An unauthorized third party accessed the **personal identifying information (PII)** and **protected health information (PHI)** of patients at **Dignity Health’s St. Rose Dominican Hospital (Rosa de Lima Campus)**. The compromised data included **names, contact details, Social Security numbers, dates of birth, clinical/diagnosis records, medical account numbers, and service locations**. The breach, disclosed around **March 2024**, led to a **$675,000 class-action settlement** to cover identity theft risks, fraudulent transactions, falsified tax returns, and unauthorized medical claims. Patients were offered **credit monitoring, medical identity-theft protection, and reimbursements up to $2,500** for extraordinary losses. The incident exposed victims to **financial fraud, medical identity theft, and reputational harm**, with potential long-term consequences for affected individuals. The breach was attributed to a **cybersecurity failure allowing external access to sensitive records**.
Source: https://www.claimdepot.com/settlements/dignity-health-settlement
TPRM report: https://www.rankiteo.com/company/dignity-health
"id": "dig5762157091125",
"linkid": "dignity-health",
"type": "Breach",
"date": "3/2024",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Patients of Dignity Health - '
'St. Rose Dominican Hospital, '
'Rosa de Lima Campus',
'industry': 'Healthcare IT',
'name': 'R1 RCM Inc.',
'type': 'Revenue Cycle Management Provider'},
{'customers_affected': 'Current and former patients '
'(exact number unspecified)',
'industry': 'Healthcare',
'location': 'Henderson, Nevada (implied by context)',
'name': 'Dignity Health dba St. Rose Dominican '
'Hospital, Rosa de Lima Campus',
'type': 'Hospital'}],
'customer_advisories': {'claim_options': ['Out-of-pocket expenses (up to '
'$500)',
'Extraordinary losses (up to '
'$2,500)',
'Pro rata cash payment',
'2 years of three-bureau credit '
'monitoring + CyEx Medical Shield '
'Total'],
'deadlines': {'claim_submission': '2025-11-11',
'final_approval_hearing': '2025-11-14',
'opt_out': '2025-10-13'},
'eligibility_criteria': ['Patients of Dignity Health '
'St. Rose Dominican '
'Hospital, Rosa de Lima '
'Campus',
'Received written '
'notification in/around '
'March 2024',
'PII/PHI potentially '
'accessed'],
'payout_methods': ['PayPal',
'Venmo',
'Zelle',
'Paper check (mail-only)'],
'required_documentation': ['Notice ID and PIN from '
'settlement notice',
'Receipts/bills for '
'out-of-pocket expenses',
'Police reports/statements '
'for extraordinary '
'losses']},
'data_breach': {'data_exfiltration': 'Likely (data accessed by unauthorized '
'third party)',
'personally_identifiable_information': ['Name',
'Contact information',
'Date of birth',
'Social Security '
'number',
'Patient account '
'number',
'Medical record '
'number'],
'sensitivity_of_data': 'High (includes SSNs, medical records, '
'and clinical data)',
'type_of_data_compromised': ['PII', 'PHI']},
'date_publicly_disclosed': '2024-03',
'description': 'An unauthorized third party accessed the personal identifying '
'information (PII) and/or protected health information (PHI) '
"of certain patients at Dignity Health's St. Rose Dominican "
'Hospital, Rosa de Lima Campus. The breach exposed sensitive '
'data including names, contact information, Social Security '
'numbers, dates of birth, clinical/diagnosis information, and '
'medical record numbers. A class action lawsuit was settled '
'for $675,000, with affected patients eligible for '
'reimbursements up to $2,500 and credit/medical monitoring '
'services.',
'impact': {'brand_reputation_impact': 'Likely negative (settlement indicates '
'reputational harm)',
'customer_complaints': 'Class action lawsuit filed',
'data_compromised': ['Name',
'Contact information',
'Date of birth',
'Social Security number',
'Location of services',
'Clinical/diagnosis information',
'Patient account number',
'Medical record number'],
'financial_loss': {'administrative_costs': {'attorneys_fees': 'Amount '
'pending '
'court '
'approval',
'class_representative_award': 'Up '
'to '
'$2,500',
'settlement_administration': 'To '
'be '
'determined'},
'individual_claims': {'extraordinary_losses': 'Up '
'to '
'$2,500',
'out_of_pocket_expenses': 'Up '
'to '
'$500',
'pro_rata_cash_payment': 'Varies '
'(based '
'on '
'remaining '
'funds)'},
'settlement_fund': '$675,000'},
'identity_theft_risk': 'High (SSNs and medical data exposed)',
'legal_liabilities': '$675,000 settlement'},
'investigation_status': 'Settled (no further details on root cause '
'investigation)',
'post_incident_analysis': {'corrective_actions': ['Settlement payments',
'Credit/medical monitoring '
'for affected individuals']},
'references': [{'source': 'Class Action Settlement Notice'},
{'source': 'Settlement Administrator (R1/Dignity Data Incident '
'Settlement)'}],
'regulatory_compliance': {'legal_actions': ['Class action lawsuit settled for '
'$675,000']},
'response': {'communication_strategy': ['Written notifications to affected '
'patients (March 2024)',
'Settlement claims process with '
'deadlines'],
'remediation_measures': ['Class action settlement',
'Credit/medical monitoring services for '
'affected individuals']},
'stakeholder_advisories': ['Written notifications to affected patients',
'Settlement claims process'],
'threat_actor': 'Unauthorized third party',
'title': 'Data Breach at Dignity Health - St. Rose Dominican Hospital, Rosa '
'de Lima Campus via R1 RCM Inc.',
'type': ['Data Breach', 'Unauthorized Access', 'Class Action Settlement']}