Akumin Operating Corp. experienced a data breach on October 11, 2023, exposing sensitive personal and medical information of U.S. residents. The compromised data included names, Social Security numbers, driver’s license/passport numbers, medical records (diagnoses, treatments, imaging), financial accounts, health insurance details, and biometric information. The breach led to a class-action lawsuit, alleging Akumin failed to adequately protect the data. Affected individuals were offered settlements of up to $2,500 in reimbursement for fraud-related losses (e.g., identity theft, credit monitoring) and one year of free medical data monitoring. The incident highlighted vulnerabilities in Akumin’s cybersecurity, resulting in potential financial fraud, identity theft, and unauthorized access to highly sensitive health and personal data. The company settled for $2.85 million, though it denied wrongdoing.
Source: https://www.claimdepot.com/settlements/akumin-data-incident-settlement
TPRM report: https://www.rankiteo.com/company/akumin
"id": "aku1102611100725",
"linkid": "akumin",
"type": "Breach",
"date": "10/2023",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'U.S. residents whose private '
'information was potentially '
'compromised (exact number not '
'specified)',
'industry': 'Healthcare (Medical Imaging and '
'Diagnostic Services)',
'location': 'United States',
'name': 'Akumin Operating Corp.',
'type': 'Corporation'}],
'customer_advisories': 'Eligible individuals can file claims for cash '
'reimbursement (up to $2,500) or free medical data '
'monitoring (1 year) by November 30, 2025',
'data_breach': {'data_exfiltration': 'Likely (unauthorized access or '
'acquisition alleged)',
'personally_identifiable_information': ['Names',
'Home addresses',
'Email addresses',
'Dates of birth',
'Social Security '
'numbers',
'Driver’s license or '
'passport numbers',
'Medical record '
'numbers',
'Medicare/Medicaid '
'IDs',
'Financial accounts '
'or payment card '
'information',
'Electronic '
'signatures'],
'sensitivity_of_data': 'High (includes SSNs, medical records, '
'financial data, and biometric '
'information)',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Protected Health Information '
'(PHI)',
'Financial Information',
'Biometric Data',
'Legal/Identification '
'Documents']},
'date_detected': '2023-10-11',
'description': 'Akumin Operating Corp. experienced a data incident on October '
'11, 2023, resulting in unauthorized access to or acquisition '
'of private information of U.S. residents. The breach exposed '
'sensitive data including names, Social Security numbers, '
'medical records, financial information, and more. A class '
'action lawsuit was filed, alleging Akumin failed to '
'adequately protect the data. The company agreed to a $2.85 '
'million settlement, offering affected individuals up to '
'$2,500 in cash reimbursement and/or one year of free medical '
'data monitoring.',
'impact': {'brand_reputation_impact': 'Class action lawsuit and settlement; '
'potential loss of trust among '
'customers',
'data_compromised': ['Names',
'Home addresses',
'Email addresses',
'Other contact information',
'Dates of birth',
'Social Security numbers',
'Driver’s license or passport numbers',
'Medical record numbers',
'Medicare or Medicaid IDs',
'Patient/unique identifiers',
'Financial accounts or payment card '
'information',
'Diagnosis, treatment, or patient imaging '
'data',
'Occupational health or biometric information',
'Medical history, billing, or claims '
'information',
'Health insurance subscriber/group policy '
'numbers or benefits information',
'Electronic signatures'],
'financial_loss': {'administration_costs': 'Up to $250,000',
'attorneys_fees': 'Up to $2,850,000',
'individual_claim_limit': 'Up to $2,500 per '
'eligible class '
'member',
'payments_to_class_members': 'Up to $1,500,000 '
'(pro-rated if '
'exceeded)',
'service_awards': 'Up to $2,500 each (class '
'representatives)',
'settlement_fund': '$2,850,000'},
'identity_theft_risk': 'High (exposed PII including SSNs, '
'financial data, and medical records)',
'legal_liabilities': '$2,850,000 settlement fund',
'payment_information_risk': 'High (financial accounts or payment '
'card information exposed)'},
'investigation_status': 'Resolved via settlement (final approval hearing on '
'December 15, 2025)',
'post_incident_analysis': {'corrective_actions': 'Settlement agreement with '
'financial compensation and '
'monitoring services for '
'affected individuals',
'root_causes': 'Alleged failure to adequately '
'protect private information '
'(specific technical root causes '
'not disclosed)'},
'references': [{'source': 'Class Action Settlement Notice (Akumin Data '
'Incident)'}],
'regulatory_compliance': {'legal_actions': 'Class action lawsuit settled for '
'$2.85 million'},
'response': {'communication_strategy': 'Notice sent to affected individuals; '
'class action settlement website and '
'claim process established',
'recovery_measures': 'Settlement agreement offering cash '
'reimbursement (up to $2,500) and free '
'medical data monitoring (1 year)'},
'stakeholder_advisories': 'Notice sent to affected individuals; settlement '
'administrator established for claims',
'title': 'Akumin Operating Corp. Data Breach (October 2023)',
'type': 'Data Breach'}