2 min read

Brightline reaches $7m data breach settlement

Image of blue shield with keyhole.

A data breach occurred within Brightline in January 2023 when the Clop ransomware group exploited a remote code execution vulnerability in Fortra’s GoAnywhere Managed File Transfer (MFT) solution.

 

What happened 

Between January 18 and January 30, 2023, Clop actors created unauthorized user accounts after exploiting this vulnerability, allowing them to download sensitive files from the MFTaaS environments of multiple organizations. Brightline, a virtual mental health provider, was one of 130 companies affected by this attack. 

As a result, the protected health information (PHI) of approximately 964,300 individuals was compromised, including names, addresses, dates of birth, member identification numbers, health plan coverage start and end dates, employer names, and Social Security numbers. Notifications were issued to affected individuals in May 2023. Following the breach, four lawsuits were filed against Brightline, which were later consolidated into a single case, Terrance Rosa, et al. v. Brightline Inc., in the U.S. District Court for the Southern District of Florida. 

The plaintiffs alleged negligence, breach of contract, breach of fiduciary duty, unjust enrichment, and violations of various state consumer protection laws. To resolve the litigation without admitting liability, Brightline agreed to a $7 million settlement, which was approved by a federal judge on February 13, 2025.

 

What was said 

According to the Brightline class action settlement website, “All Settlement Class members may select either Cash Payment A or Cash Payment B. Any Settlement Class member who submits a Valid Claim may elect to receive Cash Payment A in the form of cash compensation up to $5,000.00 by providing reasonable documented losses related to the Data Incident (“Cash Payment A”); or Cash Payment B in the form of a flat cash payment in the amount of $100.00 (“Cash Payment B”).”

 

Why it matters

Compared to similar recent judgments, the settlement is notable for both its monetary value and its focus on a telemental health provider. In recent months healthcare organizations have been held accountable by both the HHS and class action lawsuits like the one in this case. The Brightline settlements reinforce the legal precedent that healthcare providers are expected of their size or technological infrastructure.  

Related: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is a medical class action lawsuit?

A medical class action lawsuit is a civil litigation filed on behalf of a group of individuals or business entities who have suffered common injuries caused by the same liable party. It involves a large number of individuals suffering similar injuries due to the same defendant's conduct. Individual lawsuits may not be practical due to the large number of individuals affected.

 

What are some common types of class action suits in healthcare?

Common types of medical class action lawsuits include: unlawful promotion of prescription drugs by pharmaceutical companies, unlisted drug side effects that cause harm, death or permanent injury caused by medical devices, medical tort, and defective products in healthcare.

 

What are some examples of healthcare organizations that have been involved in class action lawsuits?

Blue Cross Blue Shield, a major health insurance company, has been involved in multiple class action lawsuits.

Image of someone using a gavel.

HCA Healthcare reaches data breach settlement following 27.7 million record leak

A federal court has approved a multi-million dollar settlement in response to HCA’s 2023 data breach affecting over 11 million patients.

Read More
Image of a teddy bear with a stethescope.

Boston Children’s Health Physicians to pay $5.15m in data breach settlement

Patients and employees affected by a 2024 data breach may be eligible for compensation and medical data monitoring.

Read More
Lawyer reviewing contract at desk with gavel and scales of justice

Bridgeway Center data breach settlement could pay victims up to $7,500

Thousands of Americans affected by a 2024 cyberattack on Bridgeway Center may be eligible for compensation through a class-action settlement offering...

Read More