PPLA Settlement: Breach Scope, Class Claims, and Final Approval

The PPLA settlement is a $6 million class action resolving claims against Planned Parenthood Los Angeles over a 2021 ransomware attack that exposed the personal and medical data of roughly 409,000 patients. The case, In re Planned Parenthood Los Angeles Data Incident Litigation (Case No. 21STCV44106), received final court approval on September 10, 2024, and payments to class members with valid claims were scheduled for distribution by late December 2024.1PPLASettlement.com. In Re Planned Parenthood Los Angeles Data Incident Litigation

What the Breach Exposed

Between October 9 and October 17, 2021, attackers gained access to PPLA’s network, installed ransomware, and exfiltrated patient files before locking the system down.2HIPAA Journal. Planned Parenthood Los Angeles Settlement Data Breach Lawsuit PPLA spotted the intrusion on October 17 and confirmed data theft on November 4, 2021.3Washington Post. Los Angeles Planned Parenthood Hack

The stolen files included patient names paired with one or more of the following: addresses, dates of birth, insurance ID numbers, and clinical details such as diagnoses, procedures, and prescriptions.4NBC News. Hackers Held Planned Parenthood Ransom, Accessed Data of 400,000 Users Because PPLA is a reproductive health provider, the compromised records reached into STD treatments, emergency contraception, and cancer screenings.2HIPAA Journal. Planned Parenthood Los Angeles Settlement Data Breach Lawsuit

PPLA disclosed the incident publicly on November 30, 2021, and told the U.S. Department of Health and Human Services Office for Civil Rights that 409,759 individuals were affected.5DataGuidance. USA: Planned Parenthood Los Angeles Notifies OCR of Data Security Incident No ransomware group publicly claimed responsibility, and early reporting found no sign the stolen data had appeared on dark web leak sites.6Cybereason. Planned Parenthood Ransomware Attack Puts 400,000 Patients at Substantial Risk

Who Was in the Class

The settlement class covered everyone who received a data breach notification from PPLA in or around November 2021. The settlement administrator counted 408,701 people within the class, and minors were included.7Simpluris. In Re Planned Parenthood Los Angeles Data Incident Litigation Case Study If you got a “PPLA Settlement” notice by mail or email in March 2024, that was your notification; the administrator used that generic label rather than referencing Planned Parenthood by name to protect recipients’ privacy.

What Class Members Could Claim

Valid claims fell into four buckets, and a class member could combine them.

Credit monitoring and identity theft insurance. Three years of TransUnion services valued at $29.95 per month, including credit monitoring, instant alerts, the ability to lock TransUnion and Equifax reports, and up to $1 million in identity theft insurance.8Simpluris. Second Amended Settlement Agreement

Statutory payment. A pro rata share of what remained in the fund after other costs, based on claims under the California Confidentiality of Medical Information Act. Estimated payments ran from about $66 at a 10% participation rate to roughly $359 at 2%.9Top Class Actions. Planned Parenthood Los Angeles Data Breach $6M Class Action Settlement

Documented time. Up to $210 for time spent dealing with the breach, at $30 per hour for up to seven hours, with documentation required.10PPLASettlement.com. PPLA Settlement FAQ

Out-of-pocket losses. Up to $10,000 for documented expenses fairly traceable to the breach, including bank fees, fraudulent charges, and credit-related costs incurred on or after October 9, 2021.10PPLASettlement.com. PPLA Settlement FAQ

If money remained 150 days after distribution, it went back out to participating class members when the average check would be at least $5. Otherwise the residual funded extended credit monitoring or went to a nonprofit recipient. Nothing reverted to PPLA.10PPLASettlement.com. PPLA Settlement FAQ

Deadlines and How Payments Went Out

Preliminary approval came on January 2, 2024. Notices went to the class starting March 8, 2024. The claim deadline was July 6, 2024, and the deadline to opt out or object was June 6, 2024.1PPLASettlement.com. In Re Planned Parenthood Los Angeles Data Incident Litigation Claims could be filed online at pplasettlement.com with a claim number and last name, or by paper form mailed to Simpluris in Santa Ana, California.

Simpluris sent payments by mailed check and by digital methods including PayPal, Zelle, Venmo, and ACH bank transfer. Payments and credit monitoring activation codes were scheduled for delivery by late December 2024. The final claims rate was 3.88%.7Simpluris. In Re Planned Parenthood Los Angeles Data Incident Litigation Case Study

Final Approval and What PPLA Conceded

The final fairness hearing was held August 8, 2024, before Judge Yvette M. Palazuelos, and the court granted final approval on September 10, 2024.1PPLASettlement.com. In Re Planned Parenthood Los Angeles Data Incident Litigation PPLA settled without admitting wrongdoing or liability.2HIPAA Journal. Planned Parenthood Los Angeles Settlement Data Breach Lawsuit The organization said it had “taken steps to improve cybersecurity following the breach,” though the settlement itself did not require specific security upgrades as injunctive relief.11Sacramento Bee. Planned Parenthood Los Angeles Cybersecurity Breach

A Note on HIPAA

The complaint referenced HIPAA obligations, but federal law does not let patients sue directly under HIPAA. The claims that actually drove the payout came from state law, primarily the California Confidentiality of Medical Information Act and the California Consumer Privacy Act. PPLA notified the HHS Office for Civil Rights of the breach in November 2021 as required, and no public enforcement action by OCR or the California Attorney General’s office has been reported in connection with the incident.5DataGuidance. USA: Planned Parenthood Los Angeles Notifies OCR of Data Security Incident