Colorado Laboratory Faces Action Breach Lawsuits After Medusa Ransomware Hack

November 11, 2024

INCIDENT

Six months after an employee opened a phishing email sent by ransomware gang Medusa, a Colorado-based pathology laboratory is notifying more than 1.8 million patients that their sensitive information was compromised - one of the largest breaches reported by a medical testing lab to U.S. federal regulators to date.

Summit Pathology as of Thursday is already facing eight proposed federal class action lawsuits filed in the past week centering on the breach. The Summit incident ranks among some of the largest breaches reported by medical laboratory testing firms to date.

IT systems affected by the incident contained demographic and healthcare information, including names, addresses, medical billing and insurance information, diagnoses, dates of birth, Social Security numbers, and financial information.

Incident Date

April 15, 2024

Estimated Cost

8 lawsuits pending

Type of Malware

No Malware identified

Threat Source