OnePoint Patient Care Settles 1.7 Million Patient Data Breach for $2.1 Million
The hospice-focused pharmacy will resolve a class action lawsuit following an August 2024 network intrusion.
OnePoint Patient Care has agreed to a $2,115,000 settlement to resolve a class action lawsuit stemming from a massive data breach in August 2024. The agreement addresses the exposure of sensitive personal and medical information belonging to approximately 1.7 million individuals.
The settlement follows a legal challenge titled Christopher Russo v. OP Pharmacy, LLC a/k/a OnePoint Patient Care, LLC (Case No. 3:24-cv-00649-RGJ). According to court and industry records, the breach occurred between August 6 and August 8, 2024, when unauthorized actors gained access to the company's computer network. The incident specifically affected 1,741,152 individuals, exposing a combination of Social Security numbers and protected health information (PHI).
The Vulnerability of Hospice Data
OnePoint Patient Care operates as a dispensing pharmacy and pharmacy benefit manager specifically tailored for hospice providers. Because the company handles the end-of-life care pipeline, the data it manages is exceptionally sensitive. The breach occurred during a window of just three days, yet the scale of the exposure underscores the systemic risks associated with centralized healthcare-adjacent data repositories.
Industry Implications
This settlement highlights the escalating legal and financial liabilities for providers who fail to secure patient data. For the healthcare industry, the case serves as a warning that the "adjacent" nature of a business—acting as a manager or dispenser rather than a primary care provider—does not shield a company from the rigorous requirements of data protection.
Furthermore, the specific nature of the affected population increases the stakes. Hospice patients and their families are often in precarious emotional and physical states, making them prime targets for medical fraud and identity theft. When Social Security numbers and medical records are leaked, the potential for targeted exploitation is significantly higher than in standard retail data breaches.
Next Steps for Claimants
Eligible individuals who were affected by the August 2024 breach may file claims for payment. According to reports from All About Lawyer, some claimants may be eligible for payments based on documented losses, though the core settlement fund is capped at the agreed $2.115 million. The deadline for affected individuals to file a claim is October 8, 2026.