Highmark Hit with Class Action Over December 2022 Data Breach
Marshall v. Highmark, Inc.
Filed: February 22, 2023 ◆§ 2:23-cv-00290
Highmark, Inc. faces a class action over a December 2022 data breach that reportedly affected approximately 300,000 individuals.
Highmark, Inc. faces a proposed class action over a December 2022 data breach that reportedly affected approximately 300,000 individuals.
Want to stay in the loop on class actions that matter to you? Sign up for ClassAction.org’s free weekly newsletter here.
The 21-page lawsuit claims Highmark, a nonprofit healthcare company, failed to take “even the most basic steps” to safeguard consumers’ personal and health information from unauthorized access, resulting in a data breach between December 13 and 15 of last year. According to a February 6 press release from Highmark, the following highly sensitive data was compromised during the incident:
“ … [N]ames, enrollment information such as group name, identification number, claims or treatment information such as claim numbers, dates of service, procedures, prescription information, dates of birth, email addresses, phone numbers, driver’s license number, passport number, as well as in some cases social security numbers and financial information.”
Although Highmark’s online notice says the cyberattack was caused after an employee opened a “malicious phishing email link that led to their email account being compromised,” the lawsuit contends that the root cause of the breach stems from the company’s failure to implement adequate cybersecurity measures.
Moreover, the case says, Highmark’s negligence has exposed consumers to an increased risk of identity theft and fraud. Victims must now spend a significant amount of time, energy and money to protect themselves from such misuse of their information, which is a threat that may persist for years to come, the filing says.
The suit further charges that Highmark failed to provide affected individuals timely notice of the event, as the company has only recently begun informing victims of the cyberattack.
To make matters worse, Highmark failed to heed the warning provided by the FBI in a 2014 notice that said it had “observed malicious actors targeting healthcare related systems, perhaps for the purpose of obtaining the Protected Healthcare Information (PHI) and/or Personally Identifiable Information (PII),” the filing relays.
The lawsuit looks to cover anyone within the United States of America whose protected health information, personally identifiable information and/or financial information was exposed to unauthorized third parties as a result of the data breach announced by Highmark on February 6, 2023.
Get class action lawsuit news sent to your inbox – sign up for ClassAction.org’s free weekly newsletter here.
Video Game Addiction Lawsuits
If your child suffers from video game addiction — including Fortnite addiction or Roblox addiction — you may be able to take legal action. Gamers 18 to 22 may also qualify.
Learn more:Video Game Addiction Lawsuit
Depo-Provera Lawsuits
Anyone who received Depo-Provera or Depo-Provera SubQ injections and has been diagnosed with meningioma, a type of brain tumor, may be able to take legal action.
Read more: Depo-Provera Lawsuit
How Do I Join a Class Action Lawsuit?
Did you know there's usually nothing you need to do to join, sign up for, or add your name to new class action lawsuits when they're initially filed?
Read more here: How Do I Join a Class Action Lawsuit?
Stay Current
Sign Up For
Our Newsletter
New cases and investigations, settlement deadlines, and news straight to your inbox.
Before commenting, please review our comment policy.