GRAFTON – A proposed class action lawsuit against Grafton City Hospital and Monongalia Health System claims patients’ personal health information was exposed following an email account compromise.
The complaint, filed September 17 in Taylor Circuit Court, also says the health care organizations didn’t use proper cybersecurity safeguards or promptly notify those affected. The lead plaintiff is identified only using her initials of L.L.B.
Grafton City Hospital discovered on or about May 6 that one of its email accounts had been compromised, potentially allowing an unauthorized person to access patients’ protected health information, according to the complaint.
An investigation ended June 11, but the complaint says patients were not notified until August. The plaintiff alleges the delay deprived affected patients of an earlier opportunity to protect themselves from potential misuse of their information.
Giatras
“Our firm has been at the forefront of pursuing relief for victims of data breaches, and we are deeply disappointed that these incidents continue to occur with alarming frequency,” attorney Troy Giatras told The West Virginia Record. “Individuals entrust healthcare providers with some of their most sensitive personal and medical information, and when that trust is broken, accountability is essential.
“We intend to pursue this case vigorously on behalf of the affected patients.”
The hospital’s breach notice, according to the complaint, said it had discovered “a compromise of a GCH email account” that “could have permitted an unauthorized individual to access your personal health information.”
The notice also said someone “could have had access to your health information related to services received at GCH,” according to the filing. Information potentially exposed included patients’ names, diagnoses, health insurance information, physicians and dates of service, the complaint says.
The lawsuit estimates that about 1,215 West Virginia residents may be members of the proposed class. The class would include West Virginia residents who received notice that their sensitive information was involved in the breach.
L.L.B. alleges the providers failed to reasonably safeguard patient information by inadequately training employees, monitoring systems and implementing encryption, multifactor authentication and other security measures.
The complaint says the defendants knew or should have known health care providers are targets for cyberattacks because they collect and retain sensitive medical and personal information. It alleges the organizations failed to take reasonable steps to address that foreseeable risk.
The complaint accuses the defendants of unjust enrichment, invasion of privacy, negligence, breach of confidentiality, prima facie negligence, breach of fiduciary duty and breach of implied contract. It also says the plaintiff intends to amend the complaint after a 45-day statutory cure period to add claims under the West Virginia Consumer Credit and Protection Act.
The plaintiff alleges affected patients face increased risks of identity theft and fraud, along with losses of privacy and control over their information, monitoring costs, potential future mitigation expenses and emotional distress.
The filing argues patients paid for health care services with the expectation that their confidential information would be protected. It alleges the defendants retained the benefits of those payments while failing to provide the promised level of data security.
Giatras said his firm expects data breach litigation to continue.
“The proliferation of cybersecurity incidents has created significant risks for ordinary consumers,” he said. “As organizations continue to collect and store vast amounts of personal information, they must take reasonable steps to protect it. When they fail to do so, we stand ready to pursue claims on behalf of those affected.”
Another attorney at The Giatras Law Firm agreed.
Stonestreet
“Data breaches do not end when notification letters are mailed,” Matthew Stonestreet said. “Individuals can spend years monitoring accounts, addressing fraudulent activity, and worrying about the future misuse of their personal information.
“This lawsuit seeks to ensure that affected patients have an opportunity to obtain relief and that appropriate safeguards are implemented going forward.”
The suit seeks class certification and the appointment of Giatras, Stonestreet and their firm as class counsel.
It seeks unspecified compensatory and punitive damages, restitution, interest, attorney fees and costs. It also requests credit monitoring and identity protection services, consumer credit insurance and a court order requiring a data security program that includes device encryption.
The case has been assigned to Circuit Judge Shawn D. Nines.
Taylor Circuit Court case number 26-C-47



