The healthcare data breach lawsuit against Northeast Radiology and its vendor Alliance Healthcare Services has been dismissed by a judge in the U.S. Southern District of New York court, citing failure to provide evidence of imminent risk of fraud or actual harm.In determining the dismissal, the judge referenced the June 2021 Supreme Court ruling and found that “to be concrete, an injury ‘must actually exist.’” Further, the breach victims must identify and provide evidence of “a close historical or common-law analogue for their asserted injury, although it need not be an exact duplicate.’”“Regarding statutory harms, it is not enough to allege that a defendant violated the law,” according to the ruling. “‘Only those plaintiffs who have been concretely harmed by a defendant’s statutory violation will have standing.’”Filed in July 2021, the class-action lawsuit stemmed from a nine-month data breach, which was caused by longstanding vulnerabilities in the vendor’s picture archiving and communication system. PACS are leveraged by health systems to readily share medical images and health information with connected partners, as well as data archiving purposes.But the tech holds well-documented vulnerabilities, which can readily enable unauthorized access to sensitive data. The lawsuit itself followed a SC Media report detailing the risk of these flaws and a Department of Health and Human Services alert finding 130 health systems actively exposing images through these flaws.For Northeast Radiology and Alliance Health, the overlooked PACs flaws enabled a threat actor to gain access to the legacy tech, exposing the data belonging to 298,532 patients. The data included names, dates of birth, exam descriptions, dates of service, medical images and details, and corresponding Social Security numbers.Alliance began notifying those patients in March 2020, and the class-action followed on July 8, 2021. The lawsuit argued that the vendors’ “careless handling of e-PHI is prohibited by federal and state law,” and by failing to comply with the Health Insurance Portability and Accountability Act, both Northeast Radiology and Alliance Health caused direct harm to victims.The purported injuries included ongoing, imminent risk of identity theft and fraud, “because, unlike a credit card, there is no way to cancel e-PHI.” The lawsuit argued the victims would demonstrate that the vendors’ security policies, provider communications, and disclosed vulnerabilities would shed light on the claims of harm.
Breach, Incident Response, Governance, Risk and Compliance
Northeast Radiology breach lawsuit dismissed over lack of concrete harm
The Danbury, Conn., office of Northeast Radiology. A breach lawsuit against the radiology specialist and its vendor Alliance HealthCare was dismissed due to a lack of evidence detailing concrete harm. (Credit: Northeast Radiology)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds