Anne Arundel Dermatology P.A.: Anne Arundel Dermatology $2.4M Data Breach Settlement

Anne Arundel Dermatology P.A.: Anne Arundel Dermatology $2.4M Data Breach Settlement

Anne Arundel Dermatology Settles $2.4M Class Action Over 2025 Data Breach

Anne Arundel Dermatology P.A. has agreed to a $2.4 million settlement to resolve a class action lawsuit stemming from a data breach that exposed the personal and health information of an estimated 1.9 million current and former patients. The breach occurred between February 14 and May 13, 2025, when unauthorized third parties accessed the company’s systems, potentially compromising sensitive data.

Who Is Eligible?
Individuals in the U.S. who provided personally identifiable information (PII) or protected health information (PHI) to Anne Arundel Dermatology on or before December 9, 2025, may qualify for compensation. This includes those whose data was collected, received, or stored by the company by that date.

Compensation Options
Eligible class members can choose from three benefit options:

  • Cash Payment A (Up to $5,000): Reimbursement for documented out-of-pocket losses, including fraud-related expenses, credit monitoring fees, legal costs, and identity theft recovery.
  • Cash Payment B (Pro Rata Share): A $100 estimated payment for those without documented losses, with the final amount determined by the number of claims filed.
  • Medical Data Monitoring: Three years of CyEx Medical Shield Complete, covering credit monitoring, dark web scanning, medical record monitoring, and identity theft insurance up to $1 million.

Claim Process & Deadlines
Claims must be submitted online or via mail by July 8, 2026, with supporting documentation required for out-of-pocket loss claims. Payments and monitoring services will be distributed approximately 90 days after final court approval, expected following a fairness hearing on July 16, 2026.

Settlement Fund Allocation
The $2.4 million fund will cover:

  • Up to $800,000 for settlement administration costs.
  • Attorney fees and expenses (to be determined by the court).
  • $1,500 service awards for each class representative.
  • Remaining funds for approved claimants and medical monitoring services.

Background & Allegations
Plaintiffs alleged Anne Arundel Dermatology failed to implement adequate security measures, leading to the breach. The company denied wrongdoing but settled to avoid prolonged litigation. The incident highlights ongoing risks in healthcare data security and the financial consequences of inadequate protections.

Source: https://www.claimdepot.com/settlements/anne-arundel-privacy-settlement

Anne Arundel Dermatology cybersecurity rating report: https://www.rankiteo.com/company/annearundeldermatology

"id": "ANN1775867299",
"linkid": "annearundeldermatology",
"type": "Breach",
"date": "4/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '1,900,000 current and former '
                                              'patients',
                        'industry': 'Healthcare',
                        'location': 'United States',
                        'name': 'Anne Arundel Dermatology P.A.',
                        'type': 'Healthcare Provider'}],
 'customer_advisories': 'Settlement notice with compensation options for '
                        'affected individuals.',
 'data_breach': {'number_of_records_exposed': '1,900,000',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personally Identifiable '
                                              'Information (PII)',
                                              'Protected Health Information '
                                              '(PHI)']},
 'date_detected': '2025-05-13',
 'description': 'Anne Arundel Dermatology P.A. has agreed to a $2.4 million '
                'settlement to resolve a class action lawsuit stemming from a '
                'data breach that exposed the personal and health information '
                'of an estimated 1.9 million current and former patients. The '
                'breach occurred between February 14 and May 13, 2025, when '
                'unauthorized third parties accessed the company’s systems, '
                'potentially compromising sensitive data.',
 'impact': {'brand_reputation_impact': 'Negative impact due to allegations of '
                                       'inadequate security',
            'data_compromised': 'Personal and health information of 1.9 '
                                'million individuals',
            'financial_loss': '$2,400,000 (settlement amount)',
            'identity_theft_risk': 'High (PII and PHI exposed)',
            'legal_liabilities': 'Class action lawsuit settlement'},
 'investigation_status': 'Settled',
 'lessons_learned': 'Healthcare organizations must implement adequate security '
                    'measures to protect sensitive patient data and avoid '
                    'financial and reputational consequences.',
 'post_incident_analysis': {'root_causes': 'Failure to implement adequate '
                                           'security measures'},
 'recommendations': 'Enhance cybersecurity protocols, conduct regular security '
                    'audits, and ensure compliance with healthcare data '
                    'protection regulations.',
 'references': [{'source': 'Class Action Settlement Notice'}],
 'regulatory_compliance': {'legal_actions': 'Class action lawsuit'},
 'response': {'communication_strategy': 'Settlement notice and claim process'},
 'threat_actor': 'Unauthorized third parties',
 'title': 'Anne Arundel Dermatology Data Breach Settlement',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Inadequate security measures'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.