A federal court has granted preliminary approval for a $5 million settlement in a class action lawsuit involving Geisinger Health and Nuance Communications following a significant insider data breach. The breach, which occurred in 2023, involved a former Nuance employee who accessed and stole sensitive patient information from Geisinger Health two days after his termination. The compromised data included names, Social Security numbers, dates of birth, medical information, and health insurance details for over 1 million patients. Notification to the 1.2 million affected individuals was delayed until June 2024 due to an ongoing law enforcement investigation.
The settlement addresses both the class action litigation and the criminal case against the ex-Nuance worker. Geisinger Health, a major healthcare provider in Pennsylvania, and Nuance Communications, a Microsoft subsidiary, faced scrutiny for their handling of the breach and subsequent notification process. The incident highlights the risks associated with insider threats in healthcare and the importance of timely breach disclosure to affected individuals.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
The court scheduled a final approval hearing for the proposed Geisinger-Nuance settlement. The hearing is set to determine whether the $5 million class action settlement will receive final approval.
A Pennsylvania federal court granted preliminary approval to a $5 million settlement in consolidated class action litigation against Geisinger Health and Nuance Communications over the insider breach. The proposed settlement includes reimbursement for certain losses, cash payments, and one year of credit, medical monitoring, and identity theft protection for class members.
The accused individual, Max Vance, also known as Andre Burk, was charged under the federal Computer Fraud and Abuse Act in connection with the breach. He remains in custody pending trial.
In June 2024, Geisinger notified approximately 1.2 million individuals affected by the insider breach. The notices said potentially exposed information included personal, medical, and health insurance data.
A law enforcement investigation into the breach delayed notification to affected individuals. As a result, Geisinger did not notify roughly 1.2 million affected people until June 2024.
After discovering the incident, Geisinger notified Nuance about the unauthorized access. Nuance then permanently disconnected the former employee's access to prevent further misuse.
In 2023, a former Nuance employee allegedly accessed and stole Geisinger Health patient data two days after being terminated. The breach ultimately affected more than 1 million Geisinger patients and exposed data such as names, Social Security numbers, dates of birth, medical and insurance information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.