On October 8, 2020, Community Health Systems, Inc. (Community Health) and its subsidiary CHSPSC, LLC entered into a settlement agreement with 28 states for $5 million to resolve claims related to a 2014 data breach. Community Health owns over 200 hospitals across the United States and is one of the largest hospital networks in the country. The multi-state settlement follows a separate $2.3 million settlement that Community Health reached with the U.S. Department of Health and Human Services Office for Civil Rights (HHS-OCR) in connection with the same data breach.
In August 2014, Community Health disclosed that cyber attackers had gained access to its networks earlier that year and had obtained personal information for approximately 4.5 million patients. Subsequent investigation revealed the total number of affected patients to be more than six million. The attackers gained access to, among other things, patients’ names, addresses, birth dates and social security numbers.
Twenty-eight states were involved in the settlement, including, among others, Illinois, New Jersey and Massachusetts. The amount each state will receive as part of the settlement varies based on the number of residents affected by the data breach. In addition, as part of the settlement, Community Health must undertake additional measures to ensure the protection of sensitive patient information, including, among other things, drafting a written incident response plan, providing additional security and privacy training for employees, and taking steps to limit individual employees’ access to data in the company’s systems.
The settlement with Community Health is the latest financially-significant, multi-state settlement in connection with a large data breach. Since just the beginning of September 2020, publicly-announced, multi-state data breach settlements have resulted in fines and penalties of approximately $45 million. These large – and public – penalties are a reminder of the emphasis being placed on data privacy and data breach enforcement by both the federal government and individual state attorneys general and regulators. With the passage or impending passage of new and onerous data privacy and data breach statutes by individual states, companies should expect that this aggressive and punitive enforcement mindset will continue for the foreseeable future.