US healthcare data-breach litigation and enforcement activity saw multiple updates, including new criminal charges tied to the 2023 Geisinger Health breach. Prosecutors filed a superseding indictment adding two counts of false statements against Max Vance, a former Nuance Communications employee accused of intentionally accessing a protected computer and obtaining PHI for more than 1.3 million Geisinger patients shortly after his termination; the new counts allege he lied to the FBI about downloading or storing unauthorized data on personal devices.
Separately, two civil class-action matters reached settlement in breach cases involving patient data exposure. Capital Health agreed to a $4.5M settlement tied to a 2023 ransomware incident in which intruders had network access for roughly two weeks and encrypted files; LockBit claimed responsibility and alleged ~7 TB of data exfiltration, while Capital Health reported the incident to HHS OCR as affecting 503,071 individuals. Gryphon Healthcare agreed to a $2.87M settlement (including a $2.8M fund) over a 2024 cyberattack affecting a billing-services partner relationship, with 393,358 patients’ PHI potentially viewed or obtained; the company denied liability but settled to avoid continued litigation costs and uncertainty.

See the actors and campaigns active against you right now.
13 events from the most recent confirmed update back to the earliest known activity.
Capital Health agreed to pay $4.5 million to settle consolidated class action litigation over its 2023 ransomware attack. The settlement includes reimbursement for documented losses, a cash alternative, credit monitoring, and commitments to maintain additional security measures.
A superseding indictment in the U.S. Middle District Court added two counts of making false statements against former Nuance employee Max Vance. The new charges relate to alleged lies to FBI agents during the Geisinger data breach investigation.
Gryphon Healthcare agreed to settle the consolidated class action litigation for $2.87 million, with benefits including reimbursement for losses, a cash alternative, and two years of identity theft and medical data monitoring. The settlement was reported on February 4, 2026.
In May 2025, the Capital Health breach lawsuits were consolidated in the U.S. District Court for the District of New Jersey as Bruce Graycar, et al. v. Capital Health Systems, Inc. This combined the various claims stemming from the 2023 ransomware incident.
Gryphon Healthcare started notifying impacted patients around October 11, 2024 about the breach. The notices triggered multiple class action lawsuits that were later consolidated.
Gryphon Healthcare discovered the incident in August 2024 and investigated the impact of the July cyberattack. The company concluded that files may have been viewed or obtained.
A cyberattack tied to a Gryphon Healthcare partner or IT service provider occurred in July 2024, leading to possible exposure of protected health information. The incident ultimately affected 393,358 patients.
The LockBit ransomware group claimed responsibility for the Capital Health attack, alleged it stole 7 TB of data, and threatened to publish the data if a ransom was not paid. The leak deadline cited was January 9, 2024.
In January 2024, prosecutors say Max Vance falsely told FBI agents that he had not downloaded or stored unauthorized Geisinger data on personal devices. These alleged statements later formed the basis for additional charges in a superseding indictment.
Max Vance was indicted in January 2024 on a charge of obtaining information from a protected computer in connection with the 2023 Geisinger Health data breach. Prosecutors allege he compromised protected health information of more than 1.3 million patients after his employment ended.
Multiple lawsuits arising from the Capital Health data breach began to be filed on December 19, 2023. The litigation alleged harm from the 2023 ransomware attack and exposure of patient information.
Capital Health detected unauthorized activity on or around November 26, 2023 and launched a forensic investigation into the ransomware attack. The investigation later determined patient data may have been exposed.
A threat actor accessed Capital Health's systems between November 11 and November 26, 2023, during a ransomware incident in which files were encrypted and data may have been exfiltrated. Capital Health later reported the breach affected 503,071 individuals.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcehipaajournal.com
Open sourcehipaajournal.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.