Health Law Daily Wrap Up, ELECTRONIC HEALTH RECORDS —S.D. Fla.: Patients obtain final approval of $5 million settlement with billing company after data breach, (Feb 3, 2026)
Law Firms Mentioned:Clark Hill, LLP | Kopelowitz Ostrow PA
Organizations Mentioned:Medusind, Inc.
By Justin Marcus Smith, J.D.
The court also awarded one-third of the class settlement, about $1.67 million, in attorney fees.
The federal district court in Miami, Florida granted final approval of a $5 million settlement between medical and dental patients and a billing company that experienced a breach of their health records, government identification numbers, and other personal information. The court found it should grant final approval of the settlement because the settlement class and California subclass had Article III standing and the settlement satisfied Fed. R. Civ. P. 23(a), 23(b)(3), and 23(e) requirements as well as the Bennett v. Behring Corp., 737 F.2d 982, 986 (11th Cir. 1984) factors. The court approved one-third of the $5 million settlement fund, or about $1.67 million, in attorney fees (Owings v. Medusind, Inc., No. 25-CV-20117-RAR (S.D. Fla. Jan. 26, 2025)).
Background. A medical and dental billing and software company that provides services to health providers across the country confirmed that cybercriminals accessed sensitive information about patients in its computer systems. Compromised patient data included personally identifiable information (PII) like health records and government identification numbers, including Social Security numbers. In January 2025, the billing company began sending notice letters to over 700,000 individuals that their PII may have been compromised in the data incident.
The court consolidated all related patient lawsuits into the instant class action and appointed interim class counsel. The billing company moved to dismiss, and the patients opposed, but the parties reached a settlement before the court considered the motion to dismiss. Even so, the court said the parties engaged in meaningful discovery. The billing company produced extensive material about the number of individuals and categories of private information involved in the data breach.
The parties ultimately agreed to a non-reversionary all-cash settlement fund of $5 million, which the billing company fully funded after preliminary approval. The settlement fund will pay all class member benefits; any court-awarded attorney fees and costs; and all settlement administration costs. The billing company will also provide class counsel with an attestation as to the implementation of cybersecurity measures at the sole cost of the billing company.
The court previously granted preliminary approval of the settlement and conditionally certified the settlement class and California settlement subclass. Having completed the notice program, class counsel filed the instant motion for final approval. Only five settlement class members opted out.
Numerosity. The court found the settlement satisfied the R. 23(a) numerosity requirement because joinder of all 70,000 class members was impractical.
Commonality. The court found the settlement satisfied the R. 23(a)(2) commonality requirement because the data incident affected the private information of all of the class members and pertained to the billing company’s procedures common to the settlement class. The evidence would not vary among class members.
Typicality. The court found the settlement satisfied R. 23(a)(3) because the class representative’s claims were typical of the class. The billing company sent all class members a notice letter indicating their private information may have been compromised due to the same purportedly inadequate security practices that allegedly harmed all settlement class members. The claims were all based on the same legal theories and underlying event.
Adequacy. The court found R. 23(a)(4) satisfied because the class representatives all had claims arising from the same data incident and injury as all settlement class members. Proof would involve the same issues of law and fact. The class representatives also diligently and adequately prosecuted the action through class counsel.
R. 23(b)(3). Having found all R. 23(a) factors satisfied, the court also found R. 23(b)(3) satisfied because questions of law or fact common to class members predominated over any questions affecting individual class members. As in other data breach cases, all claims arose out of a common course of data custodian conduct. Security practices did not vary from person to person.
The court also found the class action form superior to the impracticality of adjudicating individual actions. The amount in dispute for each class member was too small, the technical issues too complex, and expert testimony and document review too costly to proceed with individual adjudications.
Standing. The class representatives’ allegations that a criminal ransomware group accessed their private information and published it on the dark web supported that some misuse of class members’ data had already occurred. The actual misuse of and actual access to the settlement class members’ data were sufficient injuries-in-fact to establish an imminent threat of identity theft, emotional injury, diminution in private information value, and loss of privacy to all class members.
The court also found a causal connection between the data incident and the settlement class members’ injuries such that the injuries were “fairly traceable” to the billing company’s actions. Indirect harm was enough for standing. It was enough that the data incident could enable identity thieves to inflict harm.
R. 23(e). The court found all R. 23(e) and Bennett factors satisfied. Class counsel adequately represented the settlement class and California settlement subclass for purposes of final approval. The class representatives’ interests were coextensive and did not conflict with the interests of the settlement class members. The court said the settlement followed arms-length negotiation without discussion of attorney fees and costs until after the parties agreed on all material settlement terms.
The court found the settlement relief adequate in light of the costs and risks of going to trial. Data breach class actions are risky, and trial would be lengthy, whereas the settlement provided certain cash payments, credit monitoring, and an injunctive relief for all class members. Each class member has the option to be reimbursed for documented losses up to $5,000 or they may elect to receive a flat cash payment of $100. The California settlement class members might elect to receive a statutory award of about $100. Class members reacted favorably by submitting claims. One-third of the settlement fund for attorney fees would not affect other settlement terms, and the method of distributing settlement benefits would be equitable.
Class representatives. The court appointed the named plaintiffs class representatives because they adequately represented the settlement class members. The court also found class counsel prosecuted the matter skillfully and effectively.
Effective notices. The court found the notice provided to class members was the best possible and therefore satisfied R. 23(c)(2)(B) and due process requirements. Notice of the motion for attorney fees in the amount of up to one-third of the settlement amount satisfied R. 23(h)(1).
Attorney fees. The court awarded $1,666,666.66 for attorney fees, which was equal to one-third of the $5 million settlement fund, plus $32,384.30 for reasonable litigation costs.
Retained jurisdiction. The court retained and reserved jurisdiction over implementation of the settlement.
The case is No. 25-CV-20117-RAR.
Judge: Ruiz II, R.
Attorneys: Jeffrey Miles Ostrow (Kopelowitz Ostrow PA) for Ashley Owings, Barbara Masten, H.P. and Courtney Hopper. Myriah V. Jaworski (Clark Hill, LLP) for Medusind, Inc.
Companies: Medusind, Inc.
Cases: CaseDecisions EHRNews GCNNews HITNews FloridaNews