Michigan-based McLaren Health Care agreed to pay $14 million to settle consolidated class-action litigation tied to two ransomware incidents—one in 2023 (attributed in reporting to ALPHV/BlackCat) and another in 2024 (attributed to INC Ransom)—that collectively affected more than 2.5 million patients and employees. The lawsuits, filed in Michigan state court, alleged failures including negligence and breach of contract claims related to safeguarding sensitive data.
Under the preliminary settlement terms, eligible class members may submit claims for up to $5,000 in documented, unreimbursed losses and consequential expenses that are more likely than not tied to the breaches, and may also be eligible for a pro rata cash payment. A final court hearing to consider approval of the settlement is reported as scheduled for April 21; the two articles covering the McLaren matter are substantively the same report syndicated across GovInfoSecurity and BankInfoSecurity.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
A final court hearing to consider approval of the preliminary settlement was scheduled for April 21, 2026. The settlement also set claim-related deadlines in March and April 2026.
McLaren agreed to pay $14 million to settle consolidated class action litigation tied to the 2023 and 2024 ransomware-related breaches. The settlement includes up to $5,000 for documented unreimbursed losses, credit monitoring or identity protection benefits, and a commitment to enhance security practices for at least two years.
McLaren later reported the 2024 incident to the U.S. Department of Health and Human Services as affecting more than 743,000 individuals' protected health information. This disclosure quantified the impact of the second breach.
McLaren experienced a second ransomware-related network intrusion in 2024, attributed to the Inc Ransom group. Staff described this attack as more disruptive to patient care, and exposed data reportedly included personal, medical, and payment information.
After the 2023 incident, McLaren notified federal regulators that the breach affected nearly 2.2 million patients. The disclosure established the scale of the first ransomware-related data breach.
McLaren Health Care suffered a ransomware-related intrusion in 2023 that was attributed to ALPHV/BlackCat. The attackers allegedly exfiltrated sensitive patient and employee data, with reports saying the group claimed to have stolen more than 6 TB of information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.