Onsite Women’s Health agreed to a $2,525,000 settlement following a data breach involving the email account of an employee that resulted in the exposure of protected health information (PHI) of 357,265 individuals after unauthorized access occurred in October 2024.
Data Breach Incident
Onsite Mammography, LLC, also known as Onsite Women’s Health, in Westfield, Massachusetts, provides medical imaging services to hospitals. The incident involved unauthorized access to an employee email account after responding to a phishing email. The account was accessible for a short period of time, during which sensitive data was exfiltrated.
The information exposed included names, birth dates, credit card numbers, Social Security numbers, driver’s license numbers, and data related to patients’ mental or physical conditions and care received.
Litigation Background
The disclosure incident prompted the filing of several class action lawsuits. The consolidated lawsuits were filed in the United States District Court, District of Massachusetts under Clarkson, et al. v. Onsite Mammography, LLC, d/b/a Onsite Women’s Health .
The consolidated complaint alleged that security measures for employee email accounts were not adequate to prevent attacks. The plaintiffs stated that stronger controls could have prevented the attack or allowed earlier detection, thus reducing harm linked to the breach.
Individuals affected were offered 12 months of free credit monitoring services. The plaintiffs argued that this offer did not match the level of risk faced by impacted individuals. The complaint also stated that no assurances were provided that the data taken during the incident had been deleted or that improvements had been made to prevent similar events.
The lawsuit included claims for breach of implied contract, negligence, breach of fiduciary duty, invasion of privacy, declaratory judgment, and unjust enrichment. Onsite Women’s Health maintained that there was no wrongdoing and did not agree with the allegations raised in the litigation.
Settlement Terms and Fund Allocation
Despite disputing the claims, Onsite Women’s Health agreed to resolve the litigation. The settlement establishes a $2,525,000 fund. The fund will be used to cover attorneys’ fees and expenses, settlement administration costs, notification expenses, and service awards for eight class representatives.
After these allocations, remaining funds will be distributed to class members through available benefits under the settlement structure.
Claims and Deadlines
Each class member may file claims to reimburse documented, unreimbursed losses resulting from the data breach. Reimbursement may reach up to $5,000.
Claims may also include access to three years of credit monitoring and medical data monitoring services. A pro rata cash payment option is also available and will be distributed after other payments and costs are addressed, using remaining settlement funds.
The deadline for exclusion and objection is July 13, 2026. The deadline to submit claims is August 11, 2026. A final fairness hearing is scheduled for September 9, 2026.
Legal Positions and Resolution
The plaintiffs asserted that security controls surrounding employee email systems were insufficient to prevent unauthorized access. The defendant maintained disagreement with these assertions while opting to settle after evaluating litigation costs and risks associated with continuing the case.
The resolution concludes the consolidated proceedings tied to the October 2024 email account compromise involving exposure of PHI across a large affected population.
