More than 600,000 individuals had their sensitive information compromised in a cybersecurity breach at a Pennsylvania healthcare services company, which has now agreed to a $3 million class-action settlement. The hack exposed a wide array of personal data, including Social Security numbers, driver’s license details, financial records, and protected health information.

Details of the Breach and Impacted Data

The incident was detected around October 7, 2024. Unauthorized access to the company's systems allowed hackers to extract extensive private data of 624,496 people. Besides names and Social Security numbers, the stolen information involved login credentials, state ID numbers, health insurance details, and financial account records. The affected company provides environmental, dining, and nutritional support services to thousands of long-term care and healthcare facilities in 48 states.

Legal Fallout and Settlement Terms

The class-action lawsuit, Williamson et al. v. Healthcare Services Group, Inc., accused the company of negligence, breach of fiduciary duty, unjust enrichment, and violations of consumer protection laws. Despite denying liability, Healthcare Services Group opted to settle to avoid prolonged litigation.

The settlement fund aims to cover legal expenses while offering affected individuals three years of credit monitoring and identity theft protection. also eligible claimants may receive reimbursement for out-of-pocket losses up to $5,000, plus potential extra cash distributions. Claims must be filed by October 1, 2026, ahead of a fairness hearing scheduled for September 24, 2026.