A patient has filed a proposed class-action lawsuit against Trinity Health and Health Gorilla, alleging a data breach tied to a third-party data-sharing network may have affected about 300,000 individuals and exposed sensitive information.
The complaint, filed March 20 in the U.S. District Court for the Eastern District of Michigan, alleges the organizations failed to adequately safeguard patient data, allowing unauthorized access and potential disclosure to third parties. The complaint was views by Becker’s.
The lawsuit stems from a previously disclosed incident involving Health Gorilla, a company that facilitates data-sharing requests for healthcare organizations. Trinity Health, based in Livonia, Mich., said it learned Jan. 13 from a data exchange partner that patient information may have been improperly accessed through requests submitted by Health Gorilla.
According to the complaint, Health Gorilla requested patient records while representing the requests were for treatment purposes, but authorization for the access could not be verified.
The plaintiff alleges an unauthorized third party was able to access and exfiltrate patient data, and that the information was subsequently sold to third parties for commercial purposes.
Trinity Health previously said the data potentially exposed varies by individual and may include clinical care details, demographic information, insurance data and, in some cases, driver’s license numbers.
The lawsuit also alleges Trinity Health and Health Gorilla delayed notifying affected individuals. While Trinity Health said it became aware of the issue Jan. 13, patients were not notified until March 13, according to the complaint.
The plaintiff, a New York resident, claims he has experienced increased spam calls, time spent monitoring accounts and anxiety related to the potential misuse of his information.
The complaint brings claims including negligence, breach of implied contract and unjust enrichment and seeks damages, credit monitoring and changes to the defendants’ data security practices.
Trinity Health has said the companies involved were suspended from the data-sharing network while the incident is under investigation. The health system is offering affected individuals 12 months of complimentary credit monitoring and identity protection services.
The case adds to mounting scrutiny of Health Gorilla. In January, Epic and several health systems filed a separate federal lawsuit accusing the company of improperly accessing and monetizing patient data through national health information exchange frameworks.
Health Gorilla has denied those allegations, calling them “yet another example of Epic’s exclusionary actions.”
Separately, Pittsburgh-based UPMC said March 13 that Health Gorilla had requested patient data under the guise of coordinating care for mutual patients.
In response to that incident, a Health Gorilla spokesperson told Becker’s the company is “100 percent committed to patient privacy” and said it suspended the connections in question after concerns were raised.
A Trinity Health spokesperson told Becker’s in an email statement that it has not yet been served the referenced complaint.
“However, Trinity Health remains committed to vigorously defending itself against allegations arising from the actions of others,” the spokesperson said.
Becker’s has reached out to Health Gorilla for comment on the lawsuit and will update this story if more information becomes available.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.