Utopia Tech
HealthcareAI-assisted3 min read

ZOLL Medical Pays $3.5 Million to Settle Data Breach Lawsuit

ZOLL Medical Corporation has agreed to a $3.5 million settlement following a January 2023 data breach that exposed personal and health information of over 1 million individuals, primarily LifeVest wearable defibrillator patients. The settlement, which received preliminary court approval, consolidates 15 class action lawsuits alleging HIPAA violations, negligence, and failure to implement adequate

UT

Utopia Tech

August 14, 2026 · 3 min read

Share

A $3,500,000 settlement has received preliminary approval from the court to resolve class action data breach litigation against ZOLL Medical Corporation. The litigation relates to a January 2023 data breach that affected more than 1 million individuals. Zoll Medical is a Chelmsford, Massachusetts-based global medical device and software company that makes products for resuscitation, cardiac monitoring, and critical cardiopulmonary conditions.

Unauthorized network access was identified on January 28, 2023, and the investigation confirmed that personally identifiable information (PII) and protected health information (PHI) were exposed in the incident, mainly relating to individuals who received or were considered for use of the ZOLL LifeVest wearable cardioverter defibrillator. According to the breach notice submitted to the HHS’ Office for Civil Rights, the electronic protected health information (ePHI) of 997,097 individuals was involved, including names, addresses, dates of birth, and Social Security numbers.

Those individuals started to be notified about the data breach in March 2023. The data breach sparked 15 class action lawsuits, which were consolidated on April 24, 2023. The consolidated class action complaint was filed on February 26, 2024 – Smith et al.

v. ZOLL Medical Corporation – in the U. S.

District Court of Massachusetts on behalf of a nationwide class. The plaintiffs claimed that ZOLL Medical had failed to comply with its responsibilities under HIPAA, including a failure to implement appropriate technical, physical, and administrative safeguards to secure the privacy of ePHI, and violated the HIPAA Breach Notification Rule by not issuing timely breach notices.

The lawsuit claimed that the breach notices did not include sufficient information about the nature of the breach to allow the victims to take action to protect themselves against data misuse. The consolidated complaint brough claims for negligence, negligence per se , breach of fiduciary duty, breach of implied contract, unjust enrichment, and declaratory judgment and injunctive relief, and included allegations of violations of the Florida Deceptive and Unfair Trade Practices Act, Kansas Consumer Protection Act, New York General Business Law, Pennsylvania Unfair Trade Practices and Consumer Protection Law, and Illinois Consumer Fraud and Deceptive Business Practices Act.

Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form. Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy ZOLL Medical disagreed with all claims and contentions in the lawsuit, including claims of wrongdoing, fault, and liability.

ZOLL Medical sought to have the complaint dismissed, asserting that the plaintiffs failed to state a claim entitling them to relief. The judge issued an order granting the motion to dismiss in part; however, the negligence claims under Massachusetts, Pennsylvania, Illinois, Florida, Texas, and New York law were permitted, along with the claims for breach of fiduciary duty, unjust enrichment, and breach of implied-in-law contract.

While mediation was unsuccessful, subsequent negotiations resulted in a settlement that was agreeable to all parties. The settlement class includes all living individuals who received a notice that their information was impacted by the data incident, with limited exceptions. From the $3,500,000 settlement fund, attorneys’ fees and expenses, settlement administration costs, taxes and tax-related expenses, and service awards for the class representatives will be deducted.

The remaining funds will be used to pay for class member benefits. Class members may submit a claim for reimbursement of documented, unreimbursed out-of-pocket losses incurred due to the data breach up to a maximum of $5,000 per class member. All class members may submit a claim for a cash payment, which will be paid pro rata from the remainder of the settlement fund.

Individuals who had their Social Security numbers exposed will receive two shares per valid claim. The SSN share is estimated to be $100, and the non-SSN share is estimated to be $50. The deadline for objection and opting out has passed.

Claims must be submitted by September 2, 2026, and the final fairness hearing has been scheduled for September 10, 2026. The post ZOLL Medical Pays $3. 5 Million to Settle Data Breach Lawsuit appeared first on The HIPAA Journal .

Originally published at hipaajournal.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content