The complaint claims that Keystone Health failed to implement adequate cybersecurity measures and that it didn’t properly notify patients of the breach.
The breach, which occurred between July 28 and August 19, allowed hackers to gain access to its network and compromise Social Security numbers and clinical health information of 235,237 patients.
The plaintiffs alleged that Keystone detected the cyberattack on August 19 but waited until October 14 to notify affected individuals.
The lawsuit alleges that because of this, Keystone violated its obligations under HIPAA and overlooked minimum industry standards for cybersecurity.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.