Integris Health, the largest nonprofit healthcare network in Oklahoma, agreed to pay $30 million to settle class action lawsuits stemming from a 2023 data breach that compromised the personal information of approximately 2.4 million individuals. The breach involved cybercriminals who not only stole sensitive data but also directly contacted some affected patients, including minors, with ransom and blackmail demands. These demands threatened to sell the stolen data on the dark web if payments were not made. The settlement provides for class members to claim up to $25,000 for documented losses, which explicitly includes reimbursement for any ransom payments made to the attackers. In addition to compensation for direct financial losses, affected individuals can opt for a pro-rated cash payment of about $100. The settlement also offers three years of credit monitoring services, which include up to $1 million in identity theft insurance coverage for each class member. Class representatives are set to receive $5,000 service awards for their roles in the litigation. The legal counsel representing the class will seek court approval for attorney fees as part of the settlement process. Integris Health operates more than 15 hospitals and dozens of clinics across Oklahoma, making the scale of the breach significant in terms of both the number of affected individuals and the potential impact on healthcare operations. The incident highlights the evolving tactics of cybercriminals, who are increasingly targeting patients directly in addition to attacking healthcare organizations. The direct ransom demands to patients represent a particularly aggressive form of extortion, raising concerns about the psychological and financial impact on victims, especially minors. The breach and subsequent legal action underscore the critical importance of robust cybersecurity measures and incident response planning in the healthcare sector. The settlement aims to provide financial relief and monitoring services to those affected, while also serving as a warning to other healthcare providers about the risks of inadequate data protection. The case has drawn attention to the need for improved security practices and greater support for victims of healthcare data breaches. The outcome of the settlement may influence how future cases involving direct patient extortion are handled in the legal system. Integris Health's response, including the settlement and support services, is intended to mitigate the long-term consequences for patients whose data was compromised. The incident is a stark reminder of the high stakes involved in protecting sensitive health information from increasingly sophisticated cyber threats.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
Integris Health agreed to pay $30 million to settle lawsuits arising from the 2023 data breach. The settlement was reported in mid-October 2025 by multiple outlets covering the same development.
Integris Health experienced a data breach in 2023 that later prompted multiple lawsuits and regulatory scrutiny. The incident exposed patient information and became the basis for subsequent legal claims against the Oklahoma health system.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.