Skip to main content
Data Breach Lawsuits: What Compliance Officers Get WrongBreach Notification
6 min readFor Compliance Officers

Data Breach Lawsuits: What Compliance Officers Get Wrong

You've hardened your perimeter, run quarterly vulnerability scans, and have a vendor risk management program. So you're protected from class action litigation after a breach, right?

Not even close.

The myths around data breach litigation persist because they're comforting. They let you believe that compliance checkboxes equal legal immunity or that your cyber insurance will handle everything. But when Community Dental Care settled a consolidated class action in 2026 after exposing the PHI of more than 130,000 individuals, including Social Security numbers for approximately 7,100 people, the organization learned what many covered entities discover too late: the gap between regulatory compliance and litigation risk is wider than you think.

These myths don't just create false confidence. They shape how you allocate budget, prioritize remediation, and brief your executive team. Let's correct them.

Myth 1: "If we're HIPAA-compliant, we can't be sued for negligence."

Reality: HIPAA compliance is a floor, not a shield. Class action plaintiffs don't sue you for violating the HIPAA Security Rule; they sue you for common-law negligence, breach of implied contract, and negligence per se. Those claims ask whether you implemented "reasonable and appropriate" cybersecurity measures given the sensitivity of the data you hold and the threat landscape you operate in.

In the Community Dental Care litigation, the complaint alleged negligence because the organization allegedly failed to implement reasonable cybersecurity measures. The court allowed claims for negligence, negligence per se, and breach of implied contract to proceed, even before discovery began. Your HIPAA Security Rule risk analysis and addressable specifications don't answer the legal question a jury will ask: "Did this organization do what a reasonable healthcare provider would do to protect my Social Security number?"

That standard evolves. Multi-factor authentication wasn't "reasonable" in 2010; it is now. Endpoint detection wasn't standard in 2015; it's approaching baseline today. If your compliance program hasn't been updated since your last OCR audit, you're documenting yesterday's standard while today's threats are already inside your network.

Myth 2: "Our cyber insurance will cover the settlement and legal fees."

Reality: Your policy has exclusions you haven't stress-tested, sub-limits that won't stretch to cover a consolidated class action, and coverage triggers that require you to prove you maintained "minimum required safeguards", a term your insurer will interpret narrowly after a breach.

Class members in the Community Dental Care settlement could claim reimbursement up to $5,000 for documented losses or accept a flat $50 payment, plus two years of medical data monitoring. Multiply those figures across 130,000 individuals, add plaintiff attorney fees, add your own defense costs, and you're looking at a settlement fund that dwarfs most sub-limits for "privacy liability" in standard policies.

More importantly, many policies exclude coverage if the insurer determines you were negligent in maintaining basic controls. If your last penetration test is 18 months old, if you can't produce evidence of security awareness training, if your logging infrastructure didn't capture the initial intrusion, your carrier will argue you failed to satisfy policy conditions. You'll spend six figures litigating coverage before you spend a dollar defending the underlying claim.

Myth 3: "We'll settle quickly and move on, these cases don't go to discovery."

Reality: Even if you settle before full discovery, the negotiation leverage depends entirely on what plaintiffs can infer from your breach notification letter and public statements. If your letter reveals that the attacker had access for weeks, that Social Security numbers were exposed, or that you can't definitively say what was exfiltrated, plaintiffs' counsel will price that uncertainty into their demand.

Community Dental Care engaged in settlement discussions and mediation before discovery, but the case had already survived a motion to dismiss. The court had already ruled that negligence claims could proceed. That's not a quick exit, that's a defendant deciding that the cost and risk of litigation exceeded the cost of settlement, even without plaintiffs having subpoenaed a single email or server log.

If you're counting on a fast settlement, ask yourself: can you prove when the intrusion began? Can you show that you detected it through your own monitoring, not because the attacker posted your data on a forum? Can you demonstrate that you had controls in place that would have stopped a similar attack at another organization? If the answer is no, you're negotiating from a position of weakness.

Myth 4: "Only large health systems face class action risk."

Reality: Community Dental Care is a nonprofit Medicaid dental provider in Minnesota. It's not a multi-state hospital system. It's not a Fortune 500 payer. But it held Social Security numbers, dates of birth, and health insurance information for more than 130,000 individuals, and that was enough to trigger five separate class action filings that were later consolidated.

Class action economics don't require that you be large. They require that you have a large number of affected individuals and that you hold data types that create compensable harm. Social Security numbers drive settlement value because they enable identity theft and require affected individuals to freeze credit, monitor accounts, and spend time remediating fraudulent activity. If you're a covered entity that stores SSNs, even if you're a small community health center or a regional dental group, you're a viable class action target the moment you suffer a breach.

The plaintiff's bar monitors breach notification letters. They know which breaches involved SSNs, which involved delayed notification, and which involved organizations that lack the resources to mount a vigorous defense. Size doesn't protect you; the data elements you hold determine your exposure.

Myth 5: "If OCR doesn't fine us, we're in the clear."

Reality: OCR enforcement and civil litigation are parallel tracks with different standards, different timelines, and different remedies. OCR may close an investigation with a corrective action plan and no monetary penalty. That doesn't prevent a class action attorney from alleging negligence in state court six months later.

In fact, your corrective action plan can become plaintiff's Exhibit A. If OCR required you to implement MFA, segment your network, or overhaul your logging, and those measures weren't in place at the time of the breach, you've just handed plaintiffs evidence that your own regulator found your controls deficient.

OCR's investigation typically focuses on whether you violated specific HIPAA requirements. A negligence claim asks whether you breached a duty of care owed to patients. You can satisfy OCR and still lose in front of a jury if plaintiffs' expert testifies that no reasonable organization in your position would have left administrative credentials unmonitored or failed to patch a known vulnerability for 90 days.

What to do instead

Stop treating litigation risk as a legal department problem. Your security controls, your incident response plan, and your vendor management process are your first line of defense against both regulatory penalties and class action exposure.

Document your risk analysis with an eye toward the "reasonableness" standard a court will apply. Don't just check the box on addressable specifications, write down why you chose a particular implementation and what alternatives you considered. If you decide not to implement a control, document the compensating controls and the risk acceptance rationale. That narrative will matter in litigation.

Test your cyber insurance policy against realistic breach scenarios. Ask your broker: if we suffer a ransomware attack that exfiltrates SSNs and takes 72 hours to detect, what's covered? What are the sub-limits? What documentation do we need to preserve to satisfy coverage conditions? If your broker can't answer those questions, find one who can.

Assume every breach notification letter you send will be read by a class action attorney within 48 hours. Draft it with that audience in mind. Be precise about what data was involved, what you've done to contain the incident, and what you're offering to affected individuals. Vague language or overconfident assurances will be used against you.

Finally, recognize that "reasonable and appropriate" is a moving target. The measures that satisfied a jury in 2020 won't satisfy one in 2027. Your compliance program needs to evolve faster than the threat landscape, because the plaintiffs' bar is paying attention even if OCR isn't.

You Might Also Like