Skip to main content
Five Mistakes That Turned a Data Breach into a $1.3M SettlementBreach Notification
7 min readFor Compliance Officers

Five Mistakes That Turned a Data Breach into a $1.3M Settlement

When DAP Health faced a class action lawsuit after a cyberattack exposed the Protected Health Information (PHI) of 129,048 individuals, the resulting $1.3 million settlement didn't just reflect the breach itself. It highlighted a series of preventable compliance failures that increased both legal exposure and financial damage.

You've seen the pattern before: an unauthorized actor gains access, exfiltrates sensitive data, and your organization scrambles to respond. But the real cost isn't just the incident response. It's the litigation that follows when plaintiffs' attorneys argue you failed to implement reasonable safeguards. The DAP Health case, which alleged violations of the California Confidentiality of Medical Information Act, California Consumer Privacy Act, and California's Unfair Competition Law, shows how technical failures can lead to legal liability.

Let's examine the specific mistakes that turn a security incident into a multi-million-dollar settlement and how your compliance program can avoid them.

Why These Mistakes Keep Happening

Most Covered Entities treat cybersecurity as an IT problem rather than a compliance imperative. Your security team focuses on threat detection while your compliance officer tracks policy documentation, and nobody connects the two until after a breach. Meanwhile, state privacy laws create a patchwork of obligations that exceed HIPAA's federal baseline, and your risk analysis hasn't accounted for the litigation risk these statutes introduce.

The gap widens because compliance programs treat the HIPAA Security Rule's implementation specifications as technical checklists rather than risk frameworks. You document that you've addressed each specification, but you don't test whether those controls actually prevent unauthorized access to email servers, databases, or backup systems where ePHI concentrates.

Mistake 1: Treating Email Security as an Addressable Specification

Why it happens: Your organization reads § 164.312(e)(1) transmission security and decides that basic password protection and user training satisfy the addressable encryption requirement. Email feels like internal communication, not a transmission risk.

The consequence: In the DAP Health incident, an unauthorized third party gained access to an email server and exfiltrated emails and files containing names, Social Security numbers, financial account numbers, Medicare/Medicaid numbers, and medical information. Email servers become single points of failure because they aggregate years of PHI in searchable, exportable formats.

The fix: Implement encryption for email at rest and in transit, not as an addressable consideration but as a required control for any system storing ePHI. Deploy multi-factor authentication for all email access, segment email servers from your general network, and establish automated alerts for bulk download attempts or unusual access patterns. Document these controls in your risk analysis as mitigations for the specific threat of email server compromise.

Mistake 2: Ignoring State Privacy Laws in Your Risk Analysis

Why it happens: Your compliance program centers on HIPAA because it's federal, comprehensive, and enforced by the Office for Civil Rights (OCR). State statutes feel like secondary concerns, especially if your legal team hasn't flagged them as immediate risks.

The consequence: The DAP Health lawsuit asserted claims under three California statutes in addition to common-law negligence. Each statute created an independent basis for liability, and the California Confidentiality of Medical Information Act includes a statutory damages provision that plaintiffs leveraged. Class members who were California residents on the breach date could claim $75 in statutory cash payments on top of documented losses and pro rata distributions. State laws don't just add paperwork; they multiply your legal exposure and create per-person penalties that scale with breach size.

The fix: Conduct a jurisdiction-specific legal review for every state where you treat patients or maintain facilities. Map state privacy law requirements against your existing HIPAA controls and identify gaps. California's CMIA, for example, requires specific authorization for certain disclosures that HIPAA permits under treatment, payment, and operations. Document these enhanced requirements in your policies and train your workforce on state-specific restrictions. Your risk analysis should explicitly address state law compliance as a distinct risk domain.

Mistake 3: Failing to Audit Third-Party Access to Email Systems

Why it happens: Your Business Associate Agreements (BAAs) require subcontractors to implement appropriate safeguards, and you assume that contractual obligation translates to actual security. You don't audit how vendors access your email environment or what credentials they use.

The consequence: Unauthorized access often exploits vendor credentials, service accounts, or legacy integrations that your security team doesn't monitor. When an attacker moves laterally from a compromised vendor system into your email server, you discover that you can't determine what data was accessed, when the intrusion began, or whether the vendor's security practices met your BAA requirements. This uncertainty becomes evidence of negligence in litigation.

The fix: Implement annual technical audits of all Business Associates and subcontractors with electronic access to ePHI. Review authentication methods, access logs, and data handling procedures. Require vendors to provide SOC 2 Type II reports or HITRUST CSF Validated Assessments that verify their security controls. Terminate direct email server access for vendors; instead, use secure file transfer protocols or encrypted portals with activity logging. Document these audits and vendor assessments in your compliance files.

Mistake 4: Delaying Breach Investigation and Notification

Why it happens: Your team identifies suspicious activity but spends weeks determining whether ePHI was actually accessed or exfiltrated. You want certainty before notifying patients, and you fear that premature disclosure will trigger unnecessary panic.

The consequence: DAP Health identified suspicious activity on or around July 22, 2024, but didn't begin sending notification letters until December 2024. That five-month gap became a focal point in the lawsuit. Delayed notification prevents affected individuals from taking protective action and signals to plaintiffs' attorneys that your incident response was inadequate. The Breach Notification Rule requires notification without unreasonable delay and no later than 60 days after discovery. Delays beyond that threshold strengthen claims of negligence.

The fix: Establish a 72-hour preliminary assessment protocol. Within three days of detecting suspicious activity, your incident response team should determine whether the incident constitutes a breach under § 164.402 and begin the risk assessment required by § 164.402(2). If you cannot rule out ePHI access or acquisition within 10 days, assume a breach occurred and begin notification planning. Document every step of your investigation with timestamps and decision rationales. Engage forensic investigators immediately, not after you've exhausted internal resources.

Mistake 5: Underestimating the Cost of "Reasonable" Cybersecurity

Why it happens: Your budget process treats cybersecurity as discretionary spending. When your CISO requests funding for email encryption, endpoint detection, or security awareness training, leadership asks whether these investments are "required" by HIPAA. Because many Security Rule specifications are addressable, the answer is often "it depends," and the budget request gets deferred.

The consequence: The DAP Health settlement includes up to $5,000 per class member for documented losses, a pro rata cash payment estimated at $25 per person, $75 statutory payments for California residents, and two years of credit monitoring for all 129,048 affected individuals. Add plaintiffs' attorneys' fees, settlement administration costs, and service awards for class representatives, and the $1.3 million fund reflects the true cost of "reasonable" security. That figure doesn't include DAP Health's own legal defense costs, incident response expenses, or reputational damage.

The fix: Reframe cybersecurity investments as litigation risk mitigation, not technical requirements. Calculate the expected cost of a breach settlement using your patient population as the class size. In a class action, you're looking at $50, $150 per affected individual in settlement payments, plus legal fees that often equal the settlement fund. For a Covered Entity with 100,000 patient records, that's a $10, $15 million litigation risk. Compare that figure to the annual cost of encryption ($50,000, $200,000), advanced threat detection ($100,000, $300,000), and security training ($20,000, $50,000). Present cybersecurity budgets as insurance premiums against quantifiable legal exposure.

Prevention Checklist

Use this checklist to audit your current controls and identify gaps before they become settlement line items:

Email and Communication Security

  • Email encryption implemented for all ePHI transmissions
  • Multi-factor authentication required for email access
  • Email servers segmented from general network
  • Automated alerts configured for bulk downloads or unusual access patterns
  • Regular audits of email retention policies and archive security

State Privacy Law Compliance

  • Legal review completed for all states where you operate
  • State-specific privacy requirements mapped against HIPAA controls
  • Policies updated to reflect most restrictive state requirements
  • Workforce trained on state-specific authorization and disclosure rules

Vendor Risk Management

  • Annual technical audits scheduled for all Business Associates
  • SOC 2 Type II or HITRUST CSF Validated Assessments obtained from vendors
  • Direct email server access eliminated for external parties
  • Vendor access logs reviewed quarterly

Incident Response Readiness

  • 72-hour preliminary assessment protocol documented
  • Forensic investigation firm identified and retainer established
  • Breach notification templates prepared for HIPAA and state law requirements
  • Incident response tabletop exercises conducted semi-annually

Budget and Risk Quantification

  • Breach settlement cost model developed using patient population size
  • Cybersecurity investments presented as litigation risk mitigation
  • Annual comparison of security spending vs. potential settlement exposure
  • Board-level reporting on compliance risk and security posture

The DAP Health settlement shows that "reasonable" cybersecurity isn't a technical standard; it's a legal standard that plaintiffs' attorneys will define in hindsight. Your job is to implement controls that make that hindsight defense unnecessary.

You Might Also Like