Illinois Bone and Joint Institute Settles $4M Data Breach Class Action
Illinois Bone and Joint Institute (IBJI) has agreed to a $4 million settlement to resolve a class action lawsuit stemming from a July 2024 data breach that exposed the personal and protected health information of an estimated 568,000 current and former patients. The breach prompted allegations of negligence, breach of implied contract, invasion of privacy, and violations of the Illinois Consumer Fraud and Deceptive Business Practices Act.
Eligibility & Compensation
Individuals who received a breach notification from IBJI may qualify for compensation, including:
- A pro rata cash payment (estimated at $50, with final amounts dependent on total claims filed).
- Reimbursement of up to $5,000 for out-of-pocket losses tied to the breach, such as identity theft, fraud, credit monitoring fees, or credit freeze/unfreeze costs incurred after May 30, 2024.
- Two years of Kroll medical monitoring services (valued at $240/year), covering credit monitoring, dark web scanning, fraud specialist access, and up to $1 million in identity fraud loss reimbursement.
Claim Process & Deadlines
Affected individuals must submit claims by July 1, 2026, either online or via mail to the settlement administrator. Out-of-pocket loss claims require supporting documentation, such as receipts, bank statements, or police reports. Payouts will be distributed electronically or by check after final court approval.
Settlement Fund Allocation
The $4 million fund will cover:
- Settlement administration costs (TBD).
- Attorneys’ fees (up to $1.4 million).
- Attorneys’ expenses (subject to court approval).
- Service awards for class representatives (up to $2,000 each, totaling $18,000).
- Medical monitoring costs (based on claims filed).
- Remaining funds for approved claimants.
Key Dates
- Opt-out deadline: June 1, 2026.
- Final approval hearing: July 1, 2026.
- Payouts will follow court approval and claim processing.
Background
The lawsuit alleged IBJI failed to adequately safeguard patient data, leading to the exposure of sensitive information. While IBJI denied wrongdoing, the settlement was reached to avoid prolonged litigation. Payments and monitoring services will be issued once the court grants final approval.
Source: https://www.claimdepot.com/settlements/ibji-data-settlement
Illinois Bone & Joint Institute cybersecurity rating report: https://www.rankiteo.com/company/illinois-bone-and-joint-institute
"id": "ILL1776299040",
"linkid": "illinois-bone-and-joint-institute",
"type": "Breach",
"date": "4/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '568,000 current and former '
'patients',
'industry': 'Healthcare',
'location': 'Illinois, USA',
'name': 'Illinois Bone and Joint Institute (IBJI)',
'type': 'Healthcare Provider'}],
'customer_advisories': 'Breach notifications sent to affected individuals '
'with compensation details',
'data_breach': {'number_of_records_exposed': '568,000',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High (health and personal data)',
'type_of_data_compromised': ['Personal information',
'Protected health information']},
'date_detected': '2024-07',
'date_publicly_disclosed': '2024-07',
'description': 'Illinois Bone and Joint Institute (IBJI) has agreed to a $4 '
'million settlement to resolve a class action lawsuit stemming '
'from a July 2024 data breach that exposed the personal and '
'protected health information of an estimated 568,000 current '
'and former patients. The breach prompted allegations of '
'negligence, breach of implied contract, invasion of privacy, '
'and violations of the Illinois Consumer Fraud and Deceptive '
'Business Practices Act.',
'impact': {'brand_reputation_impact': 'Allegations of negligence and privacy '
'violations',
'data_compromised': 'Personal and protected health information',
'financial_loss': '$4,000,000 (settlement amount)',
'identity_theft_risk': 'High (568,000 individuals affected)',
'legal_liabilities': 'Class action lawsuit, violations of Illinois '
'Consumer Fraud and Deceptive Business '
'Practices Act'},
'investigation_status': 'Settled (pending court approval)',
'post_incident_analysis': {'root_causes': 'Alleged failure to adequately '
'safeguard patient data'},
'references': [{'source': 'Settlement announcement'}],
'regulatory_compliance': {'legal_actions': 'Class action lawsuit',
'regulations_violated': ['Illinois Consumer Fraud '
'and Deceptive Business '
'Practices Act']},
'response': {'communication_strategy': 'Breach notifications sent to affected '
'individuals',
'enhanced_monitoring': 'Two years of Kroll medical monitoring '
'services (credit monitoring, dark web '
'scanning, fraud specialist access)',
'third_party_assistance': 'Kroll (medical monitoring services)'},
'title': 'Illinois Bone and Joint Institute Data Breach Settlement',
'type': 'Data Breach'}