Healthcare Vendor Data Breaches: Can Patients Sue When a Third Party Exposes Their Information?

When you entrust your personal information to a healthcare provider, you certainly do not expect that it will be compromised in a data breach. If that has happened, the national data breach lawyers at Federman & Sherwood can work to hold all negligent parties legally responsible.
Healthcare providers often rely on third parties to maintain their data because they lack this capacity on their own. Both a medical provider and a third-party vendor each have obligations that they owe when they are entrusted with your sensitive information. If they fail to uphold these obligations, both can be sued when you are seeking to recover your damages.
The national data breach attorneys at Federman & Sherwood have a track record of delivering results for our clients in these cases. Call us today at (800) 237-1277 to schedule a free initial consultation.
Both Providers and Third-Party Vendors Owe You a Duty of Care
Hackers have increasingly targeted healthcare data vendors in recent years. They do this because stolen healthcare data can sell for far more money on the black market than hacked credit card information. The same reasons that make this information more valuable also mean that you can suffer even more damage in a healthcare data breach.
When you entrust your healthcare data to a provider, you are owed a duty of care. You are trusting that provider with sensitive personal information. In turn, the healthcare provider cannot simply blindly trust a third party to hold and store your data while eliminating all of their obligations to you. The healthcare provider must institute their own safeguards, even if they are not the ones who ultimately hold your data. These protections include:
- Carefully scrutinize the potential vendor before reaching any agreement, reviewing things like their cybersecurity protections and any history of prior breaches.
- Ensure that the vendor has the necessary controls in place that protect your personal data
- Continuously perform all necessary security checks that are within their abilities
- Promptly respond to and notify affected patients of data breaches
Outsourcing to a Third Party Is Not an Absolute Defense in a Lawsuit
A healthcare provider cannot simply escape liability for a data breach by pointing the finger at a third-party vendor. After all, the provider is outsourcing what remains to be their obligation. As a patient, you do not have any control over how and where your information is stored. You do not have the ability to object to any Arrangements that the provider has with a third-party vendor. Accordingly, you have the right to sue the provider in most cases when there are third-party vendor data breaches.
In these instances, the healthcare provider has typically done something unreasonable that meant that they failed to uphold their obligations to you. Lawsuits may be based on the following grounds:
- The third party was not adequately vetted before they were hired, or they should have been terminated because they demonstrated a lack of diligence.
- The healthcare provider failed to adequately monitor the third party during the performance of any contract.
- The provider breached a fiduciary duty that they owed to the patient to protect the patient’s confidential information.
- States have their own individual privacy laws, which may allow data breach victims to file a lawsuit (there may also be state consumer protection statutes that can support a lawsuit).
Lawsuits Against Medical Providers and Third Parties for Data Breaches
There have been many large settlements of class action lawsuits filed in the wake of healthcare data breaches affecting third-party vendors. In 2020, hackers breached the systems of Blackbaud, which is a cloud services provider. Many healthcare organizations had retained Blackbaud’s services for data storage and faced lawsuits. Here, plaintiffs sued the medical providers who had hired Blackbaud. When the systems of a large billing agency were compromised in 2019, plaintiffs filed lawsuits against companies like Quest Diagnostics and Labcorp for their own negligence.
There are cases in which the healthcare provider has been sued, along with lawsuits against third-party vendors. In theory, you may be able to sue either or both for your damages, since both of their negligence presumably played a role in what happened. Your data breach lawyer will review the facts and circumstances of a situation to determine who you may be able to sue. Your choice of defendant can depend on a number of factors, including who has the proverbial “deeper pockets.”
Contact a National Data Breach Law Firm
Healthcare providers and their vendors have a responsibility to safeguard sensitive patient information. If your medical records, Social Security number, or other personal data were exposed in a healthcare data breach, the national data breach attorneys can investigate the circumstances and potentially file a lawsuit on your behalf. Message us online or call us today at (800) 237-1277 to discuss your case.