OneTouchPoint to Settle Class Action After 2.65 Million Records Exposed
The Wisconsin-based vendor will resolve litigation following a 2022 ransomware attack that compromised sensitive healthcare data.
OneTouchPoint Corp. has agreed to settle a class action lawsuit, Dusterhoft v. OneTouchPoint, Inc., stemming from a massive ransomware attack in 2022. The settlement follows a breach that exposed the private information of approximately 2.65 million individuals, including patients, clients, and employees of the company's partners.
The security incident occurred in April 2022, with the company discovering the attack on April 28 after ransomware encrypted its files. According to reports from the HIPAA Journal, the breach resulted in the exposure of sensitive medical and personal data. The settlement provides a mechanism for eligible claimants to seek monetary compensation for losses and time spent, as well as access to credit monitoring services.
The Vendor Vulnerability
OneTouchPoint, a Wisconsin-based mailing and printing vendor, operates as a critical third-party link for healthcare providers and insurance companies. By handling the physical and digital distribution of sensitive documents, the company became a high-value target for cybercriminals. The April 2022 attack led to widespread exposure of data across various states, triggering multiple regulatory notifications and the subsequent legal challenges that culminated in the current settlement.
Industry Implications
This case underscores the systemic risk inherent in the healthcare supply chain, where the security of patient data is only as strong as the weakest third-party vendor. When a single printing or mailing partner is compromised, the liability extends far beyond the vendor to the healthcare providers whose reputations and patient trust are at stake. The scale of this breach—affecting over 2.6 million people—demonstrates how third-party vulnerabilities can create massive legal and financial liabilities for companies handling protected health information.
Next Steps
While the settlement has been reached, the legal process continues toward finalization. A final approval hearing for the settlement is scheduled for November 18, 2026. Affected individuals should monitor official notices to determine their eligibility for compensation and credit monitoring. The outcome of this case serves as a warning to other B2B service providers regarding the necessity of robust encryption and ransomware defenses when managing sensitive client data.