Skip to main content
Should You Settle Breach Litigation or Fight It Out?Breach Notification
4 min readFor Compliance Officers

Should You Settle Breach Litigation or Fight It Out?

The Decision at Hand

When a data breach leads to class action litigation, you must decide whether to settle quickly or contest the claims in court. Highlands Oncology Group opted for settlement after a 2025 ransomware attack compromised data for 113,575 individuals. Thirteen class action lawsuits were consolidated into a complaint alleging negligence, breach of implied contract, unjust enrichment, and invasion of privacy. Instead of pursuing dismissal, the organization entered mediation and reached a settlement.

This scenario is common in healthcare. You've likely faced the dilemma of which path to take when plaintiffs' attorneys contact you after a breach notification. The answer isn't straightforward, and compliance officers often have differing opinions.

The Case for Early Settlement

Advocates for settlement emphasize certainty. You know your maximum exposure, control the timeline, and avoid discovery that might reveal security gaps or internal emails questioning the necessity of certain security measures.

The Highlands Oncology Group settlement is typical: reimbursement for documented losses up to $4,250 per class member, or a pro rata payment estimated at $50 per person, plus three years of medical data monitoring with a $1 million identity theft insurance policy. The organization also covers attorneys' fees, administration costs, and service awards for class representatives. These predictable numbers allow for budgeting and board understanding.

Settlement also ends the news cycle. While breach notification is required under the Breach Notification Rule, ongoing litigation keeps your name in headlines. Settlement allows you to shift to remediation messaging: "We've resolved the matter and strengthened our security posture."

From a resource perspective, early settlement frees your legal team and senior leadership to focus on the Office for Civil Rights (OCR). Class action litigation runs parallel to regulatory investigation. OCR doesn't wait for your lawsuit to resolve before opening its own inquiry under the HIPAA Security Rule and Privacy Rule. Settlement lets you redirect resources toward the compliance response that determines whether you face civil monetary penalties.

The Case for Contesting Claims

Defense advocates argue that settling weak claims encourages more lawsuits. If plaintiffs' attorneys expect you'll settle after any breach notification, they'll file after every incident, regardless of actual harm. This creates a business model where the breach itself is the injury, not identity theft or financial loss.

The legal standard is crucial. Most breach lawsuits claim negligence per se, asserting HIPAA violations automatically establish negligence. However, HIPAA doesn't create a private right of action. Courts are divided on whether plaintiffs can use HIPAA standards for state-law negligence claims. Some jurisdictions have dismissed these cases early on.

Standing is another defense. Article III requires concrete injury, not speculative future harm. If your breach involved exfiltration but no evidence of misuse, plaintiffs struggle to show actual damages. The Supreme Court's decisions in Spokeo and TransUnion have made standing challenges more viable. Why settle if you can win dismissal on these grounds?

Fighting also preserves your negotiating position for future breaches. Ransomware groups persist, Business Associates get compromised, and employees click phishing links. If you settle every case quickly, you signal that breach notification automatically triggers a payout. Contesting weak cases forces plaintiffs' counsel to evaluate whether they have real damages before filing.

Discovery can work in your favor. While plaintiffs might find gaps, you might discover that none of the class members suffered actual identity theft, that the ransomware group never accessed the exfiltrated data, or that plaintiffs can't prove causation between your breach and their losses.

Where Practitioners Actually Land

Most healthcare organizations settle, but not immediately. They file a motion to dismiss, use the briefing schedule to assess the strength of plaintiffs' claims, then enter settlement discussions if the motion seems likely to fail. This approach tests legal theories, shows you won't settle reflexively, and preserves the settlement option if the court indicates the case will proceed.

The timeline is critical. In the Highlands Oncology Group case, the attack was identified on June 2, 2025, but unauthorized access began as early as January 21, 2025. Affected individuals were notified on August 1, 2025. The first lawsuit arrived four days later. This rapid sequence is typical. Plaintiffs' firms monitor breach notifications and file quickly.

Your detection and response window shapes litigation risk more than you might realize. The four-month gap between initial access and detection becomes Exhibit A in a negligence claim. Had monitoring tools flagged the intrusion in January, you might have contained the incident before exfiltration. That counterfactual drives settlement value.

Our Take

Settle if you have clear security failures that discovery will expose, if your state's law favors plaintiffs on negligence per se claims, or if the settlement terms are reasonable relative to your litigation budget. A two-year court fight costs more than most settlements, even before considering management distraction.

But don't settle reflexively in the first 60 days. File the motion to dismiss. Force plaintiffs to articulate concrete injuries. Test whether your jurisdiction recognizes their legal theories. Use the briefing process to understand your exposure.

The real lesson from Highlands Oncology Group isn't about settlement tactics. It's about the January-to-June detection gap. Four months of undetected access turns a containable incident into a 113,575-person breach with thirteen lawsuits. Your litigation posture matters less than your Security Rule implementation. Continuous monitoring, anomaly detection, and network segmentation reduce the window where attackers can move laterally and exfiltrate data.

Compliance officers spend too much time planning breach response and too little time preventing the four-month dwell time that makes response irrelevant. Settlement versus litigation is a question you ask after you've already lost. The better question is whether your security controls would detect the next intrusion in days, not months.

You Might Also Like