Heritage Provider Network, one of the largest physician-owned healthcare networks in the United States, and nine of its affiliated physician practices have agreed to pay nearly $50 million to settle consolidated class action lawsuits stemming from a major ransomware and data theft incident in December 2022. The breach affected more than 3.4 million current and former patients, whose sensitive personal and medical information was compromised. The impacted practices include Regal Medical Group, Lakeside Medical Organization, Greater Covina Medical Group, Affiliated Doctors of Orange County Medical Group, Arizona Health Advantage, AZPC Clinics, Community Surgery Center of Glendale, Pacific Family Hospice, and Valley’s Best Hospice. Plaintiffs in the lawsuits alleged that the compromised data, which included names, Social Security numbers, addresses, dates of birth, and medical information, was leaked on the dark web. Notices about the breach were sent to affected individuals in early 2023, alerting them to the exposure of their information. The $49.9 million settlement provides each class member with three years of complimentary identity and theft monitoring services. Eligible class members who submit valid claims can receive cash payments of up to $10,000 for documented fraud or out-of-pocket expenses related to the breach. The settlement aims to address the alleged failure of Heritage Provider Network and its affiliates to adequately protect patient data, as detailed in the class action complaints. The legal resolution covers an estimated 3,413,000 individuals who received notification of the breach. The settlement was reached after plaintiffs claimed that the defendants’ security measures were insufficient to prevent the ransomware attack and subsequent data theft. The incident has highlighted the ongoing risks faced by healthcare organizations in protecting sensitive patient information from cybercriminals. The settlement also underscores the significant financial and reputational consequences that can result from large-scale healthcare data breaches. Heritage Provider Network and its affiliates have not admitted wrongdoing but agreed to the settlement to resolve the litigation. The case serves as a reminder for healthcare providers to continually assess and strengthen their cybersecurity posture to mitigate the risk of future incidents. The settlement is one of the largest in recent years for a healthcare data breach, reflecting the scale and impact of the incident. Affected patients are encouraged to review the settlement terms and submit claims if eligible.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Heritage Provider Network and affiliated physician practices agreed to pay about $49.99 million to settle class-action litigation stemming from a hack affecting patient information. The settlement was reported in mid-October 2025 and represents the key disclosed development in the references provided.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.