In March 2022, Shields Health Care Group Inc. suffered a cyberattack that exposed sensitive patient data, affecting an estimated 2.38 million current and former patients. Unauthorized actors gained access to private files, leading to potential exposure of personal and health information. The breach resulted in a $15.35 million class action settlement, with claimants eligible for up to $25,000 for documented losses, including identity theft, financial fraud, and time spent mitigating the incident. The settlement covers out-of-pocket expenses, credit monitoring costs, and extraordinary losses like falsified tax returns or real estate fraud. Shields Health denied wrongdoing but settled to avoid prolonged litigation. The breach had severe repercussions, including financial harm, reputational damage, and long-term risks for affected individuals.
Source: https://www.claimdepot.com/settlements/shields-data-settlement
TPRM report: https://www.rankiteo.com/company/shields-health
"id": "shi5502855101425",
"linkid": "shields-health",
"type": "Cyber Attack",
"date": "3/2022",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '2,382,578 (current and former '
'patients)',
'industry': 'Healthcare',
'location': 'United States (primarily Massachusetts)',
'name': 'Shields Health Care Group Inc.',
'type': 'Healthcare Provider'}],
'customer_advisories': 'Eligible individuals can file claims for compensation '
'(up to $25,000 for extraordinary losses) by December '
'3, 2025. Options include out-of-pocket losses, '
'attested time, or a $50 flat payment.',
'data_breach': {'data_exfiltration': 'Yes (unauthorized access to sensitive '
'files)',
'number_of_records_exposed': '2,382,578',
'personally_identifiable_information': 'Yes (names, '
'addresses, medical '
'records, etc.)',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personal information',
'Health records',
'Private files']},
'date_detected': '2022-03',
'date_publicly_disclosed': '2022-07-25',
'description': 'Shields Health Care Group Inc. experienced a cyberattack in '
'March 2022 that exposed sensitive patient information, '
'leading to a $15.35 million class action settlement. The '
'breach affected an estimated 2,382,578 current and former '
'patients, with unauthorized access to files containing '
'private health and personal data. The company agreed to '
'settle to avoid litigation costs and uncertainty, though it '
'denies wrongdoing.',
'impact': {'brand_reputation_impact': 'Significant (public disclosure, '
'settlement, and potential loss of '
'trust)',
'customer_complaints': 'Class action lawsuit filed by affected '
'patients',
'data_compromised': {'records_exposed': '2,382,578',
'sensitivity': 'High (sensitive patient '
'information)',
'type': ['Private health information',
'Personal data']},
'financial_loss': '$15.35 million (settlement fund)',
'identity_theft_risk': 'High (reported cases of identity theft, '
'financial fraud, and government benefits '
'fraud)',
'legal_liabilities': "$15.35 million settlement, attorneys' fees "
'($5.12 million), and administrative costs'},
'investigation_status': 'Settled (class action lawsuit resolved; final '
'approval pending as of 2025-12-16)',
'post_incident_analysis': {'corrective_actions': 'Settlement fund established '
'($15.35 million) to '
'compensate affected '
'individuals; no technical '
'remediation details '
'disclosed',
'root_causes': 'Alleged failure to adequately '
'protect patient data'},
'references': [{'source': 'Class Action Settlement Notice'},
{'source': 'Shields Health Care Group Settlement Administrator '
'(Analytics Consulting LLC)'}],
'regulatory_compliance': {'legal_actions': 'Class action lawsuit settled for '
'$15.35 million'},
'response': {'communication_strategy': 'Notices mailed to affected '
'individuals (July 25, 2022); public '
'settlement announcement'},
'stakeholder_advisories': 'Notices sent to affected individuals (July 2022); '
'settlement claims process ongoing',
'title': 'Shields Health Care Group Data Breach (2022)',
'type': ['Data Breach', 'Class Action Lawsuit']}