.40 per person annually. Additionally, reimbursement claims were capped at $2,500 per class member.
These are pressing concerns for compliance teams assessing whether their security measures would withstand similar scrutiny. Here's what you need to know.
Q1: We're a third-party administrator like MCNA. Does that change our liability exposure?
Unfortunately, it doesn't. MCNA's role as a third-party administrator of dental benefits didn't shield it from allegations of negligence, breach of implied contract, and violations of state consumer protection statutes. If you handle PHI on behalf of covered entities, you're a Business Associate under HIPAA and must implement appropriate safeguards under the Security Rule.
The MCNA breach occurred between February 22 and March 7, 2023, but wasn't identified until March 6. This detection gap is significant. Your Business Associate Agreement requires you to report security incidents to the covered entity, but you can't report what you don't detect. Focus your security program on detection capabilities, not just perimeter defenses.
Q2: What counts as "appropriate cybersecurity measures" in court?
The MCNA lawsuit alleged failure to implement appropriate cybersecurity measures, leading to unauthorized access over a two-week period. While the settlement doesn't admit wrongdoing, it requires MCNA to implement additional security measures.
The Security Rule provides a framework: administrative safeguards (§164.308), physical safeguards (§164.310), and technical safeguards (§164.312). Pay attention to access controls and audit controls. An unauthorized party moving laterally through your network for 14 days suggests inadequate monitoring and logging. Your security risk analysis under §164.308(a)(1)(ii)(A) should identify these gaps before an attacker does.
Q3: How do we calculate the real cost of a breach?
Don't focus solely on OCR penalties. The MCNA settlement highlights broader costs: legal defense in the millions, monitoring services at $179.40 per person per year, potential reimbursement claims up to $2,500 per affected individual, and the operational cost of responding to 8.9 million breach notifications.
Calculate these costs for your organization. If you have 500,000 patient records and experience a similar breach, you're looking at monitoring costs around $179,400 annually for two years, plus legal fees and claims. This is separate from any OCR investigation or resolution agreement. Build your security budget accordingly.
Q4: We use multiple Business Associates. How do we make sure they're actually securing our data?
The MCNA case involved data exfiltration, meaning an attacker successfully removed sensitive information. Your Business Associate Agreements must require specific security measures, but contracts alone don't prevent breaches.
Implement a vendor risk management program that includes security assessments before onboarding, annual security attestations or audits, and breach notification procedures with defined timelines. If a Business Associate holds sensitive data, ensure they're monitoring for unauthorized access. Ask for SOC 2 Type II reports or HITRUST CSF certification. If they can't provide either, ask what compensating controls justify the risk.
Q5: What's this "medical data monitoring" that settlements always include?
It's different from credit monitoring. Medical data monitoring watches for misuse of health insurance information, fraudulent claims, or creation of fake medical records. The MCNA settlement values it at $179.40 per person annually, reflecting the specialized nature of healthcare identity theft.
When calculating breach response costs, include monitoring services appropriate to the data types exposed. If the breach included Medicare/Medicaid ID numbers and insurance group plan information, credit monitoring alone won't address the risk. You'll need healthcare-specific monitoring services.
Q6: MCNA's motion to dismiss was "granted in part and denied in part." What does that tell us?
It indicates that some claims survived initial legal scrutiny, forcing the defendant into settlement negotiations. The amended complaint in Crowe, et al., v. Managed Care of North America, Inc., et al. included claims for negligence per se, meaning alleged violation of a statute meant to protect a class of people from specific harm.
HIPAA creates a private right of action in some state courts through negligence per se theories. Your compliance program should create defensible evidence that you've implemented reasonable safeguards. Document your risk analysis, mitigation decisions, and monitoring procedures. If you're sued, you'll need to show you acted reasonably under the Security Rule's flexible framework.
Q7: How long do we have before a breach turns into a lawsuit?
The first class action against MCNA was filed on June 5, 2023, just 10 days after notification letters started going out on May 26. Eventually, 25 separate lawsuits were consolidated. You don't get a grace period to figure out your response strategy after notifying affected individuals.
Your breach response plan should include legal counsel from day one of the investigation. By the time you're sending notification letters, you should already have litigation hold procedures in place and a coordinated communication strategy. The 60-day Breach Notification Rule timeline under §164.408 isn't just about OCR compliance; it's your window to prepare for potential litigation.
Q8: What changes should we make right now?
Start with detection. The MCNA breach lasted at least 14 days before detection. Implement security information and event management (SIEM) tools that alert on anomalous data access patterns. The Security Rule's audit controls specification (§164.312(b)) requires you to record and examine activity in systems containing ePHI.
Next, test your incident response plan. The gap between the breach (ending March 7) and notification (starting May 26) was about 80 days. Some of that is investigation time, but you should be able to move faster. Run tabletop exercises that include your legal team, IT security team, and communications team. Practice the decision tree from detection through notification.
Next Steps
The MCNA settlement is pending final court approval (scheduled for November 16, 2026), but the framework is clear. Review NIST SP 800-66, which provides implementation guidance for the HIPAA Security Rule. Pay attention to sections on access controls and audit controls. If you're a Business Associate, review your agreements to confirm they include the required provisions under §164.504(e). If you haven't conducted a security risk analysis in the past year, start there. Everything else builds on that foundation.



