DataBreach.jpg

ST. LOUIS — The Missouri Military Academy is facing a proposed class-action lawsuit alleging that a June cyberattack exposed sensitive personal, financial and health information belonging to the plaintiff and thousands of other people.

The complaint was filed September 3 in U.S. District Court for the Eastern District of Missouri, Northern Division, by Kristin Adams-Vargas on behalf of herself and others similarly situated.

According to the complaint, unauthorized third parties infiltrated the academy's network servers and accessed protected health information and personally identifiable information. The lawsuit alleges the breach was discovered by the academy on June 14, and that patient data was confirmed stolen during the attack. 

The information allegedly involved in the breach includes names and, for some individuals, Social Security numbers, state identification numbers, medical and health information, financial information, debit card numbers, credit card numbers, expiration dates and access codes. 

The complaint says Adams-Vargas was among the individuals whose information was accessed.  

The lawsuit alleges the academy failed to properly secure the information entrusted to it and did not maintain its systems in accordance with applicable standards and regulations. 

The complaint references the federal Health Insurance Portability and Accountability Act, or HIPAA, including its Privacy Rule and Security Rule, while noting that Adams-Vargas is not bringing a direct claim for violation of HIPAA. 

Instead, the complaint says the alleged duties arising under HIPAA and other laws form the basis for other claims against the academy.  

The complaint alleges the academy knew or should have known that people providing sensitive information expected it to be protected. It further alleges the academy failed to implement adequate safeguards, including appropriate security protocols and encryption, and failed to take available steps to prevent unauthorized disclosure. 

The timing of notification to affected individuals is also a central allegation in the lawsuit. The complaint states that although the academy claims to have discovered the breach June 14, notices to affected individuals did not begin until August 31, approximately two months later. Adams-Vargas allegedly received a notice dated August 31. 

The complaint says affected individuals were not told when the breach occurred or how long it lasted. 

The plaintiff also alleges that the notice she received contained an incorrect name but the correct address. According to the complaint, Adams-Vargas contacted fellow faculty members and learned that they had received similar notices, which she attributed in the lawsuit to a possible mail-merge issue. 

The complaint says Adams-Vargas spent time determining whether the breach notice was legitimate and assessing its potential impact. 

It also alleges she explored credit-monitoring and identity-theft insurance options, monitored accounts and sought legal advice. The lawsuit claims affected individuals face an increased risk of fraud, identity theft and misuse of their information. 

The lawsuit proposes a nationwide class consisting of all individuals in the United States whose protected health information or personally identifiable information was exposed to unauthorized third parties as a result of the breach discovered June 14. 

The complaint alleges that the proposed class consists of thousands of people and says membership would be determined through an analysis of the academy's records. 

The complaint raises several questions it says are common to the proposed class, including whether the academy knew or should have known its systems were vulnerable, whether its security practices were reasonable, whether inadequate security measures contributed to the breach and whether the academy provided affected individuals with adequate and timely notice. 

It also asks whether the academy adequately addressed the vulnerabilities that permitted the breach to occur. 

The lawsuit asserts four causes of action: negligence, breach of confidence, breach of implied contract and breach of the implied covenant of good faith and fair dealing. 

The negligence claim alleges the academy failed to maintain adequate security practices, failed to timely and accurately disclose the breach, failed to implement processes to quickly detect security incidents and failed to adequately encrypt and monitor the information.  

The complaint also alleges that the academy's failure to provide timely notification prevented affected individuals from taking steps to protect their information and mitigate potential harm. It says the academy has not provided sufficient information about the extent of unauthorized access. 

Adams-Vargas is seeking certification of the case as a class action, damages in an amount to be determined, attorneys' fees and litigation costs, and injunctive and equitable relief. 

Among the requested measures are requirements that the academy encrypt data, establish a comprehensive information-security program, conduct security audits and penetration testing, strengthen access controls, regularly scan databases, provide employee security training and implement a threat-management program. 

Adams-Vargas is seeking compensatory damages and is being represented by Laura Van Note of Cole & Van Note in Oakland, Calif.

U.S. District Court for the Eastern District of Missouri, Northern Division case number: 2:26-cv-00065

More News