Marlboro-Chesterfield Pathology has agreed to settle a class action lawsuit tied to a January 2025 ransomware attack attributed to the SafePay group, after attackers gained unauthorized access to its network and obtained files containing sensitive patient information. The pathology provider reported to the U.S. Department of Health and Human Services Office for Civil Rights that 235,911 individuals were affected, with compromised data including names, dates of birth, Social Security numbers, and protected health information.
The proposed settlement, which received preliminary court approval, provides reimbursement of documented fraud- or identity-theft-related losses of up to $1,000 per class member, a $10 alternative cash payment for certain people whose Social Security numbers were exposed, and one year of credit monitoring and identity theft protection. Marlboro-Chesterfield Pathology denied wrongdoing and liability, and no ransom payment details were disclosed, while a final fairness hearing is scheduled for October 12, 2026.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
The SafePay ransomware group claimed responsibility for the attack and posted Marlboro-Chesterfield Pathology on its data leak site. No details were disclosed about any ransom payment.
The proposed class action settlement received preliminary court approval. A final fairness or approval hearing was scheduled for October 12, 2026.
Marlboro-Chesterfield Pathology agreed to settle a class action lawsuit alleging it failed to implement reasonable cybersecurity safeguards, while denying wrongdoing and liability. The proposed settlement includes up to $1,000 for documented losses, a $10 cash alternative for certain Social Security number victims, and one year of credit monitoring and identity theft protection.
A forensic investigation determined that sensitive data belonging to 235,911 individuals was compromised, including names, dates of birth, Social Security numbers, and protected health information. MCP also reported this impact to the U.S. Department of Health and Human Services Office for Civil Rights.
Marlboro-Chesterfield Pathology identified suspicious activity on its network and later determined that an unauthorized party had accessed the network and acquired files containing patient data. The incident was tied to a January 2025 ransomware attack attributed to the SafePay ransomware group.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.