Healthcare Data Breaches That Cause Patient Harm in California
Healthcare providers and insurance companies are responsible for collecting some of our most personal and sensitive data, including medical histories, diagnoses, treatments, insurance data, and financial information. When information is exposed in a data breach, there can be significant consequences for patients. Identity theft, financial loss, and public access to private data can all occur because of these security leaks.
In California, data breaches can raise serious legal issues. If the breach is the result of failure to maintain reasonable safety procedures, victims may be able to seek compensation. Learn more about your legal options now by calling McNicholas & McNicholas, LLP.
What counts as a healthcare data breach?
A healthcare data breach happens when protected health, financial, or personal information is accessed, stolen, or disclosed without an individual’s authorization. This can happen with medical records, treatment histories, health insurance information, billing information, Social Security numbers, and financial data.
Unfortunately, breaches happen in increasingly complex and technologically sophisticated ways. Cyberattacks that use ransomware or phishing are fairly common, targeting those in facilities who may not recognize the signs of a phishing attack or ransomware email. Other hackers use brute force access methods—testing hundreds of thousands of password combinations in a matter of seconds with the use of automated software.
However, not all breaches are the result of hacking. Some are also the result of completely preventable internal issues, like lost devices, weak or reused passwords, and employees who access records they are not authorized to view.
Not every incident is a legally actionable breach, but when sensitive data is exposed, legal claims are likely to arise.
How can data breaches harm patients?
The effects of a healthcare data breach can be long-lasting and severe, particularly if patients have sensitive diagnoses or treatment data:
- Identity theft and financial fraud: Stolen personal information can be used to open credit accounts, file falsified tax returns, sign contracts, and make unauthorized purchases.
- Medical identity theft: When someone gets ahold of an individual’s insurance information and personal identifying information, that’s often enough for them to seek medical care under that person’s name. This can lead to billing disputes and make it incredibly difficult for the person to receive medical care when conflicting diagnoses and treatments are reported.
- Emotional distress and loss of privacy: People rightfully assume that their medical and health data is private, known only to them, their doctors, and those who need to know. The exposure of medical information, including mental health treatment, chronic illness, and reproductive care, can be deeply embarrassing and cause intense anxiety for victims. For those who are well-known, this information can become widely broadcast, causing further harm.
- Long-term risks: It can be incredibly difficult or even impossible to unwind the effects of a data breach. This data doesn’t just disappear or become irrelevant over time; victims may be at risk for years or even decades after a breach. This is especially true if their SSN is exposed, as the Social Security Administration very rarely issues new SSNs, even in the case of clear identity theft.
California and federal protections
Perhaps the most well-known law affecting how medical records and information are handled is the Health Insurance Portability and Accountability Act, more commonly referred to as HIPAA. This requires organizations to safeguard patient information and notify people when a breach occurs. Note, though, that this is a federal law enforced by the government; it does not allow patients to file private lawsuits.
For non-exempt personal information covered by the California Consumer Privacy Act, businesses subject to the law are required to maintain reasonable security procedures. When a qualifying breach occurs as a result of a failure to use reasonable security procedures and it includes certain categories of unencrypted and unredacted data, affected individuals may sue the entity in question for damages between $107 and $799 per consumer per incident without having to prove actual harm. However, if they do suffer actual harm, they may be able to sue for actual damages with a personal injury lawyer.
Per California law, when a breach affects more than 500 California residents, an entity must report the breach to the California Attorney General. But no matter how small a breach is, entities must notify affected individuals when a qualifying breach occurs, and their unencrypted information is acquired or believed to have been acquired.
When healthcare providers can be held liable
Liability often falls on healthcare providers when a breach occurs. They must take reasonable steps to protect patient data, and if their procedures fall below this standard, they may be liable for subsequent breaches. Examples of negligence in this context include not implementing appropriate cybersecurity measures, failing to encrypt sensitive data, not training employees on data security practices, and allowing unauthorized access to records through poor internal controls.
Third-party liability in healthcare data breaches
In addition to healthcare providers and facilities, third parties may also face lawsuits when data breaches occur. Many modern healthcare facilities and providers rely on outside vendors for data storage, billing, and other services. If these third parties do not take appropriate steps to safeguard the data entrusted to their care, they may be liable for security breaches. Potential liable parties in this category include cloud storage providers, EHR systems, and insurance processing companies.
Proving harm in a data breach
Securing compensation in a personal injury claim generally requires you to prove actual harm or losses. In California, though, that isn’t necessarily the case when a data breach occurs. If a qualifying breach is the result of inadequate security measures and it involves certain categories of unencrypted and unredacted data, affected parties may be able to seek between $107 and $799 per consumer per incident without having to prove harm. If they want to sue for more by suing for actual damages, they do need to prove actual harm. This may include showing proof of unauthorized financial transactions, changes to credit reports, time and money spent addressing the breach, and proof of emotional distress.
Was your private medical information exposed? Call McNicholas & McNicholas, LLP
If your medical and financial data were exposed during a data breach, you may be able to fight for compensation. Let’s talk about your next steps. Give us a call or send us a message online.

As one of the leading trial lawyers in California, Partner Matthew McNicholas represents victims in a range of areas, including personal injury, wrongful death, employment law, product liability, sexual assault and other consumer-oriented matters. Learn more about his professional background here.